{
  "statistics": {
    "processing": [
      {
        "name": "CAPE",
        "time": 15.68
      },
      {
        "name": "AnalysisInfo",
        "time": 0.05
      },
      {
        "name": "BehaviorAnalysis",
        "time": 1.929
      },
      {
        "name": "Debug",
        "time": 0.003
      },
      {
        "name": "NetworkAnalysis",
        "time": 0.399
      },
      {
        "name": "UrlAnalysis",
        "time": 0.0
      },
      {
        "name": "script_log_processing",
        "time": 0.0
      },
      {
        "name": "ProcessMemory",
        "time": 0.0
      }
    ],
    "signatures": [
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "stealth_network",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_blocklist",
        "time": 0.0
      },
      {
        "name": "disable_driver_via_hvcidisallowedimages",
        "time": 0.0
      },
      {
        "name": "disable_hypervisor_protected_code_integrity",
        "time": 0.0
      },
      {
        "name": "pendingfilerenameoperations_Operations",
        "time": 0.0
      },
      {
        "name": "anomalous_deletefile",
        "time": 0.0
      },
      {
        "name": "antiav_360_libs",
        "time": 0.0
      },
      {
        "name": "antiav_ahnlab_libs",
        "time": 0.0
      },
      {
        "name": "antiav_avast_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bitdefender_libs",
        "time": 0.0
      },
      {
        "name": "antiav_bullguard_libs",
        "time": 0.0
      },
      {
        "name": "antiav_emsisoft_libs",
        "time": 0.0
      },
      {
        "name": "antiav_qurb_libs",
        "time": 0.0
      },
      {
        "name": "antiav_servicestop",
        "time": 0.0
      },
      {
        "name": "antiav_apioverride_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_guardpages",
        "time": 0.0
      },
      {
        "name": "antidebug_ntcreatethreadex",
        "time": 0.0
      },
      {
        "name": "antiav_nthookengine_libs",
        "time": 0.0
      },
      {
        "name": "antidebug_outputdebugstring",
        "time": 0.0
      },
      {
        "name": "antidebug_setunhandledexceptionfilter",
        "time": 0.0
      },
      {
        "name": "antidebug_windows",
        "time": 0.0
      },
      {
        "name": "antiemu_wine_func",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoocrash",
        "time": 0.0
      },
      {
        "name": "antisandbox_foregroundwindows",
        "time": 0.0
      },
      {
        "name": "mouse_movement_detect",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_objects",
        "time": 0.0
      },
      {
        "name": "antisandbox_script_timer",
        "time": 0.0
      },
      {
        "name": "antisandbox_sleep",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_libs",
        "time": 0.0
      },
      {
        "name": "antisandbox_unhook",
        "time": 0.0
      },
      {
        "name": "antivm_directory_objects",
        "time": 0.0
      },
      {
        "name": "antivm_generic_disk",
        "time": 0.0
      },
      {
        "name": "antivm_generic_scsi",
        "time": 0.0
      },
      {
        "name": "antivm_generic_services",
        "time": 0.0
      },
      {
        "name": "antivm_generic_system",
        "time": 0.0
      },
      {
        "name": "antivm_checks_available_memory",
        "time": 0.0
      },
      {
        "name": "detect_virtualization_via_recent_files",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_libs",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_window",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_events",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_libs",
        "time": 0.0
      },
      {
        "name": "api_spamming",
        "time": 0.0
      },
      {
        "name": "api_uuidfromstringa",
        "time": 0.0
      },
      {
        "name": "banker_prinimalka",
        "time": 0.0
      },
      {
        "name": "bcdedit_command",
        "time": 0.0
      },
      {
        "name": "bootkit",
        "time": 0.0
      },
      {
        "name": "potential_overwrite_mbr",
        "time": 0.0
      },
      {
        "name": "suspicious_ioctl_scsipassthough",
        "time": 0.0
      },
      {
        "name": "suspicious_iocontrol_codes",
        "time": 0.0
      },
      {
        "name": "browser_needed",
        "time": 0.0
      },
      {
        "name": "firefox_disables_process_tab",
        "time": 0.0
      },
      {
        "name": "regsvr32_squiblydoo_dll_load",
        "time": 0.0
      },
      {
        "name": "uac_bypass_cmstp",
        "time": 0.0
      },
      {
        "name": "uac_bypass_eventvwr",
        "time": 0.0
      },
      {
        "name": "uac_bypass_windows_Backup",
        "time": 0.0
      },
      {
        "name": "dotnet_code_compile",
        "time": 0.0
      },
      {
        "name": "queries_computer_name",
        "time": 0.0
      },
      {
        "name": "queries_user_name",
        "time": 0.0
      },
      {
        "name": "creates_largekey",
        "time": 0.0
      },
      {
        "name": "creates_nullvalue",
        "time": 0.0
      },
      {
        "name": "access_windows_passwords_vault",
        "time": 0.0
      },
      {
        "name": "dump_lsa_via_windows_error_reporting",
        "time": 0.0
      },
      {
        "name": "lsass_credential_dumping",
        "time": 0.0
      },
      {
        "name": "critical_process",
        "time": 0.0
      },
      {
        "name": "cryptopool_domains",
        "time": 0.0
      },
      {
        "name": "dead_connect",
        "time": 0.0
      },
      {
        "name": "dead_link",
        "time": 0.0
      },
      {
        "name": "debugs_self",
        "time": 0.0
      },
      {
        "name": "decoy_document",
        "time": 0.0
      },
      {
        "name": "decoy_image",
        "time": 0.0
      },
      {
        "name": "deletes_consolehost_history",
        "time": 0.0
      },
      {
        "name": "deletes_self",
        "time": 0.0
      },
      {
        "name": "deletes_shadow_copies",
        "time": 0.0
      },
      {
        "name": "deletes_system_state_backup",
        "time": 0.0
      },
      {
        "name": "dep_bypass",
        "time": 0.0
      },
      {
        "name": "dep_disable",
        "time": 0.0
      },
      {
        "name": "disables_mappeddrives_autodisconnect",
        "time": 0.0
      },
      {
        "name": "disables_spdy",
        "time": 0.0
      },
      {
        "name": "disables_wfp",
        "time": 0.0
      },
      {
        "name": "add_windows_defender_exclusions",
        "time": 0.0
      },
      {
        "name": "dll_load_uncommon_file_types",
        "time": 0.0
      },
      {
        "name": "document_script_exe_drop",
        "time": 0.0
      },
      {
        "name": "guloader_apis",
        "time": 0.0
      },
      {
        "name": "driver_load",
        "time": 0.0
      },
      {
        "name": "dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypted_ioc",
        "time": 0.0
      },
      {
        "name": "exec_crash",
        "time": 0.0
      },
      {
        "name": "process_creation_suspicious_location",
        "time": 0.0
      },
      {
        "name": "exploit_getbasekerneladdress",
        "time": 0.0
      },
      {
        "name": "exploit_gethaldispatchtable",
        "time": 0.0
      },
      {
        "name": "exploit_heapspray",
        "time": 0.0
      },
      {
        "name": "koadic_apis",
        "time": 0.0
      },
      {
        "name": "koadic_network_activity",
        "time": 0.0
      },
      {
        "name": "downloads_from_filehosting",
        "time": 0.0
      },
      {
        "name": "generic_phish",
        "time": 0.0
      },
      {
        "name": "http_request",
        "time": 0.0
      },
      {
        "name": "infostealer_browser",
        "time": 0.0
      },
      {
        "name": "infostealer_browser_password",
        "time": 0.0
      },
      {
        "name": "infostealer_cookies",
        "time": 0.0
      },
      {
        "name": "cryptbot_network",
        "time": 0.0
      },
      {
        "name": "masslogger_artifacts",
        "time": 0.0
      },
      {
        "name": "masslogger_version",
        "time": 0.0
      },
      {
        "name": "purplewave_network_activity",
        "time": 0.0
      },
      {
        "name": "quilclipper_behavior",
        "time": 0.0
      },
      {
        "name": "raccoon_behavior",
        "time": 0.0
      },
      {
        "name": "captures_screenshot",
        "time": 0.0
      },
      {
        "name": "vidar_behavior",
        "time": 0.0
      },
      {
        "name": "injection_createremotethread",
        "time": 0.0
      },
      {
        "name": "creates_suspended_process",
        "time": 0.0
      },
      {
        "name": "injection_explorer",
        "time": 0.0
      },
      {
        "name": "injection_needextension",
        "time": 0.0
      },
      {
        "name": "injection_network_traffic",
        "time": 0.0
      },
      {
        "name": "injection_runpe",
        "time": 0.0
      },
      {
        "name": "injection_rwx",
        "time": 0.0
      },
      {
        "name": "injection_themeinitapihook",
        "time": 0.0
      },
      {
        "name": "resumethread_remote_process",
        "time": 0.0
      },
      {
        "name": "injection_write_exe_process",
        "time": 0.0
      },
      {
        "name": "injection_write_process",
        "time": 0.0
      },
      {
        "name": "internet_dropper",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_named_pipe",
        "time": 0.0
      },
      {
        "name": "ipc_namedpipe",
        "time": 0.0
      },
      {
        "name": "js_phish",
        "time": 0.0
      },
      {
        "name": "js_suspicious_redirect",
        "time": 0.0
      },
      {
        "name": "loader_alien",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_internet_explorer_exporter",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_run_exe_helper_utility",
        "time": 0.0
      },
      {
        "name": "execute_ps_via_syncappvpublishingserver",
        "time": 0.0
      },
      {
        "name": "malicious_dynamic_function_loading",
        "time": 0.0
      },
      {
        "name": "encrypt_pcinfo",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agenttesla_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_agentteslat2_http",
        "time": 0.0
      },
      {
        "name": "encrypt_data_nanocore",
        "time": 0.0
      },
      {
        "name": "reads_memory_remote_process",
        "time": 0.0
      },
      {
        "name": "mimics_filetime",
        "time": 0.0
      },
      {
        "name": "amsi_bypass_via_com_registry",
        "time": 0.0
      },
      {
        "name": "access_auto_logons_via_registry",
        "time": 0.0
      },
      {
        "name": "access_boot_key_via_registry",
        "time": 0.0
      },
      {
        "name": "create_suspicious_lnk_files",
        "time": 0.0
      },
      {
        "name": "credential_access_via_windows_credential_history",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_microsoft_exchange",
        "time": 0.0
      },
      {
        "name": "dll_hijacking_via_waas_medic_svc_com_typelib",
        "time": 0.0
      },
      {
        "name": "execute_file_downloaded_via_openssh",
        "time": 0.0
      },
      {
        "name": "execute_safe_mode_from_suspicious_process",
        "time": 0.0
      },
      {
        "name": "execute_scripts_via_microsoft_management_console",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_processes_via_windows_mssql_service",
        "time": 0.0
      },
      {
        "name": "execution_from_self_extracting_archive",
        "time": 0.0
      },
      {
        "name": "ip_address_discovery_via_trusted_program",
        "time": 0.0
      },
      {
        "name": "load_dll_via_control_panel",
        "time": 0.0
      },
      {
        "name": "network_connection_via_suspicious_process",
        "time": 0.0
      },
      {
        "name": "potential_location_discovery_via_unusual_process",
        "time": 0.0
      },
      {
        "name": "store_executable_registry",
        "time": 0.0
      },
      {
        "name": "Suspicious_Execution_Via_MicrosoftExchangeTransportAgent",
        "time": 0.0
      },
      {
        "name": "suspicious_java_execution_via_win_scripts",
        "time": 0.0
      },
      {
        "name": "Suspicious_Scheduled_Task_Creation_Via_Masqueraded_XML_File",
        "time": 0.0
      },
      {
        "name": "uses_restart_manager_for_suspicious_activities",
        "time": 0.0
      },
      {
        "name": "modify_desktop_wallpaper",
        "time": 0.0
      },
      {
        "name": "modify_zoneid_ads",
        "time": 0.0
      },
      {
        "name": "move_file_on_reboot",
        "time": 0.0
      },
      {
        "name": "multiple_useragents",
        "time": 0.0
      },
      {
        "name": "network_anomaly",
        "time": 0.0
      },
      {
        "name": "network_bind",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_archive",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_free_webshoting",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_generic",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_opensource",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_pastesite",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_payload",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_serviceinterface",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_socialmedia",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_telegram",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_tempstorage",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_urlshortener",
        "time": 0.0
      },
      {
        "name": "network_cnc_https_useragent",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_exfil",
        "time": 0.0
      },
      {
        "name": "network_cnc_smtps_generic",
        "time": 0.0
      },
      {
        "name": "network_dns_idn",
        "time": 0.0
      },
      {
        "name": "network_dns_suspicious_querytype",
        "time": 0.0
      },
      {
        "name": "network_dns_tunneling_request",
        "time": 0.0
      },
      {
        "name": "network_document_http",
        "time": 0.0
      },
      {
        "name": "explorer_http",
        "time": 0.0
      },
      {
        "name": "network_fake_useragent",
        "time": 0.0
      },
      {
        "name": "legitimate_domain_abuse",
        "time": 0.0
      },
      {
        "name": "suspicious_communication_trusted_site",
        "time": 0.0
      },
      {
        "name": "network_tor",
        "time": 0.0
      },
      {
        "name": "office_com_load",
        "time": 0.0
      },
      {
        "name": "office_dotnet_load",
        "time": 0.0
      },
      {
        "name": "office_mshtml_load",
        "time": 0.0
      },
      {
        "name": "office_vb_load",
        "time": 0.0
      },
      {
        "name": "office_wmi_load",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882",
        "time": 0.0
      },
      {
        "name": "office_cve2017_11882_network",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444",
        "time": 0.0
      },
      {
        "name": "office_cve_2021_40444_m2",
        "time": 0.0
      },
      {
        "name": "office_flash_load",
        "time": 0.0
      },
      {
        "name": "office_postscript",
        "time": 0.0
      },
      {
        "name": "office_suspicious_processes",
        "time": 0.0
      },
      {
        "name": "office_write_exe",
        "time": 0.0
      },
      {
        "name": "persistence_via_autodial_dll_registry",
        "time": 0.0
      },
      {
        "name": "persistence_autorun",
        "time": 0.0
      },
      {
        "name": "persistence_autorun_tasks",
        "time": 0.0
      },
      {
        "name": "persistence_bootexecute",
        "time": 0.0
      },
      {
        "name": "persistence_registry_script",
        "time": 0.0
      },
      {
        "name": "powershell_network_connection",
        "time": 0.0
      },
      {
        "name": "powershell_download",
        "time": 0.0
      },
      {
        "name": "powershell_request",
        "time": 0.0
      },
      {
        "name": "createtoolhelp32snapshot_module_enumeration",
        "time": 0.0
      },
      {
        "name": "enumerates_running_processes",
        "time": 0.0
      },
      {
        "name": "process_interest",
        "time": 0.0
      },
      {
        "name": "process_needed",
        "time": 0.0
      },
      {
        "name": "mass_data_encryption",
        "time": 0.0
      },
      {
        "name": "ransomware_file_modifications",
        "time": 0.0
      },
      {
        "name": "ransomware_message",
        "time": 0.0
      },
      {
        "name": "nemty_network_activity",
        "time": 0.0
      },
      {
        "name": "nemty_note",
        "time": 0.0
      },
      {
        "name": "sodinokibi_behavior",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_registry",
        "time": 0.0
      },
      {
        "name": "blackrat_apis",
        "time": 0.0
      },
      {
        "name": "blackrat_network_activity",
        "time": 0.0
      },
      {
        "name": "blackrat_registry_keys",
        "time": 0.0
      },
      {
        "name": "dcrat_behavior",
        "time": 0.0
      },
      {
        "name": "karagany_system_event_objects",
        "time": 0.0
      },
      {
        "name": "rat_luminosity",
        "time": 0.0
      },
      {
        "name": "rat_nanocore",
        "time": 0.0
      },
      {
        "name": "netwire_behavior",
        "time": 0.0
      },
      {
        "name": "obliquerat_network_activity",
        "time": 0.0
      },
      {
        "name": "orcusrat_behavior",
        "time": 0.0
      },
      {
        "name": "trochilusrat_apis",
        "time": 0.0
      },
      {
        "name": "reads_self",
        "time": 0.0
      },
      {
        "name": "recon_beacon",
        "time": 0.0
      },
      {
        "name": "recon_programs",
        "time": 0.0
      },
      {
        "name": "recon_systeminfo",
        "time": 0.0
      },
      {
        "name": "accesses_recyclebin",
        "time": 0.0
      },
      {
        "name": "remcos_shell_code_dynamic_wrapper_x",
        "time": 0.0
      },
      {
        "name": "removes_zoneid_ads",
        "time": 0.0
      },
      {
        "name": "script_created_process",
        "time": 0.0
      },
      {
        "name": "script_network_activity",
        "time": 0.0
      },
      {
        "name": "suspicious_js_script",
        "time": 0.0
      },
      {
        "name": "javascript_timer",
        "time": 0.0
      },
      {
        "name": "secure_login_phishing",
        "time": 0.0
      },
      {
        "name": "securityxploded_modules",
        "time": 0.0
      },
      {
        "name": "get_clipboard_data",
        "time": 0.0
      },
      {
        "name": "sets_autoconfig_url",
        "time": 0.0
      },
      {
        "name": "spoofs_procname",
        "time": 0.0
      },
      {
        "name": "stack_pivot",
        "time": 0.0
      },
      {
        "name": "stack_pivot_file_created",
        "time": 0.0
      },
      {
        "name": "stack_pivot_process_create",
        "time": 0.0
      },
      {
        "name": "set_clipboard_data",
        "time": 0.0
      },
      {
        "name": "stealth_childproc",
        "time": 0.0
      },
      {
        "name": "stealth_file",
        "time": 0.0
      },
      {
        "name": "stealth_system_procname",
        "time": 0.0
      },
      {
        "name": "stealth_timeout",
        "time": 0.0
      },
      {
        "name": "stealth_window",
        "time": 0.0
      },
      {
        "name": "queries_keyboard_layout",
        "time": 0.0
      },
      {
        "name": "queries_locale_api",
        "time": 0.0
      },
      {
        "name": "terminates_remote_process",
        "time": 0.0
      },
      {
        "name": "trickbot_task_delete",
        "time": 0.0
      },
      {
        "name": "uiautomationcore_load",
        "time": 0.0
      },
      {
        "name": "user_enum",
        "time": 0.0
      },
      {
        "name": "virus",
        "time": 0.0
      },
      {
        "name": "neshta_files",
        "time": 0.0
      },
      {
        "name": "neshta_regkeys",
        "time": 0.0
      },
      {
        "name": "webmail_phish",
        "time": 0.0
      },
      {
        "name": "persists_dev_util",
        "time": 0.0
      },
      {
        "name": "spawns_dev_util",
        "time": 0.0
      },
      {
        "name": "alters_windows_utility",
        "time": 0.0
      },
      {
        "name": "overwrites_accessibility_utility",
        "time": 0.0
      },
      {
        "name": "Potential_Lateral_Movement_Via_SMBEXEC",
        "time": 0.0
      },
      {
        "name": "potential_WebShell_Via_ScreenConnectServer",
        "time": 0.0
      },
      {
        "name": "uses_Microsoft_HTML_Help_Executable",
        "time": 0.0
      },
      {
        "name": "wiper_zeroedbytes",
        "time": 0.0
      },
      {
        "name": "wmi_create_process",
        "time": 0.0
      },
      {
        "name": "wmi_script_process",
        "time": 0.0
      },
      {
        "name": "antianalysis_tls_section",
        "time": 0.0
      },
      {
        "name": "antivirus_clamav",
        "time": 0.0
      },
      {
        "name": "antivirus_virustotal",
        "time": 0.0
      },
      {
        "name": "bad_certs",
        "time": 0.0
      },
      {
        "name": "bad_ssl_certs",
        "time": 0.0
      },
      {
        "name": "banker_zeus_p2p",
        "time": 0.0
      },
      {
        "name": "banker_zeus_url",
        "time": 0.0
      },
      {
        "name": "binary_yara",
        "time": 0.0
      },
      {
        "name": "bot_athenahttp",
        "time": 0.0
      },
      {
        "name": "bot_dirtjumper",
        "time": 0.0
      },
      {
        "name": "bot_drive",
        "time": 0.0
      },
      {
        "name": "bot_drive2",
        "time": 0.0
      },
      {
        "name": "bot_madness",
        "time": 0.0
      },
      {
        "name": "phishing_kit_detected",
        "time": 0.0
      },
      {
        "name": "family_proxyback",
        "time": 0.0
      },
      {
        "name": "flare_capa_antianalysis",
        "time": 0.0
      },
      {
        "name": "flare_capa_collection",
        "time": 0.0
      },
      {
        "name": "flare_capa_communication",
        "time": 0.0
      },
      {
        "name": "flare_capa_compiler",
        "time": 0.0
      },
      {
        "name": "flare_capa_datamanipulation",
        "time": 0.0
      },
      {
        "name": "flare_capa_executable",
        "time": 0.0
      },
      {
        "name": "flare_capa_hostinteraction",
        "time": 0.0
      },
      {
        "name": "flare_capa_impact",
        "time": 0.0
      },
      {
        "name": "flare_capa_lib",
        "time": 0.0
      },
      {
        "name": "flare_capa_linking",
        "time": 0.0
      },
      {
        "name": "flare_capa_loadcode",
        "time": 0.0
      },
      {
        "name": "flare_capa_malwarefamily",
        "time": 0.0
      },
      {
        "name": "flare_capa_nursery",
        "time": 0.0
      },
      {
        "name": "flare_capa_persistence",
        "time": 0.0
      },
      {
        "name": "flare_capa_runtime",
        "time": 0.0
      },
      {
        "name": "flare_capa_targeting",
        "time": 0.0
      },
      {
        "name": "threatfox",
        "time": 0.0
      },
      {
        "name": "log4shell",
        "time": 0.0
      },
      {
        "name": "mimics_extension",
        "time": 0.0
      },
      {
        "name": "network_country_distribution",
        "time": 0.0
      },
      {
        "name": "network_cnc_http",
        "time": 0.0
      },
      {
        "name": "network_ip_exe",
        "time": 0.0
      },
      {
        "name": "network_dga",
        "time": 0.0
      },
      {
        "name": "network_dga_fraunhofer",
        "time": 0.0
      },
      {
        "name": "network_dyndns",
        "time": 0.003
      },
      {
        "name": "network_excessive_udp",
        "time": 0.0
      },
      {
        "name": "network_http",
        "time": 0.0
      },
      {
        "name": "network_icmp",
        "time": 0.0
      },
      {
        "name": "network_irc",
        "time": 0.0
      },
      {
        "name": "network_open_proxy",
        "time": 0.0
      },
      {
        "name": "network_questionable_http_path",
        "time": 0.0
      },
      {
        "name": "network_questionable_https_path",
        "time": 0.0
      },
      {
        "name": "network_smtp",
        "time": 0.0
      },
      {
        "name": "network_torgateway",
        "time": 0.001
      },
      {
        "name": "origin_langid",
        "time": 0.0
      },
      {
        "name": "origin_resource_langid",
        "time": 0.0
      },
      {
        "name": "overlay",
        "time": 0.0
      },
      {
        "name": "packer_unknown_pe_section_name",
        "time": 0.0
      },
      {
        "name": "packer_aspack",
        "time": 0.0
      },
      {
        "name": "packer_aspirecrypt",
        "time": 0.0
      },
      {
        "name": "packer_bedsprotector",
        "time": 0.0
      },
      {
        "name": "packer_confuser",
        "time": 0.0
      },
      {
        "name": "packer_enigma",
        "time": 0.0
      },
      {
        "name": "packer_entropy",
        "time": 0.0
      },
      {
        "name": "packer_mpress",
        "time": 0.0
      },
      {
        "name": "packer_nate",
        "time": 0.0
      },
      {
        "name": "packer_nspack",
        "time": 0.0
      },
      {
        "name": "packer_smartassembly",
        "time": 0.0
      },
      {
        "name": "packer_spices",
        "time": 0.0
      },
      {
        "name": "packer_themida",
        "time": 0.0
      },
      {
        "name": "packer_titan",
        "time": 0.0
      },
      {
        "name": "packer_upx",
        "time": 0.0
      },
      {
        "name": "packer_vmprotect",
        "time": 0.0
      },
      {
        "name": "packer_yoda",
        "time": 0.0
      },
      {
        "name": "pdf_annot_urls_checker",
        "time": 0.0
      },
      {
        "name": "polymorphic",
        "time": 0.0
      },
      {
        "name": "punch_plus_plus_pcres",
        "time": 0.0
      },
      {
        "name": "procmem_yara",
        "time": 0.0
      },
      {
        "name": "recon_checkip",
        "time": 0.0
      },
      {
        "name": "static_authenticode",
        "time": 0.0
      },
      {
        "name": "invalid_authenticode_signature",
        "time": 0.0
      },
      {
        "name": "static_dotnet_anomaly",
        "time": 0.0
      },
      {
        "name": "static_java",
        "time": 0.0
      },
      {
        "name": "static_pdf",
        "time": 0.0
      },
      {
        "name": "contains_pe_overlay",
        "time": 0.0
      },
      {
        "name": "static_pe_anomaly",
        "time": 0.0
      },
      {
        "name": "pe_compile_timestomping",
        "time": 0.0
      },
      {
        "name": "static_pe_pdbpath",
        "time": 0.0
      },
      {
        "name": "static_rat_config",
        "time": 0.0
      },
      {
        "name": "static_versioninfo_anomaly",
        "time": 0.0
      },
      {
        "name": "suricata_alert",
        "time": 0.0
      },
      {
        "name": "suspicious_html_body",
        "time": 0.0
      },
      {
        "name": "suspicious_html_name",
        "time": 0.0
      },
      {
        "name": "suspicious_html_title",
        "time": 0.0
      },
      {
        "name": "volatility_devicetree_1",
        "time": 0.0
      },
      {
        "name": "volatility_handles_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_1",
        "time": 0.0
      },
      {
        "name": "volatility_ldrmodules_2",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_1",
        "time": 0.0
      },
      {
        "name": "volatility_malfind_2",
        "time": 0.0
      },
      {
        "name": "volatility_modscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_1",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_2",
        "time": 0.0
      },
      {
        "name": "volatility_svcscan_3",
        "time": 0.0
      },
      {
        "name": "whois_create",
        "time": 0.0
      },
      {
        "name": "accesses_mailslot",
        "time": 0.0
      },
      {
        "name": "accesses_netlogon_regkey",
        "time": 0.001
      },
      {
        "name": "accesses_public_folder",
        "time": 0.0
      },
      {
        "name": "accesses_sysvol",
        "time": 0.0
      },
      {
        "name": "writes_sysvol",
        "time": 0.0
      },
      {
        "name": "adds_admin_user",
        "time": 0.0
      },
      {
        "name": "adds_user",
        "time": 0.0
      },
      {
        "name": "overwrites_admin_password",
        "time": 0.0
      },
      {
        "name": "antianalysis_detectfile",
        "time": 0.004
      },
      {
        "name": "antianalysis_detectreg",
        "time": 0.054
      },
      {
        "name": "modify_attachment_manager",
        "time": 0.0
      },
      {
        "name": "antiav_detectfile",
        "time": 0.009
      },
      {
        "name": "antiav_detectreg",
        "time": 0.255
      },
      {
        "name": "antiav_srp",
        "time": 0.0
      },
      {
        "name": "antiav_whitespace",
        "time": 0.0
      },
      {
        "name": "antidebug_devices",
        "time": 0.001
      },
      {
        "name": "antiemu_windefend",
        "time": 0.001
      },
      {
        "name": "antiemu_wine_reg",
        "time": 0.0
      },
      {
        "name": "antisandbox_cuckoo_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_fortinet_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_joe_anubis_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_sboxie_mutex",
        "time": 0.0
      },
      {
        "name": "antisandbox_sunbelt_files",
        "time": 0.0
      },
      {
        "name": "antisandbox_threattrack_files",
        "time": 0.0
      },
      {
        "name": "antivm_bochs_keys",
        "time": 0.005
      },
      {
        "name": "antivm_generic_bios",
        "time": 0.002
      },
      {
        "name": "antivm_generic_diskreg",
        "time": 0.011
      },
      {
        "name": "antivm_hyperv_keys",
        "time": 0.005
      },
      {
        "name": "antivm_parallels_keys",
        "time": 0.015
      },
      {
        "name": "antivm_recentdocs",
        "time": 0.0
      },
      {
        "name": "antivm_vbox_devices",
        "time": 0.001
      },
      {
        "name": "antivm_vbox_files",
        "time": 0.004
      },
      {
        "name": "antivm_vbox_keys",
        "time": 0.029
      },
      {
        "name": "antivm_vmware_devices",
        "time": 0.0
      },
      {
        "name": "antivm_vmware_files",
        "time": 0.001
      },
      {
        "name": "antivm_vmware_keys",
        "time": 0.019
      },
      {
        "name": "antivm_vmware_mutexes",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_files",
        "time": 0.0
      },
      {
        "name": "antivm_vpc_keys",
        "time": 0.01
      },
      {
        "name": "antivm_vpc_mutex",
        "time": 0.0
      },
      {
        "name": "antivm_xen_keys",
        "time": 0.015
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "gulpix_behavior",
        "time": 0.0
      },
      {
        "name": "ketrican_regkeys",
        "time": 0.003
      },
      {
        "name": "okrum_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_cridex",
        "time": 0.0
      },
      {
        "name": "geodo_banking_trojan",
        "time": 0.007
      },
      {
        "name": "banker_spyeye_mutexes",
        "time": 0.0
      },
      {
        "name": "banker_zeus_mutex",
        "time": 0.0
      },
      {
        "name": "bitcoin_opencl",
        "time": 0.0
      },
      {
        "name": "accesses_primary_patition",
        "time": 0.0
      },
      {
        "name": "direct_hdd_access",
        "time": 0.0
      },
      {
        "name": "enumerates_physical_drives",
        "time": 0.0
      },
      {
        "name": "physical_drive_access",
        "time": 0.0
      },
      {
        "name": "bot_russkill",
        "time": 0.0
      },
      {
        "name": "browser_addon",
        "time": 0.002
      },
      {
        "name": "chromium_browser_extension_directory",
        "time": 0.0
      },
      {
        "name": "browser_helper_object",
        "time": 0.0
      },
      {
        "name": "browser_security",
        "time": 0.004
      },
      {
        "name": "browser_startpage",
        "time": 0.0
      },
      {
        "name": "ie_disables_process_tab",
        "time": 0.0
      },
      {
        "name": "odbcconf_bypass",
        "time": 0.0
      },
      {
        "name": "squiblydoo_bypass",
        "time": 0.0
      },
      {
        "name": "squiblytwo_bypass",
        "time": 0.0
      },
      {
        "name": "bypass_chromium_protection",
        "time": 0.0
      },
      {
        "name": "bypass_firewall",
        "time": 0.005
      },
      {
        "name": "checks_uac_status",
        "time": 0.001
      },
      {
        "name": "uac_bypass_cmstpcom",
        "time": 0.0
      },
      {
        "name": "uac_bypass_delegateexecute_sdclt",
        "time": 0.0
      },
      {
        "name": "uac_bypass_fodhelper",
        "time": 0.0
      },
      {
        "name": "cape_extracted_content",
        "time": 0.0
      },
      {
        "name": "carberp_mutex",
        "time": 0.0
      },
      {
        "name": "clears_logs",
        "time": 0.0
      },
      {
        "name": "cmdline_obfuscation",
        "time": 0.0
      },
      {
        "name": "cmdline_switches",
        "time": 0.0
      },
      {
        "name": "cmdline_terminate",
        "time": 0.0
      },
      {
        "name": "cmdline_forfiles_wildcard",
        "time": 0.0
      },
      {
        "name": "cmdline_http_link",
        "time": 0.0
      },
      {
        "name": "cmdline_long_string",
        "time": 0.0
      },
      {
        "name": "cmdline_reversed_http_link",
        "time": 0.0
      },
      {
        "name": "long_commandline",
        "time": 0.0
      },
      {
        "name": "powershell_renamed_commandline",
        "time": 0.0
      },
      {
        "name": "copies_self",
        "time": 0.0
      },
      {
        "name": "credwiz_credentialaccess",
        "time": 0.0
      },
      {
        "name": "enables_wdigest",
        "time": 0.0
      },
      {
        "name": "vaultcmd_credentialaccess",
        "time": 0.0
      },
      {
        "name": "file_credential_store_access",
        "time": 0.001
      },
      {
        "name": "file_credential_store_write",
        "time": 0.0
      },
      {
        "name": "kerberos_credential_access_via_rubeus",
        "time": 0.0
      },
      {
        "name": "registry_credential_dumping",
        "time": 0.0
      },
      {
        "name": "registry_credential_store_access",
        "time": 0.002
      },
      {
        "name": "registry_lsa_secrets_access",
        "time": 0.001
      },
      {
        "name": "comsvcs_credentialdump",
        "time": 0.0
      },
      {
        "name": "cryptomining_stratum_command",
        "time": 0.0
      },
      {
        "name": "cypherit_mutexes",
        "time": 0.0
      },
      {
        "name": "darkcomet_regkeys",
        "time": 0.003
      },
      {
        "name": "datop_loader",
        "time": 0.0
      },
      {
        "name": "deepfreeze_mutex",
        "time": 0.0
      },
      {
        "name": "deletes_executed_files",
        "time": 0.0
      },
      {
        "name": "disables_app_launch",
        "time": 0.0
      },
      {
        "name": "disables_auto_app_termination",
        "time": 0.0
      },
      {
        "name": "disables_appv_virtualization",
        "time": 0.0
      },
      {
        "name": "disables_backups",
        "time": 0.002
      },
      {
        "name": "disables_browser_warn",
        "time": 0.004
      },
      {
        "name": "disables_context_menus",
        "time": 0.0
      },
      {
        "name": "disables_cpl_disable",
        "time": 0.0
      },
      {
        "name": "disables_crashdumps",
        "time": 0.0
      },
      {
        "name": "disables_event_logging",
        "time": 0.0
      },
      {
        "name": "disables_folder_options",
        "time": 0.0
      },
      {
        "name": "disables_notificationcenter",
        "time": 0.0
      },
      {
        "name": "disables_power_options",
        "time": 0.001
      },
      {
        "name": "disables_restore_default_state",
        "time": 0.0
      },
      {
        "name": "disables_run_command",
        "time": 0.0
      },
      {
        "name": "disables_smartscreen",
        "time": 0.0
      },
      {
        "name": "disables_startmenu_search",
        "time": 0.0
      },
      {
        "name": "disables_system_restore",
        "time": 0.001
      },
      {
        "name": "disables_uac",
        "time": 0.0
      },
      {
        "name": "disables_wer",
        "time": 0.0
      },
      {
        "name": "disables_windows_defender",
        "time": 0.001
      },
      {
        "name": "disables_windows_defender_logging",
        "time": 0.001
      },
      {
        "name": "removes_windows_defender_contextmenu",
        "time": 0.001
      },
      {
        "name": "removes_windows_defender_updates",
        "time": 0.0
      },
      {
        "name": "windows_defender_powershell",
        "time": 0.0
      },
      {
        "name": "disables_windows_file_protection",
        "time": 0.0
      },
      {
        "name": "disables_windowsupdate",
        "time": 0.0
      },
      {
        "name": "disables_winfirewall",
        "time": 0.0
      },
      {
        "name": "adfind_domain_enumeration",
        "time": 0.0
      },
      {
        "name": "domain_enumeration_commands",
        "time": 0.0
      },
      {
        "name": "andromut_mutexes",
        "time": 0.0
      },
      {
        "name": "downloader_cabby",
        "time": 0.0
      },
      {
        "name": "phorpiex_mutexes",
        "time": 0.0
      },
      {
        "name": "protonbot_mutexes",
        "time": 0.0
      },
      {
        "name": "driver_filtermanager",
        "time": 0.0
      },
      {
        "name": "dropper",
        "time": 0.0
      },
      {
        "name": "dll_archive_execution",
        "time": 0.0
      },
      {
        "name": "lnk_archive_execution",
        "time": 0.0
      },
      {
        "name": "script_archive_execution",
        "time": 0.0
      },
      {
        "name": "excel4_macro_urls",
        "time": 0.0
      },
      {
        "name": "escalate_privilege_via_ntlm_relay",
        "time": 0.0
      },
      {
        "name": "spooler_access",
        "time": 0.0
      },
      {
        "name": "spooler_svc_start",
        "time": 0.0
      },
      {
        "name": "mapped_drives_uac",
        "time": 0.0
      },
      {
        "name": "hides_recycle_bin_icon",
        "time": 0.0
      },
      {
        "name": "apocalypse_stealer_file_behavior",
        "time": 0.001
      },
      {
        "name": "arkei_files",
        "time": 0.0
      },
      {
        "name": "azorult_mutexes",
        "time": 0.001
      },
      {
        "name": "infostealer_bitcoin",
        "time": 0.005
      },
      {
        "name": "cryptbot_files",
        "time": 0.001
      },
      {
        "name": "echelon_files",
        "time": 0.001
      },
      {
        "name": "infostealer_ftp",
        "time": 0.088
      },
      {
        "name": "infostealer_im",
        "time": 0.051
      },
      {
        "name": "infostealer_mail",
        "time": 0.017
      },
      {
        "name": "masslogger_files",
        "time": 0.0
      },
      {
        "name": "poullight_files",
        "time": 0.002
      },
      {
        "name": "purplewave_mutexes",
        "time": 0.0
      },
      {
        "name": "quilclipper_mutexes",
        "time": 0.0
      },
      {
        "name": "qulab_files",
        "time": 0.002
      },
      {
        "name": "qulab_mutexes",
        "time": 0.0
      },
      {
        "name": "asyncrat_mutex",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_ASPNet_Compiler",
        "time": 0.0
      },
      {
        "name": "Evade_Execute_Via_DeviceCredentialDeployment",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Filter_Manager_Control",
        "time": 0.0
      },
      {
        "name": "Evade_Execution_Via_Intel_GFXDownloadWrapper",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_appvlp",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_OpenSSH",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_pcalua",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_PesterPSModule",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_ScriptRunner",
        "time": 0.0
      },
      {
        "name": "execute_binary_via_ttdinject",
        "time": 0.0
      },
      {
        "name": "Execute_Binary_Via_VisualStudioLiveShare",
        "time": 0.0
      },
      {
        "name": "Execute_Msiexec_Via_Explorer",
        "time": 0.0
      },
      {
        "name": "execute_remote_msi",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_runscripthelper",
        "time": 0.0
      },
      {
        "name": "execute_suspicious_powershell_via_sqlps",
        "time": 0.0
      },
      {
        "name": "Indirect_Command_Execution_Via_ConsoleWindowHost",
        "time": 0.0
      },
      {
        "name": "Perform_Malicious_Activities_Via_Headless_Browser",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_CertOC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_MSIEXEC",
        "time": 0.0
      },
      {
        "name": "Register_DLL_Via_Odbcconf",
        "time": 0.0
      },
      {
        "name": "Scriptlet_Proxy_Execution_Via_Pubprn",
        "time": 0.0
      },
      {
        "name": "ie_martian_children",
        "time": 0.0
      },
      {
        "name": "office_martian_children",
        "time": 0.0
      },
      {
        "name": "mimics_icon",
        "time": 0.0
      },
      {
        "name": "masquerade_process_name",
        "time": 0.011
      },
      {
        "name": "mimikatz_modules",
        "time": 0.0
      },
      {
        "name": "ms_office_cmd_rce",
        "time": 0.0
      },
      {
        "name": "mount_copy_to_webdav_share",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_legit_utilities",
        "time": 0.0
      },
      {
        "name": "potential_protocol_tunneling_via_qemu",
        "time": 0.0
      },
      {
        "name": "suspicious_execution_via_dotnet_remoting",
        "time": 0.0
      },
      {
        "name": "modify_certs",
        "time": 0.0
      },
      {
        "name": "dotnet_clr_usagelog_regkeys",
        "time": 0.0
      },
      {
        "name": "modify_hostfile",
        "time": 0.0
      },
      {
        "name": "modify_oem_information",
        "time": 0.001
      },
      {
        "name": "modify_security_center_warnings",
        "time": 0.001
      },
      {
        "name": "modify_uac_prompt",
        "time": 0.001
      },
      {
        "name": "network_dns_blockchain",
        "time": 0.0
      },
      {
        "name": "network_dns_opennic",
        "time": 0.001
      },
      {
        "name": "network_dns_paste_site",
        "time": 0.001
      },
      {
        "name": "network_dns_reverse_proxy",
        "time": 0.0
      },
      {
        "name": "network_dns_temp_file_storage",
        "time": 0.001
      },
      {
        "name": "network_dns_temp_urldns",
        "time": 0.0
      },
      {
        "name": "network_dns_url_shortener",
        "time": 0.001
      },
      {
        "name": "network_dns_doh_tls",
        "time": 0.0
      },
      {
        "name": "suspicious_tld",
        "time": 0.005
      },
      {
        "name": "network_tor_service",
        "time": 0.0
      },
      {
        "name": "office_code_page",
        "time": 0.0
      },
      {
        "name": "office_addinloading",
        "time": 0.0
      },
      {
        "name": "office_perfkey",
        "time": 0.0
      },
      {
        "name": "office_macro",
        "time": 0.0
      },
      {
        "name": "changes_trust_center_settings",
        "time": 0.0
      },
      {
        "name": "disables_vba_trust_access",
        "time": 0.0
      },
      {
        "name": "office_macro_autoexecution",
        "time": 0.0
      },
      {
        "name": "office_macro_ioc",
        "time": 0.0
      },
      {
        "name": "office_macro_malicious_prediction",
        "time": 0.0
      },
      {
        "name": "office_macro_suspicious",
        "time": 0.0
      },
      {
        "name": "rtf_aslr_bypass",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_characterset",
        "time": 0.0
      },
      {
        "name": "rtf_anomaly_version",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_content",
        "time": 0.0
      },
      {
        "name": "rtf_embedded_office_file",
        "time": 0.0
      },
      {
        "name": "rtf_exploit_static",
        "time": 0.0
      },
      {
        "name": "office_security",
        "time": 0.001
      },
      {
        "name": "accesses_office_username",
        "time": 0.001
      },
      {
        "name": "office_anomalous_feature",
        "time": 0.0
      },
      {
        "name": "office_dde_command",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_mutex",
        "time": 0.0
      },
      {
        "name": "packer_armadillo_regkey",
        "time": 0.001
      },
      {
        "name": "persistence_ads",
        "time": 0.0
      },
      {
        "name": "persistence_safeboot",
        "time": 0.0
      },
      {
        "name": "persistence_ifeo",
        "time": 0.0
      },
      {
        "name": "persistence_silent_process_exit",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_registry",
        "time": 0.0
      },
      {
        "name": "persistence_rdp_shadowing",
        "time": 0.0
      },
      {
        "name": "persistence_service",
        "time": 0.0
      },
      {
        "name": "persistence_shim_database",
        "time": 0.001
      },
      {
        "name": "powerpool_mutexes",
        "time": 0.0
      },
      {
        "name": "powershell_scriptblock_logging",
        "time": 0.0
      },
      {
        "name": "powershell_command_suspicious",
        "time": 0.0
      },
      {
        "name": "powershell_history_save_mod",
        "time": 0.0
      },
      {
        "name": "powershell_renamed",
        "time": 0.0
      },
      {
        "name": "powershell_reversed",
        "time": 0.0
      },
      {
        "name": "powershell_variable_obfuscation",
        "time": 0.0
      },
      {
        "name": "prevents_safeboot",
        "time": 0.0
      },
      {
        "name": "cmdline_process_discovery",
        "time": 0.0
      },
      {
        "name": "cryptomix_mutexes",
        "time": 0.0
      },
      {
        "name": "dharma_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_extensions",
        "time": 0.008
      },
      {
        "name": "ransomware_files",
        "time": 0.013
      },
      {
        "name": "fonix_mutexes",
        "time": 0.0
      },
      {
        "name": "gandcrab_mutexes",
        "time": 0.0
      },
      {
        "name": "germanwiper_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_mutexes",
        "time": 0.0
      },
      {
        "name": "medusalocker_regkeys",
        "time": 0.001
      },
      {
        "name": "nemty_mutexes",
        "time": 0.0
      },
      {
        "name": "nemty_regkeys",
        "time": 0.001
      },
      {
        "name": "pysa_mutexes",
        "time": 0.0
      },
      {
        "name": "ransomware_radamant",
        "time": 0.001
      },
      {
        "name": "ransomware_recyclebin",
        "time": 0.0
      },
      {
        "name": "revil_mutexes",
        "time": 0.001
      },
      {
        "name": "ransomware_revil_regkey",
        "time": 0.0
      },
      {
        "name": "satan_mutexes",
        "time": 0.0
      },
      {
        "name": "snake_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransom_mutexes",
        "time": 0.0
      },
      {
        "name": "stop_ransomware_cmd",
        "time": 0.0
      },
      {
        "name": "ransomware_stopdjvu",
        "time": 0.0
      },
      {
        "name": "rat_beebus_mutexes",
        "time": 0.0
      },
      {
        "name": "blacknet_mutexes",
        "time": 0.0
      },
      {
        "name": "blackrat_mutexes",
        "time": 0.0
      },
      {
        "name": "crat_mutexes",
        "time": 0.0
      },
      {
        "name": "dcrat_files",
        "time": 0.0
      },
      {
        "name": "dcrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_fynloski_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_mutexes",
        "time": 0.0
      },
      {
        "name": "limerat_regkeys",
        "time": 0.003
      },
      {
        "name": "lodarat_file_behavior",
        "time": 0.0
      },
      {
        "name": "modirat_behavior",
        "time": 0.001
      },
      {
        "name": "njrat_regkeys",
        "time": 0.0
      },
      {
        "name": "obliquerat_files",
        "time": 0.001
      },
      {
        "name": "obliquerat_mutexes",
        "time": 0.0
      },
      {
        "name": "parallax_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_pcclient",
        "time": 0.001
      },
      {
        "name": "rat_plugx_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_poisonivy_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_quasar_mutexes",
        "time": 0.0
      },
      {
        "name": "ratsnif_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_spynet",
        "time": 0.0
      },
      {
        "name": "venomrat_mutexes",
        "time": 0.0
      },
      {
        "name": "warzonerat_files",
        "time": 0.0
      },
      {
        "name": "warzonerat_regkeys",
        "time": 0.001
      },
      {
        "name": "xpertrat_files",
        "time": 0.0
      },
      {
        "name": "xpertrat_mutexes",
        "time": 0.0
      },
      {
        "name": "rat_xtreme_mutexes",
        "time": 0.0
      },
      {
        "name": "recon_fingerprint",
        "time": 0.002
      },
      {
        "name": "remcos_files",
        "time": 0.0
      },
      {
        "name": "remcos_mutexes",
        "time": 0.0
      },
      {
        "name": "remcos_regkeys",
        "time": 0.002
      },
      {
        "name": "rdptcp_key",
        "time": 0.0
      },
      {
        "name": "uses_rdp_clip",
        "time": 0.0
      },
      {
        "name": "uses_remote_desktop_session",
        "time": 0.0
      },
      {
        "name": "removes_networking_icon",
        "time": 0.0
      },
      {
        "name": "removes_pinned_programs",
        "time": 0.0
      },
      {
        "name": "removes_security_maintenance_icon",
        "time": 0.0
      },
      {
        "name": "removes_startmenu_defaults",
        "time": 0.001
      },
      {
        "name": "removes_username_startmenu",
        "time": 0.0
      },
      {
        "name": "spicyhotpot_behavior",
        "time": 0.0
      },
      {
        "name": "sniffer_winpcap",
        "time": 0.001
      },
      {
        "name": "spreading_autoruninf",
        "time": 0.0
      },
      {
        "name": "stealth_hidden_extension",
        "time": 0.0
      },
      {
        "name": "stealth_hiddenreg",
        "time": 0.001
      },
      {
        "name": "stealth_hide_notifications",
        "time": 0.001
      },
      {
        "name": "stealth_webhistory",
        "time": 0.0
      },
      {
        "name": "sysinternals_psexec",
        "time": 0.0
      },
      {
        "name": "sysinternals_tools",
        "time": 0.0
      },
      {
        "name": "language_check_registry",
        "time": 0.0
      },
      {
        "name": "tampers_etw",
        "time": 0.001
      },
      {
        "name": "lsa_tampering",
        "time": 0.0
      },
      {
        "name": "tampers_powershell_logging",
        "time": 0.0
      },
      {
        "name": "targeted_flame",
        "time": 0.0
      },
      {
        "name": "territorial_disputes_sigs",
        "time": 0.084
      },
      {
        "name": "trickbot_mutex",
        "time": 0.0
      },
      {
        "name": "fleercivet_mutex",
        "time": 0.0
      },
      {
        "name": "lokibot_mutexes",
        "time": 0.001
      },
      {
        "name": "ursnif_behavior",
        "time": 0.001
      },
      {
        "name": "uses_adfind",
        "time": 0.0
      },
      {
        "name": "uses_ms_protocol",
        "time": 0.0
      },
      {
        "name": "neshta_mutexes",
        "time": 0.0
      },
      {
        "name": "renamer_mutexes",
        "time": 0.0
      },
      {
        "name": "owa_web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_files",
        "time": 0.0
      },
      {
        "name": "web_shell_processes",
        "time": 0.0
      },
      {
        "name": "dotnet_csc_build",
        "time": 0.0
      },
      {
        "name": "mavinject_lolbin",
        "time": 0.0
      },
      {
        "name": "multiple_explorer_instances",
        "time": 0.0
      },
      {
        "name": "script_tool_executed",
        "time": 0.0
      },
      {
        "name": "suspicious_certutil_use",
        "time": 0.0
      },
      {
        "name": "suspicious_command_tools",
        "time": 0.005
      },
      {
        "name": "suspicious_mpcmdrun_use",
        "time": 0.0
      },
      {
        "name": "suspicious_ping_use",
        "time": 0.0
      },
      {
        "name": "uses_powershell_copyitem",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities",
        "time": 0.006
      },
      {
        "name": "uses_windows_utilities_appcmd",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_csvde_ldifde",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_cipher",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_clickonce",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_curl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_dsquery",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_esentutl",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_finger",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_mode",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_ntdsutil",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_nltest",
        "time": 0.0
      },
      {
        "name": "uses_windows_utilities_xcopy",
        "time": 0.0
      },
      {
        "name": "wmic_command_suspicious",
        "time": 0.0
      },
      {
        "name": "scrcons_wmi_script_consumer",
        "time": 0.0
      },
      {
        "name": "allaple_mutexes",
        "time": 0.0
      }
    ],
    "reporting": [
      {
        "name": "BinGraph",
        "time": 0.0
      }
    ]
  },
  "target": {
    "category": "file",
    "file": {
      "name": "E87.20_CheckPointVPN.msi",
      "path": "/opt/CAPEv2/storage/binaries/ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
      "guest_paths": "",
      "size": 35328000,
      "crc32": "C0A65F59",
      "md5": "66cf09849cd854c2e6717ad2db5e0248",
      "sha1": "0a329279777bfb9f501ac2694a7ad21df31c73ba",
      "sha256": "ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
      "sha512": "5fa5123f0020ff491ea03903bd973b936d1bd17a99d85c429d755c0f78f35a2c0067c790a8d67756fdb755515284e63b604fa879efbd485bfb3bce49b3a46ecf",
      "rh_hash": null,
      "ssdeep": "786432:yXCNAW5dEboRxf/UxQq+8fBzDIbLP6APb1CeG:vAW5eboRhh8fBPmyA",
      "type": "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Check Point Endpoint Security VPN version E87.20 build 98.61.4605, Author: Check Point Software Technologies Ltd., Keywords: Installer, Comments: This installer database contains the logic and data required to install Check Point VPN., Template: Intel;1033, Revision Number: {3289703B-61D3-428B-A496-24FF37BCE3C6}, Create Time/Date: Wed Feb 22 15:34:44 2023, Last Saved Time/Date: Wed Feb 22 15:34:44 2023, Number of Pages: 300, Number of Words: 10, Name of Creating Application: Windows Installer XML Toolset (3.8.1128.0), Security: 2",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T13E7701027E42C472DBAE16344039F7BE6ABDD820172489CB97D83D3E6D705C2673A667",
      "sha3_384": "fbf4b7389ead1408d3fd3b8ee510624e133a867ebe425d196bf5e6fb30ff02dcb350931a0ce7152832a171a70bfbd535",
      "data": null,
      "strings": [
        "}+QGB",
        "DlhK[\"",
        "*Z%u*C",
        "\\puXu",
        "Ba.J8",
        "/8~16",
        "\"cq{s",
        "ExitWindowsEx",
        ">4>]>u>~>",
        "5T8\\8d8l8t8|8",
        "l%d]w|",
        "6(686H6L6\\6`6l6|6",
        "do^9#",
        "swH,F",
        "=tJMs",
        "uswz]jPYR",
        "X7g4y6/F",
        "aUV#-Ja$",
        "C05_E",
        "\\$$1i",
        "}_.Cv",
        "mIt,[A^",
        "J#~?H\"",
        "T:)9[",
        "=yUiJj",
        "G1XF<W",
        "ffL~*",
        "@AYIY",
        "GetEnvironmentStringsW",
        "REQUEST_VERIFY",
        "u/s]w",
        "&~cSLUh]",
        "scYv1$)",
        "LmlNp",
        "0&(\"C",
        "id.D6",
        "SUVWhp6#",
        "id-cmc-statusInfo",
        ">8>I>S>Y>b>{>",
        "R0RpR",
        "bind(port=%hu) failed: %s",
        "MS6m?",
        "Xbbll",
        "\\vsmonapi.dll",
        "%rt|^",
        "ORJr)",
        "n/fw ",
        "oz0lzs",
        "tl_'W/",
        "G`4Sg",
        "q$V=|",
        "?g,rw7",
        "2)vE'j%",
        "S~%@8",
        ",/xp:|",
        "u\"/5c",
        ".PjRW",
        "Failed to remove registry key:  ",
        "1gkyfS",
        "tG;n'f^",
        "}}1w-}5",
        "=\">V>h>d?n?s?",
        "y%y5yUyeyuy",
        "Attempting to send process id 0x%x message id: %u",
        "0,0G0b0}0",
        "z`m9<1",
        "n9!}z",
        "u}uvthdNA",
        "t,'zz3",
        ";+V'?",
        "pt-PT",
        "Failed to enumerate binary table",
        "Wh D$",
        "<XROTOVO^ObOdOhO",
        "Ybj-kr",
        "WIN32_MERGER",
        "9!9&969;9@9P9U9Z9j9o9t9",
        "UTZw,",
        "1D1k1",
        "K&g'[N",
        "user=%s",
        "cj_{&",
        "?Xw e",
        "LYh'7",
        "?<?T?x?",
        "=gt):",
        "$L\"cc",
        "Rtlez",
        "jyjzj",
        ".8nxRVK",
        "x1xDg$(",
        "c'cGSg",
        "pPhc%].f@",
        "-A6~nx%",
        "~H;D!",
        "038|<>,",
        "0}C`V",
        "?1>>|d",
        "n~8?o",
        "1d6wd",
        "oS_@sr",
        "cQH'>",
        "Y3q,W",
        "m|3`R",
        "wKrXJ",
        "u49ciP",
        "operation not permitted",
        "passwset ",
        "PRM=|q",
        "I\"ex\"[",
        "OnFreshAfter:  SetFWStartup",
        "mF;hhY",
        "?$?+?4?=?F?M?V?j?s?",
        " 4R11.z",
        "8 8(8,888@8D8X8\\8h8p8t8",
        "SCUIAPI.dll",
        "jb7W#z:",
        "7M7V7\\7",
        "T|*>5",
        "D,QFH",
        ":/;@;E;L;S;\\;u;",
        "bgEUGB0u",
        "9fl9u<c",
        "q2*2w",
        "C1A5G>>",
        "$,7%Q",
        "cw03a",
        "GF^{%",
        "Excluded",
        "49q1B",
        "sk:PH",
        "{ygXz",
        "h8?zmo45",
        "11A~11",
        "LogonISReg.dll",
        "515N5S5c5",
        "FeatureAntiVirus:  FreshAfter finished.",
        ">VLH ",
        "DV-sZ",
        "MF]bC+",
        "vyAv7/",
        "2B\"K>mE",
        "n*zry",
        "InZVK",
        "z<Y(VH",
        "WatchdogAPI.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        ",_K5e",
        "/jGhqj",
        "KWF1(",
        "/d_?6",
        "PKCS7_sign_add_signer",
        "YK&NQ",
        "';D\\\\",
        "6\\.l3",
        "Sy#<-",
        "TWC!*",
        "im4W`",
        "Found pending candidate for reuse and CURLOPT_PIPEWAIT is set",
        "bhCv4",
        "3(^(FiWS",
        "aL1;Y",
        "5A5V5x5",
        "RSA Data Security, Inc. PKCS",
        "XK[-EK",
        "V6_^A",
        "v~A<T",
        "Co$^PX",
        "set-brand-Visa",
        "read timeout expired",
        "7.cG_",
        "*R{10%pZP",
        "LL-LZa",
        "ReadFile {} failed {}",
        ",]road",
        "!H&.\"E?",
        "D$HPW",
        "YGVCTvG",
        "~iz\"1",
        "-Sp/iYlL",
        "J*G4o",
        "|7KAr",
        "CANT_CONVERT_PROPERTY",
        "_\\;Fq_",
        "EXPORT",
        "AUG+`cUS",
        "N/A{V",
        "Bo7:>K",
        "8jTs)",
        "^*^j^",
        "e: YH",
        "$xwN?",
        "sVer = %s",
        "<.=>=",
        "76rvN",
        "13j#*KA",
        "~fM;{",
        "ssl2_enc_init",
        "sslv3 alert certificate unknown",
        "N:}[\\",
        "ETTHP",
        "mL{$Gc",
        "?#&*?",
        "zlib not supported",
        "SERVERLIST",
        "IT9fIB)]",
        "id-camellia128-wrap",
        "(FUpST",
        "~u?{>",
        "54d19",
        "9gmHA",
        "[2.!b",
        "!$NmY",
        "PBE-SHA1-DES",
        ":-f 6",
        "FeatureIMSecurity:  Loading imsinstall.dll.",
        ")3+r3",
        "-~77X",
        "PKEY_RSA_CTRL",
        "z[kT\\4",
        "2'2@2Y2r2",
        "OnP'FgM",
        "j&RE9z",
        "fW xnX",
        "Y(l$|$X ",
        "1 1D1L1T1\\1d1l1t1|1",
        "0\"1=1X1s1",
        "%U7If)",
        "*>@].",
        "jk|#V",
        "N$X~q*",
        ".7@'u",
        ";m8. ",
        "VNvGH",
        "FJT,V",
        "ud^0$",
        "CY&eZ",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\insthelper\\insthelper.cpp",
        "Vq1YI3~",
        "D$ <:u",
        "extension setting not supported",
        "ad'&3",
        "QG6jb",
        "\\$0VW",
        "DU{4A",
        "R1]n8",
        "*qQy;",
        "^{(O:CW",
        ">/Rv2",
        "SW,vd",
        "U%EwZ",
        "ArkM$",
        "Malformed telnet option",
        "\"bXEcx",
        "242O3[3",
        "dt.abs",
        "failed to get Command Line",
        "22Z*z",
        "x<H1w",
        "S8KlB",
        "MtT44",
        "MH]xX`",
        "/wz]S42",
        "lewY ",
        "#_`\\z",
        "failed to process CustomActionData",
        "Failed to update signatures",
        "oZ,piq",
        "GgBb@W",
        "dwInstall",
        " gi_)",
        "la{v_]",
        "5juu|",
        "RjQwWB",
        "kjoD]",
        "|p jn",
        "=%7Jl",
        "DXX}X",
        ":':U:j:r:",
        "/9K$}",
        " !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHb%",
        "<%<B<b<x<",
        "D6@l-@",
        " ,5vs",
        "17s2j",
        "Z,`9n",
        ": ;4;8;H;L;X;`;h;|;",
        "CISRyh",
        "n\"n2nBx",
        "uGzan7",
        "lP4_D",
        "g5p1F+",
        "7+80888",
        ";9 p4k",
        "<X=c%",
        "(VD~T",
        "$4`rA",
        "OnFreshAfter:  Logon to vsmon.",
        "4V`'14",
        "Ik;JD",
        "8GySA",
        "3J$q ",
        ":*:l:x:",
        "PAVGUSB",
        "d:^k_P,",
        "C#EY]n}",
        "}J?]r",
        "@=HzfB",
        "0B&A^",
        "p|Lp4",
        " uts~",
        "-)iT0",
        "SS*vs'",
        "t=Xw}w",
        "m'3U=",
        "=lN7^",
        "]S9Jl",
        "~E\\DO8",
        "SETWRAP",
        "imum configuration allowed for the Product by Check Point upon which the licensing fee was based.",
        "w|N!}4",
        "AzUH{",
        "0rgX-",
        "4dR_Y",
        "pr!9U",
        "guo('",
        "zATS>",
        "F(ku7",
        "L$$+D$",
        "DWORD ",
        "Qs0@H",
        "__based(",
        ":*N%[Md",
        "LWWio",
        "!|+GWn",
        "*C[pi",
        "?7yHr",
        "$iuFJ",
        "6#Fgd#",
        "RS-2I",
        "CRolloverMgr::TruncateLog():  unable to position write pointer",
        ".?AVFairScheduleGroup@details@Concurrency@@",
        "z1Zkzk",
        "3ASBY",
        "nck<}",
        "l$4Sj",
        "1+fuc:G",
        "invalid header",
        ".\\crypto\\rsa\\rsa_pmeth.c",
        "\\`=Ji",
        ";<c|.H",
        "%0?x_J",
        "%e/ZnvY",
        "v4f]^~a",
        "s)2>|",
        "H({\"O",
        ":>e;^",
        "916d+",
        "YXpN\"*",
        "-g\\R2",
        "mhM%Fa",
        "t`o91",
        "16h!]",
        "]JKBs",
        "]3.!9%",
        ";Y<a<",
        "X3\\3`3d3h3l3p3t3x3|3",
        "uE/1$",
        "vj#`a",
        "x\\vZ0go",
        "tBN+!",
        "rr\"A2",
        "Q/zSUdBe",
        "r74%tQwC",
        "k\"PDV",
        "$Gk^o",
        "0# 3Xb",
        "aQ7P\"g",
        "~Ir:8",
        "Software\\Zone Labs\\TrueVector",
        "[LICENSING] trial being refreshed",
        "$e\\9/|3d",
        "%avVY",
        "NZ}~$",
        "[@u*[",
        "O;MhZR",
        "O)~=$7",
        "#*#8#",
        "5G_Zfm",
        "bncNt",
        "pja1#",
        "7ca0j#",
        "7&S&g",
        "tr<bbG",
        "/[,SC",
        "Tc9aP",
        "FLT_DIVIDE_BY_ZERO",
        "algorithms",
        "mT#BE",
        " 0x1c",
        "'6?&Op~T",
        "0$0@0\\0x0",
        "a'jp`]",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669\\charrsid13774068  failure occurs in the first 30 days from the product}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid13532976 \\rquote s}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669\\charrsid13774068  }{",
        "njWj~",
        "u98D$$t",
        "l U.*",
        ",J'-|",
        "oNRDa",
        "h;u,B",
        ",ey\"$}",
        "EPAM_CleanOldRollback",
        "uN|xAZ",
        "'b:0h",
        "lKwMdr",
        "'oX+~>",
        "TYKF6",
        "| A.%",
        "<@=e>",
        "[o91`",
        "(UNKNOWN)",
        "V;@j}",
        "1'1R1f1n1",
        "qv~Y5",
        "jMb->",
        "p}cJN",
        "[W=\\J",
        "G\\c~9",
        "DAK%`@ ",
        " B?d@",
        "p}q)r",
        "e`vxJ",
        "vnaap.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "&V(?;",
        "jBjuj",
        "GetLogHeader():  invalid header size",
        "p]WRjDs>",
        "unimplemented cipher",
        "PARSE_HTTP_LINE1",
        "08\\6\\",
        "Spacb",
        "}gXS*",
        "n?e_2.3-",
        ">`?n?",
        "2*oWy",
        "]TP9HC",
        "~\"~xC",
        "b$)G%",
        "r4*Th",
        "Dj{ib",
        "h{k=x",
        "M'zrP",
        "1uak@",
        "R$\\b]",
        "d2i_ASN1_bytes",
        "g77qG",
        "~8Zwb",
        "sc stop trufos",
        "QaWdY3YYK*",
        "Tg(7f",
        "Registered ID",
        "020N0j0",
        "kFMR[",
        "otC#^y",
        "Going to terminate the process",
        "{O10=k",
        "D$H1F",
        "`zCBo",
        "^\\5`$",
        "1[dSj",
        "JLq,y\\\\",
        "$324!",
        "-k,e9",
        "HrP1Q\\;^",
        "304t4}4",
        "<)<0<6<;<I<",
        "=aXW9",
        "RegCloseKey",
        "'-.o!",
        "q30c4",
        "%wU{}0",
        "PMOVSXBD",
        "`j#5{",
        "_.ujaN",
        "a*%0h@",
        "?5[CB",
        "f^3ud~",
        "ssl_bad_method",
        "D\"B0B,$(",
        "F3{50",
        "b]4d$S",
        " 0x32",
        "<7<j<y<",
        "<[d:B",
        "Q}\\KP",
        "+LB;w",
        "&`xwI",
        "A >h+",
        "bIT/,",
        "=9q)(1",
        "JZ1E\"uph",
        "j=1hf",
        "5T6b6r6",
        "3$:*:0:6:<:B:H:N:T:Z:`:f:",
        "K^0R.",
        "CVq0v9",
        "$dZD=",
        "RAND lib",
        "id-smime-alg-ESDHwith3DES",
        "%`>z5",
        "E t%9C",
        "\\$,U3",
        "X3(Moj",
        "\\C4ha",
        "Aw]Pv|",
        "9&949K9R9a9m9",
        "eEkU\\S",
        "gt`Jx",
        "a~f<pG",
        " 377GLl",
        "N[{p7",
        "P#@=D>I",
        "<;<e<",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\compliance.cpp",
        "<e<l<",
        "4!4-4v4",
        "MD5 part of OpenSSL 1.0.1t  3 May 2016",
        "^5YjkQ",
        "<HO#m",
        "/8?, ",
        "rAw~&>cR",
        "k|G~E]`",
        "thSR}0S",
        "C\\2W$",
        "EA^N_ ",
        "!B&|[",
        "~zdJ(",
        "MOVDDUP",
        "_z8^U",
        "7\\YJ}p",
        "0sa3!o",
        "klelam",
        "Xf9DO",
        "U`*@k",
        "(Dg&S?",
        "CMS_RecipientInfo_set0_pkey",
        ")U{X9",
        "Failed to the load the existing DirectX APIs.",
        "NC|aM",
        "z]f-d",
        "747C7N7W7]7c7",
        "7H`Ja",
        "&gy)}",
        "FP;FL~",
        "K%|.H7",
        "=1=@=Z=d=p=",
        "O>#H3",
        "-bpW9",
        "Blocking call in progress",
        "9R:Y:",
        "3D$$1",
        "a#1FI%",
        "#EsKq\"",
        "V~k:}",
        "?Nz8w",
        "text file busy",
        "@~J:h",
        "t\\hXs&",
        "m1D0hKj",
        "ykDCJh8L",
        "-@Oi0",
        " 8&Bj%C",
        "E&PV(",
        "Shutdown",
        "@,,Jd",
        "roleOccupant",
        "4)4L4",
        "%+@mr",
        "Z&^s,",
        "WW{aV",
        "<M`MM``u",
        ",NC5Y",
        "vhk^m",
        "BIT STRING",
        "(C+r ",
        "*wDzZ",
        "YsznkN",
        "tMp6SZ\"",
        ")]L9s",
        "H`a`\\O",
        "H.Q47",
        "OnFreshAfter:  Register plugins",
        "o8^yy",
        "2F(@g",
        ",Wk7!",
        "UuS5Qu",
        "BLENDPD",
        "DriverSetProtectionCtrl",
        "D-faDY7",
        "FdNhJ/",
        ".faOPA",
        ",^#6XE",
        ";_!\\\\>",
        "-y99D",
        ">mMnc",
        "3lz88r",
        "@8>m1",
        "O>!8'",
        "+Bt9!",
        "}`A@=",
        "RCPT failed: %d",
        "ZLProduct.Server.PublicKey.text failed",
        "sk-sk",
        "V`=,o6",
        "f{}_lf",
        "\"!2p4",
        "&J-I<I",
        "222y2&3D3",
        "TxRk#",
        "<VmIo",
        "!HBrN",
        "%so0]",
        "RSA_blinding",
        "4B2gj|(",
        "{{u8f",
        "%43A*",
        ":gu]<",
        "XgU85",
        "PM>15#",
        "Cr\"D0Hp",
        "Q-EV%",
        "ThGJN",
        "iKB.\"d",
        "n1a(u",
        "\"%s%s%s\"",
        "OLxj~",
        "^92vaQ",
        "zbr\"ED=7",
        "T2'Pl",
        "zM\"[Z",
        "/ohUyy#",
        "6J6T6`6p6",
        "[{v)(pCY1j",
        "Failed to kill process [PID %d] %s: error %d",
        "tv:9;G",
        "N>hti",
        "cipher not initialized",
        ";?c4|",
        "Sy-\\iK",
        "x3oc1",
        "!f1$^_w",
        "02f;$",
        "J1|f'",
        "?Mf4~",
        ";_j3, V",
        ">F>t>",
        "%F:_=Csw",
        "6/TmET",
        "Dlg) D",
        "*g+go\"",
        "L=zZ&",
        "S],8+",
        "p%Dv(a",
        "invalid key encryption parameter",
        "sDcM:",
        "' ,'\\8&@rp",
        "yA-dj=",
        "{8(}o",
        "<8<{<",
        "Wn!sUk",
        "(wMww",
        "c?!(R",
        ";A9;iY",
        "o.p/)",
        "5-6=7",
        "%d.%d.%d-%s-%s",
        "X50M6",
        "T\"UdW",
        "smartdefense is not installed",
        " bh1d",
        "576F6",
        "d{g.i",
        "*n+_9",
        "Fumy)",
        "-%*5-?Y",
        "$n>w%ac",
        "x?# uV",
        "KzXDyNo",
        "U]xS7",
        "4.-o W",
        "B2,tf",
        "s#;#f'",
        "@c ]t",
        "4 4$4(4,4044484<4@4L4P4T4X4\\4`4d4h4l4p4|4",
        "1(1/1;1H1",
        "8+9d9",
        "^2S$N",
        "0,0B0]0m0",
        "V<z<+",
        "cmd /c \"del /F /Q \"%s\\System32\\epcginashim_user64.dll\"\"",
        "BiX;6",
        "101L1h1",
        "D$ _[",
        "26x`;}",
        "Failed to create script key.",
        "tx]F3",
        "6!7(7Q7c7h7r7",
        "\\f1\\fs20\\insrsid5649851 will provide }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9516106 either }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 return and replacement service}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "g*& <",
        "Latest currently installed version from registry: %s",
        ";wr\\`u",
        "r(>j|W",
        "?<TR@H",
        "tzFnJY",
        "w>Wv(",
        ":jKl!rv",
        "P C2hF",
        "Xapxa8",
        "8v}&`,",
        "*'!h(",
        "LIST_LIST_PARSE_FAILURE",
        "`({)%S",
        "T5&6}a7",
        "sa-in",
        "x:whWC?",
        "Wc/*j",
        "44595q5",
        "ELKk\"l",
        "OG!e)",
        "Unknown exception occured",
        "+(#(YA",
        "VU C|",
        ".hUb^",
        "oUMdG",
        "[3P>iQ",
        "t$@SP",
        "IW@(G",
        ")8Z~{",
        "uninstall password is needed",
        "4td@C",
        "A\\t5Q{",
        "]YZ^<",
        "4H4l4t4|4",
        "Y13ja",
        "&_12_",
        "4gZmu-",
        "dr*P'q",
        ".QZMP",
        "Y-4rl",
        "S0qeM",
        "n(h[;",
        "Big Number part of OpenSSL 1.0.2h  3 May 2016",
        "DF5L\"",
        ".LTT...",
        "6`\"*2",
        "up4Sc0",
        "P__Tv:3",
        "Q&Ix0",
        "s0sPsps",
        "*-fv9i1",
        "f*v9#",
        "0@%&i",
        "8M\"d<",
        "b0f0j0n0r0v0z0~0",
        "t$ Wh<D!",
        "N6K)#\\",
        "3!3)36L",
        "O&Ns#",
        "xK)e)0",
        "7/X9*",
        "L$$QWP",
        "}JJV<",
        "VIr9h%S",
        "I{{)^T",
        "%d Could not remove symlink le=%d",
        "r^W+kDJwV",
        "A2n}F",
        "R7(~l",
        "L$,SQ",
        "[SAPI] Certificate digest:",
        "6z[<\"EsR",
        "xg;5h",
        "?8???S?",
        ".?AV?$basic_memory_buffer@D$0BPE@V?$allocator@D@std@@@v8@fmt@@",
        "w%s|lj",
        "9-9>9V9\\9h9",
        "GNBs%",
        "#rBsrD99;",
        "+-lEV",
        "X3YsY",
        "&oc#[",
        "10RHz",
        "4pZ`X",
        "8 8D8L8T8\\8d8l8t8|8",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Third Party Software\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "R~4dT",
        "SysWOW64",
        "323=3L3e3",
        "vm<fF",
        "P3KLr7",
        "UCoSa",
        "}KeHb",
        "%-OsN0'",
        "g\"\"yA,2",
        "9 9$90989<9H9P9T9`9h9l9x9",
        "{ARP l$",
        "60hE5",
        "7NTMe2Ze",
        "829N9",
        ":~_IU",
        "0^cE\\",
        "heck Point's option, either: (i) return of the price paid to Check Point for the Product, resulting in the termination of this Agreement, or (ii) repair or replacement of the Product or media that does not meet this limited warranty. EXCEPT FOR THE LIMITE",
        "%5x}A",
        "K &4g",
        "[](sa[=",
        "8#_?#",
        "C0kp.r",
        "_Rd1(",
        "hpu=N",
        "??T>e*",
        "LIST_ADD",
        "P+sRT",
        "Content-Range: bytes %s/%I64d",
        "unknown digest algorihm",
        ".|Nhx3",
        "^3_s_",
        "D$<VW",
        "`H;4z",
        "[UT:o",
        "(S^]s",
        "Loaded ",
        "PFSUB",
        "7,7E7^7w7",
        "P{&)-d+{U",
        "83cx\"",
        "6@6e6",
        "jyjnj ",
        "setct-CredResTBE",
        ": :$:0:8:@:",
        "G7<Y?E\"^",
        "Hk Qy",
        "0EzEOpu",
        "g9ui<",
        "Z:S6;.)",
        "Re'm.6",
        "UNDEF",
        ":ljAZhP",
        "Al}Q&#w",
        "8!>nl",
        "trailerField",
        "bad function call",
        "1$1(181<1@1D1L1d1t1x1",
        "H(`GU",
        "Cookie:",
        "ja?1Lf|",
        ")z.GR",
        "V@v6A",
        "JFpbOg",
        "aYE.z",
        ")U:E'^(",
        ",*bP4",
        "v][:s",
        "a@wJ\"K",
        ".?AVLogger@@",
        "XQR)+",
        "M+hK&",
        "AY]_r",
        "s~jxj",
        "software\\zone labs\\zonealarm\\registration",
        "6?6w6",
        "J*~b{",
        "szTagFileName",
        "yh[R7",
        "failed to create authorized app",
        "474Q4g4",
        "ddddod",
        "l^vcg",
        ">C>H>^>",
        "(-wXL",
        "3\\3DX",
        "617H8d8",
        "Btvk7",
        "58m-j",
        "a>e@NsZ",
        "Signature",
        "b^n_0",
        "g_JXY",
        "HF<y4dw",
        "isp9m",
        "*akr[%",
        "e6v}^",
        "invalid public key",
        "vJ-:2",
        "n@V-f",
        "Kq^\"0",
        "jMhd$#",
        "a;g}9",
        "33331",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\ScriptRun\\1.0",
        ".(XJ9",
        ":OwOs",
        "5(565Y5",
        "wnLEG",
        "tSGkd",
        "?[e{2<",
        "Wd063",
        "263S3",
        "invalid padding",
        "2wFJL",
        "PKCS7_to_TS_TST_INFO",
        "l!DZ?",
        "ssl3_get_client_certificate",
        "}zQ4V",
        "RU\\l&",
        ":h<{<",
        "#^~1S",
        "&5>>\\r",
        "7S8a8",
        "344=4H4O4o4u4{4",
        "Ad\"b&&hl",
        "4G+tA",
        "L8L8C",
        "ukS~?x",
        ";`ptH",
        "9|\"!-",
        "V<TES",
        "!*85i",
        "@]snRk",
        "l,x_X",
        "Require Explicit Policy",
        "IsValidLocale",
        "ecdsa-with-SHA224",
        "+-n-r.",
        "3&T6O",
        "4ie<MG",
        "a;V[}",
        "/D/H/L/P",
        "Vh8;!",
        "uhzpu",
        "Js[H;",
        ":)sTp",
        "kZHMq",
        "Check Point Endpoint Security VPN version E87.20 build 98.61.4605",
        "BAD INTEGER",
        " 0xd9",
        "7dkjP",
        "U>o+V",
        "&K>5)",
        "}M|?`|",
        "7.7T7",
        "$@vr-",
        "id-pkip",
        "u,pr\"",
        "QQ!;Ux",
        "tftp_tx: giving up waiting for block %d ack",
        " +5H_#",
        "949<9H9h9p9|9",
        "D$D`t",
        "i\\po2sN",
        "zD!*k",
        "!lD\"OO",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
        "Njt/ZL4X-6 ",
        "%5Cy4",
        "7+3/!",
        ">!?v?|?",
        "PM Q@",
        "2%vyR",
        "EpQEB",
        "L$,QP",
        "gG'7lQ",
        "a!iB9",
        ".\\crypto\\rsa\\rsa_ameth.c",
        "-h|CI",
        "3SX* ",
        "d>Lr9",
        "Lt}J\\",
        "/HKhE-",
        "?:xcz",
        "?<?D?P?X?p?",
        "IjY{N",
        "GL0 )j",
        "[x[F?",
        "$J.<FZ",
        "W=jo.N '",
        "\"<r}b",
        "`W`8S8P",
        "{t-^S",
        "-]Mi*",
        "cms_DigestAlgorithm_find_ctx",
        "`QRch",
        "rMf;u",
        "{!#Gx;",
        "pKgy\\",
        " 0xcb",
        "es^m%G",
        "|m(0*r",
        "?\"?5?=?",
        "@JYiP",
        "uAIJ/",
        "x509 certificate routines",
        "3>3P3n3",
        "!C*<W",
        ":^#L6",
        "Eb2]A=",
        "Ojmq/",
        "memory shortage",
        "Jb =4",
        "G>:Dy",
        "\"1!q}",
        "-\"S%Y",
        "l5+}fv%Arq",
        "x4DIXZ",
        "niv <= EVP_MAX_IV_LENGTH",
        "8&989",
        "P96h06",
        ")M6 C",
        "989X9x9",
        "cC/]z",
        ":);Q;",
        "9sYX_",
        "0xbkQ@u",
        "$jq6E",
        "b,tp|",
        "+wU-i",
        "3 323:3o5",
        "%L-DI",
        ">2>N>j>",
        "xwylm<",
        "Xl!G`",
        "(|j\"M?~",
        "Helper::GetRebootFlag",
        "#CP`d-",
        "iHC%E",
        "&w2O%",
        "@@:*(",
        "a$N\\n9Of D!",
        "jZhqN",
        "R?pWZ",
        "(%;xlK",
        "{j{z{",
        "-|GER",
        "eufuguhu",
        "W$yr.",
        "Failed to delete %s. Error: %s",
        "X;;CI",
        ":G:\\:",
        "E0 SYB",
        "yJf3!",
        "n7Kd4x3",
        "BbKQa",
        "%Uff3-",
        "bwT(W$",
        "s)e4p",
        "k:bu7",
        ".\\crypto\\engine\\eng_list.c",
        "zh1Y\\\"",
        "1hS\"h",
        "uT_O}",
        " M1?O@",
        "5-m80",
        " @hQ{",
        "RHtbVT",
        "wrong public key type",
        "cRdRe",
        "V|cqz",
        "P'sn-Q",
        "IsSCUIAPIMode",
        "XHN*#",
        "vsmon_disabler.dll.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "~x]00",
        "Dk$)g_",
        "J)g-I*e",
        "8p.X$",
        "\\.i>q",
        "VerSetConditionMask",
        "eZzg^",
        "jAjnj",
        "PHADDD",
        "s)`?K",
        "{tPNe",
        "Fwu ?l",
        "vdg.&5,",
        "E{o/AP",
        "/XgH'0\"H9",
        "$n QX",
        "-|+BSB",
        "z=s^Zq",
        "R,taM",
        "fullname",
        ")N:dl0",
        "6=I-A",
        "6-7U7i7",
        "8H\\o#T",
        "Intel Hardware Cryptographic Service Provider",
        "\\vsconfig.xml",
        "f+5x[",
        "\\fi-180\\li6480\\lin6480 }{\\listname ;}\\listid1099259507}{\\list\\listtemplateid1292116092\\listhybrid{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703",
        ">x;3OcR",
        "v\\7{B",
        "A ?xI",
        "/]HIRx",
        "Z`:P$",
        "{b=3O",
        "0P1i1",
        "rBang",
        "KNsg.",
        "Ex0IvN",
        "bvix^|",
        "`{[:-",
        "Ejr\\P",
        "s)6iiP)J",
        "={]o[",
        "hI'~|",
        "noCheck",
        "202:2]2d2k2r2y2",
        "|o.d2",
        "tL!dm",
        "^7j6j",
        "__swift_1",
        "D$(PV",
        "pr~a$.",
        "zqqEw",
        "zwYUswY!",
        "'6rf6",
        "3\"q+CG",
        "D$$PVW",
        "3_@3^",
        ":;wqN",
        "024282<2@2D2H2L2P2T2",
        "bQVV,B|",
        "1/\":f%2",
        "3=4G4o5",
        "AU6Ga\"",
        "et%ra",
        "\\+:{tB",
        "Pj~J1",
        "? ?$?(?,?0?4?8?<?@?",
        " 0x5e",
        "B>lsD",
        "y~9;:",
        "?<vs7",
        "9a3N+",
        "=y\"\\s",
        "WA7&\"",
        "9.9[9",
        "s&#k@!",
        "DvQg9",
        "LP6Ls",
        "7B8M8h8o8t8x8|8",
        "OCSP No Check",
        "+xexk",
        "hG{L.",
        "6fWXW",
        "Software\\Zone Labs\\TrueVector\\LocalStoreDir",
        "<TEgW",
        "E[!-7O-",
        "ED{`!2l",
        "D$$QSP",
        "m8[Ow",
        "UV/uK\"44",
        "pLBLj",
        "\"BB6\"",
        "t(@'B:P",
        "FeatureVPN _MaintPrepare",
        "vt?P&",
        "jgjpj",
        "{NO`3",
        ",EUvE",
        "F]@K$",
        "2'2F2",
        "Loaded backup data: \"%s\"",
        "z\"rwE",
        "@J 4<&",
        "R*/Y2^",
        "7\"% m",
        "|COB+W",
        "8'Hw<:",
        "#j=sF",
        "a{czk(",
        "9;:J:]:z:",
        "<M_t \\<",
        "ARCHIVER",
        "r>6CQu",
        "M((e.>L",
        "9 9(9@9D9\\9l9p9",
        "SQRTPD",
        "hYT\\D/",
        "%s/%s",
        "hYMHSN",
        "uY,JX",
        "failed to get Name for XmlConfig: %ls",
        "bA*.W",
        ":g<.?",
        "great britain",
        "R>.AE",
        "y;NZI",
        "7 7(7",
        "ccore64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "FG\\E;",
        ";zBuz",
        "kY\\W1/",
        "2iF-6_",
        "bsT?~",
        "u/w9%",
        "</O*@+",
        "DHE-DSS-AES128-SHA",
        "Invalid easy handle",
        "&\"D1~",
        "pkcs7 datasign",
        "'sc}T",
        "'}Q\\C",
        "pF,rf",
        "DG%xP",
        "R\\YjL",
        " p6Wm?",
        "CqF`c",
        "k= t5",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "d=eY0",
        "v]7/S",
        "recursive_directory_iterator::recursive_directory_iterator",
        "PHSUBD",
        "zh-MO",
        ">W>s>",
        "DeleteTimerQueueTimer",
        "/sU3-<",
        "j&*,]",
        "SnNDu",
        "4`I!{",
        "1%zmK",
        "y2jyL",
        "Re\"qd",
        "Gt|klq",
        "i=*VbF",
        ">eo@s",
        "BladeFoundation.dll",
        "issuer mismatch",
        "HG)PY",
        "(]NXB",
        "CMS_GET0_ECONTENT_TYPE",
        "4_4n4v4",
        "XXo@`",
        "FR*.'\"f",
        "&%%VT",
        "am^]W]9f",
        "AA Compromise",
        "|<bWz<H",
        "x]Y%`",
        "cms_EnvelopedData_init_bio",
        ":k?&n",
        "e9G}0",
        "q'\\|M'",
        "NENO9",
        ";$;(;,;0;8;P;`;d;t;x;|;",
        "<1=G=c=s=",
        "?H?P?]?",
        "0fcxD",
        "Ph\\$#",
        "loadVswmi",
        "5VeD~>iM%",
        "(:q*v",
        "QQj<.d",
        "tmnAm",
        "L$4_^][3",
        "282i2~2",
        "wKjjj",
        "6o3;~}",
        "jljuj",
        "2 2/2h2",
        "7bBwGyOh",
        "%YL%N",
        "@,`C<2",
        "t$P3t$<",
        "e70EVjyy",
        "!F@!1IP",
        "2F4U4f6u6n8",
        "_configure_narrow_argv",
        "KR&PH",
        "JI?;t",
        ":=Ru:/",
        "a~#V/",
        "9&:F:",
        "2n)0r",
        "fMGTj",
        "U$0oac",
        "P$7nb:",
        "documentIdentifier",
        "s^yU&",
        "KED&}V",
        "t8C9o",
        "kF>E,",
        "L$ _^]",
        "D$ [_^]",
        "[{ %[",
        "8G8u8",
        "aP!]=",
        "Zjg;;",
        ";o5?\\.6",
        ":zfW ",
        "}))3_",
        ">WFY(",
        "5I6f6v6",
        "Te%4[",
        "uz9I9",
        "PVh(J!",
        "?(?H?h?",
        "J9</'",
        "y~KpW",
        "FizbG*",
        "#hw1D",
        "\\f1\\fs20\\insrsid5337217 \\rquote s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  TAC. Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5337217 \\rquote s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "tgQhQ",
        "8$8,8<8D8X8`8h8t8|8",
        "N.|dJx:",
        "UTA|\"",
        "J{zzM",
        "=StVF",
        "g=/3N",
        "H`c8}0",
        "mobileTelephoneNumber",
        ",z{fh",
        "physicalDeliveryOfficeName",
        "@RQbu",
        "4 4P4T4",
        "xR\"4S",
        "jj?NU",
        "UE\\v3",
        "o?r#<",
        "Got invalid RTSP request",
        "700PP",
        "K+2~f`QG$%kZ",
        "gCJ!|yO",
        "jBj|j",
        "RemoveVectoredExceptionHandler",
        "494O4{4",
        ";1d$T",
        "EqRJXiw",
        "McAfee ViruScan Pro v7.0 VirusScan Professional Edition (All SKUs)",
        "%u %X %s",
        "w?ea8",
        "4\"4G4Q4[4~4",
        "szOldVpnPath",
        "hO1imS2Ms",
        "3tc,w",
        "l'+YY",
        "I[`T80",
        "LsQfZ(",
        "<]<z<",
        ".'O'I",
        "+AYU\"",
        "w&GvY,Q",
        " 0xb9",
        "?B~K[",
        "iy@(}l",
        "\\ZoneLabs\\avsys\\install\\udinstaller.exe",
        "DS33hTPfI",
        "<.<7<}<",
        "Secure Client is not installed - continue...",
        "LL)rC",
        "(RTD4EDgfTe",
        "M@~Y'",
        "CAQuietExec",
        "l&&3}",
        "G}tG&~",
        "5!2sM",
        "MrnE*S9`>L",
        "Vs'/1",
        "ya)X[",
        "t!{PSj",
        "rS@Wn",
        "`m@`ADb",
        "4 4,494`4g4s4}4",
        "o+A6J",
        "2'323M3n3s3",
        "{\\f54\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}{\\f55\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}{\\f56\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}{\\f57\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}",
        "Y\"wi{",
        "bI0K..",
        "`&uuDm#",
        "rnw{^s",
        "xcKY/$3",
        "|#|_1",
        "9axAlG",
        "CheckIfInstallationIsAllowed",
        "8fMr?S8",
        "iQ&c-",
        "D$$Ph\\",
        "$]IY?",
        "hqG`i",
        "r*)Dv",
        "(D0vM",
        "AeHeq",
        "MrEt_-",
        "NOy8J",
        "CERTIFICATE REQUEST",
        "@T#sk|",
        "TQS,+.9loS",
        "O=NGph",
        "D$ ;F4",
        "T$h3T$@3T$83T$$",
        ":4:T:`:h:",
        "MNi>0",
        "Ww4dk",
        "(\"376T",
        ">7>>>M>W>q>x>",
        "sqJri",
        "Nv\".Q",
        "}_Ysu",
        "jih`E%",
        "~O[yx",
        "t;;jB",
        "2Z=k-",
        ".\\crypto\\rsa\\rsa_ssl.c",
        "&5wSn",
        "?W{WdC:",
        ";^o21'",
        "CMS_RecipientInfo_kari_get0_reks",
        "010n0",
        " e3vI>",
        "CtRwG'",
        "/l*nJ",
        "VSMain.exe",
        "lLtEUUI",
        " 0x60",
        "xQ=0?[;GP",
        "Tiny Personal Firewall 5.5 (AV SKUs Only)",
        "?Q/ADFgo",
        "h5K?Pu",
        "?D2,fV",
        "Wc[oD ",
        "1h;H<",
        "&qTtQ",
        "gb]|D",
        "K$b\"z",
        "858N8X8_8f8",
        "Pr\"8?+",
        "X}rAb|",
        "k(U;O",
        "PKCS7_dataFinal",
        "XXZcI",
        "digestAlgorithm",
        "t$LPV",
        "oBoDid",
        "^`557q",
        "T>XYT9Nak",
        "9)949<9a9q9",
        "6E7[7n7",
        "9 :@:H:P:X:`:h:t:",
        "6;7S7",
        "it-IT",
        ", 3#W",
        "0+0S0d0|0",
        "Updated server detected",
        "sxHUO",
        "S)*MmG",
        "|g_k-9",
        "!{Sci",
        "cX{s*Jv",
        "_Task",
        "Ull!-=",
        "3533pWg",
        "Y4w#8p",
        "W6WVWf]",
        ")d|O~",
        ">`-]N",
        "3ZC\\k\"",
        "2)w^Y.,",
        "hMLVd6",
        "o-,D\\}",
        "D$ Ph",
        " MiVql",
        "ProcessPemFile Begin",
        "Failed to create WcaNotVerboseLogging global atom.",
        " pF*y",
        "Rj2:O",
        "X0wy6",
        "ACCT %s",
        "x\\D!m2ba",
        "DyO,9",
        "U%CNQ",
        "rrn;/k:",
        "es-ES",
        "@m[py",
        ";%;Z;",
        "lh84'",
        "t$0Wj:V",
        ">,>3>",
        "isSDKUpgrade: Current SDK version: %s",
        "Qxx}z",
        "WDW]x-",
        "30/UZ",
        "u+_][^",
        "FzIo^ AcI",
        "~Of6I",
        "56d>a8",
        "_ 5AC",
        "eCryq{",
        "d+Vda",
        "Need: %I64d bytes",
        "yfK|Z",
        "# }{%",
        ">fU@`2!y",
        "Custom action:  OnBegin: started",
        "Server 2008 R2",
        "GetSidSubAuthority",
        "(0j5W",
        "5$505<5H5T5`5l5x5",
        "DyO\"zU",
        "#M4}:",
        "{$Qwz",
        "%tT9=",
        "~{t=k",
        "***r*v",
        "IDN support not present, can't parse Unicode domains",
        ";\";*;3;n;",
        "system library",
        "Lsup\"",
        "bx.8t",
        "I$(CZ^",
        "[VSDATA] CreateEvent failed: %d",
        "1<1O1}1",
        "wX;l8",
        "-ht4%",
        " 0x1f",
        "sJw,[I",
        "Install product caught an unknown exception.",
        "X509_NAME_add_entry",
        ";;{Pu",
        "8:k&^",
        ">L?]?m?}?",
        "4F4g4",
        "XUFeq",
        ";7=.t",
        "uR?1x",
        "z|HQ^m,",
        "p<8/&",
        "atan2",
        "PVWVWh,",
        "DIGESTS",
        "sp_k$%",
        "SLb'!",
        "3l$<3l$4",
        "?Mq\"0+",
        "\\P7<([2",
        "L+:eB",
        "QPLP<SyW",
        "C<PSj",
        "40/73",
        "@w:dK",
        "FindFirstFileExW",
        "+#i@TJs",
        "$Zo,Y",
        " vCab",
        "COMPLEMENTOFDEFAULT",
        "+xu~d",
        "h$~^)",
        "C#d1'G@za",
        "W.R%6",
        "iyHKSh",
        ";V;NBf",
        "cptrayUI.exe",
        "39i7^",
        "?1?Q?",
        "D$ US",
        "hfGS|",
        ":;:W:s:",
        ">~BVhOE",
        "XFSmuCdq",
        "S7 a~",
        "939W9\\9b9i9f:u:",
        "vt9du",
        "070_0",
        "nh]R=8",
        "(`*#Gr",
        "fi?/F",
        "86\"n%K",
        "//h%X1",
        "ShZ%>'-",
        "0'nt7",
        "u;$cK|i",
        "7]OMS",
        "e-vfa",
        "%02d:%02d:%02d",
        "8-9U9",
        "L4.oz",
        "memset",
        "`^(k0#?",
        "#.z6@",
        "jN^XV",
        "0$04080H0L0\\0`0p0t0",
        "Tn|lK",
        "K4<u~",
        "fu 0=",
        "oV:Rj",
        "m;j#)",
        "lv-LV",
        ":&FqGu",
        "PKEY_USAGE_PERIOD",
        "@Z4n:s",
        "1;AI@",
        "a.a<a>a@aBaDaFaHaJaLaNa\\a^``",
        "D`\\K/WB",
        "181<1@1L1P1",
        "Mp70Q)",
        "r.C:k",
        "8fn[4",
        "<1}k)",
        "m$Q4~",
        "UP(RS",
        "0*00070E0N0Y0`0",
        "'^~-t'",
        "l`r-3tQ9e",
        "X0\\0`0d0|0",
        "k_\"\"{;",
        "<:<y<",
        " 0x8c",
        "('8PW",
        "CH,02",
        "TID key could not be found ",
        "d98yX:",
        "0(000@0{0",
        "<$<,<4<<<H<l<",
        "21, 6v",
        "4P4V4,5@5H5r5y5",
        "F4o\\]",
        "vsdatant_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        ":l}a&-",
        "~,9~$t",
        "=jYp,",
        "VCMGN",
        "jz~wH",
        "Rw]hi",
        "^s#WgUb",
        "ReadConsoleInputA",
        "4V5a6",
        " _n[\\",
        "j::+^",
        ";}-uyUJd",
        "LP0y,Pp",
        "As`79",
        "dw1Po",
        "9.!%;",
        "-7/:k",
        " z/>s",
        "n\\[b4",
        "[ser^x",
        "ozR+n",
        "5(545T5\\5h5",
        "Av^CC+1f/",
        "7&es(",
        " failed because key does not exist:  ",
        "rzg-5",
        "3(iN08I",
        "*cW!>",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\OsMonitor\\1.0",
        "b_[o]6",
        "T&X5O",
        "MV:X2bv",
        "[GKc(",
        "8##L*",
        "869s9",
        "QNT38",
        "No timeout, exit code: %d",
        "9mXUe",
        "Conn: %ld (%p) Receive pipe weight: (%I64d/%zu), penalized: %s",
        "Internal problem setting up the POST",
        "7s2}_",
        "R#:r>W",
        "n>J3C&@",
        "E>{VM",
        "939_9",
        "-u<hg",
        "Bz)K?",
        "rPt%N",
        "o}ypp(",
        ")(aBp",
        ";=B-1",
        "-UAR@",
        "/G |*",
        "U,%Bbb",
        "4(444@4L4X4d4p4|4",
        "a<4_=",
        "]*4^}\"",
        ":Rpj/",
        "ZQZ,|:aj",
        "f(+4b",
        "qYh'Q",
        "%p  %p  %p:%p %s  (%s)",
        "61666a6f6",
        ";4;\\;",
        "HTHUi",
        "Failed to create window.",
        "&6aw(",
        "G%-1X4",
        "<U2[l",
        " UDBm",
        "failed to concatenate output strings",
        "U*/-f",
        "77OdL'",
        "/u(,c9",
        "a4\\($",
        "}p7v\\",
        "2u0{Q",
        "tObkMt",
        "3;qxd",
        "}:9uBQ",
        ":EdD'",
        "brainpoolP224t1",
        "CopyPoliciesFromOldDirD.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "ZoneLabs\\ntName16.dll",
        "75cz(",
        "7Rz\\`",
        "`*Wmm",
        "Dw  z",
        "SVWf9",
        "ClientSubType = 'M'",
        "%deLY",
        "q[38i",
        ".kernel32.dll",
        "e^F&+",
        "d5 fI",
        "EDVPV",
        "s):j:u",
        "[/;Iw",
        "FixedMACBuf = NO",
        "V]#;D",
        "8`~_B",
        "api-ms-win-core-datetime-l1-1-1",
        "+fm<F",
        "MV|v&",
        "^)AP~",
        "I!j!]H",
        "\"R2z1",
        "PMULUDQ",
        "_f/p/s/Y-Ne",
        "wwE4'",
        "ER\"j0",
        "EC_KEY_print",
        "w+Q*'",
        "Br=i)",
        "Z1P=`.7",
        "@t0=p",
        "3\\Ll4:",
        "Z/4a6",
        "ZLServiceGroup",
        "d&,;n",
        "g>\\;5",
        ":$:0:T:t:|:",
        "13pZu7",
        "ib`,t",
        "ADH-AES256-SHA",
        "UPDATETRAC",
        "/92WK",
        "func(%lu)",
        "D2H2L2P2T2X2\\2h2l2p2",
        "LM!%jV",
        ",X[tA",
        "+eD!G",
        "CMS_PasswordRecipientInfo",
        "y5~:M",
        "No URL set!",
        "LEyMy[@*7",
        "CoqBL",
        "|u,(nOa",
        "DoF=!",
        "IT<s\"",
        "sfL3[",
        ":Ji5sr",
        "L(kgM{}",
        "8!8J8",
        ")2!&/",
        "SSL client",
        ">G_7y+",
        "H{\"Iqb7$7$P",
        "~@i?g",
        ")HIRI",
        "\"G6PW@",
        "T!{%V",
        "jfjjj\"",
        "MjM@a7Nf",
        ".?AV?$_Ref_count_obj@U_Recursive_dir_enum_impl@filesystem@std@@@std@@",
        ";@;D;H;L;P;T;X;\\;`;d;h;l;",
        "LL5uh",
        "y]W\\R",
        "<c\\C/",
        "96+;[h",
        "718q{",
        "Xpu(@",
        "Failed to get encoding key.",
        "yu;I;",
        "3s4M5",
        "3T$03",
        "@Raiv8;",
        "^,`$&",
        "SOFTWARE\\McAfee\\McAfee Privacy Service\\CurrentVersion\\Setup",
        "v@rvd",
        "?Tm)H",
        "40zCz",
        "i6pj&",
        "_FA:m",
        "GYw(,> ",
        "~BE<&",
        "D3$?qi",
        "fr-ca",
        "6+606>6G6S6b6g6",
        "SSL_use_RSAPrivateKey_file",
        "!expected_len || s->s3->previous_client_finished_len",
        "%&-&1&5&9&?&",
        "1%% !L",
        "<X=u=",
        "(NEN$",
        "dynamic",
        "Hash.exe <password>",
        "AvHUa3HN",
        "Tj=^q",
        ".\\crypto\\engine\\tb_asnmth.c",
        "BciLAUL",
        "3 3(3,383@3D3P3X3\\3p3t3",
        "Aw+3qd",
        ":G:n:",
        "-E?:JB",
        "$`Zr[0",
        "Ph0:!",
        "tT`ma",
        "bW<!f",
        "hlFl%",
        "aw876",
        ":bl8(",
        "x$H%[",
        "SCqUq",
        "Z<BCV",
        "8d+<M~",
        "?r9@#",
        "#?`Z_Ov",
        ">Y9(\"}*X",
        "AuIxK",
        "jijlj",
        "@<zb<",
        "/=Oo&%",
        "2c]%Rw#",
        "Failed to schedule reboot.",
        ";\"Y_E",
        "Kru|(",
        "gsvSJ1",
        "/H-V^",
        "iB\"'mo",
        "Vh`D!",
        "unknown cmd name",
        "FirewallExtension: Cannot add firewall rule '%ls', which defines both an application and a port or protocol. Such a rule requires Microsoft Windows Vista or later.",
        "mPUm:>",
        "p]Z-:qi",
        "elliptic curve routines",
        "=7VEI",
        "=V+=Hi",
        "S==YV",
        "8YM`.",
        "WQpyBM",
        "2!2/272x2}2",
        "1!%LQ",
        "%O;Od",
        "T/!n!)S",
        "$0\"0 ",
        "\\Ox}f",
        ",u!J ",
        "F,@i:",
        "zy%o7",
        "uvb`G",
        "ppc9h",
        "n+7eujAFz",
        "6q6{6",
        "//H!_",
        "o-UK0",
        "t?wnv",
        "]Q`tp",
        ",&M]41Z",
        "+t`0a-",
        "O(l=d,",
        "> >(>4>D>T>X>h>l>|>",
        "{PmQl",
        "0nb7>d",
        "_\\bO'lF",
        "~IReF",
        "ybQx|_S]P",
        "    Revocation Reason: %s (0x%lx)",
        "BO}CN",
        "KD\"g+T8",
        "=X>e>",
        "d:L3p",
        "LP/3}>",
        "\"(./016:@HJ]dmq",
        "s2]nf>",
        "lLq+B",
        "Xkb4X",
        "i^O?Y",
        "?5dM.m[Dh",
        "~65?3",
        "NZ0!v",
        "Pea,0-xg",
        "fb3|S",
        "=0=8=L=T=\\=l=x=",
        "2*3t3",
        "aZTGsL",
        "<FtY`\\qY,",
        "d4??*",
        "AM_ENGINE",
        "qp!W5T",
        "2&GF3L",
        "/@SjON",
        "   Unable to load public key",
        "?.?5?S?Z?e?",
        "/?E}m|9$|",
        "{s3.Nx",
        "1$1,141L1T1\\1t1|1",
        "fdOmX",
        "InstallMsi",
        "U5y@ JJ%",
        "^fC{p2",
        "FF#N\"",
        "jvjij'",
        "ZoneLabs\\ntname32.dll",
        "=[c=Xh",
        "rO?Z4u",
        "gYRJU",
        "<\\?2(",
        "0PDz0",
        "`Bp%v",
        "<i_ue",
        ".\\crypto\\rsa\\rsa_gen.c",
        "2\"|ZNV",
        "&V[Qus",
        "q=%V[",
        "=H`~b",
        "=\"Hd{",
        "-2{W'4W",
        ">qrS-!",
        "}SSHd",
        "KbmAH",
        "uydd<)+",
        ")aXHH",
        ">pMfy",
        "coclass ",
        ";1;A;I;Y;",
        "-@h3Uw",
        "!evSo4",
        "/89@S6",
        "]\"_+_",
        ">'%L'j",
        " sjpv",
        "X509_to_X509_REQ",
        "\\old\\",
        ":!:-:2:<:",
        "c(mur",
        "hu-hu",
        "BQM8Q",
        "=p`'[",
        "D@#}Usnr",
        "IMAP.",
        "=-=H=",
        "JY4/J",
        "Minor Release=ravpn_is_v1",
        ">mWbg",
        "AES256-GCM-SHA384",
        "\"LcRC",
        "59j0R",
        "v*@PW",
        "OusEI",
        "8E]Q-",
        "fGa/L",
        "IN`i\"B",
        "w$Y>~",
        "+NWM4F",
        "U{j.qW",
        "2!/ea",
        "\\PatchOldDiscoveryVPN.txt",
        "#D=QO",
        "YmIqH",
        "4F4T4e4k4q4",
        "+p$+p",
        "J@qPZ",
        "\\$49\\$,",
        "6&6_6",
        "<+<X<",
        "!ycex",
        "VarFileInfo",
        "H]\\zju-C",
        "F|]Y}",
        "0/=tL",
        "tqbh;",
        "6w<PX>",
        ">,>0>4><>T>d>h>x>|>",
        "\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 5;\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 5;\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 5;",
        "2+T,c",
        "TE-YBm",
        "X.onq",
        "8 8=8C8]8c8o8",
        "M=u;6",
        "qq b)R",
        "D2na8",
        "Z6852",
        "vRf6K",
        "5\"6U6",
        "PEM_write",
        "K9C#$",
        "nRe80&",
        "BAsHP!",
        ";!<a<",
        "pWx0}",
        "XMV4['",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid8205679 upport plan}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607  with Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid8205679 .}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "b}[%3",
        "J?!+9",
        "D(,U$B",
        "WIq$0",
        "03e =p}%",
        "qyb3#",
        "K5I[L",
        "(TM2O%",
        ")h)/7",
        "-\"&{w",
        "GSSAPI",
        "id-mod-qualified-cert-93",
        "qk2:tW6",
        "Zone Alarm Case - only Mobile or SecuRemote types are allowed",
        "\\e'PX%",
        "0000001c00000000000000000000000000190200007468656d652f7468656d652f7468656d654d616e616765722e786d6c504b01022d00140006000800000021",
        "<d=k=",
        "VK&('",
        "YI,RT",
        ",kGM(",
        "rsf;u",
        "kECDHr",
        ";5|:or",
        "<$Bc%u",
        "?M}[_ ",
        "un8ne",
        "@>D-s",
        "i9?}~",
        "JDJ`%",
        "=OQY=",
        "'0D`T",
        "UpdateEnvironmentVars: Set tvdumpflags to 8",
        "j\"QGF\"",
        "Yl-NK<H",
        "2]R,./",
        "BfMC2",
        "rJLrs",
        "LEMYMyM",
        "CreateEnvironmentBlock",
        "3t$ !",
        ")HCf!",
        "qiy@]",
        "password ",
        "KE,m#|",
        "M^555",
        "server response timeout",
        ";>;C;S;Z;q;",
        "!$=0)",
        "j<%S65",
        ")q}g#",
        " 0x17",
        "jYS|tG",
        "C/l&@&NYPO",
        "Fc+CN",
        "Failed to set restore privilege.",
        ">9>f>r>",
        "[=D`pb",
        "6:[G@",
        ">=g?w",
        "8*818<8O8V8",
        "\"http://ocsp2.globalsign.com/rootr606",
        ":\":B:b:",
        "uK})i",
        "t]hd: ",
        "WF^HfD",
        "D:7\"sR G.",
        "C+=pc",
        "y/qSj",
        "(98Z8",
        "Ugg1n",
        "undefined order",
        "383@3H3T3t3|3",
        "uiH0!",
        "RbV0T",
        "api_ms_win_core_localization_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "Dzc4i!",
        "OPENSSL_ALLOW_PROXY_CERTS",
        "%V&m&",
        "Xl!*|g",
        "K@P)A",
        "PN{15",
        "jkjqj\"",
        ">??I?b?g?",
        "RMWD/",
        "D$Hj@P",
        "securitypolicy/osfirewall/rulegroup[@name=\"protmefiles\"]",
        ",NW,>",
        "JNgtSlbc",
        "TiJxY",
        "(T;,H",
        ">W[$+",
        "NTB!#",
        "ProcessIdToSessionId",
        "ZVrUKF",
        "RX>I$I",
        "[~\\+T",
        "yQe(x",
        " 3+D%",
        "=C>Z>v>^?",
        "`e8qU",
        "zXlNr",
        "Cessation Of Operation",
        "#D$ #i",
        "2pVKR2@",
        "sD,3}5QS",
        "5 S2R",
        "`)XyW",
        "IND)ind)a",
        ".j~'O",
        "c/mz-A?",
        "wqJXV",
        "3$3,343<3D3T3\\3d3l3t3|3",
        ".?AVCPerfCounter_Rate_and_Timer@@",
        "Fkh;&:j",
        "S`2k-",
        "ac19q",
        "oCi L",
        "PPPPP",
        "Cannot Delete: ",
        "-2J\"o",
        ";L$4|",
        "beq]MVE",
        "CANT_FIND_VSPWINSTREQUIRED",
        "`,dM7",
        "A04G\"",
        "BSWAP",
        "invalid padding mode",
        "L$I)I",
        ";,gMA",
        "U'Pfe",
        "jujpj",
        "missing finish function",
        "sq-al",
        "Km|H*la",
        "x]F0u",
        "}Ygiv",
        "r]f;u",
        "w[TTd",
        "xO\\\"Ms",
        "(5pg&",
        "2T3c3n3",
        "j*9XY@",
        "y7I?::",
        "~H;C]",
        "6&!Gw",
        " :3U{",
        "@^kd&[",
        "E B'.6",
        "_ )OF}ki=",
        "V`{i/<",
        "Kz'C9V9",
        "`4!l\",",
        "SS;l.",
        "KFXjL+",
        "%-.Wc",
        "HVfX8c",
        "L$SzS",
        "QK'\"SU)",
        "em{4]",
        "c/0Ij",
        "{e}L9eR",
        "There is no %s action in %s",
        ".JnJS",
        "|Xwrl",
        "2P]`t",
        "PacketMon.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "8J9U9`9h9",
        "AV is being installed.  Set ZAFM value in product key.",
        "t]j/SO",
        "j:qla'&",
        "L_A14",
        "&_.?v",
        "r;*pb",
        "FCMOVNU",
        "G;~8u",
        "ar-dz",
        "R}^.w?",
        "r>aw2",
        "UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU",
        "SSL: SSL_set_fd failed: %s",
        "3P4X4",
        ">/?X?",
        "U-()!\"U",
        "7Fh&?",
        "b2W/Y:",
        ".\\crypto\\asn1\\tasn_new.c",
        "9\\$Lu",
        "G_Po ",
        "g?<q&",
        "MGKAx",
        "bXH6i",
        "lYx.A",
        ".?AV?$sp_counted_impl_pd@PAXV?$bind_t@XV?$mf0@XVCRolloverMgr@@@_mfi@boost@@V?$list1@V?$value@PAVCRolloverMgr@@@_bi@boost@@@_bi@3@@_bi@boost@@@detail@boost@@",
        "\"dZ.1",
        "x'2%[^9",
        "-OKBY",
        "46g-W",
        ":ICPGn",
        "|IXtV",
        ">>>M>u>|>`?",
        "[TsJu",
        "p3FvW",
        "jUQT+",
        "<$\\-_",
        "`l%#0|K",
        "VSSetPWInstall: cannot log in",
        "v@usy",
        "-%>wF",
        "? 4.Od&",
        "1BHINQSY[BJQS|~",
        ",U9sm",
        "Tuy m",
        "ha{S(",
        "c:r|E",
        "ru}l;",
        "^yVj/",
        "Z`+PI",
        "id-smime-aa-signatureType",
        "@g^8}T",
        "D$T;D$ t",
        "gHhHi",
        ")C4Aq",
        ",_=2p",
        "4Bwh'",
        "FWUpgradeAfter:  SetProductMode",
        "p6n-J",
        "4Os, u",
        "|Ck02",
        "(D {JS",
        "contentidentifier mismatch",
        "en-ZA",
        "=#=.=",
        "Nc9;d",
        ":':C:_:{:",
        "Uba^~0Y",
        "9Z;%<O<g<S>)?",
        "FAILED_WAITING_FOR_REQUEST",
        "t]hLaL",
        "XKXI+%r",
        "ec8+9",
        "|V}JLg",
        "NORTELLOCATION",
        "P !XWI",
        "O(5cw",
        "SEC_E_CANNOT_INSTALL",
        "hmacWithSHA512",
        "b]]Y*?",
        "Kw3,\"",
        "aw0KM",
        "K-409",
        "'T1.p",
        ">/?:?Q?\\?h?",
        "uu6[g",
        "dnl>N",
        "ueu79",
        ":%uORA",
        "\\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext36 \\slink37 \\ssemihidden \\styrsid15147522 annotation text;}{\\*\\cs37 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\sbasedon10 \\slink36 \\slocked \\ssemihidden Comment Text Char;}{",
        "?ZU &",
        "7x!Aj_T",
        "6a*gk+F",
        "%*s<Parse Error>",
        "!:&M88",
        "2n:wm",
        "R0bAv",
        "ao<t8LT(",
        "eeCg;",
        ".?AUIRegistryProvider@RegistryProvider@LibUtil@@",
        "MsiLogging",
        "failed to write exception name to custom action data",
        ">G?b?",
        " 0x7e",
        "jvNE%",
        "TL' $Gq_",
        "$d^]xUOV\\",
        "]6#F~",
        "M97md=",
        "O3m/-",
        "cipher parameter initialisation error",
        ".YC)%",
        "@~`6 x",
        "LD$pPW",
        "Error returned from ReplaceOrAddTagIntoVSConfig(%s, %s, %s)",
        "bad ssl session id length",
        "?D?P?",
        "dtls1_send_certificate_request",
        "%Lt\\P4hX!",
        "!V\\Y ",
        "MFINSTALLED",
        "cfWVM",
        "HXc4S",
        "W!w!%A0",
        "t1Sta",
        "#iY+1tt^L",
        "eXn;tV",
        "response setup error",
        ")t\\3%Fa",
        "m`F !",
        "No space left on device",
        "EncryptClientHeader started.",
        "x&vyRt}",
        "8I[K_",
        "V0wqzD",
        "Netscape CA Revocation Url",
        "jmjtj",
        "070V0h0",
        "no GinaDLL",
        "spanish-panama",
        "90%+I",
        "CdFd{G",
        "GIlS7rR",
        "NepZ%",
        "<OTso",
        "9u/+z",
        ">W>]>x>~>",
        "}kbn@",
        "txs#l",
        "ZzkyM",
        "<?QtS",
        "x=Z\"5",
        "``miy",
        ".^M-.",
        "qu(^I",
        "md5WithRSA",
        "r%sEy",
        "CMju0n",
        "5=5R5z5",
        "=(=H=P=X=`=l=",
        "e:KN6C",
        "8lakx\"",
        "94rK7",
        "CACompromise",
        "ag;dN",
        "o\\aAS",
        "-!mfQ",
        "KiFUOYMM",
        "coefficient:",
        "t$(h@^\"",
        "_oA 3_",
        "failed to get Element Path for XmlConfig: %ls",
        "0O0a0x0",
        "4q,iB",
        "0Xb}pEj",
        "DisableServiceAutoRecovery of Service EPWD succeeded",
        "N,wy%",
        "7fUH\"",
        ">h>l>p>t>x>|>",
        "yt?[$",
        "'VzyO8",
        "p!\\S^",
        "8|$1+",
        "V3\\`\\",
        "&/ePY",
        "sy9b#;i;",
        "9O.d!Y",
        "toPVR",
        "JkjKH",
        "Wpo@4I",
        ">6>E>a>",
        ")sQ/Q",
        "D*(r,e",
        "]BV4\\F",
        "$zc`#",
        "dataEncipherment",
        "1s, \\u",
        ";9<d<",
        "domainRelatedObject",
        "[LICENSING] beta key refreshed probably due to an update",
        "l$ FG;t$",
        "fzN\\2U?v",
        ">D:}d",
        "u PWQR",
        "ic,6v\\",
        "Domain",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10178046\\charrsid4208764   The warranty period",
        "nextupdate before thisupdate",
        "(wzF]",
        ">;>L>]>u>",
        "$m!s0",
        "2i[vp",
        "Th*yNx",
        "FJ8![",
        "[[YXU",
        "*Z?#\\",
        "1?<V$",
        "dCk>h",
        "F$}5CE",
        "%.&|2",
        "$[[.L",
        "qj(F^k",
        "T$O8L",
        "oKSaj",
        "iP3gJ",
        "lsq ,",
        ":H:m:",
        ")}Zhu",
        "1.vpF",
        "W_<Z^?oQ",
        "N~?zI",
        "eFr(M",
        ")q\\\"=",
        "4$Y*C",
        "4:5V5f5",
        ";b}9B",
        "(,Z;B",
        "d.compressedData",
        "i6RJz",
        ":!:::S:l:",
        "|]r}>",
        "/oiW%",
        "V,!d+[Y0",
        "1 1$1(1,1014181",
        "A&|5o",
        "f[_-E",
        "F$L6ry",
        ";DyDla",
        "a=';A",
        "k+g';",
        "b99$%",
        "NPZQ_",
        "[LW=A",
        "V-W^i=4",
        "HmQ8?",
        "Number of simple chains %u.",
        "|ILG;",
        "J+Hz(e",
        "Tb$8vkb",
        "!8^ONv",
        "y''_~",
        "L$l;\\$4",
        "<Cx'x",
        "S3IR}.",
        "BBXdH",
        "q!O^I",
        "L*QRBRJ",
        "(~,Ak7",
        "/!CplH",
        "InstallAttempt",
        "B2C\"8",
        "DO_EXT_I2D",
        "$l-Wq",
        "GetProcessPath",
        "t$Th(",
        "? ?4?H?\\?p?",
        "D`)`v:p~Y*",
        "\".Uyl",
        "%s successfully copied to %s",
        ":P!=8`2",
        "h7D+D",
        ";az)U",
        "FnnHW",
        "eUT\\jg",
        "xwRl%",
        "/B^-#",
        "1M6(S",
        "iZ[O\"3",
        "&prd<",
        "p2;jE",
        "}%AWY",
        "\\ !/4",
        "AZr~='6Gc",
        " PiReg.exe -d return %d",
        "8'[65W",
        "j.Zf9Q,u",
        "Er@KX}H'b",
        ";+;7;\\;j;y;~;",
        "SC:^>8",
        "A3k'ppL",
        "DSA_BUILTIN_PARAMGEN2",
        "BN_rand_range",
        "October",
        "!,BdbJ",
        "dghwC",
        "InternalName",
        "+/)^L",
        "[txL^",
        "5)eWiqCFX=",
        "S~Mkp&0)~",
        "R{EfL",
        "qv#<^",
        "0)080=0B0]0j0s0x0}0",
        "=0=8=D=d=p=",
        "<[3kT",
        "0J4)r",
        "QDK#B",
        "k}0,KQ",
        "%Bw%U",
        "compiler: cl  /MD /Ox /O2 /Ob2 -DOPENSSL_THREADS  -DDSO_WIN32 -W3 -Gs0 -GF -Gy -nologo -DOPENSSL_SYSNAME_WIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -D_CRT_SECURE_NO_DEPRECATE -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DMD5_ASM -DRMD160_ASM -DAES_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DOPENSSL_USE_APPLINK -I. -DOPENSSL_NO_RC5 -DOPENSSL_NO_MD2 -DOPENSSL_NO_SSL2 -DOPENSSL_NO_KRB5 -DOPENSSL_NO_JPAKE -DOPENSSL_NO_WEAK_SSL_CIPHERS -DOPENSSL_NO_STATIC_ENGINE    ",
        "Wait complete for event (not process):  %s",
        "yb8^s",
        "5]5s5",
        "F%gDq",
        "8`k9-",
        "M(Z1f",
        "F3bNdE",
        "/(Kcz",
        "8(808F8\\8d8p8|8",
        "]d`^5s$",
        "    <PublishingInfo/>",
        "Bad read pointer - no RTTI data!",
        "-n &:!",
        ",qpM(",
        "pkcs1",
        "9.:Z:",
        "*!3U`",
        "]rf4F|",
        ".)($'Nxa",
        "W/Q0iy",
        "1D1t1",
        "HELPER_INIT_FAILED",
        "wnW3\\",
        "XuH:%",
        "4tnjp",
        "+MW/p",
        "-)Q1[",
        "3*FJ2",
        "ToWqR",
        "y&$L96",
        "5:[SN=i",
        "4044484<4@4D4I4M4\\5`5d5h5l5p5t5x5|5",
        "e}pIu",
        "Vag]9",
        ": Pkr",
        "houseIdentifier",
        "no such engine",
        "?%Ew_",
        "HUzCcT",
        "v-)V0",
        "Tv{*!",
        "CMAC_INIT",
        "PxNH@#ebD",
        "iO1qe",
        ">!>9>Q>",
        "wt:y(",
        "k4ibie",
        "5qXTP",
        "+7A99",
        "VhT3&",
        "-----END ",
        "'%](.ZU",
        "u\\;t$ uV",
        "IDLgY",
        "3\\&6P",
        "`!YJ'\"S",
        "failed to openexecute temp view with query %ls",
        "DMARK",
        "Tth!N",
        "RMVlr",
        "5m.M=/",
        "rZ6j*",
        "^C\"/td",
        "RY\"Gn=",
        ".DDs[",
        "wrong order",
        "D$,SUV",
        "y9.9a",
        "sJ?3C",
        "o^@A&.k",
        "IQ\"BW",
        "!8DK4",
        ",7b4_)",
        "D$,Ph",
        "6B7X7)898",
        "NKvgl",
        "V3Z5OZt",
        "#4FWK",
        "JbDcJM",
        "6&9ne",
        "]FHI(",
        "hUK}14",
        "W\"AK/\"",
        "RSA_NULL_PUBLIC_DECRYPT",
        "xKc5o",
        "&F2?Io",
        "~j,|8Q",
        "%c%c%c%c%s%c%c",
        "??}Or",
        "1igK`_",
        "OCB9`",
        "pb,]@rm\"",
        ">Mp$d",
        "7 7$70787<7H7P7T7`7h7l7x7",
        "?FQeJ",
        "CLIENTSTARTUP is set to NO",
        "*z6mH",
        "2f97t",
        "t',F|7",
        "N;xmB",
        "jZXf;",
        "3Q3d3",
        "2(cd%",
        "dm&X\"",
        "}oMXLFs",
        "8fJ-Ng",
        "`eB%]",
        "} 7H,M",
        "auRy ",
        "/1it,",
        "]\"_R_",
        "t_|\\5",
        "DH-DSS-CAMELLIA256-SHA",
        "R\"W:V",
        "\"==~~6ihr",
        "rb.<L",
        "'f?Er",
        "CLIENTDIR",
        ";hd`G",
        "'V@F@e",
        "vfC*P",
        "}`s95",
        "ov_\\iAs",
        "EY~}x",
        ":j<!P",
        "Internet Logs\\",
        "|!73.",
        "80<0@0D0H0L0P0T0X0\\0`0d0h0l0p0t0x0|0",
        "TE_J)",
        "E j6\"",
        "O0`=}",
        "KN~u`a",
        "t$ VV",
        "oaz<s",
        "7U7c7",
        "Y4yCl",
        "\\gzflt.inf\" /S /F /C",
        "HJXJlJtJ",
        " {_za",
        "O8Kq.?z.n",
        "id-aca-role",
        ".?AV_Node_assert@std@@",
        "^%Yot",
        "uC:&!",
        "9-9;9G9Q9]9b9",
        "S/SK3*",
        "co hl",
        "firewall.dll",
        "^5\"\\2K[",
        "t$$UW",
        "Proxy-authenticate:",
        "t)h8z&",
        "X9.57 CM ?",
        "=#='=+=/=3=7=;<?z.z",
        "V0C1C2C3C",
        "a~hqi",
        "%I64u-",
        "yp|@,(",
        "2'h.6Ft`",
        "rT7mg0",
        "4r,xw_",
        "3D$<3L$8",
        "pzqoy1",
        "?MsiCleanAll@@YAXK@Z",
        ";[/Ib?",
        "FCOMI",
        "fYGN$q",
        "K]\"}\\",
        "B;=1.",
        "B64_READ_PKCS7",
        "=Nsz~&",
        "Software\\Zone Labs",
        "EVP_PKEY_encrypt",
        ": :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\\:`:d:h:l:p:t:x:",
        "S]y&WG",
        "|\"_,K",
        "G^JW)",
        ":/gU`",
        "April",
        ": :%:):4;8;<;@;D;H;L;P;T;X;\\;`;d;h;l;p;t;x;|;",
        "tGjCh",
        ">$>h>t>",
        "WUz[rU",
        "E*EkS",
        "h\"P|X@",
        "818G8P8[8c8",
        "YRD7n",
        "Check Point Endpoint Security Tray 2.0",
        "p%8mK",
        "f*SeKd67@",
        "/2H`&{",
        "g]Ul}",
        "#qc87",
        "0%030R0`0s0",
        "Stack part of OpenSSL 1.0.1t  3 May 2016",
        "Lx`je",
        ">6?h?",
        ":#;,;",
        ".?AV?$sp_counted_impl_p@Um_imp@filesystem_error@filesystem@boost@@@detail@boost@@",
        "bad decrypt",
        "(11U2",
        "N6f$]^",
        "7Z97;",
        " U9P\\",
        ",YMd\\",
        "iu[vy.",
        "VAZU%",
        "2pBxO",
        "N%E%;",
        "]1}%'P<",
        "2bX|B",
        "415W517",
        "@Y4C)",
        "M)f_i8B",
        "$<A3!",
        "jf{Kd]Q",
        "Gw'='",
        "? KYI",
        "invalid proxy policy setting",
        "1Qg>K",
        "+d]!A^a",
        "C)HANhw",
        "4<4k4",
        "<S{$'",
        "0qFt0",
        "4k5{5",
        "le8imi",
        "777d7",
        "F~OV5pC",
        "zonelabs\\vsmon.exe",
        "X509v3 Key Usage",
        "5P>?ZY",
        "iw\"-E",
        "0\"0T0",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\uuid\\detail\\random_provider_bcrypt.ipp",
        "GetDoubleClickTime",
        "+?A/S\\A",
        "8X3LrX",
        "qh1b2",
        "7-7O7",
        "ty+u~",
        "S3Le(",
        "t.D}k\\",
        "AR?Kv",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2849700 ,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  You are free to pursue any alternative You may have.",
        "soLK8uY",
        "D$P3E ",
        "&FbbYu",
        "h-27k",
        "$~cjp",
        "fj0<B",
        ":u,!0[",
        "C@9a`",
        "jej~j",
        "r$)gO",
        "L<$@$D$H$",
        "s%ft+",
        "WSAStartup",
        ">->S>y>",
        "q%[#g",
        "-x$dzM",
        "GKhI_",
        "+K[e-",
        "8KCZ:",
        "364[4~4",
        ".}!Zg",
        "?#?.?3?8?\\?",
        "SYSRET",
        "|O5?N",
        "=9A!Mm C",
        "3+Ik(",
        "?0YpX",
        "OD&H&`$",
        "|$`WP",
        "7SAZE",
        "qk=HF",
        "*s}M*,",
        "class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > > &__thiscall boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >::get_child(const class boost::property_tree::string_path<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct boost::property_tree::id_translator<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > > &)",
        "';LS)9",
        "V28fR7",
        "U9(l4${",
        "\\M}/u",
        "ae1%F",
        "iP~z6^",
        "\";CW`",
        "id-hex-partial-message",
        "?NRa\"$@",
        "dB_:+",
        "3#kzo3",
        "\\KNeF",
        ">:?C?",
        " 0xa7",
        "1Pp`8",
        "<W8i$",
        "3SLgfo",
        "NKloy",
        "(nqN0tp",
        "t$(UW",
        "|`IF#n",
        "invalid state reached %s:%d",
        "*4hi/G/",
        "_)1fD",
        "Ip,;]",
        "ModuleBar.png",
        "]-V|L",
        "=!===Y=u=",
        "Y|6_>",
        "8!g*#",
        "A!rsv",
        "uO-pj",
        "8KMDZCn",
        "photo",
        "0\\$\"/",
        "DL@d=d",
        "a7PdL",
        "fmF*g5",
        "0<urM^",
        "Bgv{LL",
        "=TaRz",
        "knZaUS",
        "RJ_He",
        "l[DQF-",
        "\\ex*]",
        "k(6!2",
        "NUXQ4U1UAU",
        "6G;C;k",
        "SVhxp",
        "W@o!o",
        "j jij!",
        "4}vFK",
        ",E3Jy^Z",
        "G7b}t",
        "wRDL+",
        "=5RU9",
        " g>Qz",
        "2pgrv7",
        "y7 P?",
        "t}.^}",
        ">(>H>T>t>",
        "F6C>.",
        "4b(f}",
        "F _^[",
        ".?AV?$collate@G@std@@",
        "Failed to join the existing Restart Manager session %ls.",
        "UJK,W",
        "j\"Xf;",
        ":!;);{;",
        "D$0+D$",
        "Snxnz",
        "2T3w3",
        "?>t\":q",
        "5!5%5)5-5",
        ">`$X&",
        "1P\\ex",
        "oN\\+h",
        "i~kdes",
        "AoX78",
        "w~JqO",
        "CreateProcessA",
        "5:5b5",
        "ymAE|TH",
        "bhZ_RVY",
        "KeVB}",
        "yCx%u",
        "X[7]*",
        "0,1F1X1",
        "rk.\\zl6",
        "LaZ6e",
        "0(0D0T0t0",
        "N,At5%2",
        "6J6T6}6",
        "MINSD",
        "$\\Z<mERs^",
        ",&L#)A",
        "bR5vAm",
        "Vc b4",
        "<$<A<}<",
        "J;CfM)",
        "GYIhr",
        "lu2}zRxW",
        "M5l9MqJN",
        "`zXX2",
        "a>!\\B",
        "setct-AuthReqTBE",
        "is_UninstallIMSecureLSP",
        " \"'U*",
        "KZM&>",
        "W=oal",
        "6#6<6U6n6",
        "@1R-0\\",
        ")Sj11",
        ";yCE9",
        "}|@+b",
        "Z--wZ--w",
        "patch.xml",
        ":3:I:U:\\:",
        "['\">0r",
        "RegOpenKeyExW",
        "MAIL FROM:%s SIZE=%s",
        "``@ PP@",
        "5&656'7",
        "h%]b,",
        "101383|4",
        "TreeSetNamedSecurityInfoW",
        "O7l#q",
        "`RTTI",
        ")s<t^",
        "Ghq=`d",
        "<ma*W",
        "5TwgV",
        "Update (patch) install or uninstall finished successfully. Stopping EPClientUIService",
        "Fobqasa",
        "setct-CapReqTBEX",
        "K2=hj",
        "vO,ilD",
        "8d)sv!",
        "^<^[]",
        ",6hMR",
        ";.?F@lv!",
        "cvAu!^",
        "PKCS7_ISSUER_AND_SERIAL",
        "=>HPt!",
        "{b;<b",
        "uHYbN0",
        "Jkc9{]",
        "lZcbw",
        "jAj~j%",
        "cnOpc",
        "e0@vB",
        "bg-BG",
        "_mW~v",
        "AH<q,P",
        "$<\"r83",
        ":!:4:[:",
        "&B1o[",
        "/+Osv3",
        "(lEBA0XMkM",
        "]STu4",
        "Sp.$/$lo",
        "=9*(Mc\"Q~u}s",
        "JMJhJjJnJsJuJxJyJ}J",
        "0CBU[",
        ";;[ke",
        "igUfom",
        "5TFTi",
        "G:E+LB",
        "KV`_Y",
        "5#4DhVvwxW",
        "153D3D4^4",
        "7L7}7",
        "HEN<5",
        "Jcrve",
        "D-NopE",
        ",%~lh#",
        "GetUmsCompletionListEvent",
        "t jvh",
        "9\\$ t#hs",
        "`b>>O",
        "Iunge",
        "l[J2&=",
        "(Uds3",
        ":p:<Yje)",
        "CPZml",
        "4 5)525@5I5Z5v5",
        ";2<@<L<",
        "!s$jZN.q9",
        "K?iK\\",
        "9 9<9X9x9",
        "oyG(?",
        "70vFS",
        "1#<!\"Rdg",
        "%s file does not exist, do nothing",
        ",VVO8",
        "|Nd i8T",
        "->+u(",
        ";H<{<",
        "psR:`|",
        "yW.D9",
        "SU\\vz",
        "q,{=5^A",
        "\\K/$8icA",
        "gaVD=~",
        ".stS@^.+",
        "Uj^kB",
        "8u86:",
        "VPUWh",
        "RFC 5639 curve over a 224 bit prime field",
        "invalid option",
        "_hz7]S",
        "j*nj7",
        "9@:D:H:L:",
        "G*Jys)",
        "CfEJ1",
        "Quote command returned error",
        "5@Z[$",
        "Q`ubv-",
        "i=^@4~vg",
        "Cc_y7",
        "CreateIcon",
        "7[o3yZ",
        "FNSAVE",
        ":\";T;x;",
        "`uhDv(",
        "tLV0d",
        "^QPw!Q",
        ",F.ry",
        "3V4[4m4",
        "UninstallFW:  UninstallFW started.",
        "({o80=v`",
        "mailPreferenceOption",
        "(EQ,CE ",
        "7!8a8",
        "d!5/s",
        "r=XN9Y",
        "?s&?E",
        "%|D`$",
        "EPAM_OnBegin started.",
        "\\PSGControl.exe\" /cpe",
        "txo>~'",
        "boost::too_few_args: format-string referred to more arguments than were passed",
        "z~z~}}x",
        "X9Hu'",
        "UllpcT",
        "$DyB(",
        "4&5n5",
        "VSUninstallProductEx",
        "nWWxb%",
        "V*e+h",
        "Loading error information from msi database -- Failed to read record. ",
        "8) D-",
        "CpSbaUpdater",
        " 0x93",
        "|iSL*pA",
        "=^&VB",
        "+%&'V",
        "m^-CY",
        "D5}${`",
        "Bad time value",
        "[Self Validation] Fatal",
        "_N^~abEh",
        "Q|~fX",
        "salt length check failed",
        ".?AVother_error@detail@nlohmann@@",
        "\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid6823349 \\chftnsepc ",
        "rIZNe~u",
        "M~UUs",
        "<7<P<i<",
        "GC2Wp",
        "A3R\\8",
        "e|Qr/",
        "2K2s2",
        "?P?a?",
        ".?AV?$moneypunct@G$0A@@std@@",
        "Y=g#Pq/",
        "set-certExt",
        "TG)KV6",
        "q*F h",
        "~Sd4NDO",
        "R5e/q",
        "w^e2]",
        "N PSQ",
        "s3ir;",
        "z/%l_",
        "d%t9xs1",
        "`Hb!t>",
        "6 7)767<7B7k7s7x7",
        "x.,:v",
        "k$4DOb*",
        "SDq?]3$",
        "D8]4`",
        "lzJN9)]",
        "ZLG7*",
        "JXB,oS",
        "kZ7K:",
        "UF5uxb",
        "r2_R=",
        "Z0H?t",
        "Lfco2",
        "e|D|/IR",
        "!RO?k",
        "Disallowed system request to shut down the custom action server.",
        "BLg]W",
        "VMPTRLD",
        "] Vg(KnAk",
        "4CoMxZ",
        "Preparing for accepting server on data port",
        "invalid name",
        "VA)>j/@",
        "uZf_I",
        "Y.x\"E",
        "oP}A ",
        ",rA2(r",
        "UmxAgent.exe",
        "*OXBe",
        "oN?.q",
        ";?;t;",
        " @k`K|zh",
        "4-4<4W4y4",
        "IetIZZ",
        "^Hr1yv",
        "0+qTndG",
        "/OyV.V",
        "ZkKoNTh",
        "m@(mZ",
        "t$ QSWR",
        "SEC_E_NOT_OWNER",
        "EC part of OpenSSL 1.0.1t  3 May 2016",
        "SECG curve over a 163 bit binary field",
        ".95:}_",
        "WIX_DIR_NETHOOD",
        "0 0H0",
        "]f^Y;T",
        "FrrqJ",
        "o@dMEu",
        "Ed;E0uG",
        "[w<zi",
        "/O 3~",
        "\"{JkyI",
        "o.s.w",
        "`'b?GP",
        ";4<=<C<",
        "2)292H2b2i2u2",
        "StorePropForDeferredCA custom action end.",
        "~c$?B",
        "Bp'\"s",
        "9<$|w",
        "=&=B=^=z=",
        "8\\eDR2~F",
        "renegotiation encoding err",
        "SetEntriesInAclA",
        "(ZG`2",
        "2(2,2<2@2D2L2d2t2x2",
        "`8e|$",
        "lDb<SX",
        "0%1j1z1S3",
        "hX7W+",
        "?EQ%H,E",
        "Content-Type: %smime;",
        "G>\"B{\"",
        "fL[rC",
        "atp2@",
        "0-!r_",
        ",f!(W",
        "G'yf}",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477 location}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3736522\\charrsid15169477 ",
        ".)\"NF",
        "*2XHn_",
        "%JV5p",
        "~1M!l",
        "7 7N7]7o7",
        "St&:x",
        "jo UNz",
        "M0D\\#",
        "= >x>",
        "65~0*",
        "d.f]i",
        "Skipping SchedXmlFile because XmlFile table not present",
        "v`,>qd",
        "E&w7_",
        "i1{1&262",
        "\\ywb)i",
        "839a9",
        " *crJg",
        "RTSP session error",
        "~J~LR",
        "\\ ^ ` .\"d\"b",
        "%s#[a[-",
        "9%:s:",
        "FIPS_CIPHERINIT",
        "gu[{l",
        ".r2XC",
        "3*4F4",
        "}A,^3",
        "sx5NQ",
        ",ZV]\"",
        "anaO0",
        "C1MST",
        "*4b+@{",
        "&2HEZZTX",
        "^i2\\o",
        "<M9Z:g",
        "9$909@9L9X9d9p9|9",
        "E%9;#A",
        "1<2n2",
        "illegal format",
        "^0v{Ka`",
        "y&C.M{_n",
        "Gms!F",
        "#hk,w",
        "t1jHh",
        "8{pcm",
        "Xv:@n}",
        "]_\\,@e=u",
        "Bj56e",
        "8O1/`x",
        "nX<)1a",
        ":,:0:L:P:\\:|:",
        "NET'2I|",
        " 0'rqSX",
        "/4,N#E",
        "-]_'T~",
        "526=6P6q6",
        "\\c>U;O",
        "Tv15:2",
        "MF\\^F",
        "S>|~S",
        "(FM_AP",
        "=5=C=N=Y=d=s=z=",
        "<skqCi",
        "%!=X<",
        "F!pYp-",
        "||=;>",
        ".<E<J",
        "ro-RO",
        "Mask to be checked: %d in %d",
        "eTJHH",
        "4J5U5p5",
        "=-=M!",
        "A{!.Y",
        "i:(urX",
        "ew:pD",
        "'[|Q^",
        "5xhu3",
        "AbZGb",
        "7W@;O",
        "8\\U'lv",
        "4&464",
        "637T7",
        "31nln",
        "9rZNQ",
        "/FHzS?",
        ":o/h|",
        "B)svF",
        "B1Yf5'",
        "Y|+u5",
        "unable to decode rsa private key",
        "=M>W>t>",
        "srG72",
        "TnCP_",
        "m|'3u",
        "2o3{3",
        "1VjwFV",
        "1K1}1",
        "IW%if",
        "?YN2{",
        "dBr&d",
        "888[8~8",
        "$)/E.",
        "$9LtDU",
        "JG8!z",
        "iX@I?",
        "iIQq/r",
        ">J>l>",
        "e!q=9",
        "EG:U2",
        "I%u/S",
        "'}FK ",
        "5SC_\"%",
        "5K6t6}6",
        "ytuX)",
        "sT|Q.l",
        "Ao'}X",
        "y$}[V",
        "4d5!6",
        ":6;D;",
        "L$ _^",
        "3[:~y",
        "<M@US2",
        "!vC{8",
        ">|5Lt",
        "registry key %s exist, check if %s exist returned: %s",
        "\"QDBY",
        "YiFEN",
        "h[sJa",
        "1V2|2 3c3",
        "JqJ3|G&",
        ",!'C~X",
        "=G={=",
        "G'PoD|",
        "I;5<w",
        "mA15HoEI",
        "bT1AH",
        "!.TA3B",
        "I*OO)3+ts",
        "msCodeCom",
        "*t.xWV",
        "MapViewOfFile",
        "Y3N<ux\"",
        "u]9L$$uW;",
        "jzZf;",
        "6{VJZ",
        "AdminUser",
        "dD^\"F@",
        "jijuj",
        "j=wK[(P",
        "*~0Oa",
        "youBd",
        "G#d?t",
        "WJ/xd",
        ";|[YkDAozu",
        "[WCubf]",
        "Qu]Wi",
        "N,TZ3",
        "qtqtr",
        "CEAeBUq",
        "invalid extension string",
        "7/7M7Y7v7",
        "O[bh@",
        "L$43*3",
        "XC*zQ",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\HotFixMonitor\\1.0",
        "&&5sN",
        "$=t7n",
        "D7C)Q",
        "b0gt?",
        "Qb@ 3",
        "*1A}-",
        "D@m\\L",
        "CBQS8",
        "U+(P`I",
        "qYqZq[q\\q]p^",
        "s>ov)!",
        "too many iterations",
        "`\\XbA",
        "E_~-b",
        "PwSc{",
        "BSaw\"",
        "4-wEg",
        "3'3Q3l3",
        "unable to decode ecdh certs",
        ")N(CS",
        "nDXLs",
        "WVZJ=",
        "r*H?C",
        "90959\\9",
        "5MBVjX",
        "q^>Yv=",
        "ServiceInstall",
        "FzG>T,",
        "pWXf_&",
        "id-pkix1-implicit-93",
        "0x)({",
        "n1SI-",
        "C!3>p{",
        "P-384",
        "@;Q8j2",
        "failed SysAllocString for path",
        "\\zonelabs\\smartdefense.dll",
        "5@>TLc",
        "  aKj",
        "{R\\/bq)8$",
        "|nAFk",
        "q;p_0=",
        "Invalid SSPI authentication response type (%u %u).",
        "YT7#\\",
        "G~eJ7",
        "[)OgY",
        ":D;R;",
        "0 0,0L0T0\\0h0",
        "OlG2-j",
        "&&Ygd",
        "0%1q1",
        " Cl%FT",
        "jhjkj",
        "P&,N0CP7i",
        "%CIFv",
        "j(j%V",
        "peEI!",
        "2&282J2\\2n2",
        "x+g<hE",
        "='=U=",
        "7pCHo,a",
        "!-t\\.t",
        "<&Y)>",
        "\"rKMC",
        " to update vsconfig.xml",
        "3*3>3U3g3y3",
        "9#9)9/959;9A9G9M9S9Y9_9e9k9q9w9}9",
        "ox;ufb",
        "X#7k=Mn",
        "~^u_VR(",
        "LI>|9",
        ".[a.Na",
        "$=\"PP",
        "d595=4Ej2h",
        "%V\"wk<C",
        "S^+}\\'",
        "mg5vW",
        "LZ]i[r at",
        ";-'*4",
        "FD^][",
        " 0xf2",
        "r#;6V]nD",
        "7d4WX",
        "3d;nv",
        "dMdib",
        "aN=2iC",
        "bJ>{D'jef",
        "0*0)1I1s1",
        ",EFU+",
        "mOMGE",
        "D$ H9D$(s>",
        "*(gI`qq",
        "JmFc$.q",
        "!U$QW",
        "FWUpgradeAfter:  UpdateVsConfigXML skip",
        "FcCcuh+/",
        "jv|Hjl",
        "@A4!6Z",
        "(E_Mdl",
        "id-cmc-getCert",
        "*h.&@",
        "z3~l|\\",
        ".l<Ju",
        "Eu# .",
        "<*<1<<<O<V<",
        ">j7$X)",
        "CR5$X",
        "Q:\"SI",
        "5I{s/$",
        "]\"w{Yp'u",
        "~1LDN",
        "919M9i9",
        "FX_^[",
        " 0x49",
        "cU0yF$u",
        "?u#IW",
        "smj-no",
        "uHVhA",
        "\"8/a2",
        "(d2UP",
        "Kjg=q",
        "j.B'E",
        "tlsv1 alert protocol version",
        "d=;\"}t",
        "6&626D6O6v6",
        "z]#^D",
        "5-w[*",
        "p>f{+k$",
        "Vdv9dpH]T_",
        "< <$<(<,<0<D<H<X<\\<l<p<",
        "b~N.5",
        "cPm!yCW|",
        "3SU%r",
        "AS<k<",
        "Uvl^b",
        "othername error",
        "\\system32\\zonelabs\\connection.xml",
        "I|ra8",
        "7mUyw:",
        "}Dur0U",
        "kvL^G",
        "[DUMPFILE] %s suppressed because of tvdumplimit=%u",
        "M{Q.M",
        ":6/h.",
        "fC`T?",
        "PvWq83dA",
        ")mqj%",
        "qb<R(",
        "6&R7|Mq",
        "dso already loaded",
        "k,BTqZ",
        "p0M`=x@",
        "/L^@X%P",
        "M s!'",
        "GetNextUmsListItem",
        "1.2.3",
        "L: ,1",
        "SSL public key does not match pinned public key",
        "sqoLf",
        "JjYTb",
        "`X+GP",
        "OMd&L\\",
        "l \"8U",
        "_JC}w",
        "57a>R",
        "#}|60#",
        ",&,6,F,V.f",
        "oIZ0@e",
        "#Soc<[",
        "}]O>6",
        "VSSetInstalled: success",
        ";;VDG",
        "&yj6f",
        "ESS8@",
        "g>Ma>",
        "e}Z]y",
        "TJMU-",
        "t'(w\\",
        "D$(t5VP",
        "xF6qv",
        "Lk)D4",
        "expecting private key blob",
        "Xh7A~",
        "767U7h768;8",
        "()|RI",
        "`Xqi$",
        "@I3:p",
        "sa-IN",
        "020>0g0",
        "$Q_)C",
        "gVLA~",
        "N 2DNL",
        "^gbr&&v",
        "R]*>Y",
        "E]R!W",
        "LgiTH",
        ">Hqz%1.+",
        "y-I0w",
        "Another instance of the VNA already exists.",
        "]9UQy",
        "DV0+[",
        "T?>\\R",
        "=|gam",
        "Vh.k\"",
        "575?5W5",
        "xz6p(",
        "-g E$",
        ".'_}D",
        ">L=T=",
        "9)!JU<",
        "?\"?j?",
        "FeatureIMSecurity:  imsinstall.dll successfully loaded.",
        "+Ps%X]E",
        ")G&HSL",
        "3L$<3L$",
        "=\"+@(",
        "|8rlG",
        "lhEI1",
        "ou*2d",
        "package does not contain new SCUIAPI.dll no need to reboot.",
        "J.EcF",
        "`sC\"5",
        "$Tf9B",
        "FLT_DENORMAL_OPERAND",
        "token present",
        "|2~I,",
        "}M=MLN",
        "T{@mb",
        "Wj0XP",
        "GetInstalledVersion: Anti-Malware key does not exist",
        "~OB;ON",
        "(4b<'Q",
        "UGdn\\t",
        "tlsv1 alert insufficient security",
        "ClrDataClient",
        "3lsD-hg",
        "@OJNUc",
        "~xo]4",
        "i:@dT%",
        "@H??wElDj>",
        "D((l7",
        "(RX\"C",
        "/\\SBc",
        ";O<z<",
        "=OH*-O",
        "8\"9@9",
        "+8_B ",
        "GZLDF",
        "y4l;C",
        "LYrrV",
        "!7]C,",
        "~=ly:",
        "UQ,Gr",
        "T)~3q`",
        "H3?NJ",
        "/&jL{",
        "HA=_Z",
        "`>Z,UF",
        "7A7I7b7m7",
        "no cipher match",
        "Z3G>|<",
        "1,[MO;",
        "g@VoHG",
        "];uX,c=",
        "8Q~OjNf",
        "sgs'+",
        "nF[Bz",
        "gsLg7/p9",
        ";ik_-j",
        "zb9NI",
        "Vyn9@K7v",
        "c+rw,Z",
        "c;YoD",
        "}q<oB]",
        "lG2\"v",
        "6-7f7",
        "Pc)5@",
        "_DQ0v",
        "43]G_]",
        "\"nDa_",
        ",pl$C",
        "PhD%M",
        "DigestInfo",
        "qs>in",
        "jnhXW#",
        "],\\p~",
        "IdLcl2",
        "C&.sM",
        "=0=P=",
        "zQ[/d",
        "=I=|=",
        "122R2",
        "pmIUh",
        ">=2e>",
        "jWHdh",
        ";.;Z;",
        ")LSCw",
        "zcd1C",
        "y.2=N",
        "t/%K!",
        "ec_GFp_nist_group_set_curve",
        "m7c8%Q",
        "8,9|9",
        ":7;J;w;",
        "X7Wz'6",
        "<;gJo",
        "3@bJxK",
        "\" 08 4",
        "LSLsL",
        "[N(#\"",
        "ub_^]",
        "JfsOS",
        "Epilogue_spdlog.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        ".bxo9",
        "7f8~8",
        "Pu-*/f",
        "=<!3x",
        "P-l*d",
        "@ac`hxL",
        "EVP_PBE_CipherInit",
        "6#7u7",
        "sXX,I%",
        "\\UIFramework 3.0",
        "I>\"e\\",
        "^3Q5Rg",
        "*040:0@0",
        "\\wqpm",
        "h^lu<W3",
        "{Etb6s]#",
        "F$_][^",
        "'BUXu9",
        "K7)@g",
        "4l^+n",
        "AWm5O",
        ">rbg0*E#",
        "B_5(U",
        "6^7s7z7",
        "Is64Bit",
        "r?h'h",
        "ssl3_get_cert_status",
        "*.ldb",
        "g:Zt$",
        "AsVXH9",
        "tlsv1 alert no renegotiation",
        "O$JJX",
        "5>5b5",
        "failed to read file: %ls",
        "g>>iyk",
        "bO[(Rht",
        "hnsf(",
        "0F0q0",
        "Failed while navigating path: %S for row: %S",
        "F5t%z]",
        "\\zonelabs\\VSSSOPro.dll",
        "h;sj.",
        "040F0",
        "mHznL",
        "DSO_get_loaded_filename",
        "|Sdb3",
        "[xFyZ",
        "V7P7-",
        "6'6x6",
        "w{&:MG*",
        "(rib[",
        "PARENTCPDA",
        "*hbJ1",
        ":+:O:U:",
        ":(:B:l:w:",
        "$7X?C",
        "f@Rjj",
        "D0KR]o",
        "3;?o~",
        "?\\x^YN8W[",
        "wL>WpT",
        "5i*?kL",
        "m.s;F",
        "naC4bp",
        "di_9%",
        "f<\"e/",
        "=F>w>",
        "h/1IKR",
        "j,EWD",
        "[~eaa",
        "TL=?S",
        "Configuring Firewall settings (6 of 7 tasks done)",
        "{(^e$/",
        "l*hr%",
        "mob_endpointBannerBig.png",
        "1aP-c",
        "`OMU|",
        "aes-192-ctr",
        "!R9'd:)",
        "shutdownVsmon;",
        ".AZ  -",
        "of)vXX>",
        "oMjI%pr8",
        "GI,z^|:",
        ".^}&|",
        "Qg<dm?",
        "@~T[vJ",
        "4$4(4,4044484<4P4T4X4",
        "$1WxN",
        "Re-used connection seems dead, get a new one",
        ".BX%5R",
        "/cl 5.",
        "}\" bYB",
        "VX]*im",
        "?]z;-",
        "{opqq",
        "5m6=8",
        "qiX_,.?",
        "Ph04G",
        "Z`ud48,@",
        "XD}Mc",
        "j5:mz}",
        ">}UgQ",
        "%Xf,7",
        "id-Gost28147-89-cc",
        "<^dbs",
        "705F!",
        "6k\\1.",
        ".IzpW",
        "i<:h)",
        "/Jngkpgu{",
        "_ir_\"{",
        "OE#Q}",
        "cXr(iF#A",
        ";;lrb",
        "SYc@I",
        ".\\crypto\\ec\\ec_ameth.c",
        "address in use",
        "~EFC`",
        "O;!{l",
        "\"c]bd",
        "00xpa0",
        "E&{ y(",
        "A!{3eB",
        "d/mScj",
        "}MI9M",
        "J&\\d_",
        "a2PF[#",
        "<!<)<J<R<t<|<",
        "1in`X",
        "&}Y;Q",
        "f8:13y",
        ";(;,;0;4;<;T;d;h;x;|;",
        "U:yeY[m",
        "hTG0S",
        "%IG{[",
        "a{ap[",
        "L[ZHk",
        "(=_0A",
        "}B!FJ",
        "6Wc;HWk",
        "jy.:;",
        "~XL[`",
        "[TsrMd",
        "PkDwO",
        "t{VU3",
        "9\\dBE$",
        "-.bfv",
        ";1<y=",
        "sj o!j",
        "-R%lW",
        "h7q+V",
        "9 9\\9",
        " -f \"Microsoft .NET Framework\"",
        "z@,q+FS",
        "SVYag",
        "q8ZSz7",
        "b$|7<@",
        "m<fceK",
        "=(K2yx",
        "-(j2N",
        "R~SjW^UN8",
        "0&181P1[1c1i1o1y1",
        "_!gS`",
        ",s%54K",
        "@8;[W",
        "\\-|p1",
        "VSTOR installation required",
        "j0jx&",
        "U`!{$",
        "^SJd\"{Ql",
        "-g<NB",
        ";4;@;d;",
        "5O5e5",
        "coPi!N\"",
        "+`-D$",
        "@A)+B",
        "Z 7_3",
        "3wx3Oh",
        "E;AhV",
        "n=J5 ",
        "EP_VCRedist",
        "&>i\\$",
        "a+e2O",
        "*d_i1",
        ")j@U3",
        "lvAGnlL",
        "~!AU&D",
        "+}Iz6.",
        " RFa_",
        "g!:W.hz{",
        " 'no office mode' property is not found / not marked as disabled",
        "j<gn:",
        "#WZnMQ",
        "I^8$O",
        "})*?i",
        "n+<2#dGI",
        "5 5(545T5`5",
        "W>Q@i",
        "GM{Z\"",
        "&FXLi",
        "3D2wg",
        "^ Jno6",
        "4Q)G[y",
        "e+~@T\"?",
        "!%z0.q",
        "Ud8jQ)n",
        "5B6R6",
        "}-b'Z",
        "4>Ru>X",
        "muz{w",
        "9*9W93:",
        "E_Z?SS",
        "1voVq",
        "(p@jJ2H",
        ">Sb@v",
        "8M9T9",
        ";b|_UMNk~9,Enqy",
        "!d!C}",
        "'61V9",
        "}TY/Q",
        "rS#kpF",
        "b.Eh^",
        "i'}m>4DiQl",
        "eL}o_",
        "S.-3Je+(L",
        "SHA256 block transform for x86, CRYPTOGAMS by <appro@openssl.org>",
        "5P6f6",
        "|/(zl",
        "Z&v~?E*Y",
        "D3Fi|",
        "/%Y$4",
        " with no type specified.",
        "Killing process:  %d",
        ".\\crypto\\evp\\p5_crpt.c",
        "2+gPj",
        "QFc5_",
        "y-pIs",
        "2$232",
        "6JO*o",
        "Helper.start() succeeded",
        "82:y:",
        "6Ib`O;{S",
        "y\"\\mz",
        "fR.`z",
        "^KB)v\\0",
        "-eB+QH",
        "i%g!\"_",
        " 9o~e",
        "V#y^J",
        "RfQ\\D",
        "T4gQo'",
        "*oOx1U",
        "BU$V.g",
        "W*U7e",
        "t$0QR",
        "DLFCN_LOAD",
        "8C)N(",
        "bad dh pub key value",
        ":':4:",
        "<\"<@<g<|<",
        "GetModuleHandleExW",
        "wFvEQ",
        "<int$",
        "TK]ww",
        "~{me8)",
        "qKDx}",
        ",~35|,",
        "NeTZ;",
        "#%@rq",
        "k>l*J",
        "5 5$5(5,545L5\\5`5p5t5x5|5",
        "5#;z6",
        "j\\Q~9",
        "o6(ij",
        "POLICYFILE",
        ":$:(:8:<:H:X:h:l:|:",
        "YKCz ",
        "{\\*\\xmlopen\\xmlns2{\\factoidname PlaceName}}Technical{\\*\\xmlclose} {\\*\\xmlopen\\xmlns2{\\factoidname PlaceName}}Assistance{\\*\\xmlclose} {\\*\\xmlopen\\xmlns2{\\factoidname PlaceType}}Center{\\*\\xmlclose}{\\*\\xmlclose} (\\'93T}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "@?~4?}2",
        "v5(7z_",
        "\\NjT+",
        "s_]T}",
        "M1\\Y=",
        "nlq^A",
        "0'020B0b0",
        "hd\\Thv",
        "j\"[WVVVV",
        "OT2UORz",
        "pVn0@D",
        "&m'\"H$x",
        "4<$D*",
        "=>=r=",
        "?I}w;",
        "VGo4&",
        "PyT_]",
        "Qcfn{",
        "+qCP']",
        "0mlt`6",
        "!\\&tO",
        "G^j]C",
        "\\]}>1",
        "Kz}T5",
        "zQHp?_",
        "juIe)",
        "Y64Q6",
        ".?AV?$_Ref_count_obj@U_Dir_enum_impl@filesystem@std@@@std@@",
        "kY>W/C",
        "?$?,?4?<?D?L?T?\\?h?",
        "Lj)4Z",
        "&.3iQ",
        "&a'v%`",
        "^;Owu",
        "?0Tdn",
        "u+_^]",
        "{\"O:R",
        "SOFTWARE\\KasperskyLab\\Binaries\\KAVSDK8.9.1",
        "no ciphers available",
        "zb9?b",
        "mIli'?",
        "($8!j",
        "n&%CJ",
        "v\"]E=3",
        "gc;S8",
        "<j@Mr|K",
        "1Cl>MZ",
        "4rE<RI",
        "5&5h5",
        "?!?j?p?",
        "^^4r i",
        "Could not read MaxNumFilters registry value, it will be added",
        "e9sKL",
        "0$0T0t0|0",
        "9Uqnt",
        "V8=`r",
        "&BC:X[z",
        "qFt5R",
        "api_ms_win_crt_utility_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "q\\b`_",
        "$=fAU",
        "-n-G,kZ",
        "d6'*W",
        "AW:=7",
        "9^9p9",
        "uF7(k",
        ",RQ=wX",
        "jZQzi",
        "SSL_COMP_add_compression_method",
        "kS\\y#",
        "d[g[i[l[o[q[",
        "_<_^[]",
        "\\AM1.Signatures\\KAVFullSignatures.exe",
        "msvcrt.cat",
        "`/qxh",
        "ceWDc#",
        "27d>i",
        "I7IB'A",
        "not a supported NIST prime",
        "j.^f;",
        "0H0O0u0",
        "9Dm{Q",
        "`R=J}",
        "dag`fi",
        "6w}j!*.",
        "DYNAMIC_GET_DATA_CTX",
        "Vf.')u",
        "2D3m4s4y4",
        "{dpie",
        "n^x2|",
        "lR\"LI",
        "3-Ir{4",
        "3%4*4@4E4R4W4\\4n4s4x4",
        "protection",
        "w0.?sivX",
        "=<=H=P=h=p=|=",
        "w)nM7 ]",
        ";@{_:;I",
        "eFVW}A?",
        "1)2l2",
        ";0*Ht$",
        "AN*~h",
        "CT:BY",
        "0W0b0k0",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 9. }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        "F#i#R*c",
        "Installer.C0A46163_42EA_4329_B7A2_6CEB49F7CCA1",
        "\\fe]df",
        "lV1\\h7&u",
        "lX''Vk",
        "OpenSSL default",
        "\\kJrg",
        "invalid challenge length",
        "logProcessor.exe",
        "y-x[2",
        "W=@wm",
        "|!P;D",
        "dvO[Q,",
        "1$1(1,101D1H1X1\\1`1x1",
        "_?H(l",
        "j%/1h",
        "zLe:>",
        "0^3t=",
        "%q!5+W",
        ")pIH/",
        "xBuCn",
        "8$8X8h8t8",
        "Dfwtg",
        "iII[j",
        "Unable to extract AM2Signatures.exe: %s",
        "D!D-1=",
        "N~g2Z",
        "Z+1l`EP",
        "6F;=^",
        "~ecBK#g",
        "^X-{[|",
        "b28B{z",
        "jAjej!",
        ":}A/@",
        "\"DVxE",
        "'bB|C",
        ">H[04",
        "q9.o)]",
        "$c_#A",
        "G4u'GtL",
        "cK7!J",
        "b%&cY ",
        "+\"1?I",
        "6];*9",
        "K;#]u",
        "tXa7^5",
        "W#\\MJ@",
        "5 5(5L5T5\\5d5t5|5",
        "WH'wW",
        " =l>N6o",
        "t$ Sh",
        "|tjzF",
        "auf!k",
        "%c%c==",
        ".\\ssl\\ssl_lib.c",
        ":6:C:^:",
        "StoppedBladesMask",
        "n$\"( ",
        "ds{SL",
        "EbrX@",
        ".\\^U~",
        ",{t{I",
        "fJ.~mP7",
        "rg<MP",
        "([;dL8",
        "8I)lI",
        "vt(-w",
        "Q4E]M",
        "B0>*<",
        "pS/>\"",
        ".?AUIUMSScheduler@Concurrency@@",
        " [j-3",
        "BUF_MEM_grow",
        "y\"*EPK",
        "GthG$",
        "homeTelephoneNumber",
        "N@V8q",
        "?)Kqe",
        "1\"2+2",
        "OHb_d",
        "o\\V|~",
        "I?%R=",
        "ZHDL%0A",
        "1!{PG",
        "IIMSI_ValidatePassword returns %d.",
        "7`r~'D?",
        "/#ZKp",
        "dtls1_output_cert_chain",
        "TI!T1",
        "@St?k",
        "s11bS",
        "ZlProduct.Name failed",
        "RxCVb",
        ":&i:r",
        "PreInstallCheck:  Unable to create install mutex.",
        ">O(Rn",
        "t+_^]2",
        "o?\"$5",
        "0D,IU }",
        ")G/r{t",
        "HashPassword",
        "ZQepA",
        "4+`+N+N/M`",
        "I;.<Q;",
        "&@WrtR",
        "\\MpClient.dll",
        " W4FL",
        "}?[NXH",
        "Es`q.",
        "hBS\"d",
        "H>1Ua",
        "/&WFo",
        "qklIyy",
        "2gOih",
        "Ph`y#",
        ": Nun",
        "=trF6,#",
        "qeD0%",
        "X0+R0",
        "10.V>,",
        "Y?\\kJS",
        "WIN32_BIND_FUNC",
        "2PS1f$",
        ":@:b:",
        "jAjzj",
        "=6s:n",
        "fvY?kW",
        "en-us",
        ": :$:!=",
        ";;H '",
        "8lj~U",
        "6Oitv",
        "(+<uoOvB2!m",
        "0'BF\"q",
        ")VbRbrBe",
        "Lk4$%",
        ".idata$5",
        "StopEFRService started",
        ".WixFirewallException",
        "x6Q8A8gmO",
        "WixWaitForEvent",
        "@{fr:c*Yw",
        "hexkey",
        "dFlN1",
        "KillEpabProcess finished.",
        "#=HuP",
        "w7E#x",
        "\\system32",
        "v|e%)cUk",
        "Z^5Ue",
        ":A*^1",
        ":(:,:0:D:H:L:`:d:h:|:",
        "jdjdj+",
        "IT&/M",
        "s?DeZ",
        "GP*$qH4'",
        "smn-fi",
        "p 0UK",
        "b70K1",
        "cCR='",
        "&Up&[^3",
        "Yf5oy",
        "$m*fI",
        "ei8+i[",
        "u28cK",
        "SOFTWARE\\Classes\\Installer\\Features\\117CD7D3CB2C542438D083C010944001",
        "'FuHn",
        "sect283r1",
        "Ox=iy-",
        "Smu\\_-",
        "<{.B#",
        "C(+rw",
        "@%44x",
        "T$|3L$",
        "VsEnableRedirect",
        "/Q)z5r",
        "Hostname in DNS cache was stale, zapped",
        "S/+(_Q",
        "1K)[Y",
        "gp:%n",
        "):o<'",
        "B=1#\\U",
        "8;8a8g8",
        "232j2",
        "RVo-3",
        "kwm.=L",
        "Y)9qE",
        "b<99'f",
        "^cdP ",
        "[VSINIT] IsWow64: GetModuleHandle('kernel32') failed with error 0x%x",
        "*3F J",
        "P!Q]7",
        "GetBladeRequiredDiskSpace: cant MsiDatabaseOpenView on Feature: %s ERROR: %d",
        "1\"1&1",
        "<:<b<",
        "UpjD%hm!",
        "setct-AuthResTBS",
        ", abuse, accident, electrical irregularity, theft, vandalism, fire, water or other peril, (7) damage caused by containment and/or operation outside the environmental specifications for the Hardware Products, (8) alteration or }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "CC]-v",
        "QF5`=[Q",
        "=\"QP=",
        "kF'>s",
        "yHPdv",
        "NkZll",
        "store init error",
        "PEM_ASN1_read_bio",
        "mt-mt",
        "m)1J#",
        "X&kEh",
        "4iqJ'B",
        "mme}b",
        "90:=:n:{:(;:;z;",
        "MOX5Z[",
        "+AD+D$",
        "tB-Pa",
        "t ujKr7",
        ";A<t<",
        "Rh\\IM",
        "OIBg# ",
        "X;aIr",
        "86P[szJ<",
        "'WD{K",
        "Rm:eO",
        "c!s\"]",
        "p]M-pN",
        "IsWow64Process",
        "D5Wf\"",
        ")%RL(",
        "0#IAQ",
        "J!,<Y",
        "*f#mMD",
        "canadian",
        "ReadFile",
        "6*7q7",
        "HB@Dw",
        "EnBLtd>K",
        "SSL_set_purpose",
        "&v:I9p",
        "SoYK%&",
        "Zc+xuU",
        "eq}dU",
        "w8Z_K",
        "U%@-f",
        ")b5f)",
        "9I:\\:",
        "??1_Lockit@__std_alias2@@QAE@XZ",
        "4=5L5b5n5",
        "<'a\\D",
        "8'8,818A8F8K8[8`8e8",
        "Rz:h&d",
        "+ZN9gP\"",
        "zFO'^",
        "2N2\\2j2x2",
        "E,(LT\\",
        "qMOU#",
        "3I4}4",
        "1&1F1S1",
        "+|o6?",
        ":3;:;F;T;n;u;",
        "SP^W%",
        "R?Mwwz",
        "enHSH",
        "1 1$14181<1@1H1`1p1t1",
        "fy|\\2",
        "responseStatus",
        "`-I3b",
        "u2)Yrx3",
        "M\\&fGviv",
        "7rvnL",
        "J!:Lz",
        "ej7h(u",
        "OI~>&y",
        "4!5'555;5_5e5t5z5",
        "4$4?4\\4",
        "T$ f;",
        "Address   Frame     Logical addr  Module",
        "nSNAN)",
        "S\\?>e",
        "6,7d7",
        "7S7d7y7",
        "0{8CC",
        "#1b+e",
        "hBD30",
        "XARG~",
        "_#v>~!",
        "l/qyZ",
        "^LHhBx",
        ":JtVK",
        "uB8D$$t",
        "dtls1_send_client_key_exchange",
        "a_mSe",
        "Ywp> `R",
        ":*:F:\\:",
        "CnS=Tv",
        "8Ki,e",
        "Kill Mobile Agent.",
        "*1h!UV",
        "o!q*+",
        "L\\m?U#",
        "|(k#M&o",
        "put_value failed",
        "C0dRLC",
        "BQ&wa}8",
        "PJV9l",
        "DL6Sr:",
        ":';/;F;X;m;};",
        "H`JN*",
        "Sc/%R",
        "l~ q ",
        "Y$B:e",
        "__V?F",
        "|$ t9",
        "333>3^3t3",
        "jAjwj#",
        "#wum9",
        "#-sh{&",
        "c\"IR$/",
        "zKfjfP",
        "TLS header",
        "8]7V5",
        "%r<9O(T",
        "8 9$9(9,9",
        "Changed conditions were successfully committed",
        ".ALY0",
        "?QOF!",
        "Y`{Ph",
        "g}z_Jy",
        "lW(\\H",
        ".?AVUMSFreeVirtualProcessorRoot@details@Concurrency@@",
        "]}]R.",
        "CAMELLIA-192-CFB8",
        "7=7V7f7",
        "@D.vv",
        "OtRi4",
        "4*5@5V5l5f6",
        "lX_=ey",
        "Q~P\\+",
        "M0(Kmv",
        ">V?]?",
        "L$~zu",
        "[sJhky",
        "[L(Sl2",
        "Client key",
        "8!81898D8L8R8]8e8",
        "N/bwm",
        "L\"\\etc",
        "1/1\\1",
        "L-\\?DU",
        "PSSSSS",
        "5!5?5N5`5h5",
        "no reference",
        "u'jUh",
        "businessCategory",
        "[5/PSo",
        "4`4HWK",
        "Q:y]R",
        "HIHXg",
        "B4h,c",
        "[Xl|X",
        "?Xa,e",
        "LC<s?",
        "0c*6{",
        ">5><>B>G>U>",
        "`iTNK",
        ">0>8>D>d>l>t>|>",
        "1J/$%K",
        "-^&lai",
        "fvf)PoZ",
        "M~\"@5",
        ")=RR03",
        "A,2x.",
        "Xj3Ov",
        "+i1-U",
        "jSh0:#",
        "bGo8r",
        "+3`?x\\( ",
        "Zone Labs self-generated dump (requested by calling code).",
        "<=<O<[<",
        "CE Ph",
        "fX7Um0",
        "\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 1;\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 1;\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 1;",
        "atlTraceGeneral",
        "u8d3)f",
        "jdhxcH",
        "ByhkVi",
        "d`o4O",
        "4!5)5",
        "fpY>4M,",
        "DR5t$",
        "0%0+01070=0T0",
        "; ;R<",
        "9+:0:::D:N:X:b:l:v:",
        "kxZW}",
        "^|'*un",
        "M>X ?",
        "n~@pL&l",
        "LK}{FxP",
        "Q$=Aw",
        "4q4v4",
        "wfWUi",
        "OpOqOrOsOtNu",
        "go+`q",
        ";0K1/",
        "y!e= j",
        "3Vw\"#b",
        "qE|;j",
        "BrH.(",
        "<XjzW",
        "Z5-^Z",
        ": =kG",
        "uYJm=",
        "sH#4U",
        "}43dE",
        "h nv,",
        "sXOvCZ",
        "s{@M&",
        "=6>D>V?c?",
        "c8#h1v",
        ";({2C",
        "f/VM7)(",
        "4Q}L{",
        "F;t$(|",
        "8SpW]",
        "EVP_PKEY_verify_recover_init",
        "v*5]{",
        "fifteen (}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 15}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529 )}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 ",
        "s%DPH7",
        "rt1kKh",
        "E0#I}",
        "8<JO3",
        "voD*03G",
        ".~;*^",
        "< <$<(<,<0<4<8<8><>@>D>H>L>P>T>X>\\>`>d>h>l>p>t>x>|>",
        "AUTHu=",
        "3(30383D3",
        "W)+8R",
        "w+a9D,",
        "mIl\\y",
        "&7. ?L",
        "010A0Q0",
        "jDYjD",
        "K=el9",
        "IND)ind)S",
        ";5;U;u;",
        "L$$9M",
        "t'WPhX #",
        "7b_-{-`",
        "h<)l*",
        "42J2V2b2i2|2",
        "%+Mz5",
        "dEKMm",
        "failed SysAllocString for remote addresses",
        "C'R34",
        "(03y}>(",
        "1:LTx",
        ")[Up0",
        "internalerror",
        "h-0\"Bh{4",
        "K'D{?pWW",
        "l6aQs",
        "Creating %s",
        ")`tD ):",
        "4;;OG",
        "505L5h5",
        "9J9}9",
        "MOVSD",
        "u4MIm,",
        "jgXf;",
        "InstHelper is not running, will not be able to stop CPDA service",
        "<\">??",
        "Eef` F",
        "[IMAGE FILE EXECUTION OPTIONS] %s gflags=%08x, pageheapflags=%08x, verifierFlags=%08x",
        "CICps",
        "#vH+s",
        "n>q;a",
        "k;#sR",
        "$;O9-",
        "/ZDo}Z",
        "0$0*0/050;0A0F0L0R0X0]0c0i0o0t0z0",
        "J_X'>",
        "hzr\\\\*S",
        "yM}G>q",
        "Dr4{-q\"",
        "F@j:f",
        "CloseToolhelp32Snapshot",
        "p!zr0+",
        "uz-UZ-Cyrl",
        "^.0$8ctn",
        "2I2S2",
        "AqAGAMAX ",
        "2<L|]<",
        "5fog?",
        "2X2]2|2",
        "@KK6z",
        "EC_GROUP_get_order",
        "616A6a6q6",
        "{9[|4<",
        "5x865",
        "h9qW%N",
        "ocknXf",
        "iPQe+",
        "NtF>1",
        "\\p#@PX",
        " Check Point warrants to You that the encoding of the software program on the media on which the Product is furnished will be free from defects in ma",
        "OnUpgradeAfter finished.",
        "ILLEGAL_INSTRUCTION",
        "1`j<T",
        "7hPU!",
        "WUO)s",
        "\"l52p",
        "W}>p\"",
        "cms_CompressedData_create",
        "8E8~8",
        "$kCkg?",
        "G$hkT",
        "WARNING: Service \"%ls\" is not configurable on this server and will not be set.",
        "p3\"\"' ",
        "LoadVsconfigXML:  LoadVsconfigXML started.",
        ",Z\\Ie",
        "R&3e+X",
        "ED$XPQU",
        "A(u ,",
        "api_ms_win_core_memory_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "{Ymwn",
        "%s does not exist in Binary table nor in %s",
        "l9Bw}S-",
        "}g7\"u",
        "sma-NO",
        "aH`:v{",
        ",31-W_f",
        "AM2.Signatures\\SPSFullSignature.exe",
        "UQ)RkRPVA\"",
        "6Q9q4u",
        "digest",
        "ex}l>IQk",
        "S?#f!",
        "]UeU-V",
        "v+[m4",
        "Content-Type: application/xml",
        "ERROR: selector [%d] invalid",
        "E!`czA'",
        "id-pkix1-explicit-93",
        ":s>U5b~[$",
        "aO`J~",
        "$grW@",
        "s~O n",
        "3T$P3T$4",
        "dk}gRo",
        "),d[=f",
        " 0xa3",
        "^S:!'K",
        "fe9\\O(",
        "Sa{?i",
        "DO_SIGVER_INIT",
        "X509V3_EXT_i2d",
        "y[YMhZ",
        "1hf BZ",
        "dKf{r",
        "8o>JL2p",
        "Unknown telnet option %s",
        "]-D4D",
        "/?BppkQ",
        "2F!O.",
        "jBjtj",
        "b(\\XM",
        "i/f8N",
        "f2|a[d",
        "ms;#z",
        "_Kik7N",
        "asn1 parse error",
        "Oqm*f`",
        ".\\crypto\\comp\\comp_lib.c",
        "2!0(t\\",
        "J)%/LQ-*H",
        "zkLU0[~9",
        "0\"1D1",
        "*sP:b",
        "`=tcu:g",
        "Ls{*R-",
        "lq,kq",
        "OpenSCManager failed (%d)",
        "dd+]q",
        "a}p0Z",
        ":W;m;",
        ">y)NM",
        "1-1F1_1x1",
        "{`v?9I",
        "V7kf*",
        "i|T2'",
        "4#+R}",
        "Sd2P~",
        "K&}L;e",
        "n)f5n",
        "dI{]G",
        "4$4,444t4x4",
        "2(2,2024282<2@2H2`2d2|2",
        "VZY 0",
        "`4A#$",
        "Got unexpected pop3-server response",
        "c{xWX",
        "i= 1k",
        "2^x0?",
        "g?`(8",
        "bvgV*",
        "UI_dup_info_string",
        "WTLS curve over a 112 bit prime field",
        " ,s^D",
        "MSVCR90D.dll",
        "E0a2[u",
        "Adding folder '%ls', component '%ls' to the CreateFolder table",
        ":%:2:q:",
        "flH0e",
        "'#)a,",
        "CRYPTO_get_ex_new_index",
        "InstallState",
        ":.:E:S:v:",
        "b[0xZR&",
        "(]?Np<",
        "<discarded>",
        "ky,WJ",
        "~WhKcF",
        "j0hPu&",
        "yBpn:R",
        "54jlh|",
        "mDI-\\",
        "failed to read file contents from custom action data",
        "8\"C6Z",
        ":,:1:6:T:l:q:v:",
        " C2]%",
        ".?AVdefault_scheduler_exists@Concurrency@@",
        "w\\p@h",
        "W@a3P/",
        "mewCpV",
        "t$ VS",
        "finish failed",
        "'zq4{j",
        "D$Tj@P",
        "OG5)<",
        "(!@\\D`",
        "4UQ[g<E",
        "l38GE",
        ">2>R>r>",
        "<kvu,",
        "PVVj6V",
        "Vfhp68{",
        "d /)p",
        "z$K,E",
        "oXue26f",
        "<Ok4T'",
        "jAYf(",
        "-bDFT",
        ";EMx~",
        "'\\QGR\\3k",
        "&u7[6",
        "FG.XX",
        "Fk&y,",
        "yCW?}",
        "tFtvEU3C",
        ">K?o?",
        "IJ47*B",
        "ddddddddddddddddddddddddCn",
        "7+~:R",
        "thread=%lu, ",
        "StopURLFService_rollback started",
        "~[!:Y",
        "unwrap failure",
        "failed to convert security descriptor string to a valid security descriptor",
        "C8Mng",
        "z^l5;",
        ">j<jPj\\",
        "j@{j_",
        ".\\crypto\\engine\\eng_fat.c",
        "nY_7e",
        "%cE|Q",
        "<z) g&N",
        "o] CI[",
        "Z1Iya",
        "yw\\/v",
        "4<FV-\\",
        "x_$h&",
        "'w.81I",
        "eKlw?,o>o",
        "<;u)R",
        "LD Er",
        "5*5c5",
        "nWBS?w",
        "A=;c1",
        "O{ Y`",
        ".?AVbad_typeid@std@@",
        "9.#UK",
        "qT3b ",
        "!2p y",
        "Content-Length",
        "x#bX.t",
        "I7;$G&F",
        "~]Qwb",
        "=+[|ZFXc",
        "f!\\_;",
        "JK[I=)",
        "cp F:8",
        "a{^tw@",
        "<>8\\Ac%",
        "tZfkh0",
        "ZuM<(",
        ".M,Oh",
        "proxy certificates not allowed, please set the appropriate flag",
        "h,laT",
        "InstallPrerequisites",
        "m.N.i",
        "0M1T1f1x1",
        " Debug",
        "3^|Gs",
        "PajUBf",
        "Ev, D",
        ":-:I:e:",
        "9o$t!",
        "2]]Z*Y",
        "X.[)%",
        "-R:$-a",
        "lIWf,kA",
        "K>sy.",
        "1m45 ",
        "FI3(<[>*",
        "`ft3oaV4d",
        "=eDeI",
        "C}:E6",
        "zEv}E",
        "vZFqW'",
        "=1=C=M=o=",
        "u`f0R",
        "{\" CzD",
        "nakIm",
        "kCTNd",
        "CMS_RecipientInfo_kekri_get0_id",
        "w$}q5+@",
        "n|syW",
        "{h[O}YgH",
        "y\"yjy",
        "#rOVb",
        "CANT_READ_VERSION",
        "cs.Y3",
        "Jy5\"Z",
        "UTiEZ",
        "Server key exchange",
        "@$G<aM",
        "hrLmb",
        "LegalTrademarks",
        "jAjnj(",
        "#C%0G",
        "JQ7Je",
        "94989P9`9d9x9|9",
        "Dnnf&",
        "\",*b>",
        "==ZjH",
        "V($g'\\iH",
        "Rv'M7",
        "wZN$a;jOa",
        "X509_ALGORS",
        "upgrade, no need password",
        "VrK\"`",
        "SlNp4vV",
        "C\"G G",
        "=5=Y=",
        "Zp]u^",
        ">0>E>\\>q>",
        "dtls1_send_server_hello",
        "vx;8(",
        "^~0o4&",
        "72R&W",
        "Jqhc(",
        "]fHe9",
        "BiC7}",
        "=Q=m=",
        "9-9G9^9r9",
        "-$LeU`C`6C",
        ";8K(8'",
        ":h):t",
        "%gR>M",
        "6cXBb",
        "failed to get domain for user to configure object",
        "> >$>(>,>",
        "<d=t=y=",
        "i%G.]",
        "2*3M3",
        "aW_7>",
        ";)+%54",
        "GZO=!",
        ".$5Y@}i",
        "f#n\\&6uSVR",
        "=@xR[?OG0",
        "KQ3p1",
        "VPZPOP#&F<",
        "failed to schedule ExecXmlFileRollback for file: %ls",
        "Qs8aA",
        "t`3{J",
        "W<kTm",
        "=]>q>",
        "w!w1wAwQwaw",
        "Gw.EE#G]",
        "\"v9Zw",
        "5/5r5",
        "PACKUSWB",
        "cxfcPH",
        "5Y(zW",
        "XUW;3",
        "abou$b",
        "^cQyd",
        " account. If you do not register the Hardware Product with Check Point, you may be required to present proof of purchase as evidence of your entitlement to warranty service. The Hardware Product\\rquote s identification nu",
        "zH%e$",
        "4DFie",
        "KlbackupFltLoopbackFsctl",
        "z2Z-8",
        "f1,T4",
        " g\\/_",
        "=)8[EeP#",
        "l$ V3",
        "only TLS 1.2 allowed in Suite B mode",
        "uVA/LJ",
        "GDbE-",
        ";+;`;",
        "5 5(5?5u5",
        "8;J|/",
        "6]05un",
        "_@]M,",
        "N:L`Z T",
        "x74fX",
        "~NXEC",
        "z%n[.W",
        "7@8D8H8L8P8",
        "_`NzQ",
        "MV#':]F",
        "]hujG",
        "-iaUE",
        ";|'Em",
        "2v#&X",
        ":aR{L",
        "SetSecurityDescriptorSacl",
        "[/cJ{",
        "N@Q^)",
        "'kW,zC",
        "(3ewd",
        "a7e7c0000000360100000b00000000000000000000000000300100005f72656c732f2e72656c73504b01022d00140006000800000021006b799616830000008a",
        "QAxJ`",
        "\\zonelabs\\vsssopro.dll",
        "9$=IK",
        "l$-+_",
        "3*5;5S5:6l6",
        "itZ;M",
        "692uDp",
        "\\nE&6",
        "6Jm!s'pv",
        "c5SB,",
        "zt@,u|",
        "?#?>?C?",
        "bqMUZ",
        "\\[7yW",
        "=#=,===",
        "*U\"mk",
        "aes-256-gcm",
        "random number generation failed",
        "=_=}=",
        "+4!kh",
        "\\ZoneLabs\\av.dll",
        "hL{;$",
        "949M9f9",
        "RemoteProcessMemory::AllocatePageNear(proc=%p hint=%p prot=%d) failed with error=%d",
        "%=neFpN",
        "O~7%`",
        "/PS|Y",
        "<}CI-=",
        "VX^1R&",
        "#r0*J rS",
        "8c(ubM",
        "7!7'7-73797?7E7K7Q7W7",
        "6KyD3'&",
        "0]0n0",
        ";ZqOLk",
        "+kOq[",
        "_h74\"PzMVF",
        "p$qun",
        "4Q7Zo",
        "dx{DC ",
        "<nNB ",
        "Bl%7q;",
        "=\"=-=6=B=I=T=]=~=",
        "ys5W:d",
        "hw^gP",
        "XZ]\\p1",
        "~Lp+d",
        "MY.W0K~9_",
        ">8m[-kZ^[}]",
        "unable to get certs public key",
        "Uninstalling firewall exception2 %ls (%ls)",
        "7#73797V7\\7t7",
        "ch5(k<",
        "JU&3t",
        "lyzE:",
        "zWM&u6FG",
        "BT~Ln",
        "-}\\F\\",
        "PnflMtY",
        "PTYPE.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "InstallShieldSetupForSR",
        "V>@:*",
        "vAWNda",
        "+As@us%",
        ":2~n|P",
        "J[42G",
        "GNAMES_FROM_SECTNAME",
        "i6TRvDg",
        "#9\"^/[",
        "?ixh|",
        "YNv&!3",
        ":K^|2",
        "fips_mode",
        ".\\crypto\\evp\\encode.c",
        "SVWhPAM",
        "UNUSED_10",
        "S|kU'",
        "\"*2Gj",
        "8a\\x1",
        "A;_-8V",
        ".\\crypto\\rand\\rand_win.c",
        "%8hWLZ",
        "gMA4L",
        "+m#vc(",
        "lhash part of OpenSSL 1.0.2h  3 May 2016",
        "klupd_klif_klbg",
        "rBR&3",
        "hl#[;",
        "U+?K!X",
        "Zw]}g",
        "8/dPu9",
        "3dq>)",
        "ICMG3",
        "znps/",
        "7cuIu",
        "Z{:b>",
        ".CRT$XPXA",
        "='><>D>",
        "L7PIqL@",
        "9L*da",
        "X,[9J",
        "4S4g4",
        "/`lu2",
        "]Z`C2",
        "aH{(2",
        "8D|B3",
        "oZ%pb",
        "s_A_4[",
        "1x6|6",
        "9v`c<",
        "$MZs8B",
        "nj1*i",
        "\\Ra+Uk>",
        "DeleteUmsThreadContext",
        "e##F^",
        "4$40484l4t4|4",
        "=(=|=",
        "0ZV`U",
        "!QXD|",
        "XhYPQ",
        "unc$M.",
        "33333333333330",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 Hardware Product or part, to remove all features, parts, options, alterations, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11798905 data}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "eoQ#ot",
        "s/5?\\",
        "<O<V<a<o<v<",
        "vsdrInst.exe",
        "_W[;n",
        "CMS_COPY_CONTENT",
        "7R8c8q8",
        "={]V!q",
        "mY[u\\'",
        "7fxtI}d",
        "4<4b4",
        "Found %s",
        "\\$$UV",
        ";GLtGj",
        "7-\"~\"tE",
        "store",
        "MfPR!",
        "*D]LW",
        "F+B\"M",
        "2gbCA",
        "EnableVistaSDL",
        "]e2= (=d",
        "McAfee ViruScan Pro v7.0 Firewall",
        "Stopped service %s.",
        "4n|\"P",
        "zujS@",
        ".F?Jf",
        "SELECT `WixCloseApplication`, `Target`, `Description`, `Condition`, `Attributes`, `Property`, `TerminateExitCode`, `Timeout` FROM `WixCloseApplication` ORDER BY `Sequence`",
        "qg$ai",
        "C7QBU",
        "a(';s",
        "0E0Z0_0s0x0",
        "{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'07.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li5760\\jclisttab\\tx5760\\lin5760 }",
        "6+757R7c7x7}7",
        "tvc]C",
        "|^hVA",
        "7q7}7",
        "B-mO4",
        "*\"{(73V6Tc",
        "&,(!s",
        "MG eE",
        "Stopped",
        "u0zhDo",
        "not ascii format",
        "$2(2,2024282<2@2D2H2L2P2T2X2\\2`2d2h2t2x2|2",
        "hO\\$r",
        "C:@a}",
        "Failed to get handle to the service '%ls'. Error: %ls",
        " zx9+i",
        "969A9\\9",
        ".?AVCDataMonitor@@",
        "3L1-3",
        "<r=|=",
        "aes-256-cbc-hmac-sha1",
        "Global\\vsutil_dbg",
        "\\p8MY(k\\o",
        "1/x;U",
        ")!3(hv",
        " xXYMA",
        "ajI\"F",
        "\"st/N",
        "\"uO?G",
        "?B)&!9J",
        "bm(Zr#",
        "3RxE#",
        "XmWOE",
        "4 a,,",
        "7%779",
        "}<\"U?",
        "C _^]",
        "0*1|1",
        "%h-!R",
        "\\E&UW",
        ".o-E#",
        "1?1b1",
        "Z/z$V",
        "D~ByC",
        "{|'Np",
        "xb0(I",
        "           ",
        "FLT_INEXACT_RESULT",
        "\\rsid5062964\\rsid5178122\\rsid5186676\\rsid5193394\\rsid5197409\\rsid5197856\\rsid5259060\\rsid5260654\\rsid5337217\\rsid5340423\\rsid5386754\\rsid5453543\\rsid5520961\\rsid5585452\\rsid5649851\\rsid5650206\\rsid5727096\\rsid5854202\\rsid5905555\\rsid5917669\\rsid5930285",
        "english-american",
        "i:~M-",
        "MN@d[",
        "?@M19",
        "AUTHENTICATE %s",
        "ep]]4",
        "{`r4}\\",
        "3T$@3T$P3T$0",
        "a!yaL",
        "Q0VRR",
        "aes-128-xts",
        "resource unavailable try again",
        "kTRT:A",
        "909}9",
        "WD_SignalStartServices",
        ")`EoF",
        "ud_^[",
        "R#u z",
        "|[#p<",
        "$LEb:",
        "Ht6L\"${",
        "[[f?%",
        ";asYM",
        "YYDuQ@",
        "@2Z55@d",
        "o~y,.",
        "=>0<?",
        "t$DVh",
        "<<<}<",
        "Ph8:M",
        "Q-$jg",
        "Ph@9!",
        "]ry()",
        "signingTime",
        "!M1?r1",
        "J;{7X",
        "SOFTWARE\\CheckPoint\\Trac",
        "byE,|W",
        "rG9;V|",
        "SSL certificate revocation reason: %s (%d)",
        "Mu~bp",
        "6h6l6p6t6x6|6",
        "3/484A4J4S4\\4e4n4u4",
        ">#?z?",
        "1Dgpb",
        "5$6,6",
        "`?:ct",
        "Vi0yb6",
        "C%8&&",
        "DO_EC_KEY_PRINT",
        "nan(ind)",
        "5]}dqD+",
        "]r'My",
        "bUqxd",
        "Last-Modified: %s",
        "=F>X>",
        "?JvNN",
        "Rt(V/",
        "3|$$!",
        "|^YEve=P",
        "coordinates out of range",
        "h}4Mf",
        "pwa3a",
        "Ls[[n",
        "failed to add data to rollbackCustomActionData",
        "\\kq~t",
        "LLLLLL3CR~`",
        "8'9X9",
        ".,@uL",
        ":0KX)",
        "SUVWhT",
        "_\\:S.",
        "fKRJkKf%",
        "c9XmX;",
        "1-2^2",
        "2DlG]C",
        "Pk\\cDi",
        "nDA%`",
        "8WC9z",
        "qifMn/Y",
        "^\"{Gc\"",
        "%#ngCFr",
        ")4S4n",
        ">=xPieN",
        "/\\IXB",
        "m!nER",
        "M}gMh",
        "d{\\of",
        "89<9@9D9H9L9P9T9X9\\9`9d9h9l9",
        "D$Dh@M!",
        "ZI`g4",
        "3J6n6",
        "DH$0y",
        "_[fqx8",
        "n*F#o",
        "Zb&YV",
        "%J@9}",
        "694]}X",
        " 8>K'\\",
        "9Rpsm",
        "v,T50",
        "StvWp",
        "debug_malloc",
        "r1SPV",
        "ClPdY",
        "j2Z)_",
        "(#`! ",
        "mb$0Q ",
        ":QB%m",
        "#r{~a]",
        "U2]Te",
        "cuGGr",
        "1` I@h",
        "@B5:z]",
        "ccb8D",
        "10x)X",
        "X\\q! Ax",
        "9)9:9I9i9{9",
        "K\"T.&s",
        "6pGPF",
        ",~F(a",
        ";%?:s",
        "|FYw=",
        "`KV'\\",
        "8'\\ 6",
        "             ",
        "%s, %s, %dK phys RAM (%dK avail), %I64dK free on sys drive, time from boot: %u, tvdebugflags: %08X, tvdebugcategories: \"%s\" = {%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x,%.02x...}, tvdumpflags: %08X, syslocale=%s/%s, userlocale=%s/%s",
        ">1YID",
        "RE2p'c'p",
        "ewqW#kmj",
        "@G~l%i",
        "rvnTL",
        "'\"hGPS",
        "<,<4<@<d<",
        "mY'b-EP",
        "hUvHy",
        "H9#0J",
        "+VVii",
        "*t61{",
        "D$,PW",
        "tG v]",
        "jfj*5W",
        "2;3A3H3O3U3Z3`3f3l3q3w3}3",
        "P)zPe",
        "`6N[x",
        "][_^3",
        "(c) 2003-2022 Copyright Check Point Software Technologies Ltd",
        "Ys~Mx",
        "calling PiReg.exe with %s",
        "U-~y_",
        "!kU1'P",
        "KJxX\\",
        "0&040E0R0X0c0k0q0x0~0",
        "VkL5*",
        ">%BtI",
        "7-7m7",
        "U(Vl0",
        "`P\"1l",
        " \"&ro",
        "|O2/:<",
        "Cw*!1M|",
        "\\Ui>{F",
        "m^3:]f",
        "<kkXd",
        "<^<g<u<",
        "444D4H4X4\\4`4h4",
        "V+7*D;",
        "cQ`rJ",
        "n_jz! ",
        "bqu;M(",
        "d~3~p",
        "2&383w3",
        "Ch;Nu3",
        "n5^rF",
        "666O6h6",
        "oNa*0",
        "dg,mp{",
        "3UlPx2",
        "C\" @J",
        "4*5H5f5",
        "<GS+]z;-",
        "PSHUFHW",
        "jfjkj(",
        "gt7.#M",
        "5?vi^",
        "X,;u@",
        "o5<g\"",
        "-SVeI4",
        "vBm<$",
        "lfVM#N",
        "CANT_FIND_VSPWREQUIRED",
        "&(CVEK@B",
        "V}VuK",
        "Pzz&q",
        "9XF0M",
        "596?6^6",
        "h,1%o",
        "<<<V<w<",
        "OnFreshAfter:  LoadVsocnfigXML",
        "7;|u\\\\",
        "UNk|]",
        "=xU/?",
        "+A,+D$$",
        "PVj@W",
        "V4~/6",
        "Pih<{7O}P&",
        "76BC9",
        "@v;Ug",
        "X509_ATTRIBUTE",
        "kN+\"u",
        "&WR}e",
        "T:\"*G",
        "fg'er",
        "Killing process [PID %d] %s, handle: %x",
        "i/QdC",
        "!b~wX",
        "CryptHashData {} failed {}",
        "{\\flomajor\\f31512\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}{\\flomajor\\f31513\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}{\\flomajor\\f31514\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}",
        "GetThreadTimes",
        "3ex^p",
        "All defective parts, which have been replaced, shall become the property of Check Point. All defective parts that have been repaired shall remain }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3428060 Y}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "B7X!y",
        "5$5,5D5L5\\5d5t5|5",
        "{&-xBb",
        ">lD#\"",
        "od}>E",
        "Failed to send SOCKS4 connect request.",
        "oau6Ue",
        "\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2;\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1;\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2;\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1;",
        "A78IH",
        ".u. 1",
        ">,>8>B>S>]>",
        "!030i0",
        "}-'Ka",
        "XW$njP",
        "?;?W?s?",
        "z2zHxJ",
        "Failed to create %s",
        ":@;I;V;",
        "L$8H;",
        "#I=-$",
        "1*$cW#*zo3h",
        "1)3h3;4p4",
        "gQn;Y",
        "zTV/7",
        "ADH-CAMELLIA128-SHA",
        "5/5p5",
        "id-GostR3410-2001-CryptoPro-XchA-ParamSet",
        "0I-j'",
        "SOCKS5: connection timeout",
        "8jS;YI",
        "1,2f213",
        "G_eHbav",
        "&5Th+",
        "!39>W9",
        " 8Kp4",
        "yz[q#",
        "<P?PG{e",
        "ctx->digest->md_size <= EVP_MAX_MD_SIZE",
        "KxFV6?G",
        "El].n",
        ")hd4E",
        "9,929B9H9`9f9v9|9",
        "\\userc.c",
        "~I&)(",
        "zFV;!",
        "pkcs decoding error",
        "Failed to stop DAF service",
        "&`}7Zh",
        ":|$[\"\"",
        "d,kxF",
        "MKB%$",
        "ie||J",
        "l><`r?",
        "`placement delete closure'",
        "B'C$H",
        "0)00060Q0X0x0%2",
        ".F/mu",
        "$A$l*",
        "%}/R`0",
        ".|\"K[",
        "hQ%h5n",
        "4HjX+z",
        "not kek",
        "4K4r4",
        "EZCX_",
        " (T,3",
        "OyjKb",
        "_WW_S",
        "3V3[3`3j3",
        "(T<5E",
        "LOgc!",
        "]`jp}",
        "Fw9CG%",
        ">#B#W<X",
        "f[mrZUh)",
        "tq$HSd",
        "__D?\"",
        "K4C7`",
        "kekid",
        "6 6@6L6T6l6t6|6",
        "R'vn\"",
        "ucts to other systems, equipment or devices (other than those specifically approved by Check Point) without the prior approval of Check Point, or (9) any use that is inconsistent with the user manual supplied with the Hardware Product.}{\\rtlch\\fcs1 ",
        "W^<~b",
        "2\"232H2M2",
        "securitypolicy/osfirewall/rulegroup[@name=\"protbdavreg\"]",
        "t hR^",
        ";-a/9",
        "<U~\\9",
        "0.v7m",
        "< <$<(<,<0<4<<<T<d<h<x<|<",
        "ek|$)",
        " zMM<",
        "3J=,dp",
        "BG?L ",
        "(x5;~",
        "I;kXK",
        "Ki=V7",
        "de%jg",
        "QlP0*",
        "2F{y)5^]V",
        "&Exi,",
        "889k9",
        "PhLM!",
        "LL[Lj",
        "]*MaW",
        "474D4R4\\4{4",
        "y~+^(+g",
        "uXh8el`{",
        "=8CR/",
        "010Q0q0",
        "BNQfGE",
        "WqflN",
        "Kz+JL",
        "L$$SU",
        "/'o~@",
        "X;A|6",
        "~Hy(B",
        "strtol",
        "setct-CredReqTBSX",
        "@skKUY",
        ".C%t{",
        "!N%[bhc",
        "-----END PUBLIC KEY-----",
        "eNULL",
        "K<r<|",
        "SEC_E_MESSAGE_ALTERED",
        " E13)",
        "/hK2A",
        "2$2,2<2",
        "?W~D+",
        ".jpeg",
        "`ZePaS\"",
        "\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 4;\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 4;\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 4;",
        "\"cq#]5",
        "1g>PGyH",
        "]A'j-.",
        ": :$:0:8:<:H:P:T:`:h:l:x:",
        "4gB&1",
        "k*yJS",
        "5z@B)o",
        "3L$X3L$43L$",
        "2,v;qZ",
        "[?w v",
        "A)UN]8VW1",
        "5O5V5",
        "msqV1",
        "cast5-cfb",
        "LgX;-",
        ":7:T:[:b:",
        "&#*,#*,#*,131",
        "dGE]-",
        "GOST2001-NULL-GOST94",
        "s3k)Jjx",
        "\\}jNU4",
        "keep-alive",
        "<5<a<o<",
        "0O1Y1v1",
        "policy mismatch",
        "F7~,\\.",
        "t$,3B",
        ".hiiD",
        "A+K?L",
        "DtvjlzU@",
        "PBsvv",
        "FkVkfk",
        "\"6HV~",
        "Yo+]MR",
        "s`GA1a",
        "YflkDW",
        "@i8w1",
        ">QEdp",
        "SofQ8b",
        ")XFp<C",
        "R|.IN",
        ")sM),",
        "wfPK4",
        "Oakley-EC2N-3",
        "status not yet valid",
        "@\\v>Y",
        "AUTHORITY_KEYID",
        "-}wns_",
        "_!mYe@CN",
        "Bad address",
        "LBLbD",
        "aT(qm",
        ".rIbIY",
        "V]WT#",
        "NPAnO",
        "MG^zBG8O\\zL",
        "142?2L2",
        "PBLENDW",
        "Got an error writing an RTP packet",
        ",@h'H",
        "0C53849295319AD4C9B7E212E4CD9620",
        "t#.*<",
        "g/%L,F",
        "Y|[1_z",
        "?+`C9}G",
        "cpepc_plap64.dll",
        "3l,AR",
        ", not IAC SE!) ",
        "*Ltd}@zt",
        "kuD^.",
        "QQh@_",
        "qt<O4",
        "\\D:0/",
        "95:T:m:",
        ">1>n>",
        "'V6F`q",
        ":#<k<",
        "ygZ60",
        "VersionMax",
        "#Q5ud",
        "%Mux:a",
        "N_vo@",
        "9CvF!",
        "-YFNX",
        "isCw ",
        "pn6A,",
        "gBQ$np",
        "id-mod-crmf",
        "D(2P\\",
        "q]gP+<",
        "Gd'u{w",
        "UHx2TN",
        "i2d_PrivateKey",
        "5[5`5j5r5",
        "X5WZye;lc",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid11555386\\charrsid11555386 1.}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid11555386  }{",
        "g/t\"7x",
        "1/0OY",
        "?!?'?-?3?9???E?K?Q?W?]?c?j?q?~?",
        "w051C1`1",
        "[VSUninstallProduct] unable to shut down vsmon (1)",
        "OTHERNAME",
        "8<E.U",
        "C7$\"?",
        "Vl&&@AO,M]$",
        "S@/R0",
        "5`5e5j5z5",
        "yw2o\\`",
        "*:Q=.",
        "3-3g3",
        "1/1F1M1l1",
        "1%wqI",
        "eUX|2",
        "^Hk<U",
        "2w5rr93",
        "KILIMINIOI",
        "v7<;6",
        "bR,Q~",
        "Got a %03d ftp-server response when 220 was expected",
        "DefPolExtract",
        "y&v+% U",
        "D$hPj",
        "Mail64.reg",
        "J3ub]",
        "%t@cL",
        "U6JOK*i-",
        "CU@GS",
        "X#HZ5VI",
        "?rLcXK",
        "PJ|Mg",
        "mR$OU",
        "1?1[1",
        "[LICENSING] LteCheckRun: NOTICE corrupt key revived",
        "9.Q@b}g.)",
        "|%RSM",
        ";,a8MM%",
        "Qu=LYb",
        ">P>]>",
        "05%<\"",
        "!\"<W\\",
        "Nsy?g0",
        "42mD*",
        "+aDCVt",
        "V4c4v4",
        "4/4H4a4z4",
        "3*3D3I3|3h4x4",
        "]@]w.",
        "a*g5/",
        ":E9Na",
        "|}9dY",
        "#ae`M",
        "1#1*161@1]1d1p1}1",
        "s1lhO",
        "@Kxxi>W",
        "aTl9\"4",
        "Ed6;c",
        "TI%zZ",
        "G6i59",
        "{2)!/",
        "STANDALONE_INSTALLATION",
        "3u~wCc",
        "wTQ_m",
        "oJ9Js",
        "p64CZbr",
        "?PN>zz",
        "`:&kw",
        "$A:D$",
        "D$E,]",
        "&?:F@",
        "7!7%7|7",
        "L[@$h",
        "m*(X/",
        "2)303?3I3c3j3y3",
        "AIANB_",
        "8/9e9t9",
        "fY?Ipr",
        "5ben\"",
        "SSL: couldn't get peer certificate!",
        "x{axg:e",
        "VirtualAlloc",
        "z~8MD",
        "ASN1_item_dup",
        "3&3w3",
        "9$909P9X9`9h9",
        "~%z'2",
        "Bx6d@N",
        "YtHJf",
        "YC8Wr,",
        "R{L}*f",
        "AEi1v0",
        "S S S S L 0",
        "tX8\"<>",
        "zonelabs\\version.xml",
        "fV|_Y",
        "94:;:G:Q:h:o:",
        "WYTGY",
        "FeatureIMSecurity:  Uninstallation of the IMsecurity LSP failed with erro code: szUninstallErrorCode",
        "&)oz4",
        "s&Up\"",
        "\\zonelabs\\zlparser.dll",
        "CheckCurrentUser started.",
        "pbEKey",
        "friendlyName",
        "EWq.i",
        "%,zn[",
        "h$]q6",
        "Jmq<c",
        "x$_^[",
        ">6k1-",
        "TrueVector driver: Driver unload failure: %1. Win32 error: %2",
        "^$|3o",
        ", NULL, MOVEFILE_DELAY_UNTIL_REBOOT)",
        "=1UqkS",
        "8*9y9",
        "U:FS|",
        "T9**W",
        "\\ui#o",
        "2'3Z3",
        "\\|ZT(",
        "PACKSSDW",
        "GtN6(w",
        "rHf;u",
        "api-ms-win-appmodel-runtime-l1-1-1",
        "_a1&5",
        "> t|Ea",
        "D8fw6",
        "wO[\\NCM]^ZZ_D",
        "#|y4[$",
        "GJn!1",
        "2$lclG.3",
        "kSbM$",
        "8ire~Z2$Q",
        "4064686<6@6g6",
        " wJLXe$%",
        "|$LPQh",
        "tNf98tIP",
        "-2(p- ",
        "Xvq@Q",
        "dtX*#",
        "9+Nwo7",
        "@S6kk",
        "vsconfig is empty",
        "4!4&474F4K4h4m4}4",
        "ZC7ef",
        "+G0/(#",
        "\\rsid16474658\\rsid16520414\\rsid16581128\\rsid16600454\\rsid16660190\\rsid16665164\\rsid16671729\\rsid16672110\\rsid16731616}{\\mmathPr\\mmathFont34\\mbrkBin0\\mbrkBinSub0\\msmallFrac0\\mdispDef1\\mlMargin0\\mrMargin0\\mdefJc1\\mwrapIndent1440\\mintLim0\\mnaryLim1}{\\info",
        "MergeCommonBackup handle common backup policy: %ls",
        "DzA #%8o~",
        "Q7j?,",
        "D$,Ph|",
        "ARo(>",
        "8Z$)S",
        "xX\"vqSe",
        "ZX1hy",
        "e6A,N",
        "Connection accepted from server",
        "Yl2Kz#l",
        "G.O;8",
        "`8qI9",
        "IAAw$E",
        "OnMaintAfter",
        "z'd4F",
        "pq/zo",
        "pOV!1",
        ")M}2U",
        ":@:I:",
        "P}O6IN",
        "!9xUiT",
        "@rpUe",
        "?$=;i",
        "3$3g3",
        "^_<(u",
        "G<Qd]7",
        "t3JFv",
        "Z;kW[",
        "BT(Wvx\\",
        "!\"?%N",
        "2by5jD",
        "0J0u0",
        "!fb)@R",
        "8/9c9",
        "e\\;M-",
        "YptFv",
        "PHMINPOSUW",
        "+l /k;",
        "{E~yyF",
        "Q!b5y",
        "I?~z&",
        "D/Ifx",
        "#=J<Z",
        "'[V~[",
        "JQ]y,v!",
        "z$W[O",
        ":AueY",
        "yM[}G",
        "bUWseh?",
        "r}(\"f",
        "[!A.'",
        "Z02=d>n",
        "RESETVPNCHOICE.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "Login denied",
        "ChangeTimerQueueTimer",
        "XQ:pU",
        "1T8vc",
        ",pc5k",
        "<3<H<]<",
        "b&Y^V",
        "5$5(545D5T5X5d5t5 6<6@6X6t6x6",
        "u$VQ;",
        "Upgrading system and copying new files (1 of 7 tasks done)",
        "$?4{Gf",
        "+'+1+3+=+?+K+O+U+i+m+o+{+",
        ">!>A>",
        ",@hw,",
        "?az0!",
        "q>m}4",
        "C]n/x%Y",
        "u:`\"B",
        "SDLEnabled",
        "yNdu*H5",
        "!<L'{",
        "z9DF*",
        "parHB",
        "I~T8=s",
        "D$@PV",
        "1,181@1`1",
        "AR^6[!",
        "JUn756nt",
        "B\"pm{",
        "}Y[^\\",
        "5,UUUUU",
        "j)[f;",
        "N$SzSU",
        "e@M&n",
        "failed to get system directory",
        "aU2e=l",
        "SCApyG",
        "FCMOVB",
        ">E)SKS",
        ".?AVUMSThreadVirtualProcessor@details@Concurrency@@",
        "-Msvf",
        "L$83t$43t$T",
        "-`Gr@",
        "^gi$m:",
        "657%<E",
        ")#8tu",
        "PSK-AES128-CBC-SHA",
        ".\\crypto\\asn1\\ameth_lib.c",
        ";%{QC=",
        "HeapAlloc",
        "Failed to get string from record",
        "Wi-xqB",
        ":';6;K;v;",
        "d%Oc4w",
        "?vPH&&&",
        ">l?p?x?",
        "{)I`L",
        "SMALL ",
        "=)R8'rC",
        "&Ac9c",
        "FwmNG",
        "eVnV2",
        ":a'0_",
        ".Og9#v",
        "=V=[=`=e=m=",
        "-f1~RHV",
        "Ow0pw",
        "failed to write 64-bit file indicator to custom action data",
        "2 202D2X2\\2l2p2|2",
        "h?-w+",
        "[6<,]",
        "CryptHashData",
        "54*Yy",
        "c%hdS,",
        "Zuk\\[^",
        "*<T|C",
        "9]+g ",
        "V=ax)(",
        "o}'UlB",
        "<9<U<q<",
        "XcZGhe,i",
        "=U,}d",
        "Uvu71",
        "g ?Gp",
        "$)TJf",
        "1!1(101C1b1u1{1",
        "1fF9M",
        "%~:pBk",
        "|fu0{",
        "J:xrG",
        "VhHbL",
        ":%@&!t",
        "5E+e-B",
        "t$8WW",
        "2mI''",
        "tZhXwL",
        "8NqN_",
        "XdP~-",
        "R^hvs",
        "),:L6",
        "err ec lib",
        "KERNEL32",
        "4GcnM",
        ".fYUG",
        "c c!13",
        "t}h<8",
        ")07RP",
        "vj*EE",
        "z183b",
        "CmH<&R",
        "1@FYw",
        "WIX_SUITE_MEDIACENTER",
        "`\"4e$z",
        "c)Na\\J",
        "Self protection - no driver",
        "L|;=k",
        ">$>D>P>X>",
        "ukuqul",
        "u?;t$,toV",
        "1F\"e0",
        "Em|(dA",
        ".(fef",
        ";\";=;v;",
        "9 9V9",
        "hN7M>",
        "XVVV3",
        "505:5D5N5f5p5z5",
        "d]2Y ",
        "i\"ZTV",
        "}^c\\aF",
        "yjfR\" p",
        "e./rD",
        "no default digest",
        "aes-192-cfb1",
        "bKgzkm",
        "\\dpinst.exe\" /U \"",
        ".\\crypto\\rsa\\rsa_saos.c",
        "w+f.Ml",
        "m@m@m@",
        "5M|*d",
        "4l6&Bu",
        "`XB%no\"",
        "XpFAS",
        "Y6(S|",
        "bad value",
        "BY_FILE_CTRL",
        "sv6|M",
        "7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0",
        "2\"2-2",
        "0R1b1v1",
        "^NmD,a",
        "*:tqm",
        "dvLKEX",
        "ESO|w",
        "item != NULL",
        "mR#bt",
        "lUpgradeMode",
        "-3pf*$",
        "+1s4GQV",
        "Ylaqi",
        "jwnLu",
        "MiAx,",
        "]rdZO^",
        "^We^P",
        ";:;l;",
        ":X;~;",
        "Oxhx_",
        "nSJ4_",
        ")zCQ\\",
        "Error %d creating/opening debug log file",
        "abYmXB",
        "cA<rN",
        "7]-sR",
        "O6(Hx_",
        ":C:X:!;>;o;};",
        "Zc\"*nX;",
        "Failed to send message id: %u, error: 0x%x",
        "eRdJ!!",
        "AecqR",
        "]^m]J",
        "suNoV",
        "CloseApps.cpp",
        "5DX^u",
        "T4Uow",
        "I}O\\%",
        "D$4PhL:!",
        "w,!TQ",
        "?./Ac",
        "Y:}]W",
        ".\\crypto\\x509v3\\v3_purp.c",
        "PDY>K",
        "4dHEl",
        "D$ VP",
        "Failed to fix DNS security issue",
        "/g#7[1",
        "7*919r9",
        "`[SD)",
        "8+L.Z",
        "P7.e,+",
        "J]7(N",
        "}s\"mf",
        "a5-iX",
        ":aB@@",
        "6Ojyq{",
        "dLE+2",
        "\\Zonelabs\\epklib.sys",
        "feYe2u",
        "8 8(80888",
        "3%3X3e3",
        "(aXK<",
        "5^W>1",
        "Done waiting for URLF Service to stop",
        "v `-ns0r|",
        "a`a,nPB",
        "p@eg;",
        "deOGStSL",
        "Nnjve",
        "I&^\"G",
        "ug?_}",
        "8Fs49<8",
        "u@ZHx",
        "=7}bW",
        "my\\w|",
        "s0q]^",
        "a`Ar]\"",
        "IZN?b",
        "IoLr;A",
        "3U&Z:",
        "222V2e2",
        "american",
        "7 7A7M7R7]7i7",
        "SOCKS5: server resolving disabled for hostnames of length > 255 [actual len=%zu]",
        "5)5A5Q5W5\\5s5x5",
        "ox>d1",
        "m7)P/",
        "_&]L_y",
        "l0vpK_6",
        "\\&2Li",
        "7_TNq",
        "xyhnk",
        "?jb_O",
        "f%'xaT",
        "MkAmZ",
        "p4F-n&",
        "v#>so",
        "D$PSP",
        "<I]MD",
        "`Id`g9",
        "Pe_t7",
        ")8rjA",
        "etRD)#",
        "t1(==d",
        "3,3k3",
        "=wCQalC",
        "D:jh'",
        "768Z8",
        "ar-BH",
        "+1_Oj3",
        "uuUS]",
        "es-BO",
        "VUyO3",
        "?3?Z?a?h?",
        "#kl&.yL",
        "api_ms_win_crt_environment_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        ":>HG.",
        " .fE<",
        "rc2-64-cbc",
        "Outercurve Foundation",
        "5)7^7",
        "snge7",
        "(Qf%V",
        "j55_j55_",
        "Zj<=_",
        "p<NpDI",
        "Touvl",
        "kp?cW",
        ":T?!R",
        "]97$S",
        "IND)ind)",
        "6vteN",
        "D'7$F7l",
        "9]Sw:",
        "MEM_WRITE",
        "SPPP+",
        "=~9S8Re",
        "&-]kg",
        "h#Bo@=",
        "_nQXP",
        "_*3r~",
        "SSL_set_fd",
        "=dX?_",
        "O#3N2",
        "W}Sbe{",
        "?)!u(",
        "Vh|.U",
        "y5xK+",
        "n@mgF:",
        "z_kZ($",
        "~O2N^",
        "zcUaA",
        "jdjrj#",
        "=*3Kb",
        "9>:j:",
        "EIt/<",
        "{VFVLVXU\\",
        "OU:L,",
        "055cF",
        "I1^ES3",
        "Last-Modified:",
        "D1P1Z1d1h1n1r1x1~1",
        "d.directoryName",
        "[y@)w",
        "4}-vx",
        "n.1ruN+",
        "]vxqf!",
        "t$0VPS",
        "@_1HLLe",
        "<,#&i",
        "%(%4%<%D%",
        "[HEX DUMP]:",
        "q*I6P",
        "_Mvi;",
        "?MBc[",
        "zQs!z",
        "SsSDA7",
        "989C9Q9c9",
        "]u~{U",
        "kr`5R",
        "H^O1zc",
        "=9>c>",
        "SEC_E_WRONG_CREDENTIAL_HANDLE",
        ")!.zB#",
        ".?AV?$holder@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@any@boost@@",
        "owCt8",
        "mWy2A",
        "\".$x/k",
        "SpcLink",
        "9F:T:",
        "4hMo?.c*",
        "$6zt4\\5",
        "secp192k1",
        "B:'4W",
        "-]A-s",
        "=N*_-K",
        "To1+sm>h",
        "x-V,@.}",
        "XlE*|",
        "|\\QUd'",
        "UP\\O!",
        "sBtRt",
        ">$>G>",
        "77H]_Xcas",
        "9\"<g<J'",
        ")>L\"%",
        "@~d-@L",
        "Hn4xE",
        "~P)HX$",
        "ENGINE_get_pkey_meth",
        "@Re8$4",
        "yDVh@/",
        "MlMV{",
        "Af)dDD",
        "\\(#t}J",
        "R/~fYuuy",
        "|^uo_25",
        "3(3,3@3D3T3\\3p3t3",
        "7/7<7A7g7l7",
        "GOST01",
        "435H5[5f5",
        "|Cm j",
        "z553i",
        "I\"I\"I",
        "                value=\"%s\"",
        "invalid number",
        "Ql&dK1",
        "o8*BD",
        "u.m2%",
        "eoU.V",
        ">>Uga",
        "DiN4N",
        "SMIME_text",
        "z<(qp",
        "c\"qWdIH",
        "fJqf'",
        "'qay`I",
        "9B9_9",
        "W?Ku{",
        "~^5T+P",
        "`;%4|",
        "_;e n",
        "q:G X/",
        "(`=:J;]{",
        "uRu'5",
        "uU8D$",
        ")S+yD4",
        "K=(Ma7k",
        "uTVWhCb",
        "WaitForSingleObject returned: %d, error %d",
        "131?1h1",
        "@.Zcj",
        "7N8i8}8)9D9@:",
        "PRKK-J",
        "2'292G2M2",
        "vi-vn",
        "J<$S9",
        "|mF\\x",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1132737\\charrsid1132737 1.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "-\"&,/z",
        "TVFD6",
        "'tI(3M",
        "VPNTYPE",
        ".?AVstl_condition_variable_win7@details@Concurrency@@",
        "u.HZ8v,+",
        "]0;?l$<D#",
        "B QOs",
        "FqYK5k",
        ":g/^e",
        "A#NyH~",
        ":F27a",
        "f8C'k",
        "x:ki/",
        "4ik5?",
        "C]npG7",
        "MOi]vp]_",
        "Failed to clear the command channel (CCC)",
        "&u}~i",
        "RC2(128)",
        "j95ha",
        "5Hh_;7",
        "CZcz5",
        "u&:(N",
        "49#k(",
        "5qe%Q",
        "hYYMQ",
        "2B.B7F",
        "GetWindowsFirewallStatus",
        "LwH'1",
        "d4}C;",
        "jXtER",
        "JT W|",
        "ripemd",
        "All right, title, and interest in and to the Product shall remain with Check Point and its licensors. The Product is protected under international copyright, trademark and trade secret and patent laws. The license granted herein does not constitute a sale",
        "VX5:Xa",
        "E3{T+",
        "6*f(_",
        "GBI0O",
        "4(<dPi",
        ";Aq3\"y/",
        "5$6(6X6\\6",
        "?~'9 ",
        "1<Ak]k?",
        "*!r $!",
        "Qmm*n",
        "-i;#r",
        "attempt to reuse session in different context",
        "X6bmo^",
        "[VSSHUTDN] SetProtectionByPassword",
        "Pv-Lg=",
        "'y(:4x",
        "d~D\"I0",
        " 2L,FF\")",
        "D%\"/Qz",
        "i_7D^",
        "@Z5{|",
        "dLc8U*",
        "6 6-6M6W6q6",
        "=0t0x0|0",
        "E6dZl|Cx",
        "P%ekU",
        "797a7",
        ";E<P<",
        "LQJtc",
        "zD.Rp",
        "=!G&c}",
        "BT1U`",
        "L-dT\\TAaD",
        ";}>?Dtq 0",
        "B64_WRITE_ASN1",
        "U%hTo",
        "=1=:=F=T=[=v={=",
        "[-%NZ",
        "H@$wDZ,",
        "MHahA",
        "/V}dIrH",
        "\"_I0D",
        "IgC<n",
        "~hc@`",
        "llv2m`z",
        "/wv'Q",
        "M88zNb",
        "BDJBS",
        "EC_POINT_set_affine_coordinates_GF2m",
        "D$Dj0P",
        "AISqgR",
        "_ADO3",
        "+Z(rg",
        "(.:mW}V",
        "\") y3",
        "lG=`m",
        "8C9a9",
        "S8Ni>9",
        "PVVVj",
        "C<o&o",
        "8ja.D",
        "L?>HJ",
        "I&sV4E&",
        "wxRc~",
        "H8mJA",
        "6;P\"g4]",
        "j\\I@E",
        "1j)Gj",
        "bpo?O6",
        "0HinX",
        "$]I)LqFa",
        "9.K%4",
        "tEHr(",
        "o\"s4smq",
        "`-=\",",
        "4B1806C5-FA74-4271-AA40-A0610B93D4C9",
        "n/G )",
        ",)goAp(F",
        "pL:r2",
        "cIzs*",
        "18Ttgd",
        "aiID<",
        "uZlN7@",
        "Jf\"#d",
        "|*_<P",
        "YCAd]",
        "SEC_E_UNKNOWN_CREDENTIALS",
        "4I3VW",
        "`*LtT",
        "])C3]",
        "t^t,y&Vr.",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\pwd.cpp",
        "|&:vr",
        "RLTcX",
        "h(M`#",
        "9!:*:0;8;j;r;",
        "|:2Lr",
        "sIxe|",
        "FDE_Rollback end.",
        "9&919A9_9v9~9",
        "!oEK#",
        "A~!,%x-!",
        "failed to parse record field: %u as number: %ls",
        "S3NQN",
        "g\"pk6+TC",
        ")X+>h",
        "6g<hr",
        "idl$]",
        "X509_SIG",
        "+I4vf",
        "465E5f6u6",
        ";KN4Q|",
        "#!)A7g",
        "=6=T=X=\\=`=d=h=l=p=t=",
        "Unknown secure object type: %d",
        "_(MRn",
        "<,<T<x<",
        "_l1u`",
        "i_)It",
        "ExternalExtractedFiles.txt",
        "699640f6719e76b7d6ac355c7c89feca9cccad4ea7d36c65b258a206641f1b73f8b5da6a6373d9c11b90c537e7f08dce66b7bbeae00dc8e257e7f0fd2badd586",
        "1P^ar",
        "O}+ep",
        "H[HwL,=",
        "D/|_2",
        "{15}%",
        "abE9)",
        "Fv+~c",
        "s~aT9",
        "h(fDU",
        "hgn^Z",
        "GMTf|",
        "x0cq'",
        "aOiOA$",
        "yt[Zf@",
        "+GL+OL;",
        "%f!f^",
        "Zs5S5",
        "M*HpXH^/",
        ")\"/B:",
        "t$(PVW",
        "(3Z;)<",
        "y2,&J",
        "w=`^>",
        "9\\O<-",
        "`??i+=",
        "2B4^5",
        "|)3{(",
        "G%#z>",
        "B8.)Em",
        "'IcKK[L$",
        "l\\<N:V",
        "0y&TP",
        "AppPolicyGetShowDeveloperDiagnostic",
        "1H1R1a1n1",
        ".4^xn",
        "pA|\\1",
        "FP[8nB",
        "ALv~q)",
        "_9J3|",
        "aba]bL",
        "wF+qO4",
        "F>Xgx",
        "p}nuN",
        "KjT\\t",
        "8+9U9v9",
        "FGf?RU",
        "a[#aum",
        "<:1'O",
        "hIr,@",
        "gn&wP%",
        "L##fj$",
        "&l)rH1\"",
        "=S=z=",
        "AZ36M",
        "Xy}:B",
        "g.8,+",
        "Xhz/s>",
        "INVALID",
        "M01%~",
        "%u %s %X + %X",
        "(W'BEy",
        "868L8b8t8",
        "*YwdKKb",
        "}|Y~K*",
        "-WV+lD,",
        "x^L-yD",
        "\\$ UP",
        "p:)aa",
        "98;%7p",
        "PSqp|",
        "LomK'",
        "X\"R]5",
        "oVGM/7",
        "u(w1v",
        "8M8O8Rp(p",
        "F@U0A",
        "2@S]\\2",
        ";!;A;Q;r;{;",
        "[4d=,",
        "RH|PF",
        "gch6!",
        "|{{)Y",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1132737 \\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 DEFINITIONS}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "t)M%C",
        "y$,#Df",
        "+?(o9/8R",
        "8]D6ei",
        "Ps_6|",
        "c4? lEK",
        "PVWQSh(",
        "0 0@0H0P0X0`0l0",
        "gsjhV",
        "1\"1*101A1G1L1a1g1l1",
        "Y]=0J",
        "FY_&[",
        "6yW`l",
        "=2>u>",
        "o^;]x",
        "!2\\&K|",
        "W}/7.t",
        "k}DHM",
        "{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703\\'02\\'06.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li5040\\jclisttab\\tx5040\\lin5040 }",
        "it.it",
        "0[0b0i0p0",
        "1 1(1,14181<1D1H1P1T1X1`1d1h1l1p1t1x1|1",
        "tcYSL",
        "M4[iB",
        "fB:IG",
        "< <D<L<T<\\<d<l<t<|<",
        "'{T>j",
        "PreInstallCheck:  ADDFW is not 'YES': Will not check for Other FW installed.",
        "DUwJU",
        "cKIjn",
        "9*-k;J",
        ",Ye-L^H",
        "SMTP.",
        "N@52<q5",
        "mWy^m",
        " Wc.%!",
        "k bT@",
        "4'5r5",
        "4j5x5",
        "]Yl/(",
        "D+syp",
        "I-{nq",
        "illegal nested tagging",
        "22282>2I2O2U2",
        "{E>_4",
        "8(8m8",
        "S_$\\'",
        "TCTCY",
        "G0h*O",
        "p.tpBasis",
        "J#Idh",
        "vqcV{",
        ";]J4/",
        "' $@w",
        "s8J1l",
        "\\B z!\\",
        "6@vW&W",
        "f9zf`%t",
        "No2~|",
        "d&G}3",
        "&4&6]0b",
        "15J\\Kf",
        "O+?\"O",
        "FtJnEI",
        "FL8W^",
        "0o_@c",
        ">/:9}",
        "Failed to create a temporary directory %s (rc=%d)",
        "EnableDisableXPSDL",
        " THE POSSIBILITY OF SUCH DAMAGES, FOR: (i) ANY PUNITIVE, INCIDENTAL OR CONSEQUENTIAL DAMAGES OR LOST DATA OR LOST PROFITS; OR (ii) FOR COSTS OF PROCUREMENT OF SUBSTITUTE GOODS, TECHNOLOGY OR SERVICES; OR (iii) FOR ANY CLAIMS BASED ON ANY ERROR, DEFECT OR ",
        " !BJB",
        "<v<,=V=",
        "*9?)5",
        "E}$]j2",
        "B_<hg_",
        "l}mU)",
        "\"9t+Y",
        "}Op6I",
        "fjkjm",
        "MsiViewExecute failed",
        "failed to get target path of object '%ls' in order to schedule rollback",
        "pkcs8ShroudedKeyBag",
        "#4-p,",
        "x Q5Y8",
        "VMY%o",
        "Q7|p?",
        "}\\}=SxkKEQ",
        "?%^[f",
        "\\ZoneLabs\\vsdatant.inf",
        "303K3f3",
        "H7M*a9",
        "\" F\\n",
        "1S1r1",
        "RBUnl'",
        "]:k'*8i",
        "9(909K9^9f9",
        "GKy:k",
        "@X1cDD",
        "_*&_QT",
        "AgbIo",
        "4,565;5U5",
        ";\"Mw|",
        "Failed in OpenService. Error: %d",
        "6dldf",
        "j'|~zXF",
        "%*sPolicy Language: ",
        "0&131",
        "l@|+i",
        "(YrVnv=",
        ">,>N>",
        "<3=Y=|=",
        "Al$>B",
        "8!8K8Y8g8l8x8",
        "0 0*0/0O0",
        "_R-%E",
        ":T09(",
        "WixRollbackInternetShortcuts",
        "o,j-Ek(",
        "?b0J8&",
        "!db;c2",
        "ay%ncZ",
        "7#:pNb4",
        "339ci",
        "N-J@Xr",
        "PSIGNW",
        "[WinFW] SetWindowsFirewallStatus(): Calling SetWFStatusVista()",
        "pBZ))aEv=1a5",
        "FXSAVE",
        "XXAbDRP",
        "xk+\"%GX",
        "c|\"dV",
        "rmp7tH",
        "`^'\\Oc",
        "b VB]",
        ">!>h>q?",
        "7I7a7i7y7",
        ".?AVfacet@locale@std@@",
        "VvwWN",
        "\\$LUVW",
        "i],{K",
        ", error ",
        "Z>\"5;",
        "`d&#c",
        "$eNsF",
        "Q@>N+z",
        "KKFM/",
        "687<7@7D7H7L7P7T7X7\\7`7d7h7l7p7t7x7|7",
        "@-,KBX6",
        "X@w/2",
        "262Y2",
        "v.u?_",
        "u_m_^",
        "6i%iG",
        "33e7t75m7rq3eu7t580ukea0jk0",
        "VUvZJ",
        "GCcC,'",
        "ebad)",
        "kEqim",
        "E.?Hr",
        "@/pMa",
        "kAnjs2",
        "** Resuming transfer from byte position %I64d",
        "=0=P=l=",
        "/no$Hx5M",
        "=~W+Vo",
        "00080@0H0\\0d0x0",
        "6kuX+]",
        "`WK|&z0!",
        "{TV\\B",
        "y%rt}CL",
        "?G4C8",
        ",\",)<",
        "X509 CERTIFICATE",
        ":C:b:",
        "NJc5t",
        "ua9C$",
        "K&vIlI0 ",
        "`7tHz*",
        "9\":C:e:",
        "I\\\\\\C@f",
        "QueryPerformanceCounter",
        "d97`_",
        "bPasswordsOK",
        "VeriSign Trust Network1:08",
        "U5!<_3+",
        " bkZ+",
        "%u)*s,",
        "|pP\".",
        "SJ:Q_",
        "7I8[8h8w8",
        "ovrJ2f",
        "3,4>T#",
        ".8qDa",
        "6ggs9",
        "9os#d[",
        "'|]=z",
        "v|YJ*",
        "+|TfY",
        "s'm S",
        "%zE-u",
        "p2R&,",
        "rfyHo2",
        "r%U!^",
        "'5p;ajt'K",
        "ah^Ylk",
        "sOARecord",
        "p\"+=YD",
        "Ms]Eq",
        "7vB_E",
        "partyName",
        "z;e L*I",
        "short line",
        "l1?U:",
        "BSMJS7A",
        "Updating insthelper.exe in column ",
        "[VSDATA LOAD] AllocateAndInitializeSid failed: %d",
        "6(6=6[6|6",
        "Abfk]",
        "v!),_",
        "]:7=O",
        "7Tjm_",
        "f%HhT",
        "#v.-Ed",
        "unknown padding type",
        "0IDvO",
        "W*1uv|",
        ":';2;U;`;",
        "46tF\"",
        "p:v&j6",
        "|1,bU",
        "Continue",
        "=\">F>U>",
        "'yR!Ir",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "BN lib",
        "EPAM_Install started.",
        ",_{mRu8",
        "YtbX\"",
        "4A5t5",
        "mwKD0",
        "0gS[b",
        "Installer\\Products\\117CD7D3CB2C542438D083C010944001",
        "LWQtW",
        "0 0'0.0N0]0g0t0~0",
        "Ym-oN",
        "L\\& %",
        "1 2>2y2",
        "w_Rp7",
        "=%=@=L=]=f=",
        "64\\ccore64_ds.sys",
        "7~\\:_2",
        "8T$,u",
        "A=K=C",
        ";u\"-X",
        " 0xe8",
        " hgs7",
        "a.x\";A",
        "*d|j!",
        "#HA {+T+",
        "2[Sd\"",
        "54686<6@6D6H6L6P6",
        "M'YL.",
        "Exception caught: bad_lexical_cast",
        ";1=h=o=t=x=|=",
        "z/'HZp",
        "% %,%4%<%D{y",
        "+TRt%tU",
        "5nl)~(",
        "CONNECT",
        "mkdg*",
        "S`dV>xD",
        "C3g?M'",
        "@BTe+]",
        "<7<K<k<",
        ">0\"m@;",
        "TDI_MODE_NOT_SET",
        "N?'-cB",
        "SYanbp",
        ".Z~L?",
        "V?9$vV8",
        "}2c pnaz",
        "GT>nv",
        "GPN{,",
        "Q&RLF",
        "cfj[#hdxJ1",
        "auth=Bearer %s",
        "lq/bX",
        "DH-RSA-AES128-SHA256",
        "\" to readonly.",
        "WriteSuccessReg:  Successfully installed ",
        "Ebq7[",
        "U)!W\\",
        "i],|s",
        "8IY6(?+",
        "tLl5'>",
        "[4o=3&,",
        "5840{",
        "2%3.3",
        "M./0f",
        "=nar: ",
        "sC'bd",
        "iFWK>`",
        "ym?=U=e",
        "aes-128-cbc-hmac-sha1",
        "p;x_h",
        ">$q;'",
        "8\"9c9",
        "Camellia(256)",
        "kj3fg",
        "@!ML>v",
        "!F02j",
        "=!Nk)",
        "Operation not supported",
        "secure",
        "content type not data",
        "1.z<A",
        "RJ&kw",
        ".WixCaMessageWindow",
        "=PF'3",
        "Pm?/[u}Y",
        "Nh*m!",
        "n}(S)",
        "tls1_prf",
        ",.Y<Y>Y@YBYDYGY",
        "t:j@j%V",
        "?!?>?b?",
        "`=X;Up",
        "`C!u!",
        "*rN\"@",
        "fWUV4",
        "3FU$`",
        ":VVD&",
        "3h~RJ;",
        "[f\\=F",
        "<,<8<X<d<",
        "9w:,)",
        "*FRqt{;",
        "Y>;'0",
        "[v;IwX",
        "96<;<M<k<",
        "&_0h$X0Y?",
        "b&V:>6",
        "EC_POINT_point2oct",
        "/UrY@",
        "d:!l>f:8z",
        "L^WofD",
        "j Pj ",
        "zJM~{p",
        "8t-U4",
        "EC_GFP_SIMPLE_POINT_SET_AFFINE_COORDINATES_GFP",
        "lP(}h#",
        "iO{Nq`",
        "r8'$m",
        "Tf3kq",
        "xk1UO>",
        "!SESJ",
        "4,575K5[5r5",
        "/Ck+WM",
        "CryptGetHashParam for hash failed {}",
        "joK,o",
        "||n&K",
        "\\/}L#",
        "gF{F>",
        "2|.5'",
        "/ISo*",
        "(ysfjd+wY",
        "?+Q!'Y",
        "^ '>Q",
        "0 0(0,080@0D0P0X0\\0h0p0t0",
        "&FP9j",
        "\\jU:5",
        "Got a %03d response code instead of the assumed 200",
        "-&w\"AJ",
        "J\\n}P",
        "5P1;e(j>",
        "*1o+%",
        ".)r_a",
        "3]5a5e5i5m5q5u5y5*6",
        "6 6H6l6x6",
        "Lu.xf",
        "J/7D;",
        "  x6)o",
        "^Fwpg",
        "3&313:3J3U3^3w3",
        "Extracting support files",
        "TLSv1.0",
        "h~I8c",
        "1[x!d",
        "=6bYG4",
        "gHRnQS",
        "}/BxL",
        "1-Vl(Y",
        "9Q]#Vkos;x",
        "D$ USVP",
        "O[KJO",
        "]oYGt",
        "engines",
        "b)~-M",
        "<7<i<p<t<x<|<",
        "bad sig_pkcs7",
        "?Wb0V@",
        "_v1t>",
        "0$0,0@0T0X0h0l0x0",
        "id-id",
        "@wS<h",
        "360428235959Z0i1",
        "kj<L*oE",
        "%i~-<",
        "=$=(=8=<=H=P=X=d=t=",
        "j-Xf9",
        "=D>H>X>\\>h>x>",
        "6=SsKf",
        "allusersprofile",
        "UNPCKHPS",
        "@_^[]",
        "hYT`=",
        " ;<?t",
        "6,7R7",
        "AO>5o",
        "ab[7C",
        "\\/&:-",
        "iHe;I",
        "b$%iL",
        "OnFreshAfter: ConfigureClient",
        "te/XJ",
        "L$ 9L$Xtr",
        "r7M-P",
        "^p+g]S@R",
        "G;:^*Y",
        "BpLIH",
        "k$dkh",
        " 0x69",
        "3yrCLy5",
        "U.C6N2",
        "\"kWVV+P",
        "dF_c^",
        "[~6@~",
        "R6024",
        "J\"+:h",
        "g~67l02",
        "PEM_write_bio",
        "^EJ0#",
        "2<2p2",
        "5B6K6P6c6r6",
        ":CnC2#z",
        "tafpv",
        "whnSi",
        "}CH?\\",
        "],%|:n",
        "@\\7NP",
        "[R14D",
        "=gzeB",
        "Lw4|\\",
        "'cV;RN",
        "J9AT`",
        "LOCALAPPDATA",
        "XsS>q",
        "3k<js?gL1",
        "[E!{EN",
        "C:sKd",
        "U_Uw ",
        "Sl Xj",
        "5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C",
        "SPC_NESTED_SIGNATURE_OBJID creation failed ",
        "b'*S~",
        ")9,TYl",
        "-g|I@iP",
        "IWetjr",
        "}F){Z4",
        ".?AVError@WinHooks@@",
        "ay:-m",
        "uT\\Yhn",
        ":G[\"QH",
        ".3cdSF(",
        "UZ$Uy",
        ")X3T?",
        "AaSuA@",
        "he1J@",
        "8M)qN",
        " ez`H",
        ">a>E?{?",
        "0L1 0",
        "-+6?6]",
        "?b20Y",
        "0(080D0d0p0",
        "V](rB",
        "Y%Y%Y%Y%Y%Y%",
        "8?`P&rG_0",
        "ZtabN*",
        "gEbnY",
        "#b>z0y;",
        "Proxy CONNECT aborted due to select/poll error",
        "2L2l2r2",
        "-%~FY",
        "ECDSA-Parameters",
        "$I%*{F",
        "s!d$xxD",
        "/jZ\"K<",
        "#/+;)*|",
        ":#:6:I:n:",
        "yx'#w",
        "VVmqa=jyE",
        "SRHb i",
        ">MY3v",
        ",42iZ",
        "6bl!i",
        "jjZf;",
        "ciO3?",
        "protectionOff",
        "=M>U>",
        "-/M{}",
        "yb:>O]",
        "><UvN",
        "K ProgramData",
        "SEC_E_INCOMPLETE_MESSAGE",
        "Y(V1j",
        "L$L3L$",
        "!\\?El",
        "privateKey",
        "Z@ny:",
        "D0ja1E>",
        "O%n^?q",
        "failed to add app to the authorized apps list",
        "|LbIs",
        "=\"=>=Z=v=",
        "%`EGK",
        "7)7A7F7L7S7X7a7f7l7s7x7",
        "Pnf'L",
        "WTk^e",
        ":+>_>",
        "o5a;Z",
        "N0`Z!",
        "Discovery VPN upgrade product code is not found in the registry",
        "HTML\" \"",
        "tEc:<L",
        "xL&\\Z",
        "=B{~n",
        "QiP_F",
        "17G}q",
        "v~.TcY",
        "$$$bb",
        "id-cmc-confirmCertAcceptance",
        "6H:z[",
        "SSL crypto engine not found",
        "SECG curve over a 256 bit prime field",
        "D$lPj",
        "FHPSV",
        "7=SrP",
        "^rdtY",
        "F-t<*",
        "yj~4+",
        "{qTBU",
        "P\"PbW",
        " 20+Q",
        "ADH-RC4-MD5",
        "cyM4i",
        ",Ec.r]",
        "bbJZ,",
        "not supported",
        "h[hFK",
        "WD_StopService.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "Vjxhx",
        "fs]/r",
        "SetOverrideDisconnectedUponUpgrade",
        "dXkFN",
        "5f6x6\"748s8",
        "aDXMRM",
        "unsupported prf",
        "reset= 0 actions= /",
        "l-6wu",
        "4lz`H",
        "bR3')",
        "dZpv(",
        "yYRN(0",
        "_lcID",
        "PK|dt",
        "DependOnGroup",
        "Xg(r|",
        "IRT8o",
        "FBSTP",
        "a3\\h7",
        " #3=rn",
        "*eqiT",
        ".bAuo",
        "P-)r~",
        "zFHM(",
        "DigiCert Inc1",
        "*X=j]$",
        "v[(.[",
        "qqb,1_H",
        " .Kcc",
        "xGF~-",
        "6$6,646<6D6L6T6\\6d6p6",
        "V[`{d",
        "o^r_L",
        "V.jx_f;",
        "SDk{y",
        "am/pm",
        "sZk(X",
        "8e*c_",
        "4$4,444@4h4",
        "\"|V$X",
        "uMqoB",
        "DH]0Q",
        "{k]JmB",
        "&w3w3x",
        "]#)fG~",
        "eX\"u6BGoB",
        "missing equal sign",
        "Fl+Fp=",
        "MonitorSetCharValue",
        "]?4uA^",
        ":Q:r<",
        "w*qUxD}",
        "\"VSTr:",
        "2'222B2m2",
        "+[s<G",
        "C!XbZ",
        "XEo~=",
        "QdQ$QdQ",
        "Htd:R",
        "^++`}",
        "/8v[5",
        "gK;Fa.",
        "tMkW:",
        "c#;q#E",
        "4C5,6K6e6",
        "u?vR#",
        "k\"]KZ",
        "*G@Eo",
        "~-J{R",
        "hs=yo",
        "`d`e`f`g",
        "<ctp&h[",
        "digital envelope routines",
        "M3\\M?",
        "&9o04",
        "!0^+aY",
        "z!S\"n",
        "\"kwpcx",
        "privilegeWithdrawn",
        "pES^B",
        "D%RjL",
        "=b{7!",
        "=$'lfbM",
        "l+g@0",
        ":lBatxa~",
        "rvf;U",
        "ECDHE-ECDSA-AES128-GCM-SHA256",
        " 0x2a",
        "wP:X-",
        "_itoa_s",
        "Fqq3L",
        "&F`pY",
        "<$<(<,<0<8<P<`<d<t<x<|<",
        "vQw:\"j",
        "wdda`wwE",
        "6'616>6",
        "xT.UH",
        ".#;AF",
        "maskGenAlgorithm",
        "7'Yg)",
        "E(PX&",
        "jrjuj",
        "ZoneLabs\\vsmon.exe\" -install",
        "=s>{>",
        "7d0Hz",
        "P4$LosB",
        "MINIMIZECLIENT",
        "0!0Y0l0",
        "Ho?\\!p",
        "rw]\\|~",
        "g>,`$",
        "\\4Obk",
        "v.Fc\"",
        "^/~O)",
        "AhP|o",
        "7&858",
        "z@jjm<+",
        "U*'cDp",
        "m\"Nby",
        "A2o+T",
        "4#.rv9N_",
        "l=N7&d",
        ":W&?MN]",
        "l4^,Y",
        "alias",
        "-c~k,N",
        "ZXHt\\",
        "\"/M_O",
        "B/;HM",
        "W#>:}",
        "maximum",
        "$n3K(",
        "m&MtP=",
        "R~IwrK",
        "X2\"_\"Nl",
        "9b#Zye",
        "cK%V18",
        "(u0%7T",
        "C$2\\\"",
        "+/H`3",
        "statusBarRed.png",
        ".gnTW",
        "RSA_verify_PKCS1_PSS_mgf1",
        "L$8UP",
        "oNOa\"",
        "8(9H9V9a9",
        "e^ /'S",
        ". A0|!",
        "8%8S8~8",
        "G F*m",
        "7;!5}",
        "+M$#%y",
        ":3:V:y:",
        "2-2A2`2t2",
        "ME@+K",
        "cYq{Xh",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477 will attempt to diagnose and resolve your problem over the phone or web.  Upon determination of the hardware issue is related to a malfunction of one of the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "Experimental",
        "??B'w39",
        "F3U3w7",
        "Fg*uH",
        "> >$>(>,>0><>@>D>",
        "b\\QDY",
        "4:ZMF",
        "LOGIN %s %s",
        ";$<d<",
        "XMLFILE",
        "#~~nZ",
        "K:KFKPKZ",
        "L_^[]",
        "`NUh!",
        "%$%,%2%:%D%J%T%Z$bJ",
        "MPZaW",
        "pH s+)=",
        " #jFLF",
        "-E~5o&",
        "VhpaL",
        "-{KlY",
        "%Z7   G",
        "n;IoB",
        ";|zf!tT",
        "xV*XK",
        "3B4G4",
        ":3i\\Q",
        "nAH:>n",
        "E/Rt!",
        "n*IvYp",
        "I-|Vp0",
        "PD_>O",
        "D$8tT",
        "=B>W>v>",
        "1$@]y}",
        "z;T<,",
        "gf{}8",
        "_D\"%m,",
        "`A8XeT",
        "cp]q/",
        "en-cb",
        "\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 3;\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 3;\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 3;",
        "lKYf)",
        "EPAM_CleanOldRollback finished.",
        ";44P(",
        "1(1E1b1",
        "<5y \\_",
        "FIPS_CIPHER_CTX_COPY",
        "&2.Dg",
        " P6LD",
        "q U ,",
        "4TsZm&",
        "O<b?|",
        "D7C+Q0",
        "gg2^/",
        "ZQ:XRv",
        "!qSUWv",
        "0%3,ac",
        ">E4&_",
        "EN,,&",
        "0Ui@4@",
        "D$0_^[",
        "5#5(5-575<5O5T5",
        "P~KJruj",
        "50WnV",
        "Configuring SmartDefense settings (3 of 6 tasks done)",
        "ze*H^o",
        "aQ)r&",
        "pz]6@?",
        "#QN\"Pny",
        "K*2/,)",
        "Restore from ",
        "!GaaW",
        "Khb8\"",
        "tASVj",
        "Dy&.g5jM",
        " +aSZ\\",
        "T ~%&",
        "u?9t$",
        "9|$4s\"h",
        "=yQFd",
        "td,)U",
        "k2Z^l",
        "#d?&0",
        "N)ZTR7t",
        "u@S}#m",
        "\\levelnfc23\\levelnfcn23\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\levelspace0\\levelindent0{\\leveltext\\'01\\u-3913 ?;}{\\levelnumbers;}\\f3\\fbias0 \\fi-360\\li360\\jclisttab\\tx360\\lin360 }{\\listname ;}\\listid-119}{\\list\\listtemplateid-1295583608\\listhybrid",
        ">x:%R",
        "y)WoAo 3",
        "6.jtXI",
        "{}-?>z",
        "warning",
        "PWh|e#",
        "Z;{#^J",
        ".t-Fmm}",
        "Pjtj.",
        "vD2``m",
        "zydSQ",
        "_4R}U",
        "B%y%K",
        "fMIM'o",
        "b{,Yj",
        ")i? .",
        "K9L@=C",
        "Wcn,&",
        "aPe_t",
        "I.I&|",
        ")jk1s",
        "CAMELLIA-256-ECB",
        "1,1014181<1@1H1`1p1t1",
        "^KVb)",
        "z:c=F(?",
        "YNl[TAm",
        "kc6}=",
        "WJ.>_",
        "TGb}t",
        "&4722",
        "Xe?zj|",
        "Vg! |",
        "_o%EZK<",
        "/Q7N8",
        "3SnJ$",
        "A`]l=",
        "@m7ds5",
        "j#sI9y6",
        "/U41+",
        "r7[jW",
        "R8M>>R",
        "e>pG/",
        "<[1s_",
        "$\\5'.",
        "(%6T0",
        "rx`af",
        "confidentiality",
        "jCjkj&",
        ";T;m;u;{;",
        "T M\"(",
        ">\"%%n",
        "@U%b5:z6B",
        "E*^zMJ",
        "(\"W/LN",
        "q4FwF",
        ">7?>?",
        "O) `nR",
        " oF2}",
        "V]I!;",
        "8_\\CS",
        "'5kyW)",
        "wz|0)d",
        "gFU1h.",
        "jZ[Yh",
        "U0nB<#",
        "PuEt1c",
        "biZZ8<l",
        "|[#8cz",
        "_|.F)>",
        "AECDH-NULL-SHA",
        ";(<~<",
        "Cn#2g",
        "M}UE6]",
        "!mQw@",
        "7dij<x",
        "O|@YOl",
        "[`k@sOU",
        "DSO_bind_func",
        "\\drivers\\DisconnectedPolicy.xml",
        "P{.:M",
        "p,z6+J",
        "Q}xz0Ju",
        "7CQ}H",
        ".]1 q",
        "-W''V",
        "InitializeNoOfficeMode...done",
        "octet",
        "[zflg,n o",
        "stream end",
        "i53lF",
        "x%7~Y",
        "d%w6tz",
        "}v$L~B",
        "]@Hm+k",
        "des-ede3-cfb8",
        "vu$Nd&",
        "MODULE",
        "Looking for incompatible Kaspersky Anti-Virus software",
        "6)6?6_6",
        "F4|=-",
        "n+nKn",
        "JLmVA",
        "obVoTr",
        "6Nv7\"",
        " gc%&",
        "A' +;",
        "D'#JZ",
        "t/}wL",
        "RegLoadKeyA",
        ";$;G;",
        "555A5[5w5}5",
        "H%wl9:s",
        "First SetNamedSecurityInfo call failed: %u",
        "camellia-128-cfb8",
        "5vWYW",
        "PublicKey",
        "Q<[`C!",
        "D$TSU",
        "reuse cert type not zero",
        "VNy*&/",
        "5iN$,",
        "windir",
        "bLT?l",
        "setct-BatchAdminResTBE",
        "@kqqKp",
        "2$2[2",
        "Failed to stop TRAC service",
        "5C5J5[5c5v5",
        "OR\"y~",
        "bp}i)",
        "5m6~6",
        "e\\\"-I",
        "VWZJW",
        "J'FjS",
        ";9D$,",
        "2)4S4",
        "]Yheh",
        ";r!/)A",
        "v1X7P",
        "6$6;6O6d6k6q6w6}6",
        ",Y+=z",
        "o`Y#zm=\\;",
        "7$!sL",
        "\"%08X\"",
        "cleartext",
        "7%7+71777=7C7I7O7U7[7a7g7m7s7y7",
        "J2Hk-",
        "ua1MhP",
        "FoqZ\"?=S;",
        "823s*",
        "g#ley",
        "G0GXF",
        "DE,/_\\",
        "CfP9x",
        "<9 0R",
        "]nT+^",
        "|c&z(_",
        "XlCx*",
        ":f<y<",
        "4q(c{",
        "9\\ZYMN",
        "6Jf5R3a",
        "X509_load_crl_file",
        "_8;F~T",
        "7m<S~u",
        "A9\"Kk",
        "xbt.}",
        "8(9H9T9t9|9",
        "Zfq3K",
        "@b.ev",
        "@J7FO1[",
        "kS*ih",
        "/O1|M+#",
        "dfM*?",
        "28RD,",
        "Y`__aN",
        "RY.U1",
        "q?~~_",
        "D~[~n",
        "CERTIFICATE",
        "ukJ^K",
        "1_tDc",
        "x_t6B*",
        "XnpF=",
        "3L$83L$(",
        ".?AV?$_Iosb@H@std@@",
        "grsEd",
        "|>>B|>>Bq",
        "yQbf wvi",
        "MmL/7",
        "%sRebootFlag.pending",
        "q0v0{0",
        "@=x?,g",
        "s0:l}",
        "Q2t8B",
        "Ht$nx",
        "non fips method",
        ":]=O>",
        "QZDyj",
        "@ccpm0n",
        "\",\\0bh",
        "[VSINIT] %s: Wow64DisableWow64FsRedirection failed with error %#x",
        "898T8",
        "L&E(i",
        "6Ps'o",
        ">)t1Y",
        "OJ!~[",
        ":=$9s",
        "gzIpQ&6",
        "vP~_A",
        "required compresssion algorithm missing",
        "\"%svna_utils.exe\" -d -ap vna dev exist cp_apvna",
        "\\f1\\fs20\\insrsid14296673 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2703887\\charrsid9533499 ",
        "@?sTo",
        "D+^-$S",
        "6m]w ",
        "9~W4w",
        "1.1_1",
        "8f1lrn",
        "`CqSp",
        " 5hEEO",
        "2\"KBp#u",
        "&C;bSc",
        "EqO3F",
        "h\\#4,@s",
        "ipsubprotoflaggroup",
        "~kY>[MT",
        "8 8$84888H8L8X8h8x8|8",
        "Z~#`N",
        "CRolloverMgr::CopyRolloverBlock():  unable to write to rollover file",
        " 0x7c",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\sa80\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid11303137 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 8}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6166062 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        "133=3'4",
        "PALIGNR",
        "LW}SOz",
        "9lkXHs",
        "oL7#y=A",
        "Y?K1E",
        "xbwovR",
        "RxJD.",
        "!yyrd<-",
        "9XK`r",
        "V(yT)C",
        "B$+0W",
        "+snf$-",
        "1/1>1P1c1}1",
        "PARSE_BAG",
        "Sp\\a1_",
        "Py8(G",
        "7%@?;>*",
        "%-bB%m2&",
        "{w6{/",
        "1W1|(",
        "7r3C-g=",
        "D$(_]^[3",
        "MAyh1",
        "VQH:E",
        "<BWze-",
        "9-OmU",
        "D$$h4",
        "{8+*.",
        "5/B,>8z=",
        "PEM_PK8PKEY",
        "4:5E5",
        "Os_u)\"",
        "5SHFKF",
        "N2pyo",
        "/a\"i>",
        "Rdg- ",
        "jQ32K(",
        "-[O_FC",
        "< <@<L<l<t<|<",
        "LICENSEKEY.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "g,Zt'",
        "(8cN~",
        "qmi0w",
        "FIDhw",
        "Jz:Ir",
        "zFM?.'>",
        "?)?F?{?",
        "ODDSYn",
        ".[4K8ZB$x{",
        "Y!UNg",
        "j9/V1;",
        "0gz#X",
        "PCMPGTB",
        ";_\\bGLNv.",
        "tR<0|",
        "4_5v5",
        "PZ);C}",
        ">&>/>@>",
        "1'303u3",
        "t3ny@Pd19",
        "_ZZW8",
        "UEQA5",
        "wW~At",
        "wSfq .",
        "PX7,G@b",
        "CT(l3",
        "MailFrontier\\INSTMLF.LOG",
        "i:9=A",
        "u!UUj",
        "table loaded, bad count = %d",
        "IMAGEINFO",
        "4!4=4Y4u4",
        "Vf??S",
        "9G:]:>;{;",
        "\\f1\\fs20\\insrsid13240566\\charrsid13240566  specified on Check Point\\rquote s website.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14888499 ",
        "IUF'A",
        "o%V*^=H",
        "yg0Oi",
        ":a;iwVH",
        "T]nU<E",
        "K14@_",
        "]`'_M",
        ":7:S:o:",
        "cITMIZ",
        "3,343L3T3l3t3",
        "C;Wu\\k",
        "u$j/V",
        "nqrL!rz]",
        "w/'81#",
        "{\\OJ4",
        "GC*CS",
        "\\vsavpro.dll",
        "\"b]db8.",
        ".NPnP",
        "^KBRd",
        "{Ep y",
        "E}Y~y",
        "UUhUug'C",
        "lLh-0j",
        "G)w[oIv\"\\0",
        "s2G\\G*G+",
        "NTLM picked AND auth done set, clear picked!",
        "ZTdLN",
        "474E4U4W4c4i4m4",
        "EPNetUpdater.exe",
        "[d:J1",
        "HhRh\\h",
        ",glTj",
        "F0^[]",
        "2&~Ox",
        "2)DRh)",
        ">Z~r<",
        "W'W/WKTk",
        "-b<$<",
        "4.mIbg",
        "*VQ&R{-",
        "AC`NDe",
        "515Q5_5m5r5~5",
        "O6M,\\",
        "Zp*EZ\"",
        "k{,?'",
        "<,:<i",
        "9!929<9H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        "1 1{1",
        "+(My\"",
        "/aSO '",
        "$rJLX",
        "EncryptClientHeader ended.",
        "SRm>%|",
        ">'>.>G>[>a>j>}>",
        "T|4 X3O",
        "qOkP6",
        "v@`iz",
        "u;{Gk",
        "|$ Wj",
        "B'(?]u?",
        "9e8Vq",
        "Obv [",
        "a0KY]",
        "L/3$7",
        "ERROR: MoveEntryToEnd LoadData failed!",
        "o/+;@",
        ";QvT3v{^",
        "<6<K<[<h<",
        "O}HU;|lm",
        "H!0{A",
        "W?,fc",
        "z s-5",
        "oJwL;G",
        "J<[Wy",
        "a{'Kx",
        "i^{\"t",
        "6 6(60686@6H6P6X6`6h6p6x6",
        "Dk7PZ5",
        "n'/'q>m",
        "=m=y=",
        "I}]Qk",
        "      <requestedPrivileges>",
        "=N=@{",
        "Hr}'`Cl",
        "4(4,4<4@4P4T4d4h4x4|4",
        "GEx/y&,",
        "\"d0Q)",
        "[EXCEPTION] CRT terminate() called. This is usually due to an uncaught C++ exception. Writing stack trace and dumpfile.",
        "t$DVU",
        "5<kFj",
        "K-K}K",
        "%k|P=",
        "; ;8;",
        ".ll?)",
        "v[8hpS",
        "`NlUf4V",
        "80y0~0",
        "v%Vq*",
        "^I)WXjtk",
        "4F5b5",
        "~A$jg",
        "sRx5iK",
        "setct-AuthResBaggage",
        "dtkzF9?",
        "jj;u(g",
        "wF]V*7",
        "V^'Ly",
        "W/>fW",
        "777V7h7",
        "T$$SW",
        "9&9:9",
        "0%0<0C0O0\\0",
        "=iO9&",
        "n1BJ ",
        ";K<~<,=d=",
        "QmujSxoj",
        "=o=y=",
        "SELECT `XmlConfig`.`XmlConfig`, `XmlConfig`.`File`, `XmlConfig`.`ElementPath`, `XmlConfig`.`VerifyPath`, `XmlConfig`.`Name`, `XmlConfig`.`Value`, `XmlConfig`.`Flags`, `XmlConfig`.`Component_`, `Component`.`Attributes` FROM `XmlConfig`,`Component` WHERE `XmlConfig`.`Component_`=`Component`.`Component` ORDER BY `File`, `Sequence`",
        "y rrw",
        "uX{n[I",
        "U*J?_q",
        "P5F`Z",
        "w*_laI",
        "Wy(@UUo",
        "yPaM*",
        "j PjYh",
        "ec_GFp_nistp256_group_set_curve",
        "z\",x=N",
        "R(OJyL",
        "])[9[",
        "505I5Q5Y5r5",
        "ftp://",
        "Sj-e4",
        ":U7PI",
        "!r4yR",
        "m)sl!",
        "!D>M4\"w7",
        "/ZBFE",
        "l$,V3",
        "]8+Q#X",
        "<z`@qT",
        "d 1[U",
        "dF2Xb",
        "jAjij",
        "fr-MC",
        "hL0Hq",
        "WBvMW$z",
        "#&!ph&&e",
        "6-6L6i6",
        "@&;dF",
        "Vv7E=",
        "Eft%.",
        "DKW:W",
        "Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)",
        "not loaded",
        "1mmAe(.",
        "SaveXMLDOMtoFile failed",
        "***** OnSuccess started *****",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 5}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5010868 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid1729076\\charrsid5010868 DEAD}{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        " x\\_)",
        "~mp[)",
        "jDjdj+",
        ":%:Z:",
        "mMn3Fdhm",
        "zh+R.X(",
        "FfFnFxK",
        "q@C oX",
        "+U\\vq|50",
        "SfC+{",
        "EPAM_Uninstall.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "W3_5B",
        "no filename",
        "CALibrary.dll",
        "Q4W/c",
        "-v'p{HD",
        "\"<<*N",
        "+]zS=6",
        "566e6",
        "^Q<Mc",
        "n;-BJ",
        "j0Zf;",
        "Pb6b6",
        "?!?'?-?2?8?>?D?I?O?U?[?`?f?l?r?w?}?",
        "[3\\s7",
        "7O9Y_",
        "j^+SI",
        "SSUS8",
        "1V}K])g!",
        "~H^v-j",
        "20=9!",
        ";_fCk",
        "id-smime-ct",
        "g<~fW",
        "0)060;0I0y0",
        "y$BjY7L",
        "7r<~1",
        ";<;U;o;x;",
        "FKi\"{",
        "SecuRemote",
        "PWWj WWW",
        " DnqZ",
        "#Y=j$",
        ".0Aps\\",
        "a%o)0",
        "%U9B=v}A",
        "3;3B3Q3e3x3 4",
        ",Lc4f",
        "D*,)=",
        "Z#[h_6\"",
        "*#O245T",
        "ruA!;",
        "Stop waiting to process to finish - result: %d",
        "EJs<i",
        "t*;>V",
        "\\)k3a",
        ":bri8l",
        "^uMVR",
        "Object Signing",
        "VhTcL",
        "<8jS9",
        "Check Point has no obligation to provide You with any service (such as, but not limited to, technical support, maintenance, upgrades, modifications, or new releases) under this Agreement.  The purchase of services, if applicable, shall be governed by the ",
        "dUU9m",
        "2ZM%Z",
        "^VZg)cf",
        "[PQlh",
        "ZLPROPERTYFILE",
        "858Q8m8",
        "^qG9_.j!",
        "qa/!]",
        "iHTfP",
        "RqZqbq",
        "0QVol*",
        "CVTSS2SD",
        "Rth-IG-]d",
        "_@{8yg",
        "N\"ptH5eg`XV#",
        "|MRt3",
        "/(;3t,",
        "Old vsmon is still running.",
        "Upload failed (at start/before it took off)",
        "wrIAz",
        "7_ZZN.",
        "]ug's",
        "<F=K=n=",
        ">#>^yk",
        ".\\crypto\\asn1\\a_strnid.c",
        "NL/?k",
        "ny(/@",
        "[k:n%",
        "7SF5z+Xv",
        "'WzW;",
        "3x&te",
        "Delete file: MsiDatabaseCommit",
        ">q-uD<",
        "7-828=8",
        "nnSJ4",
        "ExecSecureObjectsRollback",
        "2(3@3",
        ";D*>1~",
        "6'7m7",
        "~{=rd",
        "7_(php",
        "BY\"z[",
        "u@hjP",
        "==ScDD.k  ",
        "(h7&Q",
        "j$hPhH",
        "+.;+>1O",
        "=5xig}",
        "]^gi()",
        ":!:1:",
        "'kT7o",
        "0hupR1",
        "[VSINIT] IsWow64: IsWow64Process failed with error 0x%x",
        "pD^L1:]",
        "4OeC7+",
        "tW)VD-",
        "'/gIUA",
        "+=.w|",
        "0%0+0H0V0b0l0",
        "S^W*j",
        "<c$kv",
        "vHt!hd",
        "TerminateApp returning %d",
        "PSRLW",
        "skfKk",
        "'c.]O",
        "?S`)?",
        "<i79K",
        ".8$N@",
        "-L0:&",
        "v=M`y",
        "Failed to copy %s, error: %s",
        "k/Kl]",
        " C fO",
        "-<:ha",
        "ioctl callback returned error %d",
        "<.<K<",
        "vU40b",
        "aSd&2",
        "Opened",
        "*7\"1C",
        "tvSetAltDirForInstall",
        "\"@CX(",
        "kqfSz",
        "RPqT%",
        "0 3/3",
        "Z{D@/W",
        "lk3YAnZ|",
        "$T%<.",
        "4)5F5U5",
        "C'nT)b",
        "failed to get firewall exception attributes",
        "]$I2Ce",
        "dP)!1",
        "G\\el]",
        "Iht s",
        "ldgqT6",
        "8 8&8=8D8J8W8o8",
        "cWt{#",
        "DO;M%K?",
        "FVne%/L",
        "d)TIt_]",
        "o5n{?",
        "=D=I=Z=`=",
        "v&*XJ{:[",
        "S<OdO",
        "Jn6&e",
        "{Ja*Q",
        "p+12v",
        "k-kh<",
        "0V 6i",
        "AssE%",
        "7$7)7=7B7Y7d7i7",
        "\\xIvY,=I",
        "nFup<",
        "#\\DnJ",
        "!h!bt",
        "hZ\"`Z",
        "EC_GROUP_get_curve_GFp",
        "[VSDATA] AddDataClient: existing client",
        "S%l4)E",
        "8F8U8Z8{8",
        "aW5.Y",
        "1(]G[IC/1",
        "FPBqRFX`",
        "e.7gy2",
        "`DDIO",
        "G}iDvl",
        "emf|F",
        "oP`:f",
        "FWFreshBefore.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "5;6Y6q6",
        "yPbU&",
        ";UPdYLWU",
        "51)<9!",
        "|_X&<-R$",
        "wLs5J",
        "pM0#%+",
        "nwF.{",
        "unknown protocol",
        "3\\Q9U",
        "bad rsa signature",
        ">=PVt",
        "FWUpgradeAfter:  LoadVsocnfigXML",
        "Failed to append document element on to parent element.",
        "4p\\AlX",
        "Md]7=",
        "PKCS7_ATTR_VERIFY",
        "CPINSTADDSCV_",
        "=3333",
        "4F5U5",
        "&MJ|S",
        "Gd=u\"?",
        "3I3\\3",
        "x)MO5",
        "62in9",
        "geoRl:R",
        "kGkTp",
        "uyUUV#",
        "Could not retreive PRODDIR from registry",
        "&2$U$6",
        "PFMIN",
        "Xr%!A",
        "@h7@ ",
        "5<6I6b6g6",
        "q|'\"v",
        "a]TMk",
        "<7<b<",
        "H%z8_m",
        "ComponentsInstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "mO 1mQ",
        "\\Check Point\\Endpoint Security",
        "#eU *",
        "Kill cptrayUI.exe.",
        "V=stG",
        "J&%IK",
        "slot full",
        "r.;XG",
        "fYr]#",
        "Any Purpose",
        "^Venk",
        "v_4>J",
        "$mj8s",
        "DVq[>",
        "D$ +G(P",
        ";e~^n",
        ",67`:",
        "\\a`ala",
        "UlvY0",
        "=#=,=D=S=]=",
        "^pE!G1\"",
        ">?muW",
        "$D1k\\",
        "B<7X(",
        ">?>S>f>",
        "3#3K3f3",
        "QJ[JT",
        ":# :Y]L;",
        "X].4o",
        "UnregisterTraceGuids",
        "FK.XF",
        " mT7\\Jpi",
        "+JbTT)",
        "Ia=f.",
        "wrong type",
        "TXYQ[=~*",
        "f(\"tfB",
        "6ZLz1\"",
        "hNQA_1",
        "rvp;v",
        "VWht9 ",
        "%lIhv",
        "q^UpO#",
        "=S>b>y>~>",
        "PSLLDQ",
        ".?AVnested_scheduler_missing_detach@Concurrency@@",
        " key: %s ",
        " -nosa",
        "gV?eb",
        "rsaEncryption",
        "k79hF",
        "\" pfs",
        "g[o[t[",
        "C$8>.P",
        "t@\"QN",
        "P:/)a",
        "[0f V",
        "E$J4M",
        "k!k\"3",
        "0$0)030C0]0q0",
        "Tl!C9S",
        "8 8@8L8T8l8t8",
        "9X9r9",
        "0<0H0h0p0|0",
        "c\\H}D",
        "^r/5::",
        "WPROh",
        "Xl&i%",
        "A)>d[sPD",
        "o28J=",
        "&`fbf&",
        "6vdK#",
        "turn protection on",
        "&363a4A9Q9a9q9",
        "I,.o`",
        ":$:,:<:D:L:T:\\:l:x:",
        "T&K;i",
        "{.:=>",
        "C>?9{J",
        "kt9PT",
        "_90f\"q",
        "CAST part of OpenSSL 1.0.2h  3 May 2016",
        "ChangeServiceConfig2(SERVICE_CONFIG_FAILURE_ACTIONS_FLAG) failed: %d",
        "I6|qlE",
        "/^Lt\"3",
        "U`~L8",
        "!nL/0Ky",
        "9|$dt",
        "Da%N\\",
        " <k<S)",
        "7'@yq",
        "YCK4|i",
        "*Z/9j",
        "7FQNb",
        "FI#kdhUuY",
        "RSA-MD2",
        "F|WPS",
        "wnsc<",
        "(:M?W",
        "9X4u/V",
        "HMZTR",
        "`4A.>[G",
        "9]Y6z",
        "E#`zGq",
        "Permitted",
        "EB\\F ",
        ",ueA.",
        "Ve\\FcG",
        "_F~-,",
        "%*sCRL Issuer:",
        "(HX{P",
        "r1Ry7",
        "RFC 3779 resource not subset of parent's resources",
        "SSL SESSION PARAMETERS",
        "e^c\"k",
        "UqC>8F",
        "4pYo[",
        "%d,!8P",
        "%nW#Q",
        "/.,1ik",
        "p|0DU",
        "[zdv;",
        "9&W+_yM",
        "X^2#\"",
        "ASN1_STRING_type_new",
        "[3UDN`",
        "=20G%-",
        "g`,*a",
        "D$8tC",
        "oL;0a\"",
        "p%Va3",
        "5 5,5P5p5x5",
        "&ZeTd",
        ".fdy?9`",
        "cannot obtain size of CurrentBuildNumber value %d",
        "L;Zmi",
        ">j9,U",
        "HFB>rI",
        "j$WV3",
        "??W\"Zy4L",
        "8yG=L",
        "RQZz{",
        "c>~!UU~",
        "jAj|j.",
        "~^wln",
        ";E$riw",
        "_shutdown_",
        "<W\\`P",
        "OUT_OF_MEMORY_READING_MSI",
        "$yn.?",
        "-A|M'",
        "C0XV!I~",
        "OpenSSL RSA method",
        "7C8S8^8",
        "/k\"nf",
        "t3 #J",
        "9$UjO",
        "D$ PS",
        "*!\\`Hm",
        "Dk7]2K",
        "!_i51",
        "&j)6}",
        "&{B^E?",
        "\" 9~}",
        "0%,\\D",
        "failed to get access to oldckpgina file",
        "mpwA!iGE",
        "[VSSHUTDN] BanProtection ",
        "X32$+",
        "qQI_b",
        "Kcyh(",
        ".M_%-",
        "No buffer space",
        "cGTc_",
        " @M5l",
        "swJyV",
        "p`kYg",
        "L$HSUV",
        "=.(^M",
        " 566]",
        "l%$NmZ<",
        "Failed to MsiViewFetch with error number %d (%s section)",
        "ZYzR(<F{",
        "X\"zb=",
        "<q?N9R",
        "t<SVW",
        "090_0l0",
        "#}{x&",
        ">8?<?@?D?\\?`?p?t?x?|?",
        "}kK4t",
        "}BgF^",
        "gpU7D",
        "]h^pWj+",
        "<$xP+",
        "vAao7",
        "$_nN6{",
        "b9C~Q",
        "kP\\*1\\w:",
        "*-m;S",
        "\\10j~",
        "2C/$P",
        "INTERNET",
        "LicenseKey",
        "3'SV[5J",
        "H;i&%1",
        "/dBL\"d[",
        "c2onb191v5",
        ";&<8<",
        "~7<o6",
        "JTnSq",
        "eCejiFi",
        "PCClient.exe",
        " 0xe1",
        "4= m@9",
        "7rn;C",
        "&,8wY",
        "'X{Rt",
        "HTTP/1.%d %d",
        "FNSTSW",
        "@ l.x",
        "N~0sG",
        "udj0hx",
        "tJ >`",
        "L{6h*V",
        "Rl;Rs&XT",
        ":tkw'",
        "qO01w",
        "wzw|w~w",
        "GeT!n",
        "i42$Sm",
        "dEA^=",
        "otherCertFormat",
        "nZG>d",
        "IZIBJ",
        "nOBo_",
        "6<Lyi`?",
        "Y@rATE",
        "RPB v",
        "lIH@v",
        "y,f;a",
        "5hx\"3",
        "+[u?|",
        "%s:%s",
        " mMmT ",
        "Cached msi ",
        "aD*Pl\\",
        "tc;nt?;mt=",
        "6THPu",
        "V=xPb\\",
        "TS_TST_INFO_set_time",
        ">!?&?N?v?{?",
        "L\\!.'dX",
        "t@.1`m`;L1",
        ";R<]K",
        "`dv`b",
        "K|)+N",
        "ECKEY_TYPE2PARAM",
        "$JCfI",
        "t$4SV",
        "=rRqC",
        "*IOo\"",
        "rbf;u",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 9.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "Lb'dS",
        "r>f=f",
        "4 4$4(4,404<4H4T4`4",
        "mae}K",
        "o#(PA_+U",
        "_N!p]",
        "jAjrj!",
        "g>+gS[K(9",
        "3Sdeb}'H",
        "BN_mod_exp_mont_consttime",
        ")uQd8vb",
        ")K(nT",
        "@j,ZWk",
        "<\"<,<7<B<M<X<c<n<y<",
        "Unable to obtain function information, skipping Composition Enabled check.",
        ")yZz:",
        "E=vIH",
        "Windows Defender is absent",
        "n`FB;",
        "H\"F$C",
        "HriS8",
        "`]N7P",
        "lRj1j/",
        "puH*Je8$Q",
        "2FJRX",
        "mPpyo",
        "od#+d",
        "B/=]3U",
        "?~@B \"",
        "z0<l@vQ",
        ":vn:V",
        "X509_NAME_EX_D2I",
        ";K;P;T;X;\\;",
        "HTto<#pr",
        "M%nCB0",
        "'disabled'",
        "3)343a3l3",
        "xuB8Kw",
        "UnmapViewOfFile",
        "IDEA part of OpenSSL 1.0.2h  3 May 2016",
        "wh3}5",
        ":~b&|s]",
        "fwkern.exe",
        "hb/ka",
        "g2Ry48",
        "p|(<w",
        ".$Sk(Q",
        "&I9{q",
        "|qOg%",
        "h%i2H",
        "uninstall password did not match.",
        "member-body",
        "Vg?e#",
        "nKqq!",
        "@-ro]",
        ":A;?9",
        "FdreK=",
        "\\j~%&",
        "mocksubstitution.cpp",
        "A)bD[D",
        "hashFunc",
        "2+6VF",
        ">#r6E{",
        "=9>B>",
        "4$4D4P4p4|4",
        "GF0GRw",
        "cLJ4~",
        "/..2^",
        "ec_GFp_nistp521_points_mul",
        "G8_^]",
        "zlib compression",
        "pfoI,z",
        "lnr$p",
        "DigiCert, Inc.1A0?",
        "9P*v=",
        ">7>E>`>",
        "t$LSVj",
        "!BrVm",
        "i[~)W\"",
        "!Y6=Uo",
        ".?AVstl_critical_section_vista@details@Concurrency@@",
        "9@Y74)",
        "0Sjd[3",
        "X89Z<u",
        "2E~#Zz",
        "W?':s",
        "GgQ}y8>N",
        "|4m1y",
        "F/>^m",
        "QVRp[",
        "aB~IxdgY",
        "3L$(3D$,",
        ">}dS6@`",
        ";j69a",
        "3'4T4",
        ":':,:1:A:F:K:[:`:e:",
        "?8?T?p?",
        "~+7Eo",
        "*7+QH0",
        "%Y_%m_%d_%H_%M_%S",
        "F4!]+",
        "o\\Ul>",
        "h-,k/",
        "{R;?W",
        "c0Q;I",
        " offset=",
        "2F2X2G3&585",
        "K2F #",
        "\\2&%=",
        "EFRInstallMode",
        "Can't open sub key at Subkey %s",
        ".8-1|",
        ",TRtf",
        "\"zPG08",
        "\\q2&z",
        "SUVWh|>%",
        "DeviceAgentAPI.dll",
        "Fv).J",
        "$%In-n",
        "oazRFx|",
        "ssl_add_clienthello_use_srtp_ext",
        "d;R7_6",
        "r+\\.?*",
        "(ZeL-Y",
        "R(1v]P",
        "!w'=m",
        "bad verlen",
        "4P4]4",
        "oro7^",
        "T83r$",
        "^hl-&",
        "t*U`(",
        "D$8_[",
        "YI:xztr-t",
        "P{P$*",
        "Cb;E{-",
        "&kK&P",
        "L$8_^3",
        "H0t~\"",
        ")nTXC",
        "ASN1_SEQUENCE_ANY",
        "4\"4,4_4i4s4",
        "[f||$",
        "@y\")H",
        "+{1gzz",
        "9<Zhnq",
        "mh\\u\\u\\",
        "`|v0(?}",
        "rJr>*",
        "PKCS7_ENCODE_RINFO",
        "www.digicert.com110/",
        "%*sKey Id: ",
        "tfu||gt",
        "c 50N",
        "'R'n&tS",
        "mNdQ1",
        "pTm%xz",
        "7,8SD",
        ",`+dYX$,,",
        "5e7i7m7q7u7y7}7",
        "Kerio Firewall 4.15 and 4.16 (All SKUs)",
        "]VqtPD",
        "=!=Q=",
        "7*3zC",
        "CHECK_BITLEN_RSA",
        "HSUBPS",
        ".\\crypto\\cms\\cms_pwri.c",
        "_NKe9",
        "2Y3i3",
        "No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)",
        "SYSTEM",
        "c'Omr",
        "7=L?C",
        "z9d>>/",
        "%vF.`",
        "y^xNy",
        "CP=}+9",
        "2W2b2i2",
        "\\config.xml",
        "TrueVector Service",
        "rz@|Q",
        "/aaXE-",
        "3!363P3",
        "O6:Q:",
        "u|h*@",
        "Y\"zPbA",
        "J&#:K",
        "IO7'u",
        "A!o\"g",
        "AM#qo}D%|",
        ":6Co=%",
        ">8&m=",
        "88e-K",
        "^LY}[",
        "/x!}>",
        "I!UhIY/#",
        "q_5\\1<",
        "[~m0pn",
        "zcS>O",
        "j\\P;Hw1",
        "7)717",
        "s-:a>43",
        "7.~KgW",
        "`1aqY",
        "jQ<\\-",
        "r&u*k",
        "5-575",
        "O1dF$l",
        "P{`D#",
        "p;;7#%&",
        "V32F8k",
        " $eCq#",
        "aes-128-ccm",
        "gAxE!",
        "D$8SP",
        "=)>v>",
        "vF)&j",
        "`;JK6",
        "595M5",
        "n]Z:)",
        "zB|\"J",
        "(M~*\\q",
        "2y@Au",
        "o!P{d",
        "bnpxc_",
        "cy5 i",
        "=,=0=@=D=H=P=h=x=|=",
        "=s-$1",
        "YY^hNE~\\",
        "Lo0I/",
        ")WX>*\"\\\"",
        "2@lNA<",
        ">EmX1",
        "5:5F5i5",
        "2EQJ^n4^",
        "?SJ-c",
        "\\R1k}O",
        "wwENM",
        "Compliance.exe still running and will be terminated",
        "!{k_pp",
        "Configuring Service: %ls",
        "K%NgF",
        "bk@NE",
        "ar[X'",
        " kh{v",
        "trCh|T",
        "q}Jz{",
        "Af1$F&",
        "/:\\|2",
        "/<_~\\",
        "64_BIT",
        "?9bmMb",
        "n\\Ka@Q",
        "h2xu\"V9",
        "msUPN",
        ">`>bu",
        "cDc~cSbP",
        "xsIH#",
        "95n?+",
        "nwDdk(",
        "tk 7h",
        "3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%",
        "FAILURE_TO_CREATE_SHARED_MEMORY",
        "f9D$$w",
        ";Y;P<a<",
        "212Q2q2",
        "xW872_",
        "nwMApg",
        "~4j2j",
        "u-olS",
        "`7<t^=c,*",
        "m!xCwl",
        "_&$cv",
        "dR/hK|c",
        "*AmQ\\",
        "3T$81",
        "<F<|<V=",
        "Bfw(*p",
        "z.i U",
        "Something is stale",
        "9]ar H1",
        "H23aHy",
        "(D<cQ",
        ";<tl0o[",
        "2!k<BIZ",
        "Wi# p/",
        "`LY7B",
        ".=.].",
        "C]^c]",
        "_`;)H",
        "s>r9{",
        "YKiw5",
        "SSL shutdown timeout",
        "VCRCM",
        " gv~+",
        "Q_/2q",
        "8l@N3Y3F;eK",
        "{4j46",
        "Kk8oy",
        "FFV!C",
        "LCIDToLocaleName",
        "+9F>O",
        "+Uf uH",
        "Apil73",
        "f\"\"D~**T",
        "O-)_Y",
        "9'939?9K9W9c9o9{9",
        " e^b^",
        "J1mg4",
        "JJ5A<",
        "*VTMt",
        ",fC<o3",
        "\\rp)p",
        "w*Epd",
        "v&/Q!",
        ">rjFP",
        "?\\5A]",
        "hdqaaA",
        "W~*i&",
        "4Kgyk",
        "}zQ./",
        "LoadLibraryExW",
        "z8r3,5",
        "e8AEy[V",
        "3\"3=3B3R3W3g3l3",
        "Z}DW:o",
        "Hp0K\"X",
        "3:3A3M3W3t3{3",
        "-)nC<",
        "ZLProduct.Features.pFeature[2].Name failed",
        "C;\\$0|",
        "-D)k47",
        ",,=,'",
        "!1v~V",
        "z:ar_L",
        "3)a+C",
        "-QHjF",
        "565P5T5X5\\5`5d5h5|5",
        "Helper::stop() -- begin",
        "taj*Xf",
        "+tgi /",
        "R[pR0d`",
        "IMPLICIT",
        "l/L$#V!",
        "Q0c0u0",
        ")X.}3",
        "4]NI5",
        "y)hXwp",
        "Ultimate",
        "&)os\\}",
        "/\\*Iq",
        "`VX:H",
        "]\\p!]q",
        "Common_Backup",
        "*2^ga",
        "0.wB\"4",
        "}PAr(",
        "certificatePolicies",
        "=ub&;Q{",
        "5.5f5x5",
        "Q7#MK",
        "pilotPerson",
        "Y::\\A",
        "1cP7K",
        "_K/aW",
        "mob_VPNClient.chm",
        "Ahg)Sp",
        "p=6F|",
        "dXm1:s",
        "={)uA",
        "=0=8=<=X=`=d=t=",
        "Ctd?6m",
        "&4G90",
        "Wd\\@F",
        "$iD0~",
        "p(0q,xQ",
        "+DVFmSVn",
        "7x]AJ",
        "Gr4KvuD1X-b!0",
        "%q-}3l1`",
        "3j&6'",
        ")I%]f",
        "}gYbSTD",
        "v0>02f",
        "ASN1_UTF8STRING",
        "SSL_shutdown",
        "h1.C:",
        "^8ukm",
        "uey=Y",
        "null ssl method passed",
        "#U5EE",
        "==>U?",
        "/nN{Kg.>RDK",
        "!LtgL",
        ";K=Gx",
        "CHECK_POLICY",
        "}v{kQ-",
        "<0|4|",
        "O,EkM",
        "0G1Y1",
        "ssl3_send_server_hello",
        "G6yrKZUR",
        "9>DITM",
        "8X8Y4",
        "c|>$W|P",
        "7*8Tj",
        "0'0,0V0",
        "4k,P=",
        "mQnQnQo",
        "wak4*?",
        "`}Z)X",
        "2;g^d`mcH",
        "x,KjD",
        "=*i~Y",
        "jdjyj",
        "_q_7F;",
        "YJk%i",
        "decode error",
        "8*q!f",
        "FBc`O",
        "(#%D>2>P",
        "A+%1=",
        "- not enough space for thread data",
        "We can reuse, but we want a new connection anyway",
        "=$=,=4=H=P=T=\\=d=l=",
        "eHin=+",
        "tosh5L2i",
        "7>7T7h7|7",
        "vOdBB",
        "k$4W[",
        ".\\ssl\\s3_clnt.c",
        "ttO4_",
        "9fB$p",
        "L$x3L$@3L$,3L$$",
        "Z/B3n~",
        "y>d<+Y",
        ":?9\" JN",
        "[O<)E",
        ":d4R(",
        "8t+ I",
        "XlCX||",
        "atlTraceQI",
        "\\drivers\\epklib.sys",
        "r>B{E",
        "CANT_SET_INSTALLATIONDATETIME",
        "%j&d')4*",
        "B#N|jWMp",
        "gLU9Gos",
        "XBXzX",
        "e~gW^|]y0",
        "@{nD%",
        "3/%o4",
        "h+j'D",
        " `Gq}",
        "|>,21",
        "!iAEi",
        "8<9D9",
        "GY(S@P",
        "xk$R=",
        "i!18h'",
        "6-7<8O8[8{8",
        "LNGY/",
        "cHA^5",
        "\\Rw3l",
        "wsLJ}",
        "+:@$%",
        "Ne91F",
        "id-smime-aa-ets-certCRLTimestamp",
        "+mhH\\",
        "%&LWr",
        ".]dX`!",
        "Ugka13{",
        ")Na]p",
        "@rd@t",
        "}8A&o",
        "fY'Y7",
        "Failed in ControlService, error: %d",
        "y969O",
        "Ss+Y&",
        "Rfx|'",
        "api-ms-win-appmodel-runtime-l1-1-2",
        "-=@<YgE",
        "#`t'l}Y",
        "KUxc(",
        "_8SWj",
        "\\h3,O}W`!",
        "\"{P%A*/",
        "H.>7m",
        "Oh44\\h44\\Q",
        "d8hd:&",
        ",h] G",
        "0iz[{",
        "x\"UVS",
        "b&jPL",
        "vh1v`",
        "}-L5X",
        "SJ8J|!4AB",
        "+5lk(v",
        "EvO~a",
        "UpdateVsconfigXML:  AV is being installed.",
        "WRITE",
        "4!<AnX",
        "pJpT#k&",
        "'j+~ ",
        "2'z]W",
        "no key set",
        "7!~X1",
        "|L&a?",
        "VTzt>It>",
        "=0A+a\\6",
        "; ;$;(;,;0;4;8;<;@;D;H;|;",
        "pUd7A",
        "D}bly",
        "4M=Gz<E",
        "z-$UNk",
        "1z(Mj<",
        "4NLN-NO",
        "block cipher pad is wrong",
        "u;L{'",
        "~1-Wc",
        "~)mX]",
        "failed to find WSAEventSelect function (%d)",
        "target.url",
        "%+o5B",
        "]\\3-1",
        "@U>pb",
        "UUuUA]",
        "-N#00",
        "%S}$z",
        "777Y7",
        "567zP",
        "}3'>]6",
        "s0&1z2",
        "Uy85R",
        "6-6I6d6",
        "0 0$0(0W0",
        "Bx<#~",
        "Ciz>V",
        ".\\crypto\\dsa\\dsa_sign.c",
        "1 <$[",
        "&\"A<P",
        "(7x6J",
        "Azn/x",
        " \\WmvBW",
        "@12BN",
        "pw^p'",
        "O 9U]",
        "<r)Z{{_",
        "{O[%:W",
        "#?V<je",
        " from file:  ",
        "zYLaB",
        "r!I<y\\",
        "5O?kUw",
        "PDQmlr",
        "D#X/<~",
        "<R_Hj",
        "4UGO+ ",
        "5$5,545L5T5\\5d5l5t5",
        "Found HKLM\\SOFTWARE\\Microsoft\\VSTO Runtime Setup\\v4R\\VSTORFeature_CLR40",
        "*w2OA",
        "x,|*C=]G5",
        "^@44y",
        ":72Tw",
        "jaGvU",
        ";aRY9V",
        "<VWI0",
        "jqmAc",
        "!aMpK",
        "Removing registry key HKLM\\Software\\CheckPoint\\SecuRemote",
        "VZ|s:",
        "LUiwq",
        "|?TW{",
        "/$3HS",
        "4,4H4d4",
        "8rc8u",
        "A@v&3%",
        "3a6[p",
        "@Wg1E",
        "v!v0v",
        "GM@_r",
        "_^[]Y",
        "\\connection.xml",
        "e8Q21%\\",
        "UninstallCreatedItems:  UninstallCreatedItems started.",
        "7# |@",
        ">y32(j",
        "6,6>6",
        "SetThreadGroupAffinity",
        "p,TNR'",
        "pq?^K",
        "no file specification",
        "h5Cc0",
        "t'VPW",
        ".y\"f=1@",
        "failed to fetch ServiceInstall row for secure object",
        "8NqyD",
        "EPAM_InstallRollback.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "a^\"Lw",
        "CbCGBH",
        "[qayL^",
        "[ :;!-0",
        "{n'kH",
        "`w'{j",
        "*{qCq",
        "?Y6+'",
        "3$3,3T3X3t3x3",
        "A16L/",
        "KIUxu",
        "BvH^Y?[",
        "C]>>$",
        "8\\3\">R",
        "jgS|d",
        "~{9W5",
        "\\W%08lX",
        "AmF=>",
        "31464;4V4[4`4",
        "OT&>.R.V/`",
        "reb!>m",
        "alnum",
        "MailFrontier\\unwise.exe",
        "mpr`sO",
        "EB^c`",
        "{wPC(",
        "\"VT3M",
        "x^z[(",
        "~M#+@",
        "uXJ,{U",
        "expecting a boolean",
        "6O.u2H",
        "`w=?A",
        "bad authentication type",
        "= =@=H=P=X=`=h=p=|=",
        "==]bia",
        "a2!Pl",
        "RWSW`",
        "2=2J2R2`2t2|2",
        "B5I=qG-",
        "&BnRA",
        "?Pimy&",
        "`U0xdS)",
        "? ?.?4?E?V?`?n?",
        "Remote file already exists",
        "Ii!nu",
        "YJ*rw",
        "<8<X<x<",
        "jAjij*",
        "&hjfx",
        "=J2sJ",
        "L0s=hf",
        "QJxy6z'",
        "%%&5wA",
        "68rxH",
        "7c>aL",
        "G_2ZV\\a",
        "i(e-e",
        "c aHl",
        "<-<F<_<x<",
        "jtwNx",
        "&)bK>",
        "6)6?6J6`6k6",
        "g*Q'S5M",
        "iGfE3",
        "*=i1M",
        "3zl~}Q",
        "UUUUUUUUUUUa",
        "vsdatant.sys",
        "0 0$0(0,0004080<0@0D0H0L0P0T0X0\\0a0j0w0",
        "_xu\"}D",
        "jTP?4",
        "QUOT command failed with %03d",
        "DISPLAYTEXT",
        "hb;A#",
        "? ?>?Q?h?",
        ")g8wP",
        "CANT_PARSE_PATH",
        "11161;1S1",
        "unknown id",
        "MM4)q",
        "@(-e0G",
        "M8I3S@",
        "D$ t9j",
        "bc%^9H_",
        "h[#}>",
        "wQ)iX",
        "bUOAP",
        "?.?3?;?E?",
        "N.9!N^w",
        "b\"0C!",
        "= =$=,=@=D=\\=l=p=t=",
        "1UV*p",
        "SmYyE",
        "Z\\[H=",
        "6ft1\\P",
        "=<gww",
        "brM}Y",
        "Q-$F;d",
        "cLQ8r)",
        "qo&u~V",
        "ObBqT",
        "}wp>^",
        "l ^MMz",
        "pM`<s\"",
        "8\\8m8",
        "C^IMQQ",
        "N89msi",
        "0H1t1x1|1",
        "676c6",
        "bs=~4qL",
        "z[OcC",
        "a?8\"P'nCh|lL",
        "4.Joe",
        "TrueVectorIF::SetProtection(%d) succeeded.",
        "PKCS5_pbe_set",
        ".?AU?$error_info_injector@Vxml_parser_error@xml_parser@property_tree@boost@@@exception_detail@boost@@",
        "idea-ecb",
        "H>lH4wCK",
        "L I#/M",
        "{)?F9",
        "sT_= ] ",
        "8A5.&",
        "hEl}S",
        "5',\"L|",
        "zP,Zh",
        "vB1hK",
        "%8%@%D$L",
        "DH\\0hq",
        "!txQj",
        ".`_;U'",
        "y])CJvH",
        "'nrr.",
        "gMg4O",
        "DwQJ3d",
        "\"m*y+",
        "5Rw|]P",
        "\"4GxG",
        "3&3J3U3^3g3m3",
        "fLQ(J",
        "DefineDosDeviceA",
        ":/:5:Q:c:",
        "7$7,747<7D7T7`7",
        ".AgP|",
        "MAXSS",
        "f x4w",
        "B46#?",
        "[(5*_X",
        "vnDH6",
        "Shell_NotifyIconA",
        "&yZ4m",
        "erX,(",
        ">,aj=?[4",
        "{Y7K#@",
        ":--xv",
        ",JZ+#",
        "selected-attribute-types",
        "%%|oJ",
        "191U1q1",
        "2lc/|0",
        "id-cmc-lraPOPWitness",
        "s\"@2<u`",
        "J J8JTJ",
        "W_l?T",
        "LVGyh",
        "cb(F0",
        "Rm8w=",
        ")J2 %",
        "EC_POINT_cmp",
        "19=~5R@",
        "081>1",
        "OCSP_check_validity",
        ",l^e*",
        "O9e/wu",
        "DY+Y&\"*4",
        ",NFL8",
        "5gIs_",
        "YRe%g",
        "+r9Wy",
        "dmp1 not congruent to d",
        "#D(DJ",
        "pies of the Product (as the case may be) that can be used and installed at any given time.  No Product, nor any portion thereof, may be used by or on behalf of, accessed by, re-sold to, rented to, or distributed to any other party. ",
        "/JWFGK}",
        "ppMy8;",
        "CustomActionData: %ls",
        "d{qle",
        "+cV=y0",
        "N`-@b",
        "FCMOVU",
        "DC \"+",
        "$%[kI.",
        "u\\o8|",
        "4q>L(",
        "6*6/6=6N6`6n6|6",
        "242d2",
        "gEi@+",
        "&t15+",
        "9,<F'g ",
        "1~-Tj",
        "TSOO:",
        "\\6l;=",
        "\\lsdunhideused1 \\lsdlocked0 index 9;\\lsdsemihidden0 \\lsdpriority0 toc 1;\\lsdsemihidden0 \\lsdpriority0 toc 2;\\lsdsemihidden0 \\lsdpriority0 toc 3;\\lsdsemihidden0 \\lsdpriority0 toc 4;\\lsdsemihidden0 \\lsdpriority0 toc 5;\\lsdsemihidden0 \\lsdpriority0 toc 6;",
        "*}%@h",
        "4I}Vv5",
        "DhN_~",
        "x}0F\\",
        "R=<Z,)<C)N",
        "wKJ[0",
        "expected ']' or ','",
        "LBBHL",
        ")yIQb",
        "6b&f<",
        "psk no client cb",
        "C7if.",
        "J2[.sJnma",
        "zX]jj",
        "ogj0t",
        ";6<><d<",
        ":*&N4R",
        "S{-6NU",
        "&oNoMg",
        "4+>V(",
        "9B9{9",
        "#+VYg0",
        "kJ_6.f+",
        "ec_paramgen_curve",
        "7!8'8=8",
        "ojj2I",
        "done turning protection off",
        ">$>(>,>0>4>8><>@>D>L>T>X>\\>`>d>x>|>",
        "{Ts&!",
        "75~/a",
        "Seyo)",
        "?\\q88c6IlB",
        "yg^<E",
        "Br'NT",
        "{<xNl",
        "ze/tZ",
        "zNGa%",
        "USVWPh",
        "z&vV(.",
        "ignated Nationals or the U.S. Commerce Department\\rquote s Table of Deny Orders.",
        "n-<-Sr",
        "Queb\\<",
        "R4q\"$",
        ".HYYC",
        "2$2,242<2D2L2T2`2",
        "`+H8-r-",
        "^C_EZ",
        "w,rAP",
        ":!DAi",
        "CMS_SignerInfo_sign",
        "cc1Xm",
        "-pGN[",
        "restrict(",
        "INSTALLDIR is smaller then %d",
        "[Uninstall]VSTerminateTVService/TerminateProcess failed (1)",
        "0!1E1",
        "!G/gD",
        "6}+t'",
        "bn_expand2",
        "data error",
        "D[CAa",
        "iw/$:",
        "%u %s %X + %X  %2.2X %2.2X",
        "\\ltrch\\fcs0 \\fs20\\insrsid5727096\\charrsid3875139 eriod}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid13256927 , }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid1926352 certain }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032 ",
        "o2{;57N5",
        "yzJBj",
        "u$k[q",
        ",YD|~",
        ">fJvr",
        "==>N>",
        "Y>ih-\"A",
        ":';H;",
        "7#&ac-",
        "OpenSSL X9.42 DH method",
        "?!Vps",
        "gdFO3",
        "GOST 28147-89 Cryptocom ParamSet",
        "5(5:5@5K5Z5`5v5",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\detail\\ptree_implementation.hpp",
        "Qo]P=",
        " the management of Your Service Customers who have made a valid purchase of the Product.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid473743 ",
        "0T1`p",
        "1~3.i",
        "]Uc>]",
        ".?AU?$error_info_injector@Vbad_function_call@boost@@@exception_detail@boost@@",
        "jV;/[",
        ";_:zv",
        "|]uuh",
        "]<&@y^",
        "Ddn{By",
        "sP=P?",
        "ROUNDSD",
        "cO\\=Kt",
        "\\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext29 \\styrsid13065977 List Bullet;}{\\s30\\ql \\li360\\ri0\\sa120\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin360\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 ",
        "build: '",
        "Found conflicting firewall",
        "WN+x6",
        "Ko;A$>']",
        "hc0=8Y'",
        "} j@W",
        "S=S>S?-@",
        "TMD\"}F",
        "KQiGa",
        "818T8w8",
        "WwB@9w",
        "VMLOAD",
        "~vV6b",
        "o6X83",
        "EC_ASN1_PKPARAMETERS2GROUP",
        ";=\\A ",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\caps\\f39\\fs20\\insrsid5650206\\charrsid2703887 Part II \\endash  Limited Hardware Warranty}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\caps\\f39\\fs20\\insrsid3017503\\charrsid2703887 ",
        "[WinFW] GetWFStatus, failed to get current profile, error=%x, profile=%d",
        "Dl#x_",
        "Q t)F",
        "{3,2gy",
        "[n.\\)",
        "M4yU1",
        "FqQ`T",
        "boost::filesystem::path codecvt to wstring",
        "7!7=7Y7u7",
        "Db[UE",
        "****************************** VnaInstall started **********************************",
        "failed to create secured folder instead of symlink",
        "P$4{ho",
        "3dk]t;z",
        "a&yH7",
        "svdtjL",
        "=3Wr{}",
        "DYmYz",
        "gM;y=",
        "05nh|x",
        "D$pSVW",
        "p=P7H",
        "(o9HW^",
        "{:g7<",
        "\\O/}S",
        "zWE k-",
        "t=,U;",
        "~LN)'<",
        "~07/cG%",
        "jAjtj\"",
        "S7z+i",
        "N0D#bc",
        "OEC}Z",
        "<3PZY",
        "PBE-SHA1-RC4-128",
        "tlsv1 certificate unobtainable",
        "<!<6<J<U<o<w<",
        "Fd6)7",
        ";UL9$",
        "TLSv1.2",
        "ZWS6fW%6aW?7",
        "e}/TI",
        "6LhQ8t",
        "idp mismatch",
        "gGM.uD%",
        "W'tVaB",
        "set-ctype",
        "9.L;%",
        "t`|jW",
        "5hO#A",
        "Unable to read the CSeq header: [%s]",
        "%31ETY",
        "ASN1_EX_C2I",
        "Remove Framework registry key",
        "!s$@y",
        "D$$SPUW",
        "3L$L3L$ ",
        "I-(:~",
        "z]LqX",
        "3 3$3,3D3T3X3h3l3p3t3x3",
        "sfi*!",
        ";''~y",
        "yftqU",
        "({7_)",
        "Failed to get lenth of PATh environmnet variable",
        "x}yxy",
        "0\"n%brrj",
        "xYyO)R@x",
        "X|GMa",
        "E}fw%_",
        "(0p)#u",
        "PBs w",
        "privateKeyUsagePeriod",
        "yy0Da",
        "w.k^2",
        "1!1&1A1^2g2",
        "ga#d4",
        "c}L2c",
        "&{bn4",
        "j=8!^",
        "`D&:c",
        "SdSd,;-y ",
        "u,PQRS",
        "zHee/1Y:&$K",
        "UDvfDTE3&p",
        ",EXPLORER.EXE",
        "@~zCZ",
        "7-yiW",
        "XMLDOMObject = NULL",
        "owMlK",
        ".l-<!",
        "8QI10c",
        "J JYT",
        "4pg~%`:|",
        "ec_GFp_mont_field_mul",
        "9JY S",
        "P-oiK",
        ">.>O>",
        "'%%zQH",
        "_execute_onexit_table",
        "i&Rm[z&",
        "`vbase destructor'",
        "gR[E*",
        "k?**N<%",
        "g,H7Q",
        "lq,%.",
        "41Li0",
        "/HpF{o",
        "iJ]br",
        "2]_Qx",
        "m fN}",
        "kRAOAM",
        "Qx_Nrf",
        "6r+;V",
        "GI}#2",
        "mGGB<",
        "2(O^/",
        ">4m)<t",
        "kjO!}Z",
        "[VSSHUTDN] CallClrDataClient: No data client handle",
        "89hbG",
        "t;6Rr",
        "!x?#$",
        "9tx.}",
        "M1HtC",
        "EC PRIVATE KEY",
        "kksV\\",
        "DKr|h",
        "lS;<^",
        "@&H<n.,",
        "rcCSd",
        ";*;/;4;D;I;N;^;c;h;x;};",
        "pNw #",
        "*P)2!2",
        "5f5%6O6",
        "W\"$BH",
        "b)omZ",
        "G73!i",
        "G(o5-4A",
        "8R:K;r;",
        "ed\"\\f",
        "9o`v#h4",
        "8$8,848<8D8\\8h8",
        ".\\crypto\\evp\\evp_lib.c",
        "$JO*j",
        "UTF-8",
        "5T5X5h5l5x5",
        "6=6G6o6",
        "> ?M?z?",
        "hZ{S*J>",
        "yi\"~7:",
        "q KW6C",
        "bO@nH",
        "muF)*w",
        "}cIn3<",
        "C,1CL",
        "^5i]i",
        "5/UIE",
        "/I#yl",
        "zV/G3",
        " T+sW",
        "Q>]1{:}_",
        "(v3h`|",
        ":E;xC",
        "data too large",
        ",!Iv,L",
        "M)`-^",
        "9._]u",
        "<%<+<1<7<=<C<I<O<U<[<a<g<m<s<y<",
        "2 2$2(2,2@2D2H2L2P2T2\\2t2x2",
        "R^Uj ni{",
        "documentLocation",
        "dn7:Mr",
        "1 1L1V1w1",
        "\\f1\\fs20\\insrsid5259060 .}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid2708596\\charrsid15169477 ",
        "!!!!!!!",
        ">H%[4",
        "pd@Nd",
        ":+sj_",
        "t&<-uE",
        "T$|#L$x",
        "0')?Z(y",
        "GMtmF",
        "~9C7[",
        "5Y#vcI",
        "yKC\"`",
        "MM/dd/yy",
        "4<5K5\\5a5h5m5",
        "?$?,?8?@?X?h?p?x?",
        "w:fVT",
        "8ZDQ/j",
        "\">b9.",
        "md-d=",
        "2%2)2/2B2V2_2h2q2z2",
        ".+9'~",
        ":O>Be",
        "E<T6j!Cm",
        "j}h$^\"",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "_GPR?",
        "vuOv+",
        "xR:XM",
        "0)8u(L",
        "9f1;=z",
        "PASS %s",
        "QMu#<",
        "8jX#e",
        "7M/D$",
        "%!O#O",
        "/A=BI'EK",
        "cast5-cbc",
        "fn]%E",
        "4F4{4",
        "PYG.O",
        ":qnlbS?",
        "U`{x1",
        "section:",
        "%sGroupMonitor.dll",
        "OK [UIDVALIDITY %19[0123456789]]",
        "C*RE\\",
        "}6>uh",
        "I;H5^BN",
        ":=gC=",
        "^#(?DV",
        "h>Zw|",
        "D$(f;D$ ",
        "_@]KQ-",
        "0N1V]",
        "PM2\\q",
        "&,mU1",
        "XDCe,",
        "2/*=o\"",
        "6^7c7Y8",
        "!@S3t",
        " JJ5Jj",
        "u9y,-",
        "strutil.cpp",
        ". *_%",
        "/NvJr",
        "message too long",
        "Failed sending POST request",
        "j-2~%P",
        "]D,R,",
        "2'3P3h3",
        "^XLQ<$",
        "streamed out ucp_eps.exe to %s.",
        "[VSINIT] VsNoFileRedirect::s_LoadFunctions: GetProcAddress('Wow64RevertWow64FsRedirection') failed with error %#x",
        "L|8$cht",
        "+R$.X",
        "xhp#b",
        "838@8f8",
        "5-535O5]5c5p5v5",
        "~E2OqM",
        "LGRlq}",
        "CANT_COPY_DRIVER",
        "5YdK6J`h[",
        "LS8vZ",
        "gM+f7{",
        "2.fPd",
        "6)7N7",
        "r;dpt",
        "select/poll error",
        "hmac-sha1",
        "hZ>L@8r",
        "sj^{kk\\",
        ";<;w;",
        "g,oj=9",
        ":h8N{",
        "CZJhH+F8Jx,V",
        "rAru}0",
        "bn-G$3",
        "?C?I?m?",
        "Failed to create registry key for EndPoint Security",
        "<ibDd[~",
        "Al.8{ 9",
        "44/P9",
        "hF'm=R",
        "{Q4#=",
        "c'\"Ss",
        "D$(SP",
        "J{s;)",
        "? ?@?H?P?X?d?",
        ":aU?#r!W",
        "fopen('",
        "I:5iEw+",
        "ow^Ec",
        "141w1",
        "fLR:-<",
        "|Y3C0",
        "kbiHP>\"",
        "S`_9G",
        ":mLl77",
        "!S*H2~",
        "zc+L1",
        "FX_^]",
        "VpHS%",
        "g3Zr'Z",
        "gDPR|>",
        "<!<X<c<",
        "-fmSQ<",
        "iwxRB",
        "O$@)Z",
        "%s%s%s",
        "zt>+~",
        "q*dOiCbw",
        "n;0xf",
        "<*<P<",
        "0\"1,1?1t1",
        "54585d5p5",
        "CMOVZ",
        "aX4CD",
        "u>`]O/uUz",
        "ssl2_generate_key_material",
        "UCOMISD",
        "UW%Q$R-?",
        ": :(:T:\\:",
        "P\"c'!nx",
        "g!k&a",
        "NiFzk[",
        "zg+1!",
        "zl==|",
        "fs>Sr",
        "KjE'w%'",
        "\\0!2(",
        "$MdAO",
        "Uploading to a URL without a file name!",
        "8$9(9,9094989",
        "b49jg",
        "U'6$\"%",
        ">(>K>^>",
        "D1W7f",
        "9|1sT(",
        "C8C\"D",
        "CheckUninstallPassword failed.",
        "5r627",
        "uTU\\.D2",
        "NEK=%GW<",
        "~TR$MS",
        "1 2f2",
        "/==Dy",
        "DPQ=-*",
        "lSU2lvX",
        "jW.qE",
        "\"IYE=h",
        "f!K*:?",
        "+k8^|",
        "n58US",
        " /S INSTALL.LOG.tmp",
        "< \\KQ",
        "fwG'kOG",
        ":9:h:",
        "EIa,M",
        "M*]E?\";t",
        "Jx[iwDLS",
        "_4#3gS",
        ",l`L(",
        "1>1{1",
        "0JHB}",
        ",Pn*x",
        "FDE_OFFLINE_MODE",
        "0-0:0_0j1s1|1",
        ". veh]",
        "X509at_add1_attr",
        "t,epb",
        "o$oCv|_",
        "1o=4o",
        "rNZF9",
        ";R}c!",
        "invalid fill character '{'",
        "9.9G9`9y9",
        "rS&j5",
        "5?6H6c6p6",
        "8,848P8X8p8x8",
        "x^I:hb",
        "!|}'G",
        "8]6$_^",
        "v\\a9n",
        "5WMaY%",
        "7o2SU",
        "n%OeK",
        "8&7rK$.",
        "*+O3T",
        "[*5sS",
        ".?AVCancellationTokenRegistration_TaskProc@details@Concurrency@@",
        "0$0(00040<0@0T0X0`0d0l0p0x0|0",
        "x@P6^*1",
        "|4u$O*",
        "sq-AL",
        ":An@4",
        "fa-IR",
        "&j$0OO",
        "Wxxo+",
        "S =x(@",
        "FeatureVPN _RemoveAfter",
        "v#qb{",
        "/rt%=$",
        "zh.HA-",
        "5i4i;i@i_icNgoisi}i",
        "united-kingdom",
        "T3mA\\c",
        "<'Y>&P",
        "SZ(J12",
        "AES-192-OFB",
        "3C9x;",
        "l!Dj:",
        "failed to allocate target registry string with HKCR root",
        "O`nei",
        "10Nsj",
        "zYB\\1",
        "V(lhd",
        "@ [KR",
        "f$oS|G",
        "'A-,dN:",
        "Spb?X",
        "nxp;[",
        "d+\\/v0",
        "GetTempPathW",
        "#$W9U$",
        "Qh(=!",
        ">,>1>B>H>N>X>]>n>",
        "4.4P4]4g4{4",
        "!W3W6",
        "hMMoK",
        "a'g:`",
        "bceLi",
        "]uzb\\k",
        "{@S`c",
        "|?HTj",
        "*2J:`",
        "securitypolicy/osfirewall/imageentry[@imagename=\"%s\"",
        "!=cZ\"",
        "x$/\\rk",
        "llALsd\"",
        "ke*;W",
        "r?I<t,nt",
        "0(0/0:0V0o0",
        "Dj;S#CtnW",
        "P_9b8",
        "=j!& ",
        "jRQ(xz",
        "~]jth",
        "b6g33",
        "[!fuY",
        "Xl\\5%",
        "K~.Q\\Eq",
        ".p1Ei]",
        "2`TYc",
        "vvKI+S",
        "Xdoi[",
        "Vc-m3/z",
        "H;`OCW-",
        ".\\crypto\\ec\\ec_oct.c",
        "U<GHc",
        "0 1P1t1",
        "(\\^-#",
        "7-777",
        "eNTIU",
        "dpF,s",
        "}i{?#A+b<s",
        "]esy7;6",
        "S[2u'",
        "eh9.H",
        "u2Vj@h0",
        "FBir\\5",
        "UflK6",
        "]^_H[",
        "Jr>W&",
        "L,*^MW",
        "E%68-",
        "7w( =",
        "INT_TS_RESP_VERIFY_TOKEN",
        "6-9'6-9'",
        ".mFN8",
        "yg^wd9P",
        "5 5$5,5D5T5X5h5l5p5t5x5|5",
        "6w,0ns",
        "URL using bad/illegal format or missing URL",
        "fg?@oC",
        "aBq>b",
        "w9(ss",
        "zt=oB|",
        "eWIX_SUITE_SMALLBUSINESS",
        "WuJ\"3",
        "SNLEQks",
        "tf)34p",
        "lqlZ0%",
        "kbu|s2huCC!",
        "GetCurrentDirectoryA",
        "GOhq;",
        "qBs69",
        "tp^E(",
        "%F4<O",
        "iV\\'W,",
        " )u f",
        "y-[^_R:c;",
        "=*M|O",
        ".\\crypto\\engine\\eng_pkey.c",
        "'(J >D*Z",
        "GDse@DD",
        "8E040E57-6AC0-4f49-BC35-E21E40B26C89",
        "ftJMh",
        "!3AI1",
        "GOCwwl",
        "'q$.`Xc",
        "_8`z2c",
        "(L2$Q?",
        "c:X;i",
        "v3C4M%t",
        ":A3%I",
        "y{MZX",
        "PMOVZXWQ",
        "(_^][",
        "FAILED_TO_MAKE_TEMPFILE",
        ">u?{?",
        "u#9 e",
        "gF&I-",
        "w5JR\"Y",
        "<P3`f",
        "lstrcmpA",
        "?RL^VO",
        ")D}yz$",
        "NGmPNiZ",
        "#$1zCy",
        "trac.config.upgrade",
        ">wRx&",
        "jwj#3",
        "**-O&$",
        "id-cmc-regInfo",
        "x45*~H",
        ";oq8}[",
        "!Z^pH",
        "upHz^",
        "pkcs7 datafinal",
        "t$,PW",
        "nw|N43",
        "G7a9^",
        "ZYa-#",
        "iq|E`7",
        "uQyMk",
        "@fUvM",
        "*BOw!",
        "uR}98",
        "USER32.dll",
        "rz8<+",
        "PerfRegisterStateChangeCallback",
        "!X?z;",
        "bHID~",
        "        Serial Number:",
        "+5NS=",
        "V^w=Ft",
        "-_{wL",
        "VLu)E",
        "70$(k%k\"",
        "mV4r0a",
        "t$,VV",
        "2S4[4",
        "<kM&q",
        "v,]rC",
        ">3#fM'fd",
        "c0K)@",
        "<Sn1!",
        "Vi%2=",
        "ndnjn[",
        "=aAJDC",
        "s\\IR?~",
        "CURLSHcode unknown",
        ",4(n4q",
        "\"%s\\Temp\\vna_utils.exe\" -d -ap vna dev remove_ex \"%s\" cp_apvna",
        "------------------------%08x%08x",
        "5?6a6",
        "VhXx#",
        "$tt0H7*4",
        " Mv)!-",
        "VE[XN",
        "(lM0H",
        "bA2wv",
        "e2(0`",
        "Iiw[S",
        "]59.*X",
        "81<1@1D1H1L1P1T1X1z24585<5@5D5H5L5P5T5u;\\>",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid14896606 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 If a defective Hardware Product }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "{z+^O",
        "Xo9wq",
        "(h(Dx0",
        "P%1Ez",
        "invalid universalstring length",
        "crlsign",
        "2F3X3",
        "&$e>B",
        "I V/CE?",
        ":&;2;N;i;",
        "PEo0Y\"",
        "FZr-lda4",
        "d2i ecpkparameters failure",
        "'sqG7",
        "broken pipe",
        "xH!\">",
        "FeatureVpn::SaveSettings: begin",
        "Zt:uF",
        "@U[c:[",
        "~usi=",
        "o`\\zM",
        "\\PSGControlAPI.dll\"",
        "g\"n`621",
        "d.usernotice",
        "tFVW3",
        "X509_REQ_INFO",
        "pThG0y",
        "HPh(C ",
        "O[2z^Xf",
        "qv!1mH",
        "SELECT * FROM `ServiceControl`",
        "FWUpgradePrepare",
        "`kLliN",
        "(ZyTQ2",
        "4S4`4",
        "JqFN{",
        "<\"mv-0",
        "1_WEn",
        "CANT_FIND_VSWRITEKEYUNINSTALLINFO",
        "UPm&6e",
        "CG.%4%",
        "9S@=R",
        "8#8(828C8H8R8c8h8r8",
        "[NlkN",
        "-=-b~",
        ";!?e=",
        "3E3v3",
        "failed to encode data into string",
        "p@xEa",
        "C5\\VK",
        "2P-NZ",
        "terminate",
        "}f.2z",
        "bf#&s$Q",
        "YKBuDT",
        "A4|-x",
        "VQx9_*",
        "5#6:6",
        "zZ6UWc",
        "jJ#iRO",
        "ygwo.",
        "$ (wxNT",
        "HwDj*",
        "?NspMC~Q",
        "CAMELLIA-128-CFB",
        "> >$>(>,>0>8>P>`>d>t>x>|>",
        "/ZKkYHL",
        "2^(%U",
        "W8^.u:",
        "X%)U6r",
        "22F2Y2x2}2",
        "Tz6{$4LC",
        "pdBgu",
        "OpenService failed: %d",
        ":;;h;",
        ";n;x;",
        "7J7r5",
        "]6$tx=#",
        "AEXq:",
        "Wa^|U%",
        ")*=cF",
        "&g*K@",
        "|Y7B;",
        "A3!>.",
        "x|:??J",
        "J(qE_;+",
        "iV!_5V",
        "Dr'vX",
        "_][^3",
        "d}2(h",
        "TL_Pr",
        "</CONFIGURATION>",
        ":x<tZ",
        "%3I64d %s  %3I64d %s  %3I64d %s  %s  %s %s %s %s %s",
        "sect163k1",
        "515Q5a5q5",
        "ya4|7",
        "Unknown exception",
        "wy2u.q",
        "NJlx3",
        "7$7,7`7p7|7",
        "4QI7%",
        "BF-ECB",
        "I[,R1",
        "B4OMbd",
        "t8XO'q",
        "UACUV{m}",
        "Irt.]9",
        "SetSecurityDescriptorOwner",
        "7]I)(T",
        "[{'~}Ck",
        "R2EP,",
        "ZyBCxs",
        "ux+@0",
        "um#lp",
        "$|f*4|",
        "4yK1[^",
        ">C>H>s>x>",
        "=.=P=x=",
        "#AJ8l",
        "@k}a]|",
        "D$xSU",
        "<)$En",
        "f99tN",
        ",wa*s",
        "KbI>Z",
        "whfN4",
        "$\"1$~",
        "'=F\".",
        "j STek",
        "Y|VTX!",
        "<wFDO",
        "!v)Z[",
        "Failed to write client_sub_type with value of 'Mobile' to registry",
        ".?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        "u2hL.",
        "]iDKU_j",
        "RdNoa",
        "3#.H3J",
        "~E4W.",
        "D80<y&",
        "mxEZV1",
        "miFgA",
        "WL>Mq",
        "z-W5I",
        "[:&wo",
        "9Byw*",
        "IR-b8",
        "P 9kq",
        "<5N@.",
        "CG<Tv",
        "9Z:d:",
        "2*3=3P3_3",
        "aF[c]",
        "|Urp92",
        "Heap32ListNext",
        "bm`%R",
        "Oq.w?",
        "yBPH<",
        "wRCe_6",
        "?B(w0",
        "s%92M",
        "=`=o=}=",
        "(^D3Q$",
        "a+hSB",
        "\"]v11@",
        "OrKW/",
        "}2xRU",
        "ZoneLabs\\scheduler.dll",
        "ADDPD",
        ">36Tr",
        "F!I\"WCR",
        "#thIh",
        "'d2bk",
        "808L8h8",
        "WaitMessageToProcessEvent",
        "id-aes192-wrap-pad",
        "1G$Udn$",
        "A~DfX",
        "jBjzj",
        "failed to create NetFwRule object",
        "9dcG'",
        "GQ|P$",
        "B\"$AI",
        "B)>aP%",
        "d{`y+X]@q",
        "n{mhW",
        "RIHJD",
        "fSt,\\",
        "1$1,141<1D1L1T1\\1h1",
        "PPPPPWV",
        "f+XoWyF,[:",
        "i.s0A",
        "U|dFw",
        "\\23cv",
        "hSR%S",
        "f.r8Bu",
        "Custom action was told to act on a 64-bit component, but the custom action process is not running in WOW.",
        "<3=F=]=v=",
        "Q=lel",
        "=I>:T",
        "failed to duplicate input pipe",
        "r[L0}vj",
        "C/\\G{",
        "M<Z!p",
        "mJPIe",
        "2 2(242T2`2",
        "::;I;",
        ",eYKs",
        "+NU=[qy",
        "br&7\"zr\\",
        "J6H:!5",
        " nl>7|",
        "M1N;oW",
        "}0_Z}",
        "SYSTEM\\CurrentControlSet\\Services\\Klif",
        "<>=C=",
        "r@Jmx",
        "X`ovj",
        "5[mNuM5",
        "yW:Tt",
        " INFO/REPLY",
        "7`9d9h9",
        "Z#;0J",
        "h7:6fSK",
        "]}k,D",
        "rjR>L",
        "V7#u?Ii",
        ".Lmw\"3W",
        "D$0;\\$,s",
        ".xdata$x",
        "T)TWK",
        "71.'(0",
        "^]^~[n",
        "S^dVVSSl,W",
        "%fKaF",
        "D's%,",
        ".\\Installer\\",
        "akLM:",
        ")4@79DVcM",
        "=nB]2",
        "`@Y@!",
        "D$,PV",
        "Mn~wF_",
        "jMPN2",
        "&Ny W",
        "HEhnCor",
        "g4E/T",
        "1h>DA",
        "?I|=&",
        "L$h3L$D",
        "`LrEH",
        "5|95;",
        ";&;,;7;|;",
        "@o+FR",
        "banProtection;",
        "a1,2k",
        "oyl\\P",
        "z99\"=",
        "+w)I=K!",
        ".\\crypto\\cms\\cms_lib.c",
        "/Gao|$X@",
        ".0\"$O",
        "DwmIsCompositionEnabled",
        "Response Extensions",
        "]1KxW",
        "1Ix>]",
        "YJ!YxVVXDm",
        "'s9l[i",
        "U1SMC",
        "!X##;",
        "et%\\!C",
        "6r<'*",
        "CRL has expired",
        "7QBY)q]I^",
        "~$&KtOE",
        "invalid pss saltlen",
        "[THREAD] thread \"%s\" (%x) stopped",
        " 0xd3",
        "Failure sending QUIT command: %s",
        "not uninstall case - remove property doesn't exist",
        "~ZQ)<YAK9",
        "Ydi#A",
        "tV\\-R~:",
        "t$ SU=",
        "?<~H_",
        "BMBiI",
        ";j:*afa#",
        ")~<Cx",
        "{$|VD",
        "3t$8!",
        "G{Dr.",
        "En3<d",
        "EJ3RF3",
        "R^BD*",
        "@&RHIQ$ &B",
        "=#=X=n=|=,>u>",
        "qCeBf",
        "%*sFull Name:",
        "ufJL|",
        "%R;Fd",
        "q+@CT",
        "SYSCALL",
        "SetMemDump:  SetMemDump finished.",
        "COMPUTE_KEY",
        "@c2,i",
        "A'}9!Z",
        "= :\"7 ",
        "hBACC",
        "w)Bd}",
        "<,IfW",
        "0]xQY",
        "z$$(F",
        "]wjR-X",
        "..;\\'?",
        "Found cached Check Point VPN installer",
        "$\\=/P",
        "ITHER CHECK POINT NOR ITS SUPPLIERS WILL BE LIABLE WITH RESPECT TO ANY SUBJECT MATTER OF THIS AGREEMENT UNDER ANY CONTRACT, NEGLIGENCE, STRICT LIABILITY, OR OTHER LEGAL OR EQUITABLE THEORY, REGARDLESS OF WHETHER CHECK POINT }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "\\(l+3",
        "KNhc-",
        "%5|Z6",
        "&u;Ec",
        "4@z5Rw",
        "wW6uF",
        "8DUZt",
        "\\ 1D_I",
        "<H7b2y",
        "Insert VsmonDisabler",
        "7H7av",
        "Wm-X}d",
        ">II!?",
        "7{V'Uy",
        "GetCommandLineW",
        ".H+c'",
        "-wlFY",
        "~BJ:a",
        "hjD7v",
        "MsiPropertyEx %s=%s",
        "IYP=Q[",
        "Mcypm",
        "6E#T\\",
        "!{E@H|",
        "Gk8#Y3",
        " 0xaf",
        "7W`Mb",
        "@p*y_e",
        "#P3+l",
        "MajorVersion",
        "(?R.g]",
        "= =.=K=_=i=y=",
        "i1\"}.[",
        "J1ef;",
        "[2<Rv#)",
        "F:]M'",
        "#o6L]5",
        "A '[l",
        "**DZA",
        "-C!+q",
        "CRn>G",
        "api-ms-win-crt-stdio-l1-1-0.dll",
        "5\\*j_Y",
        "QDS~7qB",
        "p(F.o",
        "C^?na",
        "<yWi^-",
        ">3nGJu",
        "u9dM3",
        "@=wWc<",
        "V\"$9w",
        "U?D<\"",
        "SECURE_REMOTE",
        "3L4Rvkb",
        "?`,Kiu",
        "hbIx`",
        "3%424P4o4",
        "*<sLR`T",
        "=J=}=",
        "nG\"/d",
        "N5135",
        "-vM9[VM",
        "Jtb^{",
        "Error: ERROR_INVALID_HANDLE (%s section)",
        "qGT@h",
        "Op\\Oh=",
        "CreateUmsThreadContext",
        "SchedSecureObjectsRollback",
        "2k2K3",
        "0yr)kP",
        "?\"w`l.G",
        "`dCh\"\"",
        "v!JtyN",
        "VSInstallerCancelEx: failed to load vsmonapi.",
        "!oakEz",
        "-W@hi",
        "'!?t3",
        "l.0Mh",
        "606`6",
        "xBr5y",
        "I%u# ?",
        "tz6I:$",
        "5H0]FF",
        ".\\crypto\\ocsp\\ocsp_ht.c",
        "InstHelper.exe: StopCiscoVPN",
        "=WK#-",
        "pR@_K5",
        "B=<#uf",
        "CreateZoneAlarmXml:  CreateProductXML failed.",
        "jkjdj",
        "<+<7<[<e<",
        "rQH693",
        "EC_POINT_copy",
        "6'646d6",
        "cD[gq~",
        "l <= sizeof(c->iv)",
        "Aj4E0",
        "DI/jP",
        "?T*X0",
        "F-n^d5",
        "3#j {",
        "q@r=[",
        "TempDir=%s",
        "Rx:%k|",
        "BCryptOpenAlgorithmProvider",
        "4`5t5",
        "888X8x8",
        "Optional image header truncated",
        "Fa:$eo]S",
        "C\"F2F",
        "@&B:WU",
        "ctBQd",
        "71dTA5",
        "regedit.exe /s \"%sScvProxy-32.reg\"",
        "^AL/H",
        "no control function",
        "zY~TB",
        "858n8",
        "=//,4Gg",
        "<*,i)",
        "SRqDIK",
        "~4\"kQz? ",
        "%SJSJ",
        "dPKb(",
        "point at infinity",
        "no receipt request",
        "9'909A9P9W9",
        "Ozn`{",
        "y_,DQy",
        "JC4:gD",
        "[A37L",
        "!W\\Z ",
        "jXhX=%",
        "~ui<uN",
        "iYJf.",
        "*-z#=?",
        "s(h\"'r",
        "'?!K$Y&2",
        "\"%s\\UINotify.exe\" finish",
        "scfUC",
        "BI\\.{",
        "[!0uD",
        "D$(PPS",
        "._kRc",
        "qv#,|",
        "]Jm;I",
        "OnFreshAfter started.",
        "\"#n0K",
        ".?AVruntime_error@std@@",
        "8)8F8~8",
        "-----BEGIN %s-----",
        "PAzHL')",
        "9gHYe",
        "Qf H,m",
        "ox7LI",
        "FQ54\"",
        "EC_POINT_get_Jprojective_coordinates_GFp",
        "B{!'8",
        "NrJV3",
        "H=H).hWt1}",
        "kzg&1",
        "cptmsender.dll",
        "PjdJn",
        "SbUk7md|C<p",
        "~E,u-?",
        "\\$$QP",
        "kV!DA",
        "uSb{-c",
        "ap]w5uQ",
        "HhvUM)",
        "QgsP>\\",
        ";8<t<",
        "xaMp9",
        "?SX>|",
        "I3c}Jc",
        "t4Ex/",
        "g]fxMa|",
        "Unable to receive initial SOCKS5 response.",
        "@yQ?d",
        ",}f2F",
        "77zw<~",
        ";xm(t",
        "ARkEr!x",
        "8^(@&t,;f",
        "n!rvAI",
        "-eg `=",
        "1wv=zQ",
        "`jsgAB",
        "Zt&,J",
        "\\DrF&",
        " /dq.",
        "@J8>x",
        "a,gYt",
        "tcj]hp*#",
        "TrScvStub.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "4s<dY",
        "bad block length",
        "_^4#nx",
        "6lV_(",
        "0Kma(",
        "SEC_E_INVALID_HANDLE",
        "XCYV1",
        "StorePropForDeferredCA starting.",
        ",,?mB",
        "add signer error",
        "gw&mt",
        "key usage does not include digital signature",
        "kPqRF",
        "M[`vSB*X",
        "vA4sR",
        "PREFETCHNTA",
        "g+mTU",
        "ot}r(w",
        "~]:za6",
        "eK+uN}=p~",
        "$Fm`XR",
        "A,_62* ",
        "=6nj ",
        "')=EXg!",
        "`%H]k",
        "hBOro",
        "SystemTimeToFileTime",
        "?;?E?W?^?d?",
        "ban protection",
        "ndv$[",
        "Pn29<X",
        "K}`RUQt",
        "=<XdE",
        "{MBvq",
        "y7{g$U",
        "setCext-cCertRequired",
        "]?)((z",
        "_seh_filter_exe",
        "\\7I 3",
        "x|qCx6",
        "EVP_PKEY_CTX_dup",
        "/?6,I",
        "a!+(P",
        "MZvfV",
        ",_D.%",
        "xc{L(",
        "f#Fi&",
        "#).Sho",
        "8V9]9i9w9",
        "\\'02\\'03.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li2880\\lin2880 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713",
        "?C*_z",
        "y9!=a",
        "9_;wqc",
        "A()bU",
        "3)3E3",
        "QV<XoI1)a/#z",
        "9,909@9D9T9X9h9l9|9",
        "b2,pU",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137 Hardware }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 Product into the {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States}{",
        "9QMK]k",
        "UNINTERRUPTED OR ERROR FREE. CHECK POINT DISCLAIMS ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. Some jurisdictions do not allow the exclusion of implied warranties or limitations on how long an implied warrant",
        ")U6)Rq1J",
        "DIGEST-MD5",
        "?\\u5=xh",
        "0Y\\.Nk",
        "^s{\"r",
        "t\"4d7o",
        "2RyXO",
        "MailFrontier",
        "_strnicmp",
        "xK&JwF1",
        ":z0{gGi?j?l?n?p?r?t?v?x?z?}?",
        ".Fh%/",
        "Xb\\6I",
        "\\XQo67",
        "Z'ld{",
        "VQbP$=)",
        "t[USS",
        "P1Z1w",
        "{FB5/j",
        "\\W|x#",
        "~Iv v0w",
        "fn^ 4",
        "cK#nK",
        "=Jqk2d",
        "jijij",
        "x@[F7",
        "(~@D%rH",
        "\\par }}\\ltrpar \\sectd \\ltrsect\\linex0\\headery708\\footery708\\colsx708\\endnhere\\sectlinegrid360\\sectdefaultcl\\sectrsid5585452\\sftnbj {\\headerl \\ltrpar \\pard\\plain \\ltrpar\\s45\\ql \\li0\\ri0\\widctlpar",
        ":uR'c",
        "n$h08",
        "]g!dH",
        "Eh1=T",
        "uHOY7",
        "MEymZ",
        "H|X%?",
        "&v?6[",
        "failed to get condition from WixCloseApplication table",
        "w1Twx",
        "0.1F1L1",
        "U'eIlD",
        "tba}pS6",
        "tQ8c`",
        "4$565",
        ">\"_h\\",
        "=+U]i",
        "clY[zG~d",
        "R!q]RZ",
        "0_!]\\",
        ".B-Tt",
        "0k(]%]=/G.",
        "zw\\y%hc",
        "CkS;\"",
        "=3KrM'`o",
        "}<8NE",
        "kzPB7",
        "\\Fl%Q",
        "OnInstallDriverFinish",
        "B,()9",
        "UpA,YGf\\e",
        "VMXON",
        "0M0_0x0",
        "3D4R4u4",
        "c,+/+",
        "BYAwgtC",
        "jAjfj*",
        "utf8only",
        "nCONOUT$",
        "\"+CzM",
        "13pP%m",
        "{7e9$",
        "Ex\"=D^E",
        "`h?U_",
        "failed to add target data to CustomActionData",
        "?&x*O",
        "l2JB];",
        "a5)\"OA",
        "Uf!^HWVU",
        "Kgn^P",
        "Jr^~I",
        "oP+<e",
        "Pb'j ,",
        "qboq{",
        "!q\\n<*",
        "'8U*i",
        "uA!ds",
        "3,N)\\nc",
        "RK:4Jh",
        "T~rxe",
        "FVU(x",
        ">#>'>+>/>3>F>c>",
        "pWmPZ",
        ")PM~9F",
        "invalid command line property value",
        "StopRemediationService_rollback failed",
        "tCfff",
        "<X[Vm",
        "H\\%;bz",
        "4*434{4|5",
        "EE>kh",
        "a@E8*8",
        "}?l=PyL",
        "me@$A",
        "\\I7v\\",
        "Failed to run MsiGetProperty to retrieve DEAFULT_VPN. Setting to EC as default.",
        "d\\8u<A",
        "n\\4Vh",
        "?,?<?H?h?t?",
        "9!THS",
        "IP?qe~",
        "LRZ8sy",
        "7C7Z7i:",
        ";O;v;",
        "r/q)p;",
        "\\$LUV",
        "d=eQdC",
        "tjj_S",
        "%\\%l%|%",
        "+[K!-#",
        ";O<h<",
        "jLUZ@",
        "!)P.FM",
        "wwwwx@",
        "%*sPolicy: ",
        "jE^%D",
        "d+4iH",
        "DZ[2R",
        "hn0jRJ#",
        "RestoreService failed - service not found: %u",
        "M<MtM",
        "e_:Gs",
        "9':,:3:::A:N:W:s:",
        "ny)(;",
        "7T7p7",
        "1Zrh92E",
        "\"RC_%",
        "6B^K@",
        "Ro3L_",
        "%VWFr",
        "minkernel\\crts\\ucrt\\inc\\corecrt_internal_strtox.h",
        "JLIxb",
        "KlqtA",
        "4QK}3%B",
        "PWh~.",
        "L4VV^2",
        ">=r+x#",
        "Ph`m#",
        ")Wg2f",
        "jRA(b<",
        "/PSN.T",
        "cjkSs",
        "`template static data member constructor helper'",
        "'npFSx(",
        "x~KLV",
        "+mK-L",
        "x~}a}",
        "]n4s{7",
        "fs3b#>",
        "[9lR:",
        "fvbf9,",
        "W{v93",
        "<YpE#",
        "t$,PSh",
        "?4?d?",
        "2\"272<2",
        "EdA\"#",
        "=`d~ ",
        "yyzIr",
        "hnc<Jd",
        "T^-{G",
        "`+'[X",
        "m?jx-",
        "provide parameters",
        ">t^#RQ",
        "jfGGa}Cs",
        "[VSDATA] ClearOrphanedPrimaries() denied.",
        "Kf,TJ",
        "<(]qc",
        "81(Gi(P",
        "h8b5$m",
        "+zyU4",
        "_5r*O",
        "&O,wBIZ8",
        "Y]9v+",
        "*BS`qi",
        "{/Lhz",
        "}yw![",
        "?W=XY(",
        "<H<h<",
        "< =b=",
        "]zM_m",
        "1 1$181<1P1T1h1l1x1",
        "9C1ug",
        "L'7~r",
        "J_\"#bJ",
        "gM1'Dj",
        "9A9J9",
        "GuR\"F",
        "F:\\ckp\\src\\cpopenssl\\E86_20/preCMpub/ssl",
        "Zdl8UB",
        "D3DX$2tZD2",
        "&#\\gi",
        "k4&+lM",
        "$`JpJ",
        "|VJQiPA",
        "o@uiID",
        "VsDataInstHelperOpenDriver - DeviceIoControl(DIOC_HOOKALLOCATE) failed. Err=%x.",
        ")E99A",
        "+V_T|",
        "\\nqwJ`r",
        "ce;'M",
        "u#j,Xf;",
        "+cC[N",
        "wrong protocol type",
        ".?AV?$clone_impl@U?$error_info_injector@Vjson_parser_error@json_parser@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "t@jUh",
        "}qv>_",
        "f$iPi",
        "3L$H3L$<3L$,",
        "x;yBO",
        "3r:K^u",
        "BN_mod_lshift_quick",
        "ScheduleReboot",
        "m9n9o9p9q9I",
        "R6028",
        "[,DkR",
        "\\)OzG",
        "2V_0!",
        "\\Check Point",
        "W^0B1",
        "n}H]2=",
        "50LMf",
        "q/IMN",
        "C9OOk",
        "Y3'SeP",
        ">\">->8>P>V>\\>j>p>~>",
        "4(40484@4D4L4`4h4|4",
        "upload completely sent off: %I64d out of %I64d bytes",
        "iF]OQ",
        "a;stb",
        "VQy'xR",
        "9*a6b",
        "]*J3T",
        "Ny*^j",
        "*$+4+d+",
        "@>qj0",
        ":+9nTM",
        "eaq[rtq\\",
        "/P6no",
        "OjGG$R",
        "<y9vF",
        "MMfU33",
        "Selected Attribute Types",
        "USVWW",
        "I7vOK",
        "];i}sM",
        "\\zonelabs\\vsdb.dll",
        "IS;8hU",
        "#j1ws]L",
        "-iafa",
        "S\\Z-1>]",
        "0,L^l0-",
        "6d7:m",
        "bTq_]M",
        "createLocalCatalogXml;",
        "hE2uD1",
        "^Zbk0",
        "#8I&o",
        "cy$ZH",
        "CreateFolder",
        "rgq@d",
        "V$g}`U",
        "-z2_=",
        "J3`!30^",
        "TH:2]p",
        "d1JF0",
        "Received ACK for block %d, expecting %d",
        "zpeng25.dll",
        "5Yta9x",
        "+n45[",
        "tc=\"\"\"",
        "=4sHPh",
        "4+4k5",
        ",Y]HpF{",
        "Aim`u",
        "R/$_I",
        "jyjuj.",
        "]IXkd",
        "3%3.33383T3z3",
        "#'VXA",
        ",R)qG",
        "verification failure",
        "=3=L=e=~=",
        "7VVDS",
        "s`uz8",
        "qYp@s",
        "failed to schedule ExecXmlFile action",
        "hr4&e4(",
        ":!{N c84",
        ":Y;v;",
        "_8#xV",
        "{7y8$",
        "Nxab~",
        "=2RNQ",
        "rXa3K",
        "t>XCA",
        "%Y|)v",
        "N#GjcIz{Y",
        "|yYY:",
        "t[,xcNt",
        "V-j<os",
        "BeBS-t",
        "VY<\"f",
        "0y,F;",
        "rSn#Z'{",
        "xWI88(",
        "h^wc5/",
        "Fu8 +",
        "'RIAT\\%Q",
        "@Dn`ATo",
        "oDRp\\",
        "L$$_^]",
        "T%:9w",
        "sv/lVWYM",
        "<S a2",
        "`{q&<",
        "l$ CU",
        "oMm$M",
        "WS2_32.dll",
        "M\\EMy",
        "aG-/,",
        "<8<P<\\<|<",
        "I?K.)",
        "Ff 8a/",
        ";}r5}*>",
        "B RUm",
        "CN?!m",
        "VT78l",
        "/GM!NX",
        "\\ZRg0",
        "6Ht\\W",
        "TIM|q",
        "nGyIgd",
        "oP/Wte",
        "5'5,515I5a5f5k5",
        "CA1/(ri",
        "3rjqj",
        "}?tN]",
        "<w@yP",
        "L2MC ",
        "vgW\"}",
        "9):x:",
        "/]L/&",
        "EC>a ",
        "?qe*T",
        "?E||\\",
        "0 0n0",
        "s6FUc",
        "5#5A5Q5[5z5",
        "Build Number=928037003",
        "*XqI>Q",
        ")(su\\s",
        "hqMi\\g",
        "DATABASE_CORRUPT",
        "y\")mC",
        "Zd{PaM",
        "rvT^{q",
        "=xDd/",
        "j\"k9Uq",
        "$h99M",
        "%K:4/",
        "#Epls",
        "Ux[Q|4",
        "CRolloverMgr::TruncateLog():  unable to flush log file",
        "g{}3=#",
        "  </trustInfo>",
        "7a4|}",
        "<iiSR",
        "8,:|da$h",
        "9i:$;.;e;o;",
        " BYP\\",
        "wrong number of key bits",
        "j0h0?",
        "E%@2p)",
        "ZEPV4H>",
        "`ov)B",
        "wUI4k",
        "73p\"u_",
        "|{S,Q*",
        "L$,QW",
        "62H2e2",
        "q7.*$",
        "l~x6wS",
        "\"dkY1",
        "11G).",
        "Plugins::UnregisterFW:  Unregistration failed.",
        "f9B@u",
        "Op30z6",
        "p/9Yr",
        "8!Zy.",
        " &RLr",
        "z==Gz==G",
        "W}ta1g'",
        "N}?]&d",
        ".h',B5",
        ";b;)<@<",
        "ZtnlI",
        ";/j]z=T",
        "oAh5n",
        "32CJopq",
        "f&9H\"H",
        "#6q( ",
        "z=L[AZ",
        "PeekNamedPipe",
        "JMWF@cw",
        "vEsx.",
        ".^s)e",
        "CertGetNameStringW",
        "nbNPUh",
        "sq6oNL",
        "sK *o",
        "\":,|})",
        "}AUqa",
        "eF=.=t",
        "6hN`*",
        "GetFileSizeEx",
        "OixA\\=q",
        "{L+_5.",
        "=TH1y",
        " set CLIENT_SUB_TYPE to %s",
        "5^jn$w",
        "T)4TQ",
        "9I:m:",
        "L$8QW",
        "tK+]Uw",
        "ORNJSyI",
        "{KO5B<",
        "/8/D*f*U",
        "S:ix3",
        "ZuAz$",
        "4-J6,/",
        "qlHhGp,}#",
        "cR=~H",
        "G(sD,",
        "jljmj",
        "LFzRL",
        "scvprod_lang_pack.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "td8tS",
        "@=BR[",
        "$eK! ut",
        "FCOMPP",
        "E4{!Z4",
        "D_b\\o@",
        "P.5ZZ",
        "p^xT ",
        "bnjuh}",
        "jmj}j%",
        "3(30343@3H3L3X3`3d3p3x3|3",
        "<S_tArH",
        "\\If$>",
        "3<3f3p3",
        "7 757",
        "lfb`$g",
        "1-2:2K2U2e2k2t2{2",
        "uninstall",
        ">.>J>f>",
        "O0t(U",
        "2B`%`",
        "failed to schedule firewall uninstall exceptions execution",
        "\"B8EB",
        "u!i:h<",
        "bejZi",
        ",qdke",
        "jZz:CM\"",
        "UXXq)",
        "dTd[P^",
        "`H5.W",
        "6S}7O",
        ":]6CL",
        "up?T~",
        "URLFUninstall",
        "v9)T)",
        "X22X(~",
        "vaK(3@",
        "FV|FgUV",
        "*c{G<",
        "jkjqj",
        "OSKR6",
        "\\bin\\SR_Service.exe.delete",
        "/~*,j",
        "v9#t.",
        "jCrl(",
        "X8Vv\\K",
        "0Gr>v",
        "?$?/?l?",
        "r5#zJ[l",
        "a;aLR",
        ".\\crypto\\engine\\eng_init.c",
        ":L;^;p;",
        "l-5Fp",
        "]s5?I",
        "</firewall>",
        "cT@S0m",
        "CANT_SET_REGDBROOT",
        ">xG[#",
        "Y[Nkw",
        "RWZ;\"",
        "failed to read shortcut attributes from custom action data",
        "xJeX@N-",
        "DES-EDE3-CBC",
        "8 8@8`8",
        ")B< r",
        "F\"@aU",
        "T+:X[",
        "ezFeO",
        "x]!!!1",
        "\\NTUSER.DAT",
        "xG;)QhNK",
        ",dvBp",
        "uWj.h",
        "[ZNqd",
        "[T\\azb",
        "2F2S2`2",
        "q<q)k",
        "4%40494L4S4c4",
        "}Um^V",
        "dg::[",
        "0D1N1k1|1",
        "UVWS3",
        "5Yq!C",
        "[<t@e.",
        "TjM$w",
        "W]|7gQ",
        "REINSTALL: delete KAV drivers for repair",
        "2\"2)202:2E2P2[2f2q2",
        "#39\\}",
        "|2Fe\\E",
        "h1;ddF",
        "=x2;~",
        "l:m,F:",
        "yVaEVv?",
        "[!=2-\\",
        "i4HbN",
        "(AB!OZ",
        "c8E>&E",
        "\\\\lgJl&",
        "tUkjO",
        "t$4Pj",
        "kNX]4",
        "oid_section",
        "-2>2D2P2W2\\2}2",
        "{\\listlevel\\levelnfc3\\levelnfcn3\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid853851628\\'02\\'00.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\cf1\\fbias0 \\fi-360\\li720\\jclisttab\\tx720\\lin720 }",
        "|bvnN",
        "'!((:A",
        "h+XIE",
        ":$:?:I:T:^:i:s:~:",
        "^t:/m",
        "2:2V2r2",
        "00-00-C5",
        "ORV$Q",
        "484Y4",
        "TYIx_z",
        "OZH#.",
        "}QpOz",
        "N=>|;",
        "Hk0*n",
        "!X\\vt",
        "--~-(",
        "ENGINE_cmd_is_executable",
        "Failed to run MsiGetProperty to retrieve INSTALLDIR. Do Nothing... ",
        "IpL=}",
        "A:@,:",
        "AcTl~m",
        "}`u5,",
        ".\\ssl\\ssl_ciph.c",
        ",!B-#p",
        "Kd8eB",
        "WixCheckRebootRequired",
        "w'd'U`",
        "r nJ.",
        "5,51565Q5",
        "5Ly91",
        "J[cW6",
        "r Up'",
        "PUVkq",
        "dingo_install_mode",
        "fYgDa",
        "<'=S=",
        "8,8V8Z8^8r8",
        "9JtDg",
        "^GWM+",
        "*rQn~",
        ">o0CSb",
        "'S)XR",
        "wdKzb",
        "<2>0b",
        "Bad content-encoding found",
        "+e@y1",
        "D{RpF",
        "e6 _?",
        "AcquireSRWLockExclusive",
        "^=mT3",
        "\"|?yp",
        "x/qcV",
        "t$(VQ",
        "= =$=,=@=H=\\=d=l=t=x=|=",
        "8=8R8b8o8",
        "0#0.030Q0m0x0",
        "V4WUdv6e",
        "L$ VQ",
        "uRuf*5",
        "_O8|B",
        ":{n~V",
        "cpepmon",
        "DeleteFile:  file not found ",
        "%){(R",
        "[c^Z~",
        "|P@Z5",
        "lUV\"{",
        ">l\\F3\\",
        "OPTIONS",
        "7<7D7L7T7\\7d7l7t7|7",
        "I|Rom",
        "=8=tm",
        "v~;h2",
        "D FTP",
        "j34;}",
        "`InDj",
        "rR@*AC",
        "im&]P",
        "=6^_l",
        "8^EmB",
        "e\\of9",
        "s,eGnzd",
        "$$Hl\\\\",
        "k/73f",
        "SHA-512 part of OpenSSL 1.0.2h  3 May 2016",
        "=/=?=f=v=",
        "DSO_free",
        "Bad tagged response",
        ":,;6;@;Q;^;e;q;",
        "AES for x86, CRYPTOGAMS by <appro@openssl.org>",
        "j/imI",
        "4\"404M4t4",
        "8,/<(W",
        "[WinFW] GetWFStatus, failed to create INetFwMgr, error=%x",
        "Uaoq;k~]>b",
        "+bzvp\\",
        "2;8)<",
        "}U|e|",
        "r|-a ",
        "t#=DDD",
        "F7Na1",
        " I)b;",
        "6,777T7_7{7",
        " @!Ht",
        "9kN5](",
        "XKXiU",
        "&].|.Y",
        "}gZki",
        "4~Sbo",
        ";#;Q;",
        "+Uq'G",
        "}*J:z<",
        "<SarI/",
        "^EHFxE<",
        "3$3(383<3L3\\3`3d3h3l3p3t3x3|3",
        "tW6%M",
        "]:3u@",
        "4mtXD",
        "Qx&|XB",
        "b%%X\\",
        "rGR'N",
        "d.=)*.",
        "tO95t",
        ")WSrb",
        "empty srtp protection profile list",
        "=+OeO",
        ">2(Bp",
        "+xlQi",
        "A|R#=",
        "\\7%{-",
        "'+S02p(",
        "7\"VuE?",
        "u|~ a",
        "\\CheckPoint",
        "&!Ldj",
        "H8l+,",
        "V\",Z+x?4",
        "2 3.3<3Q3",
        "RYK;Lv",
        "WQb[V",
        "1m*dw",
        "L1E`V}",
        ")L1%J(",
        "{^&3&",
        "M~d6l",
        "DssjT",
        "Ohxz33",
        "&3MFu",
        "KDF failed",
        "R#AgEVL",
        "9x9*C",
        "B #*)",
        "6.7d7",
        "saving data",
        "=g!Gz",
        "Qeou)<W",
        "_zZp|a~",
        "TmCn9",
        "x<QLT",
        "#P&)t",
        " qEM:A",
        "qt?:uc]Sk",
        "%YnMY",
        ">c<0W",
        "$`Wc{",
        "ufMlc",
        "Ni$/gA",
        "$}~&g",
        "141>1V1h1",
        "ImportTablePatch('%hs', '%hs', 0x%x, 0x%x) - no import table",
        "):Wvs",
        "'i=z&7o",
        "]r;rGLVp",
        "b@sI\\",
        "@cCjVc",
        ";4<<<L<w<",
        "yDVC3",
        ";=;c;r;",
        "3a5!69",
        "z_F((",
        "vM7bO?",
        "|j:z^?V",
        "`P?~_#",
        "DSO_bind_var",
        "A=\\&RHyN",
        "9!yU(",
        "CM<S6e",
        "2F3T3]3",
        "%GiyW",
        " y1&q",
        "u->>rl",
        "'mT}--",
        ":f;k;};",
        "1Rxhk",
        "7_^][",
        "@,A\"#",
        "S~$pQ",
        ";D$@sV9l$",
        "StopTEService_rollback finished.",
        "0\"090h0",
        "yFPklu",
        "jwYY9P",
        "u^;~bMg",
        "%c4zh",
        "prime256v1",
        "3\"3,3V3y3",
        "m2E(A",
        "2 2$20282<2H2P2T2h2l2",
        "*FTZ.",
        "(0hAXtq86",
        "Failed to get previous size of property data string.",
        "rE11z",
        "Sll0K",
        "ASN1_OUTPUT_DATA",
        "%%D]}",
        "d~y`Y^",
        "ASN1_SET_ANY",
        "ADD_CERT_DIR",
        "VUX-S}jM",
        "MHoJ/",
        "1<1H1P1h1p1|1",
        "GetPrivateProfileStringA",
        "3[/B].",
        "4Q4t4",
        ":S7_m",
        ".?AV?$string_path@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@U?$id_translator@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@property_tree@boost@@@property_tree@boost@@",
        "OLEAUT32.dll",
        "\\&p.Q",
        "9%N!a",
        "DK2<eY`",
        "8SA2i",
        "LfW /L",
        " 9v[Pt}",
        "/5bvd",
        "ENGINE_set_default_string",
        "><?p?",
        "Z,8o2",
        "Configure vsconfig.xml to protect AM E2",
        "j-Xf9E",
        "uSI-]",
        "646<6H6h6p6x6",
        "QpGEB",
        "9_EJ*",
        "Vh : ",
        "?#?(?O?v?",
        "=d/O&",
        "i?A)rv",
        "realm",
        "=F=d=|=",
        "Q!\"Y0R2",
        "(U`%`",
        "JL0NP0@D4",
        "umf]F",
        "zk}>L",
        "c*[cM&",
        "9y/!q",
        "~S$ugc",
        "ei_9I",
        "c3#iz",
        "=/D0f",
        "o`-tU",
        " U4I7",
        "PKt1 ",
        "'_&mnL",
        "i 8G}",
        ",0M)M}",
        "Q7Pc6",
        "`!vBX",
        "VjNhD",
        "0#.Hp",
        "5Z6%7",
        "\\vsdata95.dll",
        "KLfe0",
        "FWSTARTUP",
        "Q/u4CO",
        "*;C-+",
        "=%=.=3=9=l=",
        "sm;w(",
        "7;n+=.",
        "8(8,848L8\\8`8p8t8x8",
        "]5XOeA[",
        "precision not allowed for this argument type",
        " `|QG",
        "Q'xsb",
        "}{5QA",
        "G)L&2",
        "L$(_^]",
        "y%U,A",
        "+&s6n",
        "R;<2.",
        "Ncfj/",
        "3%1 8%",
        "R|w#Pc",
        "bIThh",
        "8$u*9",
        "g %sM",
        "NAm*:S",
        "d|f[>",
        "bc^`j^egilnpsrvxz",
        "[XA+,",
        "KD[DkD",
        "_wcFuk",
        "4f-Sx",
        "dYhpco",
        "DMC(=",
        "X~w0 ",
        "hhc=7G",
        "\\zonelabs\\qrsrecl.dll",
        "read error",
        "Ph0e!",
        "j}p#f^U}Y",
        "`{2J,q&:.",
        "~Qb =",
        "Checking version to avoid a downgrade.",
        "Enterprise 2015 LTSB N",
        ">4><>D>P>X>",
        "5 6@6L6l6x6",
        "N+i(a",
        "?#?2?",
        "3D){7",
        "3 3'3c3",
        "Gwb]\\",
        "A libcurl function was given a bad argument",
        "M$3H43T$h3L$l",
        "r8$j:J\"",
        "9F:S:o:",
        "i(uy[",
        "v(qj/s",
        "m{nH+",
        "QR-d/",
        "#u_/B",
        "__pctype_func",
        "63j~:",
        "d2i_ASN1_OBJECT",
        "d`TBo3;9",
        "4Y6^6",
        "pOLf,",
        "i,+\\B",
        "7RV2-",
        "\"%'x<",
        "&z*Lt",
        "#0Kb3-S#*",
        "(cKS3?",
        " WRF-",
        "\"-Jzgu}",
        "6#6@6T6Y6^6y6",
        "CRL Sign",
        "4&4C4T4i4n4",
        "l$4VW",
        "404L4",
        "ssl3-md5",
        "NtC8&\"",
        "Oq$l~",
        "._csx",
        "=K#uO",
        "t(_^]3",
        "CVTTSS2SI",
        "D$(WjF",
        " o#~Z",
        ";=;D;c;",
        "v6nSv",
        "tV/}s",
        ".1 doesn't exist.",
        " 0xa8",
        "{q^K/#!{",
        "@bdLa",
        "''(BMhA",
        "7X8x8",
        "3yI@K6",
        "%S>+@=",
        "i{ObI4O",
        "PbW`>U",
        "#BsPG",
        "zifxDDEZ,*",
        "[*** LOG ERROR #%04zu ***] [%s] [%s] {%s}",
        ">E?]IU",
        "ppBasis",
        "/L)xn",
        "S7b7l_",
        ".?AVinvalid_scheduler_policy_value@Concurrency@@",
        "%*S1u0",
        "6o95e",
        ".E~'`",
        "vhJQgD",
        "registryfile.reg",
        "*\"ac}",
        "0|b`c",
        "}\\w:(",
        "3PTpO",
        "nEI~O",
        ":C;&<r<",
        "tXa+K",
        "yB@s\"-",
        "&&)TK",
        "2i3I> ",
        "]6ndun+",
        "G%|-@",
        "E!pr%]%",
        "quZYB_5",
        "6(6T6`6",
        "=U>]>v?",
        "KSc]7",
        " 0x7b",
        "F`$QM",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "vv5en:",
        "J2QPv",
        "#ININ'",
        "OnUpgradeAfter: ConfigureClient",
        "WhR=Uis",
        "3S2-Mg",
        "WW;5& D",
        "2uKKg",
        "9@:H;",
        "QPVpd!b|",
        "Fa(-K",
        "*G]<u",
        "failed to write exception profile to custom action data",
        "R9`7P",
        "2<&0&",
        "2Z2e2",
        "C#D+1",
        "D$ WP",
        "F11-L",
        "3Nu*c8",
        "c7iXe{9Zg",
        "1P1X1`1p1|1",
        "2x|C_",
        "#|geT$.",
        "pJ{4,i'l",
        "?_1%R",
        "CBDYS<|K",
        "U_MyW",
        "[?kC\\K",
        "application/pkcs7-mime",
        "VS7&/~",
        "k `])",
        "8$80888\\8d8t8|8",
        "&JKQU",
        "tVr;Z",
        "b89zga",
        "X|$3Y",
        "l3!-Y",
        "!^\"(D",
        "E#\"}d",
        "F+v.Ll",
        "{_=x>BX",
        "}?cQg",
        "o[7!i",
        "m/gO+",
        "c:,ii",
        "D$,VPS",
        "c:7.X",
        "image/jpeg",
        "707L7S7",
        "OBFPO=",
        "y#aQ+",
        "L$@Qj",
        "0}09a",
        " }y(a",
        "pVylhI",
        "DbO'MeY9",
        "RmnN`",
        "NORTELICON",
        "iqAs/",
        "OnRemoveBefore started.",
        "s4s6s8s:s<s>s@sBsDsFsHsJ",
        ")V<qS",
        "bd^`=1",
        "(Nas3",
        "failed to get shortcut directory",
        "5`%Vj",
        "YMJ~(",
        "OqN%B",
        "SDz1D",
        "0N0z0",
        "j$8+/",
        "X#\\p2",
        "eLDmq",
        "X509V3_add_value",
        "1C_1-X9h",
        "ziFxI",
        "n_F0'",
        "y-^n$",
        "BTvwVg",
        "vHxgsn",
        "J9TE^",
        "1M2g2",
        "j'QXN~",
        "5aP2Um",
        ";\\$ s",
        "!zJ5%",
        ".=IXmh",
        "DcrK~",
        "Ec%sV=",
        "R{d~'",
        " 0x85",
        "4&404X4`4p4",
        "AE1{J",
        "\\dRcP",
        "timeStamping",
        "F'#]@",
        "l4tLn",
        "E$3D$",
        "}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 H}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918\\charrsid15169477 ardware}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918  Product}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "^ZVQ,=",
        "NNVE<",
        " 0x71",
        "yRQmC",
        "{*y8qb",
        "BD`<Ti",
        ";<&7K",
        "e,.%%",
        "bj#f!/v",
        "Eg`%#",
        "In_Mh",
        "6$>[^P=",
        "C8=E~",
        "B_Ixxz",
        "Uhta\"",
        "7z2!b",
        "wgqw}",
        "8(8A8Z8v8",
        "a-T+o",
        "UU](u",
        "3+4R4",
        "%s %d %d",
        "q+}w1",
        "*>h|O",
        "TKhKz",
        "q}jLrk",
        "3a7q7",
        "%L#81",
        "9|oR=0",
        "T*_\\YAj",
        "|3/&?",
        "\\,cc(",
        "z3u{s",
        "Feature not enabled in this library",
        "I,<[\\,5",
        "v`Go,",
        "7$707T7t7|7",
        "$?D'#N'Nu",
        "4\"4b4",
        "141D1H1X1\\1`1d1l1",
        "Nzp.*",
        "?O2u*",
        "*D@h3",
        "([Vza71R;",
        "a<%8Y?",
        "jmjpj!",
        "}}:AO",
        "@hM2L",
        "F*ld*",
        "K<|(L",
        "~[CIM^",
        "`,;x5",
        "rg~f\"",
        ";t855",
        "P|_{0!",
        "0(pnr",
        "\\par 10.3\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Government Restricted Rights.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "M1B 7",
        "j0!q:",
        "zu0b!~",
        "<x.16",
        ".}>M[",
        "GGzpt",
        "ce/9w:",
        "A9ox9I{EZ5",
        "^6rZr",
        "3[?A->",
        "D$ _[^",
        "id-smime-aa-contentReference",
        "^!FoZ",
        "U7l]5",
        "6+;w|",
        "l$L3L$",
        "7$70787\\7d7t7|7",
        "invalid numbers",
        "Installing network driver",
        "wIz `",
        "h]_K=80v",
        "-ZZ&u",
        "^p8}I",
        ">1q[Ii#",
        "RHyxI",
        "Sg>kkx",
        "7HO-]",
        "UJK@r",
        "a4TV6",
        "{L?c(",
        "8;8^8",
        "n_dohb6p",
        "IThTj",
        ";S;f;w;",
        "nbio connect error",
        "96PwO",
        "4UY'x",
        "3O3T3_3-5",
        "5#6s6<7[7u7",
        "#L$T#",
        ")X62_U",
        "PKCS8_PRIV_KEY_INFO",
        "x5VPP",
        "Error opening program data folder as symlink",
        "retrieved CLIENT_SUB_TYPE property: %s",
        "public key no rsa",
        "C7Qk8",
        "sT7RP",
        "T$$3\\$@3",
        "1AZs}",
        "ITPaZ",
        "=\\X7w",
        "Microsoft Encrypted File System",
        "8xR;W",
        "UQ&v7",
        "cdRAy",
        "r}f;E",
        "szTag",
        "809W9",
        "#DsrG",
        "T.=VUb",
        "*~&n>",
        "\\lsdunhideused1 \\lsdlocked0 Table Colorful 1;\\lsdunhideused1 \\lsdlocked0 Table Colorful 2;\\lsdunhideused1 \\lsdlocked0 Table Colorful 3;\\lsdunhideused1 \\lsdlocked0 Table Columns 1;\\lsdunhideused1 \\lsdlocked0 Table Columns 2;",
        "1W=^U",
        "Failed to query security context attributes.",
        "nested asn1 error",
        "FeatureTVDriver:  FreshAfter finished.",
        "OpenThread",
        "g7%{;",
        "D`(1;",
        "P-L\"|",
        "/&Hr(",
        ".\\ssl\\d1_pkt.c",
        "gKf\"9",
        "516\\7",
        "sheIB",
        "MIY71SkN",
        "Small Business Server Premium",
        "3WUMA1W",
        "i\\l'aC",
        "2,202@2D2H2L2P2X2p2",
        "S3M_e",
        "6&6[6",
        "5*5Z5",
        "\\v3]~",
        "D}<!`",
        "&3bgdgrgtgvgxgzg|g~g",
        "help.bmp",
        "GKFe4",
        "5wEe<V",
        "FeatureVPN Remove VPN registry services",
        "IX*3-",
        "@:R9p8",
        "!This program cannot be run in DOS mode.",
        "Proxy-Connection:",
        "Ph,T\"",
        "fpx6US",
        "RZ2*y",
        "ObOcOfOgOhOiOkOlOoOpOqOrOtOvOxOyOzO}O",
        "*bXyj",
        "yb(8~I~",
        "t+!Wt",
        "InstallDirDrive",
        "5u.(8",
        "1F}Pm",
        "_WDL7D?",
        "ZVd(;?",
        "\\s29\\ql \\fi-360\\li360\\ri0\\widctlpar\\jclisttab\\tx360\\wrapdefault{\\*\\pn \\pnlvlbody\\ilvl0\\ls2\\pnrnot0\\pndec }\\aspalpha\\aspnum\\faauto\\ls2\\adjustright\\rin0\\lin360\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 ",
        "ZIw+!",
        "G$rOP",
        "heWbs",
        "<S5ll",
        "[]UdG",
        "&<;j$3'",
        "8'k6%",
        "#X.0fB",
        "\\nBA^",
        "\"gG#uE",
        " ]0=T",
        ".CRT$XCC",
        "8f^^b",
        "&Check Point Software Technologies Ltd.1>0<",
        "6t%}v~]",
        "DeleteFlag",
        "\"z%oL",
        "=m!:t",
        "&.nvo",
        "<-<3<:<B<R<[<g<m<w<",
        "and attachments not under warranty service and ensure that the Hardware Product is free of any legal obligations or restrictions that prevent its exchange}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3736522 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "`?RyI",
        "{pWpAi%",
        "hZ;i#|#",
        "P`.-9[K",
        "uninstallFW;",
        "q6cGC",
        "4#j&K",
        "`}'[L",
        "signature failure",
        "\\f1\\fs20\\insrsid9056778\\charrsid15169477 AC\\'94) and open a Service Request}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 . }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9056778\\charrsid15169477 ",
        "3P3C3W",
        "B4\\~+",
        "g7WyfUB",
        "u0hp.!",
        "SWj P",
        "-WUC0",
        "&$-zZ5K",
        "i1Bq1",
        "pQj=]",
        "ll?3]xV",
        "32R.Uk",
        "7y2K~[>",
        ")uzo3D",
        "91w;k",
        "W3g9L",
        "b|.9\"",
        "&'[#@",
        ",(m&la9",
        "r-xNq",
        "QQSVW",
        "V{;zKz",
        "rM)\".F",
        "UO[>LB",
        "=f:u\"O |",
        ":c;z;",
        "Internet Logs\\Telemetry",
        "e,e<eOe",
        "jejrj",
        "54gRp",
        "Proxy-",
        "'8'tNh",
        "g%tDd>>k",
        "58~+Nx",
        "+k|s<",
        ".{i7:",
        "rM5H:.|%",
        "E;{2-G",
        "tCYe2",
        "}$8!N",
        "KR>k:",
        "pbeWithSHA1And128BitRC4",
        "-orQ3\"+",
        "}s8og",
        "Cl~qL",
        "v\"lD-",
        "TNC_GATEWAY",
        "q/Ud(",
        "2SSP{",
        "F8p/v",
        ":$e1y",
        "?..Cj",
        "\"3%ob",
        "i'i7iGiWagw",
        "'ZqB)",
        "OTs.G",
        "Y?jSmKdj",
        "{}^xC=s",
        "1HY+%",
        "\\sbasedon36 \\snext36 \\slink39 \\ssemihidden \\styrsid15147522 annotation subject;}{\\*\\cs39 \\additive \\rtlch\\fcs1 \\ab\\af0 \\ltrch\\fcs0 \\b \\sbasedon37 \\slink38 \\slocked \\ssemihidden Comment Subject Char;}{",
        "m}?_E",
        "Gg1jq",
        "(Gf6[P`~>",
        "@)|!q",
        "7-fFC",
        "x~)DzJ4",
        "%F5#v",
        "vOQ4_\"",
        ",^A&}",
        "!1bcD",
        "\\z&X5i@y",
        "0!4.N*",
        ":h]M&E",
        "D~!$,a8",
        "Iy6>V&>",
        "VXPaY",
        "6X(zc",
        "?6?D?a?i?v?",
        "N?K%c)P:]'",
        "Uh@-$",
        "4mh|`",
        "0$0,040<0H0l0t0|0",
        "3<?3}",
        "failed to copy XmlFile record Id",
        "Failed to set %s\\uninstall value. Error: %d",
        "LookupPrivilegeValueW",
        "MOVZXD",
        "A'hi@BN{",
        "wF}^6",
        "sBjf/",
        "S&1Mc9-N",
        "5-FFy",
        "dsfainstapp.exe32.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "=5F:2h",
        "SUW/>!",
        "1@=P=X=h=x=",
        "setPropertyInCachedMsi(%s,%s,%s)",
        ")RA#0",
        "FORCETLS12",
        "D\\|1Wm6",
        "6O7g7",
        "CreateWellKnownSid",
        "/^OWG",
        "AltDirDebug",
        "_Z[.I",
        "[U+[i",
        "ElF/!",
        "sIGZ5",
        "{oRG]e>",
        "7$b'f",
        "T\\W8h",
        "4V4e4",
        "#r{MX",
        "I81_s",
        "h4H\\Y",
        "cdGl\"iC",
        "S)Q\"2",
        "!Ws2-",
        "!#lt3!",
        "L9Tl?",
        "jsjtj\"",
        "3(jZ-",
        "w?AOoo",
        "successfully set certificate verify locations:",
        "T$D1T",
        "</Zs7",
        "J9QC'",
        "VPxFl",
        "ZS=4|",
        "!=.Q$",
        "\\^G~<",
        "+F8\"r[@",
        "^lSsX",
        "60)2x",
        ".\\crypto\\evp\\e_aes.c",
        "$4%dI",
        ">+q'g",
        "[.{F&O",
        "hL'?u",
        "ydQG]",
        "Wx *n",
        "nyB\\ZZ",
        "m;lC/U",
        "oL7?~",
        "+@7^q(",
        "TuU}v`",
        "RSA PUBLIC KEY",
        "a&x!x",
        "_eX|`<<bJ",
        "-oK>T",
        "{\\f37\\fbidi \\fswiss\\fcharset0\\fprq2{\\*\\panose 020f0502020204030204}Calibri;}{\\f38\\fbidi \\fswiss\\fcharset0\\fprq2{\\*\\panose 020b0604030504040204}Tahoma;}{\\f39\\fbidi \\froman\\fcharset0\\fprq0{\\*\\panose 00000000000000000000}Arial Bold;}",
        "@S7mC",
        "Certificate Hold",
        ".WuxP",
        "cACertificate",
        "Y-%$v",
        "'UFHt&",
        "KD3M3",
        "O_tP,G>",
        "HnLjx<",
        "}[g&v",
        "Z ui&Xh",
        "5%5+51575=5C5I5O5U5[5a5g5m5s5y5",
        "rxDxNBh*",
        "extern \"C\" ",
        "O-E@8~j~nw\"",
        "N`Z*|",
        ";5w{}",
        "S)4pc",
        "\"PJi_",
        "-p(u8",
        "u+P+&",
        "9;3}*S",
        "OQh ,",
        "1?1U1r1",
        "W)zjd",
        ";\\':f",
        "ZQ!a%_",
        " dABu",
        "DZ&HW'0",
        "AGENT_BIN.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 or {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}{\\*\\xmlopen\\xmlns2{\\factoidname place}}Sudan{\\*\\xmlclose}{\\*\\xmlclose} or (ii) on the U.S Treasury Department list of Specially Des",
        "F\\_^[",
        "*HzAK",
        "[*]5`",
        ",},^[",
        "vKbF$",
        "X509v3 Subject Alternative Name",
        "A1du%@",
        "9vc5k",
        "A#`Wh",
        "wRK\"+I",
        "'@@&(",
        "<9v-<'t)<(t%<)t!<+t",
        "?K7[0P",
        "uVUmg",
        "no child process",
        " R19 %",
        "'$a<Z",
        "L*bB1",
        "YnD}M",
        "Failed to allocate Property for RemoveFile table with property: %S.",
        "d[q<@",
        "WIX_DIR_RESOURCES",
        "L'%96",
        "VL*r\\1a ;Y",
        "V|oe@",
        "wMaq--",
        "uq=WL",
        "'KtQN",
        "4#m\\7I.",
        "!Mwze",
        "Server finished",
        "ftware as if they were the Product and Check Point, respectively. ",
        "Dee'e",
        ".?AVoperation_timed_out@Concurrency@@",
        "&?R )b",
        "dV6<YjH",
        "|XBc-",
        "QPsVx",
        "Cf93u",
        "CIPHERS",
        "v2i_GENERAL_NAMES",
        "StopURLFService",
        "|@3ws\"P6",
        "=K>j>",
        "]\"_d/",
        "9h=5)&1",
        "[k.L]",
        "?y/%@:",
        "6)6.6t6z6",
        "4eE,e",
        "$u& k",
        ">*{vhwBV",
        "~mJ<t",
        "GN:YceZ",
        "&Mh<e",
        "C14ln",
        "/f;fq",
        "H~Uh$",
        "4%q/'",
        "QfIA#gs",
        "93t$h*",
        "zMi+`",
        "`(GAU",
        "Mz7Fdm",
        "u.qpAxB",
        "@zq,^",
        "fO0bLG",
        "nNmknJ",
        "qgI!]",
        "=L)@r",
        "vN}f}",
        "P\\il;",
        ";?%vssu",
        "*lU6:",
        "2G3b3",
        "s$jz6|",
        "1}OLo",
        "8K3Q]Vk'",
        "$)8z(",
        "=o>v>O?",
        "-6EeL+",
        "&\\_;/8/7/>/",
        "Mf{(!",
        "H~tdI",
        "4 4$40484<4H4P4T4`4h4l4x4",
        ".YL>E",
        "*]4^a",
        "VY.\\L",
        "(YZbP",
        "#b#B#J#R$Z",
        "=0a=F",
        ":=;Q;",
        "BWNESl",
        "No embedded signature",
        "9_9u9",
        "WVNnW",
        "g]$jN",
        "!Q!Q!",
        "6 6(6@6d6t6",
        "?^)Lr3pL",
        "Mz}5p",
        "SystemRoot",
        " GO!u",
        "vsdatant driver is not installed",
        "!8VEb",
        "ey\"pG",
        "Wx+N\"",
        "7h@U!",
        "fsz=^<",
        "[!{It",
        "Z@db5",
        "T$(WVUS",
        "gJii3",
        "JLbcjfT",
        "6,606@6D6T6X6h6l6x6",
        "P]S\\[",
        "failed to open file: %ls",
        ";|$ r",
        "8<8V8|8",
        "<+=F=i=",
        "9$L3|",
        "I&[x1",
        "Decipher Only",
        "(.01j",
        "^AKE8Y",
        "vkN`=hz",
        "%!U?l",
        ",@67,",
        "@d\\S6e",
        "y:tZL",
        "SOCKS5 read timeout",
        "A;N||",
        "M:9AS",
        "DS_CopyToSystem32.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "7$7,747@7`7h7p7|7",
        "wERo>",
        "\"~$IO",
        "Certificate for %s found",
        ".?AV?$bind_t@_NV?$mf0@_NVCRolloverMgr@@@_mfi@boost@@V?$list1@V?$value@PAVCRolloverMgr@@@_bi@boost@@@_bi@3@@_bi@boost@@",
        "8=8L8S8Z8",
        "<o-1kb",
        "7$7,787X7`7l7",
        ">$?B?",
        "b1G?(",
        "<&AHQ3$!",
        "kMP[WXv",
        "o7o8o9o:o;o<o=o>",
        "f]M8$",
        "HpfFeQ",
        "+Ya&,",
        "AES192",
        "qw[d7",
        "0$0[0b0i0t0",
        "'Q5D.J",
        "8's^Y",
        "<hwyW",
        "/};S3\"v",
        "VYdP]",
        "!+1FJ",
        "8xxc'",
        "YQB]\"",
        "PKCS12_newpass",
        "@5HxE",
        "1cHo,",
        "l0x<b3",
        "px9zH",
        "566t6L9",
        "E@s,!P",
        "D{!z`q^o]",
        "~|zye",
        "EnumSystemLocalesW",
        "glzLt",
        "'2|QS",
        "\\$ USWVj",
        "wYz+a",
        "\\a%6$",
        "sl2o.",
        "9l$@uf9\\$Du`",
        "V<;V8}",
        ".@@8Xp3R",
        " gi/w",
        "ec_GF2m_simple_point2oct",
        "B&ZJn;S5",
        "O$=1x<",
        "C2KW48",
        "+?m,c$",
        "<c\\>\\",
        "121R1r1",
        "fI|ygo",
        "p1qh.i",
        "KasGP",
        "$6$dd",
        "MIC-CLEAR",
        "id-smime-aa-signingCertificate",
        "tGhH[%",
        "2 2(202@2d2l2t2|2",
        "l|@;k",
        "GetFileInformationByHandle",
        "?lSU%",
        "|YBkVN0",
        "oH\\CR",
        "|S2Xc",
        "I~[dD",
        "<mxg;",
        "Bp}vL",
        "superseded",
        "iLL8M7=-",
        "X*zUb",
        "S{,U'",
        "Dt!+3",
        "?P1]%",
        " <FxP",
        "PRODUCT_GUID",
        "[_1xm",
        "dZ}1b",
        "M-#--x",
        "t\"tKbX",
        "Fw}lX!CK",
        "TaiJaQ",
        "k[\"TY",
        "F{ 'E",
        "n>Fi-",
        ".6b%%",
        "Nonce",
        "Failed to copy file %s -> %s",
        "vp;ZsQ",
        " .wqF",
        "$X/==",
        "Phx,!",
        ";-]*\\<",
        "rv*Ky0",
        "]`>ys",
        "`0>i`",
        "M,&rI",
        "5OI62",
        "bzHjqX4",
        "sKWjQ",
        "Comments",
        "= >3>=>W>b>",
        "$\\ER8",
        ";1<G<O<V<e<Y=",
        "J#K$Pyd",
        "t&*`s",
        "4L16d",
        "private key does not match certificate",
        "OTHER_INST_RUNNING",
        "`';ry+",
        "wi-74",
        "3)7s=",
        "091I1",
        "vhVSWj",
        "*7}/l78",
        "VR/e|",
        "SI;W`",
        "pAj8J<T]",
        "l5%4e",
        "jAZjZ^",
        "Ivaba",
        "80848H8L8`8d8x8|8",
        "[(&&Z}",
        "L:%@=",
        "failed to retrive file info size.",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Liability.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "33LA_\\+H",
        "C+ME=^",
        "qkQ0osY",
        "4j6h$",
        "DJYY;P>oW",
        "Failed to open registry CheckPoint reg key, Error: %d",
        "ASN.1 part of OpenSSL 1.0.2h  3 May 2016",
        "(J@ \"\"\"H",
        "{LU6?",
        "S,QV ",
        "}ea4o",
        "{\\fhimajor\\f31536\\fbidi \\froman\\fcharset163\\fprq2 Cambria (Vietnamese);}{\\fbimajor\\f31538\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}{\\fbimajor\\f31539\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}",
        "=7>R>`>s>}>",
        "424M4p4",
        "n^Jm?J5",
        "8 8$8(8,8084888<8@8D8H8L8P8T8X8\\8`8d8h8l8p8t8x8|8",
        ".97yY",
        "5c'l2",
        "M:;N@",
        "WJ3zdQD",
        "}9&(LZ",
        "R5n:Jo",
        "_xU`u",
        "2A3K3h3y3",
        "streetAddress",
        "3oB0(,_",
        "[*[jl",
        "C@^Bb",
        "#9'*w",
        "idzlU[jK",
        "NnG`G",
        "B?^,ocW",
        "X509_EXTENSION",
        "failed to set security info for object: %ls error code: %d",
        "/)b ./]l",
        "p !l(",
        "/w]/mOR",
        "O5U9$y",
        "WD_CheckFolder failed on recursion check.",
        "BzQgv",
        "ErrorDotNetInstall",
        "5)5E5a5}5",
        "f*!4C@\\",
        "t$,UR",
        "CVTPS2DQ",
        "E( uV",
        "P8O>j[nK",
        "\\r9RN",
        "mX~2!O",
        "\"g vl",
        "V%0@ ",
        "Xb\"U$z",
        "7468656d65312e786d6cec594f6fdb3614bf0fd87720746f6327761a07758ad8b19b2d4d1bc46e871e698996d850a240d2497d1bdae38001c3ba618715d86d87",
        "494f4",
        ";?{za",
        " (INVALID PSS PARAMETERS)",
        "r,M0l0",
        "Ac_>qv",
        "?rs}N",
        "1$181@1H1P1T1X1\\1`1h1|1",
        ">=)OAmq",
        "2_;Qq",
        "g{;\\\\",
        "JkfMF",
        "\\M+%D",
        "o]IAp",
        "qHXmI",
        "failed to stream out ucp_eps.exe to %s.",
        "y}g8A",
        "Vl0<V",
        "oHXMp",
        "MaNXN",
        "_(kPf",
        "h/,7O",
        "8#9F9i9",
        "040d0",
        "(_IWd",
        "27.t3r",
        "6/6K6g6",
        "=+ >p",
        "y{PIu",
        "EW`*1:",
        "$H<$vi",
        "Yrw4)!>",
        "y8~mK",
        "W@`K[ru",
        "Ccf&g",
        "Zu#mDXa",
        "`.dpA",
        "3t0_f3",
        "P?K?F?",
        "YYf%uk ",
        "]|.Qb",
        "+E^q ",
        "Missing folder property: %S for row: %S",
        "^`R^^kf",
        ",E.bO",
        "failed to read protocol from custom action data",
        "9%:,<:<H<M<Y<f<q<",
        "'VQF@",
        "4X)W)",
        "g 1y5",
        "XE*7$Z",
        "G:|xkps",
        "OYQD!O",
        "rI9oY)",
        "t\\HQg^I",
        "+tN7&,",
        "o!>6O",
        "xtCb&",
        "g4.=U=",
        "5Q+<]",
        "Ta$Eua",
        ",ot#o",
        "fX1xG:",
        "6xv#=",
        "ai)LQ",
        "uD]m# ",
        "/)<|N",
        "LNKf\\",
        "RemoveVpnFiles()",
        "jcdv7",
        "^GQHA",
        "m-P^,",
        ".CHgr",
        "!}yl:",
        "too many links",
        "AJ;5r",
        ";#'#Xr",
        "FV?\"NH",
        "zKO<}Q",
        "ati+B",
        "Tw<(t",
        "}K+]M",
        "DSe'7",
        "@H??wElDj;",
        "u&h<0 ",
        "}*O7[W",
        " WVVNb",
        "7z\"m\"iN",
        "yW9ltV&A",
        "f^PQ#qa",
        "6_6 7m7",
        "DBD8h",
        ":(:0:8:@:H:P:X:d:",
        "7@7J7e7",
        "#M :A5",
        "Njjjj",
        "'?3W}pf",
        "x=_[!1",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669\\charrsid3233976 as may be needed. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid15480523\\charrsid3233976  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid3233976 ",
        "7R8h8",
        "\"j>0!/[",
        "5;6'7W7",
        "}A*Y,",
        "D$$][_^3",
        "not a socket",
        "R6027",
        "j0Yf;",
        "Bb-E=",
        "mW-ue",
        "^KnME",
        " 0x76",
        "?26zU",
        "S4')$",
        "n$>uz",
        "e-{7E",
        ".(/>g",
        "}|RE@S",
        "vVqTs",
        "$dDQ`yF",
        "4WO+:,DC",
        "AiFC.",
        "MSFuS",
        "8!818A8Q8a8q8",
        "<W +{ ",
        "@*^E8",
        "{wCI-",
        "/'?p~",
        "/32$n",
        "$vV?m",
        "8E!K8",
        "SNPXwNK",
        "T^%.7$",
        "WTLS curvs over a 224 bit prime field",
        "HN&1w_",
        "b+E=.^",
        "=<u0G",
        "d[F7@1U",
        "L9Ome",
        "5#5.5B5S5^5r5",
        "W3}uj",
        "2?dF}S?1ou",
        "muz/r",
        "[~|1|y",
        "5,.J_",
        "b(::$YU",
        "SHGetFolderPathA",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\caps\\f39\\fs20\\insrsid344604\\charrsid2703887 ",
        "VsDrInst_win7.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "pZEb\\A",
        "FCMOVE",
        "{UCMC",
        "5!555f5q5",
        "qualityLabelledData",
        "$<~0a",
        ":@:O:a:t:",
        "D$$ht",
        "rsf;E",
        "GrU6)",
        "%*sUnknown Qualifier: ",
        "tRsdo",
        "]Bv;T",
        "\"10Ik",
        "1(1G1",
        "+V;VKV[VkV{V",
        "%*sExtensions: ",
        "W$S^&",
        "'nb)r5",
        "co$v+V",
        "\\yY!+",
        "table loaded, incomplete count = %d",
        "hl?Ju",
        "qEz*@",
        "!WG~O",
        "Mck:/",
        "missing ceripend info",
        "5^e\\J.",
        "NX:>=R",
        "q8xWn",
        "qpE>N",
        "zs,p6",
        "pub_key",
        "~Ltl*g1",
        "FAjyo",
        "3X4^4i4p4",
        "LU*\\L?",
        "JSW>}E;",
        "8B8e8",
        "0/K8Y",
        "K3;>a",
        "2b)<U",
        "e(e41",
        "O+;_Z2",
        "8&9=:",
        "FLDL2E",
        "9k*F,7",
        "Z2~aVD",
        "> 8y(",
        "= =8=H=L=\\=`=d=l=",
        "yiAAE",
        "D,E,F,G,",
        "regedit.exe /s \"%sScvPlugins-32.reg\"",
        "APN2&}H6k?",
        "failed to copy file name",
        "3mVnQ",
        "ppVirtualProcessorRoots",
        "F`ntI",
        "SEC_E_POLICY_NLTM_ONLY",
        "t+`x)",
        "keyblob too short",
        "3G3N3U3\\3s3z3",
        "SvtK6",
        "N$'6_",
        "6(747s798|8",
        "x&kjzR",
        "T:KQ^",
        "CIH0v",
        ",3EvK",
        "U`'Y.",
        "73w_v",
        "$,2J5",
        "^X{9_",
        "!SU./",
        "#JC>y",
        "&GP,F",
        "7[e<'",
        ".ShuQ",
        "N0%-X",
        "CMS_dataInit",
        "\\ltrch\\fcs0 \\fs20\\insrsid16581128  1}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid15169477 , and solely upon confirmation of a defect or failure of a hardware component to perform as warranted, shall }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "~][,u88",
        "O6`~BH6",
        "j/Zf;",
        "V22B%J",
        ">e>q>",
        "X}y}T",
        "/SiuB",
        "MW-_cYc|",
        "tyheX",
        ",cgMC-",
        "9#9?9[9w9",
        "Ms2VBdZ",
        "SetEvent",
        "U3=Z[",
        "Plugin name does not exist",
        "PANDN",
        "x3!i<",
        ">$,6W0",
        "!j)(aV",
        "ug,`&@",
        "=VJ[tY{",
        "f\\}r=",
        "WatchdogDir.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "&Nn!q",
        "nn)7s",
        "8{=.h",
        "Xz]0^RO",
        "&X6c@f",
        "4z_(J",
        "%>MA;",
        "E;G2C",
        "yh8UPx",
        "D$ RP",
        "jP9F[",
        "lpKrj",
        "Mg$f`8",
        "2;RiT",
        "6D7I7Q7H8y8",
        "5/6K6e6",
        ":j:y:",
        " *kvp",
        "/Pq4b",
        "ATo}?mv",
        "LmCTu",
        "3L$L3L$<3L$(",
        "Failed to delete %s\\PRHelperIsRunning value. Error: %d",
        "#\\(xa",
        "JGkbn",
        "f5Ha2",
        "5,545@5`5h5p5x5",
        "r+I2HW",
        "qSP+s",
        "!D;fo",
        "SBb-p",
        "w%nxH",
        "response contains no revocation data",
        "ReplaceOrAddTagIntoVSConfigEx(%08x)",
        "Saving value ",
        "\\15I)",
        ";6;C;K;g;",
        "4o$zZU",
        ":`Vh_",
        "5YsY[",
        "mv~1T",
        "TS_ACCURACY_set_seconds",
        "g:][To",
        "z&H*&",
        "invalid safi",
        "s0P1C",
        "*CD*7",
        "[WinFW] SetWFStatusXP, failed to get standard profile, error=%x",
        ")qw9;)'",
        "@\"V=3",
        "D]lLM5",
        "Y/y~fA",
        "m%!~a",
        "K [Ln",
        "zkS<B",
        "2W>CF",
        "/%52=8K@^[^",
        "PBsvl",
        "s#Yk+n-",
        "p.ppBasis",
        "..\\lib\\vtls\\openssl.c",
        "I:IZIzI",
        "=W>>[",
        ";bFMw",
        "61<#u",
        "AC_TermOnExecutionInPolicy",
        "y?a3Z",
        "regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.",
        "TL[AZ",
        "hi7C]",
        "4zD3gQ",
        "non fips dsa method",
        "21mW\":",
        "AeJe:",
        "reu)$",
        "z5<0.",
        "ssl3_connect",
        ";K=^>",
        ", name=",
        "H;ww*",
        "DS_UninstallFACDriver started.",
        "#GA/pFM",
        "G.(ba",
        "`==EC",
        "K,_-IB",
        "|?iC8V",
        "+Q(EEE",
        "&>`sH=3",
        "\\U:8E",
        ".8N]hK",
        ".&B_*",
        "App: %ls found running, %d processes, attempting to send message.",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 guideline}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "7?7E7I7O7]7a7u7",
        "VzKp?",
        "Register: %s",
        "9w:Xl",
        "DL|lX",
        "codeSigning",
        "id-regCtrl-authenticator",
        "3,4t4",
        "WIX_SUITE_STARTER",
        "YkNZ=",
        "Mz%.JC|",
        "\\'02\\'04.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li3600\\lin3600 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715",
        "jfjmj",
        "MNga$V[",
        "5{+TD",
        "2N2{2",
        "JX.R$",
        "'zF|&",
        "L$LQj@W",
        "a5\"\"p\"",
        "cW\\s<~",
        ")#DZf",
        "6#6v6",
        "MD8ZDpT",
        "Pqi \\cFy",
        "v|dr={",
        "lJ6C}:n5",
        "M81pw",
        "]/g 2",
        "l$ VWU",
        "g+*.Ta",
        "P\\T[H",
        "lupjm",
        "-N(<M5",
        "_8H!>",
        "Duaeb",
        "X?jT ",
        "?TCTF",
        "9)989n9",
        "O3d  ",
        "DuPScgx",
        "vJ#`'",
        "7msww)",
        ":1;{;",
        "$;*$B",
        "5hK2Xc",
        "7t<[|",
        "D$4]_^[",
        "F:\\ckp\\src\\EP_CALib\\E87_20\\CMpub\\lib\\win32.release.32.msvc141\\CALibraryVPN.pdb",
        "ktF>_Z",
        "${VrM",
        "W?<Cs",
        "*X*P3Q.2",
        "rRAnq",
        "Installer\\Features\\117CD7D3CB2C542438D083C010944001",
        ":+;7;?;U;z;",
        "Oc[Fi",
        "5aR~fQ",
        ":.:J:f:",
        "gTc?Jyd",
        "'E+0zP",
        "').(E<DjC",
        "Bh_<P ",
        "w?Wgd",
        "#?*dT",
        "ClearUserProfile",
        "hE~{'",
        "Failed to locate DllUnRegisterServer in %s, GetLastError()=%d",
        "3-4C4",
        "t&Utm",
        "i*z;:Z6zy7e&,",
        "A2.'4",
        "0b_n7",
        ":@<aK",
        "3@D f",
        "+m_aW",
        ":35@]rf",
        "$P%P&",
        "zAnwH",
        "5hLd}",
        "!ti>0",
        "RC4 part of OpenSSL 1.0.1t  3 May 2016",
        "j=Zp&",
        ".L!9r1",
        "w#qJ86",
        ".tWZ|",
        "%0t-j*",
        "uninstallIMSecureLSP;",
        ":5:T:k:p:",
        "5\"6,6c6",
        "+/@5Rn",
        "2'<5,",
        "^=|PUw",
        "9$9,949<9D9L9X9x9",
        "nTT}>@",
        "8gRL[.x",
        "&+YJ2",
        ")K`QX",
        "duDnb",
        "BG4%5",
        "8N8S8",
        "2v2Jt",
        "ct`Ici5r",
        "-d(38",
        "=no,_",
        "6Lpc1",
        "tQN3)",
        "yu'W*",
        "@kX:|mc*",
        ".wro1G",
        "This indicates a bug in your application.",
        "\\s#id",
        "':8_?",
        "3Y{LtlIi",
        "e8a(H",
        ">(>0>8>@>D>H>P>X>`>t>|>",
        "y,Kt&q",
        "0(090",
        "AQR4 ",
        "igr2g",
        "8M8.W)",
        "({ ZU",
        "|@>pB0Dy",
        "9kR}I",
        "RjipZ",
        "w5F,P",
        "=J&8N",
        "60}0l1",
        "v,)Cp",
        ",5NEy",
        "setct-PANOnly",
        "'h>cC|",
        "t:Gr,",
        "z -ef|e",
        ":#ehT",
        "id-GostR3410-94-a",
        "{q9@|~",
        "whole or in part. You must reproduce and include the copyright notice and any other notices that appear on the original Product on any back up copy. You agree not to allow others to use the Product and You will not use the Product for the benefit of third",
        "*2PO[Qj",
        "rw1(I",
        "5g|fv",
        ";$S*T",
        "@v/LT",
        "Removing files from Program Files\\Common Files\\Check Point",
        "aN\"oCh",
        "0?]+Y",
        ",section=",
        "[$k p",
        "3L4Q4Z4i4",
        "W}`>Uk",
        ",pML-7",
        "iF]1v",
        "PCMPGTW",
        "sWHtYo^",
        "rJml\\",
        "m'jc'",
        "m<MAr2",
        "R_eYU#",
        "$kG=}~",
        "HN(<&B",
        "?AxV.A",
        "L(Q+6",
        "qH\"9x",
        "7OXlm;Cl",
        ".>$#.w",
        "secp521r1",
        "#:'VN\"1",
        " )CA<",
        "\"ijZQ",
        "MgVSt",
        " ,$$ bXf",
        "&ki^t",
        "9R:]:h:m:r:",
        "fE>wC",
        "_%oVfB",
        "B_BBi#r",
        "H1cD-U",
        "k)!l?L",
        "_[Bq=",
        "\\|6j/q",
        "H_&mg",
        "ulSmj",
        "EdiPartyName:<unsupported>",
        "G-}B}",
        "v33lxx",
        "&IC}N",
        "Q~}6'YIf",
        "E9fx>",
        "<$<4<D<H<X<\\<l<p<",
        "UMeZ0a",
        "PatchOldME",
        "8f}E.",
        "returning %s",
        "TY`qV5",
        "@Pz,Q",
        "*{d#C",
        "trB[&",
        "`8ux>",
        "8St;C",
        "Uo=9=W",
        "8<9X9",
        "b}hkS~",
        "{j?_'>s",
        "P@m<4",
        "m1WY$",
        "X>(tNs",
        "49xr ",
        "2Jr)O",
        "<M=G>",
        "_@|te",
        "; ;0;8;@;l;t;",
        "I(Hrl",
        "mCDDDfXGf",
        "+/l[47",
        "INTEGRITY",
        "9{b.a\\",
        "DUMPFILE",
        "P5\\6/",
        "IswRecursiveThreadSpinLock::Leave: called from thread tid=%u, whilst the owner thread tid=%u",
        "\"Ml|irT",
        "3$3,3034383@3T3`3",
        "liQ,V",
        "><=D>",
        "/[ rUC",
        "OZ1=^",
        "5.QR~",
        "maaw]",
        "\"N5NMN]NaNeNiNmNqNuNyN",
        ">7>|lz",
        "+ffl;",
        "*\"e3#2",
        "=#>A>`>w>",
        "m' JA",
        "L1@D9m",
        "FXTRACT",
        "Vf^RBl",
        "y!C=V",
        "F)bQI",
        " 9<yN",
        "z(xc@",
        "JMJN7",
        "&sa5n",
        "1<2B2L2W2`2e2k2",
        "f9LT$S",
        ",NoPL",
        "8h0,b",
        "~\\Rpz",
        "4adc5a9aec1b703b8b93caec1a0bd8e5de7b132fe5113cf312503b998e2c2927274bd051db6b35979b1ef271daf6c6704e86c73805af4bdd476216c26593af84",
        "ar-IQ",
        "R&N =&%",
        "B'Z^Y5",
        "`RWn!",
        " lfonv",
        ".6+~D",
        "N/n>t",
        "ORs)!",
        "cXz>1j",
        "]j=5a",
        "7e%^V",
        "l\"Zh7",
        "UNKNOWN_ERROR",
        " c:('u^",
        "DA'r-",
        "#:t)^",
        "bK'ZE",
        "'\"Ww>|",
        ":,:4:<:H:h:p:|:",
        "}<|_<",
        "K%;VzBDC",
        "_y0BI2",
        "9uee*",
        "BC2z^y",
        ":3zoo;",
        ":X-bK",
        "&*Bof",
        "<&|O2",
        "7wv,?",
        "iH&),",
        "}2aXz+",
        "%s (%d)",
        "SHA-512 part of OpenSSL 1.0.1t  3 May 2016",
        "l1V3n",
        "`7A_p}",
        "h*~7$",
        "7 7H7N7r8{899Y9s9",
        "a\\3JO",
        "9#9.9>9w9",
        "5)5/5F5X5",
        "0ODk9",
        "es-PR",
        "$=\"%K",
        "IHJ$hn",
        "`*@*{",
        "9ug7%v",
        "SVj03",
        "\\r;v8IP#",
        "t$8UW",
        "id-ecPublicKey",
        "AsPu ",
        "*@Y&J",
        "ec_GFp_nistp224_group_set_curve",
        "d_\"0,n",
        "SOFTWARE\\CheckPoint\\SmartDefense",
        "mUlv3",
        "< <@<L<l<x<",
        ")!L7-H",
        "QL{u\"",
        "UC3Z]",
        "3ByDh",
        "?(?,?0?4?8?<?@?",
        "/0-0+",
        "83VXru",
        "2+3O3u3",
        "TYS][",
        "9$9.9;9A9Q9[9e9k9u9",
        ";9<@<G<N<U<",
        "Modules_Compliance.png",
        "%02x%02x%02x%02x%02x%02x%02x%02x",
        "Wc$E-",
        "QO|eE",
        "j]5]-\\5",
        "+%.2:*",
        "!FZbO",
        "y%$g*",
        ".?AVfailure@ios_base@std@@",
        "uninstall case",
        "\"?>~>",
        "qwj&C",
        "B:   ",
        "obwQ4",
        "PXUG0",
        ".y+9.<",
        "OD>|Q-",
        "S69Xx",
        "ShellExecute failed with error %d",
        "?3Ps'",
        " Gnj4",
        "eQk!8",
        "dk-ty",
        "UfV?K6",
        "c|,5M",
        "'Uu0d%$*",
        "[%s] CreateZipFile: Error %d writing zip %s - CreateFile %s",
        ".bGdF%",
        "1G{14",
        "DH_CMS_DECRYPT",
        "(HB(J>",
        "xuXS_C9#(VeI",
        "3oyXr({",
        "[[:EZQOt",
        "qFMmKQ",
        "SpvlZB",
        "3`%EG",
        "LocalService",
        "t*dB}",
        "<v5h*",
        "_Ff(0mD",
        "BpYoPl",
        "2hT%K",
        ";Ig9@",
        "~jfCH",
        "}{aF\\",
        "1$1D1P1p1|1",
        "j <= sizeof(c->iv)",
        ":D:P:b:l:",
        " d2C'",
        ":!:3:E:",
        "f@5n/",
        "2g4f5x5",
        "-V(.~|^",
        "#^XmD",
        "GET_SERVER_VERIFY",
        "A\"*kB8",
        "0NX2T9",
        "or;(yz",
        "=KJUs",
        "jdjsj",
        "h;~T.Yy",
        "9}4|5Y",
        "C1zgP",
        "}=RM&",
        "r@X/K",
        "=#>J>k>",
        "IqpF7",
        "lZJHN",
        "alQWm",
        "$EPs{",
        "2Y2{2",
        "v.#@t|6?",
        "OS kn-",
        "=9=f=",
        "m00B(",
        "SMR:M",
        "!U^::0",
        "<$u,V",
        "6#6e6",
        "484=4B4`4e4",
        "}g8wH",
        ";'=\"2",
        "qKNDh",
        "Oux73",
        "knoOF",
        "9oi}-",
        "Reboot flag is FALSE",
        "P9]FX",
        "=&=I=x>",
        "iNs?cvy",
        "MbUf6",
        "VKojc",
        "failed to read file path from custom action data",
        "@nbJe",
        "_}+U/",
        "}g@^\"",
        "r.jVd!",
        ":;:L:}:",
        "*b3dk",
        "|e-74",
        "Vg<gxZy",
        "         h((((                  H",
        "%)z})s",
        "1EWQ;",
        "!wB54",
        "4Y'qO",
        "W;~Cvn",
        "G5\"S.",
        "drI+O",
        ":E;a;",
        "W @et",
        "?,?E?o?|?",
        ".~n0W",
        "$?&dS",
        "EC_PRE_COMP_DUP",
        "-}9q_",
        "z<PNe",
        "UNUSED_8",
        "> >(>4><>T>\\>l>t>",
        "j;j<j=j>j?",
        "9>>0=",
        "0Ibfj",
        "230222153536Z0+",
        "z<K<]",
        ".`=p[M$\\",
        "%s file not found - firewall not installed",
        "G+.=^",
        "CCCCCC",
        "[{nR7a",
        ":+^dd",
        "!a\" N",
        "KnbU~",
        "jKhp?%",
        "OL<jFLg",
        "3Xz*1",
        "L$PQP",
        "-U;]a",
        "263S3_3",
        "-RcuR",
        "short read",
        "zrD]@:",
        "e4)L] O",
        "ec_GFp_nistp256_points_mul",
        "hsHfG",
        "H*tf*7",
        "$x@LG",
        "j!11%M",
        "QT~,RH",
        "\"`#3;w",
        "xj{ce",
        "NaZy/n",
        "\\Z\\[\\Z\\Z",
        "&x(2)",
        "applicable Service Level Agreement. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13779108  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "_X/xy",
        "{TpQh",
        "jMR/X",
        "C<m!5",
        "ENGINE_remove",
        "l]]sG,",
        "/f:Hv",
        "e^CiT\\",
        "4YMeF",
        "vna_utils.exe",
        "G--~iD",
        "0~$IjCkr",
        ">(?H?",
        "2(20282D2d2l2x2",
        "0j1w1",
        "kDBu;",
        "616N6q6",
        "TLS alert",
        "819C9h9",
        "Local AppData",
        "?\\#8m_",
        "Su:vQU",
        ".nb`'t",
        "?$?,?4?@?`?l?",
        ">B>_>w>",
        "nun~L|",
        "3(393N3S3",
        "UZZltEu",
        "p(O4q",
        "w.sjD",
        "zKG=!$",
        "#(^&V+",
        "i5Uj9",
        "0>0r0",
        "8-8I8e8",
        "1\"j|H`",
        "s\\,yeV",
        "&FFMe",
        "UEVQ^EY",
        "z<p4m",
        "\"<NvD",
        "P]oOt",
        "t$$PW",
        "348E^8GM",
        "EVP_RIJNDAEL",
        "]viui",
        "6J^TJY",
        "9}dsbg",
        "pgctq",
        "&4i!%b",
        "=,=@=T=h=|=",
        ";\"\\5C",
        "\"rF?a",
        "cR,cL",
        "?\"?,?",
        "6p8'9",
        "t<[@i",
        "LDAP remote: %s",
        "6Z~UFe",
        "u!6c4",
        "!_opp",
        "G;DXV",
        "tlsv1 alert export restriction",
        "Custom action was told to act on a 64-bit component, but was unable to disable filesystem redirection through the Wow64 API.",
        ">$>,>8>X>`>l>",
        "Zm3+_",
        "StopNetFltDrv_rollback",
        "oq|x%",
        "wg]e~y",
        "failed to create child element: %ls",
        "F;Z#\\kyY",
        "9Xp\\3}",
        " expire date: %.*s",
        "H0443",
        "R|\"PI",
        "id-smime-ct-receipt",
        "sJt=c",
        "rB%v*y",
        "r<S+4",
        "Ixsqui\"",
        ";cw?b",
        "wnU<p",
        "9$9,979<9D9O9T9\\9g9l9t9",
        "ET<!F",
        ">0s\\2",
        "w32?i",
        "\\Rz,R",
        ">1 M'V",
        "WIN32",
        "=?>Q>W>",
        ")qckI",
        "1Eom-",
        "yeT!]",
        "SUBPD",
        "unsupported md algorithm",
        "Open directory %s. Error %x: %s",
        "DATACLIENT",
        "==Z\\Xp",
        "VvP`k",
        "+p6tt",
        "?41.e",
        "~${;0",
        "PQOSN",
        "-c29l|I",
        "[Y)v\"[",
        "PSWh(l#",
        "AMXHA",
        "T(0r-",
        "q50qV9~",
        "j]S=Po",
        "?(?0?8?@?H?T?t?|?",
        ":#:,:Z:a:j:s:",
        "FFFFNF",
        ",lBCJ",
        "can pipeline",
        "I'@F%",
        "id-it-confirmWaitTime",
        "050H0\\0p0",
        "****************************** VnaUnInstall ended **********************************",
        "D!7E}",
        "5B~4]",
        "*6:eh",
        "5`ZP)",
        "pRX&IA",
        "+A Vj$",
        "4>jKV",
        "J/|v#JH]i",
        ">O?_?",
        "0 1,141L1T1`1",
        "6!6&6;6",
        "465\\5h5r5w5",
        "MVvLt",
        "H*{WA[",
        "#>RIT",
        "%gPkT",
        "a&yFm",
        "L,>.90p3",
        "$%T\"$L",
        "%jV[$",
        "s:VCW",
        "CRL is not yet valid",
        ":C60nLz6",
        "686D6h6",
        "!1FuX",
        "< <$<(<,<0<8<P<`<d<t<x<|<",
        "k#s{iK+",
        "8buNL",
        "3<3L3X3x3",
        "A9ngh",
        "9\\+Ig",
        "19I<F3b!",
        "Jo<:O",
        ": :,:8:D:P:\\:h:t:",
        "|Q?km",
        ")GTS1\"~",
        "?/|I6(q",
        "|,^OK9d%`",
        "snmpv2",
        "CMS_SignedData",
        "Z]Zg\\",
        "b#gpIq]",
        "RsFg|N",
        "}h$[n",
        "DLk^B\"",
        "N'Kbq+",
        "5AQ!8p3",
        "pbeWithMD5AndCast5CBC",
        ";.}63o",
        "kfg}M",
        "k]p$W",
        "c2i_ASN1_BIT_STRING",
        "{e(>xY",
        "C.mj%",
        "D`C~c",
        "tgje2",
        "wK_T,",
        "}~0eU",
        "2<\\AB",
        "TY/Mg",
        "xwc$u>2",
        "vqz(i ",
        "FNSTENV",
        "\"ryL,",
        "\\}^8d<s%",
        "0E^_$",
        "@X@0E",
        "az!LZ",
        "w>{k>>",
        "F9y[f",
        "vCynU",
        "030O0k0",
        "6O$Om",
        "1&1B1^1z1",
        "Parameters",
        "!~:9$",
        "-wx\\o;@",
        "@'BC!",
        "McJy'",
        "XZ'yd",
        ">/DR'",
        "@f+EU",
        "d.crl",
        "ReplaceOrAddTagOrAtt():1 succeeded",
        "@QqO><",
        "kX:1:",
        "ct^O^",
        "]033k",
        "_NtY=",
        "%m-.BHJ",
        "4&464[4b4",
        "2O3,4",
        ";P;p;",
        "setct-CertInqReqTBS",
        "&$MO#G",
        "RC!736",
        "#Wu'G",
        "2;2W2s2",
        "u\"hHd@",
        "+~s6d",
        "`8.Mj",
        "nF!_Y",
        "_N`Xg/-Y",
        ",I!q!F",
        "FD$ C",
        "}VX%|",
        "0yNyvX",
        "Ph`7M",
        "}iIOB",
        "trylater",
        "!8fuq\"x",
        "\\!g]A",
        "x(-#ZGX_;",
        ":6;D;`;",
        "9e\\c)",
        "YX7g^",
        "3[jKt",
        "oS0Ry_",
        "{44/Z",
        "Q#saU",
        "v\"T]&)",
        "=]`:/3b",
        "1%131@1N1{1",
        "=?AYr",
        "`)+pJz",
        "%b}?6,",
        "ei\"$o",
        "t$$UR",
        "_=v~M",
        "Waiting to process to finish...",
        "!$.>;",
        "GwIUM",
        "N$ pV",
        "he object code copy of the software program}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7940874 , including Third Party Software,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "-cS4u$Z",
        "9J|Q$j",
        "error setting key",
        "Failed to copy 'runCommand' into action type.",
        "N'p3w",
        "Kernel32.DLL",
        "gu7mc",
        "ERFWm",
        "R3a6v6",
        "+6;4s",
        "w$q9BWw",
        "CleanupRegistry:  CleanupRegistry finished.",
        "^SIKM",
        ".OmP<",
        "-?j>uo",
        "5Xd0\\=",
        "w_D%J",
        "[z/c/f",
        "~GSTkoHJW[rvM",
        "Mmc*@",
        "5g6t7",
        "6\"7E7h7",
        "T$\\3L$",
        "\\$0Sh",
        "OnBegin",
        "X509v3 extensions",
        "XP5,!",
        "!w/rk",
        "[VSDATA] %s acquired DataClientLock.",
        "eRGsFr",
        "Jg:>g",
        ";y\\HfHBHA",
        "'MEqi",
        ">-rX#",
        "62$zfi",
        ";,;:;A;F;V",
        "];Y3e/",
        "YrAkm_",
        "t!2!1",
        "!FxkQ",
        "u*4'm|=",
        "Failed to escape percent signs in string",
        "N.ks\":}",
        "3%393D3]3",
        "PY~Q\\N",
        "aECDH",
        "fVXQu",
        "m1c6!",
        "@SeXl3",
        "|1\\CEU{",
        "6,6B6h6",
        "8x70-",
        "8*:<?BE@",
        "V.{4t&",
        ":5:k:",
        "$nO\\J9",
        "La2B=",
        "-E|+8w",
        "3wJ)>",
        "SeRestorePrivilege",
        "CertFindCertificateInStore",
        "S}7t\"",
        "dO&&&&&&&&&&&&&&&&&&&&&&&&&&",
        ",K|;f",
        "3K3&3+3\"373",
        "SnTd3",
        "4}xa@",
        "22!mSK*",
        "91:P:\\:",
        "wf~'9",
        "TerminateAppEnum",
        "|a{vz",
        "$gkiL",
        "3\\$ 1",
        "bHzQXk",
        ">Cu43",
        "!0(0g0",
        "9#:\\:x:~:",
        ",Pt][",
        "ep?U|",
        "42}iQ",
        "58>^A",
        "te6 o",
        "Commit custom action CopyPoliciesFromOldDirC",
        "HELPER_PROC_ERROR",
        "|tW60.",
        "F4}>|",
        "=n2;,41",
        "gK:cs",
        "iQ]2u",
        "p4'`f97CZ",
        "$wJ:I",
        "LPhg.",
        "Error: ERROR_INVALID_HANDLE",
        "nr%`]=B",
        "vpngui.exe",
        "jwiZ>",
        "Exception: %s",
        "jAjgj!",
        ",_{+>",
        "lstrcatA",
        "Y,TSC",
        "u9+|2",
        "ShpMM",
        "ACPT_STATE",
        ".?AVCWin32Heap@ATL@@",
        "Le{E]QF",
        "t;hWp",
        "data too large for key size",
        "334M4s4x4",
        "0j|%{}M",
        "z$L;>n%",
        "+lo0/",
        "O8N6S",
        "CHPjPW",
        "u0jhh",
        "+6T_S",
        "nLVOo",
        "316CD8FA70C1D8D43A3523D36F63A32D",
        "-$&IY",
        "AJP4`",
        "`udt returning'",
        "PRPQh",
        " ~XKB/",
        "PRET RETR %s",
        "&;rs[7",
        "95:X:{:",
        "6 6$6<6L6P6T6X6l6p6",
        "3 3*3A3{3",
        "Wc.D:yw",
        "!e8,?",
        "PROT %c",
        "G6ezMG",
        "5b>l{",
        "Check Point Endpoint Security has been protected with an administrator's install password.",
        "GM@l+j",
        "9 9<9",
        "N+EUb",
        "Sending data failed (%d)",
        "st1a^",
        "7*828",
        "r*s@k.jtFRBV",
        "@X8A7",
        "tAh81#",
        "0$0,040<0D0P0t0|0",
        "%r[v*",
        "1=bl2",
        "!B\\/h",
        "integrity.pem",
        "~0uNc",
        "[}.SO",
        "Success.  We deleted the property.",
        "sWcaDeferredActionRequiresReboot",
        "{^VL`",
        "GOST R 34.10-2001 DH",
        "%(4gz",
        "YeY(~",
        ": :@:L:l:t:|:",
        "Failed to set property in cached database",
        "d!.3h",
        "qY>j<~",
        "RQUPh",
        "SSL_SET_PKEY",
        "@5MoV",
        "@Z#Kk",
        "!,y[^",
        "bjfE9w",
        "{rj1I",
        "3#4P4s4",
        "Unable to restore (error %d)",
        ",KOi[~{",
        "*#==%",
        "SVWPP",
        "ptbIK",
        "]Alu]",
        ")\"|dj'$",
        "8Ugx.yQ",
        "htLT;DTt",
        "h~:qg(",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\helper.cpp",
        "YLLl_",
        "8>FT-",
        "~_e/2",
        "CKb/Zu",
        "t\"}le",
        "+D$ HP",
        "b~4?1",
        "yO0QtOZNT",
        "9]?)L",
        "AXSO&,",
        "id-smime-alg-RC2wrap",
        "jVZf;",
        "HtQWP",
        "B&nu.",
        "G*X&9",
        "{)#GB%",
        "hL@Gu",
        "7^ol_O",
        "g=D\\0",
        "AnMz@C",
        "^5Jujs|",
        "688C;",
        "^rtz^",
        "D$@RV",
        "\"=<YFzIS",
        "+rcQl",
        "^1MMI",
        "/_L7;f\"sV",
        "2!2A2a2",
        "112f2u3,4",
        "> u0F",
        "_k\\GU",
        "P77z]n",
        "ECDH-ECDSA-AES128-GCM-SHA256",
        "SAO%C",
        "fVGFJ",
        "N0$aEV",
        "k'nGp",
        "EXt,XE",
        "T9eUe",
        "Ei7oEuEq7w",
        "2=Ou?",
        "(8zDb",
        "8*8:8A8H8S8Z8e8t8",
        "0@1J1P1`1",
        "Q1Tpv/0n7",
        "33{N(",
        "q'l]_",
        "=!2hX",
        "h>y(VP?",
        "2U<]~",
        "aObOf",
        "<|`\"K",
        "Rz}kIL+e",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{3EB7FEC3-A8A1-4EA3-8F4E-8A6D1782E9F7}",
        "WIX_ACCOUNT_ADMINISTRATORS",
        "Ct&dH",
        "S1}&N0",
        "_:ne%",
        "Lw#d#",
        "7YNOj",
        "-&GS*",
        "NXis#'",
        "un'6!",
        "515?5X5`5g5v5",
        "o3AE7a3n",
        "|~]8d<]",
        "3,444<4D4L4T4\\4d4l4t4|4\\5d5l5t5|5",
        "I8`\"L",
        "tDo$C",
        "^T}ih",
        "configfile.xml",
        "\"]9bw",
        "|$4WSj",
        "fO%f[C",
        "l\\)#H",
        "D$(VUP",
        ")n5o{",
        "4%4:4?4",
        "s#gBU",
        "U#D>c",
        "R,B}D",
        ">5?U?n?",
        "3<3\\3f3",
        "xi;5X",
        "icrIy",
        "_k)\"di",
        "Netscape",
        ")UVYRJ",
        "[(KT!",
        ">.>N>q>",
        "ED$$PVRh\\@!",
        "%w/AT",
        "6'kmJ",
        "OJHL6",
        "Or\"F>",
        "n\\Dj/:Z6",
        "0xI$[ ",
        "X8_8|8",
        "*8^v)8",
        "w}k^=R",
        "OkT<:",
        " <'`=O",
        "2zt.}d",
        "id-smime-aa-ets-revocationValues",
        "t$0UR",
        "3u#dy[",
        "4;'\\Ji",
        "\"*`rL5",
        "gb;y#",
        "mr{C'm",
        "BH5R#",
        "vcYGpW",
        "=T3},5",
        "=1>?>",
        "181z1",
        "545;5G5T5{5",
        "ME&TCv",
        "pE{Zx",
        "StopNetFltDrv started",
        "<<xx++",
        "3#nrn",
        "\"dV)}&#T",
        "dK|+;",
        "id-cmc-responseInfo",
        "=G>X>]>t>x>|>",
        "8!8:8S8l8",
        " HTTP/%d.%d %d",
        "{mOMIe]",
        "B3\"IZ",
        "Sbn*]",
        ")KHjN",
        "4U#5^",
        ":\";o@b",
        "Characteristics Value was changed to 1 at Subkey %s",
        "tlsv1 alert internal error",
        "7U8i8",
        "JE5us+",
        ".]m! V",
        "/\\GJ|,",
        "SiyYm",
        "PyRQyO",
        "xM}Qf",
        ";;<A<V<",
        "~21kl",
        "0$0,040<0D0L0T0\\0d0l0t0|0",
        "Yua3\\",
        "ClrDataClientClass",
        "@gx/xI",
        "1`M:V",
        "cms_DigestAlgorithm_init_bio",
        "CREATOR OWNER",
        "4)t|[",
        "m%929",
        "serial",
        "{(F6<",
        "t{T_\"",
        "itu-t",
        "4:e>_",
        "e%f<i",
        "I!<RkV",
        "7(747@7L7X7d7p7|7",
        "oAtkf",
        "X$k?zZ",
        "soft.png",
        "lKNq.1)",
        "m.ud.y",
        "Oakley-EC2N-4",
        "\\reboot_file.log",
        "^W(g&a",
        "2vW7{",
        "Xc8EB",
        "\\f1\\fs20\\insrsid131787\\charrsid15169477 ",
        "jBjpj",
        "X509_CRL",
        "C~D<-AI",
        ">oLe\"",
        "A.4?L,;",
        "Q!\"V,",
        "HtcHr",
        "x][$#",
        "6.6x6",
        "60646@6x6|6",
        "It!It",
        "^wTAW=",
        "AhM0@B",
        "}j{fS",
        "S)s5o",
        "@u6Dr",
        "^.) y",
        "5=UrL",
        "O{MB7",
        "0<0B0W0]0b0h0y0",
        ";1eT%8W",
        "4yt>P",
        "fQUtLk",
        "g6aM2W",
        "7N}I;B",
        "dhSinglePass-stdDH-sha1kdf-scheme",
        "ssl_bytes_to_cipher_list",
        "1btC1",
        "!mM* ",
        "e5^/(",
        "O-P)w",
        "I&p;b",
        "3RHmv'",
        "j3~=AO",
        "3Bi@t",
        "DH-RSA-DES-CBC3-SHA",
        "9O-]l",
        "GGXdT",
        "i_LE}",
        "#nwHL",
        "<Nd8y",
        "7pzH~",
        "~VwNP",
        "xF>\\6Mm",
        "NDsH%\"]+",
        "*e4o=",
        "UfUfU",
        "]U9/_",
        "4:35~",
        "8|^q+",
        "uW_]^3",
        "vbiX`",
        "J?Q-0",
        "/D$R`",
        "WiX Custom Actions",
        "2x*%f;",
        "Tq&^q",
        "t h$cG",
        "*/bM9",
        "PRINTABLE",
        "080j0",
        "1szx&/N",
        "Se~py",
        "bE89\"T",
        "eEXE:W",
        "_#D~#",
        "=g^TU",
        "c3i:V}@y",
        "]e.rW",
        "0a_ZE@",
        "-Xj#z`Qq$",
        "Up96o",
        "fg}UB",
        "4h!eoI",
        "DSA PRIVATE KEY",
        "DGRAM_SCTP_READ",
        "SEED(128)",
        "=\"=,=6=@=J=T=^=h=r=|=",
        "TI|d3",
        "^TZi@",
        "\\Internet Logs\\",
        "BhA,*<",
        "Hew[#",
        "igjrG",
        "2;F7i",
        "t jzhx",
        "3\\92b",
        "2W&X%",
        "3hh-\\o7",
        "^e jM1",
        "jqUfk",
        "+EMM9",
        "yMK17QLW]k",
        "jDjtj",
        "L .{@C",
        "VersionNT is: %d, Kav drivers will be uninstalled.",
        "8&S~-",
        "Grc`\\",
        "JCURo",
        "vwV/X0l*)",
        "WfalY",
        "cWgv{",
        "-w_=}I",
        "R\"R(S",
        "~|![\\",
        "0</ s",
        "X1W.Z",
        "atlTraceCOM",
        "i$jTj",
        "w:87i",
        "Iu~vZ|",
        "7DZ?K",
        "x|uL6n",
        "~ DSv",
        ":J{OZ0D",
        "VoWQEd",
        "SealRDBmsg",
        ":*:I:_:i:",
        "W@.}G",
        "x{EuC",
        "ujZ[!Z",
        "*g\"0~",
        "V|m!i!",
        "no crl number",
        "mqzLk",
        "YYYaDawG",
        "X509_REVOKED",
        "S[2n[ttm",
        "Js+`DA",
        "](w$[",
        "S|jOM",
        "X509V3_EXT_add",
        "51c6I",
        "4&4+4=4o4|4",
        "'siTE\\",
        ".?AVcharNode@@",
        "f:};/",
        "h1iK4",
        "#\"%:x",
        "J_;m*K",
        "^'$5PA",
        "y2Yql0",
        "failed to add temporary row, dberr: %d, err: %ls",
        "hz*QJ}",
        "JHJXJhJtJ|J",
        "pps29",
        "@Pe Z",
        "&(~o@",
        "%kUKXXE",
        "` c &",
        "lLMzK;<",
        "otlP^",
        "qp }@",
        "EUG>,",
        "qDwCp",
        "&7)q6w",
        "\"F?D31D",
        "Q}:}hx",
        "R.yK\\^s",
        "&wLnt",
        "\\n.|H",
        "NORTELLOCATION.7F579463_4BEF_48D0_80B8_41508273B36D",
        "BSq/S",
        "PI).#",
        "714A60C4-96B1-4CF1-ADEF-23FA47D708BB",
        " 0x87",
        "at<AB)",
        "=]XmZm",
        "eEeC4%NI`,",
        "\"y[Vcvs",
        ">i?u?",
        "r-Mq2",
        "js?&8})",
        "tUD:#",
        " Gs6G",
        "te7V:",
        "`ZMUe",
        "\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\snext0 \\sqformat \\spriority0 \\styrsid13065977 Normal;}{",
        "3t$(1",
        "a_,<K|",
        "E%3;o",
        "1 yOb",
        "]^[_Y",
        "?am8C",
        "file exists",
        "wg|-Fl<h",
        ">+{b^V",
        "Server hello",
        "bn(%d,%d)",
        "wTlTv",
        "tABp)s><",
        "Netscape CA Policy Url",
        "Eg%k4vM",
        "[VSSHUTDN] DriverSetProtectionCtrl: Action: %d, Proto: %d, password: %d, regResponseName: %d, usersResponse: %d ",
        "101L1x1",
        "Failed in OpenSCManager. Error: %d",
        "8)808>8J8X8|9",
        "B4FhD&B",
        "0X]6EX",
        "(yz,=",
        "o,a5L",
        "888?8",
        "KKN\\9j",
        "6p2DYB",
        "1tI0&",
        "p^1~$",
        "`T6{Ls",
        "bn3xx",
        "m%~\"f",
        "h\\z}P",
        "3~nu#",
        "CheckServiceExitCode",
        "f@}(b",
        "/LGI*",
        "4kQieu",
        "_6s'}_",
        "xG9`3",
        ";3;;;l;u;",
        "a=eQq",
        "*fq8<.",
        "R==ef",
        "_aH=u",
        "&jqh}Q",
        ".uw'Qkh",
        "EPAM_CleanOldRollback started.",
        "cpmsi_tool.exe",
        ":N:`:l:",
        "deflate",
        "535]5",
        "&TDI,",
        "*Z(*o",
        "/=0Q(",
        "3(1_[",
        "KmL=}",
        "-XY)u",
        "b\"ok(",
        "UyIQ>",
        "ty`A/",
        "m<Y?F",
        "I[eZl",
        "USR$r2",
        "!\"f[k",
        "-15O{V",
        "5xvDk",
        "|--pU(z",
        "489=&",
        "WnW.Pn",
        "`Tn>:",
        "b1q1HU",
        "PEM_X509_INFO_write_bio",
        "fp,v\",|",
        "Read callback asked for PAUSE when not supported!",
        "080X0x0",
        "%)aN(",
        "[i%&K",
        "[H'uv",
        "ravpn_is_v1",
        "s eRI%-",
        "8M8d8",
        "VC-WIN32",
        "5(7F8",
        "Invalid backup data: \"%s\". Skipped.",
        "K/V!!Z",
        "9?xBSX",
        "URLFprepare ended",
        "6$6D7",
        "mOI93",
        "bv~.>|P",
        "{npL}m",
        "id-Gost28147-89-CryptoPro-D-ParamSet",
        ")P=c3E",
        " iR^:_0",
        "~CR+g",
        "O49TJ4",
        "south korea",
        "7E8n8s8~8",
        "Remote file not found",
        "EC_GROUP_get_trinomial_basis",
        "506K6d6",
        "2!2'242=2G2Q2\\2j2",
        "R{cYQ",
        "?a`w 5",
        ">(?t?",
        "2.0 and later UIFramework exists.",
        "KgI[s",
        "s/uC\\",
        "DH_generate_parameters_ex",
        "cXS\\+",
        "KG.&a",
        "w.T,J",
        "I]`McCY",
        "I5]9$",
        "Checking %s",
        "]10ih",
        "Ul>kR",
        "&M>+Q(IT",
        "FeatureTVDriver:  FreshAfter started.",
        "6o[(n",
        "DS_CopyToSystem32 succeeded.",
        "4(o4mhn",
        "~UOp1x",
        "pBie}",
        "n\\Mq b&",
        ",ixx@",
        "#\"-?}",
        "1>)^e8",
        "Q lx,",
        "\\$8US",
        "4t(#\"",
        "8c9n9",
        "JQ sU",
        "z/k.[x",
        "fZlZzZ",
        "invalid fips mode",
        "VPN_ProxyServer.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "~+.v4gC",
        "2L]Ci",
        "/q~RBtY",
        "G!.i'$f",
        "rG>%\"",
        "->r?]",
        "D$$_^]9",
        "Lkui-",
        ".)~+^`",
        "W~AH#",
        "$QWR0z1",
        "L0-t_RdY@",
        "FfqGX",
        "m0V- ;",
        "*1Cp@;",
        "<(h=!yAx",
        "^q6 v",
        "BFWg)",
        "75'$w(\\",
        ")b&BS",
        "YUw=]",
        "Z3L$@",
        "#X\"8_&",
        "laoc@",
        "[l`h*7",
        "\"z~8t",
        "a]NlH3",
        "*)Pd+",
        "XmgUJAb;",
        "F'j8k",
        "!NiS\"",
        "internationaliSDNNumber",
        "0;1O5m5",
        " 86(vp]",
        "F9r4%",
        "#4u4s",
        "~<&XLl",
        "I)4&V",
        ".\\crypto\\cryptlib.c",
        "x~M\\/",
        "b4t(#",
        "VY\\\\n",
        "rCd-w",
        "u!i4,",
        "QJh.E",
        "bkQBp",
        "VGm:+",
        "6`7m7",
        "5i;1S",
        "unknown public key type",
        "jF&FSsM",
        "M6^%N",
        "8#[Y{6Z",
        "|ZNmpgteZ`tj",
        "3%4x4",
        "^[Qou;",
        "j 5~-",
        "71=J{",
        "h?a$$[U",
        "W=t&M",
        "=C=t=",
        "J,J8J\\%",
        "'j}?`",
        ";WmOn",
        "FeatureSC INSTALL_SC=NO",
        "belgian",
        "ZO*)i",
        "m&I\"+r",
        "qV'15/],",
        "<7<S<o<",
        "[G;rw",
        "cWJ(Rb",
        "G76@9",
        "^zLCY",
        "&=J:,y",
        "I?2js",
        "Yd=;4",
        "5#_wI]T",
        "^8zK}",
        "n'#&n=",
        "wmMzH",
        "=l#ME",
        "4O:^E",
        "vFPI$",
        ">L $U",
        "H6SfFwk",
        "#VA:)",
        "5B&@W",
        "=x=[>j>",
        "ConfigureClient:  Configuration file copied.",
        "@ewdK",
        "8+R=V]",
        "YD}FR",
        "passed a null parameter",
        "SOFTWARE\\CheckPoint\\SecuRemote\\",
        "a-qM,",
        "{~M*%=",
        ")K8$ ",
        "ae7b4c191ba8292337a469bc25ec3d411f06f53a73e224c5292c8de0516732307070a1c0660d125c7d44553488700a4d7bddd3444299910e254ab984c3a219ae",
        "=0=8=@=L=l=x=",
        "7OypH",
        "w~e?e",
        "gh](=",
        "!/EMm",
        "R&e<Y",
        "fg@1O'",
        "}/MzZ",
        "f#<I9",
        "qJf]1",
        ">mfSd",
        "FO;t$ |",
        "bad pad byte count",
        "9?mVq",
        "4#4+464d4",
        "ghBy_",
        ";t$,r",
        "Sp'p8",
        "=2#?c",
        "CD$XPj",
        "7/1@V",
        "aux:)",
        "m$xx0",
        "tS>L,",
        "?'?C?_?{?",
        "_NK2>",
        "Fp op",
        "3|Hlb:",
        "rnzev",
        "v^;K<",
        "BhS.I",
        ">%po`n",
        "IsM[=",
        "6 6$6(6,6064686<6@6D6H6L6P6T6X6\\6`6",
        "L$h3L$H3L$83L$$",
        "@}D(=",
        "4,5Y5",
        "RSDSn%",
        "gs]dy",
        "313C3",
        "~'Mm/",
        "zpzi'",
        "ExecuteUmsThread",
        "B6/wQ",
        ",*KLxd",
        "<-=G=T=",
        "HAIe=",
        " m4g^5S",
        "laAl?}V",
        "+*\"1,\"",
        "%s\\System32\\CPEPC_PLAP.dll",
        "c!>$P3FX",
        "M$IH#",
        "[Z-),?",
        "!G\\Pz",
        "3M4W4t4",
        "[VSDATA] tvfwFirewallAddXMLRulesFromFile tvfwFirewallAddXMLRulesFromBuffer failed %d",
        "t\\eoN",
        "iSjKf",
        "go\\'=",
        "TPpCMR",
        "b1$0F",
        "DJ,f\"0",
        "SSL: Unable to open issuer cert (%s)",
        "Ll'NH",
        "M0x@HM4",
        "0N6sc",
        "Xwy]wT",
        "&Oka#",
        "`[N[d",
        "tli!6&",
        "t$hSV",
        "]0W0b",
        "uGhtf&",
        "GetLocalTime",
        ".?AV?$basic_memory_buffer@_W$0PK@V?$allocator@_W@std@@@v8@fmt@@",
        "Te8$s",
        "G+ l#^",
        "H)bH@ ",
        "%a%ec",
        "FU-Aaa",
        ".\\crypto\\ec\\ec2_mult.c",
        "Oo\\J2",
        "\\2'7l",
        "p88Hp88H",
        "3!mJ!",
        "&Rd'l",
        "L@I2r",
        "3\\$ !",
        "46X77",
        "\\yTQo ",
        "-bp]<",
        "0$0O0l0",
        "?h_=a",
        "Dak[S",
        "46G^k",
        "zwFtQTh#",
        "6$6U6v6",
        "saving file names to %s",
        "bB9\"gw",
        "9Ia^4",
        "Kb56Y",
        "e4*S]Ak{",
        "ISH.T",
        "ExtractInternalFilesToTempDir ",
        "H_zW(",
        "v1(0)",
        "xv??Y",
        "8 8@8\\8",
        "C\\@>!",
        "~m\"G8",
        "ZyN< ",
        "\"(S2@",
        "id-cmc-popLinkRandom",
        "'z%Jzuo",
        "N.s%i2~+",
        "M='jCX`",
        "5{G4*2f",
        "8KCa|",
        "~:sEL",
        "d.sign",
        "wgLZ_",
        "Mnpak",
        "?:u\\G",
        "3Mez8",
        "ie5A23",
        "5 5(50585D5d5l5t5|5",
        "}BUC ",
        "GetCurrentThread",
        "Z\"n;{",
        "&,/yAQ",
        "iwzJy5W",
        "2_^g#",
        "M/8WbW",
        "V%(:r",
        "Yqj(rE",
        "RSA_ITEM_VERIFY",
        "twi;z",
        "$5=GW",
        ";T0#-",
        "ByAicL",
        "Q4<L1+",
        "JE_i-",
        "*jiJ8",
        "FC$.zw",
        "\"v3e8l",
        "id-qt",
        "Q$lD-F;",
        "hNJ02,",
        "PATCH or MSIPATCHREMOVE exists. Will not add CleanAvsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989 row to RemoveFile table",
        "7C7T7y7",
        "5#5?5[5w5",
        "3949L",
        "]K!PI",
        "vHPOZ^",
        "V#q&hz",
        "2swF)",
        "7:`p0",
        "CheckIfRebootRequired",
        "293k4",
        "0eo$OP",
        "DSO_set_filename",
        "exit update_config_tool with rc = %d",
        "-up*]",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2260672\\charrsid15169477 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "])Z(uVO",
        "*WQ:e",
        "jsjpj!",
        "i~PW9",
        "C WVP",
        "h]NM3",
        "klC%n",
        "|Z4:l",
        "/CVuMw8",
        "i\\zh{1",
        " `5_P",
        "jt>m)",
        "}Xk{I",
        "%5.G|6Z",
        "94]}r",
        "FN##-TVZ",
        "wqfGV",
        "hz)\\m/",
        "DisableServiceAutoRecovery of Service EPWD failed",
        "WHkF=%;",
        ";a$Ji",
        "you%O",
        "9'_;bM+",
        "]NQG,",
        "k7E\"'",
        "FWRemoveAfter",
        "< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<",
        "|(J9s",
        "3-5Z1",
        "$*dMlb",
        "|(@0Qax",
        "KPQ0-",
        "3QDXBSImTo",
        ":{h}@",
        ".a!`w",
        "SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\GroupMonitor",
        "KqEQ#]",
        "X{L=6",
        "[)_)P",
        "[WinFW] GetWFStatus, failed to get the standard/private profile, error=%x",
        "'<I?b#W",
        "WP$8h",
        "4Z4_4v4",
        "@^*Z+",
        "ji|U`3",
        "t=mgg",
        "D$DVP",
        "<>csy",
        "=(>E>b>w>",
        "RulesGetPropDWord",
        "){xuC",
        "=H>1g",
        "+KVQJG^",
        ":LvXo",
        "dO|XE",
        "Reboot will be required before the next installation attempt (this version or a later one!)",
        "-A65J",
        "[J4=n^",
        "poDbw",
        "090U0q0",
        ":'<I<[<",
        "=&P|&T}=",
        "ZN~\"f",
        "L$P3L$T",
        "dgJ'4x",
        "y5HR3",
        "yQhcw",
        "G:   ",
        "R$-15x",
        "\"E{i-m",
        "Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.",
        "<Piu<",
        "no config database",
        "oVW?{G",
        "[R\\TB",
        "S-gm=",
        "6S[QBW",
        "V;PtW",
        "V$n3n]",
        "$9w.B",
        "Uh`Kd",
        "\\Mje]",
        "e>oHSnOP%",
        ":Dg`O%",
        "\"$ZN9d",
        "u-RQSj",
        "]<)uY",
        "=!=:=S=",
        "f;`xo",
        "O.m&]",
        "[thunk]:",
        "4)4D4|4",
        "(!8g$",
        "J`s'R",
        "*ve{e",
        "=P.{`o",
        "@O~MD",
        "Y9|Y/",
        "A2|)u",
        "K[\"'}",
        ".\\ssl\\s3_both.c",
        "[g~1j",
        "-n|p[",
        "OXY4#?",
        "4M>]x",
        "Stopping existing product (0 of 7 tasks done)",
        "unknown format specifier",
        "^maA;",
        "0 0$0(0,00040",
        "'=-~X",
        "3}\",D*<",
        "*;\"*]",
        "zd]Zu",
        "rt}d,",
        "hlv,9",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477  or its software to third party locations around the world, and you authorize Check Point to do so.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13922132\\charrsid15169477 ",
        "4.<+@g0=J",
        "2j/@n",
        "jSYf;",
        "BH~sf",
        "_V_A:Fr=",
        "q&#eT",
        ".wvS8",
        "&a{?3",
        "UTCTIME",
        "YHXNU",
        "[=;{*",
        "2IGo.",
        "3U4_4",
        ">/>|>",
        "op\"}b",
        "Added %s:%d:%s to DNS cache",
        "&R&sv",
        "_(``T",
        "PMADDUBSW",
        "uk\"(%",
        "W#s0Ld",
        "vO~{O",
        "XWy$sN",
        "\\sbasedon10 \\sqformat \\styrsid13193413 Strong;}{\\s26\\ql \\li0\\ri0\\sb100\\sa100\\sbauto1\\saauto1\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 ",
        "unregisterPlugin",
        " 0x8f",
        "x=JeK",
        "!hm\"VXP*Z=4(",
        "\"7LA*z",
        "=nT4p",
        "#+.&)M%",
        ",Jqa:",
        "3\\P@`",
        "T$R%(*",
        "tUsvR",
        "X509_NEW",
        "9k5dF",
        "\"(V=)C|",
        "iE+)v",
        "securitypolicy/osfirewall/rulegroup[@name=\"protmereg\"]",
        "29!i:",
        "fn99( {",
        "G[Y=o",
        "pubkey",
        "expected digits after -",
        "!@*3,\\",
        "[>,qh",
        "t1AeXX",
        "#(^k*%UL",
        "\"E@n|b<",
        "yyq`]v",
        "4Vd}X",
        "X509_CRL_add0_revoked",
        "ir\\`NG",
        "W\\?8y",
        "m* `.",
        "&B*m6",
        "Ha7RPA",
        "\\Y3H&~",
        "+U{*[",
        "Q?SV%",
        "4dz%T",
        "L$X9L$",
        ">R4/E",
        "D<]U_",
        "6,72787>7D7J7",
        ";<<]<x<",
        "\\par \\tab a. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5000668\\charrsid15169477 F}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ollow the service request procedures that Check Point or its partner provides; ",
        "D$\\jPP",
        "PKCS12_pbe_crypt",
        "64'vI",
        "XE|DR",
        "4>{{N",
        "S%i^-1",
        "d\"L G",
        "m6WN`xx",
        ";M<\\<",
        "a^fF[",
        ".uTG3)4wb",
        "LsnFX",
        "Netscape SSL Server Name",
        "\\*k[N",
        "#V'V)~8",
        "@U'qG",
        "LK#~R",
        "\\n).RZ",
        "Ao-H?",
        "O-wq\\)",
        "\\j&C:",
        "GetTempPath2W",
        "<B<_<",
        "7KDj%",
        "Uh@^\"",
        "*N?YU",
        "N7U$B",
        "aPoLv",
        "rHA#\"",
        "VUk1Y",
        "\"aqX;",
        "_8kZ!",
        "szCOz",
        ",5tKh",
        "Tuesday",
        "-Pj:!",
        "g5MS&[",
        "6/6<6E6R6w6",
        "4#4(4.444:4?4E4K4Q4V4\\4b4h4m4s4y4",
        "8s[(,",
        "414Y4",
        "6K.3y",
        "~72+L4",
        " Xv4f",
        "6qCXK",
        "LQJXs",
        "PZT-i",
        "83~)h",
        "RemovePRHelperReg",
        "-PsGA",
        "\\*+3T",
        "hK1IKb",
        "J<x2CQ",
        "lT%lH",
        "D8$8!8",
        "F]JH*",
        "wz=N M",
        "i%daK",
        "oE!b*P",
        " .aw`",
        "ejczl%",
        "]8OrL",
        "set-brand-AmericanExpress",
        "5!^h%",
        "/7]IU2",
        "QF+ts%",
        "4RfWE",
        ":2|nh",
        "9F9~9",
        "&U^L%|",
        ".?AUITopologyNode@Concurrency@@",
        "=;>z>",
        "qnXfB",
        "'0yffS",
        "cTn |R",
        "'V?LJ",
        "P@.\\crypto\\engine\\eng_list.c",
        "DllUnregisterServer",
        "2-2A2[2w2",
        "c&e[tp.t",
        "`local static guard'",
        "318.;m",
        ";E;|;",
        ",QHgZ",
        "WeHt*",
        "7e#$9",
        ";vxA-8|",
        "qL(~i9",
        "8?8g8V:y:",
        "insufficient memory",
        "\"g4Ud",
        "Of%Ix",
        "1s!Th]+n,",
        "Mv7A9L!",
        "SSL server",
        "Sbt}%+<",
        ",`EF!y",
        "no shared sigature algorithms",
        "0th8^c",
        "4m437h7",
        "&U+,1",
        "U$AkKzm",
        "PreInstallCheck:  Check for minimum file version.",
        "D$dPhP|",
        "\"->er",
        "6`7P9",
        "R4_i%",
        "KNyl\\@",
        "iN|NC",
        "0G4z\\]",
        "o|M|t",
        "]k8<,xGW",
        "keyAgreement",
        ".cdP;",
        "K(X*a",
        "\\E&4Z",
        ".?AV<lambda_b690109b5df829e3c59a10ce74b30101>@@",
        "[e;-8G",
        ">i*|@",
        "E*5q`",
        "H'/LU",
        "2/3J3O3U3[3m3s3",
        "0D0|0",
        "9V:j:",
        "]6\\+8",
        "FNJ|W",
        "^2Jxt",
        "0h*{kD{P",
        "Km-_I<.",
        "?x3x2",
        ";|$$|",
        "|u+dq",
        "B:J=H",
        ".?AU?$output_adapter_protocol@D@detail@nlohmann@@",
        "H4q{v",
        "H:0:c",
        "LnD3aLa,I",
        "z|gy1B",
        "[H69`",
        "DuAp3",
        "EpRGN[",
        "pK.z%v",
        "LSN4+",
        "A),1X",
        "_KDnx",
        " %HQ0",
        "V,G7Gel",
        "prim: ",
        "6Q{kEnt",
        "<\"&cEt+@8",
        ">uqi\"",
        "eT^*O",
        "upj=h",
        "OPENSSL_DIR_read(&ctx, '",
        "j _f;",
        "F(hiu",
        "=Qf:n",
        "id-smime-aa-ets-signerAttr",
        ":MARx",
        "f(E_:",
        "curl_easy_init",
        "[OaKAv",
        "AVSignaturesUpdateStatus",
        "Avl<OLj%fr",
        "Ct\\'d",
        ">?}*i",
        "z@Fjw",
        "=Rj9N.",
        "0H0L0P0\\0`0",
        "QvEvA",
        "E-i5$].<",
        "6d[0j",
        "Wu(0[",
        "/6A0|B",
        ">~3y#",
        "juX}Gj",
        "wB+6 l",
        "*1@Iik",
        "77#*[",
        "=y4At",
        "8o\"8=Vg",
        "_C;h:",
        "/+`+MR",
        "WNW={",
        "=i/!,.",
        "Za'el",
        "PVVj/V",
        "[`1px",
        "n@wKB",
        "q+)`Q",
        "wVwZw`w^uf",
        "'cZY.,",
        "OLD_EC_PRIV_DECODE",
        "p+=u_",
        "j}k-:8",
        "1.kFt",
        "q&}xW",
        "5%5V5f5",
        "Jy{,!)",
        "rSW4H",
        "Ag{QL",
        "&iD!6",
        "V*B[Z",
        "/_!mU",
        "error signaled by ssl ctx callback",
        "a=F\\f",
        ";t$8~",
        "0V0e0",
        "cert_info",
        "6S6Y6p6",
        "}<8wT^",
        "&?k}>",
        "_V_Z_[_\\/",
        "8.9.2.0",
        "mb\"f>",
        "SECG curve over a 192 bit prime field",
        "-pSac",
        "P'T(B",
        "|!='{",
        "N/VP<y",
        "N^R^&fRf",
        "dK-e*To",
        "nK$n,",
        "zY5ksT7tI",
        "?V\"kY",
        "$@wVG4",
        "USERPROFILE",
        "DTYP@",
        "qvw]-",
        "dJKTBN",
        "3&3-343C3N3`3g3r3",
        "K|G^N",
        "$3xJ-",
        ",>06U",
        "~6hjxw",
        "he license and delivery of technology and products abroad by persons subject to the jurisdiction of the United States, including the Export Administration Act of 1979, as amended, any successor legislation, and the Export Administration Regulations (}{",
        "LoMN/",
        ".\\ssl\\t1_reneg.c",
        "ities to permit Check Point to fulfill its obligations}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3736522 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  ",
        "h_OE<",
        "sKKm9",
        ":'hk*}Wn",
        "rV1;y",
        "FVV@|]hm",
        "input not reduced",
        ">=PVt#",
        ".?AVbufferedString@@",
        "KP5zRA",
        "}UGW+Q",
        "g/Et[",
        "PvDuQ",
        "Ezz#dI",
        "0ud/v",
        "6/6W6",
        "f9F0u",
        "/lli;&",
        "%>=gb",
        "GqnsC",
        "w_^[]",
        "Ad*;G",
        "failed to set integer value at position %d",
        "t3Sh\\",
        "NFZT'",
        "r*RD{L",
        "ZD`98`",
        "IA5STRING",
        "Failed to write number to script.",
        "Sc\"e9",
        "failed to open view on WixFirewallException table",
        "PostSwitchbackChoice",
        "';S.:",
        ".?AVlogic_error@std@@",
        "W#y;o",
        ")0.0x0}0",
        "ReplaceOrAddTagOrAtt():2 failed",
        ";,<M<",
        "8!8A8a8",
        "3>y7d",
        "D$ Ph(",
        ";<]|y",
        "u*Y0,",
        "bfr$&",
        "RPlwC",
        "boost::filesystem::copy_file",
        "<V<`<}<",
        "&!Xu5",
        "6(606<6\\6h6",
        "A~hoO",
        "{:Xt}",
        "l+6T$",
        "O\\*VhT&",
        "VPWhhk#",
        "[w;yd",
        "ac6?6",
        "ZucGS",
        "pci|NkJ",
        "iF0V4j",
        ")-0V=P",
        "?(?7?I?S?`?i?v?",
        "NO_64_BIT_SUPPORT",
        "failed to store ssl session",
        "9QpM%",
        "!~ssL-r",
        "oNC{Wn",
        "F?eT|",
        "UpdateVsconfigXML:  AV is not being installed.",
        "TrSAA.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "w%(E)",
        "l;c3c",
        "w\"%w;d6",
        "2(2H2T2t2|2",
        "Zq]I;_",
        "vsinitSA.ini",
        "bF1+M",
        "w2;zp{U",
        "g2K@)",
        "6|[jA",
        ".text$mn",
        "-w!#e",
        "4Z4l4z4",
        "KbuJg",
        "4<4H4h4t4",
        "NiQ?uy",
        "{\\_^][",
        "3^N/j",
        "5eROO#",
        "_c{eh",
        ":r7k753AGP",
        "~cB?8",
        "},I}{",
        "G_XYGS",
        "`mWZ:",
        "X.<]q",
        "!x('+",
        "s>6ieZ",
        "s\"E{f",
        "{r|V)",
        "nsRevocationUrl",
        "Ai13=p",
        "(:{P<_",
        "Af~n ",
        "Ff@%q",
        "t45M~'",
        "Ht!9@",
        "EVP_SignFinal",
        "v/EMK",
        "AESGCM(256)",
        "5dk\\}a",
        "RSA part of OpenSSL 1.0.2h  3 May 2016",
        "9 9(90989@9H9P9X9`9h9p9x9",
        "ftp server doesn't support SIZE",
        "hH,uz",
        "=&=?=[=w=",
        "4Zqr%",
        "F.&m90",
        "failed to load WS2_32.DLL (%d)",
        "messagedigest attribute wrong length",
        "+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v",
        "I[_zXY",
        "nem_svc.exe",
        "qO8Up",
        ".!!zJ[",
        ",_[WN",
        "^wJ@/",
        "psg_enabled",
        "NMN+0>",
        "R9i-*O",
        "qTqMf",
        ",5,E,",
        ".?AU?$error_info_injector@Vbad_format_string@io@boost@@@exception_detail@boost@@",
        "IJOFK",
        "\\curl_cli.exe",
        "G8V8_",
        "no hostname specified",
        "Cy'9i0",
        "(null)",
        "*`&Ai",
        "@gA`Me|",
        "pMh'y",
        "cdIH'",
        "2S;O)",
        "4jY')",
        "MDUgl",
        "otherCert",
        "(IC})",
        "54lU*",
        "CVTPS2PI",
        "$B3!BW",
        " rIU~",
        "setct-CredRevReqTBE",
        "H|^`J7N",
        "mP+,\\",
        "]@gj\\",
        "x3TWx",
        ";';9;k;",
        "es-VE",
        "T4Ur:?",
        "yv+*#",
        "OiuT\"",
        "<+Od:&4",
        "`.W$^~@H5",
        "DO_SSL3_WRITE",
        "JnbLL",
        "J MNG",
        "J?'G>^4",
        "u!jfh|",
        "AC_TermOnExecution",
        "p8(Y/",
        "s{uaW",
        "vR;UJ.8",
        "2:7Be",
        "Standard",
        "$tPDW",
        "unsupported parameter to CURLOPT_FTPSSLAUTH: %d",
        "+FL+NL;",
        "gT@jaO/",
        "5w6V8",
        "x3 FFo",
        "343P3l3",
        "w76Db",
        "3vQbQk",
        "?%?T?^?l?~?",
        "RegisterSecureAccessDSM:  Unable to create SecureAccessDSM registry key",
        "WN)-$",
        "long ",
        "jE\\ef",
        "ujxft",
        "|d3H.",
        "z}*z~",
        "f4LP2",
        "PKCS7_dataInit",
        ">!>1>A>Q>a>q>",
        "D$@Ph",
        "0IQ06",
        "t f;E",
        "YP?e0q\"",
        "IXF]=",
        "),tSU",
        "p4O($",
        "2Z3|3",
        "api-ms-win-core-file-l1-2-4",
        "%*I>k",
        "digit",
        "tQfff",
        "^OTj$",
        "f0my&",
        "+f(\\Z",
        "2]2j2",
        "+-E]l",
        "VU:xk9If",
        "IUMTV",
        "_VU_G",
        "s7+e0F",
        "aMK^]&",
        "8X![j:",
        "WSAEnumNetworkEvents failed (%d)",
        "9$9=9E9L9j9",
        "shutdown.exe -r -t 0 -c \"Restart after Microsoft .NET Framework installation\"",
        "0Q0t0",
        "z p~!",
        "Y;-1A7",
        "+yN8.@",
        "DATA failed: %d",
        "x;*!T",
        ";!<<<h<",
        "j*-U03c2",
        "=dYKG0",
        "H6`t `",
        "-tPsQ",
        "80.90.5592",
        "QoA#f",
        "^@4E=@",
        "t)F<r",
        "XAGBAHd9",
        "\"s\\s;}",
        "|]E-K",
        "Y@fwf",
        "H|&Gw",
        "(D78&",
        "9TG#]^",
        "rk[04",
        "b-m_i",
        "l> UN",
        "iuUk6?",
        "]~<i^",
        "v86~o",
        "|&Mw,",
        "TnYekY",
        "&$bI#{",
        "c\\TLP",
        "/Kzgs",
        "8$8<8L8P8`8d8h8l8p8x8",
        "http://ocsp.digicert.com0C",
        "failed to remove attribute: %ls",
        "d=o#y",
        "h5IS`",
        "U9NDxI;6.",
        "gS'!J\\u",
        "9%91989>9H9h9",
        "CT;CXu.",
        "rUW^1V\\",
        "%u %s %X %d %s %X + %X",
        "s\"eoLqM",
        "eAwnA",
        "%p\"(G",
        "[s.v,e",
        "Mkv2+=",
        "CreateXMLDOMElement failed",
        "C\"vk?a",
        "4\\]4\\\\",
        ";K;o;",
        "8$888X8k8",
        "$)$=$A$C$M$_$g$k$y$}$",
        "InstHelperVPN.exe",
        "?)x<H",
        ">` y;",
        "Rb9_n",
        "3/3d3",
        "X=J=wv",
        "LoadNTDeviceDriver",
        "##yvp",
        "rx|iF",
        "]Tv)F",
        "GetEnabledXStateFeatures",
        "failed to write exception remote addresses to custom action data",
        " Xf0wD",
        ";{q,~",
        "6 6H6W6p6",
        "I2mb#",
        "\\*%@9",
        ";4mu'",
        "W\\HWf",
        "?'{pu",
        "2\\3r3",
        "\"-Ryi",
        "FIiVDUq",
        "H%N{^",
        " ~q5E",
        "3S)uX",
        "xzH#f",
        "E('oK",
        "V\\]z'",
        "E+@Vv",
        "{=q1&",
        "2/353D3J3S3q3",
        "99Zxukr",
        "3/i?DU",
        "2Zfjf",
        "dumpIndex",
        "0I0e0",
        "494k4",
        "ZNKhc",
        "qualifiers",
        "5F6}7",
        "vRL,}",
        "<yfv&",
        "Ty`G-",
        "AES-256-CBC-HMAC-SHA256",
        ".?AVstl_condition_variable_vista@details@Concurrency@@",
        "german-austrian",
        "rf/V%",
        "==cQJ",
        "2OWwP",
        "YPhG)G",
        "dtls1_send_server_certificate",
        "h?/j)",
        "IQPWvEvy",
        "Cisco is installed.",
        "elCCk",
        "Yl-2n",
        "=F=\\=",
        "n3@oH}",
        "fD$v#%",
        " t.]:Qq",
        "Agtx6",
        "*/b<YZ",
        "@hR-k",
        "|c!O7",
        "no conf",
        "(lPL2",
        "otherRevInfoFormat",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\f1\\fs20\\insrsid15742087 WARRANTY DISCLAIMER}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9971420\\charrsid2646135 .  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420\\charrsid2646135 EXCEPT }{\\rtlch\\fcs1 \\af1 ",
        "g)1n}o]",
        "o0_q+3",
        "archiveCutoff",
        "<4<g<",
        "<'<@<Y<r<",
        "1\"2Q2f2",
        "qw%X0)",
        "ogqm ",
        "jpjij'",
        "\" m>xv",
        "DIk.j",
        "RVlIy/",
        "l*p8d",
        ".?AVCacheLocalScheduleGroup@details@Concurrency@@",
        "X5MnIO'L",
        "Failed sending PUT request",
        "l{Cd[",
        "9{V~g",
        "PasswordVerified RC=%d, token auth is on therefore selfProtection is not Disabled",
        "Zmw[u",
        "sI*rw",
        "h?B\"k",
        "PbPl2",
        "(&w6A",
        "T$L#L$T",
        "FeatureSC INSTALL_SC=YES",
        "fHvxH",
        "Rdeo{",
        "1&282^2",
        "<0:08",
        "@+d_*q#",
        "7\"888h8",
        " WFaU^",
        "Vjqh`",
        "=V=b=~=",
        "76xC@ ",
        "WTLIX",
        "{YY]]",
        "2/+%r0",
        ".?AV?$_Func_impl_no_alloc@V<lambda_b690109b5df829e3c59a10ce74b30101>@@XABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@K@std@@",
        "yX\\&l",
        "=i>$?j?",
        "\\#`+#P",
        "$i%mB%",
        "0R6q=",
        "\\YM^0",
        "yUKdoA&",
        "<ry~ ",
        "L>7JhNB",
        "DTLS1_PROCESS_OUT_OF_SEQ_MESSAGE",
        "GetCustomerNo",
        "ocElU",
        "%a:j;",
        "L'|Jc",
        "InstHelper.exe is not running.",
        "%02x%c",
        "C3U/wZ@",
        "7>7f7x7",
        "\"uH\"f",
        "oVgMZ",
        "{wLZ`",
        "dtls1_read_failed",
        "*rV|VvVzV",
        "1kF4,",
        "cP|]%",
        "Cv%a+",
        "e+rJr",
        "rrrrq.",
        ":I?Qh",
        "/dY&Fy",
        "KKW)j~",
        ",~ v3",
        "Sm>Bs|",
        ";Am|^",
        "FbK|n`",
        "8zM#L",
        "h+wBtI",
        "%>2/tb0R",
        "hash.exe returned %d",
        "<J<T<h<r<",
        "hQ~;I\\/",
        "767R7n7",
        "n_yPXd]WB",
        "4)Tn|",
        "0+0G0c0",
        "b-z,Y",
        "cipher parameter error",
        "W.#o$",
        "/t/CN422s2",
        "{} bytes written to {}",
        "FreeDataClient()",
        ">xpB5(?{",
        "%5^n ",
        "*@L$^",
        "x:x;x<x=x>x?",
        "vr:t[d",
        "v'<rw",
        "yK5/}",
        "]By.d",
        "0dHTl",
        "MPO.|",
        "I$D{8!",
        "DSA-SHA1-old",
        "?{7D(>",
        "encrypted length too long",
        "wkkJk,",
        "8nnL8",
        "'w\"^}",
        "7cGZB?X",
        "vMOom",
        "|wHi]",
        "bvqy(",
        "!N}uF}8!Ve-_",
        "iIUXJ|8",
        "n`@WmNf",
        "y,o,M",
        "383>3G3P3n3s3z3",
        "PKCS7_verify",
        "unused",
        "0.<~8~",
        "Ftar*",
        "?(qIz",
        "ox(z6",
        "W.#,.vP9",
        ")7/OO~",
        "0p$h\"[",
        "7U8r8",
        ";O;m;",
        "#Cohor",
        ": :@:`:",
        "oyj~'0",
        ":,Zn\\",
        ">d]Q@",
        "Failed to MsiRecordReadStream (%s section)",
        " discretion, that the allegedly defective item is not covered by the terms}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11029351\\charrsid15169477  and conditions}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 ",
        ";$;0;P;X;d;",
        ">_^][",
        "i@)tY",
        "E(#e5{",
        " :~i%",
        "0!020]0l0u0",
        "a_!0`Uy",
        "F3JKB",
        "<H78e",
        "YDv7~i",
        "^lIa*",
        "B~@mi",
        "m%K_.",
        "l\"W%g",
        "T'!+%",
        "\\q(3Y(",
        "* 4CJB",
        "ra|pM>",
        "Ar#,F",
        "`g@aT",
        "-@Gr-",
        "[=~W'",
        "7a)(292",
        "9^ tO",
        "|_XXF",
        "3u;/O",
        "8\"4,H",
        "z:1)5",
        "FETCH %s BODY[%s]<%s>",
        "Mw*1=E",
        "=p]\\|v",
        "#c}][",
        "1pA+Axc9A",
        "z;jbK",
        "#b&o-",
        "T~qR/",
        ":(:4:@:L:X:d:p:|:",
        "%PNr4M",
        "9s,~g",
        "I7Ai[z",
        "7*888a8p8",
        "3,3S3\\3|3",
        "\"F*YT",
        "/pA6y8",
        "$PRhc",
        "#DYNM",
        "'3)IHM8j%",
        "aq4u*H",
        ".\\crypto\\buffer\\buf_str.c",
        "&g9bY",
        "?`;Rk",
        ".sMQo",
        "scsv received when renegotiating",
        "rigl`",
        "O853N",
        "InstallPrerequisitesNoWait started",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  359",
        "!R%x=G",
        "EDIPARTYNAME",
        "nOe]$",
        "wV$jtJ)",
        "#-,m;M",
        ";(;,;8;<;\\;`;l;p;",
        "wS/xRv",
        " g.M\"",
        "X;uQ0L",
        "0P/x9r",
        ":kbd|U",
        "HtPHt",
        "LI3z}C",
        "Going to add temporary record to RemoveFile table: (CleanAvsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989    kave8.dll.8792D4CE_35B7_41EC_AEEC_B7D5617B0989    *    Avsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989    1)",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Limited Software Warranty.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "7>w7\"",
        "d$qX%",
        "&I,nT",
        "|~0<@O",
        "Y[BJO",
        "X<aak",
        "llVmY#",
        "C0L.@E",
        " Abnq",
        "kEA?$",
        "9\\$ t#hq",
        "(0J;|U",
        "MmZ-Ho",
        "4M7^YZn",
        "4>Yt^*",
        "u(ZXH",
        "WXhk,",
        "K+rHW,I",
        "R)9hXO",
        "&<J\\LH",
        "3H4i4",
        "}}mL??",
        "(,FGD",
        "PKCS12_create",
        ">E?J?O?",
        "RC2 part of OpenSSL 1.0.1t  3 May 2016",
        "Vm~G@",
        "d^yf6",
        ".?AVUMSThreadProxy@details@Concurrency@@",
        "979S9o9",
        "J/59?",
        ";\";;;T;m;",
        ">Er<+r3",
        "UNINSTALLFW_FAILED",
        "Z)oA+N8\\",
        "Failed to register the service name with the Restart Manager session.",
        "v)#|q>7",
        "4F4F5U5l5B6",
        "PMINUB",
        "e+M&W3",
        "aoJl8o31",
        "](Vg2",
        ">|!@YY_M",
        ";L;\\;h;p;",
        "generator:",
        "F[I2J",
        "UKC\"TAZ\"",
        "6/7Y8",
        "8WT1z",
        "8M8o8",
        "~T5D<'u\"",
        "aL^Fi#",
        "J5$-P",
        "I*hQ *",
        "Q4:0A",
        "WV@~.>",
        "F:\\ckp\\src\\EPC_Slim\\E87_10\\Slim_Standalone\\WIN32\\release\\slim_install.pdb",
        "_exit",
        "'hSHR)",
        "lt-lt",
        "%HN X@",
        "Failed to create the Global\\WixWaitForEventFail event.",
        "_yy# ",
        "Pireg.exe",
        "zgSt?",
        "f4om$lq",
        "<Wq,#",
        "7L%q?V",
        ".b}xrq&t",
        "*&UAT",
        "~EeP1",
        "9(:W:",
        "1ghf>",
        "DRNi~",
        "7D0U>",
        ",_~*P",
        "s]e1Sa|9t~R'",
        "vsmon_StatusUpdate",
        "~s&Mt",
        "\"&^PX+:",
        "leHcV",
        ")@1<&'P",
        "\\ :.-",
        "=*=D=W=q=",
        "a@~#.",
        "eCz3U",
        "U@3io",
        "437l#",
        "#nxW^",
        ">]9s3",
        "eQh'v\"",
        "jd.~>",
        "LUgDH",
        "X509_NAME",
        "686C6e6",
        "q(cz]K",
        "2H2X2]2b2g2o2~2",
        ".\\crypto\\conf\\conf_api.c",
        "010e0",
        "LoadDisconnectedPolicy: LoadDisconnectedPolicy started.",
        "4Qv;y",
        "@sF9G",
        ".\\crypto\\objects\\obj_dat.c",
        "mRw-[A",
        "8&d<4",
        "StopAllServices ended.",
        "000Q0s0y0",
        "EA%$g",
        "173Pa",
        "B64_READ_ASN1",
        "incorrect policy syntax tag",
        "Ou>T3",
        "Z>EAA",
        "H>fwc",
        "% k1:",
        "RgxsL",
        "H7]x}",
        ")AxLx",
        "5%5*5",
        "SVWh ",
        "fie>f",
        "cli::array<",
        "4M7c7",
        "MH.I~WA",
        "Loading error information from msi database -- Failed to execute view:  ",
        ":F<K<]<{<",
        "Candidate Whitelisted by Subject",
        "7A8p8~8",
        "ea3YQ",
        "`o<iT=D",
        "<+>F>X>",
        "uZfr9",
        "RS!of",
        "gd5D%",
        "P;f{D",
        "t|%HG",
        "2A:tLVM",
        "elR1d)",
        "Fw<P]",
        "IGDBt",
        "+7&c++9",
        "`scalar deleting destructor'",
        "#D$,#",
        "3@-vl",
        "9D$8s\"h",
        "'/KI$",
        ";.;?;",
        "\\IqkUy",
        "bhCon.E",
        "n8dT^",
        "X7iii9P",
        "sKW,w",
        "^W`T5J",
        "H8hE\"",
        "E}.J?",
        "HxGja(W$",
        "u3V{s",
        "YCGkJUH!",
        "\\ts11\\tsrowd\\trftsWidthB3\\trpaddl108\\trpaddr108\\trpaddfl3\\trpaddft3\\trpaddfb3\\trpaddfr3\\trcbpat1\\trcfpat1\\tblind0\\tblindtype3\\tsvertalt\\tsbrdrt\\tsbrdrl\\tsbrdrb\\tsbrdrr\\tsbrdrdgl\\tsbrdrdgr\\tsbrdrh\\tsbrdrv ",
        "vamdVV",
        "xv9$;",
        "runCommand",
        ":gtAU",
        "{Hu&fLn",
        "?,F@;",
        "n]F8N",
        "E8KT8",
        "1\"1'1",
        "ig{r\"K",
        "RBU-On",
        "uh_$;1=Uh",
        "'5'7'M'S'U'_'k'm's'w'",
        "Major Release Number=5",
        "MZ*&l",
        ";c^s9i",
        "5#5-535A5K5W5",
        "Dno5E",
        "pa8=<",
        "%j.4UU.",
        "c-5T]\"@",
        ")J*l!8",
        ")^D718",
        ">F?Y?r?",
        "=R>X>",
        "#P,?[",
        "ffffffffffffgf",
        "Vbzl'#?k\"/",
        "Pjmj ",
        "ended with %s",
        "8k<bVt",
        "1\"'V$",
        "{_4$T/",
        "j}h0^%",
        "9D+xL",
        "NKg9q",
        "92%\\k",
        "daJe9x",
        "92O/L",
        "ByaJO",
        "t/*,V}",
        "Registry error:  Failed to set value.",
        "CVTPI2PD",
        "ED/Dq",
        "oyG;Kz0",
        "5*6R6",
        "g:=TXP",
        "v\"}}C",
        "'|<Do",
        "192B2e2",
        "jwjrj!",
        "NcGhvg",
        "E%+<lZ`arT",
        "d!H9n8",
        "F7[WZ",
        "c7@Qw4",
        "(hy*5",
        "_aJZS\\",
        "=(=,=0=4=8=<=@=D=H=L=P=T=X=\\=",
        "=yB-eTZ/",
        "cannot find free function",
        "q>)FyBX",
        "?(?C?",
        "e`%_]",
        "Critical",
        ")k]Ng",
        "9~4v!S3",
        "CMS_RecipientEncryptedKey",
        "c0kFt;yg<X",
        ">Nk0k",
        "x-}Yj",
        "<!<1<A<Q<a<q<",
        "iI0Pm",
        "zI1[*",
        "=Fw~&C",
        "regex_error(error_brace): The expression contained mismatched { and }.",
        "5&686",
        "Gbzb^",
        "DSO lib",
        "='>N>",
        "Zs'Ce",
        "$CLTH",
        "7V8r8",
        "SOFTWARE\\CheckPoint\\SecuRemote",
        "Ap_~x",
        "f;5H8",
        "]2,WN",
        "CMS_add0_recipient_key",
        "2 2$2$3",
        "`NOeU",
        ".mafDu",
        "3\"4)4S4Z4e4l4",
        "rp6 m",
        "D3f/Q|",
        "`5.$ I",
        "\"%s\" /e \"%sDefault\"",
        "3D$D3D$@",
        "NhcCbc",
        "g3|}Wp",
        "p~[ )K",
        "-X5m+",
        ";/;>;^;y;",
        "e]q9xe",
        "<QHy'I",
        "_`kW0",
        "SSL_CTX_use_certificate",
        "num2)H",
        "1@E[j",
        "6(qm\\",
        "D3}T_",
        "a]1``",
        "\\vsdatant.cat.delete",
        "s8S\"3w",
        "{ft7) ",
        "4;xRz",
        "RegisterClassW",
        "Yw0H[",
        "UY?E+",
        "EyTU6",
        "=z>+?d?",
        "S+ou1<",
        "4PoOw",
        ":8:P:",
        "removeVpnFiles",
        "4.4J4f4",
        "rpcrt4.dll",
        "7=7n7",
        "Z8Y8<8",
        "psg_disable",
        "${AEX",
        "SZGY:",
        "iNYZQ",
        "spanish-mexican",
        "lo#dR5B\"$k",
        "2[7H9",
        "QF`@]",
        "documentPublisher",
        "9 :$;~;",
        " OKT.",
        "R92{r",
        "Poc<2",
        "tXf/^",
        "l9^72",
        "PAp(h",
        "]_< .X",
        "=*>=>",
        "norwegian-bokmal",
        "sr_endpointBannerBig.png",
        "0e2k2}2",
        "DES part of OpenSSL 1.0.1t  3 May 2016",
        "cZ_EHC\"%C",
        ":&ck4/:",
        "n)IwCf",
        "(UFp\\",
        "]p]M]N,On",
        "RV,hO",
        "'Lbf*|",
        "?qM7?ur",
        "8{-zT",
        "progress_hc.gif",
        " q@BxR",
        " 0xdd",
        "~&&)7",
        "H9=oH",
        "/Kl=F",
        "9 Ys*",
        "+HMH\\",
        "\"@9E>",
        "1a^w=",
        "jsG#F",
        "t$$PVS",
        "Restoring upwval...",
        ">)>E>a>}>",
        "CJm{y8",
        "es-PE",
        ">CX`s#",
        ")0\"[c",
        "~a8ia8",
        "s0|8'wI",
        "[P|7w",
        "gtxU>f",
        "9Zi_;",
        "K{O2V",
        "L\"vFH",
        "c6\\gX@",
        "?,?,@",
        "< <(<0<8<@<H<P<X<`<h<p<x<",
        "x\\b%!5",
        "+7 uB",
        "N@{R/LP",
        "upper",
        "%q\"{#",
        "~pD]W",
        "KCxIFq",
        "<S~=t",
        "hg=sn",
        ")'$D]",
        "AtWWZ:",
        "s2+h-",
        "RO%UH",
        "=(Ai]",
        "zx\"p?",
        "No more connections allowed to host: %d",
        "tKKi!",
        "#@_dN",
        "no certificate assigned",
        "v?pvtg",
        "BOXQP",
        "m5HlV",
        "QVWh?",
        "sT76[",
        "sF:,P:,F|",
        "sha224WithRSAEncryption",
        "=&=-=",
        "t2Wh0GM",
        "r permitted use of the Product under this Agreement infringes any patent, copyright, or other ownership rights of a third party. You agree to provide Check Point with written notice of any such claim within ten (10) days of Your notice thereof and provide",
        "LX$N+\\",
        "PMINSB",
        "\"@T!f",
        "8O\"3t",
        "tH Jn",
        "y1~(Y",
        "1]gBQ",
        "I|?PURp",
        "7|9}6",
        "0[LdE",
        "AbLX{",
        "Fm]uDC",
        "ey4S;v",
        "[/_'<",
        "C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/ssl/certs",
        "U:6O5",
        "IRjxP",
        "1B2J2X2m2",
        "missing dh dsa cert",
        "=A\">B^'",
        "%F %T",
        "rE\"*_o@7",
        "393>3Y3^3y3~3",
        "adq}s",
        ">+_oa",
        "^Zw~sdz",
        "uuyc~T",
        "%`,z#7",
        ">`a_o",
        "<=8s7",
        "{XQPa",
        "hZLlT",
        "aC+kt",
        "opendir",
        "\\par \\tab b. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5000668\\charrsid15169477 B}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ackup and secu}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607 ",
        "Service is active: %s. Wait 1 second.",
        "9\":=:X:s:",
        "5{]P='",
        "failed to add attribute data to CustomActionData",
        "BN_bn2dec",
        "4$515f5r5",
        " y+:z>",
        "\\zonelabs\\avsys\\prloader.dll",
        "kkX8Q",
        "jCI4,",
        "z[fEt",
        "=.>3>;>",
        "4$4,444<4L4T4\\4d4",
        "jtjuj",
        "$jc#1Q",
        "ccore32.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "|\\e#+",
        "b\"io,",
        "u$utv",
        "id-cmc-addExtensions",
        "{\\fhiminor\\f31571\\fbidi \\fswiss\\fcharset161\\fprq2 Calibri Greek;}{\\fhiminor\\f31572\\fbidi \\fswiss\\fcharset162\\fprq2 Calibri Tur;}{\\fhiminor\\f31575\\fbidi \\fswiss\\fcharset186\\fprq2 Calibri Baltic;}",
        "bMnoND",
        "S9{hL",
        "4K1'~",
        "9.u)AJ3",
        "DEl6E",
        "1B]tAF/vu",
        "Qr]<e8",
        "iYCBw",
        "CertCloseStore",
        "\\R3F,)I",
        "v`LQ>C]",
        "@x{FB",
        "ae&u~",
        "8F9w9",
        "8 8(848X8x8",
        "S=KyM",
        "D=|z`",
        "SOFTWARE\\KasperskyLab\\AVP9",
        "(BG\\~",
        "8F8V8~8\":",
        "s)7lK",
        "fread",
        "L$ 3L$P3L$<3L$,",
        "9NS='",
        "97Z)e",
        "5{j\"q",
        "eX;\\m",
        "v6Xm7",
        "3>3N3`3h3x3",
        "Ox)e5",
        "LzgP'",
        "/vI3y",
        "A0PbTf",
        "Nj^P+",
        "r\\h0F",
        "6]SzC",
        ";T]41",
        "_VW87",
        ",3'D+",
        "q9u-&Hfn",
        "PerfSetCounter64",
        "Iw Fx",
        "pkcs7 add signed attr error",
        ")!O`L",
        ",*]`&",
        ">H?M?",
        "bffVN",
        ">6>R>n>",
        "}@74It (",
        "NETSCAPE_SPKI_b64_encode",
        "Can't resolve new host %s:%hu",
        "O1,?eL3",
        "t$8UWV",
        "XW|eD:<i",
        "ec_GFp_simple_oct2point",
        "PB[\"D",
        "'*mnR",
        "ETARh",
        "q~`|8",
        "'m)v'q)x'u)z'y",
        "q@ W,",
        "isATM",
        "J^V&`=_",
        "QiJk~o",
        ")v*/J",
        "s\\D`5",
        ".-[Pd",
        "id-kp",
        "1C0n_",
        "'/<\\B'r",
        "m_R?w.G",
        ">v2D+",
        "\"cToDk",
        "U*KDU0",
        "_x!'\"",
        "uKJQ ",
        ":D$ u",
        "&_T6A",
        "6^1@]",
        "DL$[=\\",
        "bl <= (int)sizeof(ctx->buf)",
        "}u/ho",
        "QUX?Z.",
        "b0wLK",
        "[VSUTIL] GetCustomerNumber() writing to %s\\%s: %s",
        "j#r#y#",
        "st/bF",
        "^QZ-:G>",
        "2X5F*",
        "bW<;8Y",
        "2$2,2@2H2L2P2T2X2`2t2|2",
        "&UkQ9t",
        "go_\"[0",
        "Je C9j",
        "(t;qv?",
        "JE\\=q",
        "a[.AB?6T",
        "NLPYl",
        "rS2\\0o",
        "x'U76",
        "k*,Bd",
        "&6F6&7F7f7",
        "value.good",
        "api-ms-win-crt-math-l1-1-0.dll",
        "bY?5{",
        "`]* E",
        "FNSTCW",
        "my[34",
        "dj`.iT",
        "n]xsS",
        "Yu_4%",
        "-ukVG",
        "c(:X(",
        "`template static data member destructor helper'",
        "CwYfm!",
        "I=<7<",
        "j~Yx:B",
        "0hAZ;8",
        "ssl_session_dup",
        "TnqZ$",
        "L$x3L$<",
        "t\\r'c",
        "QPbKkj",
        "2sw?||",
        "GcH3|",
        ":(a!&",
        "ir!)D",
        "C>?k#",
        "kB63^",
        "KX$P2",
        "=Ha2?",
        "h@@xr",
        "&k.:_>",
        "\\zpeng25.dll",
        "nhcj)G",
        "?ho =",
        "x]UpBM",
        "$6v&/4&",
        "zU:4:",
        "&/z;o",
        "3&3E3L3",
        "0^_[]",
        "z`GT5~",
        ",EhBO@(N5",
        "6ndx%",
        "kW\\^E",
        "78:}L",
        "no close brace",
        "getProductModeFromLicenseKey",
        "gtgugv",
        "MEnoUG",
        "`4p`_>",
        "=G95B<",
        "Lt#lq",
        "ECParameters_print",
        "0+1r2",
        "VVVVVVV",
        "/xE]_",
        "d.V]pb",
        "9S3*C",
        "%=QtI",
        "hJ:di3p0",
        "~H1LK",
        "W/%<O",
        "l|zWh",
        "XM2yRH0t",
        "O9]f'",
        "$i*_s",
        "oQ7;t;F^S",
        "(v\\+r#",
        "{vs: w",
        "eYrBu",
        " lW9''zs.",
        "av>.\\",
        "~G`#U[",
        "slI,T",
        "+-bZN",
        "VBE^*gWt",
        "#^c^jY",
        "-:7Xc1",
        "kPo55",
        ":<|d]S",
        "0 0$0(0,0004080<0K0",
        "\\{(mN",
        "KE}y*",
        "$nJD@2",
        "Zb3WE",
        "xWj.?J U",
        "_g1rBf",
        "mvQ,'",
        "wqvdY",
        ";7%X*",
        "proxyCertInfo",
        "-:mAh",
        ",XHa#",
        "uZ;o4",
        "jR?H-",
        "AEdA'M8H-",
        "w~`tt>fO",
        "E [WY",
        "7E1S`h",
        "(r&U\"",
        "p+rm:'",
        "\\ep`@",
        "Z44w=A",
        "(X8'q",
        "G w#U",
        "contentEncryptionAlgorithm",
        "L^(D6",
        "Is wZ",
        ")&3t<",
        "Le\"q#",
        "_U.z\\z@r0_",
        "8oNy8q",
        "t!h8ML",
        "Hw}>I",
        ">C?Px",
        "0>1l1",
        "Sn<d9p",
        "O|]JC",
        "~5AUXk",
        "*fG^9^",
        "tBBB9=",
        "jc7%.dK",
        ".d]|>",
        "hyq:O",
        "0 0$0(0,0004080<0@0D0H0L0P0T0X0\\0`0d0h0l0p0",
        "hWXY(D",
        "[!~2'",
        ",re%;",
        "[BP+DI",
        ":@z82",
        "5zZFNv",
        "if){b^",
        "1Mw:X",
        "iG#[I",
        "F.g71A.J",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid15807945 ",
        "[VECTORED EXCEPTION] Interface not registered.",
        "nEjWC<H6",
        "RW`)p?",
        "'xeIC",
        "b3G|Cj0?$",
        "121K1d1}1",
        "R^QbX",
        "5h$;%",
        ".?AVexception@boost@@",
        "~q!:&V",
        "NEW-ENVIRON",
        "yvHQtn",
        "li;|1h8@[",
        "pOBeE",
        "DH-RSA-CAMELLIA128-SHA",
        "y3/cI",
        ";T;^;",
        "(c,lI",
        "MsiViewExecute(hViewShortCut) failed",
        "~Xma7i",
        "+,e&Q",
        "{PJD$n",
        "b.C[I",
        "X0&[|",
        "(]Bq$:",
        "2|;+|",
        "other_error",
        "6/#'p",
        "3J|*G",
        "-!-'-2",
        "1b2r2w2",
        "Ne@5Y",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid8149378 i}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ficat}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid473743 i",
        "T$P1|$p",
        "<._K*",
        "\"Myx&",
        "Rollback custom action CopyPoliciesFromOldDirR",
        " XN`,L",
        "i/Dw9eY",
        "7T^0v",
        "qgRm`!c`",
        "J;36P",
        "a\\~kZ",
        ",c'oc",
        "'gg\"7",
        "R@Sv&",
        "aY[Cq",
        "PROXY_POLICY",
        "; ;(;,;8;@;D;P;X;\\;h;p;t;",
        "`|Z{[",
        "ji>(L",
        "o71Rw",
        "~f aC|j",
        "progress.gif",
        "=~g4$[",
        ".'*~\"",
        "^G,>@",
        "1,1@1E1y1",
        "E|Y?X|",
        ";/-A&J",
        ")<qsJ",
        "]KVw[",
        "jNPpu",
        "4\"4,4X4f4",
        "Failed to execute OnDriverStopFailure command",
        "404A7",
        "1P]#_ql",
        "#CZU7",
        "GetXMLDOMObject failed",
        "bSQ4S",
        "'x:Qg",
        "status",
        "6JbtW",
        "S)')g",
        "too many files open in system",
        "KzE/i",
        "[t0B\\Ru",
        "4!4'4-43494?4E4K4Q4W4]4c4i4o4u4{4",
        "`{yuSvzN",
        "FW?U ",
        "2zI:'_",
        "D5F\\/",
        "Ref-*",
        "qpE6M",
        "k[7vu",
        "NQXnG",
        "UFm*2\\_",
        "I2,e8D",
        "zwxno",
        "{FN&w",
        "BAD_RETURN_WAITING_1",
        "\\O&*@",
        "5rSO*",
        ";YDaza<M",
        "20oNb",
        "[VSUnloadServiceUI_silent]",
        "i>A'T",
        ".-~R'",
        "5'6b6",
        "#0(0p0y0",
        "bad lexical cast: source type value could not be interpreted as target",
        "~t%Vh",
        "Wow64RedirectOff",
        "D0I0M0\\1`1d1h1l1p1t1x1|1",
        "|:_0X",
        ";i}:<",
        "9sx~ ",
        "4M4q4",
        "mO_y4",
        "@_R_eMudW",
        "Q\\I8tK",
        "J~fKW",
        "H/In{r",
        "C!Jx4C3",
        "fnM8(0(K",
        ")xbxE",
        "[DUMPFILE ERROR] error in UpdateDbgHelpVersionin GetFileVersionInfo determining %s version GetLastError returned %d",
        "__int8",
        "0!0(010?0S0Z0i0u0",
        ">@?[?",
        "656U6^6i6z6",
        ";QNH+",
        "RD&!V",
        "z<8~/z(",
        "nJ)qT",
        "es<XH",
        "AK]awo",
        "Failed to start WatchDog service",
        "0\"0?0E0M0[0",
        "Failed to stop EPWD with InstHelper",
        "+HE]H",
        "2?@=:W",
        "*tD=+",
        "VCRUNTIME140.dll",
        "97+tn*",
        "c4u+mE\\*5wXs",
        "`\\Qw:D",
        "}m~0@=<",
        "%08x-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x",
        ":$:::P:n:@;u;",
        "6(6G6N6{6",
        "2XStP",
        "ssl23_peek",
        "-F|C]",
        "tc/$b0R",
        "qm*Jm",
        ")yZDG",
        "ZoneLabs",
        "N|1\\$",
        "{vyHn",
        "2)2;2J2t2",
        "6z;7<",
        "tracsrvwrapper.exe",
        "lJ$n@",
        ">).O)",
        ",-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVW",
        "8bt)M",
        "w\\]^ 7}",
        "EC_POINTs_make_affine",
        "=6=G=",
        "9(:U:",
        "OEQ8u",
        "pk8vRKc{$",
        "v7- W",
        "Gbrpi",
        "[iysK{",
        "dNjwU",
        ".rsrc$01",
        "djSG ",
        "[s?!A",
        "$d0^_",
        "CANT_LOAD_VSUTIL",
        "X509_verify_cert",
        "zW1Ia",
        "PELUKY",
        "@ b1Rb",
        "+!g\"r2L",
        "myy9>",
        "n%Ni&*",
        "L$@UV",
        ";=??]",
        "EP]3co",
        "~G):*",
        "_~||U",
        "%9>3=",
        "TvUH-",
        "mb**W",
        "9GT@So",
        "3l6`Yj0",
        "g^Ym&",
        "*l&XeC",
        "The resource type %d for %ls is not supported and will not be registered.",
        "/S%R l",
        "&N$J1",
        "\\lsdunhideused1 \\lsdlocked0 endnote reference;\\lsdunhideused1 \\lsdlocked0 endnote text;\\lsdunhideused1 \\lsdlocked0 table of authorities;\\lsdunhideused1 \\lsdlocked0 macro;\\lsdunhideused1 \\lsdlocked0 toa heading;\\lsdunhideused1 \\lsdlocked0 List;",
        ".\"$fO",
        "<Z8vQ>G",
        "\"TK36",
        "(Fq&.]",
        "file redirection restore failed - return %d",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\117CD7D3CB2C542438D083C010944001",
        "Mh,NEi",
        "x}c]Z",
        "8`PQf",
        "Microsoft Corporation.",
        "8O[HuZ",
        ".w$6/i",
        "I-{RwW",
        "[A_f^\\",
        "\\ii.b@",
        "Qn;{'",
        ".W:Cvp",
        "hij*7 55",
        "KzRr3",
        "-}6qd",
        "m,#foF",
        "2|M9/",
        "Imk44",
        "r|6b_K",
        "t^k+w",
        ");qqR",
        "Z5Vv%",
        "^*EHT",
        "9j3[>c",
        "5GuNHh",
        "z`~AF",
        "locator",
        "5F5G6w6",
        "/N\"m80",
        ")-=U)",
        "6WQVh",
        "isSDKUpgrade",
        "~Rp9z",
        "[LICENSING] ERROR: trying to insert a trial key with too long a length",
        "KvM~zd",
        "bT1<A",
        "d36K`",
        "=jV#d",
        "3e*c[",
        "Yr\"ht",
        "5o8HB)",
        "Tg#qo",
        "t$8WVj",
        "Q;VIb",
        "VZe]a",
        "N-HCM",
        "b~oPF",
        "#zLz\\",
        "GoH\"pZ+T",
        "AHJ~<I^s",
        "L.&\"=",
        "OcK57",
        "csymjA",
        "m,e6!",
        "T!sb-'",
        "7\"v|@",
        ">\"?^?",
        "DS_RollbackFACDriver ended.",
        "^_uy%",
        ":9:@:F=W=v=}=",
        "cT.epF",
        "O#sW{NKQ",
        "3x$cI",
        "879@9",
        "141H1S1",
        "J%\\m4h83W",
        "Yu-f;",
        "IL t~Y7c",
        "D$@PQ",
        "6j5]'",
        "@n6G0=",
        "!5h#J2>",
        "P(@iB(b",
        "404N4Z4g4",
        "G0SGr8",
        "KU&/\\",
        "R),\"Q@",
        "?\"iPjM=",
        "CevC%{o",
        "\"b]#AY<",
        "pyY^?",
        "EVN-r",
        "id-GostR3410-2001-CryptoPro-XchB-ParamSet",
        "z oW=",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{79B986AD-54D8-4498-AA06-89808829ACC0}",
        "$9&:r",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\prodconfig.cpp",
        ">ku%z",
        "T$(+D$",
        "_-?A1",
        "djsbI",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\epam_svc.exe",
        "RJ!EB\"EA$",
        "A:]s_",
        "\\vyh4d",
        "E-oh4?d",
        "[B[rK",
        "uu}NYg_&",
        "3_(b5N}]",
        "7R4e=[",
        "gk4J_",
        "onU\\FT",
        "8:8e8",
        "WixRegisterRestartResources",
        "\\C]W4.r",
        "<ySdI",
        "&eC.t@",
        "Ngcx,",
        "f=9%6",
        "fi-fi",
        "IYq/h",
        "UPL0>UH",
        "=9'}.",
        "Vhl8#",
        "_c[Z+",
        "[#S}c1",
        "575P5}5",
        "k8fM]",
        "F+jxgn",
        "=xW,#",
        "19N)>",
        "ONJ<-",
        "$T*\"\"_",
        "(qO_$+",
        "};)O_",
        "?~AIZu",
        "G)R`>",
        "YD\".@",
        "PK;C_y",
        "~sK$\\",
        ";.o:#",
        "t$,WS",
        "Ut'#+",
        "z;^b;v",
        "<Q=u=3>",
        "566k6d7",
        "=7SNJ",
        "; PTFK",
        "epregflt",
        "L$X_^[3",
        "\"W;yX",
        ".UDp'",
        "cpMMh",
        "D$<CP",
        "2R4)5",
        "@R5nyk",
        "Couldn't resolve proxy name",
        ")sJKD`(\\",
        "ta-in",
        "tXw.0",
        "S3nes",
        "D$<PV",
        "qh4@0&\"",
        "title",
        "K;MI^",
        "WIX_DIR_COMMON_MUSIC",
        "FQU7VCJ/",
        "V\"5B:Z",
        "Lh>#[Ey",
        "FIPS_MD_CTX_COPY",
        "Sh:Uh",
        "id-smime-mod",
        "0P3~3",
        "PEM routines",
        "sj# y",
        "s)``)1D",
        "5aL-b",
        "F>gG-",
        "ARNI@",
        "4<5Z5",
        "hH2&HK",
        "999(;1;j=",
        "0M1M3M6M8M9M?M",
        "^}d.g=",
        "m+J^lV",
        "*!+a+",
        "r}jZ2>SK",
        "3v:$Y",
        "nubE,",
        "n`n,U",
        "DmBd^S",
        "i8O5Su{",
        "8}:W~",
        "DSAparams_print_fp",
        "Failed to add row to remove folder for WixRemoveFolderEx row: %S under path: %S",
        "v&gmP",
        "tO9xp~J",
        "XN|+z",
        "Wo;L<,",
        "N9S6we",
        ")&=Q4H",
        "tyJnC",
        "2(2L2^2t2y2~2",
        "OCq<Iy",
        "Original PATH is: %s",
        "4^}Vaw\\?Tm",
        "NkdwQ",
        "O~^wEh",
        "=jph`E%",
        "/0}p-",
        ",|YAag",
        ")nm$DR&u",
        "p&j_M",
        "1W\"G'",
        "<\"<><Z<v<",
        "`L/6<",
        "FNH>ad*",
        "noW8QG",
        "Vh|CM",
        "92\"CG",
        "-c Jn",
        "E$M'Mj",
        ";dU~\\",
        "f;A);q",
        "~!@F|",
        "EiVKgi93!U",
        "UMM`5",
        "accept error",
        ",C0B,",
        "m}ml=",
        "35gjxUuE",
        ">vnR`l",
        "~!uXc",
        "6\\.Cr",
        "qYvN`",
        "4b=&E",
        "`H.`J*",
        "4{-[+",
        "\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
        "%zd bytes of chunk left",
        ")O|>y",
        "Helper::stop() -- set quit event.",
        "N[`n@;",
        "K.6 bW",
        "f+]B-{ [,D",
        "t17w:#",
        "M,#:W",
        "\"`7-t",
        "vX%Cn",
        "):BTy",
        "Install firewall driver.",
        "rc#Ah",
        ":wNdwp",
        "J1,4p",
        "Cp]~x\\R",
        "DefPolPrepare started",
        "unknown object type",
        "SET_DIST_POINT_NAME",
        "F?l}X",
        "/C4%`",
        "G(9_Lu8",
        "N7#iH",
        "QLM[5J",
        "C8;sx|",
        "eps_VPNClient.chm",
        "Ka|,o",
        "on6wW",
        "llk#L",
        "}y#0R_",
        "Kt^ \"B",
        "@|-i9r",
        "~[UUW",
        "[_,vV",
        "GvAwE\"",
        "AGO0H",
        "template-parameter-",
        "9=:{:",
        "D$HPh",
        "w)DUA",
        "gN`!2V",
        "m_7Aq",
        "<0+jyp}",
        "e=Zq3",
        "PMOVSXBW",
        "HLtXd",
        "!Psd9z4",
        "O.vfN",
        "RegistryFileExecute:  RegistryFileExecute finished.",
        "mz+!tvVI/1t",
        "FQlB/",
        "StringFromGUID2",
        "2Ya.~d",
        "'\\@>T2",
        "k_Oz'",
        "M- }/",
        "Zbo5<",
        "CNY|m",
        "768>8d8",
        "I=y}hA",
        "5g)JBW",
        "DX,[u[",
        "q nDB",
        "jAjqj%",
        "jJ)_h.",
        "WUTd\"",
        "jPV1A",
        ",e)y3",
        "9%pOm",
        "{x`M`",
        "OSthf",
        "s|#l+",
        "5(5,5<5@5P5T5X5\\5`5d5l5",
        "ZJJ@PB",
        "j`$|M",
        "l7lQ^e",
        "eH?#k",
        "M*o'K-",
        "(}?#H",
        "km8$L1",
        "7(7C7L7f7",
        "\\$?v5",
        "\\lt^i",
        "yd\\Y-6",
        "fCERI",
        "q1+~=",
        "3\"4V4w4",
        ".sbkC",
        "SFF\\W\"BQ",
        "wxjh>",
        ":!;2;J;P;d;j;",
        "os0D<",
        "|$0h<",
        "[msBe",
        "a2H7\"",
        "vST&M",
        "NpL~$",
        "^WwF%+.",
        "9G9y9",
        "3,4E4",
        "Y3Y4Y5,",
        "v=1wY",
        "v+r=i",
        "ahsII\\",
        "62opG",
        "4!4A4b4k4u4~4",
        "max-age",
        "?&?B?^?z?",
        "9J[i\"",
        "ICxTb",
        "^(O= ",
        "wEsE}s",
        "ZoneLabs\\vsmon.exe",
        "%mm0:",
        "656<6Z6d8",
        "|$0hy",
        "181X1x1",
        "l0PFd",
        "]XCp*",
        "$'F#-",
        "2\"'0A",
        ">$?B?`?",
        ".NxGIz",
        ".?AVDNameNode@@",
        "EC_GROUP_get_degree",
        "5xVJUa",
        "[VSSHUTDN] CallAddDataClient()",
        "~~v!FlF5y",
        "0qbK~",
        ".?AU?$error_info_injector@Vbad_lexical_cast@boost@@@exception_detail@boost@@",
        "V;5Z*",
        "M:Z&5",
        "^8hP<!",
        "Tom0L",
        "=$=,=4=<=D=L=T=\\=d=l=t=|=",
        "3L$83L$4",
        "A/zpi",
        "*_I?6",
        "ExecXmlConfigRollback",
        "md2WithRSAEncryption",
        "total ",
        "RC5-ECB",
        ";w;|;",
        "d[gri",
        "=I=`=t=",
        "-;e VW^a",
        "AntiMalwareAPI.dll",
        "BDz(AcE%",
        "Yz,V8",
        "?<b^z",
        "/7mtk",
        "[DUMPFILE ERROR] error in UpdateDbgHelpVersionin GetFileVersionInfo determining %s version. GetLastError returned: %d",
        "nLAF`",
        "WF&#+$",
        "T%~)O@ V",
        "495C5N5",
        "*E[?Y",
        "[C%LeM",
        "?|+9f",
        "@Q)'S",
        "`@c\"^",
        "0M1k1",
        "6H7c7",
        "7S7e7",
        "rR+Dl",
        "qdo;\\",
        "W`d }",
        "wrong final block length",
        "------%s%s",
        "848?8K8[8h8o8}8",
        "}\"\"v@",
        ".TPUTz",
        ",Mo1$",
        "D$DSPj",
        "HLh](",
        "mpYHa",
        ")4aW~",
        "bad srtp protection profile list",
        "|uQ~I",
        "F_v!A",
        "n8Mm%4_\"T",
        "qD|we",
        "7w52H",
        "U\"mp6",
        "{`g`=",
        "njUukL",
        "1|1V3",
        "\"##6/",
        "r2F-QE$",
        "OurO,",
        "t];h&YD",
        "fltmc unload gzflt",
        "r?;Fe7",
        "L\\-p_",
        "TfRO.",
        " S=6LH",
        "yPTwN",
        "H\\R-[0",
        "m>hA~",
        "7rg{@",
        ".\\crypto\\pkcs12\\p12_key.c",
        "zcA{?",
        "v<H~(",
        "!4QQr",
        "8$:=:P:X:",
        "7oa=m#",
        "E!Pv$",
        "FiX(l",
        "y0S* ",
        "q}^\\eya",
        "+k~7G",
        "r8N5]",
        "Ohs6DH",
        "545P5l5",
        "_iUXY",
        "|OZ:Y",
        "RSA-SHA",
        "<<<D<P<p<|<",
        "2ENek",
        "I,NzO",
        "\\v%,X",
        "G<3Lz",
        "k6U<JI9",
        "c~9md",
        "\\$pUW",
        "7V:@<~<",
        "^G]Y8",
        "setct-AuthRevResTBE",
        "AES-192-CBC-HMAC-SHA1",
        "t$8USV",
        "Es$e7&",
        "gJ7sB",
        "VC90.manifest",
        ">(>,>0>4><>T>d>h>x>|>",
        "PYZW4;W",
        "1\\>g!h",
        "[WinFW] SetWFStatusVista, failed to set private profile, error=%x",
        "*/Z{d\"",
        "#+_1Wj1",
        "X'$aF",
        "hzs=5kl",
        ".j`&A",
        "t`q'6^",
        "D>VzR",
        "98?>:",
        "\"\\o.:",
        "2/2K2g2",
        "YX7E+",
        "Sj~=eI",
        "JKP38",
        "^*`;~",
        "{tO7d",
        "&TDuK",
        "G[N%T",
        "o;G'l",
        "s0(Rv",
        "eU$ACP",
        "g+{[!",
        "0%191V1",
        "SwetV",
        "/=j*zU",
        "\"10+i",
        "A2q:/",
        "LY/@1,[",
        "Zf{~*F",
        ";-;2;8;>;D;J;P;V;\\;b;h;p;t;x;|;",
        "&xRO:",
        "X2gba",
        "WaitExclusive(0x%x) - 0x%x [I'm last thread]",
        "YY]+!T",
        "Zj|Zf=",
        "LS.yL<.",
        "D$<UP",
        " Z\"iC",
        "c_553\\",
        "FEDISI",
        "HLCtp",
        "3T$T3T$8",
        "srtp could not allocate profiles",
        "QUuiQ",
        "hu4G3",
        "`nM$9",
        "|iPSV",
        "AECDH-AES256-SHA",
        "hQHk[",
        "aP#sA}Z",
        "F.WuD",
        "H*tvm",
        "FFGqF|",
        "&kzVw@",
        "%^Q5T",
        "Z-LTA",
        "9zQvD",
        "Wait FAILED",
        "+*SJw",
        "giNQ1",
        "`}~y)",
        "MoveFileExA",
        "s0TKv",
        "$IHD1",
        "U:h|Z",
        "CON~Mx",
        "!XtJ0",
        "IvAXq",
        "485M5",
        "K&r}LG2",
        "\\3&4:5",
        "2Q2V2[2o2t2",
        "setCext-TokenIdentifier",
        "Olaz,",
        "TELNET",
        "D$4VUP",
        "4X4b4h4r4{4",
        "k4f%k",
        "nvyWUw",
        "_UXj+q",
        "LFENCE",
        "0S1u1~1",
        "P9p90kh",
        "4M&Ki",
        "=g{g=S",
        "yye!l",
        "6KAMD",
        "e6?<y",
        "%x^k@",
        "&050X0",
        ")69P;w",
        "nWFu3",
        "Dg(+-\"",
        "Ln+$W",
        "J~uYX:",
        "7*05j",
        "z{L+%k%",
        "v4;5l-",
        "ar-iq",
        " 4,ObY",
        "+Kj,C",
        ".?AV_Node_capture@std@@",
        "b^X+XB",
        "5^7:\"",
        "ImportTablePatch('%hs', '%hs', 0x%x, 0x%x) - failed to patch 0x%x",
        "ibrkvra3u67rqq5srifkne166k0",
        "_5mh3",
        "Internal error removing splay node = %d",
        "init_resolve_thread() failed for %s; %s",
        "m1\"tT",
        ".pw[g",
        "4+5E5c5",
        "NM?i&",
        "#2>>U",
        "6gwv:",
        ".oa-F'",
        "J<esx",
        "ew2fA",
        "g/atE",
        "No backup data is found",
        "yU\\\\/",
        "t'QPV",
        ");aOvx",
        "94#43",
        "49S?(",
        "9$9,949<9D9L9T9\\9d9l9t9|9",
        "6bUe\"}",
        ")PvK!",
        "Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.",
        ";Gawo;{",
        "ASN1_CB",
        "ConvertSidToStringSidW",
        "2sk>i",
        "RSDSND",
        ";5<J<_<",
        "GB,&$,vJd-",
        "KROm*A",
        "<`Rs.C1%",
        "uo<<~",
        "9hN>9",
        "W#5LK",
        "Failed to close handle",
        ":tQB(#r",
        "; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\\;`;d;h;l;p;u;y;",
        "?ZMwf:=",
        "ROUNDPS",
        "___lc_codepage_func",
        "t$,SW",
        "VMRESUME",
        "\\dZv^2",
        "70:b:v:",
        "6h>P2",
        "(+Ex8",
        "|OZzw",
        "f%s[8",
        "5~&;'",
        "x:a9>_",
        "iW$U1",
        "8w,{E",
        "rj3-a",
        "Failed to allocate string for Property '%ls'",
        "hHDLy`]",
        "d - UnInstall",
        "5(50545@5H5L5X5`5d5p5x5|5",
        "~&NWS",
        "h4MXX",
        "R]]pw(",
        "c2onb239v5",
        "Z+g|h",
        "wr\\yC",
        ">@>G?",
        "SbK9YHU",
        "OG&Zq",
        "D}|<1",
        "p.`hD",
        "VVWSj",
        ".lwx(k",
        "qgx>q",
        "0?$JU",
        "5 585P5T5X5\\5`5d5h5l5p5t5x5|5",
        "Up Version is not in a word format",
        "PsNyE",
        "4<A*Z",
        "@t.9]",
        "rNF/.|i",
        "SSL alert number ",
        "FDIVR",
        "Q[^0+",
        "k~Q4M<",
        "!'EmO",
        "1%9*^",
        "yME==",
        "-Jb{V",
        "=NBk.",
        "6$6(60646L6P6X6\\6d6h6p6t6|6",
        "x|;u#",
        "tw))B",
        "X78#=ye",
        "Z\"nos",
        "CMS_OriginatorPublicKey",
        "^P<)M",
        ",%;'R;",
        "162F2i2",
        "mCe0@",
        ":>;D;",
        "SqI1#",
        "]2i19",
        ":0Jm=",
        "~>\"kA",
        "5z659",
        "em;&f",
        "&9M|)U",
        "e 3M.",
        "MaxBootTime",
        "yAU{H",
        "zxNho",
        "f*JOI",
        "^R>6j6",
        "\\XDIbo_0",
        ";:^_\"+s",
        "2)X=.",
        "8p\"5r4",
        "L4/>!9",
        "132q2i3",
        "n!~D6DG",
        "95VmG",
        "pTu53Xp",
        ".\\ssl\\ssl_asn1.c",
        "t[^_][",
        "CAMELLIA-192-CFB",
        "YrbNc",
        "7d0uh",
        "S^5?6o",
        "dSTE\"",
        "4i%2c%",
        ".#,Re",
        "postalAddress",
        "nyN|)",
        "uN|2-",
        "090J0U0]0m0",
        "DA_PrepareStopCPDAService",
        "<><b<",
        "i=sIG",
        "j0jpk",
        "CAMELLIA-256-OFB",
        "O$ES6",
        "hL&u\",",
        "GS3#m&53r",
        "THq5)",
        "5@5J5[5a5",
        "ess add signing cert error",
        "5,`<g*(",
        "Vc94a[",
        "E\\)d4C",
        "L$X_[3",
        "7\"7'7<7",
        "jZh,B%",
        "t$jchl",
        "vXNWy",
        "676g6",
        "Ld\\dld",
        "f>QO&",
        "\"VI|^W_",
        "MYow1",
        "}JOeuJ",
        "wFH!$",
        "id-smime-aa-dvcs-dvc",
        ":ZAsjbV",
        "*y;|y",
        "aj_U5",
        "PKCS7_dataVerify",
        "?nv/T",
        "sidebarBackground.png",
        "0$000<0H0T0`0l0x0",
        "4w; dr",
        "D$ j@P",
        "[<,o6",
        "PADDB",
        "P8IWC",
        "weNx}h",
        "bla`m",
        "yKsf:",
        "6 696R6k6",
        "08N8w8?:E:K:Q:W:]:c:i:o:u:{:",
        "RECW9",
        "Sy\"c.",
        "8\"8R8i8p8",
        "VSEQi",
        "SV+~Kl",
        "eCL>M",
        "4(525O5`5u5z5",
        ";R<'>.>",
        "%s.dll",
        " %Mhu",
        "<%<><W<b<",
        "hH=5s",
        "sRytA'",
        "hq$Vb",
        "_]`_]",
        ";$<P<W<h<",
        "OjaySE",
        "7Ks)yFG",
        "1@2e2",
        "dAe{G",
        ";Ir:<0(S",
        "-zZ}?cE7",
        "%sproxystub.dll",
        "=AR&L",
        "t$8UWSj",
        "W&(>H#B\"",
        "%38Sb",
        "\\Q /?",
        "Probable in uninstall - continue to check...",
        "iWd^j",
        "5q~)o",
        "|zq'3<",
        "21e\"1",
        ",>&,z",
        "d$8zZ",
        ",(1$m",
        "!jj#y",
        "znHiL",
        "y_3Cgc",
        "ETdmS",
        "5T6Y6",
        "9^\\ty",
        "*'?)5",
        "b.j&{&\"",
        "HrsLL(",
        ">\">&>*>.>2>6>:>>>B>F>J>N>R>V>Z>^>b>f>j>n>r>v>z>~>",
        "`t.=<",
        "AdH{-",
        "Jq4-6+",
        "@qod8",
        "3P4z4",
        "7(787<7L7P7T7X7\\7`7h7",
        "E*bw8",
        "-n61-",
        "[IsServicePPL] OpenSCManager failed: %d",
        "8 8(848T8\\8h8",
        "<;=Y>",
        "DSAPKEY2PKCS8",
        "vKbE-",
        "*;C%SL",
        "!#^q}L+Q#",
        "in.32i",
        "tp8p<OO",
        "|.T1j ",
        "xf;@H",
        "wD|,W",
        "JkzJd$",
        "B3Q;S",
        "3#>o%",
        "98?O0",
        "`(_5_v",
        "FAILED_TO_LOAD_PROC_ADDRESS",
        "I/#dO,",
        "1C7\\w",
        "Q?X2?q",
        "il)KZ$",
        "QTxv\\",
        "1\"1-1N1^1h1r1",
        ":f;s;",
        ")hl(=",
        "4C5HY",
        ". #(\\",
        "|i:nw",
        "Si\\0D",
        "<ML 9",
        "\\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\f36\\fs26 \\sbasedon10 \\slink3 \\slocked \\ssemihidden \\spriority9 Heading 3 Char;}{\\*\\cs18 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\f37\\fs28 \\sbasedon10 \\slink4 \\slocked \\ssemihidden \\spriority9 Heading 4 Char;}{\\*",
        "t/[k?",
        "{3v%X",
        "}i.F/",
        "S;t}-",
        "q;`QP",
        "545=5u5",
        "Z%<zb",
        "Y^Y=o",
        " Y|sIVb",
        "dh public value length is wrong",
        "yS~Jjz",
        "57n=W",
        "A(;rDwE",
        "pEvents",
        "^]c$G\\0c",
        "{aWUi",
        "Uy45CQ",
        "$,u^L\\",
        "DFV0x.L'",
        "F|Dx9",
        "to Check Point shall be borne by You. Any transportation costs incurred in connection with the redelivery of a repaired or replacement item to You by Check Point shall be borne by Check Point; provided, however, that if Check Point determines, in its sole",
        "\"55UoR",
        "t$<UW",
        "SupportDir: %s",
        ")%5sA",
        "BTF|c",
        "sa\"ph",
        "_=Hdf",
        "i2d_RSA_PUBKEY",
        "aExecSecureObjectsRollback",
        "I$4\"#",
        "EouI?rK",
        "J#{sl",
        "3:v9r",
        "@W`c_M7",
        "0N@nc",
        "$AmH0",
        "NUon*",
        "}6kOX",
        "ref;u",
        "#0+0;0V0i0q0",
        "umJRWh",
        "Qdq\"yN<",
        "RS\\aT",
        "v-*_3",
        "S_,MW",
        "%0A`_YR",
        "H<0)M5",
        "r0Qb8Ud",
        "}$^gX8",
        "G4IYr",
        ":2:8:\\:q:z:",
        "T@;p_",
        ">!?E?r?",
        "id-smime-cti-ets-proofOfSender",
        ">xgG^",
        ".\\ssl\\d1_lib.c",
        "EZ#,9",
        "CAMELLIA-128-ECB",
        "mlbxBw",
        "0H1d1",
        "A`yL.9",
        "PSSSSSS",
        "#2#'>*a",
        " q!nr*B_",
        "758G8",
        "=_@_IT",
        "[u<u1",
        "FTe(y",
        "CleanTray20Component started.",
        "Zy#ZK%",
        "7!%1u",
        "Slim_Standalone.dll",
        "/@S\")",
        "[lP_!A",
        "m~^9hFu4",
        "t'vrC",
        "-=I\\l",
        "t:Ob`5",
        "Requested range was not delivered by the server",
        ".\\crypto\\hmac\\hm_ameth.c",
        "9q9|9",
        "2*2b2",
        "!D*1R",
        " 0x63",
        "d##F$",
        "7xK#?",
        "c2d0383fc818c798cf64e52f597c740f1cbd05df0c264c49134cf09d4a60e8a107260f20f92d47b374e32f000000ffff0300504b030414000600080000002100",
        "iz~)2",
        "1.7)z",
        "?W,1;",
        "[LICENSING] LteCheckRun: NOTICE corrupt key revived (2)",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 For }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid1729076\\charrsid15169477 Warranty Replacement}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "\\Arr\\",
        "E$m=`Z",
        "+2/itm",
        "xslA\"3",
        " A*/3C",
        "?<Qf+X/",
        "d't3$d",
        "T$)BIk",
        "I=JGJ",
        "t9a`bb",
        "ADMIN_REQUIRED",
        "6Q(!\\u",
        "AcUQfQj",
        "i#=O5",
        "<iZq\\",
        "9>:}:",
        "D<QN|",
        "\\v:ne",
        "}`II6",
        "dn|i{",
        "O-I-7",
        ")G%2;v",
        "%1w|O}",
        "sdI)BdD",
        "V:f?|",
        "v\\[xL5*\"",
        "Failed to add name to CustomActionData.",
        "jJ*4dn",
        "-G$v3",
        "id-aes128-wrap-pad",
        "dl49c",
        "vJv>9",
        "Kd_Jt_",
        " 0xf5",
        "%,4k!",
        "mOk5Qg",
        "O`L_T$7)W",
        "#vU<W",
        "stoll argument out of range",
        "v)vYI q",
        "?qP$#U",
        "<[=`=V>",
        "R=;Dv",
        "Xh0F(",
        "=m}y|",
        "F@9L$",
        "R:}^p",
        "o@P5H",
        "93:s:",
        "Qo\"0_",
        "~B#1A",
        "9G?eC",
        "oP1\\'",
        "AX%U]~!d",
        "9-veI",
        "0 _}U",
        "TS_VERIFY",
        "IswRecursiveThreadSpinLock::Leave: _ctx.recursion_cnt = %d <= 0 before decrementing (owner_tid = %u)",
        "??0_Lockit@__std_alias2@@QAE@XZ",
        "C|)nlE",
        "q 2lUv",
        "Uvi9O",
        ",&slM3",
        "#H!FH",
        "=$=,=4=<=D=L=T=\\=d=t=|=",
        "<^s1$r",
        "{'{^cn",
        "+%a2]k",
        " 'no office mode' property is found + marked as not disabled",
        "a}vXL\"Tm",
        "|re}s",
        "4F8jp",
        "StopAllServices",
        "eR!fy",
        "bits: '",
        "94U,d\"",
        "ASN1_dup",
        "GM=LF",
        "959`9",
        "b*c*d",
        "0zKRq",
        "ndDR>",
        "181D1d1p1",
        "!T>7l,",
        "(4L\\W",
        "k*k& @",
        "U@&Bc",
        "ArD>C",
        "4i![C",
        "0rNt;",
        "+SMQKz",
        "nU`W8",
        "2iEB?",
        "2Y3)Q",
        "(hP w_",
        "asn1 encoding routines",
        " 0x13",
        "vI:!B2",
        "BOoD2a",
        "y9yI&",
        "HcX:m",
        "H 4i{",
        "jkjej",
        "s<`K.",
        "(^^:*",
        "jZh<8#",
        "OP/06",
        "qgt.PQ",
        "ojS8L\\",
        "Registry error:  out of memory reading a binary value.",
        "omb,=",
        "8{1I|",
        "%s------%s%s",
        " I$n9",
        "qEiVv",
        "A&RwV?",
        "#P8U5O",
        "3\"zRu",
        "7H7j7",
        "N[A/:v",
        "^cKN`",
        "p?h<p",
        "uz#Q?",
        "zlscvins.exe will no longer run",
        "gzX^l^",
        "?'?-?4",
        "O0i!z!",
        "){DMAG",
        "C]&+#g",
        "socks",
        "?/-^2TM",
        "!l Bo#",
        "656:6A6F6M6X6m6",
        "?#6{@Hj",
        "Q^['F<",
        "T<MvK",
        "pYCSRZ",
        ",'hL\"G1",
        "koVRl",
        "@iM =",
        "^aO'_t",
        "\\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566  }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid16076773 the technical support phone numbers listed at }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1591330 ",
        "MzIKA",
        "X!d3\"`",
        "A#h(_u",
        "Gv^l*",
        "fYr-w",
        "V`oD<j)",
        "8 8&8,81878=8C8H8N8T8Z8_8e8k8q8v8|8",
        "Y@>/l+",
        "pLLb{",
        ".]?1*",
        "435<5X5g5",
        "n=Tj9'",
        "jAj{j",
        "singleLevelQuality",
        "6%6+6",
        "v\"#--5",
        "+'|U+",
        "regex_error(error_paren): The expression contained mismatched ( and ).",
        "cCuh_",
        "1TNg'",
        "&P=YRe",
        "M6Mu$",
        "656Y6}6",
        "Su+ ?a",
        ":p 7@",
        "-5M|x",
        "&I0l[",
        "%-+n]",
        "C/PUm",
        "jsjvj'",
        "{kOFE",
        "4c;x;",
        "p]2Kn",
        "fp+JY",
        "O5pnd",
        "CMS_RevocationInfoChoice",
        "0/0K0d0",
        "-w_3h",
        "$*RZC",
        "Zd\\suRA",
        "no need to restore SC uninstall settings. Continue...",
        "Plugins::Register:  Registration failed.",
        ".lCA>",
        ".1w7v",
        "ECDH-RSA-AES128-SHA256",
        "LgP]h",
        ".{uea",
        "2zfzfzf",
        "STNZxa",
        "C`@2*2R",
        "z( [\"N",
        "YdCAB",
        "6/6Q6c6",
        "$m0e6",
        "1G2y2w3",
        ">^^B5<X",
        "2>)<E",
        "? ?@?H?T?t?|?",
        "cU u;L",
        "LkV&9\\",
        "6!777x7",
        "d5G<{ThS",
        ")qJ)F",
        "6/6Z6~6",
        "Du>.%_",
        "|<`N^",
        "8%BTD",
        "could not load ASN1 client certificate, OpenSSL error %s, (no key found, wrong pass phrase, or wrong file format?)",
        "wo'E^",
        ":kU9sGs",
        "Y^Uap",
        "z]sb\"",
        "ZSwQ6",
        "m$>~Q",
        "m7fFI",
        "Pg/xQ",
        "F{h0p",
        "RSA_padding_add_PKCS1_type_2",
        "k'1}(",
        "k olzl",
        "c=GxK]d",
        "B\")%$/F",
        "GzY{zC",
        "<\"2D;",
        ".?AVFeatureSmartDefense@@",
        "RB%3wS^s",
        "4&4=4F4~4",
        "VokE*",
        "n7*6\\",
        " Pqwe{",
        "lt<Wy",
        ".rdata$zzzdbg",
        "ZLN%010u%04u",
        "6|hI*S",
        "zTsOj",
        "!+L:I",
        "aH=9v",
        "!w~AA",
        "\\&Q_*",
        "F-qOE",
        "TEL AVIV-JAFFA1/0-",
        "~|:0y",
        "[VSUninstallProduct]before login to vsmon. Flags=0x%08x",
        "8$8,848<8D8L8T8`8",
        "&3Rs|",
        "klmDZbg&*",
        "]qf5G69b",
        "US8SJ",
        "GetVersionExW",
        "26 x*QY",
        "lv>0?3",
        "wK\"8j:2",
        "q\\VZ,5<Y",
        "|caD>",
        "lB<-8",
        "=A>L>q>}>",
        "_[z9Vt\\$",
        ">9(*!",
        "y'?ya",
        "noA8G",
        "2~nRo",
        "?T!\"G",
        "NDZ}{",
        "parse error",
        ":|v~uH",
        "'8BW$",
        "t}XC]",
        "jrjej",
        "=(>L>",
        "mjv`k",
        "s&fYb",
        "!DW&-",
        "A)`U|",
        "WLmD!",
        "#=Z3oO",
        "3XxN#-",
        "WRVx9[",
        "6GT'G",
        "211125000000Z",
        "lY#y4",
        "`(5lV",
        "5Xvkb",
        "(Y-g1",
        "QaQdQgQl",
        "ZAJu1",
        "1cRcy%",
        "V#2hs",
        "/1.1;H",
        "*LaE%:",
        ".pj1x",
        "abTjj",
        "'i$\\_Vh",
        "DiHcj",
        "8!828G8L8",
        "0s0\\UX",
        "zS8QH=",
        "E}9\"X",
        "eb*HF",
        "575S5o5",
        "ALPN, offering %s",
        "jtp\">Wup",
        "Hqk8CCJ",
        "TDjyml",
        "LVAc7NWtK>",
        "051@1F1O1",
        "4wE2UU",
        "4?4E4V4h4",
        "L$P3L$\\3L$$3|$,",
        "LN_0Yr",
        "3#343E3_3d3s3",
        "6-7Z7",
        "xSy_X",
        "xE;5h",
        "I&aOJ",
        "U7iYE",
        ",)wr,",
        "P81{>",
        "3V3h3",
        "7`tGMv",
        "dCaA1w",
        "t$Pjgj",
        "F=9?7@7",
        "eZIS_",
        "3ovAU",
        " cacb",
        "D$@SP",
        "Qw{,(",
        "X,hkF",
        "4J6e6",
        "#zC|m",
        "9&ezb",
        "UpdateVsconfigXML:  Checking if AV is being installed.",
        "GyT$;",
        "&j:z6X",
        "O9n{YE=",
        "6W6b6l6q6",
        "x'saYR+",
        "]Y&44",
        "setct-AuthResTBE",
        "*LcEs",
        "Kerio Personal Firewall 2.1.5",
        "@s <s",
        "696L6",
        "eodowo$o",
        "\"%(#T",
        "PAO{n",
        "Rewind stream after send",
        ")\")$L",
        "XDISPLOC",
        "wpR2JT",
        "4`tis",
        "V[)-on",
        "5Qi`;M",
        "@Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds",
        "hMzFO",
        "ymRkK",
        "FLDCW",
        " hjd ",
        "*g^V4",
        "KQ!vB4",
        "MSXML.DOMDocument",
        "%EN=x9",
        "}Viux",
        "z@uu`",
        "]bTTD",
        "nZw|fcf\\xlm",
        ">4>]>o>",
        "Wxg-n",
        "r;{B+",
        "id-pda",
        "k+^5[jC",
        "Ufp/{",
        "N/Cpkh",
        "5/6:6Q6]6n6",
        "ntlocal://%s/%s",
        ":rd]R",
        "9!9>9V9n9t9~9",
        "V-6A[",
        "2B2Z2",
        "}E**A",
        "r!W%ow",
        "(=J7Cd=&",
        "p#myo",
        "NrAB@",
        "RZJr3",
        "1I2R2",
        "So(Himr",
        "3zJ-lV",
        ":`gf$",
        "3v*j&p",
        ">>uZ'",
        "yimN2",
        "/.T3d",
        "B@-sf",
        "bad base64 decode",
        "xBV(C",
        "M>S|'y",
        "@?b@2",
        "mj\"M#LQ",
        "8haT>",
        "Af#DCX",
        "AT9J^",
        "S5=K?",
        "@(1o4F",
        "}^VpK",
        "X1n@bH",
        "d,:YeC",
        "6}v$<",
        "Y^/Ib",
        "}\"L~K",
        "R\"R\"S$)D)",
        "t}RuD",
        "6.6R6]6k6w6",
        "es-es",
        ">ub\"\"u",
        "ADDLOCAL",
        "bJ9Y}",
        "K@0gh",
        "Xr'hj",
        "jBjsj",
        "@Pnx\\",
        "/7NB>",
        "no ciphers specified",
        "6Rhb2*",
        "$U%i%",
        "hNpe\"N",
        "1bdno",
        "Als7::",
        "737[7",
        "a2YE,",
        "q*(Z\"",
        "LY48HS!",
        "IsValidCodePage",
        "YM`kc",
        "NUb~=",
        "59<le%",
        "9J]yW",
        "jvt3!",
        "T6$:.",
        "FuFaFmFyF}F",
        "Z*g4=",
        ">\"><>@>G>V>i>x>",
        "REMOVESC",
        "w eGZS",
        "UpdateVsconfigXML:  UpdateVsconfigXML started.",
        "Xr%&hQ",
        "l*>-j",
        "#n Td",
        "qM\\#>",
        "5lo!F",
        "rK2XLnFb",
        "Global\\vsmon_StatusUpdate",
        "Id;S,",
        "BR/XI",
        "c^gef",
        "$!UQj",
        "1cb/1\"",
        ".\\crypto\\hmac\\hm_pmeth.c",
        "tY|Z1",
        "tls12_check_peer_sigalg",
        "*@7 n",
        ";?#Ib",
        "AUTH %s",
        "5i:Fu",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\CheckPointEndpointSecurity",
        "jp5!v",
        "1%151@1J1T1^1h1r1|1",
        "AA'e/",
        "*5#49g",
        "$G>/?~G",
        "JTBIZh",
        "RwGV8G",
        "5?o_z",
        "]y}Gf",
        "Bad access",
        "<2pb#",
        "kkkYn",
        "{\\f456\\fbidi \\froman\\fcharset177\\fprq2 Times (Hebrew);}{\\f457\\fbidi \\froman\\fcharset178\\fprq2 Times (Arabic);}{\\f458\\fbidi \\froman\\fcharset186\\fprq2 Times Baltic;}{\\f459\\fbidi \\froman\\fcharset163\\fprq2 Times (Vietnamese);}",
        "{;m_9",
        ";3MsB",
        "h$j:T0",
        "7xE3h",
        "tp|}U",
        "hQ5i\"",
        "6>aE]\"",
        "ZD1hlI",
        "#PBTJ",
        "Vi ;?",
        "|E_MVUw",
        "484T4p4",
        "Gr=O<",
        "(ZdOt",
        "rvFo}",
        "A<\\8M{",
        "n`Y`^} ",
        "0$0*00060<0B0H0N0T0Z0`0e0j0p0u0{0",
        "\"p,>v",
        "OATCz",
        "^c{,>O4",
        "D$4SVW",
        "_ak,%",
        "YA33:o",
        "GetLogicalProcessorInformation",
        "JSN{K",
        "z\\r{T",
        "VersionMinInclusive",
        "vh@m&",
        "vR_p!",
        "6;=ycx",
        "5K}PK",
        "<c9`\\",
        "qFzWE",
        "u,T-`H>fA",
        "78,ts",
        "I@#h`}",
        "UL( Q",
        "[DUMPFILE] Error getting the install date",
        "/Wlo:",
        "y^}yW",
        ":g{P`",
        "~_&Goe",
        "D$Dj ",
        "Remove From CRL",
        "Ll6ihR",
        "<,=e=",
        "E\"NQcun",
        "5+D7no[",
        "8(G!e",
        "\".Lt~MC",
        "*VE!p",
        "df2rd",
        "\"T4FL",
        "ur]#R0&",
        "kdFdVdf`v",
        "3['6J",
        "SunMonTueWedThuFriSat",
        "qke:e",
        "nEPK+",
        "9[ziJ",
        "j5[K^*",
        "<Ck0(l3M",
        "[JJdJZ",
        "[c$dm",
        "AhP:[",
        "d< de",
        " (%s)",
        "~/91C-2",
        "    DisplayName=\"ZoneAlarm ForceField (preinstalled)\"",
        "a12f4",
        "q\"+M|",
        "SELECT * FROM `RemoveFile`",
        "_(-7>41",
        "bases_version.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "8g#B`",
        "}e'nfK",
        "#%3rs",
        "291+B-",
        "XijKzF+r",
        "Cy&jD",
        "oE0@r",
        "$c.sIE[",
        "9t;v]S",
        "],!BZQ",
        "9J9Y9n9x9",
        "INT_DIVIDE_BY_ZERO",
        "O[2x7!",
        "E&sDw",
        "!145d",
        "hex_to_string",
        "CONOUT$",
        "N5xLJ9",
        "Sectigo Limited1%0#",
        "04q2|",
        ".?AVclone_base@exception_detail@boost@@",
        "VDL_CUR_DIR",
        "PzQ2^L",
        "hCIY=&",
        "Failed to set backup privilege.",
        "]GrL/WUX9W:]",
        "}G|\"x",
        "/Do+mt",
        "wGD't",
        "gB9Bx",
        "nij:$",
        "\\securemote",
        "6(60686@6H6P6X6`6h6p6x6",
        "i\\GWX",
        "]Zwp:",
        "1S1^1y1",
        "_b6Bn",
        "t#F;5",
        "tl%\\\"",
        "Dn^Q[",
        ":?:c:",
        " 7b!/",
        "GetTickCount64",
        "saving due to change",
        "? ?0?4?8?<?@?D?H?P?h?l?",
        "j?>nC",
        "Endpoint Security not found exiting %d",
        "it}lN",
        "cEQ<q<)",
        "S3&MBH",
        "t3:zK",
        "41xU*",
        "Y!3^d",
        "m0aao=f",
        "I/rYD1",
        "jKz1,",
        "r)<Q~ij)",
        "\"?)Bl",
        "Cx~'g",
        "x4Y`r",
        "9Z:a:j:",
        ":IBG4",
        "n,z5{",
        "bV<TS",
        "64oBL",
        "utory law, attempt to (or permit others to) decipher, reverse translate, decompile, disassemble or otherwise reverse engineer or attempt to reconstruct or discover any source code or underlying ideas or algorithms or file formats or programming or interop",
        "Xvxa86",
        ":$:0:8:P:X:`:h:t:",
        "d93b64b060828e6f37ed1567914b284d262452282e3198720e274a939cd08a54f980ae38a38f56e422a3a641c8bbd048f7757da0f19b017cc524bd62107bd500",
        "o&1m&",
        "JY5]5",
        "q9`+7DF",
        "4!bc!",
        ";P;r<",
        "DDMwOo",
        "&}?j/",
        "zB}U}a~",
        "faw=w",
        "anw!b",
        "E!PKz6j",
        "j5hvqhisiu3s4he7bhx644bu4g0",
        "TS_RESP_CTX_set_def_policy",
        "(EJ%%",
        "Ix(\"?V",
        "5?6f6",
        "evNrH)m",
        ",|'cP",
        "w#wCL?* ",
        "lg'EG",
        "<,=X=",
        "wLC6G8C",
        "awn]{",
        "SELECT",
        "W8CC*bd~X",
        "n=nJ!n%",
        "{nQB9i",
        "TFu/&I",
        ">;d46",
        "3T$L3T$03T$$",
        "]tNFY",
        "up>&V",
        "Helper::stop() -- got done event.",
        "{/?\\p}",
        "7t0S&G",
        "BV7;u",
        "VE8]Lq:",
        "<.s\"Y",
        "SETLE",
        "bad ecc cert",
        "?_\"Rg",
        "4J4`4",
        ".CRT$XLZ",
        "g[d&z|X",
        "VSPWInstPasswordRequired()",
        "wpOY^4",
        "h8\"&l%g",
        "33ub?",
        "qn?uG",
        "MODULE_RUN",
        "[EXCEPTION] logic_error \"%s\" caught; rethrowing",
        "ygE.dO",
        "jojnj",
        "~p.iD",
        "k g^`C",
        "setAttr-GenCryptgrm",
        "r3]/Y2",
        "mY-!rq4",
        "R)l&X1",
        "zh-cht",
        "lt]pf",
        "Not enough space",
        ";P-Mx",
        "SWm\\];",
        "|%bJ(",
        "I-71.y",
        "C?,H!}",
        "ST)T)=",
        "GOST89MAC",
        "=N>r>",
        "]G&A\"h",
        "-: Q8",
        "UOLe| ",
        "4*464>4C4y4",
        "\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\f36\\fs32\\kerning32 \\sbasedon10 \\slink1 \\slocked \\spriority9 Heading 1 Char;}{\\*\\cs16 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\i\\f36\\fs28 \\sbasedon10 \\slink2 \\slocked \\ssemihidden \\spriority9 Heading 2 Char;}{\\*\\cs17 ",
        "88%:0",
        "b=#`>",
        "vPN<bp<",
        "n^y2/6",
        "i/6TI;",
        "Wh0;!",
        "NC/!g",
        "1#1*1`1e1",
        "a7uvwO",
        "ECDSA_DATA_NEW_METHOD",
        "o2i_ECPublicKey",
        "1T d(",
        "N*sEo",
        "(gfPj",
        "7rZT:I+,",
        "f{hr\"",
        "Bf^1Y",
        "8 888H8L8\\8`8h8",
        "<;\\$t",
        "@M/RW",
        "6)rDe",
        "ffIFb",
        "8\"tD+",
        "UNb!1",
        "v~<bF7",
        "q07z:",
        "CD]^_[",
        "3{\"=@",
        "535_5",
        "}6.Js",
        "[jCKH",
        "wmryEr;'",
        "Got:  %d, GetLastError()=%d",
        "131Q1_1f1l1x1",
        "VJ~p_|@{",
        "`Fj_(",
        "{SPZT",
        "SHUFPS",
        "ZHDLE0B",
        "7']Cj|@",
        "uz-uz-latn",
        " 35T1",
        "2wU.:b",
        "B]lNDx",
        "b`RkVu8f",
        "ECenDt",
        "6o.]j",
        "r]=d8",
        ":$:4:Q:y:",
        "StopRemediationService finished.",
        "a}F't",
        "aJL?Dh",
        ".?AVcodecvt_error_cat@?A0x372a21cc@@",
        ";8;P;",
        "F{6iO1",
        "@y_6PZ",
        ")KM[+",
        "]H(2e",
        "unable to get issuer details",
        "[?Yez6\\",
        "jrjvj'",
        "$a;ad",
        "g0MSxsq",
        "['sc=",
        "PPxD<<%",
        "8yj&Dfjb",
        "failure in sk_push",
        "%v*Fu",
        "MD4 part of OpenSSL 1.0.2h  3 May 2016",
        "'`{A8P",
        "K1'$v",
        ".?AV_RefCounterBase@details@Concurrency@@",
        "failed to duplicate output pipe",
        "HM78m",
        "SOlM`",
        ";uUob",
        "3 3$3(3,34383<3@3D3H3L3P3\\3d3l3p3t3x3|3",
        "Internal Error - Failed to retrieve CLIENT_SUB_TYPE property, return Endpoint Security type",
        "7<-`w",
        "OpenSSL 1.0.2h  3 May 2016",
        "bu_V1",
        "setDriverMode;",
        "'RH9q",
        ":\":):3:M:S:Y:`:q:w:}:",
        "FeatureSmartDefense SD=YES so run sd_uninstall.bat",
        "_z7\\5",
        "Zm?gB",
        "\"\\ D/",
        "BH2d1\\",
        ".yoLpU",
        "ns5`0Z",
        "8Ap M",
        "t$(EV",
        "UnBa'",
        "4 4<4@4P4T4`4p4",
        "H-~;X",
        "Dl[x7",
        "t$@h;",
        "\"u5ug",
        ":*;o;",
        "signature algorithms error",
        "[/bd1",
        "@.U?8",
        "<HP$B",
        "LfTRuk",
        "^_=jt",
        "ka8Bt'G",
        "\"&1Zkp",
        "ClientSubType = 'E'",
        "PRHelper.log\"",
        "{'bs*r",
        "XeLOPu",
        "#WtGq]y",
        "RSA_new_method",
        "9C(tX",
        "pbeWithMD5AndDES-CBC",
        "D$ +D$,",
        "wKWz#",
        "qJrrp",
        "\\[:[d]",
        "RVL)%",
        "0`$i1:",
        "E<Qk?",
        "AVeKOB",
        "****************************** VnaUpgrade started **********************************",
        "Di]<D",
        "boost::filesystem::system_complete",
        "G6>PuU%",
        "q0WKC",
        "3sK-E",
        "(bFM=",
        "D7(g{",
        "O0~S/I@",
        "z=y'<",
        "failed to get special folder path",
        "U8y8(x",
        "86*kF",
        "kw4/9",
        "U~?=4r",
        "FO}*r",
        "YZE'1D",
        "<<<}|",
        ";A<a<",
        "5ERrqK",
        "Ssc4ubS",
        "~6ORL6",
        ":gD,:P",
        "=5}CC",
        "+ndS0",
        "Z*ZjZ",
        "smime.p7z",
        "FQWW~",
        "l$$C;",
        "8.8J8f8",
        "P\\Z0<",
        "J?dU%",
        "\"R[~c`",
        "}USVW",
        "*[*q*r*s*t*u*v*w*x*y*z*}*~",
        "D b\"p",
        "/BD3}f",
        "7MIl]",
        "HHty+",
        "7)86:H:",
        "o[/S8",
        "/3xv[",
        ">Q>j>o>x>}?",
        "[\\#\"?",
        "j)iW2",
        "2fT$v",
        "~x9{b",
        "f@+fQ",
        "949T9\\9d9l9t9|9",
        "calculated and stored hashes mismatched",
        "24383<3H3L3P3",
        "Installer loaded Vsutil.",
        "l69xq",
        "MJ2 J^",
        "8Of(P",
        "3O&\"~.",
        "F:\\ckp\\src\\EP_VSInit\\E87_20\\CMpub\\lib\\win32.release.32.msvc141.ansi.mt\\vsinit.pdb",
        "?!?A?a?",
        "mEYPh",
        ":a?+u-",
        "BITSTR",
        "6%606",
        "ZGmMS",
        "VQPPt",
        "#jE%%",
        "N~K8)R\\R?",
        "HYr!v",
        "e/*sM",
        "zMKw(u",
        "u(j\\h",
        ",q*YY",
        "h<D- ",
        "o'nT(k",
        "7[7v7}7",
        "GPegx",
        "< <$<(<,<0<4<8<@<X<\\<t<",
        "@9$v%",
        ".ftq7",
        "u0St:",
        "[LicMon] %s",
        "~7.1O",
        "s)c9V.",
        "sv__a",
        "mY._+X",
        "kcJ4h1",
        "xt^u-",
        "%1hkSo@d",
        "k_MAU",
        " UNINST_PASSWORD=\"",
        "726S%m",
        ";J;w;",
        "CompanyName",
        "PD11L",
        "N'700_",
        "l$@;T$(|",
        "V$T -",
        "3Cqr8v",
        "9z<gh",
        "D$ PV",
        "So{y-",
        "B&!M8",
        "L`O<?",
        "+dCXZ",
        ";'zHB",
        ";J'N(P",
        "P) %c",
        "Iq^^L",
        "?4e[b",
        "094!}",
        "Oi*n{1w",
        "=P=Qz",
        "G/`(}~s",
        "xNAwRw",
        "+?ka_lX",
        "g~g,Y",
        "CMS_RecipientInfo_set0_password",
        ".?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@",
        ",1WL\"",
        "PYSn~Eo",
        "expecting a time",
        "7!777g7t7",
        "CryptMsgGetAndVerifySigner",
        "8e8~8",
        "cMeG0",
        "08-00-2b",
        "8Zdf,`",
        "3@_ba",
        "|/QxL",
        "XJNz?",
        "0Q0z0",
        "};D\\y",
        "Nbv!&",
        "vHYa8(oS0",
        "k-:+j",
        ";Dk78",
        "~aKRx",
        ",&-@@*",
        "~E;^ ",
        "GetTempPath failed",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386\\charrsid15169477 ",
        "UVWhp",
        "\"Ha\"@Hi",
        ".WcaNotVerboseLogging",
        "ei<n)",
        "failed to read component bitness from custom action data",
        "D$ St4PUP",
        "7!c}w",
        "}'8Fs",
        "Installing virtual network adapter",
        "XuUD?",
        "OBnq1%",
        "`^zuOs c",
        "IqL#;",
        "gd>g=",
        ";2<q<^>",
        "L(29MfY",
        "0)0E0a0}0",
        "o.;D4px",
        "t7`Rs",
        ";Kt&j",
        "%lm!ic",
        "PKCS7_SIGNER_INFO_set",
        "v$,K0xB",
        "extensions",
        "u'Jq<01",
        ")f ,q",
        "J_o1r",
        "PL5O5",
        "= =$=0=8=<=H=P=T=`=h=l=x=",
        "O;M#)z(p",
        "#SqUw",
        "!TwRc/",
        ".0V0%A",
        "):hO_",
        "bad handshake length",
        " 0x72",
        "eLjIGz",
        "VnaInstall",
        "RemoveOldVpnFiles(%s)",
        "%cBda",
        "hMSb6u",
        "=W_vt",
        "au9/!!o",
        "0(0<0X0p0",
        "y{+UB",
        "koNL~",
        "gfa{3",
        "yB$Wt",
        "eA_7,",
        ":]PT@",
        "tQ7pX",
        "Fn#UZ9\"",
        "tOm&0",
        "kimY]n",
        "gq*?FU",
        "ZDhR`",
        "Hr_R\"",
        "1~.uc",
        ".?AVScheduleGroupBase@details@Concurrency@@",
        "KbtYy",
        "`8;`P",
        "j~=@q_Q",
        "ks{37",
        "`Ql(U",
        "G\"C;s",
        ")Pjy=",
        "dbghelp.dll",
        "uihg6",
        "Hg#; ",
        "l1Xi7W",
        "group2pkparameters failure",
        "prime192v1",
        "1 1$1",
        "FaultSection",
        "m~m~<",
        "Z7Z8Z9Z:Z;Z>Z?",
        "R\\dd:",
        "|I|th",
        ".......",
        "TerminateApp",
        " 0x12",
        "ZmvAO",
        "A$`12#",
        "Operation not permitted",
        "?\\JiG",
        "SSL connect error",
        "tQ9x tL",
        "\"U.yHz",
        "uF*CQ",
        "BPzj`",
        "or/4N",
        "]|IQ!P]",
        "aK,-k",
        "&9tp-TN",
        "6&6J6n6",
        "5G6!k`6",
        "~~{R8",
        "FeQ{L5",
        "||!I3",
        "o&!'P",
        "7\"8-8",
        "@0%`3X",
        "&C`Owv8",
        "9 9$9(9,9094989<9@9D9[9t9z9",
        "ZzL=O",
        ".BzB~k'Y",
        "AS)lP",
        "CreateZoneAlarmXml:  CreateZoneAlarmXml finished.",
        "^yZ#[",
        "9V9_9",
        "GetLastActivePopup",
        "][W L",
        "*>F3*JXgn",
        "K#6io",
        "nFg1NAd",
        "qM[}F",
        "]C&5L",
        "6 707<7\\7d7p7",
        "9p=x=",
        "ua}_2",
        "gftXP",
        "3,FUh8",
        "FAILED_TO_REMOVE_KEY",
        "p?q|T",
        "=A|Ps",
        "292C2d2k2u2",
        "InstallationFinish started.",
        "2Y2|2",
        "@^W$P",
        "y`t\\q",
        "GZ\"?D\\",
        "cIXY.Z",
        "\"8  >}",
        ";FD~H",
        "MsiPropertyEx %s=<hidden>",
        "XYH*Z",
        "7,8{8",
        "R|/\"7",
        "\"IzQ}L",
        "ib 7*",
        "3=&6P",
        "library bug",
        "failed to resolve the address provided to PORT: %s",
        "4*424H4m4~4",
        "\"V04y",
        "i-:=Ccef",
        "oe:J.jm",
        "[q27h3%",
        "A7zRU\"",
        "OM disabled in registry",
        "@o7QBx",
        "doapr()",
        ".?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@",
        ";QLu$;QPu",
        "x=RU4^",
        "deleteFolderAndFiles",
        "2 2$202@2P2T2d2h2t2",
        "_-?% ?T",
        "user too long",
        "_K*IJW",
        "Z=3BC",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  outside of}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14171957  the}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 ",
        "SUWPV",
        ";tY(\"=",
        "iuMe,",
        "=VZhJ",
        "2'#FG",
        "*ZEZd",
        "OnUpgradeAfter:  UpdateVsConfigXML",
        "LTs1+",
        "2&3D3c3",
        "Str|24",
        "@E}#t",
        "nr5v5(7rF",
        "need dictionary",
        "bC?s-",
        "no recipient matches certificate",
        "q4p>N",
        "G5j,+",
        "@Q3_)",
        "c`WP2.",
        "/A]_k",
        "<5Zz#6h",
        "ua:N|",
        "IntegrityMode does not exist in registry - FW_ZA_INSTALLED is installed",
        "P1\")b",
        "}v.|<lz",
        "s\\Tj+",
        "!H#p#",
        "jN2?H",
        "No such node",
        "9B9~9",
        "\\system32\\vsdata.dll",
        "6(6-7",
        "abandoned_transaction_",
        "G(TU=]",
        "YbYjYr_z/",
        "=&>3>G>N>w>",
        "|1bL:",
        "8x8D:J:X:^:d:r:",
        "USERNOTICE",
        "D2=, ",
        "=O>b>",
        "x!S~m",
        "Xa.xd",
        "UPDATE Binary SET Data=? WHERE Name=?",
        "DP~)e",
        "HgGE2",
        "SiP_<",
        "LeG@p0J",
        "?D;Wx+",
        "{d7:W",
        "p|X/{ZBF{",
        "q/,Q(!",
        "TL|/iQC",
        "WIN32_NAME_CONVERTER",
        "HZWHc?C>",
        "x@GCi",
        "q+QrS/",
        "5?pLj",
        "k*9 `D",
        "3L$D3L$01L$(",
        "3 3(30383@3L3l3x3",
        "&X&z+",
        "y+{e<",
        "55d3o",
        "$?d\"kt",
        "5#5k5t5",
        "$A3!#",
        "&b1+J",
        "TLRyKV",
        "EMAILSCAN",
        "Q7&SB",
        "RegisterEventSourceA",
        "The driver is successfully uninstalled. OS restart is required to finish uninstallation.",
        "        </imageentry>",
        "6m7t7",
        "1(12181I1",
        "f46&,v",
        "rlSIxA",
        "-.-Et",
        "3u'w%",
        "i!4e< ",
        "smTW,'",
        "pXH=&*",
        "/rk\\8",
        "t'xgv",
        "nL;*~",
        "Extension Request",
        "<atw<gt[<lt8<q",
        "g} zs",
        "<) T`",
        "g.VLfz",
        "~AyDZK",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\preinstcheck.cpp",
        "X=1~l)",
        "' ' '`",
        "FDE_Remove",
        "ANSI X9.62",
        "3$3,3`3p3|3",
        "[}SXU",
        "333M3o3",
        ".>ua$",
        "Xry1q",
        "+CKxI",
        "E8=ZbC",
        ">&>J>m>}>",
        "D$4PhT:!",
        "Sunday",
        "rYu{0k",
        "|N.u]",
        "D!i9D",
        "Zone Labs self-generated second chance exception dump. Use .ecxr to see the correct fault stack.",
        "4/4[4",
        "QuKrJ",
        "ytyWb",
        "WW$}0(",
        ";t2'.",
        "Ub}A<7",
        "&$n9L",
        "*H*(,",
        "Xw)-{",
        "!VFQ9",
        "<ItC<Lt3<Tt#<h",
        "smimesign",
        "BY CHECK POINT UNDER THIS LICENSE FOR THE PARTICULAR PRODUCT(S) WHICH CAUSED THE DAMAGES. Some jurisdictions do not allow the exclusion or limitation of incidental or consequential damages, so the above limitation or exclusion may not apply to You.",
        "oo0- ",
        "lk\"MB",
        "mob_endpointBanner.png",
        "UIFRAMEWORKVERSION",
        "?\"|*U",
        "cb/'~",
        "+54yp",
        "D9;5q5{",
        "I`M\\5y?\"!F",
        "}fvsX/",
        "=v5Lb",
        "7k*KBK",
        "dY9Ay",
        "\"0R-[",
        "/O0=p[3",
        "xLgt;",
        "[>PpX",
        "\\f1\\fs20\\insrsid11543880\\charrsid15169477 RMA}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477  number issued by an authorized Check Point service representative. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "X509v3 CRL Distribution Points",
        ".D_CX<",
        "TB{d^?",
        "q;^TT",
        "*GApH",
        "WTA.L",
        "@VK;cBm",
        ";TNUT",
        "Yg'Dw",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{4471FF45-62BD-11D6-B259-00C04FF4B435}",
        "heB{<vW",
        "#AMe_?",
        "MEkL)",
        "bRebootFlag",
        "0eV2>",
        ")>_ml",
        "6WGs|",
        "In SUBOPTION processing, RCVD",
        "q%1kr",
        "\\D(F^",
        "0-0F0_0x0",
        "'(R70k",
        ":t}36",
        "wO;bV",
        "o6rXv",
        "4DAVX",
        "8%HjX=@",
        "Ep@T&",
        "L4DOE",
        "YP[2#",
        "c/BRa",
        "s+:QpET!",
        "{3wB3",
        "CMS_RecipientKeyIdentifier",
        "WHzQ\"",
        "%QHK<.",
        "receiptsFrom",
        "UUPx((",
        "q`9tya",
        "hU=;Z",
        "t4UWV",
        "failed to get id from WixCloseApplication table",
        "pQBUH",
        "'{7YbB",
        "{S%zQ",
        "SEND LOCATION",
        "? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        ";R;g;",
        "#lU|F5CJ",
        "}?u[vv",
        "B/=m}",
        ")m2~X",
        "^xCqp3ZI",
        "L$4+\\$,",
        "?B#95",
        "tgR!{",
        "RLo4Q",
        "/HaeEs",
        "?y;r@",
        "4TmO5",
        "Tb$9e",
        "f)A#(M!",
        ";#<P<}<",
        "2s3}3",
        "f9eJ'",
        "\"B(n_",
        "jAjgj",
        "Y?Qj!",
        "5Kf6D",
        "t^WjU",
        "GTNNF",
        "R&eBu",
        "6.a+f",
        "@C55C",
        "y}5za",
        ">>>H>_>",
        "swa$r\\",
        "(Xf|z",
        "nlGA\\",
        "D:F %",
        "xgPNY",
        "ZLProduct.Features.pFeature[1].Version failed",
        "StopInstHelper",
        "6?gxr",
        ">N Ka<",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid3552546 License Grant}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "s|69[",
        "819A9Q9a9q9",
        ";;K9lX#",
        "!A9FB",
        "ZCkNI",
        "I)=I-",
        "jmjrj",
        "p:jO1",
        "D}W<z",
        "|IK=n",
        ">i/_^[^O",
        "7 8N8S8d8",
        "\\p<^>",
        "'\\lG,@Q}WobAT",
        "1 1-1>1E1S1_1d1",
        "4/XIV>",
        "$9x>r",
        "bsUWe5",
        "l[B;\\",
        "1 1(1L1T1d1l1t1|1",
        "`L1Jb",
        "!QVj*",
        "QFu~\"Z",
        "ag_iI",
        "J.M;7",
        "ha_1hk?",
        ".l\\3V",
        ">l!%?",
        "0;0R0_0t0}0",
        "t]j3B",
        "L}H\\P",
        "SET4o",
        "<xZ7A3",
        "}H=`|",
        ")wjy5",
        "yiLCT\\F",
        "c1R36qA",
        "c^V5&.",
        "j$k,5N",
        "safeContentsBag",
        "unable to decode dh certs",
        "Ob Mj",
        "X7R[w",
        "vBB.2",
        "Gf;7L",
        "38gPf",
        "]Y$[T",
        "#Ze\"`l",
        "w'A:(n",
        "Z3L$H",
        "Q\\T\"f?",
        "y)G&_",
        "Z3n( ",
        "U!h>-",
        "ee2ZN6~",
        "D$49G",
        "2$E.~",
        "1eFve",
        "|\\\"+<#^",
        "t$ UVWP",
        ";jyKJ",
        "ArBEY",
        "@58(6A",
        "(@xAZ",
        "hV{Xw",
        "Failure sending PORT command: %s",
        "2$2N2U2\\2c2~2",
        "%04d%02d%02d %02d:%02d:%02d GMT",
        " 9-;R",
        "Wi@m=",
        "p+~[h+",
        "J7^}n_",
        "-4&/S",
        "><>@>p>t>x>",
        "vA/#E ",
        "(zU:m",
        "$H6NqC",
        "H{XCkE",
        "id-cct",
        "EPNetUpdater.exe still running after 3 minutes. Killing it and continue.",
        "bL!fk",
        "qSi)<K",
        "UvR#+",
        ")urF5",
        "6)6\\6",
        "\\f1\\fs20\\insrsid6904607  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "Itbgd",
        "\\SecureAccessDSM.dll",
        "`z%Q~",
        "*Yot\\P",
        "566B6",
        "tr)LRt",
        "\"aMwK",
        "!dIaI",
        ",&;gA",
        "t\"hhi%",
        "u,h@M!",
        "= tte",
        "FeatureAntiSpam:  RemoveAfter finished.",
        "Shh:M",
        "ok>h@",
        "&x|Krj",
        "YY^[]",
        "1(1s1x1",
        "FY:w`&",
        "3iPZa",
        "FII:~K",
        "t$$SV",
        "758|8",
        "Pja_ L",
        "/?!V2",
        "kZjI*+",
        "b(im3h",
        "#;el7x",
        "de.de",
        ")\\mBk",
        "M*sg:",
        "ta-IN",
        "4xp}4",
        "!HPnl",
        "RegEnumKeyExA",
        ">6ap%B",
        "YSWhp",
        "3ITn,\"",
        "jnjij",
        "uxDL6l",
        "B]b 2",
        "(RK++",
        "]:L?r",
        "n\"jAq9",
        "\\ A]nk",
        "ln-Os",
        "i 4=@)",
        "<%<1<N=U=",
        "&N?%[",
        "r\\)67B",
        "failed to get install state for component id",
        "#\"p!f",
        "\"NK@O",
        "7KE6&_",
        "0'181K1X1",
        "N6Jdh",
        "0,0004080<0D0\\0l0p0",
        "1*191F1U1",
        "\\\"39l",
        "@{ECR",
        "\\ICHQ",
        " s|`P",
        "W*TS/",
        "^3+mo",
        "dH_X=",
        "Z9@LMVf(",
        "-af[M",
        ":'&@:,/I",
        "\"~4Jt",
        "6;7A7T7f7|7",
        "2JJ!w",
        ".h;kc",
        "KG;!]",
        "G0/Ii:h",
        ">b\\cdP",
        "\\Q^qGb",
        "F>c&0I",
        "GPEHG",
        "aGwu)",
        "mv?O_c",
        "8)_AQK",
        "FS-~f",
        "z_\\vQE",
        "sv[}[Lp",
        "?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "FF%\\w@",
        "ib0:z",
        "w'LT0a",
        ">3?F?`?f?",
        ">,>2>E>K>^>d>w>}>",
        "f&uBX",
        "xsS@8",
        "f`De6",
        "SLtoJ",
        "5.S+,",
        "TzHQO",
        "8<9a:",
        "Zf]^/bn",
        "*,%3~",
        "#~ckWP",
        "QqynU",
        "jqjrj!",
        "B_#XHO",
        "eAvkM",
        "Fvdot",
        "AM1 not found",
        "w4s)!",
        "4:v_c",
        "'_5Sx",
        "in&s@",
        "SQPUW",
        "D$8PP",
        "4(RHy",
        "Z6`I}",
        "IB&kF",
        "dqEcx)",
        "'c)'('",
        "dXk^v",
        "KMfZa",
        "E+JVu+m)}",
        "2.f+0&",
        "CnXK]",
        ";o<x<",
        "+iP {",
        "(;|hw9",
        "n$KTt",
        "Name '%s' family %i resolved to '%s' family %i",
        "0#tFu",
        "8-8A8I8a8v8",
        "api-ms-win-core-xstate-l2-1-0",
        "E$nA*",
        "u,johDx#",
        "CryptImportKey failed. can't use key",
        "Y|RC:",
        "oU7,>_~",
        "PMAXSW",
        "v Qco",
        ";Q<|<",
        "2FYmD",
        "#iT+V3Uf",
        ">D]q!",
        "TlsAlloc",
        "O0U0|0",
        "8@%IG",
        "3t0 ?9+",
        "~.ut$",
        "Invalid new VNA file version.",
        ">*M |",
        "lower",
        "JV{>U",
        "ffM{gf",
        "l)XS;",
        "Helper::StopCiscoVPN",
        "RZ6g \\.",
        "i386-pc-win32",
        "T9@CL",
        "J-5Bz|n",
        "fJ&:I",
        "wq)DP",
        "qt+A^",
        "kbTsr1",
        "i8'N\\",
        "D$(PhP|",
        "8w\"e/",
        "C4C5F8868570986459B06B66D9B75386",
        "January",
        ":O:_:",
        "+-jB|",
        "\" %\\kc",
        "y71GP",
        "ddcL&",
        "h98.m,X",
        "az(leM",
        "WWVSW",
        "w\\tCa&X_o",
        "9;9W9s9",
        "secp160r1",
        " !\"#$%&'()*+,-./0123456789",
        "%$')+-)+-)+-25",
        "~zw~hGC",
        "y@gJ8",
        "Unable to extract mirror.exe: %s",
        "{CP_g",
        "Xligt",
        "I=aTw",
        "[Gh}-",
        "0x2|20545x8|8",
        "z-+z~",
        "$:%Z%",
        "Cm}M?",
        "[tAbmRo",
        "0.0.0",
        ".kdji",
        "pueU.5'4n",
        "ECDHE",
        "< t8<",
        ">Y>a>z>",
        "0&0-020;0@0I0]0e0k0y0",
        "?U;K0",
        ")qj2?^",
        ".[!yz",
        "hRuMC",
        "L=^;6",
        "#I<@J",
        " 03Q\"",
        "EMy3,",
        "Bi[-L",
        "+(0  ",
        ">$>3>9>J>r>",
        ":WJ/I,",
        "explicitText",
        "$aVO*",
        "6|cj8~i",
        "`,3K!T",
        "setct-CertResData",
        "TP<@C&8",
        ":$:X:s:",
        "G,>g|",
        "O5>%6%,9\"",
        "o%h@h=",
        "17]!6r",
        "&8Fbb",
        "jyw^Y",
        "\"6FFS",
        "Socket not ready for send/recv",
        "ye}j4",
        "ProgramFilesFolder",
        "3!aMdLamx",
        "VXQ/l",
        "0 0$0(0,0005090L0P0U0Y0l0p0t0x0|0",
        "o`6\"6",
        "OOQF,",
        "uSj\\W",
        ":lG%Ir",
        "<\\etJ",
        "$x#$_",
        "bUlJ>.i",
        "(N)0P",
        "IO/9O>w",
        "KLTlW",
        "uch)C",
        "LqG)N",
        "Y)XQXq",
        "l?6=|",
        "O\"y,/Pw/K",
        "\\<T(c",
        "Jfu>.",
        "3T$L3",
        "~35RL",
        "uwfn4@",
        "Couldn't parse CURLOPT_RESOLVE entry '%s'!",
        "D$tPW",
        ":4:@:`:l:",
        "(vmA\\",
        "ssl_add_serverhello_renegotiate_ext",
        "!!y-{",
        "/j}FH",
        "h-%Q6",
        ")+-)+-",
        "SSL_CTX_use_serverinfo_file",
        "BS'n%+",
        "n8cxr",
        "-N,P*2x$",
        "F*ja\"",
        "0m&TB{Y",
        "EP_ShellExt2.dll",
        " .w5\"Q",
        "ih>.z;m*",
        "failed to add object data to rollback CustomActionData",
        "~d\"o7",
        "bFDRn6",
        "G d38B",
        "URPQQhp",
        "-brvv",
        "yCh`|",
        "Bo&oS",
        "'o2l|",
        "|)P!?Ua0",
        "mem_test_",
        "6[!v\\",
        ",bPB*",
        "6d:b=",
        "DynamicProgressFeedback",
        "?'?/?",
        "jefgB",
        "$)|j7",
        "tQet7",
        "%UY),",
        "ydj5h",
        "cs\",\"S",
        "1E(ZC",
        "~A&IE{H",
        "6e;pl",
        "MCPC\\Nq",
        ")6vHt]",
        "o\\ l:",
        "saa.png",
        "= >(>:>G>i>",
        "tIj?S",
        ",6;cM",
        "dL T^",
        "'(T|V\"",
        "2222222222",
        "w9'l/",
        "[s;O;",
        "V!c+!*Z",
        "CMS_ContentInfo",
        "*';BfZ",
        "@(;A(s",
        "Mw|!%?,",
        "4oMF,v$",
        "s$PS,",
        "b!Haw",
        "|+'[X",
        "}]~^TE",
        "!uSct",
        "m*AwEDC.",
        "K8aU.Eu",
        "Y* qO",
        "}}0}]kv!<",
        "QIV!zT",
        "9jk099",
        "?G?S?",
        "AgxX`",
        ";\\$ v ",
        "D4,F2",
        "8s9z9",
        "^u#rA",
        "sA$]b",
        "(rfxq8",
        "SVWj P",
        "ko5nn/",
        "'DTwz",
        "G7\"u_M",
        "jejkj",
        "A[!{>",
        ":Of+V_",
        "incomplete UTF-8 string; last byte: 0x",
        "Zy24a",
        "VW+NP",
        "uVhpi#",
        "zMvM1",
        "Wh:0H",
        "ve\"/A0",
        "0v:E$1(",
        "qA_LR",
        "9g+dPL",
        "Recv failure: %s",
        "v$9^ u",
        "[WinFW] SetWFStatusXP, failed to set domain profile, error=%x",
        "KMKWK\\KiKlKpKsKwK{K",
        "g!gAh",
        "T}~erK",
        "qKQ+j+u?",
        "padding check failed",
        "9 9$94989<9P9`9p9t9",
        "Verifying DAF stop",
        "\",#9,",
        "acSw(N",
        "(yEF#X",
        "compressed-data",
        "~~_O9T",
        "Fc){|",
        "WIX_SUITE_TERMINAL",
        "$P!UsU",
        "hT2UE",
        "gqKZ6",
        "-|,u&",
        "`_u7/",
        "]-Wn4",
        "/xVqQz$I8",
        "t$(VS",
        "X509_CINF_NEW",
        "2E2m2",
        "7aB;i",
        "N$LUJ",
        "2BX\":",
        "(?$dR",
        "{0T?i",
        "q_3xb",
        "RSkQ\\",
        "<M1uY",
        "EC_ASN1_GROUP2PKPARAMETERS",
        "uyMe!",
        "v<'*6",
        "181H1P1U1`1",
        "CTM+$",
        "(g]*1",
        "2I2O2T2_2j2",
        ")*/OPT(",
        "sOkxE",
        ",<TY=",
        "ExtractHelperFiles",
        "%TR%yF/",
        "C,Mu_",
        "RC2 part of OpenSSL 1.0.2h  3 May 2016",
        "n+9YC",
        "303;3",
        "%UP[8:",
        "\"vkP<g",
        ">8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "gQG=.",
        "g=#'K",
        "!}f.CZq;",
        "'52vD",
        "g(foX",
        "1I8fD",
        ">$>,>4>D>L>T>\\>d>l>t>|>",
        "Yjxbi",
        "%HQF*iY",
        "uJAay",
        "?m qR",
        ".TgCyy",
        "I+0NW",
        "%^x9p]e",
        "No such file or directory",
        "2$2@2\\2",
        "Upgrade vsdatant.sys driver via vsdrinst.exe",
        "$bV!G",
        "U<J-H",
        "SV.4'",
        "w=p/E|Y",
        "k0Y=-,9XtP",
        "<'DcD",
        "KZ)Sw",
        "2&2B2^2z2",
        "0 171x1",
        "N<^][Y",
        "C4FX$",
        ":&;6;[;b;",
        "tlfff",
        "212%2)2-2125292=2A0Edjd",
        "(Bz'w",
        "@z~l5]V",
        "0c;[|",
        "BWmOk",
        "4vw*I",
        "vk)_G",
        "CryptDestroyHash",
        "'Htv\\Zu",
        " FD5C",
        "_jmE7",
        "un.B<Nj",
        "0B^M!",
        "5S6|6",
        "AC\\:C(",
        "J;xe$T",
        "8C+JM",
        "jqdSo",
        "<!z{Ws(#",
        "RJp)A<",
        "?V#QXYN",
        "HYJ<E",
        "EPWD.toml.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "qBp{ &",
        "zlcomm.dll",
        "Enterprise 2015 LTSB Evaluation",
        "JHQK7",
        "!t>1a",
        "q@,`XA",
        ";SE_S",
        ">77lB",
        "kEcyP",
        ",Bs6X",
        "j2kT5\\},",
        "D$ PUW",
        ".\\crypto\\ec\\ecp_smpl.c",
        "cVc^Dd",
        "n}pg@O",
        "zab~~`",
        "'f?~O",
        "\"ceaN ",
        "xOW~Dd%",
        "Q];A}",
        "<%<A<]<y<",
        "\"@.T.",
        " Sq:0",
        "\"7 f>m",
        "~%tHi<",
        "Y2\\}c",
        "EPAM_Install",
        "dtls1_get_record",
        "CaTv)x",
        "q'qgy",
        "L$DQj",
        "4Q;~&",
        "RjX@&",
        ".'a[`U",
        "3,343<3D3L3T3d3l3t3|3",
        "[J)EiJRH",
        "I\"-9)0",
        "RM)q2",
        "x;+_Lm",
        "PMINUD",
        "NYU8i",
        "m\"#'f",
        "0N/V1",
        "a1#Zb",
        "n$kUJ",
        "y^('jL%`.",
        "2[h\"ee",
        "vy+E9\\",
        "T||?:",
        "RY{Xw/",
        "BN_rand",
        "\"{IEWW",
        "GRAPHICSTRING",
        "3|rN>",
        "NTDLL",
        "OVE(k",
        "dV22tN::",
        "2+K9x",
        "1(161F1S1b1o1",
        "{'$b:Pa5",
        ")fu5y",
        ".?AVstd_category@error_category@system@boost@@",
        "ER;5U",
        "ORdG+1bq",
        "\\%qRY",
        "/F!s+Y",
        "r#h4H",
        "s pTpT",
        "x?VW:",
        "Nhc$9/",
        "1;/#D",
        "mHON v",
        "'OF~eb0",
        "invalid tsize -:%s:- value in OACK packet",
        "1{{CVQ%",
        "+cb#{",
        "TH*S%",
        "=msWS",
        "[**SESSION START**] [PERFORMANCE]",
        "\")MU5E",
        "jnjwj",
        "VN.rD",
        "D$@WP",
        "4 5/5A5",
        "j#TW~",
        "!1`FZ$E",
        "0 020;0@0R0[0`0r0{0",
        "*~cJY",
        "IV[!^",
        "EVP_PKEY_keygen_init",
        "1'1,111R1b1j1o1z1",
        "|`gPE&M",
        "7n<#3",
        "|d>lA",
        "<>=AT",
        "[Es<&",
        "cgF5[",
        "UPGRADEKEY",
        "-^;^_^c^g^k^o^s^w^{^",
        ";,;8;@;G;N;X;c;n;y;",
        "0 0,0L0X0`0",
        "3T$43",
        "kY&_u",
        ">z@Q`",
        "!iR1f",
        "=;LU ",
        "3}yA-",
        " is sold by Check Point for the purpose of executing the specific Check Point Software supplied with it. NOTHING IN THIS STATEMENT OF LIMITED WARRANTY AFFECTS ANY STATUTORY RIGHTS OF CONSUMERS THAT CANNOT BE WAIVED OR LIMITED BY CONTRACT.}{\\rtlch\\fcs1 ",
        "WE\\#vH",
        "}qI}6.%",
        "]a1;\"'",
        "%.k^V",
        "-^Dx,q",
        "N1;&z",
        "qDnl]",
        "r{=h`'",
        "6!6&666;6@6P6U6Z6j6o6t6",
        "8doiIG",
        ":`}!]",
        "Y_5Vu",
        "v+B,O",
        "@n=Qa",
        "093M2'",
        "I_y(nxd",
        "3D$X3",
        "ecp_nistz256_windowed_mul",
        "?E?a?",
        "lcaUZ",
        "[nn.}",
        ")!)A)",
        "\\m`mgmA",
        "Anr$B",
        "amd%k",
        "=*6U]\"",
        "$9'h[",
        "found external file entry - %s",
        "-zq#6h",
        "0*0;0H0L0P0T0X0\\0",
        "a3Ux=M^",
        "authorityInfoAccess",
        "]mqn+j",
        "0;1uz",
        "=vQ~j",
        "dYpgs",
        ":z6=KU",
        "searchGuide",
        "Stoppable",
        "< <(<0<8<D<d<p<x<",
        "}wQ+>",
        "_L%J[",
        "Wkernel32.dll",
        "jj4^h",
        "%^IB4",
        "t.Gj:W",
        "ctx->buf_off + i < (int)sizeof(ctx->buf)",
        "H^uI20",
        "8|)E2<",
        "157D7c7r7",
        "0Swo<",
        "UFoiZ",
        "BbRm$a",
        "OsScv.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "qCGU1",
        "{G\"`>nd",
        "<QZHn/j3A",
        "l,'33",
        "\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 3;\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 3;\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 3;",
        "mfQs5",
        "0|U#F",
        "wTX]U",
        "al2S@&",
        ">$>,>4><>D>L>X>|>",
        "T?I\\Ih^",
        "Cv@K:K",
        "CommitAction",
        "4!4-4H4\\4p4",
        "H',jV",
        "V +V4+",
        "p[qIL?",
        "@Jo0L",
        "X509_NAME_INTERNAL",
        "9m*RP",
        "39&5 P",
        "y&[_^",
        "?invalid stoll argument",
        "FV'bp",
        "i+K6MrH",
        "1cu*%",
        "jAjjj",
        "DLT+8",
        "^lBE!",
        "6yrZS",
        "\\drivers\\omdrv.sys",
        "4$424\\4",
        "{~z$<0^",
        "3H*d9",
        "CSPName",
        "Y*J@@",
        "?\"?(?.?4?:?@?F?L?R?X?^?d?j?p?v?|?",
        "MxmMm",
        "kP/Ec",
        "tMw\"4",
        "Ln:oQ",
        "bV\\x^V ",
        "9:8\"+",
        "Z<{PH",
        "YRhL4",
        "PIvE\"",
        "270g:8",
        "JEaqz",
        "b2;AmG",
        "N/#u2",
        "1L2U2",
        "xRk5Q&",
        "]+:0j",
        "(gWD@V",
        "2a&2}%",
        "}Fxfh",
        ";JFX/f",
        ")~z_Q",
        ">%>0>8>j>u>",
        "`\"(Tj",
        "6W(W'W5V<",
        "oJ >Y",
        "8 8)8>8_8",
        "LlVBf",
        "#LT!rp^",
        "LfMmW",
        "KAk>I",
        "TO=Kyn5",
        "x/D+_",
        "G8~ R",
        "SEED-OFB",
        "|i#RA'",
        "d'E\"Kj",
        "3vNWj",
        "DjbNC",
        "terial and workmanship, and that the Product shall substantially conform to its user manual, as it exists at the date of delivery, for a period }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid3766116 ",
        "= =f=k=p=z=",
        "ftp_perform ends with SECONDARY: %d",
        "f5@]Z=",
        "21>^0<~",
        ">-???",
        ",%Zzu/",
        "t!F;t$",
        "wCP4,",
        "C-)d[",
        "A|y.d",
        "Pw<F$",
        "7Mcl}q#",
        "g without limitation, technical failure of the Product, the acts or omissions of third parties and other causes reasonably beyond the control of Check Point. Certain features of the Product may not be forward-compatible with future versions of the Product",
        "FSTENV",
        "wA?l<",
        "{.lR)",
        "J~\\cP",
        "Rl[vb",
        "Zy$w2",
        "L$ ;O,t",
        "8>:~g",
        "K0eD$",
        "LocateXStateFeature",
        "INT_DUP_EX_DATA",
        "8<9L9}9",
        "R|=C!",
        "jcsT9",
        "~2Mg{PB",
        "X||k/",
        "rHC^BL'",
        "!*M4&",
        "n! )Q",
        "|IH\"!J",
        "o}pr-",
        "*N5LJ",
        "P}#.r",
        "g8UjRk",
        "=U0U1R",
        "z9\",m?",
        "?3h7hK",
        "#42e?",
        "DLk\"+OZ",
        "iq'bT",
        "$A#I$",
        "~^e5a",
        "m9`rn",
        "7,?;^",
        "?9`x,",
        "oJ!a8",
        "05=c/O|",
        "{<Cg!",
        "%oogm",
        "bmbDc\\",
        "#piu?:",
        "(=dX,o",
        "112Q2]2b2l2",
        "CryptCATAdminReleaseCatalogContext",
        "a)Y-`O",
        "'m^(^eU",
        "CollectBootStatistics FetchBootTimes failed.",
        ";jU>(",
        "=z=JN",
        "2`f =M",
        "&a{B,",
        "D;6:8t",
        "?G?l(",
        "SJp!-qn",
        "5+uT@",
        ".8&cu",
        "=NOwS+(&.R",
        "7\\lJ9",
        "^ppPI\"Ug",
        "]ibNA5]",
        "UvRVq6",
        "CWiWZ",
        "{.M]75",
        " ERROR - unknown client type",
        "U{EYu",
        "uE64]0",
        "EC_GFP_SIMPLE_POINT_GET_AFFINE_COORDINATES_GFP",
        "=1>P>X>",
        "6z{9J",
        "RPos'",
        ";;^_-",
        "Qu MjS Q",
        "s8qW\"#",
        "61xgc",
        "X`5cf",
        "[JU1g",
        "lNj2M",
        "SSL certificate problem: %s",
        "@u%RPU",
        "?~c9$",
        "{1UiJ*K",
        "\"%svna_utils.exe\" -d -ap vna drv unload",
        "]e-l_",
        "FXfRt",
        "kA4&~",
        ",R-0|5",
        "hxqCt",
        "5$5(5`5d5h5t5x5",
        "pp{CZ",
        "zT*p#",
        "unsupported certificate purpose",
        "-%:Zj",
        "iW^WD",
        ">H<Xu",
        "OL(63E",
        "vna_install64.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "F&\\O1",
        "rv(Y=",
        "M.Lm'",
        "<.<f<",
        "~c(9L",
        "3?3s3",
        "SDL is disabled eraseing files",
        "j&F/&",
        "+D8~11",
        "N^.LTn",
        "LcX^`>",
        "6?tM?",
        "i_gyU0H",
        "Unknown option",
        "X&2>~",
        "CRolloverMgr::TruncateLog():  unable to write to to log file",
        "$~-!v8V",
        "\\f1\\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext0 \\slink21 \\slocked \\sqformat \\spriority9 \\styrsid131787 heading 7;}{\\s8\\qj \\li0\\ri0\\sb240\\sa60\\widctlpar",
        "A-<Fu",
        "&GNIKh",
        "Sealing the RDB.",
        "KlG{H",
        "->}/'",
        "6F{UEW",
        "hUjW(",
        "BM3ru",
        "p04qD",
        "jM=mI",
        "unknown pss digest",
        "oyqA,",
        "y\\',Lr'Y",
        "<p<z<",
        "SHCreateDirectoryExA",
        "4Ot\\w",
        "Q~8F=",
        "ZJLX3\"",
        "EC\"%F",
        ">SASLu%",
        "7#7(7=7g7",
        ":I,QL",
        "wPT.7AG!",
        "fCE&k8j4",
        "serviceconfig.cpp",
        "nrFZ&",
        "2@2[2y2",
        "bxI1%",
        "CE$QW",
        "mSM22N$",
        ";%<P?1",
        "CQ:ES",
        "-Zu%B",
        "cV4Fu",
        "<@6`|`",
        "sdIcZ",
        "9>9F9O9X9^9",
        "Send failed since rewinding of the data stream failed",
        "RunClientHotfix finished.",
        "4D4T4`4",
        "212A2i2",
        "sr-SP-Cyrl",
        "#s#RU_D fm",
        "=0m@Y",
        "i/\\Dmt",
        "~aT}8",
        " jrOv",
        "l\"jz}<WR*",
        "6szt8b",
        "ApS-2S",
        "rM392>",
        "5rQ*lWE",
        "F!8s)",
        "Upgrade, ISACTIONPROP1=%s.",
        "z&]Gf",
        "ssl3_output_cert_chain",
        "mK[n0_",
        "\"c)d+",
        "8,818r8",
        "@9\"].J",
        "869E9f?x?",
        " m}IC",
        "WB|!Qx",
        "= =2=L=P=W=f=y=",
        "~9x{[",
        "*DGK8'7",
        "!7w$}52",
        "l5LC!",
        "COMw^",
        "*%)ko2",
        " 0xb7",
        "< =6=",
        "<1<D<X<c<q<",
        "96C9qsU",
        "eTAR0",
        "@{_.Q",
        "='9-6d",
        "s (zP",
        "Z+*{=",
        "j8E\":",
        "d-]xd",
        "Y&|Je",
        "HLnpp",
        "rGg_X!",
        "?I?M?Q?U=Yzb",
        "yl` )",
        "InterlockedExchangeAdd",
        "3tw'A",
        "id-qcs-pkixQCSyntax-v1",
        "w*-@>",
        "y4@(l",
        "WoQX-",
        "d>ws_",
        "8qpV/",
        "DJb.G-3R",
        "<:=O=j=",
        "'>=DC",
        "455bN",
        "TrendMicro Internet Security 2004 (All SKUs)",
        "CRC32",
        "hi-IN",
        "G8^*V4",
        "rQqxg}",
        "5/C_P",
        "Q{\\~z{",
        "3SQX*kO",
        "U;-`{,",
        "9$:(:,:@:^:",
        "nF\\;u",
        "PKCS7_final",
        "pI0}Sq",
        "MaxNumFilters has reached the maximum available number, exiting",
        "failed to open view on ServiceInstall table",
        "kXJ\\o",
        "failed to open view on WixCloseApplication table",
        "L$h3L$T",
        "z8HsU*",
        "?+*C{Ji",
        "vJwh7ah.",
        ".json",
        "YJmYFU",
        "lAzAU",
        "JDuAK3$",
        "<AtX<DtT<ItP",
        "OjL>\\cP",
        "I]3n8",
        "L2(K(",
        "@ 4*<",
        "'n@2=",
        "Of!ZF",
        "1cH4`",
        "L$`_[3",
        "Q7aX&",
        "missing dsa signing cert",
        "4H4t4",
        "95P6@",
        ";-h>d",
        "D$,PUVW",
        "ole32.dll",
        "<^%`2qL",
        "nikSt",
        "jV7] ",
        "_;9t|o",
        "W?UG[",
        "|*P!U\"",
        "jAjej.",
        "'tSXM",
        "LmcqfLS",
        "5UvBX_",
        "b$_zLK",
        "gZ!O*",
        "EnableCleanup node not found",
        "t= :@",
        "YVJH-",
        "cY#p[[",
        "c?BI!",
        "0(Q-YA/",
        "Ew`\"G/",
        "m%.R%",
        "Uc:+C",
        "nz:@-",
        "D$4PQ",
        "b7aj1u",
        "=DtzZ",
        "=6>@>J>T>",
        "Failed to allocate Binary table query.",
        "lQdIJ",
        "I2D_ASN1_TIME",
        "<V<c<",
        "3w(;j",
        "W}_n?",
        " [n^X",
        "W3^bv",
        "cUXg]",
        "!WA? ",
        "3'roJ*2",
        "8g(Z#fLMb",
        "?0?8?@?H?T?t?|?",
        "d0h0l0p0t0x0|0",
        "6.>.B.J. ,PX",
        "/=^\"^",
        "g(Tcp",
        "OoD34",
        "stoull argument out of range",
        "S&tH9",
        "X&Gs;",
        "H]0Em",
        "B0PCA",
        "n0hAN",
        "c*jC-",
        "ANQNrO",
        ">,>4><>D>t>",
        "rN$n\"",
        "5L5R5`5",
        "&Y3#5",
        "INT_ENGINE_MODULE_INIT",
        "e2 ee",
        "LARGE ",
        ">(>6>K>V>.?3?M?R?l?q?",
        "D$XSUVW",
        "z`qBZ",
        "1/2T2",
        "=YxM\\T",
        "RwoEor",
        "7E9|9",
        "`+-Oj",
        "hX&y+",
        "8$9o8p",
        "H=?5:",
        "ZLProduct.Client.Repository failed",
        ";\"<N<Z<",
        "=uaZp5",
        "'r:a1",
        "logonToVsmon",
        ")e*o+<",
        "\\RF8>",
        "W5(pf",
        "SCUIAPIMode is set to false",
        "\\(e#m",
        "p)>A~",
        "fA#B`K",
        "=w=Kc",
        "Failed to delete %s. Error: %d",
        "CertGetNameStringA",
        "4'5?5s5",
        "v(<C-",
        "9M9U9`9b9q9s9}9",
        "Nr_+$",
        "' &%N",
        "PMINSW",
        "0:0V0r0",
        "3L$@3L$83L$0",
        "CodeAllocator::Allocate: failed to commit 0x%x bytes at base_4gb=0x%x",
        "__strncnt",
        "/{>qB",
        "F0dLx",
        ">Q8E2.",
        "fnn'o!f",
        "J,[?`",
        "j[qQO",
        "7B7N7f7x7",
        "GD$$+",
        "t$H3t$",
        "\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 5;\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 5;\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 5;",
        "5BdsofU4",
        "Y4AO4",
        "02nhw",
        "-dOz3",
        "kQ6_9='Q",
        "Goq}}",
        "TaIvw",
        "O+iad",
        ")smLkw3F",
        "(sO8/",
        "88a8:74n",
        ".\\crypto\\buffer\\buffer.c",
        "3-3I3c3",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11543880\\charrsid15169477 ",
        "7)z-z&{",
        "3sF\"L",
        " 0xb2",
        "2C2X2",
        ".f(2f",
        "F~bQD",
        "x_\\z1Pxq",
        "RANTIES OF ANY KIND, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.  IN NO EVENT WILL CHECK POINT BE LIABLE TO YOU OR ANY OTHER PERSON FOR DAMAGES, DIRECT OR INDIRECT, OF ANY NATURE OR EXPENSES IN",
        "| \\l^M",
        "1O@m,O",
        "\"#CP=",
        "R|*w.J",
        "%+(]m",
        "d;^oj",
        ";<;D;P;p;x;",
        "SetClientStartup:  SetClientStartup ended.",
        "xOaO1I\\",
        "4Fd)i",
        "1\\Ea,",
        "O[kzV",
        "w*_ H",
        ",+k?;n",
        "`gMCc",
        "5r6`7j7w7",
        "smj-se",
        "K+*`E",
        "e;7TP\"H8",
        "8TME>",
        "G_[4]",
        "j h8!&",
        "`B%U/",
        "Dl{6<",
        "C)C%=",
        "~:v#}e",
        "6\\sCUN,",
        "t$ US",
        "holland",
        "2SH2@",
        "mfNM+",
        "SnB;UG",
        "jujuj\"",
        "CVTTPD2PI",
        "xQ=m9",
        "<G]*2",
        "FdJ.M",
        "D$<US",
        "3\"313\\3a3v3",
        "CertGetCertificateContextProperty",
        "HuJ]#",
        "PEM part of OpenSSL 1.0.2h  3 May 2016",
        "S:T\\]",
        "Th(<g",
        "1)1@1",
        "==zGdd",
        "a`A\"xQlq",
        "[j.42",
        "ASN1_COLLATE_PRIMITIVE",
        ":*/cq",
        "<cclx",
        "cmjAYW",
        "6 7;7V7q7",
        "5<6g6m6z6",
        "`~gCzQo",
        "4#4-434E4M4w4~4",
        "QZs!}",
        "3V44pSue",
        ";/<+q",
        "mxUM?",
        "Windows Defender is not running",
        "C7#9?",
        "zZD;}",
        "zci[`",
        "YK]xtyU",
        "KQZaX",
        "3 4^4n4|4",
        "zWU[/",
        "'D@@A",
        "kTOIm",
        "0030dd4329a8060000a41b00001600000000000000000000000000d60200007468656d652f7468656d652f7468656d65312e786d6c504b01022d001400060008",
        "@&CaR",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Limited Hardware Warranty.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  Check Point\\rquote ",
        "Y?-@44",
        ";8H|p",
        "mac_secret_length <= sizeof(hmac_pad)",
        "v$0>Lk",
        "l$TQSU",
        "MkaekbN",
        "KAC$@",
        "8$8V8\\8",
        "E*44,",
        "Write callback asked for PAUSE when not supported!",
        "IE}qYP",
        "dGw*{",
        "LJe<N3G$",
        "7|'stx",
        "Z6/_f",
        "7:lsi",
        "xf+E)",
        "x%dh\"",
        "n\\mtf",
        "}5sKb|",
        "%d (unknown)",
        " ss{2-",
        "z3A>.]",
        "t}$XP",
        "<*=k=",
        "d:VVp",
        "C_~o<",
        "IV%1{",
        "iL''E",
        "?Q}Ea",
        "No error",
        "YI1/1",
        "sNcTg",
        "qA~BCI",
        "<S=a=",
        "[Ht>3",
        "ChW?+)",
        "|7~/h",
        ";/;`;k;",
        "080<0Z0m0",
        "'ilT&s6~",
        "U%l@n",
        "cy3}uV",
        "SEED-CBC",
        "B*_h&",
        "D$@St",
        " csKW",
        "<L<y<",
        "USuTZ",
        "_%$=J",
        "TV%?>",
        "uBl&@2M",
        "whh@U!",
        "%+S}t",
        "$8y2T&",
        "wTe3C}V_k",
        "data length too long",
        ")~:Es",
        "Y)*8)",
        "7/mdz",
        "$5j~k",
        "\\$Hu2",
        "@}.O7",
        "Cipher selection: %s",
        "X~pds",
        "O=Check Point Software Technologies Ltd.",
        "MR8/N%",
        "l+-mN\"",
        "jAjqj",
        "GET_SERVER_STATIC_DH_KEY",
        "<{EP$<8%",
        "O+AYNJ",
        "L4|Nb",
        "}~2_}z<L",
        ".R^]B",
        "Vh8K!",
        "only DTLS 1.2 allowed in Suite B mode",
        "-oHBA",
        "N4/Y@",
        "MpfIzkC-S",
        ")ds8g=",
        "fDP`6be",
        "@D/WU",
        "q*(CL",
        "oSPPWh",
        "1F2X2{2",
        "_]nYL4",
        "*BO+w",
        "wj[&V",
        "/a9fRC",
        "YLT3r",
        "H~QxU",
        "eS0KS",
        "jqR|j",
        "~T=,~",
        "E!JPM",
        "I$u-KQ:",
        "=L=V=`=r=}=",
        "fV]Ej8",
        "4J&?.",
        "c?Uk7vf",
        "u/j,Xf;",
        "\"tRe%",
        "%u]\\8",
        "M^03I",
        "/aiN8.",
        "F<lr]",
        "zXbFs",
        "u-v]t[p",
        "[VSINIT] VsNoFileRedirect::s_LoadFunctions: GetProcAddress('Wow64EnableWow64FsRedirection') failed with error %#x",
        "2V3g3y3",
        "jyh0^%",
        "IKo{?",
        "^IU8J",
        ";}9w =",
        "OnUpgradeAfter:  SetFWStartup",
        "MS Sans Serif",
        "P( SA",
        "Q^v)?",
        "z {2z^|Z}",
        "{RbBn",
        "ahgoH",
        "3rQK6@",
        "lH:#:",
        "'=?=g",
        "YnUCy",
        "#pRm1",
        "s:9[>",
        "t$PUS",
        "'WUQa",
        "TU,FI@",
        "Lzx,[",
        "|tva,",
        "failed to set exception description '%ls'",
        "@?xTEo",
        "7d8m8",
        "=t*f1<",
        "lePH9k <:>",
        "].Cw/",
        "7(70787<7D7X7`7h7p7t7x7",
        "ZSRgo*",
        "\\5`J3",
        "r'~iZ",
        "XL[Fq#9",
        "[d\"Mm",
        "?;;Li",
        "J^i)AgbB",
        "bCwB\\",
        "n2F?C",
        ",Bn{7",
        "xj8W3",
        "7,5_\\",
        "qt.conf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "waQE`]@",
        "{_zel3",
        "]N|a8t",
        ";&<W<",
        "l$(VW",
        "DisableThreadLibraryCalls",
        "Failed to run MsiGetProperty to retrieve INNER_MSI. Setting to NO as default.",
        " %4%u",
        ".\\crypto\\x509v3\\pcy_cache.c",
        ") Djt",
        ",iF3>",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ship the faulty }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 H}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477 ardware }{\\rtlch\\fcs1 \\af1\\afs20 ",
        ":+:I:X:",
        "})Ps>",
        "9W:}:",
        "b}\"21",
        "~|j`!",
        "pKm$lB",
        "(:xjc",
        "l+f9KQr",
        "\"3U[v",
        "/Grn2",
        "?_w~N",
        "Y~i,ie",
        "x~nuJ9~",
        "--%s--",
        "}e_H_",
        "~{k<C",
        "5 5054585@5X5h5l5|5",
        "pOs%;",
        "&pvom",
        "tZrFNF",
        "j45Dl",
        "ok<jf",
        "N9\\#r|",
        "848Z8n8y8",
        "2 3&3",
        "<=<e<",
        "V2O&S",
        "%ju=\\",
        "*B;~hM",
        "y $,!",
        "6<yM0",
        "T$D;T$x",
        "p6qM`",
        "StopABService",
        "!qGc*",
        "6?8K8",
        "NCONF_get_number_e",
        "5!5L5c6",
        "pI uq",
        "Access denied: %03d",
        "=b:OG",
        "JVBSQ",
        "?/6jb",
        "wH]NU",
        "DZ(M%",
        "DriverSetProtectionCtrlEx - DeviceIoControl(DIOC_SP_CTRL) finished. Result=%x.",
        "oqIS|>",
        ".\\ssl\\s23_lib.c",
        "D`p@(",
        "iDkom)",
        "*N$5I",
        "}O~09",
        "PZc\"b",
        "/v)qP",
        "L40$3",
        "^swj|B",
        "O)wO,BS",
        "@+: (\"",
        "GinaDLL",
        "ar-bh",
        "'[V^@\\",
        ";(;,;D;T;X;l;p;",
        "FLDENV",
        ".Y\"&gw",
        "9D$(t",
        "english-aus",
        "{hX\\<",
        "3^D{H",
        "u*42K",
        "?*3_ <",
        "o9<P`",
        "K\"DY1[g(",
        "sslv3 alert illegal parameter",
        "4d4}4",
        "1,\"Y:",
        "X509v3 Name Constraints",
        "p0M2W2\\2",
        "A9lGf",
        "W0t|-",
        "vEVhhD!",
        "X509_NAME_ENCODE",
        "P\\Fb@",
        "$%H^B",
        ">\\SvX",
        "XKJtx",
        "+F~R=",
        "Cr%BG",
        ",JKih",
        "ET%T1Y",
        " 5v]?",
        "\\$,VS3",
        "o1gKB",
        "Iwn<w",
        "/RGYF",
        "ssl_parse_serverhello_use_srtp_ext",
        "+UJz;4",
        "unsupported keylength",
        "jhjnj\"",
        "u:AXgj",
        "y'vlo",
        "B{\"(A(*z7",
        "QaE~x",
        "OHF!:",
        "eK&^L4?",
        "b!46.",
        "gopo~^k",
        "%cVZ7",
        "<&Dpd",
        "3or. 9Z",
        "6/oaJ",
        "ENGINE_LIST_ADD",
        "Pk^yC",
        "Fli\"3",
        "nXsM`",
        "*kAd9",
        "L$4SUV",
        "E0M0f1u1",
        "Ago{v3",
        "1+*C4",
        "SPYWARE",
        "szInstallErrCode",
        "v(*3^>Zk",
        ">|'j%q2",
        "71010086F13E055438AB5A54A86EA936",
        "5R49Op",
        "5I\\5|",
        "L\\Fa|",
        "4\"5+5f5",
        "[W24v ",
        " ;LcR8",
        "D$,Ph\\$#",
        "+L$ +",
        "9l:p:",
        "ikUBMO",
        "PSIGNB",
        "[q^j~m",
        ",141a1i1",
        "8Lk&h",
        "!|b{<(q",
        "]6pnT$",
        "cz&Hp",
        "_tzset",
        "m-&zO",
        "if\\uW",
        "id,~nQ",
        "P/r7A",
        "'k9j9",
        "failed to add temporary record for duplicate BladeFoundation.dll.DA5C0B1B_759E_4256_9F02_1D6C54339DBB to EPAM",
        "b1-HSsd",
        "=)}hd",
        "h>[$D+r",
        ")XqRd",
        "9+9O9g9",
        "Sy\"&d",
        "?:XVY",
        "FTP: weird server reply",
        "upYbV2",
        "D$4SPP",
        "szVswmiPath",
        "6}E-$WV",
        "7X~OY?d",
        "Gn6}uR",
        "E6|ZZI",
        "F333N",
        "}1Fes9",
        "IPj3tN*",
        "|y5-)",
        "QH[X=^",
        "ov>s76",
        "GetVersion",
        "_mock",
        "XTf6$",
        "/X/ON",
        "z4WYG",
        "Pu@Ap",
        "mBGn5",
        "`[i{$(W",
        "gR<Y&a",
        "@R`I`a",
        "FAILED_TO_CREATE_KEY",
        "u_9=Xxe",
        "TDUgB&V",
        ")Fd\\\"g",
        "vibZ*",
        "l#2p+",
        "AntiMalwareAPI.dll.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "/Oj1U",
        "2j384Q5J6W8",
        "XP7&\"3",
        "VC}0MT(",
        "^8=;M*'GV",
        "5F2WA",
        "b h ;",
        "So7l|",
        "Gn$QD",
        "S;0*sVP",
        "6n'<\\",
        "sZHU}",
        "TuP1y",
        "w'bln@",
        "P3%Q@R",
        "8`cMM",
        "ug3fU",
        ".6riPA_",
        "u\\a#rN",
        "IKC7\\",
        "%E)\\1{SI{",
        "Zl#F8",
        "'s'&O,O3O9O",
        "L%ar`",
        "pl,cl?",
        "StartInstHelper started",
        "h[^M!l7",
        "NETWORK_PROTECTION",
        "2f4v4",
        "`F#|z",
        "TS_CONF_set_default_engine",
        "CRaWT}",
        "7 717F7K7",
        "WaitForMultipleObjectsEx",
        "N.#10",
        "m(@O1",
        "0&5^@",
        "e]FK[",
        "VU6Pi",
        "G{~^p",
        "pN;M'G5",
        "W-^?)",
        "GetTimeFormatA",
        "ssl3_generate_master_secret",
        "- not enough space for lowio initialization",
        "@V Qf",
        "0!010A0a0q0",
        "VaW7Y",
        "1:15g",
        "819M9V9p9z9",
        ".rdata$r",
        "fh=*]",
        "FeO/\"",
        "SH.w#",
        "vs;oN",
        "\\\\.\\ZLTcp",
        "\\m1Pv",
        "H_Tl[",
        "T{f0f6A",
        "cprg/",
        "Z@AFy\\",
        "WSACloseEvent failed (%d)",
        ",|HJ+",
        "Z\"YjM",
        "VGuP9",
        "unknown mask digest",
        ":%v%d%j",
        "k `x<",
        "xuW+t",
        "889>9M9S9\\9b9s9y9",
        "o^n+vE",
        "2z4z6",
        "KT*B_",
        "$F&`4",
        "3 3$30383<3H3P3T3`3h3l3x3",
        "<7<Q<",
        "'9\"a'",
        "]<LygU@",
        "eukUh",
        "[%s] %s=%s",
        "]_^]3",
        "#b*/-",
        "MASKMOVDQU",
        "y\"b`L",
        "xT4g&",
        "\\AM1.Signatures\\KAVMinSignatures.exe",
        "1(141T1\\1d1p1x1",
        "X&O(!",
        "fv5*jo",
        "ASN1_GENERALIZEDTIME_adj",
        "?e1*(",
        "X509_EXTENSION_create_by_OBJ",
        ")^[x\\",
        "|{\\vB",
        "y?;H%",
        "D$ hTY#",
        "Y03.\\",
        "h\\Gzy",
        "psL)(",
        "cannot switch from automatic to manual argument indexing",
        "R!9mu",
        "e{Byt",
        "J(J8JLJdJ",
        "m36!x",
        "tLw@cF",
        "B$LBO",
        "vsconfig.xml",
        "aB0V@",
        "cms_CompressedData_init_bio",
        "e)QrM\"",
        "*72C4zk",
        "zpTB'Bm6",
        "D\\<#q",
        "@$B'8",
        "0#0?0[0w0",
        "t$(UU",
        ";3tDV",
        "G4{So",
        ":0;~<",
        "=M5AV",
        "fo ;Fq5",
        "ssl_get_prev_session",
        "b.~T{v",
        "t$ PV",
        "II{%,6;f",
        "t6==h",
        "x!Hi:w",
        "HpApb",
        "lJe7X+",
        "9qk!\\",
        "0sro{n",
        "U%UPE1C^",
        "\"sD9xk",
        "9#:v:",
        "N`;O`t_",
        "ypYX4",
        "InstallProduct: InstallProduct finished.",
        "T$Y4,J",
        "AO=~h",
        ".\\crypto\\x509\\by_file.c",
        "#2`J8",
        "G8,2o1",
        "4'40454;4k4",
        "Content-Type: multipart/form-data",
        "?1_HzE",
        "aiI\"DE",
        "U`j_y",
        "Hdc8i",
        "March",
        "f~1[49",
        ")cpIhK",
        "rBMJg",
        "dY{vb",
        "BB&k[z",
        "4DK7C",
        "FAILED_URLF_SHUTDOWN",
        ":.:Z:{:",
        "5;?R$u",
        " subjectAltName: host \"%s\" matched cert's IP address!",
        "t.tNtnt",
        "dynamic_path",
        ")!>V0",
        "\\,r&+u9",
        "*'tfs",
        "I!<-e%L",
        "djxlN",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 of these programs may be in violation with other license agreements that You have knowingly or unknowingly agreed to. The deletion }{\\rtlch\\fcs1 \\af1 ",
        "cns<<6",
        "_{Jz=",
        "decoding error",
        "020E0P0U?",
        "'wwrr''wI",
        "U6Q#v~",
        "R7P=\"",
        "X*<Lt",
        "Q<[u)",
        "FWRemoveBefore:  Failed to unregister SecureAccessDSM.dll.",
        "g[x(M",
        "TJzh5(",
        "fOcx\\n",
        "Ey@z;b",
        "Z#t#~",
        "BkbDu",
        "sK:j%",
        "mA;>J",
        "1$101<1H1T1`1l1x1",
        "lRAaA=#r",
        "m4RETgFVfpCV",
        "Failed sending DICT request",
        "wBix:",
        "J(J4J@JLJdJtJ",
        "z)V1}",
        "9OZW}",
        "L$L]_",
        "yhHiy/)",
        "StopServices",
        "6ED9`",
        "<a|;<f",
        "I+I018",
        "no memory",
        "TFTP: Access Violation",
        "pWseRegisterPlugin doesn't exist.",
        "OwIGs$",
        "5h;rP",
        "\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 2;\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 2;\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 2;",
        "]LE'GME",
        "tXT<6",
        "F.3mD",
        "X>jM3",
        "9q$xm",
        "invalid object encoding",
        "<~FMX`SR",
        "setct-CapRevResData",
        ", GRV",
        "?]-/D",
        "6%db#",
        "*j3Al",
        "+=,$e",
        "NwhU%",
        "Uat`y",
        ">\"?b?",
        "s#Wx@f",
        "<&xM/",
        "868H8e8",
        "boost::filesystem::copy",
        "Nal,r?",
        "Zq2UJ{",
        "SG%[w",
        "}i%.4\\",
        "CaDXH",
        "tKhp9L",
        "B6Jy$",
        "T~ta2",
        "y} S ",
        "787<7H7L7P7l7p7|7",
        "BN_mod_inverse",
        "; kM8",
        "Aox5Y",
        "[%05d %s]",
        "]tLmxx",
        "Gg{yPc",
        "??o?F",
        "kv~:\")]",
        "m(1FU",
        "U9`nW",
        "DfL=T",
        "paHYZ",
        "xc;5X",
        "hash  {}",
        ",iy,$",
        "B*KUP",
        "`6.Pd",
        "PARENTCPDA property is not set. It's a manual or 3rd party tool update. CPDA should already be stopped...",
        "8,]m^",
        "Failed to allocate wildcard path to ca scripts.",
        "bad rsa encrypt",
        "T$ SV",
        ")5rV|",
        "3[9~{",
        "UmH\"2",
        "L$(+L$",
        "mX),)L)l6",
        "AVQO7",
        ";7,s|",
        "atlTraceAllocation",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{00F822AD-0798-4F54-BA6B-440D0BD687D7}",
        "r:   ",
        "P9\\9b{",
        "g<JO-",
        "8,8<8H8P8h8",
        "Rr=KpS",
        "QQ5tx",
        "h#Iy,wh",
        "9uR!#",
        "z*O?=vu",
        "Y{zez",
        "9 9@9H9T9t9",
        "</destination>",
        "\\XbP7",
        "Cn`N`",
        "SNCNK",
        "3=B07W",
        "fileutil.cpp",
        "q|X2hD",
        "{for ",
        "XYZ[\\]^_`abc",
        ";#<U=",
        "9(JL-",
        "56@B!a",
        "+fz1:_l",
        "yk#k|",
        "(FOl]",
        "Y\"!L~",
        "cleanup method function failed",
        "t#gWLb",
        "J&6v-H",
        "e?{Qp",
        ".qO0/",
        "nRUCm",
        ".\\crypto\\objects\\obj_xref.c",
        "8(8D8`8|8",
        "xn~c-8b",
        "[VSDATA LOAD] %s %s into %s",
        "qIq53",
        "]/O`0",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 You.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12735761\\charrsid15169477 ",
        "(& E./",
        "hN;6.0",
        "mA* km)",
        "asn1 unknown field",
        "Djt/4",
        "HE F5",
        ",4T!Z",
        " izkR@",
        "<UpdatePackages>",
        "^LT@XI",
        "$\\`sL",
        "6n]4z",
        "SetConsoleMode",
        "EG(]8",
        "X<[]_^",
        "BladeFoundation.dll.DA5C0B1B_759E_4256_9F02_1D6C54339DBB",
        "@%.L15",
        "xg-A\\^",
        "HE/7=0",
        "J`2lW",
        ";]J#o",
        "]OV4Z",
        "6H6y6",
        "9H9Z9o9",
        "uL)EL%",
        ")sA;1",
        "XtqBa",
        "1olk/Z",
        "DIR_CTRL",
        "=l.#|W",
        "<MMMMMM",
        ";]!oC",
        "O_|+]",
        "'g=XR",
        "Q3*$#Z",
        "@!ME`",
        "YsZNx",
        "=$=,=8=X=`=h=p=|=",
        "%#1nh",
        "W5wA}R",
        "ITU-T",
        "ADDSD",
        "Ver`.",
        "E-csGK",
        "\\zonelabs\\streamapi",
        "failed to get firewall exception protocol",
        "<8-4?",
        "bmzHg{{{",
        "TS lib",
        "+,^l@",
        "CPDAStopRemove.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "Check Point Endpoint Security VPN",
        "A8>#Zl",
        "?;?c?",
        "time not ascii format",
        ",8,h-",
        "the{%",
        "got option=(%s) value=(%s)",
        "iK#'w^$",
        "9Xh#ga",
        "jbf8t",
        "L~To1y?",
        "='=v=",
        ".K&:]",
        "ConfigureClient:  Copying configuration file.",
        "9 9,969:9D9N9R9\\9h9t9",
        "X!;3; ",
        "NJr:`",
        "zwk+?t",
        "3.3J3f3",
        "Ac6PWH",
        "EUxI9",
        ";g0n7I",
        "n/9mI\\",
        "`)8u<",
        "<6[\\MM+",
        "<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>",
        "Dgd=b",
        "^*^2sn",
        "Wj|h\\",
        "<%<t<",
        "recipientInfos",
        "3*5T5",
        "M$M,M4M<MDMLMTM\\MdMlMtM|H",
        "PROCESS_PCI_VALUE",
        "J(J4JDJTJ`JpJ",
        ":!Pk}",
        "@ZC]o",
        "/S=*>Q1",
        "Cpn]b",
        "nUX$2",
        ";=;D;K;",
        "AUTH=",
        "CRolloverMgr::TruncateLog():  dwFileSize < m_RolloverData.m_dwFilePos",
        "[79O ",
        "E~Gq! ",
        "36~#r",
        "1>z6O",
        "?\\WE~",
        "Ghfwf",
        "0!G}k",
        "o*y\"xC{",
        "-%Dnw",
        "O9$ 2",
        "%;X!$|",
        "3L$,!",
        "Unreg request was generated",
        "N1{e\"",
        "welcome.png",
        "B(I~5e",
        "cB6D%",
        "1.1K1e1",
        "u+5(+",
        "jgjlj#",
        ">mPibyf\"",
        "*VKHO",
        "Z0d0q0{0",
        "failed to clear text value",
        "lEF 2",
        "*k$CJ",
        "EetE(",
        "EPDRIVERSVERSION",
        "Failed to receive SOCKS5 connect request ack.",
        "XOPQd",
        "format specifier requires numeric argument",
        "6<6H6h6t6",
        "[>bKe",
        "\\rsid12926876\\rsid12982799\\rsid12985423\\rsid13050417\\rsid13057840\\rsid13065977\\rsid13173947\\rsid13193413\\rsid13200219\\rsid13240566\\rsid13256927\\rsid13260676\\rsid13309272\\rsid13532976\\rsid13701052\\rsid13774068\\rsid13775897\\rsid13779108\\rsid13844772",
        "@m~zl",
        "du^3ck",
        "~7SUU",
        "Y'17R",
        "\\f1\\fs20\\insrsid8205679 re available for customers }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9068002 who }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607 have purchased }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 ",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\remove.cpp",
        ";(=W=",
        "m{*R!",
        "Wy#}/",
        "nOvrQ7N",
        "213>3m3y3",
        "T!VP0",
        "api_ms_win_crt_runtime_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "B.y#A",
        "B<s9-%",
        "TLFNQ",
        "]4]DV",
        "8*V#q",
        "`oGE{",
        "Pf&`)",
        "x5~iN",
        "6eYDZ",
        "6[$G9",
        "6 6$6@6D6@>D>H>L>x?|?",
        "jCVSO",
        "ljSHh",
        "\"`e=W",
        "failed to fetch single record from view",
        "U.Tky=",
        "%R:<$,",
        "VPkVW|",
        "0+020P0V0\\0{0",
        "3l6w6",
        "LkqVM`9-",
        "v1CUI",
        "$9;G ",
        "j#Psp",
        "CCT8n",
        "FW_BeforeUninstall",
        "/o?3(h",
        "l/)y8",
        "j5O!C",
        "/l>]T^",
        "1pcr/",
        "|}|>G<",
        "Ar+Ng",
        "KmI)p",
        "x>;w}",
        "{}6!0",
        "ZY&`l",
        "-IY|{",
        "Y~3JO",
        "vAKUBV",
        "N',S~xc",
        "}'a9F",
        "[oJ|M",
        "(VXZ_",
        "'4whZ",
        "USER %s",
        "integrity",
        "b3,Bb",
        "%]b\\O",
        "Set value of Process ID = %d in shared memory.",
        "CMS_CompressedData",
        "A,{F1",
        "7<8K8",
        "Zr&X[+KQ",
        "XHf)E",
        "ZiLe+X%",
        "3dy:p;",
        "8jLIS",
        "g-#6x",
        "s$Yy=",
        "9g=LF",
        ";wSk3{l",
        ";8;E;",
        "F@@3!",
        "ADDSUBPD",
        "zu-za",
        "bV]LK",
        "Zl_ K",
        "8[9t9",
        "CreateXMLDOMInstance failed",
        "'.'=U",
        "d! 8x_",
        "ase04+",
        ";l$,}L",
        "^mf?y",
        "Hs^1+*",
        "fPh@w",
        "Cdd j~`",
        "#Y]x4o",
        "permittedSubtrees",
        "0P3wT",
        "jcb[O",
        "yIr:R",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3297348 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477   ",
        "a(>@*",
        "/2OS\\",
        "qtc_i",
        "J{@`3",
        "];!ZX",
        "K\\wC?",
        "[hX=w",
        ".?AVLoggedRegKey@@",
        "_*%Rn",
        "kn-in",
        "o2E\"\\",
        "0^B&#",
        "hXmXJ",
        "\\UXp]",
        "LZm<9(",
        "%s:%hu",
        "YTB)i<",
        "\\nb\"O+",
        "xd9i0",
        "first num too large",
        "trMRG\"_*",
        "#{:9\"u",
        "jyjqj ",
        "c'')z",
        "9V(~?j",
        "FirewallMonitor.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "8risN",
        "XMM13",
        "A_fL$$",
        "QH[]w",
        "._-N[?",
        "ASN1_UNIVERSALSTRING",
        "raTdR",
        "Q|PA`",
        "unable to find dh parameters",
        "tfQUPj",
        "7{n&8{n.9{n6:=o",
        "W:Qo?",
        "{\\*\\xmlclose}, {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Syria{\\*\\xmlclose}, }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\insrsid131787\\charrsid15169477 {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Lebanon{\\*\\xmlclose} }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "~z:Su",
        "rhK2b",
        "!:D+T1?",
        "ChvP#8",
        "4F@z9",
        "818Q8",
        "WxEA]",
        "t<a@.",
        "1W!A6",
        "t,0x#K",
        "snXkn",
        "%15[^",
        "MP(q#",
        "cptrayLogic.exe",
        "|22ZZ",
        "M=Ld8",
        "iK5 k",
        "D$4Pj0",
        "gAXiGw",
        "R?+n/_aB6",
        "[pPx-",
        "\\efg~",
        "E~$yW",
        "HSb.R",
        "Delete old local catalog:",
        ";~j_4",
        "889{9",
        "EPAM_InstallRollback",
        "uH/bj",
        "K~|91",
        "=nL]q",
        "Sh`@%",
        "M:K~N",
        "sN59{",
        "SOFTWARE\\CheckPoint\\SecuRemote\\5.0",
        "]W)}/m",
        "e{x[A",
        "n YOUB",
        "uR<BT",
        "{v|!4",
        "L;;V|",
        "des-cdmf",
        "SXNET_get_id_asc",
        "#jU%J",
        "N<^[]",
        "optionalSignature",
        "iv!\"E",
        "Yw1_7E",
        "Q@Wh]n",
        "`x3yS5k",
        "W7{2/",
        "ssl3_send_server_key_exchange",
        "))2&7",
        "!@u\";",
        "gq1b5",
        "oS~5b&|",
        "oRxf ",
        " 0x4c",
        "^cd8td",
        "=(=4=T=\\=d=l=x=",
        "rb7aeq",
        "\\g@5q",
        " !\"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~",
        "U 31NP",
        "@dC6G",
        "?@?L?T?l?x?",
        "J4Z;DHa8i",
        ") =@NO ",
        "5N1j}",
        "x\"5L3",
        "Q|||M",
        ":V;^;",
        "MpClient.dll is absent",
        ";1#.0",
        "t!jHhx",
        "\\\\8X>",
        "P@S.Dz",
        "85D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        "-H]pC",
        "%MW`D",
        "OTkWQX",
        "<V^5W",
        "_KPeA",
        "kKo7GV",
        "$;wE_Q",
        "s]MF$",
        "hf~FHz",
        ".5yK]#",
        ";6=Q=}=",
        ",s\\A&6",
        "D$4_^]",
        "WtBv6",
        "j4F>(",
        "232N2",
        "Jy}KI",
        "DZ}g\\",
        "2$UZb+uj",
        "rsa_mgf1_md",
        "xO[vc?/o",
        "Php#!",
        "k8@5kP",
        "`Oh(r",
        "o*qq[",
        "{|bI4",
        "VhHD!",
        "qt4~=",
        "dV_pG",
        "\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 2;\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 2;\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 2;",
        "e\\]m8&",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\instutil.cpp",
        ":;w0tBj",
        "}J:_+",
        "758j8",
        "OGncK",
        "2-i,p",
        "failed to process target from CustomActionData",
        "t$4;T$l",
        "G->E`%",
        ":b:)4Bf",
        "mPF$D",
        "****************************** LoadGUI ended **********************************",
        "a2Nkd",
        "VJm2E;",
        ";L<P<X<\\<`<d<h<l<",
        "X%\"bqc[G%A",
        "ygAX}",
        "iMhE\"x",
        "XB,\"1",
        "9l:};$</=",
        "C,q~`",
        "MsiProperty %s = %s ",
        "J}9MWQ",
        "1D3H3L3P3T3X3\\3`3",
        "6^L=`",
        "yJC,*x",
        ": w`t",
        " G>N,",
        "9jvhh",
        "x9c=O7S",
        "fExG~",
        "jAj|j",
        "6^7x7",
        "jjCq[",
        "PSK-AES256-CBC-SHA",
        "TRX`.BM",
        "Windows Installer XML Toolset",
        "Response Single Extensions",
        "UZM9n",
        ",YM75>",
        "FINCSTP",
        "^jPQa!",
        ".\\crypto\\srp\\srp_lib.c",
        "7v;[9'",
        "Y%j]>S",
        "xn&5G",
        "@$4{-0",
        ")aZ9-~",
        "Logging on to vsmon to do configuration tasks",
        "/?))~",
        "r-f;u",
        "hgUTX",
        "ck:pO",
        "}ujiW",
        "J\"DXI",
        "i&RyS",
        "SV:[,\"",
        "JX#mVJ",
        "rWQ Y",
        "3;#6!",
        "_7R]x",
        "b@*7f",
        "R6008",
        "3(3F3M3T3r3",
        ",'9{a",
        "%0W0k0w0",
        "PTEST",
        "EPAM_DATA_PATH",
        "failed to set modified time of file : %ls",
        "Wx+QB",
        "bz+5=",
        "^s2./",
        "#020I0N0V0^0e0j0o0w0}0",
        "(DigiCert SHA2 Assured ID Timestamping CA",
        "4Y_gM^a",
        "wsNR(",
        "x$'\\i",
        "ct. If your Licensed-server is disabled for any reason, Check Point may, at its sole discretion, issue You another License Key which will enable You to operate this Product on a substitute Licensed-server. In this event, You agree not to use the Product o",
        "i>H1J",
        "\"/.XL",
        "Ij/Zj\\Y",
        ".?AUctype_base@std@@",
        "O/>] ",
        "class ",
        "*n`NM",
        "n;pyH",
        "V4e.E",
        "^Ar\"L",
        "tua6G",
        "xG/`us",
        "^@soa",
        "5>TPk\\",
        "9Mg~F",
        "EnterpriseChecks_OK.bmp",
        " n9UF",
        "-$@b7",
        "$V2bC9",
        "N^;#*",
        "entityUInfo",
        "r<LE-t@",
        "pU\"Hp",
        "DKsue",
        "9d0F|N3$;",
        "LDI33]",
        ")_Zz2S",
        "Module32First",
        "Bhz[!",
        "N<5[7^",
        "4(4H4P4X4`4l4",
        "t@oB7_",
        "Vh\\bL",
        "xE;5X",
        "|$$3L$X",
        "0Q0W0j0r0{0",
        "?<~9Y",
        "4m5w5",
        "N_oM6.&",
        "deQ\\)",
        "xuZ}k",
        "[[gS%",
        "Up5FK",
        "{m]Ou",
        "ddldd",
        "Dq=lA",
        ";);?;\\;l;",
        "JTrPI",
        "h$_o^H",
        "<yJ+l",
        "(\"o%y$",
        "vQ!$?",
        "409MLX",
        "`F21DJW",
        "u#johl",
        "Error getting a registry value:  ",
        "<8<@<L<l<t<",
        "x+.aW",
        "uity share capital or of more than fifty percent (50%) of the voting rights.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2703887 ",
        "G2JB<",
        "iulJV",
        "ntlMXGbk",
        "DslGR;w",
        "[yD;`",
        "nDLEOG",
        "&sgVR",
        "@PYj.",
        "}f8 . ",
        "lp'B1",
        "`\",<~F8@<",
        "3A5W5",
        "X|l}V",
        "5N$0f",
        "]swK>*T",
        "t~=\"df",
        "Q5A[w",
        "M!?#t>>",
        "{d`t]",
        "c{NC:",
        "N%Z$'.",
        "6'E8fe",
        "ON\"$>",
        "type: ",
        "JnH3g",
        "3c*{\\",
        "Y#%13",
        "yng#c",
        ";);4;?;J;U;`;h;o;v;};",
        "K8ksm",
        "i#*Mx",
        "[Tvc(",
        "]3K`%",
        "0\"x[/",
        "^KDLz0-",
        "5$5D5P5p5x5",
        "4 4&4,42484>4D4J4P4V4\\4b4h4n4t4z4",
        "%2d/%2d/%4d %1d:%2d:%2d",
        "n5)*&",
        "'PV43",
        "&''Ni",
        "Qm5:Ms",
        ".I7?V",
        "?>l{a",
        " $mN7p?(P",
        "zd;H%",
        "0 0,0L0X0x0",
        "ByKi`",
        ":[h]n",
        "EvVO4",
        "\\ZoneAlarm.xml",
        "n>65f",
        "sv9z9hw",
        "g^.5Ze>J",
        "DLFCN_MERGER",
        "634d1",
        ";+;1;",
        "-J8d2",
        "0s1~1",
        "S*8.U",
        "NcZr^J",
        "zY050",
        "u[9=P>",
        "m+mkm",
        "E|!pr",
        " )-!5",
        "&AYBX|dqP",
        "Z!#aR",
        "6{nb6",
        "F]d74J",
        ":EgM}d=",
        ":w\"W=",
        "*I4% T/",
        "4At+b",
        "swoWyH",
        "=oAQ[",
        "X9.62 curve over a 163 bit binary field",
        "8B8o8",
        "FLT_INVALID_OPERATION",
        "7d|&e",
        ".ZyF.2p",
        "pNuU=#",
        "QrE<B=N<",
        "v<^2N",
        "Z&Nn\\",
        "<8]h'*",
        "X/:{s",
        "gS^Kk",
        "}bqws",
        "Zol-J%",
        ";$uXW",
        "<0=7=",
        "X\")O3(",
        "dJyOl,",
        "O.L1r",
        "volatile",
        "N2%Q3_T",
        "52z1>3",
        "!&t3jV",
        "CLSID",
        "0N;X_e#",
        "9/:?:d:",
        "6`7l7",
        "9d\"Of\\6",
        ")t&ZX1,",
        "@x\"BP",
        "g95/uW",
        ";$;>;O;f;o;",
        "F3&cc",
        ">OPHK",
        "&^Ja+",
        "MiM\"-",
        "~:&Sw",
        "\"2_;!",
        "2*3H3c3",
        "'.P0W",
        "4Hhro&",
        "_*$aiU",
        "jpW|+I",
        "oeZ%q",
        "lS:rrf",
        "t$DPh",
        "2?3N3U3e3}3",
        "CNU`~",
        "PY 6AOf",
        "k,4(L",
        "s->init_num == (int)s->d1->w_msg_hdr.msg_len + DTLS1_HM_HEADER_LENGTH",
        "=J)4x1",
        "7U]{hZz",
        "}c7h5",
        "kn-IN",
        "1)?wo",
        "\\zkmi",
        "\"01qR5",
        "5r.3-",
        "1cSK~vJ",
        "SEC_E_TARGET_UNKNOWN",
        "?^Y*I",
        "Bm|P[",
        "[EXCEPTION SUPPORT] FileOldestFile: FindFirstFile(%s): Error %d",
        "$hgR/Smi",
        "minsize=",
        "Mpu*/",
        "__crt_strtox::floating_point_value::as_float",
        "8F9U9&:3:",
        "Reboot is required to stop a broken vsdatant driver",
        "V q'+",
        "connection refused",
        "&<FrB",
        "/_N!w`",
        "?cQof.",
        "?I^q+",
        "oidR9m",
        "!nsZ3",
        "qwBvTh",
        "gTBvfK",
        "9fUoS",
        "SetFilePointerEx",
        "]b(V+",
        "@s^yH",
        "n:;;VR",
        "N,~Qu*",
        "U\\N0o",
        "5T3&4",
        "K:2ML",
        "LrM\"T",
        ";.o}zk",
        "|WZc<a",
        "9|$l~`f",
        "%%%T_",
        "fHV3x",
        "#=E4efUdFu",
        "}0-db",
        "OQx8Q",
        "8Z4axp",
        "+?Iqx",
        "<I{F3",
        "registerPlugin",
        "aes-192-ofb",
        "+5OK9",
        "~\"!)e",
        "\\!\\QZ",
        "P1%)DW",
        "747<7L7T7\\7d7l7t7|7",
        "--KWUI",
        "1(1K1n1>2",
        "R{.Se",
        ">8Pn4",
        "o3BC6+",
        "64j\"A",
        "zxYn1",
        "{\\flominor\\f31552\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}{\\flominor\\f31553\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}{\\flominor\\f31554\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}",
        ",806Pn",
        ")<+3b",
        "EZAMb",
        ":G;Z;",
        "u(Ne2[,",
        "gYQj^",
        "n7y/.r",
        "r\\O#k",
        "L0P, d",
        "2W1{L1+",
        "+r9,QY",
        "U^0?'3",
        "PQk4]",
        ".S\"$?|eH",
        ".?AVExecutionResource@details@Concurrency@@",
        "7B8V8l8t8{8",
        "0;1b1",
        "ydc';gN;-",
        "8T8^8{8",
        "`mPQ1",
        "Bs!e.",
        "CheckCurrentUser finished.",
        "o_ep-",
        "vNlA`1vM",
        "2!VDQ",
        "ASN1_item_sign",
        "2^3d3",
        "DisconnectedPolicy.xml",
        "q<fG>",
        "sXf,?",
        "T?\"UG,",
        "*W;dO",
        "NIST/SECG curve over a 521 bit prime field",
        "5O6w6",
        "~*$&u'",
        "&NN1h [",
        "0e041+2",
        "fkbu~V",
        "a\\Jbh",
        "z-Pv7",
        "2+2G2c2",
        "44-IM",
        "3\\$(1",
        "rerDx",
        "OSy%q",
        "NZ\\Ej_",
        "6}eiy>",
        "End of output of the command: %s",
        "O]=:z",
        "d*D)P",
        ". ,\\Yh",
        "jWhDB%",
        "*U\\uK",
        "89^Ht\\j",
        "=D>N>T>^>n>",
        "x5 Co",
        "?JCU}:",
        "808;8H8\\8p8",
        "1>1v1",
        "gOD6c",
        "9OyQR",
        "+C@uU",
        ";`-X^",
        "a@wXA",
        "495C5`5q5",
        "3P3b3h3{3",
        "_%8sa",
        ".\\ssl\\s3_srvr.c",
        "POST ",
        "T[)b>U",
        "IZ%iS",
        "BB$*y",
        "n}rh>|",
        "0&070T0",
        "be@kN",
        "\"o}2@-rS",
        "559c9",
        "!$S!Pe",
        "+=$<\"",
        ")8)X)x)",
        "_jbF~T",
        "r#x`i",
        "eg-=~",
        "(r*N#",
        "of these programs and the potential violation of a third party license is Your responsibility.  Check Point has no ability to verify what, if any, third party agreements You may have agreed to.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "NHZT^Z^",
        "\"kZ h",
        "Cml c",
        "/)%Yo",
        "FLDPI",
        "C6Ip$!HO",
        "B!,~l",
        ",h<g)o",
        "(/ChLn",
        "5ye_D",
        "YQ:'&",
        "=%=6=G=_=i=",
        "ig/2-",
        "-LSYH",
        "SEo'f",
        "B$~if",
        "2GpUE",
        "|/F?/",
        "; <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\\<`<p<t<x<|<",
        "C/%j|",
        "B<D|u",
        "((93>",
        "VeriSign, Inc.1",
        "TpuQikJn",
        "SEC_E_TIME_SKEW",
        "!#=5:",
        "SDL is enabled eraseing CPEPC_PLAP and marking epcginashim to be delete after reboot",
        "?6o;.",
        "'J~>L",
        "D/&\"]",
        "hC]Lh",
        "Q|qi~",
        "Gq} ;",
        "8CMey",
        "jQf_V>m",
        "?2qB:",
        "QHQ (",
        "z,&Sf",
        "Q78nv<",
        "unable to get local issuer certificate",
        "242<2G2S2_2c2i2m2s2w2",
        "v>5UN",
        "vj_t\\",
        "?Zgv:",
        "JERyi",
        "PhlX!",
        "|S`agT",
        "3(30343H3L3`3d3x3|3",
        "<8u)<H",
        ";.;5<z<",
        "6e*:Dva)",
        "ml-in",
        "HvCB3",
        "W*KTMOi",
        "mZ<.q",
        "wFGHIJKLMCNCD",
        "L4p6\"",
        "mF#fn",
        "]Bl|ylJ",
        "6';F2",
        "CAMELLIA-256-CBC",
        "K[S[\\[",
        "q|?U5",
        "U|5k0S",
        "N\"dX5",
        "_oe+j",
        "|m$66",
        "IpM(&O",
        "TYPE %c",
        "[ShX!",
        "Failed to set SO_KEEPALIVE on fd %d",
        "y=Ve?%T",
        "/G91}",
        "'Bl|T",
        "RSA-SHA1-2",
        "%s executed successfully",
        "C{5~,",
        "2&3+303:3k3r3z3",
        "M]%)it",
        "!s4?)",
        "dRP]Q",
        ";]).;",
        "70Q0l0g1",
        "%'&b_",
        "LSJ!n",
        "LWQw4?-",
        ":BW/E",
        "OLDINSTALLDIR.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "*G_rR",
        "m^b^mV",
        ":N:W:i:p:",
        "OZckg",
        "b!I/h",
        "id-smime-aa-securityLabel",
        "t:1ur",
        "67R%ONZ",
        "Internal state machine error",
        "o+oko",
        "<C=u=",
        "\"lzE^",
        "c(4kv",
        "Z)g4A",
        "C1V1|1",
        "JeBWhO",
        "-NfjXk",
        "ADDDS",
        "NCONF_dump_bio",
        "logs.png",
        "f6DE]1",
        "BKL@w",
        "5Iw@W",
        "QOl0n",
        "+p!@7",
        "S}G<%",
        "kVA?'j-",
        "8U t\"",
        "6+6G6c6",
        "+^gS*",
        "P&'Rp",
        "oR|d$",
        "2;99j",
        "SWz#J4",
        "d\"8E\\",
        "+baVI",
        "/KH@ ",
        "Q%Mw8G6)",
        "5c6x6",
        "+@nzHl",
        "dd #.[",
        "bs-ba-latn",
        "BIO_get_accept_socket",
        "ExceptionCode",
        "6cs)I",
        "VF\\Gp",
        ":,:L:T:\\:d:l:t:|:",
        "FLT_STACK_CHECK",
        "=~xK|",
        "tGvH)",
        "9s(~&",
        "[pEr?6",
        "T6kn`",
        "nx[{-ilR",
        "Ke{c +u%",
        "9ae4d$",
        "GEg[<B@8",
        "jM w!:",
        "CreateHardLinkW",
        "oC74`r",
        "h5bG?!",
        "Id1KRy",
        "wl'\"2",
        "B@]4B",
        "5E5V5e5|5",
        "565F5",
        "VnM8D",
        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/",
        "Any purchase of upgrades shall be subject to this Agreement, unless otherwise indicated by Check Point.",
        "L$ SQ",
        "}Ie6q7",
        "535L5e5~5",
        "k,8wP",
        "]'FX5",
        "U#rL ",
        "\\m7a.Q;",
        "8$;`]s",
        "4gVjj2'",
        "bN.q@(",
        "0}}n[",
        "module initialization error",
        "`t#[_^3",
        "1(c) 2006 VeriSign, Inc. - For authorized use only1E0C",
        "2.2J2f2",
        "#y3ewr2o",
        "!)r>sSt",
        "5/656:6U6q6",
        "}WSDt",
        "'zjk.M",
        "a3i-V",
        "AHqfC",
        "Nxf+)",
        "lm5D*",
        "$:3]F",
        "3'353F3U3a3n3",
        "=Nonf",
        "D$$jPP",
        "7g899",
        "Failed to delete EndPoint Security reg key, Error: %d",
        "~huVD",
        "secp160k1",
        "jQxqMc",
        "%p073G",
        "9!:O:",
        "integer not ascii format",
        "\\5IaNV",
        "yWI]5(",
        "334d4",
        "+Xy_}u{",
        "Uf0C2",
        "NCONF_load_fp",
        "%5I64d",
        "@C)bE",
        "y,*<e",
        "Ph m#",
        "9_PDe\"$",
        "/=jN`f",
        "5 P|Z",
        "t5rk+",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\ScvMonitor\\1.0",
        "msCodeInd",
        "Dg[;HL#L",
        "W/HOW",
        "e8{qD",
        "Installing new driver.",
        "TbwAR;]7",
        "setCext-Track2Data",
        "mW%=J",
        "vnaap.cat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "*`t\"N",
        "7@8Q/Z",
        "-VUq2",
        "nG[#L#",
        "af/PP",
        "#><wP",
        "]J )f",
        "A\\\\0N",
        "i-8WV",
        ",-WF~",
        "T7qICa",
        "(>/.\\",
        "PPPPPWS",
        "pbeWithSHA1And3-KeyTripleDES-CBC",
        "T2mE_",
        "Lkkd7",
        "    <protection zlcommdb=\"true\" avregistry=\"true\"/>",
        "<(<8<<<L<P<X<p<",
        "]R|43",
        "2?t7cc",
        "SP&h\\",
        "H<=N!",
        ";]jWi",
        "5=n\"&'",
        "Df\"\"T~**;",
        "CONFIGFILE",
        "\"4ixP$",
        "1*L\\4E",
        "enum ",
        "done with support files.",
        "8 8t9",
        "{?LCU",
        "J3uw e",
        "zKksY",
        "\\dF)On=",
        "XTO!a",
        "p|*_V",
        ">#>)>/>5>\\>",
        "SLUpn",
        "=wbS'",
        "done insertVsmonDisabler",
        "G9-dW",
        "ripemd160",
        "0!191F1N1b1k1",
        "v$]VI",
        "EqWnj",
        "Cvl.;k.\\5",
        "!>s@5i",
        " e4\\yAka",
        "i7gWfM^as",
        "[W($N",
        "ln`tN",
        "*UJ9o",
        "StartWatchDog",
        "ihj& Z ",
        "\"j[mH",
        "r{cSt",
        "^G%qP",
        "Mf=aX",
        "CreateXMLDOMProcessingInstruction failed",
        " ;Y(!",
        "7X7e7",
        "5R5a5v5",
        "}D}p>",
        "SV5$ggY==",
        "ihyA+ti",
        "#[-XE",
        "%7Lc\\y",
        "D\"nTK%O",
        "|<x_o-to",
        "& HD2",
        "tSl\\[",
        "[.H2i",
        "zJ~~(",
        "PcjW(",
        "TPe'w8",
        "&Ln5\\*",
        "\"Ni.}",
        "owner",
        "97=tb[+",
        " %*4ZG",
        "@KFf\\3.",
        "YD!l-a",
        "disabled for fips",
        "}0TQ>",
        "!maGh",
        "nkx!Sm",
        "o/cC2",
        "gMPm[",
        "~vb=A",
        "j}Ye,",
        ":M=i=2>>>E>W>c>y>",
        "Qn#Wk",
        "FW_INSTALL",
        "gQ7<D",
        "3.8.9002.0",
        ";?;L;a;j;s;",
        "i}i7m_",
        "=4m(dI",
        "cmd.exe /c ",
        "WTLS curve over a 113 bit binary field",
        "Vf1D\"",
        "qOuC6.",
        "f[ED>",
        "4}}3v",
        "Proxy CONNECT aborted",
        "6d9k99:@:",
        ":s#1sm",
        ":!LfV",
        "O<WD`",
        "WSh<8",
        "@n26G",
        ")TJ,)",
        "X3u:m(X ",
        "*}eQS",
        "wo.7>2C",
        ".idata$6",
        ":&QKg6",
        "fD0C>",
        "0ls5H",
        "<K<W<_<",
        "BN_mod_exp_recp",
        "S.Q<J",
        "-#2/Ha",
        "w>v4d",
        "Tuk`Q",
        ")pk+r",
        "w$}G;",
        "u0tpC:",
        "ut_A$>&",
        ",X)~ S",
        "\"tNk.c",
        "n?0BV",
        "*080x0t1",
        "9P|2$",
        "fzM]Y",
        "sYE?jg%",
        "\\ZIx(",
        "fVq``",
        ",=UGe",
        "^q|6)",
        "\".|^^e\"OZv",
        "7gPbX/",
        "9C2RP>_@",
        "`<YZ:?",
        "7M!JU",
        "4$4,444<4D4L4T4\\4h4p4",
        "CB#gt",
        "tEh<T!",
        "9ju;Na",
        "{R3ae",
        "!IZe(",
        "T\\3^8aiJ",
        "5<5\\5h5",
        ".?AVWaitAllBlock@details@Concurrency@@",
        "j^qBX",
        "35_F/",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 8.1 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "WB!5Z(",
        "Ft2Zf",
        "{h^x=/AB",
        "#/B qMJ",
        "` i@~",
        "}[y<]",
        "b_>Q^",
        "8@8D8`",
        "{TBR~",
        "#x#JJ",
        "PrVu*fa",
        "vT~Zl",
        ":kX8S",
        "mf>{)",
        "FUCOMP",
        "WU81^",
        ")DYbey",
        "//`W%",
        ".\\crypto\\txt_db\\txt_db.c",
        "invalid keybits",
        "|xo9|I",
        "OW<(wmB$^",
        "<\\>%N",
        "B*k@5",
        "VSProductMode: cannot log in",
        "u'fv@",
        "Z'\\\\=&",
        "C65jz",
        "8._S~",
        "failed to get shortcut filename",
        "jr$kI",
        "o3@E3",
        "dh not implemented",
        "%9l /4ki",
        "&XO1+y",
        "vx{)K",
        "939>9",
        "n)#[HN",
        "\"%svna_utils.exe\" -d -ap vna dev install  \"%svnaap.inf\" cp_apvna",
        "failed to get security descriptor control for object: %ls",
        "],G7e",
        ":Ryq@i",
        "$.Q.k]",
        "FGLk3",
        "3f3t3",
        "3LHtB",
        "AD\"JJ",
        "P*@t%",
        "FsgpJ",
        "asYsP",
        "~B`_^",
        ">=?ls",
        "ph!{a",
        "N)$qQ",
        "k\\-Ya",
        "mqyn}9",
        "\\ZoneLabs\\qrbase.dll",
        "*bF@&",
        "l$,WV",
        "W;<)H0",
        "0ps%;",
        "_updateStatusInt@12",
        "8>8i8s8}8",
        "u%u-u5u=MF",
        "](QL_%",
        "q%.0h^w",
        "0WqYxZ",
        "0y&kh\"",
        "= J x",
        "au0sD.mT2|",
        "1.1B1G1Z1{1",
        "[L%V1gL9$",
        "r}7ac",
        "-dU%[X=",
        "`X?<-",
        "[9y|Zv",
        "3r/R2",
        ";B;Z;",
        "z(@Y*",
        ":};g< =e=R>",
        "FPREM1",
        ";tVuq",
        "9Y(2f",
        "ng7$2",
        "W>Myx\\",
        "6$6D6T6`6",
        "5aRQ\\F",
        "TFT@oO.",
        "[jE;M",
        "%[iszYJ",
        ";#;?;[;w;",
        "yMa&:&",
        " jv#,",
        "4P4u4",
        ":DaF~",
        "-rp\\1p",
        "bad file descriptor",
        "vRZ,naQ",
        "%s, %02d %s %4d %02d:%02d:%02d GMT",
        "mgf1 with sha1 (default)",
        "s$5~3 ",
        "iKL!k",
        "dm^Gw",
        "~bUUW",
        "fJf#U",
        "gl-es",
        "3%3.3",
        "ENGINE_UNLOAD_KEY",
        "-3$=0",
        "3l*$\"",
        "(Sb4.",
        "DE-Lp",
        ".\\crypto\\dsa\\dsa_ossl.c",
        "f,Sil<4;8",
        "_QKb=",
        "kN!IM",
        "-Y#cs",
        "cI`-}[",
        "~@x&s",
        "Y5-u\\",
        "?USERu",
        "H(bm+%0",
        "xYve<",
        "3 3(343T3\\3d3l3x3",
        "NNE];",
        "\\=|\\%",
        "J-^:&",
        "]\\CXe",
        "9h<~\"',",
        "b<MKW8",
        "VQK.L",
        "zO(Z\"",
        "8[9[,O=",
        "u _^3",
        "Y{?Nx",
        "VXGL::",
        "UINotify.exe",
        "Y/<XEi",
        "^*V9+[",
        "dp@D'J,Z}",
        "4J4r4",
        "&6w&F",
        "*X(p'",
        "jynE*d",
        "SELECT `XmlFile`.`XmlFile`, `XmlFile`.`File`, `XmlFile`.`ElementPath`, `XmlFile`.`Name`, `XmlFile`.`Value`, `XmlFile`.`Flags`, `XmlFile`.`Component_`, `Component`.`Attributes` FROM `XmlFile`,`Component` WHERE `XmlFile`.`Component_`=`Component`.`Component` ORDER BY `File`, `Sequence`",
        "VX_/i",
        "L!jV]",
        " >\"k!j",
        "D,^10<",
        "6{ w\"",
        "'gc?|R",
        "sN][F",
        "C&='m;.g#N",
        "{v\"sSX",
        "%WWx9",
        "PI&8N",
        "\\i:Wby",
        "rI'rz",
        "K`cfBy",
        "q;|7/",
        "bad rsa decrypt",
        "D$D_^]3",
        "Qy3ox?",
        "7Kt+Fn",
        "6*6A6j6",
        "E]:+EB.",
        "\\Y5$ G",
        "7.787I7R7Y7^7e7s7}7",
        "HM|'d|}c*",
        "NbUXA",
        "    Responses:",
        "686D6d6p6",
        "T1P(4",
        "0}J?%",
        "UVFp7",
        "C<vJv+",
        "/4[h,@",
        "BdiV\"",
        "}ks|t*",
        " Y\"@[",
        "GOOD SESSION(S)",
        "erE&,",
        "KQ$HQ",
        "LD<=a",
        "*-^Mm",
        "O)%fBV92y",
        "0'0J0m0w0",
        "\\ZoneLabs\\dbghelp.dll",
        "@>z9S",
        "wX0Z|",
        "WN%0RQ",
        "E*1EgqV",
        "dddddd#",
        ";/;K;g;",
        "VHhJB",
        ";Z<d<n<x<",
        "x509 lib",
        "^-1l\\",
        ".?AVSS_TrayIcon@@",
        "ngS3n",
        "t$$UP",
        "te-IN",
        ";},sk",
        "&r.$G3",
        "-J9lu",
        ":#;C;W;l;",
        "040C0",
        "xWxb]e",
        "&u*2q5z",
        ",-B];",
        "\"&;Oa",
        "&Zk9b]k",
        "KqvX)",
        "bZB9.s",
        "Received too short packet",
        "invalid srp username",
        "bL-8+p=",
        "CANT_FIND_DELETE_FOLDER_AND_FILES",
        "az-az-cyrl",
        "=}>(?",
        "SuspendThread",
        "@7X$fA",
        "Call stack from last DbgPrintf (ignore first 4 frames):",
        "v7G`G",
        "^]_[Y",
        "HTTP server doesn't seem to support byte ranges. Cannot resume.",
        "S^Y.0WI",
        "_/J#L",
        "|nXbXA",
        "|$@9D$",
        "`MMM`",
        "v}1d!>=",
        "VFE4:1",
        " -zt#",
        "yH=yk",
        "-m/E1",
        " 0xc0",
        "addressgroup",
        "D@b8-",
        "A2n%dA`{xt",
        "1/[]\"",
        "<U(Xy",
        "\"Ua?(",
        ":6;>;x<",
        "$%&'()*+,-.",
        "3T$(1",
        "g47hW",
        "K&Ee(",
        "w7f\"k",
        "hQB\"/",
        "aQ9>/",
        "9fBaF&&",
        "g$t-\\",
        "E|6;/",
        "!\"!&!*!.!2!6!:#>",
        "    InstallCommand=\"ZAFFSetup.exe\">",
        "R*''a",
        "/u^{N!",
        "p=q4:",
        "0'1}i",
        "Qy|&Rm",
        "3(343<3d3h3",
        "]Iq$7t",
        "guJf%",
        "Ou52.",
        "?vxs@\\",
        "hk} a",
        "`2)Maz",
        "x pWr",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\",
        "w\\9o(B",
        "QM\\qW",
        "Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received",
        "xc[O|9",
        "0lXg9",
        "SQ0K=",
        ".E!E&",
        "Y`YD&)y",
        "8 :?:v:",
        "zb''cj",
        "|;-K@+",
        "SSL for verify callback",
        "]bvG_-",
        "g=/fDL",
        "l<8%O",
        "<!<6<K<d<x<|<",
        "@4th>k^F7g",
        " o{7/uMR",
        "+a}0,_",
        "zM^Fy",
        "3&4;4Z4",
        "|V5gH\\",
        "zV^.}",
        ";+Br@",
        "JVXXj",
        "H.E#3",
        "11eU%",
        ",T6Z!nQH",
        "PoR}9",
        "!*({>",
        "8)KgJR",
        "qF(NZ",
        "wW2mC",
        "+k<?.",
        "3pNgF ",
        "Netscape Communications Corp.",
        "'x1$(",
        "PhdX!",
        "6$6<6L6P6`6d6t6x6|6",
        "invalid serverinfo data",
        "2V)yl]Zf",
        "\"*gO'",
        ",a}U,",
        "G}\"i[",
        ">5[Ks",
        "2V3v3",
        "n]B)NkI",
        "#k#C*",
        "3GuY[yO1",
        "^\\>03",
        "wY9%!",
        "B.P#&ZB",
        "?$?D?\\?h?",
        "Wh,9#",
        "GetModuleHandleA",
        "728H8",
        "8@9^9",
        "111Q1q1",
        ",65sj'",
        "pGKaG",
        "n$_^]",
        "P$|l1",
        "4~I!L",
        "BootDir",
        "!X-cm",
        "_xR0hfHsV",
        "v Hj67X",
        "0/1a1~1",
        "8uR6e",
        "RK5_\\",
        "Jv~C<",
        "~Pz+7",
        "CHPUVV",
        "CANT_RELEASE_MUTEX",
        "Z8Iiu",
        "38s/a",
        "]+LAh",
        "count",
        "3%]!>",
        "k;)K|l*",
        "P a8^|=",
        "]fXQ]",
        "}HG,g)$",
        ";4!7J",
        "b*d/I",
        "3xPh&",
        "8$8,848<8D8L8T8\\8d8l8|8",
        " 0x39",
        "|mL{!F",
        "ZS_}8",
        "n|Q5N",
        "qUkH=",
        "k6}Eqx",
        "cpNewDigest",
        "UJKb\\E",
        "~q_Le",
        "nioW;",
        "ABTq7",
        "uAQ4<r",
        ".'I(C",
        "nT2/s",
        "AES-192-CFB",
        "_])Heh",
        ">Q?n?",
        "}?D)~P",
        "rSD\\)",
        "u:U0O",
        "$m2.B",
        "Y_}5@",
        "pYa=_p",
        "RegSaveKeyA",
        "^K5'r",
        "failed to initialize Wow64 API",
        "8F9C!",
        "N\\HyS",
        "aI5,@",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mcafee SecurityCenter",
        "O 1r\"",
        "Z u22&",
        "Ne}!o",
        "hs\\/)r/",
        "3^.O>X",
        "CVTSI2SD",
        ">\\2\\T",
        "?/gC!",
        "}9cd'",
        "o./_N",
        "Resource device",
        "}7z{_",
        "(2\\fl",
        "dHnrb",
        "homePostalAddress",
        "jMDt$%<#",
        "a^ktc",
        "skjQS",
        "Va;SA",
        "to8^lu",
        "aa7w\"",
        "favouriteDrink",
        "\"|ow2",
        "535S5`5g5",
        "be4+H:",
        "ZkJ,Mp",
        "H6Aa6",
        "F'AoW%",
        ",cDj`d",
        "rz~97",
        "$KtZ}r",
        "t'WPh",
        "<:T6W",
        "0-MWS",
        "2s#J%",
        "SYuH[+",
        "lhuO\"",
        "jx}C6",
        "':_hD5",
        "^u%^c7",
        "8.8S8e8",
        "2Rd=5",
        "=F>X>~>",
        "GHO}2",
        "QHe,7",
        "(GlobalSign Timestamping CA - SHA384 - G4",
        "uk1*x",
        "!|* $D",
        "No6n`\"",
        "Eyc6-ok6Y",
        "k-,,1h",
        "i+Vmf",
        "FPATAN",
        "Dp`F ",
        "Pipe could not be created",
        "XM!0u",
        "k-Wi5l",
        "v>NBW",
        "9 9$9(9,949L9P9h9x9|9",
        "J\"in!",
        "=WXYX.I2",
        "k!-}i",
        "EVP_OpenInit",
        "; BfB_",
        "1(10181@1P1t1|1",
        "B*THU",
        "pB 3H29[",
        "s35G?",
        "QFHu#",
        "n].#&<psx",
        "7|(+Z",
        "IuagG>",
        "tv+#r",
        "v|i-~",
        "tls invalid ecpointformat list",
        "5UUSS55UUSS55UUSS5?U",
        "r%6>M",
        "0A;Ux;-",
        "3?u'h",
        "F\"/M^4:",
        "SxY\\{",
        "^H]F/",
        "3$3C3n3",
        "'/JEOC8K*",
        "PBLENDVB",
        "j~k:l",
        "+b!'g`c",
        "%'4{+",
        "b64Bit",
        "mm+ej",
        "RegDeleteKeyValueA",
        "x:*J3",
        "PUSHF",
        "WIX_DIR_PROFILE",
        "ASN1_BIT_STRING",
        "j@jyS",
        "Lk16!",
        "KXIolD",
        "8^(u-hD",
        "T_v\\#",
        " kR<x",
        "Nj-<T",
        "QrC|#",
        "<qwGJ",
        "ePtZI",
        "<E<X<",
        "uo)Xy",
        "f+\"THQU",
        "~4F(gI",
        "App: %ls found running, %d processes, setting '%ls' property.",
        "fgLSp",
        "mo>(JH",
        "DHE-DSS-AES256-SHA256",
        ">Gu=J",
        ".\\crypto\\ec\\ec2_oct.c",
        "u`E#TT",
        "[INSTALLER]",
        "wB;p|",
        "A:5YK#",
        "X^</.",
        "oA%NNZ",
        "ELsQk",
        "'*ZF!lt[",
        "9#959B9a9",
        "jg\\A ",
        "A\"6/JFO",
        "$3=akNK",
        "]klSP",
        "*wS Z",
        "?iYnO",
        ",0c-'",
        "kNmi5",
        "*4%-x<",
        "WT3G]:",
        "uefeDd",
        "A$BKd-",
        "xxz~z",
        "f$l'L",
        "#)PB0",
        "D$4g&3g",
        "D$,VPU",
        "!r4m3",
        "InitializeConditionVariable",
        "5ez}^",
        "HH'-'mm'-'ss",
        "*%Kc_",
        "8\\tNA",
        "%{Hsu",
        "-,oBY",
        "5GXyM",
        "Wxi`va",
        "'0'=;",
        "pilotAttributeSyntax",
        "5J7T7X8b8",
        "GdUC&",
        "hnk>6",
        ">]fz;",
        "GetTimeFormatEx",
        "<!%l&j",
        "l>`3GX)-",
        "0/`J,1",
        "X1\\rF",
        "0%1D1L1z1",
        "yVt/_",
        "c<4,C",
        "m*DRy",
        "EC_GROUP_get_curve_GF2m",
        "retrieved INNER_MSI property: %s",
        "5(5A5Z5s5",
        "n3I[`o",
        ":$T|t",
        "bn-IN",
        "m4_sv",
        "CANT_FIND_ISMODULERUNNING",
        "RunAs.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Lva\"4",
        "E`cOQ3",
        "6d`]W",
        "FH~u`zBB",
        "fz!UZ",
        "id-Gost28147-89-CryptoPro-C-ParamSet",
        "</=o=",
        "4.M<O5J>E",
        "tC{d4",
        "kcdy2Y'",
        "}wO#|",
        "$8+|g",
        "wEd\\8",
        "lPBYB",
        "s)?eF$d",
        "{4sx-V",
        "_'QCE7gFA",
        "{SOj_",
        "EFRCommit started",
        "Pt7du",
        "NU#i1",
        "Aj2ci",
        "=&=@=s=",
        "hKcUE",
        "rME6G",
        ";fiv%",
        "3'$( $K_",
        "9|0UDqV",
        ",1Lbj",
        "[DUMPFILE ERROR] error in UpdateDbgHelpVersion in VerQueryValue determining %s version returned %d",
        "rZ0~#]S",
        "@NA&N",
        "certificate revoked",
        "gpI%p?",
        "TS_REQ_set_policy_id",
        "SSL_write() returned SYSCALL, errno = %d",
        "H\\mrk",
        "rlO?s",
        "Y^Dw@",
        "xE;5 ",
        "V\"|0Vy",
        "sha1 (default)",
        "*zK[dK",
        " ]KsZ",
        "H,nA(",
        "!Te*,",
        "YP5Y}9gc4",
        "vlvbrl",
        "L*RG!w",
        "pW+pU",
        ":\"s t",
        "BITSTR_CB",
        "636O6k6",
        "$|ym&",
        "ja-jp",
        "A_{#l",
        "|e)R$",
        ".bwkwlw",
        "\"R@|O",
        "s8|5h",
        "~MuS;!",
        "ype_Ssf",
        "DTLS1_BUFFER_RECORD",
        "!F-?<",
        "failed to copy xml file path",
        "oOfs9",
        "bj/_c(",
        "ze(~g",
        ",dXLU",
        "5%6a6 7B7N7U7`7",
        "o%BS!",
        "N=tYx",
        "KTBRI",
        "B(\"[.",
        "dddddddd",
        "F_c}9!",
        ">[>n?",
        "jzjwj\"",
        "Command not found: ",
        "0G-7+)[[u",
        "=?=b=|=",
        ":G;j;r;",
        "index.html.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "BJ:~G",
        "g$eOt",
        "bE@T5",
        "2%vjw",
        "6i8/:",
        "171]1b1",
        "(l a>5'",
        "4>5f5",
        ":Bu-O",
        "i1n\\=",
        "^d7@6",
        "}2(%l|/",
        "*9pcj",
        "struct ",
        ".3pWl",
        "KI$$w%",
        "NBhDr/",
        "^(xO/",
        "TS_GET_STATUS_TEXT",
        "HQ*!>",
        "C/7;$s",
        "; ;$;(;,;0;4;8;<;@;D;P?T?X?\\?`?d?h?l?p?t?x?|?",
        "&0la~",
        "q3TT=",
        "csksrs ",
        "ExpandEnvironmentStringsA",
        "VtX2VUk",
        "\\rsid3501646\\rsid3545685\\rsid3552546\\rsid3702746\\rsid3736522\\rsid3737333\\rsid3766116\\rsid3875139\\rsid3938971\\rsid4144294\\rsid4208764\\rsid4215042\\rsid4272055\\rsid4410457\\rsid4602388\\rsid4727815\\rsid4860160\\rsid4873124\\rsid5000668\\rsid5010868\\rsid5013025",
        ")s67PU",
        "ZK oSh",
        "?.?<?",
        "9$9D9P9p9x9",
        "I'X64",
        "Wh4`%",
        "&x<R\"I",
        "o~NTT",
        "r(/_R",
        "'9VNYs6",
        " 5| u@",
        "'e@t5",
        ">EN|e",
        "oA;=z",
        "4Q3{C",
        "\"_N%vx",
        "*\"P~h(",
        "PS?ZG",
        "&0{j)2a'",
        "Jd. 8",
        "\"d`,0.b]v",
        "BN_exp",
        "opst_ui.dll",
        "0?0Y0`0o0x0",
        "{@x$}",
        "]Qsdx",
        "Helper::stopTEService",
        "LL;Wn",
        "update_config_tool.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "^*}|p",
        "HnX[(",
        "K^B%5",
        "=)Z>i",
        "boost::too_many_args: format-string referred to fewer arguments than were passed",
        "bEQE^`a",
        "m:Zgl",
        "ecp_nistz256_pre_comp_new",
        ".?AV?$ctype@_W@std@@",
        "7$7,747<7D7L7T7\\7`7h7p7x7",
        "*t\\n3k",
        "f/lC+",
        "vq~rr",
        "Ri.E Sa",
        "RRvM;;",
        "fOYA6",
        "9Q)DL~",
        ":#+)z",
        "P,!AV\"",
        "|h?g#",
        "n$H3.",
        "g6K>p",
        "7\"L=5",
        "3L$,1",
        "sDS-#",
        "VW9OZ",
        ";,;A;[;",
        "k)B'`",
        ".H}*:",
        " (Error code:",
        "2Tx/V",
        "Mj=HI",
        "{/Yv^2*",
        "0 0,0L0T0\\0d0l0t0|0",
        "Tes\\%=2",
        "8?8I8b8x8",
        "@F%GK",
        ":N9r+",
        "x$^/;r",
        "0)1.1c1v1",
        "UT`fV4",
        "hH*f4",
        "ZP:#rR",
        "Ql6SJ",
        "@yWhv",
        "Xw*vY",
        "7U#qw",
        "CAPABILITY",
        "%s %s %d",
        "fq!b(",
        "h.!=H",
        "z6 Fp_~",
        "47,j(",
        "=W>q>",
        "EXTENDED_KEY_USAGE",
        "eoPr:-",
        "%,fUY",
        ".\\crypto\\asn1\\a_enum.c",
        ":1iy-",
        "2y#CA",
        "k=MH\\k",
        "IZgnM",
        "svmt3",
        "3!323C3T3e3v3",
        "8 8m8",
        ")[z&,,",
        "wpS)v",
        "0EQp3k_",
        ",<&\"V",
        "rw?rw",
        "t$,SS",
        "|Ft w",
        "QY`%C",
        "c<RcT",
        "N4Z!i",
        "jnjij&",
        "EJmY^",
        "'MHHh",
        ":(:::w:",
        "x7zK&",
        "=_M54",
        "@>< }Vh",
        "vsdata",
        "tUSWj",
        "4g5q5",
        "6(676S6}6",
        "FTP: The server did not accept the PRET command.",
        "installing gina",
        "Rq+~Q",
        "PcC!eI",
        ")8s?1?",
        "successfully created secured folder instead of symlink",
        "plagI",
        "Boc4~",
        ".7?6-P!gsw",
        "\"M+O9",
        ",s0qlLZ",
        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_",
        "Epam service stop DLL path %s",
        "J_LX6&",
        "<A0QRQ",
        "The existing driver's version is lower than the new driver's version ",
        "@3P83H<3T$p3",
        "c7qc[u",
        "j,j#<f",
        "=&>8>l>",
        "L_@3%",
        "ssl3_callback_ctrl",
        "!EiX3",
        "zy@(g",
        "WH-@(",
        "5bG2+",
        "'Xt.:b",
        "zZy[B_aH",
        "Going to add NoRemove for SC uninstall under %s ",
        "FPTAN",
        "UYsab[",
        "({oB9m''",
        "si9)O|[",
        "(#UjQ;",
        "'C_}gr",
        "K|_rY",
        "xz}yy",
        "W23N3",
        "\\sl :G",
        "'<D5V",
        "z9ypH",
        "Cf\"u?",
        ",6Lm%M",
        "#H]\"O",
        "Piqis",
        "l$(Ph",
        "PatchSBAInstaller",
        "CLIENT_SUB_TYPE",
        "bwHSE",
        "n+nkn",
        "[z=+j;",
        "2&222<2Y2`2l2z2",
        "Failed to receive SSPI authentication response.",
        "wdx4y",
        "9)]WH",
        "'&nh:g",
        "b0M@)",
        "';4fKY:t",
        "LOGVERBOSE",
        "f;\" x",
        "|=LDP",
        "&\\Zd-",
        "E4Zq_",
        "%i&hs",
        "-%mFF",
        "?BL|U",
        "WIX_SUITE_ENTERPRISE",
        "1,jmv",
        "Yh\"T(+",
        "RGh'a",
        "Turn off protection before shutting down.",
        ",g6eAC",
        "l^/z:P",
        "@BbL3",
        "aU:d=",
        "libdes part of OpenSSL 1.0.2h  3 May 2016",
        "8$8,81868H8V8{8",
        "M?z`x",
        "11QXa",
        "0Yg]o",
        "FAyHtUh",
        "szZlcommPath",
        "404P4p4|4",
        "Epilogue_spdlog.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "vQ] S:",
        ".w4T}U",
        "jQIo ",
        "~q'@C",
        "+jyG3",
        "This is NOT Standalone mode",
        "x[kk]",
        "cross device link",
        "[5Ftv",
        "t3Z8\"",
        "L]uad[#",
        "UkLTQ",
        "D$PPh$",
        "MSVCP140.dll",
        "WQp,_>~W",
        "|.\\-@vE",
        "6<6A6S6d6",
        "3T$P3T$43T$",
        "aQ,@c3W)8{<*",
        "*)7>V*",
        "n.,W$",
        "^MKh5w",
        "2(282<2L2P2`2d2|2",
        "cnYM6\"",
        "7]ZE'$",
        ":/]5Wq0",
        "li.H.4",
        "5yOm8",
        "'[2+9",
        "-q|Sd",
        "n-Y%h",
        "/[6?U",
        "Validation failed for %s.",
        "iKiZ5",
        "%\\GMe#",
        "lk^4%",
        "+>\\9tL",
        "_OK`>",
        "D$4CV",
        "1C1H1Q2a2",
        "oS!A!\\DBD",
        "6Y.?@",
        "',VJ[",
        ".hK51",
        "6af[XfEYa3}",
        "&^JSKD",
        "dyq/j}Q",
        "cookie mismatch",
        "6(7`7",
        "6%6+61676=6C6I6O6U6[6a6g6m6s6y6",
        "91;A;U;q;",
        "rqO=7|",
        "!`?>1%",
        "ZA>JY",
        "GD,8}",
        "ZjVbvKz",
        "jzjij!",
        "D$ PVj",
        "M#cd3N",
        "E}(S*",
        "[n()Yp",
        "Yw{|JkL",
        "pz<HAw",
        "y u4;",
        "CMS_add0_recipient_password",
        "E1W,v",
        "{oHRo",
        "HGdwF",
        "3{032@",
        "7\"d.OJ",
        "2-353V3h3B4",
        "0 0004080<0@0D0H0P0h0l0",
        "dmq)I1",
        "Bf@cH",
        "gf2m not supported",
        "IsWindow",
        "bind() failed; %s",
        "<6<4=c=",
        "x^-x;",
        "<'<1<=<S<o<~<",
        "i\\F[I",
        "Uq\"Nm",
        ".O]WF",
        "k$g*j",
        ")&$Ll",
        ".\\crypto\\pkcs7\\pk7_smime.c",
        "D$8Ph<",
        "id-smime-mod-ets-eSignature-97",
        "D3|M#",
        "bJ-}e",
        "a,0MsOmD",
        "sKrEqFD",
        "Q^r3A",
        "<<Q/B",
        "1y2&393)4:4D4N4W4^4g4p4y4",
        "k.\\IZd",
        ")1gpl",
        "vzOM9G3",
        "<G_Qy",
        "\\]R!s",
        "Byc*<t",
        "? ?$?0?4?@?D?P?T?`?d?p?t?",
        "PSLLD",
        "Registry Error opening key:  ",
        "Jk:&'_",
        "K RC7",
        "o|e2OFe",
        "LsV\\kvA",
        "j%E/2",
        "0&151[1s1",
        "!1$+-",
        "m(:Vz",
        "71(_{",
        "`|$)hn",
        "X9.62 curve over a 176 bit binary field",
        "&]+T:79",
        "NZ809",
        "6-9-:",
        "2j3w3",
        "}\"eb5",
        "}YCcop",
        ".w|>4",
        "GCgq0",
        "[k&n M",
        "0.0C0H0",
        "8Avl1",
        "j$j,k65",
        "&>y>U>",
        "q_;tB",
        "@~fY_@",
        ")H_:,",
        "3\\&~%w",
        "?+74@",
        "nhd,?",
        "7J8X8",
        ":(;,;0;<;@;L<P<`<h<",
        "azJbd",
        "7&b}t",
        "/WiEL",
        "0dw39!43",
        "+7p{+",
        "*iu5^%",
        "Rx`oj",
        "t\\SUW",
        "1E1m1",
        "' 3$s",
        "q$7KR",
        "HM\"6q",
        "tC]gS",
        "P,2Xh",
        "k*lVE",
        ":jKY^S",
        "Y1UdY",
        "*>fS\"",
        "{=rcQ",
        "=,SGI=",
        "_j1~B",
        ":_:C;x;",
        "SMTPS",
        "\\$`U3",
        "invalid digest",
        "jhjvj%",
        "mz|\"V4m",
        "/!W\\(F",
        "D$ PVU",
        "Nb)re",
        "y'1HC_",
        "ExitProcess",
        "RaG*X",
        "FlsAlloc",
        "expected ?>",
        "rCf;E",
        "nqE^i",
        "FxgU3",
        "i77Yk",
        "EC_GF2M_MONTGOMERY_POINT_MULTIPLY",
        "JpUSFg'",
        "yW|ohh",
        "`])4#",
        ".)&m&",
        "p&p&a",
        "PKCS7 lib",
        "4'5;5",
        "}^,UL",
        ">A2B^",
        "3L$L3L$@3L$0",
        "`1[#0",
        ")t5UR-",
        "vQL^?",
        ";/<n<",
        "Oj70^",
        "Vg3LE",
        "3OlS%",
        ")/%,-+",
        "aq'-6?",
        "$j;;,",
        "pI7)~",
        "]8gGQ",
        "CleanUIFramework finished",
        "Q`sf\"",
        "MiniDumpWriteDump",
        ":=ily$",
        ".\\crypto\\asn1\\x_pubkey.c",
        "AppPolicyGetProcessTerminationMethod",
        "020f0u0",
        "K~~8p",
        "BXX>y1",
        "4w#l*",
        "M$+E4@Pj",
        "T$03l$4",
        "D$ hp:!",
        "`w5|$",
        "y1K.A",
        "yALG*_",
        "M9Kx(",
        ">%Z5A",
        "23+{?",
        "-O@Z}",
        "SIoOI",
        "ZV9fW",
        "X9.42 DH PARAMETERS",
        "!bpmj\"<",
        "T=@1n",
        "SIGNATURES_VER.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "#<s3'q",
        "SR{c{",
        "_.g/Vy",
        "DLA)$",
        "9TH-3",
        "3eu$*M",
        "=_V&e",
        "cQw%l3",
        "'%ntu",
        "+ra\"\\",
        "J)SHB",
        ")6J5s",
        "8U!nt",
        "_kB;s'I}",
        "o5W#ey",
        "@/Y|`",
        "v`)s_",
        "httponly",
        "n~ZF1",
        "<5<M<g<v<",
        "0e/9A",
        "{v^b%",
        "]_qIQ+",
        ".d=aZk",
        "wnY&P",
        "<M=a=y=",
        "RSQRTPS",
        "?V$v<",
        "S I4\\Y",
        "vcruntime140.dll",
        "PADDQ",
        "]aS<?",
        "aFqKG",
        "`#.oiE",
        "2(202d2t2",
        "T$.!W",
        "%-*.*s%s%s",
        "Dl4x7W",
        ")7o!;",
        ",~.sV",
        "Not suitable for ECDSA.",
        "8A9Q9~9",
        "6 CbI'",
        "vfq(N",
        "TNT\\2",
        "#Rv6c",
        "0%[~p",
        "L2E#*",
        "9Z9e9",
        "4['iU",
        "~$V^i-",
        "75Pgw",
        "4wDX\"y",
        "`3QbE",
        "PpujP",
        "F{XJF",
        "6*6F6b6~6",
        "qopg2i",
        "pn`SyIu",
        "H6TQpk",
        "TK3Fu",
        "KO1,$A",
        "(d>pg",
        "ps7j ",
        "(E\\<M",
        ")n%u%",
        "J+FK@$~",
        "XG:4Rv",
        "~OmN(",
        "y}~rzDL8",
        "nI{^h",
        "F0[_^+",
        "1.vqhT",
        "]^_[Y",
        "mXRecord",
        "9qKlh",
        "Vh-[@",
        "f[=^'",
        "es-hn",
        "Ff%LY",
        "Em5d(",
        "t{\\cI",
        "i?hqhL",
        "P%@f$",
        ";2;8;H;",
        "asE9p=/",
        "=#=T=X=\\=`=d=h=l=p=",
        "FDE_Install",
        "o89iw",
        ";QLu!;QPu",
        "DOMAIN error",
        "spanish-uruguay",
        "CIb@f",
        "http://s2.symcb.com0",
        "Q2Y'&zF",
        "NCONF_get_number",
        "1,141<1D1P1p1x1",
        ",RI'l*3",
        "=^)O}",
        "1GgDi",
        "PC-cillin 2002",
        "es-ni",
        "#.N<q",
        ":VBnD",
        "yo$C<j",
        "6,6<6@6P6T6X6\\6`6d6h6p6",
        ";9O9V",
        ")FQ~y~",
        "G0K3S:[:",
        "=49i7",
        "\\lsdunhideused1 \\lsdlocked0 Table Elegant;\\lsdunhideused1 \\lsdlocked0 Table Professional;\\lsdunhideused1 \\lsdlocked0 Table Subtle 1;\\lsdunhideused1 \\lsdlocked0 Table Subtle 2;\\lsdunhideused1 \\lsdlocked0 Table Web 1;\\lsdunhideused1 \\lsdlocked0 Table Web 2;",
        "Xd!Vn",
        "Custom action:  StartInstHelper: ended",
        ":'k/Q",
        "c8MX0",
        "n]t}&",
        "#J|r\"",
        "0J^{`",
        "bR+R]",
        "}qH\\Jn",
        "Cp;q#",
        "EXp-T",
        "7K1Nn",
        "0!0=0Y0u0",
        "../D2",
        "0,0q0",
        "@8:dB",
        "y6Jw-",
        "+YZ$x",
        "=->H>",
        "dh key too small",
        "O>$$M[",
        "?,K&\"",
        "DEAFULT_VPN",
        "-<<?  A",
        " )njS",
        "X@V%}",
        "3@3P3",
        "Error opening file %s",
        "&&fR>",
        ">X?\\?`?",
        "&[jO|N",
        "U#|p9",
        "i2b_PVK_bio",
        "jcRu1",
        " D_^H",
        ".f/SF",
        "lM2svu",
        "8Mi@Q",
        "A^\"[F",
        "DH(512)",
        "y0w0$",
        ".]mgN}",
        "PatchOldInstHelperCA",
        "~mhS>,",
        "XZy=rh",
        "Iu??ES",
        "/T#N!'",
        "8<9L9U9",
        "d+8Z;&M#",
        "E(;EH",
        "<)~0<*t",
        "failed to read mode from registry",
        ";5Z1N",
        "?oE[><",
        "qq<@M&",
        ")[JLM",
        "$vt\\u*",
        "wz(lm",
        "27k/ctS?",
        "En{#i",
        "1]I\"QJ;",
        "H.,Eo",
        "aKrD?",
        "]W55'9",
        "i9Tcd",
        "OCSP_sendreq_nbio",
        "J|<,Z",
        " J>CO\"",
        "g#ZnC",
        "t}$;4",
        "Jh. )*",
        ".&!-w~",
        "LMMdh",
        "pw'SUi",
        "DpJpU>",
        "2F2S2f3t3",
        "9Ut<XF",
        "{\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}U.S.{\\*\\xmlclose}{\\*\\xmlclose} government, including the U.S. Department of Commerce, which prohibit e",
        "k03%9",
        "/xst=",
        "1$\\DL",
        ":(P:4",
        "aes-256-cbc",
        "zcjS9+G",
        "y/jm6vWDVp",
        "PKCS7",
        ")!)q*",
        "tJj_S",
        "yXcEW",
        ":&;0;q;",
        "x9DNo",
        "m\"$s&l",
        "ASN1_TYPE_get_octetstring",
        "r$uL*",
        "mrb\".",
        "t`v&T",
        "HJOH\\U",
        "mR/$k",
        "h;mdQ",
        "E:s'+#",
        "c0sG6",
        "3(3,30343<3T3d3h3x3|3",
        "1y5F9P9Z9d9",
        "Can't set value to Characteristics Value at Subkey %s",
        "ffV+X",
        ";nha^",
        "`|l|C=wuD",
        "Mkc8E",
        "+!XBqJt",
        "nc~&p",
        ">->7>K>i>|>",
        ":':m:",
        "ProdConfig::SetFWStartup() created key:  HKLM\\Software\\Zone Labs\\TrueVector",
        ";=;t;",
        "O)$>F",
        "(#u[.",
        "se-se",
        "IsModuleRunning",
        "`MAKX",
        "BFMO=",
        "s%B'P",
        "em;?jJ1",
        "1f2w2V3e3",
        "5x;'Z",
        "|LSRZ",
        "failed to free xml file value in change list item",
        "6]6j6x6",
        "Any Extended Key Usage",
        " `o_%",
        "aR4N\\B",
        "#!]'-",
        "<$=5>|>",
        "?Z?n?u?",
        "w3t*=",
        "PCMPGTQ",
        "4fgf ``i",
        ",`bUZ",
        "PhXi%",
        "GQS}%",
        "GetNumaHighestNodeNumber",
        "UH,@Q",
        "3'3/3",
        "GetDateFormatA",
        "d<Fnc",
        ">)?Y?",
        "1b5)\"<`",
        "rtificate.png",
        "d\", &",
        "I,[x)",
        "LjC/S",
        "*'_?!f6m",
        "{b{h=",
        "W>#li",
        "v+mL+",
        "-5(EW[",
        "wmk;&[",
        "}M-)*8z",
        "G;GGGN",
        "<5<j<",
        "WHPh8F ",
        "counter",
        "\\uuUryaQ",
        "(C'nd",
        "yaSuT",
        "UwEFJD",
        "h~] &",
        "wgFJ?'.$",
        "3{sQ30",
        "YJSOT",
        "3GET(!",
        "m5F-(",
        "CmyvlB",
        "5(545@5L5X5d5p5|5",
        "J`jSx",
        "\"$FHD.)",
        "e_u)F",
        "fm/#=",
        "yh?m4L",
        ">/>:>J>U>e>p>",
        " :C&E",
        "k|t_Ax",
        "Q/xtJ2",
        "Tt@NZ",
        "\"GNgj",
        "}\"QX}",
        "Vf6}f",
        ".GP\\c",
        "FADDP",
        "JB%H%N%",
        "SERVER_VERIFY",
        "EfT:8<",
        "6G6M6q7z788X8r8",
        "Wi1\\El",
        "Rs[K~",
        "cF>/c",
        "SleepConditionVariableCS",
        "3P=T=X=\\=`=d=h=l=p=t=x=|=",
        ";0;<;D;l;p;",
        "4sK*l",
        "Iz/-MQ",
        "api_ms_win_core_timezone_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "BV!V!Vaw",
        "FxNUXn",
        "h{9>_^",
        "id-GostR3410-94-CryptoPro-C-ParamSet",
        "O(0iF",
        "kzY/;",
        "T(UPD",
        "CustActionLib.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "606T6x6",
        "_:xRC",
        "p@:S8Rj(",
        "Not upgrading driver files.",
        "t1RWV",
        "d0_+N",
        "s?Nx9",
        "v]uVrkT",
        ".ZqEL0",
        "WIX_WDDM_DRIVER_PRESENT",
        "r2}>W",
        "5->FM",
        ";<k=$",
        ".:#R`",
        "F-ZPk",
        "{(x)Y\\l",
        "]ll+fr$",
        "d^C)o?",
        "4'`*#",
        "@Hiax",
        "-R?-A=4",
        "_sendNow@4",
        "failed to allocate string for shortcut directory",
        "AdjustTokenPrivileges",
        "+ M=]J",
        "nti1\"",
        "SAVEDVSDATA",
        "(+L>%",
        "id-cmc-encryptedPOP",
        "DEF_ADD_INDEX",
        "S=V9E2l)",
        "Got a message# %d -- %s.",
        "t0y'h&'",
        "f&`-`",
        "7PQRVWS",
        "X3i-D6",
        "PqJ9J",
        "3CWyv",
        "fba2Xe",
        ".Y-o|>AnD",
        "4i2f,",
        "|FvP'",
        "<xjb4",
        "dd9s\\",
        "EM%11",
        "010A0Q0q0",
        "Failed to save value \"Time\" into registry. Error code: %ul",
        "=<=W=p=t=x=|=",
        "\"\"D>^w",
        "0[M9c@",
        "1GvrF",
        "cw5p~&\\",
        "wIb;x",
        "~244>tD",
        "8p8u8z8",
        "vr(-Kas\"",
        "=Q=z=",
        "7-7U7y7",
        "g}5^,N",
        "F7V{|",
        "tmHUGb",
        "Yy\"\"D",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  Except for copies solely for back-up or disaster recovery purposes or as may be permitted by applicable law, You may not copy the Product, in ",
        "_]N|#&",
        "kQt.L",
        "BP&Z(",
        "5bu~LN",
        "SSt.{R4D",
        "hzhTX",
        "FDMuF",
        "IlmX]~",
        "5/3a)C",
        "mwrE~",
        "4-424>4K4U4t4",
        "$&4t\"a4",
        " sj\\X",
        "renegotiate ext too long",
        "< =3=?=M=R=",
        "|VSN,",
        "&yH@O",
        "RX7dl",
        "<s{F*",
        "WU>\"1K",
        "SECG curve over a 113 bit binary field",
        "9='A$",
        "\\n)eY",
        "t!+<3?",
        "1FMzW",
        "|q*tv",
        "j:Zf;",
        "DhE7G",
        ".?}<$",
        "vLRK5",
        "Gd/=z^",
        "5:6P6",
        "TrendMicro Internet Security 2003 (All SKUs)",
        "+,Nj)",
        "jMy6~",
        "Daqup",
        "KcM64l",
        ":?FEj",
        "h79W>",
        "z hIz ",
        "CMS_SignerInfo_verify_content",
        "\\3jag",
        "CQqI5",
        "Y'#iA",
        "5t.{5",
        "33?>0Am",
        ">!< w",
        "9\\$Pu",
        "SrLMHOSTSRevert",
        "d2i_RSA_NET",
        "9t9|9",
        "D1}~\"Q",
        "Fx2U9",
        "n%(qD",
        "XbB6_",
        "disabled",
        "M|Lg*",
        "VA=0-",
        "8$8,848<8D8T8`8h8",
        "F2L8E",
        "|]tH!",
        "KtY*&Ye",
        ")/M{s",
        "D$ Pj",
        "n,C=%",
        "53@%Q",
        "0%1m1",
        "g4=hJ",
        "4H6W6",
        "nfa_\"}",
        "lDbv3",
        "wkHoO",
        "SEC_E_MAX_REFERRALS_EXCEEDED",
        "eKM#5",
        "&e7_M#",
        "R>b>r>",
        "21CLR",
        ">(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>l>p>t>x>|>",
        "fVkY_",
        "7(7H7T7|7",
        "/Gx8m",
        "B=zl)",
        "RV\"G\"*,",
        "5)sS}Q=",
        "626I6n6",
        "wL12tJ",
        "O'7H<",
        "_crt_atexit",
        "h6;w{",
        "`4wO7k",
        "GjuF&",
        "Vsutil is loaded by InstHelper.exe",
        "\"x_bQK",
        "*BH,YU",
        "lG>4o",
        "2D5+w",
        "R1nn@-",
        "0&172",
        "PHADDSW",
        "`U}96",
        "6+6t6",
        "6QxQ\\ A",
        "<;&Tz",
        "Vkdf_",
        "M'IG`/",
        "g<.+v",
        "l$L#T$$#l$P",
        "8.9K9_9",
        ">4/c5'Q",
        "=\\x(N",
        "T$43L$,",
        "2,2_2|2",
        ";?(g$?",
        "$*VZH",
        "j^:3yk4",
        "L(oBx",
        ",5qBUS=n",
        "TS_REQ_set_nonce",
        "nTW9R",
        "O/mvL",
        "IxR05",
        "\\;TBe",
        "r0Hgaf$",
        "OnBegin custom action end.",
        "0-jq=*",
        "6(60646H6L6`6d6x6|6",
        "x+VrY",
        "j%v?[",
        "COMPLEMENTOFALL",
        "8&8:8M8",
        "jGYf;",
        "PMULHW",
        "oPC&&Z",
        "4>G>`>o>",
        "+ih@`q",
        "B3\"sWB",
        "feSHOm",
        "XC3sj",
        "*fGR%",
        "8,O=K",
        "W%]{E",
        "'}a;y",
        "ADH-CAMELLIA256-SHA",
        "D$ Rh",
        "'I$Y'q",
        "676S6o6",
        "*1xpL",
        "Ea:Bv ",
        "H\"j}'h",
        "6ggsl",
        "8b37a088d1e4600ead1ddaef67d40bc898b3ed4af81ac0d76a197c86826828a24bb318f3442d8ab518dfe3a20f000d6458d104a9694ac6d88728eee2782428d6",
        "]M$w2",
        "uhtty",
        "9Whv@",
        "'Wmq=",
        "setProductMode;",
        "0L0@@",
        "lCmj881",
        "Recursing path: %S for row: %S.",
        "R\\/rA)5",
        "!(D$:?<",
        "hK5RG+",
        "prf-gostr3411-94",
        "o,5wS",
        ".M\"^-",
        "#],c(`xR",
        "G+*R4?",
        "9E9w9",
        "-3FOL",
        "id-ppl-independent",
        "M6u`D#%",
        "TQjJW",
        "7fkY]",
        "c`]UQ",
        "kzKp;",
        "Wj0XPV",
        "1<Z8B",
        "*~{a3<7j",
        " FilT",
        "8\"9H9y9",
        "rT9o/",
        "yK\"O=",
        "Ev<:@",
        "IvTB)=",
        "9~!lI",
        "s@-=]3rE",
        "F9Vyq1",
        "Fh,BM",
        "M{@Jbp@",
        "tYPc'U)",
        "fCkXu",
        "\\w|l'",
        "8%8C8",
        "DSA lib",
        "0},-[",
        "failed to get formatted value for property: '%ls' with value: '%ls'",
        "5'555>5Q5]5b5g5|5",
        "lX5B,|_",
        "?8Bz1",
        "]EtcK",
        "f)H7i",
        "TGc':I",
        "wnR0S",
        "7r:\"2F",
        "R@|L{",
        "_\\d<|m",
        "vDt-Du",
        "nj.R*L*",
        "*~m#s{",
        "Z tT*l",
        "F%,,o",
        "zVBaw",
        "+1-YA",
        "=F=[=r=y=",
        "u+G;}",
        "starve_",
        "S=C0P1",
        "Wl,@&i>j]kK",
        "-+A`y|(",
        "l9NaW",
        "$PJ\\JhJpJxJ",
        "zR/Uv",
        "AH?to",
        "j!F/s",
        "-=&4'N",
        "u'Z)]",
        "m*(wL",
        "6!!4-",
        "Z(F=5@",
        "#4 *K",
        "97dd '",
        "1(10181D1d1l1t1|1",
        "C-k}qYQ]",
        "2]6!7c#>",
        "ONN2@",
        "WQVYf",
        "FZ>LBLp ",
        "{h3o0",
        "Yb6c8A",
        "L&Mn,",
        ">WKUB",
        "JXl[[j",
        "JP^f6R>",
        "F$\\cw",
        "4:K~6",
        "BOOL ABSENT",
        "Gbj+ik",
        "^u}TTMT",
        "`$gb.",
        "q@c#>",
        "5z{:7",
        "4[h9!",
        "OYjGB",
        "table loaded, incomplete table = %d",
        ".RdYr",
        "EdEpd",
        "#3\"Kj*",
        "v0/.GI",
        "Q{l&i",
        " 0x58",
        "bad array new length",
        "compression id not within private range",
        "CleanupUninstPwdReg",
        "NV4\"q",
        "wYHLAkNE",
        "3a394",
        "]mNw:",
        "O32A#V",
        "Mj<XF",
        "yO9bQX",
        "-3XF|g|",
        "a6UP7e",
        "=#=T=",
        "L?v:Yw",
        "D&uZy",
        "!L%aD-",
        "4FqLZ",
        "2$2,242<2H2h2p2x2",
        "ST'-L",
        "%LIo:u",
        "9.:9:H:V:e:n:n;",
        "G$Ifw",
        "<.FF=",
        "4+unW",
        "illegal hex digit",
        "error getting public key",
        "y# UHl",
        "L^a*,",
        "LoadIconA",
        ";n9^v~",
        "C4AIL",
        "nd%6bI-",
        "/;[tg",
        ":6:H:",
        "QSi0B",
        ".NET installation required",
        ">aB5y",
        "id-smime-aa-ets-escTimeStamp",
        "?][YI",
        "6!6W6]6g6",
        "ivkXK",
        "setext-pinAny",
        "FullProfile",
        "YHJm ",
        "9N1&#",
        "A.c)/",
        ":=q} _.",
        "&x|r;",
        ";(;0;@;d;l;t;|;",
        "7@M?t&(@e",
        "1996509affb3fd381a89672f1f165dfe514173d9850528a2c6cce0239baa4c04ca5bbabac4df000000ffff0300504b01022d0014000600080000002100e9de0f",
        "9 9,9<9L9P9d9h9|9",
        "ssl_add_cert_chain",
        "565E5e5",
        "G^Q,B:B6",
        "4(}0q",
        "9E9^9",
        "_$/%-k",
        "*H_zI",
        "[S(2BJ",
        "E$LiH%",
        "u';Y`i",
        "t` xx",
        "h$O%E",
        "{aQqM",
        "DequeueUmsCompletionListItems",
        "\"RM!F",
        "vdi.O",
        "Sygate Personal Firewall Pro 5.5 (All SKUs)",
        "@$c@%AB",
        "+o%R$",
        "ISSUING_DIST_POINT",
        ",:1r=",
        "WVRQh(E",
        "051{1",
        "8B9N9`9r9",
        "Q|jBB",
        "686X6x6",
        "Ekfs-",
        "D$8Pj",
        "*bS'n",
        "3 3,343L3T3d3",
        "\\jep|",
        "9&;7;",
        "&(&:W",
        "(*+&K",
        ".data$r",
        "c/>Dfo",
        ")e(EY",
        "l$ ;H",
        ";$;*;6;T;Z;p;v;",
        "oJ1*`",
        "<0=@=",
        " :;,n2:",
        "keHLl/",
        "-uzWw",
        "=+=I=\\=",
        "sa+v?",
        "G'q*q",
        "$@$2A",
        "RSA_MGF1_TO_MD",
        "L$+e` ",
        "y]D!Z",
        "}1)pBw",
        "3K2[f",
        "K#qf>",
        "r}!UW",
        "2D:NT",
        "wmS@)S",
        "@W@] ",
        "ec_GFp_simple_point_get_affine_coordinates",
        "]KjOK",
        "<8bow",
        "|cm*o",
        "X}.`c",
        "GR|[x{",
        "X i'Lp",
        "Nd,sw",
        "jrC G",
        ">%?+?=?",
        "'g4#N",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 7.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "6Yw\\[p",
        "6L'N|",
        "7<)|H",
        "Could not get Content-Type header line!",
        "U=9%U<9",
        "Bz@h0",
        "{8R?V",
        "%%Dp`",
        "N}s],",
        "A[m I(",
        ">&?5?",
        "O(kPC",
        "p#AQB",
        "xEyJg",
        "j)'V+L|",
        "Or`A:_",
        "mhiw77",
        "ssl3 session id too short",
        "Lc$-A",
        "DH-RSA-CAMELLIA256-SHA",
        "x^P_3",
        "r}f;u",
        ":SB8l}",
        "S#\\**",
        "NKJ+50",
        "=\\o$`",
        "52$e\\",
        "$rA0A",
        "V]v<. ",
        "[:=V'",
        "iNOm1K=",
        "eZoz*n",
        "concrt140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "oX1rN",
        ",WPQVS",
        "AkrVo(",
        "p94G)]",
        "=0bZ3",
        "+M?z'",
        "i*l8^",
        "ECKEY_PKEY2PKCS8",
        "agksC&_",
        "opaque PRF input too long",
        "SerialNum",
        "j.A.X",
        "&/|_\"",
        "R!R-R=R]ReRuR",
        "KIK)!",
        "`DicC",
        "?vLyX",
        "l71~<O",
        "wd12$D",
        "pVGL'",
        "G0G F*",
        "3*464<5N5x5Z6",
        "C(:Km",
        "q\"&b4",
        "7:738A8o8",
        "3>cm*",
        "DQ4-1",
        "|9Ohz",
        "z04a4",
        "c^VWTX",
        "}^ ~%",
        ">.B.%",
        "bVBp~",
        "=1=C=S=i=q=x=",
        "061;1@1~1",
        "r!OyLv",
        "lzj.>",
        "6*8u8",
        "nT!C<",
        "s7<xK",
        "7$7<7L7P7`7d7l7",
        "~!M4}",
        "f3|656G",
        "6+6Q6",
        "IN_PAGE_ERROR",
        "The requested URL returned error: %s",
        "9]}G);",
        "DY RL",
        "iIU7X?",
        "V;wFC",
        "~\\;|D",
        "8*O~5",
        "Z`xHL",
        "RJ&9w",
        "i`(HD",
        "FD9$}",
        "3L$H3L$83L$$",
        "-IRpZ",
        "The driver isn't installed, error code: %x",
        "((O2*",
        "N8~yQ",
        "B{i&M",
        ":;9|M",
        "&.7.XJ",
        ".6%==C",
        "vLy/F",
        "HandleError:  %s",
        "=|)0?",
        "<_B x",
        "S*M3r",
        "i7vHAds",
        "d@evf",
        "eZ41)",
        "_Oz0,",
        "fMBe[H",
        "q;wX;D",
        "r\\Q~te5",
        "ktNw!)",
        "aA0-%",
        "#8^:gC[.",
        "H!#/'",
        "1}`N^",
        "83`T_Z;jll",
        "6%6/696",
        "].K<9",
        "%Xl F",
        "M'uzR",
        "^kn>f",
        "9l9t9",
        "q^p{V",
        "j5Mo5/",
        "'Q:4%,",
        "(y%Wv",
        "D \\dx,",
        "/V/a/l/u/",
        "I{FE>",
        "\\r*fN",
        "dZBV>",
        "%JCj!",
        "kXqll",
        "BN_usub",
        "eoSu7",
        "'~$Eh",
        "oImSr",
        "77R4 ",
        "U{b\"f",
        "{wz1y",
        "a5ztj",
        "@l*kNF",
        "8!959A9K:}:",
        "CVTDQ2PS",
        "eJd9K",
        ";P<k<",
        "5yzm8",
        "LHJ\"hB",
        ":<;@;D;H;L;P;T;X;",
        "too large",
        "3I3N3S3X3f3p3v3",
        "jv+}*",
        "q]ve(",
        "9lOAT",
        "H1'@}",
        "/Fqh-",
        "z7]sVL",
        "l/Pr.9~",
        "?2Q1N",
        "}dfj;",
        "K+PLi",
        "oxr/J09",
        "RVQWS",
        "~]3pyU",
        ">2w|y",
        "hrxB/",
        "Tbv p",
        "5MU\"9J",
        "='=C=_={=",
        "D$(PhH",
        "PFRCPIT1",
        "EaV5.r",
        "<WaI:",
        ";4;M;f;",
        "'?4{[*",
        "1[5{5",
        "5+505M5_5s5",
        "~rEj#t",
        "\\uRma",
        "T!<%H|",
        "iHiGK",
        "6kL6XN",
        "1*1y1",
        "l?YB:",
        "i128@",
        "8F8K8w8",
        "j1=y;",
        "[#prdf",
        "getservbyname",
        ",VFW_",
        "2%[5s]",
        "/R]ax",
        ".\\ssl\\t1_enc.c",
        "WZ4RS5",
        "whh@]!",
        "^VVU\\D",
        "DefPolExtract_rollback ended",
        "\\6|m}9<",
        "8q$_|",
        "X509_STORE_CTX_get1_issuer",
        "Gv4etM",
        "\"Dt9C",
        "3CYT?",
        "4|p/[",
        ">MGMha",
        "YATS?",
        ".\\crypto\\asn1\\f_int.c",
        "202H2Q2c2",
        ":>;E<",
        "rTxsn",
        ".u ]P",
        "UBWT+W",
        "ENGINE_new",
        "0'1[1",
        "sA)UwB",
        "=!4;Zd",
        "pRLPtw",
        "i<'Yt>+",
        "PKCS7_add0_attrib_signing_time",
        "FU-=l\\",
        "ASN1_OCTET_STRING_NDEF",
        "p~T}^",
        "%uBSt",
        "s-&c}E0",
        "rid+M",
        "6M6T6",
        "8 9'9m9",
        "f~TyZ?",
        "aZfT=^'",
        "ET7b-",
        "-lJ=t",
        "9<9_9",
        "GetOEMCP",
        "6)6D6_6z6",
        "S+-$/",
        "(S Lt",
        "B[DTSc",
        "z.T4TC",
        "[!}_6",
        ",~6=JP",
        "X<4]yn",
        "IPSec User",
        "9L9R9b9",
        "aaControls",
        "7%7,757;7F7M7a7g7m7s7y7",
        "8 969E9\\9m9",
        "ybFC?",
        " ,cY[",
        "\\mY$>\\",
        "3[tK9@5",
        "^y|;\"]:",
        "P1T1X1\\1`1d1h1l1p1t1",
        "G(Ph@",
        "]ecKzO_",
        "dirName",
        "#0x0!",
        "#Fo0|>",
        "$w,Uz}",
        "ASA+y$s(",
        "Xt,,4.",
        ".sf(\\",
        "I[fI`",
        "$rL}z",
        "+Gn%t",
        ". Q>X0<~",
        "9!9A;Q;a;q;",
        "c>,MQ",
        "ig&!c",
        "8m}78",
        "0r0w0",
        "ZXprsz",
        "SEC_I_RENEGOTIATE",
        "`uP36",
        "v/JR[[A",
        "c3z$i",
        "G?kUj",
        "I/fxt",
        "wl3yk.:v",
        "51qSSLt1Q",
        "failed to get modified time of file : %ls",
        "6T()`=",
        "%/%EH",
        "5m[n'TW",
        ",4xC}XQ",
        "{|$!}OL",
        "ZMwVe",
        "nI@E3",
        "ewVgf",
        "spanish-chile",
        "L18WWR",
        "invalid vector<T> subscript",
        "@=Ijat",
        "@)\"m7",
        "aImxA",
        "_exM^",
        "O5qR\\",
        "S5M:q`",
        "333>3o3",
        "ms Mezr",
        "<t'+ex",
        "z+L'iS",
        "~b1G7",
        "'eCvY",
        "_H()H",
        "Failed to disable WOW64.",
        "x5O9@tvk)",
        "InstHelper finished:  %s",
        "=Y=a;",
        "Td6q8",
        "3RG}D",
        "~T~Cc",
        "Yjs\\R",
        "5*HDi",
        "*TY@L",
        "RegisterTraceGuidsW",
        "des-ede-ofb",
        "4?4d4v4",
        "CJ]x^",
        "`QeCm",
        "2da!RYn",
        "Serial Number",
        "hm7VD",
        "|o24l",
        "&0k0p0t0x0|0",
        "keyblob header parse error",
        "Voq.F",
        "jqjij",
        "8v#:<y",
        "5Oq]]",
        "ae[MU",
        "JPlp_",
        ",,:O5?",
        "Y`JAR",
        "t$8Pj",
        "{]/qZ",
        "Failed stopping TE Service",
        "q<nJw",
        "6@F<Kx@",
        "445;5",
        "[.cyc",
        "3>9vg",
        "0h%U9",
        "FAILURE_TO_CLOSE_SHARED_MEMORY",
        "/xEJr",
        "YRjoH9",
        "`$'\"P",
        "=H1H9",
        "%)Rac",
        "Our{?",
        "Accept-Encoding:",
        "535<5|5",
        "GET_SERVER_HELLO",
        "Wpu{YJ",
        "BKokw~",
        "{[:-hkc",
        "{Ag/P",
        "5.5G5c5",
        "]HSj(p",
        "kernel32",
        "?N*(1",
        "~$+~8+",
        "Q+Z^&",
        "!\"\\kN",
        "8&888e8",
        "040904b0",
        "tn;`3",
        "yv?QP",
        "BN_CTX_start",
        "Lk-S ",
        "fJ(20_",
        "t1V{:",
        "w~x}E\"",
        "dW#i~",
        "Refusing to issue an RTSP request [%s] without a session ID.",
        "\\AM1.Signatures\\mirror.exe",
        ">!?>?Y?",
        "jkvZRZ",
        "`7#Dd",
        "@2hI3",
        "pI|KeD",
        ":4:f:k:",
        "ORLx.",
        "0jXH4",
        "&y,_?+Cc",
        "d/xycs",
        "eJ4\"%",
        "KaB-=,h",
        ">:>G>f>|>",
        ",@ro$",
        "h4m$5*",
        "7Um*@",
        "q4dsD",
        "0B1y1",
        "M$N0NFNNN~L2",
        "8q6v|d",
        "-_+i8",
        "S2#-g",
        "'+bOL(",
        "f`S\\*'_",
        ":Sd_t",
        "25~=>",
        "mqY`^.Z",
        ">g1sE",
        ".p,*)",
        " +1b5",
        "i-O*-",
        "/}vt/Wc",
        "u^,bX",
        "SOFTWARE\\Microsoft\\VSTO Runtime Setup\\v4R",
        "LC_CTYPE",
        "DIVSS",
        "?Dm)/",
        "?J^fL",
        "213?3M3R3^3k3u3j4",
        "(xliL",
        "CRL_DIST_POINTS",
        "*f8FL_",
        "Loading error information from msi database -- Failed to open database",
        "+zNS_",
        "Change Characteristics KeyValue ERROR",
        "K[P0{",
        "CU\\d4hVqb",
        "CANT_FIND_VSCHECKPASSWORDS",
        "9&n90",
        "?(?,?0?5?9?",
        "iZl;f",
        "}QwI-",
        "#rD<ii",
        "1+2\"5",
        "dsa routines",
        "<+ZOh",
        "<ccE.l",
        "X$]:@",
        "1_2t2",
        "'K3gf",
        "AddToWinFwExceptionList:  AddToWinFwExceptionList() succeeded.",
        "&b\"#c;<l",
        "DH_compute_key",
        "!Th G",
        "O)-Z+",
        "{JAsC",
        "*z<}:",
        "S`lM}r",
        "a=z:O<",
        "Dac<7",
        "%D:`_",
        "X509 CRL",
        "E*n~oX",
        "boost::filesystem::create_directory_symlink",
        "xo!MD",
        "2FfDP",
        "5Phf3Ae",
        "30x5p",
        ">\\gD-N",
        "; ;*;4;>;H;R;\\;f;p;z;",
        "0(0,0004080<0@0H0`0p0t0",
        "RUTb7",
        "KJ&a^",
        "OO2zy",
        "3 3,383D3P3\\3h3t3",
        "IL`Cr",
        "+u'bbB",
        "ECDHE-ECDSA-DES-CBC3-SHA",
        "Installing checkpoint integration.",
        "Failed to get module filename",
        "*r$HI",
        "h@^_ ",
        "}+]RB",
        "=BI2@",
        "oBxNYB|",
        "-k%#T_F",
        "<2<N<S<`<~<",
        ";*<.<2<6<:<><B<F<J<N<R<V<Z<^<b<f<j<n<r<v<z<~<",
        "%.=ZW*'",
        "qp2o!",
        "F.1{Y:",
        "*QkZ'",
        "L.%XBx",
        "x[nh>",
        "Failed writing received data to disk/application",
        "CMS_add0_cert",
        "jAjdj*",
        "X%/_oH",
        "CI`z^<:",
        "OXf9E",
        "\\JkyZ~",
        "bE(+^",
        "Zgl<g",
        "q6rtB",
        "ey.aS",
        "&x[F]",
        ":G:l:",
        "252{2",
        "3YmGN",
        "hINL{",
        "B$&D|$",
        "deBTZ",
        "W4Ek$",
        "]W0fM",
        "<$<.<8<B<L<V<`<j<t<~<",
        "d\"IeQ",
        " fyLDk",
        "LP3+m",
        "TMO,={",
        "w>leY",
        "~HLd>",
        ",Ug<n",
        "sIh:H}",
        "!0>0n0",
        "Nc?hO^",
        ">T>x>",
        "S%So~",
        "memmove",
        "?i#X?",
        "^6w/}^",
        "{dddddd",
        "m58T.",
        "s&0Qy2S$1A",
        "<H<)=9qrC)",
        " 0xc6",
        "/*QZ4p,",
        ":';X;|;",
        "J|~I<",
        ")6D.'9",
        "=Gp{v",
        "CMS_dataFinal",
        "`2Y/ o",
        "LACt$",
        "^PO0n",
        "</<6<",
        "policy",
        ":(:,:<:@:P:T:X:p:t:",
        "\"T`uM:",
        "Q>[yT",
        "Sanv3",
        ".?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        "BAY$.",
        "appl [ %d ]",
        ";B:qv",
        "}<?rV",
        "C0X0m0y0",
        "V[\"Qu",
        "u0vab",
        "<b/\\u",
        "x[ Z2",
        "/RU/XP",
        "0hv^~",
        "prime239v1",
        "yFGV*/J",
        "~^R9e",
        "7S8Z8e8r8",
        "m31;e",
        "V@VDVIVUVYV[VjVmVpVtV",
        "!^~ms|v",
        "l#`}!",
        "$)*6)",
        "'@d|^",
        "17~n*",
        "}4~4N",
        "2i^5x",
        "{p{uF/",
        "4$404P4\\4|4",
        "4S<It@",
        "P3l *",
        ">P=)z",
        "Ny>K>",
        "{,fjRh|",
        "~09~8t",
        "566D6Z6",
        "InitializeCriticalSectionEx",
        "H4u6fK",
        "CNK(j",
        "W(}Ft",
        "&Mauw*H",
        "B<>[Z5u",
        "lowU)k",
        "83b5]",
        "aIv*y~",
        "_time32",
        "ihof6bBB9",
        "*t`=+",
        "jlYf;",
        "Lq}qf",
        ")ADcn",
        "DAJ|GR",
        "?1V\\5",
        "3A3f3u3",
        "|j@7$&o",
        "the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10176163 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10176163\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 s}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "7'7;7B7X7i7",
        "jdZj+",
        "7-7X7",
        "zs9!8F6<H",
        "$H,!-",
        "SEC_E_STRONG_CRYPTO_NOT_SUPPORTED",
        "Failed to open service %s. error %d",
        "ACW>^z",
        "$[8.g",
        "0B(JR-",
        "E=[c1",
        ">B?X?",
        "No known authentication mechanisms supported!",
        " N'D[",
        "8Z9f9k9p9",
        "3,3H3d3",
        "sU))4",
        "Check Point\\rquote s }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid8868444 TAC.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  After }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "hlPHwC",
        "&EDe4b",
        "|cii?g",
        "`4MygJ",
        "XKkK@",
        "U4b]'e",
        "}H)$+-g^",
        "iWGet",
        "vBXY]",
        "pi$Fs",
        "h(Ye:E",
        "Dal:Z",
        "ap'8`",
        "| _][",
        "DZ#84",
        "M5CSX",
        "HSKgX$P(",
        "La-QNtb5",
        " VNXw",
        "Wq+]|",
        "rhrirjrkrlrmrnro",
        "tvjsv",
        "Et]z{",
        "r$dww",
        "mXy^Ht(T.",
        "5c<}C",
        "UUUUUUUUWUUUUUUUUUUUUU",
        "V@,>X",
        "^G;d_",
        "]@cl93",
        "CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC",
        "Pgw11",
        "L7(p%",
        "029v6",
        "2o3G4",
        ":,12\"",
        "b;(.c",
        "rZKl|",
        ".wf!L=A",
        "Found cached Check Point SBA installer",
        "`virtual displacement map'",
        ")(i<`T*",
        ";HMui",
        "zlqrtdb.dat",
        "D30oK",
        "*.dmp",
        "<(<}<",
        "f3G-'@",
        "_|%}Nw",
        "need one signer",
        "v-b7:!",
        ";6;R;i;x;",
        "|t ?^T",
        "$`| 1",
        "WIX_DIR_MYVIDEO",
        "S6PUj",
        "I;qpW",
        "+{'wv0",
        "mV+?q^#/C",
        "T#UFD",
        "Configuring Firewall settings (4 of 5 tasks done)",
        "i3zBVI5",
        ";.<<<R<_<",
        "Y_M2)",
        "3!4+4D4I4s4",
        "4iEKC\\",
        "=-=i=q=u?}",
        "L$(UP",
        "@mw/k",
        "DSA_do_verify",
        "d*\")X",
        "6'%2'",
        "5=*@I",
        "35i+H",
        "1!1S1o1",
        "X|I3F",
        "4e=S-",
        "$!&1='",
        "]*'|$",
        "removeFromCRL",
        "FwThread",
        "dztyi",
        "6#6-626?6I6S6_6",
        "cOst!",
        "VBc*{5",
        "|L8)Bp",
        "D$DSP",
        "\\4]t]",
        "| [_^",
        "W.]}Wy^",
        "-CYMR",
        "~eODE",
        "s4R[I",
        "Yk*dk",
        "iL2T&x9",
        "public-key:",
        "I+46w",
        "B$k?\\c",
        "5+ATF",
        "#1@$]$",
        "AES-128-OFB",
        "*h1BV",
        "value.safes",
        "{K#*'6",
        "REGFILE_DOES_NOT_EXIST",
        "7>7c7s7z7",
        "rHu?`x",
        "HJ0Fp",
        "In8y\"",
        "QGwrru",
        "u$>l\"",
        "m@zZj",
        "j85r.gb",
        "H={O{",
        "Qcfao\\",
        "2Ean=",
        "6^Q/R0_",
        ">,>1>6>S>l>q>v>",
        "g`X2F",
        "=vb.i",
        "GUOmW",
        "9[RRt",
        "C46Xv",
        ".CRT$XCA",
        "t$DPV",
        "\"f1\\H",
        "9[9d9",
        "QhP}&",
        ",O8l=",
        ")Y=Thc",
        "uovSS",
        "Sg<)w",
        "b_T`zd",
        "a*VsP",
        "=D=H=L=P=T=X=",
        "mob_CP_Left.png",
        "s1G.A",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  that the Product is used to communicate with a Check Point VPN-1 gateway licensed to the entity using the Product and the cu",
        "0(020&2^2c2m2",
        "l{',h&",
        "zab~x`",
        "OMf+f",
        "=!=V=",
        "Ge~DFP",
        "WIX_SUITE_EMBEDDEDNT",
        "y*I1W",
        "Y=25\"",
        "12JCD",
        "-r^\\O~R",
        ":ZA,Q*",
        "WVsqR",
        "MATCH %s %s %s",
        "ipsec4",
        "T_&*$B",
        "F;a{x",
        ":2HP7M",
        "DJD0r&",
        ".Y6Pz",
        ":LCEP",
        "&Y+'dG",
        "?jp5-",
        "L)wh<",
        "\\5~m5",
        "J|vtJ",
        "Ih_cG#",
        "K>-;u",
        "CPDAstart.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        ";&[l,",
        "k<#U4F",
        "fz6i+",
        "^n_XN`",
        "@NcV\"j`",
        "F\\_gT",
        "!\"-V_",
        "191S1m1m3w3|334L4",
        "9$:o:",
        "Uninstalling checkpoint integration.",
        "6ZoLim",
        "YlpRJ",
        "v@nT=(",
        "FzKc`",
        "E!4@P",
        ">/wDd",
        "c=0mYN",
        "In`a5-(",
        "h~k7km",
        "XVOWw",
        "Products.json",
        "9w,~ ",
        ".t%FN=",
        "7b7}7",
        "}\\&(N",
        "m^d/`",
        "001b1",
        "INSTALLATIONDATETIME",
        "Mb#5+",
        "7xo=m",
        ":< rJ",
        "Tww& ",
        "# This file was generated by libcurl! Edit at your own risk.",
        "orqRH",
        "X||ok",
        "Qb3deoY",
        "jg>Q3",
        "k_Z`B",
        "G;~@|",
        ",Bh;&",
        "O'QCH",
        "\\ey.%B",
        "s.EMp",
        "K5<@e",
        "8kl!\\i",
        "LK~Px",
        "A&3&@n",
        "_r1*_",
        "<]O;G",
        "M3b$%",
        "/_XYx",
        "TvU22",
        "y)yd\"",
        "\"hN)I_/",
        "aojQ ",
        "2+323",
        ":w#}Z",
        "$C4oQ",
        "sHTWu",
        "T-ynH",
        "4`X8H",
        "8p%\\v",
        "_kPba",
        "`#J>*",
        "yH(9y",
        "DztAJR",
        ",.-XB",
        "Enterprise 2015 LTSB",
        "=K#nt ",
        "]e7zO",
        "bD$]]x9",
        "7E#,y",
        "l$D;i(",
        "#t$$3",
        " key=",
        "<0|,<:}(",
        "3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#",
        "WN#x)",
        "RyF](S7E5",
        ":~SZ{!",
        "w>t6;",
        "q6mkME",
        "/KSk8|",
        "pO21.",
        "M`nFo:",
        "JoIhg)",
        "\"n#oP",
        ")\"{*b",
        "\" WY>e",
        "`copy constructor closure'",
        "CElk$_",
        "VnaInstall ERROR",
        "kB*=[j",
        ":+qA/W",
        "U)W=WUW",
        "mq]+*",
        "OP5hS",
        "uyH{Q",
        "p>|B>",
        ";]c$G",
        "bb1zdI",
        "`ha:x",
        "MAE;}0Y",
        "Qx=HT",
        "GetSecurityDescriptorControl",
        "iy%,f",
        "y<NbU",
        "#)<y8",
        "]l%0x",
        "-u~fYI",
        "SM[MEOy",
        "\"E`*>",
        "vnaap.sys.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "4:4V4r4",
        "39:{3u",
        "&>{`A",
        ".y)hz{",
        "uA~2$}",
        "=gI$<",
        ">2>_>",
        "7aQes",
        "Begin scrubbing system ...",
        "/I=ep",
        "jx];3g",
        "#w8#f",
        "{<MSC",
        "}Tk25",
        "&&Lj66lZ??~A",
        "2(2.2A2G2Z2`2q2w2",
        ")eg9lI",
        "VABE?%",
        "4=JvVX",
        "C`rwQ",
        "value.revoked",
        "*np35<Y",
        "WDd*01%",
        "VX#x'",
        " users, number of cores or exceeds the maximum throughput capacity presented to the Product with the intent, or resulting effect, of circumventing the Licensed Configuration. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "(b !F",
        "W0CI|",
        "hkDJ@t7R",
        "-Uw(Y",
        "t:h|w&",
        "I's2}",
        "6P7s7",
        "fr-LU",
        "N;93C",
        "g6Z.aj[",
        "8OmLi",
        "2Q2\"%",
        "151Q1m1",
        "Connection was aborted",
        "IwLQP",
        "ASN1_item_pack",
        "v]1v-=",
        "\\SD.9",
        "failed to allocate buffer for value",
        "6l;OU",
        "GOST 34.10-2001 Cryptocom",
        "g=`/:}w",
        "9M|~1_",
        ";7;\\;j;w;",
        "w;Yip",
        "%*s%s:",
        "\"JbUG",
        "XqB8)",
        "}0)lEr",
        "1g@3@",
        "jugp|Vn",
        "DM6]Q",
        "KdY&_",
        "#`e-?",
        "TKNy';",
        "[\"xb>",
        "=4>e>y>",
        "']\\>Ll",
        "2 2-2<2P2Y2q2x2",
        "A3/^8",
        "0ADwl\\D",
        ">4><>`>l>t>",
        "socks5h",
        "2#3F3Y3",
        "sF[&y",
        ">l,2o",
        "Penalized, skip",
        "Failed to read Binary.Data.",
        "Uz;]_",
        "[e-:E",
        "Bm%92y",
        "b`{Wj",
        "u 52<ACi",
        "G90|dS",
        "?'?h?",
        "bsA`X",
        "\"aNke",
        "s?b|'",
        "mF6#8%Vy",
        "Kmj>R",
        "\\k*%\"",
        "(S9I#",
        "Sef4d",
        "KmF\\m",
        "setct-CapTokenSeq",
        "'4vtF e",
        "ZwClose",
        "6\"6)6V6",
        "CjoQp",
        "72\"Rg",
        "2IF[Vh",
        "Mm}_R",
        "invalid cmd name",
        "DO_RSA_PRINT",
        "NaGe&",
        "M N0NJN",
        "\\~GTb",
        "[;^>z",
        "9_PY?Z",
        ".wi4N=}",
        "7A>AKLjg",
        "0sKMm",
        "Check Point VPN-1 SecureClient",
        "{59FEFB1C-B5F9-4AA5-841C-FCAA18483B52}",
        "EUCb))",
        "80B0y0",
        ";'<,<7<\">",
        " 5*Lb",
        "R*Z*b*",
        "u#eJGo6",
        "/`d{d",
        "$sfgT<|uPn",
        "^Q;&A",
        "uI-fg",
        "yGj5f",
        "JE'ST",
        "?zPkv",
        "!moTY8",
        "$ k43",
        " 3d[ ",
        "lbm\"m",
        "a:LDK",
        "zzTz(",
        "EMPTY",
        "4&5<5",
        "Y b8\"",
        "U(<<Ee",
        "^lG1Q",
        "\"%supdate_config_tool.exe\"  %s\\Temp\\trac.config.upgrade  \"%s",
        "dRo$D",
        "5n7hxO",
        "X509v3 Issuer Alternative Name",
        "uJ{)'",
        "4%DuJ{",
        "?!pqm",
        "v:/fI",
        "\\par }\\pard\\plain \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "< <a<h<",
        "=Ho,B",
        "I`O0E",
        ">B;7)",
        ";/)6P",
        ":O<`M",
        "`y`r^",
        "&*:x&8:p$~tH",
        "*eCf,6",
        "w1-&z",
        "Vh<< ",
        "$Ze TQ",
        "FFQ{`",
        ";j?/H",
        "gw#~o",
        "ImVBS",
        "dQ\\'`",
        "HO#L]",
        "k/|icG+",
        "=5=v=",
        "Y.cvvs",
        "};FMw",
        "FeatureAntiVirus: Cleaning out any leftover AV sys files.",
        "qB&5V",
        "S#U+<E",
        "|[[4r",
        "34393]3",
        "O%PuQ",
        "3:3V3r3",
        "v.:8w",
        ";|<'=",
        "i7ocm,u",
        "BB&Eo",
        "Y,=Zq",
        "{l03C4%",
        "6#6B6m6",
        ",0i%Y",
        "setCext-TokenType",
        "r<sC6",
        "wjO+d",
        "'w&S&",
        "c0NI-H",
        "\"U6!9",
        "9?:J:Z:",
        "7!7:7S7l7",
        "$UqDf",
        "74JR2b",
        "c@.VF",
        "/q4/t^.ip",
        "*PH=+.r",
        "9bYE$",
        "disconnectedpolicy.xml",
        ";:;N;~;u<|<",
        "gwevents.checkpoint.com",
        "=$=A=",
        "GetWindowsDirectoryA",
        "tUTX%",
        "b'u,F",
        "3G[AJ",
        "(V(G1",
        "invalid escape sequence",
        "OnRemovePrologue",
        "5p_!D",
        "*`gE!",
        "5.1.2600.3295",
        "WcaVerboseLogging",
        "E]N-oh;",
        "-KM#>Vv_\",",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ship the faulty }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 H}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918\\charrsid15169477 ardware }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "<7o-'",
        ",h$\\p",
        "Yp'=K",
        "Source of error:  %s",
        " 'tik/",
        "ir*~5b",
        "Ca]P*",
        "hg>>dF",
        "MOVNTSD",
        "K^>d%",
        "RFC 5639 curve over a 192 bit prime field",
        "Q}DF/",
        "x{G!y;_(k",
        "_tx\"l",
        "Wt<G#",
        ")CM(hl",
        "FirewallInfo",
        "kt%9-`",
        "@e@_'",
        "GI0fZ",
        "H#;r)",
        "VsDataInstHelperOpenDriver - Old driver assumed. Err=%x.",
        "8>wa0",
        "UQ^KD",
        "c5MEi",
        "'(=b'",
        "PpLl-",
        "> >$>(>,>0>4>8><>@>H>L>P>T>X>\\>`>d>l>",
        "KEr~[",
        "I5>1v",
        "VZKp?",
        "MQs3x:",
        "|sO?O",
        "14=z&W",
        "\\$ GS",
        "373=3C3X3",
        "recV(I",
        "0<)z2",
        ">S~0Zj",
        "1o5JK",
        "K]Kyr",
        "}S0*X",
        "152m2w2",
        "8zAyve{h",
        "b/S[g",
        "Failed writing data",
        "[_Wmw",
        "484\\4d4l4t4|4",
        "}nk:|V",
        ".1E<w",
        "a/}\"'",
        ")dZb)",
        "{dU/fb0G",
        "t&90t",
        "Whx*$",
        "e877f0034e16bafb0e258ebb4faf06b769e888340b103d331115bebc4eb813bf83291b63624a0d1475a756c734f9bbc2cd28546ecbe1e20a3794ca175f3fae90",
        ":rIiD",
        ":ffT!",
        "jqvb2",
        "E`\\}7",
        "AJpu~",
        "6!616A6K7C8",
        "SOCKS5 server authencticated user %s with GSS-API.",
        "2ZRjnv",
        "5S5a5h5s5z5",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\Device Agent",
        "bObhU:Wt",
        "040W0z0",
        "T\\mk/",
        "hmacWithSHA224",
        "X509v3 CRL Reason Code",
        "ecdh required for suiteb mode",
        "bm_UO",
        "tXf97tS9u",
        "&:?lXs_",
        ">=bF_",
        "REST %I64d",
        "*eU~@",
        "|*XaI",
        "{ evN",
        "=_<Uy",
        "j\"O!z17",
        "{4gSG",
        "TAC4E",
        "e1U.X",
        "DAJ.\"",
        "Owaq0",
        "D@(_,",
        "D$(;D$ ",
        "s5)!n",
        "HUwP{",
        "(V?qY",
        "6Uo^6dO",
        "Z>T=)",
        ". k2cx",
        "*%^V1",
        "dwc_#Ri",
        "Gl5Dn",
        "97-dfR",
        "!hpy+",
        "5=opK",
        "ec_GFp_simple_make_affine",
        ";aV<8",
        "P\"PbO",
        "^WW&\\G",
        "Uninstall old drivers.",
        "DHE-DSS-SEED-SHA",
        "EPAM_CleanLeftovers finished.",
        ";FJiJ1",
        "%:H(&",
        "HTP}Y",
        ">(.%xwp",
        "m5595",
        "VmK?=",
        "(Uruu",
        "{c^3!y",
        "5+6J6",
        "yy/@g",
        "E/!!P",
        "QqDm,9=",
        "v8kih",
        "RDTSC",
        "*%\"/j",
        "q-t,p",
        "mAm.R",
        "unable to finalize context",
        "!bcPct",
        "w&0^;",
        ") 0j;",
        "\\$LV3",
        "~e5{[",
        "qrLAh8",
        "eA9;x",
        "`*n(0",
        "2ZUCx",
        "%4095s",
        ";q3.y",
        "S>n,}",
        ")w>8>",
        "nfq;Q",
        "EI_*[",
        "o9JsW",
        "NXvM[5",
        "tPfqW",
        "382le6S",
        "5Qkzm",
        "Checking for server connect",
        "c\"p63",
        ",w3Wq",
        ";t$ u",
        "cont [ %d ]",
        "ECDH-RSA-NULL-SHA",
        "0~,2h",
        "MD91m",
        " -upgrade",
        "+&\\Di",
        "lq[qO",
        "Rq}~|",
        "TUNNEL_STATE switched to: %d",
        "a\\19|L",
        "H~P~0",
        "tWPVR",
        " 5&Ss",
        "vq=oq#K",
        "m-ZJH",
        "id-HMACGostR3411-94",
        "V</<t",
        "K4BkxG",
        "T&pK+",
        ":@:H:N:T:Z:",
        "=.@qt~",
        "PC-cillin 2003",
        ":v8q%",
        "575<5b5g5",
        "is a directory",
        "<}t.P",
        "SOFTWARE\\Zone Labs\\ZoneAlarm\\Registration\\",
        "DriverVersion",
        "WS[78",
        "J =fOW",
        "]EG n",
        "1!1'1-131",
        "S,LF)J",
        "O\"XFK",
        "pCjP'",
        "URLFextractUCP.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D",
        "H]Rich",
        "{H!xd",
        "&:Fw~",
        "/)--b",
        "Avsys\\install\\udinstaller",
        "Hgaja",
        "} did!2",
        "#M6Bi",
        "-m+n%)",
        "ti/Ln",
        "W}[1Pu_",
        "T`,^7aQ",
        "m0 WQH",
        "<L=r=",
        "<i(dA.h",
        "H|3k_L",
        "Code Signing",
        "\\s1\\ql \\li0\\ri0\\sb240\\sa60\\keepn\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel0\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\af1\\afs32\\alang1037 \\ltrch\\fcs0 \\b\\f1\\fs32\\lang1033\\langfe1033\\kerning32\\cgrid\\langnp1033\\langfenp1033 ",
        "\\\\b%f9",
        "`/p] ",
        "G!pGJ",
        "@i+}M",
        "OxY\\(XX",
        "<M=&>",
        "#q~kWK;",
        "t't9t",
        "7I8o8",
        "4#'X[r",
        "X9.42 DH",
        " .}!&0",
        "tT=-n",
        "MER`MFRa",
        "{jXm@^",
        "k/h@X",
        "{4?0B",
        "\\R(+?",
        "/_Edy",
        "Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.",
        "69sxg",
        "irZlD",
        ">ZlhO",
        "'QA=A",
        "9JezD",
        "=ADBU",
        "b&Z;j&QCr3",
        "3+'6kk",
        "\\sa0}{\\pgp\\ipgp28\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp11\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp9\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp",
        "7-8>8",
        "xOMkR|",
        "\"G'8f",
        "/<57r",
        "U%jU|",
        "5-585",
        "rD}pE ",
        "7?7]7d7h7l7p7t7x7|7",
        "Lva(F",
        "37^=T`",
        "u$AB;",
        "*!EBY",
        "DW@BY",
        "6X.6Ey",
        "JY9V9",
        "<2{AhcBs?5%S",
        "@b*gZ",
        "5G5R5h5",
        "42474",
        "DataThread",
        "l\\4/DJU",
        "O:S<@",
        "8!9A9]9",
        "U0W/W_",
        "'p_kM",
        "Z<?>Qe",
        "yTf0C",
        "VOxs&",
        "\\e]*P4OZ",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  This Agreement will not be governed by the United Nations Convention on Contracts for the Internati",
        "{7T.n",
        "}u33(",
        ",(n:/",
        ";.IQN",
        "D>TTrR;",
        ">6g1o",
        "1b10$",
        "n] zg",
        "D2O2b2l2",
        "tCJ/Ae",
        "TcsVh",
        "T#J-6,",
        "x_6Q8",
        "k&]M8g",
        "t$0US",
        "PN(Ca",
        "57E1iN",
        "\\FE7C",
        "kCYWo",
        "2KUi|$83",
        ";&<-<2<<<F<P<Z<d<n<x<",
        ":5:::@:N:h:",
        "i59*eQi",
        "(m 2>",
        "LDcl8",
        "&2JzO",
        "}&=S2",
        "quz-ec",
        "{4=;=",
        "BuGfCsy",
        "]PA*)",
        "~=1q:",
        "pP%7l",
        "invalid policy identifier",
        "DeleteFile:  Cannot delete ",
        ">Ku8pv",
        "iEsf!",
        "SEC_I_COMPLETE_AND_CONTINUE",
        "1Hyp.",
        "zBE!/",
        "wC}W}",
        "g3]Cy(",
        "01EM^",
        "ZQZ1Y",
        "Failed sending Gopher request",
        ";%;>;W;{;",
        "ph!=393Q",
        "<Kva2ZME",
        "Mu_(SV1@",
        "uZYW`z|",
        "@T2UE",
        "toz$$",
        "XgwRW",
        "+<-HH",
        "%5DSG#",
        "da-DK",
        "0(0?0D0I0l0u0~0",
        "LOOPZ",
        "P[0] == %d",
        "8u(y8",
        "_x=B2",
        "Jx$\"E",
        ")F#DP",
        "<&=N=V=c=i=",
        " OcS$",
        "JM!<t",
        ">ad5$=",
        "W$q1~",
        ";$;,;8;X;d;",
        ",X\"`y",
        "JlDt8",
        "tg$ue",
        "='=9=o=v=",
        ":(!y\\g",
        "* e)S",
        "-(Ct$",
        "\\\"vyW",
        "g+V}+",
        "5Z\\<#",
        "&qD,!T",
        "a-wk2",
        ",H,ac",
        "Vh4bL",
        "ewg3g",
        "o\\9s(",
        "Failed to move file pointer to end of file.",
        "Jq=CI",
        "QB_\"`J",
        "^%L/x",
        "documentSeries",
        "J6S&tR",
        "2d2s2",
        "HMAC-MD5",
        "3,343D3L3T3\\3l3t3|3",
        "YfmT9",
        "Endpoint Security not found ChallengeMode %d",
        ".A>R9~",
        "O~'/FK",
        "4B)u|",
        "w7M4_",
        "\"V-7Fg",
        "\\4L!AT",
        ";B;J;",
        "y@h<b",
        ">4>@>H>`>l>",
        "FindNextFileW",
        "^'iO7",
        "UEqV=.xc",
        "r~{8)_",
        "=jehF",
        "i~C-, ",
        "]C!yV",
        "*S+%iD",
        "]@)K7",
        "67(889:;*0-",
        "8x7XD",
        ",lzXvo",
        "M2c,B[P",
        "DMdBd",
        "SaO}-S&",
        "(K^V1!qu",
        "n(uI[#",
        "+-6\"v3",
        "-(sgl",
        "QN(s]",
        "il0'}",
        ">^r5v",
        "&e3sxK",
        "h[Tvt",
        "New or undefined Updater",
        ">?>b>",
        "p{KaK",
        "EVP_PKCS82PKEY_BROKEN",
        "zAX( 7",
        "HeapCreate",
        "9>=Rk^V",
        "FqLiX",
        "<C=P=w=",
        "nk'SC",
        "6u#7$bT",
        "StopURLFService ended.",
        "V1o/.",
        "566WWvy",
        "l<OTR",
        "f Ryh",
        "InstallationFinish ended.",
        "em\\!(",
        "{j\"V^go",
        "RcFZ0",
        "aGOST",
        "<%[qk",
        ")Knd|G",
        ";4Wx)",
        "GlobalSign1",
        "l2qAF",
        "T$(SQ",
        "{\\f431\\fbidi \\fswiss\\fcharset238\\fprq2 Tahoma CE;}{\\f432\\fbidi \\fswiss\\fcharset204\\fprq2 Tahoma Cyr;}{\\f434\\fbidi \\fswiss\\fcharset161\\fprq2 Tahoma Greek;}{\\f435\\fbidi \\fswiss\\fcharset162\\fprq2 Tahoma Tur;}",
        "N\\)I>i",
        "HTTP/1.0 connection set to keep alive!",
        "6B6M6q6}6",
        "_5!#8",
        ")!yy~",
        "4lknk`i",
        "WSDO':",
        "mDNXL",
        "pyXK8",
        "r`fQG",
        "3g4`<",
        "H]_^o",
        "Nr6\"Z",
        "ez\"Zo4Uv?",
        "2L2\\2h2",
        "R|Cnad",
        "\\'02\\'05.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li4320\\lin4320 }{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703",
        "msvcrt.cpp",
        "DQZQ+",
        "WSASTARTUP",
        "2f7FB",
        "9|:$;.?s?",
        "D00<y&",
        "Ph`v#",
        "Qn{cClk",
        "CC C!\"#C$%&'(C)*+CCCCCCCCCCCCCCCCC,CC-./01CCCC234CC567C89CC:C;<=>?@ABj ",
        "]Wy=3",
        "YihpZ",
        ".'&I0Q",
        "r1sXO%tb8#@k",
        "ChiKp",
        "`loCt!",
        "GetDriveTypeA",
        ":zYYuv",
        "$Y,4c",
        "dw/#Ya",
        "id-it-suppLangTags",
        " 0x8a",
        "Vhh3&",
        "<?xml version=\"1.0\" encoding=\"ANSI\"?>",
        "Z3Zb1f",
        "$eJ>R",
        "T2l2r2x2",
        "#L$L#",
        "jkL^zc",
        "JCR 5J[;9",
        "APPS_PROCS",
        "new minor version newer then current file",
        ">Nx y,",
        "%)JE|",
        "e;\";0",
        "8b9t9",
        "nX&Jo",
        ".,\"qZ",
        "MXH,o7A-",
        "SELECT `ServiceInstall`.`Name` FROM `ServiceInstall` WHERE `ServiceInstall`.`ServiceInstall`=?",
        "libcurl.dll",
        "[Q(s[Zv",
        "P%F]` ",
        ":u$f9Q",
        "VIfu:",
        "0iQ|Z",
        ") failed",
        "99rKJJ",
        "4*A\"e",
        ";D<_<x<",
        "l&=:\"ko",
        ";./\"\\",
        "hv lH",
        "I^tI~b",
        "25<hCc79",
        "{ #2m",
        "regsvr32.exe /s /u \"",
        " w@.o",
        "Zz=pdF",
        "5?Cy_",
        "<4<<<D<P<t<|<",
        "6TDSF",
        "i|%b\"O",
        "ZATBQ",
        "b${w-",
        "0ZCBA",
        "DS_RollbackFACDriver.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "=$*d?",
        "0_\"g`)",
        "ufS:X",
        "D$8SPP",
        "go[|.",
        "<<~Ip",
        "3cJRR",
        "\";idG_",
        "\"od#8c)",
        ":\"6/DLe",
        "1!1(1D1{1",
        "(GVlG",
        "B<[R8",
        "0t3yj",
        "\\A?Yfh",
        "emailProtection",
        " means any software programs provided by third parties contained in the Product. ",
        "jQ-{1",
        ";b<y<",
        "fiQFn",
        "ReleaseSRWLockExclusive",
        ":T;f<",
        "ek:Gh",
        "]}^0n",
        "4J]|VZh",
        "G>O`'=",
        "-UWN`R",
        "axCzv",
        "GetExitCodeProcess",
        "6'7u7",
        "&;0kD",
        "/THBcu",
        ",:duD5",
        "8&8/888A8J8S8\\8e8n8w8",
        "\"0V%*",
        "5kh;}",
        "XFPW|",
        "F]BuB",
        "EnterpriseChecks_Error.bmp",
        "zW*v|3f",
        "R*2(-",
        "SjmeS~",
        "8(80888@8D8H8P8d8l8t8|8",
        "/nH:z9",
        "mH6C@S",
        "~0~3'c>",
        "!uH\"r",
        "U?G0S",
        "r2jSR",
        "XEq]]]",
        "VV1Up",
        "a-Ch\"",
        "1%1i1",
        "252<2T2n2",
        "v^941",
        "L!|a G",
        "icWr:",
        "nb-NO",
        "_ptgV",
        "F? =D",
        "0p1x1",
        "cOFQ{",
        "]#@d^",
        "Setting done event.",
        "1)2D2g2",
        "T;Gakw",
        "t=fff",
        "unable to create new section",
        "1vn3+",
        ")dT_E",
        "n8-7Iq",
        "U w`n",
        "JmT[j{",
        "9T:e:",
        "$$%d%",
        "PO`E{",
        "LE;x+cR",
        "p>.A7",
        "sJ \"}",
        "6*6e6l6",
        "z$?,J 0",
        "e_q5rXJ",
        "%V1KI",
        "{O_Eh",
        "ESw4[I",
        "Transfer-Encoding: chunked",
        "G,_^[",
        "oXCHJ\"",
        "yIGp4",
        "6;7<8L8]8e8u8",
        "<xX{P,3",
        "ar-ae",
        "oIn_V",
        "j>SpM",
        "l3?;/L",
        ".\\V\\_",
        "MV]m-",
        "4 4@4D4P4T4p4t4x4",
        "0P18yI",
        "172\\2b2v2",
        "QUi)J~Z",
        "GetProcessHeap",
        "`}6PZw}(",
        "^K&##iN",
        "ZwDelayExecution",
        "^VWGm",
        "t1h|w&",
        "(gu]e",
        "3apM#",
        "unknown control command",
        "tq+~>H",
        "+Q;[U",
        "$nptON",
        "*wRv?",
        "-(5xd_`",
        "[Mkz<",
        "\\fs20\\cf0\\insrsid11303137\\charrsid15169477 {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Lebanon{\\*\\xmlclose} }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 or {\\*\\xmlopen\\xmlns2{\\factoidname place}",
        "X%%;d%",
        ":<:D:L:T:`:",
        "03t$H3t$,",
        "E)F(c:",
        "$iDhs",
        "8(wDy+",
        "OqWwi",
        "|_zPp1",
        "~`*C0Z:",
        "crlDistributionPoints",
        "XG}K7",
        "=4Yf7",
        "`zDd1",
        "O}j}J",
        "<F=U=s=",
        "Couldn't resolve host name",
        "DiR^?",
        "*z]_Enj",
        "int_field4",
        ";(WB\\",
        "7^8~9",
        "`/o+`",
        "2pcXxP",
        "GET_CLIENT_MASTER_KEY",
        "3N3iP",
        "L$DVj",
        "mB^[{",
        "r0Xp(1O{.",
        "4=4{4",
        "mZ pU",
        "@^kfMW",
        "CjOv!",
        "EsVOD",
        "dJGoa",
        "_ri_s",
        "jd.cJ4B",
        "9%`] ",
        "pE;af(d",
        "OO o8%",
        ";4=8=<=@=D=H=L=[=8>w>",
        "5(545T5`5",
        "sc0b=#Y.",
        "EVP_PKEY_decrypt",
        "A[,}@[",
        "wM^?G",
        "V2I_CRLD",
        "_e/lo",
        ":(;K;v;",
        "4'0/\\",
        "{A<;mw",
        ".?AV?$basic_ostringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@",
        "Wj\\9]V~",
        "kw`xi",
        "d[B\\3",
        "A4F9-",
        "TQ5Qe",
        "?dA/B6H",
        "(&a)+",
        "8)8H/",
        "OVh;[",
        "WTiZWe6i",
        "z%#3w",
        "szOldInstallDir",
        ">:>^>i>n>s>",
        "cn$lj+[",
        "u;'K Bv",
        "K6krd>)",
        "Could not seek stream",
        "%s%s%s%s%s%s%s%s%s%s",
        "VsDisableRedirect",
        "L6~BL",
        ":':-:Y:h:",
        "jzueS>",
        "V(y!b0",
        "3-4B5",
        "urVR%M",
        "`Wno#yEYg",
        "signed-data",
        "E]Z6SU",
        "sWqXJ",
        "0<1.^",
        "J;q=!",
        "wrong curve parameters",
        "tfiPX(",
        "ZLERR_FILE_VERSION_REQUIRED",
        "kernelbase",
        "no cipher list",
        "8:6.\"s",
        "protectEPAM;",
        "/?6gjm",
        "zk.G#0",
        "Nq%5l#",
        "aWY7X|",
        "RemoveFile",
        "IPR/]~d",
        "c]VG\"",
        "&#YUe",
        "CZX\\{vGS",
        "XpezG",
        ">6JR1",
        "MxEF\\>",
        "'CeKCh",
        "{MAMl",
        "+CSzqn[",
        "2<3b3",
        "8.u1@;",
        ")KF60",
        "P=,pV",
        "]}a^C",
        ";t$8~b",
        "bYM%p",
        "9mBb9)",
        "Hp!Eq",
        "*\\ZTYz}",
        "t$D3t$@3t$L",
        "khU.1",
        "bh`#4",
        "2`poyd%/v2",
        "g=JB`1",
        "+b \"lT",
        "3T$83T$43T$",
        "?54lPPva",
        "%5M&XK",
        "unsupported mask algorithm",
        "Q,y-Kt",
        "MOVSXD",
        "y-h<2",
        "=Wvxt",
        "5K=\\}|",
        "X)H\\e",
        "708u9y9}9",
        "D$PPVW",
        "kj_Pa",
        "07W-+",
        "duplicate zone id",
        "536N6{6",
        "OCSP_CHECK_ISSUER",
        "x.l1d",
        "URDuS",
        "88i&*",
        "/9hK4",
        "r:{6PK",
        "^v%Im",
        "}Py]mw",
        "lKs8a",
        "yyD</",
        "4&414;4Q4[4c4v4",
        "5$565T5j5",
        "ECDHE-RSA-AES256-SHA",
        "_yEP}",
        "3=(78",
        "bJI(l",
        "hdrek",
        "-Yr{Q",
        "#QBpa",
        "r:w<6",
        "585M5s5",
        "t$ uib",
        "?*?F?b?~?",
        "P1FRWY)",
        "p_1_(Et",
        "SELECT `SecureObjects`.`SecureObject`, `SecureObjects`.`Table`, `SecureObjects`.`Domain`, `SecureObjects`.`User`, `SecureObjects`.`Permission`, `SecureObjects`.`Component_`, `Component`.`Attributes` FROM `SecureObjects`,`Component` WHERE `SecureObjects`.`Component_`=`Component`.`Component`",
        "prime239v3",
        "E4^bR",
        "~E0d\\",
        "!@CJ'",
        "}Z.0v{",
        "58}|C",
        "!tAk}",
        "{38(h",
        ";';-;",
        "1'1@1Y1r1",
        ".rsrc",
        "M  f)",
        ">K'2X->@",
        "<$<0<<<H<T<`<l<x<",
        "INITSERVERLIST",
        "aG9`;]=0h",
        "gH,jh",
        "FWUpgradePrepare finished.",
        "6$J}d",
        "M$F[l",
        "~=_^3",
        "P2!I0!",
        ";&;I;l;",
        "Pr2PGy",
        "<1=y@",
        ")tUzd",
        "TK7tAY[",
        "info.png",
        "2!3*3a4i4",
        "p_NL~V=",
        "F6[\\?\\j",
        "o8\"hG&P^l",
        "@\"@&o",
        "D,mX8h",
        "0(0G0Q0f0",
        ",FC(\"",
        "+-GprQ",
        "RY*tu",
        "!(8_ ",
        "#1Hq!\"",
        "G`w\\gJ",
        "HvnN@",
        "ZC?\\uI~dVq",
        "}KbL%x",
        "0*_4:AZ",
        "<securitypolicy>",
        "3nytI",
        "OiLDr7",
        "9/:]:",
        "wsxgcp",
        "2%2?2k2",
        "HRv`xQ",
        "1I D\\_o;6",
        "lqT3d[",
        "e2nS/",
        "DH_PRIV_DECODE",
        "CDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ab",
        "i`LLS",
        ",]jq}",
        "PK^ls\\6",
        "7uj&s",
        ":A#.7",
        "3olmKTB",
        "YoV{~",
        "IH=WtR",
        "bd?lrXk",
        "rzH9>(&",
        "9/9G9Q9_9v9",
        "Hash len {}",
        "C[#nh",
        "=#{W37`J",
        "JIU6m",
        ": :3:8:F:U:n:~:",
        "ar-LY",
        "ENUMERATED",
        "id-smime-cti",
        ":{6Pf",
        "xEav<\\==$",
        "VgRsL",
        "N\\gY7e0",
        "wCH4T\"",
        "no client cert method",
        "failed to processCustomActionData",
        "InstHelper got quit event.  Clean up and terminating",
        "{my-fM",
        "PlugPlay",
        "oTT`$",
        "'@YW[",
        "2#lu[",
        "html.7z",
        "kea=jo",
        "WWf|_",
        " y\\Uy",
        "hovyv",
        "_kr7U",
        "R=l\\C",
        ";,;6;<;|;",
        "XMM10",
        "8'8:8G8S8`8",
        "\\TvB;",
        "*/g;ngL",
        "05Imq.",
        "value.set",
        "c(3|<",
        "%+CM)U",
        "jAS7rkR]",
        "_:P&'u",
        "W|RW\"AFn",
        "u(Ph@",
        "invalid numeric character entity",
        "kwGZ_{",
        "?}bqb",
        "KSVp6&",
        ">#?G?",
        "n=a&E",
        "]=[DZ0L",
        "Nm=~t",
        "^WP4e",
        "zQt3a",
        ":+EdJ5h",
        "_Sq.-",
        "=L=V=^=",
        "H!x:3",
        "KySk ",
        "1AlDpf",
        " HEb,",
        "6MB~G",
        "YRhoO",
        "z^?5&F",
        "(O*yD",
        "ww|lGx@",
        "6$6,686X6d6",
        "$Jx<Q",
        "XURQf",
        "2'252~2#3*3U3c3q3",
        "\"%-U^7",
        "jsjwj",
        "RP.{#_^}",
        ":\":p:",
        "yOt-i",
        "<%C*d:",
        "SSL3_GENERATE_KEY_BLOCK",
        "ssl_add_serverhello_tlsext",
        ";@;P;",
        "YUSKW",
        ",_(}Pr",
        "RSA_padding_add_PKCS1_type_1",
        "/#!5c",
        "r6ax#s",
        "X!m3'",
        "*n1iK",
        "263H395",
        "TQJ(E",
        "9ddu70q02k41jse8pnq82hxiak0",
        "6T6X6",
        "@|]S:",
        ",wVDv",
        "q>gUa",
        "P,cl;uz|)KW",
        ".bY9<",
        "nxb%?",
        "(<@<P<P7",
        "Failed to copy driver. Error: %d",
        "SIxrl\\",
        "WixCloseApplicationsDeferred",
        "vVMWU",
        "_2aY9",
        "R&#;{",
        "ojCqe~",
        "@2r!F",
        "D2I_NETSCAPE_RSA_2",
        "j4mD6$)I",
        "c!\"@3",
        " a us",
        "****************************** VnaCleanWithDir started **********************************",
        "&q%3at$",
        "dA>U\\",
        "2]0^LtR",
        "uHjIh",
        "+V*4)g",
        "0%0<0A0V0[0g0l0v0",
        "j%lEd",
        "FrJ#5Lr",
        "TMInstallationFinished",
        "not supported file type for private key",
        "Failed to get product mode from license key",
        "RSA_padding_add_PKCS1_PSS",
        "kv>2P",
        "77Z:<",
        "NAN(IND)",
        "C]<Y<",
        "p\\<U?",
        "u,~~5",
        "$!$Y2",
        "?!@D ",
        "3hl{N",
        "+q9{p ",
        ">V>l>t>",
        "Bytes at EIP:",
        "kDewL",
        "5$5Y5l5z5",
        "KB\\h%9",
        "n]s<D",
        "8\"[\\[J",
        "4#4'4+4/43474;4?4C4G4K4O4S4W4[4_4",
        "!-9@'7",
        "MailFrontier InstallPath is ",
        "kts9w6z",
        "SaT5G",
        " ATP_5",
        "i;_K;ey#",
        "}:7_O",
        "nNa`kTD",
        "C,@==w1",
        "j_k_l_m_",
        "1 1$1,1D1H1`1p1t1",
        "6h4u2",
        "n0>Mm",
        "Cn{_1",
        "czOL)",
        "/09S&A",
        " 0x51",
        "?$?(?,?0?D?H?`?",
        ".?AVcontext_self_unblock@Concurrency@@",
        "Allocate memory failed",
        ";;;W;s;",
        "D?t20",
        "=mv`[",
        "[IsServicePPL] OpenService failed: %d",
        "D6oP4Lg",
        ",KHrBlI:",
        "k:k2l",
        "NU1@TJH",
        "X509 lib",
        "7 7m7",
        "~ntO<f",
        "0,080X0d0",
        "^8fET",
        "o8Qum]",
        "5&676'7'8Z8_8f8m8t8{8",
        "IPAGx",
        "7+8F8U8",
        "minimum",
        "2;PFkn",
        "~]0oMj",
        "O$^*A",
        "<^s,r",
        "'-[kj",
        "`ea@!",
        "L$$9H",
        ".\\crypto\\engine\\eng_lib.c",
        "/s^2so{Z",
        "Y?px7A",
        ";:;e;",
        "*Osiv5",
        "wigiF",
        "*Rn9$X",
        "=Os\"x",
        "C0D.@E",
        "jgjsj#",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 means to the extent applicable, as indicated on the License Key, the choice of features and the maximum number of users, devices or nodes (an internal comp",
        "2R2Y2}2",
        "kP|1Hp",
        "^AlKE7",
        "?5?D?e?",
        "(=L\\f",
        "_6Ybk@",
        "Wi\"&F",
        "BF-CFB",
        "5.5U5",
        ";GLu(;GPu",
        "::;j;'<",
        "(FT *",
        "chJ!z",
        "nA(O1",
        "b1r|k",
        "9YYG+",
        "$>$#]",
        "ge]]<",
        "Y-BO)",
        "jsr&3",
        "WSEInit()",
        "!,|l<",
        "<wu%2",
        ">a?z?",
        ")+Q7~",
        "wwwx@",
        "id-smime-ct-TDTInfo",
        ";`HI2H",
        "camellia-128-cbc",
        "h8XH{EUX",
        "AB$T~z",
        "a#*i|",
        "x+o+s",
        "b ,?d",
        "HcL4 ",
        "cC,Z ",
        "9%5=Rjo",
        "X509_NAME_ENTRY_create_by_NID",
        "ua].z,am1",
        "wDDGx@",
        "IXEi)+",
        ",r~Ha",
        "mCg&0",
        "&2\\!''9",
        ",=EZp#",
        ":8:@:H:P:X:`:h:p:x:",
        "2j2u2",
        "WZssmt!",
        "MODULE_LOAD_DSO",
        "0[011F1e1",
        "a6@-s",
        "^*VjH~",
        "+U02j",
        "|$ ;>~0hS",
        "wx$\"K",
        "+Z\"9br",
        "Uj$Y^nG",
        "b]_g8_",
        "fGJq~*",
        "yh\\-x",
        "3xmrV",
        "eK, uJ&",
        "455t5",
        "lT1H:",
        "424A4P4_4n4}4",
        "rsa not implemented",
        "\"AFH-I",
        "?D)xh",
        "<Wnf{#",
        "ozjNhA",
        "?6?{?",
        "NsRIw",
        ".**Q5",
        "T(xlG",
        ">d`Q{",
        "D$DWP",
        "''PFO",
        "Py#aHK",
        "ln_%{",
        "i8jI:",
        "%s%c%s%c",
        "Pai5b",
        "RSASSA-PSS",
        "Cannot find Discovery VPN InstallProperties",
        "servicerequest.exe",
        "0MOp@",
        "@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/",
        "Not supported client type.",
        "ZLN%010u%04u-%s",
        "f^}CTs",
        "=#aMc",
        "xS)Q7",
        "#Hxo2",
        "IN13e",
        "Xt*@k",
        ":7CUa",
        "^OYoY",
        "~4@tU",
        "Q#u15[",
        "u\"gBu",
        "6,7^7",
        "O9O;OIOKOQOoOs",
        "YFFyK",
        "AC6F<",
        "6TvHn",
        "p!Nx#",
        "Itb'd",
        "z/pyL",
        "S\\d)w",
        "7T8d8u809@9G9W9h9",
        "gzOM*n",
        ":7:B:G:L:g:q:",
        "Gz:Of",
        "sOzV>.",
        "vfFc{",
        "+o\\[ky ",
        "Ps(_T",
        "CWYcC",
        "QcN9D)",
        "h)U~?",
        "Fc|Jw",
        "737O7k7",
        "0+050f0",
        "D$xPU",
        "sZ/$u",
        "E033gZ",
        "&X#{h",
        "MjQRTR",
        "4-4T4]4}4",
        "f#VP20",
        "B%\"YGB?",
        "invalid null value",
        "Lr:2L",
        "Failed to create %s. Error: %d",
        "LC_ALL",
        "J}$+e*",
        "failed to create secured folder",
        "CMS_KEKRecipientInfo",
        "il]ZVHe",
        "S'UEl",
        "fpr<0288",
        "3 3(3@3P3T3d3h3l3t3",
        "u.# .",
        "]uNZB%",
        "{3eS ",
        "wv&$ktc",
        "(  x$h",
        "qq`#\"+",
        "5#5,5",
        "#92^1",
        "/MATCH:",
        "*QNaO!}",
        "Co,+2",
        "t\"SS9] u",
        "&#[uo",
        "object identifier routines",
        "s?5+Wtz",
        "{0y/!",
        "juYUJ",
        "3]3+2i",
        "EUjN,",
        "t/hlz&",
        ">lm/oK",
        "M+O9-",
        "q.1mrB0",
        "WxW@$",
        "&53bJKAF",
        "en-ph",
        "KCKL \\",
        "kdn_9",
        "%+/-..JNL",
        "j@j ^V",
        "DO_B2I",
        "|e#_e",
        "XFV5I",
        "p>Ft^",
        "MHJO7",
        "+$uE~",
        "4<Xe'",
        "J>Q^|d",
        "FcvL>",
        "s[hP3c$`<",
        "L2&nu",
        "<5<<<Y<",
        "84`>[A",
        "RRp.a",
        ":nh*%",
        "%qeA@",
        "&8n3+",
        "F}0%z",
        "SDOp7(",
        "7]o6x",
        "24H68",
        "7YG7f",
        " #[{ph>",
        "6\\2Q<",
        "Do$NX",
        "QV=\"3",
        "`f`x^>",
        "gxH)q",
        "<+x[lI7",
        "u7<B/+(g",
        "sfs0Z",
        "Jsywk",
        ";JWj!",
        "f0uS75tk",
        "qL-OJ",
        "kl`,&\"",
        "46!.%",
        "rD1j[dkc2",
        "jAjpj",
        "> ?)?5?",
        "$GD{r<$",
        ";<<t<B=a=",
        "|T:O(",
        "6`zhG",
        "S@pz3",
        "50545H5L5`5d5p5x5|5",
        ">=>M>",
        "7 7$7(7,7074787<7@7D7",
        "l]}U6`",
        "D$(Pj",
        "+A$tU3",
        "41494W4",
        "+@tFm",
        "i\\-TOoL",
        "!r(y ",
        "617t9",
        "K///*",
        "'1LF)f",
        "6/666E6O6",
        "rG{@@",
        "?)-8.",
        "[os!)7",
        "Aoo>o",
        "4=4f4",
        "\\H]Jf",
        "net start TracSrvWrapper return %d",
        "#G)(s",
        "~leIJ",
        "k/sS,",
        "9 9'9.959?9G9y9",
        "6 6$6(6,6064686<6@6D6H6L6P6T6X6\\6`6d6h6l6p6|6",
        "*]*RGv",
        "74L;d",
        "'^Kk2",
        "Sj ;Km",
        "kK{EU",
        ".@mK E",
        "[q%22B",
        "Ns#?s",
        " 0x25",
        "Ko Rf;A`",
        "V8J{s4",
        "CANT_UNLOAD_DLL",
        "<0<I<b<{<",
        "O={#X=",
        "ur-q;",
        "Z}RX{q",
        "a-DS*",
        "L?D3N",
        "3e^oi",
        "~MMsH",
        "7\\s2-@ip",
        "3Ac5b\"",
        "E<?]H",
        "h|`(wR)",
        "WIN32_LOAD",
        "X509_load_cert_crl_file",
        "N,3b88",
        "!mu!0",
        "F55Oz&(w",
        "O*+Z4p",
        "D$ SP",
        "&$>DI",
        "U\\e`j",
        "lz)*+#O",
        "4V5f5",
        "aes-192-ecb",
        "e9Y(2C",
        "8URtQa",
        ">U][&",
        "*>.CG",
        "xC:2[K",
        "\\|M\"O",
        "SEC_E_REVOCATION_OFFLINE_KDC",
        "\"XKSD$",
        "9*:E:~:",
        "5,545<5D5L5T5\\5d5l5t5|5",
        "EW'SB",
        "no renegotiation",
        "IH46J",
        ">Ft'!",
        "7+0&o",
        "0S64!",
        "LR|1&",
        ":Dy\\u",
        "A-RlAb",
        "j2`r^",
        "zl?z,",
        "GnR&8l",
        "G-2,E^",
        "to\\vy",
        "Ly3*{/|q",
        "YWW;J",
        "saltLength",
        "D$4;D$H}",
        "0,1[1",
        "CPpfs",
        ")\\_E0Q",
        "bnw[@",
        ".'4KL",
        "C[j(d",
        "hd:Pe",
        "MATeE,",
        "~LkM.",
        "4L4P4`4d4p4",
        "!}>/3J(",
        "W@6F6",
        "$V*ad",
        "6 6X:`:",
        "inuZp",
        "t->P)],g",
        "EAvY4",
        "(jT>+",
        "v?m}y7y",
        "<{>we",
        "Jh`TE",
        "4>4W4I5",
        "mqjY{",
        "V}cl%",
        "{3(A:M",
        "~8Z;+",
        "bL'vW",
        ";0;L;h;",
        "INVLPGA",
        ">  kwo",
        "L_Hcx",
        "\\u],//",
        ",\"\\-;Fr-4D*",
        "WinHttpCloseHandle",
        "(C`mP",
        "#W#Z:",
        "W?36b",
        "_0-*)",
        "<hJFsA",
        "h,DUu",
        "n7|.m5",
        "G(JS@",
        "SRldA",
        "MOTJs+",
        "J_pea",
        "D{n6j",
        "H8Ql-:C^iA",
        "<3 zQrq",
        "*>t[L.",
        "$$R]=G",
        "9hQat",
        "= =0=@=P=h=t=x=|=",
        "ybdN7",
        "r}KfE",
        "k@~kQ",
        "=L$LJ",
        "N{\\,w[",
        ".bgBe",
        "4ggg@ygC",
        "}S&~(",
        "D$hSP",
        "__p___argv",
        "Cz'$-B",
        ":#:I:[:j:{:",
        "io error",
        "zQVqO,",
        "#[jwb",
        "AYw2u",
        "R)){R)){",
        "(%9Hm",
        "687\\7[8]9",
        "no field mod",
        "5?U#l",
        "lLM~v",
        "I0Ag`",
        "E&Ysu",
        "!-,g=",
        "31:5[",
        "gYj7fh",
        "<M!tK",
        "+ eno",
        "3|$@3|$(3|$",
        "3!313Q3a3",
        "=xo*5F",
        "C%7r#",
        "F>/[G",
        "t0f98t+",
        ":)RyU",
        "=/\\@i",
        "Ny?KU[?",
        "3#k[8s",
        "j{cGq2",
        "int_field9",
        "There is negative response in cache while serv connect",
        " <[s LM{",
        "@gr]1",
        "QEP}<",
        "Buffer too small",
        "Zt8pQCZ",
        "jejvj",
        "UIJV0",
        "WhfdJT",
        "_OKxu",
        "R{ 0)",
        "OPENSSL_ia32cap",
        "####'#",
        "RegGetValueW",
        "X509_CRL_diff",
        "1/1A1f1",
        "WIX_DIR_PERSONAL",
        "q)5f=rDV_",
        "z9o]Sqc",
        "k!HxV8",
        ")wN9v",
        "Remove UIFramework2.0 files",
        "w47YY",
        "]EG4dO+B`",
        "Z@)5H",
        "xW5kw",
        "Dv^EL/BuvR",
        "ssl_ctx",
        "^vw3b",
        ">,DV;",
        "7;7Q7g7p7{7",
        "w~v3E",
        "PVVj(V",
        "XSftY",
        "EnumProcesses",
        "6$6,6`6p6|6",
        "_V9UQX#",
        "vJxWT",
        "K.:bH",
        "SB9dF",
        "YV)og34",
        "EQ,e<",
        ")13zwB_",
        "6>v_DFH(y",
        "xY _st",
        "UhNz5",
        "AES part of OpenSSL 1.0.1t  3 May 2016",
        "oolQB_",
        "Ia&j\\",
        "unloadImsinstall;",
        "mv=,J/K`",
        "pnd6\"",
        "LFrw:",
        "<s}/ ",
        "sealRDB",
        "m'(i\"",
        "9DKX<",
        "ZLProduct.Features.pFeature[0].Version failed",
        "XDs/dB",
        "7'tFu",
        "3tyAxT(",
        "S.^?gw",
        "edition: '",
        "OnBeginExec started",
        "t,|2s",
        "(z)D)",
        ",,L.2b",
        "\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 1;\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 1;\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 1;",
        "s\\0{+",
        "j<;T{",
        "Sc#?@",
        "28f99f05-d91b-734f-5f68-9f7fa1c4cb91",
        "Failed to open view in ",
        "pbdJ+E^",
        "/fvu|",
        "zbtwp",
        "PC//W",
        "--<$j",
        "rkI30",
        "SetVPNAtInstall",
        ".\\crypto\\evp\\p_sign.c",
        "Jq*Tm",
        ";N2Gl>8",
        "<CMk<",
        "=&>k>",
        "i9ZVN",
        "M=M5K",
        "DEF_LOAD",
        "}d4My",
        "w&Dmo",
        ">`^+ ",
        "N%U@uk",
        "0zaO\\",
        "O?5vV",
        ".po;Pr#",
        "id-smime-cd-ldap",
        "5$5,5\\5|5",
        "Ev{`z",
        "?w]@\"xdW",
        ";c1Kk",
        "3-3F3_3x3",
        "hAsyx",
        "V?*[Z",
        "S'J@c",
        "dnL&[cB",
        "`u!*J",
        "4-5=5M5u5",
        "BKDi</",
        "2?2d2",
        "vkoLj",
        "t,LdL",
        "[HU(u",
        "4,5j5",
        "qm.BRT>",
        "3&4F4U4o4|4",
        "Wv`5h>",
        "&hts2HQ",
        "e*]3Y",
        "*:+~+",
        "H\"SPL",
        "b6:Xd",
        "D$PPj",
        "9^{7Ha",
        "=%=f>u>",
        "_cV5Dx",
        ",0004080<0@0D0H0L0P0_0",
        "&.$DFP",
        "7c{6\\",
        "DY}7T",
        "iyiLA",
        "\\E6oaD",
        "X509_PURPOSE_set",
        "m^t8?",
        "V[#sO",
        "(;Jat",
        "<*#,h3=",
        "DSA-Parameters",
        "Xbref",
        "3<3q3",
        "8f9x9",
        "RCPT TO:%s",
        "9fn~>",
        "wR'Y%",
        "&nL,Z7",
        "Failed to generate unique key name.",
        "viFf/7",
        "6*7/74797A7O7W7",
        "A%B17",
        "{{XlT",
        "8'9H9",
        "!TEOW",
        "=.DVE",
        "yo//d",
        ":WjUiX",
        "${($N%",
        "5/6]6e6n6",
        "r,(4,",
        "X509_ALGOR",
        "hi9&9m",
        "vf9V,",
        "gmH(Q",
        "\"B$R.g",
        "ECPARAMETERS",
        "=QPkK/",
        "]1GV]",
        "w:`m2",
        "SetClientStartup:  SetClientStartup started.",
        "jrjxj",
        "Y.3?)sD",
        "\"&&jn43",
        "HEO5+",
        "as~Lc",
        ";e~Gf",
        "Failed to get the Component_ field value.",
        "?{/,x|",
        "VQ%!kFP]",
        "o,WT[y",
        "+$+/+",
        "08CW2",
        "Ugt4y",
        "0G1Q1",
        "ChangeServiceConfig2(SERVICE_CONFIG_DESCRIPTION) failed: %d",
        "policyid",
        "PREFETCHT1",
        "q{F$k",
        "B;QUrM",
        "7U8%9",
        "<f6Y)",
        "!pWuXE",
        "_&fLF;",
        "NgON%",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid3552546 No Obligations}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "Program Files (x86)",
        "removeOldVpnFiles",
        "=,=>=^=x=",
        "4=4E4U4",
        ".?AU_Crt_new_delete@std@@",
        "CryptGetHashParam for len failed {}",
        "}/KZe{/",
        ";@3i\\kn'J",
        "z_ Cq'",
        "Gt+zX",
        "PreInstallCheck:  Created an install mutex.",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 2.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 10}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "6w;n{",
        " 0x9b",
        "J.: $Td",
        "6n)cq=LRh",
        "525g5",
        "jU6if\"",
        ".me<UV",
        "Endpoint Security installed",
        "N@a23",
        "Hkk(d",
        "D$ UPP",
        "#Y`hWt",
        "A7CrD",
        ",a{\\&<",
        "Jr4Td",
        "*[APj",
        "VR[x|C",
        "}JckXw",
        "epab_svc.exe was not running",
        "<`=r>",
        "mz*l=",
        "OCSP request",
        "eZhXl",
        "'xPpX",
        "[30Op",
        "3:3?3",
        "[NLxx%",
        "7NXaQ%y",
        "d\\_B(",
        "ON St",
        "jhjyj%",
        ":!:':;:A:Q:W:",
        "b[6L:",
        "4)'XG$",
        ":!:1:A:Q:a:",
        "hYNJC[_",
        "*Y!qgB",
        ":,S%T",
        "Va5,M",
        "9mw[TE",
        "Ru5`e%o",
        ";X;k;",
        "Registry error:  out of memory.",
        "Found FDE upgrade product code",
        "2I3r>\\",
        "invalid signer certificate purpose",
        "607<7J7_7q7",
        "SSL_CTX_use_PrivateKey_file",
        ">1?:?x?",
        "T++PDE-",
        "><:Q9",
        "kk~0vR",
        "ez7/6",
        "int_field5",
        "RC5-CFB",
        "y!61U",
        "Z/rkE",
        "2NAO&C_M",
        "<;<E<W<b<k<t<}<",
        "p(5!p",
        "v )A.A8A=AEA",
        "j%Zf9",
        "+7VGL",
        "2URlL",
        "RO&f%#",
        "VSPasswordRequired()",
        "8;8_8v9",
        "}e$UES_",
        "`!].??Zk",
        "o,SbB",
        "cwH=6",
        "t0QQQ",
        "PKCS12_MAKE_SHKEYBAG",
        "ds_P!T",
        "*yGLEz",
        "*Od*?+",
        "EVP_PKEY_verify_recover",
        "<atz<gt]<lt9<q",
        "7dY?{",
        "elUV\\",
        "07p><",
        "qL4tG",
        "WuWN+",
        "111g1x1",
        "6(646T6\\6d6l6x6",
        "eX;%R",
        "Q}`8\\_",
        "G/XgLn",
        "c?Yz~",
        "2{iWr[",
        ",Xbwb",
        "4.%g/",
        "  1,|6",
        "enable",
        "Xv_dV",
        "516;7",
        "2VuUM'",
        "<woO-+",
        "!*RQ!",
        "T$D3L$x",
        ")U=~_1Y",
        "GykW0-",
        "unknown extension",
        "OS/400",
        "ExtractInternalFilesToTempDir",
        "h|j;F",
        "$@rkF",
        "xport or diversion of certain products and technology to certain countries. Any and all of Your obligations with respect to the }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137 Hardware }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "r*Q^U",
        "9Q:q:",
        "414A4",
        "C-s}\"",
        "[a=E-Pg}79",
        "2=2f2x2",
        "RVWh(v",
        "t>))r~",
        "`Xsr]",
        "1cLnD",
        "ho0|(",
        "deleting license for move...",
        "[PERFMON] killed update thread",
        "Pxrjy",
        "&Nd?+.",
        "b3]<P",
        "?\"?H?",
        "HE1@n",
        "DES-EDE-CFB",
        "\"xs4C",
        "ga6lx",
        "W}jg!<:",
        "7c7s7",
        "3D$T3",
        "3T$X3T$<3T$(",
        "Z*[,YJ",
        "krb5 server tkt skew",
        "T{Sst",
        "!y6m}O",
        "j,0.F#",
        "_DisplayName",
        "cx)$>uFY!",
        "bXo6UUaR",
        "}`L..",
        "QLj1^",
        "7\\7o3f",
        "6FwQ.<",
        "4BP_*",
        "%X9:Yo",
        "QRdYv",
        "SSL_CTX_use_PrivateKey_ASN1",
        "u;j}h",
        ";$;4;8;H;L;P;T;\\;t;",
        "f81]1={",
        "T,S8R7",
        "sp++!<",
        "XY_O)",
        "*)KI@I",
        "N5]Es<",
        "P1AE$",
        "-HH|b",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 10.2\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Third Party Software.}{\\rtlch\\fcs1 \\af1 ",
        "OWONV1",
        "J{eC8",
        "_:mxl>p",
        "?$JI<",
        "ASN1_NULL",
        "y for the Licensed Configuration. You have no right to receive, use or examine any source code or design documentation relating to the Product.",
        "}g}c}e(=p",
        "failed to read remote addresses from custom action data",
        "8~ox:",
        "/Yb E",
        "WuIuL",
        "tKd_E",
        " HSQ>",
        "0RL=Q",
        "kernel32.dll",
        "QueryUmsThreadInformation",
        "|F(OY",
        "X=>z8",
        "7$74787H7L7\\7`7p7t7",
        "393W3",
        "[OSFW] vsdata::OSFWCtrl() DeviceIoControl() FAILED with 0x%X",
        "F4 0>0",
        "s0\\Hu0J",
        "wap-wsg-idm-ecid-wtls8",
        "N/08^",
        "brainpoolP224r1",
        "{Q:A%",
        "Failed to concatenate CustomActionData string",
        "0Tedete",
        "=)=/=:=",
        "\\a\\63",
        "2 2(20282@2H2T2t2|2",
        "-#_1{",
        "6EWfX",
        "Jv/F++,V",
        "n1ly]",
        "?-?A?t?",
        "S2K[$C",
        "sc*Q%4=Q",
        "mscoree.dll",
        "J1v<9",
        ">H?R?_?i?",
        "\\par }{\\*\\themedata 504b030414000600080000002100e9de0fbfff0000001c020000130000005b436f6e74656e745f54797065735d2e786d6cac91cb4ec3301045f748fc83e52d4a",
        ";'aws",
        "JD#rS",
        "NOYy+p",
        "+z@hG",
        "$#mjGx9B",
        "K0O/Y",
        "[C]+s",
        "VX}66w",
        "ci G{",
        "CF<_A",
        "\\m1lw",
        "?Cb7)N",
        "'r2HXm$",
        " Gm`u",
        ">pXzUxn",
        "v@j:\\d",
        "t$$PV",
        "bzgDlO",
        "QCEr_",
        "kW1W)S!kd",
        "0v-(P",
        "$gxo~N",
        "oMinghuaQu",
        "dddddd",
        "\\Le^>",
        "pIN-IK",
        "OQ0^&",
        ",.#=a",
        "@:IiL",
        "0Zm@5",
        "LOAD_IV",
        "=3333w[",
        "3(3D3`3|3",
        "jAjpj%",
        "TZea;'",
        "A<}NX[",
        "@` @ ",
        "WsC],",
        "1aiRj",
        "Guzu?",
        ",v4b7",
        "jgjjj'",
        "jljij&",
        "i2s_ASN1_INTEGER",
        "1M2W2t2",
        "C]K0'",
        ".SF+!",
        "` OEY,",
        "[4\\')J",
        "U]S:S",
        "}TWF:o",
        "/^{xLX0",
        ";8;@;L;l;x;",
        "qrf)j",
        "acx85",
        "?+Q6%~",
        ">V>]>",
        "~~OAt",
        "wIL0P",
        "58Ae^",
        "wJjld2F",
        "%)w|qg",
        "cpbcrypt.dll",
        "QBpH,Q",
        "@Pl07D",
        "ASN1_ANY",
        "Hhc7B{",
        "]@mtA",
        "%s IAC SB ",
        "]\\Do}",
        "5IagT",
        "m-d%H",
        "J`^>?",
        "U-Uu}a",
        "^(Yiy",
        " d Hz",
        "~.IuV",
        "_F_4`",
        "Wyowp",
        "]j,UD",
        "SUg.|",
        ":\"cU;",
        "8/xQw",
        "4|b36",
        "5SG4x?",
        "+tMD/",
        "t;v6{",
        "-&-%F",
        "q(:v)t",
        ",)xV@",
        "is_UninstallIMSecureLSP;",
        "K{B,Q",
        "rMJ%/",
        "aIH\"S",
        "mxY-=",
        "lfzg$:",
        "(V0uX",
        "sK\\tO",
        "U}B0I",
        "illegal byte sequence",
        "?3?R?",
        "SXNET_add_id_asc",
        "7>8p8",
        "CONFLICTLIST",
        "]9D\"<",
        "qsgTd@V",
        "ecE-%7",
        "DIGEST-MD5 handshake failure (empty challenge message)",
        "f@;zn",
        ")boEhJ",
        "uS9D$",
        "2J2R2b2",
        "aXzJG",
        "h2k2m2t2w2y2",
        "\"Sa &S",
        "<I\\8lT",
        "dJFQ2L",
        "[,ZHR",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  110",
        "$\\}Cz",
        "f,O&*",
        "sKQGf",
        "mC,#C",
        "6EjG ",
        "[VSDATA LOAD] LocalAlloc failed: %d",
        "=K=\\=",
        "7/8j8x8",
        ".?AV?$clone_impl@U?$error_info_injector@Vbad_lexical_cast@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "JEr*O",
        "?,eJu`",
        "+y(*:",
        "@^}f6",
        "v!a4tuD0",
        "\"k{sq?",
        "'Uq7\\",
        "_#]/M\"",
        "FEXrr",
        "6`6:#",
        "~'b'h]",
        "<H=6>B>",
        "QPh0=",
        "~1gWc",
        "Zt+B-",
        " already exist.",
        ";K+I:",
        "3Y:F<J<N<R<V<Z<^<b<",
        ";AQ0=",
        "Received HTTP code %d from proxy after CONNECT",
        "AQRJ^",
        "`i\\YL",
        "Cfz\\V",
        "Gau2K'W^.8",
        "Ha[ H",
        "C}MZ$",
        "section not found",
        "RSA-SHA384",
        "0k@\\[",
        "z;\"$V>",
        "4n%#g",
        "<kCqua@",
        "761l%Ag",
        "(p_6t",
        "8T\\^@",
        " 9\",ABP",
        "6Hd$U",
        "^ 'RV",
        "K7*Fb)pr",
        "?FireWallExecuteCommand@@YAJKPAD0@Z",
        "&.,wlY",
        " u.{3",
        "Xjy,+",
        "467G7",
        "#X ^\"!",
        ":Fo/LQ@D",
        "J^mnn",
        ":8:X:x:",
        "NUMERIC",
        "lirbMA",
        "=_cG(",
        "FT51u",
        ">m%6f",
        "jAjqj#",
        "EVP_DigestInit_ex",
        "MAIL failed: %d",
        "SSL_CTX_MAKE_PROFILES",
        "cs4\\UY",
        "xLp|BcH",
        "~#?`-",
        "failed to fetch Registry row for secure object",
        "0123456789-+Ee",
        "6tpD4",
        "=iDbn",
        "k_z^Z7;",
        "l6~grs",
        "EGp?w",
        "boqi!",
        "wR3~t",
        "?Vxqu",
        "1F!X{",
        "hBF ~\\",
        "invalid shift",
        "Caught an error object. Error: %s",
        ";mMKP",
        "%$'\"RU",
        "chT4LE+",
        "d<[Gc",
        "77}S}",
        "RKTeO",
        "JA! !`",
        "\"[>/>P",
        "cwDR)",
        "R$`+.",
        " of the Product or any portion or copy of it.",
        "SB?'G ",
        ")]l2^",
        "k3&20",
        " ZxkX",
        "CEvQ{H>",
        "::;T;e;",
        "te2dN",
        "l[]_^",
        "F8]'0",
        "mFn59",
        "VsDataInstHelperOpenDriver - DeviceIoControl(DIOC_HOOKREQUEST) failed. Err=%x.",
        "C ,J%",
        "5+626=6[6a6o6",
        "$';\\P",
        "NYWiJ+",
        "#{!J,",
        "`(jl(",
        "]k<z&",
        "GUARD_PAGE",
        "Q6N:ajA",
        "m^q1O",
        "= =$=(=,=0=4=8=P=T=X=\\=`=d=t=x=|=",
        "[<|c>",
        "commonName",
        "$$q62",
        "nl-be",
        "!h!_?",
        "Lpa|Vo^#",
        "V],|pW",
        "wUkO4Sd",
        "Q/BE^",
        "}!a)zjI",
        "Dk6%^C",
        ":I;7<A<N<",
        "\"K\"H=NqD",
        "%2;2B",
        "q@yOXX",
        "sra(\"G",
        "=j=}=",
        "cast5-ecb",
        "RSDSS",
        "{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'02.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li2160\\jclisttab\\tx2160\\lin2160 }",
        "TrueVector driver: Data thread startup event timed out.",
        "api-ms-win-core-file-l2-1-1",
        "nRk4|",
        "^XTLd",
        "EPS64_DEVICE.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "StopCipollaServices started",
        ")6sF3",
        "$/(iF",
        "E|nCkF/NN",
        "(wR~X",
        "VqPiX@",
        "#zG/q",
        "Php1G",
        "4DM`9",
        "UojyxC",
        ";D$ v",
        "4%4M4:5u5",
        "K@hHZ",
        "@_^][",
        "_&q9W",
        "Hi%%i",
        "mI?\"g",
        "$k}$Q",
        "RSA_private_decrypt",
        "q!NI0/",
        "= =@=H=P=X=d=",
        "w>`Bj",
        "g+cgI~",
        "Y7!G<T",
        "0T[<+].E",
        "9N<t#",
        "`3f7:",
        "C%C-C9CECICM",
        "w|KsR",
        "S_k_s",
        "start the helper process using Helper::start().",
        "C5Hr]~",
        "CAST part of OpenSSL 1.0.1t  3 May 2016",
        "RWe}W4",
        "el&(DA\\'",
        "7Y=t1",
        "L^<4b",
        "0.0Q0Z0",
        "c;BZc",
        "EPAM_BeforeUninstall",
        ">4>M>f>",
        "jj\"Q1&",
        "Succeeded to run %s",
        "3%3+343:3C3O3U3]3c3o3u3",
        "KF9LW",
        "Nk#_=",
        "4#4I4O4n4t4",
        "J-h'`:",
        " dG*k ",
        "\\T!xq",
        "RSA_padding_check_PKCS1_OAEP_mgf1",
        "<+<m<r<z<",
        "_09\\y;",
        "u@s$PF",
        "hj(5W<",
        "4F3D^",
        "id-it-encKeyPairTypes",
        "N^@6\"",
        "cipher or hash unavailable",
        " You are solely responsible for adequate protection and backup of the data and equipment used in connection with the Prod",
        "?(?3?>?G?S?_?x?",
        "siI:6",
        "(8*BR",
        "|8h.k",
        "<9!l\"8\\",
        " name=\"smime.p7s\"%s",
        ";/;6;?;H;v;};",
        "\\J1SO)",
        "h![Gzj",
        "W]0;%b",
        "mI~~6",
        "`NTsw\\",
        "U\"fqG*)8",
        "~F:kmx",
        ":GN]e",
        "Is-&>^*5",
        "4/KIR",
        "wrong number of fields on line %ld (looking for field %d, got %d, '%s' left)",
        "?$?,?4?<?L?X?`?",
        "tlsv1 alert inappropriate fallback",
        "uU\"Tg$",
        "BLV}_",
        "7E8^8h8t8",
        "<!%z*DZH",
        "w3AHh",
        "fM MLZ",
        "< <(<,<0<8<L<T<`<4=<=D=H=P=d=l=t=|=",
        "~{h*S",
        "RSA_memory_lock",
        "000000000000",
        "ad0i+e",
        "7U8q8",
        "VfarG",
        ";v1wt",
        ":hOd~",
        "rR;K'l",
        "de-at",
        "0 0(000<0D0d0l0t0",
        "kiOz^",
        "\"Qa{>",
        "w:A,`",
        "`:AJ%",
        "4W)DK",
        "a$z/a",
        "ic*=+",
        "[zU3IDM",
        "1xE!;",
        "?eaDY",
        "^/M?%",
        "failed to extract binary data",
        "yuj;h",
        "D3?(A",
        "2 2@2L2l2",
        "{TV2/",
        "mDkP1",
        "+L$@QRV",
        "}_vJQ#",
        "@m(lj_U",
        "X.`30F",
        "|C$mTw",
        "bad magic number",
        "595H5Z5{5",
        "e\"^b1+T",
        "XU(t[",
        "SSL certificate verify result: %s (%ld)",
        "\"fK=LJ",
        "1!161",
        "e+:IOS6;_$Q",
        "(fLF^T+",
        "3$3,343<3D3L3T3\\3d3l3t3|3",
        "/A8'YpZ",
        " undefined type %s",
        "DlHC~",
        "m0^Ck\\",
        "UI|c,",
        "<C<a<y<",
        "*e&(6",
        "A\"gA5",
        "^hXpX",
        "J[OV[",
        "<c7gU",
        ";&eA<d",
        "jFex.4",
        "\"TphC",
        "tUXZ,B",
        "bad fixed header decrypt",
        "8.9.1.0",
        "0^1i1}1",
        "moY'F",
        "`4d4h4l4p4t4x4|4",
        "*aMyq",
        "]sMzx",
        "?f}>K#",
        "Lf*Vj",
        "nteluM3",
        "MYzoP$",
        "d,2G2r",
        "8=g#h",
        "{C1d3",
        "BaW+e",
        "=@<PIf4",
        "Q@&&p@",
        "Failed to backslash-terminate path: %S",
        "vAgQ~",
        "q[+8$fY",
        "=I>/O?",
        "CheckInstallConditions:  No sufficient privilege to perform install.",
        "#R*NA",
        "2#2)202H2W2]2",
        "J:t|L>",
        "\\W,L1np",
        "6%7c7",
        "E(~bh",
        "3t-5G",
        "r0[cW",
        "a\\,UL",
        "`r&2]",
        "%\\ZVL",
        "[Ok`q",
        "wRjxk",
        "6K\"|pg",
        "u#,&^",
        "$!>3B",
        "C{;M\\n",
        "c=o45",
        "<KlfbM",
        "F,KTt",
        "d v@0T",
        "hHqRL",
        "#S8:,~",
        "N1D6[",
        "N}ofvzk4",
        "SSL_CIPHER_STRENGTH_SORT",
        "e4`q:",
        " }I*@",
        "7o`fj$",
        "2p7a>",
        "0 0@0H0P0\\0|0",
        "81878@8K8f8v8",
        "6>7L7T7g7u738",
        "jqy`'",
        "w=.od",
        "4A}.O",
        "3(30383D3L3l3",
        ">(=T4",
        "JY!oAk",
        "1!1+111A1T1f1u1",
        "~CVFH+",
        "tr*#/N",
        "7^=*+",
        "}t+So",
        "gY+H;0",
        "_o^Fwj",
        "#JJ5Jj",
        "$n=hb",
        "Failed to open process with id %d",
        "/|Kt)B:",
        "\\bIB8",
        "g)v6*",
        "+^m#<t%x",
        ":K;L<\\<m<u<",
        "ghK,c2",
        "2X3o3",
        "I@%|aFA",
        "bmGgmyOkfN",
        " hBU^",
        "#AKK0W",
        "#IR_)",
        "8#949X9r9",
        "t$$SSS",
        "@L!&g",
        "gn$:Nv",
        "64]Np",
        "6xa'P",
        "%jod>",
        "BEK/l",
        "I[=r?",
        "ZKIc_.",
        "QOS6j&i",
        "'waoz",
        "ktit!",
        "o=azR32",
        "}Jl/^^",
        "=4>w>",
        "D+(44$",
        "\">=6.V",
        "[VSUnloadServiceUI_logon]",
        "Wj5_f;",
        "e6iC]",
        ")nhaV",
        "z#cda*",
        "700WP",
        "W-gQTm",
        "Vd.Kh",
        "GH.iR",
        "]L>Ci",
        "x}KPY",
        "Rw-\"BD",
        "q|$)&",
        "Connecting to %s (%s) port %d",
        "Nm`lT",
        "YMYC4",
        "hp=(z",
        "]0Z:Y",
        "\\e.Z9",
        "IYg=mW_",
        ",9za@,@",
        "h$66^",
        "fdVoC",
        "J`8,)>",
        "T*U[G",
        "?(5`j",
        "SetHandleCount",
        "iB\\@d",
        "stopEndpointConnect",
        "tEi6*",
        "<&nye",
        "@ ``@",
        "K0Q_I",
        "(P45i",
        "T.{{-LZ\\f",
        "\")h?\"",
        "Server returned nothing (no headers, no data)",
        "}J;z`_",
        "_IgqO",
        "SUtCt",
        "2.LoZ",
        "(Q6EAyj",
        "Aulme",
        ">\"?}?",
        "MmMu=qKy",
        "W`V{U",
        "\\NL/^#",
        "CPSUITEVERSION",
        "H*_9\\",
        "UE%A!",
        "?z>L~~}",
        "^d,#S",
        "`=_;Lz",
        "!CuZjKK",
        ":_LUt",
        "nkiQV|",
        "Sl Y%0",
        "zagr{`",
        "Fm@;d<D",
        "QQQQQQQPQQQ",
        "y`$xbyy",
        "4NY]]}1",
        "=yZ)$$",
        "<#t8uxd",
        "gN,N5",
        "U+UvU",
        ":gy2,",
        "Failed to set product mode from product mode code",
        "v[@n ",
        "NJ_wH",
        "tejqhd$#",
        "?M254",
        "modulus:",
        "m[L{|",
        "8Wga{V;",
        "fIJ|HM:",
        "osinfo.cpp",
        "k^;[i",
        "0{g n",
        "8r=ec",
        "8\\8i8",
        "b0/0U",
        "E2v`F",
        "J(FE^",
        " c+(Y",
        "unmatched '}' in format string",
        "9&9B9^9z9",
        "pZ*VaAQ",
        "id-it-implicitConfirm",
        "869C9_9",
        "G~FH4",
        "+\\S=`",
        "eeH%|",
        "L$8WVQU",
        "4B5M5",
        "?p%db",
        "<?!FK",
        "HE9:p",
        "6[7t7|7",
        "}X\\#:W",
        "qu`nq",
        "T1.;S",
        "R=w;*|q`",
        "IU%gU[",
        "4#4+464<4G4M4[4",
        "_^tWh",
        "Ye<Cq",
        "/T+*,",
        "SNw|*w",
        "dNC`A",
        "jNjVk\\5\"",
        "wfAmX",
        ";I<a<g<w<",
        "G-GOGZG|",
        "D$ _^][",
        "3|$,3|$",
        "j@j M^\\",
        "2j2y2",
        "CnZ+&",
        "[WinFW] GetWFStatus, failed to get local policy, error=%x",
        "_|2AG",
        "B[%h*",
        "tsc|r",
        "$|x#E[",
        "9*:Z:",
        "595H5S5X5]5x5",
        "zie;I",
        "=Vi5x",
        "B1 ZG",
        "\\f1\\fs20\\insrsid9516106  or replacement with a refurbished part/unit}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  for the Hardware Product under the type of warranty service Check Point designates for th}{\\rtlch\\fcs1 ",
        "Fs4rWE0",
        "1n%c/",
        "W{j:6p",
        "C!.M= o",
        "ny6^-",
        "eKn?z",
        "`84c:",
        "value missing",
        "6*7b7d8f9",
        "-ylt*R",
        "K1An2q",
        "DueS;#",
        "ZSJCi",
        "zr,zm?",
        ":S>SBSDSFSJSLSNSPSTS\\S`SbSdS",
        ":%'pK+",
        "L$<3L$,",
        "0(010<0",
        "c|Pkse",
        "a1\\xv",
        "{} [{}({})]",
        ".?AV?$moneypunct@_W$0A@@std@@",
        "2dV2:tN:",
        "U Sq{",
        "JLC_ALL",
        "g/>Q;",
        "858@8",
        "J&v*z",
        "='>o>",
        "Stopping existing product",
        "=b}?ZF",
        "JECXZ",
        " hu SR~ ",
        "q'@2e]Fq",
        "^r:l=",
        "p|4McD^?",
        "Dvkzd",
        "^7oX@",
        "nH:M2s",
        "EC_GROUP_get_pentanomial_basis",
        "##'\"r",
        "gyOx{",
        "q?)s|",
        "P{TqP",
        ";);E;a;};",
        "'nFo}z",
        "QSO{n",
        ">@?p?",
        "[J_L_O_.",
        "Vj7hD(",
        "Am7Wu",
        "?w%L&",
        " -%J:",
        "ynzgf",
        "],R*d",
        ".O g5G",
        "[`B'A",
        "erD)1",
        "%%)$f",
        "$bBP0",
        "&fBd[",
        "ZFoxDw@-T7",
        "%*sAlias: %s",
        "<C/lhD>m",
        "5rm.7",
        "Jbh):",
        "|Z3TK",
        "c+$v~",
        "}~7IAa",
        "Winsock library not initialised",
        "x5l6Gw",
        "jY-fe",
        "tzciB<ni%3",
        "#.Y8GJO",
        "\\ChkpEap",
        "$bS/J%",
        "#*&fj",
        "v\\F<!",
        "t_,IJX7",
        "NEbPp0c",
        ")xFG6",
        "{\\fbimajor\\f31541\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}{\\fbimajor\\f31542\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}{\\fbimajor\\f31543\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}",
        "`1Dm0",
        "`!.Cl",
        "+G`c\\",
        "+a1ir",
        "@}:,&",
        "dP39k",
        "iwc:I",
        "LI&u76",
        "-^s5M",
        "&PK9E'",
        "Access violation - no RTTI data!",
        "3L$T3L$8",
        "9w0Sd",
        "Z7k@1",
        "y[2:r",
        "1E)WjU",
        "\"D|~d",
        "L$0QP",
        "jq%p%T",
        "?ZkWa",
        "ttc.\\",
        ")T0^J\"dW",
        "{vYy2+t",
        "}`q-?",
        "Mdtye",
        "FPVWS",
        "=;|W|Bj",
        "lGPA2f",
        "[VSINIT] VsWow64EnableWow64FsRedirection: File redirection %s",
        "brainpoolP160r1",
        "mZ4}V",
        "rmutil.cpp",
        "???P?",
        "6B6a6{6",
        "digest err",
        "Failed to stop driver %s",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 2.9 }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid2388238 Check Point Data Loss Prevention (}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid883884 \\'93}{\\rtlch\\fcs1 \\af0 ",
        "-i`\\4I",
        "78=R)'",
        "V[w/J",
        "\\4X'^",
        "^Mhz6|",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
        "FG;t$",
        "^*`AXVtP",
        "6-Bgi",
        "qw\"xL3",
        "Z_NwQ`E",
        "4Mp<U",
        "w '(t8G",
        "(\"*C`",
        ",mnYf",
        "emEfgT",
        "4!414A4Q4a4q4",
        "3_qup",
        "eKvcv",
        "=4zSZ}",
        ">0>@>D>\\>l>p>",
        "!baQQ",
        "%,Rsx&",
        "uB5@k",
        "4+WAW",
        "\\zauninst.exe",
        "wf@%*R",
        "))ud>",
        "#Hg1AI",
        ",eAKe",
        "$sFE%2",
        "LGqMD",
        "uu@eK\\M",
        "K?y86r",
        "/iPf#",
        "343@3`3h3p3x3",
        "0!0.0:0o0z0",
        "ECDH-ECDSA-NULL-SHA",
        ".\\crypto\\bn\\bn_recp.c",
        ".?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@",
        "dE|n)",
        "V+v+MV",
        "y&Dz\\",
        "gS'PeT",
        "PKCS5_pbe2_set_iv",
        "&&\"Kn|",
        "j~^8}CE;3S",
        "yurL1Se",
        "3$323>3M3R3",
        "Vg}]w",
        "S,qJp",
        ">iu\\v",
        "IyOq*",
        "OCSP Signing",
        "xq@[(VY",
        "id-camellia256-wrap",
        "EEtN0#",
        "V)+X|",
        "/EYE8",
        "+RHv6",
        "i/Pn_",
        "(<oEB",
        "/vd(i",
        "XI1T*",
        "U+K>\",",
        "invalid null pkcs12 pointer",
        "CRd1~",
        "=XR 9",
        "q>D9B",
        "{h$;J",
        ".c[<G",
        "Z[[[\\[]",
        "K(Rq^",
        "\"F200",
        "9+999G9U9h9o9",
        "56vj>",
        "zde12<mDQ",
        "@&uP+!y",
        "EZ9hE",
        "gT1 y",
        "?o%1(f`^jg",
        "9<9q9",
        "cY/qAR",
        "K]@?N",
        "plHRZ",
        "(lR6;",
        "(X_$x)",
        "5Twyt",
        "}?K.bh",
        "REw%,%",
        "9'9b9k9",
        "\\,0X\\",
        ">,>0>D>H>`>d>h>l>",
        "}XuDx",
        "NJFVsS$",
        ".?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@",
        "7AA>{",
        "bh4cA",
        "}A9.AW",
        "10me8",
        "<Q#HB",
        "wXPqrI",
        "|FxDD",
        ";D<H<L<P<T<X<\\<`<d<h<l<",
        "314A4Q4a4q4",
        "N/X=:}",
        ";by^Q",
        "CryptProtectData",
        "33'd>p|",
        "Lnr8<",
        "6cYX;v(",
        "^CA@%",
        "D$|PW",
        "Created",
        "8I9Q9Z9z9",
        "8,9t9",
        "} p2c",
        "Mjmi+Z",
        "3X(RkD",
        "8BYqHDc",
        "s^%iI",
        "sr-ba-latn",
        ".\"*ZT",
        "Is1^[",
        "O{hRPR",
        "id-aca-authenticationInfo",
        "0K2g2",
        ":&:D:",
        "16WiA",
        "InstallDirDevice",
        "FAj9;",
        "0Na'7+",
        "? o%s)6",
        "InstallProduct:  InstallProduct finished.",
        "jpj~j",
        "%SS00%",
        "tV62V!k",
        "h:f*h",
        "MOVNTSS",
        "5`5k5",
        "&Adf<O",
        "&r%[?K}V",
        "D>O#}",
        "87C2o",
        "Failed to get address of proc MD5FromFile()",
        "PABSD",
        "];;H`T",
        "Tq3A{",
        "`;l}$",
        "38Bmb",
        "Invalid share handle",
        "r3+9k%",
        "3G=lr",
        "*q9j,\\#a",
        "rEJ6i",
        "u,j^Y",
        "^)SQ;,",
        "f*+,$",
        "\\$8UV",
        "7e8}8",
        "*}={07",
        "o6 \\7",
        "CDJwu+u",
        "1NHi;",
        "m768696:6;6<6=6=",
        "(Empty suboption?)",
        "=y^F=",
        "o1kg?a",
        "4#i:K",
        "EEh(D",
        "`]/L&",
        "9>9};v=",
        "T7c,Q5",
        "^nwS:P",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13200219 \\rquote s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  TAC will sen}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "7*'\\F4^P|",
        "<<H!Q{",
        "tftp_tx: internal error, event: %i",
        "failed to set attribute: %ls to value %ls",
        "SAe{#",
        "?Q>i'",
        "8<8D8L8`8h8p8|8",
        "quMfq",
        "o0L)]}&",
        "w97`WU",
        "\\dsfainstapp.exe",
        "K2K5u",
        "}]n?Y",
        "[N w@#7",
        "eVw6R",
        "r\\f;u",
        "don't know",
        "0123456789ABCDEF@|M",
        "6DcB_s",
        "N&Du.",
        "F67{j",
        "qU4gl&c",
        "B5jWq",
        "&6DV#",
        "+L$$QWR",
        "tDw8)",
        "Failed to send SOCKS5 connect request.",
        "X9=za",
        "*:4^*",
        "(.x#e",
        "]D@O.",
        "MPSADBW",
        "j3:p:",
        "/[=dz",
        "L$,VW",
        "798W8p8t8x8|8",
        "L2e?v",
        ".k4E\"",
        "]3uPy",
        "(l@y5",
        "*Wo*0",
        "S1KDc(",
        "qb_R%",
        "jtjjj&",
        "5d8a314d3c94e018c8de1a8fa94fd05093f43672e23d06af89927ac06762a049136785c10607758d9053d965021d62d6f6804fc08f86e4bef210c352c144dbab",
        "O1K8&",
        "=;G-Vxt",
        "{au4m",
        "NYx9$",
        "5.0.556.149",
        "\\oNeG",
        "k?lh)B)",
        "f+.<$hf",
        ".JZ!8",
        "}Zmm8",
        "8D820_6e",
        "Y[]5b",
        ".\\crypto\\asn1\\a_bool.c",
        "U7;..N\\;1q",
        ",2JT5hG",
        ",72x181",
        "6N7h7",
        "9Z:c:",
        "\"%Ow7\\j",
        "W{~Q^",
        "VWh$u",
        "ofJq\\>",
        "EnI`I",
        "/N!G{",
        "Y#r@K_H`",
        "8(\\gD+",
        "!{!D4",
        "Tj9fq",
        "o6OV!",
        "`SiS\\2",
        "9t2rHs",
        "missing export tmp dh key",
        "(P<8G",
        "lARE3y",
        "VAwqee",
        "ccore64_ds.sys",
        "Intel;1033",
        "QhH|&",
        "ka+&F",
        "v?(8g",
        "contentType",
        "1JnraD",
        "~WswtA7",
        "wlRk(#",
        "aN?ZG",
        "t6:,H",
        "J\\\\#!",
        "t}I3W~S",
        ": :%:*:::?:D:T:Y:^:n:s:x:",
        "CONFIGFILE.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "]X2?Cj>iw",
        "a!j8e",
        "m~Qyx",
        "qLb\"8",
        " yCb(",
        "lmdci.exe",
        "2{E]&",
        "# 3!>{q6",
        "Couldn't connect to server",
        "HgkYRc",
        "E'A@`q",
        "\\,7LU",
        "Thread32Next",
        "StopURLFService_rollback failed",
        "kT&{H",
        "jvjgj",
        "^%u6e",
        "[DUMPFILE] zipping .old file",
        "EC.J`",
        "7bCh79g",
        "ZGayO",
        "%H : %M : %S",
        "1'1B1r1",
        "jJEi!w",
        "8H8l8",
        "-|y=a",
        ".xsNs",
        ";7<><P<b<",
        "^zI@v",
        "_'ee~",
        "\\cs19 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\i\\f37\\fs26 \\sbasedon10 \\slink5 \\slocked \\ssemihidden \\spriority9 Heading 5 Char;}{\\*\\cs20 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\f37 \\sbasedon10 \\slink6 \\slocked \\ssemihidden \\spriority9 Heading 6 Char;}",
        ">$>@>d>",
        "V.Wb$",
        "VSInstallerLogoffEx: succeeded. ",
        "y2|sW",
        "basicConstraints",
        "wT?Rp",
        "v^SnIf",
        "S)=Qua",
        "TVv)*a",
        ",xat*/\"&",
        "PX 721",
        "ZK\"A/l",
        "api_ms_win_core_namedpipe_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "o|gT9\\",
        "(m-[~",
        ",z>Z]f",
        "wl44qZXv",
        "zF)lF",
        "5R.:yT",
        "d@\"7(",
        "<x~i'6",
        "iEB^;",
        "=yOE6m",
        "TW:[@",
        "}/-R~jl",
        "Do not schedule deletion",
        "N9`Qs",
        "!FL|t(",
        "KaPQC",
        "\\F=SgK",
        ",ENF\\",
        "ksvgh",
        "CUjypi",
        "9;\" 90",
        "XY{q2",
        "W:]du",
        "Y9>2b",
        "<>Onf",
        ".?AVSS_TrayIconWnd@@",
        "Jk>`z",
        "HL%cF_5",
        "`%~PO",
        "S{[}P",
        "2>?$?",
        "*#*.E",
        "&07+{",
        "O}R5@",
        "u=29a",
        ":.|,H",
        "]vthI",
        "fLn29c",
        "D8DDf",
        "s_i~5",
        "Failed to allocate buffer for output.",
        ";KD)UK",
        "!%I7Hb",
        "9TZ'E",
        "HIErF",
        "s`JL}",
        ".Gk`'",
        "_Beb#M",
        "Ao`&:",
        "singleExtensions",
        "4=YV9E)_",
        "7~P=n",
        "9B7t$&",
        ".\\crypto\\evp\\evp_pbe.c",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 This License Agreement (the \\'93Agreement\\'94",
        "\\i\\fs24\\loch\\f31506\\hich\\af31506\\dbch\\af31505 \\sbasedon10 \\slink8 \\slocked \\ssemihidden \\spriority9 Heading 8 Char;}{\\*\\cs23 \\additive \\rtlch\\fcs1 \\af31503\\afs22 \\ltrch\\fcs0 \\fs22\\loch\\f31502\\hich\\af31502\\dbch\\af31501 ",
        "0H2L2P2T2X2\\2`2d2",
        "kq8|nGL",
        "+h}C0",
        "IazHKB",
        "Check Point Secure Access is already installed on this computer.  It has been protected with an administrator's install password.",
        "3L$P3L$",
        ".M38u",
        "/I,&'",
        "aZ.`~",
        "JAdJB",
        "%(QtH",
        "|yYkl",
        "M#1A!",
        ">;s8j",
        "'}-d+",
        "_zjUA",
        "zhvvn",
        "686@6`6p6x6",
        "&>j4R`",
        "a$6*<",
        "@1AT6",
        "aVl*y8",
        "gO'^l",
        "#&P9h",
        "ul49Q\"-nE@<",
        ";l<Z=d=q=",
        "g-c!q",
        "l>cjfo",
        "*`73VI",
        "yb5'q",
        "t0#ud-E(",
        "lkrW`",
        "BN_BLINDING_update",
        "q+7%6(]",
        "7(7,7<7@7P7T7`7p7",
        "N0D;@EC",
        "aes-128-ctr",
        "IR jel",
        "#T^~y",
        "tC97u?j",
        "digitalSignature",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sb40\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "W*B$j>",
        " E gB",
        "n*\\CB",
        "IAE1erR",
        "CHECK_BITLEN_DSA",
        ";><k<",
        "<,<H<d<",
        ")?VZR]",
        "tG]B1",
        "*'W3M",
        "-!4>#",
        "F<s6 ",
        "RJVL/",
        "holdInstructionCode",
        "s>8J;",
        "G;|$l|",
        "sR,lsO",
        "BI{sJ",
        "f:f9t%yW",
        "ncsEPI",
        "889G9Z9w9",
        "D_|yQ",
        "[4]*`0",
        "\\lsdunhideused1 \\lsdlocked0 envelope return;\\lsdunhideused1 \\lsdlocked0 footnote reference;\\lsdunhideused1 \\lsdlocked0 annotation reference;\\lsdunhideused1 \\lsdlocked0 line number;\\lsdunhideused1 \\lsdlocked0 page number;",
        "QKp.A",
        "S}3:b",
        "_\\2X?",
        "deleteFolderAndFiles;",
        "QVWj ",
        "x04Fs",
        "jBjlj",
        "prime2:",
        "RFb.&",
        "(+EKCk",
        "12bq|",
        "WEQE)",
        "LBdn,&",
        "UuRw*",
        "ModifyUpgradeTable finished.",
        "$BuYY",
        ";+;@;\\;`;d;h;l;p;t;x;|;",
        "5:Y}(D",
        "JS]4m",
        "wG@rh",
        "<ZtC<-t?<+t;",
        "D$4US",
        ";w&yj",
        "t$HPj",
        "rIf;u",
        "X509V3_EXT_conf",
        "bmgNbSH",
        "TK@{T",
        "LdrUnlockLoaderLock",
        "SufWm",
        "$bw{`",
        "GTVYGZ`",
        "+V`JiF8",
        "PUf3G",
        "T!i9\"s",
        "S[a8Y;",
        "$3!]d\\]!",
        "33CRm",
        "zG&gM\\",
        "T7Q8M",
        "|AGl7",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Kaspersky Anti-Virus Personal",
        "EC_POINT_is_on_curve",
        "Z,k'0",
        "dEU/&W",
        "H0j]#",
        "- pure virtual function call",
        "9.9\\9o9",
        "AJH)NC`;",
        "r.H2EE",
        "(%10Q/GO",
        "7%(_q",
        "k%MhF5",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Licensed-server\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "JXxgw",
        "ab&ps",
        "eP+Hh7",
        "?Z;zmj",
        "sect571r1",
        "_%0ba",
        "ke^3z",
        "FISTTP",
        ";serm",
        "PBSZ %d",
        "IMAGEPATH",
        "d&I?,",
        "0W0r0",
        "+A15v3",
        "Ts~}y",
        "_ay.:*r",
        "?@?`?h?p?|?",
        "%i7C\\`aI",
        "<'<<<I<U<^<d<j<t<",
        "JVXND",
        "*;D$@~(h",
        "545K5V5",
        "949a9",
        "%s%s%s:%hu",
        "7Qw3y",
        "f}|4Y",
        "+G~5G",
        "Bzhv<",
        "9 9(949T9\\9h9",
        "d`\\,_",
        "_\\SPy",
        "Ty;Iz",
        "'piT*",
        ",~&2'",
        "0+1L1",
        "\\b\\caps\\f39\\fs20\\insrsid5854202 ",
        " 0x62",
        "O5_Qh",
        "LAUXx",
        "unsupported requestorname type",
        "<j0%&",
        "JJ&>m59",
        "6X607",
        "@-E$I>",
        "eFs&$",
        "A-#N(",
        "#bgJU#",
        "keylen <= sizeof key",
        "s<:eO}",
        "VWhx*",
        "pTc6[g",
        "?mKPAD",
        "ASN1_UTCTIME",
        ":cm3i",
        "[N<JgG",
        "\\nrAZ",
        "+CA.);f1",
        "ssl3_digest_cached_records",
        "6$606P6X6d6",
        "vU|W:Bk",
        ";eiACH",
        "[K'VG+L",
        "kGSOl",
        "vsdata95.vxd",
        ";$Zt\\(",
        ".?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@",
        "#mC97",
        "jejpj",
        "Ch TK%(L",
        "w'\\#\"",
        ":O,|<b",
        "+TUD7B",
        "E0vci(RT",
        "111M1i1",
        "S:!>Bp",
        "G^LjV",
        "l&u#[/v",
        "7;*kvz",
        "c&xnQ\"",
        "~q5z?",
        "<))99YY",
        "6,6>6I6\\6k6",
        "0@1o1",
        "VWjPh",
        "^9Qma",
        "-B}kc?",
        "LtKC?B/",
        "KJO,|",
        "{>GPn>$",
        "TTUk*l*m*",
        "6.v8[",
        "Connecting to port: %d",
        "HM0;sEv",
        "defective hardware components}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid16581128 ,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid15169477  shall be that Check Point, subject to the terms and conditions of this Section}{\\rtlch\\fcs1 \\af1 ",
        "\\3\"5+",
        "D7C'Q",
        "6FmxY",
        "=y()T",
        "5 646D6L6T6",
        ";b;3=|=",
        " [NX0j",
        "bad ecpoint",
        "^,Fj]",
        "H5#h!",
        "iGP>J",
        "iKg/V",
        "fRKK\"9iD`",
        "9/Hrb",
        ":[oX4",
        "e#SqVOI[",
        "^*m,9Nge",
        "&~>g2",
        "`p'!T#v",
        "YR[:(",
        "0F1R1j1r1",
        "5&:m9",
        "lNdv`",
        "i,6}*=",
        "*w=^(@8`",
        "mkNf:a",
        "rjTno",
        "<cNC9",
        ")@v@s+\"",
        "W[ko\"7k",
        "0&0?0X0q0",
        "update_site.gif",
        "(@(zL<",
        "Z$-`-",
        "m*&KH%",
        "\\nss4DQ",
        "jQnra",
        "D$,WP",
        "1^1i1",
        "*Xu7y",
        "XWXKqK",
        "#*\\_.",
        "b`jZ}-",
        ",iOyO2",
        "IZF \\T+",
        "RemoveVpnFiles",
        "1*-?.",
        "M1 *M",
        ",0c0o0",
        ",76Br-",
        "5C7O7",
        "VWuih",
        "h\"/`>\\",
        "userNotice",
        "1^5|5",
        "|7r]h]`",
        "^aGdh",
        "M!XRc",
        "2{ y5",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 year from the date of }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid13775897 activation of the Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "r8f;u",
        "Q$\\7z",
        "dLS=)",
        "]`)7.H",
        "a^;Ag",
        "II{25",
        "_cW/1",
        "q+%=$",
        "1)@[&",
        "v\\,Wk",
        "nQ8j,o",
        ")!>P>b",
        "]t3uY4D",
        "Ze3WY",
        "\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 5;\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 5;\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 5;",
        "v)n~o",
        "jAjej",
        "[BX+DI",
        "aDTMu",
        "PEM_F_PEM_WRITE_PKCS8PRIVATEKEY",
        "n8=\\SIw",
        "'~k{?n",
        "hPJtK>",
        "b*?1.",
        "5J&nB^",
        "8P\"gt",
        "W5;k&",
        "2S4%7G7~7",
        "F3Ye,",
        "eS({C^/",
        "u szA",
        "RegisterSecureAccessDSM:  Registered SecureAccessDSM.dll.",
        "M\"b$m",
        "RsP-E",
        "NN7?|",
        "D$`PV",
        ";8;\\;|;",
        "FY]Lv",
        "a4fEqXL0",
        "`P^d1",
        "E9l$ }",
        "Y~5dl@N",
        "KdxiR}",
        ";|_1o",
        "Ex/#B",
        "CryptAcquireContextA",
        "e'SPB",
        "SIZE %s",
        "t!5%DP",
        "7#lhB",
        "7EN,+]<OO)",
        "q^=>'5",
        "checking user defined external files to copy...",
        "fNzK`",
        "\\$tUV",
        "5$5/565V5\\5b5h5n5t5{5",
        "9F<V<!=1=D=v=",
        "H}JL9hq",
        "8Nc'R]R",
        "ki!S^",
        "he-il",
        "/DxU2\\",
        "5*7nNyg",
        "y]LMk",
        "application/x-pkcs7-signature",
        ":rnQr",
        "@! J0b",
        "OriginalDatabase",
        "hF) Dd",
        "F$2Zh",
        "IqC:^",
        "xyCc@&",
        "3$4N4V4",
        ":0_L$",
        "!ZgfN9`",
        "$NG~v",
        "UTvJ[",
        "Z\"_{ar[",
        "fOkG{",
        "error setting certificate verify locations:",
        "y--n]-5",
        "5!5:5S5l5",
        "F<Yvc",
        "e2{1A",
        "JcqD1M",
        "V&aW-",
        "Hdo1e",
        ".?AVbad_function_call@boost@@",
        ":3:^:",
        ">d3<W",
        "failed to write delete element action indicator to custom action data",
        ",c a<G9L",
        "404@4D4T4X4\\4`4d4l4",
        "Error creating registry key:  ",
        "t#mzq",
        "not proc type",
        "&:;t:",
        "N1'XN",
        "InitializeSRWLock",
        "#kx8i",
        "tDIP,",
        "sha1WithRSA",
        "UserPWRequired() found ProcAddress for \"VSPasswordRequired\"",
        "XE-EDEE\"",
        "_)'1>/",
        "Leftovers after chunking: %zu bytes",
        "dJ=c5",
        "Gj@56",
        "`p</A",
        "OutputDebugStringA",
        "W4rF9C",
        "l$0CU",
        "RSA_verify_PKCS1_PSS",
        "KM09B",
        "W{m=68E[",
        "cK]V_",
        "*LSbLll-a/",
        "9|tXhX",
        "GoG42",
        "9(9/9V9\\9g9",
        "sW]r)",
        "i2P1.7",
        "r9m|e",
        "K[OEI",
        "missing '}' in format string",
        "!e61I",
        ",-!Yx",
        "ProductState",
        "|QkhlrA",
        "id-cmc-popLinkWitness",
        ":ev/7",
        "T`MM`a%7/",
        "Policy not found or failed to be decoded - continue install",
        "}kpv!",
        "StartServices started.",
        "f#n;e+",
        "kD 'L",
        "e4$yJP",
        "DZSI3",
        "Tu3;]",
        "krq}+",
        "x]]JH",
        "T$$;t$",
        "IsZoneAlarmInstalled",
        "a@Q&O",
        "ZLProduct.Server.Url failed",
        "pN5@B=",
        "@`Ghc",
        "aP{pDU",
        ">7/m4",
        "t*QUV",
        "hu!B$",
        "cT>><0",
        "sf.aJ",
        ">\"!Jh",
        "l>Yk\"",
        "@(p;4:",
        "~ry-Y",
        "2Knzk",
        "d \\  An",
        "*pTWE",
        "MsiDigitalSignatureEx",
        "T;Z/s>",
        "'(t,J",
        "jkz^-{\"H",
        "= =(=0=<=\\=d=l=p=x=",
        "j-^ o",
        "0!161H1a1t1",
        "lsjz=Y",
        "%_t6qu",
        "XDm%h",
        "fh#|$(",
        "==mkj",
        "X#X1w;",
        "jlhDB%",
        "DSO_get_filename",
        "7!7,7:7A7G7b7i7",
        "?D?t?",
        "novry",
        "FEp/k",
        "client finished",
        "9<:Y:i:",
        "!72yd\"",
        "Lx>}g6h",
        "klifsdk.sys",
        "no certificate returned",
        "5<\\V8iZ",
        "9#989=9",
        " 3x(<B",
        "M^WY~",
        "sd#I1",
        "J4Z4j4z4",
        "&`!.z^f",
        "}co!Z",
        "len <= SSL3_RT_MAX_PLAIN_LENGTH",
        "UPGRADE",
        "|\"4oiF",
        "IG+|#VW",
        "T>Dk@'a4t9",
        ".O9ii",
        "F5nJm",
        "Failed to get reg key for secure object: %ls",
        "zxVLH",
        "O?h[m",
        "GWwfyl",
        "<\"I),S",
        "O uAO4",
        "@I4qD",
        "qpA.@.",
        "&;OQw",
        "ProgramFiles",
        "m]*S+7[d",
        "n(i`t6",
        "RQ9A'<",
        ".?AV_Ref_count_base@std@@",
        "j8*w!",
        "5r2\"$",
        "Found Check Point VPN upgrade product code",
        ")=lC#\"",
        ">->4>H>O>q>",
        "jNlmnopqr",
        "e0c0a",
        "2<fBX\\",
        "Dcxmj",
        "T$D3L$h",
        "ERROR: Unable to clean temp folder",
        "PY*2r",
        "5-7,&",
        "^;Xwf",
        "7bV~q",
        "R>e0a",
        "T yk}G",
        "0\"1m1",
        "t$ SWU",
        "f?NGSmMxXk",
        "t$@Rj",
        "RaD3n",
        "cnTBs",
        "/uxk(a",
        "OET[P",
        "*b$ws",
        "q2-k?",
        "Phd|#",
        "QsRCSCTCUCVCWC",
        "%4zd#",
        "PatchDiscoveryVPNCA",
        "UX3fj",
        "Q_uF*",
        "6 6%656:6?6O6T6Y6i6n6s6",
        "ZLERR_MISSING_ROOT_SIGN_CERT",
        "WBfI@",
        "n=l\"V D",
        "$|NLL",
        "N@~'`",
        "chozU",
        "5HU?h",
        "1fwV_5g",
        "NH<!e",
        "DisableProtection RC=%d",
        "dLkWa",
        "1>jk'",
        "uWE_k",
        ">Y?a?x?",
        "kHIw)",
        "p`Jev",
        "R1=PL",
        "j}|\"D",
        "w6M/L:c",
        ")e0$.",
        "tL4 tU",
        "OPCkl3",
        "c.3H%PM",
        "klbackupflt",
        "J0O0T0Y0c0}0",
        "mc$S`",
        "N%rhH",
        "Axpz\"p",
        "8VS++",
        "&\"#Mu",
        "8 w1]",
        "LoadPolicyFile:  LoadPolicyFile finished.",
        "%9]M+i",
        "Udh6A",
        "?t'aE",
        "{!mgL7",
        ")mZ5^-J",
        "EC_GROUP_new",
        "{\"dKK7`",
        "Qp-19",
        "8$\"|X",
        "wCL|a",
        "89to#c",
        "jYZzq",
        "$h'zv",
        "?$?N?s?}?",
        "CC.'<",
        "1q7AG",
        ".?zI*",
        "Missing dll to unregister.",
        "DigiCert Timestamp 20210",
        "BFM\"J",
        "vKU@%",
        ";b&q{",
        "THM*Nl",
        "<%o*p",
        "5#zEi",
        "W=cX+",
        "%$Rl0",
        "<~#r.[S~",
        "k/I+t#",
        "?$lc.*",
        "n{HdzX)",
        "VR-I*",
        "S}k~T_/",
        "\"#%%t",
        "wOnO&",
        "$Jfnf",
        "/qJo&L",
        " zXIX4",
        ">*=8P",
        "O{1#o",
        "P9t$LsJ",
        "Application Path",
        "~Z'LS",
        "RemoveOldFirewallFiles(%s)",
        "YNB)o",
        "u2OxRk",
        "|Y-8Vv",
        "CS}y'",
        "8P8U8",
        ",-''-\\",
        "5hME\"",
        "'?s4wo",
        "crVP=6",
        "SS8IF",
        "wIawx",
        "/.S!qY",
        "certificate chain too long",
        "6TZ=r",
        "b%';P9",
        "-)p>1",
        "n~Frr",
        "$cexWmL",
        "ZIb#n",
        "T7D7/y",
        "OnFreshAfter:  InstallProduct",
        "L<maB_h",
        "\"Pw9|",
        "g~O{w",
        "(\\5#LL",
        "Z*eH[^",
        "tzShp;!",
        "!qNY3",
        "%ePE[",
        "=W%,X",
        "Mg([#",
        "NJ2\"v",
        ">yv3!",
        "4!4y4",
        "=o$zVXx",
        "xG(OC",
        "iF=Gi",
        "^v,8]",
        "S-WDh",
        "]jn9,",
        "=/=D=Z=g=u=",
        "f?5bt/s",
        "l^gc-",
        "Zvgbs",
        "=iL'0",
        "mQ]nS",
        "%L:J+",
        "WaitForThreadpoolTimerCallbacks",
        "uPj`hh",
        "F\"]+8V",
        "Q?jD.",
        "x-Z|.{5",
        "$2O\"4/",
        "P:c?n",
        "Al2I%JY",
        "S3)4X4",
        "unknown group",
        "y[Ue`",
        "[LICENSING] subscription expired",
        "zh-hk",
        "+FL+NL",
        "lpsDIx",
        "|EBdXk",
        "2_6x\"",
        "p}_*sh",
        "ya_PW~",
        "B_ty}\"Y",
        "xr:Qj",
        "goY(&",
        "DIVPS",
        "k3uFiv2",
        "othername:<unsupported>",
        "ReXy\\",
        "KERNP",
        ".Bm6mw\\xj~",
        "olnWo",
        "OK\\|(",
        "~q_?-",
        "R1)BC",
        "N*=:Ne",
        "0qd'F",
        "owner dead",
        "=8>Q>",
        "SDDIR.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "2Q2_2{2",
        "mj{d6",
        "0)010o0",
        "4>^-v~",
        "otherRevInfo",
        "M/lM`M=+",
        "FXYoyF+b(",
        "This is Standalone mode",
        "Vsdatant_opt.inf",
        "]m)>x",
        "$f} X",
        "syLF7",
        "n&9-#",
        "Z$\"WA",
        ">4>8>h>l>",
        "\"*\"\"#66",
        "3uH&|",
        "R6IRI",
        ">u?|?",
        "6\"f@w<s",
        "2;2E2x2",
        "HM?e,(",
        "7X87]",
        "th#~=",
        "L@MEZ(",
        "{d*2yc",
        "3$Fzz",
        "W}9D*",
        "id-smime-cti-ets-proofOfCreation",
        "ncUz*",
        "#;g(6",
        "2{!s_\"",
        "Proxy Certificate Information",
        "0<0H0h0t0",
        "MQINz",
        "3\"3'383=3d3i3z3",
        "`~-KJ0",
        "232L2p2",
        "sr_ConnLogo.png",
        "T*sq^",
        " 9R+n",
        "L$,_^[3",
        "=+=:=`=o=",
        "(EQ)^",
        "HEIgJgKg",
        "O(Ik[",
        "xS*K-s",
        "|$,Ph",
        "(cAu;<[",
        ".?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "!dz,H",
        "1g2B3d3",
        "H8nn,*",
        "v|hgl]",
        "G2i~K",
        ",:w(r",
        " 'nd ",
        "b*|,gP",
        "0!1A%#",
        "oQwgLdv",
        "GOST89",
        ".?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@",
        "q]BcZN",
        ";$;/;M;X;o;",
        "*1)XIw",
        "d/bZb",
        "t$\"hYc",
        "CustomActionError.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "%:nP+",
        "operation not allowed in fips mode",
        "= =P=X=",
        "&OJ.%",
        "Ku o~",
        " /T_;",
        "QGew*h",
        "Y4\"&U",
        "'l27BbU",
        "MxLMn",
        ">#[A@",
        "q'h|L:bu",
        "invalid closing tag name",
        "7llug<",
        "DY5\\l",
        "Zva#i",
        "1i!PQbUH",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Secure Uninstall\\ChallResp",
        "\\[ gl",
        " Ge'7",
        "AES_XTS_CIPHER",
        "DP{L/",
        "{5p\\H[",
        "+b|dH",
        "Y6#XG",
        "V#RT5",
        "j+]k\\",
        "digest failure",
        "7!7,767>7G7O7X7c7n7v7Y8b8h8&989M9e9p9y9",
        "G5c;*",
        "L$$PSS",
        "F-<gt",
        "bzQoX;",
        "w&qHf&",
        "oOTvT",
        "3`j(h6",
        "$Y(*uQO",
        "D$0UP",
        "7UUp_IP",
        "s?iHI",
        "7,8R8x8",
        "rxfAs`",
        "X&N&v&X$xM",
        "y4bFp",
        "bq<qv",
        "data too small for key size",
        "G=oKN}w",
        "pc=Vb",
        "SSOClean",
        "]p/4d\"zaCt",
        "T2uhP",
        "Ok%4<",
        "\\3]s]",
        "051>1",
        "3X*Dik",
        " \\vWD",
        "HHI7%",
        "jmPnW",
        "E0hhq0",
        "262t2",
        "242<2H2h2p2|2",
        "H+\\GF",
        "gxsi2L",
        "=XI~]Jd",
        "n\"'OLe",
        "y~xI0e4",
        "jAjuj!",
        "c,Quh",
        "gzUO,A",
        "FD9o0",
        "D$XSUV",
        ":=:`:n:z:",
        "GET_CERT_BY_SUBJECT",
        "failed to get %ls",
        "|,{o##",
        "rpbH,",
        "(Ljm`",
        ".CRT$XCAA",
        "U7m*[",
        ";!;C;i;r;",
        "Q.t!d",
        "|Y.XI",
        ".#+hk",
        "3O4U4Z4u4",
        "TempFolder",
        ">*W7m",
        "4q&h\"",
        "QSUVWh",
        "w-NHy,",
        "or@|<&",
        "?qq6`",
        "kMk#j",
        "iH$My]",
        "UAw}~",
        "1#141q1",
        "`nH$o",
        "'pBv-M^",
        ">ZI%0",
        "2-d:g",
        "i;1bP",
        "Email address mismatch",
        "()L-g",
        "$@:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday",
        "yq]95'",
        "Uf}=,",
        ".?AV?$clone_impl@U?$error_info_injector@Vptree_bad_data@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "VZI%1",
        "[y[QX",
        "n,<vG",
        "<!=6=H=a=t=",
        ";F<U<s<x<}<",
        "4)b;0[",
        "Fs[k'",
        "]5NC7",
        "%sAntiVirusMonitor.dll",
        "7&7F8T8s8",
        "wU}<jo0",
        "sHG?AZ",
        "Successfully deleted %s",
        "xU@ULUVUdUlUtU|U",
        "em-5e",
        "p/.)J",
        "v!1kD<jc",
        "~gL?3x",
        "EmF(!",
        "$(ErZ",
        "YM>$Rp",
        "MsiRebootActionScheduled",
        "!w5?XC#K",
        "$06lE",
        "%l%F%T%b%h%n",
        "DI~16",
        "1*3J4",
        "MLq?w",
        "p[YHT",
        "]dgx-#",
        ":9;P<",
        "iJrWy",
        "!!Up:",
        "#iD*l#",
        "H/P1g",
        "av%0?",
        "(Y#jTzF",
        "h8Iae",
        "1#f}%",
        "080@0H0P0\\0",
        "u><&;",
        "'R,x}X",
        "9n(;D",
        "TS_RESP_verify_token",
        "\\BMr=",
        "KW*}/7",
        "Folder",
        "g\\ `2",
        "JOC-N,",
        "V.cN'U",
        "4F7X7",
        "X509_NAME_ENTRY",
        "2Va6G9",
        "j0jPjpj",
        "ECKEY_PUB_DECODE",
        "UY$Uy",
        "|Hk&]",
        "7T7|7",
        "3^-wO",
        ":P:q:",
        "yB^{!",
        "uYPPP",
        "nE#j^]",
        "Nvkxx(",
        "4QRF\\W@",
        "[]'_o",
        "o[vbN",
        "nU,)O",
        "4\"h-U",
        "PN8+S",
        "L!8i5",
        ".$nxU",
        "  In purchasing a Product, You are acknowledging that Check Point may need to make a determination for You on the potential effect the identified programs may have on Your system. You agree that the Product may automatically delete }{\\rtlch\\fcs1 \\af1 ",
        "9fHj2",
        "LDAP local: Cannot connect to %s:%ld",
        "BIO routines",
        "CANT_READ_VALUE",
        "?YxZ?q",
        "a{97(",
        "{ja-k7Nr4",
        "*+cn@f<i",
        "|TA4D",
        "~ruZ~",
        "n42lnY",
        "X_ltF:",
        "H\"/Vd",
        "#5R*e",
        ";#;f;s;",
        "Ssh)$",
        "RInI)",
        "s4% .",
        "[:\\G+",
        "S7xrSS",
        "q9R8Y\"1",
        "$u&P\\",
        "2(2/2;2H2o2v2",
        "L/4&~6",
        "@M/_rT",
        "VsDataInstHelperSetProtection - DeviceIoControl(DIOC_DRIVERCTRL/DRVIO_SET_PROTECTION/FALSE). Result=%x.",
        "zEA/O",
        "DPNCm",
        "ZOM(dN",
        "durdg",
        "kV 7oM",
        "h5G-b",
        "\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 6;\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 6;\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 6;",
        "-xR*6",
        "^r+DzH",
        "l-nb}i",
        "&5@1,4",
        "9 9D9L9T9\\9d9l9t9|9",
        ")v*NS",
        "TG>GX",
        "/xlXI",
        "cg[lH3",
        "}vmutmX",
        "-Wcef",
        "82D2P2\\2h2t2",
        "&9ijW",
        "Z^24;!",
        ";ylyM",
        "6<x2%y8",
        "szProp",
        "*O%NR",
        "e|pWW",
        "BMSH= h",
        "jmjdj",
        "l[<y}",
        "6`[Aow",
        "$u$y`",
        "gxYUZ",
        "]7n)~",
        "t+Whp",
        "Z6go\\Y",
        "<at.<rt!<wt",
        "@kj44",
        "zSSSSj",
        ":E;^;",
        "GkJet",
        " $CRp",
        "1!212Q2a2",
        "RegDeleteValueW",
        "<0r6<9w2",
        "We}*@l",
        "UwYvb",
        "39%N>nl",
        "qcStatements",
        ".*RM ",
        "L#\"YT",
        "tlsv1 unrecognized name",
        "Ze2Zh@",
        "4-4B4y4",
        ")`ghc",
        ">$~R0b",
        "0y@Dh]3=",
        ":Dk_P",
        "he.$Y",
        "6$6,6<6D6L6T6\\6d6l6t6|6",
        "i/iC]-%",
        "BX5xw",
        "path too long",
        "1K142",
        "hb) C",
        "SKIP USER: Can't get user hive path",
        "7[8K9",
        "2k{C!",
        "N?X*2",
        "EN9TX",
        "!v P?",
        "!471l",
        "i}1\\4",
        "N;Kf>(P",
        "F`g4+?LEy",
        "[%s %s %s]",
        "1A@kJs",
        "%s%c%08lx.%s%d",
        "Bad PASV/EPSV response: %03d",
        "CheckCurrentUser",
        "/Qcm.O\\",
        "1c7\"9+9",
        "767G7|7",
        "lf$n9[2G",
        "V*^cE",
        "ECDHE-RSA-DES-CBC3-SHA",
        ")>@,=",
        "BAN_PROTECTION_FAILED",
        "unknown object type: %ls",
        "m1H,V;",
        "(dtF.",
        "WZ0\"kL",
        "UNDCZ",
        ".8HVM@",
        "X l^y",
        "CancelAScheduledReboot:  CancelAScheduledReboot started.",
        "VIDEOTEXSTRING",
        "C5^HW!Y",
        "[qZ3\"",
        ",BqEa",
        "[IPADAPTER] GetIpAdapterInfoNew failure %d",
        "t9 9e",
        "818c8",
        "~@JHd#",
        "deY,5",
        "oU>]p1+",
        "^)r.;",
        "%TDQ1",
        "FmK!EoD@#",
        "#\"#<rk^",
        "dvuvU",
        "C\"QFR",
        "BN]yn",
        "@?[O'",
        "R$QyG",
        "kdAt'",
        "oJ'}t",
        " ~:0$",
        "P@`fG(",
        "5)5I5i5",
        "_ep{h",
        "7T7[7",
        "3#3+373]3",
        "< <$<;<",
        "<$=t=",
        "787c7",
        "l~V3Yy",
        "Wnm2fZb7b:y",
        "]eVk\\C",
        "8^~g1P",
        "^^$cCb",
        "Vc@Ex",
        ".W3\\a[`2Jk",
        "N$3p^",
        "}#'oX",
        ":h*J0",
        "Y^v3cQ",
        "~JVWU",
        "3>vZ$",
        "={7\"g*:",
        "ofQ+Zt",
        "~AJG&+",
        "^Q,Q0Q1",
        "n)+m::*",
        "@;R@6",
        "k]aW\">",
        "t|rKE",
        "th,uA",
        "CryptAcquireContext failed: %d",
        "1,262S2d2y2~2",
        "KA4`I",
        "e4[g&",
        "<*<0<T=]=",
        "default.toml.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "?@TdY",
        "siC^m",
        "New and old files have the same MD5 value. %s will not be replaced.",
        "{{(~b6",
        "ri<Q6C",
        "\\$@UV",
        "ZLDEVELOPER",
        "\\ucp_eps.exe",
        "D$(jPP",
        "StartCpdaServiceInMinDa",
        "4_^][",
        "WDStatus error %d",
        "M\\S#/",
        "            imagename=\"%s\"",
        "jyjoj ",
        "pe;|3!#",
        ":=V+W",
        "8z#f\"\"m|y",
        "Gwlb+",
        "X509_REQ_to_X509",
        ";);-;1;5;9;",
        "Dvw>'",
        ">x>H8L",
        "2(222:2G2U2",
        "onetree",
        ">3>Z>",
        "|M!o|:L\\",
        "w7~+p",
        "IsRebootSuppressed:  REBOOT=",
        "8\"8C8J8U8",
        "~WErG",
        "Bs$Ob",
        "gz2-GP",
        "1\"2,2i2w2",
        "wQ82,",
        "D$49D$Xt",
        "03@4d",
        "\\07Qf",
        "(ss|8",
        "M/CE&o",
        "G;q>rG`M",
        "yGf/=5T",
        ".^H]EabKaC",
        "TI#%S",
        "SELECT `Data` FROM `Binary` WHERE `Name` = ?",
        "YPCWM",
        "3L$43L$(",
        "nC5Iuw",
        "z?z2#",
        "253?3",
        "\\'02\\'07.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li5760\\lin5760 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715",
        "J Lqn",
        "2ddc#;G!",
        ":Ry#9",
        "C$BKi6",
        "Srv6^",
        "q9Be$",
        "#?VA0C6(D",
        "uCP 0",
        "Netscape Data Type",
        "bio not set",
        ";,;L;",
        "tOO,3",
        "3({'3*{+3,{/3",
        "1$1,181X1`1l1",
        "sl\\6G",
        "xEPW5",
        "QD)>/l-",
        "Done waiting for 100-continue",
        "JIcuik",
        "NTE R",
        "id-GostR3411-94-CryptoProParamSet",
        "failed to allocate string for shortcut filename",
        "t-)<FG",
        "a;H:i",
        "#I9d\\0",
        ",HrGW",
        "Y3'GV",
        "DA<{G",
        "qQHPX",
        "S]m/\\",
        "||]&P(<v",
        "a\\7+&",
        "_increaseStatus@12",
        "Kz~B_(",
        "H`Mu5",
        "\\'02\\'01.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li1440\\lin1440 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715",
        "qr[d8",
        "@]d$f",
        "`(]2c",
        "HH`h)",
        "SEC_E_UNSUPPORTED_FUNCTION",
        "q)Dx|",
        "Y'Sb1",
        "-D_r9C!",
        "t 6-|\"nX`",
        "HZ<J7",
        "8ZiO_",
        ".{MQ$",
        "=^=i=",
        "D_I~1",
        "PROPERTY_NOT_FOUND",
        "Connect me again please",
        "Af`hs",
        ";51\"CO6",
        "./r3/",
        "a0;O[",
        "]zfd~",
        "fj6hi",
        "?\"7F@",
        "(Sf M",
        "\"=8aq",
        "sJ14-6",
        "IMAPS",
        "'B8$v4",
        "&2r`$",
        "e+-f@5O",
        ">??{?",
        ",U-U/",
        "Rzc]?",
        "M?_)e",
        "N4gqq",
        "?WcNH",
        "Ut\"6)[a",
        "%7->r",
        "setpwinst ",
        "Z;,\"Q",
        "<C41 ",
        "UUPUU",
        ".\\crypto\\asn1\\f_string.c",
        " GetLastError() returns:  ",
        "fM&iQ",
        "xbxj@TeN1b",
        "SetMemDump:  DumpFile =%SystemRoot%\\Internet Logs\\MEMORY.DMP, CrashDumpEnabled = 3, LogEvent = 1",
        ".?AV?$_Node_class@_WV?$regex_traits@_W@std@@@std@@",
        ")s'L\\}(",
        "$20{}",
        "D$tj@P",
        ".\\crypto\\x509v3\\v3_ocsp.c",
        "UX<~b",
        "JRN3}",
        "RESETCONFIG",
        "/F9 ,",
        "th-th",
        "\\Redistributables\\",
        "vPA`!E",
        "V@l`#}}",
        "@U:$e",
        "ZrZ[XDFA",
        "&8?c?",
        "^Yw]Z",
        "iu!=<Qp~]",
        "1C2y2",
        "HZdKx",
        "<!fuE",
        "MAXPS",
        "blhn$",
        "FOiGL",
        "4U{X4",
        "fz*k&",
        "9:\"<o",
        "dC]J7 Y",
        "GV6%xa)",
        "eps_endpointBannerBig.png",
        "Y3sH~",
        "~l,N'",
        ".\\crypto\\rand\\md_rand.c",
        "rGX3w",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5453543 seven (}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid12985423 7}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5453543 )}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "@##j,",
        "TZ\\&V",
        "F8BMH",
        "o~\"} ",
        "invalid format string",
        "b-G&!B",
        "!nVA$`",
        "+,.qu",
        "id-pe",
        "~(o9%",
        "PKCS8_set_broken",
        "MGvsP",
        "s~k;>",
        ":$:T/",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "CoTaskMemFree",
        "536a6v6{6",
        "i PTE",
        "NO_OFFICE_MODE property is 0 -> return false",
        "Yp[U?",
        "a- co",
        "YBi/c",
        "WIX_DIR_RECENT",
        "Z=]'j",
        "XWKZ\"\"(",
        "&-acc",
        "14 (default)",
        "P5GV1",
        "vb5dT-",
        "&bq0My",
        "endpointDisconnected.png",
        "=c}m:",
        "ermitted by the terms of this Agreement, and no license to the Product is granted to any government requiring different terms.",
        "2K2D3X3r3",
        "1U]l;",
        "_q0*\"X",
        "g=<b:",
        "ChangeWSCSVCStartupType",
        "EC_POINT_set_to_infinity",
        "> >$>(>->1>D>H>L>P>U>Y>",
        "/!b?x",
        "R:P\"u",
        "jX_V[",
        "k:U}X",
        " If You are a Managed Service Provider, the Products are licensed to You for use by You to manage the functionality of the Product only for the operations of Your Service Customers. You are responsible for the compliance with the applicab",
        "Ipi1E\"J^",
        "uWbi(",
        "=(=,=",
        "0rJAhi",
        "545]5d5",
        "BHo:P@?",
        "PMADDWD",
        "ZS)A{",
        "c`XVc0",
        "{nBNu{",
        "/CYL}n",
        "YI=#v",
        ">\\>.O",
        "KB~OZ",
        " q.]E",
        "uVI@II8",
        ";!;B;T;m;x;",
        "6`y5N",
        "9ife^",
        "Wh C%",
        "0cf03ac1a5193be4cbb921cd0b495fd054b5bd0f530c1931a3f7eaf9f7af9e3f45c70f9e1d3ff8e9f8e1c3e3073f5a42ceaa6d9c84e5552fbffdeccfc71fa33f",
        "7(7I7a7",
        "PKw[g",
        ".QE}#",
        "707L7n7u7",
        "]8)l;k",
        "6%|+d",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5186676 and/or }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7940874 restrict access to }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "K$%v}{b",
        "qza/XO",
        "}vd'x",
        "J\"s`}",
        "bh{KK",
        "-n#\\u&",
        "4_i#:",
        "d4KR,",
        ">rrkt",
        "4A4n4",
        "1a}<W",
        "F4Nz\"BY",
        "F}u!\"",
        "Rc3|T",
        "sb&jH Z",
        "?E|_FgfZ",
        "{2/To",
        "]8CGe",
        ">I?}?",
        "3~Oz3",
        "EhE-E6E>ECe^A",
        "_mL;ckZN",
        "1!2V2",
        "eWIX_ACCOUNT_LOCALSYSTEM",
        "E!,WXh",
        "\\=R$,",
        "Cannot APPEND with unknown input file size",
        "$;u;K",
        "1}enW",
        ":O;];k;y;",
        "/1/eB",
        "j~'ep|",
        "WP}&R",
        "9L9x9",
        "%u, dwSizeDigest=%d, pNodeDgst->m_Length=%d",
        "]z4MG",
        "Vws~C",
        ".\\crypto\\x509v3\\v3_skey.c",
        "Failed to delete WcaVerboseLogging global atom.",
        "u\"^_]",
        "ToolInit",
        "EPewx",
        "DLFCN_BIND_FUNC",
        "SSL_CTX_new",
        "<z13l=<",
        "m?\"-t",
        "f3ZKM",
        "384X4",
        "CloseThreadpoolWork",
        "z8$~s",
        "ycE\\i",
        "GIUh,JNW",
        "+b9)F\"",
        "*s_9T[C",
        ":$:-:B:O:p:",
        "f \"g!_",
        "vQ2SYc",
        "dOi,'",
        "5<gvL",
        "SIRUv",
        "Couldn't start InstHelper",
        "313y3",
        "s$~DH",
        "Y*mO0",
        "5\"696R6k6",
        "@4[]}",
        "RSA_EAY_PUBLIC_ENCRYPT",
        "fr-CA",
        "regedit.exe /s \"%sScvProxy-64.reg\"",
        "P1zt{",
        "Winhttp.dll",
        "f1Y)c ",
        "!~F:#",
        "% %y-",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\string_path.hpp",
        "@AGyqy",
        "Sq\"]p",
        "3h3y3",
        "zIw^v \"",
        "J*ezbu",
        "It7;\"F ]Q",
        "fCVg^",
        "OfZ^}",
        "-GZ^0",
        "q6dPD\"",
        "$ae[j",
        "[G/i9`",
        "%+,tI",
        " 0H#AV",
        "df`Zg",
        "QEGlzAg",
        "485?5R5",
        "n3L$@",
        ":&:g:",
        "gHsy0",
        "filename too long",
        "T ]r\"",
        "D$LPj",
        "Brr*&;",
        "55>q5",
        "'C{8}.",
        "Otzj@",
        "FeatureVPN _MaintBefore",
        "i5V#/",
        "E!ZM|",
        "hM9uB",
        ")^h>S",
        "-7.Uz9",
        ">Y^pS%K",
        "sDn=~",
        "L^foT",
        "7h8y8",
        "SLbPj",
        "ASN1_INTEGER_set",
        "&w'@Z",
        "<xmltext>",
        "l$H3l$",
        "NETWORKPROTECTION",
        "PFRW:",
        "W9VhvD",
        "TW-k2H",
        "WIX_SUITE_TABLETPC",
        "B0TPF>",
        "]Qvi\"",
        "2-242;2R2Y2`2",
        "90LYV",
        "W8^0u:",
        "K08;5P",
        "e~QwP",
        "dsaEncryption",
        "EnumSystemLocalesEx",
        "dLAD<.",
        ";-;;;F;Q;\\;k;r;",
        "C|s+K",
        "/z[1ZE",
        "PojA<",
        "QueryDosDeviceA",
        "7!7A7a7",
        ">6X**",
        "map/set<T> too long",
        "4]5f5",
        "#rVmF* (",
        "X0\\0`0d0h0l0p0t0x0|0",
        "^ >G*",
        "Y/<=E",
        "'-<d~",
        "T{Inb",
        "D$HPS",
        "CT*|m",
        "7TY!n",
        "/S!IO",
        "$?_gDz",
        "%8r(d",
        "BcjBT",
        "8b>XG",
        ".PUB&q",
        "I]QEQ",
        "nH7Vac.",
        "tbAKR",
        "8$u-9",
        "D&<jc",
        "c%_?$",
        "sHP2c!",
        "ZH,=Ip!",
        ":=:a:x:",
        "H*6zU",
        "GetTraceEnableLevel",
        "MGQT`",
        "nested_transaction_",
        "<LB9N",
        "&'EF~",
        "'#_INEf{*",
        "<ruleset name=\"runningruleset\" start=\"onstartup\" stop=\"afterstartup\">",
        "-vjE5",
        "):s(hT",
        "4Z*ZSe",
        "6Wlle6/k",
        "283X3x3",
        "xWc!E",
        "N+,,e",
        "\\u=OH ",
        "x?hA!3C a",
        "O>I%]Db",
        "5j=4o<",
        "GetCkpOldGina",
        "itstc:Oo,",
        "37u$f",
        "{yi1V",
        "PWVUS",
        "klgse",
        "KnNWoJ",
        "f}2!*[",
        "6|F:c",
        "9n1S}",
        "nXI2r",
        "invalid bit string bits left",
        "nZB_P4",
        "ceL5\"",
        "aes-128-cbc",
        "2A<_/Mf",
        "NC?<G",
        "NULL-MD5",
        "T~OXu",
        "f9[YLu",
        "3ExV^",
        "?&?U?",
        "j$Dd2",
        "{^<%^",
        "}!7K^",
        "Digest",
        "[YOkm",
        "L8Clf",
        "[4S]A",
        "t/j=[f;",
        "9b8oA",
        "o'O4*7",
        "R3D>[J",
        "EoWve",
        "DO_DIRNAME",
        "0 0$080<0L0P0`0d0h0",
        "h\\1!8",
        "Z)EwNTd/t",
        "-!yl^f",
        "E ,cD,*",
        "[L?K4p",
        "U-t#v",
        "rA@ec",
        "qQi *",
        "L:M>M",
        "Y9sY~k",
        "yQUYV",
        "UiIOg",
        " w7r7r/",
        "@X} 0",
        "NI,Y:",
        "[nHcF",
        "wrong version number",
        "PxlRM",
        "lCOcr",
        "YBF4X",
        "*Y0%Mr*",
        "%d,%d,%d,%d,%d,%d",
        "Y#}T9",
        "publicKey",
        "Filesystem error %x: %s",
        "WsN>U,",
        ";=<L<",
        "KCCsI",
        "dO0wa",
        "k$l\"[[",
        "I<(ZR",
        "A7a#h",
        "Gs{<`d",
        "QpW-Q",
        "7KA`s",
        "+hm\"L~F",
        "i3D\"_",
        "*t8nu",
        "K~?iJ",
        "/v~tl",
        ";-;Z;j;z;",
        "[]>p|",
        "`';Q<{",
        "-a~]p",
        "x11pn",
        "KNur=\\",
        "031G2",
        "ISSETUPFILESCOMPLETED",
        "A? 7>G",
        "Y,g[p",
        "m\"qn+",
        "D$ PVW",
        "gB:+;",
        "Lc>i ii%",
        "u8XY{",
        "1G1f1x1",
        "q 3!b",
        ">h?m?r?w?",
        "h/fMa",
        "\"\"vf[",
        ";';J=",
        "woPM=",
        ".CRT$XPA",
        "0$040X0d0l0",
        "`eB|5pL",
        "PZFJg",
        "H2*HX",
        "Db^6H",
        "*$+E,E-EvE",
        "({$&6",
        "~_~>/",
        "]B)I!M",
        "W3{fgU",
        "C7Ku[&a",
        "C+N*?",
        "2!212Q2a2q2",
        "3L$\\3L$",
        "Asn1HeaderLength error: type ID  > 30, we do not support this",
        "~:%MN",
        ":v*V#",
        "5tm+km*mxm",
        "y}!z[",
        "8M{~g",
        "SOFTWARE\\Data Fellows\\F-Secure\\BackWeb",
        ">*>@>f>x>",
        ";@;<<",
        "Configuring VPN settings (1 of 5 tasks done)",
        "r<rtue",
        "\"1kV7",
        " [/cd./",
        "WXH(0B8H",
        "=C>I>",
        "545G5{6A7T7^7e7l7s7z7",
        "VsAew",
        "read function returned funny value",
        "k`r,$V",
        "|-\"e[",
        "0QOa$",
        "Stb;X|#",
        "d?!N'x",
        "y~ym*",
        "<NajZ",
        "GzK]#4",
        "#Y>A)",
        "ZG\\$?",
        "b(l6z$",
        "?&q|/m7",
        "jP$qU>",
        "w/d|5",
        "\\zonelabs\\vsmondll.dll",
        "QVWjDXj",
        "#hUA%j",
        "n#U[uIIB",
        "d<G<E",
        "[WinFW] GetWFStatus, got the standard/private profile instead",
        "$)0m.",
        "CQh4QT9",
        "h$@&hHb",
        "8NbUv/",
        "AES(256)",
        ";N<T<Z<",
        "5T5{5",
        "|a|nh",
        "WIX_DIR_INTERNET_CACHE",
        "5<n}r",
        ")v>w3",
        " [oH^",
        "OmgA.o",
        "\"s{pj",
        "4K5n5",
        ".(>cp",
        "\"rT+oFP",
        "pX)/>",
        "%ynWIz",
        "v(CP<Q",
        "name constraints minimum and maximum not supported",
        "CoInitialize",
        "V(x{0",
        " new[]",
        "No1JL",
        "?0?[?",
        "v.&{$",
        "(unknown)",
        ">yatx",
        "ZmmGu",
        ":Jy~U",
        "MonitorSetDWordValue",
        "f@]4p2Me",
        "%s PARAMETERS",
        "YNB>gEx",
        "3??9,",
        "T%D!C?",
        "hbJ*(\"",
        "\\6i=P=",
        "nkrD>",
        ">->F>_>x>",
        "51565;5",
        "R&/\\^",
        "#XB5pVjv",
        "&-hCt",
        "RoDv)O",
        ")wu2(7",
        "vKp?(",
        "CustomRestartCountdown",
        "/^xDq",
        "PgOddx1",
        "sOS9O",
        "63a/0Wt",
        ".CRT$XLA",
        "LdYo,",
        "mcIp8",
        "M`g39",
        "0M1T1l1",
        ",9}LZ$p7",
        "vPU#~",
        "    Name=\"ForceField.10.",
        "HD8M3",
        "RE>' ",
        "Lj\"pB",
        ".v3<Z",
        "ErE<H",
        "#wI)4",
        "7o'b+^/q",
        "-u5!C",
        "nD!vIsg",
        " Y5W$",
        "c2i_ASN1_INTEGER",
        "V1Qq=&",
        "2T$(3",
        "064Ap",
        "6\"6(626K6T6^6w6",
        "v%M -",
        "cX1{#-",
        "2W`r|",
        "id-smime-aa-ets-contentTimestamp",
        "6M6_6x6",
        "7\\#B]",
        "v{LU_",
        "yRRv4uv~G",
        "K,tR(",
        "ls9s_`",
        "sOYEBR1",
        "95Q&S",
        "eRB#w",
        "N)>i>C;",
        "l$0VWU",
        "volatile ",
        "&1^iye66\"~",
        "yxvbAv<D",
        "?%*f2",
        "1Kp iP",
        "A5p7[",
        "()\\ `",
        "5\"kn'",
        "A,8\"!",
        "ASN1_UTCTIME_adj",
        "+%Me2d9",
        ";$;,;4;<;D;L;T;\\;d;l;t;|;",
        "r=CK:",
        "I}voy",
        "6XXEI",
        "t0sT*!",
        "6Ws#B",
        "H\"dU^",
        "l3GS?",
        "Unsupported SSL protocol version",
        "D$$SW",
        "+R\\^N",
        "92d?f",
        "%d.%d.%d.%d/%d.%d.%d.%d",
        "g[>f(",
        "q),I.",
        "(^[>X",
        "0M1T1",
        "zh?$\"_N",
        "]IMrV",
        "u!j/V",
        "!$M`a",
        "(relevent for upgrade only) error %d to delete key %s ",
        " notrayicon",
        "__clrcall",
        "DSm,W",
        "d#]gjQg",
        "Z+F@q",
        "4'\\*s",
        ".?AUIUMSThreadProxy@Concurrency@@",
        "Qz4g J",
        "zB/0G",
        "(r::x",
        "}c 6}+",
        "    Signature Algorithm: ",
        "qsLa+",
        ">oWyP",
        ".>1pYJ",
        "O:7&<>",
        "$/gaY",
        "V/U`I$SyWo",
        "C8QRP",
        ";ZE!'P",
        "#b$u|w",
        "wLSVG",
        "MK'w &",
        "8a:i:}:",
        "SCRemoveAfter",
        "&v?$h",
        "t`jyMQ>\"",
        "69Du\\",
        "&^*r>cc",
        "@wK98",
        "{(0B|",
        ";.<M<",
        "]!V))a,",
        "7 7$7(7,7074787P7T7X7d7h7",
        "ENG[F",
        "QhPEp",
        "09dy,",
        "<a!a_R",
        "20242L2\\2l2|2",
        ">:>i>",
        "]KZ=O",
        "JVVm[",
        "p$?.g",
        "69|`b",
        "?(?A?Z?s?",
        "t(>EI",
        "sig_pkcs7 failed",
        ">(>0>4>@>H>L>X>`>d>p>x>|>",
        "WSERmdir(%s)",
        ":gOE?",
        "zAj?|h",
        "rG3t1Q",
        "Set up events complete.",
        "%YM&]?",
        "SRDIR.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "4Ic=H*Y",
        "Nj|tY",
        "FLkI.",
        "+aCie",
        "ps%-V",
        "joIX%d",
        "=vul'",
        "4(484<4L4P4T4\\4t4",
        "|/?$^",
        "nPg(O",
        "_oOIu$",
        "i-CTT=s",
        "ybtPGp",
        "HzJ6%^",
        "[-fUJ",
        "tag mismatch",
        "S>WQD",
        ":9:R:l:u:",
        "2i3q3w3",
        "EgL)H",
        "5(545J5]5p5",
        "3 -'J",
        "Ud__;",
        "`e&?j",
        "n]XdS",
        "compressed length too long",
        "@AJho",
        "9,9_9",
        "Ia!,0",
        "VjPhD(",
        "(eqzHP_aA",
        "H$]A?M",
        "Y$qUNF",
        "1P@D[",
        "smartdefense\\policy\\cp.lf",
        "Ffp<'",
        ":KM(h=",
        "i)K>,Wz",
        "9*0;j`n",
        "D<#OP",
        "A7My=(",
        "`7&5u",
        "tvfwConfigChangeEx",
        "[VSINIT] VsWow64EnableWow64FsRedirection: GetModuleHandle('kernel32') failed with error 0x%x",
        "pNF'T",
        "RAND_get_rand_method",
        "`se5ZM",
        "*,4GZN7n",
        "VRaZ~P",
        "boost::filesystem::permissions",
        "UeH}VUu",
        "1 v#9",
        "DES-EDE3-OFB",
        "\\$XUV",
        "i796C",
        "\"HH&e",
        "t$8SVV",
        ")qEfTC",
        "919G9[9f9x9}9",
        "$'KC=",
        "\\ytE#)",
        "<I;GQe",
        "0Bpd^U",
        "public_key",
        "t$ RV",
        "\"HAq ",
        "ES<lw",
        "9w9K:",
        "CRolloverMgr::CopyRolloverBlock():  unable to create rollover file",
        "NL2vN",
        "`2`fl!",
        "~$/%V",
        "tmpnam returned null",
        "t%Oe?",
        "no.qrstuvw`xye",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\DSM\\SecureAccessDSM",
        "[fQ`&^",
        "L=<Z#fK",
        "BG^@Z",
        "_,,dy",
        "RC2(56)",
        "1t$,3",
        "%Hc$pZ",
        "K%,;Me",
        "~aSUV",
        "The driver is successfully installed, but could not be started. OS restart is required to finish installation.",
        "M&Y_9F:",
        "PUPNd",
        "0 0@0L0l0t0",
        "dtls1_check_timeout_num",
        "A0y`7",
        "_7z@<e",
        "-VHcti",
        "V%WE43",
        "Aa,ka",
        "*7uwq",
        "BSo5Y",
        "BN?N;",
        "&=ym[",
        "'FMtjQ",
        "XayxY",
        "tH#@9",
        "**TH9",
        "bKn#l8",
        "91;p;",
        "-QhLG",
        "vKwY'",
        "D$$]_^[",
        "=5$I@#",
        "?NByr",
        "TrackPopupMenu",
        "{|nh18-",
        ":3:s:",
        "ig1C`x",
        "uVh(l",
        "+k.?E=L..j",
        "H>V's",
        " >*y~D$jW",
        "bS!!l=p",
        " 0x3d",
        "`MxG&O",
        "TgUgWg",
        "d.ZX<NjZ",
        "Failed to execute view in ",
        "`y3*z`",
        "$*J `",
        ".rtc$IAA",
        " tRG]V",
        "I JV26c",
        ":st}O",
        "|v5e-",
        "eYZ>Qy",
        "EDTe:",
        "dX5&_",
        ",L/,/a",
        "{!Gj^",
        "dhSinglePass-cofactorDH-sha224kdf-scheme",
        "NM'\"A",
        "a!VfnB",
        "xXuLTO",
        "mJnz/j",
        "r`f;M",
        "Sn{-Kiy",
        ".CRT$XPB",
        "c4i*1",
        "8L9V9s9",
        "OCSP_CERTSTATUS",
        "c=Y`\\;",
        "^C8f)A",
        "-c^k_{?4!",
        "0#dB$",
        "g{CQ]",
        "CKg[6}q2",
        "HMx:;l$",
        "O34&A",
        "oh,Cm",
        "hv2TF",
        "7 7X7.8",
        "ACZ6l\"|9",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Limitation }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5186676 of }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "LocalAlloc",
        "XNk9&Y",
        "state not recoverable",
        "}U:/9b}",
        ") 7tS",
        "*8&3aNA",
        "SP7H\"1",
        "+[MC`",
        "VOFnof",
        ".yyg\"!-",
        "\"Vk_s",
        "SELdc",
        "%5ld:",
        "(QZ[l",
        "424=4Y4d4z4",
        "VRg\\LP",
        "rAy&j",
        "IqIAM",
        "wX~>+",
        "Ph4n#",
        "messageDigest",
        "5zV)XR",
        ":=|v:",
        "||j) 1",
        "272?2E2J2n2",
        "5Rg$,",
        "Installation resumed! Cleaning ISSETUPFILESCOMPLETED property to force ISSetupFilesExtract to extract setup files again",
        "eq/3m",
        "2#2'2+2/232]2g2",
        "CMS_RecipientInfo_kekri_id_cmp",
        "k]Wh7'",
        "6^h[$",
        "AY'Ge",
        "y6+Oi<h",
        "(8*O&",
        "UQf;S",
        "socket failure: %s",
        " ^_d\"C",
        "g!nW&",
        "Start date",
        "PFWJjb",
        "uj!]-",
        "P$k_N=",
        "999>9P9c9l9r9",
        "'jbB\"",
        ":Z;o;\\>s>",
        "aI1=#xVIE",
        "es-DO",
        "l$4Of",
        ")@||\"",
        "00c0r2",
        "C9V k:",
        "/=*d\"+",
        "[|^C^",
        "LY[w`g ",
        "q#P81",
        "[(gJsJ{!",
        "jAjij\"",
        "SELECT `Component_` FROM `FeatureComponents` WHERE `Feature_`= ?",
        "];q5GK",
        ">/tW;",
        "tEz%CS",
        "I1(Hm",
        "md4WithRSAEncryption",
        "1-d`+",
        "qyyCI",
        "IsUninstall",
        "= =$=(=,=0=4=<=T=X=p=",
        "O!!K;lG",
        "I.eaE0Js",
        "G*p]W",
        "!clZu",
        "l3}7t",
        "d@_g:LB1",
        "FIDIVR",
        "my~t,-",
        "I:&IS",
        "<cKW-",
        "oY}JX*Y",
        "g6c^^",
        "0n}Xf",
        "y1_oF4",
        "D.BnB",
        "RAND_init_fips",
        "5@|Ss",
        "#:?Pm",
        "~SmFMp",
        "tXbN8",
        "ye]0=6JL",
        "5q}:N",
        "% P}I",
        "/<Qa5",
        "vZ)1S",
        "!!!!!!!!!!!!!",
        "HMAC_Init_ex",
        "d..S.",
        "<5=K=Y=",
        "rd*#;",
        "818l8",
        "tdZO!",
        "%04d%02d%02d%02d%02d%02d",
        "6{!{|",
        "mnm|*,",
        "7h8'$[",
        "0(030A0T0",
        " y34f",
        "';90L",
        ",8\\5}",
        "Oai6,",
        "szCustomerNo",
        "W^;evPK~",
        "~lJuI",
        "!U*j@",
        ";(;0;8;T;d;p;",
        "? ?$?(?,?0?@?L?P?T?X?l?p?x?|?",
        "hXh0h",
        "V[mTCc",
        "xUzqG",
        "jAjhj\"",
        "r{1/k",
        "$~TY[",
        " */{56",
        "Q(Wx9",
        "=5=q=",
        "mCvi_",
        "jljmj\"",
        "smn-FI",
        "32ls@",
        "MVB-Gd",
        "a?IhrrF@",
        "7e^6ce.x",
        "g_Q18",
        "Ro01o.",
        "iai0nx",
        "sGJLA",
        "$+s{uu",
        "%*sNo Qualifiers",
        "W]6BG",
        "%P[# ",
        "L-T>=CX",
        "111\\1",
        "TERM SPEED",
        "8~h@3",
        "61 /E",
        "EPS key is not found in registry",
        "*ic({",
        "|Y7*/",
        "Z\"5=P_",
        ":V{f<Hp",
        "54M:S",
        "=_J~.",
        "!&*5vc",
        "C0hcK",
        "{)*T<",
        ">S]<8v",
        "#ai)Qfo",
        ")SRPzP",
        "i|n:%",
        ":'5q\"",
        "$6q-h*",
        "Iq%$$c",
        "~.]5t",
        "'nOlO4N",
        ",:\"YG",
        "&fQ$Y",
        "Lnpo_/C",
        "V` DR",
        "P=*(r",
        ", !LW",
        "jqj~j!",
        "Oc?f4",
        "5Wx&)4",
        "}`@F`",
        "\\x\\_&",
        "setct-HODInput",
        "pF=^a,",
        "U$S*P",
        "Or`\"&",
        "'z<by6",
        "{grgA)",
        "<.<U<'=D=",
        "282^2",
        "TY?PE",
        "(w.b{",
        "RBe=7^",
        "n>b_Y",
        "WixQueryOsDirs failed to initialize",
        "2(5m5w5",
        "pq6y:",
        "{`(7=",
        "BN_div",
        "Mc3C#(",
        "^u/k~X",
        "syS8$dB",
        "9]vA}'",
        "\\5I~t",
        ";kKi*",
        "]U^SoY#",
        "InstallationDirectory",
        "646<6D6L6`6t6",
        "6#M&R",
        "cElO\\",
        "Bld%E\"b!fL",
        "^g`Dq<y",
        "0*gqy",
        "iyT|{=z{",
        "t0vB04",
        "6.6H6V6\\6g6v6|6",
        "gG*HQ",
        "`;^iCl",
        "kHF=A'",
        "failed to open view on database with SQL: %ls",
        ":8:T:",
        "#S+LOO=",
        "6A6<@u",
        "#1GEc",
        "/////////////",
        "8y>S*",
        ".\\crypto\\x509\\x509_lu.c",
        "=dSIz~",
        "GcL-^",
        "!&?zo",
        ";%;i;",
        "Rfk.?V",
        "p\\$C#i",
        "[cH9\\",
        "Verify failure",
        "Z4'Y&",
        "Qh }&",
        ")..I<",
        "q~I|{",
        "MSVCR90.dll",
        ";$;(;,;0;4;<;T;d;h;x;|;",
        ")mp!8Q",
        "QoZ(t",
        "&E>0;",
        "U_<P]9ng1B",
        "[MikfL",
        "YQZMW",
        "9[KpV",
        "owS*2",
        "6Z7z7v:",
        "bInstIMSecure",
        "<\\S?o",
        "4'{wf",
        "Broken pipe",
        "1+%r=)~-O",
        "M+,!bJ",
        "ih`*a*",
        "|<C!FReQ",
        "StopInstHelperError",
        "PVSWS",
        "B|L :",
        "7CVPc",
        "d/gQxf",
        ".?AVmissing_wait@Concurrency@@",
        ".?AVbad_function_call@std@@",
        "ssl3_setup_write_buffer",
        "SSL_CTX_use_PrivateKey",
        "Qav9J",
        "jAjdj",
        "|l x;",
        "setCext-PGWYcapabilities",
        "0.0@0m0",
        "illegal or unsupported padding mode",
        "!rsd9%",
        "2G3W3n3s3}3",
        "J2Bh)?",
        "<X7Xo",
        "c!.L@",
        "DXy6>",
        "hxLro9",
        "EXK ]",
        "fs*;4",
        "tK{`n",
        "CRolloverMgr::TruncateLog():  unable to read from log file",
        "^9?Gc",
        ",,%2S\"",
        "FH|i,1{\\(#d",
        "}8F\\t",
        "No authentication method was acceptable.",
        "qp-us^IQ'",
        "jgj}j#",
        "75YQ:2",
        ",...,...",
        "XQsyW",
        "5%5_5",
        "?j84C",
        "string too long",
        "jgCdac5",
        "Failed to get remove folder property.",
        "\\f0z1gn",
        "Omp&E",
        "UxO\";",
        "tyDS\"",
        "KY\"vr",
        "\\X>7n^",
        "WinRTInitialization",
        "Y.O;#jd",
        "GSXR&",
        "Pv8CZ",
        "L_fpN",
        "%0cTSq",
        "MinorVersion",
        "?M?r?",
        "jAjrj'",
        "V3Z4Y",
        "7$8,8P8d8t8|8",
        "hfo$/Pac",
        "646O6_6s6",
        "FAC driver installation failed with error: %d",
        "HSlht",
        "@&Nlsi",
        ";$;,;4;<;D;L;T;\\;d;t;|;",
        "pk%~Y",
        "U,LM-d",
        "?N?t?",
        "m,'#{",
        "Jtc9v",
        "D$8SV",
        "ad_timestamping",
        "i5Q\"js\"",
        ";,;H;d;",
        "dF{HQy",
        "r)|('r",
        "D$8PQ",
        "T$T#L$P",
        "%Z;@;",
        "_gqF'",
        "(_~+k",
        "-chS!mp",
        "3m)_}G",
        "=!=)=N=S=`=v={=",
        "X,ca ",
        "bnzPq",
        "Business",
        "puerto-rico",
        "6<#&L:",
        "cI9 z",
        "&XY;Q",
        "4]wh7e",
        ">hK$2O",
        "PageHeapFlags",
        "=2=G=",
        "B.Su <",
        " .!p*",
        "Wh8;!",
        "ggggg",
        "At5=%",
        "G^%By",
        "7]%.a",
        "pX'y4",
        "MergeCommonBackup ended",
        "xs4r M",
        "&YJ5X",
        "id-Gost28147-89-TestParamSet",
        "jt\",P",
        "dG$=H,J",
        "YS\\'W)18",
        "+@dcPA",
        "error.png",
        "NeU`dz]",
        "%S is a symlink to %S",
        "<MEFileProtectionON>",
        "u^538v",
        "n\\Z-hq",
        "f_C%p",
        "q%A4>",
        "&3fe\"",
        "Dr}Jw",
        "SOFTWARE\\CheckPoint\\PRNG",
        "9AI3\"",
        "BP%jvN\\#MZ1K",
        "H):}X",
        "woPC|K",
        "W#Fw>",
        "<zC=P",
        "9#2a~<",
        "NWn6S",
        "8vXN8",
        "aq}5l;c",
        ",kMmf*~",
        "t$$W3",
        "2(2N2t2",
        "9D$ t",
        "Rb'@l@r",
        "qSwz#",
        "&NQpe",
        "UD2^o.r",
        "loadImsinstall",
        "{mM]$*R",
        "<<<G<",
        "nW$kbsFF|",
        "QQQQQ",
        ";-;d;",
        "000`0",
        "^+otU",
        ";9<M<",
        "@uH@x",
        "tkokv",
        "Ds6\\j",
        "`.~[ ",
        ":8:<:@:L:P:",
        "SK{T<R5",
        "tB'CY",
        "y+a;A",
        ";^'~j",
        "59OK7",
        "JBQ:l",
        "} b/s;",
        "i.l5\\D",
        "?P?`?}?",
        "uG&> =",
        "*Y};M",
        "QN:C,",
        "Ze)K'",
        "kTm5C",
        "W~~r7",
        "tnSj0Zj",
        "3L$x#",
        "=_bmhGC$",
        "<4@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        ")zhli",
        "+W8ii",
        "<$<p<",
        "p@2|T",
        "&?cIU",
        "V^.3X",
        "L2a0{",
        "4VHtI",
        "!5Eu.",
        "rzT\\.",
        "hz@6M",
        "QUr8((",
        "OnFirstBefore",
        "LEpVz",
        "1lemx",
        "(3d!@3",
        "FX8d>o.6",
        "Insert file: MsiViewClose",
        ":7,O/",
        "PreInstallCheck: Total Required Disk Space is: %I64d MB",
        "c8eTe",
        "9Pb`UX",
        "Proxy CONNECT aborted due to timeout",
        "+\"BD ",
        "U#FD*",
        "$K`+lF2",
        "gTd5P",
        "epk/s",
        "t$0t$R",
        "veQrC",
        "'.]Z@",
        ";$;,;4;<;D;T;",
        "&#7J\"",
        "0\"0B0b0",
        "german-swiss",
        "zlxeap.log",
        "Pq8a3Y",
        "WixRollbackFirewallExceptionsUninstall",
        "{T~6)",
        "Opbe^",
        "D7[uQ",
        "=V%gA",
        ";|s4Ix",
        "m6mx}j",
        "9GJ4!",
        "ZgP,%",
        "jCjjj&",
        "l^P3Rq",
        "?(?,?0?H?X?h?x?",
        "tlsv1 alert user cancelled",
        "t$8PR",
        "g}>z=",
        "V+u.,r",
        "AmvEvev",
        " f:) ",
        "Unable to extract AM1Signatures.exe: %s",
        "!/E88",
        "@K,mv",
        "\"^Chv",
        "%-*&u",
        "5yu\\D",
        "Enterprises",
        "=\"=I=",
        "@o_r>",
        "Uninstall firewall driver.",
        "Gapi-ms-win-core-fibers-l1-1-1",
        "8bc_%",
        "F@Nfj",
        "a(N}/",
        "s378C",
        "(8c2m(]",
        "o s#dV",
        ")7;l@",
        "8\"8>8Z8v8",
        "}Q~Zz4",
        "4s`*]",
        "%w&+cI",
        "4gY@nL75K",
        "\\$(UVWj",
        ":hqCiw",
        "localhost",
        "1*212",
        "dP](.",
        "WjU]p",
        "6+7C7I7",
        "=$=D=L=X=x=",
        "SJ]}vL]",
        "0f1{1",
        "invalid multiple rdns",
        "=(o;Ik",
        "N,k/lm",
        "$+Zwmq",
        "3D$03D$,3",
        "JjTvp",
        "Ju[aTF!",
        ";6<{<",
        "F#p~c",
        "D$ SU",
        "%ksX+",
        "fEwI6",
        "ipsec3",
        "<?<\\<{<5=?=W=r=",
        "Found HKLM\\SOFTWARE\\Microsoft\\VSTO Runtime Setup\\v4R\\VSTORFeature_CLR35",
        "fo-fo",
        "%)G>k",
        "ucp.exe was running",
        "u'jWh|",
        "bG^NF^p_",
        "+&9c%t!f",
        "p{.kg0Gvmk",
        ">>'nW",
        "F:\\ckp\\src\\EP_Vsdata\\E87_00\\CMpub\\lib\\win32.release.dynamic.32.msvc141.ansi.mt\\vsdata.pdb",
        "-n&XRf",
        "5G7N7V7^7f7",
        "3=W]q|",
        "u|mQK/",
        "9 (Y?O",
        "L$0.N",
        "031q1",
        ";@OQZ",
        "b.-|#",
        "$tcPa",
        "8FpJ*",
        "96lA?Q",
        "0uC6&",
        "ZjVD@",
        "(6.__",
        "xESv.VZ",
        ")YrBln4m",
        "Nb`Qhm",
        "1!1R1_1",
        "2$2,242<2H2h2p2",
        "socketgroup",
        "svRYK(",
        "5TEnZS",
        ";M rb",
        "636G6[6o6",
        "_QFl9{zp",
        "sA~``S=hX@",
        "o/a^2",
        "gL829j",
        "the ioctl callback returned %d",
        "cY[^Ek",
        "%vVcE~",
        "Giz|i",
        "^_]1y",
        "8C9O9]9p9",
        "ZPLh7",
        "d\"ISi",
        "policy path length",
        "<\">2X",
        "<;<W<s<",
        "VsDataInstHelperOpenDriver - DeviceIoControl(DIOC_SP_CTRL) - new driver assumed. Result=%x.",
        "6 7H7",
        "g{FJ<",
        "P_n`6~p",
        "j~N$h{",
        "Gi#KN",
        "UIdid",
        "dmecq",
        "!q^36x",
        "dY yG",
        "pvaSF",
        "v_UV3",
        "0$0(0,040L0\\0`0p0t0x0|0",
        "&jiCw)",
        "i5)fV",
        ".x83U",
        "6[xxh&",
        "\\}+1]",
        "4+4A4\\4h4~4",
        "{dnlb",
        "->i\\T~",
        "y|>2_ Q",
        "(o#75",
        "[$}%!",
        "not.in.domain",
        "(|wRSj",
        "!K75Y",
        "D$(UP",
        "4`SA'",
        "t$(VSWP",
        "d*f;K=",
        "^^{fh",
        "'oj3[2",
        "fvc{& ",
        "#}gW3Z",
        "@Fj,P",
        "2!Q!C",
        "=$=0=<=H=T=`=l=x=",
        "YG`\"F",
        "*O$&N",
        "1wu!U",
        "hs4%xKD",
        "P>:=f",
        "6h7s7",
        "calloc",
        "Uu$\"O",
        "&s?@H",
        "K.|i#_`",
        "1!2+2>2L2^2",
        ".pe(\\ ",
        "ELC_ALL",
        "dNZjE",
        "bIZ~.*,",
        "*AH\\f",
        ":=v|v",
        "7{2? ",
        "%Y-%m-%d %H:%M:%S",
        "]93A`",
        "vswmi.dll",
        "8m9w9",
        "e<|1gl",
        "`\\!9Z7",
        "(()JO",
        "^jODWO",
        "M'MAMK l?",
        "|pt|wJ",
        "}pedCh",
        "Ft3g&\"y",
        "x3TuJ",
        "AZ=!-2H",
        "6!6&6C6Q6Z6m6y6~6",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 Transportation costs, if any, incurred in connection with the return of a defective }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 Hardware Product}{\\rtlch\\fcs1 ",
        "6>G}y",
        "< =,=",
        "invalid non-CA certificate (has CA markings)",
        "Unknown SSL protocol error in connection to %s:%ld ",
        "W4Mj!",
        "9_#&i",
        "<+: w",
        "4)4N4S4b4",
        "3:LId",
        "3 Nzv&H",
        "tVlfbM",
        "4o+I,",
        "q\"/@R",
        "a_`g:^",
        "*rArQ%",
        "J6yE]",
        "EKB*{",
        "client",
        "2=2z2",
        "ep{_D",
        "4 4)4/494D4",
        "t$,+t$<",
        "LONG_C2I",
        "2G3g3",
        "DSsl;e",
        "Lc4M/p",
        "FCMOVNE",
        "8SVUW",
        "u_MF.{",
        "^]Vtln",
        "_65]J4{E",
        "M2K;P3",
        ".\\crypto\\engine\\eng_ctrl.c",
        "C\"8j#m",
        "id-GostR3410-2001-CryptoPro-A-ParamSet",
        "o)ahv->X",
        "aZhIx",
        ")(b&pj",
        "Ce_c{",
        "ASN1_ITEM_EX_COMBINE_NEW",
        ")[h_}V",
        "&g+>!",
        "[k7,Zm",
        "F@>Q[",
        "b]\\sw",
        "U_\\`&",
        "%z}(2[",
        ".qIWo",
        "=7>l>",
        "conflicting engine id",
        "^fP+S",
        "SF# *@",
        "QgO9IY",
        "828R8r8",
        "(:K32",
        "e5KUN",
        "WindowsPatchData.zip",
        "p}T^YW",
        ">P6*x",
        "Hv\\O*s",
        "q7%zFE",
        "D$\\PS",
        "ssl23_accept",
        "<=<a<",
        "}SBVU=",
        "so oj",
        "\">KoM",
        "00-20-e0-73-bf",
        "HZHKC",
        "M:q42",
        "er[kFn",
        "x#o+og",
        "id-ce",
        "`opT ",
        "1Qn[*w)",
        ".XY]11Z",
        ".\"g8g",
        "[5~M9",
        "<0.|[NSr",
        "Failed get new VNA version",
        "!GMO(",
        "qcUCc/",
        "4:5z5",
        "og*{c",
        ":<:@:D:H:L:P:T:X:\\:`:d:h:l:p:t:x:|:",
        "90989@9H9P9\\9|9",
        "cast-cbc",
        "pwn-,1",
        "I``e\\",
        "5y(Fn",
        "VZZhZ",
        "jLLvs",
        "Rlm|ZAR",
        "3333)\\",
        ".b25e5",
        "jshDx#",
        "_callnewh",
        "<b9/<",
        "<|vR,0i!",
        "D$$Pt4j",
        "%:14,",
        "t6SUW",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\helper.cpp",
        "zKd\\}",
        "2A_D^[",
        "eF_pgfa",
        "1<>'I",
        "7!737",
        "|$(3D$",
        "D$$_^f",
        "7tfSW",
        "Wp7uw",
        ")KiuW",
        "_hKPoL",
        "5D6Z6",
        "rLF87",
        "1 1(141T1\\1h1",
        "0$000X0|0",
        "9OMpH",
        "gxm\"y",
        "5FS4!9Q\"",
        "Wn2uQ",
        "S!(9Q",
        ";8;<;P;l;p;",
        "Ih<HuF",
        "fg_(P",
        "6I6a6y6",
        "RC2-CFB",
        "tE9ndu@",
        "!)'%'C",
        "[a|q0",
        "I=#qx=",
        "d%k2\\",
        "cfA~iD",
        "duplicate compression id",
        "strcpy_s",
        "YVV()7",
        "\"0|5h",
        "$FdC|\"",
        "CopyAndRegisterFilesFromTempDir",
        "&UG\"d",
        "=-cfi",
        "Y(xR;{",
        "U+RD5",
        "!|&_pW",
        "jsejy",
        "jhjjj",
        "x4CIU",
        "7$7,747<7D7P7p7x7",
        "lt8D_",
        "aU{ntZ",
        "P-9C'qy.VLq",
        "\\f1\\fs20\\insrsid13240566\\charrsid12218863  countries}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566 ,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5905555  }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5905555 to reach }{",
        "RulesNewObject",
        "KJlq!l",
        "dP4?{",
        "yUHT[7G",
        "K+u*F",
        "#t$$#D$",
        "PApJ8",
        "X/w\"_",
        "2(2D2H2\\2",
        "<94 m\"",
        "5,l?%]",
        "H/-b}j",
        "!~z:6<89",
        "&+]u-",
        "pH'ik",
        "C-A\"2O",
        "gb?|,",
        "{X&@8@x",
        ")B{hZ",
        "dLdLh",
        "-)X>I",
        "UY[2V",
        "w<y?J",
        "zIuUl",
        "IsBadWritePtr",
        ".?AV<lambda_0181ba6b4c688320166279c58f783d31>@@",
        "=[f, ",
        "4O4l4",
        "j\"^f92",
        "1Q1}1",
        "2&363M3",
        "C*X^X",
        "x$66T",
        "v$YB_",
        " 0?n!,",
        ")vlY^",
        "4/2wtS",
        "k,eXRbF",
        "2&_{Y",
        "a'9mJ}",
        "Qc'|8",
        "i<q'U",
        "{2V^Xb",
        " B{`h^",
        "1(1,1014181<1D1\\1l1p1",
        "Zz~0:8",
        "RSA_padding_add_PKCS1_PSS_mgf1",
        "u:~8-b",
        "FP-^ ",
        "]Q6R6qD",
        "fr-be",
        "\"%]_q",
        "qbrjrzq",
        "EDEdE",
        "4JNE;7",
        "spanish-costa rica",
        "0\"0/0E0\\0s0~0",
        "io&btb",
        "h?K>?",
        "(jT''",
        "failed to enable filesystem redirection.",
        "vR@aTu",
        "7r@kN",
        "364H4&686",
        "\\>xM$",
        "lu%fz",
        "`*\\Z]",
        "1u~|d",
        ".$WOb\"",
        "p/%H-$",
        "]!YB-",
        "EJqaiq9",
        "CkiJqs",
        "O(-lq",
        "=(Ufs",
        "expected key string",
        "service was successfully signaled with the required control",
        "lL\"Wgg",
        "'9sUZ",
        "=6LNb",
        "D[t11",
        "3!7FAm",
        "5C,:G",
        "y~iUZ",
        "UEV5Y",
        "tC;D$T",
        "ea~6\\PZ",
        "nsBaseUrl",
        "b`F7B",
        "q@^v|~",
        "ta=c}",
        "Q+j&F",
        "Uii7`j",
        "BQULYCr,",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 5.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "0A0n0",
        "J|j-7I",
        "ki`G$",
        "9L4]=",
        "Qs.9I",
        "?fM@3",
        " version ",
        "The easy handle is already added to a multi handle",
        "V{Qp ",
        "Y_[^]",
        "Tlo2q",
        "n`SHv",
        "AV_UPDATE",
        " Iz9g",
        "9F|o`",
        "{=Cq~",
        "b0Gdr:w.x",
        "hGao0",
        "K/Kfc",
        "W:lHA",
        "9Q:V:",
        "WG%]3",
        "OM is not disabled in registry -> return false",
        ">lHI~|w",
        "a2Q93",
        "H,0#E",
        "lziBx*",
        "=.=V=",
        "L![zu",
        "hUO{&",
        "0 0@0`0",
        "<2<v<",
        "2V7e7",
        "p+f\"<",
        "V@b;O",
        "ECKEY_PARAM2TYPE",
        "/tGo`",
        "NerP7V",
        "?$?,?4?<?D?L?T?\\?d?l?t?",
        "UcrP.",
        "Hjcl76",
        "RjOJA",
        "oZ?@6",
        "=kn>l}",
        "\\Tr~(",
        "}E+f2M",
        "q3848",
        "f,fLf|f?",
        "JOx8e6",
        "$1l]u",
        ".,Yb#",
        "made to %s to take effect.",
        "TLSv1",
        "r%*YYi",
        "% r\"|",
        ".CRT$XPX",
        "Custom action was told to rollback a 64-bit component, but the Wow64 API is unavailable.",
        "616O6d6m6v6",
        "!v*c7l+",
        "6qCcx",
        "GST2O",
        "&(KJN",
        "c6NpO_",
        "ez'1c",
        "UW>}`",
        "Sj%PS",
        ">&>->K>[>",
        " --cleanup ",
        "\"B@r(",
        "|(>|BC",
        "m5LpsQ",
        "@NZq.\"",
        "Bh%4S",
        "N1<A`",
        "d3 X\"i",
        "system\\currentcontrolset\\services\\",
        "627O7r7",
        "digest_info",
        "E]un!",
        "ZauVi",
        "; ;P;T;",
        "unloadVswmi;",
        "q~iV<",
        "CJsPqI",
        "A~6_f,-",
        "id-smime-aa-ets-RevocationRefs",
        ">3>v>",
        "DR>L]V9",
        "bPlx+",
        ":*I\\qLO",
        ".SjAdbK3",
        "JyP+s",
        ":V;h;",
        "3T?1B",
        "lfL+z",
        "Jj3XQ",
        "9Ll!A",
        "lNx#k",
        "cd>VI`+",
        "h7DN'",
        "[4J;AO",
        "@?u{c",
        "DNMp1?",
        "<destination>",
        "C0ve{T",
        "8Q8j8|",
        "Mmh?(6",
        "8g5DC",
        "VLJYY",
        "T\"~'e",
        "S`\"|~",
        "x\\INs",
        "LPkQ!P",
        "alz}/l",
        "~i\\eO",
        "_E5$Q#",
        "b@QNh",
        "CKX)=",
        "OtpG*cGbLN",
        "_xn:%63",
        "+n/-.",
        "d.encryptedData",
        "4_fc{",
        "*^rcQB",
        "$sKOX",
        "@j\"eu2",
        "5ae07e17a621a8e082dafc17e450ffb739676998b48643a4daa7211214f623150942f6a02c99e83b85583ddbbb2c4996113211551257a656ec1139246ca86be0",
        ":9nW ",
        "162H2^2i2q2",
        "=-A\"I",
        "H-0VP[D",
        " 9$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        "2<YOI",
        "t3h(\\!",
        "WIX_SUITE_SMALLBUSINESS_RESTRICTED",
        "FAILED_TO_CREATE_EVENT",
        "2ImSH",
        "NEWUSERPASSWORD",
        ";@ !Qc",
        "\\par }}{\\footerr \\ltrpar \\pard\\plain \\ltrpar\\s47\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "0,0H0d0",
        "7-7;7Y7~7",
        "lp:14",
        "h)\\VH",
        ">aS^=",
        "eHbi _",
        "(fRhRnRpRzR8Q",
        "7,707l7",
        "w=prTP",
        "%8%O=",
        "wS):vZu",
        "kExZ %",
        "k;!h<",
        "GetSystemTime",
        "maBII",
        "&j$jI",
        "2$sACoz",
        "0=qXL",
        "c|;lxGhd",
        "PSAPI.DLL",
        "hRPfwO",
        "!:hc=O3",
        "d.C#\\b",
        "AA_vx",
        "SE[@he",
        "ig`U=Pa",
        "(=(NP!",
        "j\\Yf;",
        "232?2",
        "chinese-hongkong",
        "8*3<6",
        ":(:0:4:@:H:L:X:`:d:p:x:|:",
        "Could not set owner. Error: %u",
        "9.9@9R9d9v9",
        "a;Cen",
        "aDk19u",
        "_)0hUP'",
        "&nZRR",
        "Not Before: ",
        ">kc=F+",
        "m)3ARp",
        "WseRegisterPlugin",
        "n?o150N'",
        "7^7y7",
        "network down",
        "NiQjt5-",
        "ECDH-RSA-AES256-SHA384",
        "sJUUZV",
        "uadM4",
        "C*w+3",
        "cubm370cjmn5cvw5t2amnn7kh00",
        "4 4$4(4,4044484<4@4D4H4L4P4",
        "kQUdV",
        "boL[@Y%",
        "\"L:`SmC",
        "tG;#`n",
        "7$7,747<7L7T7\\7d7l7t7|7",
        "N8!Nq",
        "+e?d\\",
        "U l\"P<",
        "0X0]0h0",
        "t$Wh0",
        "T%;G\\",
        "c'F&/H",
        "999A9f9k9v9",
        "zVx<u",
        "kEk%^",
        "E%XYfnJ8",
        "fw5+g",
        "8(848@8L8X8d8p8|8",
        "0CjD5X",
        "}|Roq",
        "-h*fP",
        "EDvfUU3C",
        "pI'WH",
        "%:\"B0",
        "T'Qcu",
        "Failed to set modified date of file %ls.",
        ")Q+4Q,",
        "%m,>G~",
        "<)a?)",
        "-v#|k",
        "^u_S2",
        "missing value",
        "-+l=a#w",
        "&0+0:0e0j0",
        "3f,\"d",
        "2\\3l3",
        "hITll",
        "o?|Rk",
        "2m0}y1",
        ",J^N(I",
        "/Wl#L",
        "http://ocsp.sectigo.com0",
        "Fxwo.",
        ",|o6X",
        "^)/tG-,",
        "kM& %",
        ">*t2;",
        "sWzT`b",
        "6<6D6T6\\6d6l6t6|6",
        "27Z1`",
        "a(q3)",
        "P`]*R",
        "mjM,IE",
        "xPnl1",
        "x*-7$",
        "WJ($<",
        "cyFK+*",
        "AqpBx",
        "v^7FJv",
        "0],I:",
        "jV<+[",
        "eS%3k",
        "OPENSSL_malloc failure",
        "7;7O7U72;N;",
        "(\\>8_",
        ":`:~:",
        "~0+|c",
        "UkqE\\",
        ":1AM9",
        "u'FJ{",
        "no protocols available",
        "invalid separator",
        "8!8(8/8a8h8z8",
        "OnCleanInstallDriverRollback.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "<c\"?f",
        "K#i*y",
        "Nh%gk",
        "@+d)/1",
        "7-757Z7_7o7",
        "(\"Q&Q*Q.Q2Q6Q:Q>Q,P",
        "&=;t)",
        "o'K`4",
        "Ri#3[",
        ".rtc$TAA",
        "Mwl=N(=",
        "9Dqi`c5",
        "[nfxq",
        "es-CO",
        "Ux>4B:",
        "BnQ0s`$y",
        "Oor7V",
        "ZU%n!|\"#",
        "k'Rjl",
        "D)#(4",
        "ewyts>\\",
        "\\%t=+",
        "I&gI/`i",
        "Lt5:O",
        "1L1S2",
        "?/Y!-",
        "A{sp#",
        ") UAR",
        "3$303P3X3`3h3t3",
        "]?hp)",
        "dNrtH",
        "DT(l$F",
        "yaEY[",
        "3_]^[",
        ">8>@>H>P>\\>d>|>",
        "ARCD9",
        "context not initialised",
        "P|nNm",
        "dq]\\CF",
        "#4>9I",
        "Kv:>jal",
        "%oo~E",
        ")9#s9V",
        ">!>A>Q>a>",
        "rms:\\",
        "0%0,060K0^0n0",
        "Saving upwval...",
        "MaxNumFilters is set to %d",
        "Q*G<\"",
        "FICOM",
        "^b=M.",
        "F/Y'A",
        "SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters",
        "Th_^;",
        "?S?W?Y?`?l?p?s?{?",
        "4=PZt",
        "/C8+rG",
        "*F;VZ",
        "bad length",
        "LjnczP=",
        "LZN(J",
        "7vpzW",
        "?\\J|!~",
        "e/yt2",
        "kj7z}",
        "eB>A`",
        "+F|\"D",
        "FWUpgradeBefore",
        "Invalid SSPI encryption response type (%u %u).",
        "<|U'S",
        "!vh{F",
        "`%2>]",
        "jBjwj",
        "t<h0;!",
        "C?e:7",
        "rsa_oaep_label",
        "3C<{P",
        "l|@Dl",
        "'(R2jC",
        "3(30383@3L3l3x3",
        "t$AGb",
        "certificate rejected",
        "Upgrading driver.",
        "80.83",
        "bZtg)P",
        "&h1zFTb",
        "L$(PUU",
        "6+awW",
        "5m#&`",
        "_(_^[]",
        "&dD44",
        "'Ks4ZH&",
        "fgZGR_",
        "8*<y|{+",
        "eq~vfq",
        "9z'B4",
        "$M &]LED",
        "N`R@J",
        "This error will be ignored.",
        "jOU*J",
        "%u*^?O",
        "bsbubn",
        "0Q0V0",
        "D(3|i-mOL",
        "R1*Aq",
        "6bqO,",
        "digest check failed",
        "!MDa4",
        "%4Y|\\C-",
        "PedRy",
        "SSL_use_PrivateKey",
        "{ne-_\"",
        "-0zQ5",
        "K$fV4",
        " F|XP",
        "3I3e3J4",
        "Hac<9",
        ":l[5wC",
        "?$&,,",
        "wB0<V2",
        "SOFTWARE\\KasperskyLab\\AVP8",
        "U3SV#u",
        "uaSSW",
        "9|sX^Ml",
        ",%y_G",
        "yL6zH@_",
        "33383@3d3",
        "515K5T5o5",
        "SC unisntall batch file was created succesfully",
        "$[IBN",
        "bad data",
        "3,343T3h3p3x3",
        "rmrg*",
        "pWx+\\",
        "CleanUpInternetLogs:  CleanUpInternetLogs finished.",
        "LdrLockLoaderLock",
        "6X/HZ",
        "@A@1\\",
        "D$\\SW",
        "mrBI8",
        "_=4D(",
        "-j^Ee",
        "PBKDF2PARAM",
        "X\\p/Y",
        "d4>=/]Y",
        "C2g\"H",
        "ZHM51",
        "(~)JB&/_;",
        "T13r8k;",
        "_delete",
        "LaA#0$L",
        " h(8Th",
        "2i9D)~",
        "5lEk6",
        "263H3w3j5t5",
        "prime192v3",
        "de'MJ",
        "^'|7Wgy",
        "m)>#;",
        "7mm4t",
        "H[ >I(\"",
        "zd+sD",
        "Ve!Fm",
        "E[`:]",
        "failed to get size of stream",
        "(:(Z z@4",
        "cq*xcY",
        "4Y4h4|4",
        "B-571",
        "x_cmu",
        "T!BaA",
        "Ikr+E",
        "U.WJKG",
        "CS'6H&",
        "F-tXr",
        "WhocaYs",
        "imD-[a",
        "%9.d*",
        ".$$BY03_W",
        "1Tb)bBg",
        "x509_pkey",
        "fL?T?",
        "* T.A",
        "NKtaZ",
        "|ft_?",
        "=>8q+",
        "~VM*$",
        "z*#Oi",
        "P*=`dY",
        "r software specifications, as declared by You in Your purchase order, or request for License Key, and upon which the licensing fee was based. If the Product purchased by You does not come with a License Key then the Licensed Configuration shall be the min",
        "CompStopComplianceService started",
        ".\\crypto\\asn1\\a_mbstr.c",
        "Z\\iT,",
        "Unsupported extension feature",
        " 0x92",
        "P$}Ms3Rw",
        "\\R:# 1",
        "T;~4r",
        "}nLza%",
        "WQVPR",
        "3;[3|",
        "[lS@?",
        "bEGE,",
        "PhHq&",
        ".00cfg",
        ";t=IW",
        "ZFCuK",
        "3v$W0G ",
        "jgjkj",
        "*SE@k;V?",
        "vsoxX",
        "7D;\"C",
        "X$(]Y=",
        "4@U&:",
        "1r4o 7",
        "I<NN+",
        "InstHelper.1.log",
        "buddyUI.xml",
        "HX\"WP-",
        "MF5O8",
        "%+{/t",
        "0 0%0*0H0q0",
        "9s6eo",
        "&xj?g",
        "value.single",
        "S~zyo",
        "3a3Z>",
        "%x-~F:",
        "wqTi0",
        "BT!O!{",
        "U}0~*",
        "BgbYG",
        "7http://secure.globalsign.com/cacert/gstsacasha384g4.crt0",
        "NnG(5G",
        "x-\\I3",
        "Registry operation succeeded.",
        ",Y.l^",
        "4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:",
        "g-JKw",
        "kn=p^U",
        "AW}l)\\",
        "OoZOB",
        "5;6\\6",
        "requestorName",
        "x^9LS",
        "7}L9/",
        "9s?%Z",
        "8B5>1",
        ",6~KK",
        "sbhRl",
        "bXpU]",
        "B CJY",
        "eUhfm",
        "*.Ye)<",
        "?Ll<c-W",
        "])d}1y",
        "0u-z3",
        "3T$L3T$03T$",
        "4G|Ss:",
        ":C;z;",
        "Z'8_5",
        "|mU7T",
        "uHXFxi~",
        "UH=z'H",
        "0<0\\0d0l0t0|0",
        "jCjxj&",
        "XfQoj",
        " 0xed",
        "2u?)5 ",
        "l1Dw?",
        "KSL10@",
        "=RE(%",
        "Ny)6W",
        "=w:YwP",
        "W!uXOp",
        "?cCDM",
        "SMkP;r1",
        "l6j\\a",
        "`),E!",
        "InS*H",
        "0L1t1",
        "4N6K7",
        "Tray icon tooltip = %s",
        "8cmSJD?~",
        "?If90t",
        "F 'hv",
        "R+E8+x",
        "~6}LN!",
        "sbgp-routerIdentifier",
        "hKc,cJ",
        "WinHttpGetProxyForUrl",
        "Y0x-5",
        "F,#iZK",
        "H5TlC}",
        "QDC8X",
        "4,4:4C4V4b4g4l4",
        "1ybPm8Be",
        "g,Mn9{",
        "gMy\"\"l:",
        "&070H0g0",
        "Z\\16k",
        "SSL_CTX_set_session_id_context",
        "Upgrade process. Driver version is the same. No need to upgrade driver.",
        "QOr~vn",
        "ssl3_check_cert_and_algorithm",
        "=c=q=",
        "|1P-m",
        "z*4#zu",
        "j|:8u",
        "An!w,8g",
        "}jEQ-J",
        "]$z|Tr",
        "cL.%}L",
        "CryptHashData failed {}",
        "p\"iK_",
        "x*0ld",
        "y5MnkZ_/Lh",
        "id-smime-cd",
        "8<z{&",
        "9cf?=",
        "$HurW$",
        "i2d_DSA_SIG",
        "t&nMO",
        ":!:D:l:",
        ";h=.>4>",
        "G\\D#p",
        "F|VUB",
        "Result",
        "d]#0Y&E=",
        ":@}-r",
        "Stopping service: %s",
        "?/?L?l?",
        "a.Ij+",
        "UMk.K}@v9\\'#",
        "/tEP|Qhd/",
        "ASN1_PCTX_new",
        "g{)#t",
        "zlib inflate error",
        ".F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "~=\\jF",
        "Couldn't use REST",
        "LB$6I7",
        "6h6y6",
        "u+x)Bpn",
        "MnXUX",
        "%dYKc1t",
        "K\\']w",
        ";<d\\*",
        "e$IV@w",
        "=E\"=z",
        "DSA_PRIV_DECODE",
        "No such process",
        "5^6i7",
        "x@(nj\\n>",
        "sM&z/",
        "logmon_",
        "GLOBAL_LOOKUP_FUNC",
        "N8$:Ep6",
        "[Nl%?",
        "82Wq}U",
        "R>w&4",
        "0@M[a",
        ":`5k+",
        "N/nOnon",
        "To upgrade, modify, or remove Secure Access you must enter the password:",
        "3(4P4p4",
        "SS$^a8",
        "//.$n",
        "jhjuj",
        "ssl3_write_bytes",
        "wVRBe",
        "h3l3p3t3x3|3",
        "fY&j(",
        "1\"2_2",
        "cBRDZ@Z",
        "+hjy&jwI",
        "`J|u(\\",
        "Disco GA is installed",
        "zE`Nor6",
        "T97B(",
        "Cc_!}3",
        "\\@}! ",
        "value.byName",
        "505X5",
        ",~uxe",
        "~0[_74",
        "d>qc1#:",
        "ev<[+BI",
        "F~\\~f~v",
        "U0J1~Do",
        "PEM_def_callback",
        ">D?L?Q?i?",
        "kZHSe",
        "I4rzCL\"",
        "illegal optional any",
        "F:%FV",
        "!n0.ZZ:{F[U>",
        "#$@Lr",
        "JTalP-",
        "INTEGRITY_PEM",
        "ps%,,d",
        "nK-~G",
        " define it based on your organizational needs. However, it shall be your sole responsibility to comply with all applicable laws and regulations in defining Your inspection rules and privacy regulations. You understand that this feature enables decrypting ",
        "XIK+L",
        "PhlIM",
        "KoWFQ",
        ":$:,:4:<:H:h:t:",
        "E\\wT'",
        "8'8C8W8",
        "h]AYR",
        "UfoNaUE",
        "GK*RF",
        "WhgB5r",
        "=5=?=K=",
        "bDT\\,",
        "p1D2P",
        "syReVru",
        "HotFixMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "    Revocation Time: ",
        "A}MIj",
        "X{;m^w",
        ">:>Q>r>",
        ",'q<r",
        "gvh\"7",
        "XSDeW",
        "{3`8i",
        "*2gidW:",
        "Ks#Hl",
        "?$?,?H?h?x?",
        "Avsys\\Mail.reg",
        "V&%(%+",
        "@>W>2>",
        "curl_slist_append",
        "9<:m:",
        "d\\8LjT",
        "rRP2n",
        "n)Nxo",
        "B xj>",
        ":4:i:",
        "9?_^k",
        "636d6",
        "_C\"k;9",
        "l)<^PN",
        "iM(?<",
        "$24j]",
        "oA:47_",
        "}$O.j",
        "relativename",
        "Y+@7<",
        "W.)@r",
        "SE]CZh",
        ":HKVv",
        "3EK%zGjo\"",
        "Qq`og",
        "4LGQ<H",
        "uL5P9",
        "tLhP$",
        "CVi\\5",
        ":M}:C5A6",
        "*2Z@P*",
        "o*z\\e",
        "Is@^7",
        "6E]lX",
        "BLBUA",
        "ISACTIONPROP1",
        "@|2tDn]z]",
        "YQi\\3",
        "yv9nj[",
        "1^Ujy",
        "W\"c26",
        "J\"YeA",
        "XC8v1",
        "NONCONTINUABLE_EXCEPTION",
        "runtime error ",
        "1mza\"",
        "$|b:y",
        "+ /Pb ",
        "%2I64d:%02I64d:%02I64d",
        "'vhbJ",
        "vFvVvvy",
        "(<3[%M",
        "3@EHf",
        "7@7a7h7",
        "j(/\"\\t",
        "3-4O6Z6",
        "M`sAH",
        ")\\-XR",
        "h\\B7s/",
        "ogz>sn",
        "%$%Iq",
        "S%;-m",
        "6^ck/",
        "F43A379DDDC9A4643B5EF9DDF4A52078",
        "helper::setUpgradeMode()",
        "O2}}Qi0",
        "&&&&&&&&&&&&&&",
        "A<|}9",
        "DefPolExtract_rollback",
        "C1A5G~D",
        "#~s(y\\l",
        ")]!`gq",
        "9gU4C",
        "huw*OC-V",
        "o=N?\"ZS",
        "r(nKO",
        "_mktime64",
        "'uNun",
        "=']'\"",
        "^<M^d",
        "L8p}q",
        "0(1J1b1i1",
        "YZ\\6n",
        "kVJ^R",
        "@9u/,",
        "SetMemDump:  DumpFile = %SystemRoot%\\MEMORY.DMP, CrashDumpEnabled = 3, LogEvent = 1",
        "yG=9u",
        "IYke*%",
        "1CrJf",
        "wap-wsg",
        "y'WhH",
        "X]4j{?",
        "qBmO9",
        "O-XBj",
        "*s]:Z",
        "}RLmnm",
        "QV0wJ",
        "_Gye4",
        "34383@3H3P3T3\\3p3",
        "3u@K+u\"",
        "-[`$=",
        "uIFJ|3",
        "#I2e]`",
        "XORPD",
        "Qh991(@7",
        "[PqmFTc",
        "(~wSB",
        "YUO(x7",
        "5UwHn",
        "$Shk{lkEL",
        "XNZ%,",
        "<v}{ln",
        ")[-( MMF",
        ")fMK?",
        "L}Z:,-",
        "8#.E.",
        ";;c!\"",
        ">#o_e",
        "_,fd9",
        "tcvJN",
        "$;+;a#",
        "WINTRUST.dll",
        "<]0S(1",
        "3v_5f",
        "ZMFC2",
        "Rb&=`",
        "CT'=|k",
        "7\"IQF",
        "0Y+<|+B",
        "=2>^>",
        "u!9L$",
        "RCPSS",
        ".A&3W",
        "requestList",
        "class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::get_value<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct boost::property_tree::id_translator<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > >>(struct boost::property_tree::id_translator<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > >) const",
        "\\a'4\\",
        "50545@5D5H5d5h5t5x5|5",
        "~u:+Nq",
        "X Gi0",
        "zl.!O",
        "@cdDg",
        "Ia_i>",
        "<g7M`",
        " {_kkd",
        "FTP: unknown PASV reply",
        ",gQ9q",
        "d$QiI",
        "~03-Fb",
        "t:wGo",
        ".?AVinvalid_scheduler_policy_key@Concurrency@@",
        "\\NH2r5",
        "%*\"[r*",
        "4[4`4m4x4",
        "JMFZ{:",
        "NAOLFD",
        "!Wj&1 ",
        "x:CB{(",
        "9$9,949<9H9h9p9|9",
        "585X5`5h5p5x5",
        "262R2n2",
        "kl#(n",
        "mnTa@n[",
        "a/54,",
        "7;k]:5",
        "azh\"M",
        "F?tS\"",
        "LB'O ",
        "-F6AM",
        "eikJ>",
        "p{*}'",
        "CMS_RecipientInfo_ktri_cert_cmp",
        "ue4@m",
        "`template-type-parameter-",
        "oLRy]",
        " qyb=",
        ";\";G;e;y;",
        "'HPUs",
        "9|3`Ve;",
        ".?AVUMSThreadInternalContext@details@Concurrency@@",
        "3bo[g",
        "?Pr3Q",
        "DWpn#",
        ")f]\\+",
        ")4^-L",
        "unsupported private key algorithm",
        "'7j[qX",
        "RC4(64)",
        "@=pe]z",
        "tiWSV",
        "CT Precertificate Poison",
        "9]0xT",
        "http://sv.symcd.com0&",
        "2l2x2",
        "zh-@w",
        "Pmr\"o",
        "rwa<<",
        "modQZ",
        "z-b!X",
        "Qht\\N",
        "o2M@r",
        "hFRLjr",
        "Hh9cG",
        " EWPr9e20`",
        "<{Q}<",
        "9yoA(c",
        "sT3Gg",
        "DSA_do_sign",
        "uZxYZ",
        "1?2P2W2e2~2",
        "9fERN",
        "_Wkiu",
        "SZte:@",
        "VA~5@",
        "*O-4~",
        "pa=z8",
        "$X<ra",
        "~=H=x",
        "4^U!Z",
        "iN0`A",
        "K6zB.",
        "**~te",
        "t/NO&Q",
        "ew__[",
        "lm+u{3",
        "6<xF]",
        ";7;G;t;",
        "Vz2G(<H",
        "/:Sb\"Uq",
        "=5=V=f=",
        "8\\9s9",
        "*;x]b-",
        "Kz+R:)R>UI",
        "^\\]uL",
        "fsM^z",
        "kYe6v@K46",
        "~lq5OS",
        "Z-F+pA",
        "|nylP:",
        "(\"(b(",
        "565R5n5",
        "i`.wd",
        "2J2{e",
        ":}9Fj",
        "8/\\or",
        "RC2-CBC",
        "K9zG=",
        "}r2sF",
        "<.=4=^=o=",
        ";n=!#",
        "QinlQ",
        "not upgrade, do nothing...",
        "9)9L9S9x9",
        "2/3q3",
        " 0x80",
        "6`OIw7",
        "6.g C",
        ")Y;!?",
        "telephoneNumber",
        "j+j;j[jk",
        "Not ZAMailSafe entry",
        "DT-BK",
        "sect163r2",
        "OB<Y@j",
        "gI2,Z",
        "bx2yk]",
        "oldKAVdrivers",
        "(Cxi~wC",
        "tN9\\$",
        "ke92l",
        "jIh,B%",
        "Ceax^",
        "n{Bhs",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\featuretvdriver.cpp",
        ";-<H<",
        "QHGmo",
        "{ilF~",
        "jejfj",
        "6(6B6J6U6l6",
        "]i|HH",
        "xS@(VSo",
        "DH-RSA-AES256-SHA256",
        "`r)I%",
        "%eZi`Q\"",
        "w;gBP97",
        "v)u}@",
        "zcnHLv",
        "1 fco",
        "ecdsa-with-SHA256",
        "7M7T7]7f7",
        "\\par }\\pard\\plain \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid13701052 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af1\\afs20 ",
        "8\\.VF",
        "nameConstraints",
        ":5)wL",
        ".a)\\nR",
        "[cQMU",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386\\charrsid15169477 ",
        "VhDcL",
        "_bc$\\",
        ">(>0>4>@>H>L>X>x>|>",
        "@+$%{",
        "6 6@6L6l6t6|6",
        "!E~U-",
        "SHA224",
        "0CrA?",
        "<<=@:",
        "pp~WoFO",
        "s:M5;H}o",
        "VTZZ]",
        "0(.<M",
        "VersionMin",
        "LDAP local: trying to establish %s connection",
        "3tfZ=",
        "FindFirstFileA",
        ",6LAB",
        "nwlut",
        "tmDk+5",
        ".t~?$",
        "aZg]F#",
        "A+q7N",
        "RSvox",
        "h#v-DWxP",
        "w.^+T",
        "3E0Z@",
        "333~3",
        "7<6[S",
        "=m9_}>0L0",
        "0jc0E-",
        "tgeFZ",
        "v\"y4bC~",
        "rJm<V",
        "Y$i;}",
        "G`uTnY",
        "oHzi3",
        "b~h}4",
        "[tEgB1",
        "$\\GEX",
        "qmhW7(",
        "?ecP<",
        "a*['\\",
        "Ij,TdY5'",
        "2/2H2a2z2",
        "Oa&+d",
        "SeS.O",
        "i_gomi0Er",
        "9-:D:o:",
        "838M8h8",
        "FC__>BG",
        "8\\<>'",
        "5jpP$",
        "no need for uninstall password",
        "gj.Ds",
        "W\"pJQAE",
        "_y+[3",
        "1.2i6O7y8",
        "sr-BA-Latn",
        "F|RRF",
        "L|9!=V",
        "qfk-g",
        "$ba;x&",
        "p Uy(",
        "McEax{k",
        "Cnzcq",
        "xd%;f[X",
        "T=SP6",
        ": :$:(:,:0:4:",
        "VenOHsX",
        "failed to get CustomActionData",
        "5!575O5Z5q5",
        "uR9B$t",
        "4\"7V7",
        "c2pnb163v3",
        "4x &]",
        "GetMsiProperties: %s : %s",
        "yNS({",
        "KrK,cY",
        "g^>\\=Ez",
        "9<}Ph",
        "k8LK?",
        "klupd_klif_arkmon",
        "FORCEREBOOTDIALOG",
        "L#Wy_",
        "CVTSS2SI",
        "cUhxLO",
        "]WA!3~",
        "<_=e=7>h>s>",
        "QxF~Q",
        "JoNTO",
        "icjJT",
        "ADcqk*",
        "%s\\%s was scheduled for removal after reboot.",
        "<~xM?",
        "NO_OFFICE_MODE property is empty -> return false",
        "\"@WMP",
        "x|%vC",
        ",_o&[",
        ";!=%=)=-=1=5=9===",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\removeconsumerclient.cpp",
        "Configuration",
        "jqj|j!",
        "ngM1W",
        "Q]2u6",
        "%$(hl",
        "problems mapping cipher functions",
        "FF*lw",
        "-f@U=",
        "#g)?U",
        "3t7&ag",
        "Y!?T7",
        "+5m|\\",
        "6-7V8f8",
        "\"t.=*Y",
        "Failed to copy 'none' into action type.",
        ";';|;",
        "8B9#<",
        "=.=V=g=o=",
        "%Y<Et",
        "l+HR@",
        "^<^<^P{Q",
        "5*5=5L5|5",
        "jhjlj(",
        "@fpAKd",
        "Wemagd",
        "\"%(Ha$",
        "personalSignature",
        "=$.TcLY",
        "FWb~tnZ`",
        "3H4_4",
        "o/\\vjHI/C%",
        "_g|z9v",
        "W*hD[[O",
        " \\VzDI",
        "e$_H_",
        " >\\.k{)%",
        "|uIHwu",
        "8hT58",
        "Eab p",
        "5R(zQ",
        "zYp/<O|",
        "j1dP9",
        "%s(%d)",
        "g/IWO_",
        "APvd]",
        ":W`J's",
        "7'787]7m7|7",
        "<ftj2",
        "DUUUUUTAQ",
        "sU8VGP",
        "@@3$c",
        "$[e3)",
        " soHa7i",
        "*9./V",
        "Xw_~u",
        ":F:i:",
        "M)#:GP",
        "+o4K)",
        "}k\"VP",
        ";!q8u",
        ".(z_.h]BV",
        "&Z.W1]U",
        "L$  D",
        "Generator (hybrid):",
        "/L1#:",
        "\\!rl`",
        "DeleteFiles:  Deleting ",
        "Vy09y",
        "+CyB*",
        "a:q1.",
        "wW*G\"",
        "des-cfb8",
        "3=1Cm",
        "C7Bz(",
        ":(:H:P:X:`:h:t:",
        ":U;5t",
        "CKD6|x+ViF",
        "/:Q)jdW",
        "YVEnq6",
        "qKc{y",
        "r63pO",
        "o;r0{",
        "Ni-Rt",
        "_tRzQ^",
        "jUe)&",
        "f(sEE",
        "HuO{|^",
        ">6>V>j>",
        "e.v\"y",
        "In state %d with no easy_conn, bail out!",
        "666H6a6t6",
        "J2kk*",
        "RoInitialize",
        "_'qc^",
        "ALPN, server did not agree to a protocol",
        "(yPLm=",
        "!e~fU",
        "\\90g-",
        "%9>w!.",
        "%`$dJ",
        "\\Oye{",
        "G<1rZG",
        "9Snb;",
        "G&bv'",
        "99Yh?",
        "[,v$#z",
        "C1A5G>B",
        "zN>~}",
        "1BEPcjwx",
        "Check Point Installer",
        "MT!}w_",
        "WTTM'{",
        "[3{EYt_/bvV",
        "=UHZ5",
        ";bO0|",
        "RUpBM",
        "tr;},sm",
        "L^3eG",
        "+QSqG.",
        "Nq:1X",
        "P/7i2Ib",
        "6F6K6",
        "Bb'.a",
        "south-korea",
        "sr>p ",
        "tB;wPt",
        "5sX>P",
        "6pH]\"F",
        "stopping vsmon.",
        "qrv:t",
        "SwWE!",
        "('\"]N",
        "2F5[ Q",
        "&!^3,!v}",
        "\\+,}UO",
        "r''sQ",
        "sdtDu",
        "excz/D",
        "ocN*8:<F",
        "SetPropertyNoOfficeMode",
        " PiReg.exe return %d",
        "iuv<o",
        "AtaX.",
        "htHjlY;",
        ".#{cf/",
        "3D$$!",
        "SystemTimeToTzSpecificLocalTime",
        "!C3`W",
        "<[.12N",
        "c[+Ht",
        "rability interfaces of the Products by any means whatsoever. You will not develop methods to enable unauthorized parties to use the Product, or to develop any other product containing any of the concepts and ideas contained in the Product not independentl",
        "J{8rs)F",
        "TRr6:",
        "Eo\"Yw",
        "C/n&F",
        "\"+_]JN",
        "/,&[I",
        "certStatus",
        "`.CaY",
        "KHC0+Ai",
        "=Q=V=[=p=",
        "b243fb67cd01feffffff00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffffffffffffffffffff00000000000000000000000000000000000000000000000000000000",
        "pContext",
        "%K-\"v",
        "j\"_f9y",
        "HfQ5[",
        "<f\\wbZ",
        "InstallSDL",
        ">J>U>",
        "\"idD-",
        "&0If;",
        "Mg fZ",
        "9 9(949T9`9",
        "WIX_SUITE_PERSONAL",
        "?1xs$",
        "?SetSCUIAPIMode@@YAXKK@Z",
        ";u?AG",
        "mNx-/",
        "xHE(!",
        "Zl}]8k",
        "P#[IZ",
        "WinVerifyTrust",
        "X:`YZ",
        "8'}YW",
        "8/QA;",
        "ZPWSGK",
        "bD8|Dv{",
        "071W1",
        "Unj\\33,",
        "dingo_old_installed_path.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "?,?f?",
        "R-2Ps[,x<",
        "0A.NG",
        "#8fM`",
        "CPEPConnectDrive",
        "ASN1_HEADER_NEW",
        "T'Q07",
        "SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\GroupMonitor\\1.0",
        "hH:1F",
        "8(aiR",
        "3,3L3",
        "8E8X8~8",
        "\\>:T/(",
        "nL,q`",
        "20 iY",
        "0ChGY",
        "747P7l7",
        "031V1h1",
        "02XA7",
        "bgpvxa8vpvmx6i998ci8hujh740",
        "`3q+MB",
        ")RT-K",
        "-}xEN",
        "nt99*",
        "=~hcb",
        "r,G~2",
        "}|C}FVG",
        "{d#d_",
        "EMo*$%n",
        "%s %02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x",
        "DIp:b",
        "CMS_decrypt",
        "D:vlh",
        "{1j@9",
        "~twg_",
        "\"@KLq",
        "b;v~YX",
        "HL=[?",
        "U^Xs'",
        "1+@MUe",
        ">(s&\\",
        "QP6'>",
        "qDOW'",
        "dB <cL",
        "UZ'0g",
        "ODd?D",
        "OL-{bO",
        "b]{-[",
        "fOmdM",
        "Eo$Qp7}",
        "JUmK,",
        "/LD^y4",
        " 0x55",
        "}B0`k",
        "]NH#9",
        "6AEHo",
        "CheckIfRebootRequired started.",
        "}c4Pl?",
        "MGL0d|",
        "slG_Sw",
        ".Ag3=",
        "Zone Alarm Case - and trying to install Endpoint Security - exit installation",
        "!FjYQ:3",
        "wwjyR",
        "$.dZq",
        "id-aes192-GCM",
        "u3pB{",
        "YSZR^R_",
        "FAILED_TO_SET_MSIDIR",
        "s&CN\\]'",
        ":2;ZFT'",
        "<I,xk;]",
        "ccXb7",
        "<7<D<\\<r<",
        "7Ogva",
        "`M`MT",
        "\";^}<",
        "tU@>&g",
        "|?!n4",
        "/RV7s",
        "7t&Ww",
        "3 3(3C3K3b3m3r3",
        "M5:=K",
        "cR&|q",
        "#FR|@",
        "=[Nsg",
        "mBtN9Iki).`X",
        ")ZPfa",
        "vT[*_",
        "decrypt error",
        "|Zdj*Fk",
        "o6\\.a`",
        "L:c+W",
        "}7#KV",
        "{1n^,",
        "d2,j[",
        ";Lmkho",
        "{\\f68\\fbidi \\fswiss\\fcharset186\\fprq2 Arial Baltic;}{\\f69\\fbidi \\fswiss\\fcharset163\\fprq2 Arial (Vietnamese);}{\\f391\\fbidi \\froman\\fcharset238\\fprq2 Cambria Math CE;}{\\f392\\fbidi \\froman\\fcharset204\\fprq2 Cambria Math Cyr;}",
        "&./qh",
        "|(-*!",
        "wZ}Qu",
        "8Rix{",
        "IBrEH",
        "b?h;S_",
        "8-Cf-.4",
        "\"dQdQ",
        "u}Z -",
        "`U#l2;",
        "p4D{FE",
        "Sw?,a+",
        "/vY/v_",
        "SOI[m",
        "0*1M1",
        "H_x*aG",
        "Fj)[f;",
        "5!50585@5",
        "9pxEY",
        "l-S@_",
        "353N3g3",
        "`RK0Y",
        "aw!{'",
        "?IOV7",
        "nJ6tF",
        "Q+G,lV",
        "ExXhJ",
        "S:!{L",
        "M(b O",
        "6F(&n",
        "`J}51 ;",
        "`5~bX",
        "\\\\?\\UNC",
        "^=(QA3",
        ",z)MVhS",
        "[:_qb",
        "-:1c:",
        "SEC_E_NO_IMPERSONATION",
        "VXyBh",
        "hB/JQ|",
        "58*]S",
        "5 545M5\\5",
        "M19NL",
        "`7,7uW4",
        "&!JTp",
        "ikmdi",
        "flliUo",
        "kiLR7E[",
        ")G5k}@",
        "V2I_EXTENDED_KEY_USAGE",
        "-K^<V",
        "2,3z3",
        "?JONZ\\",
        "PSRAW",
        "4>5N5",
        "0kmY>",
        "T3{[-c",
        "@V`H69J",
        "}OY'Z",
        "ur^CNLq",
        "oC6{R",
        "__std_type_info_destroy_list",
        "vv~:2gt",
        ";5<Y<d<r<",
        "KI}J)]",
        "cwdEU5",
        "$(`RH",
        "sj$4y",
        "R9-y8",
        "XC^0+_",
        "System\\CurrentControlSet\\Control\\Network\\{4D36E974-E325-11CE-BFC1-08002BE10318}\\",
        "zv,Pt",
        "F(kKI",
        "LpY9f",
        "|2)`lIf",
        "s{4Rk",
        "-<hY\"",
        "y[nm*DA)",
        "{v%Eb",
        "#3\"L\"c_0",
        "kRh.`W",
        "Hi>3r",
        ".?AV?$_Ref_count_obj_alloc@V__ExceptionPtr@@U?$_StaticAllocator@H@@@std@@",
        "IAbIsj",
        "\\)HkU",
        " --install core;network;anticryptor;elam --klhkum_dir \"",
        "pDr1Sd",
        "*q9_G",
        "/`2z4K[]",
        "hZdT}",
        "qcIsw",
        "_';i\\",
        "jAj~j!",
        "U-R(U",
        "$Dk0D",
        "MyCustomAction",
        "LYl\\h",
        "777N7~7",
        "Yen~7",
        "Kqt\"F",
        "0t 1JS",
        "WAn_9",
        "bya?WIKk'",
        "ssl3_ctx_ctrl",
        "j]v8<",
        "(Ai@@",
        "FMz#?0",
        "7$828A8R8",
        "M@Lco",
        "D$PUV",
        "oPNfe",
        "{MDMf",
        "1r1z1",
        "\"$]DO",
        "NppW$",
        "M3rA@",
        "8q8z8",
        "%W=tO",
        ";D<K<Z<h<",
        "+eNRL",
        "XW?!<",
        "ji^DF;s",
        "HC~xE=",
        "b=1X|",
        "S~<qTi+s%",
        "+S!y@",
        "yI`-Duq7;",
        "UpdateZoneAlarmXml:  Upd_MergeConfigurationFiles succeeded.",
        "D$@h0V!",
        "\"ZE=3A",
        "KzVFS",
        "9.:W:",
        "L_fH^c",
        "6jC]$ry",
        "o|q|s|u|w|y|{|}|",
        "D$TPU",
        "DS_CheckIfRebootRequired",
        "k4r`0GiP%Q",
        "+u'wQB",
        "?A?F?",
        "+khK]j",
        "/9Zqg",
        "Delete shared dlls",
        "g(~X:",
        "Hg%^7V",
        "t5;L$$s/V",
        "\"aCzCc",
        "1.3.6.1.4.1.311.2.4.1",
        "=M<=/",
        "*y<X@k",
        "`bm[<BG",
        "&NeN1N",
        "6>c}&",
        "p?%wmK",
        "\\d @u",
        "'l-31",
        "W4#!6",
        "Qmw8t",
        "Q[>L]&",
        "_yY*m",
        "oU<@c",
        "jqjgj!",
        "ECDH-RSA-AES256-GCM-SHA384",
        "<'=\\=",
        "|5&NF",
        "J>pYZ",
        "_g@Cg",
        "Je(fX48@-",
        "cpnnWn",
        "`eh vector vbase copy constructor iterator'",
        "uW7_y",
        "kztj-",
        "Q94;#",
        "bQk-I",
        "qf6g]&R<",
        "hx49Z8",
        "SCUIAPIMode",
        "O=Ge@",
        "yYzj|",
        "MOVLPS",
        "`Lu.k",
        ";>_H_-^",
        ">DU#d",
        "S|sru",
        "krb5 client cc principal (no tkt?)",
        "1U2i2",
        "%Y},x",
        "9WsK%",
        "}\"7--",
        "eE[y&#0",
        "#C~!:|",
        "J4JHJXJlJtJ",
        "kzN~Nn",
        "ZlvIf",
        "(pE126",
        "d2i_ASN1_BOOLEAN",
        "`T)Y:",
        "[2gi1",
        "TLS1_GET_CURVELIST",
        "E?3M/",
        "Spgp%",
        ")dlKJ",
        "{cssX",
        "5 5(5L5T5d5l5|5",
        ":TFyX{",
        "VUW9\\$@t",
        "}F5o0",
        "uState",
        "CustomActionData",
        "858<8S8i8v8{8",
        ">Q3@r",
        "cX/ k-",
        " Fx[RS|*O",
        "PCMPEQQ",
        "h:#UPf",
        "\\!$u?c",
        ",X`<d",
        "!\\|tO)",
        "f:\\ckp\\src\\ep_libutil\\e87_20\\src\\utilities.cpp",
        "h\"XU:",
        "7)MZ23jD",
        "mLRA|-?@",
        " s\\7-",
        "_tqPVj@",
        "#M$j3",
        "~`.s!Dw",
        "|zH'#G",
        "<tK94",
        "\"]`FK",
        "cpjA1eH",
        "PreInstallCheck:  Another instance of install is running.",
        "a}o%TA",
        ",OL@<[",
        "StartTracService",
        "919\\9",
        ".?AVInstAction@@",
        "7i7lm",
        "Q:COY",
        "@RoE)",
        "D<</q",
        "protectEPAME2;",
        "VeN&Us.",
        "X\\ki?",
        "9 90949D9H9L9T9l9|9",
        "lnTToon",
        "UnregisterClient",
        "#YqYk",
        "SELECT * FROM `DuplicateFile`",
        "LfMvel",
        "bad locale name",
        "6#6+686N6V6",
        "_#7mrL",
        "PnB{xL,B",
        "QfvxbYBg",
        "q}E]X",
        "2'282I2Z2k2|2",
        "&2ghf<",
        ":\\H&'",
        "_<p)/6",
        "!SleJsnb",
        "KKYe;I",
        "r{;zJ*",
        "` \\ xO",
        "W##\"k",
        "y-wJ+",
        "rkcIc7",
        "6_vb40yvj)",
        "H<^b[",
        "899C9`9q9",
        "(`bnb",
        "f\"ynt@x",
        "4aID]",
        "=gO!T",
        "9EoZh",
        ":{se=",
        ".\\crypto\\pkcs12\\p12_p8e.c",
        "p%~I&",
        "i:LYK",
        "8!Xs'",
        "Q04qP",
        "4(4,4<4@4L4\\4",
        "ucp_files.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D",
        "4[,H\"",
        "%QL4)",
        "SINGLE_STEP",
        "h_e`W",
        "nCT}G8",
        "b-K-8",
        "9SWBt",
        "u$q6m",
        "RSGkt",
        "\\ZwSy",
        "Wj37b3",
        ".\\crypto\\asn1\\asn1_gen.c",
        "id-smime-spq-ets-sqt-uri",
        "4 4@4H4P4X4d4",
        "BP]IA",
        "=9>@>",
        "#|29k",
        "IRZ?'",
        "ME&r.P<",
        "+sM]T",
        "<JhD;K",
        "D<OM&",
        "2H!.:",
        "ProcessPemFile Done",
        "zu-ZA",
        "cu)RE",
        "\\L V8",
        "wBMU0W",
        "8%8A8]8y8",
        "\\4#[N~r",
        "fq&I'",
        "6gv)'",
        "s?s/;",
        "piKbg",
        "need organization and numbers",
        ",lA\"EX",
        "-%r#[",
        "=%=}=,>",
        "UUUEQi",
        "fI,h9",
        "DefPolPrepare ended",
        "<n/,Y",
        "+kqM\"1",
        "pF!2G",
        "{0}ai",
        "&Mio\"",
        "\\ZoneLabs\\zlquarantine.dll",
        "e W.t7CfwX",
        "\"PBQ\"R",
        "XD'o/",
        "Host not found",
        ".?AVoverflow_error@std@@",
        "'qvq5M",
        "Wx=sm",
        "2O3|3",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 TITLE AND INTELLECTUAL PROPERTY}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "5$5,5<5D5P5p5x5",
        "y.T*Y",
        "^T{bT",
        "4zwcZ",
        ".=a>R",
        "0$131J1O1W1_1f1k1p1x1~1",
        "7SUUV",
        "061E1p1",
        "9\":,:I:Z:o:t:",
        "3V7iN97e",
        "]e19rm=",
        "GOqDl",
        "|oOEnt",
        "T;Qs\"d",
        "SYSTEM\\CurrentControlSet\\Services\\FW1",
        "]YL~g",
        "<+=<=M=",
        "eq(O4",
        "o.q2R",
        "DPx)va",
        "T$$;_",
        "-<:[H",
        "TIA2*/+",
        "Kj'?)",
        "?$?,?4?<?L?T?\\?d?l?t?",
        ">?)j>",
        "QIGBG",
        "RunVsmonInstall:  RunVsmonInstall started.",
        ">GS#'",
        "generic cryptogram",
        "PADDUSW",
        "?R,]t",
        "3V3^3f3n3v3~3",
        "t\\j:N",
        "**>*4",
        "t$ hT",
        "EMMjkTi",
        "a_i[@",
        "'=o<<#9",
        "7)I6 ",
        "T^Lyl",
        "3\"4l4q4|4g6",
        "b\\x'z",
        "PSIGND",
        "#?d%,aa",
        "X06e^",
        "MWm2zh",
        ":;:R:]:m:",
        "1\\BNl",
        "$)'*qD!",
        "XJD*(",
        "X8vu74",
        "b\\P)/`",
        "/Do/5&",
        "O!!Pc2",
        "283S3n3",
        "O(/9[Q",
        "3F#\"\\",
        "ntdomain://%s/%s",
        "{h(ho",
        "t.y0sq",
        "9~8uN",
        "848K8b8v8",
        "unsupported option",
        "-P,ce",
        "o9:X`ZY",
        "B&W'a_",
        "0(0H0P0X0d0",
        "McAfee ViruScan Pro v7.0 Firewall (All SKUs)",
        "rWf;E",
        "Z9T-P",
        "FindWindowA",
        "y:yPW",
        "Connection #%ld to host %s left intact",
        "g3h~1",
        "[K.\"]t",
        "=_jd04",
        ": :$:(:,:@:D:T:X:\\:`:d:h:l:t:",
        "5)6B6",
        "dIo]aB",
        "~r@05M",
        ";(gpl",
        "si\\O<",
        "9=UFs",
        "L$|_^[3",
        "}II@qJ",
        "s$0j+",
        "a\\2d`",
        "V#J+R3R",
        ">w}vW",
        "*-&\"-",
        "Z5,UH",
        "rcOL6",
        "#.X'=",
        "kMffhJ",
        "mg4uD~",
        "ykU}+5",
        "33&R;g",
        "pTRRS",
        "eWn_M",
        "9~LtP",
        "_*_j_",
        "WiG>H8f!",
        "uNMM\\",
        "#N&^BA",
        "H@1&0\\",
        "V0Z0^0b0f0j0n0r0v0z0~0",
        "3Pcxc*",
        "Es[cr",
        "8D$0t$",
        "oe(,-w",
        "dwp[_",
        "`6%}1*",
        "m-IXc",
        ":0zFp",
        "Ld(x?9C",
        "6w67'",
        "data is wrong",
        "2Q2[2",
        "SUPERINSTALLER",
        "[o`oBm",
        "&w&ag",
        "k;GnjIS'",
        "JQ%GJ",
        "<9h'H=7",
        "-----BEGIN PUBLIC KEY-----",
        "4GfyW] t",
        "Rqor;",
        "?9?G?R?b?",
        ".?AV?$_Node_str@D@std@@",
        "< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\\<`<",
        "H0{12",
        "?}:gu8$",
        "KYzFM",
        "UiCjlk-Q.A",
        ".\\crypto\\ocsp\\ocsp_cl.c",
        "2ZtQ<",
        "`8oo-,",
        "===e=|=",
        "[WinFW] SetWFStatus, CoInitialize failed",
        "?5?Q?m?",
        "twu$9",
        ",m0*u",
        "CV,u=",
        "'zO{T",
        "RY?,l",
        "0.1>1h1p1",
        ",EWc/",
        "jsjzj",
        "$8<0[",
        "Fn9{4=3",
        "2Gz*GD",
        "U85u~",
        "6%>%H%T%Z%b%h%",
        ">!?H?",
        "OnEnd",
        "7FAio",
        "api_ms_win_core_heap_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "''I^@",
        "F.-ZK",
        "CY*`F$",
        "?!?=?Y?u?",
        "r%EeqE.",
        "**[6I\"",
        "Npu6-",
        "9XK08",
        "4':](",
        "uJ$FY",
        "J=WW>+",
        "tt!Xe",
        "G$MmN",
        "+Rw?~",
        "s=&rc?",
        "DecodePointer",
        "policy path length already defined",
        "/,++p@",
        "]^w<v",
        "VXfeSf",
        "zh0ch",
        "SSL_CTX_set_trust",
        "!1'D8",
        "#C3]*ZY",
        "EnV[|",
        "%Ty*cZ",
        "[l/}\"",
        "ASN1_STR2TYPE",
        "AIQ7QO",
        ",u: Y",
        "nw]!7K6",
        "6-6L6",
        "c-\"u-pmA_0",
        "=93P%kI",
        "2\\.K#",
        "n^Ct'",
        "gRg%G",
        "\"M_[K,a4G",
        "J<_^[",
        "Q5uJE",
        "0n1y1",
        "Q$:OZ",
        "V:o#5",
        "?,d`/g-",
        "VNA_STATUS",
        "k!f|m",
        "$rG0N",
        "\"8F`8)t",
        "tM([uMEu'f",
        "FAC driver Rollback failed with error: %d",
        "BY5\\h",
        "Wudj\"(6",
        "CreateEventW",
        "X$GsP",
        "KflTf",
        ":1;H;S;^;g;n;",
        "%RcL1",
        "kn{(l",
        "lPOv6",
        "Error: ERROR_BAD_QUERY_SYNTAX",
        "jxhG+",
        "Disk full or allocation exceeded",
        "{8B|-",
        "uYp`m",
        "GetBladeRequiredDiskSpace: MsiDatabaseOpenView failed with ERROR: %d",
        "F;sx|",
        "R6033",
        "n=a6M]",
        "z):|?",
        "w3V$_",
        "P?Pc ",
        "qUbZS",
        "_@7^$-",
        "BUF_MEM_new",
        "!C#&y",
        "6?6T6n6",
        "uJCC97",
        ",<\\.0g",
        "SQ_XH",
        "s^gS_+",
        "8w^+^",
        "{|CKy",
        "9(9,90989<9@9D9H9P9T9X9d9h9l9p9t9x9|9",
        "[L~jr",
        "GId?C",
        "Independent",
        "x{RUeZ7w",
        "t_h5>",
        "tp38|",
        ",I7b/",
        "5Z6r6",
        "Y`9\\9",
        "t8tXt",
        "v ?J)",
        "or other countries}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14296673\\charrsid9533499  and/or may be subject to additional export control laws applicable to You or in your jurisdiction}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "+8;<F",
        "b!)r#",
        "1 1$1`1d1h1l1p5t5x5|5",
        "22222222222222222222222222222222",
        "#n3n?J",
        "=&>E>_>",
        "0S.Jj",
        "rM2-S^",
        "|C/fV",
        "o>7bj",
        "]prw-",
        "u,9]4t",
        "e}@Zk",
        "CheckUninstallPassword",
        "t$Ph@",
        "Nx3Ek",
        "kZZS*s/i",
        ":yKa?)",
        "u 9G(ti",
        "ReplaceOrAddAttOrTagIntoVSConfig():3 %s",
        "3MM%]t6sEpM\"S",
        "EPAM_CleanLeftovers.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "`a_wMf|",
        "\\XV g#",
        "#iYC&> Q",
        "[H{Mw@",
        "SRP-3DES-EDE-CBC-SHA",
        "[^HO/",
        "BuildTrusteeWithSidW",
        "nnv^FK",
        "encryption ctrl failure",
        "E2f4H)",
        "{]{eI",
        "S_+,T1G",
        "P&+Ba",
        " 8q~j",
        "v:SS0q-",
        "1)D(i",
        "0-0H0b0o0}0",
        "{YQg?H",
        "#]R>B$",
        "3R3h3",
        "~Q1I<",
        ">tZ /",
        "R|\"\"l",
        "7ra#CL",
        "A0V0[0",
        "'KN{a#",
        "3_?Rby,X.`!7",
        "3X\",L",
        "nYbt\"",
        "-o|2:",
        "VjwqN",
        "record too small",
        "1{s$~2I",
        "__setusermatherr",
        "l&:[n,~",
        ";\";h;",
        "`{N/h",
        " 8gy@",
        "w!_iI",
        "zw}..u",
        "\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\f40\\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon11 \\snext43 \\slocked \\spriority59 \\styrsid3737333 ",
        "+R@Ue7",
        "f75U]",
        "`$<a_",
        "?s31*)",
        "$`JtJ",
        "`cC#( ",
        "sc+&*",
        "}5ySp'F",
        "C_9G&",
        "/p,Wi",
        "8D9L9",
        "9ekfs",
        "CreateService failed: %d",
        "+-ni-",
        "Vj'fY",
        "&*ow<'",
        "(@]D%",
        "h*O+!",
        "<^ufl",
        "N1nF\"",
        "$=.i9?",
        "mXLAU",
        ",505T",
        "(GEk|",
        ";$mj}",
        "\"Gu!.",
        "Q{k3S",
        "l0e06m",
        "jpjuj",
        "i<[is5{",
        "m+n>^",
        "k6w6T|Q",
        "epcginashim.dll",
        "3?*2;q",
        "zi-:C",
        "~r\"=Bj",
        "Og{F!",
        "T7TWTwT",
        "P'M' ",
        "B:gKv",
        "[W?*=",
        "Gd,GD",
        "h[S|@",
        "invalid range",
        "QueryFullProcessImageNameA",
        "9gTVO.",
        "8YINI",
        "Copied vsdata.dll and vsdata.dll.1.",
        "lE^.t",
        "6v8Wx",
        "OJHmuj",
        "32y/Z",
        "XIMcJ",
        "4Q8yo",
        "cnq0K",
        "PKEY_RSA_CTRL_STR",
        "?J8+.E",
        "%=?vC",
        "H/P]lH",
        "Cx{_5",
        "f7e5#",
        "31dNI",
        "OnInstallBegin",
        "Z2[tY",
        "g'qcg",
        "194l;.[2",
        "olmbM",
        "Vj|h $",
        "TFY{z",
        "qtexec.cpp",
        "Zf[\"W",
        "c1I}N",
        "|$b\\A",
        "+}A%e",
        "<$<.<8<B<L<",
        "/\"%V$",
        ",+\"tZ",
        " 112JF",
        "n0*+Y",
        "\\q!B-",
        "2op>l",
        "#D[bdd",
        "L$$1t$l1|$h",
        "/D'\"O",
        "dF^-p",
        "9=YbPd`",
        "YPSWA",
        "u3juhp",
        ".\\crypto\\asn1\\a_d2i_fp.c",
        "e m,D",
        "j-Yf;",
        "BO#Sw",
        "QPa?D",
        "6S:e;u;",
        "F:\\ckp\\src\\EP_CALib\\E87_20\\CMpub\\bin\\win32.release.32.msvc141\\InstHelperVPN.pdb",
        "<0|H<9",
        "NQ;;'T%%",
        "norwegian",
        "2Op^1",
        "?P'C\"8s",
        "?(?4?@?L?X?d?p?|?",
        "zzNW~x",
        "u0jsh",
        "#rc&E",
        "<mE?^",
        "cM KQ",
        "ExecXmlFile",
        "Cj%pV",
        "Jq1o<",
        "buffer error",
        "SjmhD",
        ".|$~F",
        "X509_ATTRIBUTE_set1_data",
        "=VT:~",
        "(';3\\",
        "V`@i@S",
        ";)Ixin",
        "IsRebootForced:  REBOOT=",
        "E4j8h(G",
        "\\f1\\fs20\\insrsid11543880\\charrsid15169477 To request an RMA number, you or your local Check Point Certified Solution Provider (}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8463807 \\'93}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "k{\\> ",
        "P[{\\^",
        "Z8T'o",
        "1b5z:",
        "KsKsn",
        "rRj;B7|",
        "gyZ@k",
        "$yoMZo",
        ".?AV?$_MallocaArrayHolder@PAVContext@Concurrency@@@details@Concurrency@@",
        "90t6A",
        "jQjFB",
        "*t^DX",
        "T4p#P",
        "2~lvm",
        "J&88J",
        "gSC^U",
        ".&QUE",
        "AECDH",
        "v.Lkc",
        "&ZFNR",
        "QQ2g-",
        "fsv}:",
        "5V5a5k5p5",
        "N<PSR",
        "ENp,9",
        "G3Sbj$",
        "PVO!?",
        "I1zuN",
        "7rCGn?",
        "+%2*q",
        "processes",
        "HENEE]u",
        "^M)Hj",
        "\\QjL2X",
        "\\K7..O",
        "9Wi*:",
        "|;V#[>",
        "XWq;{",
        "c'xj:",
        "uf}_H",
        "@W>yRN",
        "fPXPR",
        "BV9Yq",
        "'&+fGB",
        "P`f&BzA",
        "7{MC9",
        "Zw m*E",
        "9M>]y-",
        "Yf6uye",
        "gg+klB",
        "CANT_GET_COLUMN_NUMBER",
        "z0p%N\\B:",
        "93t!hh",
        "L#y6{",
        "@q@dh",
        "VZrU@",
        "QhvB/",
        "C*hPh",
        "DQKU;",
        "7e+7e",
        "./01234",
        "e%4@D",
        "e*xV*",
        "-,WRj",
        "u*1y]",
        "Sw{Z\\",
        "&h(H.\"/w",
        "~=+y%",
        ">~!Q(",
        "lfVMRN",
        "t#[;L",
        "F<iZ)",
        "qB/0q",
        "d:4BN",
        "pqT3^-ZI",
        "verify",
        "7-L8}",
        "a<^2_",
        "!GW. ",
        ".9JHO",
        "[\"8%9(9,9?9C9G9N9d9!",
        "<yy2<f\\",
        "ja-JP",
        "Vxs~}fX",
        "DllRegisterServer",
        "!i5i8",
        "v2i_ASN1_BIT_STRING",
        "NCONF_new",
        ",V(L\"",
        "\\QFz.b",
        "ae'Q]",
        ",>uj2b",
        "(Ht5F",
        "^oa)h",
        "IS!K&",
        ";-Kjc",
        "=w!J2",
        "file type P12 for certificate not supported",
        "TS_RESP_CREATE_TST_INFO",
        "SystemFolder",
        "xPh4r=",
        "-:=qAl",
        "pN1!,",
        "dkyIq",
        "ZLC(C ",
        ".\\crypto\\ec\\ec_lib.c",
        "n#Ak}",
        " 0x5b",
        "}bR$4",
        "TPzf/2",
        "9 9)9A9U:^:",
        "jp.ja",
        "'YatB`",
        "?{2]j",
        "wk@_%*",
        ")1c:|",
        "$e_ f'",
        "H&:@8",
        "FGcpN",
        "CFn=/",
        "upR8c",
        "223D3y3",
        "OnFreshAfter:  started",
        "  yfM",
        "-pXsD",
        "[VSDATA] FirewallAddLocalIP: adding IP %d.%d.%d.%d",
        ">:?g?",
        ";Y87&6",
        "\\@C5+)",
        "u @pJ",
        "L.x(J*",
        "FoYPTUP)",
        "a^?i3",
        "Private-Key",
        "qE\\@7",
        "q<=!(",
        "logging on to vsmon",
        "w,bnL9",
        "6xL?i",
        "2q0ZRd",
        "+F,uY",
        "4;4K4Q4V4",
        "-}4}%!",
        "2].Tf",
        "C35|AN",
        "[}T[F",
        "# }mpQ",
        "QQSVWh",
        "*X]m9",
        "HsPmK",
        ";?Iw3",
        "0<1Y1_1y1",
        "length mismatch",
        "PajuR",
        ">z/Rk",
        "Wu!WWW",
        "t36<i",
        "VzNs-vU",
        "0S0z0",
        "N%su2?M",
        "s<*0U",
        "- not enough space for environment",
        "=7>>>I>",
        "private: ",
        "Zp7 2",
        "2+2:2 3",
        "_5(V ",
        "+3J%LoGT?5T",
        "+(S,H",
        "ot6K-",
        "MmiP$",
        "L/N2@",
        "l8L23C\\",
        "#V6#<",
        "tKZWi",
        "5N@pSsa",
        "4 5$5T5X5",
        "pra0p",
        "|j{W ",
        "< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\\<`<d<h<l<p<t<x<|<",
        "Kt?69",
        ">~z$VN",
        "p[T~ajH",
        "tx/wD",
        " set ProductName to %s",
        "cH?4Y",
        "NOP*Q1BR'S8/T",
        "9L9e9",
        "!F>XQ",
        "bF\"U$",
        "3&4/454",
        ",r\\X$",
        "de$GN",
        "1J'hN.",
        "LD5e!",
        ";(;E;v;",
        "9n949H9L",
        "wp,$Y",
        "\\zbJ2",
        "E)yBP",
        "-c}F{y",
        "3CP1:C",
        ">\"?B?j?",
        "6@=D=H=L=P=T=X=\\=`=d=h=l=p=t=x=|=",
        "2(3|3",
        "3!3/3=3B3N3[3e3",
        "+i^L>v",
        "\"F~-6",
        "I\"o`}N-0",
        "2?5C5G5K5O5S5W5[5I9S9Y9m9y9",
        "Z#\\rp",
        "7&,p\\",
        "5EA1O`P",
        "Yk/F3",
        "GetDateFormatW",
        "]\"qG~",
        "$:WM``",
        "-JKM=#",
        "jBj~j",
        "?P[c5P",
        "s@wTh",
        "eDa/c5y",
        "U\\r9nmT",
        "unknown digest algorithm",
        "K|p%[",
        "Check Point EPS Firewall Service Dll",
        "vNvNvNDE",
        "8UweQ",
        "<;u:V",
        "S6Lo!==",
        "u=ibp",
        "zU&3n",
        "PIX3|",
        "9D$8t",
        "3X6Op",
        "<*vA)",
        "\"{-693<",
        "3<Lu!",
        "!`^`@AY.",
        "B>G!T",
        "N/SK?B",
        "}*Go\"",
        "47wcvr%O",
        "7C7(:",
        "#$}ia",
        ";XX(;ov",
        "uZA6h",
        " q yX",
        "?SASLu",
        "::;h;'=6>U>",
        "~Y/GA",
        "_~iTY",
        "j){:a",
        "DEC A",
        "kOUTUv",
        "Om&~~",
        "xd`+oz",
        "|>IH_",
        "VS_VERSION_INFO",
        "/]\">.",
        "YoAWK",
        "We=0T&",
        "Pgt\"cY",
        " 'cpd0",
        "YmEpR",
        "7o\"E5]",
        "%0?XJk",
        "_)1un",
        "PRHelperIsRunning was already created",
        "#zylM",
        "0EBNxcC",
        "|:n]X^",
        "gnvbW",
        "vyp^<8",
        "qG]pT,|",
        "7 7074787<7@7D7L7d7t7x7",
        "7!My(",
        "/x2Kf",
        "7,707H7L7T7l7|7",
        "ef&LO/",
        "^;h,T",
        "tvfwConfigChange",
        "7j)M !>f",
        "unknown pbe algorithm",
        "h'N+K9",
        "wcautil.cpp",
        "5#=L=",
        "4-4F4",
        "fFP/_",
        "v'&.m",
        "8U,`q",
        "Zb.=-",
        "Aa}r1",
        "l=6PX",
        "wrap mode not allowed",
        "ssl_parse_serverhello_tlsext",
        "%z_(b",
        "@I@I@",
        "fzdPX",
        "9%z\\x",
        "t0xfK",
        " T4g(o",
        ":6;H;b;r;",
        "File already completely uploaded",
        "jr1jN",
        "XI38c",
        ";(m[/",
        "7_zF<A",
        "{S0ZU",
        "WixCreateInternetShortcuts",
        "H5gRR-",
        "0wL/7C",
        "@<g?g@",
        "\\2Mu&6",
        ".bOm7",
        "[BP+SI",
        "4<(0z",
        "I6BAm",
        "Hg,F*",
        "tu>+(",
        "BeUNO",
        "(0J0^0e0l0",
        "~(9~0t",
        "D<$hF",
        "$55BL30/",
        "=%>[>t>",
        "Removing shortcuts from Common start menu",
        "REMOVEPRODUCTS is empty, there is nothing to remove",
        "MlZ]ZG",
        "=Ut{r",
        "e/Kl2",
        "QVVVP",
        "9H^pN",
        "QRVSQ",
        ".;bdC",
        "#&wj<",
        "~d|G ",
        "dp?^\"x%\\Gx",
        ">{\"a9e*",
        "Closing connection %ld",
        "h0vNvq",
        "ssl_undefined_void_function",
        "transfer closed with %I64d bytes remaining to read",
        "AES-256-CFB8",
        "7UptT31",
        "IrW\\U",
        "2%2U2",
        "C\"k(2:b",
        ";type=",
        "aExecXmlConfig",
        ":q'Mcm6",
        "S`tE!l5",
        "cR-mN",
        "-QWfyv",
        "&Z;TT",
        ":#;2;9;g;l;",
        " nCE]",
        "NIST/X9.62/SECG curve over a 192 bit prime field",
        "new_extender.bmp.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "jXYZl",
        "F4lqW",
        "bcBe\\6",
        "gu|sg",
        "&Y+]&",
        "\" aSB",
        "]'!1.$",
        "failed to tick progress bar for shortcut: %ls",
        "7 ~gf*",
        "\\$r\\(>",
        ";3$/tM",
        "767S7",
        "shutdownVsmon",
        "LIST_CREATION_FAILURE",
        ".?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        ".?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@",
        "UKQ LA!/",
        "y@Aa]}",
        "2t0HW",
        "aK!CW",
        "C#z^x",
        "gT/a;",
        "Host:",
        "3V4g4",
        "WGsf9",
        "3t$83",
        "PMOVZXBQ",
        "94~vb",
        "OuiqC8^",
        "9##$%",
        "!(!uJ",
        "e%!.=",
        "48&'=",
        "0@0D0t0x0",
        "lSHV|+",
        "z)/3Z",
        "L=l6q",
        "OutputDebugStringW",
        "}F\\0'",
        "$.EBg",
        "!Y+e`'",
        "(V),[K~",
        "<BDAVFileProtectionOff>",
        "+hbs5",
        "3\"4`5",
        "1;R0X",
        "m<d3M",
        "}6V)*",
        "|9z]Y[f",
        "!]ZU\"",
        "<(M4b",
        "nf:x3",
        "d9jN}R",
        "7,7@7T7h7|7",
        "y*eq,^h",
        "4'4O4o4",
        "H/qc@",
        "VSINIT",
        "rw9<UD",
        "ZLProduct.Features.pFeature failed",
        "[VSDATA] Failed to allocate %d bytes of memory",
        "?)p\\%;$",
        "<N_>9",
        "~p^~Qi",
        "0RIS<*",
        "1=u~i",
        "8F9BE",
        "H_WKd",
        "|^A)x",
        "?e4e3Q",
        "Y\"v'<",
        "SSLv3",
        "}g>ol",
        "{\\f394\\fbidi \\froman\\fcharset161\\fprq2 Cambria Math Greek;}{\\f395\\fbidi \\froman\\fcharset162\\fprq2 Cambria Math Tur;}{\\f398\\fbidi \\froman\\fcharset186\\fprq2 Cambria Math Baltic;}{\\f399\\fbidi \\froman\\fcharset163\\fprq2 Cambria Math (Vietnamese);}",
        "4[s=q",
        "jkjgj",
        " UNINST_PASSWORD=<hidden>",
        "nO=a#>ST",
        "uaqvIr",
        "~5O_U",
        "K6wPH",
        "= hzU",
        "$s[@|",
        "aB\\YY{^d",
        "mCtH(+d",
        "Cd%FH",
        "i$gtH",
        "1,1P1\\1d1|1",
        "0`*Aj",
        "3T$D3T$<3T$,",
        "\\f1\\fs20\\insrsid12151078\\charrsid15169477 roduct }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 (or replaceable unit) suitably packaged according to }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 the }{",
        "/~F#r",
        "_)UN.",
        "W`VlVB",
        "3K`||",
        "uGj\\h\\",
        "DRuntime Error!",
        "|(vo.",
        "[]+&;&O&d",
        ";g#/jh",
        "M4  pj",
        "%Rvy!",
        "msSGC",
        "j1RT)",
        "(THrZ",
        "n\"O~bMk|",
        "]@?~`",
        "\"#+:>_l",
        "E[b9=7",
        "HM|y0",
        "4%b!,",
        "0O1\"6",
        "W&z2:",
        "70RZH",
        "TUUbC",
        "3C0dq?",
        "n-d0P",
        "V2jx_f;",
        "ShE87",
        "UmZ1K",
        "X21r(",
        "c}A\\(",
        "[VSDATA] AddDataClient: OpenDriverHandle() failed",
        "[X/$=y",
        "Sdo>2",
        "$p)8s",
        "5:6*8",
        "$cH~Un",
        "[<3Tu%GO{",
        "MJK[`",
        "8xx33",
        "Ep?bo",
        "T#rsJ4N,_",
        "c `:$>1",
        "fO=Zfz",
        "I0-0-EA",
        "]bP=<",
        "BAgai68!",
        "rZ63*",
        "P^:{Z",
        "t2vqeXA",
        "enc->iv_len <= (int)sizeof(iv)",
        "iSVx#';",
        "^OQd-",
        "mFnah",
        "MB';'",
        "5(6-6\\6x6",
        "DEF_GET_CLASS",
        "TZG_5>S",
        "=:nuv",
        "eai<|",
        "eh;;Er",
        "1BO<~l",
        "8X<jl?",
        "G#D$(",
        "bIaP-V3ua",
        "VSInstallerCancel: failed to get client. ",
        "o}9g0{",
        "kp3C-",
        "74v8q*j/",
        "=VG1t",
        "~^wRy",
        "YX1#7",
        "4[Tti",
        "EVP part of OpenSSL 1.0.1t  3 May 2016",
        "*h2`U",
        "=4>O>",
        "`4.]{5",
        "VE[Zl'-",
        "%-/J2",
        "|yfgav",
        "NMqVp|",
        "Jtz=T",
        "7F8X8",
        "gE{=x",
        "Xk $b",
        "Cp_]|",
        "(1a2xD",
        "B|eQ5",
        "q0p8p",
        "Extended OCSP Status",
        "v6$kv",
        ";C;H;};",
        "JDHW\"",
        "\"aj&V",
        ".]`q}",
        "#':QNgW",
        "M/9)HK",
        "CSOk?W-b",
        ")3CHa",
        "rG%m0",
        "D_Dj/",
        "PreInstallReboot",
        "pOSP=Iz",
        "+&{ww#",
        "SpIz\\>d",
        "x>B=}",
        "3^}\\=",
        "T]k=rX",
        "auG7j",
        "InstallationType",
        "e5WQ49",
        "7xX.  ",
        "$Y`^H+",
        "1.3.6.1.4.1.311.2.1.4",
        "GetFileVersionInfoSizeExW",
        "Ft\\k9",
        "NETSCAPE_CERT_SEQUENCE",
        "> >(>0><>\\>d>l>x>",
        "9l$ |Pj",
        "CONN_STATE",
        "}ip]c",
        "U0Hqi",
        "99:l:",
        "?]xP)",
        "''k@)",
        "wvsprintfA",
        "h)%#K",
        "'K[=|",
        "VhpLM",
        "GiZO ",
        "JW[Y`=y",
        "dL((+",
        "*pLN]",
        "{EPI-P",
        "SOFTWARE\\KasperskyLab\\protected\\AVP7",
        "RegRestoreKeyA",
        "RhtFe-",
        "3O4b4y4",
        "<&'D18",
        "@E{[T",
        "gY&L]",
        "BbACtg",
        ">Y?r?z?",
        "i\\?W[",
        "?Sgid",
        "=+>5g;",
        "689ec9166e0a522183792b8907ba55ca6e943bbf2a26e52f48957218ffcf54d1fb09dc3eac04da033e5c0d0b8c74a6b43d2e54c4a10aa511f5fb021a07533b20",
        "K9K33",
        "ayEe/",
        "f^w\"\"t",
        "Trying to terminate process brutally",
        "`MMMMMCK",
        "6`6O7w7",
        ":0:;:",
        "8[e\\a&",
        "}?N\\Y",
        "^{=Ml",
        "C_^][",
        "?va?\\",
        "setct-PIDualSignedTBE",
        "*7!m(",
        "NzUq\"",
        "twcOo",
        "4qK7g",
        "yYl\"b",
        "D$43G",
        "*6w]^",
        "qN\\~0",
        "MCz~Kk",
        "!bVH)",
        "Y*Wgd",
        "?btvx",
        "{s.w=i`",
        ")kUkD",
        "ht1%yH",
        "R!=qA",
        " wb,F",
        "t.U+.",
        "]U>2$",
        "mVV[h",
        "9kc\"}qR",
        "I`\"a6",
        "EHLO %s",
        "ENCRYPTED PRIVATE KEY",
        "<2<J<f<}<",
        "es-uy",
        "6'767",
        "ka-ge",
        "Ni`n#bA",
        ",^O;M",
        "4b:@UF",
        "5B5V5r5",
        "`{Ctj\"J",
        "KW:yS",
        "WjcV:",
        "0 00040D0H0L0T0l0|0",
        "1CAw`",
        "SUVWhh",
        "1(1A1Z1s1",
        "3-3I3e3",
        "L@Xdr}",
        "jCjtj&",
        "*X9QQ",
        "jEdxqv",
        "G}J/xw",
        "2P3T3X3\\3`3d3h3l3p3t3L8P8T8X8\\8`8d8h8l8p8t8x8|8",
        ";5=M`",
        "6\"7D7X7n7",
        "R1M1S1",
        "MEMORY_LOCK",
        ".m?Me",
        "6<8K8",
        "2<2@2D2H2L2",
        "<ZkX?=US;I",
        "e%t;h",
        "3'474",
        "00-C0-45",
        "SKul5",
        "@teh|",
        "=+fY/",
        "$8_vsq",
        "wREk/",
        "sz#^+",
        "-`+Aq",
        "fRV9PS",
        "msvcp140_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "CertEnumCertificatesInStore",
        "Mg+&> R",
        "q'9]q",
        ":wrJO",
        "EsU\\As",
        " 0x5c",
        "O&>s)Sny+",
        "d.ediPartyName",
        "\"wX}W",
        "%>2\\5",
        "_Uvob]",
        "AbybR`",
        "&{:y*",
        "n}rJ!>",
        "?-L'z_v",
        "(h]Ud",
        "uYMVD",
        "eeeS&",
        "y2p>S",
        ";}^J]",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid12071538 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566 You may contact Check Point t}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        " 0x91",
        "lB8%o",
        "3cn$\\^",
        "S4}&'",
        "aes-192-cbc",
        "]~mdw",
        "'ma,^B",
        ";6;R;n;",
        "dl:HQ{KDM",
        "PFFis",
        "f6u1#.",
        "trV:}",
        "cKVt(",
        "CL,r.",
        "H4k[7",
        "w9;RU",
        "'DaTB",
        "b[[oN",
        "_lopen",
        "_h#Z#'",
        "QNE/l",
        "a&A+NeK",
        "Hx5Jc-N",
        ":p(Or",
        "TerminateThread",
        "ejT=S",
        "?\"?2?7?<?L?Q?V?f?k?p?",
        "*w;+L",
        "o76eA",
        "9,9791;H;",
        ":-_wK",
        "l?kUb",
        "[wXce",
        "s`3<Y?",
        "3]kqD",
        "9M9j9{9",
        "w#e:B.",
        "`X1w^8",
        "{f#aw",
        "uw2~p",
        "}8fE>f",
        "gw_S-L4",
        "rGsgs",
        "C`yQud",
        "RdqyF/R",
        "lr@i9",
        "x/H<k",
        "GetProcessAffinityMask",
        "!X.=N",
        "k:+,S59L/]",
        "5+5G5Q6",
        "C$nJ+",
        "5#5/5H5",
        "/nU*x",
        "spkac",
        "1\"1/1C1Q1Y1e1o1y1F2U2q2",
        "U),m;WW",
        "INlU\\",
        "RAWt:",
        "tldo!\"",
        "EVP_PKEY_get1_DSA",
        "e#FpV",
        "(7n~'b",
        "j4LKR",
        "J[EDKjY",
        "tmUVU",
        "]1Sf'",
        ";GF5`",
        "MdxZp,",
        "]?H=dz",
        "u58D$",
        "quz-PE",
        "ITs$sCs|",
        "lt%4Y",
        "%#S5-8",
        "1A2O2]2b2n2{2",
        "8'848;8K8Z8g8v8",
        "; ;,;L;X;x;",
        "9?/X(",
        "BCqq9",
        "p-U-u(",
        "#eU4D",
        "RSA PRIVATE KEY",
        "t?w!n7",
        "'UTSNX",
        ",$P\\&,{Kgm]X",
        ".?AU?$error_info_injector@Vptree_bad_path@property_tree@boost@@@exception_detail@boost@@",
        "Z]^fDL*ZFb",
        "oA{9+",
        "QuTL@Vk",
        "eQ:SNQ",
        "^w%0+",
        "&,X|@",
        "5VoXe",
        "t2`qw",
        "T:d$y",
        "858J8R8b8",
        "_<_q/",
        "';6HQ[_",
        "f3c|2",
        "KF*1*)",
        "Lmh\"2",
        "mR})}-r",
        "IM_SECURE",
        "?$?,?0?8?L?T?\\?d?h?l?t?",
        "@-mI,",
        "o(feo",
        "Eoaw?",
        ")t3ELF",
        "1 222L2X2n2",
        "7(8|8",
        "m[ELB",
        "CiRvJ",
        ":(:B:Q:r:",
        "h\"N+|x`>",
        "*-\\p!",
        "#p+\"d",
        "J%kK.R",
        "eMWOx",
        "removeFromWinFwExceptionList",
        "4oQ-y",
        "nGZ\"bv",
        "h 3JR",
        "ROj-u",
        "q\\~hC",
        ">TbQp",
        "SNpBI",
        "-ITcS",
        "z~-qF",
        "7]c|y",
        "a;;:;b",
        "zezuz",
        "StartWatchDog.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "n}{,W",
        "YY_^]",
        "GL8la",
        "iSp,P",
        "a>jc]",
        "nQNE9",
        ">7=<<",
        ".-DKK",
        "length",
        "hlqRHn.Yu",
        "52.ZuO>m",
        "7>eM@",
        "prVXF",
        "%<!d0",
        "Sa0jr",
        "c<Yl.",
        "b{hA&",
        "lt%Z=",
        "6C6a6y6",
        ">Ozum",
        "WR?$^{",
        "Vjxh $",
        "t{F.Bu",
        "@qz:]6}3",
        "pQ1aj",
        "1,1X1k1w1",
        "o8<>MY",
        "|6lID",
        "hUKt,",
        "gokWAQa",
        "9$9,989\\9d9l9t9|9",
        "K$.yI",
        "LNxA.",
        "(W{~6B",
        "X?<4OvN",
        "OCSP_request_verify",
        "Qn-|b",
        "p^hU'",
        ".?AV_com_error@@",
        "lmV_{<",
        "{Su4x",
        "'][9t",
        "]F>PN",
        "!?$V_",
        "fG'O~_",
        "2c3l3",
        "X4?&L5",
        "VAycA",
        "bPV[}:",
        "tQGr.@",
        "4N%-_",
        "tv/oI",
        "<3lHwY",
        "de-de",
        "\\?qNhO",
        "wv\\w6",
        "kMswJx",
        "5qCl\"",
        "U!UOW",
        "I#<IU",
        "TRo|I",
        "j>H8~k",
        "%*scrlNum: ",
        "aZSk3r",
        "a2KIb",
        "djv\"B",
        "certificate verify failed",
        "2,2L2l2",
        "Stm7s",
        "5151e3",
        "%7y^s",
        "]Po+J",
        "gh>|w",
        "2GRGrG",
        "E0@'P",
        "8ZUUXW",
        ",value:",
        "%d / %m / %y",
        "|'3ZBT",
        "2_3-1",
        "1Ck_-",
        "5V|$[",
        "<2<M<",
        "3|Ytgys4",
        "Z:blkM",
        ":S?l!",
        "8\\&:2Y",
        "Tjkag",
        "Tq[A=",
        "zLZA^!",
        "0w='!>",
        "I\\mx0C!",
        "<F1'$",
        "`SJz~",
        "DES-CDMF",
        "O+~8k?",
        "                          ",
        "(ZOzht",
        "p|B(x",
        "6D9W9u9",
        "!]w*&",
        "0:0K0",
        "/BDVV.",
        "iC`vUi",
        "D$pSV",
        "?\"_jc",
        "D8$(3",
        "gc^>'",
        "G-$XF",
        "=[nG_~",
        "_;.`[",
        "WM5h ",
        ")rg[R",
        "qk)LOg",
        "j.Xf;",
        "%,%LM",
        "`y9L=572Q",
        "fL%4cn",
        "|A-W2^;R",
        "vqs-/",
        "f6jD\\.",
        "sS&g+",
        "l(l|e",
        "nY+wv",
        ".\\ssl\\s3_cbc.c",
        "\\G2Yo",
        "}0U;m[",
        "fbKCcU",
        "R-T@r",
        "%%`i/C(",
        "0B)2bg",
        "l%nV`",
        "GC;G8",
        "7!))^SJr5v",
        "Server doesn't support multi-use (yet)",
        "cY'Aw9C",
        "Not upgrading driver.",
        "Im4~v",
        "\\f1\\fs20\\insrsid815761\\charrsid15169477 Standard On}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 site, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 Premium}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "748O8j8",
        "Bwgxi;",
        "Rn4/2Ed",
        "6F6K6!8>8",
        "1)111U1",
        "L`Pm4!",
        ":':D:l:",
        "o~lB0",
        "4_5Q7a7",
        "yN/7n'",
        "nwh$8",
        "Ru3O%e",
        "M<gdE",
        "W^Q-b9I",
        ",z;`1l(",
        "AES part of OpenSSL 1.0.2h  3 May 2016",
        "<#=I=o=",
        "%.14s.%03dZ",
        "YbBMr",
        "ASN1_INTEGER",
        "?<?\\?d?l?t?|?",
        "RScY+",
        "p>O0B1",
        ".B\"A4",
        "6yaE:",
        "S/MIME CA",
        "B{k:$",
        "\\?Yw-<H",
        ",9,Q,",
        "<.<5<A<N<",
        "L`Dr:e21",
        "B$u*W",
        ".z.?N",
        "glktj",
        "JTcr_",
        "D$tPj",
        ":ZtwN",
        ".\\crypto\\bn\\bn_shift.c",
        "[m1Bo~;@",
        "WIX_ACCOUNT_LOCALSERVICE",
        ".ri2]",
        "4{(D$",
        "gSBmP",
        "161z1",
        "R4_p0r{",
        "X:Zx`",
        "t)mph",
        "QH\\{q",
        "5)xyI",
        ")W<dw_",
        ",C-J{",
        "#'%h&",
        "WYL3-",
        "yD,_'",
        "t$ CV",
        "Failed to load Crypt32.dll",
        "aes-128-ecb",
        "/YUHX",
        "_OPENSSL_isservice",
        "^)_;d",
        ";7mOQ",
        "too many temporary variables",
        "9k4A/",
        "W,t`1",
        "59`9=",
        "kZ!m6",
        "BOs1n",
        "lTvt l",
        "bMPBB",
        "\"[@3u",
        "Failed to write client_sub_type with value of 'EndpointSecurity' to registry",
        "qw\"8u8\"",
        "?;mFX",
        "yKBJV",
        "KS0*Z",
        "D$(@PWQ",
        "tcu\"g",
        "yJ;US",
        "RKagqA",
        "zm%OJ",
        "/(: ;m",
        "!_is_double",
        "^+EUIB",
        "!T;|3",
        "#37a/(",
        ",_^][",
        "838[8",
        "e3VH=9",
        "646d6",
        "\"M!5}",
        "13n*U",
        ",v\"h:",
        "^#}{hX?",
        "ExceptionCodeStr",
        "jojrj",
        "0C7B9FF90EBD986478B6F8E3D5C6BADD",
        "K{[6m",
        "sR1??",
        "Bq7<{;",
        "&060&1;1v3",
        "uIh$)",
        "~5C#{+",
        "L$,_I^",
        "[P\"O_Ba",
        "'~Iw>{bGWw",
        "y#;|Io|",
        ",;Wm^",
        "G(;~?Wp",
        "[gYOo",
        "id-smime-mod-ess",
        "6 6@6H6T6t6",
        "W)qSc",
        "pisS)W",
        "\"m|rE",
        "{D~Xz",
        "'.s-?",
        "v4zY+",
        "e?DfT",
        "d\\`<e",
        "1+1G1c1",
        "userId",
        "*~%(N",
        "unProtectME",
        "^V>W<A",
        "&8c0K",
        "GetHU100() called.",
        "8>[WP",
        "^F!/g",
        "%*scrlUrl: ",
        "X%FRE",
        "/(|e9",
        "'}2|_i_",
        "x0\"7P",
        "Jq4:.$\"#",
        "nBjz4tK",
        "jkR Vy6&",
        "Q/@X>.A",
        "Type=",
        ";{[51",
        "*Y>~zz|K",
        "table loaded, incomplete header = %d",
        "T'0P#",
        ":7wQ;",
        "y?hBZ",
        "KBU\\yjnh",
        "$fh#C",
        "XFl7+",
        "regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.",
        "Y0];E",
        "A,0C`",
        "t$@hh",
        "MONITOR",
        "+9r~,s",
        "certicom-arc",
        "\\#:CL",
        "^XF% ",
        "J\\hv?",
        "e9S2exr",
        "UF$\\3E",
        "V]bSsJ",
        "Y`dp1eS%",
        "\".g~<",
        "za^~@",
        "H>;B6]",
        "Sw|H3D",
        "pa*BJ",
        ".BU.f.",
        "Nj}&g",
        "$){X3>(",
        "v'M}I",
        "#3qtn9",
        ".?AV?$buffer@H@detail@v8@fmt@@",
        "[Ea^\\",
        "FE0#7",
        "5[6a6u7~7\"9+9",
        "7Jef'",
        "vJy+=",
        "2P)l& ",
        "Phe)G",
        "GA@s~",
        "gqIWXKO*",
        "-PjWW",
        "SSL: public key does not match pinned public key!",
        "pQzSX",
        "/|863",
        "Ba\"WT=",
        "@T[$?",
        "v;C#;",
        "za`n\"6",
        ">@W+%z",
        "/Cb8oO",
        "'b)AQj|",
        "XecU)",
        "pMsW\"",
        "Calling helper.GetCustomerNo()",
        "=6>E>q>",
        ">.eRB>",
        ".,>~<7=",
        "7\"]Z4",
        "%''345",
        "2O2Y2d2n2y2",
        ".\\crypto\\x509v3\\v3_info.c",
        "]@Iz/",
        "9*eo3",
        "0 0$0(0,00080P0T0l0p0",
        "7!8V8y8",
        "[%02d:%02d:%02d] ",
        "B;V\\|",
        "K&ruyY",
        "rundll32.exe \"%s\",%s %s",
        "\"Df\"*T~*",
        "7ZHP,h",
        "LrB(2",
        "DSO_load",
        "%0~@\"",
        "|W~^>",
        "oqoqosoq",
        "B-1y/",
        "pbeWithSHA1AndDES-CBC",
        "&gB8e",
        "tcam5",
        "ACH\"J",
        "o[w(`\"",
        "8lCK!",
        "Y;z&s",
        "tfC0E",
        "747<7L7T7\\7l7t7|7",
        "6q;)M4~",
        "~JtE|Li",
        "7RLDC",
        "NlgwG",
        "B\\fh4P~I~t",
        "eh78MQ",
        "dotNetInstaller.exe",
        "7<7C7",
        ")eY)9%",
        "ENGINE_get_cipher",
        "CVTSI2SS",
        "&i3Rr",
        "dNS4?o",
        "RdC3h",
        "cdefghijklmnop",
        "8]HWMRh",
        "0:`b{",
        "fOg9K",
        "\\&#{'",
        "return material authorization (}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid84110 \\'93}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid13256927 RMA}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid84110 \\'94}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "nQB\\!",
        "?h 2)",
        "<,<0<H<X<\\<`<h<",
        "IsBinaryExist: %s found in BinaryTable",
        ":W;\\;a;",
        "$tOR5x",
        "CRAM-MD5",
        "frexp",
        "oH#U&D",
        "udy'L",
        "0c0}0",
        "0 0$0(0,0004080<0@0D0H0L0P0T0X0\\0`0d0h0l0p0t0x0|0",
        "d jNWg",
        "Bm6B}",
        " D.(7-",
        "MsiDirectory: ERROR_INVALID_HANDLE %s=%s",
        "{U)|&",
        "m`]=}",
        " ,;+GV",
        "u>\"`%",
        "gkC]*",
        ":#:>:N:b:",
        "vyAQH",
        "&=5dgm",
        "Y!t$xXtx|\\r~",
        "p]`RKj",
        ";!;8;",
        ":+:4:e:l:",
        "CALibraryVPN.dll",
        "=T>v>",
        "8zr#)",
        "igy8t1y8}Ty8?",
        "K,);F",
        "+miub",
        "Ve(D$",
        "?_WG.",
        "8}2k#",
        "Xl*0J",
        "=e8P>",
        "Oa+B1_c",
        "eUlEm",
        "D(Y_o",
        "93W=\"",
        "3G3Y3",
        ".^;OD",
        "`Afc2]",
        "rJ'kr;y",
        "|jisV",
        "kpu/2B",
        "key copied, key count=%d",
        "f,NLhHD",
        "NTLM-proxy picked AND auth done set, clear picked!",
        "8*9_9x9",
        "}tUS[",
        "bhzi{jGt",
        "BDgNM",
        "*{j[r",
        "BH7,.",
        "Uh+[}",
        "eiv]#D",
        "Iv}G ",
        "QIN<?",
        "Remove Framework2.0 registry key",
        "g.\"+5)",
        "C6s*I",
        "-Cu<%",
        "GZHe$",
        "|A:dr",
        "6uWOm7",
        "1*1F1b1~1",
        "-pbH@",
        "465E5",
        "$<v2:",
        "gXV#'<",
        "7<]y)",
        "9X.+r",
        "4\"5`5",
        "|_Xx;?",
        "$-}^v",
        "OG/o2",
        "#Kpcs",
        "failed to get description from WixCloseApplication table",
        "`0>+)",
        "3!+;>",
        "TzME'",
        "#L$$#",
        "_Put\"",
        "3'323:3A3H3",
        "\\{.b8)",
        "{aM!t",
        "A1{ah",
        "3Hj|FE",
        "*;j9oEX.<",
        "'\\[TC",
        ",@{h6",
        "Y,PW&",
        "?_Q0 ",
        "#$k;x",
        "PI]jj",
        "jcciB[",
        "jBjqj",
        "0lkM7",
        "orJY\"q",
        "KD^9JVpX",
        "N~3bb",
        "t$8SVVV",
        "7{u50",
        "}G4.3",
        "TdYX|",
        "WixFirewallException table doesn't exist, so there are no firewall exceptions to configure.",
        "ryh4^_",
        "b26$}",
        ";4xVM",
        ";t;x;|;",
        ";_^[]",
        "\"[DMM",
        ",$kl?G'",
        "0i0s0",
        "STARTTLS denied. %c",
        "}AfCz",
        "H:W/v",
        "+h8szD",
        "l4:YY",
        "m5{RG5",
        "$iVL{",
        "roduct is subject to export control laws of the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid4272055 {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States o}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "w E2x",
        "e#kg6",
        "]\"A+a",
        "``#>4",
        "U\\V1(",
        "setct-AuthRevResTBS",
        "a2H)Q",
        "kWu&67",
        "%fSjG",
        "9G$v&",
        "n^jqY",
        "_V,.E",
        "W}X-Y",
        "vrPE%",
        "V)So>",
        "\\'6Rw",
        "2B{0S",
        "x}$;4",
        " s#Ybw",
        "S)f'I",
        "2QdvU",
        "cj'Z(",
        "4'4~4",
        ".?AVContext@Concurrency@@",
        ":!;A;",
        "/Gi8N",
        "P9r{Q",
        "G\\~F=igtn",
        "6 6$6(6,6064686<6@6D6H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "cCO$?K",
        "p.onBasis",
        "Read-only file system",
        "37T^<",
        ">&>1>A>s>",
        ";*Z~a!",
        "DriverXMLCtrl",
        "qYfd!O",
        "4DvM5|'",
        "key usage does not include CRL signing",
        "I$s&]",
        "[k3Bv",
        "ptree contains data that cannot be represented in JSON format",
        "no multipart body failure",
        "QPPPPP",
        "frAKn",
        ":8Unj+u;",
        "gQotNV6z\\",
        "P{[3vzep",
        "'jIt;",
        "i-F*z%",
        "T=%<z",
        "rA1@\\\"@6",
        "909H9`9",
        "gm\\.u",
        "7)7I7",
        ";oWVW",
        " uw,f",
        "i$'6_",
        "^U?>(-",
        "GetTempFileName failed",
        "StopCipollaService_rollback",
        "a;6eb",
        "}luea",
        "IX^qw",
        "Y[qCV^z",
        "(v^v;-3E",
        "eGwt)",
        "HR,-L",
        "Stg=^fz",
        "e!\\`I",
        "+aRcn",
        "W:E]c",
        "RJ6u{r",
        "|zTKl",
        ">!>A>a>",
        "47\\2d",
        "%6%>%B$FJ",
        "rDpC'",
        " ^x\\K",
        "DTLS1_GET_HELLO_VERIFY",
        ")~9X-O",
        "eLW`kSu",
        "{E{2=",
        "aGwm7",
        "Q=!fA",
        "~@wB%",
        "cPCu/",
        "Xpu_k_",
        "@D2^T$",
        "YkTav",
        "=-*AE",
        ";1<7<=<C<I<O<",
        "System\\CurrentControlSet\\Control\\Session Manager\\Environment",
        "dA4d#*",
        "BHkW($",
        "xPjAh",
        "=Tn9m",
        "+! &S",
        ":2?w2|",
        "Attention! Deleting old VNA on install.",
        "<&<4<=<j<p<",
        "Removing registry key HKLM\\System\\CurrentControlSet\\Services\\SR_Service",
        "es-NI",
        "^h.K~x",
        "X9.62 curve over a 272 bit binary field",
        "'i2`.",
        "ETnFM",
        "QcVP9eeS",
        " D{KE",
        "!W~N[",
        "z#? )",
        "7eWDT43",
        "D^J@{",
        "UNPCKLPD",
        "|kE3]",
        "Srp:u",
        "Failed EPSV attempt, exiting",
        "vUxS@",
        ";AI0&",
        "February",
        "c+o[7",
        "\\d[Wa",
        "~#J^J",
        "A,273t",
        "TnaEm",
        "U2%>$",
        "~wxX]",
        "Q'=ic6",
        "bind failed with errno %d: %s",
        "failed to write Value to custom action data: %ls",
        "ArchiveLogFile: Error %d zipWriteInFileInZip %s",
        "(^Z4<%",
        "hYEX>",
        "@#+tGh",
        "1>K^9",
        "zWHUK",
        "mI2Z:",
        "Ec(JhWu",
        "VzYL/",
        "s`$EsV.",
        ".?AVbad_target@Concurrency@@",
        "Toj_=",
        "D2[M=",
        ";;;c;",
        "lmsvcrtd.cpp",
        "B66%s",
        "J^n#H",
        "WxL>u",
        "?'k$s",
        "X?B1t",
        "D:6&n",
        "~O-QFR",
        "3&=Ry",
        "1^_7CA",
        "id-smime-aa-ets-sigPolicyId",
        "HC%,9",
        "=&>T>^>",
        "0)0/0o0",
        "N&tuG",
        "UninstallFW:  UninstallFW finished.",
        "OgicL",
        "FVD<Q",
        "E;l$4",
        "\\w(O.'",
        "qY1l ",
        "MZ?'zR&-",
        "})6oR:",
        "vv-I1]",
        "?#???[?w?",
        "(r{@un$s",
        "5C5W5",
        "= =$=(=,=0=4=8=<=@=D=H=L=P=T=y=",
        "dll name is missing",
        "\"& ->",
        "{W,}^",
        "D$Hy!~",
        "@GMKZm4",
        "aC(c:",
        "4hTWbU4",
        ";l$ tG",
        "%%`Vg",
        "6_ue?",
        "Failed to update InstallAttempt counter",
        "]\"xcw",
        "*^HzAs",
        "9 :Q:j:",
        " with ",
        "eFOD&",
        "*J-=*",
        "]/qNn",
        "\"I@u@0b}",
        " 0xca",
        "G|@Bj",
        "0@ycK",
        "\"Gop1j",
        "L5pa@",
        "d9>8W",
        "ztd{r$",
        "T_+eT",
        "1$g*h",
        "%\"\\>H",
        "-}6H2=$w",
        "7-8p:",
        "5 5@5L5l5x5",
        "GetTokenInformation 2 failed, err=%lu",
        "\\ZLComm.dll",
        "-xFtbxW'Fx",
        "yuVa&",
        "a}:P;",
        "p61aU1",
        ".ww, ",
        "Kaspersky Internet Security 6.0",
        "!%2q{",
        "T??w9",
        "C(~Vc+",
        "ytA2u",
        "aH(GB",
        "'{Mez",
        ")$$yz))$H>",
        "eq*i\\",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<int,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,int>>(const int &,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,int>)",
        "X_M%t",
        "`2L-F|",
        "GetCurrentProcessId",
        "WT#K\"t5",
        "y,\"K%",
        "(|F$6",
        "x h%jB",
        "3,4h4",
        "iQmn4",
        "PPwnP",
        "=v6D@5",
        "aX<0*",
        "VYFBL",
        "Service %s - query result %d, status %s(%d), Sleeping...",
        "8/8;8R8",
        "]z<&4",
        "CreateSemaphoreA",
        "H3J~u*",
        "E){7E",
        "3+44494L4`4e4x4",
        "0#0'0+0/030?0G0",
        "D$0PS",
        "\\!+CT",
        "No\"}WEW",
        ">\">P>b>h>m>",
        ";E<N<",
        "Zp+xI",
        "/W7`-o",
        "r-w\\\\w",
        "U\"KWn4tV1",
        "<w~as",
        "_`9BU",
        "+B;#N",
        "!HNr#",
        "a*oG Vfp",
        "&(t+Y",
        "d\" Zq",
        "'2,:DO",
        "f'ZjV$",
        "8\"8-:",
        "Creating ExecFirewallExceptionsThread thread",
        "lIg%k",
        "#LvA)",
        "c!5;d",
        "|$ FW",
        "Failed to get install state for Component: %ls",
        "y'{.U",
        "{_n \\",
        "Gtrrh",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 10.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "7ow21 ",
        "$^-{h",
        "&C%PH2",
        "+u|VI",
        "U\\DAJR",
        "ExecSecureObjects",
        "_8>vj",
        "'Y{8nO#",
        "(&Z(T",
        "? ?$?(?<?@?P?T?X?p?t?",
        "\\]3y=",
        "242<2D2L2T2\\2d2l2t2|2",
        "@\"o.,",
        "tU&'UB<",
        "Vb7vt",
        "0a\"'Si",
        "ITX~o",
        "37%cR",
        "yNS7gO",
        "{XwvQWO",
        "[EXCEPTION] HookAbort: Terminating the process.",
        ":k=Isz",
        "4~Oa=",
        "BXN3q%.",
        "0wS2Xq",
        "d.ktri",
        "U8%*1#",
        "=IQ3_",
        "gG'tR7",
        "yhu4x",
        "`BinY",
        "SEC_E_TOO_MANY_PRINCIPALS",
        ":':::M:`:s:",
        "camellia-128-cfb",
        ";dXcSS",
        "0OGKU9",
        "lKK&Y",
        "UhRWa",
        "%_8bwp",
        "o>Is\"}",
        "105*qf2",
        "PZ$4C",
        "c1g1V0",
        "u5hp:L",
        "RUNHELPER",
        "w)rc]",
        "}<KT'H",
        "/g_}-",
        "0-050C0",
        "D$(SUV",
        "failed to get component attributes for XmlFile: %ls",
        "9U+97",
        "jhh$?%",
        ";-;=;N;0<s<",
        "(XA06",
        "+J8p%:1",
        "~eGD6B",
        "e~],~",
        "smc_install_path",
        "\"(j*Z7",
        "o!W&#",
        "jAjyj",
        "`iWI3",
        "6T~LtL",
        "g,.X:S",
        "5%5.5\\5c5l5u5",
        "<i<x<",
        "jxjqj ",
        "44-45-53-54-77-77",
        "}Y{FqO",
        "Q\"R\"S",
        "h59L[G",
        "s?@-5",
        "(JMiC",
        "\\zI>X=q",
        "o}gxE!",
        ")m!m^B",
        "*73m*9",
        "%RtQA",
        "ddX(0",
        "/A~}g",
        ":*:F:b:~:",
        "0N1\\\\",
        "HEtsU",
        "N?19Q!>",
        "s_Kw!%",
        "5c5h5s5",
        "_n}I]",
        "-e)M!\"h",
        "SpcString",
        "error creating extension",
        "~+.1A",
        "uw$]B",
        "Host not found, try again",
        "}!\\$E",
        "D`aKl",
        "NE=ix",
        "<V!@$0 r",
        "YmxsBUk}#",
        "C#]mHc",
        "cQf$3",
        " '_mV",
        ":x@bq",
        "%#`o$:",
        "2Rwc9",
        "y1'ak>",
        "aw 1,D",
        "4m`CZ",
        "sslv3 alert handshake failure",
        "`~Xad",
        "bg=,k\"",
        "? ?&?+?1?7?=?B?H?N?T?Y?^?e?k?p?v?|?",
        "z0==m",
        "Wg^/M]",
        "ydV:]",
        "t$4UWV",
        "C/xnC",
        "2D9-$",
        "NEWUPGRADEKEY",
        "9*9/9=9O9g9w9~9",
        ":;;X;b;",
        "(h\\F\"",
        "I-t82",
        "*Cb/,n",
        "6rzTV",
        "n%%E}",
        "'W^{#",
        "eG[[E\\qy",
        "K~w<6}d",
        "Failed to allocate memory to read in ca script.",
        "5$|ZNmpg",
        "X8h8_ML",
        "engine configuration error",
        "6oA1M",
        "CdY(%R",
        "8U6\\H",
        "fuP|U",
        "m%qm`@",
        "+4NA`",
        "D1>?C",
        "PWWWWW",
        "hi/|O",
        "\"t'C}",
        "@ika$N",
        "(=`@ ",
        ".o2t1",
        "hep}i",
        "WJHlzYa",
        "#6B)o;=",
        "6$6,686\\6d6l6t6|6",
        "m{>}Q7E",
        "@!HNac",
        "`cZu\"",
        "0Mu<rO",
        "7;-b_",
        "j3FS!",
        "hUn,W",
        "Authentication problem. Ignoring this.",
        "rdu)&R",
        "3`.mf",
        "-*)iMMn",
        "tn9,\"",
        "\"x\"M1_E",
        "5#5*595E5q5x5",
        "j02Ng",
        "bf(AS",
        "Q<QgS\"",
        "Rk]el1",
        "!o:_}",
        "HandleDriverInstallHang: vsdrInst.exe seems to be hanged.",
        "xm0z=H",
        "`vector vbase constructor iterator'",
        "2lZjVB",
        "/V;aM",
        "N%_U']",
        "2t+&n",
        " EP!D",
        "D>?QQJ",
        "w{ch5",
        "y~1E/5",
        "Saving ipwval...",
        "rc4(1x,char)",
        "PTUUQe",
        "6-6A6Y6",
        "wIPS3",
        "s=.f3",
        "!v\\`-Qo",
        "cLs}\\",
        "ZmK(Y<",
        "AmI$V",
        "w<fFG",
        "2dd;x",
        "}mWo>}",
        "0&0c0u0",
        "sl(KY",
        "]n3j`+",
        "!c{{@",
        "Qgsp6",
        "}R]D_",
        "9TQ1'mL",
        "!NTS[_{",
        ")[y\"Byo",
        "TqxG2e",
        "787@7L7l7x7",
        "I!7+^",
        "EK)82Y",
        "rw=?n",
        "3D$P3",
        "GetFileVersion",
        "A9a3Q",
        "_0I3v",
        "1<EVF",
        "G&lP8F<",
        ";h;q;",
        "7\\7c7l7",
        " aux!",
        "{nPIO\\A",
        "Received only partial file: %I64d bytes",
        "0e6d8",
        "mNO9-",
        "'g:h[",
        "[M/PqY",
        "<<0A1pq",
        "4,5E5]5",
        "'}9E2",
        "3B4R4f4z4",
        "e2?zhJ",
        "~\\=gt",
        "SECG curve over a 131 bit binary field",
        "ECP_NIST_MOD_192",
        "Tt2J/",
        "4{QZG",
        "q,b+1",
        "oyb_l",
        "Mmybg",
        "&)0=x4,",
        "Q.h3{",
        "#8czj",
        "(S+=]V",
        "% i@B-",
        "+R+C+c,/[",
        "gvgG3",
        ")q$P#",
        "*HN:;",
        ">0010",
        "$i:Q}7",
        "ucQA7",
        "3WPv*",
        "X:(fA",
        "CAMELLIA-128-CFB1",
        "N]?RcB",
        "#J[$tK",
        "g@nC3",
        "??$Jf",
        "@|L*hlt",
        "KAdr=",
        "rL|;g",
        "F@Ph`",
        "{6n@f",
        "y may last, so the above limitations may not apply to You. This warranty gives You specific legal rights. You may have other rights that vary from state to state.",
        "k((Uk}^d",
        "gR:OB",
        "J&R7,",
        "Mr,8^",
        "system32",
        "y*kkb",
        ":G!mQ",
        "BN_BLINDING_invert_ex",
        "7 707@7P7T7d7h7x7|7",
        "{_ec2",
        "nsCertSequence",
        "R\\:X>",
        "$XKrh",
        "xQd$f",
        "SnhPE",
        "dy<8Y|+c=",
        "&>:,(",
        "+F1H!",
        "z8N1!qT",
        "4 4/4N4]4|4",
        ",mBR)",
        "S|Oyj",
        "__eabi",
        "=umEUW",
        "there must be one signer",
        "+GL+OL",
        "d+D#(MO{",
        "0h 4#",
        "<(<D<H<h<",
        "=gwSV",
        ".#2e(",
        "n(^~N",
        "Hn7#U",
        ".?AV_Node_rep@std@@",
        "Ykh\\<",
        "LQO`5-S",
        "0?E\\CO",
        "I_}F>`",
        "<e`q_",
        "2m$\\J",
        "32bit",
        "!WB!0B",
        "UninstallFW:  Can not access vswmi.dll",
        "d?.Sh",
        "MpfTray.exe",
        "484@4L4l4x4",
        "XY{-?",
        "]r`74",
        "#,#lF",
        "717a9",
        "y~T]Jl",
        "wz }@",
        "?*Gntd",
        "SFO1N",
        "Ck%*@",
        "Zwh%\\x",
        "s=D^j",
        "]mydF",
        "yc^=G~",
        "8o8M9",
        "mWtr ",
        "A`^sgU",
        "7$717;7N7Y7`7g7",
        "<ASN1 14>",
        "3*4N4p4{4",
        "7]a#c",
        ">2x[Js",
        "k(N|O",
        ":c:D;d;n;",
        "e[+9\\",
        "3m&6&",
        "iBT@,",
        "-:-St",
        "3%qD*{(<",
        "[DPi9Gh!1",
        "N7U\"x",
        "-hn+>",
        "X,O.^",
        "@mKU_f",
        "GetFileType",
        "t\\hpX",
        "=3}A*",
        ".2xzF",
        "dZbHUj",
        "dingo_install_mode.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "-9d5P>;",
        "])3|o",
        "s^/kZ",
        "GetActiveWindow",
        "yTdoy]",
        "SBK0{k",
        "MergeCommonBackup policy copying from backup failed, error: %i",
        "M-=RQ",
        "[emP)",
        "FWRemoveBefore:  Unregistered SecureAccessDSM.dll.",
        "bN/Z;Oe",
        "F<xVT",
        "}A|uw",
        "~\\kL4d",
        "[_^]3",
        ":jj$'",
        ")%J#N",
        "Nl(jd",
        "a0n{;",
        "7#7)7/7L7V7]7h7",
        ">K>X>i>s>",
        "?s($E",
        "1HAKb",
        "727K7",
        "9(7@x",
        "%]maD",
        "SSL_SESSION_print_fp",
        "bYm~M",
        "=&=o=y=",
        "2#333Q3c3s3",
        "Ps#vh",
        ":hHR<",
        "D:DE\"~",
        "cD\"5d ",
        "^g'1{",
        "SA|X=G",
        "]w$(F",
        "0-151",
        "\\sbasedon10 \\slink31 \\slocked \\spriority10 Title Char;}{\\s33\\ql \\li0\\ri0\\sa120\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 OR ITS SUPPLIERS WERE}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 ADVISED OF",
        "%fcn2ru",
        " arI&",
        "lZH7B",
        "q`[e(",
        "m<kU@",
        "5F?=+",
        "|6.(3r>",
        "U[v[r9",
        "$(5Xj",
        "t.= !",
        "CMLL_T4_INIT_KEY",
        "PKnJ~",
        "a$pJr",
        "pbj_g",
        "j4J~Yv.c",
        "V=LdV",
        "GetFileVersionInfoExW",
        "0sfe.i",
        "y*c]o4$",
        "=*O'x",
        "MD=v$[p ",
        ",M%\"S",
        "regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.",
        "9vJwt",
        "sQMYF",
        "jxRcFlp",
        "u7:2~",
        "j{N.!3",
        "BzLmJ",
        "4)4D4",
        "4C9o*gh",
        "*/Z!hZtS",
        "l$8PVj",
        "fZ;YO",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477 Hardware Product }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 components, an RMA process will be initiated by Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "TUYV^N",
        "+zsQH",
        "^n%<y",
        "e|'}Gd",
        "to<\"W6)",
        "setct-CertReqTBE",
        "VSMon.exe",
        "W,~:*",
        "\\$0UW",
        "/U6fK",
        "GetTimeZoneInformation",
        "9V:{:",
        "<76nMMMM",
        "7&7v7",
        "qQYC:",
        "8<8L8X8x8",
        "M512$",
        "M&*n_",
        "a@QbO",
        "5 5$5054585<5@5D5H5L5P5`5l5p5",
        "eu~%|",
        "Private key does not match the certificate public key",
        "B`X`S",
        "@nABX",
        "Tq4_7",
        "E@b^V",
        "client_sub_type",
        "*|g8Gk",
        "s0$HU1",
        "hSB/I1d",
        "x{yq*X",
        "{~Lygk",
        "z+7/aP",
        "Found that SP was off before calling hash.exe",
        "2$2,2",
        "F<.]-",
        "aJdH7",
        "Eku@X+",
        "IoC?Q",
        ")y-}xD5",
        "OT)^?=.",
        "CERTIFICATE PAIR",
        "EC_PRE_COMP_NEW",
        "`)bC+T",
        "\\]4WH{",
        "8 8$8(8,8084888<8@8D8H8L8P8`8d8h8l8p8",
        "/P.Z\"",
        "=Wmin",
        "iQq(J",
        "oW5a6",
        "?o*oXo`",
        "Q,<lF",
        "rnuD#B",
        "u$PPW",
        "~,VSU",
        "raEMG",
        "],l[cvb",
        ":/l%D",
        "ju|ih",
        "3\"3b3",
        "z+#^E",
        "[gCXL",
        "%s://%s",
        "Cn77Yn77Y",
        "ArchiveLogFile: PopulateZipFileinfo: Error %d finding file %s",
        "xI?L#",
        "-2#P=",
        "#A('p",
        "d_$wL-m",
        "Q!35V",
        "VjXh<8#",
        "{DIaJ",
        "6ar_<",
        "m%|]_",
        "L-jFq",
        "w|a]!",
        "G.ANK",
        "leZ38n",
        "1 1@1H1L1h1p1t1",
        "7{+zZU",
        "fnBfv",
        "not uninstall, no need password",
        "Pjxj&",
        ":>\"ux",
        "r\\  u",
        "O</|~",
        "e;*Oa",
        ";^,(0[",
        "[zkfA",
        ">Mz0P",
        "msvcp140_2.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        ";|$ v",
        "u<^ B{N[:",
        "e@`=Y",
        "*&^C^",
        "D$$PPU",
        "QybM[n",
        "=Q:hO",
        "Op/(d0;",
        ";15Bf<Mn",
        "C_?wvTo",
        "t7A>I",
        "joj~j",
        "]rlhW",
        "^-)LS",
        "1e{(j",
        "Failed to get current VNA file version.",
        " cVgR",
        "Rlc2%",
        ")d6*g",
        "U^RU?X",
        "Jn:2n",
        "Y<^Kp",
        "47X;_'o}",
        " \"5dZ\"l",
        "F=F?G.G",
        "1hY5u",
        "S6Im)%[",
        "GetAndSetRebootStatus: cannot log in",
        "e)MY(H",
        "klw\\|",
        "1$1,141D1P1X1",
        "3\"vctYe",
        ">:uBFV",
        "qo_ImiBTT,",
        "bCO$OCI",
        "1bvp@",
        "/7*{G",
        "J2HcP",
        "Z n|&",
        "\\7uEn",
        "QLS/W",
        "*~4}>U",
        "L_af+l5",
        "N|2s ",
        "/$2;U",
        "G9q__<",
        "vO!R!*",
        "Failed to delete driver %s. Error: %d",
        "GgD*u}g",
        "Eke#m",
        "[VSWriteUnisntallInfo] Can't map view of memory mapped file",
        "Nwx]n",
        "kh`#)",
        "(AY7n",
        "|$$CW",
        "*)/V*",
        "%g,UkC",
        "#09HA",
        "&FC0~",
        "9 9$9(9,90949t?",
        "?Od3%",
        "C}ijl",
        "979I9c9",
        "re~N>,",
        "* eoM",
        "(|g[T",
        "^z(][",
        "FSETPM",
        "~AoR:",
        ">1>M>i>",
        "3,323R3_3i3{3",
        "HMy[jjm",
        "runOldInstHelper",
        "L pBZ`-n3",
        "E\"+3S==",
        "9?:E:_:u:",
        "Y~Nj{",
        "=>=UtWE",
        "xzX(|dn",
        "W!dkRD",
        "X509v3 Subject Key Identifier",
        "$2632c",
        "1P2T2X2\\2`2d2h2l2p2t2x2|2",
        "V{$T3",
        "2QI*+",
        "\\O dR@",
        "FlsGetValue",
        "7C8s8}8",
        "_fM?S",
        "=,Up8",
        "Time Stamping",
        "4+5D5L5",
        "vH%>(",
        "-\"V4{",
        "U)-+R",
        "c2rw6|",
        "t<0\\(",
        "des-ede",
        "t h$6",
        "f}'\"(",
        "0P4U4Z4x4",
        "z4Aw;",
        "/N?ld",
        "?$?4???F?",
        "bRh?F",
        ")Y8S}1",
        "GetHU100",
        "QJAPA ",
        "~0ym,i",
        "q {.g",
        "6#bvuT",
        "rpz9it#",
        "ep(!'",
        "3t$43t$",
        "Callback aborted",
        "9_`ur",
        "%u %s %X %d",
        "[ADAPTER] NdisQueryWirelessConfig: Retry: %d CreateFile LastError %d Adapter Desc:%s",
        "51e*dju",
        "Zv-<x}0",
        "C>Y z",
        "Jn;Pa",
        "3nZSBXt",
        "Bn4l8n",
        "wJQQP",
        "]aZxd7<P",
        "%s (%d) %s (%d)",
        "SSL_SESSION_set1_id_context",
        "wl\"i{",
        "9^:b:f:j:n:r:v:z:~:",
        "*jyZf",
        "|r@Hti",
        "COMMONAPPDATAFOLDER_DEVICE.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "7sg=0",
        "}]wAM(h",
        "uT4T_D@",
        "\"19_O",
        "s_L+hi",
        "QEgzH",
        "\\:YGe}",
        "2(2L2T2\\2d2l2t2|2",
        "I`/yRL",
        "\\$ US",
        "A@NM!",
        "2,282",
        "\"-7~=lA",
        "Yxd1s",
        "ENDPOINT_SECURITY",
        "0S1B0",
        ".}PZ!",
        "F%j/l_",
        "9P*Q6",
        "\"3conL",
        "t2jPW",
        "d:t?s",
        "[VSDATA] FwConfigChange: skipping adapter %d - \"%s\". Invalid adapter flags",
        "9V:f:",
        "81969a9f9",
        "0E@&k",
        "hEQ?\"57",
        "FeatureAntiVirus:  CleanLegacyComponents ended.",
        "VPNINSTALLED",
        "3$3,343D3L3T3\\3d3l3t3|3",
        "CMPXCHG8B",
        "'*snrM",
        ":+:G:c:",
        "kWgO}",
        "6G=PE",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 Product shall be subject in all respects to such United States laws and regulations as shall from time to time govern t",
        "0lBFA",
        "q(Q95",
        "YJ{FyS",
        "sf6f6S2",
        "InstHelper.exe.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "vE R(",
        "Iot!j",
        "bi*b<v",
        "&:UL!g",
        "bODu6Vh",
        "Q$&`}",
        "GetSecurityDescriptorDacl",
        ";*;@;",
        "wmo'5@",
        "Gk/e<",
        "Je_n^.HZ",
        "r3p-G",
        "b5^c1",
        "\"U!u)",
        "VPB<a",
        "Peer certificate cannot be authenticated with given CA certificates",
        " H-ef",
        "Failed to delete Common policies backup folder, error:%i",
        "{\\*\\pnseclvl8\\pnlcltr\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxtb (}{\\pntxta )}}{\\*\\pnseclvl9\\pnlcrm\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxtb (}{\\pntxta )}}\\pard\\plain \\ltrpar\\qc \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 ",
        "0F.op",
        "*C.Vb",
        "M/Z['",
        "qGgL#",
        "3%3+3/353A3G3[3_3g3k3s3y3",
        "f-n)q{",
        "$bAqNF,",
        "0\\qVD",
        "EVP_PKEY_sign",
        "failed to write change data",
        "+Nm80",
        "fLhuD",
        "ta7*y{\\wt",
        "5S\\Xq",
        ";$;0;P;\\;|;",
        "d3d9.dll",
        ",(41d",
        "v]1$J",
        "k-irI",
        "cQ\\n^",
        "0'0g0",
        "Failed to create WcaVerboseLogging global atom.",
        "1$1)151:1N1",
        "t]]>X&",
        "zonelabs",
        "1!w{r).",
        "`PC8l",
        ";1;8;I;V;",
        "*WjSRI",
        "[VSInstallProduct]before login to vsmon",
        "_583k",
        "T$P#L$P#",
        "Upgrade firewall driver.",
        "C';NK",
        "F>D-e\"",
        "[mS-(9",
        ",SR*g",
        "j [f;",
        "`4%'t",
        "=\\D\"s",
        "<0G6K",
        "^#?kP",
        "j+-a+4",
        ":fn9I\"",
        "Ucxf?",
        "TN^=x8",
        "Error writing InstRes.",
        ">m[^}\\",
        ".\\crypto\\asn1\\t_x509.c",
        "'Z81^@",
        "Robbc",
        ";L;1Cd",
        "2*3o3",
        ":$:4:8:H:L:P:T:\\:t:",
        "xOS1os",
        "J<JDJTJd%",
        "xvzYRE",
        " 0?:96",
        "383}3A4",
        "zs]t\"",
        "s7=4G",
        "TracSiteUpdateSuccess.wav",
        "o||<=:",
        "~M\"Kv",
        "U?5#V",
        "1]E@;",
        "@AmE7c",
        "t%.wEr",
        "dEcnuR",
        "T$0sO",
        "CMS_OtherRecipientInfo",
        "\\regedit.exe /E ",
        "0u@f0",
        "EiM9[(\"0",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\caps\\f39\\fs20\\insrsid2703887 ",
        "k)9y)ng$",
        ".N/N0N3",
        "0I0V0`0p0",
        "$.RB0",
        "SuG#6",
        "(;Rbvb",
        "DYNAMIC_LOAD",
        "3 3(3,34383@3D3L3P3X3\\3d3h3p3t3|3",
        "R/r.?",
        "dVf1I",
        "#:IQ*7}",
        "unknown bit string argument",
        ":%;s;",
        "#*I_*I_fhk?o",
        "K]7|(",
        "L;aa#",
        "z{l\\o(7,",
        "0UK7?",
        "pSVl.",
        "Fd83P",
        "dE_'w",
        "<pN+1",
        ".:DdVk",
        "t~zaK1#",
        "type not primitive",
        "'AC!*",
        "rwH~b.>",
        "RemoveOldVpnFiles",
        "RSA Data Security, Inc.",
        "0?(Wk",
        "\"lH(@}",
        "Zd`Z/DyJ",
        "ctrl error",
        "i/I%]",
        "4M4h4",
        "3#70Jc",
        "SaveVsdataDll",
        "Ps+A*",
        "/\\HS7_",
        "deW3z",
        "*A3 q",
        "}R{v6",
        "application/xml",
        "eaj2;",
        "eVwd,",
        "VjXh$",
        "vB|%f",
        "~[qQ@",
        "\"P\\LY",
        "1c0p2e",
        ":(:0:H:T:t:",
        ":,:>:Q:^:m:",
        ".&L}w",
        "\"<%\\:",
        "7G1Lz",
        "7)~ke",
        "    OCSP Response Status: %s (0x%lx)",
        "ToufUpg",
        "`template-parameter",
        ";`;o;",
        "$<E~j",
        "50D8.S",
        "&H;AC:",
        "KI&[lo,f",
        "y1#u\"A",
        "success copying file %s to tragetdir",
        "ABORT",
        "CANT_FIND_ENV_VAR",
        "$SHBZ!",
        "7cUmQ",
        "l$PVS",
        "[y7o%",
        "n}Et>",
        "f@Vdf@%-",
        "n:zmf;",
        "tU,7~",
        "SBBtyC",
        ".k<k>k@kBk",
        "^1I0H",
        "\"-%li",
        "5&6e6",
        "VC!gp]",
        "USERINSTALLMODE",
        ";0v>f",
        ";k5Cj",
        "<&=8=Z=r=",
        "Y>P:0",
        "0 080<0T0X0p0t0",
        "W+M{y`a&",
        ")yq{q",
        "Q{sz6",
        "<$<2<8<H<T<Z<d<v<|<",
        "4ifTCi",
        "X;GUM",
        "jIR?Z",
        "V/?jdi",
        "1$1?2[2",
        "[VSDATA] AddDataClient: too many clients",
        "#MwH0",
        "r!j9v",
        "'0e+G",
        "+X/aj",
        "jj9`G",
        "=Nf{%",
        ")j Pj",
        "OP-kN",
        "f~c_j[",
        "Field=",
        "VmCrb",
        ".evBX",
        "`+?KM\\",
        "BnFv=C",
        "cM}oy'5",
        "RX1_1",
        "w>$^L",
        "IKWk3",
        "e6aW-",
        "/O.C^",
        "-WfdT",
        "*V%0#",
        "]#{+c%",
        "y8Rc<",
        "2$2,282X2`2l2",
        "? a2%",
        "+(SR.",
        "IqBn%G",
        "L=lF^F",
        "@c}z/<",
        "}v<O>Wl",
        "6*E'E",
        "*]u#Ze",
        "tc'`o2lo!o",
        "iUlg|",
        "'~*2k",
        "!my\"1=",
        "@BE@Y",
        "\"A'b*-S%",
        "3ibuQ",
        "Tj?@^d7",
        "#eI9V6",
        "$/:V'",
        "uT_Rm#",
        "WiX Firewall Custom Actions",
        "?^Q#1",
        "o.Kvl",
        "P`m;F",
        "kn`Nj",
        "vjG&W",
        "W0[N5",
        "WJ:l|",
        "nz;o6",
        ">\"p~:",
        "jU$?s",
        "operation not supported",
        "*ZorU",
        "rD.Hw",
        "^LJH_",
        "5ir-W",
        "|$(Sj",
        "]&.:X}t",
        "9N:\\:",
        "y-DzA",
        "A@+ a",
        "SEC_E_CERT_WRONG_USAGE",
        "272v2",
        "P6c~_",
        "seed-cfb",
        "2Un%L",
        "L_De>",
        "=,=7=W=`=o=",
        "ASN1_ENUMERATED_set",
        "=@=E=f=v=",
        "G4wT$",
        "BIO_new_file",
        "B!*Ez",
        "Y|eIL",
        "X509v3 Subject Directory Attributes",
        "DcO/lcK+hSK",
        "*F6M<{",
        "l*KT_C@v",
        "GuardDog.exe",
        ";5*QK2",
        "b=3?%",
        "ee0Eg",
        "z:G^~",
        "$ErB{",
        "D$4hHO!",
        "4 5q5",
        "86D1@",
        "p39oj$",
        ";8;l;r;",
        ":]0pa",
        "@i0X`",
        "RT_Li[",
        "QZ~VH*",
        " Z\"dA",
        "%=Dej",
        "%},?#",
        "#6M9H",
        "N5|.<",
        "\"x~%\\R%",
        "fH,*6O",
        "A.R~D",
        "'llwX",
        ")`q6OI",
        "9*w1U",
        "0r8sV?e",
        ":&xGr",
        "xo#bA JG",
        "UzhLa",
        ";U<`<o<}<",
        "9%:E:",
        "PreInstallCheck: Original Database Disk Space needed for EPS.msi cab files is: %I64d MB",
        "+fZ!:",
        "\\zonelabs\\ssleay32.dll",
        "\"6275",
        ".?AUIExecutionContext@Concurrency@@",
        ".9.a.m.",
        "*O+I?",
        ".rdata$T",
        "86<VB",
        "AES_INIT_KEY",
        "ExitThread",
        "Ye_4o",
        "a#?(}x",
        "VnaUpgrade",
        "3 3$3(3,3034383<3@3D3H3L3P3T3X3\\3`3d3h3l3p3t3x3|3",
        "+g&62M",
        "F^SHAT",
        "C4Z=9",
        "q|,E1",
        "[w/*Pm",
        "d;EDPi",
        "DES-EDE3-CFB",
        "R+m'k",
        ":]$d9",
        "6<ETD",
        "HZb$$",
        "DUI*<",
        "Pdfd<H",
        "Z,5,K'",
        "`4lc1G",
        "1m6&,",
        "im(.g",
        "snTm-dj9",
        "\\$L$\"",
        "\\eM|0",
        "wK;TU",
        "tkB!o",
        "M*@yX",
        "lOHmD",
        "DW5[/=|",
        "~Q8<Z",
        "s<%R\"",
        "(<EMe",
        "$Cs,6",
        "Failed to extract curl_cli.exe",
        "U,UG6N",
        "LICENSING",
        "][a*K",
        "n(-.v",
        "*Jz$d",
        "L$,9|$(u",
        "9FCD`PF",
        "HUT|4",
        "9'9@9G9T9[9b9",
        "o{t-(",
        "tpBasis",
        "%\\Hqx",
        "hOn!QG?c",
        ";q)])L",
        "S~UF5",
        "Rqo1L",
        "Ji:Y,",
        "[]H &",
        "dzez8",
        "l8*7;",
        "PARAMETERS",
        "IXnV#",
        "Mn4:,",
        "f4bh]",
        "?tN*&",
        "Y1$t6",
        "e:W%(0",
        "H,/h^",
        "GOST R 34.10-94 DH",
        "<9=C=J=j>",
        "\\f1\\fs20\\insrsid5000668\\charrsid15169477 T}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 o obtain authorization from the owner to have Check Point or its partner service }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "Plugins::UnregisterFW:  PluginsUnregister started.",
        "WIX_SUITE_SECURITY_APPLIANCE",
        "Vs&J[",
        "^#]y(",
        "ECDH-RSA-RC4-SHA",
        "|MM<Dl",
        "RC4-40",
        "q2#`K",
        "u`!$?",
        "FFFFOF",
        "!/,ly",
        "1_>}(u",
        "j&jdj*",
        "= >5>Q>",
        "= =$=8=<=H=P=T=`=h=l=x=",
        "OjvnV",
        "?`li=!",
        "ND*Hn&",
        "@n+ve",
        "S~=:Qzg.-",
        "gVrAD",
        "[7!}{H",
        "565<5@j j",
        "id-PasswordBasedMAC",
        "7 7(7,787@7D7P7X7\\7h7p7t7",
        "X<-^q",
        "> >v>",
        "Tr;E_",
        "FeatureSmartDefense INSTALL_SD=NO",
        "data between ccs and finished",
        "j^6@yDC9",
        "6n6zi",
        "Failed to find the Process address for ReplaceOrAddTagIntoVSConfigEx.",
        "3|$p3|$4",
        ").!y4",
        "~#GdT%",
        "8Xl'<Q@",
        "*\"9$*\"9",
        "3(6[v",
        "%xV?Sj",
        "CNK'x",
        "j-'Q'C",
        "K,P)4",
        "# %|;\\",
        "= =6=L=b=x=",
        "Zc\"t>",
        ":2vq$",
        "k]k[T%>",
        "fXOBTI",
        "fr-lu",
        "070S0o0",
        "cbSqQU",
        "sDhTF!",
        "rt-E^",
        "):U{P",
        "2_BCiK",
        "DateTime",
        "iL(fXB(S",
        "5I5d5y5",
        "1(1|1",
        "1'151;2l2U3",
        "Please call curl_multi_perform() soon",
        "Xe?`v",
        "5>5R5e5",
        "292R2k2",
        "~NlJzHz",
        "%4HPY",
        "%s2M^Q`",
        "FXb,p,",
        "5DW|?",
        "!0yf1",
        "%\\f!V",
        "XL>Bl",
        "cipher initialisation error",
        "3 3B3V3j3~3",
        "tvdebug_a",
        "< +q+",
        "+/0,t1z",
        "~4.>[",
        "WrmS@y?",
        "<*+k(",
        "can't get current directory.",
        "qx)UqQ",
        "'H$g<",
        ").<JC#%7",
        "(b@L(",
        "-KgcP",
        "BIO_new",
        "*|;~\"`",
        "hTknM",
        "<MEFileProtectionOff>",
        "n0i!I5",
        ")$ $8",
        "LS.pA",
        "9$9`94:",
        "WWWSHSh",
        "german-lichtenstein",
        "&Y!|n3",
        "UYC&?",
        "IqLNc{",
        "e!gK~`-",
        "aag4l",
        "aUrJz",
        "<o<}<",
        "|knrj",
        "8*8W8d8",
        ";5XNN",
        "}HYB5",
        "z:=J?N",
        "zOX*e\\<J",
        "Slz6wC",
        "|`k,[b",
        "=Rw;1",
        "BN{QX",
        "1A$V7",
        "oTW-T$",
        "= =A>\\>c>",
        "r?Dg'Z",
        "CNM/8",
        "jhh~Y",
        "L$L3L$83L$03L$",
        "~/pVthr",
        "JTk1\\",
        "****************************** ChangeWSCSVCStartupType started **********************************",
        "TVFUNC",
        ".\\crypto\\bn\\bn_sqrt.c",
        "zonelabs\\plugins",
        "J J,JDJ`J",
        "L$,#L$(",
        "W-&4Y|zz",
        "#C\">FzB~",
        "SXNetID",
        "HBa9[",
        "v$z\\*1",
        "/40q6",
        "X!*Am",
        "%2fD|",
        "<N9Du",
        "L6!{%",
        "mqUQ_",
        "UPb)\\\"",
        "invalid stoul argument",
        "H(zz7",
        "RegisterDate",
        "_ST4D",
        "OhHq&",
        "ymmPq",
        "portuguese-brazilian",
        "2V3n3",
        "VSInstallerLogonEx: cannot load vsmonapi.dll",
        "#xa;;",
        "}_qsr",
        ";q_;ev",
        "2VBY9",
        "Yjrlf",
        "_1L5Us",
        "^rnkR",
        "SetNPVersion: Network Protection registry key found, version will be updated",
        "=xp`;",
        "x<<Dx<<D%",
        "9\\$ u",
        "ssl23 doing session id reuse",
        "_1j*j",
        ":K yqD",
        "zEa=q",
        "$.$*I",
        "h*kw/NU",
        "HqD7v",
        ">\">/>O>Y>g>p>v>",
        "6$6,6H6L6",
        "TLS handshake",
        "~a'?Q",
        "_W'=w",
        "Dho-<",
        "Setting InstallDirDrive",
        "Configuring Xml File: %ls",
        "P^\\c{",
        "~w\"cZ0&",
        "<rule name=\"rule-0\" persistafterstartup=\"true\" relativeposition=\"first\" rulestack=\"hard\">",
        "cipher is null",
        "CB89F91D-BBC0-4895-8C92-3DB59665D0CC",
        ":.:5:<:J:\\:w:",
        "e}@*C",
        "Jy;YR",
        "6x)ai",
        "A3dKr",
        "V-Gnd",
        "ycv+nYy",
        "a1C/%",
        "Ot<@~a",
        "rGqRb2.",
        "|/D]B",
        "T$X3t$(#",
        "!5aO%Z",
        "BUF_memdup",
        "Rt\"@A>K",
        ",-No}",
        "SetUnhandledExceptionFilter",
        "98ucj",
        "lb}`r",
        "{Q6Z`Yn\\'",
        "*D@k3",
        "*M*rd(2",
        "%{ F7",
        "!ZVa|",
        "0%80]1",
        "T7N_I",
        "u-KPu",
        "\"^dA'",
        "hg;9f",
        "r3_@O",
        "\"NfiR",
        "0U$#t",
        "&9C`a",
        ">9~xLh?",
        "3`AwT%Au",
        "SJJ~Q",
        ",Uw0*",
        "Z]Kpo",
        "< <0<4<8<P<`<d<h<l<t<",
        "^[#%v3",
        ":\":*:6:\\:",
        "#$]uU",
        "5#5)5m5",
        "*3cqM",
        "R0R]ZC",
        "D$ 3L$@P",
        "ShOeA",
        "0FG9/",
        "9$9[9m9",
        "=7Afd/",
        "N$r E",
        "\\ZoneLabs\\",
        "U=Orc",
        "usJO[",
        "XVDwM'",
        "J2)h@Ms^",
        "Xe^27q",
        "jejqj!",
        "7&7,7j7t7z7",
        "2Ey\"&",
        "5pCS&",
        "McAfee Internet Security 6.0 Security Center (All SKUs)",
        "caSa* ",
        ")*u(!",
        "IIMSI_SetProtectionByPassword RC=%d",
        "2]4e4r4",
        "R+tL0qc",
        "%yq,/1",
        "7;&&g",
        "sUy3|U$",
        "!k[&2?",
        "wn>Jj",
        "U0]-C",
        "HgTMs",
        " |_Ty",
        "g,hX,",
        "1k6;nVQ]",
        "1ePVW",
        "PKCS7_sign",
        "1H_Nfrg;",
        "EP{p}+",
        "!|@~x",
        "fifIq",
        ">k} a4",
        "Zvru}TkW",
        "S8+?]",
        "W\\WlU",
        "MWAIT",
        "bbB{ ",
        "epcgina.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "}>BJ|)",
        "VISIBLESTRING",
        "WD_ExtractFiles started.",
        "Montgomery Multiplication for x86, CRYPTOGAMS by <appro@openssl.org>",
        "GSGSKS",
        "\\h!T[",
        "pAWs8",
        "enhancedSearchGuide",
        "#D$ #Y",
        "GU$N$",
        "-\\@}:z",
        "698=8A8E8I8M8Q8U8M9o:",
        ":3;^;s;",
        "o0|US",
        "PFMUL",
        "rFQN;QB",
        "sr#)7",
        "Wt4<PJ",
        "s!)Vd",
        "NhE'LXh%A_",
        "'y<^e",
        "^edz/",
        ".?AV?$messages@D@std@@",
        "PVSRj",
        "c&$*VY-Cc",
        "1M1q1|1",
        "Content-Disposition: attachment",
        "Y3ZsZ",
        "1yqyx@",
        "WDStatus",
        "illegal tagged any",
        "H9'OzX",
        ":1;t;",
        "'xpl6^",
        "t/UVS",
        "XFzd'^%>Y8",
        "o#;'f",
        "[R~=#",
        "?0???J?O?T?r?",
        "international-organizations",
        "Ky_%L",
        "0uw:z4,",
        "h(!8BD",
        "{i!sY:E*YT",
        "q2:9=",
        "c>SlX",
        "YYt$h",
        "\"aOV,",
        "\\P_BD",
        "+%.^__",
        ":Vc,|",
        "%BWxL",
        "h3v`~j",
        "o`.\\,2`1",
        "DQ,JF",
        "pjHy8}Iy8l_y8",
        "S5^8K",
        "setct-RegFormReqTBE",
        "<$ygB",
        ".3cP;",
        "t'yH>7",
        "1V7G\\6",
        "84T~P",
        "iQXT$",
        "fiY]sk",
        "D!:^}",
        "RC4(40)",
        "mTy01~",
        ":f;>u",
        ";2;N;j;",
        "\"CallStack\": \"",
        "Pj)V6P",
        "piCyO\"",
        "S*h%_",
        "Genuu_",
        "D69LDw",
        "BEOS_NAME_CONVERTER",
        "}P6@(",
        "'Q( K}",
        "GXSVj$",
        "ld3yP:C",
        "****************************** MsiCleanAll started **********************************",
        "zo|D]",
        "T+eHO!<1",
        "9^<mB",
        ";(!%`",
        "L$$1L$(#T$(",
        "Jd(^lZ",
        "RestoreOldGina",
        "8=8j8",
        "EVHmRTm",
        "unknown message digest algorithm",
        "8:8t8",
        "hiGn&",
        "tt-RU",
        ">6>@>N>l>q>",
        "-B33q",
        "t.0N0n0g:;",
        "lT6M.",
        "dsfainstapp.exe64.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "5G6m6",
        "C_?@h",
        "0$1E1",
        "Y]p2/",
        "\"t(m<",
        "GA1L?",
        "@o,jb",
        "^b`3g",
        "S^cyWR",
        "4UUaMwIG",
        "jAjfj.",
        "'DDDDfWWp",
        "8gM@Ec]",
        "}wr%3",
        "'Qv%|",
        " cLI|",
        "$BM*h",
        ",&HL^2",
        "M7YdtR",
        "U2Z2`2e2p2v2|2",
        "PSHUFD",
        "T'C'{5",
        "%4[P2 ",
        "Z|?Zd",
        "(p;N_",
        "CAST-cbc",
        ":5@aU",
        "+'+TdR\\",
        "j2N@h",
        "$v4?W",
        "SystemWithoutConsoleWait",
        "^eh#o(",
        "\\\"YzW",
        "=$=D=P=p=x=",
        "UYpsr$.",
        "m%d9f",
        "NrQ>O\"us_\"",
        " cc|u",
        " u7j2j",
        "</=L=",
        ">#>?>[>w>",
        "} 82&",
        "GH=[[",
        "UI_Framework = NO",
        "l^rXh2i",
        "jnx0v",
        "GetModuleFileName",
        "`2~w0!",
        ".:6a!",
        "\\m81f",
        "dH4MC",
        "O&N5qH",
        "l$,u9",
        "Dn>Ky",
        "B`K$*",
        "0[26W",
        "*JG7A",
        "W i`X",
        "u#QSV",
        "- inconsistent onexit begin-end variables",
        "9@3{&EVR",
        "-:}2g_D",
        "YX4;l",
        "T3w&6P",
        "OsName",
        "5m`Inc",
        "4&,y1",
        "5 5$54585<5@5D5H5P5h5x5|5",
        "RFC 5639 curve over a 160 bit prime field",
        "\"hmP ",
        "'jw<|",
        "DH-RSA-AES128-SHA",
        " Zb7A",
        ")S#Va",
        "syK({x",
        "291O3",
        ":;^pB_",
        ";#<0<",
        "fx:K;",
        "2U}(3$0",
        "5W5{5",
        "1DiYVl",
        "FY\\w-",
        "jfBXv",
        ",,mxm",
        "$-{gXd}",
        "MGGV0",
        "L5geg",
        "0\\`N(xl",
        "ZSd%i",
        "8V,Y\")",
        "|a_ea",
        "%04d%02d%02d%02d%02d%02dZ",
        "mN$tV",
        "/;)?f#O",
        "obXDK",
        "\"sU&\"!",
        "~v/_U",
        "QT(;r/*7",
        "\"0{qHc",
        ">{VBk",
        "l$,VWj.S",
        "maskGenFunc",
        ")%XKU",
        "h-3d%Z",
        "7uaG ",
        "revocationReason",
        "Ovm}~Q",
        "#L$H#",
        "615b8116d8a5fb34d93a6c1dd0afb0475292c5585e9236d88aad3e2412f9e3fbff1e1fa9abd7eec70c1d1221294fda5efd72cd4324f1794093b0eddd1ef62fad",
        "\"i?64x",
        "ycaB%",
        ">s.|r+#c",
        "~ogRl;",
        "&@sQ9%`&",
        "LAAK2",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 2.1\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "CONF_load_fp",
        "8%8:8?8",
        ")!zJ_R",
        "cNt[5",
        "F\"\"&*",
        "unsupported key components",
        "YT&iX",
        "issuer decode error",
        ";!;4;G;V;a;t;",
        "SHA1 part of OpenSSL 1.0.1t  3 May 2016",
        "S1r y",
        "]N*)$",
        "\"EkMW",
        "P3D)!rL",
        "Failed to stop vsmon service",
        "0<EpP",
        "FO1BX3",
        ":7:J:",
        "$&itEa",
        "}1l-YZ",
        "_time64",
        "|$$WV",
        "5$6Z6",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid11555386\\charrsid15533839 ",
        "XQL)VC~",
        "}c!ag",
        "dddd, MMMM dd, yyyy",
        "Type=executable",
        "uW<~wSA;",
        "3K4w4",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\GroupMonitor\\1.0",
        "b%~s:",
        "9+9D9]9v9",
        "29b)QV",
        "APbcF|",
        "4$404T4\\4d4l4t4|4",
        ":M;f;",
        "~ADWH7L7P7",
        "Pi$HD",
        "ao4k|",
        "zip.old",
        "A!A3A5A;A?AYAeAkAwA{A",
        "=&=I=l=",
        "VVVVV",
        "2EbA[K",
        "\\Ci)s>.",
        "sma-no",
        " +[:X",
        "4c.XU",
        "]v)&na",
        "W@[<XK",
        "t@,}8",
        "D$TUW",
        "!_N2'",
        "bV}TS",
        "LN^&s",
        "Cisco is NOT installed.",
        "(PT9\\",
        "UctF:{",
        "[VSUTIL] : MakeVsmonPath:   GetSystemDirectory failed with error %d",
        "dDpP4E6",
        "7P`{6",
        "MY9N\"",
        "GetFileAttributesW",
        "1u7Pz",
        "V}fl)",
        "D$LSP",
        "@~MAu",
        "x<)Zr",
        "0Kx~b_I\"",
        "S7,vJ",
        " \\F^+",
        "'V\\>=",
        "[WinFW] SetWindowsFirewallStatus(): Calling SetWFStatusXP()",
        "n)3:;",
        "gjFsT",
        "nC3Cngm",
        "v'qc/",
        "6'797T7",
        "{jB`1i",
        "4@-EYj",
        "Cor~=",
        "_dA^-",
        "L)})k-E/RW",
        "L)}1U:y~",
        "Mco^'",
        "L$P3L$<3L$43L$",
        "D+!=D",
        "'FI`$]{U-",
        "|{X?I-",
        "R&w#(",
        "6P!)oN",
        "got a fin before a ccs",
        "{F%i;",
        ">R?s?",
        "V!qf%",
        "Qw_L?.<",
        "9):&<",
        "IAjYv",
        "_U#U4",
        "h1dOK#",
        "9Ghv_3",
        "5Q5l5",
        "LBa%<",
        "Endpoint Security was detected, installation will exit.",
        "DELETE FROM Binary WHERE Name='%s'",
        "|B8+}~",
        "no client cert received",
        "l5sIc",
        "n66`n",
        "u=y$u?R(E",
        "`e{e)",
        "&&&&&&&&&&/&&",
        "ft!}z_x",
        ")\"#RK",
        " 4kBh",
        "j:Y9%",
        "PJ'm&",
        "tm_^][Y",
        "w@**B",
        ":F;X;",
        "Unrecognized parameter value passed via CURLOPT_SSLVERSION",
        "1X\\B%",
        "vQY=Q$",
        "k.i%I",
        "?@\\Hq",
        "ZRUr2",
        "@,?oC",
        "df&#nX",
        "*xk!T",
        "D$Ht8",
        "^W:B(",
        "X+6LD",
        "qsqk=y!",
        "Failed to figure out path",
        "uHPLE",
        "949D9H9X9\\9`9d9l9",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\BrowserMonitor\\1.0",
        "<*<_<",
        "'a&xX",
        ";Y\\5`Z",
        "<?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?>",
        "]:%e06<R",
        "}buZ+X",
        ".\\crypto\\x509v3\\pcy_node.c",
        "WixQueryOsDriverInfo",
        "5NX8p",
        "&N;p@",
        "4+6F6X6",
        ":O K'",
        ":U{*a",
        "O~_72i",
        "~JeA<_]",
        "|o/dl",
        "gz@KJeg>",
        "8jgu<",
        "0P0U0z0",
        "SRs&x",
        "5#5<5U5n5",
        "xso:L",
        "sOuM=",
        "6$646D6H6X6\\6l6p6",
        "1|o+pE",
        "eM2z{",
        "mz8}5",
        "!bH\\q",
        "S=sF|",
        ",IXI\\A",
        "lXjw{F",
        "3AtD5Z",
        "axkp7",
        "3g3}AR^",
        "3,WuX",
        "failed to set exception port",
        "!-MYk",
        "6!6A6U6q6",
        "K5'uz[=",
        "1P3a{",
        "[Dx@R",
        "Tqe4s:NG4",
        "KyUOe",
        "5H\\M~3Ad",
        "c8#>=8",
        "}Mm#V",
        "4!Diw",
        "m)0E!^",
        "%33331",
        "Found Check Point VPN installer",
        ";AG#8dO8",
        "EOF on memory BIO",
        "<bvHBR",
        "X?D*\\",
        "\\lsdunhideused1 \\lsdlocked0 Body Text 2;\\lsdunhideused1 \\lsdlocked0 Body Text 3;\\lsdunhideused1 \\lsdlocked0 Body Text Indent 2;\\lsdunhideused1 \\lsdlocked0 Body Text Indent 3;\\lsdunhideused1 \\lsdlocked0 Block Text;\\lsdunhideused1 \\lsdlocked0 Hyperlink;",
        "XeD$x",
        "0lLDFEv",
        "}u*hh",
        "uYaXFZ",
        "ldxpW",
        "UZ\"]Ug",
        "a>{(B",
        "0t;!s<zr",
        "ZwReadVirtualMemory",
        "1$101P1X1`1l1",
        "unknown remote error type",
        "616Y6m6",
        "[\\N#A",
        "RH.,r",
        ";)<w<",
        "R^|k\\",
        "=a!P9",
        "pqF)bK",
        "y<Ptb",
        "Return code: %d",
        "YN2!>",
        "NTLM handshake failure (type-3 message): Status=%x",
        "WL290",
        "<-<3<",
        "}^& 7i",
        "m[Xc5",
        "AES-256-ECB",
        "E'>y</",
        "P<xD<",
        "D$ u.",
        "nTwY+Wy{",
        "Qmc7\\V",
        "onlysomereasons",
        "J)b)1",
        "-Grzt~U",
        "O0=.O{s",
        ")ejXS-D",
        "+\\_d_`2",
        "Issuer check against peer certificate failed",
        "s@N,)",
        "UtM'F",
        "82:9:>:",
        "/x-DHa",
        ";8;[;s;",
        "FLT_UNDERFLOW",
        "?L?z?",
        "failed to write component bitness to rollback custom action data",
        "3DB_\"",
        "Registers:",
        "=mO:C",
        "d!V-T+",
        "rvD3t",
        "omN}F<x",
        "hSVWj",
        "t\\a)_",
        "aZ=Q a",
        "@@\"#P",
        "-et9ma",
        "][yzB",
        "Ny[CF",
        "Could open process. PID:%d Error: %d",
        "_8b!I'",
        "rc5-cbc",
        ")re0~;",
        "CreateThreadpoolWork",
        "Z!a2!",
        "bz'\"x",
        "a)HjJ",
        "9s;nQ0",
        "Mu1b_BsO",
        "r$X3uS",
        "P+OOu9_T",
        "1g KQ",
        "J?=q.",
        "gV]KQ",
        "22S5wZ",
        "=aFhB",
        "BIO_new_mem_buf",
        "fM]Bv",
        "7?Wby",
        "CheckNetworkFilters ended.",
        "=w6m-",
        "GetStartupInfoW",
        "%*sRejected Uses:",
        "Rfi;3",
        "-cc:{",
        "application/x-pkcs7-",
        "5\"Ve_",
        "Bdd])D",
        "t$$UWVj",
        ">0t-N",
        ">X>t>x>",
        "2)e)U",
        "FM7H;Le",
        ", path=",
        " 0xf8",
        "\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid3017503\\charrsid15169477 L}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid13844772\\charrsid15169477 IMITED HARDWARE WARRANTY}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503 ",
        "write error",
        "Can't Query Characteristics Value at Subkey %s",
        "7MKs^*",
        "Failed sending HTTP request",
        "E<3PL:[0",
        "{cRxg",
        "eWIX_DIR_ADMINTOOLS",
        "DE TERMINAL",
        "GwjKt",
        "Unable to check %s",
        "Failed FTP upload: %0d",
        "void __cdecl boost::property_tree::json_parser::write_json_internal<class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >>(class std::basic_ostream<char,struct std::char_traits<char> > &,const class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > > &,const class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > &,bool)",
        "HcK ]",
        "m\\v(,0",
        ",]xj;",
        " gMs}",
        "bNrK&",
        "|SHpKqm",
        "(>6T@",
        "*Ea\"u",
        "No valid port number in proxy string (%s)",
        "8$848T8",
        "M[U[Cg",
        "Whitelisted",
        ",\"+Sp",
        "x>,BP",
        "3=,`w",
        "Tr4vY,xN",
        "/&{x\"",
        "yc<UH",
        "0s[Kb",
        "'PMjF",
        "D$$VP",
        "c}WvK",
        "JBYWR7]",
        "$h^Yh",
        "$xeUm`",
        "M|1}0",
        ")67)N",
        "Cl,h[A",
        "b`jed",
        "QQM&8=",
        "=,=:=H=U=_=",
        "C?aQW!",
        "sw=J ",
        "g-^TU|",
        "i0>kc",
        ";gK',3E",
        "u5ZY5",
        "r<.JH",
        "b1-.C",
        ",'k. ",
        "jF{!z",
        "id-smime-cti-ets-proofOfApproval",
        "vsdatant_win7_64.inf.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "Y?=E-",
        "DIVPD",
        "?)?4?;?M?T?_?j?z?",
        "9$|H<p",
        "eoURl",
        "Xg]c#dL",
        ";*<w<",
        ":7dW-k",
        "8>G;8",
        "Check Point Secure Access Installer",
        "X2Gs8l",
        "Input/output error",
        "\\sc(3W",
        "spanish-paraguay",
        "QSSSSj",
        "m>2:x",
        "Visual C++ CRT: Not enough memory to complete call to strerror.",
        "'9)zs",
        "2z:%|",
        "jG{$]Y",
        "JRV/m0",
        "\\Rjuc",
        "T3\\l|",
        "mI#w#X1",
        "XR:n1",
        "$#:.z_",
        "NX7qXo-",
        "6g=>f",
        ":):3:::v:",
        "ERuX6",
        ". KC;e",
        ",4-d-",
        ":4:l:",
        "0=1}1",
        "_o/r/",
        "G<{u/",
        "b]N@@",
        "9^Xhl",
        ":A:f:",
        "1 1-1T1[1g1q1",
        "6V;,y",
        "d.other",
        "|.Z5\"*lz",
        "N5,Q&h",
        "]EhOra*",
        "lPPBM=K8`",
        "(ddR,kU",
        " \"HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\SecuRemote\\5.0\\sites\"",
        "7(737>7X7g7n7y7",
        "`WH?W8c",
        "Finishing",
        "UtT>E",
        "un|-W",
        "J|Is7",
        "McAfee SecurityCenter",
        "S}4x\"",
        "8SSc}z*G",
        "IeU.7",
        "SSL read: %s, errno %d",
        "y)>]]$",
        "ub#!G`>",
        "TrueVector engine: %1",
        "okYDa",
        "GOST R 34.11-94",
        "t<x<|<",
        "l@\"y4",
        "v!h-%",
        "V0N=GP",
        "AAAAAAAAAAAAdZ",
        "@ep>Q",
        ">$2,d",
        "installwix_(\\{[A-F0-9]{8}-[A-F0-9]{4}-[A-F0-9]{4}-[A-F0-9]{4}-[A-F0-9]{12}\\})",
        "l$(#H",
        "<#=J=",
        "1J8(>",
        "5,5E5X5",
        "=|ti8",
        "R_!\")",
        "1dF&X",
        "MU4x!",
        "d|kw{",
        "bFg2'V",
        ")T7tw",
        "%s\\%03x",
        "`f5c,",
        "^hR?V",
        "7R0<?",
        "RpcA!",
        "R4HY&",
        "9%ywud",
        "b01d583deee5f99824e290b4ba3f364eac4a430883b3c092d4eca8f946c916422ecab927f52ea42b89a1cd59c254f919b0e85e6535d135a8de20f20b8c12c3b0",
        "e=.XVI",
        "V\\v4z:",
        "nCSBn",
        "bR#PA",
        "x)zu;",
        "SeTakeOwnershipPrivilege",
        "6 6p6|6",
        "4mqhK",
        "8{z6B",
        ",xz3&h",
        "7%UBkk",
        "(K4;w",
        "Whitelisted by Subject + trusted Chain",
        "ri.;Y_",
        "failed to get value of ALLUSERS property",
        "Failed to generate unreg request",
        "i2d_EC_PUBKEY",
        "WIX_DIR_DESKTOP",
        "A@r_=",
        "rd_Y<Z6",
        "@%6\"@",
        "1&222J2R2_2s2",
        "aes-128-gcm",
        "T$L3T$",
        "yog /",
        "[PERFMON] error %d getting class factory from provider %s",
        "FTP: Accepting server connect has timed out",
        "##e[}o13",
        ".>!Rf",
        "Eho_A",
        "*(.FCBl",
        "hQcvt",
        "c*13t",
        "CMS_COPY_MESSAGEDIGEST",
        "6;7a7",
        "RZe6[",
        "2pgY=",
        "hxcK_",
        "[yk'1",
        "Vh<cL",
        "E@q;J",
        "Ab?1%a8",
        "/^\"wS_",
        "XoLgH",
        "K<S=N",
        "SeDebugPrivilege",
        "Kcy4%",
        "zxcAlC",
        "9@9L9b9~9",
        "0q/wAf",
        "10RRg",
        "7#707L7^7h7r7",
        "7Ob5+A",
        "G(D]JWA",
        "WTSFreeMemory",
        "Hn3a^",
        "Proc-Type: ",
        "(bF+[9",
        "W=/r/",
        "4gXup",
        "X|P3c",
        "Uk hz",
        "\"28umK",
        "c@rPQ",
        "pQ9oe_",
        " LWya",
        ".kNlB",
        "4Od+W?",
        "3)303?3W3^3i3t3",
        "7.8\\8",
        "Wews`",
        "bVR:,",
        "k$k,k4k<kDkLkTk",
        "{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States{\\*\\xmlclose}{\\*\\xmlclose} laws and regulations in effect from time to time.}{\\rtlch\\fcs1 \\ab\\af1\\afs24 \\ltrch\\fcs0 \\b\\f0\\fs20\\cf0\\insrsid11303137\\charrsid5013025 ",
        "GXSQW",
        "mzIo&",
        "@\\auS[",
        "C*|R7\"",
        "nF' U",
        "o Hxga",
        "DRPo,8",
        "RJg~A",
        "a(\"Yd",
        "oK:.2",
        "#3S?2",
        "`CcY ",
        "888D8d8p8",
        "\\zonelabs\\vsruledb.dll",
        "%jbb~",
        "V<=+nK",
        "j_5~I{",
        "\"; boundary=\"----%s\"%s%s",
        "8+8[8",
        "\\$$GS",
        "FRSTOR",
        "y23tF",
        "u9YJ/Iz",
        "F;]  e",
        "_dwoQ",
        "r}8[9",
        "A%eNE3",
        "street",
        "%I4I0I",
        "INVALID_HANDLE",
        "]cP2T",
        "Eu,`6",
        "4J[Z?",
        "A!rB(.",
        "u%^lil",
        "&W7r&",
        "\"@q*FPQE",
        "Failed to do PORT",
        "=.>6>",
        "-{RL5w",
        "PCCClient.exe",
        "iBSy#z",
        "x?`pwnL",
        "rZN@<",
        "security descriptor does not contain a DACL",
        "4|7:r",
        "DH5qD9",
        ";6<B<P<c<",
        "Q;OEx",
        "3r)srX\\q",
        ">*?5?E?",
        "Wh!IC",
        "Vc;*W",
        ",4T[D",
        "s+4\"RT",
        "2  .)-t8+",
        "XhORG",
        ";<;Y;v;",
        "Roe)K",
        "b26}7^",
        "mFT+|",
        "camellia-192-ofb",
        "y%==J",
        ">N>s>",
        "ub_\\7)Kbz",
        "%v%f%n",
        "1%id^HZ",
        "WD_RemoveWatchdogService ended.",
        "| bJr",
        "connected.png",
        "$BKJK JQ",
        "5MY;:",
        "+e|fuA",
        "!{{A+]h",
        "1)dsw",
        "rW%)L",
        "> LRc",
        "EPAM_CheckUpdSrc",
        ";F<X<y<",
        "\\Eav9",
        "<.L^9",
        "TJjOM",
        "<#JZ~s",
        "~LPqpE",
        "{Lr_+;.{",
        "#BEw/I+",
        "D$XVP",
        " 0xc3",
        "; ;$;(;,;0;4;8;",
        "lE={&%",
        "4\\PId",
        "JsPC,",
        "zh-mo",
        "'T9({",
        "Immediate connect fail for %s: %s",
        "w7MZ>",
        "'o9-r7",
        "F2N2V2^2f2n2v2~2\\0",
        "03mLZ",
        "\\zonelabs\\ZLCommDB.xml",
        "Un[7x+",
        "OuvC3",
        "VH]^_",
        "__c cz",
        "fk |)z",
        ";w?(|",
        "GHASH for x86, CRYPTOGAMS by <appro@openssl.org>",
        "U}+tpB",
        "%Z=)'9N",
        "[TSvf",
        "pm7veq",
        "Nv>0f",
        "PVNT-",
        "L$(VQ",
        "061A1d1n1",
        "$^(zL",
        "7g8k9%;&<K?U?_?",
        ",kdL6",
        "7}?^'",
        "<8=f=6>E>~>",
        "7?*{C",
        "VhP; ",
        "qe=c9\\",
        "_)5)[Z",
        "707<7\\7",
        "PZ/c((",
        "0H<!40",
        "?vk(1",
        ",An+x",
        "|0*~}",
        "DL%%*",
        "nC0#<",
        "fieldType",
        "Interrupted function call",
        "4Fm.7$",
        "1IE3.",
        "tSVW3",
        ";{CL!",
        "%s(%s)",
        "|4}ou",
        "o?M]b",
        "9w`=j'",
        "$m|uQK",
        "SQ&;T",
        "k&'7:*",
        "R2(<hu)O",
        "D9@q;",
        "747?7_7h7w7",
        "oMr$ 7Y",
        ">29|n`",
        "CLp+?",
        "\"tKS/",
        "U2U:UBUJUZUbUjQz",
        "?-]Ql 7z",
        "?d$cFG",
        "07!Tds",
        "L$D][_",
        "R6019",
        "gv?te",
        "iQ]/H",
        "L$H3T$P",
        "bBab ",
        "465C5",
        "PRET command not accepted: %03d",
        "\\=a}c",
        "uV5xN",
        "jfjoj%",
        "u4~PG",
        "SK)eVU",
        "6!6,6",
        "+FO(s",
        "pJ$:GB",
        "Creating IShellLinkW shortcut '%ls' target '%ls'",
        ".\\crypto\\evp\\evp_key.c",
        "kveE0",
        "-Cfw\\j ",
        "ZLA@N",
        "k/{HL",
        ";_Q(v",
        "+z3!yB",
        "^#L@Xh",
        "Ksqhr\"\"zx~",
        "/ZeQY?`Ru",
        "1G1r1",
        "JZZ#?",
        "N5w>u",
        "7\"<;<",
        "$x)Dkq",
        "|G~=@",
        "E[gym",
        "ChJ;v",
        "kF+PF#",
        "+/|{.",
        "CreateServiceA",
        "*IBa|",
        "^\\\"_zHk",
        "a0~;\"Pz",
        ".\\crypto\\asn1\\x_info.c",
        "0JFMxL",
        "WMoLu",
        "-&)'|",
        "1'121",
        ";:6^\\",
        "j:KqK",
        "t ndWl",
        "L#geq+]ulFj;",
        "^$+^8+",
        "missing dh rsa cert",
        "X{\\8Qc",
        "Y%Qq9",
        "UI_dup_verify_string",
        "4HF)p[x>",
        "MfSit",
        "F.pd(",
        "q(z-;",
        "^0:r7",
        "t8Ln3",
        "x509_info",
        "parameter",
        "IsBinaryExist failed to Fetch View. Result = %d",
        "zezVCee",
        "!%L=Zr",
        ";T$4|",
        "x//>{",
        "w%p)h",
        "UqGq+N",
        "hF\"q$",
        ":e,=n",
        "7A\\Zp",
        "Z~UA>",
        "pkeyalg",
        "H[/5H9Q",
        "T`@Ll",
        "7e9n9v9",
        "'(-^iW96",
        "%aQ)ql",
        "!]r)n<P",
        "{c2Ze",
        "4s!&.",
        "3)4e4",
        "\\LWTW",
        "Pha55",
        "8k.s\\",
        "A;L$,",
        "2\"436o6",
        "r{^U+y",
        "Uiz/\\L",
        ")42%bFD",
        "W`MK&",
        "PH]zfv",
        "PRHelperIsRunning = 1",
        "krb5 server init",
        "=+=9=N=Z=t=",
        "}O!/S",
        "dy6)Z",
        "~p<@_",
        "xsgY*",
        " subjectAltName: host \"%s\" matched cert's \"%s\"",
        "+5}PG@",
        "8/8H8a8z8",
        "c)^ 5",
        "+)vN-5",
        "VP`&B",
        "0^3ys",
        "E7wg.$I",
        "Mdwv0",
        "Q)Ge3m$",
        "U&S l",
        "@jJZV",
        "8fu&|",
        "6+7l7",
        "jnjgj\"",
        "krb5 client mk_req (expired tkt?)",
        "CMS_digest_verify",
        "u8l]M",
        "!ns.gh",
        "B`VcIPw",
        "/bCNhQj",
        "=[8v<",
        "5A7X7^7",
        "aiQdPg",
        "^'M+W`",
        "K1I`r",
        "1&181b1",
        "8<8J8X8]8i8v8",
        "ZU9UVj5",
        "@[0?w",
        "4~kV5",
        "vO_~U",
        "qzl?[0",
        "_{0^IAc",
        "R]EVQ",
        "j&jjj",
        "D$4PSSS",
        "\\;bxB",
        "atlTraceDBProvider",
        "]|I@*",
        "?}7Nb",
        "t$(h`",
        "tSV1@",
        "]T;9W",
        "Fw#[(7",
        "6p+fL",
        "RtlQueryEnvironmentVariable_U",
        "7o-uo",
        "O8HH~",
        "Installer",
        "4#4*434G4^4{4",
        "\"*^Za",
        "bad mac decode",
        "R+Mft",
        "-!6\"cq",
        "_]LV\"",
        "TWJs{",
        "qG_4N",
        "xRK&m6",
        "3Hhnr$I",
        "XXHcw",
        "g^Ig\"Qt'",
        "`IK% ",
        ";S-9&",
        "]5q7N",
        "=yvy+yfxJ",
        "Ubo1|",
        "|HX\"0",
        " m~OR",
        "Gy0)F",
        "?L_&YV",
        "0C1M1W1a1",
        "SEC_E_INTERNAL_ERROR",
        "e-=[!Uq3CjU",
        "}$\"K-",
        "BN_mod_exp2_mont",
        "; ;N;f;x;",
        "GetForegroundWindow",
        "=|,|c",
        "sIY^?",
        "0h@w#",
        "$hM8N",
        "SOFTWARE\\TrendMicro\\PC-cillin",
        "j;IsS",
        "7 848`8",
        "k;r$a",
        "SS_Wnd",
        "Kw#Nj\\",
        "qJvWT",
        "r_h\\y",
        "@[Ga J",
        "]4M9k",
        "|p4uDH",
        "]-b4P",
        "f`(`5;",
        "/YqKD",
        "\"]{&K",
        "t&hPm",
        "hCa2v",
        "}`5-4",
        "zpz KP/",
        "|kVaN",
        "image/gif",
        ">s:QI",
        "_controlfp_s",
        ":UOxm",
        "3r+eA)C",
        "OsBuild",
        "Hl~EDu{",
        ".|[S^>YI.",
        "cLOX*",
        "t.GKYN1",
        ".+]x=(Z 6",
        "7|>`O",
        "SJ.M:zu_\\",
        "K7GSU",
        "\"4(WA",
        "QSphA",
        ":u/qK",
        "\"[Ss:",
        ";1<Q<",
        ";\\{,G",
        "\\TMStatuses",
        "U8]R6",
        "JHxdG",
        "6T?$_X",
        "C%b?3",
        "UnregisterClassW",
        "o1tp3X|>",
        "h[$aL",
        "fQKkl",
        "8i=a0",
        "m{a,G`",
        "0'zPY",
        "B6co>rBM",
        "d4IJN",
        ":abfv",
        "L*CKd6",
        "lyB=c",
        "/d8'o",
        "0Z1^1b1f1j1n1r1v1z1~1",
        "FE]{!",
        "PW|QY",
        " +>1#",
        "i2jZj",
        "5(525@5I5S5t5",
        "!<=.L",
        "@#%s?3Tw",
        "G=+.f",
        "YRl-K",
        "+ )|Va1",
        "!n\\~1",
        "~\\_[W$$",
        "`omni callsig'",
        "=$=,=4=D=L=T=d=l=t=",
        "l{<A$",
        "LvO_Sd",
        "A^ye,",
        "?lu+7",
        "_[eQ\"",
        "T~sE%6",
        "RSA_verify_ASN1_OCTET_STRING",
        "0\"2>2",
        "xnpn^Np",
        "handlekmsg.exe",
        "}UnNQ",
        "{l=Dg;",
        "addToWinFwExceptionList;",
        "E_ !V",
        "algorithm_id",
        "u]8D$",
        "\\f1Ps",
        "3#3?3[3w3",
        "wC07i",
        "c/^/PS",
        "SEC_I_CONTINUE_NEEDED",
        "organizationalStatus",
        "}bO0{",
        "U4=XZ3",
        "MlN>O",
        "z4D17",
        "@$,Q+6#",
        "Nb1V-",
        "#^Edx",
        "%sL|~",
        "B|0nmfR+",
        "t520l",
        "%J?fw",
        "b8@v,",
        "*F,FDG",
        "091L1",
        "AiTq:",
        "c<+&]%D'+",
        "p#Ee1e",
        ":Z:c:n:u:",
        "\\$DUVW",
        "\"Zra\\0u",
        "b\".V5",
        "Va5Nx",
        "Qy.9h",
        "g.UH$",
        "h*{wPQ",
        "yqi;p",
        "c\\2y0",
        ",-!NF",
        ":6:E:[:b:h:n:~:",
        "1E+TJ",
        "o}g9*",
        "aDXhl",
        "g\\.GCn",
        ";\\s(b",
        "wwwwwwwwwwGx@",
        ".\\crypto\\evp\\pmeth_gn.c",
        "{4{+O",
        "U@@Il",
        "YYj,Z",
        "CLIENT libcurl 7.49.0",
        ",JXCB",
        "iO.{5`",
        "[\"fw:",
        "[LICENSING] License file attributes are %#x",
        "5s526I6",
        "&gYq4",
        "5=(t3",
        "-uMumu",
        "\\1^2p+?<",
        "b|TjL",
        "NitUfGA",
        "vaZ:?",
        ";*:RZ",
        "Ww>}K",
        ";5L_#",
        "SELECT * FROM `%s`",
        "_t0%T",
        "O_zQ2",
        "Bh/8)",
        "Please use /createMSI option to get a proper EPS.msi from exported package",
        "_U{RC",
        "_[w^[1y",
        "R[dds",
        "b~jo*|",
        "a'0m_",
        "6;*hw",
        "6/LnE",
        "yb}t?!",
        "The Restart Manager is not supported on this platform. Skipping.",
        "6328|}",
        "<1 yj",
        "5%515N5f5",
        "MNOPQIRSB",
        "*mo@ ",
        "%7N9Yy",
        "xy;54",
        "ZsTU8:",
        "1Q1\\1",
        "sl-SI",
        "*9u!x",
        "Tb5a3",
        "I=/d|",
        "}^0vO",
        "3|^/;",
        " Q:{z",
        "[e~y\\",
        "s*X0yTj",
        "l.;!-e}",
        "X0!E%I",
        ">f_/z",
        "dZv/;",
        "z0pN%",
        "?`*Fx",
        "1Mnlhp>;k",
        "J9_[;}4",
        "SCUIAPIEndpointBanner.png",
        "\\handlekmsg.exe\"",
        "6d&->",
        "x,Fl6*",
        "OaY{U",
        "localKeyID",
        "W|ZDB",
        "8,W4^T",
        ";$Am^",
        "EoC&.",
        "_5|Bj",
        "osfirewall",
        "O,9O(vV",
        "M*vohn",
        "-1.%U",
        "CO|78+",
        "\\fs20\\insrsid8673032 (}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid3083316\\charrsid13256927 which are not covered under this warranty}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid5386754 )}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid3083316\\charrsid13256927 ",
        "byVK;",
        "E~t53",
        "7G8Z8",
        "00-ff-ff-00-00-00",
        "Uhl8#",
        ";j3Db\\L",
        "*jxOz",
        "HqkmY3T",
        "setct-CRLNotificationResTBS",
        "8.999H9s9~9",
        "-b8 3",
        "~sx*&",
        "&'7FrA",
        "s|g8@*6o'PK",
        "<xI,M",
        "^JPz/\"}",
        "jujjj#",
        "ECDH/ECDSA",
        "212C2H2T2b2l2",
        "\\s6\\ql \\li0\\ri0\\sb240\\sa60\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel5\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\af0\\afs22\\alang1037 \\ltrch\\fcs0 \\b\\fs22\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "wl\"Ym",
        " 0x1a",
        "Dr3h9",
        ";h(MM",
        "&Yi\\W5",
        ">#@]7",
        "|@8ZL",
        "*t`Z~",
        "a4adf1d0f82b7bd46cea4388ad1c12ab5d1ed8e1153d9c9f350a3246aad01c6873462b9ac05999ad5cc988826eafc3acae853a33b7ba11cd1445875ba1b236b1",
        "ImportTablePatch('%hs', '%hs', 0x%x, 0x%x) - AV",
        "`cc `B",
        ">i.S4",
        "G:*I$",
        "fW%3%",
        "OReO`",
        "0>0P0",
        "RpB%:u",
        "CM%v*",
        "ssl3_get_server_certificate",
        "XJV6Sf",
        "+'4HewU)",
        "'jc<T]}pF",
        "?mRRUR",
        "`p(DA",
        "YS}ucE",
        "q9Xry",
        "VMREAD",
        "?'vt^]C",
        "jnjpgr",
        "s=g>7s",
        ">Tfyx",
        ".?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "boost::filesystem::copy_directory",
        "removeKlif",
        "7S0'}",
        "j,d|r3",
        "Yg\"_J",
        "xU^nh",
        "CWGgO",
        "xXl}P4",
        "id-Gost28147-89-CryptoPro-KeyMeshing",
        "]YT\"m",
        "58kUO",
        "8$84898>8N8S8X8h8m8r8",
        "ITRcm(NP2^",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\installdriver.cpp",
        "(-'W%`",
        "ZvYpS",
        "I_Us]",
        ",~1?[-",
        "issuerDomainPolicy",
        "}:=M]",
        "Gz\\]$",
        "_AO%#",
        "8T9a9",
        "6n-iX",
        "q<')\"",
        "&QzP|",
        "(Rlm%\\",
        "$>loo",
        "o:5b*",
        "$bYL/",
        "P;]Me",
        "(JSNS$R",
        " 0x48",
        ":0D0a0r0",
        "ZLTcp",
        "ezsD`5F",
        "4)u.M",
        "dVKyz-8Z-",
        "1hZ=1",
        "3`]Lk",
        ",}ET}",
        "t<JePm*'",
        "d]%sm",
        "YZjx@",
        "x509_req",
        "30Z>}",
        "K5Nh4~yq",
        ":vgXe?+k",
        "l$$VW3",
        "< =$=(=,=0=4=8=",
        "(\"jku",
        "#L$ #D$",
        "Host: %s%s%s:%hu",
        "cZ<csWVa",
        "M;z^H{c",
        "%6:8\"",
        "DX0U~{",
        "mGv`5",
        "969Z9q:",
        "}7K0a",
        "lth*_",
        "@Vu\\P",
        "4K7OsF",
        "R~+w$#4",
        "V\"v<R",
        "nL&Iv",
        "=\"4.\"*g~P",
        "*Za1H",
        "sha256",
        "&vR,s",
        "T4<{(",
        "tlj2j",
        "ox~1P",
        "_tcvJ",
        "p?x)\\_",
        "]9ar,m",
        ")e:7W",
        "bmpstring is wrong length",
        "invalid message length",
        "c2tnb191v1",
        "<:<O<e<r<",
        "<;l\"A",
        "mN/8zj",
        "9.9A9^9",
        "0SW71sW",
        "1!1L1",
        "I$UJ)",
        "nrt{Ko",
        ")FqzY",
        "\"e2qX[m",
        "R^q@p",
        "787@7H7P7X7`7l7",
        "S2mx5YX",
        "\"!$|P",
        "U,WM-",
        "cdklib.sys",
        "Windows update for SHA-2 code signing support is not installed. See KB3033929.",
        "\")4YGYM",
        "E9ny\"",
        "{wi_Q{DEyR",
        ".N\"vnn",
        "i7f,^",
        ":VfHs",
        "~SX8i",
        " [PVPN",
        "6'686I6Z6",
        "OnUpgradeAfter:  started",
        "rL4 ;y",
        "%E -n",
        "MAJOR",
        "(e0D(o",
        "WiTTQz",
        "EC PARAMETERS",
        "2C85EFD9A323CBA4D829353AF4B05657",
        "'7&KjHo;",
        "6h`3I)",
        "(J`e$",
        "}l?)h",
        "YF?G_",
        "B|@0J';3",
        ",pMQH",
        ",=<(r",
        "}EWLl",
        "u#Vh<",
        "crlUrl",
        "_Wgrc",
        "Y`9(x",
        ".?AVCAtlStringMgr@ATL@@",
        "$eJgG",
        "bSavedVsdata",
        ".@6B$",
        "7E[+L",
        ";eg{rt",
        "--%-b(",
        "<,<4<@<`<l<",
        "}X04B",
        "-Ys1~",
        "merchant initiated auth",
        "&}'JFT",
        "Aa[F[",
        "l2GJyU}",
        "4V(xi9",
        "X?Vc0J?",
        ".&'T.",
        "<(MMv'",
        "id-alg-des40",
        ".?AUmoney_base@std@@",
        "Fx.'M",
        "`Ed`'&8N",
        "i;G8f",
        "F:\\ckp\\src\\EP_CALib\\E87_20\\CMpub\\lib\\win32.release.32.msvc141\\vsinitproxy.pdb",
        "=$$5%c",
        ":+:;:K:[:k:{:",
        "=RtS*",
        "Mm@rz",
        "2,3A3T3",
        "<:<C<R<p<",
        ">8^{A",
        "Qhd<!",
        "responseExtensions",
        "#I\"8'",
        "`yRFz",
        "\\3;L$:",
        "G[W1W",
        "\"!\"%\"+\"1\"9\"K\"O\"c\"g\"s\"u\"",
        ":\":U:",
        "kDy$C",
        "<UAUIU^ceUwa",
        "H_S#w",
        "[7q9;",
        "2,3#8.8Z8",
        "9#1#E\"]jm3b[v",
        "i2 (S",
        "nNF)Gla",
        "DIH{e",
        "fHS'6",
        "_~ZF7",
        "p9yso",
        "D$<VPW",
        "Eo*D>M",
        "D.;zq8z",
        ">J(L19f",
        "qUk[}",
        "$t-t|0",
        "4=<]<",
        "lZg84",
        "6Mn(8 ",
        "Ea4=ii",
        "vRx@\"m",
        "=woLN-Qs",
        "Failed to register window.",
        ";<;@;D;H;L;P;T;X;\\;P>T>X>\\>",
        "#niLH",
        "OCSP_SIGNATURE",
        "R7chE",
        "?7<LS",
        "*y:\\#",
        "Caught unknown exception.",
        "686Y6|6",
        "y()78",
        "]Z>$dXQ@",
        "2$202P2\\2",
        "M7MWMwM",
        "_| !.{AZ",
        "$w*T:",
        ":oTio",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid5186676 Hardware Products}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477  damaged}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9533499  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "9F9X96:O:",
        "9`O:Q",
        "7`8=:A:E:I:M:Q:U:Y:",
        ":>:a:",
        "db9Dd6U=",
        "moyeN ",
        "$2W<#",
        "797N7\\7~7",
        "U,|F-",
        "8;8@8d8",
        "N 4]#1",
        "}I-u[",
        " EYCx",
        "Heap32ListFirst",
        "\\z:S}TT)+",
        "m[9$X%",
        "3_9`^K",
        "Failed to receive SSPI encryption response.",
        "\\[3<a",
        "cFYw0",
        "ReplaceOrAddAttOrTagIntoVSConfig():1 returned %d",
        "fEmeYJY",
        "t$(QRP",
        "TeMTz",
        "&^vk2",
        " ~sO9]",
        "8$8A8",
        "GI:b+",
        "4gBy1",
        "#C|>k^o>",
        "E69]X",
        ": ;N;",
        "/0M2t!",
        "{}:{} failed to write log - ex: {}",
        "29cJk",
        "f|54%",
        "\":I:q>",
        "G`0wy",
        "6FA2C545B2F581A45B205B15A79A268B",
        "ryj2r",
        "IcS}h",
        "=*=8UL_",
        "KV@}_",
        "uomvO",
        "s/<do",
        "IK]'y",
        "`generic-method-parameter-",
        "m<(~G~",
        "Zwk>n",
        "3:9?M",
        "Xltm7e",
        "etk?#m",
        "=|zh5",
        "xR>3B]",
        "~8]/w",
        "N#vCH!DP",
        "Pug9A",
        "}zdQ;",
        "^$W0^",
        "d|VQBi",
        "WJ[V@G",
        "P3g>:F",
        "Xja?*",
        "E]Q8b=@",
        "0&1-141;1]1n1",
        "l$pVWP3",
        "=T+Zz[",
        "a^\"iMcs",
        "#R(kB02",
        "+-p<q",
        "G[GXE",
        "@Capq",
        "f>^_*",
        "c__{A",
        "G%M?;",
        "BVzM+2",
        "<L<f<",
        "IP]!0",
        ";FK{Kt.",
        "oriType",
        "Xd2N ",
        "Ef<[M",
        "bJ]j\\",
        "\"Jt0}^",
        ";g&TG",
        "#qTH\";m",
        "6}?KH",
        "%(*nU\"",
        "$X[7c",
        "mP}GI",
        "pUai^",
        "V9;Q2",
        "#P9~5",
        "mOfaVId",
        "VUT'!",
        "id-smime-mod-cms",
        "H\"|B/",
        "p[wjri",
        "lNYfo",
        "DS_DeleteFromSystem32",
        "oHhl,bjn",
        "SdS:A",
        "Jwv.*",
        "9<6:X]0",
        "O8_^[",
        "dUC='",
        "{nvy.5z",
        ",WS5a",
        "value=",
        "< =@=d=",
        "0p1z1",
        "#9cj=",
        "Flf+Fp",
        "-TB`:",
        "d$i}k",
        "-\\?Sv<",
        "(ZI;D",
        "setct-PInitResData",
        "L$LQP",
        "38rK&",
        "Pk[k;kG",
        ":r:x:",
        "FC6j~",
        "5lQ8.)U",
        "N7?KV",
        "A.WhD",
        "\"yVA7",
        "YA&i6",
        "-Q!t>~",
        "2N8nR52",
        "`h~(T",
        "/:*C\\",
        "'_Wj(k",
        ":rWUn",
        "I$naP",
        "#%:EWq",
        "A\"#zNi$",
        "ZL3J0",
        "s8%?wE",
        "><>D>P>p>x>",
        "mm.{</",
        "*jbjC",
        "=FWaBe",
        "encoding error",
        "F8,4p",
        "=,=<=D=L=T=\\=d=|=",
        ">T>Z>n>t>y>",
        "\\zN#?",
        "B8#wM8",
        "G42Tuc",
        "$Za%~P",
        "c'KG'4",
        "d,dUY",
        ".\\|8y",
        "7C_w^",
        "BU:v=",
        "!5br:`",
        "F=Hu`",
        "m?Wcd>H~",
        "qCF+Z[",
        "]7<Mqa",
        "EnZ.u",
        ">+qs_",
        "bases.50F05011_FC3E_4209_A92A_9D8DF4E71D10",
        "kHm#$",
        "jdjlj\"",
        "]_^[3",
        "w=._&",
        "D$4PV",
        "dZ.*y",
        "999>9",
        "wJPU3E-/j",
        "ny6?35",
        "TS_CHECK_STATUS_INFO",
        "\\f1\\fs20\\insrsid7438025\\charrsid15169477 the Faulty unit is}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  return}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7438025\\charrsid15169477 ed to Check Point}{\\rtlch\\fcs1 ",
        "NmZ[&",
        "vz$9N",
        "XBKSEJhG",
        "Kn\">/",
        ",]&XI",
        "H94I^2",
        "}p`l)",
        "Jy6V ",
        "~GXm$",
        "K^yT|(",
        "CJ*]XnunHzMa1%Ui\"Y",
        "7G>3L",
        "\" zm}",
        "protocolInformation",
        "ne584",
        "X$5@do",
        "y|y=B6/C",
        "$Mw'i^`",
        "GdT@h",
        "e\"=yk20",
        "DW[sl9u",
        "_hklp%",
        "Chain 0 built with %d certificates.",
        "2AqA$m",
        "[Ny9\"",
        "?61F3",
        "EQ~Bc,",
        "r! |t",
        "CMS_SIGNED_DATA_INIT",
        "~\"4Wx",
        "2 #[e`m2",
        ";+=h=",
        "L$8^][3",
        "R^nKzpe4",
        "O%z/ ",
        "7;\"^D",
        "2[I@T",
        "I=){l",
        "{f{j{n{vz",
        "Successfully restored registry key.",
        "V&E>rQa",
        "*Ff$A",
        "%M=\"N6",
        "%UYA ",
        "WGv G",
        "=X=]=e=I>z>",
        "94989X9t9x9",
        "8?69:2~",
        "CK-UNKNOWN",
        "InstRes",
        "q:KGe",
        "(\"\"++***",
        "mPK<hZ8",
        "j5uh^",
        "?!?(?F?f?}?",
        "Folder '%ls' already exists in the CreateFolder table; the above error is harmless",
        "&xOAL",
        "Am0LS",
        "7#8K8",
        "0-nX0",
        "ms-bn",
        "\\qR$J",
        "QX=;V",
        "{G isGM",
        "2!212Q2q2",
        "y-'CT",
        "J1Y:j6",
        "7)Z.6b",
        "G] }=",
        "+GTAx",
        "E{TGF",
        "Uy*m_",
        "/=8[r",
        "/|L|j",
        "nwqYp",
        "x%C<\"",
        "(upgrade) try to read from registry",
        "YBXq#>m",
        "IHiC%1",
        "8B8e8j8",
        "?+rLUj",
        "jqn7##",
        "*#@u$nUY",
        "TQuLH",
        "4\\`8,XZ",
        "&anht",
        "jvjej",
        "b5_0b",
        "A:W|d",
        "6$6,6`6p6",
        "+J(I*",
        "]xA{Y",
        "5-(-t",
        "$p'o*R-",
        "(u{@3",
        "3H4E)2",
        "bJ[7ZV",
        "~6'/G",
        "8]'xh",
        "*s\\Xr",
        "&KB8`)E",
        "W@U22j",
        "VVA+Ek|+",
        "j3os4`",
        "QEtqJ",
        "mS`<\"3",
        "jjjjj",
        "}^b](",
        "B6nM)u",
        "&z_M;",
        "U~Uq>",
        ")5gw,t",
        "Failed to compute MD5 for %s ",
        "JLveb2",
        "x-jTt",
        "^_P6S",
        "GetDateFormatEx",
        "Br4Cq",
        "es-CL",
        "Q6%`ic",
        ";|iBw",
        "adtDR",
        "ras{v",
        "ytMo\"",
        "n{CW6G",
        "M*y K",
        "f;oL=",
        "8P^\\d",
        "autoexec.bat",
        "_/X4(",
        "ZaK\\i",
        "> g&e",
        "jMG\\^",
        ",T2pM9",
        "muv8ai6+",
        "V<hQwP",
        "L$ QP",
        "aR_q s ",
        "FSR-p",
        "B*aj9",
        "E{0 5d0",
        "Fv*nL",
        ">3a |",
        "Ld8kb",
        "y=J)?",
        "$%ZY0z\"",
        "+m|Hz",
        "'Mqoz",
        "RY}rn",
        "[VSUninstallProduct_silent]",
        "KJv\"I",
        "0,040@0`0l0",
        "n|<~(",
        "illegal bitstring format",
        "H5H}Mx",
        ",MI5\"V",
        "r5eJ5",
        "91E.T(",
        "Umw\\]",
        "f{-!6`",
        "Pd_,^",
        "ADH-AES128-GCM-SHA256",
        "Zxjqwh",
        "v]Gu$G",
        "V_W_X_",
        "YTT(m",
        "K6]t.D",
        "OnRemoveAfter",
        "A5695010-94A4-4491-B3E2-C4F55E8E3056",
        "li;%I%",
        "type not encrypted data",
        "Counters",
        "-V[S`-",
        "%s\\Common\\*.cppol",
        "8'8-8\\8",
        "?Rk)d",
        "9/9?9",
        ".[cB]N,9B.",
        "2\"2,2G2g2l2w2{2",
        "qB6_l",
        "3k3x3",
        "\"+}&6",
        "MJ.yR>0",
        "J=FyD",
        ">$al^d",
        "i*iJi",
        "4,444L4T4l4t4",
        "zXhS=u",
        "J~m1$",
        "%MJPY",
        "pydb~[IY_#",
        "O uW$",
        ">~h3|e",
        "Bg<!{",
        "\\{(~d=W",
        "IldF36",
        "LZvp4B",
        "B5_]$",
        "The current status of the service %s is %d",
        "[Q[%qd",
        "d70y2",
        "GetTraceEnableFlags",
        "Nj`xem-",
        "]R.>F",
        "Proxy CONNECT connection closed",
        "@\\oV\")",
        "umcSi",
        "$hQ5,",
        "VMMCALL",
        "VeI0k",
        "p52l9",
        "w%f>%|",
        "575?5F5M5T5[5b5l5w5",
        "3(303<3\\3d3p3",
        "detect64Bit",
        "K.S@/",
        "('9'o",
        "YwP\\@",
        ".R!FC",
        "FY;w(|",
        "<}:x@",
        "\\XwoN",
        ")KSbyD",
        "FH9X,t",
        "NOTICE install date overriden.  New date: %d for license %s",
        "/h/H4",
        "s jqh",
        "qiF=d",
        "CANT_OPEN_INIT_EVENT",
        ">uGme",
        "D$hPV",
        ".6_8_",
        ".:E;c",
        "WZ;gP&0}",
        "R}@yX;",
        "St.PVP",
        "lOuRAimQ",
        "OnInstallUIBegin",
        "XHvGX\\",
        "\\fD~ ",
        ".\\crypto\\ecdh\\ech_lib.c",
        "Adding %s products for uninstall",
        "^|DQO",
        "5P9pe4",
        "%&K&'",
        "y]hI_",
        "7&C4nT",
        "s3-g[",
        "D$4j}hP+(",
        "CONF_dump_fp",
        ": IUt",
        "_k^`U",
        "^@/C`o",
        "aPk<@",
        "304J4e4",
        "t}hDwL",
        ".?AVScheduler@Concurrency@@",
        "jI'1c",
        "t;stw",
        "0S9SI",
        "5dn/C",
        "`)xHn",
        "(0<`2A",
        "<>g=h{",
        " failed to set EnableLMHOSTS value (%d)",
        "hpJR]",
        "Ml43K5",
        "SleepConditionVariableSRW",
        ">8HO}",
        "V+l%:",
        "wy2Ro",
        "9%`a+",
        "F=MW[\"j",
        "fy\\O!",
        "c.!Fp",
        "\\5wg0",
        "Configuring SecureClient VPN settings (1 of 5 tasks done)",
        "&[=jHE",
        "{tDK2GxiBF>OP",
        ",WPVS",
        "a:c|9#ymt",
        "$joQn",
        "t(.'#",
        "=\"Fwo",
        "q_5w*;",
        "8A*H2q",
        "vS,K4",
        "dbyPn",
        "QY`\\q+H:",
        "FlushConsoleInputBuffer",
        "b6SDrfdQ",
        "PKEY_EC_SIGN",
        ";,<7<^<u<",
        "1 1(181H1l1t1|1",
        "mjOAf",
        "REBOOT",
        "Iq][:",
        "bT@(l",
        "Could not set MaxNumFilters",
        "d3!@c",
        "|Vu1G",
        "X-sEV",
        "sBsjs",
        ",C\\1KI",
        "ETE]CDC",
        "select/poll on SSL socket, errno: %d",
        "VxYje",
        "Fad,T",
        ".\\crypto\\dsa\\dsa_lib.c",
        "zS.(w",
        "OriginalFilename",
        "subject",
        "SetFWStartup:  SetFWStartup started.",
        "cm$H#j",
        "$8Ekh",
        "&/Qq\\1A",
        "/~}Pt",
        "gJ#Ms",
        "MsiDirectory: ERROR_INVALID_PARAMETER %s=%s",
        "Z.ykT*",
        "<(<9<?<V<b<",
        "`vector vbase copy constructor iterator'",
        "97v&9",
        "Jn07!",
        "tY?Q@",
        "*qp$]Yj",
        "~51c&5",
        "(!ClL/",
        "5y%~Z",
        ")(qo^",
        "Skipping %s installation. The file is missing",
        "No FW component was installed - continue installation...",
        "\"\\8J\\~",
        "%'1pr#Dp",
        "pilotOrganization",
        "r{}<F",
        "e'sW[^",
        "Can not read MailFrontier InstallPath",
        "failed to add installation dir to PATH LoadLib will fail.",
        "Tu%H8",
        ":$:,:8:X:`:l:",
        "(-pB ",
        "$9r{p",
        "6ogog+",
        "ZYZ+f",
        "token not present",
        "E#-44",
        "[0\\p\\",
        "B(|29",
        "failed to get target path of object '%ls'",
        "uTloA",
        "OD)N^z",
        "unstructuredName",
        "p.3`>",
        "C1A5G~F",
        "gZC}(",
        "T,_Ro",
        "E$SVWf",
        "OYC.@",
        "tsize parsed from OACK",
        "Plugins::UnregisterAM:  Unregistration failed.",
        "Q30,8",
        ")qP'3Sa",
        "YLYhD.",
        "GOST R 34.10-94",
        "=5CX+",
        "nwMiG",
        "uOFN}",
        "i2d_ECPKParameters",
        "1-1J1b1",
        " _qMt",
        "(=Q$1",
        "oG}\"!",
        ".Um#ajjH",
        "X\\'$k",
        "b'gd_t",
        "~n96f",
        "(\")b)",
        "5za})",
        "f9cTe",
        "%-<w[",
        "Yez>j",
        "RETrP",
        ",n:Lh",
        "J J,J8KD",
        "a3KbsV",
        "WF3q&gO",
        "/j54}<y]",
        "(y1s`'",
        "4:C-M|",
        "-~Mj8",
        ">l=t=",
        "(t{,^",
        "\"P74W",
        "9(9H9h9",
        "S>&t9",
        "QBm 9",
        "x;?=^",
        "nJ/Re",
        "fO~3>D1",
        "s>d8B",
        "/-mXu",
        "?RoInZ",
        "= =;=A=Y=_=o=u=",
        "Y{]hr",
        ":B;j;",
        "Constructor done.",
        "jEjUjej",
        "Failed to allocate file search string in path: %S",
        "PACKAGE_TYPE",
        "{|yQ\\4",
        "N\"e|O",
        "v<neYc",
        "07ow5",
        "gEW/D",
        "ZwQueryInformationThread",
        "F^D5PU",
        "SZCmX-V{",
        "Data conn was not available immediately",
        "?JJOO",
        "9qMO}H",
        ">E?x?",
        "=%>F>W>f>",
        "collect.bat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "zjG\"[",
        ",g,=7",
        "u.hD$$",
        ".\\crypto\\lhash\\lhash.c",
        "O;:(W",
        "Qzn `",
        "30B[_|",
        "}'m0UV",
        "o[.Hh\"",
        "lREEwr",
        "'tw5M&",
        "T\\yi4v0]t",
        "FhAqtT",
        "E8 Fn",
        "d\"<+j|I",
        "_updateArrStatusInt@16",
        "=:=@=F=L=R=X=",
        "q]V'K",
        "=qK~1",
        "vH>!V",
        "ng7TN",
        "vsutil",
        "unable to verify the first certificate",
        "Z3z4WY",
        "o8mr`",
        "MtPE>A",
        "f#r=v",
        "71<5SR",
        "Kaspersky Anti-Virus for Windows Workstations",
        "mn&-yF",
        "$[&2e",
        "GzM,E",
        "?.?J?f?",
        "q.g_Z",
        "]JYZ*",
        "Jk#\">o=m",
        "FISTP",
        "Z(\\ &",
        "38n\">",
        "'hmkE",
        "Xf5Ca",
        "PSVhPOM",
        "b5%aw",
        "\"z?cP",
        "ZV3H%",
        "G<(XU",
        "(M]\"Aq]",
        "n}2#,",
        "AUTH %s %s",
        "8R9W9m9",
        "iAi[}m~",
        "P2wKV",
        ".\\crypto\\evp\\bio_b64.c",
        ")/Fhw",
        "XW$:^",
        ".\\crypto\\asn1\\tasn_utl.c",
        "*6>*&v%%",
        "w_T*[",
        "/)[N{Sb",
        "WKuWW",
        "XU.BE",
        "tv)kP",
        "Ou*<_",
        "MqB,ZpN",
        "lfL7Mzd",
        "1Xi0|",
        "g<8;B",
        "$+ FC ",
        "hmac-md5",
        "8!849",
        "M4Nsy+E&",
        "j\\[f;",
        "6H1Bxb",
        "&lu3xr*",
        "msgsigdigest verification failure",
        "expecting an object",
        " b$pr=",
        "xWq11",
        "IQTYK `",
        "%b %d %H : %M : %S %Y",
        "unProtectEPAM;",
        "I|8Q*3",
        "Fs]SK",
        "0`|!M",
        "6%;MX",
        "e&AUZ",
        "7IpB.",
        "non sslv2 initial packet",
        "xe#Oxm",
        "009pRL",
        "#H2wR",
        "c,L|6",
        "StartService failed: %d.",
        "encryption not supported for this key type",
        "9)9K9]9",
        "y(=-QH;",
        "mac generation error",
        "illegal null",
        "KyF^h",
        "`sn*!",
        "i;6WJj",
        "9W&R5",
        "<*<@<f<",
        "RuhVh",
        "@6t@(",
        "-:;wx",
        "@EKbm",
        "BI.3HLR32",
        "j3/6S",
        "wlmZnop",
        " 0x33",
        "0#0)0F0K0W0a0m0y0",
        "value.sdsicert",
        "1 1(1P1X1`1t1|1",
        "K^nUA&",
        "=X\\y%",
        "OIB):",
        "8Oqg,",
        "Xxna.",
        "oa(P.&lA&P",
        "W^t}g",
        "N3v]9",
        "F|;|$",
        "tT3F8",
        "9Ssn^",
        "DnwJx-",
        "B)E\\+\\",
        "1W;n2",
        "eVmd|",
        "pThreadProxy",
        "@Jy5M",
        "^NUkH",
        "EMeCVAnoZ",
        "(i3I]C",
        "no cipher",
        ",?DRV",
        "343<3H3h3p3x3",
        "WybWX",
        "Hr\"BJ\"",
        "4?\"^G",
        "q( 38",
        "4O>,Y$",
        "j|jwj",
        "t#SQU",
        "w^Sl \"",
        "iF8JN;[",
        "*oG?@",
        "DES-CBC3-SHA",
        "i0i'9",
        "252~2",
        "jB~i\"",
        "5I}3dnF",
        "LCI|Oe",
        "aE%d0",
        "Q&6Z<68C",
        "j&}P>",
        "m!NsNm",
        "=]%0_",
        "ASN1_d2i_fp",
        "mvJBj",
        "Microsoft Enhanced Cryptographic Provider v1.0",
        "4>KNdI",
        "eqg20",
        "D4H]|",
        "wGdI74",
        "DfEV.",
        "DHparams_print_fp",
        "c\\xCTr",
        "05!<|s4",
        "n~Yd;}",
        ";;|/g",
        "r-NMo",
        "kypw6",
        "7LnZPQ@",
        "8s8O9",
        "Cn8HH",
        "6-7V7j7",
        "m$536",
        "p\"bY4",
        "^Q#h(zh",
        "2$&tW",
        "=n@u+",
        "7FJKw",
        "]`{\"b",
        "Failed to get the RestartResource field value.",
        "'%M+,",
        "<rNih",
        "wuDm<",
        "t jnhh",
        "#z|vTB",
        "283\\3d3",
        "\\vV=+",
        "U]k+ei",
        "f\\)#A",
        "LRJCs0Z",
        "-i*Eq",
        "7 9W9",
        "mN}]k\\",
        "iO|Qe{",
        "BTLy2",
        "|MYYj",
        "EC_KEY_check_key",
        "\"NuQ}\\",
        "^9!>.",
        "!uA`x",
        "ZXl2p3w",
        "7h4 Z2",
        "nN(Edh",
        "%*sZone: %s, User: ",
        "%RP\\*>",
        "7G8W8n8s8}8",
        "IV\"[w)",
        "xo}}Y",
        "hT,L9 ",
        "dSAXM",
        "UmA+s|<",
        "1tf\" ",
        "krZK7",
        ".\\crypto\\x509\\x509name.c",
        "w1V+%",
        "'O&/!",
        "+Lb_(",
        "=i#pa",
        "x[{Q`",
        "8SZox",
        "u8jTh",
        "A4Z*:",
        "231209235959Z0",
        "ky,-DY",
        "<K=^=i=",
        "(8L8x8",
        "=&y&e",
        "55$E#",
        "11rz1",
        "fe 4~",
        "`&aUH",
        "e>F9-",
        "<rules>",
        ";` aR#+",
        "sX='Ay7",
        "5#5H5",
        "NjIYy",
        "!`|^P",
        "%v\"#D",
        "*TVdVtVxE",
        "Ty|v5",
        "y?z4s/O4S",
        "[A^yf",
        "^.Nj[",
        "k{7@:U",
        "{N<0U",
        "|$(SP",
        "a!:blA",
        "6,6l6",
        "Wd8\"(",
        "6YPuW",
        "EPWD.exe\" install",
        "|kxg78]O",
        "R2k=q4a",
        "bPWPjX",
        "G[SG;",
        "y4-gk",
        "l$XUh",
        "[xahk",
        "QQ_wH",
        "u-=nMLs",
        "|g_@[",
        ">mmm)",
        "_JQ$7g",
        "{X68vD#",
        "?C\"Q3",
        ":r8A`",
        "Sm\\wf\"",
        "nrTb0U",
        "excludedSubtrees",
        "&1<1G1",
        "%d.%d.%d",
        "u_]*.",
        "Uo@rb",
        "!AU4<:u",
        "S(eJSO",
        "!oB>7Z",
        ".*aMq",
        "405Q5s5",
        "yeL-wa",
        "VhJmS",
        "\\s28\\ql \\fi-360\\li360\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin360\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext28 \\styrsid13065977 List;}{",
        "UyNE<o",
        "r43nV",
        "1Yr]3",
        "VC6uK",
        "U!Y00",
        "cvQy2",
        "eYXn@",
        "+m<6w$z",
        "D$ UPV",
        "!7NJ]",
        "nC(I>v",
        ":P^GqEs#",
        "YOu<O",
        ".?AU?$error_info_injector@Vjson_parser_error@json_parser@property_tree@boost@@@exception_detail@boost@@",
        "2-2f2",
        "vP&%i",
        ")VqS*c0",
        "5G4rP",
        "m~yEX2",
        "K86Bj",
        "expecting a dh key",
        "%x2>-t",
        "8\"919@9O9^9m9|9",
        "S7gX*",
        "0I8qn",
        "rfPH+",
        ">4?X?",
        "789C9J9P9_9j9p9v9",
        "P|=&M",
        "@eFPT3D",
        "5`5|5",
        "7$7,747<7@7H7P7X7`7h7p7x7",
        "6QxSx",
        "1F!(*8T",
        "!5q3z_^w",
        "6a{$M",
        "1P1@2G2",
        "%K_fw",
        "KS_{2",
        "w57!-",
        "FqDyNBP",
        "NY/JBb",
        "to,)S",
        ",^&()",
        "xFb+0I",
        "0S^E9",
        "0Ou;)+",
        "Table Grid;}{\\*\\cs44 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\sbasedon10 \\spriority0 \\styrsid6889473 hl;}{\\s45\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 ",
        "565Y5x5",
        "4@5%6",
        "htOPB",
        "D{B=a",
        "?(?0?8?L?T?h?p?x?",
        "R_S9(",
        "{~C*n",
        "S\\_ot",
        "4(St?y",
        "q1Sx5'",
        "%&!#P",
        "__vectorcall",
        "Dny_H!",
        "T~W[5",
        "<0<d+M",
        "Xg =|",
        "7O8d8",
        "X&;w?",
        "D$0PW",
        "tXw;d",
        "7(7H7h7",
        "|_/sE",
        "}0?w(",
        "Si1p6Y$",
        "3O<_<",
        "`/Axu",
        "9+939L9W9",
        "L:2lF",
        "EJdS-",
        "q`?*.",
        "9MvMSM_Kk",
        "1 1(1<1D1X1`1t1|1",
        "3.nf1",
        "M8G@'",
        "{flat}",
        "~'Xirf",
        "i?2Xk",
        "IcGU%",
        "T-8p6",
        "0p'f,x",
        " 0x89",
        "5,6@6G6w6",
        "e H8.9",
        ",<ellipsis>",
        "0r>Y*!",
        "\\yH:(",
        "c6Edb",
        "RqVZQh6",
        "5 5$5(5,5054585<5@5D5H5L5P5T5X5\\5`5K7Q7",
        "=4?g?",
        "z^$6b<",
        "9hm~cB$o",
        "EC_ASN1_GROUP2FIELDID",
        "=YsRD",
        "363G3M3Y3g3m3|3",
        "<n\\\\]",
        "}(-<kV",
        "CRolloverMgr::ClearLog():  unable to open log file",
        "\"P49w",
        "D$@3D$0",
        "*RCJN",
        "8lt*H",
        ";!\"5rM",
        "(JLJl",
        "{hkOl",
        "[hB.2",
        "H&&<C",
        "~^utIB",
        "|(Z/V@K",
        ";<;H;h;t;",
        "b`v<$",
        "mRf~5",
        "=6x-(",
        "Wa@SR",
        "Connected for receive",
        "'S/yJ",
        "*y`+)xc",
        "ct)9j",
        "+2abC;",
        "appdata",
        "6=ye\"K",
        ",R\"la",
        "uninstall password was not provided.",
        "c<oqZs#C",
        "M,0dB",
        "n/ZE<",
        "Failed to get windows path.",
        "[INSTALLER] MSICreateLocalCatalogXmlForUpdatingComponent(\"%s, %s, %s\") - begin",
        "t$,VW",
        "X7x;)UT",
        "UwLq?",
        "sqQ.n",
        "Ww7JI]",
        "_bvhl",
        "sFht<qpO",
        "3]$Q)",
        "qhI~%",
        "HO@>;",
        "[VSUninstallProduct] unable to shut down vsmon (2)",
        "bCFZ>Dh",
        "-q*.p",
        "}b]1{(",
        ">=fnC",
        "}S1{v",
        "P=KlO",
        "W%v$0",
        "#6Q5tt",
        ":XR^v",
        "RSA_PSS_TO_CTX",
        "UUUUUUPU",
        "[pIs@lNBWC",
        ">K K$,",
        ")kEu-NM]M",
        "^n<)CM",
        "miZ8Iq",
        "h#nkO",
        "vsmon is not running.",
        "515A5a5q5",
        "+om_YJ",
        "vB5;-+",
        "b^8zZ",
        "n![o!o",
        "TDV-c^",
        "+ojr\\`",
        "0&1+111:1@1K1R1[1m1u1",
        "33V4fg",
        "UhtB!",
        "int_field1",
        ":Hy>5|#Q",
        "H>J&0",
        "set-brand-MasterCard",
        "D7bJ*a",
        "rgOPj",
        "\\W4Fa",
        "*0W/^$",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\SecuRemote_UnInstall",
        "9VU)z-x",
        "D@JEy",
        "\\q;A+",
        "D$KQP",
        " 6'lv",
        "k_8)K",
        "<`~l>",
        "no certificates in chain",
        "0C1I1b1",
        "~'PSj",
        "@.xxO",
        "xpNcsJ'",
        "MIt\\!",
        "lZ(GD",
        "w2l78]`",
        "%s: (%d bit)",
        "string_to_hex",
        "wR*/(&",
        "7\\Gx?",
        "X=P.<L",
        "5V7QU",
        "(_yg!}",
        ":$Ed$2F",
        "6b4we1",
        "P(A+`",
        "#p2WR",
        "r^oet",
        ",`:$&.",
        "7%db2",
        "'|M}x",
        "Gs&v4",
        "nho1m",
        "+ Qtz",
        "N`X(N",
        "PKCS7_ctrl",
        "Q-FsQC",
        "YF\"k*z",
        "5>5mo",
        "d.t\"?^",
        "=A>a>q>`?",
        "(.Gh!",
        "E1z+\\",
        "586p7",
        "Myl/l",
        "Custom action:  StopInstHelper:  started",
        "setct-AuthResTBSX",
        "]&A9H",
        "CONF_def part of OpenSSL 1.0.2h  3 May 2016",
        "K,B]QuZ",
        "_I9}L",
        "G(]pZu",
        "L$D3L$43L$,3L$ ",
        "F\\!J{",
        "2(2w2",
        "9y1zT",
        "LN*iu",
        "i|3{f",
        "S]s*;+",
        "@vhjq",
        "cD;|+F(",
        "G%I^}C",
        "Ys$Z1",
        "dWm+a",
        "c/y$Y",
        "t\\9D$",
        "AdN,?",
        "[0Hs51",
        "(QO\">T",
        "vtwq;mv ",
        ".\"%R(",
        "{<89X",
        "QN|<+",
        "vY6kN",
        "tDFLz",
        "H$$Im",
        "RMI_Y",
        "KP\\4 r[",
        "SRP-RSA-AES-128-CBC-SHA",
        "Failed to turn off protection.",
        "aes key setup failed",
        "7(8Y8",
        "qze/S",
        "CBT;m'",
        "s|ReHu",
        "]=WI,",
        "\\sG7tPD",
        "}BCFO",
        "pX9CLH",
        "s.:R\\",
        "%o\\l#",
        "n,']>",
        "QqARjE",
        "psGt0",
        "wb/,(",
        "ReplaceOrAddTagIntoVSConfigZL(%08x)",
        ",O($G",
        "f51C4",
        "_(y'G",
        "LRdzs",
        "D$<_^]",
        "SA?.*",
        "BN_rshift",
        "Z)T*O",
        "GBL@5xPZ&!",
        "t+WSP",
        " verified",
        "! wt4HSRGPDQEFJKIrlo],^-_+.he`ab",
        "8~AyG",
        "\\*gaS",
        "&https://www.globalsign.com/repository/0",
        "7v7z7|7",
        "^So,NV",
        "=mOij",
        "Server doesn't support multi-use yet, wait",
        "Ea_=(",
        "D#9@s3",
        "xCAca",
        "rsa operations not supported",
        "]C^+K",
        ">$4Nk",
        "BS?9[",
        "Invalid SSPI encryption response length (%lu).",
        "2,3034383<3@3D3H3L3P3T3X3\\3`3d3h3l3p3t3x3|3",
        "'-/B/NR",
        "g@5yE",
        "[LICENSING] Removed Read Only Attribute. Set License file attributes to %#x",
        "L9xi,",
        "_`x QT",
        "3|rph",
        "k1R~M",
        "rDJ}C",
        "9J#_C",
        "]d6%_A$",
        "FoAoR",
        "dn:qMU",
        "=<6HRet",
        "1SG6m",
        "L Pn_",
        "A1$=::9100",
        "Phlm#",
        "CB7E*<",
        "a.OAt_;n,x",
        "S~W| ",
        "WfuUL_",
        "0o3sP",
        "Secure Client is installed on machine.",
        "949@9H9`9h9p9x9",
        "kg4bt~",
        "ubr.A",
        "E=%Zym&",
        "zrux%i^&",
        ">Ng*w,J",
        "w#~4L",
        "x`kLr",
        "L$ IP",
        ",Gr`+>",
        "failed to initialize WixSchedInternetShortcuts.",
        "}Ihwi",
        "PBH1R",
        "001S1",
        "LoadLibraryA",
        "@3CEOT",
        "char ",
        "D==wI",
        "G>i8s{4",
        "A'{P'",
        "6!6'6-63696A6W6h6{6",
        "9Jt-W",
        "707L7P7X7`7h7l7t7",
        "{LY+-t",
        "fopen",
        "SE\"e9",
        "khK=X",
        "7P8T8X8\\8`8d8p=",
        "2\\6Hz~",
        "-E)!:",
        "qL*z ",
        ",0HTG",
        "Hz9ue",
        "X[CFU",
        "|dS9J",
        "\"B]W1",
        "=6\\93",
        "F?wTL;",
        "I=\\zd",
        "OU_Xa",
        "&`Pqy?",
        "W~7~q",
        "\\G|r~",
        "4^h+e",
        "section=",
        ":j/p_f",
        "EVP_CIPHER_CTX_set_key_length",
        "f:)m6",
        "HsokL",
        "XEj9/[&",
        "7>8r8",
        "ENGINE_TABLE_REGISTER",
        "$=eglYD",
        "3@4^4",
        "t9C7t",
        "p,[P1",
        "D.j5O",
        "wyI>8$V",
        "E%zJvID",
        "#0M=J",
        "gB-?FM",
        ";\"2:*",
        "7dX,,x",
        "certificate extensions",
        "a null shared library handle was used",
        "PRODUCT, license or SERVICE AND DISCLAIMS ALL Statutory or IMPLIED WARRANTIES, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, or arising from a course of dealing or usage of trade and any WARRANTIES OF NONINF",
        "|BL2o",
        "l|pBG",
        "O$wSKV",
        "|a`&f",
        "<&<D<R<f<z<",
        "4SmN,",
        "M%Ix4",
        "K@~h[",
        "e`tT$.",
        "E\\+D]",
        "T5^D)",
        ".?AV?$ctype@D@std@@",
        "<a^][",
        "eNINRO",
        "cmd /c \"del /F /Q \"%s\\Start Menu\\Programs\\Check Point\\Check Point Endpoint Security.lnk\"\"",
        "Ru=^##v",
        "X,F/3",
        "9OHtph",
        "o7R8q8",
        "'nonm%",
        "4ZHXnP",
        " \\LUv",
        "o>y]8",
        "pkcs7-signedAndEnvelopedData",
        "es-UY",
        "asC,5",
        "_HJ%~",
        "i;'>XA$4",
        "norwegian-nynorsk",
        "SETUP",
        "BN_GF2m_mod_sqr",
        "[d9=H@",
        "j3s2Zq",
        "'cVHF./",
        "Gxwv4",
        "616~7",
        "q|7s=",
        "Ct|_w",
        "cD[Tjl",
        "X509v3 Authority Key Identifier",
        "CustActionLib",
        "6x_:pe",
        "winevt\\Logs\\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx",
        "=*yWW",
        "7ba|Z",
        "[XJ+S",
        "Ik$t%N",
        "telnet",
        "l:GAT",
        "szDeletePath",
        "glEHv;",
        "3??fj",
        "<P,($",
        "pem name bad prefix",
        "SrP\"H",
        " %e/6",
        "?4?@?`?l?",
        "g6+oY3}",
        "S$pd0",
        "aD$x\"6",
        "Failed to add service name to Rollback Log",
        "Klb'PQ`",
        "8%969G9b9",
        "Q9rsf",
        "Ctd5U",
        "eCL.g",
        "9%/-9",
        "|,[J1M",
        "E<-tv",
        ":%mjr7",
        "xRzuy|",
        "aN=RX{",
        "CMS_KeyAgreeRecipientIdentifier",
        "H9z!~)",
        "bafajanasc",
        "B#]^T",
        "o@`I1",
        "@P{yn, ",
        "PTYPE",
        "<!=1=9=I=w=",
        "U\"cPpJN",
        "6~'[K",
        "y!'v<",
        "RegCreateKeyExW",
        "ENGINE_up_ref",
        "CANT_LAUNCH_CHECKPOINT_INT",
        "5Y~0p9X",
        "9>9F9|9",
        "*1*a'",
        ":::e:",
        "6X,Kr",
        "1N,CZL-",
        "not dek info",
        "qJ!RZJ",
        "9p:)<4<7=",
        "Rsno|",
        "ka-GE",
        "LH3Y;",
        "8*xf-",
        "3:4_4o4",
        ":IGO?r",
        "&P( v",
        "8$8,848<8H8h8t8",
        "7/8N8",
        ".-s%_}",
        "~ii]1",
        "55\\P,5",
        "6kE>bo",
        "4:wo9",
        "LeaveCriticalSection",
        " 0x4b",
        "4K^>^",
        "Q:   ",
        ":M'j;",
        "-a_o/v!",
        "8w9}9",
        "P6j/L",
        "4]4F'H",
        "Failed to copy 'reboot' into action type.",
        "&jR(M",
        "?n@rwS",
        "@)I{m",
        "Bx=*s",
        ";\";0;3<$=?=_=",
        "44-45-53-54-42-00",
        "<7usL;",
        "\"2i}yu",
        "tugK>2",
        "\\FJBdp",
        "R:3vh",
        "NvAvU",
        "&E5Ki",
        "IkzkE",
        "SSLEAY_RAND_BYTES",
        "u hTX!",
        ".QS^b>",
        ";ez,S",
        "l(t'p",
        "8)91999A9I9Q9Y9a9i9q9y9",
        ">PO5R",
        " %P8D",
        "Cd*v,&",
        "pM>'k",
        "zJQhJ>K",
        "Zi}UL",
        "S/{@nb#",
        "7 70757:7J7O7T7d7i7n7~7",
        "V5=';",
        ".kr;I",
        "2'2B2]2x2",
        "#wP\\NH",
        "B}x62",
        "Cisco is installed, vsdatant.sys will not be deleted",
        "pMnr ",
        "fwVd?",
        "\\{\\BT",
        "}E<ks",
        "\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2;\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3;\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List;\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading;",
        "AC}o8",
        "error",
        "x5NI,9",
        "}^J.~",
        "camellia-128-ofb",
        "QUOT string not accepted: %s",
        "1#1?1[1w1",
        "4c3Xk",
        "!wq;!Z",
        "s$Hz_q",
        "Vcn7..",
        "/6wN\"",
        "D$@hhU\"",
        "gRK?Z",
        "%I'KK",
        "BrowserMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Q&Xx~",
        "IJk$<Jh",
        "I2V_AUTHORITY_INFO_ACCESS",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\installdriver.cpp",
        "N$)7c",
        "YB>8%",
        ">^Bjq",
        ":=Vr,",
        "`%f%n% ",
        "$>'i;/",
        "KP&4P",
        ">}j6\"",
        ".^}m5",
        "E[CjhmrZ",
        "KGT;x}+i",
        "!,Ka>",
        ":-:4:J:Q:z:",
        "3om6*&H",
        "TracSrvWrapper",
        "B,Z7(",
        "4+5L5\\5+6L6T6s6z6",
        "Y\"v5DY",
        ":?>t`&]",
        "PATCH",
        "isOvc",
        "vw53v",
        "0b1u1",
        "0dNfFr",
        "SEED-SHA",
        "6F7U7",
        "f2\"`Jz",
        "unknown order",
        "LL$ 3",
        "Jmfy=",
        "EqEs\"",
        ",a*R56B",
        "6]h\" ",
        "CaQ_O",
        "g$)1B6",
        ",[>w`",
        ".4.T.th",
        "_K bT",
        "1D4oJ",
        "PKCS7_add_signature",
        "]w]sk",
        "OL@1Uj",
        "VnaClean",
        "}z}~zu}",
        "dyaM0",
        "R^LO0",
        "rr}|w",
        "&xTzn",
        "vMCONdO",
        "r+\":<",
        "$HZ!|",
        "aZT|Q",
        "8*A'jB&13",
        "@l2OK",
        "URLFextractUCP",
        "CPUID",
        "7fOA ",
        "3\\4{4",
        "t$4QUR",
        "u6Ff;t$ ",
        "7Eey|",
        "INVALID_DISPOSITION",
        ":Wt^un",
        "L$x3L$D",
        "0A.p@d",
        "<8=B=G=L=",
        "jj@6ww",
        ":,BL4",
        "-+Ux*",
        "Yiht:",
        "cL\";CiM",
        "=t[yQ",
        "7vY5@3R",
        "Mj--Y",
        "EWf)-}A",
        "id-regInfo-utf8Pairs",
        "?jL`O",
        "SCUIAPI.dll.upgrade",
        "IF6KnfP",
        "NZ~.!x",
        "s1 ]|",
        "7=\"^%",
        "d^mjK",
        "=E>J>O>T>o>",
        "q/W0*",
        ";-;P;s;",
        "cba|9VM",
        "boost::filesystem::path codecvt to string",
        "R.%X=",
        "7I(y&",
        "\\0.F;",
        "#bML\"",
        "O-VcH%e",
        "Qi_b,6",
        "I5GY)a",
        ")6t^aEh",
        ">2~fx",
        "SYSTEM\\CurrentControlSet\\services\\vsdatant\\Parameters",
        "9+9g9",
        "0y\\9kN",
        "Refusing to issue an RTSP SETUP without a Transport: header.",
        "*HB-;{",
        "D$(PWhho%",
        ".>ujN",
        "765u\\mn/0213",
        ",9)Wg",
        "fQg9=",
        "3 3&3+31373=3B3H3N3T3Y3_3e3k3p3v3|3",
        "@&!0d",
        "Failed EPSV attempt. Disabling EPSV",
        "2GcAW",
        "yov%Y",
        "responderId",
        "Y=sFV@",
        "031:1E1",
        "T Y!qq",
        "Z&R{k^:",
        "\"#3q_",
        "kkm<D",
        "> >$>4>8><>@>D>L>d>t>x>",
        "Xa 81",
        "[Gqq\\",
        ">23t{S",
        "Cl4&x",
        "cO}X';q",
        "B{iOY",
        ";=;a;",
        "AF&(X",
        "Fmn0#",
        "3j_B?|",
        "n?o@p",
        "BIO_gethostbyname",
        "IsUserProcess",
        "-]!Vc",
        "\"2]rg",
        ";gdwF",
        "zM;~;",
        "4LQP5",
        "9y='I",
        "mDXHfH",
        "CMS_KeyAgreeRecipientInfo",
        "^.vpp2,",
        "/nuf@",
        "z:)b{\\O",
        "6,6Q6v6}8",
        "eyDJd",
        "qkivy",
        "606<6D6d6",
        "~^x*^`&cR",
        "sKM:Op",
        "=&=4=",
        "Failed to save patching old MSI error into registry",
        "Vector Permutation AES for x86/SSSE3, Mike Hamburg (Stanford University)",
        "7 7@7`7",
        "A\\`cq",
        "nstaller\\UpgradeCodes\\A3122864DEC94E444992B26D2D1900E2",
        "7 7;7V7q7",
        "0g1l1w1",
        "('Mes",
        "5Z$TM",
        "O##'#",
        "<$<,<4<<<",
        "w@PVk",
        "?OUbH",
        "z].*o0L",
        "2~qIi",
        "XqL2~",
        "fi-FI",
        "  WS\"",
        "]a>3P",
        "@d}eDC+",
        "KUP9T",
        "tAfKr",
        "_WVj@",
        "=<M9]i",
        "%B>,I<",
        "KEz+F",
        "*Gq5ic",
        "VYRja",
        "uXAS,",
        "MSYzt",
        "zg.g\"0",
        " ` iQ(~",
        "FindFirstFileW",
        "WINDIR",
        "9&969`9",
        "2qUEV7",
        "SSL_CERT_FILE",
        "SuGQx",
        "8B8j8",
        "NU+lQ",
        "Zv'g\"u",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 Check Point }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "OjlZ;",
        "Phaqt",
        "H2P/[",
        "Incrementing tick [1] of [2]",
        "glgb5[",
        "8)zBgy 0",
        "5ec;=",
        "ExUDH",
        "7h8U!",
        "i.saN",
        ";kdSg{FpB",
        "!u*=W",
        "M-5Zr",
        "#tBFwr",
        "R1h58",
        "u.j_h$^\"",
        "6D6H6L6P6",
        "6EFp(",
        "xA%VN",
        "898B8",
        "5M=g=.>",
        "6$606P6X6`6h6t6",
        " qFF8,",
        "\\O51=",
        "p5t5x5|5",
        "OEc,u",
        "H? dG=",
        "78 27",
        "~TYT#",
        "need new setup values",
        "0a0}0",
        "<G<N<\\<a<z<",
        "-95[6",
        "variable has no value",
        "121U1o1",
        "?~uqz",
        "\"0[ll",
        "/wXpg",
        "?H?t?",
        "4 454?4E4K4Q4",
        "p}|x-",
        "}8qU`DBb",
        "v8n#\\&",
        "b'QoT",
        "S f\\`",
        "L$ WQPU",
        ".?AVfile_parser_error@property_tree@boost@@",
        "0G}nd",
        "4:4T4X4\\4`4d4h4|4",
        "string pointer is null",
        "J:P!2_u",
        "=O_|S@",
        "sN:%8",
        "zB/u}",
        "2Gs}\\(",
        "+\\EO3",
        "s+HkJA",
        "7!747c7",
        ";)=\\O",
        "rP@_`\\J",
        "%Bs e",
        "=H>p>",
        "Function not implemented",
        "^G|d|",
        "*t/*6",
        "J:JNAI",
        "n51:K@",
        "!9wv+",
        "%r <m",
        "f/9@k",
        "l`:*;P",
        "#>}*p",
        "wchar_t",
        "CheckInstallConditions:  This is an upgrade.",
        "8.=|,",
        ">`;@}",
        "q+V=Q+@r",
        ":y@A)%J",
        "&xxUP",
        "iAxj6",
        "k6\"9V",
        "Q/qV+",
        "!~`L$[(J",
        "fdbdh",
        "_4Pt5",
        "dKP%'",
        "787X7x7",
        "7(7_7e7{7",
        "#NKHf]4",
        "?X5Ek",
        "jbGy%",
        "v)2DA/",
        "[r8=u;",
        "a*87vCM",
        "%+v;U",
        "Y?FT,/",
        "###Oo`",
        "5b5Xl",
        "^l;r,",
        "3!^Alm",
        "NN%NJk",
        "?*?I?",
        "CLIENTHEADER",
        "QhH-!",
        "ZaY[+",
        "R[f/82",
        "n'Di6,3",
        "GV'v}",
        "Qcm)k",
        "%YK2b}",
        "6gouP",
        ",*,kgPh",
        "0)0<0",
        "Lock already taken as a writer",
        "s/ws]",
        "I1Tad",
        "3$3,343",
        "WIX_DIR_COMMON_ADMINTOOLS",
        " zGXV",
        ">g5(L",
        "2jDKsE",
        "u]A@u",
        "d7St\\)",
        ":2;K;v;",
        "{7bq(",
        "ar-SY",
        "g\\_gF-&",
        ";:N'j",
        "id-it-signKeyPairTypes",
        "rB:f2",
        "S:}Z:",
        "7DBdf+y",
        "'n/ >c",
        "L$`VW",
        "wCm*;",
        "#Ae3fO",
        ")CF#X",
        "@P9xwp_0Z.$6",
        "F6@9*",
        "brE6x&x",
        ":3`<tf",
        "CV/>=$",
        "al,;=",
        "EEEEEEEEEEEEIE",
        "OLD_DSA_PRIV_DECODE",
        "+*]8-",
        "&.d|j@",
        "; <(<",
        "MOVNTQ",
        ":(:L:x:",
        "-[AbC:x",
        "9%BN`",
        "t].?r,",
        "^C7m1",
        "=#W7 1",
        "YXw{[s)",
        "SYSTEM\\CurrentControlSet\\Control\\Network",
        "api-ms-win-core-synch-l1-2-0",
        "D^efJ",
        "q0;1F1R1`1~1",
        "`?sK6c4|j",
        "-z2_$&",
        "pK>&=^",
        "6kr1*",
        "= =0=4=D=H=T=d=t=x=",
        "&pO/'",
        "hU74s",
        "<g.^fP",
        "failed to begin file change for file: %ls",
        "r2RT6s",
        "-wczBC",
        "7&757L7T7Z7",
        "XQC~%O=",
        "`^dW@",
        "o>=J<",
        "f;cZ'",
        "1&181X1`1r1",
        "7:8E8W8f8",
        "D81hij\"I",
        "0tI%F",
        "kI(\\(",
        "<)Ul`",
        "55v(8O",
        "Bf/S#",
        "Lm[a}G",
        "B/]NX{f<",
        "~$i`%\"",
        "x;uRoaYY",
        "}@7$r",
        "certs",
        "failed to read profile from custom action data",
        "FW'TF",
        "HM\\E3bg",
        "2 242L2P2p2x2|2",
        "<$<,<4<<<D<L<T<\\<d<p<",
        "<hzjz`y",
        "rkX9+",
        "dL3F>e",
        "ANDPS",
        "XJ{1&v{",
        "*hG2Gq",
        "\"F<W0",
        "N}qh!v)$",
        "E[6S-1",
        "!_BP;",
        "?DUQu/(",
        "DGSnQ",
        "Failed to decrypt contents of ",
        "n.0SQ",
        "-mqf\\e\"",
        "F0WDdR",
        "x#k!-",
        "AmH-u",
        "2t!\\Ay",
        "2ez\\~dJ",
        "<H[I_H",
        "XXu!s",
        ";D$,r",
        "3>3m3",
        "SVEg%f",
        ":!\\iYvV\"",
        "$8sS3",
        "Z$#?b",
        "t=jGh<",
        "1M2.3v3+6",
        "@I@qE1$Dk[OC",
        "\"k`}+",
        "&Y;)L",
        "5/-@#B",
        "t(hTT!",
        "\"B<EnN\\",
        "missing export tmp rsa key",
        "<2<r<",
        "T0>IIi",
        "{C[c&",
        "#%Qx,",
        "]10!T",
        "m`9#S",
        "g?B\".",
        "i*)%:",
        "_\"7cny",
        "6\"6*6p6u6z6",
        "F`9pF\"",
        "hMIZ+V\"K",
        "DHE-DSS-DES-CBC-SHA",
        "<, Ik",
        "npN'[",
        "(QH[?",
        "D$4VP",
        "oD$ f",
        "1(1,1<1@1D1H1L1P1X1p1t1",
        "Ul.]Q",
        "qs.iW",
        "; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\\;`;d;h;l;p;t;",
        "dp$KV%q",
        "URich=9",
        "s->d1->w_msg_hdr.msg_len + DTLS1_HM_HEADER_LENGTH == (unsigned int)s->init_num",
        "szUserPW",
        "name translation failed",
        "6@*W9",
        "wCd'Pj",
        "helper is running.",
        "regex_error(error_collate): The expression contained an invalid collating element name.",
        "YSuZ5M",
        "Cannot FETCH without a UID.",
        "4%4*484",
        "%MaU*#",
        "DTLSv1.2",
        "0o1w1",
        "?%?.?",
        ",$s]F",
        "UWak\\1",
        ".SFER",
        "3p0VhI",
        "%ssystem32\\msiexec.exe",
        "7.3k7",
        "w8t_H",
        ">#>w>",
        "va*D(",
        "XDIm'",
        "=\"\\`\\",
        "uwxdu",
        "StopURLFService finished.",
        "rjv^|",
        "=dfP%C",
        "< <@<D<T<X<`<d<l<p<x<|<",
        "1$1.121<1F1J1T1^1b1l1x1",
        "]!!)2",
        "O,?6:y'",
        "z_DZ=",
        "Hl4gL",
        "]>'\"$5h",
        " U)XR",
        "gYV,SXqd(",
        "t*jVj",
        "NOPASS",
        "?,?8?X?`?l?",
        "181T1p1",
        "InstallDirectory",
        "PWKv!",
        " characters",
        "eY@mDof",
        "!!DdEP5",
        "YX`$n",
        "h_(=e",
        "=_;vs",
        "\\CIb@",
        "|pz3i",
        "d.encrypted",
        "bTP\"l",
        "b|Nn :",
        "=x!u1;4",
        "RPCRT4.dll",
        "^j%%m",
        "Education",
        "8-ERRu",
        "ESI:%08X",
        "@|Cks;gX",
        "fF]>4",
        ";0;4;L;\\;`;d;x;|;",
        "W.gE1",
        ")uj'iY",
        "[C+T5*",
        "Ph`>%",
        "dsa_with_SHA256",
        "'yYzB",
        "VEVyV",
        "Windows update requested a reboot that should be done before this installation",
        "|XV<(",
        "gost94cc",
        ": :(:,:8:@:D:P:X:\\:h:p:t:",
        "Completed",
        "1Mk|M",
        "!i+vmy",
        "OCSP_CHECK_DELEGATED",
        "/CZpN",
        "V,0+5X",
        "/l-~?&w",
        "6.6I6d6",
        "4_^[3",
        "p20l;",
        "&@Y4B",
        "6#)+s6",
        ")xSUU]",
        "|!PhD",
        "\\par 9.2\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Export.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "MsiRecordSetString failed.",
        "K'wX9",
        "dq=6F",
        " url2",
        "vk;RY",
        "GET_SERVER_FINISHED",
        "SB!rJ",
        "0*K/M",
        "HqnkV",
        "S&r:yr9P<1",
        "@LhGp",
        "Xby>z\\",
        "F]?qwf",
        "?7???V?h?",
        "%e&C91",
        "DeviceAgent.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        " of your Affiliates or (b) You indicated in Your purchase order or in requesting the License Key, that You intend to use the Products on behalf of Service Customers, and (c) You purchased the managed service provider package, if applicable.\\tab \\line }{",
        "@~N<pr9",
        "woMu/",
        "3D$@3",
        "=gU{~",
        "u)`bh5A",
        "Vn'.l",
        "PEXTRD",
        "`1)DxM",
        "EVP lib",
        "GX L0",
        "<U<r<",
        "H-Asi",
        "srA9%",
        "BM]N*:U",
        "eVTQE]xi",
        "3y&,FF",
        "\"u$<#",
        "sr-sp-cyrl",
        "3%4+4i4o4{4",
        "Ugf9(",
        "overwrite",
        "+W}\"1q",
        "v`%{S',",
        "-u8&e",
        "iH'LeN",
        "1S2{2",
        "F2XM1",
        "z@/&{",
        "Kj;'I",
        "Wsvtw",
        ",.'Oa",
        "BOzcF",
        "/RI)y",
        "323b3",
        "k6AA4",
        "Hostname %s was found in DNS cache",
        "THu7[,",
        "g/!.+",
        "tIO)$\\",
        "jCjlj%",
        "lu<1/",
        "$>Zpgt",
        "s@\\~c>",
        "1ml'}",
        "{S-Xv_",
        "W&zS9",
        "`'nSN",
        ">3?]?",
        "K5XQ;",
        "u@VVRQV",
        ")P'g$#",
        "]ctj4FH<",
        "*aFyE]",
        "]2[T6",
        "SSL: unable to obtain common name from peer certificate",
        "*[J!]f",
        "J J0J@JPJhJxJ",
        "Adding True Vector vsmon.exe to Firewall exception list.",
        "need at least one digit in exponent",
        "WS&}xO",
        "btm!'",
        "= vx:",
        "J}sr;",
        "N>28V#",
        ". Ney",
        "BI&zj",
        "# Netscape HTTP Cookie File",
        ":K7+6",
        "sGp%H",
        ")@VvQ?",
        ",V^1 q3/X",
        "WixRemoveFoldersEx",
        "1,2d2",
        "2;2_2",
        "K{W'e",
        "8/8e8",
        "5l6v6",
        "=$>f>",
        "===A=E=I=M=Q={=",
        "N>3a)",
        "\"2@(n",
        "dpAY@",
        "CfEdX\\",
        "?@a< 3",
        ":f}MJ4",
        "odWm2",
        "mPGt4",
        "]opMa",
        ":(60V",
        "  You probably are missing a necessary root certificate.",
        ",k-_'",
        "2%2+202>2",
        "T8\\:v",
        "pc&<M",
        "isSDKUpgrade: Installation SDK version: %s",
        "StartDriver: OpenService(%s) failed with error 0x%x",
        "[y9wQD",
        "LLgBEh",
        "qIBEc",
        "P^w?!",
        ",)V)0",
        "252D2J2k2",
        "D3g+B)",
        "8&9e9",
        "<1=?=",
        "t$ WS",
        " _0XQB",
        "GetFileAttributes(",
        "af-ZA",
        "dK@z|",
        "SSL_do_handshake",
        "mzgX]",
        "7hlU!",
        "yX#QR",
        "^o3Px",
        "?z7P=",
        "M{b%S",
        ":tcvd",
        "CleanCPTray",
        "O5\\A^6",
        "(14Hs",
        "=8=e=",
        "z@Q\"(s2",
        "l1l)$_Z",
        ",\\f0@:",
        "t&VQj",
        "FAi=`",
        "pl-PL",
        "^A`oO",
        "c=BLSjpFKX_wyQTb3",
        "LA`0q",
        "fv\"L9",
        "9Ph[$1{",
        "rc2-40-cbc",
        "TS_CHECK_NONCES",
        "6 6@6L6l6x6",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480 2.11 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "SchedFirewallExceptionsUninstall",
        "7#7?7[7w7",
        "VoDf~W",
        "2\"3=3k3",
        "=kjWxBp",
        "FeatureAntiVirus:  FreshBefore started.",
        "Self protection %s",
        "CY_`o ",
        "szToolTipText",
        "=d__a_",
        "GpXXu",
        "iG^2D5",
        "Lp##3q",
        "^Si,qq",
        "software\\zone labs\\zonealarm\\registration\\",
        "z7p+T",
        "*1:4_",
        "I($+Rb",
        "p@Ij/F",
        "<,<W<",
        "zh-CHS",
        "sIX/|G",
        "L+E\"f=",
        "@c76bkA",
        ":OR$D",
        ":`NdM6",
        "424P4n4",
        "A78pu",
        "$0,040<0D0L0T0\\0d0l0t0|0",
        "1F1Q1j1",
        "&$(.o",
        "x*XKT",
        "7z{C{",
        "8#8,8I8U8y8",
        "!OIW*",
        "4IU#E",
        "t,/2x",
        "mg(8Bu",
        "\"m[]b",
        ";,;4;<;D;L;T;\\;d;l;t;|;",
        "N8Iu+",
        "<.5o>",
        "F&1iu:",
        "'xU(;",
        "\"]@sH",
        "F?3-z:",
        "RSA-RIPEMD160",
        "`e0vY",
        "NT)zA!Z",
        "a+;/JC",
        "PEM_X509_INFO_read",
        "sXn%pK",
        "]M`'Zr",
        "cXAKp",
        "\">:J0",
        "5W5z5",
        "wrong signature size",
        "GjE%g/",
        "X9.62 curve over a 239 bit binary field",
        "3|L n",
        "2CX[R}",
        "8<k:h2yY",
        "\"4E8,",
        ";-;F;_;x;",
        ":,rb@u",
        "2rIU[",
        "huNtn",
        "^<Bf$!M",
        "HF o ",
        "2}%|c",
        "ca3A\"",
        "= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\\=`=d=h=l=p=t=x=|=",
        "Q/ydmF",
        ":,:\\]}K",
        "*&jXVO",
        "GiITF",
        "TL$[Y",
        "]|}S=",
        ")Cl.~/q",
        "vJ^2w",
        "d&%AOJ",
        "FFKC&",
        "V,vKes",
        "?2xSW>=p",
        ";7Hs/",
        ".2d~y",
        ".*a{4",
        "#Du`{+~",
        "?F?g?o?",
        "4?4[4",
        "a8]S`V",
        "R>2T3",
        "LoadMenuA",
        "S]k5nlo",
        "Env-3",
        "Hj;XE",
        "{F>0>",
        "byhUX",
        "~]h;P",
        "?4?k?r?y?",
        "SSL server certificate status verification FAILED",
        "2BC|FUX4",
        "Bcdt=",
        "<rN_x",
        "G%D3H",
        "\\e-cM",
        "L4l\"7'6",
        "?rZ5fb_I",
        "9kpu09stu+j",
        "_Wg_#",
        "`6+z\"",
        "!~U}f",
        "j*Xf;",
        "Cannot change service configuration. Error: %ls",
        "GetCursorInfo",
        "829\",:",
        "1zud ",
        "F-j*MU",
        "spanish-argentina",
        "Kc\\mnQ 2",
        "EVP_PBE_alg_add",
        " volatile",
        "<8<D<d<p<",
        "CANT_RUN_VSMON_INSTALL",
        "mihR\"CS",
        "z{&n4",
        "Z1lRe",
        "CS<?h6",
        "6xY$77q",
        "vsdata.dll",
        "wGzB{",
        "g(U2{",
        "XF6yxx",
        "g.\\cz",
        "(CPfB",
        "l$(WS",
        "UhL^\"",
        "r~x2uu!)",
        "bin\\sr_service.exe\"",
        "w87x]z]|]~]",
        "J~|xH3",
        "failed to create new open port",
        "vm?[Q",
        "win.nt.nt",
        "tWB7@",
        "5(6,606H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "ssl2_write",
        "Cannot get ActiveDatabase for extracting %s to %s",
        "]VIOL",
        "2H2X2d2l2",
        "aT\\NB;",
        "DHw|i",
        "objCA",
        "{U*%<",
        "uihQ/\\",
        "ip;b2]",
        "%127[^,],%127s",
        " 0x22",
        "'PwA~^",
        "vh^:-",
        "format specifier requires signed argument",
        "15'7$",
        "#.#X#G\"",
        "s_db5<*",
        "&fC2kC>",
        "[jwU5j",
        "*d02h",
        "tc'MS",
        "\\\\8)^",
        "203X3",
        "o`$Gs?",
        ":{20!",
        "6{IP3uGE",
        "=8=@=L=l=t=|=",
        "o>oLh4",
        "Ak2xO",
        "DHE-RSA-DES-CBC3-SHA",
        "zp660",
        "101@1D1T1X1\\1d1|1",
        "scQO}",
        "MsK2oF",
        "b.]DL",
        "Yi3M2",
        "6;L2g=9",
        "*N3|} ",
        ", or export the Product into any country, or make available or use the Product in any manner, prohibited by law.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid10708013 ",
        ";(TD7",
        "*t;~ 6y",
        "c/S*=z",
        "K?Yw2",
        "ah\"QE1",
        ")-b93",
        "INSTALLER_FAILED_VALIDATION",
        "D80f ",
        ";$;,;4;D;L;T;h;p;x;",
        "11A1Q1a1q1",
        "=0=4=L=P=h=x=|=",
        "!qQn$",
        "sbj:2E",
        "e6?\"f)",
        "#B[Z^K$",
        "+}HI-",
        "NetworkService",
        "~0(-m",
        "x7Iv@",
        ";#<F<",
        ")jJB4",
        "L*TRaD",
        "_iI,<QE8@",
        "Xh6aZ",
        "0VD,1U",
        "A)pv &",
        "e.1G<F",
        "ECDSA",
        "yo47{!",
        "2j3x3",
        "2g3O4j4",
        "lQLgw",
        "]@.A.B.C.",
        ")E)F)G",
        "#5}n^",
        "@$g&3g",
        "< <K<m<",
        "H(h`O?|s",
        "KIL>{c",
        "j1Cic",
        "Jd5b!",
        "brainpoolP256t1",
        "H_^][",
        "Check Point Device Auxiliary Framework",
        "8fo*Wk",
        "3T$03L$T",
        "h/ ,=",
        "E!Jdz",
        "Users",
        "#0@Z(",
        "H}2 M#",
        "EU%$x",
        "1*^7\"",
        "Hqbxc",
        "$Cw!R",
        "{{,`L",
        "O5kuy",
        "CryptGetHashParam",
        "E~T9l",
        "]!]%],]",
        "?rs!:s",
        "5@5T5f5B6",
        "zhn9%X",
        "OLJNk",
        "_}T\\W%&",
        "hF9,4",
        "U=PuC",
        "D$ hDB%",
        "SSL_add_dir_cert_subjects_to_stack",
        ".X#6$",
        "~qlE\"",
        "=2=N=j=",
        "~xG33",
        "e!J`r",
        "-]7_U",
        "Failed to delete %s. Error: %d. Triyng to replace using ReplaceFile",
        "1$1,141<1D1L1T1\\1d1l1t1|1",
        "?#uET)EJ",
        "+#tnq",
        "4VddM",
        "f+TuK8J",
        "runas",
        "\"\"\"(((...///001166::::::@@@HHHHHHHHHHHHJJJJJJJJJJ]]]]ddddddmmqqqqq",
        "z{D(_",
        "T%.VN",
        "%yg\"^",
        "MonitorLogon",
        ")fF~N",
        "failed to create formatted string for securing file object: %ls",
        "SwC.p",
        "~h0`)",
        "S]$ES",
        " !\"#$%&'(",
        "{WUvop",
        "PAVGW",
        "R[-Nw",
        "{?MOI",
        "P'\\9t",
        "lB7NR",
        "Om\"/&d",
        "5q?`7",
        "szLocalCatalogXmlPath",
        "<.TWz",
        "N.';u^",
        "|TEhl",
        ".Z5]\"",
        "jw@aT",
        "{5Ip'",
        "RunClientHotfix finished with error.",
        ";\";5;F;S;^;{;",
        " 0xc9",
        "#9@E#Si",
        "]i]Gy@a",
        "i'>ct5-iwiB}",
        "{`k@U",
        "zf,W8P",
        "T,U+$~",
        "a)d:!",
        "`%,Ri",
        "]RV!84C",
        "XRJ=ykOQ",
        "3kl'9X6nz",
        "473om",
        "3270 REGIME",
        "R(0pMEfR",
        "u45D\\L7",
        "@fui:",
        "Nh{aq",
        "G!iVn",
        "not implemented",
        "9G:e:r:",
        ":#:+:",
        "Need to restore SC Un-Install settings",
        "`g1{1",
        "\\Se6M",
        "_u,[w",
        ">=whkc",
        "Cd}#%",
        "ygdP<4",
        "s6e87O'",
        "p-qaj",
        "=d.JzP",
        "m{3fg",
        "VX7]|T",
        "&rvRKHphckV2YL",
        " W5=_a",
        "r4(M&",
        "o&&i*q",
        "International Organizations",
        "3 3$30383<3H3P3T3h3l3",
        "WUr9J",
        "d}D?[",
        "{1{S(",
        "l;4;}",
        "J@E*Q",
        ",Ueg=",
        "RBIei",
        "yYWw<",
        "p<XK,",
        "7kf9wbz",
        "iA5StringSyntax",
        "missing init function",
        "=aY2Wn<",
        "COPY_ISSUER",
        "WD_CheckFolder started.",
        "jojkj'",
        "5_ETa1C",
        "4fL(\\",
        "CCG!EZU",
        "(`/|9~",
        "M\"Hn!*",
        "NYVZM",
        "1[#}y",
        "GRa[o",
        "ReleaseDC",
        "w2A#f",
        "1N_K/9b",
        "gqv/\\",
        "XVH5_",
        "X)u*=B",
        "5<v%q",
        "Q)@tVE",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\epam.cpp",
        "@m`n$hJ",
        "h[9eG",
        "w]Usi",
        "b`ayy",
        "failed to get name of object",
        ":0:4:@:D:H:d:h:t:x:|:",
        "unsupported compression algorithm",
        "\"^-,*",
        "PKCS12_MAC_DATA",
        "Fxwk/",
        "%p=OZN$K",
        "293D3I3a3q3",
        "V,KC&",
        "CMS_OriginatorIdentifierOrKey",
        "j\"_f9z",
        "FTgep",
        ";:;g;",
        "IgcDC#$)",
        "PZ?*T",
        "_&\"EsD3,y",
        "{GHqA",
        "R!)0X2",
        "J'H;8o",
        "J!Nx\"",
        "7 7,787D7P7\\7h7t7",
        "PKCS5_PBE_keyivgen",
        "Ew\"pErE{E",
        "316bb31a795600b3d256d0cad2fe354538e7566b2bd69cc6cbcd5c38f0e2bcc63058344429dc2121fd07f63f2a7c66bf76e80d75c8f7a1b622f878a18941d840",
        "m5} zfI$",
        "<@=G=P=Y=b=k=t=}=",
        "e2_tC",
        "Jo_(9q*BYH",
        "c\\]wb",
        "[r)q3",
        "jchDB%",
        "KN4<'",
        "S]#Dc`",
        "%]6x5s ",
        "WTSQuerySessionInformationW",
        "tb`iz4",
        "1!2E2\\2",
        "{6dZ=@",
        "nmMEuec",
        "/NiBiHi",
        "!M;&gFe",
        ";`kET",
        "S_eo!",
        "6=OwE`",
        "WHsHi",
        "6]*=u",
        ">A>Q>a>q>",
        "cn8Hd0",
        "CV*+EH",
        "=)@ph",
        "I;\":x",
        "Password did not match.  Please",
        "u7Uj0",
        "%IQq{",
        "CANT_FIND_VSREADKEYUNINSTLLINFO",
        "BJ,]a",
        "gp/<{",
        "P3)t*",
        "d$t_^[]",
        "v~wCA",
        "926007302",
        "X@zf/",
        "8h!xD",
        "iswkl",
        ")B$[j",
        "H-B.s",
        "T*fDo2",
        "i`,qyl",
        "Ucx)q",
        "Wy(PFv}",
        "Rq$),",
        "fpwC9",
        "CMS routines",
        "X>4r#?D",
        "]4m83h",
        "command takes no input",
        "T9}<,",
        "MsDTS",
        "setct-RegFormResTBS",
        "93av*",
        "aes-128-cbc-hmac-sha256",
        "4Q;FD~Z",
        "2)2l2",
        "[1i|M'",
        ":  does not exist ... can't set string value to ",
        "td\" Ym",
        "REMOVEPRODUCTS_C",
        "9IjI8",
        "Yf/cb",
        "a&DA7",
        "SSL_CTX_use_RSAPrivateKey",
        ";8azd",
        "dNNNb",
        "Session ID cannot be set as a custom header.",
        "264>2>",
        "jBjmj",
        "^ruZG",
        "EWY?f",
        "^E\\`i",
        "W;G&z,o",
        "StopABService_rollback finished.",
        "=F|,2",
        "6gu]c",
        "7F8J8N8R8V8Z8^8b8f8j8n8r8v8z8~8",
        "&??Pd#",
        "t32no",
        "3;4@4k4p4",
        "\\@V$*",
        "<g,5(1",
        "=(=0=4=@=H=L=`=d=p=x=|=",
        "5MxYU",
        "5h|d|",
        ">F?l?",
        "ZC)8xw_,",
        "7G8`8",
        "UNUSED_3",
        ".Xa+l",
        "K<\\c5",
        "_]nGjb",
        "{7GBW",
        ".PyXB",
        "OnFreshAfter finished.",
        "N;4QQ",
        "'k#a#'",
        "1:1f1",
        ">1>J>T>[>",
        "DZ!gazi",
        "IcXa:&",
        "inFs'",
        "P)v%[",
        "K:gW.",
        "%2yrZ",
        "vz+T9D",
        "=3bj[",
        "</ruleset>",
        "expected element name",
        "?{`G=Y",
        "s10*So",
        "jwjmj'",
        "ZLERR_FAILED_KAV_DRIVER_INSTALL",
        "D)B|5",
        "Ss\\&V",
        "e}x/\"d",
        "D`|-A",
        "O5Em/",
        "0^R\"`4",
        "xFisl",
        "ZNpH1Z",
        "nameAssigner",
        "md_algs",
        "4WM34",
        "^&yF;J ",
        "Fl;K*",
        "j\\hZY",
        "Just set the init event -- we're ready for messages",
        "44^RB)",
        "&~yfQ",
        "t$0RP",
        ")_8NK",
        ".?AVUMSSchedulingContext@details@Concurrency@@",
        "i:$)@",
        ":$:0:<:H:T:`:l:x:",
        "fKi]'",
        "3bY{X",
        "ILnF$",
        "j#+DU",
        "i^b;G",
        "._hB12~4IDp",
        "JP$Ea",
        "Xc{:m^",
        "oTWl(",
        "=UM>D ",
        ">tp;L$",
        "Ny52q",
        "|>HEk",
        "uXJ\"J",
        "4+G*pI8J",
        ")C\\1C",
        "0ZD_K",
        "g~85X",
        "invalid oaep parameters",
        "8MS'W;-",
        "K*qA0!",
        "Ei]C0s",
        "U>lFX",
        "0eGKL",
        "**c\"i",
        "ec_GF2m_simple_set_compressed_coordinates",
        "]viRQ",
        "|jFUi",
        "unable to decode issuer public key",
        "eue}e",
        "90:F:",
        "SA+{T",
        "Y,q)*",
        "TUW (",
        "=6>E>",
        "e~N~~",
        "9${Lo",
        "s]hWC:",
        "2e7<`p(",
        "Uq*0E",
        "VNxR+",
        "lAs*?",
        "nxxrghK",
        "n >= 0",
        "u)jWh",
        "NkdN1\\",
        "%s in chunked-encoding",
        ".\\crypto\\evp\\evp_enc.c",
        "ogk+,",
        "2>>^k",
        "operation not supported for this keytype",
        ",4.&j<h",
        "3c2)&",
        "8l.x<",
        "3T$L3T$,1",
        "-)2\":",
        ":I}3Y",
        "USPhL",
        "Custom action was told to rollback a 64-bit component, but the custom action process is not running in WOW.",
        "4GhO]A%",
        "i)Z>m",
        "pR!GL",
        "aaM)n9",
        "f>:Fm[",
        "r9@h+",
        "*k o7B",
        "jWUoF",
        "`YVcUs",
        ";RNNM",
        "%Vw\\3",
        "9[9e9",
        "&80RD",
        "ASN1:",
        "TS_TST_INFO_set_policy_id",
        ")15%S",
        "H?`02",
        "Did not find FDE InstallProperties",
        "TF5_K",
        "0xR(d",
        "jIm(}",
        "cmd /c \"rmdir /S /Q \"%s\"\"",
        "x';f;TQ_",
        "B5fxpr6",
        "%+:T\"",
        "AA)9N,",
        "uH.p}K3",
        "www.digicert.com1$0\"",
        "Iw\"Kw",
        "xfK&x5",
        "Gq[;G",
        "Failed to stop URLF service",
        "V2I_SUBJECT_ALT",
        "a /]L",
        "/%%/jDBG",
        "AM2Signatures.exe",
        "y4j3d",
        "gQ`Ti",
        "3}~P/y{_",
        "fS3FS",
        "JK|`$",
        "Q:^X]",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "<%Nj>",
        "mdW/6",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11555386 ",
        "Can't execute view to update properties.",
        "1HAKB",
        "crV/p22b",
        "3`*\"\\",
        "L$DQPW",
        "failed to get sid for account: %ls%ls%ls",
        "\\ZLCommDB.dll",
        "l.GyX",
        "ext-ms-win-ntuser-windowstation-l1-1-0",
        "AES-128-CBC",
        "L1k89",
        "[eL\"g",
        "zjD,D",
        "failed to read file name from custom action data",
        "nkrb{",
        "Y%Nem",
        "rGtO!4",
        "fbruI",
        "QqT%A",
        "g><,xZ",
        "D$4SP",
        "969w9",
        ".<6P3i",
        "Bd; =@",
        "`rjqp",
        "Polynomial:",
        "jCjwj&",
        "Nr(V=",
        "1MnT@",
        "1Q1y1",
        "wAv9MO~",
        "unsupported label source",
        "W\\84 ",
        "a~,{#",
        "<ASN1 %d>",
        "9BrWyE",
        "PKEY_ASN1",
        "y{A+\\",
        "Z_Z]y",
        "2N<G*",
        "0(0,080H0X0\\0l0p0|0",
        "h5^yw",
        "W~+Qx",
        "`a.io",
        "9}yF~R",
        ".Ws_bf(",
        "@NzDO[r",
        "plL5T",
        "Failed to read encoding key from CustomActionData.",
        "958&'",
        "\\ZoneLabs\\Scheduler.dll",
        "'B5z&",
        "D]t+&",
        "1(1-2",
        "ZBri%|5",
        "$_%_&",
        "|u?0k",
        "9'9E9S9",
        "uwE(++5",
        "r~f;u",
        "07'+6S",
        "3p\"0T",
        "o`31P",
        "\\C1YAD",
        "qX21A",
        "s/O%Pd",
        "e;X}`",
        "y6[>bE",
        "aWC~#",
        "l<-9B6",
        "?!?.?R?Y?h?r?",
        "`(b!P",
        "i.---H]",
        "1A1f1",
        "9b:q:x:",
        "Esaau",
        "\\ q)E&",
        "~ZBrt",
        "t:SWV",
        "5B5P5w5",
        "lpN[i",
        "GetVersionEx(%d) failed last error = %d",
        "F:\\ckp\\src\\dtis\\ravpn_is_v1\\CMpub\\bin\\WIN32\\release.dynamic.msvc141\\PiReg.pdb",
        "r.Lql",
        "Trust Root",
        "< <$<(<,<0<4<8<",
        "5/2{?",
        "Failed to shut down the SSL connection",
        "unloadZlcomm;",
        "xoWfGy",
        "->.ad",
        ",fqPtSy",
        "H6\\JV%[",
        "l.){R!Y",
        "6 /iB6",
        "ycxc:$;",
        ",HzG$",
        "D}WEL",
        "0!0B0",
        "SetDriverMode:  SetDriverMode started.",
        "M4-pHz",
        "\"Li@V",
        "<l64sq",
        "o}+o4",
        "\"> l-]z",
        "FlE<R",
        "M>ZCE",
        "rr*\"U",
        ".7rqdP",
        "z]t$t",
        ">BJQh",
        "VhLcL",
        "SetEventGroupInVSConfig failed.",
        "858P8k8",
        "P~&Qr",
        "`/j0#",
        "ru-RU",
        "z8'fR",
        "~1q-;^\"V",
        "G`6Jam",
        "^;O.p",
        "@Mlc=",
        "2,313;3s3",
        "FGnG@",
        "UNISTALL_PASSWORD",
        "5~3/~",
        "%u!58",
        "FB$\",",
        ">5>E>U>e>u>",
        "0SfN7o",
        "vTN-?",
        "y~3JT",
        "GB>'4ii",
        "3tOz[9",
        "5j5t5",
        ">CD>T",
        "> ?Q?j?",
        "{&}_tV",
        ">b`a]M",
        "):4Nm",
        "w$g.Xe}",
        "|$,3B",
        "jx[Ik\\",
        "lKN3]",
        "H\"*9D",
        "Failed to calculate script file name.",
        "}|(TXC",
        "Jd^U\\",
        "ulv~B",
        ":i:s:",
        "A.GQ>",
        "}2IDo",
        "*t}FA",
        ",1Cl3e",
        "Unable to receive SOCKS5 sub-negotiation response.",
        "iR~`|R&",
        "1 191R1k1",
        ":_}y18",
        "UI_Framework = YES",
        "!8ayCM",
        "1(10141@1H1L1X1`1d1x1|1",
        "F4uA9",
        "x33-#0",
        "> >(>0>8>@>H>P>X>`>h>p>x>",
        "&:0hD",
        "o<O0O",
        ":E;g;n;",
        "QSBY?",
        "\\5XWp",
        "xW)Nvw",
        "uYlTb",
        "Command not found: %s, truing old one",
        "95ya3IJX",
        "!]l;.",
        "838`8h8",
        "k=<+Z",
        "OnUpgradeBefore",
        "`(@|VaR'",
        "tW,c=",
        "GetSecurity() failed",
        "y\"Cz(",
        "a'd;g",
        "'6C-L",
        "OZuy%",
        "!f]5#",
        "^\"zj6V",
        "w[\"Ch",
        "B91Y(",
        "^c(3_",
        "Yr^Yw",
        "3iUuhi",
        "\"4+\\K",
        "zf|)1&s",
        "sv9|$,w",
        "l!5v6:",
        "0~%T6",
        "l=Qol",
        "Gm;D3w",
        "dS$=}",
        "MdtuV",
        "rlU!c",
        "0'0C0_0{0",
        "TS_RESP_GET_POLICY",
        "L$ 3H",
        "z:NW]",
        "mv]RG",
        "id-qcs",
        "}zS%H",
        "pw'#5/",
        "0vw)HV",
        "80868S8p8v8",
        "3\"3R3",
        "2t4w&",
        "?J?u?",
        "8=+st",
        "2!O_I",
        "0oCU(",
        "|$0WSj",
        "I)!^;",
        "QueryServiceConfigA",
        "02-00-00-00-01-00",
        "';<=#",
        "=d+tXb",
        "Q]ye.",
        "&Fto7",
        "mn3H1",
        "tBinary",
        "_a[wo",
        "&Nw9y",
        "&rqK-2",
        "GLU\\bZ",
        "%#q.3",
        "b2i_PVK_bio",
        "g_V^>",
        "z0<i4",
        "c^2P&",
        ",VXmo",
        "~W#@X",
        "`[;Z*",
        "KR*@@f?",
        "5:5j5",
        "fmgA3",
        "vbM*e",
        "3L$(3L$",
        "Z@1?~@uc ",
        "4?j+l",
        "W.q|q",
        "L$H3L$43L$,3L$",
        "WFq?wh",
        "Jr)Dz",
        "uxro8",
        "zGQII",
        "lFl1c",
        "D$(u43",
        "ZlS5b ",
        "f% &]@",
        "Sgqw?/",
        "qNY&?",
        "#)e-po",
        "Cannot write a 0 size RTP packet.",
        "To remove Check Point Endpoint Security you must provide a password.",
        "D!T!X?uuw",
        "^_=qx",
        "0 0$0(0,0004080<0@0D0H0L0P0T0Y0]0l0p0t0x0|0",
        "Command failed: %d",
        "9 9<9H9",
        "]~yI@",
        "T*bvA",
        "zUVX\"",
        "}#WHek!yk",
        "O+9?1",
        "sLQSP",
        " f`Ac",
        " 0xce",
        "q*zmw",
        "9~u6_",
        "Remove temporary installation file directory",
        "4R9#\"' ",
        "iv/|$",
        "2,f ]{,>C",
        "PKCS7_add_recipient_info",
        "AES-128-CFB1",
        ":,:4:D:L:T:\\:d:l:t:|:",
        "-\"cx.'",
        "c4:<u",
        "%tPWL",
        "'LO.}",
        "|+m81",
        ")I3Xk",
        "C-PjWW",
        ",76x+h",
        "I?XBZ",
        "918$Z,",
        "Too many users",
        "{L?ud",
        "4a?vD",
        "FhDC!",
        "mClCUc",
        "6Z$}H",
        "DH_BUILTIN_GENPARAMS",
        "4/4[4q4",
        "K`TnY",
        "j.hpb",
        "Tlt8B:s",
        "QOnWs",
        "*tI=+",
        "yxLM?",
        "a}0!_",
        "jBwMJ",
        "TqBa~:{\\",
        "nl-nl",
        "1GpG<",
        "Y~A0G",
        "_M^^G",
        "Y\"|QX",
        "pZX-<",
        "ctx->buf_off <= (int)sizeof(ctx->buf)",
        "uCSq)",
        "4*5C5",
        "=-=8=",
        "@oz:_",
        "5 5(50585D5d5p5",
        "\\q:R#",
        "Vb)*_",
        "sI!c4C",
        "N/NONoN",
        ":!:*:K:k:v:",
        "VhPD!",
        "XrlrH^Y0",
        "Y1_Q*",
        "10|'%",
        "/B8zQ",
        "!_#1Z",
        ";b/i0",
        ",gkhY",
        "gD:(p(",
        "M(hd?_",
        "bR<oK",
        "LSs%#",
        "-aJ?d",
        "rnl4CP",
        "#`(\"?q0",
        "6$6,646<6D6L6T6\\6x6|6",
        ":\"`!$9",
        "Y)4]{",
        "; .M;",
        "6,686\\6d6l6t6|6",
        "!kc+C",
        "aZ3/v",
        "LiW?e",
        "digest and key type not supported",
        "@gm:(",
        "ceM?RFbD",
        "C`.p+k0^",
        "9\"<64r",
        "Tiry(",
        "S[#u;I",
        ":rDQ?",
        ";0^BK",
        "*s99g",
        "/U/m!",
        ",^wXw",
        "bI#csA",
        "Z4#;9H1(L",
        "34']{",
        "f58>.9G",
        "M$#0]",
        "zN{B=T",
        "win.9x.me",
        "z=e[y",
        "Kk{>n",
        "q2]#IR4J",
        "tgG\"K",
        "24S~W",
        "|]Euap",
        "HUU~j=",
        "u<j}hp?%",
        "vjrg$",
        "EC_GROUP_get0_generator",
        "UTF-16 string is too big to be converted to UTF-8",
        "4'4.4E4u4",
        "MQ,G;J",
        "b:J\"H",
        "Proxy replied OK to CONNECT request",
        "8 8$8,8D8T8X8h8l8p8t8x8",
        "ohe17",
        "(2>c^0",
        "1~(,0,c5 /",
        "0%?2i4",
        "Starting protection",
        "7B8{8",
        "r7`B[",
        "Ac\\rs",
        "EPWD is running. Trying to stop Watchdog service...",
        "# %B~",
        "ignoring failed cookie_init for %s",
        "AddDataClient",
        "^C(vW",
        "FQM`x",
        "LZcK&",
        "&8,zb",
        "?u'};",
        "<-p1Tb",
        "hy<#E",
        "4 m`5",
        "idAL5",
        "6)`B-A<",
        "k(7*F",
        "0L0X0",
        "- Attempt to initialize the CRT more than once.",
        "^/=.++",
        "PFCMPEQ",
        "V!VYVhV",
        "o1#UK",
        "{|_j\\",
        "}B^_3",
        "Z{/\\8",
        "rFf;u",
        "8`AgR",
        "xFh(_",
        "?IT$7",
        "zVfHq",
        "RaO{!",
        "455A7T7q7",
        "B~=<,>m/",
        "EVP_EncryptFinal_ex",
        "M24C,",
        "*ZVg`",
        "KTh,]tb",
        "a886.",
        "jw[pB",
        "L$@^][3",
        "XgnH4",
        "pI@\"!b",
        "8/,sP",
        ":{l+s",
        "kYxRI",
        "BjXBr",
        "aNr3`1m",
        "u/WSQV",
        "3Ardf'",
        "failed to get max length of string",
        "D;M5+8",
        "&&}]Q}P",
        "Iv I)6R",
        "%%%02x",
        "ssl3 session id too long",
        "Go\"zJ",
        "<\"=q=",
        "LocaleNameToLCID",
        "VSWKJ",
        "bKw40",
        "6mR*3",
        "OGK5e",
        "84:ac",
        "hsS\\o",
        "CMS_SharedInfo",
        "}J,,&}",
        "k|'-l",
        "UTF8STRING",
        "RUgg*T",
        "S9j!e",
        " ~GcN(",
        "bhYDo",
        "qzdl/x",
        "dKD,{",
        "*^r9$",
        "dFu3P=",
        "i\"$g`Ud",
        ".?AV?$clone_impl@U?$error_info_injector@Vtoo_many_args@io@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "f@h8m$M",
        "URx%Sz6",
        "twI)^",
        "Failed to MsiRecordReadStream upon receiving the buffer size (%s section)",
        ".?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@",
        "*t3K}",
        "A +A,",
        "Je<E`",
        "]QREZ%d%",
        ";v}R *\\",
        "8W@u%",
        "e<jtu",
        "-p-Hg",
        "f4/czU",
        "VSInstallerLogoffEx: failed to get client. ",
        "XeS-%&{}_YNZ`",
        "&=H0$",
        "]We>^",
        "Global\\",
        "&);,F4l",
        "DZ^:.[",
        ":r}Sd",
        "S\"QIT",
        "<-;;w",
        ">p~Wcs",
        "Uqs[}",
        ":jH+I4\"`",
        "u:jk}",
        "@i.M2",
        "a[qpd",
        "H^ EX",
        "Kernel32.dll",
        "lO>R>",
        "$gFAy",
        ";3;O;k;",
        "*HZbV",
        "GXX&S",
        "Found cached EPS installer %s of version %s",
        "Rg|DkA",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\featuretvdriver.cpp",
        "^!%f+",
        "#S7mo",
        "2Y%0RW",
        " h_d6",
        "OS.dll",
        "PjB|<s",
        "bnp).",
        "zMK=2",
        "[I*7H",
        "-zOnp`",
        "H}HE$",
        "# <ry",
        "HoyV'5;",
        "tbUew",
        ";_^[Y",
        "'ou8o",
        "AT BcR",
        "@^QB>=5&",
        "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384",
        "eV:E&m4@",
        "(282H2L2\\2`2p2t2",
        "z3aiU",
        "e`}5A",
        "EvC-A",
        ":7F 9|v",
        "<uHI?/",
        "htK&e",
        "zD3vUW#",
        "{3)#[",
        ";#;QQQ",
        "Hotz\"",
        "m?[h.p",
        "wH!e8",
        ".\\crypto\\x509v3\\v3_bitst.c",
        ":\\$ ,",
        "3B3k3p3",
        "pt\\}8",
        "u#Vh,",
        "8-9F9U9y9",
        "f9~2k",
        "zJynp:",
        "CB2ng",
        "oD'}~",
        "qDncky",
        "*7/O@",
        "(!?Ct",
        "j0Z9^4t",
        "FWtn,",
        "w> Pw",
        "z94@,",
        "_:5y-",
        "Connected to %s (%s) port %ld (#%ld)",
        "~@uJ+",
        ">pX5d",
        "`:R]z",
        "q7E~u",
        "SetSC_UIFRAMEWORK",
        ":29~c",
        ".?AVTransmogrifiedPrimary@details@Concurrency@@",
        "1,1L1l1",
        "W[pq}",
        "FQ|K=",
        "6,s3L",
        ">fDl#",
        "]W_gH",
        "PWD_TOO_SHORT",
        "yBGQt",
        "jjh,B%",
        "unimplemented public key method",
        "HKLM\\SOFTWARE\\Microsoft\\VSTO Runtime Setup\\v4R\\VSTORFeature_CLR35 not found",
        "Address not available",
        "9-959d9",
        "alg_section",
        "dYm=\\",
        "swg(8N",
        "GetCustomerNo()",
        "EvtQuery",
        "CMS_uncompress",
        "E`;E,uO",
        "POPCNT",
        "0?]qn+6q",
        "int_field8",
        ".?AU_Chore@details@Concurrency@@",
        "Bh9Gg",
        "c(\\sd",
        "Failed to restore key from ",
        "V2I_IPADDRBLOCKS",
        "z1\\i}",
        "JLCJ^^<",
        "3vs2e",
        ";/a>q",
        "WIN_BUILD",
        "I~Y\\eAAZ[eeAv",
        "cV4j'",
        "@`0ON",
        "+\":\\>fko",
        "+4sgk",
        "52%JMP:Y",
        "WTSEnumerateSessionsA",
        "lNqv?v",
        "0Nh*\\",
        "~MeZw)",
        "#/]1Z",
        "e<FWZ4",
        "zo(fG",
        "yy^c)",
        "KhoqD",
        "O14of",
        "%)Vy7l'",
        "8>;NAOJyH6G",
        ")YyXU",
        "%08x: ",
        "$|2= ",
        "BW* D",
        "$FHfEz",
        "*vsx*",
        "j2^.s5",
        "J8;j7",
        "Om&?\\",
        "failed to process timeout from CustomActionData",
        "(Z)%I",
        "_Kc/O",
        "Tg6Ot",
        "cd9/6",
        "&*1zr",
        "7EMg[7",
        "j&a$tO",
        "cY^#~",
        "9]o<t:",
        "3k8EE",
        "9zI9#k",
        "=H=R=a=p=x=",
        "J{vo%&",
        "failed to get second failure action type",
        "8!8A8o8",
        "X\\2w9",
        "|,hZ10fX",
        "5Vo9rqJ",
        ":T*\"5",
        "floor",
        "=)#2F*",
        "setct-PANData",
        "?8?X?x?",
        "l44nf",
        "$ij@u",
        "y*H[L8",
        "#0(0]0b0",
        "r@: d\"GC",
        "Ru+Q7~",
        ":ZN%M",
        ":B u#",
        "(VSM|j",
        "qHJle\"",
        ";Cyrr%",
        "Fi+t5:*",
        "#hHc?",
        "bE{ 1",
        "_=*:e",
        "g#1 w",
        "yCEPob",
        "p@>Fn",
        "l;`; ;03H}0>",
        "jBj}j",
        "NB:@:",
        "F8Duo",
        "2T2Y2`2e2l2q2",
        "kf:=5",
        "V\"</&",
        ".|eJ[",
        "b <= sizeof ctx->final",
        "Enter PEM pass phrase:",
        ",qF;#",
        "026`f",
        "5Sy\"4",
        "a2=7Nw4h",
        "13&|\\",
        "cgik&",
        "(D-zk",
        "k-E`f",
        "c}s]}",
        "INSUFFICIENT_DISK_SPACE",
        "et-EE",
        "Q}p9l",
        "?#3XUN",
        "+Zx;=",
        "gbC}{",
        "\"lRJ((\"8",
        "}u>p4",
        "l$PSU",
        "\"rHJF",
        "PY>-m",
        "cVzg&",
        "=^UHO*",
        "w nj`A",
        "RSDS1_",
        "CryptEncrypt",
        "@#zQ!",
        "?VQ.,",
        "<5<V<]<j<}<",
        "-)T#c",
        "KFd 3\"g",
        "2v2|2",
        "Failed write property",
        "g~Z\\15",
        "g=DrV",
        "\"nuk\".z",
        "sHd. ",
        "OI).2",
        "X&..,",
        "7D^&/h",
        "4<4Q4q4",
        "192p2t2x2",
        "yg)zIk",
        "4xI<oDF",
        "G.M(*",
        "ASN1_PKCS5_PBE_SET",
        "not enough data",
        "jAZf;",
        "okygf{]S",
        "A2)\"b",
        "&U^,b",
        "n4C]b/",
        "|qZ-5",
        "D0H0L0P0T0X0\\0`0d0h0<1Q1v1=2f2",
        "e}9^V/",
        "|M}\"`",
        "!K~\"^U",
        "3;3Q3c3j3",
        "(1e^h",
        "SiDI3",
        "invalid cmd number",
        "elkn+",
        "P(#pg",
        ")\\(O'",
        "x#_KoZ",
        "tm%Qc",
        "SNOqjZ",
        "Fq8#N",
        "SDL should be installed",
        "u-jAXf;",
        "bQdx2",
        "D'PE>",
        "F?U\"5",
        "2EKV!",
        "cL!>_",
        "5`kL~",
        "\\brdrs\\brdrw10 \\trbrdrh\\brdrs\\brdrw10 \\trbrdrv\\brdrs\\brdrw10 \\trftsWidthB3\\trpaddl108\\trpaddr108\\trpaddfl3\\trpaddft3\\trpaddfb3\\trpaddfr3\\trcbpat1\\trcfpat1\\tblind0\\tblindtype3\\tsvertalt\\tsbrdrt\\tsbrdrl\\tsbrdrb\\tsbrdrr\\tsbrdrdgl\\tsbrdrdgr\\tsbrdrh\\tsbrdrv ",
        "Y0]0a0e0i0m0q0u0",
        ")9]-C",
        "17MBK",
        "Gk78f",
        "RJ$)a",
        "\"YK1\"",
        "(ls>R",
        "2%m@CX",
        "v!j\"X_^[",
        "FhX}#",
        "ADH-DES-CBC3-SHA",
        "\"+R3?",
        ",PQVS",
        "s->sid_ctx_length <= sizeof s->sid_ctx",
        "I[q+b",
        "B!..Qe$",
        "es-ve",
        "5 f61",
        ":rW4!",
        "nsJEbW",
        "iTlm3aW8",
        "kMm<T",
        "3mca3",
        "l$ S3",
        "0&PNiC",
        ")9d?A",
        "H55RC",
        "r.nv1vC",
        "1))Mi",
        "xU<3^",
        "PI8!EJ",
        "CMS_RECIPIENTINFO_KEKRI_ENCRYPT",
        "[XhyX",
        "o,~~2",
        "Q<E|\\7",
        ".\\crypto\\ec\\ec_print.c",
        ">;oq-",
        "q+p;Q",
        "z`VY]",
        "8W_Wy",
        "=pdN{",
        "F)+Tr",
        "unsupported name constraint type",
        "t2tru",
        "zpb+Y",
        "\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority30 \\lsdlocked0 Intense Quote;\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 1;\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 1;",
        "l`8R(\\",
        "rMaiAO+",
        ",&\"T\\?3Q",
        "7'8w8",
        "k%3=b4",
        "\\8=p5",
        "u\"Scn",
        "D$\\SU",
        "888@8N8[8i8",
        "4$4<4L4P4`4d4h4l4p4t4|4",
        "QzPINh",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 8}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11303137 .2 }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14296673\\charrsid9533499 The Hardware P",
        ")`{0$@",
        "a902P",
        "EtGbz",
        "q[/%Z",
        "no password",
        "#*/D}",
        "nf5_Q",
        "^KzPk",
        "SpawYDA",
        "ZMR@E",
        "<22B222222",
        "#\\9C?u",
        ".;(F;",
        "REO22222222222222222222222222222222222222222222",
        "@n`-Z[",
        "\"fRG=",
        "Nn&3;",
        "[:u>q",
        "l77=_B",
        "clienthello tlsext",
        "atlTraceControls",
        "isSDKUpgrade: Old Kaspersky SDK was detected.",
        "3a8G<",
        "B\\Kyg",
        "8WY*\\",
        ";$4Y#",
        "UpdateVsConfigXML in Zonelabs",
        "(lpI]",
        "gNpZ|GG",
        "> VTnq",
        "8!8*83898",
        "A,#D$",
        "00080h0",
        "IT:%Ht~",
        "9O`u79Gdu2",
        "xAa`^",
        "xtzhO&",
        "~g.?7lH",
        ">KT07",
        "9!9N9",
        "M' <{",
        "daiXBt",
        ">g\"XY",
        "[^f_d",
        "5 5,5A5b5",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products",
        "_'SJ0",
        "bad reciprocal",
        "e-UzR",
        "tTRQh",
        "8~Li ",
        "NED^!",
        "TyWia",
        "|}Aa6",
        "8# LT",
        "d$0_^[]",
        "2-3N3",
        "?J?`?p?",
        "=K:cs",
        "M?LuX",
        "SVWjuZjiY",
        "L\\vsinitproxy.dll",
        "jKM1{",
        "d[3),,",
        ")D!vt",
        "|\"h[D",
        "3B3{3",
        "requireExplicitPolicy",
        "tG,AZ\\",
        "parameter encoding error",
        "=8=D=h=",
        "5%5o5",
        "only tls allowed in fips mode",
        "v2\",7",
        ".?AVpDNameNode@@",
        "QFVdF",
        "7xNx\\",
        "(u.I(",
        "QID@A0r",
        "Vezkm",
        ".?AVimproper_scheduler_attach@Concurrency@@",
        ".?c4i",
        "YK6UKr",
        "_KLqZE",
        "RegisteredSerial",
        "H,%0@",
        "(&'Ry",
        "BXytR",
        ":^5zM",
        "7Y8Y9Y:Y=Y>Y?Y@YBYCY",
        "nvfLR",
        "-??gGB",
        "^1#%I",
        "VacZqC",
        "H3[0%",
        "caseIgnoreIA5StringSyntax",
        "TS_RESP_verify_signature",
        "-090H0q0",
        "5 5$5(5,5054585<5@5D5H5L5P5T5X5\\5`5d5",
        "d8x\"f",
        "w^Ih$",
        "RegQueryValueExW",
        "This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.",
        "33T5h",
        "hG40jD",
        "@:'b+",
        ".?AVscheduler_not_attached@Concurrency@@",
        "1u5}7@8",
        "LX,D=$d",
        "[%\"q'",
        "\"&7$v",
        "vMIW%%I",
        "36K_B",
        "7$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        " 0Y0=1C1P1W1g1",
        "G2AYO",
        "BJ7:c`[o?>",
        "+YXZq",
        "4a%C:",
        "bL\\=KhU",
        "&HesKh",
        "_&fb0",
        "cAla|",
        "Set DAApiDllPath to %s",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{CA7FDA46-DFA8-4748-8F2E-8864E545735B}",
        ".?AV?$basic_memory_buffer@D$0PK@V?$allocator@D@std@@@v8@fmt@@",
        "\\zonelabs\\zlel.exe",
        "0:4bV",
        "N1^YcT",
        ",,0V_gTXe",
        "566^6",
        "P\":Lyr",
        "%s does not exist",
        "CrHjC}",
        "9rl&Ba",
        "-=uHNdF",
        "jAjzj&",
        "Sai?*",
        "es-cl",
        ".>HKbV",
        "ua5gu",
        "GetMessageA",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\WindowsSecurityMonitor\\1.0",
        "t'S? ",
        "_)q`z",
        "=B|s'7",
        "@:I<un_X",
        "'0G0]0",
        ",'sB2",
        "^+59r6",
        "es-MX",
        "Bo]^I",
        "V<.Bd0",
        "zO2jc",
        "Qhdbb?",
        ".#,xW",
        "OCSP_CRLID",
        "INSTALLPASSWORD",
        "i%_1(N",
        "zr&<t",
        "[^`\\C",
        "SuA!?",
        "SELECT * FROM Binary WHERE Name='%s%s'",
        "kimim",
        " )uDZ",
        "6\\7h7",
        "UYUgV",
        ">q>=?S?",
        "$%pJD",
        "4>5Y5",
        "1'2D2L2q2x2",
        "\"zKqQH",
        "8k'Ox",
        "FGJ{6V8!",
        ";$;+;S;[;e;",
        "Q\"<(y",
        "9 939N9S9",
        "api_ms_win_crt_filesystem_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "0\\{&$",
        "FbRc/{",
        "3c$)\\vR",
        "=r^%g",
        "^qfG8",
        "e^V-F",
        ".?AVContextBase@details@Concurrency@@",
        ":/@QG*",
        "d&dU-~",
        "FBl#*",
        "3C4{4",
        "6@=]>a4ey",
        "Given file does not exist",
        "]W?Vi",
        "F\\CZn*",
        ")k<=b",
        "u}HL'&^h",
        "5(6H6T6\\6t6",
        "SQSh?",
        ";!<O<\\<",
        "wrong tag",
        "Okv&ip_",
        "installMsi",
        "cl8-o",
        "'V\\fK)",
        "RPWKz",
        "AsJp0=",
        "G@9_8u",
        "F P~L",
        "2 2$2(2,2024282<2@2D2H2L2P2T2X2\\2a2e2t3x3}3",
        "gn1<r",
        "4lOe.",
        "JA}WvA#",
        "={j1#",
        ":$:(:,:0:4:<:T:d:h:x:|:",
        "3Mi)&",
        "1h _1OE",
        "a]T#;",
        "=t\\}*G",
        "S3`lC",
        "CPEPC_PLAP.dll",
        "<hk9>",
        "c du>",
        "r7!v8",
        "<D%(*",
        "It,DC",
        "NEW CERTIFICATE REQUEST",
        "/M![)",
        "F THIS AGREEMENT, YOU MUST RETURN THIS PRODUCT WITH THE ORIGINAL PACKAGE AND THE PROOF OF PAYMENT TO THE PLACE YOU OBTAINED IT FOR A FULL REFUND. ",
        "SOFTWARE\\CheckPoint",
        "!!iU4",
        "dh-cofactor-kdf",
        "szFriendlyAppName",
        "YRj)i",
        "O ~6o",
        "DataThread()",
        "(HXE&",
        "-O/l?@",
        "C|9Uf",
        ")Z-7|sA",
        "9.9?9K9",
        "Mxyuue9",
        "PHADDW",
        "J\"(?l+A",
        "{5t2~",
        "*05d{|",
        "l>9S`=",
        "`&H;}/",
        "!b4Fe0",
        "mac string set error",
        "-QPL3~",
        "tfKjykcg]",
        "S~mh\"",
        "-I-fAm",
        "7(T=~",
        "Check Point VPN upgrade product code is not found in the registry",
        "YN@B%",
        "E~{,N",
        "#|T^N@",
        "CVjs>~",
        "huGLk",
        "2t3.H",
        "U;HZl)VO~",
        "Failed to allocate buffer for %s file",
        "LC_MONETARY",
        "\\A:9v",
        "c2pnb208w1",
        "0\"1'141N1^1d1j1",
        "Qa*vS",
        "869E9e9",
        "AM@S_ ",
        "U{Z`F",
        " R8L@",
        "Y0ZpZ",
        "7s1Pc",
        "RSA_sign_ASN1_OCTET_STRING",
        "!lF[Z{?R",
        "dsfasvc",
        "xeP)!\\",
        "D$4PVj",
        "i-)bg",
        ":  does not exist ... can't set DW value",
        "WriteSuccessReg:  WriteSuccessReg started.",
        "t<2!C",
        "4&SwL",
        "I,\"(1",
        "1S2]2X3",
        "tc-c;1",
        "< <@<L<l<t<",
        "BIO_new_NDEF",
        "[+68l",
        "(T82^",
        "|quFBg",
        "=i'/_",
        "Non Repudiation",
        "I^izOn#~",
        ";\\$ls",
        "j0CGD",
        "x U-<",
        "f9.{nD",
        "O&L P=",
        "unregisterPlugin;",
        "ds]mIk",
        "invalid type specifier",
        "<)=T=",
        "`L-F!",
        "&O|]e",
        "D[zBK",
        "xNcGy",
        "IX/=xgd",
        ":?uRL",
        "afmN`",
        "E,5'h",
        "OjmHs2",
        "PKCS12 routines",
        " ;YK'z",
        "B8Dr5",
        "]nu3H",
        "Vx;&J<P",
        "ZA#0}",
        "remove old KAV drivers.",
        "s[g*I",
        "thv\"K",
        "eQ7+vV.)",
        "WN+(w",
        "]R1<#",
        "43Hf?IF*V",
        "4 4L4X4",
        "Rg]w'",
        "cpbak",
        "MODULE_LOAD",
        "WCIGW",
        "buffer too small",
        "TFTP: Illegal operation",
        "555V5r5",
        "\"3WFT",
        "2 2B2T2",
        ".?AVFreeVirtualProcessorRoot@details@Concurrency@@",
        "PSUBQ",
        "80X0`0l0",
        "9/.|C",
        "1-2}2",
        "k?R4^v",
        "nNJ=pbQ",
        "@4zAPD",
        "s\"Yjg",
        "failed to schedule ExecXmlConfigRollback for file: %ls",
        "j'JO[",
        "S@Rcj",
        "O7m&~L",
        "C{uaG",
        "p&h- ",
        "B(\\<iq",
        " 0x46",
        ",-OwO",
        "u,lGL",
        "d?Lg$",
        "\"PN G",
        ".v=ew",
        "VF1&`|",
        "?(?[?j?",
        "iP/rCf",
        "]xBWF",
        "id-GostR3410-94-aBis",
        "]*b[z%>",
        "ZR\"t-",
        ">+>7>C>O>[>g>s>",
        "-~FLe",
        "uTX4TX",
        "O[=y<W&",
        "|VWj=S",
        "1_=&j5",
        "`adjustor{",
        "<=upG8",
        "&w:zi_",
        "Fhg16a",
        "YL}KA",
        "@.X,D",
        ";rdeh",
        "it-it",
        "#KQH0P",
        "#>G>#",
        "unknown trust id",
        "VerifierFlags",
        "\\tvr!",
        "D$<WP",
        "TXRaXB",
        "mE)<(A\"^8D",
        "bo3yCO",
        "aj0W<",
        "2{veYT",
        "=#=T=d=",
        "4]zXf",
        "<8=Y=h=",
        "9(s&k^@",
        "4p5N6Y6d6",
        "}5ScQ",
        "DIan&8BX",
        "']r^e",
        "'Ji.K",
        "5*\\Kws",
        " 0x86",
        "K}bhdHJ",
        "< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\\<`<d<h<l<p<",
        "E6hqzK",
        "j,Yf;",
        "b,`a  ",
        "P5T5X5\\5`5d5h5l5p5t5x5|5",
        "8X<x]",
        "*&!Rm",
        "C5<Euf",
        "ms-MY",
        "zFU-C",
        "}ZW${",
        ">zH(\"Iy7",
        "SHGetFolderPathAndSubDirW",
        ".L&X`0",
        "eiV6f",
        ":#[Z{",
        "\\mD&x:",
        ">_.-r",
        "!G5Z/M",
        "s7P W",
        "35@`C",
        "Can't get the size of %s",
        "D$XPjr",
        "/B8lV",
        "R!QLB",
        "3c3m3",
        ":B;L;Q;q;{;",
        "]WP2c",
        "@a#/U",
        "@$i:`",
        "EVP_DigestUpdate failed",
        "7S~=.",
        "!|.gh",
        "/;fG[O\"|&v&",
        "-f 3mk",
        "\\Y1:*",
        "lf}r2",
        "(HTBg",
        "iwjm<",
        "%s does not exist.",
        "Home Single Language",
        "l$z}u",
        "343?3Y3u3",
        "%nW,z",
        "secp256k1",
        "dN}*=",
        "WyzAZ;",
        "VM1dN",
        "hSM%yd n",
        "<O(&$k",
        ">1>Q>v>",
        "1+_lT",
        ":6:g:q:}:",
        "B41)S/u",
        "t$$Pj",
        "0&1+1V1[1",
        "XOAUTH2",
        "Check Point Software Technologies LTD.",
        "hpF4d",
        "En>m;u",
        "j27 ;",
        ":Glvzs",
        "u%P1E8",
        "e(=@a",
        "9X`jR",
        "F[iQZI",
        "5$575",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  90",
        "IP address mismatch",
        "D$$PWV",
        "5Adv(",
        "D$(+D$",
        "2MjIm",
        ",QH'P>",
        "nhOn*Z",
        "e|Fy[",
        "CleanUpInternetLogs:  CleanUpInternetLogs started.",
        "t$v%c",
        "]&g''}",
        "Bx_4\"",
        "!TlTeJ",
        "Yzy|~",
        "Va%Mi0i",
        "),ES0",
        "&XQ\\E>",
        "%020]0",
        ",avGl",
        "[#Siy",
        "#]`A/3",
        "@p]`\\",
        "*9{|E",
        "2(J2i",
        "e8n0}",
        "J))7D",
        "6.6[6",
        "l(+5'|#",
        "oodQJf",
        "1 \"m~",
        "2Gujc",
        "P3V/D",
        "wF 0!0",
        "v3GD&_",
        "?k%.RB",
        "7J7c7",
        "13$DC",
        "aBT#)",
        "6'G}*",
        "t!f;U",
        "{`{b{d{f{h{j{l{n{p{r{t{vyx",
        ".t1o19",
        "a ABT",
        "4'4@4Y4r4",
        "]pR''",
        "D$0PQ",
        "layLf",
        "]lxU;W",
        "gRc}9",
        ".\\crypto\\cmac\\cmac.c",
        "5$5D5L5T5\\5d5|5",
        ":7;I;[;m;",
        ".g{X[i",
        "Internal error: Unexpected packet",
        "&~H0p",
        "fb-%[O",
        "[QhQOhqu",
        "C+dx#/",
        "r!2b#N",
        "~Zlb[",
        "NI)\\U",
        "MOyN.",
        "u2Vj@h",
        ">Vr5d1",
        "031R1t1",
        "dwMode",
        "#L$,#",
        "pu('{G",
        "2(( !@",
        "O|_lz ",
        "[Ly/KOI",
        "M_:vP",
        "T5O(*",
        "1&202e2o2T3X3\\3`3d3h3l3p3",
        "gF`7)y",
        "F'[Y:!",
        "9u~\\8,(",
        "<md.v",
        ": >( ",
        "Fv1Tv",
        "v9QhP",
        "em\\>\\",
        "TrueVectorIF::BanProtection() succeeded.",
        "b*S\\I",
        "7(70747@7H7L7X7",
        ".YQEA",
        ";uLqR`",
        "Client key exchange",
        "? ?(?4?<?T?\\?t?|?",
        "raB3G",
        "/~M;Ue",
        "bqe} ",
        "uaQY(",
        "]J%X+",
        "5Q61)A",
        ".'\"BTI",
        "$~xXn",
        "*[GJO",
        "b7kus3Cdz",
        "u/4J>w",
        "L|Y; ",
        "90d)v",
        ".yO79",
        ";3;\\;j;q;",
        "j`w]?",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall",
        "P,mNi",
        "PreInstallCheck:  Check for other installers.",
        "223~3",
        "T Tt[",
        "SetUmsThreadInformation",
        "Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing",
        "Qpo3Kn",
        "Couldn't bind to '%s'",
        "O{g5X [P?",
        ".RebootRequired",
        "aLo^d[",
        "WsR=-",
        "t$ hD",
        "@8Dp>c",
        "c&&&vM",
        "1x}'x",
        "S\"Py2",
        "U39S<",
        "4x5clX",
        "Q}j&k",
        "i~6eq",
        "\" failed",
        "QC>}]",
        "This is an S/MIME signed message%s%s",
        "^PQQQ",
        "QOMrE",
        "3A3I3N3a3u3z3",
        "G5 &/d",
        "7B(fh'",
        "48Xgdv%",
        "Ge\\pL",
        ">y:-6",
        "no signatures on data",
        "f the Product will be uninterrupted or error-free.  Check Point does not guarantee that the information accessed by the Product will be accurate or complete. You acknowledge that performance of the Product may be affected by any number of factors, includi",
        "}:Iv.8*W",
        "t9.~t",
        "H*qD1",
        "ZX,CR",
        "Of;Y-",
        "U]jv+",
        ">??z?",
        "2$242@2",
        "WOI[\"",
        "]JMfs",
        "Ku:\\,",
        "T4O(#i",
        "z#RDw",
        "Y1HBv",
        "6nwIz",
        "U%GzX",
        "*k('z",
        "7dnhvS",
        "CeQ4g",
        "jqjdj!",
        "DoBbq",
        "CAMELLIA256",
        "\"%svna_utils.exe\" -d -ap vna dev remove_ex \"%s\" cp_apvna",
        "e~Y_6",
        "Cn-6 ",
        "uSoftware\\Policies\\Microsoft\\Windows\\Installer",
        "GZ1!^)",
        "2p3u3",
        "=R>o>",
        "%s %s",
        "5($!k\"I",
        "-fcw{A",
        "*3:3I3r",
        "W=%?;",
        "=(=<=D=L=X=x=",
        "Tg)dC",
        " public key hash: sha256//%s",
        "eE_Sj.",
        "N2|$F",
        "2xZh=",
        "\"_~I7",
        "%02X-%02X-%02X-%02X-%02X-%02X",
        "\\pV66",
        "['Lb:3%W",
        "?56WTZ(q",
        "R`a;7",
        "J\\^}f",
        "%(]0J",
        "O%q'%[",
        ",nF7&C",
        "dg;}\"",
        "Created key ",
        "HandleError:  HandleError finished.",
        "2!2Y2",
        "jjjlj%",
        "`XnVB",
        "*1#jO`",
        "l%C@(",
        "XW=?'",
        "H</9p",
        "r/f;E",
        "XX0?h?",
        "[}.Ty",
        "Extract dll to patch old MSI",
        ">]IDATx",
        "g]]!+",
        ".\\crypto\\dh\\dh_lib.c",
        "mwfU>T",
        "l\"[lb",
        "20UC1|jv(",
        "L$T_^][3",
        "0/0R0l0",
        "> >(><>D>L>\\>h>",
        "id-cmc-dataReturn",
        "-exZL",
        "kZ>e_",
        "K[k:(z",
        "xhxgQ",
        "B3KE<",
        "y^kSON",
        "ArchiveLogFile: Error %d reading file %s",
        "r4GMK",
        "> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>|>",
        "S:s-R4<",
        "@i9#y",
        "Iu[8*",
        "jCjrj%",
        "y8Sh`",
        "|@-iJ>",
        " MSVC32",
        "A2Q2a2q2+3d3n3q6",
        "0p@-u",
        "Lot]k",
        "HaGRB",
        "U*y;9U",
        ":7;J;",
        "\\1xAVjl",
        "bUPA*",
        "pPM>3",
        "GHqa3:",
        ">4l?$",
        "'\":%G-",
        "kx{$kco",
        "_n]I9]0",
        "Ks=;U;`;",
        "F,aM-",
        ",,!E2L",
        "67tXH",
        "=\\kPd",
        "SystemTimeToFileTime failed to process end time of the driver upgrade. Error code: %ul",
        "FZH>LH",
        "5.ze7R",
        "VmWmXm",
        "rqnQ}",
        "{lQf>b",
        "G;pxJ",
        "[X)Wr",
        "/[I@<",
        "(YDs@",
        "%-K}I",
        "LW]O<",
        "content types",
        "SSL_write",
        "oZVh_P#",
        " xB%&W",
        "{pWS|",
        "D1`jc",
        "-m]Cn",
        "qmSrY6",
        "%n%J%N%R$XJ",
        "NV8$m",
        "Dp$A[",
        "ZCXS+",
        ">CP~Y",
        "5E5Q5Y5o5",
        "=&VD?",
        "t\"2>w",
        "0$0,080X0d0",
        "_<h:^",
        ")m_%~",
        "'5IME",
        "4Dg\\%",
        "m[Qiy",
        ">VMIrW",
        "Yik[m",
        "I6JL$S,",
        "__swift_2",
        ";*VJe.",
        "wZKf4d",
        "11M=x",
        "holdInstructionReject",
        "Prime:",
        "5V5{5",
        "!JbMA",
        "m8xR~;",
        "UpdateZoneAlarmXml:  Not all required files are found, ZoneAlarm.xml will not be updated.",
        "G8CMO",
        "~3f!j",
        "M$5~R",
        "mFNjh|76",
        "readdir",
        "4$4,444<4D4L4\\4h4p4",
        "94W\"r",
        "?@_`z",
        "2C2U<",
        "a,\"3>",
        "zFcNdA",
        "eK\"1Md",
        ">Pn-dE",
        ";E;l;",
        "GhtX&",
        "$oEDE",
        ":j`2G",
        "9tjkL",
        "failed to get security descriptor's DACL - error code: %d",
        "vcd0m",
        "47HZCP",
        "?z4Ic",
        "^'3q?",
        ",)(?z",
        "w]6,j",
        "u^9^\\t/",
        "WakeConditionVariable",
        "6'6G6<7q7",
        "Gt-Y)(3",
        "SU%pO",
        "JTup;",
        "y^XME8",
        "U.UZ*3",
        "[%o8(",
        "X[AT{",
        "ed]{M",
        "P|8Rx",
        "?N.CG_)m",
        "member",
        "0j9N5Ja",
        "^X_^]",
        "3%.q8",
        "}SCLRw",
        "i/9hL",
        "3nl=5",
        "TSMeA",
        "jdefK0m5",
        "lQ*E+",
        "A d|.G",
        "969N9q9",
        "%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%s",
        ";3<@<z<",
        "@Sltf",
        "KN]?C$",
        "83'Fd",
        ";A$v\\",
        "Ne]f.",
        "?\\?s?",
        "1a1q1",
        "`C`?D",
        "AES-256-CTR",
        "ASIDENTIFIERCHOICE_IS_CANONICAL",
        "a~Hnx",
        "%c%c%c%c",
        "d2.g9",
        "!L*V|#",
        "`l^GdNMp",
        "9a:z:",
        "7>+G&",
        "(li![!",
        "?ghM5(",
        "<#=v=",
        ")IMV1",
        "bg@T0",
        ",GAif\\",
        "(1(q+",
        ">uebH",
        "setTrayIconToolTip",
        "&Me$3",
        "Mc$88a",
        "8 9;9M;z;",
        ";);J;_;p;",
        "hknJf;",
        "9n{|S",
        "MULSS",
        "@?mY[",
        "x@j%Sj",
        "result too small",
        "7,7l7x7",
        ",R;U?",
        "uz$EW",
        "&d5)`",
        "='=1=;=",
        "hxj5=",
        "sipX|Pt`y",
        "<n6'p",
        "P*Mgl",
        "f~6K9",
        "Zrj7]",
        "OpenServiceW",
        "?#?(?<?",
        "?HGV|+",
        "=(=D=h=",
        "jejij'",
        "aExecXmlFile",
        "7-777Q7X7g7u7",
        "n `}9",
        "X<\"^%+",
        "y,ewVo",
        "(AmIEfn:",
        "bciRj<",
        "01161;1P1a1f1k1",
        ")A>rEov",
        "yt3z8",
        "tGfr$",
        "2C8m`Rw",
        "Yy7gP",
        "q%P^+",
        "~r44>",
        "oB^b| Xl|",
        "By$ X",
        "rsa_keygen_pubexp",
        "\\vQZmZ",
        "=<=H=h=t=",
        "#:GMB;C&",
        "6<6\\6d6l6t6|6",
        "UninstallAS:  UninstallAS() in vswmi.dll succeeded.",
        "PF2IW",
        "api-ms-win-core-fibers-l1-1-0",
        "K!HqC",
        "fao(jxE",
        "3!313A3Q3a3q3",
        "m)4=O",
        "h;tn)4",
        "sMVjx`J6l~",
        "%*sPath Length Constraint: ",
        "Dm4tKs",
        "I)wM{7",
        "?(?A?]?y?",
        ";!;1;H;\\;",
        ")VcnZ",
        "0He6L",
        "6>7D7H7L7P7",
        "&(7Ph",
        "<lgQI",
        "%FsHbH",
        ";A<O<",
        "Dbre`",
        "@2r=U",
        "RYy L",
        "|+\"B2h",
        "j_-2&!",
        "jlhTY#",
        "Ac{Z] c",
        "MlNVm",
        ";H;W;s;",
        "?x!,w'",
        "_3SPPi",
        "1G4W1",
        "DHE-RSA-AES128-SHA256",
        "{\\fdbmajor\\f31501\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}{\\fhimajor\\f31502\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02040503050406030204}Cambria;}",
        "Mk~8`",
        "r`N6q",
        "\\(~1Rs",
        "[xp@,",
        "S/Tnm]",
        "cty&b",
        "B1}Tf",
        "8G=NI",
        "1@1K1",
        "Kb+^i",
        "WSAstartup",
        ">1>M>",
        "rUA)X",
        "8_9r9w9",
        "*L)3A",
        "2M2Y2o2",
        "gS%O%",
        "icMZRG/",
        "v:PhT",
        "Can't Query ComponentId Value at Subkey %s",
        "JUh5c '",
        "SlsE\"",
        "}cKlZi",
        "Ah?_Z",
        "ZrbllM",
        ",[=B{",
        "I'\\'e",
        "qZRZQ",
        "Z$j?LA",
        "Unknown",
        "kFX]\"",
        "4i.\\R",
        "text/plain",
        "j.VeZCY",
        "YY_9]",
        "{J|#C",
        "9 9$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9l9",
        "[%d:%d:%d:%d(%d)] ",
        "hS'2j(",
        "RC6s1B",
        "VWkT<",
        "6M1jq-",
        "09rNe",
        "eX$SI",
        "~opj0o",
        "0(080@0D0L0P0T0h0p0",
        "Unused",
        "?:I}s",
        " V71I1~",
        "p>{ q",
        ":;lDt",
        "~|Cgw",
        "?|os?",
        "5!6@6",
        "V:+e~",
        "R+%'Ib;Mt_",
        "%]6Z-",
        "\\gBBL",
        "0G1M1S1q1w1}1",
        ";?Vm\"",
        "client sub type not found in registry ",
        "353m3",
        ")aIBG",
        "p%{)TIt",
        "@WWh`",
        "Qf0G^",
        "BnW/E*",
        "Rb~F^",
        "K^6Tqz",
        "invalid stoi argument",
        "/U!d6",
        "2L`wH",
        "\\$4VW",
        "NS)HIFdw",
        "tKpUCZ",
        "LM:_++n",
        "oIz!r-",
        "38UDS",
        "Ox@$o",
        "-jd[;",
        "Ss9##",
        "6VHPdj3",
        "k3uR8",
        "OOEKr",
        "%eh w",
        "wjjfc",
        "\\CKK1Kbz",
        "D_r?y",
        "qb,5v\\",
        "<b~1<d~",
        "2z=nog",
        ",m?O9",
        "Asal~",
        "BF<=j",
        "PBE-SHA1-RC2-64",
        "5e9.>",
        "H@=E?",
        "X\":RS",
        "2jFf7",
        "2doyjw9b",
        "YiNv2",
        "uunb9",
        "{/Bj{",
        "=D=t=",
        "Runtime Error!",
        "@@VSUW",
        "mf/\\F",
        "d6&|7m",
        "T$ ;V",
        "setCext-tunneling",
        "1+101",
        "U)P+)/",
        "K6\"EfK",
        "b@WX*",
        "zghk04>",
        "EPS_DEVICE.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "CRolloverMgr::CopyRolloverBlock():  zero file position",
        "9ELr%",
        "\\ap$:5[F",
        "Q-%l+",
        ",;,K,[.k",
        "=MXpw",
        "=rNkn3",
        "F;mb:v",
        "Order: ",
        ",zFqV",
        "U+;.b",
        "^3`wh5",
        "[ZUk`*",
        "Te8\\<a",
        "6AotE",
        "9;|! ",
        ">0?>?F?W?e?l?",
        "80=jL",
        "fFDk]<o",
        "_6qW\\>\"",
        "0Globalsign TSA for MS Authenticode Advanced - G40",
        "&%Ncc",
        "x509_store",
        "70x(~k",
        "cYT{Y",
        "}Xb.7",
        ">)>V>",
        " 0xfa",
        "FPf\\+~*LU",
        "q#^0v",
        "UxPQe",
        "ECDH-RSA-AES128-SHA",
        "`==l6",
        "df\"8x",
        ">0>8>D>d>l>x>",
        "7J\"n:O",
        "?B?m?",
        "L$4QP",
        "3rlXB",
        "GjSZK!",
        "g07aoaN",
        "wXSR3",
        "t'nKm",
        "c_^_S",
        "Bu,4]",
        "<Zv9< t5<0r",
        "4&e2<a",
        "Q$B@;",
        "\\UJ/vS%",
        "LFzw4",
        "DZ$=%",
        "{NINi",
        "+Wgr2",
        "Q3`2z",
        "H?i<a}I",
        "Not a downgrade:   %s to %s",
        "p.~yc",
        "^>iDO",
        "P]3*m ",
        "2*3O3U3f3x3",
        "BJO.!",
        "m214P",
        "z@Ye*",
        "7$7+727S7]7z7",
        "\\$ WS",
        "vWU>B",
        "UO]Gm",
        "NetApiBufferFree",
        "2tpwc947id6jeq6q32pwxa1jhg0",
        "FSFK$)",
        "E8)$<d",
        "M(jf\\",
        ".6zT^O",
        "L8kDG",
        "@ %vn",
        "dN`;M~\"",
        "3jLCJ",
        "lCADBi~Kz$",
        "!Bdo`",
        "teLda",
        "z>=zf",
        "ko9m;",
        "Q5k)0D",
        "o6i:_H",
        "Ux,r-HX",
        "invalid syntax",
        "6+7Y7",
        "Currently registered package name in registry: %s",
        "OB/>I",
        "X,&}7Z",
        "#NNa,",
        "R=]A]",
        ">rdPxa",
        "U7UWUwU",
        "3Z90 ",
        "E\"(!\\z",
        "I|}17`+}",
        "u@_^3",
        "7*787J7p8",
        "2!2+252?2I2S2]2g2q2{2",
        ";\\HG:I",
        "d*y 7",
        ",C&_y",
        " d=I1",
        "9SWGG",
        "gB/[@",
        "zq.a3",
        "wa~uc",
        "xHYJ%",
        "Ox;@IM",
        "hT&2H",
        "\"KndSi",
        ")K%\\W",
        "otNM.",
        "CKd{T]",
        "vC95v",
        "20282@2H2T2t2|2",
        ".\\crypto\\evp\\m_sigver.c",
        "}y``*H",
        "Nq^t,Z?\\#",
        "(l?lyc\"",
        "@_?.r",
        "-bW+}",
        "bdw6{",
        "ASN1_OBJECT_new",
        "0'H yd",
        "th)Dt^*N",
        "j&p*lB}",
        "}MI38C",
        ".?AV?$clone_impl@U?$error_info_injector@Vxml_parser_error@xml_parser@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "5H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "fng#3",
        "b3(^B",
        "=b)N{",
        "t*=E'",
        "[gNN\\",
        "_,sup",
        "2Hm[F",
        "wwe;mz",
        "<>=N=X=s=",
        "fb9+ ",
        "<Y|[V",
        "wgwg~",
        "%9+*-Zc",
        "A+ZrKpo",
        "H,_^Jf][",
        "2IJNX",
        "zP}O9d",
        "%+f5U",
        "r)&a0",
        "glUJj",
        "ZPK>mb",
        "<(<A<d<t<",
        "R9w=VV",
        "$_^][",
        "909l9",
        "KZ($V",
        "MZ6K(",
        "<c7zo",
        "x|c`{",
        "M&+L-i",
        "@sR!_",
        "r-eguZ",
        "^h|d*",
        "TempDir: %s",
        "Y8AU{Ye)c",
        "J5=i=",
        "value.shkeybag",
        ">:j3_",
        "7 7'7.7h7",
        "M%h3$",
        "aes128",
        "s<B0:",
        "MlNV)To",
        "mS1nk",
        "0;%\".CZ",
        "!|qor",
        ",!Mgs",
        "W4u?U",
        "3+3@3E3",
        "FSNCR",
        "={:/0",
        "-^u9/K",
        ":C9p/",
        "Latest installed version: %s",
        "content_type",
        "(cykq",
        "[][)h",
        "exponent2:",
        "hY&n!",
        ")a\"wf",
        "WRJRP>H7",
        "=xxw32",
        "!O:bM",
        "3Br7Z",
        "\\$XVRP",
        "FEMMS",
        "j$r1!+w",
        "uting device with an IP address) on the trusted side of the network or that is trying to traverse the firewall, and the numbers of cores, or the maximum throughput capacity stated, or the code generated from the master installation, or any other hardware ",
        "MaxNumFilters should not be changed",
        "yoq\\I",
        "&;q6d",
        "=h>l>",
        "[Oc0^",
        ":R:\\:w:",
        "VX3CV$?",
        "A$2b:",
        "/Xj1L",
        "F,zc<#",
        "N%gJv",
        "hF:(n",
        "32tG_%4",
        "p*;+O",
        ":`wc\"!(",
        "EO&LX",
        "  -;N",
        "CANT_LAUNCH_CLIENT_FOR_CONFIG",
        "O.?k66",
        "/t@Sd",
        "AR/^e",
        "9>cKb",
        "{8x9!",
        "9Nm!:",
        "Can't complete SOCKS5 connection to %s:%d. (%d)",
        "7O8Z8k8|8",
        "7p9*:2:1;",
        "L.j:$",
        "~w,Ir+",
        "gJqS^",
        "%WindowsSecurityMonitor.dll",
        "no shared cipher",
        "@JaTJ",
        "&`d\"b&&hl",
        "a-])kP",
        "^o;d2",
        ":9#[x",
        "f^Tc0]",
        "supportedApplicationContext",
        ".?AVbad_exception@std@@",
        "2PabcC7",
        "2+3A3H4|4\"535",
        "`\"&l$n",
        "mPxA^R",
        "g%575R",
        "6X0~X{",
        "*m'`A2",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "k+WV#",
        "9qW._",
        "%c%c%c=",
        "C|MjB",
        "k&iF\\@",
        "UninstallCreatedItems:  Internet logs directory is ",
        "$Rnt9",
        "'NU*V",
        "F#c2u",
        "\"Vb?D",
        "g%x@Mc",
        "w/788O",
        "!Tx{/",
        "D$HSUW",
        "|DD8E",
        "*PBXa",
        "dWq{i\"",
        "i7(D^4|",
        "}]rK=",
        "*Wy=S",
        "EU*9%",
        "3)3M3e3k3",
        "Loading GUI",
        "oj;Nm",
        "H(55YdU",
        "k1.X\";",
        "vMze~e",
        "!on^7",
        "Gf:Kn",
        "0|C#*",
        "1 1,181D1P1\\1h1t1",
        "@Sh',",
        "gN?<R0(",
        "39F0ua",
        "jAjtj",
        "vV!~+s",
        "0b1o1",
        "Cw{Oz<Q",
        ".G,.R",
        "7E.9f>",
        "cG=ui#",
        "63*W!7",
        ":GMbN4",
        "[sd'a",
        "B6553834-7C0F-492C-A3C7-1D4B700FA47A",
        "`s;,\\2",
        "ArAqQq",
        ")7Mxr",
        "rVO`m",
        ":8:D:d:p:x:",
        "3F3R3Y3",
        "9~Xt#",
        "2{`ws",
        "Rn$o[FZ:",
        "jMaiR",
        "zlscv.dll could not be de-registered with the CheckPoint client",
        "DS:%04X  ES:%04X  FS:%04X  GS:%04X",
        "GMW'u",
        "p8WQL",
        "*o>1h",
        "'Q5B_",
        "6O\\N5w",
        "ezd<f",
        "Failed sending RTSP request",
        "73B4I",
        "atlTraceMap",
        "#JU+()",
        "Y :'\"",
        "invalid or inconsistent certificate policy extension",
        "Xlq>J",
        "Lv||I",
        "s?e>#",
        "+x`cTig",
        "Yu.\\BS",
        "8a9r9",
        ">A?M?a?m?y?",
        "2\"2b2s2",
        "8S9]9g9",
        "t3+T$",
        "FBZDM",
        "!Wyh5",
        "?m~pq",
        "W'Y4]",
        "uUNtT/",
        "(1zV{,",
        "@i-6@&C%`",
        "h(b,c",
        "?$?,?4?<?D?L?T?d?l?t?",
        "2Q3y3",
        "\\par }\\pard\\plain \\ltrpar\\s42\\qj \\li0\\ri0\\sb40\\nowidctlpar\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\f1\\fs22\\cf1\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "C#'rJ",
        "3Zd`Q",
        "L S\\$O",
        "dO>X2",
        "bad dh g value",
        "t?f98t:h",
        "sc.exe failure ",
        "w+\"j}AI",
        "YKLiIL",
        "wDw`wzu",
        "it*'U",
        "I*I.+5",
        "kCFaF",
        "=LMRh",
        "Gh>q|",
        "i;jt+",
        "edx&_",
        ";P2UT+lS",
        "Wildcard - \"%s\" skipped by user",
        "qDarp",
        "E_jsi",
        "+r$Ix",
        "/Eu3o",
        "K>VQ\\",
        "0k.`\\#",
        "hx484",
        "!$2`b\"')",
        "put_nodeValue failed",
        "DfsQS",
        ">$f\\i !",
        "Ho{FGZ",
        ";:;V;r;",
        "udzKMG",
        "&_6_W",
        "9bM|D",
        "Gx'Yb",
        "C\"saG",
        "{ZQU2x",
        "Q1Qe*",
        "n1xOW",
        "+}A)C",
        "_$Ta/",
        "%BfKN",
        "IN`\"`",
        "{RHMW",
        "u)u-w1",
        "arF>cc",
        "J:0^R",
        "|*E\"0",
        "m({L?",
        "=1=W=u=|=",
        "D#Sz$4",
        "p?h2hsC",
        "\"p5w4",
        "N7N?$",
        "$RVoLN",
        "mAo.iK",
        "\"bzGH",
        "^1G_5",
        ":G;t;",
        "8@_@F",
        "taq)c)[",
        "D2I_PKEY",
        "-nR x",
        "OCSP Service Locator",
        "^d?=P",
        "E%oJD",
        "subjectDirectoryAttributes",
        "wl9Yz(",
        "JVx.v",
        "\"L2Xw",
        "@r\"b*`J",
        "?1-<8_q[G",
        "qoaQ?",
        "q:Fbj",
        "r3c:?",
        "Pl'x2",
        "3<jG?|7",
        "%sAuthorization: Basic %s",
        "cslI{",
        "Unable to schedule rollback for object (failed to convert security descriptor to a valid security descriptor string): %ls",
        "WD_SignalStartServices started.",
        "72%Af",
        "jShX=%",
        "My6dn",
        "|K`M1",
        "H3pb5",
        "{Eh={",
        "bind(port=%hu) on non-local address failed: %s",
        "SOFTWARE\\Zone Labs",
        "Im3n|",
        ":nHZGp",
        "N~2'l",
        ".:yU ",
        ":H:Du",
        " v9Kd",
        "13FF^",
        "1 1&1,12181>1D1J1P1V1\\1b1h1n1t1z1",
        "Go1Mh",
        "=H>R>o>",
        "@eFu=",
        "Xxz&{",
        "5(e3t",
        "EOijn",
        "1\"z_.EJ",
        "r^P0s",
        "+,~Ck:",
        "Version",
        "XIALj",
        "qiEU^",
        "W]V]^Q^",
        "eS0`C",
        "b 8mRr",
        "ul9D$Huf",
        " 0x18",
        "i!I+y",
        "#$#)#",
        "3IsmF",
        "DaS)Gk#e",
        "=4=<=D=T=`=h=",
        "[wzv-",
        "<no protocol>",
        "utDXi",
        "Gf@+*",
        "ck5]V",
        "A#?67",
        "0Z*zog",
        "P.%(5",
        ";#<?<",
        "aO40zG",
        "1w6tE",
        ",rJ:UP",
        "9^8j:",
        "_gHz:",
        "ij~7A&",
        "99/F\\",
        "GENERAL_ALLOCATE_STRING",
        " K(`v",
        "2$2,242<2D2L2T2\\2d2l2t2|2",
        "J5 q<",
        "P47Nd",
        "j~j{j\"",
        "6#797f7u7",
        "1 1(10181@1H1P1X1`1h1p1x1",
        "ChangeServiceConfig2 failed: %d",
        "w;Ud,",
        "q~4E_",
        "5%5=5S5u5",
        "P$n30",
        "j:nzo",
        "AES_XTS",
        "[Da:jX",
        "-\\.L\\",
        "\\vtA7",
        "WJkI&;(5S",
        "`0:E_",
        "UO=.t",
        "9!919A9Q9a9q9",
        "Y$ Lz\\",
        "SEC_E_PKINIT_NAME_MISMATCH",
        "\"8VIN",
        "klEx.",
        ",t\"T^9",
        "g~_n;",
        "<(<0<<<\\<d<l<t<",
        "R6031",
        "2!YT:",
        "L GM+$",
        "V5Kvtl}",
        "JLJd%",
        "2_zD@",
        "aJ[y%Dm",
        "32494_4",
        "LYxavh",
        "!M#)J",
        "fS2=E",
        "lB(DB&}",
        "?B?L?",
        "(9fF5B",
        "/}^Vx",
        "subjectInfoAccess",
        "ui level is unknown ('%c') -> launch message box restart message",
        "xkO:)?",
        "SU4,S8",
        "-----",
        "<;J0Jm@]",
        "5#5\\5t5",
        "<;/;5J",
        ")O Jl",
        ".5+x6",
        "wap-wsg-idm-ecid-wtls10",
        "71;CF",
        "Y*|/1",
        "cZ0-DE",
        "EVP_PKEY2PKCS8_broken",
        "G?C6K",
        "cO*AX",
        "Cv]17",
        "unsupported public key type",
        "\\vnasc_coinstall.dll",
        "=:=t=",
        "-:5:e:m:",
        "=>=i=",
        "L@glh",
        "QG:&q",
        "#\\PttFy",
        "%Ci|n",
        "AdH,T",
        "pOI&zr",
        "z=n:\\ ",
        "u;>LZ|",
        "}'Nh\"",
        "[=c=k=s=",
        "P0d0h0x0|0",
        "|Aa($",
        "]Qc&2",
        "';UOy",
        "7,747<7D7L7X7`7",
        "El3P>9",
        "tv!znS",
        "v6j`6n",
        "X509v3 Extended Key Usage",
        "j~V0c@<",
        "T }`*",
        "Z\\7Ia&^",
        ";+RsH",
        "-]t%H",
        "5@Vd;Fw",
        ">w->u",
        "hrncT",
        "yiTUs",
        "vB>1+W",
        "-fM{2b",
        "373b3",
        "2u<1a!",
        "M@`U7s",
        "UninstallCreatedItems:  UninstallCreatedItems finished.",
        "class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > __thiscall boost::property_tree::string_path<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct boost::property_tree::id_translator<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >::reduce(void)",
        ".^][Y",
        "$YN]V",
        "qm'+X",
        "3Vd-K",
        "B&#JUx.",
        "%02x ",
        "1>7CE)",
        "Q`V-V",
        "'+8d7",
        "\"+(v/UmbC",
        "MIvg:",
        "2F2M2S2Z2l2q2",
        "L|#cf",
        "l$ UW",
        "SaA>D",
        "1-1R1}1",
        "%UQWJ",
        "o_{MfN",
        "GetBladeRequiredDiskSpace: Blade Required Disk Space found is: %d Byte",
        "&J^ZO",
        "[c?Q6QI",
        "3G;7c|i",
        "5$636",
        "!0%0)0-0105090=0",
        "U8az\"",
        "8 8$8`8d8h8l8",
        "Zh\\ O",
        "9P\\1Q",
        ":*;/;6;;;",
        "uF)~D",
        "W7l?h",
        "u.|Fr_",
        "Z*wV+",
        "2 2@2`2",
        "x^Uj^",
        "_1DQv",
        "Wow64RevertWow64FsRedirection",
        "bv7sf",
        "ms{audx",
        ")rDY;",
        "FH<bu",
        "CreateTimerQueue",
        "gS2sb",
        ">CGO:",
        "DGRAM_SCTP_WRITE",
        "Uu!U6(*",
        "5b'D-",
        "[/BTv'Nj",
        "=NXI)",
        "<(<5<",
        "Hw{O\\",
        "?aXN^",
        "CPqcd",
        "m(P*i#W",
        "n\\Jn6y",
        "S3Gjb",
        "6 7l7v7",
        "=HqS.",
        "&0.pLxX",
        "*m9\\L",
        "'P7Qk&",
        ":f:s:",
        "!/[%-w",
        "\\84r\"9",
        "H%P3s",
        "P3|{K",
        "x~.XS",
        "|ez`[=",
        "X509_NAME_print",
        "Kq~K?",
        "c'HM`",
        "9F:I;",
        "zyZ* ",
        ":7:e:",
        "`aJu.q",
        "sd>P#H~",
        "D$hSUV",
        "Y%{.l",
        "O|uK8",
        "H{Lm>(",
        "=2\\PA",
        "q+XOK*",
        "e1:[8",
        "Yc^H3",
        "!dc#q",
        "wsId]XX",
        "0c895fcf6720192de6bf3b9e89ecdbd6596cbcdd8eb28e7c365ecc4ec1ff1460f53fe813d3cc7f5b7f020000ffff0300504b030414000600080000002100a5d6",
        "Kerio Firewall 2.1.5 (All SKUs)",
        "(lRj9cKm",
        "L&YLY",
        "e~T8%",
        "PKEY_SET_TYPE",
        "PRHelperIsRunning",
        "::06n",
        "k|_m2",
        "sQH@U",
        "Vx+W)4@",
        "16v;(Y",
        "]\"uf!",
        "jg[BjG_",
        "xB'\\1lK",
        "p~C[i(j",
        "'_c7;",
        "\\$$VW",
        "30=%[n",
        "a3Sub",
        "=(=0=8=@=L=l=t=",
        "G_H]A",
        "NoKeep = YES",
        "p^7Y5",
        "'$NWk",
        "&)\"wU",
        "![P6I",
        "]pU]y]VG",
        "s_5<@",
        "+Kju1:",
        "W3EUW3EU7",
        "M'ikg",
        "0E&!aF",
        "RECi=",
        "=]u*&7",
        "m;=d]",
        "failed in querying IXMLDOMDocument2 interface",
        "Fg1BJ",
        "X/dDw$",
        "U**,Q",
        "i{:'Z",
        "*?]gl",
        "t|]9Y",
        "vKsFe",
        "p+7)QP",
        "hWz@d",
        "9<>Us",
        "asLx$D&,",
        "Unexpected return value from message pump.",
        "v(}S/",
        "x\"7ax",
        "b/7L$Dpk",
        "^1>LE",
        "Tm.HO",
        "SUITEB128C2",
        "license table is different from previously loaded license table (prev caller: %d, current caller: %d)",
        "J/7<=m",
        "SpOeL-!",
        "~G$=oo",
        "OnDriverStopFailure",
        "LookupAccountSidA",
        "\\OBfIU",
        "unsupported key encryption algorithm",
        "L}rU5",
        "EECDH",
        "`wYdb",
        "*\"Zj}Z",
        "6+CisiAJ",
        "D$PPWh",
        "4w\"fm",
        "d3Jf/",
        "gAy)Wi.",
        "Zxbb^",
        "tvwLE",
        "u*cHJ",
        "(o?'j_#",
        "r5;YWM",
        "UpToDate",
        ";<;\\;d;l;t;|;",
        "6(6-626J6y6",
        "CAMELLIA",
        "^6^Jw",
        ":BuCu",
        "{#G 2",
        "kczy-m",
        ",2L2l2",
        " 0xf9",
        "`vector copy constructor iterator'",
        "LLLL33",
        "oc<UI",
        "&atmB",
        "NJ~)az",
        "_^}~V",
        "sha-384",
        "@K{zJ",
        "Q8<11g'",
        "#z'vC",
        "ow{&#",
        "fAz$a<",
        "oV?Akn",
        "oVBeE",
        "dr\\^$",
        "X509_EXTENSION_create_by_NID",
        ";@<t<",
        "869N9S9",
        "IBs2_F",
        "bdCHS)",
        "2!2H2{2",
        "gpj0g",
        "JZ45 ",
        " apPe",
        "vsdatant driver is in STOP_PENDING state. Reboot is required before the upgrade, so vsdatant will return to working state.",
        "4n'K!",
        "MfD/8",
        "!pC:f'",
        "Z*Z%%?",
        "5H6y6",
        "U}@ki86V",
        "t*[@bN",
        "1#1@1Z1~1",
        ">$>,>4><>@>D>L>`>h>p>x>|>",
        "K*)J%",
        "5U6 7",
        "]5,o\"4",
        "!~\"v6",
        "9'979",
        "040D0T0X0`0x0",
        "4G.dEd*R-",
        "__std_terminate",
        ";oknJ",
        "1NX<Kz",
        "ARPA>",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<wchar_t[4],class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t [4]>>(const wchar_t (&)[4],class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t [4]>)",
        "http://ocsp.usertrust.com0",
        "Z;ABaLDU",
        "+;hgS",
        "f/4DY",
        "@LrDK}",
        "Unable to save changes to XML file: %ls, retry attempt: %x",
        "3DES(168)",
        "1!_Z\"",
        "_sendXml@4",
        "IntegrityMode",
        "\\Start Menu\\Programs\\ZoneAlarm",
        "Z\"Z)o/z?x",
        "g*Z\\8",
        "3)GO{",
        "oK6M}",
        "Tro(H",
        "kiau?",
        "1:2k2",
        "> >$>(>,>0>4>8><>@>D>",
        "OU06z",
        "U=M[i",
        ".\\crypto\\bn\\bn_mod.c",
        "=O>e>",
        "uPQ P",
        "|]zAYr",
        "-----END %s-----",
        "pKJi9",
        "aiajak",
        "0Y1h1s1",
        "AyFpZ",
        "RSA_NULL_PUBLIC_ENCRYPT",
        "YV!RoY",
        ".m,(w ",
        "F.la`J",
        "jK_D&",
        "unknown key exchange type",
        "<.<Q<k<y<",
        "r%W/c=*",
        "|<9yIC$'",
        "QtExec64CmdLine",
        "}&9Ps/",
        "NMVBRUV",
        "9\")wf",
        "AbATy",
        ")^N7jES}T",
        "DO_PK8PKEY_FP",
        "s9$])",
        "\"I,.-F",
        "?CPCopyFile@@YAJPAD000@Z",
        "2;3R3\\3l3",
        "*MzCc",
        "=^6JV\\",
        "L_6{h",
        "SOFTWARE\\KasperskyLab\\protected\\AVP6",
        "4U4v4",
        "hr-BA",
        "7d8y809+:v<V>",
        "&6D-e$",
        " '9]F?",
        "d7)2\\",
        "9.979E9W9{9",
        "2 3r3",
        "lZrNlZrN",
        "=~RY:,",
        "#XTqX",
        "H~N;\"",
        "8  @A",
        "c3S!V",
        "-#%<f",
        "@f2-3",
        "@r[rf7",
        "=~x~v'",
        "Q`a*Q",
        "!UZ1R4o",
        "&*\\!7",
        "^`>BV",
        "|L&I)",
        ":#:9:A:k:{:",
        "8 9%9",
        "wc%R ",
        "YAUnnEq -",
        "GKsy?",
        "3h|=!",
        "!g*Jj",
        ",qNgL",
        "s<f~R",
        "1:1^1",
        ";7-uh'",
        ":x7~~",
        "sJW?M2",
        "0I1\"2q2",
        "XNEML",
        "FM22%",
        "4d9l9t9|9",
        "utV~.",
        "(DNr};",
        "!0Gf(5P#",
        ">`?h?l?p?t?x?|?",
        "f|tZt",
        "3J3U3|3",
        "FSUBP",
        ">)m<g",
        "G3)c/g",
        "u&WVS",
        "nx[un",
        "z~)(F",
        "t:#[=",
        "~&2M>e",
        "[\\~^'\\",
        "pkcs7 add signature error",
        "g5=A#HFDQ",
        "$'|&|",
        "\"JBC@",
        "Zlc.G",
        "DBGSYSINFO",
        "target.moniker",
        "3dE[\\8",
        "2lVo{",
        "InstallDir",
        "t2Be{=",
        "@vq\\&",
        "1\"b%~",
        "k&Bw*",
        "CA@Vd",
        "?R?*?+?,?-?.>/~",
        "]1%}T",
        "_d]Fz",
        "Vi-A/",
        "\\$0UVWS",
        "WfM{,",
        "D$Hff",
        "hXa/[",
        "?AcVKjH",
        "Uh,-$",
        "dSDIt",
        "Z&e%S",
        "<0|]<9",
        "A6I=?",
        "F>@3+",
        ";=sMtSz",
        "/^15R",
        "du,c~F",
        "c0`CU",
        "DKRnf",
        "uUMMs",
        "YuU:Z",
        "\"i_kPD",
        ":);X;s;",
        "Ej<&@6",
        "X509_REQ_print_ex",
        "s#LHi3",
        "'\"Xp$",
        "Ok){W",
        " 0x94",
        "fhE@B",
        "{f3IQ",
        "t]%D{",
        "9Hx~G",
        "7Uaqr-",
        "~3wCx",
        "`BZ^MJ",
        "PILVr_$",
        "9):n:",
        "{]EUrz",
        "A\\T)S",
        "-Y]QV",
        "failed to get Name for XmlFile: %ls",
        "6\\an&",
        "f}QJ3",
        "Q5.s0Sjr",
        "^]E_db9",
        "c4u2]",
        ">)>;>u>",
        "MTMdG",
        "PACKSSWB",
        "*>?]T|i",
        "InfFM",
        "0u8=X",
        "m1J9f",
        "f')%%fP;qSz",
        ")5'KoC",
        "Yy5!_%+%",
        "<^#~|",
        "v5%3S",
        "=?$ZW",
        "[G.I9h",
        "0h$ag",
        "===G=_={=",
        ")3U#\"'",
        "VWLh7*",
        ":.zYE|",
        "\\f1\\fs20\\insrsid3017503\\charrsid15169477 ",
        "1/1W1",
        "Getting file with size: %I64d",
        "3%3/3:3C3H3N3k3",
        "636B6g6",
        "F(^[]",
        "a\"W`*",
        "wb%HT&d+*",
        "81@n.",
        "u{Gcy",
        "6&787~7",
        "i3P-v",
        "MKbsg",
        "/yn[z",
        "8C8V8h8",
        "V/Vp[",
        "incompatible version",
        "|+i?w",
        "0%0s0y0",
        "FIMUL",
        "$Fr79k",
        "A<G_%",
        "oM~i6SW_",
        "/SVy=Mb",
        "TCbE^",
        "z<CKI",
        "&XfKH?",
        ">4\"uX6#",
        "T;OF4",
        "s0T-?",
        "(A[Vj",
        "EndSession end",
        "@xa&If",
        "A?+Qa!{P",
        "5q}*r,.",
        "?$SSQ",
        "&WimV",
        "FK# A",
        "NF,**P",
        "qVw%i|;H4",
        "r~Nd6M|k",
        "7 7$7(7,7074787<7@7D7H7L7P7T7X7\\7`7d7h7l7p7t7x7|7",
        "/y{P0",
        "r#2cw",
        "72j$D",
        "ndpdrdtdvdxdzd|d",
        "Oc4@VBYL",
        "oDM3I",
        "SYSTEM\\CurrentControlSet\\Services\\SR_Watchdog",
        "v>3tK",
        "Za3C8",
        "rVV!%",
        "UI_set_result",
        "e*5k>",
        "~H5h ",
        "Q1g:>",
        "(2<V#I",
        "k9hwlA`W",
        "_c1/O",
        "][$C2",
        "| e?C",
        "@w'lG",
        "-5l3`",
        "Sx1>[",
        "\"Mo1W>",
        "!ogQV)",
        "s3[2(",
        "=Mw_h",
        "W1HX+",
        "=$=+=",
        "Z }Z/+",
        "x)VWS",
        "Dependent Libraries=FileHash_ST:SecureFile:HashDB:OS:cpbcrypt:DataStruct",
        "Lc>H)",
        "Yl1;9",
        ":5:`:",
        "50D0`0",
        "@(\\hf",
        ":0;D;M;",
        "D$LWP",
        "PdfB~",
        "\\|0YytE",
        "\\8,2Q",
        "2$.Z|",
        "YiS(0",
        "t0\\Hz`av",
        "field missing",
        "8*9Q9",
        "GOEY#",
        "oa!Z+,",
        "?l'.c",
        "\\zonelabs\\dbghelp.dll",
        "PUNPCKHDQ",
        "5G6hUs_",
        ">\">;>T>m>",
        "gOTu8~^",
        "i;|/t",
        "V(5|4",
        "t\"h0k",
        "t$0h  #",
        "Cm6%}",
        "\\@Niy",
        "akX+:",
        "M0)R0I",
        "9?oQ)",
        "CHECK_SUITEB_CIPHER_LIST",
        "DZPd~O[",
        "2G2X2v2~2",
        "~1ZUM",
        "r=1{N",
        "initialization error",
        "ij=8c",
        "5G5x5",
        "zwv/?",
        "4V:\"(",
        "9xni|",
        "a ajfx",
        ";;865",
        "s(Ybc",
        "=8=T=p=",
        "L0U_Fs",
        "Y`\"xU",
        "PpP((J",
        "V(1h:",
        "TvL&aR",
        "Tt1jhZ;",
        "WIN32_BIND_VAR",
        "9f9l9p9t9x9",
        "getSessionKey;",
        "n3L$8",
        "+{8no",
        ";]v1P",
        "Lz@b ",
        "|L)M<",
        "FOLE}:T",
        "n%n9nun",
        "Y?,LtN",
        "Failed to alloc scratch buffer!",
        "=#>->7>A>K>X>a>j>z>",
        "fltmc unload avc3",
        "=<2!Ah",
        "949<9L9T9\\9d9l9t9|9",
        "1(1D1`1|1",
        "81G*8\"",
        "Should Fail Install Due To Windows Defender",
        "kku$M",
        "0(0H0P0\\0|0",
        "IDEA-ECB",
        "B#HJQ",
        "aN{fU",
        "uU]6n",
        "RSA_OAEP_PARAMS",
        "SDL is enabled MoveFileEx returned %d",
        "|7r12",
        "AzoMg",
        "Ih\"iA^",
        "FreeLibraryAndExitThread",
        "jkjyj%",
        "';m/t",
        "O/IQ\\c",
        "CN`*wUsu.:-~",
        "vAFP8",
        "<ellipsis>",
        "M9\\ |8uq^Lm",
        "7 7$74787H7L7\\7`7p7t7",
        "q)C`564",
        "CONN_CTRL",
        "J`Chzvs",
        "N%=t:",
        "a`bU6#kV",
        "rAjPo",
        "LookupAccountNameW",
        "`k@]{",
        "52-Kq",
        "Vh T!",
        ">Ogi6",
        "K7\\v>",
        "8sJypH7",
        "az-AZ-Cyrl",
        "D8TP3",
        ",*67S_",
        "-\\JgG",
        "<{94I_",
        "e8{sd",
        " restored.",
        "000E0J0",
        "Z4Z|h",
        "DEQV8",
        "y\\)j@",
        "6ZIj=",
        " f8UE",
        "xi}Ji",
        "<B)Y$",
        " YdAO(",
        "{Qz?lL'F=",
        "jzNBr",
        ")y.c_G",
        "2\"teZG",
        "Ln-nf",
        "#WTVX",
        "q}:;l}U",
        "@/-f|Ml",
        "uO5:,",
        "m/u&^",
        "setct-CredRevReqTBS",
        "{#g^b",
        "#x?;j",
        "@hO)(",
        "~=B6#R",
        "53 6{",
        "Mb%-x?",
        "@L\\jQ",
        ".\\crypto\\asn1\\tasn_enc.c",
        "/D@D ",
        "dGG][d",
        "hR&Q,",
        "FIXED_MAC",
        "7u466",
        "nK!1sP",
        "szVpnRegFile",
        "-----------------",
        "0.0.0.0",
        "D7gx5",
        "APMB=",
        "B{MQPQ",
        "x`\\`U",
        "@Eh@Y",
        "T,A q",
        "@Gx,8E",
        ".?AV_System_error@std@@",
        "7074787<7P7T7d7h7x7",
        "WRMSR",
        "PKEY_RSA_VERIFY",
        "sg5Qt",
        "v\"GUv",
        "&<G,?",
        "%u %X",
        "-|BII",
        "8$8`8",
        "#S#9I+",
        "_Y9I4p",
        "Q/VM)",
        "y'(.]",
        "272S2o2",
        "H+rfF",
        "XM/uc",
        "?D?{?",
        "TDdEGX",
        "Uj5}9S",
        "SEC_E_SMARTCARD_CERT_EXPIRED",
        "JjJoJ",
        ">FfQ!",
        "RYU2*n",
        "of*`bpd",
        "787L7\\7d7l7",
        ".?AVparse_error@rapidxml@detail@property_tree@boost@@",
        "/s``0",
        "627G7",
        "Wu0WSh<8",
        "IU0{;",
        "9E9f9_:f<r<",
        "U-=2p\\p",
        "0I1S1Y1_1",
        "CNAT_FIND_VSWRITEUNINSTALLINFO",
        "Xp02P",
        "l+6Gv",
        "JW+?+`=",
        "f`9LI;YP",
        "Ak2n\"",
        "BIO_ZLIB_WRITE",
        "(t^ r",
        ":F;N;t;",
        " /nobreak >nul 2>&1 & ",
        "cr'fg",
        "2A2N2W2=3B3",
        "j1l<k",
        "@wa`*!",
        "+]ma]Kmd\"XN",
        "<Q),9",
        "8084888<8@8H8L8P8T8X8`8x8|8",
        "dqiH9f",
        "2Zv?l",
        "A\"QX-",
        "%0g)W",
        "3T3X3\\3`3",
        "D$ QR",
        "Ef]O7",
        "1;(].",
        "Ce[RdN",
        "J_J]_",
        " X=pb",
        "R=Xf&(",
        "Y%2y'",
        "1?tYJ",
        "!y1ah",
        "PV%?~]M4}",
        ")f}TJB",
        ":+<OT^J",
        "xojx<",
        "+I-$V",
        "Couldn't interpret the 227-response",
        "p.prime",
        ";(;@;X;p;",
        "{b0Q_W",
        "\"wUQk]|",
        "Z[@I}",
        "format error in CRL's lastUpdate field",
        "InitializeCriticalSection",
        "sc?8D",
        "vYC)!7",
        "HP=q*",
        "SetFileInformationByHandle",
        "=*=e=q=",
        "x+(0[Ut",
        "L$83L$H",
        "\\drivers\\vpn.sys",
        "i{]@Z",
        "9%959I9",
        "T  2u~",
        "%67kz",
        "256japakk40bppdgci3qw3659q0",
        "89 TV",
        "PG9S(h",
        "partial",
        "stopped vsmon.",
        "Z]/*R.v",
        "c>rt*",
        ";.<=<L<",
        "-1c/l",
        "(@h;q",
        "xVY\\SV*7SP$G",
        "W `YF",
        ".AjeZ",
        ":'J?FUp",
        "LJMU~",
        "3>F[]",
        "364<4B4H4N4T4",
        "x8yN<",
        "kBnD`",
        "#;$uW",
        "DO_EXT_CONF",
        "6>xp)",
        "2 2(2<2D2X2`2t2|2",
        ".Ot&s",
        "VXE7R",
        "Uninstall Salt not found exiting %d",
        "%2I64d.%0I64dG",
        "t$$PUSVWW",
        "USTE)",
        "LUrz&",
        "failed to remove authorized app",
        " ,2(b'Z/",
        "2&2_2",
        "2 3@3H3P3X3`3h3p3x3",
        "L$x3L$<3L$",
        "9PG]y",
        "PtZ(+m4",
        "0K0X0g0|0",
        ":`;e;v;",
        " eT39",
        "cc1e=",
        "Failed to allocate string for formatted string: '%ls'",
        "#}e%~eBC",
        "cpbcrypt:I:ravpn_is_v1",
        "k[f&1",
        "type not data",
        "G6_f7n ",
        "Xx);M",
        "[12 W",
        "S-}'T",
        "kF!CJ",
        "RSA_PRIV_ENCODE",
        ",y<kh_xzI",
        "P,-x\"",
        "u:9{@tB9}@t=",
        "V|'U5",
        "X400Name:<unsupported>",
        "+(o1{",
        "#Jog!",
        "ssl library has no ciphers",
        "BP+ZI",
        "]^CD4",
        "'<\\8B@j?",
        "UrrJ~",
        "NT|Cy\\$B",
        "onP{2r<",
        ":Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December",
        "REINSTALL",
        "3j3z4",
        "<?<S<",
        "qB4da",
        "gKa)S",
        "$LG3r",
        "localityName",
        "H8]Ln`",
        "'Vb'x@}",
        "failed to get open ports",
        "<{xxxi2Q",
        "SRM5-",
        "\"rx4c",
        "hH>z(%",
        "\\$`UV",
        "?$?(?D?H?d?h?",
        "{98j`Q.",
        "TJAG ",
        "ocl1b",
        "X qH\\",
        "f4D05",
        "m@o.D<",
        "0B,-hy,",
        "D;3x%",
        ";B.VJ",
        "HeapSize",
        "YTeG9",
        "= ='=.=7=K=^=",
        "9L$lv",
        "Setting InstallDirDevice",
        "*ilbr",
        "]8~[<",
        "$~yoDc",
        "h!+`>",
        "qqX\\v",
        "?IsSCUIAPIMode@@YAKK@Z",
        "1;1A1K1]1",
        "<N<Q0TNIyi",
        ".i#qGr",
        "j5LUaG/",
        "`kYPE",
        "X3=Xj",
        "Enu*^",
        "file type P12 for private key not supported",
        "CCchb",
        "q?e\"|",
        "pCX r",
        ":C3]nN",
        "2 33393L3]3j3p3",
        "zh6$Ux",
        "637V8e8",
        "5?5b5",
        "a\\s.y+",
        "eLv2%",
        "SELECT `Name`, `RemoteAddresses`, `Port`, `Protocol`, `Program`, `Attributes`, `Profile`, `Component_`, `Description` FROM `WixFirewallException`",
        "I2$\\F",
        "aes-256-cfb1",
        "E%E.E7E?EzE",
        "?d_\"h",
        "^rzX=?0 T",
        "G+5-X",
        "hHFRQ",
        "#`Cmvi/i",
        "Uoh~r",
        "UfdJ$\\Z",
        "lvU_h",
        "PFzHm",
        "i}ilV",
        ":$:?:g:",
        "YR*A-SV",
        "@QHle*",
        "$UFS1",
        "N0k|(",
        "[(=JMsF]",
        " \\M:V",
        "\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Standard User\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "~]p1l",
        "M)E!`5W",
        "mQwD2",
        "t$,VPU",
        "@>\"I(",
        "A[G]4:",
        "P$[./",
        "]$T%{5",
        "FILE_CTRL",
        "@91=}",
        "ZV?\\X",
        "U%bkq",
        "+qahY<s",
        "L../c",
        "l)34N",
        "BQ}TM",
        "QDREc",
        "Successfully set MaxNumFilters",
        "{\"P>W",
        "10181D1d1l1t1",
        "[R#HG",
        "1TzJ13",
        "i[;e*",
        "<[u j]V",
        "{*`F5",
        "vn':K,",
        "6/666d6h6l6p6",
        ">f?~?",
        "nAufl",
        "'7lPuqa",
        "848>8O8_8",
        "$uIIvU",
        "*l0J~p",
        "ish^w",
        "`1*!N",
        "    Version: %lu (0x%lx)",
        "7nwdz",
        "Y/|dr;iR",
        ":=O7Qk}",
        "l78JK%",
        "c|'?.N",
        "zwF}$",
        "|U!Vf",
        "GetFinalPathNameByHandleW",
        "y6Mr:@",
        "[%s] CreateZipFile: Error writing zip %s from %s - wrote %d bytes",
        "CheckNetworkFilters",
        "3Q-gg",
        "w9{2u",
        "Q^H*<@~D",
        "HandleDriverInstallHang: No action required.",
        "3>>KL3",
        "<~YKu",
        "1:1F1c1o1z1",
        "?c&So",
        "%02x%02x%02x%02x-%02x%02x%02x%02x-%02x%02x%02x%02x-%02x%02x%02x%02x",
        "9d9x9",
        "%`NX1",
        "+6Y'\"]",
        "lE/ymE",
        "^AOOK",
        "(`':3n",
        "!}>lp",
        "0c2c3c",
        "NM>?K~",
        ",=xLNs",
        "M\\I:I",
        "0^B\"12",
        "hujnY",
        "4.fy{",
        "f.\\ho",
        "bO1E&|",
        "~~mdQ",
        "?L?V?a?",
        "7$787D7L7d7|7",
        "@>H V6^",
        "dzLel",
        "VIrZ?V ",
        ">:>P>c>j>{>",
        "[VSDATA] %s waiting for DataClientLock.",
        "h<\"Xy",
        "20WI.",
        "NEau~",
        "AHx5v",
        "Delete file: MsiDatabaseOpenView",
        "baH\"rX",
        "F 1`_",
        "({oDS",
        "<N38j",
        "e<7BV",
        "CRYPT32.dll",
        "L64^o",
        "9!:J:n:",
        "R+Q2I",
        "xgjDs",
        ">~LFpH@",
        "A4N<H",
        "e.BDP",
        " /Ye?",
        "s7o^%",
        "GGnoH",
        "En` \\",
        "[Zgd-Icl",
        "uc_>eB9",
        "Cd_[lB/",
        "-c7Pk",
        ")Aq}E)q",
        "(qnH.",
        "S1+OY",
        "BS4y[",
        "nYp p",
        "X-_yLaL",
        "9f^(7",
        "\\system32\\drivers\\",
        "PKCS12_AUTHSAFES",
        " >p|Pw`pz",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\fresh.cpp",
        "IDLOCK",
        "7*898h8",
        "Removing directories",
        "yNy^H",
        "4+\"@y",
        "v%OXo",
        "_x#msl!",
        "2DQl^d",
        "q:]?ITvI",
        "/7Gf{",
        "ssl3_handshake_mac",
        "(50i7B)",
        "U%Su0\"",
        "9a\"osg",
        "friendlyCountry",
        "+V(Ht",
        "Agu(\\",
        "IW1>5",
        "EPWD.exe",
        "sFxF/U5",
        "Xx,5N",
        "y(OSp?",
        "B)O,S0)Z",
        "r/<k2",
        "1}jfg<Z",
        "?fXa%",
        "#@K)!r",
        "u$/t]",
        "BZ?D\"",
        "F-<at",
        "signature has problems, re-make with post SSLeay045",
        "Zumpu",
        "mkWUn",
        "9$9`9",
        "vy@{D",
        ":H5yFN",
        "j[Yj~f",
        "*TL| ",
        "5S/`[s",
        "%u %d %s %X + %X %s",
        "686@6L6l6x6",
        "RXHr=",
        "b\"CJe;pwHU}",
        "(I`RW",
        "0rq(+",
        "7(70747@7H7L7X7`7d7p7x7|7",
        "yfwN6R[",
        "Us&uJ",
        "9#:7:?:P:X:v:",
        "{l$fd",
        "4AMUp",
        "HD E7g1",
        "4w@]~",
        "9T$n8",
        "9(:P:i:",
        "{DXFwG",
        "T9sFg",
        "69m~Y",
        "-Q]+6",
        "lyL||",
        "[ValidatePEFile] Could not get the file signature for - %s.",
        ">-N?'",
        "Ud^+B",
        "\"T_&}c",
        "s2?&Jg",
        "i\"'F8",
        "H^7qW",
        "boost::filesystem::remove",
        "signer certificate not found",
        "Running cmd:  %s",
        "7'WGwg",
        "AEwG\"",
        "*dO6c",
        "Lx\\L_T",
        "`H)fA",
        "x#&2c#",
        "dYkQ-",
        "$|6NY@",
        "XtXm B",
        "LOL=y",
        "\\$D3\\$P",
        "UninstallCreatedItems:  Deleting contents of Internet Logs",
        "_W@V}I",
        "\"Oe7C",
        "363Y'",
        ";:ds@B",
        "CYfn7",
        ".2 99",
        "~c8!IjZ",
        "aCU =",
        "~VlUx)886a",
        ":[S'k",
        "&oy7j",
        "-$-5M",
        "(-W!:",
        "w__5grsA",
        "RkCk{",
        "hBq(,",
        "uwKqL",
        ".&_%@",
        "i/t.|F",
        "\"/GmuTd",
        "'jystTrFs'R",
        "setct-AuthRevResData",
        "+8FP7",
        "5+.T9",
        "5E5^5",
        "[PtJoZ",
        "6;I+`",
        ".iExY",
        "documentAuthor",
        "H}77H",
        "c+ bt",
        "m8w`l2",
        "zHOK6",
        "\"C$)t",
        "%cJYQ",
        "EPAM_Install.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "x>J\\KP1",
        "9\\cKXB",
        "m0Rx5",
        "IiAiE",
        "7A8>:/;",
        "4#4;4A4K4b4",
        "%s IAC %s",
        "I;Gd4",
        "N_3~%",
        "Q33a}",
        "\\Yo-1",
        "=H=!p",
        "~s02P",
        "V+VKF",
        "D2@\"q",
        "GGtPy[",
        "lq)\\>Z+",
        "Wildcard - Parsing started",
        "e(|1;",
        "GDB~/?",
        "|,Ce3",
        "jmjoj",
        "LCMapStringW",
        "6&7S7",
        "B8@{0o",
        "7(70747@7`7d7p7x7|7",
        "d)77W",
        "(Pb:T",
        "Fy\"kL",
        "iGEKG",
        "ta<&6O",
        ",LNpJ%",
        "H__{=",
        "wJ.}'$,",
        "cOW?{",
        "*92voF",
        ":noMd",
        "0o0[1",
        "9u^RDm",
        "w\\\"%c",
        "GWSWS",
        "h/qb'CF",
        "y0!Jp6;",
        "sA>h70",
        "amm$p",
        "lBB~$",
        "Ryq?o",
        "fVok>Co",
        "!n0l!",
        "A}0fR",
        "9W9i9",
        "X)i>r",
        "6R6\\6e6",
        "8/8Z8",
        "oHr{x",
        ",u>XC8g",
        "Oh+_g",
        ".text$yd",
        "-4Z(q",
        "wKfPr",
        "(J}DC'",
        "1^|X}",
        "gMCpA",
        "Wht5#",
        ":[d0\"DJ",
        "2.3[3",
        "6W$ge",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AeDebugProtected\\AutoExclusionList",
        "tkj<h8",
        "C<djd",
        "d7A1,",
        "WIX_DIR_COMMON_FAVORITES",
        "Nb$@m",
        "YR$ou#8",
        ">Lm@s",
        "Q]qK$]",
        "oY![j",
        "d75o|",
        "}qb$6<",
        "SSL Server",
        "<(<H<l<",
        "#/eay`/@",
        "Failed to terminate Fbl",
        "D$Ej P",
        ".CRT$XCU",
        "t$ WP",
        "rm::'9M]",
        "''txb",
        "ch1!R",
        "K9zv]",
        "EJ8{9",
        "Z15F#",
        "FWRemoveAfter started.",
        "w9G#)k",
        "(jN<k",
        "m0N0p4\\",
        "zKZ-J",
        "bUy##",
        "|F!`L~7",
        "pC[Q@",
        "6 /SX8",
        "aUiUqUyU",
        "Failed to concat Installer directory on windows path string.",
        "Ph`6M",
        "3$3,3<3D3L3T3d3l3t3|3",
        "1xZ-s",
        "MD4 part of OpenSSL 1.0.1t  3 May 2016",
        "T=F#:",
        "|P>D(",
        "aq?JE3",
        "i7&S!",
        "R*Y28",
        "+s78T",
        "]Yltt",
        "3\"3(3.3;3J3Y3k3v3",
        "+8`HB",
        "?!?2?;?A?^?h?y?",
        ",+;0&",
        "Vq)Gx",
        "RunSwitchbackWizard",
        "3 4d4.5d5",
        "wtufF",
        ";a]t`",
        "+(bF&drJ:x#",
        "CShell.jar",
        "mYI{I1v+",
        "o.~@a}=",
        ".\\crypto\\asn1\\x_name.c",
        "}Rq(W )",
        "k)3-+",
        "n;ARa",
        "j7`TqkT",
        "4dpN7",
        "J`GYHI",
        "%1LI?",
        "1(1L1l1t1|1",
        "p3?H-7",
        "595I5|5",
        "6[8Lx",
        "^ZF}n",
        "Gvjv~Ea",
        "NKuG L~",
        "*57?K",
        "%c%c%c%u%c",
        "VersionNT is: %d, Kav drivers will be installed.",
        "ZPB|Et",
        "ab?*:*J",
        "x&Zv(",
        "Z~r<#",
        "''n+c6",
        "[$< @",
        "6-:zY|",
        "6(6H6T6t6",
        "Yl*,C",
        ">?,j4",
        "P9p9&",
        "9`:0;",
        "LogEvent",
        "V<\\t,Q",
        "Global\\vsdata",
        "2$2,252<2G2M2T2_2s2",
        "~'$5L",
        "cCy:j1",
        "!soO9",
        "N4`*GIW",
        "W^O~&",
        "iy<Go",
        "{&5TP",
        "vDQUX",
        "mMQKyj.",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid11819894 software}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669\\charrsid13774068  activation, Check Poin}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669 t will replace it with new part or full unit }{",
        "'YLv9[",
        "4FO(q",
        "6*FR@",
        "d#nD(",
        "K&R\"h",
        "@s17 ",
        "u%J'53",
        "jjZkX",
        ";^!AY",
        "i-Sg#!(",
        "ljBr6",
        "/}\"PW",
        "@4#4L",
        "^ Y ?",
        "v5fCiC",
        "Od[}{]",
        "l;nz$S",
        "J:o`#",
        "5bl5>",
        "j;Xf9",
        "+%LHWF",
        "invalid null name",
        "[aw*4",
        "B^\"+'$",
        "[ib7gX",
        ")6tmj",
        "#/Z i",
        "NQzna",
        "3@H)e",
        "Q6%dx9z",
        "gl$w ?",
        "o\\$jY",
        "DSO_up_ref",
        "181T1d1p1",
        "jioe2",
        " w{Eb",
        "*3%-ik",
        "f)\\<t",
        "qBFEW",
        "Nt,T=",
        "iL5}Q",
        "Q-wR3",
        "T JcI",
        "s?'pL",
        "&]N>C",
        "D).<5",
        "?WaSZ",
        "yK6[lz",
        "pf5ea",
        "O2N;;",
        "Jg]^t\\X",
        "@f\";`",
        "f=&Ej:",
        "KIBsd($mHY",
        "dcObject",
        "A4x{%`",
        "J-ct6m",
        "JFj>h",
        "E]@,P",
        "digest too big for rsa key",
        "urF2'",
        "@Up|^",
        "RegEnumKeyA",
        "Cg4UN{",
        "OEM9+",
        "D$(WP",
        "Upgrading vsdatant.sys driver",
        "MqFjg",
        "sYX~75q",
        "w.v'2",
        "<4<P<l<",
        "ueY\"2",
        "qg'gWd{",
        "5<5D5L5T5`5",
        "84i/~",
        "gw&2X",
        "aZ#6\"IE",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  or (ii) if the license of the Product is terminated for any reason. Upon terminati",
        "__acrt_iob_func",
        "lOGJY",
        "FrLQ(",
        "%|dy!g'",
        "h[f0p",
        "*5e?0",
        "~L0E#0",
        ",=mf/",
        "1&2F2",
        ".u`jm",
        "1V2f2",
        "uGjZWV",
        "T'e\\5",
        "7%7>7W7p7",
        "|/bPL']",
        "wO={`[l",
        "VNko{",
        "T 7\\|",
        ";7HYa",
        "AmrTZ",
        ".-|P5",
        "2E9i!",
        "j_<?$",
        "|O|a+",
        "N5Slj[",
        "d!xfG",
        "Setting properties",
        "uHxEb",
        "z]-`T>",
        "PBPMm",
        "QVlmb",
        "LdrGetProcedureAddress",
        "x^|.|5\"",
        "ET;E u?",
        ":I;O;Z;",
        "*C3Y88xJ~",
        "0d~f$m",
        "0http://crl.globalsign.com/ca/gstsacasha384g4.crl0",
        "jV[f;",
        "D~Ut7!",
        "BlWHlUf",
        "@6T%Y",
        "PSWAPD",
        "strlen(objstr) + 23 + 2 * enc->iv_len + 13 <= sizeof buf",
        "Q;s1H",
        "'q*Cf",
        "?<h_.",
        "tehF<",
        "CANT_COPY_CONFIGFILE",
        "0*0F0b0~0",
        "1]2d2p2t2",
        "OM*\"#2",
        "PKCS12_parse",
        "VsRevertRedirect",
        "{A7\"9",
        "I2YjR",
        "sw-ke",
        "subjectAltName",
        "CLSIDFromProgID",
        "'~)eQ|",
        "cQdb1",
        "((d%+",
        "*u\\2Ao@E",
        "sORm-pPi3",
        "}|}W~",
        "{+Z& lQ",
        "ys9$/",
        "&Y8!X",
        "c/j%a",
        "Yc}dK",
        "4A!;i",
        "VT_^uY",
        "3HFUV",
        ": :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\\:`:d:h:l:p:t:x:|:",
        " ;@\\QN",
        "B\"(r&",
        "6S+w.",
        "^&;wf~",
        "ec_wNAF_precompute_mult",
        ".rdata$CastGuardVftablesC",
        "2+u':*",
        "JHJXJ`JlJxJ",
        "Mk\"V}",
        "<qjOAW*",
        "k,e'5",
        ",7^6l{",
        ":-WG~",
        "ax`W-",
        "x'Nb.CM",
        "Xy%,\"q",
        "4^uoo",
        "_getDailyEventId@0",
        "7$7G7",
        "{XjDz~",
        "=WN~W",
        "UYMT-",
        "$&afu5",
        "coHa8",
        ":AgFp/.",
        "/vx9+",
        "}xZbW~",
        "GetSystemInfo",
        "6dTvD",
        "=G=Q=\\=g=",
        "]Uruv",
        "3P*/S9",
        "c1trY",
        ".?AV?$numpunct@G@std@@",
        "v<F&'aV",
        "\"#{)|",
        "&.tsp",
        "<6<;<@<E<",
        "8`OXqLOv8!",
        "BC .=",
        "D$$_;H",
        "DumpFile",
        "1pJ{[Z^",
        "m:1R`",
        "z[S@He",
        "wD]m+",
        "idf!\\{",
        "JLJ\\JhJxI",
        "d/%{)",
        "YN'5>=",
        "[%s] could not compress file %s",
        ",~ciF",
        "9uN+.s",
        "*c!_9)",
        "NLLLP",
        "K\")'*",
        "~F%/d",
        ")aKOQ9",
        "k &4V",
        "CheckInstallConditions custom action end.",
        "syMmz6",
        "VWSU3",
        "xc;5 ",
        "7E8&9?9r92:",
        "E[$Xd",
        ")}~>B",
        ".oWIJ,",
        "%Sxr!wVd\\-w",
        "Xcqy ",
        "6ZV%>-",
        "MD*A~",
        "?3{<tm",
        "KQ=!T",
        "V`~WCW",
        "j9oo$",
        "qpl} Wm",
        "u!jih$",
        "d e not congruent to 1",
        "6-6F6_6x6",
        "X509_ATTRIBUTE_get0_data",
        "SEC_E_INCOMPLETE_CREDENTIALS",
        "wSrr=",
        "DfenK",
        "s5d|g';",
        " 0x53",
        "J9~Aa",
        "7FX`l|u)",
        "0dd1909fb60000001b010000270000007468656d652f7468656d652f5f72656c732f7468656d654d616e616765722e786d6c2e72656c73848f4d0ac2301484f7",
        "TL6^r5",
        "LexyY",
        "?3vCj",
        "(yTqA",
        "`&bWe7;7",
        "D$ ;F",
        "|99-,<",
        "#2x$^",
        "%s\\system32\\ZoneLabs\\vsmon.exe",
        "INr*u",
        "0e8+tV",
        "S_B[6",
        "7Tw5+L",
        "whirlpool",
        "@Ei7r\"",
        "CheckForReboot:  A reboot is forced.",
        "4P+Tt:!",
        ";+;0;X;];s;",
        "[VSSHUTDN] ValidatePassword",
        "7.869E9",
        "? ?,?8?D?P?\\?h?t?",
        "OCTETSTRING",
        "flTMwZH3",
        "\\ipgp19\\itap1\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp29\\itap0\\li0\\ri0\\sb0\\sa0}}{\\*\\rsidtbl \\rsid12064\\rsid84110\\rsid96625\\rsid131787\\rsid222364\\rsid226695\\rsid289795\\rsid344604\\rsid394066\\rsid395593\\rsid400274\\rsid405650\\rsid463379\\rsid473743\\rsid477636\\rsid526510",
        "J-%gEIu",
        "At38m",
        "AT;An",
        "W8^(uc",
        "QZh4w",
        "q?mzu",
        "{`uo/",
        ">#>2>",
        "D$DPh",
        "d|(pG&r",
        "`#yjL",
        "$`PgW",
        "wsw3wSwcx",
        "XMM14",
        "~)xA2",
        ";v6t`",
        "[/{~q",
        "b/''NdP-",
        "/*)*/",
        ")X.xJ",
        "must enter the password:",
        "<X=g>",
        "!%Vz)",
        "}fO&[g",
        "u[S#8",
        "{Chay",
        "*7+tE",
        "IJ<'0",
        "6\"6;6T6m6",
        "fdNn@F",
        "/Tf/X",
        "yGQG1YhC",
        "/. }OmY",
        "[3@Jc",
        "?O$H2$",
        "8o=Bi",
        "zz_[c",
        "e)(PSn",
        "ssl3_get_server_hello",
        "222b2",
        "9F)WC",
        "(Lu-I",
        ";6k%s9",
        "/eDP0",
        "u=j\\h\\",
        "countersignature",
        "pXkd$0aha",
        "boost::bad_format_string: format-string is ill-formed",
        "fDj*>",
        "<9Zbq",
        "hClkA",
        "D[\\Sp$",
        "JXu4&r",
        "#0VWH",
        "8f;J%",
        "CleanTray30Component finished.",
        "fZz;;",
        "n:OSq",
        "KB_Lu[",
        "Vi|& ",
        "g1FGZ",
        "ygy>-",
        "8-WMD",
        "kWmy6",
        "GetQueueStatus",
        "8aNxn",
        "7^7c7",
        "SUITEB128",
        "= =(=X=\\=`=",
        "r)#80",
        "R/\\Zb",
        "LU&sG",
        "9HsRW",
        ">O!vM",
        "UT=B|",
        "jGonmqjl",
        "FDIVRP",
        " --uninstall ",
        "Z&SMW*",
        "0\" J&H",
        "H@H9xqI",
        "F5$f7",
        "wC)hK",
        "WjFhd",
        ";\\Ek$",
        ";X<]<v<~<",
        "z/oYwY~",
        "C@F7[",
        "'J=d:0",
        "6`PV1",
        "I~j\\2",
        "_kmkX",
        "u?^p?o4",
        "t/_^]",
        "8$808?8E8X8k8q8",
        ",{JzQiQ/",
        "q^)#b",
        "9fzNl",
        "=]>s>",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 Your}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 location. }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "Dy'C_w",
        "boost::filesystem::relative",
        "H_H*/",
        "Mm{9^",
        "D$83D$(",
        "1a'gb",
        "j&jij",
        "=yIVBpeH;",
        "ImagePath",
        "CPDA service stop DLL path %s",
        "7nUnx[\"~q",
        ">.?{?",
        "S_%s_%u",
        "dc-L;",
        ".2ZB'",
        "hj$L|",
        "XqW*d",
        "``CfJH",
        "eoB:2",
        "Rwd))",
        "/0Z0t0",
        "8i9}9",
        "V$_uq:",
        "U@SD\"q",
        ")n'+4",
        "NOFo/1U",
        "8EjLV",
        "ssl3_get_server_done",
        "&u'poF",
        "cwi4^",
        "nWObru)A",
        "2)#59",
        "E_Fcf",
        "dtls1_connect",
        "kg`^}",
        "{\\fbiminor\\f31507\\fbidi \\fswiss\\fcharset0\\fprq2{\\*\\panose 020b0604020202020204}Arial;}{\\f51\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}{\\f52\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}",
        "RQ<FSE",
        "jJ~IX",
        "$cD+w$Q",
        "DIST_POINT_NAME",
        "+;o1]",
        "1XXr~",
        "/iLtpF",
        "ECDSA_sign_setup",
        " \"@Bl",
        "q`mg#",
        "VhtZ\"",
        "\\ckpginashim.dll",
        "I=:Hj:7k",
        "2 2$20282<2H2P2T2`2h2l2",
        "132:2z2",
        "|NRj2",
        "rT|L(",
        "h*'v@",
        "secp224r1",
        "G/R6m",
        "bad password read",
        "X10P1",
        "7,7H7h7",
        "FDE_Rollback",
        "D$ 9n@",
        "Command failed to execute.",
        "k-<y4,'",
        ")go~Y",
        "NFm_r",
        "f;1u;",
        " *cQF",
        "u*9D$",
        "j>'70",
        "sl9\\$,w",
        "BV2Tc",
        "!2H(P",
        "7\"_.!=;",
        "?p|DU",
        "G9g>x",
        "Caught an InstError object. Error: %s",
        "WjBl'Q%",
        "{W6Ya\\",
        "[].b8",
        "{D8o3",
        ",9t8%",
        "N_t,8u",
        "smj-SE",
        "^VbV5",
        "|{%*lp<9",
        "vl\"AI",
        "05G,h",
        "dka$[3",
        ")NBA9(p",
        "D5[9x",
        "`lzFF8=2",
        "8nnAA",
        "SSL re-using session ID",
        "4 4$4,4D4T4X4h4l4p4t4x4|4",
        "t$|PVV",
        "yHHu!C}",
        "=@>P>s>{>",
        "+L=@7",
        "r+\"+pr(",
        "ipwAA",
        "<7=P=",
        "ejv[2B",
        "NEB[<",
        "tD221",
        "_!!}H4",
        "`.ann_MH",
        "8u`T7i0W",
        "McAfee ISS 2003 Firewall (All SKUs)",
        "Ff3%\\h",
        "[dqM:C",
        "\"sd.[",
        "X%qxox",
        "av3Y8B[",
        "#E$RI",
        "$cK}t",
        "jg[jG",
        "O=_T[",
        "4=4W4",
        "(<P3@j",
        "Modules_VPN.png",
        "&%6%K%",
        "FeatureIMSecurity:  imsinstall.dll is newer than 4.5.88 so call new uninstall function.",
        "fddy3",
        "sha256//",
        "KL.}br",
        "l<(uh",
        "SVj\\W",
        "{q<{&W",
        "C%Qm`",
        "vcruntime140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "dv[lN",
        "M(\"x#HE3pPd",
        "qAkRU",
        "[@rg|",
        "T+]ON",
        "!={D%Q+j6iS",
        "A~`P^",
        "bri7l",
        "H(=m<w",
        "x,JIT",
        "#(b)4",
        "G38pE",
        ";Tb[q",
        "G@DU=Z",
        "d1`mT",
        "BxD>\" ",
        "first octet invalid",
        "3L$H3L$@",
        "RR4Q#g",
        "oL$Pf",
        "NTDLL.DLL",
        "!^)0O",
        "5!Q$(jRG",
        "`/f;$FA",
        "eS{kr<",
        "=!='=-=",
        "NYy}yx",
        "Le8%\\",
        "xg;5X",
        "F6x$6Z'",
        "zk/BU",
        "sect571k1",
        "IqgMo",
        "^]A#t",
        "PEM_ASN1_write_bio",
        "`*\\I:1",
        "ECDH_CHECK",
        "eu-es",
        ",0y@`",
        "<!<1<B<L<X<`<k<w<",
        "/ T~k",
        "S=#n!m2",
        "W6pjZ",
        "JyaFP",
        "~5;ak",
        "Ojy\\d\"n",
        "{>%UH",
        "seed:",
        "^KkEtD",
        "56M)\\",
        "D=l 9",
        "&9o{Z",
        "t$(hl",
        "SSL_set_rfd",
        "<;='+^",
        "1Zn}~",
        "rv].^@",
        "-Dhdiv",
        "no such device or address",
        "H/T6Ml",
        "^[TfG",
        "qp;oV",
        "xg4Cu",
        "||#xA",
        "pcPathLengthConstraint",
        ";%;8;",
        "4K|3m",
        "d2h2l2p2t2x2|2",
        "u*$sGB",
        "4u~@W",
        "uk-ua",
        ":c;|;",
        "`K}c)CC9",
        "FFFFFF2N",
        "/bM)M",
        "h,jZR-",
        "nU k:",
        "(D*<S,",
        "-CHK8",
        "nV.[_",
        "; ;$;4;8;<;@;D;L;d;t;x;",
        "01X7@",
        "{y*K^ ?",
        "}qDcz",
        "{Z`>OY",
        "gH[m +",
        "%;2.0",
        "<d4]~",
        "718B)",
        "b;#8!",
        "t!wl%rg~'",
        "L$h3L$",
        "7(8[8",
        "CryptQueryObject",
        "c&gL=\"ob",
        ",X3]j",
        "l&SeR",
        "@PUl{",
        "called a function you should not call",
        "Okc80",
        "\"W,o6",
        "O4jB9",
        "<\"<<<E<P<",
        "5;6H6k6",
        "P=P*N",
        "[fpn1",
        "I9IKIOISIaIiIqI",
        "8(8D8d8",
        "cT!.ma",
        "afOvH",
        "Ol&][",
        "JKo,^",
        "lK@#uY[@",
        "4NTa~",
        "nZk7*^=@",
        "J4}Kr",
        "r*n+2",
        "0F2W2",
        "6 7W7t7",
        "LL%kW",
        "6b7NCb",
        "NO:gW",
        "8`r?q",
        "\\zonelabs\\minilog.exe",
        ".?AVbad_lexical_cast@boost@@",
        "TlsGetValue",
        "S3ri`",
        "Wg+B_",
        ")KEFy",
        "rY9Y!",
        "w6wow",
        "Update KAV environment variable",
        "$NUM\"9",
        "\"T9:i",
        "x?Ww[%",
        "Stop Watchdog Service",
        "7N-Y*",
        "7'Qk-",
        "V=(s$9K",
        "R^u>pM8n",
        "ju.W}",
        "3<3B3_3",
        "failed to load library %s, error %d.",
        "z:#tK",
        "I^~8U",
        "{_eQ}",
        "|t99T",
        "0(1aD",
        "}kW]8;-",
        "M`<!2",
        "4&4@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "&>4<@",
        "error setting recipientinfo",
        "bWr[C",
        "oH)((",
        "V@P#B",
        "8B9`9",
        "`xd\\g",
        " ' ) - 3 G M Q _ c e i w } ",
        "T]B7m",
        "bAxJZ",
        "5(5H5T5t5|5",
        "$*>*[",
        "<*<F<b<~<",
        "64-bit MSVC redistributables were updated before this installation and reboot is required",
        " 7\"2>s",
        "9P9Z9",
        "f_g&m",
        "kx%6L>",
        "fR65t",
        "UVdm>",
        "xXz&]8!",
        "VPPPPP",
        "ggV}++",
        "C@7qIe",
        "PostThreadMessageA",
        "{&_L\"",
        "526t6",
        "!4W?g",
        "Zj\\[f;",
        ".SF$i$",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  91",
        "X.J~r",
        "GovmW",
        "X;%*w",
        "n75C4TW",
        "5z[ND",
        "#-Dy_",
        "8%9;9I9X9j9p9}9",
        "No firewall exceptions scheduled",
        "_:%)A",
        "x(YA`~",
        "c7Zfs",
        "5(50585@5P5X5|5",
        "L$8PQ",
        "=Y>}>",
        "Wio35",
        "D$Hh!",
        "&M$vx",
        "8Y;{[",
        "X.v8[",
        "CMS_ATTRIBUTES",
        "4(4d4l4t4|4",
        "=*^e}",
        ";7H)u",
        "zepL,",
        "=O:n0",
        "?zsm>:Rp",
        "*2p=*",
        "00h9<",
        "UCOMISS",
        "V#]o-",
        "u-Fh`g",
        "I$FSi",
        "0*ojK",
        "9#9*91989?9F9M9T9\\9d9l9w9|9",
        "ICC or token signature",
        "RCLt~",
        "J((2^",
        "cfyq^h",
        "~I5Om",
        "=K#:0",
        "$aCSRcm10",
        "re{rn",
        "*_~=U",
        "vJn@W",
        "u=j\\h",
        ";k]uw",
        ".MA,F",
        "3^],0B",
        ",j3f23",
        "6W3Cd",
        ".?AU?$error_info_injector@Vptree_bad_data@property_tree@boost@@@exception_detail@boost@@",
        "L7Ql3",
        "> >+>>>Q>Z>s>",
        "/,@3Pc",
        "FyFaQ",
        "OVi&N",
        ")$sF$",
        "<1Lki",
        "6V*nxi",
        "'_/Q=",
        ":F:T:w:",
        "=@>@?",
        "ssloc inet_ntop() failed with errno %d: %s",
        "K.&to",
        "hhAB=2",
        "8*u7B",
        "\\ so/",
        "#uR,y",
        "pa-IN",
        "4\"O0*S",
        "?)]W)",
        "\\B9L'K'",
        "{f7@#",
        "WXw>i",
        "=$=3===",
        "4s,,c4*",
        "4'4C4_4{4",
        "Qkkbal",
        "$_]^3",
        "*IG+P",
        "BS,if",
        "\\Ls$Ld",
        "brUnJ",
        "Yzvp}@~",
        " yR[7",
        "^\\e</",
        "W1wRwr",
        "7$7,7L7p7|7",
        "qK`Vx",
        ":-Zb}",
        "KvU>oG#YL",
        "'+'k'",
        "7,N~6!",
        ";6;G;q;",
        "jzjkj!",
        "HandleDriverInstallHang: Giving vsdrInst.exe a chance to complete...",
        "v`_^(]",
        "ZsG2&V",
        "9~|ANep",
        "4rg4p",
        "p`gN^",
        "luuiQ",
        "PFNACC",
        "Client finished",
        "6 6064686@6X6h6l6|6",
        "zMT*a",
        "S/;QDM",
        "utH\\]",
        "PPh8$!",
        "cdlh-",
        "Ri<[Q",
        "?8?D?d?l?x?",
        "G=A'+",
        "W3ep/",
        "?R$31",
        "BJ9qs%",
        "Gnv1#",
        "iy\\wa",
        "0f+KP",
        "TIq1`",
        "RemoteProcessMemory::CopyOf(proc=%p addr=%p hint=%p size=%d prot=%d) failed with error=%d",
        "\"7n,9+",
        "O3Ze%",
        "^q'o-",
        "T+$c0",
        "TS_RESP_CTX_add_md",
        "0hZzq",
        "j,Vf/%;",
        "5U=5M=7OW",
        "s{;=;<",
        "iE`yo",
        "$~M4H",
        "_L }*",
        "fw3tm",
        "S2I_ASN1_SKEY_ID",
        "hn}}-",
        "PEM_get_EVP_CIPHER_INFO",
        "Update MsiProperty: %s=%s  (old value=%s)",
        "VU8!B#",
        "3Fs^\\",
        "Wait for a message from a client.",
        "a.l,s",
        "AY?Sv0",
        "W;`+0V",
        "+[I=A9",
        "\"[_4LI",
        "v2LOC!",
        "> >$>(>4>8>@>D>P>T>X>\\>`>d>h>l>p>t>x>|>",
        "k=5,[",
        "\\jexpand\\viewkind1\\viewscale100\\pgbrdrhead\\pgbrdrfoot\\splytwnine\\ftnlytwnine\\htmautsp\\nolnhtadjtbl\\useltbaln\\alntblind\\lytcalctblwd\\lyttblrtgr\\lnbrkrule\\nobrkwrptbl\\snaptogridincell\\allowfieldendsel\\wrppunct",
        "9O=6w",
        "J}.9n",
        "h~a*7",
        "1?1X1|1",
        "bstr_type failed",
        "setct-CredRevResData",
        "8}f%U",
        "WM;1o",
        "1(2a2",
        "`~6qC",
        "o{weM",
        "D8wgY9",
        "o!>hc~",
        "jAjfj'",
        "8B8]8",
        "Microsoft Visual C++",
        "textNotice",
        "giu$p3",
        "m0mpm",
        "QhP<!",
        "RC4-SHA",
        "dW8\"Y",
        "<invalid>",
        "'Be0m",
        "Pn<}N",
        "\\avc3.inf\" /S /F /C",
        "|$N+M<",
        "0I0[0",
        "/RyC.",
        ".w3vK",
        "blD?A",
        "rmuW|",
        "-\\$d:~",
        "DB/h(",
        "lbm$o",
        "6}bI78",
        "t4UhlU!",
        "Y^l!W",
        "pnXav",
        "u;3vH",
        "t`,|j",
        "HFZN!",
        "o?S[#",
        "jzB_V",
        "[6Z8c9w#",
        "Rt[U7+7",
        "/FG;XNQ",
        "0R8:f",
        "njO]:",
        ".?AVScheduleGroupSegmentBase@details@Concurrency@@",
        "GInstall",
        "yozS544wv",
        "[f,N)",
        "C0A$&",
        "*||K)k%{P",
        "'(5{c",
        "7x=>L ",
        ",@  `@  `",
        "tmSj0U",
        "ASN1_UTCTIME_set",
        "5K6F7q869",
        "mrL6v",
        "9 9094989P9T9X9\\9`9h9",
        "Y@d%c",
        "D,tv^",
        "WYh11",
        "83.e-'",
        "DQDj*",
        "i)vsV",
        "3 383<3@3T3X3\\3d3|3",
        "l$(VSU",
        " R2}Q5",
        "7$7D7P7p7|7",
        "}~|p64",
        "w&97v",
        "1\"353R5m5w5",
        " }dc)4Z",
        "ye4-$ci",
        "twFkjO",
        "wtcC~o",
        "3*`;+",
        "?/8[&",
        "-M^ZJ",
        "%nugR",
        "u]=@;",
        "HiC%!&BL",
        "c|2;v",
        "(R~`Z5",
        "_7ti,",
        "7'quJ",
        "PIMAC",
        "m>@rv",
        ")p{7/C",
        "[)`u'",
        "eO@x^D~",
        "#rS$G",
        "bQNp6",
        "0,0?0R0a0l0z0",
        "kR@rc",
        "D=jTt",
        "YsPv=C",
        "o%QWz0",
        "\"vtRh7",
        "<%<Q<V<_<{<",
        "RAA`F",
        "U?2d\"",
        "1kDs^",
        "L$P3L$",
        "6 6$6(6,6064686<6@6D6H6L6P6T6X6\\6`6d6h6l6p6t6",
        "Zg']d\"G",
        ":C\\q7",
        "N@LVc\"qq",
        "IQ`aA",
        "Jl%\",",
        "!C'zY",
        "LogMon thread failure.",
        "Jkb.nM?",
        "nG8=kt\"da",
        ":L:V:y:",
        "=9gyJ",
        "@0't4hT",
        "3jBw}z",
        "tLZKn",
        "hLVw/",
        "#l5sq",
        "=]GNJ",
        "ECKEY_PRIV_DECODE",
        "lg:(YZu",
        ":D$RN",
        "N[|ca",
        "l3qzS/",
        "JU{c_TD",
        "Ks?$,",
        ",Hr{?@}L",
        "]sI.}",
        ";R9pK",
        "zr<.<2",
        "8.9g9",
        "4];gQgSY7gUgW",
        "Qy5x`",
        "hE7Kl",
        "`buoS",
        "6T-z-",
        "V5=xp",
        "[VSUTIL] : MakeVsmonPath:  GetProcAddress('hKernel32',GetSystemWow64DirectoryA) failed with error 0x%x",
        "_local_unwind4",
        "unsupported key derivation function",
        "TgkPK",
        "~*x)5",
        "@_`PGR",
        "`pb*L",
        "2tkr-",
        "%QyLH",
        "9$90989P9h9p9|9",
        "3`c`l",
        "7_u3Z",
        "BIO_ZLIB_NEW",
        "!7\\3Y",
        "X=}m@/a",
        "(v+i?",
        "qhcryt",
        "XPD1q",
        "aGOST01",
        "}Y;h'",
        "r!Mc-",
        "W'EOrCii",
        "`$OQB",
        "%v7V'w",
        "p.other",
        "\"Jj8u",
        "&;e=c",
        ">crG'",
        "`&R)i",
        "@#7TIv0N",
        "iostream",
        "E ^PQQQQ",
        "ecdh_cofactor_mode",
        "f]+6J",
        " 0x15",
        "b*qRo",
        ",hE(c",
        "p@)4tT",
        "SOFTWARE\\CheckPoint\\TRAC\\5.0",
        "4/484@4O4x4",
        "k{h8#",
        "9+1QR\\n5",
        "sS~\\we",
        ",C6J$",
        "CvP%Aq",
        "jwkYoH?",
        "T$2$5b{",
        "v IUW",
        "_i#Enw",
        "i_8`3",
        "$VlRwV@",
        "TrueVector driver unloaded OK.",
        "\"3z.T",
        "0A fH@",
        "jAjjj(",
        "UNIVERSALSTRING",
        ";2;F;b;m;{;",
        "q}m64",
        "o\\$p1",
        "VM;\"ANtw",
        "C'a1m",
        "r=~\\.",
        "CjE8z",
        "O:wg^",
        "-e=YW9",
        "%s\\system32\\drivers\\vnaap.sys",
        "'QF9?P",
        "Jm/YI",
        "*@fB$",
        "|FUlbZ",
        "U^$}R",
        "@8 ,i",
        "%s/%lx.%lx.%lx%s",
        "id-cct-PKIData",
        ".?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@",
        "-7y7=yd",
        "MH cFn[",
        "~`&@P",
        "b99D)+",
        "yQojQ",
        "ddhn}",
        "7!7/7j7",
        "\";evu+",
        "failed to get string from record",
        "PPPPPPPh",
        "IM5rQ",
        "AYM7b",
        "!_8tC",
        "4D`1t",
        "}2$03-",
        "@>+`G",
        "D6c\\AO",
        "BL0/^",
        "EIT;|",
        "l*8~pr",
        "_\\^8]7",
        "n|\\;pm",
        "-[.tr",
        "NAOHTD",
        "gmL#6",
        "Q8c]ck",
        "Result 0x%x",
        "uZj(h",
        "szPath",
        "<plugin path=\"",
        "X\\]]j",
        "<|lSL",
        "@_Q%R",
        "@E\\g`",
        "#3eHf%n",
        ">(>@>L>P>T>p>t>",
        "kpmdLEX",
        "g<Tv`",
        "t\"PQS",
        "pvpFW",
        "{F7B:",
        "8&9>9",
        "mk&5@",
        "[:1;N",
        "S]`NO",
        "5BKM!",
        "cYKol",
        "IH4d,",
        "INSTALL_POLICY",
        "V/em(MS",
        "4(R&\"",
        "75YNq+",
        " --uninstall",
        "?v[+KT",
        "SU<_h",
        "xc<f>",
        "M} uB",
        ",I3{[",
        "+O{O3",
        "c2c[lf^\\",
        "qk!<Q",
        "%$$dn",
        "_R}#>",
        "IzHL9O>",
        "LgW9{",
        "D$HWV",
        "B`7#i",
        "QVWSU",
        "8_J_j",
        "LOADED_LIBRARY",
        "\"XHi0",
        "o'#<C",
        "^BEXjM",
        "e1%X\"",
        ">k'aj",
        "373S3o3",
        "r\\RH^",
        "G*OdHb",
        "w@?D1",
        "ijD;E",
        "H,xEko",
        "JKMNR",
        "<WWyr",
        "*A_D:",
        "5 5$5(5,5054585<5@5D5H5L5P5T5X5\\5`5d5h5l5p5t5",
        "J9AjB",
        "<-=A=p=",
        "LO#@F",
        "9\\:m:K;",
        "VW9-8",
        "`\"Z,9",
        "}p1rh",
        "xgPDz",
        "|K/YI",
        "k42Aj4H",
        "}XnQ7",
        "-F}u_",
        "]yg9[",
        "z#S$4",
        "sDyOCh!",
        "6!7'7",
        "id-ppl",
        "wA[3c,",
        "EAX:%08X",
        "jAXf;",
        "zh-TW",
        "R'0K ",
        ")wp)wl)w\\",
        "0AEbdH",
        "=Sxv6",
        ";|M;?[",
        "c|0KdH",
        "c$x^#Ig",
        ".Ksh+",
        "tfWSU",
        "3<4@4D4H4L4:5",
        "nX_],",
        "LogonISReg.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "YwX^+",
        "+S#.'A",
        "HmM^,",
        "*99+o7",
        "<ps-X",
        "^bOv1W",
        "_823w",
        "^Z_0h",
        "D8(HtU",
        "_initterm",
        ";\"6$l",
        "4$5)5=5Q5e5y5",
        "u/h@U!",
        "WpbgS",
        "5!7}5",
        "^~8)0",
        "(y,T<L",
        "(bbe7C",
        "5fco_r&@",
        "L@:Z`",
        "X)E+uI",
        "~Ct,y3",
        "{(_WT=L",
        "Exception caught",
        "=0JdI",
        "~JVWS",
        "string too short",
        "+`!,2d",
        "0uE8K",
        "G=X3b",
        "<bzK<$",
        "]{4/-4",
        "b\\W-K",
        "e')i!",
        "P-%RxM",
        "B`EYA",
        "{W\"W:\"FV70w",
        "25Zl-h^zC",
        "~b$F9",
        "MlGbX",
        "'\\q-L",
        "B~3fv3",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\detail\\xml_parser_read_rapidxml.hpp",
        "3N4b4",
        "meta_data1",
        "2B!{gn",
        "sFbF(",
        "$PSyG",
        "Loop??",
        "C'_WXK",
        "REBOOT_PROMPT",
        "2=4*=",
        "(FHut",
        "\\qmHY",
        "\\0]p]",
        "+EK~[",
        "I[d-|`",
        "RX6*x",
        "jkjlj",
        "2/B{,X",
        "Software\\CheckPoint\\TRAC",
        "6qu!!",
        "y P#K\"",
        ".?AV?$messages@_W@std@@",
        "869C9W9^9",
        "gtf@L",
        "<v1s%",
        "'ElR$",
        "UMa^-",
        "Kfo2H",
        ":,*o$",
        "nq 1+",
        "D8(Ht5F",
        "L$ 3L$<3L$(1L$",
        "i.DVG",
        "H3:sb",
        "5AwJV",
        "xNU\"f$",
        "dsaWithSHA1",
        ";$;4;<;D;L;T;d;p;x;",
        "lLL|>R",
        "value.implicitlyCA",
        "uf^pA`",
        "    Responder Id: ",
        "result out of range",
        "A0K0P0g0l0",
        "nSs4w%",
        "F9kPY",
        "apWgK",
        "(x<d*",
        ";:;E;N;U;q;",
        "\"Zf3)",
        "49b=q",
        "4zp6>",
        "[6vH}",
        "0.<}}8",
        "~1'_2R",
        "VldU<b",
        "`9F/1&",
        "Desktop firewall still exists.",
        "=@fe\\",
        "sad.png",
        "eFr0'y",
        ">Jw\\]w.",
        "/4KDc",
        "$~2K5",
        "$8\\ee",
        "{1+'R",
        "8nrn@w",
        "`,4Z.+",
        "`Xl6k",
        "lx'tC+",
        "#$llFAB",
        "L5/-=",
        "c2tnb191v3",
        ";#;/;4;9;W;a;m;r;w;",
        "no private value",
        "t9WTvX<Km",
        "D9%^p",
        "K4sJ+",
        "weC~>V",
        "0~ qA",
        "&:&\\$|MLHH",
        "j>Lw~",
        "A$?fu",
        "fatal",
        "-/KVf",
        "^W_uy~",
        "6qo@^",
        "`yb-%",
        ">\\A*jI",
        "10181@1H1L1P1X1l1t1|1",
        "2(2H2P2\\2|2",
        "GCqLYP",
        "UVd J",
        "B?3Sf",
        "GQwxL",
        "d.>x[N",
        "<ABSENT>",
        "tkvoD",
        "b1jkpK",
        ",A%$ Qx",
        "C7n%Oy%X",
        "dhSinglePass-stdDH-sha224kdf-scheme",
        "Reboot required by at least one custom action or upgradeability is disabled. Setting MSIRUNMODE_REBOOTATEND",
        "?mZA|",
        "[C~e(o",
        "?#?;?E?Q?",
        "7Va}2",
        " \\R;aB",
        "/>,Zf",
        "X-,UxM",
        "L$x3L$T3L$@3L$0",
        "I#qX4O",
        ";:)m1 ",
        "u|HCQ^F",
        "PEXTRB",
        "IE|hP",
        "T3x=D",
        "mjZ->!w",
        "$DC J",
        "l{.z#",
        "QMssY",
        "/+TdT",
        "Cg1s)K",
        "8!8~8",
        "j/cb.",
        "SSL: Unable to read issuer cert (%s)",
        "GFK~QK",
        "=+=;=F=b=r=",
        "S39VZiM",
        "kEE-kc",
        "&uz2)0",
        "%kAjE1",
        "`W\\45:",
        "B5\"DDph",
        "N\\&}=,",
        "'g~hZ",
        "&ac=;",
        "%ulpmf",
        "am8 =",
        "SSVWh ",
        "TelemetryAPI/0.2",
        ".?AVFeatureSC@@",
        "S\"Qz]",
        "?+?G?c?",
        "\\=udm",
        "qu<x,",
        "<^uI0",
        "hLS^&",
        "O5l*1",
        "<!?C1",
        "6bal?<",
        "SSL_set_session_id_context",
        "YgU,^",
        "R%AE|e",
        "f0&b7M",
        "q ~aa",
        "9AHL:|",
        "4`4l4",
        "Bv,9G4H",
        "6&I+9",
        "?:H]<",
        "KM:k;",
        "9K4u&",
        "m.vK>O",
        "EwvRE",
        "dcK[fN",
        "60}jQ",
        "%d%2$>J",
        "|HUl5",
        "_getUnformedEventsCount@0",
        "4OX :r",
        "])/[m7Wb",
        "0J_w},",
        " 0xd8",
        "Q{$Z%",
        "LmwR!",
        "/#A+k9",
        "9;9^<",
        "U#5?,",
        ".?AUtime_base@std@@",
        "QQSVj8j@",
        "bGn\"F;g",
        ")8y=wi",
        "W}WRw",
        "m__6d!",
        "T,+(W",
        "ySm\";",
        "|nZfu",
        "\"4Qh7",
        "@!D^*",
        "{N(jP[",
        "\\Y>@TJ",
        "n>9Ky",
        "^Q-8t",
        ">F>L>S>]>p>",
        "848O8n8",
        "-}f`lB",
        ":P:|:",
        "[0/M7]",
        "/_;WM",
        "Nj[|tZ",
        "9Y@YF",
        "%u, Writing dump at point of failure",
        "R`/,>",
        "%.%rV;",
        "$ig>U",
        "I6[=t",
        "2ghkR",
        "XZJ^ 6",
        "bta#>`",
        "%P,U:v",
        "unTWz)",
        "Z).V$",
        "NOj4\"",
        "`Gk3S",
        "4=*x2",
        "H0[I'A[S[",
        ",Ii2O",
        "KYBhb",
        "qJP'k",
        "ASN1_i2d_fp",
        "1Fjso_",
        "CP.UEPM.Console.FDE.Authentication.dll",
        "|]mdZ8",
        "RuG{>",
        "}b7z)#",
        "=eLJ{",
        ">v FP",
        ">#?Bq",
        "FeatureAntiSpam:  RemoveAfter:  ",
        "3(3H3T3t3",
        "G~Q~x",
        "70898U8f8",
        "6\\h?(",
        "RC2-OFB",
        "6Zg93R<",
        "nBxz.",
        "`Z/&1",
        "operation aborted by callback",
        "g{f\\p",
        "Zip+0",
        "=-^c>",
        "mjUx+:",
        ".?AU?$wrapexcept@Vbad_lexical_cast@boost@@@boost@@",
        "b8.>R",
        "Nd^q6",
        "{_Q\"m",
        "%!:j8",
        "6I7S7",
        "2#3(3",
        "jRwh,'",
        "%H%G]",
        "$k?GM",
        "W|kSr",
        "D0TH3!",
        "d.rKeyId",
        "JUj#mS",
        "brainpoolP512t1",
        "<@F0E",
        "aosSd'",
        "zh-HK",
        "rk|^p",
        "xG!Pj",
        "lStVe/t",
        "\\vsdatant.sys.delete",
        "*zOTv#",
        "z5E7^^693 ",
        "PESkM",
        "s+9Gwz<",
        "6'5iS",
        "VPf$U",
        "VWh8KM",
        "$8d#(5",
        "T|%[i5",
        "[lmCB",
        "&A\"6)",
        "Content-Length:",
        ",Zw:(",
        "+.5pg",
        "GPr>_",
        "]HAz4",
        "9F{n;_?Q7!W#",
        "HtpwD+",
        ":1:J:c:|:",
        "#HgKn",
        "SVWj03",
        "i6A/`",
        "?\\?e?",
        "(N9:I",
        "n70=m#e",
        "KPkZB",
        "bTB[7",
        "95b/D",
        ",6Ptg",
        "WUSER32.DLL",
        "O==``",
        "DzNR[",
        "K]t9$",
        "@cH|6",
        "D$XPh",
        "=mTbB",
        "9!9+9^9e9s9",
        "JSAmw6",
        "ADASUPPORT",
        "hzz<7.",
        "^7p),Wm8Q",
        "k:mba",
        "z\"RnQ",
        "_P*a)",
        "tsa untrusted",
        "y>LA\"",
        "WM-w(",
        "_u&vi",
        "y6?'LJ",
        "Hn]kX",
        "f*; d",
        "8:<?B*E@",
        "]yE~!",
        "uwsMm",
        "email",
        ";;\"%_g",
        "D$(PVh",
        "XY)mE",
        "qEmG}",
        "cR!+Ph",
        "<%<<<v=",
        "CANT_GET_TEMPDIR",
        "ISO Member Body",
        "Netapi32.dll",
        "Failed to allocate space for cascript handle.",
        "3 3(303<3\\3d3p3",
        "*_small.dmp",
        "=<=t=",
        "=%=C=P=c=",
        "y~l$|&",
        "SSL: illegal cert name field",
        "'NH{8",
        "X>UDd@",
        "prO_'",
        "'`#ol",
        "DO_EXT_NCONF",
        "I~RXl",
        "qfkAf",
        "RETR %s",
        "%R7k5P",
        "`qF!l",
        "on=Vo",
        "IgW!b",
        "kRej!SB",
        "@d$1'",
        "I{5)$",
        "S_SbSh",
        "]62-!qJ",
        "h[#DM",
        "~`bJh8r",
        "J+E6eD",
        "\"EL^,",
        "SSL_CTX_use_psk_identity_hint",
        "'.gEjs(eoM",
        "S=2zn",
        "tzHE 4*)",
        "hnH]-",
        "^WgJ&",
        "?`_bP",
        "J1!Lhd",
        "!iKh)",
        "y|7id",
        "y*,Z2r2d<(",
        "jW;5_",
        "2GB<Up",
        "Ag4rr",
        "PreInstallCheck:  The OS and Service Pack Level is supported.",
        " (q<aI",
        "FAILURE_TO_MAP_SHARED_MEMORY",
        ">$>0>8>P>X>`>h>t>",
        "B^td3'",
        "$BpDd",
        ".pp@0",
        "<1Uc6",
        "UpDA\\",
        ">]DJ<Ms",
        "v[P`Z",
        "cInH/",
        "nTO=d",
        ".\"GO\\",
        "d%))Nd",
        "Jne[Z|",
        "2<e(a",
        "-iwg_",
        "pLotGK",
        "O{>Bx",
        "kV{CW",
        "Yu(hX#",
        "b/jf1li",
        "B).1\\",
        "1(1H1T1t1",
        "XBd>5",
        "?F9#{",
        "626C6N6b6s6~6",
        ":5;=;",
        "1%141:1P1m1x1",
        "^+YuJa",
        "SELECT `Registry`.`Registry`, `Registry`.`Root`, `Registry`.`Key` FROM `Registry` WHERE `Registry`.`Registry`=?",
        "9@9f9",
        "; <$<T<X<",
        "yk%hX4",
        "Y@_--:0",
        ">d>V?h?",
        "Fkhc>7",
        "3myM2",
        " cannot open key 'SOFTWARE\\CheckPoint\\EndPoint Security' -> assume EPS_R80 is not installed",
        "content and data present",
        "b7}5?p",
        "=~2\"='",
        "i~:$b:",
        "Sh}r}",
        "a290G",
        "\\widowctrl\\ftnbj\\aenddoc\\trackmoves0\\trackformatting1\\donotembedsysfont1\\relyonvml0\\donotembedlingdata0\\grfdocevents0\\validatexml1\\showplaceholdtext0\\ignoremixedcontent0\\saveinvalidxml0\\showxmlerrors1\\noxlattoyen",
        "<\"pxS",
        "?n41%",
        "bIJp/",
        "Nz0`v8",
        "1#V2$",
        "Qoc`\"",
        "RunVsmonInstall:  Setting \"",
        ",m!t1",
        "%ot+Y",
        "8)?O}@",
        ":EA\\g",
        "8cKJ/Sl",
        "We are in Secure Client mode",
        "z{6EB#",
        "BDL?=",
        ".\\crypto\\objects\\o_names.c",
        "2,3F3V3p8|8",
        "MEM_READ",
        ";KV0<3",
        "removeOldFirewallFiles",
        ";<Z@C",
        "o8>-[",
        "Z'SW*",
        "`local static destructor helper'",
        "SZ+X\"",
        "GIATZ2",
        "`w*+s2",
        "f_Tut",
        "1L(2N",
        "\\cxRn",
        "X509v3 No Revocation Available",
        "el-gr",
        "G@Z]1:",
        "zTS]GJ",
        "6:6K6s6",
        "%s %s RTSP/1.0",
        "api_ms_win_core_file_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "&k%;$;i",
        "]^,sK",
        "%s %2d %02d:%02d:%02d %d%s",
        "5}T*!",
        "#.N's,@",
        "}(~_/,",
        "Mu.={",
        "jijwj%",
        "qR.Rd",
        "M3NsN",
        "X&uBU)",
        "T$<34",
        "qjMZ0",
        "The RestartResource table does not exist; there are no resources to register with Restart Manager.",
        "BB{?a",
        "d.v2AttrCert",
        "1:2?2D2I2Q2_2g2",
        "failed to query SFA object",
        "SSL_CTX_set_ssl_version",
        "G!t@$k",
        "~Y3q=P",
        "O3EAk",
        "mS0X|",
        "#GYvl,e[+",
        ";%P]QXq",
        "4EEsP",
        "@{* 1",
        "fN~fZ",
        "B1HP2",
        "EPC_Default_VPN = NO",
        "Q}VOL{",
        ".\\crypto\\ocsp\\ocsp_lib.c",
        "EYfHE",
        "Xq[iy",
        "K5\\\\8",
        "0pya-",
        "g3v$;",
        "Failed to modify view with updated record",
        "no chunk, no close, no size. Assume close to signal end",
        "SdVb\\",
        ";H;;%",
        "4 5P5",
        "EVP_DigestInit failed",
        "Fy3r1",
        "R6FA6",
        ";vS>u",
        "BJxdUg",
        ")w--Z",
        "^%M|T",
        "9(qU!",
        "<Rh1[Ixf/lQa3",
        "5\\*q?",
        "a?U>G",
        "o}x+B",
        "^XHdY",
        "di;eU=",
        "<\\u,;",
        "l$ VU",
        "Maxdownload = %I64d",
        "&Check Point Software Technologies Ltd.0",
        "1:1g1",
        "WD_StopServiceFromSCM",
        "b/v*Qc",
        "{p=B]",
        "/U m(",
        "WQb1S*:k",
        "s)3tLX",
        "cw/BF",
        "KmXdw",
        "!e[t/",
        "NfB]]",
        "roomNumber",
        "\\s40\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af38\\afs16\\alang1037 \\ltrch\\fcs0 \\f38\\fs16\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext40 \\slink41 \\ssemihidden \\styrsid15147522 ",
        "Found SBA InstallProperties",
        "9g%oEs.+",
        "7 7(70787@7H7P7X7`7h7p7x7",
        "SSL Engine not supported",
        "neu%f%",
        "~uTx<",
        "'u8ZT",
        "(rgh3(.",
        "RsU[Q",
        "???s?",
        "UcN1a",
        ">f?x?",
        "7mKj,",
        "xU&Wl",
        "returned code: %d",
        "0b0g0r0]2",
        "><>x>",
        "cvX^RV",
        "'`t>1",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 8. PRE-RELEASE VERSIONS}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "mO=9x",
        "WixRemoveFolderEx table doesn't exist, so there are no folders to remove.",
        "`1'Y}6g",
        " )8Pn",
        ",ITkNAB",
        "6$676J6_6z6",
        "DSA-old",
        "er'uD",
        "fOgSz",
        "l&HT,",
        "5ogH%K[",
        "Enterprise for Itanium-based Systems",
        "^p?xC",
        "Ul.]iLY\"",
        "&&$SO",
        "XR27L",
        "&N''iN''i",
        " 0xa9",
        "$Dr5KC6",
        "_ WHx",
        "}kwui",
        "PWWWWWWWj",
        "?@|E6",
        "[^g)=",
        "./fT;",
        "T=,Gw",
        "9~\"A(P",
        "{\\f64\\fbidi \\fswiss\\fcharset161\\fprq2 Arial Greek;}{\\f65\\fbidi \\fswiss\\fcharset162\\fprq2 Arial Tur;}{\\f66\\fbidi \\fswiss\\fcharset177\\fprq2 Arial (Hebrew);}{\\f67\\fbidi \\fswiss\\fcharset178\\fprq2 Arial (Arabic);}",
        "X%%C5\"",
        "223p3",
        "PkXkZ",
        "LH+6T",
        "d>bu_Gx",
        "OpenSSL default user interface",
        "ulxxL#",
        "aoN0Q",
        "],)M8",
        "-*txA",
        "~f99F",
        "2zYx.>!_",
        ">-~V<",
        "%8s;I",
        "ms&~XSk~k",
        "E0C0A",
        "Failed to open new temp file: %ls",
        "n\"zCN",
        "K:\"00",
        "ADbQ8",
        "p]A\":g",
        "Etw'.",
        "~R_R;",
        "7T7X7h7l7|7",
        "id-smime-aa-ets-signerLocation",
        "vbJLB",
        "TS_RESP_CTX_set_signer_cert",
        ">iF2cL",
        "HhG.C",
        "&T0\"b",
        "r*f;u",
        "aN&^X",
        "StopInstHelperSuccess.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "[C!U$=.",
        "{K^`U",
        "O_[+;wX",
        "}IJUx",
        "YueO6",
        "ygE]JG",
        " ^{I'uQf",
        "BA7Ed",
        ":AcJI",
        "3$4F4=5]5",
        "0)zhA",
        "y&r~Q",
        "Iua,=",
        "[RsA.!#",
        "o,`^\"",
        "twuCm(",
        "RegEnumValueA",
        "YXwNx",
        "F\"&Iz<B",
        "][^_Y",
        ";$;/;a;o;{;",
        "z<w}&",
        "yo^9%|R65",
        "lMuJO?O",
        "id-mod-ocsp",
        "HTTP error before end of send, stop sending",
        "`/a):",
        "[(<Bn",
        "3T$(!",
        "\\9B_g(",
        "TzGnZ",
        "S/MIME",
        "]V&YP",
        "=d,qA",
        "RlcB(",
        "^gI>udh",
        "BqwU%",
        "8 8$8,8D8T8X8p8",
        "failed to create input pipe",
        "0#0;0e0",
        ":\":J:r:",
        "/{(!72",
        "0}L.b",
        "!p2*M",
        "}i#fh",
        "illegal implicit tag",
        ";r=x=",
        "<2<g<n<",
        "iE!AQ4|",
        "JzuX)JT",
        "INI_FILE_ERROR",
        "[NONE]",
        "V<UYb",
        "failed to get the data type for %d",
        "uF/p6/",
        "J.9jk#",
        "cpd.exe",
        "cZ-0e",
        "4,4h4",
        "~*!)@",
        "B2@C\\Jf",
        "SetEntriesInAclW",
        "__int64",
        "A{Yz(",
        "??K~UG",
        "cQcMQ",
        "*[h!|y*",
        "@lj16tG`",
        "p, 2&(",
        "~a_Zz",
        "Failed to reset to beginning of ca script.",
        "1U2l3W4&5",
        "KcRh<",
        "S=XjS",
        "BIs:|",
        ":5Z^!",
        "XxG-m",
        "eJ,wf.i'q",
        "]X}sBb",
        "8;/}1",
        "<QB4g;",
        "qe1s6",
        "emgt+5",
        "t$TQj",
        "#`t/:",
        "BBPAn$",
        ":&:9:w:",
        "e+o*q",
        "3G-~::b",
        "V>9IK",
        "KI^?.",
        "Securing Object: %ls Type: %ls User: %ls",
        "=,C6e",
        "<(=u=",
        "1B2q2",
        "~iOa=",
        ":%:+:1:7:=:C:I:O:U:[:a:g:m:s:y:",
        "3#4>4a4",
        ",lM{r",
        "JD_|O",
        ".\\crypto\\asn1\\bio_ndef.c",
        "DewFUR",
        "ZwQuerySystemInformation",
        "tvDisableZIPDMP",
        "S;^$/E",
        "LOG_MESSAGE",
        "4M4U4",
        "6f6r6",
        "HY ep",
        ")j'Q1",
        "_]R%h",
        "SksUq",
        "*i$vOZ",
        "pd,f2",
        "^q;7h",
        " !\"#$%&'()*+,-./012345678",
        "{\\title Hardware Warranty}{\\author Administrator}{\\operator username}{\\creatim\\yr2012\\mo7\\dy17\\hr9\\min52}{\\revtim\\yr2012\\mo7\\dy22\\hr14\\min15}{\\printim\\yr2009\\mo9\\dy3\\hr10\\min30}{\\version3}{\\edmins1}{\\nofpages10}{\\nofwords5779}{\\nofchars32943}",
        "nc:y0",
        "{Ra|0",
        "67_@9",
        "WPPlC",
        "|a%$0I",
        "3Mh]l",
        "70Tr5 ",
        "$nU`y",
        "FU\"U$U3U8U?",
        "1$1@1P1\\1|1",
        "l0p['",
        "<%}w3K",
        "#),)3W",
        "eXcD/",
        "B>&E8>1^",
        "\\f1\\fs20\\insrsid9533499\\charrsid9533499 You agree that you}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2703887\\charrsid9533499 ",
        " 3Jn^Y",
        "c_0+%",
        "Oh[\"i75)",
        "q8yrQ",
        "\\$pUV",
        "_____4",
        "3'3.363L3h3}3",
        "PU^xA",
        "B~'&]",
        "bad srp s length",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid15343697 ,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid15343697 at its election, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "?N3s;",
        "!H88p",
        "|5:).",
        "(|uvht",
        "A\"4Et",
        "xx}67",
        "bad mac length",
        "cms lib",
        "Computer should be restarted after .NET installation in despite of retCode because it can be 0 even when restart is required.",
        "e(eDeceVP",
        "p!ZS!\"?,Yz#=",
        "BG2BGUPG",
        "D06NN",
        ">4>}>",
        "reserved",
        "X22 PiW:H1j4",
        "r$rmquUo",
        "[3U-c",
        "ECDH part of OpenSSL 1.0.2h  3 May 2016",
        "4(444T4`4",
        "@7Zai",
        "pr\"Ph",
        ")>4e&",
        "CW8az",
        "SEC_E_BUFFER_TOO_SMALL",
        "DlhN0",
        "B_o+:/",
        "ar-eg",
        "/)y_mc",
        "uGF(Y",
        "8L{/X",
        "blksize is smaller than min supported",
        "8S8[8",
        "WL=y)",
        "Qg>l?N",
        "h,4/R",
        "|iTQ:,",
        ":?OGe",
        "Sh(wN",
        "YbrFr",
        "E'YNrq",
        "y\"Kba",
        "5_>KU",
        "sFzjE!WX:$",
        "N IFg",
        "9#:-:G:",
        "dam?W",
        "/A-GkD",
        "m(*<Q",
        "qTb+]",
        "=A>[w",
        "S[+Gk8",
        "t$,UU",
        "U%s('",
        "unknown alert type",
        "_;eS=\\1=ys0O#",
        "&v]zT",
        "g|zr0",
        "vQO+t",
        "yw;mw",
        "Y ny/\\",
        "Lzc'Q",
        "X-WG4",
        ":-$2P",
        "s6`*%",
        "wdJp1HJ4",
        "72777",
        "t<hBS",
        "Sap$4",
        "nJa>]",
        "ipsecEndSystem",
        "4M5r5",
        "506:6C6",
        "T2>^\\",
        "onwT1",
        "I6H,Q",
        "[5&.\"",
        "-JQ}(",
        "F$YO#",
        "\"^(/v",
        "%!S{R",
        "V+8u|",
        "&h>V~",
        "uz-uz-cyrl",
        "CgObmJ1K",
        "tvdebug_b",
        "CloZ2r",
        "Hy2-m`A",
        "~=pgJt_",
        "<<@/?",
        "a(ing",
        "u:%EY",
        "BIO_accept",
        "thpimpl.ppl",
        "V^8au",
        "YtUQ>",
        "L&mU#",
        "Id-,0Xz-z",
        "6lt-P",
        "rJG'd:",
        "pBa-(,-2",
        "odd number of chars",
        ">bqb[",
        ";';?;q;",
        "OvP:/",
        "[EP:4s",
        "|KU88#gK",
        "jjjjjj",
        "vsdb.dll",
        "1n2Ro",
        "Content-Type: application/ocsp-request",
        "0$f`C",
        "D$<VS",
        "i Wum",
        "PFACC",
        "poP7-",
        "?#?F?[?q?~?",
        "J/Q_y~",
        "D}spB",
        "IR>9;",
        "L9K^f",
        "@`^329(",
        "iJY@U",
        "7:8W8",
        "1|~9zM",
        "QK9iw;",
        "`t(B1O",
        "jFeA K",
        "Bgf-%j",
        "#(Cba",
        "K0MwV",
        "8l.]P",
        " P20\\",
        "s4ximC",
        "t}#-d",
        "Xzc`J",
        ".$,\\$",
        "+89kJ",
        "xlY1,",
        ">;I2d",
        "1!Fg<",
        "=C=w=",
        "c@.Ar",
        "M$kw%~Gl",
        "PCMPESTRI",
        "Kaspersky Lab",
        "NYQW-U",
        "RANDFILE",
        "A+4U9^",
        "d6/LD",
        "jH|(k",
        "error generating tmp rsa key",
        "PRODUCT(s) WILL MEET any REQUIREMENTS or THAT THE OPERATION OF CHECK POINT }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid11349575 Hardware }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420\\charrsid2646135 ",
        "313G3[3f3x3",
        "O=p*Zc",
        "V)f;J",
        "]#1V^D",
        "OSM1)",
        "2gAxU",
        "D$ ][_^3",
        "Ykb^yn",
        "8'8W8",
        "7 7,9",
        "Djy;Z",
        "1(:hl",
        "^&iM^hp",
        "{rEBk@F",
        "^D(?Xzcg(",
        "M#voq[hRZ",
        "-T0s5",
        "M_xO4S",
        "MOVLHPS",
        "4R5Y5k5}5",
        "+WMQ>",
        "rstrtmgr.dll",
        "xa%<b",
        "G~`c[",
        "b-}[Y5",
        "M>Q#p",
        "n$DeA",
        "rg(tS",
        "+dJTu",
        ":O;l;",
        "trX20",
        "cA$\\Q",
        "tiP?Jz",
        "EVP_CIPHER_CTX_copy",
        "U*5+\"",
        "\"SAC0CM",
        "*6%t!",
        "53+Rx]P",
        "0^}`r$",
        "xf~Z{n",
        "414G4P4[4c4",
        "X#DX<<O",
        "IiWw]",
        "HpH8x",
        "0!111A1Q1a1q1",
        "2H2L2|2",
        "<iv48[",
        "cQe\"H",
        "h+u]~",
        "D)I#Xa=",
        "%IXWl",
        "1}8}@",
        "U:ViO",
        "h=L9!P",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  28",
        "86-1*",
        "HCx*-",
        "wQ1U=",
        "tiL8fi",
        "w*#Ga",
        "ws!e\"h,p",
        "<@LYf1",
        ":K;J<",
        ">N?R?V?Z?^?b?f?j?",
        "}Hr@2",
        "6/686Q6",
        " OW{w",
        "03191?1",
        "qX;xS",
        "):7OA",
        "A(\"1H",
        "W'nxj=c",
        "iD{@L",
        "uo\\6Y",
        "<UL-+",
        "h2O^d",
        "\\stat",
        "lv^)l@",
        "`g6?u-K",
        ";)<9<s<",
        "-<k>'",
        "&.Dwvy",
        "N2~d#M",
        "LUUIoN",
        "3&363P3W3c3q3",
        "irish-english",
        "en-CB",
        "@ZdT`",
        "WVzXR ",
        "SO_\\*b/",
        "Failed stopping Watchdog Service",
        "\\qhYe",
        "XJ 8BO",
        ">c*>=",
        "5CEB802AB7E5BE6418F2C25A767717E2",
        "O8ZV+Z",
        "jU[S;",
        "*DX7Z",
        "]K]N]R#",
        ";,<S=S{",
        "~Qi2B",
        "failed to get firewall exception profile",
        "!:`<|?{a",
        "]>KR8L(",
        ";x2/:",
        "setct-CapRevReqTBE",
        "eWe0Gu1u]",
        ";F(u4",
        "EWEgEhEqEyE",
        "Exception code: %08X %s %s",
        "3L$D3",
        "SOFTWARE\\CheckPoint\\TRAC\\Plugins\\ScvProxy\\1.0",
        "2`vs%h",
        "/`!F'",
        "cHx~A",
        "0;C~/",
        "t$ QP",
        ".?AV?$_Func_base@XABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV12@G@std@@",
        "8P9X9h9p9x9",
        ";:;r;",
        "S%Pee",
        "SblB0",
        "9N{ee\\",
        ")n7vU",
        "V$Oe[Y",
        ".?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@",
        "_[dm#",
        "\"@7,f",
        "=pL~ ",
        "EVP_PKEY_paramgen",
        "6<6H6h6p6|6",
        "<A=Q=e=",
        "=+=G=c=",
        "vQ6A2X",
        "!H:=`V",
        "2@3H3p3x3",
        "[F^A>",
        "+$j%^",
        "YANmG",
        "NmA;qLh\\",
        "7Yb6]",
        "B2)6I",
        "2G2T2q2y2",
        "awO]\\",
        ".UW<4",
        "4o&I4W",
        "g du=",
        "F,f1e4",
        "|\\E;x",
        "raB3GPkM",
        "K>hGR",
        "9BCDEF",
        "no method specified",
        "ZY4++",
        "failed to read XmlConfig table",
        "1!2*272j2",
        "-)Gw,,",
        ".~D1\"N",
        "QQDG-",
        "D$@UPW",
        "?(?4?T?`?",
        "DHx.x",
        "tPSVWP",
        "wMIO<R=$Lc",
        "*?x$o",
        ">Z>L\\",
        "9'9S9b9n9",
        "]b#2k",
        "[TH]l",
        "]q'(@",
        "um<BJ",
        "2c2n2",
        "k?DeD",
        "2=2i2",
        "$qWI.",
        "?4?D?H?X?\\?`?d?l?",
        "Cnt W",
        "NWo9(",
        "oV_56",
        "hSwMI",
        "YuC:S",
        "[5t.w",
        "failed setting cipher list: %s",
        "3&GE<",
        ";$<T<",
        "v%r!/a",
        "fl29O",
        "T$(PVQ",
        "#nCI<",
        "ur&8l",
        "!A8<D_x",
        "SEARCH %s",
        "EC_GROUP_set_curve_GFp",
        ";7;X;j;w;",
        "rl`jU",
        "c9%>xJ",
        "?Q\\\"n",
        "^wy$q{",
        "lx~0Ly",
        "block type is not 01",
        "B0\"+D",
        "xr^sd8Eq",
        "InstallPrerequisitesNoWait finished",
        ">m+Pk",
        "5-535;5A5Q5e5o5q5w5{5}5",
        "`e6jT\\",
        "x#!\\W",
        " |]@U",
        "qvFC2",
        "LVX+n",
        "=uB<dj\"",
        "^w!:s",
        "cqu([",
        "3&373H3`3j3p3x3",
        "9!BBD",
        "E5}uE",
        "ipDi_`3,",
        "NS?->8j!z",
        "Zqx-\\",
        "0ARAK",
        "%eL)^",
        "|J,yX",
        "]i9Wg",
        "CZg@$",
        "t0Xo~",
        "Suh`D",
        "OuN}0",
        "kXr;d",
        " WRVPS",
        "UQ_e4\"",
        "3-*m_k",
        "A(p~i",
        "$~&e?",
        ":8:@:`:p:x:",
        "voOS;",
        ";\";N;",
        "8M9_9",
        "d;F?r",
        ".]3t@",
        ":$:+:\\:d:k:",
        "^^\\tJ",
        "8 ;Gol]",
        "Y2.8,.",
        "Home N",
        "7;8J8",
        "]|]r]v]",
        "UQ)f_",
        "ar-KW",
        "w%`?#(+9",
        "a;?{;alV",
        "3\\$D3\\$<3\\$4",
        "LICENSEKEY",
        "FqRvf",
        "? ?$?(?,?0?4?8?@?",
        "$1`b\"",
        "Q /t~g:",
        "KPs-!",
        ".Fv~ ",
        "A+8(|",
        "Ygd`UW",
        "? ?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "ENGINE_SET_DEFAULT_TYPE",
        "+`FF{",
        "b$ M!",
        "<\"<3<l<",
        "v~6`.",
        "/[>vb",
        "4=8T92",
        "|2x/@",
        "27):e",
        "cNAMERecord",
        ">;>E>",
        "x=ZFt",
        "Ly\\Mi\"",
        "t$LRQ",
        "6,6G6f6",
        "URLFUninstall finished.",
        "kA?05r|:",
        "3E7fhN",
        "xi;5h",
        "TA!EYr",
        "cz:W`",
        "E3p0M+'",
        "(=Boj5\"",
        "02f7o",
        "Content-Type: text/plain",
        "<QzW*",
        "+S#M>",
        "9@:R:\\:s:",
        "([9Ta",
        "FZVVc",
        "0f;2t",
        "9#k#D",
        "f^W])-R",
        "!\"gOv",
        "0\"1=1",
        "!3ycp",
        "L3FwN",
        "Af,kf",
        "i2o_ECPublicKey",
        "PHkfbtG1",
        "&_m:;",
        ":bZW]a",
        "^5>74",
        ">s0%s",
        "hcuM\"I",
        "0BWq}",
        "03I+]@",
        "?*?M?|?",
        "E+/AF",
        "4)586a6C7",
        "<i-R54",
        "X#YcY",
        "Changed condition: %s",
        "SA&++",
        "h^NW@",
        "W ^75",
        "Low Version is not in a word format",
        "=E!4!",
        "tJ L[",
        "cp@j,",
        "0)tDD",
        "`U6ZO",
        "*.Z _",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 ",
        "?=p`V",
        "PWhXu#",
        "74002f0069006e006400650078002e00680074006d006c00000000}}}{\\fldrslt {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\cs24\\f1\\fs20\\ul\\insrsid923653 contact}}}\\sectd \\ltrsect",
        "; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\\;",
        "XB1AZ",
        "CJc!|y",
        "P')c>",
        "iApeH[v",
        "NRaoK/",
        "8 9<9`9",
        "LocalContextCacheSize",
        "HB&UI",
        "8-B|{",
        "ZO#d|",
        ";8;T;p;",
        "GetSystemWow64DirectoryA",
        " w'LI",
        "OpenProcessToken",
        ".?AV?$ctype@G@std@@",
        "~K70X",
        "40444H4L4`4d4t4x4",
        ".?AVRegError@@",
        " /vIa",
        "!J'H1",
        "WFADl",
        "v7$Gc.[",
        "kbRXJB",
        "4*4X4s4",
        "BNj}E",
        "[qzvq",
        "4IQ4K",
        ".?AVformat_error@io@boost@@",
        "=U=K>q>",
        "$%m&W",
        "=.>q>",
        "h_}*x",
        "uu\"&n",
        "5WbzVQjy",
        "3d7KpD",
        "kl0A$U",
        "#yb;R,*",
        "yfT&$",
        "wgTM5F",
        "|Zb\"\"sF~",
        "7R7$9D9",
        "Heyen",
        "E\"q^%",
        "\"2%t5,U",
        "]|x1r",
        "idea-cbc",
        "WindowsFolder",
        "= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\\=`=d=h=l=p=|=",
        " vg}a",
        "YR>LG",
        "&(A85l~",
        "JGVn$",
        "BuDDN",
        "R18&L",
        "Pp>A>_T",
        ">.?e?",
        "EAPTYPE",
        "(n2_{",
        "defghijklmnopqrstuvwxyz{|}~",
        "g:^]4?",
        "cu;r^",
        "TzK47",
        "D$$_^]",
        "You must be logged on as Administrator.",
        "w7~p0",
        "C@~g;&",
        "8moYc",
        "y0xO ",
        "aQcQO",
        "iY33R/",
        "[i8o]4",
        ":/tqh",
        "<W4M!",
        "characteristic-two-field",
        "8#898K8T8b8t8",
        "vi$@R",
        "X500algorithms",
        ";s<C=",
        "Q\\o|NZoc",
        "A-=f|",
        "nT+/)",
        ")uu!Ph",
        "MaxPolicyElementKey",
        "F$gJ-",
        "k=slL",
        "5.>v3>",
        "ZP?;d",
        "4FRb#",
        "jmjlj",
        "> ><>X>t>",
        "md5WithRSAEncryption",
        ".\\crypto\\evp\\pmeth_fn.c",
        "?:`zL",
        "|d3Vz",
        ",uY^}",
        "1Y=;2i3",
        ":}@o:",
        "YC|OF",
        "w{JzO",
        "G]:G.",
        "K6W6j6n6y6}6",
        "BTehn",
        ".?AVSingleWaitBlock@details@Concurrency@@",
        "a2!/n",
        "^ ^4_\".O",
        "p&_(+",
        "}f,}yBYX1#X",
        "</<[<",
        ">,?O?",
        "&&{G7",
        "Register plugins",
        "B Z/K:",
        "C?}fU",
        "Vh$:5",
        ";d:{d{",
        "CMS_RecipientInfo_ktri_get0_signer_id",
        "failed to add temporary record. [Avsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989] folder will not be cleaned.",
        ";{1M\"",
        "dGRz$*",
        "R:P?>",
        "ExecServiceConfig",
        "'VwQ4",
        ".uB6O",
        "s!J#e#",
        "e!rR4",
        "e[bh\"",
        "Pq@N$",
        "attrib",
        "2!212A2Q2a2q2",
        "]22GsPd+",
        "gUx8Fu",
        "azDm3=",
        "Z<D%t<",
        "E8_EeW",
        "\"mp['",
        "-T%LW",
        "zh-CN",
        "wcxMaC",
        "$M\\.$",
        ",0A*S",
        "sv=\\_V",
        "`:B}|",
        "xzAn6",
        ")#b<o",
        "RunVsmonInstall:  RunVsmonInstall finished.",
        ":3Q\"*",
        "f<|\"\"w",
        "spv[c@",
        "FIP\"+'O",
        "RDJ{{8",
        "psyR+",
        "nG]OE",
        "ELYiCR",
        "disknet.exe",
        "\\lsdunhideused1 \\lsdlocked0 HTML Sample;\\lsdunhideused1 \\lsdlocked0 HTML Typewriter;\\lsdunhideused1 \\lsdlocked0 HTML Variable;\\lsdunhideused1 \\lsdlocked0 Normal Table;\\lsdunhideused1 \\lsdlocked0 annotation subject;\\lsdunhideused1 \\lsdlocked0 No List;",
        "MOVHLPS",
        "Xc&Lk",
        "ym9A:>V>W>",
        ":(;{;",
        "+u15U",
        "<8)].8P",
        "zRk@\\\"`",
        "Ad0em",
        "M2dc{",
        "Ff1VD{k",
        "f|XosF.`F",
        "2'kdL",
        "M!yo}=",
        "HJ%{y>c",
        "Y4UP\"n ",
        "9$909<9H9T9`9l9x9",
        "797q7",
        "3&C|A",
        "N\"<r#",
        "X+G|J",
        "lil`Ce",
        "Bti@&Y9@c_",
        "\\$,UV",
        "J~Jn`V",
        "FtXT9bq^F",
        ")Wy-%G",
        "1l1m1n",
        "5MS\\l",
        "lstrcmpiA",
        "QejAg",
        "Kaspersky Anti-Virus Personal Pro",
        ";,<q<",
        "cWQbl=",
        "8F(Lm",
        "ectc`",
        "$dD^L",
        "RC5-OFB",
        "GXSVj",
        "@3{Xd1",
        "pkcs7 add signer error",
        "_[TV0u",
        "66u|_",
        "'Q(Oq",
        ".?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "6,686X6`6l6",
        "$+!,M*",
        "ExitCode",
        "P&kG(",
        "ryJHY2",
        "u+rFH@",
        "talra9H",
        "zE%GS",
        "y-<E?",
        "E\"xpgxT",
        "&oe!0",
        "key values mismatch",
        "CmH~srn",
        "CURRENT_USER\\",
        ".\\ssl\\s3_enc.c",
        "9c9p ",
        "ASN1_unpack_string",
        "yAPgB",
        "COMMONFILESFOLDER_DEVICE.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        ">G0&m,#",
        "vna_install64.exe",
        "; ;<;X;t;",
        "(7bi:ffF",
        "`cAl`",
        "+t[$1-)ZH",
        "-${mU",
        "LXch3=v",
        "1D1H1x1|1",
        "`qv/!",
        "KutN$+/",
        "b1=SSNj",
        "$dsl$",
        "uD^vtG",
        "DigiCert, Inc.1 0",
        "<p<t<x<|<",
        "4,5@5H5f5",
        "tgYft,",
        "M$3/(V",
        "RoHNN",
        "`wU? ",
        "N^|}M6",
        "L:oTT",
        "cy&(b",
        "VKur%",
        "i$+?H",
        "fP+v{B",
        "2\"2A2~2",
        "+NQDV",
        "PRODUCTMODE",
        ";<'V1",
        "RW]MO",
        "jGkw]",
        "~R0%P",
        "uZmYQ]",
        "#@(\"3",
        ",,ZO\\",
        "< <$<(<0<H<L<d<t<x<",
        ">pH(<j",
        "A\"b?w",
        "ZyyMp",
        "o7~1q",
        "L;`DC",
        "L@Z_/9",
        "2lgng`e",
        "Failed while looping through all rows to register resources.",
        "a;w0tV",
        "m $1I",
        "{Su8h",
        "std::exception():  ",
        "/u1D}",
        "Q%:.C",
        "{n82P",
        ";9;>;E;L;S;Z;a;h;o;v;};",
        "expected >",
        "`Uy[BLJ",
        "Za%XI",
        "Z#t2_L",
        "Avsys\" --no_reboot",
        "Qhl(M",
        "yaE)^$",
        "3(3-373<3F3K3U3Z3d3i3s3x3",
        "+.T#B",
        "Kfxif",
        "IVsJJ",
        "L=:}8{",
        "9<9D9L9T9\\9d9p9",
        "$T`L<",
        "J+;iV",
        "$FIJINIRIVIZI^ImK",
        "Cg*js!",
        "O.tOm6q",
        "o3Tos ",
        "[Ou)~2bj.",
        "lCFJ2",
        "The registration of zlscv.dll was successful.",
        "&W09^<",
        "uB>q%",
        "pkS{!",
        "%60,q",
        "T/o+i",
        "|d&ZN<=",
        "Ub)JX",
        ":(:A:{:",
        "203l3",
        "Wdr+!",
        "CE PWV",
        "ysl(C",
        "QR:WD",
        "FS61h",
        "Y'w7[6`",
        "1BX_^M",
        "R+3g}*U",
        "|,-Y'",
        "Pex?0",
        "08R1G,",
        "3I@t3",
        "Failure occured while processing WixRemoveFolderEx table",
        ",DIR*p",
        "(;GQ ?",
        "]_cd3",
        "KqkG#",
        "4%4-454@4E4K4U4_4r4w4",
        "i-(4#eUgfTV",
        "<0<:<o<",
        "Z9\\^a",
        "failed to get firewall rules object",
        "4.4B4R4b4r4",
        "\"6?#OI",
        " SC}Wr",
        "J-!dP@",
        "7`8+9",
        "TS_TST_INFO_set_nonce",
        "D$(h^",
        "S%_Vz",
        "J/[]cM\"M0",
        "Od% <",
        "8=-bk",
        "5>}>#ft",
        "d(Hm#;",
        "Rf^;ct",
        "c^k*,5",
        "RxWbA",
        "HN8%_",
        ">R9VF",
        "cETCwWTg",
        "Vsc-V7",
        "zyKia",
        "Z PS6",
        "4(4L4l4t4|4",
        "5I6{6",
        "?(WdP",
        "Cdpnv",
        "6T)@-}",
        "(jamB",
        "'h9U&",
        "u|{&,",
        "zZM; ",
        "d:EHB",
        "_<+N2Sp",
        "2:2g2",
        "5!6,6l6t6",
        "395x5",
        ".?AV?$clone_impl@U?$error_info_injector@Vtoo_few_args@io@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "FaJ5LI",
        "{dbb?2",
        "WF_e*f",
        "T(*m~",
        "5[9!dsq",
        "CertGetCertificateChain",
        "WJ?,C",
        "/|Zdh",
        "f6r3A",
        "&OePW",
        "piJf.\\",
        "$*Y%-",
        "L{zL}",
        " 0x6a",
        "jCeu|9",
        "9Q:UVb",
        "IFv&~",
        "]~u=j8",
        "TH}2RZ",
        "&5/v@",
        "F#$23n{",
        "9(:g:t:",
        "\"%sPiReg.exe\" \"%s%s\"",
        "AxJsv|",
        "$:Q%~",
        "4'4?5I5?6I6p6",
        "[e_F(z",
        "HggSS",
        "CR-5:-",
        "VMq3I",
        "><Y8Pkf",
        "cxQ?%",
        "FileHash_ST:SecureFile:HashDB:OS:cpbcrypt:DataStruct",
        "~I~9~ApI",
        "j7]w`w",
        "6:6r6",
        "unknown",
        "[&sJ<",
        "Z>;KC",
        "XttWO?",
        "6 A.;R",
        "DH-RSA-AES128-GCM-SHA256",
        "KKZ4V@",
        "*^KOA",
        ")Ap=70",
        ">J?T?g?r?",
        "=D6Kf",
        "-<zHE",
        "&9,[Y",
        "==>B>",
        "M-LOG",
        "V[jrD",
        "415N5",
        "RegMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "SB>Xy",
        "ctx->buf_len >= ctx->buf_off",
        "6pxk_2gBC",
        "2;?1[",
        "Yn+?!^",
        "]z\"2V",
        "pD7H\\xg",
        "'+*%^ah",
        "Vh8@M",
        "2[zuj",
        "O26*6",
        "U9UAUEUQUSUWU[UiUq",
        "2,uv-",
        "DK1^a",
        "^^>kc=P",
        "blxlMI",
        "@8M8Zy",
        ",_Tak",
        "Zi-C3t^",
        "0EZ-#:",
        "q5IP$r",
        ",aH|a",
        "&JaUh",
        ":4w6w",
        "1(141T1`1",
        ". X&w",
        "cViL>",
        "Y%baWi",
        "Tx]Cj",
        "P3P4P5(",
        "R< sc",
        "LrQN!`[f",
        "GetFullPathNameA",
        "505u5",
        "t$PRQS",
        "DQ@2>",
        "Found %I64u bytes to download",
        "PVVj0V",
        "Ta[mm",
        "[r:E+6",
        "Sh,*$",
        "6$7T7",
        "/8Xc{",
        "v|Sp8",
        "0C-<f6",
        "M3$*G",
        "I>39k",
        "es-ar",
        "SlbvQ",
        "QFs#d",
        "a0zjq2",
        "xN~#_",
        "!9d$+",
        "X'9\"K",
        "D$41D9",
        "MsiTrueAdminUser",
        ")MkA4$",
        "1jk#I(H",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid9462072 ",
        "lA!X,",
        "u V&S",
        "._'rL``.",
        "yChW&E",
        "!?0m'c",
        "99<T\")5",
        "Zs!<;",
        "<[=n=",
        "kIGaQ",
        "R*Jj^=H",
        "k(V/H",
        "t_4@?",
        "Z\"tySc",
        "/j/&o",
        "3w26j3a",
        "kQOfy",
        "gKH_4",
        "tc;L$",
        "NO_PROXY",
        "setct-CredResData",
        "value.named_curve",
        "SVWhT",
        "Vt%L7",
        "tXGA:",
        "r*nbwx@",
        "3OJ*5f",
        "u7CV+",
        "_Ca3Q",
        "-t-4/H",
        "<,3<d",
        "[lC b",
        "xikxp",
        "P4]5#G",
        "qRUJ;{",
        "]Jv<pX",
        ";:|78",
        "McAfee Internet Security",
        "`8IoT",
        "j[=@9R",
        "5q}<&",
        ">d>n>y>",
        "/B]z%",
        "'A,dI",
        "< <<<X<t<",
        "25SgT",
        "%f>Gc8",
        "g1'[}n",
        "`uDM&",
        "3Kpl%",
        "8_zL@e",
        "ZwxWii)E",
        "ENGINE_get_prev",
        "122F2r2",
        "M$pM-)(",
        "/'1$(",
        "?!?/?3?9?B?J?R?W?]?c?i?n?v?{?",
        "LL!&|",
        "r>I@ ",
        "Vb74!",
        "t$$WV",
        "]0^0_0`0",
        "O98S=",
        "Mh)V#",
        "\\jj6Z6",
        "|s{;0p%",
        "*j^2z",
        "1(z5/?l",
        "fm<Pm",
        "}qb8,",
        "WhP<!",
        "OnUpgradeAfter:  SetProductMode",
        "[LICENSING] ERROR: (moving) wrong number of licenses after moving (expected %d)",
        "OFI8v",
        "wfUZZZZZZghiw",
        "2<2J2_2",
        "= =$=(=P>T>X>\\>x>|>",
        "insertVsmonDisabler;",
        "G '2}%,",
        "ste'1",
        ":k;p;v;{;",
        "`.o=X",
        " (( X",
        "IY^yO",
        "('|C`",
        "+Rmid[",
        "ddddd",
        "swx&J",
        "pX0XG",
        "zb6w}",
        "/{o L",
        "o!tRs\"",
        "V99ho",
        "Xlh&7",
        "Cofactor: ",
        "d9 Sx",
        "hh j#",
        "4(idC",
        "Z&a!p",
        "te+'B",
        "^1DZoU>",
        ",,,,,,,,,,,,,,,,,,,,,,,,?,%",
        "!)[+@?",
        "7.9@9v:_;",
        ">xbqJ",
        "(u|2H",
        "i!J6E",
        "HG|BA(1",
        "Q\\\"g+n",
        "9E WW",
        "Y~!8]",
        "%*sIssuer Name Hash: ",
        "jK5XyOW",
        "P_`b,",
        "\\H>5J",
        "invalid group order",
        "j>z1c|",
        "z@J'za",
        "[T\\QHF",
        "id-on",
        ";1;M;R;_;};",
        "ssl3_get_key_exchange",
        "=U=h=",
        "UbaTh",
        "0HQ3c",
        "-lOLh",
        ":hZbA",
        "pkcs12 algor cipherinit error",
        "v1Bs ",
        ">=?M?",
        "PGQut",
        "384W4",
        "f^K\"5",
        "NpT_K",
        "EWs)k",
        "CryptHashPublicKeyInfo",
        "415D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        "I[Zad",
        "WV;|qk",
        "v+Kg&",
        "RESETVPNCHOICE",
        "repair",
        "^Kq0_a",
        "E6wY* ",
        "3%3W3y3",
        "ndE;*5~",
        "=dled",
        "l8ZYq",
        "t$$hp",
        "rF#)q",
        "?7)+z",
        "P# pP",
        "yC>;)1>Zg",
        "r{DYlU",
        "7au{c2",
        "6@N;xi",
        ".<jynyryvy",
        "(HtMf",
        "4Td@CUc",
        "Z;p^ 3",
        "Zone Labs self-generated first chance exception dump. Use .ecxr to see the correct fault stack.",
        "1!$C,o",
        "%BR `HsK",
        "V'Q#a",
        "aRQ#*",
        "Access denied. %c",
        "3\"3.3;3E3Q3_3m3r3~3",
        "keyUsage",
        "T_w@;",
        "~evu$",
        "G#bF ",
        "[4q$`M",
        "Q?0e[",
        "4gI_1",
        "`fZ^|",
        "CFCV!",
        "4.4n4",
        "^oEZ_",
        "?x,T7g",
        "Failed to insert new property record",
        "+/,o,",
        "3t$P3",
        "XzL=6",
        "ISATM",
        "\\;Z5j5",
        "2T3k3N5",
        "3H4Nd",
        "1,}\\f",
        "~Kp=J",
        "e3Xf?",
        "3D$,1",
        "2759N",
        "%`)qn",
        "e~-,U",
        "SAME_SA_VERSION",
        "6)i$9",
        "(lLirl8o",
        "[([X[",
        "WD_CheckFolderForZAUpdates",
        "'V>F`i",
        "\"aK&JhY",
        "0g@Of",
        "Ig#X.",
        "^Rc;b",
        "*yrWhn",
        "bad tag",
        "SCRemoveBefore",
        "fGtS|J",
        "eWwa~j",
        "od~8d|",
        ".t%JW",
        "H32o=",
        "\"}i~R",
        "5X6v6",
        "[Self Validation] Msvcrt Fatal",
        "hu.`d",
        "S1A+T",
        "sxW)3",
        "4_Y?4",
        "1/i4X",
        "LLLLLX",
        "5'd^G",
        "k%<$`",
        "nJa8(",
        ".`\"(<;'",
        "MOVUPS",
        "3lG/,",
        "X_^wI",
        "C*v{!",
        "0Q#S^H+",
        "*[Z1Ll~'",
        "CertFreeCertificateChain",
        "l7A*1",
        "- abort() has been called",
        "(CC3g",
        "84N{X",
        "*65u9",
        "v-tUE3v",
        "z;gS-B+",
        "O5C|(",
        "NccC<",
        "!~OaW",
        "&yO*T",
        "d{!Bp",
        "_initialize_narrow_environment",
        "!/|>WK",
        "d$P_^[]",
        "_pv@5",
        "5K6e6[;",
        "c'!l%)",
        "=ETT~'|#r",
        "|rb|c",
        "CheckConnectivity.exe\" curl_cli.exe",
        "|i/xV>",
        "5,515@5f5k5}5",
        "yKnBs",
        "Failed to open MSI database view",
        "kIk;JiH",
        "?,?4?<?D?L?T?\\?d?l?x?",
        "?^S&e",
        "JnRk4",
        "\\KOx$aIX",
        "invalid string",
        "spPc0",
        "!%\"NE",
        "qD[I@h",
        "Me,yF",
        "$:KL2",
        "que?kW",
        ",@7UIt2",
        "DSA_SIG_PRINT",
        "6P6T6`6h6l6x6",
        ";kE(9",
        "Z_vAI",
        "i[+y/B",
        "f*rj9",
        "!L{dr",
        "CFMy5",
        "D7C(Q",
        "pyP!pB",
        "*$>+#",
        "s+$Ue",
        "929]9",
        "Em :b,H",
        "\\hash.exe\" verify ",
        "a)BM6",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "R~o\\k",
        "k9+}R",
        "^!e3TZ",
        "nD)0k",
        "D(<lg2w`",
        "!|j2{B",
        "9)919A9o9{9",
        "^(pT}b[",
        "3!3&3?3U3Z3",
        "1:1B1K1V1[1m1t1z1",
        "F|a9y+",
        "(3 vG",
        "8C2S,",
        "D%*6 ",
        "VR!V}",
        "q\\|YR",
        "6)AFD",
        "ERsU[k)",
        ":);P;",
        "h!Opf!",
        "G%Jqw",
        "~dbjCTK",
        "pk%T$XH",
        "xA!7X",
        "N\\;]M",
        "}m(KD",
        "~\\\"2s",
        "=0=L=h=",
        "g0>dUR",
        "p2kfvh",
        ";);L;[;",
        "$QdVT",
        "no multipart boundary",
        "1[3c3i3",
        "$juh0",
        "id>G__",
        "OEpJ_",
        "te[/\"a",
        "jms\\BO",
        "(z$)Z_",
        "I2T&P",
        "sco|G",
        "7E9f9{9",
        ";L<P<T<X<\\<`<d<h<l<p<t<x<|<",
        "fCmI\"",
        "D%*/G@I",
        "kI:mw",
        "DtRUY",
        "****************************** LoadGUI started **********************************",
        "<G-D2",
        "XOXLXQ\\",
        "WSEGetAndSetInstallerRunningMutex()",
        "$4z+%ek",
        ",Mv9Ntw",
        "x}47F#",
        "W$Ryy",
        "p%h<@UVT",
        ">$:sH",
        "@hb9}",
        "QUHWMS",
        "`lAt*k",
        ";Z'1*",
        "the meth_data stack is corrupt",
        "S4pm<",
        "7$7,747<7D7L7T7\\7d7l7t7",
        "W<Q<>",
        "'%%Os",
        "G~NxP",
        "t#_^][",
        "1 1$10181<1H1P1T1`1h1l1x1",
        ",(ZIZK",
        "GetUserDefaultLocaleName",
        "D<=u@",
        "i3)a+t",
        "pupepU(E",
        "Cp\"Kg",
        "m|mx_",
        "MA nO",
        "{b|ti",
        "0Kv*aO3^",
        "$Cm{A:/",
        "P_ZtU",
        "QNUeh%#",
        "5gV;J",
        ":(:A:T:h:s:",
        "lRwv{",
        "7{2`u",
        "eps_endpointBanner.png",
        ";7)fiM",
        "fE?)9",
        "PSpu]o",
        "tm\"2;;",
        "E2xm^W",
        ":$eB|d",
        "3= 8>",
        "PEM_READ_BIO_DHPARAMS",
        "4&4+4=4",
        "'^~MG",
        "r<TWf",
        "`bC0I++",
        " \"yk[",
        "qPF5n",
        ".idata$2",
        "Jy@JQ",
        "EVP_PKEY_paramgen_init",
        "k)VgV",
        "PKCS #7 SIGNED DATA",
        "Z.^;05",
        "P-224",
        "+d=f+",
        "[tcTffYW",
        "Nm^~}",
        "setct-AuthTokenTBS",
        ".\\crypto\\asn1\\tasn_prn.c",
        "Failed to save driver telemetry into registry.",
        ";#q5@",
        "5{5.N",
        "515J5c5|5",
        "'nQ>#",
        "q7.sa:\"",
        "jyjwj\"",
        "GM#M%M4M9M@M_MjMv&",
        "M{6=2",
        "Rr$E$",
        " 0x6d",
        "t >= 0",
        "KVMr#",
        "jnPTUt",
        "000<0h0",
        "3/3Z3",
        "DHE-RSA-CAMELLIA256-SHA",
        "8*8>8a8u8",
        "8Ea~8C",
        "\\drivers\\vsdatant.sys",
        "Lwgva",
        "\\.]4j",
        "N#Ao3",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{75D46594-4DE1-4A90-AE74-38637D301EF2}",
        "A{fLT",
        "n3hF\\:",
        "e8] R9",
        "UninstallAS",
        "o(~,j",
        "9 9$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9",
        "#WwtT",
        "A!(;dLhNtRb'",
        ".?AVFreeThreadProxyFactory@details@Concurrency@@",
        "t&i7=",
        "OnCleanInstallDriverRollback",
        "?!?1?A?Q?Z?",
        "}b}Oo ",
        "8!8T8r8",
        "@RotL",
        "kWMg;",
        "clearance",
        "=-@m5",
        "0B0Q0d0p0",
        "x!J&O7",
        "h!9,?",
        "QWHV6",
        "x]D)M",
        "lcs:4",
        "=B=d=z=",
        "W`QfJ",
        "CLIENT_FINISHED",
        "Vm~O&",
        "VjKh $",
        "salu$ ",
        "+q\\^N:",
        ":8;C;m;y;",
        "%VTc6",
        "e-0^v|;",
        "p$KGS",
        "SXNET_add_id_INTEGER",
        "LDAP local: %s",
        "3L$L3L$03L$$",
        "=*`%B",
        ")9[Z9",
        "$~{@h",
        "#1h9v!O",
        "E6;lw",
        "originatorInfo",
        "<#<T<a<",
        "p+nShL",
        "_;}7YT",
        "<,<1<",
        "~3Ih$a5",
        "^RVu9:D",
        "PREFETCH",
        "@Q]2q=",
        "282L2",
        "W*&`[0",
        "^l?)[",
        "DES-EDE",
        "Malformed encoding found",
        "S@ 'YuA",
        "96QL<",
        "7&7N7",
        "Ff`}T+",
        "#KPn/",
        "banProtection",
        "Sr>tr",
        "L$\\UV",
        "%s\\Default\\*.cppol",
        " 2 yo",
        "edxcg",
        " y$nR",
        "JeT?o>BxW3",
        "2/31435N5i5",
        "Hj\\EP",
        "#F\\+.*z",
        "=lT~P",
        "<W[TI",
        "T$<3L$@",
        "__thiscall boost::uuids::detail::random_provider_base::random_provider_base(void)",
        "%x %x %x %x %x",
        "&Z}gW!",
        "v2i_GENERAL_NAME_ex",
        "?S?t?",
        "Rethrowing unknown exception in logger",
        "?`,(J",
        "3/3L3i3",
        "KVj6Sq",
        "CryptAcquireContext failed twice {} and {}",
        "I~/0<E",
        "[>r?g",
        ",N]Z ",
        "j:6c6",
        "3L$83L$0",
        "*wOIj",
        "#!FADd",
        "223f6",
        "ess signing certificate error",
        "w\"~cY",
        "& RwM",
        "ZX|:Fk",
        "96UG9p",
        "_@c@e@h",
        "2h|G)",
        "HXrCO",
        "(JJ(Yw2{b",
        "2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0",
        "`LX;j",
        "vna_utils.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "`]13b\"`@[",
        "xfGA;",
        "B9Q2]",
        "key gen error",
        "3X4q4{4",
        "[ys\\:qrR",
        "vH0[4[",
        "X{0.3$_",
        "Xq<K=_",
        "cga5l",
        "5zr~03,",
        "{/lrx",
        "iv@F@M",
        "0/0Z0",
        "_o$0d",
        "4BBI@",
        "c_SAiq",
        "K3V6.",
        "$,FWdO",
        "080G0R0W0\\0z0",
        "999o9~9",
        "[DUMPFILE] zipping thread received early exit signal.",
        "$>nzL",
        "'d)$gZ",
        ">AUTHu-",
        "Fault %p in exception filter (double fault) at %p %p:%p %s",
        "{N,sk",
        "yFu[hSn!",
        "*C?p}",
        "O>II=",
        "%127[^= ]%*[ =]%255s",
        "3\\]UV",
        "vXv)kz\")",
        "FGKp5(",
        "j4)<[",
        "0cq'A",
        "Starting watchdog after successful install without NoGracePeriod",
        "KCcIheb",
        "eEHA*(Z",
        "gUU23",
        "`0J2 ",
        "TXJpQ8.",
        "ZUCkV",
        "6&7f7",
        "w)Ns2>",
        "#KYDstd",
        "VbbH ",
        ">\"mS*",
        "%>MR<",
        "pAfA3",
        "L;h&5j",
        "=5V2|",
        "W$$:b",
        "D<.jt",
        "90LX$",
        "5nt_J",
        "unable to decrypt certificate's signature",
        "Ik=(B!",
        "#a&jy",
        "9zv>;",
        "{X^[_]",
        "[VSDATA LOAD] data mapped",
        "fH[bQm",
        "ZH 0A",
        "[h:BS",
        "Uh\\.a",
        "!l7&S",
        "@`*0 ",
        "L?dK8M",
        "qer+6",
        "H 8P!$",
        "Z)\\(ow.c",
        "@E\"m5",
        "1&1-1W1]1h1",
        "y:%<A",
        ";3! -c",
        ".\"RrR",
        "id-on-permanentIdentifier",
        "t5Ge:vhy",
        ":C:];c;h;",
        ";KWqL",
        "oI2my",
        "f;F,t",
        "_S_SP",
        "0Ab^m0",
        "8%B&o",
        "3$303X3|3",
        "&yMhA",
        "textEncodedORAddress",
        "-lMjt=G",
        "t0Qh5",
        "b'M1*~",
        "_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974AModuleInstallUISequenceCustActionLib.6B6E64A3_4478_4297_9CD9_3D71DBCD974AInstHelper.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974AHash.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974ADisconnectedPolicy.6B6E64A3_4478_4297_9CD9_3D71DBCD974AOrgDisconPol.6B6E64A3_4478_4297_9CD9_3D71DBCD974AFW_INSTALL=\"YES\"{2A6864EF-AA82-4305-8001-6C41DDE49BA7}{7628BF7B-4A89-4A4A-91D9-29FAE875CF4B}{1D5626F0-85DF-4A89-9A39-74C8604B5352}{CCAA09B4-8B05-43E6-80F0-3E49F5D9E1BF}{F17E06DE-E1B2-449D-AC0",
        "hw'lGs",
        "8\\XxG",
        "[qAEC",
        "Q)e(x",
        "h2{ZgH",
        "RBj}e",
        "+X<rJ1",
        "+dYQ)",
        "]r_*U?+{",
        "yY,`2",
        "0qz@^",
        "nh$^$",
        "JNiI\\4UOL,d",
        "{:]Tt",
        "n_.RX",
        "^H\"=~j.RR",
        "HQMR#",
        "D$HPQ",
        "#6(4:",
        "@p9-VE%*|",
        "ertain Check Point products and/or features may enable the inspection of encrypted traffic. The ability to define the inspection rules is provided to You and You may",
        "[-6O~",
        "\\Q\\0v",
        "UCCo4",
        "RnN:A",
        "#])L^",
        "=Oh]o",
        "+}@Uw",
        "bOQz0|S",
        "^D>n~",
        "Ct@lJ",
        "ptC%0",
        "k/X|N",
        "f#HFc",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\detail\\xml_parser_write.hpp",
        "?$?,?4?<?D?L?T?`?",
        "'8zZ8+",
        "RR%\"IY",
        "Schedule deletion",
        "3!3,333Q3[3s3",
        "yN1m3",
        "m/&z;",
        "DSA_PUB_DECODE",
        "@P]jD",
        "$@y]1#:",
        "tu;B%",
        ".I0[cid",
        "3(3<3P3d3x3",
        "5p*^P5",
        "unsupported encryption",
        "qv{/N",
        "#eW7gQo",
        "+/BxG",
        "\\,}Tf",
        "b7`<V",
        "I~HJa",
        "}7Qkf",
        "}/Mov",
        "zjI+BV",
        ")/ga)",
        "4$4<4D4L4X4x4",
        "Failed to run MsiGetProperty to retrieve FIXED_MAC. Setting to NO as default.",
        "e9$SG",
        "loRoI",
        "CKq?D",
        "jCjhj",
        "wuHUo",
        "='>F>",
        ")T\\9;",
        "/2dQ@>",
        "VSTO_RUNTIME_CLR40",
        "z<v}-",
        "aZ;KM",
        "*?#1*?#1",
        "):.z519o",
        "content type not signed data",
        "@t7[nx*",
        "7Y7e7}7",
        "443,44,e",
        "n!Oba",
        "Iyxz>",
        "d.*@X",
        "7G_-_7_?_G_e",
        "CMS_Attributes_Verify",
        "uI0qn",
        "P'uCo",
        "c*{9x'",
        "cntrl",
        "Error: The length of PATH is larger then we thought...",
        "s]= ^",
        "Hs_\"[VY",
        "X5%#X",
        "--s) @A",
        "d-<Pu",
        "x;G3R",
        "NameTableTypeColumnIdentifier_ValidationValueNPropertyId_SummaryInformationDescriptionSetCategoryKeyTableMaxValueNullableKeyColumnMinValueName of tableName of columnY;NWhether the column is nullableYMinimum value allowedMaximum value allowedFor foreign key, Name of table to which data must linkColumn to which foreign key connectsText;Formatted;Template;Condition;Guid;Path;Version;Language;Identifier;Binary;UpperCase;LowerCase;Filename;Paths;AnyPath;WildCardFilename;RegPath;CustomSource;Property;Cabinet;Shortcut;FormattedSDDLText;Integer;DoubleInteger;TimeDate;DefaultDirString categoryTextSet of values that are permittedDescription of columnActionTextActionName of action to be described.Localized description displayed in progress dialog and log when action is executing.TemplateOptional localized format template used to format action data records for display during action execution.AdminExecuteSequenceName of action to invoke, either in the engine or the handler DLL.ConditionOptional expression which skips the action if evaluates to expFalse.If the expression syntax is invalid, the engine will terminate, returning iesBadActionData.SequenceNumber that determines the sort order in which the actions are to be executed.  Leave blank to suppress action.AdminUISequenceAdvtExecuteSequenceAppSearchPropertyThe property associated with a SignatureSignature_Signature;RegLocator;IniLocator;DrLocator;CompLocatorThe Signature_ represents a unique file signature and is also the foreign key in the Signature,  RegLocator, IniLocator, CompLocator and the DrLocator tables.BinaryUnique key identifying the binary data.DataThe unformatted binary data.ComponentPrimary key used to identify a particular component record.ComponentIdGuidA string GUID unique to this component, version, and language.Directory_DirectoryRequired key of a Directory table record. This is actually a property name whose value contains the actual path, set either by the AppSearch action or with the default setting obtained from the Directory table.AttributesRemote execution option, one of irsEnumA conditional statement that will disable this component if the specified condition evaluates to the 'True' state. If a component is disabled, it will not be installed, regardless of the 'Action' state associated with the component.KeyPathFile;Registry;ODBCDataSourceEither the primary key into the File table, Registry table, or ODBCDataSource table. This extract path is stored when the component is installed, and is used to detect the presence of the component and to return the path to it.ControlDialog_DialogExternal key to the Dialog table, name of the dialog.Name of the control. This name must be unique within a dialog, but can repeat on different dialogs. The type of the control.XHorizontal coordinate of the upper left corner of the bounding rectangle of the control.Vertical coordinate of the upper left corner of the bounding rectangle of the control.WidthWidth of the bounding rectangle of the control.HeightHeight of the bounding rectangle of the control.A 32-bit word that specifies the attribute flags to be applied to this control.The name of a defined property to be linked to this control. FormattedA string used to set the initial text contained within a control (if appropriate).Control_NextThe name of an other control on the same dialog. This link defines the tab order of the controls. The links have to form one or more cycles!HelpThe help strings used with the button. The text is optional. ControlConditionA foreign key to the Dialog table, name of the dialog.Control_A foreign key to the Control table, name of the control.Default;Disable;Enable;Hide;ShowThe desired action to be taken on the specified control.A standard conditional statement that specifies under which conditions the action should be triggered.ControlEventA foreign key to the Control table, name of the controlEventAn identifier that specifies the type of the event that should take place when the user interacts with control specified by the first two entries.ArgumentA value to be used as a modifier when triggeringBMX$",
        "XLIC7",
        "8i8t8",
        "M`MMMM",
        "\\1G]n",
        "C<B)D",
        "] ]*].]:]B]H]T]\\]",
        "v~,Ol",
        "&uU#R",
        "`1#k(",
        "@(/nU",
        "u*4/$\"]gK",
        "Eo\\4C",
        "q42$X",
        "3psC'dcG,",
        "0NgN_",
        "S3S;WC?l",
        "z+i+)!Ij",
        "VXs|GX:[",
        "An?nd",
        "Pe%N`Y",
        "daO&5",
        "-d'f+",
        "TF`Nhn",
        ")8^n6<af",
        "1ip0o",
        "/{Ktjl",
        "xIxix",
        "@>ML*",
        "l$T#T$",
        "n;KO>",
        "k_3,k:z",
        "rs*8K",
        " 0x66",
        ";-;H;L;P;T;X;\\;`;d;h;l;p;t;",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\efr.cpp",
        "|58#C_n]",
        "b{#gQ",
        "MLbBu h",
        "5U5e1",
        "G0~$}",
        "Timeout while execute firewall exceptions",
        "6;6J6T6a6k6{6",
        "@D@rc#",
        " !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~",
        "T%?Qnr",
        "\\]b\"Zk?D",
        "\\$ ;^0",
        "A/L*izOUN3a",
        "R+$WI",
        "Ja*A+cL",
        ".?AV_Node_endif@std@@",
        "DHE-RSA-AES256-SHA256",
        "9!:C:",
        "v^ofa",
        "?1f6v.",
        "%sRegMonitor.dll",
        "m39>O",
        "HBn(i",
        "J[L[N[",
        "the above Check Point website}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1591330  }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1591330 for }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid16076773 the number }{\\rtlch\\fcs1 ",
        "cL13e",
        "M;+(.",
        "@*=e^",
        "`SL7F",
        "T0Nng",
        "brainpoolP160t1",
        "70P0i0",
        "xw:X-",
        "8Z6?.",
        "zQ+/x",
        "FeatureAntiSpam:  RemoveAfter started.",
        ">%>,>9>?>K>T>z>",
        "{9:_P",
        "m/@N3u",
        "T$$3L$",
        ",\"x:?",
        "18R%b*1'R",
        ":2:=:W:b:j:z:",
        "hi1yOy",
        "dBs.Q",
        ";0;V;~;",
        "c1LO=",
        ">2$3N4",
        "4@4Z4}4",
        "$b?[+",
        "E/akOA",
        " 0x75",
        "m5(`I\\",
        "PreInstallCheck:  Check for 64-bit incompatible programs",
        "%*s%s OF %s {",
        "6w*)G$",
        " 0xdb",
        "O0+37",
        "3~w1'",
        "A MG({",
        "LSl]O",
        " b+DHyt",
        "j5Zf;",
        "e>xG<",
        "t~UR_",
        "DSA part of OpenSSL 1.0.1t  3 May 2016",
        ",j>Zm&",
        "R>%*P",
        "%,\\W+",
        "S'rVX",
        "nt9ZD",
        "SOFTWARE\\KasperskyLab\\sdk\\AVP8",
        "7Z7d7",
        ">1?:?G?i?",
        "atlTraceRefcount",
        "PMULLD",
        "O/szO",
        "Ya^_\\",
        "#'B)Ff",
        "y1UHz",
        "(x?{G",
        "x/0'&",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\RebootRequired",
        "q0WZ@",
        "U[@E9q",
        "{S'o/",
        "w~ M8I",
        ";+<2<",
        "u9#W7LI",
        "lf{&`",
        "6s.80",
        "D(NN{",
        ")#f}x",
        "% Y:.%",
        "2s7#X",
        "j}+*,*|",
        "n J($",
        " y9]T",
        "W>\"NpYZ}D",
        "Custom acion:  OnBeginExec: ended",
        "t`\\E9rt,",
        "9olp~",
        "B.,Dc",
        "~sk-(",
        "p.]jX",
        "'mckBiI",
        ">E.M%e.",
        "xy4DI%+",
        "}[uFo]",
        "fWrO!+",
        " protocol=\"%ssignature\";",
        "j!mYf",
        "343?3I3X3`3h3",
        ";$;0;P;X;`;h;x;",
        "jB)S$",
        "ARc.\"",
        "%s (%s)",
        "5%(jT",
        "dV~~]",
        "YbCcE",
        "TU_'#",
        "wI0RH|",
        " szMsiClientType=%s, SecuRemote=%s",
        "CUSTOMERNO",
        "H%SZ{%_",
        "435n5u5",
        "`<{.CTTT..L--.x`;",
        "pp-x8",
        "N42xW",
        "gVD 4g",
        "wE]@~, ",
        "PHCb?q",
        ">{;)U~",
        "9_0~+",
        "InstallProduct:  InstallProduct started.",
        "PjuLF",
        "-T3G[~A",
        "StopRemediationService",
        "k(Iyq",
        "vc[gO",
        ">\"r(f",
        "ALLUSERSPROFILE",
        "(W\"l{#",
        "gS]Ze",
        "rsE{v",
        ";rg:$",
        "Szd1Y",
        "|rC]D3>",
        "DJAgZ",
        "uk-UA",
        "(m8b9e",
        "4-484?4j4u4|4",
        "Auq 7T",
        "[#[z8",
        "5gKZ@",
        "Plugins::UnregisterSC:  Unregistering ",
        "4`kPR)f",
        "p>l07",
        ";q%W\\",
        ":p}\\^Y`t",
        "August",
        "&`3PCS",
        "8-82888H8W8a8",
        "=w\"mYu",
        "OpenTVDebugLogZip:  error creating zip file, ",
        "GGZ4qKn",
        ";HjX7",
        "jZ2<T",
        "NvU--",
        "#XlXN",
        "CMS_data",
        "dP]\\}",
        "CZrG;;K",
        "zq}qK",
        "5O4n#c",
        ";%Cac\"",
        "U*&wabP",
        "_%*B^",
        "Wf+Gu=/",
        "|0:HY|k",
        "$iVV|",
        "^n6K~6",
        "k\"{\"W",
        "2e&TF",
        "\\Check Point\\UIFramework",
        "3-4K4",
        "Sjmh\\-#",
        "<LbH~",
        "m[nsi",
        "`-iK*",
        "ConfigureClient:  ConfigureClient started.",
        "g'7<ECG",
        "D1D2D2D2D2D2,2Xh",
        "1z&8 ",
        "nombstr",
        "jmjzj",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\SharedDLLs",
        "UA5Fji",
        "2M2S2^2o2u2{2",
        "4l<9<",
        "iti84+Is",
        "dz$|FI",
        "R]F1/",
        "fFB2h\\p",
        "DH_PARAM_DECODE",
        "id-cmc-identityProof",
        "RJGJ\\!",
        "VSIsUninstallInfo",
        "h4iXZ",
        ")d8~hxd",
        "L$ M3\\>",
        "`Ml9Ai",
        "EA}vP",
        "\\`nA(|",
        "yQq:*Y",
        "i2d ecpkparameters failure",
        "EC_GFP_MONT_GROUP_SET_CURVE_GFP",
        "5K&}&",
        "7+7G7c7",
        "6j.:<",
        "l$H#T$ #l$L",
        "?.6@-",
        "II?*<",
        "'dHv#",
        "incorrect file syntax",
        "T\\TNo",
        "Ul00akfo",
        ":3:L:e:~:",
        "0&151G1",
        "0.13181=1E1S1[1",
        "aes-192-cbc-hmac-sha256",
        "2A2V2f2s2",
        "UjbrJ",
        "XYBf&",
        "RSDS-",
        "585^5",
        "1 10141D1H1L1P1T1\\1t1",
        "2$4T4w4U5b6",
        "1*1_1",
        "y}){l",
        "InstHelper.exe",
        "*JX\\F<8T)",
        "SUuw]",
        "{X_^][",
        "^a^e#",
        "gU$\\^",
        "E*b@|",
        "$?N?Y?{?",
        "=i)tPp",
        "FgK=Y'",
        "}5$\\j.A",
        "5\\6~6",
        "w$q5D1",
        "y/'CeU'p",
        "t@5yx",
        "1 10141@1H1P1`1d1t1x1",
        "JmbB)l",
        "QOC 3/",
        ",/NP\"",
        "}y\"a\\c@",
        "7 (]a",
        "\"sC&]",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 7.1\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "<f)\"'",
        "Wt.Vh",
        "@8]Ou",
        "7M2a6",
        "L$@;H",
        "I41.5>",
        "@LY9wa",
        "kZgal",
        "i)Gs)fpo",
        "};yA7",
        "&Pt\"B(*",
        "T<dsk",
        "ca%Su",
        ":T;h;",
        ")~-{4",
        "dH*@dZ",
        "Y0;-{",
        "D|>2,",
        "T3{&6P",
        "IsawGg",
        "tWXeB",
        "8g`|W",
        "^/h6W>",
        "1F2X2",
        "<%<H<",
        "Z1H#i",
        "AUu(+",
        "k/~hR",
        "XwUUK`\\",
        "F,-0,:w.",
        "DIRECTORY_CLASS_NOT_INITIALIZED",
        "|/z'y\"",
        "NTLM auth restarted",
        "L?AQ3",
        "Csd:s",
        "h>h@{>",
        "^!=%#\\",
        "lM}r>.",
        "9{w^O",
        "b5N`F",
        ">%>3>U>i>}>",
        "fZwD+",
        "oJAStd{f",
        "3K3r3",
        "VWXMa",
        "PWj~e]",
        "GFfEL8E",
        "q\"`\"}",
        "TracCAPI.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "za9UZ",
        "R9\"]{",
        "Vh@8!",
        "(Zp`ri",
        "'^NWptn",
        "E9166BDCDB3B5354B9A0FFBA5CB1019E",
        "iDm#:",
        "BrJ }z",
        ":\\iE;eh",
        "7Ek0;",
        "\\1ce8",
        ">0>L>",
        "&H:)z",
        "obE-m",
        "/<Pp9Xd",
        "^BFPT",
        "invalid status response",
        "6r$[+3",
        "0KI~m",
        "pSiOF",
        "2r1G#",
        "DES-ECB",
        "oMc`5",
        "D$@_^",
        "failed to read shortcut path from custom action data for rollback",
        ">:!f9l",
        "x^{/o",
        "`Z\\{[\\",
        "u>VUY_",
        "*],l#",
        ".nrN-",
        "='=4=}=",
        "=F?U?",
        "G-KH~",
        "3 4$4(4,4044484<4@4D4H4P4`4d4x4|4",
        "(B,Zp",
        "rJlE{",
        " 4eq>",
        "VQ&UVe",
        "\"#Y&Z",
        "4 4(4",
        "tL_uyy",
        "WHPh C&",
        "(n7F]X[",
        "OrmM-YY",
        "qw.n5S(L",
        "\"{4;,Y",
        "lS]-D",
        "D$$UPP",
        "no result buffer",
        "]UD53\\",
        "%0Tu)",
        "vp49{q",
        "V\\#-4",
        "k,@^ ",
        "\"=ny6",
        "<jtTi?",
        "nLP8ev_",
        "0#<#O#",
        "`%;m_",
        ">h)%%`",
        "p6mkE",
        "25D'B",
        "/eLT_m",
        "r/oA3$D",
        ";;fH ",
        "successful",
        "WLDAP32.dll",
        "MmA9#5X*",
        "4MQo(",
        "uGN5\\",
        "(>=^O",
        "QRhlX!",
        "A?Y+FU",
        "setct-AuthRevReqTBS",
        "tls1_export_keying_material",
        "R8K!7!`r",
        "3&353@3R3W3",
        "s4XF0+",
        "DelNP",
        "0WbbXEOe",
        "GZ]__",
        "pkMz2",
        "SVWjA_jZ+",
        "$4[k~K",
        "xB};k",
        "1w4^\\",
        "Standalone",
        "pbpBx",
        "P/+\"3",
        "N@b#uH",
        "1!F?)",
        "TG~i4|",
        "PG9j9R",
        "3+455",
        "Failed to allocate string for target path of folder: '%ls'",
        "7h8u.|",
        "a$$PG&",
        ".?AUIUMSUnblockNotification@Concurrency@@",
        "9*:\\:>;W;",
        "5/~Sg",
        "api-ms-win-core-synch-l1-2-0.dll",
        "[PY_o",
        "u5S;e",
        "HeOa?",
        "y.5nC",
        "\"4GdW",
        "?r7'z\\O",
        "mK<7M%A^1IY)",
        "ctx->cipher->block_size == 1 || ctx->cipher->block_size == 8 || ctx->cipher->block_size == 16",
        "MeADf",
        "Option Pack Number=5",
        "WELct",
        "IFsfo",
        ".(%z@",
        "=$roKv/",
        "Unknown error returned from FwComponentInstalled function",
        "u|#u^P!4",
        "tlsv1 bad certificate status response",
        "d8lX)",
        "g%~y8",
        "[b\\^U",
        " G4%z",
        "setext-genCrypt",
        ": %ld",
        "Failed SetPrivilege call unexpectedly.",
        "7j,@ ",
        "requested",
        "!!6^R",
        "[N0Nf",
        "INCREASENETWORKFILTERS",
        "S9N^O_",
        ",/AiR",
        "Going to add temporary record to DuplicateFile table: (Copy_BladeFoundation.dll_2EPAM  BladeFoundation.dll.DA5C0B1B_759E_4256_9F02_1D6C54339DBB  BladeFoundation.dll.DA5C0B1B_759E_4256_9F02_1D6C54339DBB  null  EPAM_App.8792D4CE_35B7_41EC_AEEC_B7D5617B0989)",
        "{k|g ",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Kaspersky Anti-Virus Personal Pro",
        "o}4N_",
        "^Ugy3Y",
        "{+~5@",
        "iv[~S6",
        "l$|X}",
        "]XijC",
        "Y^w4O",
        "{wO`pJ",
        "+nF\\\"",
        "iH\\K2",
        "El%*3",
        "=i>i?",
        "W{%Wr%",
        "TS_RESP_CTX_new",
        "}>4Xbq",
        "6-7.8}8",
        "1Qh,U",
        "*Zy\"zj",
        ";n`0HL",
        "N</uw",
        "`1Q4H",
        "error setting cipher params",
        "BpX1zf",
        ".W,dBp",
        "H%).n",
        "DZs s3",
        "MonitorLogonShouldProtect",
        "-V3QZEN",
        "qLBGK",
        "sg*IB",
        "ee7pK",
        "Fv*9&",
        "{J+S|",
        "2#7PY",
        "1S`4K",
        "bGrud&",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\ul\\insrsid923653\\charrsid7500015  HYPERLINK \"https://usercenter.checkpoint.com\" }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\ul\\insrsid923653\\charrsid7500015 {\\*\\datafield ",
        "jAj{j.",
        "4r%XA<C",
        "<RhO*N",
        "\\LNi/",
        "Zex_Y",
        "2f~p\\9",
        "0ocb N",
        "e.Z},qG",
        "FW_INSTALL_REBOOT",
        "2cLb~",
        ";bh1j|[X",
        "CVTPD2DQ",
        "vHqF[",
        "/+CK9F",
        "^\"y<<",
        "]\"hl+",
        "|jn+&",
        "8(8U8",
        "\\'02\\'00.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fbias0 \\fi-360\\li720\\lin720 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713",
        "1S:Ur",
        "\"?fDsByu",
        "u0>,L",
        "<o?oBoDoGoIoLoOoQo",
        "`0U#j*",
        ":,x6h",
        "decipherOnly",
        ":$;b;u;",
        "DataStruct.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "x9t$yFj",
        "54<S%",
        "Product is incompatible",
        "gq'tz]",
        "5#\\)l",
        "8(8,8<8@8L8T8\\8p8",
        "59Jy$",
        ".?AV_Interruption_exception@details@Concurrency@@",
        "BIO_BER_GET_HEADER",
        "X=_<m|",
        "7!8s;z",
        "32~b?",
        "lzv<#",
        "~F,3t-",
        "@XkGK",
        "O[]nY",
        "Nr5nC",
        "l'Eu$",
        "](t*1E",
        "0$000P0X0`0h0p0|0",
        "4'4F4M4w4}4",
        "s;73A",
        "8)8=8e8t8",
        "#`rIfBF",
        "GvK|[",
        "jY;([",
        "QZW$t",
        "'f&H\\-",
        "r\\FMu",
        "__std_exception_copy",
        "StopURLFService started",
        "UF({t",
        "t%Y64",
        "OMwk}6",
        "CYl3m",
        "e[Cu#7",
        "JanFebMarAprMayJunJulAugSepOctNovDec",
        "k9Mm!",
        "\\y1! ",
        "j=)gR",
        "Vj@Z3",
        "y^o?>",
        ":6<D<Z<",
        "wEc/|o",
        "> >(>038|",
        "l(R!2",
        "Backed up vsmon.exe.",
        "Version String=NGX",
        "7n}>Q",
        "HEs/~n",
        "EDH-DSS-DES-CBC3-SHA",
        "0qw`|",
        "r]dd?<[",
        "Bc`i}m",
        "o;{W7",
        "T\\>Qb",
        "(R2tB",
        "3OBlHq",
        "8&9Q9V9[9",
        "aN&*\\{9",
        "1cw.-",
        "|iyzx",
        "{_82^p",
        "858J8",
        "/-/et.",
        "0$1T1",
        "m2@+A",
        "kG%]<U",
        "T9Emn",
        "{V`8x",
        "PWWh ",
        "QG<z@",
        "tEp{>",
        ":0n=Un",
        "F=[cCT93",
        "qgxRh",
        "&FB+hW",
        "`2-1Mi",
        "I>UJT",
        "a/rF${",
        "8Wux ",
        "Connection failed",
        "04k#v",
        ">B-eo",
        "/B6@w",
        "((]YZi",
        "GUQmF",
        "WNfRX",
        "eVi2w;",
        "2&2a2l2",
        "`p&jcB",
        "Wy.eN",
        ")U*mN",
        "5@7J7",
        "domain",
        "aYrMKN",
        "Could not open network registry key",
        "q#q7n",
        "hn-wW",
        "&:oBQql",
        "MwY;0Tr",
        "jMh}A",
        "]JJe}",
        "D4m1A",
        "wJ(b#+",
        "j0n0r0v0z0~0",
        " from key ",
        "vX&lPpI",
        "u9Ef~",
        "Y?ZLd",
        "f\\iz:",
        "@uQKl",
        "(k&>Ua",
        "CRolloverFileInZip::Open:  zipOpenNewFileInZip failed with error = ",
        "v{/U&",
        "<Q5f[",
        "<i>w>",
        "T[ECq",
        "G-zdH\\|",
        "vlTP+UZ",
        "=6=G=f=m=",
        "tlsv1 alert decode error",
        ">\\c/H%w",
        "?7?J?",
        "{>Lk*",
        "j.+IuyY",
        "setProperty failed with bad parameters",
        "InstHelper is not running, will not be able to stop Remediation service (RemediationService)",
        "Failed to get name of service.",
        "VjOh $",
        "D??1^fJ",
        "\"DP~P",
        "%NIxa",
        "%vr6hY",
        "1VEZ[",
        ";5Nd&",
        "}/Rf]:",
        "7u>}8g",
        "OI=\\[",
        "SDxqI",
        "SEC_E_SMARTCARD_CERT_REVOKED",
        ")t@WH",
        "u2]~I~>=e>8z?O",
        "*o:*j]",
        "t}1NF",
        "8V<LW#",
        "AD Time Stamping",
        "\\f-I}",
        "hWnbc*v",
        "w8yM/",
        "D$(Ph,",
        "t$,SWh$",
        "Z(9{#",
        "T?'on",
        "J[5-{",
        "&. *A",
        "s4L'A",
        "+}U/[&",
        "OljC- +",
        "5B[6s",
        "0\"0P0h0",
        "O-Wc-",
        "VH`eU",
        "4$4(4<4@4D4\\4`4x4",
        "v>PhL",
        "jegdt",
        "05;@r",
        ";2a'|>",
        "5XoUm<",
        "7|@1%",
        "Going to stop EFR service - CPEFR (EFRService.exe)",
        "#m s7",
        "!4H\"y",
        "9Tk}-",
        "1_RxI",
        "%RosV",
        "aJ$pt",
        "^WfW)V^",
        "/X#J<",
        "G2q?3",
        "v!3p<s",
        "Y6Rn*",
        "u`VSW",
        "8$8@8\\8x8",
        "n@^W+",
        "z$Lkd",
        "[VECTORED EXCEPTION] CLR exception",
        "rQ+Cz",
        "3y2kil|<]Qo",
        "str_field9",
        "2IE0'J",
        "`dRRD,v",
        "Lu[+8",
        "-]w(7>:",
        "GQ>/%t",
        "j=fuX",
        "account",
        ":j;k<",
        "9j:s:",
        "pI6b>A",
        "0gt*r",
        "9wEz)",
        "NqR4%",
        "]P8'diei",
        "? ?(?0?<?\\?d?l?t?|?",
        "NY31 N",
        "int_dhx942_dh",
        "[VSDATA] tvfwFirewallAddXMLRulesFromFile MapViewOfFile failed %d",
        "\"U^[z=RW",
        "jd rS",
        "ORip4",
        "^hMB5S}SMS",
        ")|>P,",
        "7pMQgE?",
        "\"L6*x",
        "*M'{r",
        "OyOwO",
        "X,J=lbR",
        "~P[hg",
        "v#yo^*2",
        "4q^76",
        "JS PG",
        "; ;(;4;T;`;",
        "w#?I);",
        " ',M8-8",
        ")+h\"ni",
        " 2xh>",
        "DUMMY",
        ",/8qb",
        "t$0h(",
        "uLR82_",
        "Error happened during patching cached MSI: ",
        "iZsln",
        "!RJ$%dP",
        "1\"2'2:2D2n2",
        "Unrecognized or bad HTTP Content or Transfer-Encoding",
        "?:$T ",
        "bb5s[3",
        "FTEw|",
        "1NlOk",
        ".\\crypto\\pem\\pem_pkey.c",
        "lT.w~",
        "B/WyX.",
        "+#nhq",
        "3''1N",
        "P_%Yn",
        "5(5,5<5D5X5\\5l5p5",
        "Starting dsfasvc service",
        ":RY|+[",
        "nwD$iO",
        "<6=n=",
        "naaG7",
        "vnAT,",
        ":KfP7\"",
        "j4==;",
        "\"L@.-",
        "<ZZ {",
        "J=U?t",
        "Owx[ ",
        "ycwc{cuc",
        "d=1/dxK",
        "programfiles",
        ".]?vir",
        "0)0=0Y0u0",
        "replaceOrAddTagIntoVSConfig",
        "SecProtectionByChallengeResponse returns %d.",
        "/cPin",
        "uF%TI2",
        "X[_^]",
        ":&:8:6<E<",
        "OpenServiceA",
        "h|8Q.",
        "User is an administrator",
        "k@*J\"",
        "ZoneLabs\\zlparser.dll",
        "UninstallSecureClient.exe",
        "<#<1<:<@<W<`<w<",
        "x$<f'G",
        "Au|pk ",
        "An=&;",
        "0_EcR",
        "i3H<Y",
        ".$E_7",
        "FCkgj",
        "W&#\"j",
        "w.Xhsm",
        "no certificate set",
        "202<2\\2d2p2",
        "\".#a!g",
        "/4Z&~",
        "vDFB]",
        "ak=du",
        "l-/hf;",
        "T_m}\"",
        "id-characteristic-two-basis",
        "failed to add/update application exception for name '%ls', file '%ls'",
        "q].ci",
        "U)l:T^8rv",
        "VUY7>",
        ";HNI\\V",
        "iZj*P",
        "zL&IV",
        "Wt4wft",
        "Vg+'3",
        "8D8t8",
        "bCheckSignature",
        "Anzho~<-",
        "}.RRV",
        "pIX~5",
        "c2pnb163v1",
        ".i+.r",
        "Removing default policies...",
        "-NDi(B",
        "n?~??L",
        "#HYRy)~",
        "'G(*r\"Z",
        "W5%2~;q",
        "&{UG0b",
        "vsdatant_win7.cat.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "6[8.^",
        "<*<8<\"=4=",
        "G%N2.",
        "aF[oX{",
        "};B@{",
        "X509V3_add1_i2d",
        "Fj!FQ",
        "m>V <]%g",
        "Y!qw~",
        "=z4bE9",
        "xkgpl",
        "[^/o1",
        "MnwYN",
        "3&434P4j4",
        "=x&f{r",
        "*([pZD",
        "ey^dY6",
        "di7\"3I",
        "[!4[^%E",
        "M~.P(",
        "0v[N!",
        "viV4u",
        "#\\seM{,9",
        "protocol is shutdown",
        "|75We",
        "Bz3&\\",
        "Igehu=",
        "DHE-DSS-CAMELLIA128-SHA",
        "h/#]vzG",
        "ssl3_get_new_session_ticket",
        ":5:x:",
        "w PO4",
        "=0>:>U>_>s>}>e?o?",
        "OpenSSL CMAC method",
        "&I@L7",
        "r%R121",
        "(>sOX",
        "39ZrL",
        "`jtJy",
        "TJsT|",
        "expecting a ecdsa key",
        "$0P5q",
        "bad x509 filetype",
        "\\zonelabs\\ntname16.dll",
        "B7)b8K",
        "DWbklw",
        "qeJrd",
        "m\\AMY",
        "CoUninitialize",
        "d`(R#",
        "m<UF`",
        "bdMj[I",
        "JX9;zd7",
        "R6 R1",
        "zSWHE",
        "[l^kn",
        "^j-s/",
        "sha1WithRSAEncryption",
        "78.v3",
        "<dEmm",
        ":(:0:T:d:l:t:|:",
        "A\"w ^",
        "][l9W<",
        "Change Characteristics KeyValue",
        "S'!NO",
        "T$(_^][",
        "J0TB#p",
        "8SK-]8",
        "%Ess@",
        "\"r.,q",
        "r|{t+h",
        "sc config wscsvc start= %s",
        "\"z)q%",
        "CMOVGE",
        "Set event:  %s",
        "9#ir*BW",
        "Not signer",
        "iT*4>H_",
        "8O\"eu",
        "8(878G8j8",
        "969[:",
        "py;3 ",
        "t ONB1",
        "86F/2",
        "6T7}7",
        "PMr!_@",
        "t$_>7",
        "SVRwP",
        "Process32Next",
        "\\4S6_h",
        ".RV~R",
        "2ft h[",
        ")G'`S{",
        "Problem with the local SSL certificate",
        "u4WX_",
        "9ayk[",
        "vsdata.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "Z;!KkI",
        "FU1c#1",
        "wqRIo",
        "ZodrTe",
        "Gf5)>J",
        "r#HzR",
        ".H\\p=g",
        "OIl/L",
        "HeV>u",
        ";Qfez",
        "9 9$9(9,9094989<9",
        "D$(PW",
        "gtAct",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{DCB2928E-61F6-11D6-B259-00C04FF4B435}",
        "8,9^9{9",
        "CRolloverMgr::CopyRolloverBlock():  unable to read from log file",
        "<$<.<9<C<N<X<c<m<x<",
        ":C;t;",
        "authAttrs",
        "Y#Y3YCYS",
        "uninstall password is correct.",
        "A(gb;",
        "PKCS7_set_digest",
        ")>_a1",
        "9&9,9O9",
        "L$,QPj",
        "L$X3L$@",
        "9$9@9\\9",
        "=v.~p",
        "1rcv?",
        "~~3YTu",
        "=31C%|",
        "f:5:]",
        "494g4r4",
        "#/)111",
        "server read error",
        "g7o6hm",
        "Kaspersky Anti-Virus 6.0",
        ":,:E:^:w:",
        "d2dGi",
        "6)J36;",
        "H3,w'",
        "!H#i?@",
        "str.bmp",
        "SKoha",
        "x\\Bcc}T",
        "<rz<=",
        ".\\crypto\\bn\\bn_blind.c",
        ".?AV?$codecvt@DDU_Mbstatet@@@std@@",
        "]!D)7",
        "Kr<,s",
        "P)@e\"",
        "6-6L6[6z6",
        "b4Cv&",
        "}g:(y",
        " [@Sn",
        "P-256",
        "<2U`G",
        "vsinitproxy.dll",
        ">,wmX",
        "NVSWM",
        "blksize is larger than max supported",
        "G\\v#?",
        ".?AV?$holder@V?$string_path@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@U?$id_translator@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@property_tree@boost@@@property_tree@boost@@@any@boost@@",
        "br1e>_e]",
        ".\\crypto\\x509v3\\v3_akey.c",
        "LocalAlloc Error %u",
        ".`'[A",
        "3<7:Y",
        "9AVd:",
        "7Y?#c",
        "RGE7!",
        "1!1/1l1r1",
        "H\"WZ@",
        "_3#pG51B",
        "p:(7h",
        "iAd$~",
        "r?rsD",
        "3I3O3U3f3u3",
        "vp]]6",
        "j j}j!",
        "$QQYQ",
        "aq<1l",
        "\\vsxml.dll",
        "jqjdj",
        "vkZ9^Issa#<",
        "lGO44",
        "of2V{",
        "&%2cq",
        "}Kd&#",
        "id-cmc-senderNonce",
        "advapi32.dll",
        "T?xhNo",
        "9+vg(",
        ")S~>{",
        "gost94",
        "}9P9$m",
        "Lyv}&=S>3",
        "l(pRl",
        "<=<x<~<",
        ",q2-,,",
        "Z59dd",
        "=mR)l",
        "iFbbFJg<EfYg[",
        "+APOP",
        "_;j-2",
        "certificateIssuer",
        "}r7^,z",
        "8 8$8(808H8X8\\8l8p8t8x8|8",
        "COULDNT_RETRIEVE_DATA_FROM_SMEM",
        "CA79d",
        "JQK:eS",
        "}ZP%e",
        "?]\\e<,E",
        "w1Q!e",
        "BlockMessageEx",
        "BknR2",
        "~y;]3",
        "eY5 \\^",
        "(?z_NP}}r",
        "@%m[{L",
        "ngr{u",
        "v2!L.2",
        "Helper constructor initializing shared memory with name %s",
        "FCe|S",
        "-6=<,",
        "failed to write Preserve Date indicator to custom action data",
        "E}_9^",
        "[`_Yy",
        "8'8c8~8",
        "g9 KY_",
        "5[^`A",
        "iif7s7_",
        "s7T`_ C",
        "UcUeUgUhUjUl}n\\N\\U]",
        "2omB}",
        ",P^-L_",
        "|$$VW",
        "Pipe is full, skip (%zu)",
        "s:2V8",
        "8vcf+",
        "ZF8I,",
        "5+52575@5G5N5X5k5q5w5~5",
        "eJj^H",
        "nf]}k",
        "Nn4AC",
        "^&\\\"u",
        "{Wjp\"#",
        "SOFTWARE\\Classes\\Installer\\Products",
        "{O&;*@7-",
        "#G=,_2Ui",
        "PWLvi>",
        "4<4D4P4t4",
        "O4%VW",
        "Software\\CheckPoint\\TRAC\\SCV\\Plugins",
        "?>eQ-Et8K%",
        "zk7/q",
        "5+5T5X5\\5`5d5h5l5p5t5",
        "c2>{PxI}M",
        ";7;S;o;",
        "L$,Pj",
        ",H<bc",
        "3 hp>",
        "3L$X3L$83L$,",
        "2+U.6",
        ",p+z+{",
        "7:7`7o7",
        "HYnAW",
        ".j_{.",
        "failed while looping through all objects to secure",
        "99:R:",
        "7!7g7",
        "^R& &",
        "5k[%x",
        "~6}0w]",
        "2-;<[",
        "n9Tl<",
        "Gg}o(",
        "p\"*CB",
        ">~O:H",
        "*gIzz",
        "\\)y3.#Q",
        "-&AN`H?",
        "The two certificates are not identical.",
        "7W8j8",
        ",yl^Q",
        "UJ;[u",
        ".8a3w",
        "InstHelper.exe: RemoveSC",
        "ZThread:",
        "GetLogicalProcessorInformationEx",
        "\"S%V=R",
        "mpqq|\"",
        "RsTj{|",
        "AM1 signatures will not be installed",
        ")y&*j",
        "3L$<3L$(3L$ ",
        "Getting current package name failed with errorCode: %d",
        "m|KHN",
        "EQDZB",
        "'Z*=q",
        "rlx`R'",
        "#$CFS+Y",
        "PMl[K",
        "0k7r;",
        "aAX:r",
        "k*^2m",
        "YO&<Y",
        "kQ!^V",
        "Pu*Jt",
        "9N~^vj$",
        "CreateZoneAlarmXml:  CreateProductXML succeeded.",
        "r4\\>R",
        "id-regCtrl-protocolEncrKey",
        "N-/(g",
        "x4]Zn",
        "Pi:p-C",
        "g|gpe|",
        " '-iC",
        "C8p1B",
        "Lp8=H",
        ":,:4:<:D:P:p:x:",
        "Helper::stopURLFService",
        "{`QKi.*c",
        "unreg.bin",
        "T+mJzB",
        "Aw1~H",
        "Delete outdated files",
        "2X<1^4",
        "qFX&g",
        "KgQ)1da",
        "S48Ecx",
        "`UV@@TFc",
        "=6>D>[>",
        ":-E;&",
        "+%/>/UY",
        ">(p>~",
        "^tyRCx\\",
        "@,-to",
        "|PEiE_0",
        "COCCm",
        "Mp.h~.W",
        "9PQ`J#",
        "LU5Z<",
        "acR)$",
        "VPNAtInstall is set to true",
        "[VSLoadVSMonAPI] LoadLibrary(vsmonapi.dll) failed, error %d (error 126 is normal during clean installs)",
        "failed SysAllocString for description",
        "jpjkj",
        ".w[hh",
        "X509_ATTRIBUTE_create_by_NID",
        "3|e0C",
        "Z~:1h",
        "Lp%Rf",
        ">S>Z>f>t>",
        "Doing the SSL/TLS handshake on the data stream",
        "AdqvkJ",
        "|'%3\"N",
        ",_^][Y",
        "IDEA-CBC-SHA",
        "o\\`\\U",
        "Iq/\\B",
        "X)g>g%",
        "S[\"V+",
        "/H!V46",
        "iduwwNC",
        "|\\-AfeSS\"8]P",
        "            Not After : ",
        "#?M!Jn",
        "engine section error",
        "Z(*-,",
        "BVpEJ",
        ":$:,:8:|:",
        "?j{XO",
        "<..i^g",
        "~J%u,",
        ";\"[d/B",
        " ^U+ ",
        "sud8^",
        "3t'Or",
        "N8#hXM",
        "#7#<%D",
        "J*[-~",
        "#w-HsL",
        "Z'*O/;?",
        "vMX+5",
        "*~Pu7",
        "U{8w\\-_",
        "4\"5B5b5",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid10178046 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 The foregoing warranties and remedies shall be void as to any }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "'0;0K0U0",
        "D$0PhT",
        "?\"?B?L?Y?",
        "3Q4a4",
        "x;ie`",
        "Tc.dz3",
        "gcA^_",
        "Qkak/",
        "c#aEB",
        "P`}gTx",
        "id-regCtrl-regToken",
        "R$2cF",
        "akid mismatch",
        "j/h8a",
        ":pg5AKn",
        "O(qw`",
        "O'E!@",
        "AO,T\"lp",
        "0>P~i",
        "Z%!Z|a0",
        "1f,AC^=",
        "6U\\rBX",
        "Wh>>>fW",
        "YE_'QSI",
        "c66^p",
        "LXF[-",
        "p~ O,mE",
        "43n+-",
        "0f3I9b",
        "45g}Q",
        ".t5m#",
        "Request has same path as previous transfer",
        "30YK0",
        "9ycRx",
        "qtH:,",
        ".vvTfN",
        "K&|@5",
        "{6Zgk",
        "m'.S&",
        "l3ryJl+",
        "sv6t/",
        "0CC5k(",
        "8W9_9",
        "__p___argc",
        "%'^c$}",
        ">w|QH",
        "9-9P9k9",
        "\\^=9 ",
        "0!2d2",
        ":.:5:A:M:",
        "u$M/ 4u/jj",
        "3uH/\"",
        "pQ[!)",
        "y/V\"p",
        ":$:0:P:X:d:",
        "|Ob{B",
        "5g?([",
        "{LqIvG",
        "M`'6| ",
        "/o<)v",
        "Z[vqa",
        "j4PSb",
        "SEC_E_DELEGATION_REQUIRED",
        "Modulus:",
        "3L$<3L$03L$ ",
        "%YcxCc?}",
        "ee5o3U",
        "g~G9E",
        "jmjsj",
        "~ $s%r",
        "SlUq?",
        "UPDATEKEYFILES",
        "VY*&E",
        ";~/}B7\\3",
        ",S4zp",
        "dp#8>",
        "yXECrx/i",
        "U5Q7a/",
        "@_[Z0>",
        " |Zxe",
        "~aN_]",
        "O@-vJ",
        "0F '!",
        "\"7oA@",
        "Ef^\\h",
        "Y 6fW",
        "#Logd",
        "nExecServiceConfig",
        ")n-/-q",
        "US.*@",
        "'MMF9",
        "5%6.6N6|6",
        "PATHBYADDR",
        "1$1,141@1d1",
        "696S6h6",
        "aes-128-ofb",
        "8+UeMA",
        "W2D'K:",
        ">0kt}h",
        "hXJw=",
        "$eO}}",
        "[l9B6",
        "[Il}e",
        "CRL path validation error",
        "DISCONNECTEDPOLICY",
        "\\7<g<+U",
        "O%1L~",
        ")?9(vy",
        "Failed to open file %s",
        "No valid port number in connect to host string (%s)",
        "div-mv",
        "'8-eT",
        "QSWVj",
        "Vsc`X",
        "~?Nzn",
        "configuration file routines",
        ",I*RO",
        ".?AV?$_String_alloc@U?$_String_base_types@DV?$allocator@D@std@@@std@@@std@@",
        "\"0G<IB",
        "Se0kNU",
        "&>Ltp",
        "~pOAN",
        "`:U:>",
        "Bcyvx",
        "a2i_ASN1_STRING",
        "7-!^`x",
        "*>cr>",
        "s$t)r7~Drjr",
        "LQxJH:",
        "SJ`B(,",
        "vRKN>5",
        "K-6!v",
        "imslsp.dll",
        "f@l!k ",
        "BCryptGetFipsAlgorithmMode",
        "6.6A6P6m6r6w6|6",
        "iw6pY",
        "sq``w",
        "ts@`'",
        "H>>$T",
        "9*9e9r9",
        "RuG=--",
        "CCIY%%",
        "kfLd,",
        "jthp?%",
        "A*A/A2A8AQA",
        "1j7Qi]o",
        "<0<K<}<",
        "fMf[_",
        "6Xd=A<",
        "?BDl.",
        "qeu0d",
        "LUSazb",
        "sCRIr",
        "R-I'`",
        "e4Bk+f7\"+",
        "call GetClientTypeFromRegistry...",
        "yOc\\C",
        ":(;@;",
        "Ty}<{",
        "?@?H?P?\\?|?",
        "wO5H~Bwv",
        "2\"Zv(J",
        "parties. You acknowledge that the source code of the Product, and the underlying ideas or concepts, are valuable intellectual property of Check Point and You agree not to, except as expressly authorized and only to the extent established by applicable sta",
        "EPAM_OnBegin",
        ".3_~g",
        "{ BUw",
        "6?1qh",
        "UILevel",
        "8e!]WS",
        "<O=f@",
        ",W2q#",
        "-lC^#",
        "N<cMly",
        "Q*v_(",
        "EVi;x",
        "R)dxQS",
        "J~HX^",
        "s}(- GD1",
        "<t9d ",
        "I0&kvn",
        "0?0J0",
        "C1A5G>F",
        ".\\crypto\\srp\\srp_vfy.c",
        "[HQC_",
        "5V'm+",
        "D$ PU",
        "$ b!]",
        ",whM5",
        "0F1W1",
        "#Nyo9;",
        "i^<#u",
        "kzIyd",
        "0C1N1Z1",
        "@'`Ky",
        "GbYUJ'",
        ";ZG@w",
        "A{%.J=",
        "Ya'uy",
        ")589a9V\\n!",
        "SSL_clear",
        "{4]*9",
        ",>$??&",
        "_a}eT",
        "8y_nq",
        ">(>4>T>`>",
        "9&:-:g:",
        "5&5H5U5x5",
        "CryptMsgUpdate",
        " %x'`vn#",
        "A6YoS",
        "|xjD7",
        "~wd8$A",
        "CompareStringW",
        "Z4/Vuu",
        "\"YU*Pc",
        ".S9c$",
        "+g*Rsf",
        "7%7,787E7t7{7",
        "F@m:X7",
        "< <,<L<T<`<h<",
        "9#9,9<9I9a9j9}9",
        "`|12w",
        "FyEfK",
        "muY^1^%X0m",
        "Qqx^'",
        "@=I:M",
        "9KvFN",
        "-%ScI",
        "XW($H",
        "eYgY>",
        "[#wo\\",
        "Jb{,{",
        "TempDir = %s, ProdDir=%s",
        "S;R!N",
        "!a[F1=",
        "o_}Wz",
        "e.,fY",
        "!x9MB",
        "9F8t\"G",
        "oG(zf",
        "SOFTWARE\\Classes\\Installer\\Features\\",
        "Pd-+`",
        " SVW3",
        "@FUe~",
        "Gh;G<",
        "/CdM2_",
        "JSPyx1?",
        "YBTn+a,0",
        "gqSO!\"0",
        "$-+qn",
        "/=do$Q$",
        "%02X ",
        "o:ANb",
        "l%KB!",
        "L$h3L$P3L$01L$",
        "EVP_CIPHER_CTX_ctrl",
        "B52uxj",
        "jdjgj",
        "2B2O2W2n2",
        "9Dgd|",
        "\\zci~S}",
        "\"G+qQ",
        "\"Dk4]/",
        "94999I9_9d9",
        "f{2lg",
        "2mJ>>P3",
        "4(4H4h4",
        "o\"Q14",
        "k,pu=Y",
        "So>(;",
        "{$|Y(Z",
        "(i\\ex",
        "DSA_new_method",
        "ej~<4",
        "O,LwP",
        "timeout",
        "D@7<w",
        "lvM/c",
        "\\TbgYm",
        "545<5D5L5X5x5",
        "1$1)161]1",
        "{q`z~",
        "aaaaaaaaaaaaaaaaaaB",
        "p7OtkF",
        "Ihf3VQ",
        "EvtRender",
        ".\\crypto\\bio\\bss_file.c",
        "I;ws7",
        "sWV]Z",
        "4D4a4x4",
        "9$909<9F9J9T9`9l9x9",
        "K'4<D",
        "w,F?iW",
        "H#$pU",
        "'&Fh^",
        "Z+9>s",
        "/b'\\s",
        "Mgwb#",
        "wap-wsg-idm-ecid-wtls12",
        "BL$W1",
        "_HEeJ>",
        "/LrI \"",
        "f ?Gk",
        "Kc\\R_",
        "!>8`A",
        "SgNf/%?F#",
        "rpf;u",
        "\"J:t!",
        "/2/g-h",
        "GENSTR",
        "N[qk@",
        "G]iX[b-",
        "D$8PV",
        "jfjgj",
        "=J>O>i>",
        ";\"<R<k<p<v<",
        "BN@$N$",
        "T.D9w",
        "`MB71",
        "TrueVector driver: Driver install or load failure: %1. Win32 error: %2",
        ">->>>S>X>",
        "TBYTE ",
        "DH_PUB_ENCODE",
        "606z6",
        "'e`P`",
        "3!3+3",
        "]E?w0y",
        "5C'`at",
        "1[2=3T3",
        "wv]/T",
        "$uJHkBJ",
        "\\par 2.2\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Standard User Restrictions}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid473743 . I}{\\rtlch\\fcs1 ",
        "mrF:h",
        "zlvf{`",
        "4\"424F4v4",
        "D61BD29D7EF253F4794309024181C728",
        "mj\\RL",
        "nqI-z]",
        "CG~a(",
        "QVhL6M",
        "%*sVersion: %ld (0x%lX)",
        "!edU>",
        "fn58,",
        "Bq23B",
        "vZxGp",
        "QH)QT",
        "P[`k_%",
        "7-7T7p7",
        "1;&d{",
        "%UUUU",
        "|$P3|$@3",
        "]E=G]",
        "Zb{<\"",
        "!YKC~5",
        "W<MYi~",
        " 0xe4",
        "2 DX%#]",
        "qwMiO",
        "kuv\\t2x[",
        ".cS+g",
        "_w%;1",
        "b6f.J",
        "=<baW",
        "inity",
        "kn?)@>",
        "[PVVVVV",
        "=$=_=",
        "KW`r*",
        "VVVVj",
        "PKCS7_SIGNED",
        "{Y=>T7E2",
        "Kill logProcessor.exe.",
        "7O7~7",
        "PBJN9",
        "#}EQh",
        "r.-JW%",
        "unp)=",
        "FsR(q]",
        "'WRx[",
        "R'E8?",
        "uGc#{",
        "Y^WQ]",
        "zA<U9<",
        "rN;#b",
        "FSq9B",
        "Hi*=e",
        ".\\crypto\\pqueue\\pqueue.c",
        "4G5\\5e5n5",
        ")wu-a^X7",
        "invalid field",
        "6a7z7",
        "D#07ZO2",
        "q[kqI",
        "CRolloverMgr::LockLog():  TV debug log mutex acquisition failed.",
        "key arg too long",
        ".?AVexception@detail@nlohmann@@",
        " 0x84",
        "khE@R",
        ">[>o>",
        "':v&iv",
        "9D$,sQ",
        "L0P0T0X0",
        ">p?t?x?|?",
        "&.%a`",
        "d;m'|U",
        "101B1X1]1b1",
        "T'IFz",
        "PhD&!",
        "Dc?zj",
        "set-msgExt",
        "wT[TQg",
        "9\":[:",
        "<.=Z=f=",
        "\\@,=/",
        "RN\"%%R9!",
        "gpW7%",
        "2,D\"h",
        "l%1h\\",
        "=$=D=P=p=|=",
        "n<|f6E",
        "$'=/!",
        "lc&m}",
        "0TqU%",
        ": Qz&i4",
        "USWh\\",
        "D$(_[^",
        "(hsQ8",
        "e0CP7",
        "<=e*QW",
        "}\"XK*7D",
        "M8Y[Bo~",
        "Dc bq",
        "%794vb>",
        "8*9b9|9",
        "O^kX3D",
        "828;8G8~8",
        "N'LZr",
        "S4\"rHWc",
        "uB^C0",
        "illegal characters",
        ".gSp\"",
        "RG%Lq",
        "failed to launch target",
        "3)3A3Q3b3y3",
        "|^'VAx0=",
        ".U\\[G",
        "84989X9x9",
        "qhBI.",
        "=e'Q#",
        "2 2$2",
        ">JZB|",
        "Fsg=#",
        "-1W2t",
        "g1426Q",
        "uM9D$,u",
        "1.1B1Y1",
        "iS2A{v",
        "2i%l*",
        "EJ~Uu\"\"z",
        "lntQ\\",
        "};YJY",
        "PBE-SHA1-3DES",
        "P_7;!k",
        "u/f\\8",
        "uQ\"<ut",
        "\"tcgj",
        "jRZ;=",
        "(N.QR6",
        "3\\CHkv",
        "`f*B4",
        "D$DPh(",
        "A\"p{O",
        "[(~mO6",
        "|+t\"o{",
        "ssl_prepare_clienthello_tlsext",
        "d8y:H",
        ")7;=%)O",
        ",-T\"-a",
        "X6C^h",
        "hfns1",
        "X&.~A[I9",
        ":bvo%",
        "Q7sL{",
        "[t%IM",
        "5YDWZ",
        "XP[f1",
        "L;-2U",
        "D$(SU",
        "qWhhYC",
        "9A>9E",
        "VQj4z",
        "eU,jY",
        "GXT}`",
        "OCSP_MATCH_ISSUERID",
        "@yah#^",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  77",
        "^C7|G",
        "u_&wup",
        "bs\\>5",
        ";%;/;:;P;Y;f;l;w;~;",
        "7vv^ut",
        "KC2R/",
        "6&P(!'",
        "*_+7=",
        "tesa]X",
        "id-smime-alg-3DESwrap",
        "ADDSS",
        ".uqwn|",
        "bVR`S",
        "`|\\:(",
        "sIyA'",
        "xH75Y2",
        "Ejxwv",
        "uK9D$",
        "W_}aR",
        "eQ>n0-?",
        "@Dyed",
        ": :,:4:E:c:t:",
        "|\\HX2",
        "o_hGQo<",
        "x^B}'1;",
        "OyM$tQ",
        "MjVf:",
        "=}~O;W",
        "Q2PVp",
        "d9_vk",
        "NONCONFORMITY IN THE PRODUCTS OR SERVICE, FOR ANY AMOUNT IN EXCESS OF THE PRICE PAID TO CHECK POINT FOR SUCH DEFECTIVE PRODUCT(S) OR SERVICE; OR (IV) FOR ALL OTHER CLAIMS NOT RELATED TO AN}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "I3LBM",
        "\\lsdunhideused1 \\lsdpriority37 \\lsdlocked0 Bibliography;\\lsdunhideused1 \\lsdqformat1 \\lsdpriority39 \\lsdlocked0 TOC Heading;}}{\\*\\datastore 0105000002000000180000004d73786d6c322e534158584d4c5265616465722e362e3000000000000000000000060000",
        "t-f98t(",
        "2|{u>V",
        "%Dv-{(",
        "O$opefHU",
        "+&Kth",
        "$e!|U",
        "0\"0)0/040B0",
        "@~cn&CW",
        "Cached msi of Check Point VPN (",
        "JIX1g",
        "crfCZ-",
        "Q;FD~Z",
        "e-mPC",
        "t$(SU",
        "a1t=P",
        "SEC_E_BAD_BINDINGS",
        "vZy\\-",
        "[JXq6o",
        "LM:r@",
        "rW_L)F",
        "La>3Qc}w",
        "u./d@",
        "EVP_PKEY_CTX_ctrl_str",
        "jI60P5",
        "`FYU;~'",
        "'w`<_{",
        "GpTY\"",
        "URQ&z",
        "Ip:KT",
        "0Cb)S",
        "[&B%n",
        "+O&tC",
        "EPAM_CleanLeftovers",
        "|m}5#1",
        "smimeencrypt",
        "g@=-z'",
        "`8}_7",
        "ta%no",
        "BbaRZK",
        "dsaWithSHA1-old",
        "wjut\"",
        "[{Q/We",
        "BfIK1",
        "7f\\;4",
        "JVyX^",
        "<H<P<T<X<\\<`<d<h<l<p<t<x<|<",
        "0f$sKr",
        "t$0UV",
        "+iCH_B",
        ">\"7dp",
        "]Ia`!$",
        "y(kEMZ",
        "c6dQw",
        "server did not report OK, got %d",
        "l~cUP`",
        "!G6OI",
        "FN)(I",
        ":;fu4,+u",
        "i^Srt",
        "{hFD\"",
        "?_ScV",
        "yChJJ",
        "Z3L$D",
        "(wq'd",
        "cGfD\"Y",
        "7V:h:",
        "IGQ[.",
        "M-5gGV",
        "]A1(vL",
        "\\#'YM;r",
        "of ninety (90) days}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 . Check Point's entire liability and Your exclusive remedy }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "\\^T??N",
        "ECDSA part of OpenSSL 1.0.2h  3 May 2016",
        "Lm&+F",
        "%u %d",
        "4px}@",
        "SBg[t[",
        "F|6CzI",
        "Xp:P!",
        "#'tZ\"",
        "5A5F5q5v5",
        "C$\" 1",
        "FiG6H",
        "D$4Pj",
        "Jjl^f;",
        "DBe2^9K:",
        "UJn1_",
        "b&&1S",
        ">%>A>]>y>",
        "fU8#M",
        "Utkc'+",
        "en-CA",
        "CC So?",
        ".!Z q",
        "hOL|S",
        "unsupported any defined by type",
        "0!0A0Q0a0",
        "1(),Z",
        "&K4h.\\",
        "t)-rStR^/",
        "ngM%C",
        "no buffer space",
        "UnprotectPPLProcessByPid",
        "l\"XI\"`A",
        "Lying server, not serving HTTP/2",
        "1Hrhr",
        "^1UI[",
        "(YR_p}6",
        "c~) +",
        "F95$q",
        "BnfHU|",
        "4N7^7",
        "j/-qNQ",
        "n|T.&",
        "/XNl+&",
        "RR.Kj.",
        "Pu,P{",
        "Ftw\\0x",
        "]X(Ng",
        "{ceD'4F",
        "(\\Iaj",
        "aU4+j",
        "u-jrh",
        "W'jN>;",
        "XdqYj",
        "S0A!%",
        "=~4I5\"",
        "jIV[|",
        "y_SaL",
        "!H|Tl",
        "}*}.}D}L}p}z}~}",
        "<*Ve1g",
        "='=D=U=j=o=",
        "Aif]_",
        "OnInstallFinish.1F357923_E5ED_4F4F_9B28_B146153C7446",
        "V^|t{Z+v",
        "q_/PZIqj",
        ">[EJ)",
        "_|g*X",
        "aZKK#",
        "`C>&Xo",
        "94z!v0",
        "NF7]1",
        "/%?{S",
        "g?vj *~",
        "^m<1c",
        "<JnRb",
        "mS.wQ",
        "5v&h[70",
        "\"kZzWg",
        ".t_D\\",
        "[JhjR",
        "Failed to get CustomRestartCountdown value from registry key, use default timeout.",
        "u.(am",
        "U-Y-]-R,",
        "I)z+}+",
        "ps[V&",
        "u1uNu[",
        "+h\\4S",
        ".  The file has been deleted.",
        "?0?]?",
        "|CC:@",
        "=.\\A/r",
        "[=q+;k",
        "U]geH",
        "4>5i5n5}5",
        "'GfBQn",
        " o@yZG",
        "-b.|4",
        "_CBLd",
        "<be;Z",
        "J6Nel",
        "w|!ni~X{",
        "%QF|A5.",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Full Disk Encryption",
        "7Oa(5",
        "SHA part of OpenSSL 1.0.1t  3 May 2016",
        ";F ~\"_",
        "Gy 4]T",
        "J!)_<",
        "6H6}6",
        "Xkp~%?",
        "\"Qy&%Tb",
        "}>5UI",
        "[lkC'",
        "545`5",
        "cG,%v",
        "v\\fikzhh.",
        "ECXAt9n",
        "70767>7C7K7P7X7]7d7s7x7~7",
        "createProcessingInstruction failed",
        "BmTP?",
        "iY> K",
        "aZ<;n",
        "vJUY-",
        "-sWy0",
        "EVP_PKEY_decrypt_init",
        "R%DY2",
        "20H0R0\\0f0p0~0",
        "*Q5In0[",
        "cXgVcWcUeY",
        "Dghz,",
        "E\"\"I/",
        "[CL&f",
        "u52_Up",
        "ZCrf;L",
        "dt}fu",
        "$,]9p-(",
        "7R7b7",
        "Kq=*G",
        "El)puU_",
        "Installer.log",
        "%ht8c",
        "I0Y>S7",
        "<<<g<",
        "jw-ln",
        "$vYJ9W?",
        "aes-256-cfb8",
        "?7?{?",
        "Xhy@v",
        "/$'X'V",
        "q21*~",
        "'j't(",
        "3k R>",
        "s@u@w@",
        "< XKN",
        ")Vt*km",
        "jAjsj#",
        "U\\CBC]?l/zW",
        ".?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "6GvaM[",
        "C]sNK",
        "Tq:0*\\",
        "2lcZuY",
        "~@mU49",
        "l.[4rrpM",
        "L@-P2",
        "~u-j0!",
        "U,U-U.",
        "0C0N0o0{0",
        " sj_2",
        ")^VZ[",
        ".@ QV_",
        "x'lt1",
        ";L<;y9",
        "\\DueU",
        "#Gnny",
        "n1Z[4I",
        "VFf&#W",
        "B7b>/",
        "OnUpgradeAfter:  InstallProduct",
        "_open_osfhandle failed for writing {} - {}",
        "5+6@6U6f6{6",
        "L} 0 ",
        "f1S_5+",
        " common name: %s (matched)",
        "MF@8e+)",
        ")-AE=",
        "V@xcV",
        "^'n^`x",
        "DP>EN",
        "|bdE4:",
        "!k'bvQ3",
        "r9!zgEke",
        "dql%P",
        "Sig)#:ju",
        "FZ/+7/",
        "^o>W$_h=",
        "5bc^L",
        "<WpudT",
        "758Z8",
        "`F!S[",
        "6CY6x~",
        "AJFWy%{Y",
        "d2yZqV~",
        "bJ|8@",
        "2h/^D",
        "MG\"HV",
        " 0x96",
        "+wlx:",
        "codecvt",
        "8h@}#",
        "#A$jv~",
        "lHaqW",
        "eGi/u",
        "RaALM",
        "%NYA8",
        "26<=U",
        "lo}q0",
        "8'8J9m9",
        "recipientEncryptedKeys",
        "<+=\\=",
        "FU!(O",
        "R,\"y9",
        "vM][*",
        "X=iIaF",
        "ty(ywU",
        "^4P$ ",
        "%B-B5BMBUBeBmBuB",
        "9|R6Q",
        ")#'Z?",
        "&dtn3",
        "argument out of domain",
        "#z^B(",
        "7>7j7",
        "hs&<u",
        ";&<8<P<j<",
        "Nl#KR",
        "epc_id",
        "8(9A9H9^9",
        "Pn{2k",
        "4$VD*%",
        "Iy^#TT",
        "879P9",
        "SSL CA",
        "s[6S.1",
        "=Ji*8j",
        "@~5Y`/",
        "<X=p=",
        "-%ko_-f",
        "< <*<2<7<G<T<q<",
        "Jv8Tj{d",
        "9-:4:]:e:t:",
        " 4A$1",
        ",`SBt",
        "set-brand-JCB",
        "OnFreshAfter:  SetProductMode",
        "CMOVAE",
        "tQ3L#",
        "X=}{`",
        "L~>mi",
        "b/KU}R",
        "0m0x0",
        "}E3+O8",
        "(R?X#",
        "Engine.dll",
        "y@CN?;",
        "|:a@5",
        ">7?k?",
        "3#szH",
        "]a*G+d?",
        "%Z{so",
        "D-\\J?",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  means the third party that has the right to provide and grant licenses for the use of Third Party Software.",
        "/dW@*",
        "n5Vvy&",
        "G-kk\"",
        "70]s>",
        "/MgMOMU",
        "#>Qit",
        "YE4(V",
        "}6!s\\",
        "M.^ \\",
        "sAQbp",
        "o[f~]Q?",
        ";dcI#",
        "U[4W/m",
        "KZ0_8",
        "mq|~r",
        "u5;=G",
        ",.aG$|C",
        "Y53HO$",
        "7H}$U",
        "npS/3",
        "k=v%R",
        ":#:D:Q:f:o:x:",
        "dIGVm",
        "&Jt()_",
        "fNG\\K",
        ".?5v`>",
        "__int16",
        ">+>B>_>",
        ">7>A>K>d>s>y>}>",
        "l*uAq",
        "x&Z<o ",
        "0#0(0C0P0Y0^0c0~0",
        ">+?I?g?",
        "~\\'jNp",
        "..er#",
        "q9'`c",
        "m@GEF9G",
        "1]fQ/",
        "tU}3~",
        "8%7O0",
        "Az9kf",
        "raP2s",
        "SEC_E_NO_KERB_KEY",
        "606@6D6P6`6p6t6",
        "api-ms-",
        "wOPQRLMSTCMLD",
        "|0~ yA",
        ":G:V:l:",
        "/4*&{",
        "K{MPa",
        "There are Convert2MSI.exe and Config.dat and no RECONF property set. It seems like installation from extracted exported dynamic package without all the required properties.",
        "lv-lv",
        "~laHSt",
        "~rH&b",
        ";/;,b",
        "GEAju",
        "$Nd[\"",
        "KR\"SVX)N>B\"",
        "p.k62",
        "dJ_E7",
        "fmj#rg`",
        ">C?C@CAC",
        "QoirO",
        "H>?qZ-+",
        "GetModuleFileNameA",
        "-LU#\"",
        "Q6N&Z(",
        "42Z6!",
        "~]Q;X",
        "zssE_",
        "l~=(k!",
        "(4br>",
        "You must restart your system for the configuration changes ",
        "5bjDF",
        "3:}A?",
        "\"{Qh3",
        "InitSecurityInterfaceA",
        "=<1kNS",
        "+tD9b",
        "6.6?6u6",
        "4.4)5J5S5_528(=\\?",
        "GWs+4",
        "U1{V<",
        "M'P55",
        "%s\\system32\\drivers\\DisconnectedPolicy.xml",
        "\\{Y6+o",
        "setct-PIUnsignedTBE",
        "\\zlcomm.dll",
        "051_1",
        "303<3\\3h3",
        "4R4l515",
        "6F7S7j7q7|7",
        "ADDSUBPS",
        "KPz$ ",
        "=<=h=",
        "r~Qgj",
        "CMS_RecipientInfo_ktri_get0_algs",
        "FindNextFileNameW",
        "WDv$2",
        "?(?u?",
        "g9QRmO",
        ":3~{aV",
        "SSL_new",
        "G/lw[wx7",
        "),L4.bV",
        "Failed to run MsiGetProperty to retrieve REMOVE_SUB_TYPES.",
        ":g~uAH(}",
        ";<;U;",
        "@h<B#",
        "INT_FREE_EX_DATA",
        "Hh#`7",
        "9!9W9p9",
        "4&454U4y4",
        "M>``:",
        "\\rsid551312\\rsid678364\\rsid735494\\rsid807904\\rsid815761\\rsid854170\\rsid883884\\rsid923653\\rsid997758\\rsid1070107\\rsid1132737\\rsid1140480\\rsid1190034\\rsid1210937\\rsid1377203\\rsid1460060\\rsid1468885\\rsid1519421\\rsid1521245\\rsid1535536\\rsid1535878\\rsid1580952",
        "3,V'{ ",
        "CANT_EXECUTE_VIEW",
        "=&=4=N=U=a=k=",
        "d.digest",
        "5L6m6",
        "D{k_4KX",
        "{8_E\"",
        "V8(?N",
        "wq9UR",
        "84\"Ezs",
        "0!1F1M1p1t1",
        "(wDWL]",
        "1(191N1S1",
        "RN!\"af",
        "n%1ad",
        "HNsEeP",
        "protectionOn;",
        "IncreaseFiltersMaxNum ended",
        "InterlockedPushEntrySList",
        "9R:F;P;",
        "N,$[+:I",
        ">v1E,",
        "=v[Yj",
        "? mVZ",
        "bW6;!7xYa]",
        "phrase is too short, needs to be at least %d chars",
        "CollectBootStatistics finished.",
        "D$,VP",
        "id-GostR3410-2001-CryptoPro-B-ParamSet",
        "CRolloverMgr::TruncateLog():  unable to open log file",
        "CGwsE",
        "no`{J",
        "invalid field name",
        "5F5s5",
        "2u*RM%",
        " ]_^[",
        "ZA;$V",
        "D|(gF\\-",
        "MN&qe",
        "wxaan7",
        "ssl_get_new_session",
        "gmANO",
        "v[_.z",
        "|.ctQg",
        "jAjlj#",
        "qbpJg",
        "1Uvj@>La8;(",
        "1#r''",
        "+]ua&o",
        "DS_RollbackCopyToSystem32",
        "ctx->tmp_len <= 3",
        "K*j}Sq",
        "IwUUo-W",
        "<C9Wc",
        "CheckRelatedProducts: CheckRelatedProducts Begin",
        "vJ.$6",
        "~GsKP",
        ";Q<f<u<",
        ":?4(U",
        "renegotiation mismatch",
        "Uh9jxR",
        "7#7[7",
        "K2-`p",
        "Cannot delete %s (error %d)",
        "s@A{l",
        "u)Vh`",
        "uz13g",
        "UninstallCreatedItems:  Cleanup the internet logs directory.",
        ">D?i?",
        "s,mpsl",
        "9Z5me",
        "k4l0z'",
        "s;,y^4@",
        "p/%)%",
        "https://www.digicert.com/CPS0",
        "6Z=[/",
        "4'`/@ZU",
        "w\\IF[",
        "T9b*E",
        "m>!/g",
        "u7hl%!",
        "UB#XY",
        "EC_POINT_set_compressed_coordinates_GFp",
        "1 q\\6",
        ")zLX9",
        "T4QU#",
        ">2?R?",
        "1D14C38E6BB021B45B6502FFDAA092DC",
        "GetTempFileNameA",
        "vEWF_",
        "`miQt",
        "vREO)",
        "7&8~8",
        "X9.62 curve over a 368 bit binary field",
        "RemoveFromWinFwExceptionList:  RemoveFromWinFwExceptionList() succeeded.",
        "h6:cG05t^",
        "</securitypolicy>",
        "+zu<!",
        "!'2yt",
        "vY&pfnP",
        "ye6|9",
        "vamgdv",
        "7+8V8e8",
        ":f<H=_=f=",
        "nuk]^",
        "N4o9L`",
        "bJ#G)M",
        "t`odT",
        "0^\"k.",
        "}NBef",
        "([F-(",
        "Q zyfoK",
        "=/=K=g=",
        ")]mMxVa!",
        "{xc#1",
        "~Nl\"/",
        "O7]W\"E",
        "K4kIdA",
        "0dgR>",
        "&2@3J4J",
        "{)yfO",
        "sdP?}*",
        "zK;xU",
        "76s0<",
        ".?AV_Node_back@std@@",
        "15c308d3f28acd249438c19a4b05fd9e8a1cf4cd296699771c393ac4b5e01d01e5a30a787d72cf1178108989a2159c77a2d801ee72ce3a5c545a6147f32a9979",
        "-#drK",
        "`g@dp",
        "`cqP>I&y",
        "~eKY}",
        "'W[;D",
        "btKNg&",
        "4$4,484\\4",
        ",4u9k",
        "p8]l6u",
        "W&a7\\Q'",
        "[=bQ|a",
        "*\"r}Q",
        "xmy}P",
        "}8a2=",
        "6]7g7y7",
        "j$+MX?5",
        "ZN9U*L~",
        "o`JI-",
        "SIZEu",
        "PKCS12_unpack_p7data",
        "LTGd`J",
        "020R0W0\\0",
        "_ek:5",
        "Tq$)K7",
        "Oe+{Q",
        "jgYf;",
        "YI#wx",
        ">T\\aO",
        "KAB J",
        "If}8y",
        "_\\*1?",
        "0p0(zo",
        "wbm(fh",
        "*=|33",
        "V,7_~",
        "HTTP/",
        "Inrc%",
        "K\"bxr",
        "F%e,a",
        "4c-Hfz",
        "{-{87h",
        ".w#IRj.",
        "Tfzuz",
        "T\"Q^u",
        "@kIsY",
        "_4Wiz",
        "HHY4^",
        "nG0B>R",
        "np|OK",
        ",sj~w",
        "NdMZc",
        "^[o?5",
        "N1JW. C",
        "8$8,848@8d8l8t8|8",
        "9}:=;",
        "[l\",t",
        "tac0rI",
        "D$ Ph(]\"",
        "7)7H7z7",
        "Jy:gL",
        "MXvwm",
        "FWUpgradeAfter:  InstallProduct",
        "PfXOL9",
        "?az7E",
        "t`B+p",
        ">?>k>s>",
        "a(j/y",
        ":2]H>",
        "](i=H4",
        "1I2`2",
        "Wk,|>",
        "LB9AC",
        "6~0-pq5",
        "ssTu^",
        "y'MRn",
        "(3tNX",
        "@3?2#83",
        "a:oh,",
        "`,uolj",
        "brainpoolP384t1",
        "aZ}&7",
        "'y$`Q",
        "hX+t\"",
        "w}Fq{",
        "=\"=R=]=",
        "D#aoB",
        "'w9Nk",
        "G9GF ",
        "0,0004080<0@0H0`0p0t0",
        "? ?$?(?,?0?4?8?G?",
        "hS6d@",
        "d1]t|J",
        "8W:pV",
        "&!qo\\",
        "@k}o\\#S_y",
        "wmA_c",
        "@K 4}",
        "+} z3q",
        "2+3X3",
        "tcB%@",
        "<&:'.",
        "SERy[b",
        "VGRoT",
        "CN0&#KcY",
        "060L0s0",
        "Result too large",
        "(1(q(",
        "YN%_O",
        "Gck0h",
        "E7QqM",
        "^L=I\\;Pc.",
        "a\\i>t?",
        "]kKdD",
        "ALJBF",
        "t(L}~",
        "cE;8F",
        ":Tm>=6",
        "|S?!+",
        "/=LpM\\",
        "S_>00",
        "ssl_build_cert_chain",
        "es-AR",
        "bAXJr$n",
        "9spW3",
        "gFipr",
        "KKX\"!GJ",
        "l.7D4",
        "m?fy*",
        ">*nDX (",
        ",\\%7Y",
        ">O>+I-",
        "X_c# ",
        "jkj~j\"",
        "Sm9~;,",
        "b8,=E",
        "ay>gG",
        "t0'z/",
        "Unable to load backup data",
        ",6PB1zk",
        " yyi%",
        "4=DIdZ",
        "X'&ap",
        "}slT]-c_",
        "K<i|0k^",
        "! >DC?",
        "Z2ku9",
        "0ll-qD",
        "v(C:j",
        "u6p1;B",
        "praif",
        "9-4Sn",
        "BL`C*+v",
        "bx\\Q(",
        "2W`Yv",
        "[\"|L'",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\instutil.cpp",
        "IN#j`zp",
        "s_(HKiO",
        "\\'>Wg",
        "1?T 1!",
        "K;Ae4",
        "4=4]4",
        "[Jj-`",
        "<H<`<",
        "]ryV\"Q ",
        "vhobq_",
        "[SAPI] Computed digest:",
        "failed to get Component attributes for secure object",
        "iGbmKm",
        "H}M~]68",
        ">))q[",
        "D$DPUS",
        "#hDB5",
        "?<xG;UB",
        "+r9aT",
        "|?n\\r)",
        ":D;z;",
        "<(<,<0<4<<<@<D<H<P<`<d<x<|<",
        "LegalCopyright",
        "WG}`B",
        "_(vcS",
        "t$ te",
        "'nU&S=_.",
        "aes256",
        "gRiR{F$",
        "french-canadian",
        "D$(VW",
        "(x9u(",
        "8yx!B",
        "\\\"&nL",
        "#u_Hbi",
        "5^bOx",
        "eGjdj",
        "0j%$`",
        "_^4L]",
        "Acn@-",
        "?#?M?r?}?",
        ".?AVThreadProxy@details@Concurrency@@",
        "6y+V|",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\cs24\\f1\\fs20\\ul\\insrsid923653\\charrsid7500015 User}}}\\sectd \\ltrsect\\linex0\\headery708\\footery708\\colsx708\\endnhere\\sectlinegrid360\\sectdefaultcl\\sectrsid5585452\\sftnbj {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "CPzdn",
        "de-CH",
        "1eaB@",
        "$Zddi-",
        ")nMt=p'5",
        "HxHO>",
        "Y9W6zw",
        "%0[Gi/",
        "Fz$0o[",
        "yn!m'",
        "6d$>)",
        "$\\}}~X",
        "x!X'/",
        "8s.`b",
        "D<+OP",
        "$6;1%",
        "Paused",
        "=F=Y=",
        "8Bt+{",
        "GOBN+",
        "jDjfj",
        ";M=T=\\=d=l=",
        "wtqK!",
        ")kOM3l>EbkC",
        "P:2&.",
        "kif2v",
        "x}#$4",
        ":[,Xpu",
        " (%ld unused bits)",
        "9Rg.@",
        "L$xPQ",
        "0 0$0(0",
        "+*I,|",
        "rkTAK",
        "Kill 3DCompliance.exe.",
        "A1<Fu",
        "6DIG,",
        "XrT4u",
        "1<1Z1",
        "6%7;7N7y7",
        "8[<K@",
        ",M[f[",
        "ASN1_TYPE_get_int_octetstring",
        "D$@PVh(",
        "ECPKParameters_print",
        " \"OmK",
        "XqBN0",
        ";/ZIBGDq*",
        "':Ni|%",
        "o]_k^e` ",
        "jI$3.",
        "616T6",
        "7(7.787",
        "5~F,E",
        "fj1n1",
        "':o4/",
        "8oW`)!",
        "0>0`0",
        "&0Cc`zT",
        "3l\"oa[",
        "Xw}33",
        "`DBUDvvTf`3f",
        "5:[MIQ#",
        "1V2e2y2",
        "LnHH}",
        "t}7{J",
        "nf8a(Y(",
        "es-do",
        "r?*I!",
        "ssl_cert",
        "xzcvCI",
        "SEC_I_INCOMPLETE_CREDENTIALS",
        "%c%03d",
        ")1sUs",
        "|X%V9",
        "Windows Defender",
        "_akepJ",
        "cQJ1F",
        "!Ah\\?",
        "YJXl=",
        ":*LHq",
        "peer error certificate",
        "Caught an unknown error.",
        "K?5 D",
        "KqP*^",
        "f5A#y]",
        "011Q1q1",
        "0M\\ZY",
        "Dki8=\\`",
        "131F112",
        "2whF!f",
        ":\":';",
        "_`'Z0",
        "os.length <= (int)sizeof(ret->session_id)",
        "]^W>\\N",
        "3}/xs",
        "~yzz~",
        "%Fu{d",
        "Ft>0M ",
        ">u?d[",
        ">0>8>V>_>e>",
        "n0eOn",
        "| fcy",
        "e}EYLq",
        "Y z~q",
        "j#4O9|",
        "SEC_E_MUST_BE_KDC",
        "xnCLl9",
        "RR|/:",
        "#aQr}9",
        "4&5A5J5Q5{5",
        "Q@u<{@",
        "EL]R\\",
        "If-Unmodified-Since: %s",
        ":I;r;",
        "j>_WVR",
        ".YHd\"",
        "r7D-i",
        "~-j:h",
        "camellia-256-ofb",
        "a/tx\\J",
        "x;-8T",
        "'&b'J",
        "nM<7?",
        "l 0Mx",
        "2&3/3d3l3",
        "`rEV+",
        "6 6$6(6,6064686<6@6D6H6T6X6\\6`6d6h6l6p6t6x6|6",
        "/_N!6k",
        ")z;H,;!",
        ".Mm$+",
        "2I}n;",
        "J}aR!",
        "F,%wK",
        "av(M,",
        "2r!#(",
        "PPPWP",
        "F?zTK",
        "\"%s\" -i \"%sdsfa.inf\"",
        "(-S1Sjd ",
        "State_Error.png",
        "99hG$",
        "9s$tV",
        ":r4K;",
        "scL?Di/gd G",
        "5J9GFP",
        "67t/z",
        "!$\"T\"",
        "l<vj,",
        "There are more than %d entries",
        "9\"909S9",
        "Qj)Zf9",
        "g/7!b!",
        "K&ukq_",
        "052u2",
        "t@?s7",
        "vAn+y",
        ">O~j|v",
        "v.st*iU",
        "[i~58bn",
        "4'4B4G4L4i4",
        ")a064l",
        "UA^^6R",
        "ifM#3",
        "QueryPerformanceFrequency",
        "%W^GV",
        "VQ8\\3",
        ".\\crypto\\dsa\\dsa_pmeth.c",
        "StartInstHelper custom action end.",
        "*']WV",
        "{s+=<2",
        "5.5{5",
        "BcmBoR",
        ":;0vw",
        "t$$QW",
        "<3<O<k<",
        ";iJ{pv",
        "~$|FsBA",
        "uyU=Q",
        "/ky\"j",
        "XrVW3",
        ";a5d<",
        "b1Pt5uh",
        "nK0!!FX,",
        "G&A%H",
        "Ax8uD",
        "9#929Q9`9",
        "]g{.f",
        "EEU]q",
        "/l!DYRx",
        "A!f\"kT@2",
        "FWUpgradeAfter:  RunVsmonInstall",
        "J)Z\\iKL",
        "bmARX",
        "1C2[2s2v3",
        "LB_[<d",
        "?\\zJk",
        "*(5~M4k",
        "ISW_LOG_WIN32_CALL: '%S': %u %u",
        "DESX-CBC",
        "3%3b3p3",
        "`wa!^0",
        "8 8$8(8,848L8P8h8x8|8",
        "4B4b4",
        "d[pTQ",
        ",!h{[",
        "ZWP4./@",
        "7.7o7",
        "K'$.u",
        "<o,Hk",
        "aA?M~r",
        "P*1|UlS",
        "KK$(E",
        "tQtttt",
        "J/7*q",
        ")NP.c~#",
        "`$_wX",
        "re%$&",
        "M[A`\"",
        "<J5A;<",
        "EndSession started",
        "wIMl'",
        "vdxuz",
        "ucp.exe was not running",
        "FSTSW",
        ",jnof",
        "iK#r\\",
        "?;L],",
        "ju.FNk",
        "4Z557",
        "=5=Q=m=",
        ">+-=F",
        "SSL3_CHECK_FINISHED",
        "iJJi!",
        "The driver is successfully uninstalled.",
        "Vj/>H",
        "rc4(4x,int)",
        "Bases",
        "1)1@1J1[1l1}1",
        "\\&s$|",
        "VersionNT",
        "?G?^?",
        "-7B1`",
        "PKCS7_encrypt",
        "do4jc",
        "eMc8\"",
        ":N-;$O:Q",
        "sv{$+T",
        "3aA!%B",
        "bhb@1",
        "7+8n8u8|8",
        "RRYXF",
        "\\CceE;",
        "2i2|2",
        "b}L*v",
        "V Yz)",
        "`eh vector constructor iterator'",
        "Z/*x2oR u",
        "invalid ipaddress",
        "7zr!N",
        "zZjRJO",
        "RSkjr",
        "-C,3Q",
        ":|u&z",
        "<aXO6",
        "\\w\\]\"pT4",
        "0,0004080<0@0D0L0d0h0",
        "lb$m?D",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ) to install and use the copy of the Product in accordance with the relevant end user documentation provided by Check Point only on the Licensed-server and onl",
        "BN+w:!!sw::!!{",
        "E]l#*",
        ">5Go4",
        " O%f>hK2",
        "|MwRw",
        ".WEp?",
        "E~7z$",
        "fV/#b",
        "rQ9eeZ]@",
        "PKCS7_DECRYPT_RINFO",
        "655aq",
        "XWXj?",
        "CS00%%S",
        "(Fi/#3p",
        "kb,l7",
        "         (((((                  H",
        "u7fLY",
        "+w!(<",
        "9%9K9t9",
        ",050>0L0U0f0G1g1q1",
        "yEIZr",
        "KIg9w",
        "JiDv[",
        "L*'*3",
        "x*m<{",
        "a_/w>Z",
        "~k$\\\"F",
        ".'Hpgw",
        "regedit.exe /s \"%sScvPlugins-64.reg\"",
        "o~Cv|",
        "Rv0sO",
        "WWWWj",
        "MACHINE\\",
        "SA_INSTALLED",
        "OpenEventA",
        "7#7@7Z7",
        "[\\rC2Y",
        "Zoe+i",
        "eVxO6m",
        "SO/D ",
        "Dq}%*#",
        "t+h4*",
        "B<[<;T",
        "Reb)r",
        ") is an agreement between you (both the individual installing the Product and any legal entity on whose behalf such individual is acting) (hereinafter \\'93You\\'94 or \\'93Your\\'94) and Check Point Software Technologies Ltd. (hereinafter \\'93Check Point\\'94",
        "FirewallExtension: Cannot remove firewall rule '%ls', which defines both an application and a port or protocol. Such a rule requires Microsoft Windows Vista or later.",
        "ISBpJ",
        "=.nKG",
        "2,2?2a3q3",
        "9%9=9E9t9",
        "XJ0Uv(",
        "7x-?fwsz",
        "C=MZm",
        "H7}6`",
        "1 1$1(1,1014181<1@1D1H1L1P1T1X1\\1`1d1h1l1p1t1x1|1",
        "7&Zia",
        "pm`k{",
        ">I$9D",
        "E0aC+9L",
        "#h/+z`",
        "`1:,I",
        "Internal HTTP POST error!",
        "H`lYfz",
        "Apdv.",
        "AO}lH",
        ".CWyR",
        "Ss>I*",
        "'Ho?yv",
        "sD[d_?C8",
        ": :$:(:,:4:8:<:@:D:H:L:P:\\:d:h:l:p:t:$;,;4;<;D;L;T;\\;d;l;t;|;",
        "PUNPCKLQDQ",
        "`xi=p7d",
        ")Z-hQ",
        "L?HR,",
        ">Ei-a",
        "1]yV'",
        "AES128",
        ";6]aB",
        "{XPFio",
        "Q+g7F/",
        "encipherOnly",
        "PEM_READ_PRIVATEKEY",
        "t$<PP",
        "4#}e ",
        "`O676Fk",
        ";;B&F7B",
        "-b>2Bp",
        "44hlh",
        "@>\\wn",
        "Ue.tS",
        "@n;'J",
        "KHD&a",
        "AhxW!V77y'",
        "0^k~ h",
        " FG;t$",
        "u{]0]",
        "kmy\"1",
        "s'_v.q",
        "n'TB\\M_",
        "QYj-p",
        "MP!.o",
        "RaiseException",
        ":#:0:b:",
        "EVP_PKEY_keygen",
        "pxncd",
        "q}Hf6Fc",
        "DlAqE",
        "**6FO",
        "jAj~j.",
        "J9,2{",
        "3H$3T$X3L$\\",
        "sT*1G",
        "FgI(qy",
        "2 2(20282@2H2P2X2`2h2p2x2",
        "pg86m",
        "jjjmj%",
        "jZ&@-",
        "jgjfj",
        "kXq8s",
        "_`\"e+",
        "{<u}i",
        "BF&T(|S",
        "YGmWs",
        "Error setting registry value:  ",
        ":$:,:4:<:D:T:`:",
        "$SVWh",
        "o+B/)=",
        "EH>$IBh|H",
        "?<3<%",
        "_KZ<\\",
        "oo@\\m9o",
        "TsV%%V",
        "`D$daM-l",
        ";\"<-<6<O<[<d<k<p<u<",
        "l;:Z,",
        ";ya)*",
        "Fefe+",
        "0-Kf1W",
        "}S{Hr8",
        "XRXZLba",
        "Y.c,[",
        "MTMvL",
        "m!1&8~",
        "CTPUD",
        "qTsq9",
        "s3~W~",
        ">VW+B",
        "Failed to SetDriverMod",
        "\"JRrV",
        "o.DwD",
        "|>=+,",
        "%$%d&",
        "QupVeJ",
        "RegCreateKeyExA",
        "U<g0K\"",
        ">,:LXH",
        "R[@(`1",
        ",JBgxrpX%k",
        "NlbNI'",
        "t$$GV",
        "b^3P$",
        "aGRt.",
        "jC<\\A",
        ";1;7;=;D;Y;_;e;l;",
        "h?3b>",
        "ZXpI5",
        "l$,VW",
        "f98t~",
        "PSUBD",
        "J$J4*",
        "C!H~Y",
        "t]+ v",
        "g5&'29f",
        "/+{b|",
        "!RU6\"",
        "IsOG]",
        "J$Nk)",
        "SNMPv2",
        "Wke;d",
        " U$/<",
        "t0<WhVK[",
        "d.dNSName",
        "EPAM_CheckInstallConditions started",
        "CryptDecodeObject",
        "&V=V]",
        "o7nY2",
        "A5zhM",
        ">$?D?W?c?n?",
        "\"X5 A}",
        "HVqj$",
        "(EDh^8L:",
        "B\"\\rG",
        "F^H(E",
        "8$8=8V8o8",
        "' i3{+20",
        "GN~uO",
        "+>KH]O",
        "s6wC>",
        "QX<{%",
        "CopyLastMSILogFile",
        "AKF|v",
        "t$<3\\$H",
        " $t-x",
        "jljlj%",
        "5{w]+",
        "_4q8p%'",
        "=uw0i",
        "=.->(",
        "SI{h'4",
        "?A\"x3",
        "\\>9Bi",
        "&UZYH",
        "&,D,>",
        "_$za8",
        "BIO_puts",
        "bn X=si~",
        "1(2X2h2x2",
        "162G2M2]2k2r2",
        "Vbjb^",
        "[ Eq+GK",
        "=Y'-v",
        "V>Gy.",
        "9)9E9a9}9",
        "KY+2-B3",
        "7-NpW",
        "a2Q_']",
        "@WEoZ9FGa",
        "9t$xu",
        ">N?t?",
        "h]^=6s",
        "xW:u7+",
        "Vu<QLl",
        "78u6A",
        "$vr9%%",
        "jAjxj.",
        ">&>:>?>U>x>",
        "BWRF{AB",
        "P;<ot",
        "QUQVQY",
        ".z;CC(",
        "`v7/!",
        "}VP9Z@",
        "LA).Y!",
        "failed to open view on WixInternetShortcut table",
        ";:F8q",
        "<+s!e",
        "696N6t6",
        "`iz2?",
        "Ta?s^",
        "u;*$8",
        " |Xtl~",
        "-'Y<7",
        "JF%\"J%-y",
        "NMU(y[",
        "?uamc",
        "dVBWR",
        "a3i'YmCE",
        "RP`am",
        "08`!R",
        "737f7v7",
        "<v7'y",
        "?CPSystemVoid@@YAXKPAD0J@Z",
        "#AF1K9",
        ">ow`xb",
        "(Kp.7",
        "_yL[ag-F",
        ".auI\"",
        "+UH|4m",
        "Fn%W-",
        "4QK0S",
        " Q`@Ce",
        "SELECT * FROM Shortcut",
        "+e/CT",
        "cOtgg",
        "Az'PY,A",
        "X509V3_EXT_nconf",
        "iv gen error",
        "D.QV{5",
        "+u4u$q",
        "ATT7o",
        "\\_5id",
        "ews@j",
        ".050A0K0h0o0{0",
        "f&qp7i",
        "XU3\"}",
        "111`1u1",
        "ZV9b&",
        "/F)1@",
        "H#\"ZQ",
        "!3tog",
        "P`R\\=",
        "L*5Uj",
        "dCK_J",
        "[Uninstall]VSTerminateTVService/OpenProcess failed (2)",
        ".>.,<i]}^",
        "4(4,40444<4T4X4\\4d4|4",
        "?hT>!",
        "TX:Gqw",
        "l(B2Z",
        "7i7x7Y8",
        "}Ke>T2",
        "?0Wsl",
        ":1:Q:_:m:r:~:",
        "pKFi2a",
        "plAsC",
        "35o6t",
        "n4+Xp",
        "*cY`%",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\tx2520\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid12071538 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607 For }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid6904607\\charrsid6904607 Hardware}{",
        "OaxI,",
        ".\\H\\Z",
        "D$FUP",
        ".w]V?",
        "MD ]s",
        "YlTKkS",
        "ECDH-RSA-AES128-GCM-SHA256",
        "rd^w.",
        "P\\N9/",
        ".?AV?$sp_counted_impl_pd@PAUHKEY__@@P6GJPAU1@@Z@detail@boost@@",
        "OpenSSL HMAC method",
        "YL+qff",
        "5NT\\<",
        "o)dZ${",
        "RegDeleteKeyW",
        "[VSReadUninstallInfo] Could not find value for key: %s",
        "1t?H;(f",
        "X^d Ob",
        "H}_2l",
        ")cE\\F6",
        "$K{Ds",
        "$UI,D",
        "\"mkSB",
        "$P3KU",
        "p.+<\\",
        ".?AVCPerfCounter@@",
        "_TCKn_g",
        ";j:Zw",
        "+\"peF",
        ":J+,,,,)(xn",
        "]B%$B",
        " JjVeeJ",
        "ql)gsP",
        "5UK+p",
        "[6/!eT",
        "3w.]:?",
        ":=$;5=5=",
        "0f1x1F3\\3",
        ">P.yK",
        ">C>g>/?S?p?",
        "+pAcM",
        "?Qls*",
        "h\"}%v",
        "vH6!5",
        "Y*$6d",
        "95UFA^r",
        "*j!y0",
        "/u'zw",
        "Done waiting for Services to stop, result %d, unstopped services: %s",
        "@ZgVK",
        "<*=3=x=",
        "x^}h0",
        "e]RrA",
        "`'_3*",
        "({C1p",
        "#:''\\#X{",
        "ITdW ",
        "#,`pH6",
        "ZrA/$",
        "it?c7",
        ">%?g?",
        "d.iPAddress",
        "}QiJA",
        "failed to delete file '%ls'",
        ",2ZjE",
        "Rqs0fS",
        "6A7b7",
        "1$10181X1`1p1x1",
        "zKgCM",
        "U-UmU",
        "[-='W,",
        "ZV`ba",
        "SCapD;)C",
        "[)p1s{@_l",
        "fwk~-",
        "O8x!*k",
        "/w}P4",
        "#SX)R",
        "d=%-2d hl=%ld l=inf  ",
        "D$$S3",
        "bUAjg",
        "cA\\S,",
        "AIDEW",
        "o'~Q+",
        "[bihO",
        "E.\\crypto\\rsa\\rsa_gen.c",
        "0 0$0(0,0004080<0D0H0L0P0T0X0\\0`0l0t0|0",
        "8H8T8t8",
        "9(929<9F9Q9\\9k9",
        "-N3'V",
        "CP Integration",
        "tI97uEjD",
        "n@d JA",
        "oPUUW",
        "O#OGOSO\\OfOtO",
        "CPupS",
        "SUVWh`",
        "4#oTH",
        "l,'Fd",
        "\\r5\\v{",
        "\"(A4lB",
        "[kDi+9^",
        "bt qHD",
        "v\\C.%",
        "),)hR",
        "Z_5hMV",
        "D$@~F",
        "9(0sY",
        "cast5-ofb",
        "Q77vxq",
        "LoadGUI",
        "Permission denied",
        "paHSY",
        "z'K5s",
        "id-pda-countryOfResidence",
        "/M,q|",
        "FS)$Q",
        "Kp*3c@",
        "5[8[9",
        "5+psZ",
        "=0=[=",
        "{9tN6",
        "=i=X!",
        "0J0X0r0",
        "filename after the strrchr: %s",
        "=N=T=z=",
        "QyfmfI",
        "WTLS curve over a 160 bit prime field",
        "vEaJx",
        "        <imageentry",
        "SetProcessAffinityMask",
        "Ui%jL",
        "QCXeV)U",
        "&r3%D",
        "mG@I8",
        "Z}H30d",
        ".yMPT",
        "A\"mKg",
        "0>Z7U ",
        "2>3H3",
        "atlTraceSnapin",
        "{\\mT&",
        "/0D),",
        "!)cJ;",
        "7$:t:",
        "_,Lx:",
        "!XdsWlKW",
        "cjdO;",
        "K5Fc'!?",
        "QgDKP",
        "EVP_PKEY_derive",
        "MfIDJ",
        "client write key",
        "7UO&7",
        "090C0L0f0l0",
        "i`O7u",
        " doesn't exist.",
        "_4,ei",
        "I@n5kH",
        "?4?;?X?\\?`?d?h?",
        "qT9}<D",
        "F(NS_",
        "\\ug(nU",
        "o+RoI-",
        "wc^UXt",
        "<SdZV",
        "ko>:'",
        "cv'kg",
        "u,DOW",
        "bad checksum",
        "]9=a=",
        "0V5Cx",
        "^e\"k9E",
        "DS_InstallFACDriver ended.",
        "L_}Nn",
        ";g%UkL",
        "Third Party Software may be provided with the Product for use in connection with the Product subject to the licenses of their respective proprietors.  The provisions of this Agreement shall apply to all Third Party Software Providers and to Third Party So",
        "cz#!N#",
        "B~B\"B0BBC`![X",
        ";D<T<|<",
        "5]EX`",
        "STARTTLS",
        "8,9V9d9",
        "WSP7C",
        "zs*%.]",
        "!!h8IZ",
        ").el[bb",
        "IY$2o%",
        "W)6+HR+",
        "JGf/x",
        "2tcOZ",
        "o P B",
        "SUITEB192",
        "no pem extensions",
        "Checking for 64 bit machine.",
        "O-O?5O",
        "{'g,D",
        "ssl3_check_client_hello",
        "6 60646L6\\6`6p6",
        "SxiT?",
        ">STAR",
        "*Pww*",
        "Su>nu",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid12071538   }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\lang9\\langfe1033\\langnp9\\insrsid13240566\\charrsid13240566 More information on the Check Point support programs is}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        "< <@<H<d<h<",
        "&j`|4'",
        "*&Fv*\\",
        ":u&a+",
        "happy.png",
        "G@S^<",
        "McJY_{7Zr",
        "~F6)S",
        "1E)X2",
        "DvY*W",
        "S;D>tnDC",
        "thJiD",
        "yVW?@^",
        "Professional",
        "jvUa2&[+",
        "CollectBootStatistics LoadBootTimeStatistics failed.",
        "Fj?ZH",
        "aEXX?",
        "%;p?5",
        "%m / %d / %y",
        "IsOfficeModePropertyDisabled",
        "4<4q4",
        "D$ USWP",
        "cf}gO",
        "CancelAScheduledReboot:  CancelAScheduledReboot finished.",
        "/O;UK",
        "%b,t+",
        "Set binary key ",
        "8P8V:h:",
        "z_NtaoU",
        ":Mq(|",
        "xs13U,~",
        "N;Fc0",
        "Uze=(",
        "P3!hB",
        "ah1n3i",
        "D$\\PW",
        "*SU?/",
        ">#>1?A?_?x?",
        "VLAi{",
        "$9#/ix",
        "; 1M$",
        "eD_W{%M",
        "vp8Rp",
        "PExOf",
        "MHW^%",
        "h+eTk",
        "*Y]dZ",
        "yc9$&o",
        "({+A_\"6",
        "Cannot find %s\\%s*",
        "error setting nbio on accepted socket",
        "rqgfz",
        "qC(4Z",
        "Kof\"-",
        "DO_B2I_BIO",
        "tlYK,",
        "Nw3C1",
        ")DX-lM",
        "!t6_B",
        ".\\crypto\\ec\\ec_asn1.c",
        "Ie3L~",
        "J&WL$",
        "<unsupported>",
        "d{;[D",
        "ECDHE-ECDSA-AES128-SHA",
        "Done waiting for CPDA Service to stop",
        "8*8C8\\8u8",
        "ph}jQ",
        "(Ndun",
        "@C2sK",
        "|InRuzo",
        "1&4sD",
        "|4b'-V",
        "j9EXK#",
        "gMl{s",
        "s4gA0",
        "rwjHA!#n",
        ".?AUISchedulerProxy@Concurrency@@",
        "XUw6e`",
        "|u#>z",
        "-nCkP|",
        "=4wioq",
        "Q?<Yu",
        "<LbTg:",
        ")94a^",
        ",;s3ii",
        ".?xo=",
        "RAND part of OpenSSL 1.0.2h  3 May 2016",
        "AV is not being installed.  Remove ZAFM value from product key.",
        "X\"eHH",
        "UWFaj",
        "Z-*@D",
        "+jiA*",
        "?)7{y",
        ":?T.jQ\"mP2",
        "%9r\".",
        "BOR ?i\\n",
        "+$zri#",
        "uB)i\"",
        "Y,[5A",
        "]q_%b",
        "CfTNu",
        "a!>SL>Jf",
        "tftp_send_first: internal error",
        "Failed to read rollback script into CustomAction data.",
        "br]b/",
        ".\\crypto\\evp\\pmeth_lib.c",
        "EC_PRIVATEKEY",
        "unauthAttrs",
        "V@lcO{",
        "y]O1{G",
        "`r9`m@T",
        "0,1Y1",
        "F~LU|a",
        "D:(A;;GA;;;WD)",
        "uQ9n\\tL",
        "]9iVE#",
        "\"qeFT",
        "; ;(;8;@;d;l;t;|;",
        ")&VCf",
        "qN2`Un",
        "sL8U!-",
        "2$2+20252=2C2X2h2",
        "<oY1L",
        "setAttr-SecDevSig",
        "<-<g<W=_=s=",
        ",k3aO",
        "wR'Zu",
        "6n5M8",
        "9QB(@",
        "Q^8hTo5)",
        "A 2~A",
        "F3j('",
        "01m@dR",
        "XC9 `",
        "ZIF&G",
        "/7A2Tv",
        "password based MAC",
        "w3^~}TY",
        "RSA-MDC2",
        "?#_^>",
        "Qt#Qr",
        "bB\"`3",
        "jphDx#",
        "R2H\"u",
        "HS$1Xk",
        "?OuW[",
        ".u#H#",
        "E2 q#",
        "@u'%E",
        "WQ(>9",
        "/)eEz",
        "BbEhz`",
        "MhU2]",
        "M(=[iD",
        "jijqj",
        ".\\crypto\\hmac\\hmac.c",
        "setct-PResData",
        "ql}M{T!",
        "h&*Izl",
        "SeGqk",
        "1.gc|w",
        "\\n*FH",
        "failed to create an instance of IShellLinkW",
        "7w,?/",
        "%e:}Zjy",
        "CANT_LOAD_PROPERTY_INI_FILE",
        "3D$,3L$(",
        "C77nYmm",
        "{!C\"!",
        "B1z]$",
        "Y(gwxP",
        "D5m`w",
        "NpDv<",
        "whPVJ'9",
        "sLc%;",
        "Z&bdM",
        "171_1s1",
        "VerQueryValueA",
        "t&h@%",
        "?J?a?g?r?",
        ":OfJI",
        "GHFE /",
        "^[u:f",
        "}6ern",
        "!@4pv",
        "5R6[6c6",
        "pH\\#%",
        "q2tSo*wG",
        "4p5&|",
        "a7}8Ae",
        "..W\\Q",
        "J>Qh3J@3",
        "'Z&(^",
        "F0>9&bV",
        "_46/s",
        "RSA-SHA224",
        "vvuDN",
        "c,*m@",
        "484D4d4p4x4",
        "|fE~TN",
        "Ph0MM",
        "lwWFBi",
        "GetLogicalDrives",
        "rv~*~",
        ">:m!P",
        "soUnp",
        "%s %s %s",
        "4(424E4",
        "encryption.gif",
        "1 1\\1m1|1",
        "OEu!/%",
        "BIO_nwrite",
        "90uBPS",
        "G @;G",
        "I'6<M}",
        "^5OhI",
        "Failed to update ",
        "7,lHO",
        "t$8UV",
        "y)JTp",
        "=%>;>K>k>r>",
        "7Y&-4=",
        "-.uti",
        "\\fs20\\insrsid10102966\\charrsid3875139 After the }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid5727096 W}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid5727096\\charrsid3875139 arranty }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid5727096 P}{\\rtlch\\fcs1 \\af0 ",
        "@{zjz?",
        "cu1Bu;",
        "+CVJO",
        "\"#$%&'()*+",
        "PUSHA",
        "_^]@[Y",
        "Event/EventData/Data[@Name=\"BootEndTime\"]",
        "Delete after restart %s",
        ".=^=K=L=M=N=O=P=Q=R",
        "gdf^V",
        "1U1_1|1",
        "Helper::stopWatchdogService",
        "gost2001",
        "7D8x8",
        "A2D38",
        "nyPAG",
        "FrbzW",
        "Z;Jbj",
        ">2>Z>",
        "application/octet-stream",
        "_QH)?",
        ">#>@>Y>^>c>",
        "GZ/aK",
        "&-uqd",
        "cYEN8",
        "yrE@u=gH",
        "SHGetSpecialFolderPathA",
        ":Gy2m",
        "6D7E8",
        "MMFNewUninstallInfo",
        ">q/*]",
        "(.[,af",
        "ios_base::badbit set",
        "=8=D=d=p=",
        "ai\"J@",
        "PA&**~",
        "    IsInstalled=\"1\"",
        "x$&+`.",
        "  <trustInfo xmlns=\"urn:schemas-microsoft-com:asm.v3\">",
        "VC20XC00U",
        "t'USW",
        "!\"DB@",
        "I#WCqe",
        "=11d3",
        "8V,23",
        "44<iB",
        "ETvgTupC1",
        "Oj~oG",
        "d$!DD",
        "Xdmh9",
        "H0T-v",
        "PKCS12_add_friendlyname_uni",
        "StopRemediationService_rollback finished.",
        "000W0",
        "s#L.$v9S",
        "OXuu|",
        "+\"o3L",
        "+pf?4",
        "-kak3",
        "_c+lXV",
        "bad rsa modulus length",
        "2*2M2\\2s2",
        "'*42-",
        "m;^Qh",
        "`+Kn`",
        ")T`E<",
        "\\F7JL",
        "AeM6h`",
        ":bK-U",
        " $s$8",
        "2G2v2",
        "3i'{g",
        "SEC_E_INSUFFICIENT_MEMORY",
        "S]WZ|",
        "6.t6]",
        "=4>\\>",
        "H%oZL",
        ">#e<b{",
        "Xs,$*",
        "oK`,a",
        "[BgQRB",
        "2G;g7Q",
        "\"qwmE",
        "2.5.4.3=Check Point Software Technologies Ltd.",
        "k5~|Hj",
        "$+6^$D",
        "052V2h2",
        "STREAM_ERROR_CREATE_FILE",
        "= caz",
        "4j+d5",
        "decryption failed",
        "RI-mm",
        "=6=M=q=",
        "rG/__",
        "\"o;h(Y",
        "SVWQP",
        "/98Lq",
        "0V3&\"PpE",
        "R8E7KN",
        "88\\_;",
        "Zo>b$",
        "=43+%",
        "CSeq:",
        "reauthentication.png",
        "0'1N1",
        "+Hj||",
        "random number generator",
        "D$(PUWQt$",
        "?(?-?W?f?k?",
        "DZ:`~",
        "5<6[6u6",
        "kL*fm",
        "'BIJS#C",
        "T~_EK",
        "7.7G7`7y7",
        "MY#2I+",
        ".CRT$XIAC",
        "hUkOj=-",
        "`zu'g=0:",
        "\\dg=!6",
        "1 1$1(1,1014181<1@1D1H1X1r1",
        "go2i&",
        "Y=;=P;",
        "dJY\"r,",
        ")3UfC",
        "ij?I_ ",
        "`Yh{_u",
        "Q].5hl",
        "pSpecified",
        "YtbVc",
        "6$6@6`6x6",
        ";D!]A!",
        "id-ad",
        ".Ptmh",
        "F2M6?",
        "jnjyj",
        "abr~S",
        "J/g(h",
        "w(:K_4",
        "7'\\B\"%",
        "E.-U$",
        "T$(Rj",
        "jsjrj",
        "WixSchedInternetShortcuts",
        "x]Fav",
        "TeqZ|",
        "2!YdI",
        "Z`Q2^",
        "l=M@u",
        "mUfw^e",
        "O<,vQ",
        "DDRL-.",
        "CzUiNe",
        "N09^4",
        "w'1iR",
        "Dcp;Ya",
        "r\"\"''rr\"",
        " 0xc5",
        "P;s<+y+",
        "3oNDn",
        "4Zg>*",
        "NY~)M",
        "<$<,<4<<<D<L<T<\\<d<",
        ".I$;3#3",
        ";C<j<",
        "RemoveSC()",
        "l7Kx,",
        "1G3f3",
        "x9}2:",
        "-;C-0G",
        ")'0F$",
        "X,S]L{",
        "t!j=Z+",
        "u4'yS",
        "`jY;S7U1W",
        ";-dz7q|",
        "\"=Q@ }",
        "Sn@E3",
        "d}p(2c]",
        "sigrequired",
        "b;\"XU",
        "STREAM_FROM_BINARY_NO_FILE",
        "B7,2s",
        "5WF4gszR",
        "|[u$x",
        "XV\\_]]",
        "TLS1_CHECK_SERVERHELLO_TLSEXT",
        "w$k}:",
        "d~pp ",
        "NAwUG",
        "I?<rR",
        "*<emqO",
        "CANT_CREATE_PW_DIALOG",
        "6{'FI",
        "?AF!?",
        "OXhZZ",
        "-].]2\\6",
        "Qk\\vY$",
        "~%^M'",
        ":<;c;",
        "$y +Y",
        "Failed while looping through files in directory: %S",
        "n_TK@",
        "M^]tq#",
        "}Cz!e$1!E",
        "=3=?=b=",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\tx5352\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid10707243 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 ",
        "digest requred for handshake isn't computed",
        "7~)(\"?>",
        "EN0D/",
        "ekernel32.dll",
        ">'>;>A>F>N>}>",
        "52\"sX%",
        "LvXII",
        "#Uv%1",
        "private key decode error",
        "QoVxW",
        ">SF0{|C",
        "xb7^S",
        "=di1P",
        "\\fi-360\\li2880\\lin2880 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'04.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "CreatePipe",
        "wGT?T",
        "+Io#W",
        "b+rlY",
        "GENERAL_NAMES",
        ".?AVCAtlException@ATL@@",
        "8yr|%",
        "SS^vM",
        "a051u1V3",
        "china",
        "$1Nf6)P",
        "bTM)93",
        "/`(ri",
        "&Fa+U",
        "WBWO7",
        "G-,<m?~",
        ".Luy`",
        "6zh^w",
        "smj-NO",
        "D$HPV",
        "7G(Ni",
        "payment gateway capabilities",
        "-U3tG",
        "1*Afjx",
        "dugGz`F",
        "TESvc",
        "+rCEN$Rs",
        "Ph<@%",
        "d.v1AttrCert",
        "rTf;u",
        "ZHU9+",
        "4Zlv$i=",
        "p^UN4",
        "3<Vi\"",
        "Done waiting for EPAM Service to stop",
        "2XmXVDZ5",
        "Q0r*k",
        "DICT.",
        "1*2J2",
        "j~jlj",
        "[7v]L",
        "4O9O@OPO",
        "SeHx;F",
        "vsmon_StatusInfo",
        "2'2G2N2[2e2u2",
        "A8P&7",
        "RjK?\\#",
        "l8nLBXR",
        "+P5wT",
        "~$k-|m",
        "oFlW}",
        "9Q9l9",
        "SSL_CIPHER_PROCESS_RULESTR",
        "H<H9e",
        "FINIT",
        "SECG curve over a 128 bit prime field",
        "P62#<",
        ">]R&H",
        "C.*9{",
        "N_G9`",
        "]:\\|^",
        "u_4Q;A",
        "RTSP CSeq mismatch or invalid CSeq",
        "IKEGAC",
        "w>Nr#",
        "<75^fa",
        "222x2",
        "g:wE-",
        "R;a\"k",
        "ar5\\D7",
        "JyRCY",
        "f:O<yB",
        "Integrity level is %d",
        "`C0tUf[2",
        "auth_attr",
        "F:\\ckp\\src\\EP_CALib\\E87_20\\CMpub\\lib\\win32.release.32.msvc141\\CALibrary.pdb",
        "Mbd!y",
        "8k>)?J?",
        "y{L7/s",
        "-G bT",
        "mD@|/",
        "TERM TYPE",
        "a yqB",
        "1%2,282F2`2g2s2",
        "Hqu> ",
        "rx@`K'",
        ";5<V?",
        "failed to set exception name",
        "Y*YjY",
        "yGTr=",
        "6tSxQl",
        "tNziW",
        ";G=F>",
        ">qqeY13k",
        "!{q3C",
        ":AbUP",
        "%1-J#",
        "\\Iqo7",
        "6(7K7v7",
        "9\"$i)",
        ",;1l*",
        "not supported for this key type",
        "4%4<4O4",
        "tpe7Ii",
        ",t*\\~",
        ";%;2;C;O;`;l;};",
        "device or resource busy",
        "PCMPGTD",
        "BN_CTX_new",
        "BeginSession ended.",
        ",TMgM",
        "Ax#?uN}*",
        "<-8Ly-",
        "I3ICx`6",
        "Z`9iD",
        "5$505P5X5d5",
        "s<5'Zj",
        "SQRTSS",
        "4181@1D1H1L1P1l1p1t1",
        "dtUI7_",
        "PerfCounterSetUpdate",
        "tN7'B",
        "3T$ 1",
        "O>Io:",
        "qz?}4",
        " 0xb0",
        "VMCLEAR",
        "|FCz[",
        "H}z]1",
        "sm>k'zJ",
        "&Lttb%",
        "n)cau",
        "Uninstalling existing product",
        "R^G+9z}",
        "Dwd!1",
        "%:SIbG",
        "U}KTIpY",
        "Failed to receive SOCKS4 connect request ack.",
        "FlushProcessWriteBuffers",
        "write to read only BIO",
        "at9Bi",
        ";(;-;4;;;B;O;X;t;",
        "MOVNTI",
        "3(4:4",
        "%swix%s.%s.%c%c%c",
        "null ssl ctx",
        "[UKIo",
        "Removing ZoneAlarm",
        "$40,@4PLl\\",
        "O\"\"_&4~",
        "230110230200Z0+",
        "ITlq^",
        "EwQ~T",
        "\\fi-360\\li3600\\lin3600 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'05.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "<!<'<-<3<9<?<E<K<Q<W<g=",
        "]52kG",
        "ASN1_TIME_adj",
        "KrR{j",
        "GfTDf",
        "S^Us:",
        "^`cT^/",
        "N0([q",
        "OVl/kS",
        "D&!$J",
        "0,0<0D0L0\\0`0p0t0",
        "GhSNje&@\\",
        ")'yJ=",
        "B ;2B #/",
        "XMNI$M",
        "3p7Za",
        "YvXj7",
        "<PC l",
        "zya+\\]",
        "`C\"uR",
        "ic$I#V",
        " cp'0C",
        "L$,^[3",
        "FWFreshAfter",
        "8O q(",
        "l@>OY",
        "swipHQ6",
        "0&OYd)",
        "%H?UQ",
        "twQ#vm=l",
        "F0~x\"",
        "addToWinFwExceptionList",
        "5)515T5_5",
        "\\j-O/",
        "Zm[]+",
        "woBD[]",
        "v,eGJ",
        "R+~o\\",
        "Cnr~9",
        "QH84iN(_f/",
        "F^TKF",
        "'pi+QH",
        "4x4Vl",
        "c(Np]",
        "WcX#Ys[#\\",
        "/):r=",
        "<\"=*=:=h=}=",
        ".yHE'",
        "szN j",
        "tx49,",
        "tBw7#",
        "6.6J6f6",
        "[7F=*",
        "VhXD!",
        "issuerUID",
        "rKh;v5",
        "InstHelper is not running, will not be able to stop AB service (EpabService)",
        "O>+tJ}H",
        "rL+!R",
        "cy-gb",
        "!vp$T",
        "SSL_use_certificate_file",
        "b4\"B*L",
        "explicit",
        "^wRsJ",
        "(H-Z}",
        "f!:P ~",
        "t(hT;L",
        "7N;n;",
        "tLXv1",
        "?<?D?P?p?x?",
        "DMs2,",
        "?R$3+",
        "+L$ QSR",
        "? ?b?s?",
        "!~T9z",
        "Failed to copy CustomAction log name: %s",
        "3L$\\3L$<3L$4",
        "L$(1L$ #T$ ",
        ",[:x1",
        "=A!dT",
        "QVuhZJA",
        "vgu\"L",
        "+}I3+",
        "V$K+]",
        "3L$43",
        "uc\"W/H",
        "D-lY6b",
        "8!u'f",
        "8kz>\\~",
        "&qaS:",
        "{e e@",
        "f^W]4",
        "/s!#\\?",
        "Ph%2G",
        ":^@`Q",
        "z33;(z",
        "t]=DDD",
        "-D$:+>*l",
        ";,;9;Q;Z;g;q;",
        "738C8c8",
        "!Rvbj",
        ";'N?;",
        "Global\\WixWaitForEventSucceed",
        "'nU_O_M",
        "U/p)o+K",
        "[B'IU[4f",
        "? ?@?L?l?t?|?",
        "&+8\\d",
        "x*qMd4",
        "<C<t<",
        "Prodconfig: InstallProduct starting.",
        "BY{u9V",
        "W_K6G1",
        "Remove files",
        "]%C.u3",
        "D$@Pj",
        "phNa=",
        ">S?t?",
        "llR9C",
        "/GY`t10",
        "9)3g\\V",
        "3]!| ",
        "A'l7t",
        "T6a0!E",
        "\"Q9n_",
        "1~)1+",
        "YNG\\#",
        "0Z0g0",
        "{(7\"+",
        "$XhJ#K8",
        "api_ms_win_core_handle_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "9G$s$",
        "jyjgj ",
        "C~zXaP",
        "p(t&6BK",
        "missing ocspsigning usage",
        "+s$[I",
        "missing verify message",
        "O;8HY",
        "Request Single Extensions",
        "E({? ",
        "@.|uICco^]$",
        "203~3",
        "]dR(C",
        "!<t?.",
        "ctrl command not implemented",
        "cert length mismatch",
        "P<[na",
        "D$ 9D$",
        "7e3}K",
        "PARTIAL",
        "Et@pg",
        "1,1<1L1P1T1l1p1",
        "9]4wi",
        "bX:aI",
        ".e+s;2s",
        "nM,Vn",
        "x$0-g",
        "TqBoR",
        "n9:<H",
        "<'<`<}<",
        "+3>$(",
        "mif:X",
        "P@e2,S",
        "GetProductInfo",
        "%04-1",
        ":4:8:<:L:",
        "<P'0;x",
        "\\PAC_1_Pol_CPEPS_SID20_ID_*_content.cppol",
        "fvkK`BAa",
        "`Kaj\\",
        "g_>P_",
        "@h(k+l`",
        "jijxj",
        " Bb3q",
        "r|*XXWG;a",
        "YboFg!ob",
        "YFh*{",
        "jAjgj.",
        "d:Eu^",
        "executable format error",
        "rKUQE",
        "<'>F>m>",
        "vE>J>N",
        "3A5O5",
        "baIkj",
        "fips mode not supported",
        "'3.3w4",
        "FBNrI",
        "gRw ,",
        "P+z{z",
        "zdz8x/j",
        "l^)?&",
        "0\"iX9",
        "@9EEu",
        "IDIDH=",
        ";n$5#+",
        "555Q5f5s5|5",
        "y`%L=",
        "Cnr23",
        "es-PY",
        "{/zt[",
        "S)cug",
        "2A)*k",
        "e*z$@",
        "d Jk X{",
        "i13Vv,",
        "g(99k",
        "B1oPo",
        "t_USIF",
        "]96)\\",
        "srhnu&Xc",
        ".?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "%^$|h",
        "mM6vVF",
        "Checking App: %ls ",
        "SI25QF",
        "t>6ec",
        "3A3L3",
        "v]|t2",
        ")H(7#",
        "[,{@,^",
        "Skipping time comparison",
        "{t9Dz3",
        "4)G((",
        "#k)<+",
        "2$2(282<2D2\\2l2p2",
        ".?AVRebootAction@@",
        "PpX&\":",
        "<<6AEA",
        "39Klx",
        "VhXy#",
        "\">>,B",
        "*^?EjK",
        ")g\\he",
        "1G3c4",
        "IO^rY",
        "KB}g<",
        "zN&${",
        "W`}PG",
        "]Qg0S",
        "`Hx#z9",
        "zKrW4",
        "RBuB\"",
        "1w;w-",
        "3@/|J",
        "Installing firewall exception2 %ls on port %ls, protocol %d",
        "mpz[W",
        "$>4@K",
        "<+=p=",
        ">$]kB",
        "iu1e@",
        "=l5D/",
        "<6CVL}'",
        ">c32x",
        "mOv8$",
        "+._ee",
        "F?ap4",
        "9sa2E",
        "<5<|i",
        "8s&lC",
        "37YjNs",
        "mny@/>",
        "X<YDO",
        "7^hva",
        "keLg0",
        "PtRWP",
        "LzA>+",
        "vwv\"%",
        "B/0bxQ~",
        "\\F-\\T/t",
        "_S.E,",
        "api_ms_win_core_errorhandling_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "Y^;F;VL",
        ";]DK;K",
        "6GUNJg",
        ":MKMr",
        "EhUxZ",
        "SELECT Property,Value FROM Property WHERE Property = ?",
        "8PL{xA",
        "HLazE",
        "?s_IP",
        "kS/,?[",
        "#4`g ",
        ".ICbOA",
        "6v4Qw{",
        " |$P_|",
        "tZrD7",
        "QB7?Uf",
        "jtjwj#3",
        "N1,G.X",
        "&dbF:xrJ'$#",
        "h,^ ,&",
        "347;T,",
        "AR:|p'",
        "6<Q.'",
        "<LQK(",
        "en-tt",
        "w\\-?p",
        "null string path supplied.",
        "$.GER",
        "ec_GFp_nist_field_sqr",
        "S34?A",
        "C0A,NII",
        "ZU<=c",
        "C9/rB",
        "oE(u ",
        "e1I\\M",
        "Prerequisites installation require restart",
        "5!]_}",
        "xlL<d",
        "3Uz5P",
        "I@A8^",
        "fR`38",
        "dFailed to execute firewall exceptions",
        "K,5E3",
        "KR<(m",
        "{3gjr",
        "qe,D],Q",
        "avc}Utb",
        "LiP@v",
        "ECDHE-ECDSA-NULL-SHA",
        "BhM`~",
        "@\\2I4",
        " is2}3",
        "*x&Gfx",
        "T97<g",
        "Bxs/k",
        "jjjxj",
        "cL_M4",
        "bnH8>",
        "hxjfM",
        "n,^ Q",
        "kbV'y",
        "Jqq8Y",
        "2)2.2S2Y2_2e2k2q2x2",
        "4=4`4",
        "5> rZ",
        "&fU)Q",
        "6(|lX",
        "?*R@R",
        "$Pw^C!Y",
        "7$7)797>7C7S7X7]7m7r7w7",
        "1QGE<",
        "qvnwO",
        "=^\\aqW#",
        "3.\\crypto\\pkcs12\\p12_utl.c",
        "RegOpenKeyTransactedW",
        "`)}I0",
        ",J4<W",
        "dN+GQ",
        "os Bq",
        "SummaryInformation",
        "VJxS'",
        "jZ+1_~",
        "YH{Pc",
        "7DJA}?",
        "d$D N",
        "d&k/#XG",
        "\"U-ta)",
        "Password did not match.",
        "G2I`a|",
        "I9`SE",
        "d2i_ASN1_SET",
        "ir$y[",
        "N_KRN'?",
        "89+?T",
        "\\;la}*",
        "w^^e]^",
        "dhSinglePass-cofactorDH-sha1kdf-scheme",
        "Am66A",
        "Z4}0UJf",
        "SrFcg",
        "w=EH]X|",
        ";l]Xm2",
        "o3<{$",
        "Agnitum Personal Firewall 1.0 (AV SKUs Only)",
        "Pc|Li",
        "=O=x=",
        "668G8",
        "4o]KYX",
        "B_~\":%",
        "3V>f=5",
        "3 3$3(3,303<3@3D3H3L3P3T3X3\\3`3d3h3l3x?|?",
        "}.c,}",
        "j:jjj",
        ".?AUIThreadProxy@Concurrency@@",
        "m_Oq*",
        "8X%@\"",
        "wNe4%",
        ">0_E+w",
        "unknown library",
        "0ok,Ty",
        "'Yi*2",
        "vi-VN",
        "A.JHb",
        "_I^yO",
        "U=<Oh",
        "Yy-.FT<",
        "@Bn^K",
        "VJ[w]",
        "l<I!\\3",
        ",RQ`\\",
        "YY[9}",
        "1.h\"-;dz{",
        ")(F%O+",
        "Dh27M",
        "Da%{^",
        "net start TracSrvWrapper",
        "c?A=HN",
        "D DF\\",
        "bldyG",
        "?$?,?4?<?D?L?T?d?l?t?|?",
        "1!prI",
        "#H`{.g",
        "9E\"g1n",
        "n&nro",
        "e)y^b",
        "@t1#0",
        "u!'Ch",
        "q?6AStfo",
        "_^[]3",
        "'xbB~",
        "api_ms_win_core_processthreads_l1_1_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "SMIME_read_ASN1",
        "X*DCm>",
        "Avsys\\install\\udinstaller.exe",
        "UmA25",
        "{\\flomajor\\f31508\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}{\\flomajor\\f31509\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}{\\flomajor\\f31511\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}",
        "'=9lc",
        "SetFileTime",
        "4$4)4/454;4@4F4L4R4W4]4c4i4n4t4z4",
        ";;YFP",
        "/o:;k",
        "KL2Ju",
        "g7rC2\\",
        "N&-_Y",
        ",NNWc",
        "7,7H7d7",
        "9,78n(j",
        "protectME",
        ":Z#%a",
        "MZPVD_k;",
        "jej}j",
        "u(L\\2",
        "d?=;.",
        "OP3pt'",
        "%[BO\"",
        "X>^'k",
        "Invalid LDAP URL",
        "NI/XS5",
        "<?>U>j>o>",
        "Failed to detect WIX_WDDM_DRIVER_PRESENT",
        "ECDHE-RSA-AES256-GCM-SHA384",
        "8G.;.",
        "{{{{{{x",
        "OnMainPrologue",
        ",y63A",
        "!1mDAXwYn",
        "tSj/P",
        "[GbSS5",
        "e.Ywx",
        "M[.Rx",
        "\\+H2r",
        "@y3.]H",
        "#nZ\"3",
        "[V)wpVa",
        "LdcseD",
        "%Tof'",
        ")CKju",
        "+DT Qr",
        "[#L8{",
        "ASN1_ITEM_EX_D2I",
        "Y3k%q",
        "type_id",
        "Gx[h!=}",
        "gEg5\\",
        "POLICY_SECTION",
        "kxT|!",
        "zDz@#C",
        "8Qe!uw",
        "A3YHM}",
        "Cv`wiL?B2",
        "7E8O8l8}8",
        "&(3bC",
        "Tv\"g;",
        ".6(2V",
        "a^ZK#Y",
        "s}qBT",
        "2 LtO/",
        "~:BwK",
        "IoXP<",
        ">E6E3",
        "Error %lu installing catalog file",
        "~JyRz",
        "naE5-",
        "rAM3%",
        "Deleting the certificate",
        "JC\\DN",
        "%O?W0",
        "\\zA8`",
        "B)L%Z.",
        "\\{a|P",
        "system",
        ".T*2l",
        "]|8wZ.",
        "enb*\\",
        "WrF_v",
        "Tkp,E",
        "DfjYd",
        "System",
        "h}yq+\"K",
        "wkq:w",
        "BIO_ZLIB_FLUSH",
        ":c:f|",
        "uH;!P",
        "5TJ,=",
        "zCPno",
        "9)949H9W9b9v9",
        "~0fxD",
        "1C%zf",
        "0/161B1P1g1n1z1",
        "rWM48",
        "DSO_global_lookup",
        "-z Kr$",
        "&*G+?",
        "%15[^:]:%[^",
        "O`LOs",
        " ?^nw",
        "HptOj",
        "1W@k,",
        " +-htg,",
        "O&O0O:'",
        "invalid encrypted key length",
        "pKqDg",
        "Calling GetCustomerNumberEx() failed.",
        ">4N%]Y",
        "Qh8Y#",
        "/^kp{",
        "TCP_NODELAY set",
        ".\\crypto\\ecdsa\\ecs_lib.c",
        "F2$`N!",
        "^RpQX",
        "&X+D~",
        "afM:L",
        "^6hhy",
        "L_FTN",
        "Lpa\"\"",
        "LtsDm",
        "yX+[]?<",
        "|ImSi ",
        "USWVV",
        "7*8F8",
        "F;t8(C",
        "U]G.o/C",
        "MOVNTPS",
        "949:9k9p9",
        "X`[UFqC-",
        ",})Pk",
        "=8%mpB=",
        "dxD{3<",
        "EXP-DHE-RSA-DES-CBC-SHA",
        ".mRNiN",
        ")4uu@",
        "Protocol \"%s\" not supported or disabled in libcurl",
        "J/AGD",
        "5f|Ki)",
        "6$6,646<6D6L6\\6d6t6|6",
        "BwpZ<",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{796E70BB-C20D-4956-99DA-72BD201846E8}",
        "Yu(hD|K",
        "9 999R9k9",
        "VpG8m",
        "@><8{",
        "#+&,\"",
        "768H8p8",
        "& 5W~",
        ">#.(.",
        "3_|Ff",
        "t\\ M.D",
        "7[a_u1",
        "%O.(evO_",
        "MfRd:",
        "KnDdIZ",
        "YE+GWv",
        "DisconnectedPolicy.xml was not extracted. There is nothing to copy.",
        "0}s G",
        "PCMPISTRI",
        "]AAtm",
        "directory not empty",
        "n{(nl#",
        "64bit",
        ",4mZH",
        "W?O9.v",
        "}hlw\\W[i",
        "A9X}:",
        "6:%{gN",
        "[&f&K=",
        "#CHLR",
        "CMG\"jk",
        ">K?hS",
        ":A`$u",
        ".[.yD",
        "x@x)a",
        "thh4h",
        "CLIENTTYPE_NOT_SET",
        "e>N8^W",
        "\\?S|O",
        "!ba/TxT",
        "WyxfV",
        "<x:~r ",
        "RO\\(<",
        ":.;J;O;",
        "!050f0l0s0",
        "Zlv19",
        "EgbE;",
        "H?JIP",
        "JK9#T|1",
        "IwGh`2t",
        "2yeB6N",
        ":I;[]",
        "FhK4v?",
        "h[=U]lz\\9e",
        "rsa_padding_mode",
        "A``$ ej,",
        "=Um4`h",
        "y~xzy",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid12071538 ",
        "UpdateVsconfigXML:  Could not set processes tag in vsconfig.xml, use default.",
        "FFN*g6",
        "?KGs+",
        "n},%}",
        "mu3Rn",
        "q/aK{",
        "{tI4E?",
        "H_c^)",
        "Directory not empty",
        "crlNumber",
        "wVsB5YI|z",
        "4bHBWf",
        "MSzkl8",
        "8gJLN",
        "8CN'$",
        "ArD)C*H",
        "=[wm3G/",
        "[VSDATA] Driver version: %s",
        "EtH| UkQ",
        "'TL$?k",
        "FPw_C",
        "]/a/e/",
        "=)}#-",
        "5 u&tn",
        "id-pda-dateOfBirth",
        "\"#/q|",
        "G,KQm",
        "jS4}E",
        "bm2Fd",
        "jijvj%",
        "t$TVS",
        "V^,\"P",
        "rRAI0",
        "0 0(0L0T0d0l0|0",
        "wDS?Cr",
        "J*;;t",
        "EJHT6",
        "B]p.T",
        "zID^9",
        ">\">>>Z>v>",
        "{,LTmZ",
        "3L$ #",
        "(>3G7",
        "L@xt{Nb",
        "2Xt>u",
        "pE]%:%D%P%X%^%h$l",
        "\\h^fG",
        "n#L:r",
        "jGhxE%",
        "S/rN-",
        ":D;q;",
        "+b7RW",
        "uhD+~",
        "pilotAttributeType",
        "sU0&?W",
        "3-IE6HtP4l;",
        "9>:R:^:",
        "\\m9CR",
        "M.!nU",
        "=e=\"<$z",
        ":6;>;N;y;",
        "po?I'",
        "Mlz8>#Sc!",
        "|$$;D$",
        "XcumpT",
        "3j7PGH",
        "3L$T3L$<3L$ ",
        "m7Gjo",
        "Q#Ua&@8",
        "~qGcCu",
        "}?pMM/-%",
        "[WINFW] Removing %S from windows firewall exclude list",
        ":-:<:D:[:",
        "6 6$6,6D6H6`6d6|6",
        "1Jq_UN",
        "QZk2n+;",
        "&A/e{",
        "9T:Z:",
        "r5*_5",
        "*c.dG",
        "iH`]b%",
        "545<5D5T5\\5d5l5t5|5",
        "u2Vj@hx",
        "sGb}1",
        "<*gKH@",
        "SYSTEM\\CurrentControlSet\\Services\\vsdatant",
        "7zGWg",
        "s}Y*!#",
        "gE*Oi",
        "wl]azW",
        ":gu{J",
        "vzY/{",
        "We9vy",
        ":B:t:",
        "Xt+Y'",
        "3T$<3T$(3T$,",
        "[p6*8",
        "!X%~zR",
        "J%ZEZ",
        "?Sk\"vaN",
        "g\"OKC",
        "6el{u",
        "6G]E&#",
        "B=i?-",
        "Timed out",
        "=V?h?",
        "9E9h9",
        "3#;r?",
        "O6Z]w",
        "2<4QF",
        "zP6.u8X=8",
        "OiS+l",
        "UV4D`e6",
        "RETR response: %03d",
        "3kO# G",
        "9\\$<t%WV",
        "StopWatchDog.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "2ROo_o",
        "H{2yL-",
        "NCi!@",
        "j2n,\\",
        "<+x\"B",
        "!F!H#@9^9#u",
        "C*7UL",
        "((N)#!",
        "8/ >?",
        "Q3fVY",
        "M[}mj",
        "+U-{#;",
        "easy handle already used in multi handle",
        "7,777O7^7r7",
        "Image header invalid",
        "ytNB-",
        ": :@:H:T:t:|:",
        "PdN=is",
        "=29:#",
        "nA8\";",
        "RafVY",
        "m\"+6{",
        "F41?/<",
        "kP+T+",
        "131W1k1",
        "2XO)L",
        "d,)A:",
        "M}\\((",
        "empty.xml",
        "!!1R$+",
        "UV^t}",
        "(F~$r",
        "(h9OH",
        "SSL: no alternative certificate subject name matches target host name '%s'",
        ".\\crypto\\pem\\pem_oth.c",
        "`%ETUd",
        "VX]:v",
        "!J_uB",
        "PPPPj",
        "xy~~x",
        "nWyH<",
        "U801+4DS@,",
        "prime:",
        "x^bhv]",
        "i5}\"c",
        "2_vxb",
        "t$$SS",
        "?Qz+w'",
        "Z0+MHaN",
        "Failed to get the Resource formatted field value.",
        ")}Gm]",
        "3)3^3",
        "o2.5i",
        "f7Fw-",
        "0]]Es",
        "T|odg$",
        "mcbf#",
        "GRoQm",
        "2&2R2`2j2p2",
        "ZkCy[K",
        "S@feF0u",
        "#`?1}",
        ">/?9?C?R?\\?",
        "c|ks&",
        "bj)T}",
        "WD0^-",
        "\\VI|a",
        "xr2$X",
        "MGVxZ}",
        "1iWqX",
        ">0MSi",
        "v4(8Z}",
        "XlYC$",
        "RI>%e",
        "d/]4e",
        ">f'S!{",
        "]LY0#",
        "vp2Ob",
        ";}+D)EQ",
        "FISUBR",
        "Empty reply from server",
        "xg_yB",
        "] 6W)",
        "QC+ B",
        "?b0/t",
        "{id4-",
        "3=Z<]",
        "=W<<:",
        "jDjhj",
        "XXXX~XC$aaaaaaaaaaaaaa",
        " zcXV0!s",
        "L=J'z",
        "kernel32.cpp",
        "Hut.W.",
        "X&/^6",
        "Kkk)_",
        "~=zG=d",
        "4,444D4L4T4\\4d4l4t4",
        "k0pFf",
        "K-163",
        "QOCIXW/",
        "$TZzU",
        "(51\"t",
        "6t]ek",
        "[{aq;",
        "e|.(H",
        "lDPP:M",
        "FUON#",
        "Y}uE(a;",
        "://DmQ'",
        "mEM2.%",
        "kKkXuu",
        "9 9,949<9L9P9\\9l9|9",
        "]P2\"PnE+K",
        "IOdlZoZ|y",
        "t2=UUU",
        "7c}.oI",
        "y/!gF",
        "\\h]#+",
        "\\[wCdH",
        "boost::filesystem::temp_directory_path",
        "d:UlS93",
        "y{^,I",
        "<N<U<y<",
        "6KT??5",
        ").}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "0=1o1",
        "e.i'*",
        "[VECTORED EXCEPTION] 0x%x flags=0x%x (%s)",
        "uIvqvrwX",
        "0Ko$h{",
        "Tb,gM",
        "E.5:(d",
        "BN_new",
        "4>il6$",
        "setCext-merchData",
        "bX@1a",
        "<q-b3",
        "yX8:F1",
        "`h4II%'",
        "7hv(w",
        "J=Ru$",
        "J,nG0",
        "Ea,KcY",
        "{U^OW",
        "ydP+B",
        "iX<B;",
        "&N1D^",
        "FD)Oj",
        "ZXGu\"",
        "6:>=`",
        "-<,>0{",
        "D06V8",
        "1th5'.",
        "'yl9='",
        "K[&\\{",
        "KGTjL4",
        "[/RgHi_",
        "CryptGetHashParam failed: %d",
        "QJW4G",
        "^[tb~",
        ")^wh=",
        "n$oco",
        "Ijf IX",
        "p_!oWR",
        "M*eQw",
        "l7cX0",
        "jAjxj\"",
        "t$pQWV",
        "=;T{by",
        "5c6s)",
        "@pz1c",
        "\\[[Q-",
        "1h7l7p7t7x7|7",
        "4a$L3",
        "oz^?:",
        "#/18J",
        "0.0J0f0",
        "-Yk!&",
        "_}Mdx",
        "<<<D<L<X<",
        "^@[P@?R",
        "Ut}24",
        "content type mismatch",
        "=Lb!M)'",
        "2Iia++\"",
        "@XM`B",
        "zA|jbn",
        "^|W2q",
        ",+67m",
        "8 8,8L8T8\\8h8",
        "?]N4)",
        "o_sq1",
        "str_field3",
        "z..`K?",
        "'RS R",
        "'udT|R",
        "\"!U,,",
        "0{2k5{9",
        "GM.MR",
        "-eS%d",
        "JEs~!",
        "jejsj",
        "S4C~4",
        "\\9NhJLj",
        "|^bWz",
        "byjW7",
        ".plVS",
        "E&`A!t",
        ";7* s\\",
        "i}bk ",
        "L$8Vj",
        "1$cWQ",
        "`E%\"6",
        "\\MailFrontier",
        "ac-auditEntity",
        "-5-=-E-M-U-u-}-",
        "D$$PP",
        "InitializeNoOfficeMode",
        "_Zuyr",
        "F4&QL",
        "Gz5DwE",
        "1VX(K6",
        "[f[^do",
        "\\SO7tsG",
        "MR)mP",
        "GetUninstallInfo() called",
        "IW=vj",
        "?3HYZ",
        "It#=VN",
        "S(De ",
        ",,t2sZ",
        "/~/_/d.p_",
        "missing parameters",
        "F@?Rb",
        "C5N5%",
        "@p^j(",
        "3U;z8",
        "|'ite",
        "BDav\\Install",
        "TXRhbi",
        "taj:V",
        "rhvQ^_Cm",
        "=+=\\=p=",
        "+,%Oe",
        "0Dlh_",
        "282C2M2d2",
        "2H3f3~3",
        "dnkgz",
        "Q/\\At",
        "4&?5NGr",
        "The requested document is not old enough",
        "6Q3Pe",
        "FileTimeToLocalFileTime",
        "d1<sK",
        "t$,SVQW",
        "84999",
        "0F1u1",
        "N\\Zk~",
        "B.]$h",
        "Fx3Dy:!y",
        "'.mTp^",
        "=5>S>",
        "fQIduc",
        "UpdateEnvironmentVars: UpdateEnvironmentVars Begin",
        "}y>il^",
        "Generator (uncompressed):",
        "O*8RVbp;",
        "?4?B?",
        "3849c26ae66252c6ed637c58c5bb8b13c7bfbd490a75330f4b47f16e441c31f7184e140e494214d273fc80900aedee52ead87597fa824b3e56e82e451d4c2b4d",
        " +'X*v",
        "8sIPY7,",
        "\\A}fof",
        "hNUYC~w",
        "Os=S\\!",
        "ao{jYK",
        "=mSJW",
        "7Q7d7",
        "x=]gfug",
        "cBooD",
        "Lr_|!0=",
        "Sv4y`",
        "*%!Rr&",
        "!`]#/.C",
        ";'n*a",
        "5g5n5s5",
        "\\$(GS",
        "4W4r4",
        ",c$<Z",
        "5`r,U&",
        "\\`0O$",
        ",eYKQD+WY",
        "lD)h&",
        "AV:[Ao",
        "F-6P(",
        "7GH6kc",
        ">1sO)",
        "_El*]",
        "k$a2i.~>@",
        "VIcNm",
        " qEC 9",
        "bR_*U",
        "!dx{:",
        "SSL certificate verification failed",
        "J7{MMt ",
        "SxY_W",
        "j~'x_",
        "*020i0p0",
        "AR*6m",
        "9aO;5",
        "3hEK2",
        "MXMtM",
        "])B&b\"",
        "RSa$y",
        "1*,qb",
        "9,:S:",
        "qmSFY",
        "i~Dj5",
        "*7,Hpa",
        "8f~0,",
        ">Aeik6",
        "c\\z|q",
        "qHHz@&",
        "9+9D9x9",
        "P2Ktq",
        "8D8k8r8|8",
        "J8 3D",
        "/i^*X",
        "@b}hr",
        "'BA|}9hZ",
        "%i%CLf",
        "t/hxz&",
        ",Jasm",
        "$p{#.",
        "SvuJb",
        "={n{m{k{j{g{e",
        "4$bY6",
        "b#u@ik",
        "cVc7Ua0",
        "C+,Qv",
        ",}z\"f",
        "a=4Cv",
        "T*51r",
        "757?7S7",
        "BITLIST",
        "S'Vhd",
        "F(_^3",
        "tqh@O",
        "9\"9Q9t9",
        "DisabledAdapters",
        "2wV.Xcp",
        ";n:Vu",
        "a0@IZ",
        "><xkf",
        "rU{:m0",
        "tUj\\Yf;",
        "<H<|*swP)",
        "191=1A1Z1a1",
        "4-4E4^4w4",
        "User32",
        "x\"ns7?",
        "252_2",
        "$+,q6",
        "null before block missing",
        "?2?N?j?",
        "Failed AdjustTokenPrivileges",
        "n,=|<",
        "3_qA{1",
        "4bt7*",
        "(TV;s",
        "0$1H1T1\\1t1",
        "<><f<",
        ":$:I:j:~:",
        "_]*=.f",
        "1wsHp",
        "Error: current MSXML version does not support xpath query.",
        "Yny%R",
        "oq3SL",
        "ASN1_SEQUENCE",
        "N#FL\\a",
        "`5di_",
        "!ZAs ",
        "[_T}@",
        "+LfY|'",
        "A#]+J",
        "]nV#n",
        "W~{6s",
        ";5<y<",
        "I8N6h",
        "hvqt$z",
        "3~Kr\\q^",
        "RxJ)T",
        "%u %u",
        "+Kl*+",
        ";!;);R;Y;p;",
        "l>X0E& ",
        "IQWbJt",
        ")8 kuf",
        "y EkA/",
        " delete[]",
        "C1oUc",
        "qho=g",
        ".!m7ou",
        "PKCS7_ENCRYPT",
        "St;U\\",
        "SmX`n",
        "1?6(L",
        ".?AV?$basic_istream@DU?$char_traits@D@std@@@std@@",
        "extension not found",
        "oXA_{",
        "!#u8`,",
        "fSluv",
        "documentVersion",
        "D$XPj",
        "KAP4`:pq",
        ";3!I*",
        "x-gzip",
        "N,7@Q",
        "signed ",
        " ~x%qaz7-",
        "*8$ 7",
        "1n#@p^",
        "sW$hf;",
        "8q\\cf",
        "O.iQS)c",
        "792}b",
        "F(<2G",
        ">'?A?",
        "9%~@j",
        "1pmX%}G",
        "removeFromWinFwExceptionList;",
        "u#8&_*",
        ".\\crypto\\ec\\ecp_mont.c",
        "001<1\\1",
        "75@OM`",
        "2|u8Y=",
        "Q@2TB",
        "RHYNn",
        "ICK7B",
        "Iht$G*",
        "D$H@P",
        "6<e#M",
        "L$DPy",
        "xRYC{u",
        "Header",
        "j(8@3A",
        "failed to get message to send to users when server reboots due to service failure.",
        " I@}x",
        "!!]TP",
        "i,$^yr",
        "zpD8>",
        "TS_CHECK_SIGNING_CERTS",
        "\"l&slO|",
        "b#F]@",
        "[R15D",
        "?YErEs",
        "~:2aT",
        "This windows belongs to our application, sending WM_QUIT to it",
        "4b0d592c9c070d8a65cd2e88b7f07c2ca71ba8da481cc52c6ce1c715e6e97818c9b48d13df49c873517d23d59085adb5dd20d6b52bd521ef2cdd5eb9246a3d8b",
        "PEM_SignFinal",
        "\\VQ{X",
        "gk 3_",
        "+:@L;",
        "Kx1c/(",
        "|}$s>",
        "B#&{'",
        "hc yh",
        "CommonAppDataFolder",
        "sGT:.C/",
        "[-&LMb#{'",
        ";6<E<h<",
        "1ODf-",
        "AWH[+9",
        "$1{=0",
        "p2a*.X",
        "zK<do",
        "r:K)j",
        "%s. Last error: %d",
        "5|D*J:",
        "%7eL/Wa",
        "*@j4_.",
        "GV1N11",
        "A0TD\"g",
        "`yzaQkA",
        "az\"2#",
        "j}jlj",
        "cT4r~",
        " of version ",
        "SU\\Ci\\",
        "ckLk:",
        "sJz\"b",
        ";oEI!7",
        "bC*Q`",
        ", .NET Framework",
        "uK|M#",
        "^I:{&n",
        "?jy<G",
        "yujBh",
        "LlT?rw$",
        "R L2&",
        "eigP:",
        "wfO}R",
        "FaultModule",
        "3\"3B3b3",
        "[VSDATA] Clearing orphaned primary client with pid = %x",
        "[0g0}0",
        "5`{8Q",
        "(vSW)`)[",
        "?\\?j?y?",
        ";S<X<b<l<",
        "3)373E3S3a3o3|3",
        "n4$JX",
        "j kcRx",
        "o?^FV",
        "7ncqu",
        "(F'e1",
        "XtPT3`XK",
        "SUVWh",
        "aQ<KJ",
        ":':h:",
        "9kE9+",
        ".?AV?$clone_impl@U?$error_info_injector@Vptree_bad_path@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "G<EyH\"",
        "OCT#S",
        "?t:Gyx",
        "wauk8p",
        "XoB*ax",
        "b6uT9",
        "b;&1kD<",
        "E_cRDIfIN",
        "8$84888H8L8P8T8X8`8x8|8",
        "Q(Rf ",
        "L:szX",
        "w4<q$",
        "pZ8Z\"X\"b",
        "PF>Fe",
        "MIME MHS",
        "}8rxx",
        "P}:\\tz",
        "|?q2?",
        "jCjoj%",
        "id-smime-alg-CMS3DESwrap",
        "}QD;*",
        "VZ|'=",
        ")p8'hk!s",
        "n98FJ",
        "GetThreadGroupAffinity",
        ":|tPQ",
        "\"030:0B0X0t0",
        "Li9r1",
        "/oMuK*O4",
        "D8IF!",
        "?'?L?s?",
        "@}jbU",
        ">H=G;",
        "failed to get Value for XmlFile: %ls",
        "D$HPUSW",
        "'_(3,",
        "1!n9;L4[",
        "xYX<Z",
        ":g1d@t",
        ")O4V@",
        "N890=",
        ";FD~@",
        "t(r4i",
        "+0C0I0O0r0",
        "a*Pdu",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "nt:4c",
        "iTb$oxku",
        ".&MLuI$T",
        "(uH?p",
        ".?AV?$ThreadProxyFactory@VUMSFreeThreadProxy@details@Concurrency@@@details@Concurrency@@",
        "WIX_DIR_COMMON_ALTSTARTUP",
        "$:iK\"E#G",
        "[x$L$L$\\$l$|$",
        "SWrX7c",
        "tQi[C",
        "}%GYA",
        "@!&ny",
        "G@6HO",
        "HiOH)",
        "3RCQq",
        "ASN1_GENERALSTRING",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 provision of this Agreement}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid16457937 ,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "__stdio_common_vsnprintf_s",
        "7lLX:",
        "vnaap64.cat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "HELO %s",
        ":'tJW",
        "CryptGenRandom",
        "c9e9$",
        "s<!A;",
        "oduct for an initial evaluation period. The license is valid only for the designated evaluation period and is designed to allow You to evaluate the Product during such period. In the event that You wish to enter into a longer-term license agreement with C",
        "#7Tt9*+cn*",
        "X6A'$e",
        "_00=`",
        "^k*ByEH",
        "1y2~2",
        "l58,}G",
        "727M7l7",
        "3qfz/",
        "<&<w<",
        "N(bW*",
        ")AQQg",
        "wa(cl",
        "Sy'E ",
        "6 6N6`6{6",
        "Obt2J",
        "RBQ!?",
        "zo/=l",
        "lsvzh/",
        "FOKa`[#`",
        "GetXStateFeaturesMask",
        "D<y|-U",
        "*gJ6jb",
        "UNSUPPORTED_OS",
        "juZ]?",
        "`nGx;Vk",
        "_JquC|",
        "\\$(Nf",
        "InstErr",
        "9QLmH",
        "oO,@pC",
        "jAjnj#",
        "TQ\\ne",
        "DALuL",
        "cmd /c \"",
        "RDdr&D",
        "K-\\r?]rK* q",
        "\"V8?E(",
        "qKrmE",
        "jQg-V",
        ")ty3tz-0",
        "Ph|T!",
        "ar-qa",
        "{OS-#",
        "8D*<8Ut7U",
        "o,8X%",
        ";);z;",
        "-56z)S",
        "t9VPUW",
        "DSA_print_fp",
        "v@~Mh",
        "`- SY",
        "6$7W8",
        "2{4?~",
        "g|ivK",
        "unable to decrypt CRL's signature",
        "0 0(0@0P0X0h0|0",
        "zr4z ",
        "$Ih2i",
        ")VuXZ",
        "|XKy3-",
        "VPWPh",
        "GetCurrentPackageId",
        "b_I4t!",
        "y9U},",
        "P)A$Y",
        "c0j]^m;Y",
        "NSRUo",
        "M@4OcS",
        "LBchy",
        "o4oToto",
        "-th 0H",
        "tCSVWU",
        "9b:h:",
        "id-smime-ct-authData",
        "7r#4s",
        "4 4(40484@4H4P4X4d4",
        "H$rWLj",
        "ZsUwj",
        "3L$ 1L$",
        "? ?4?<?P?X?l?t?",
        "B56^x\"#-%~",
        "\\l<eq+",
        ":'/W_~j",
        "Gu6oH",
        "C:su\"",
        "No child processes",
        "MessageBoxA",
        "SrSPSLSdSJSX)",
        "080D0L0l0",
        "UEO^a",
        "=Pfuu",
        "tkvJx\"",
        "cQ([P",
        "s)?ra",
        "4K4u4",
        "96<E<6=E=",
        "i;lr+>;",
        "=;=S=|=",
        "*r=/Q",
        "2B3_3",
        "@v5:1",
        "ps\" F",
        "ID'}3",
        "~_!9$",
        "4(434Q4a4n4{4",
        "4!4-4d4",
        "Diffie-Hellman based MAC",
        ";EYnP",
        "B%:\"j",
        "LE-(w",
        "z#vkJ",
        "BqFwQ6",
        "n92DU",
        "h`H(|sO?",
        "Failed to get modified date of file %ls.",
        "F:f6y",
        "rc=&DN",
        "tGYdMe",
        "MMFUninstallInfo",
        ">f}K%",
        "T$x3L$83L$ ",
        "%02u:%02u:%02u:%03u",
        "dd(c\"",
        "=`>q?",
        "F*Kz3",
        "u.hpE!",
        ",]^3D",
        "<?=X=",
        "lnp8,",
        "0H0'141",
        ";\\2^%i",
        "y6j.a",
        ";~:*j",
        "=4#s.Fv",
        "$Rg\\,P",
        "}j.wD",
        "~Z&wE6",
        "MkX8V",
        "W@oSM",
        "!-rxT",
        "4$4*40464<4B4H4N4T4Z4",
        "(<Pv3",
        "%AbmPm",
        "0T4i4n4",
        "9B:k:w:",
        "[Slh^",
        "SNY09",
        "^'^pA",
        "!3+'2",
        ":w&nK",
        "\\expshrtn\\noultrlspc\\dntblnsbdb\\nospaceforul\\formshade\\horzdoc\\dgmargin\\dghspace180\\dgvspace180\\dghorigin1800\\dgvorigin1080\\dghshow1\\dgvshow1",
        "7\\Df|",
        "8h,qR",
        "QQg1;*",
        "Ycg8V",
        "Opr6$nY",
        "Z8wbQK",
        "$h)Sd",
        "394A4",
        "/]_^[Y",
        "i~nywv",
        "t$4PV",
        "cz<V&",
        "vXeMu",
        "*uJq;V",
        "v_l/0",
        "VDI#a",
        "j.Yf;",
        "EC_POINT_is_at_infinity",
        "-sv\\s",
        "3/3D3U3h3:4s4",
        "`hDVJ",
        "stoi argument out of range",
        "E  kkTi",
        "TS_CHECK_POLICY",
        "Service %s is stopped.",
        "D$(;D$,",
        "G;~x|",
        "0F?-\"",
        "T~^0_@",
        "+5#q-C",
        "Q9Cd;",
        "o%-)'",
        "/AQGc",
        "76r)~",
        "u?5TJQd",
        "C\\rN#",
        "failed to write firewall rule description to custom action data",
        "med{*",
        "3( pO",
        "3D3`3d3|3",
        ">!Zkh",
        "Jb+Go",
        "v.A|\"",
        "u#9@y",
        "^aWqB",
        "A;Uf|",
        "DW5-{",
        "],lTw",
        "[xTsL",
        "tkmIq",
        ";GBbF",
        "DefPolExtract ended",
        "/h-$I",
        "D;:w>wHwNwTwVw\\w^w",
        ".F\\K}",
        "SCRemoveAfter.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "g?pbBJ",
        "b<DS(/[`",
        "SHGetFolderPathW",
        "3P0gU",
        "q0UgC",
        "YOeEw ",
        "%4(b#",
        "mW/Lf",
        "Couldn't get response value",
        "L^5>|",
        "l.iC~",
        "T5]y#;",
        "zACvC",
        "rWlNs",
        "3(3C3b3",
        "gJ)wi9",
        "%Iu;\\",
        "cp#.e",
        "policy language already defined",
        "=(>G>",
        ">$>0><>H>T>`>l>x>",
        "RYWQ1O",
        "j}jsj'",
        "`1?~)",
        ")i*T%",
        "a5E!V",
        "`*yj\\",
        "SP\"^P",
        ")Dq&'I",
        "*f[!fDs#",
        "Tn%,rI",
        "FDECSTP",
        "zGrr4N",
        "EE<GT3",
        "rmD;}",
        "J/V(^t",
        "EvA^Z",
        "R8N_P",
        "i$a.g",
        "t0?@_",
        "K@!x{1",
        "9.9[9h9",
        "CH%4`",
        "%u src=%s trg=%s",
        "EHBCG",
        "-@7za",
        "MSI_ERROR",
        "uW-7l",
        "UninstallCreatedItems:  Removing registry key HKLM\\Software\\Zone Labs\\MiniLog",
        "Remembering we are in dir \"%s\"",
        "3M3T3l3",
        "E~kvb",
        "'!3n7",
        "hQ?[I",
        "#N:N(;",
        "^~(1m",
        "LWwrK",
        "%dO.E",
        "L$h3L$ 3L$",
        "T$H#L$H#",
        "pd/+Y",
        "\"xF6%N",
        "2m`MG",
        "C,nf;",
        "rloq+",
        "/y`4_",
        "policyIdentifier",
        "McAfee Internet Security 6.0 Internet Security (All SKUs)",
        "1pw&Ru",
        "555]5",
        "]2{NX",
        ">p:sK",
        "6&6W6b6v6",
        "d#4hafy",
        ")X;#=N",
        "=%X%`",
        "4`BCc",
        "if=% i",
        "Can't concat strings",
        "FTP: unknown 227 response format",
        "7'7'I.h",
        "\" qXYX",
        "DO_I2V_NAME_CONSTRAINTS",
        "$,!!!",
        "8#8i?q?",
        "AllocateAndInitializeSid Error %u",
        "VSDATA.dll",
        "~)FN[",
        "s?}<|",
        "Erir?Z",
        ";B<g<",
        "de-LI",
        "9G@t7",
        "1#2N2y2",
        "D>B<)",
        "#hNKK",
        "InstHelper.exe: RemoveSD",
        "7*7G7M7g7m7y7",
        "gOY&]",
        "GG<e)",
        "u|Bfh",
        "0Taf#",
        "PfX0-",
        ">L>|>",
        "5+6H6N6z6",
        "7!8D8_8}8",
        "4R=6x",
        "L-&TJo",
        "h!Hy6[l~+",
        "vcruntime140d.dll",
        "MAXPD",
        "}~P:>",
        "2>3H8P#Zsf",
        "H<?kk&g",
        "|dMhI",
        "5C6K6e6m6",
        "X_!c*",
        "dqo2V",
        "C98.U",
        "3!313A3Q3a3",
        "vooiC0",
        "FTeDe",
        "%s: %s (%s),",
        "RO4[N",
        "tXr2T",
        "KCm's",
        ".$_aN6:ZN",
        "kkc%e",
        "m}6@kF",
        "You must uninstall Checkpoint Endpoint Security before you can install Check Point Endpoint Security VPN.",
        "OnInstallDriverPrepare",
        "b^XA<",
        "b\\\\@L",
        "Checking if VNA already exists...",
        "1DPw[",
        "5!515Q5a5",
        "oYtF{o~",
        "S&Xkp",
        "D#AUL",
        "T)URD",
        " 0x8b",
        "1(F[{",
        "B))XBc",
        "6yV5o",
        "<(<H<T<t<|<",
        "yZ>8u",
        "qO1b1",
        "&*PM\\X",
        "%<cv$",
        "t$<j0P",
        "\\lsdunhideused1 \\lsdlocked0 List Bullet;\\lsdunhideused1 \\lsdlocked0 List Number;\\lsdunhideused1 \\lsdlocked0 List 2;\\lsdunhideused1 \\lsdlocked0 List 3;\\lsdunhideused1 \\lsdlocked0 List 4;\\lsdunhideused1 \\lsdlocked0 List 5;",
        "n!$6Sx1",
        "r<'W&`",
        "MZOsi=",
        "8@8m8",
        "52c3+",
        "'<rh(T",
        "yUESif",
        ":%?aDh6",
        "D$lPW",
        "*yJW-",
        "|?bZkh",
        "3>R5[#.",
        "zazizqzyz",
        "8?8R8\\8j8r8}8",
        ";O;l;",
        "%s finished with: %d",
        "kWwOx",
        "W.V,G",
        "585D5d5l5t5|5",
        "VScMstbn",
        "li>XDf",
        "D\"NdD",
        "@[hLg",
        "Qtm/q",
        "%PPc6",
        "VSTORFeature_CLR40",
        "GENERATE_PARAMETERS",
        "tE9od|@",
        "i:OGw",
        "BU-$8",
        "@%1>_",
        "2JRLd",
        "!D>l!",
        "Z<5s$",
        "No backup data to save",
        "#sVKr",
        "Avsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "7-j)J",
        "#}|V ",
        "4<4`4",
        "9wkTc)",
        "-cqqM",
        "sgI0\\",
        "9yk@G",
        "T60=68",
        "707P7a7",
        "7.7Q7l7",
        "eJ?VXPnf",
        "3GrHp",
        "YWy3E'",
        "\"0LkR^",
        "@%^IP",
        "9F:U:s:",
        "_gH>K:",
        "\"Jn $az",
        "curl_cli.exe -K unregConf.txt -o NUL -k --retry 5",
        "2F2[2b2",
        "FE*z~We=",
        "fD|_=Z5",
        "4L:lCB",
        ":4:_:",
        "~Rr*>",
        "r.d@|",
        "(>nH&p",
        "RDTx!",
        "}r%/.fv",
        "ug#;_D",
        "E.(5o\"$YIRl%",
        "vk0as2",
        "+[*KB",
        "h[nhs",
        "{$t]a",
        "JnK]N]]]i]s]",
        "^9qlQ",
        "sDtda",
        "ro-ro",
        "Ok#N ",
        "]T*:]0#",
        "\\zonelabs\\zlsc.dll",
        "^d@@S",
        "q!ccy",
        " 3m(O",
        "1kc9q0",
        "DO_DH_PRINT",
        " (x86)",
        "4}/|s",
        "<P=`=",
        "Wmw)=U",
        "r0fh]",
        "jtHee",
        "jn?qku",
        "L3,ppy;y",
        "ewe~g",
        "E9:9=",
        "]\"`y6Yq&",
        "Setting DNS\\Parameters\\TcpReceivePacketSize=0xFF00 and restarting DNS",
        "*v|Wp",
        "sDy|+",
        "=+=B=I=h=",
        "989K9",
        "lbr3C",
        "B7AZ7",
        "^,pyV",
        "WjHT@",
        "8M}EZ",
        ";Q)\"9",
        "OhAth",
        "l3=L2%wv",
        "NJv?`La",
        "b&gus",
        ">M =A4{",
        "9m*Y$",
        "Q4=cS",
        "+mO&T",
        "T\\bZB",
        "%ZP0^PV0;}7",
        "OCTWRAP",
        "G+3qC",
        "Vc^n7",
        "M Y=+}",
        "4^4d4",
        "9k8`D",
        "gy(F4",
        "k\\_B7",
        ";2<D<l<s<}<",
        "E(9o_",
        "4R%oO",
        "$1P73",
        "TLNA!",
        "0#1X1q1",
        "?QG9(",
        "M]9uEE+J",
        "=q.^s",
        "Qqf\"^`",
        "4C06A4171B691FC4DAFE32AF747D80BB",
        "3B3o3",
        "M#zu&!",
        "v V:+",
        "HkN@q",
        "F%T%^%d%n%",
        "`TKV<Bc",
        "Sx1_m",
        "+UquGQU",
        "'ZOv(\\",
        "kECDHE",
        "n0/=h|C}",
        "c$L)6",
        "@rL/.s",
        "%0nV4",
        "InitializeClientSubType",
        "1]1j1",
        "e$$t'\\NQ",
        " ISZ}T",
        "+d*7s",
        "EIPw1{",
        ".I!$%",
        "IDEA-CFB",
        "_KfE&",
        "B=LL!",
        "I#c-A",
        " KvXB",
        "rv'QL",
        "^Wd34",
        "http://ocsp.digicert.com0O",
        "u6]`+",
        "E'E8EFEMESEm",
        "' tZX",
        "^45*E",
        "3#333W3w3",
        "Bvic*v",
        "Gs8u,",
        "t$0VW",
        "d^j(nyk",
        "CE&Ib",
        "E?Gn?",
        "QZu1^[",
        "L.N$:",
        "]Z,0W",
        "ApsVA",
        "D$\\SV",
        "N/j5i",
        "L5E\"oZ",
        "4[=Kqh",
        "zvAYKII",
        "?#TZc",
        "o]I.w(",
        "gE #K^d",
        "y>>>O",
        "2J|t,",
        "SOFTWARE\\Zone Labs\\zonealarm",
        "Kfa_H",
        "wK|JR7",
        "]1k^vp}",
        "NTLM send, close instead of sending %I64d bytes",
        "secp112r1",
        "{R#n<X)~)",
        "bf2c}",
        "WU%VjS",
        "TU6C@",
        "%MNjFVAl",
        "RXzGD",
        "=/9>A",
        "dh_paramgen_prime_len",
        "\"NxQM",
        "s86wT",
        "B{35i",
        "Gz\"TeN",
        "929C9I9O9V9_9d9j9r9w9}9",
        "7r|Og(%",
        "QXKL>",
        "gYQ7>",
        "@+KO`",
        "V$}=HI",
        "n*~G~M",
        ">(?@?",
        "9\"929R9c9r9",
        "es-gt",
        "7UX]V",
        "}`W%PO",
        "cJ>Mt",
        "~e-Kt2",
        "BBx]sfq",
        "-uL_]",
        "tracCPInfo.cmd.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "WUL^7.",
        "2Y2f2",
        "The latest MSI log file is: %s",
        "jAjwj!",
        "iAgJj",
        "&kshIZH",
        "8$808<8H8T8`8l8x8",
        "Fe/^Y",
        "8jZZf;",
        "D$hj@P",
        ".KC=3Nb",
        "failed to open %s",
        "FWFresh:  setProductMode - default is Integrity (Check Point Network Protection) (7)",
        "Ox#>f",
        "XUl|&",
        "`'U;i",
        "Cf6(m",
        "OpenMutexA",
        "<$=0=p=|=",
        "%1mMT%I",
        "#ZoeA",
        "{NdXUJ",
        "me\\I&",
        "X%jwi",
        "{Jydqh@",
        "ASN1_item_d2i_fp",
        "q.o& ",
        "\"P?:lH",
        "By}X)Qm",
        "IQt&_",
        "ok&Dn",
        "hUI:, ",
        "4?\"e/",
        "Vea%9",
        "f,[QB",
        "T>KQ]xD>",
        "? FbQ!",
        "ForceRebootDialog:  ",
        "YYt$h$",
        "v&_n=",
        "8g8l8{8",
        "=$=,=4=<=D=L=T=\\=d=l=|=",
        "6d7h7l7p7t7x7|7",
        "~5*(~",
        "M4&#[>C",
        "Qjr]!",
        "*QXi]N6",
        "^4mHFGT?p&E",
        "R8(m&",
        "494M4",
        "zRF\"=",
        "8L/$q=y",
        "i{b<:",
        "F)-2@",
        "XpFz.",
        "SizeofResource",
        "AAVFJV",
        "1d3L76:",
        "W6r%JP",
        "xM\\;9x",
        "n6^ZVMU)k",
        ",Ac&l",
        "array",
        "Jp^i`",
        "g:An/",
        "6@C@q",
        ",#^w@'",
        "Q}Th!%",
        "d&0k.^",
        "\\;s$64",
        "!}Hz9",
        "k%$6S",
        "RH;b0",
        "yXFYX",
        "d.certificate",
        "7 W3zV",
        "7G8L8l8",
        " 7zLW",
        "@e-eMjr",
        "F!J9vx",
        "Vf!#w|",
        "GpJ=+D",
        "d&[l=",
        "f99t7",
        "Vh(1&",
        "AllowProcessStopService",
        "L*uKz;",
        "!]SDm8WA",
        "3&'RG",
        "w jVMe",
        "F0X0p0~0",
        "P;nGE]",
        "5D5t5",
        "/=Y3<L",
        "HyMr * O",
        "StartProtection.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "umrmZ",
        "e/ND\"k.",
        "g,3$3",
        "dWV~5y",
        "4#4'4+4/43474)575",
        "Be|[-\"B",
        "F=\"FC",
        "unable to find certificate",
        "class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > __thiscall boost::property_tree::string_path<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct boost::property_tree::id_translator<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::reduce(void)",
        "9=pirL",
        "qLrO?",
        "h$Y'!a",
        ")/IGg;0",
        "dhSinglePass-stdDH-sha256kdf-scheme",
        "5.5Q5y5",
        "Check Point Software Technologies Ltd.",
        "v+L4Hxz",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "|8[R6\\",
        "Done waiting for AB Service to stop",
        "GXrs%",
        "(mW6F",
        ",_h^aS",
        "\\P7sX",
        "/GmJZ",
        "Twoy%",
        "+GAt>4",
        "&_uQh",
        "%s (unsupported)",
        "wrOXi`",
        "&S\")YE",
        "HU {7",
        "6|b?r",
        "Select failed",
        " SLqJ",
        "$u'Mm",
        ";Q5_p",
        "/Sz^o4",
        "A[L>Y",
        "tyJ}/",
        "<$<8<L<`<z<",
        "c(xor",
        "QYv=\\\"#",
        "3L$L3",
        "0 0$0(0,000<0@0P0T0X0\\0`0d0h0l0p0t0x0|0",
        "4<m8i",
        "#ew'i",
        "sd_uninstall.bat",
        "xVv^vm",
        ".M;)qt",
        "veU(#[",
        "Xm=l\"x",
        "o_25>",
        "K@ZYBGZ",
        "Protocol option is unsupported",
        "t$ hd",
        "Iauv^",
        "Ln\"IB",
        "aYiY{Y",
        ",nlV%v",
        "3P)8$",
        ",\"2?h^",
        "tT#Y*",
        "52Ar7",
        "}wn{1",
        "\"5(2t",
        "4f5t5P8p8",
        "<6<R<`<p<v<",
        "=C=F>W>w>",
        "M$j\"^QRRRRR",
        "8w<Sj",
        ":L;6<j<r<",
        "6#7K7",
        "E IAm",
        "n;AM:j",
        "f%5(L",
        "anG=0",
        "RY?1(",
        "Dl)*x",
        "bn8tm'-",
        "ar-sy",
        "`-CN8",
        "I)f+J",
        "WZ3UJa",
        "ForceRemove",
        "Xo2/vC",
        "CreateFileMappingA",
        "sj#*l/",
        "failed to get command line to run on service failure.",
        "%AMaF",
        "mo6}h",
        "glD*_E",
        "SUBSS",
        "GR9G{1*",
        "YUN_-",
        "F}q=3",
        "m, 1#",
        "7_S&6#",
        "C q'O",
        "@DFWh",
        "7}eAt",
        "?J?q?",
        "ecp_nistz256_mult_precompute",
        "}U7pR",
        "[R:.+:",
        "zpB&=",
        "Saturday",
        "JZ6y[",
        "DNS\\Parameters\\TcpReceivePacketSize already has the correct value",
        "%pJG_",
        "qBX1<P,A",
        "50r0{1",
        "5C)d(",
        "_.!DgU?",
        "7@_GZ",
        "oT$`1",
        "WinHttpOpen",
        "&J!4w",
        "2\"2q2{2",
        "GBge/",
        "aA x9",
        "zrn9{",
        "~Mv\\YR",
        "0I2/;",
        "M bV54",
        "|,D5^",
        ".wM=U",
        "K*<(0;",
        "e`d0f",
        "%<%L%\\-|",
        "179\"LP_",
        ")Fl|v",
        "SVj83",
        "paC;>",
        "rant~{/",
        "U.iFn",
        "efNvF",
        "qkO_U",
        "jPCDKo",
        "149IP",
        "kL3Yw",
        "OpenProcess",
        "O11EaX",
        "mD4u]",
        "Jh\"LN",
        ")ln1gy",
        "Yo(bf",
        "\"u 1c",
        "lcKKNF",
        "system32\\drivers\\vsconfig.xml",
        "oeS'n",
        "swedish-finland",
        "-lGSX",
        "Failed to get remove folder component.",
        "\"YUp$",
        "8N[sp",
        "onBasis",
        ">Dx/s",
        "%9f5A",
        "-r\"PH",
        "X(.88",
        "j5l]T",
        ";~FC$",
        "444X4k4}4",
        "gQ(0s",
        "enabled",
        "0+1c1",
        "{WI^e",
        "Z3^8=Z",
        "o%}v>",
        ".?AVfilesystem_error@filesystem@boost@@",
        "t$ h:",
        ")( )L",
        "t$(PV",
        "G+C}D",
        "#v@.F,",
        "cpDigestInit",
        "HTQ,+(",
        "TS_RESP_SIGN",
        "+kU]RqC",
        "-4/(j",
        "]Vtoh",
        "1hqOz",
        "O.F.+a",
        "bad object header",
        "jj@0HK4",
        "(|EaH",
        "3$4(4,404",
        "ye67z",
        "VjR0-",
        "%>NNJH",
        "d=B?f2s",
        "QueryServiceConfig2A",
        "$'dkDk",
        "pvk too short",
        "4[I*:",
        "Lu0Wz8",
        "hlx}eW",
        "KjH!I}",
        "25\"UQ",
        ">P/Lv",
        "<.mz=",
        "S\\M>Y",
        "1)U#I",
        "Bj5 3",
        "2u^WBO*",
        "ec_GFp_nist_field_mul",
        "ESS_CERT_ID_NEW_INIT",
        "4SUmO",
        "7T=b=r={=",
        "&HH=Z",
        "E>'EM",
        "<5=O=T=",
        "*=g1^!",
        "vg2RmboD",
        "EPS_ICA.config.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "A AHAd",
        "A0!<5",
        ")0B0G0P0U1",
        "404W4z4",
        ".opsO",
        "(Q@DAn",
        "&'$-#",
        "eoLKY",
        "-&.gs ",
        "{VbD+L",
        ":(:,:D:T:X:h:l:|:",
        "= JA<",
        "qu;*s",
        "NpOu:",
        "kC8qU",
        "MSJ.P",
        "stopCiscoVPN",
        "T0[W ",
        "`mae&",
        "invalid random_device value",
        "415V5`5g5",
        "FaM14",
        "].x;!a",
        "{/I*e",
        "\\f1\\fs20\\insrsid14122115 f}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid4272055  America{\\*\\xmlclose}{\\*\\xmlclose} }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7943135 and/}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid4272055 ",
        "4.5:5B5d5",
        "vNs@f",
        "O$-h:",
        "$SK'b",
        ";{J,\"K",
        "GOST 28147-89 MAC",
        "'L%\"$",
        "*V(0hC]",
        "gn#66",
        "Feature",
        "ZK6W8aOMds?K",
        "9[j[(JcP",
        "stopVsmon",
        "vicsI",
        "char16_t",
        "xGHO=`H\\XBpR",
        "vX%0e",
        "vV57:",
        "Characteristics",
        "TS_RESP_set_status_info",
        "m_P4(M",
        "$U!ojQ",
        "Tqipri",
        "8co~T",
        "h{H{8s^",
        "73$i7",
        "203b3j4!565",
        "USERPASSWORD",
        "\\j!N4",
        "g$}T#",
        ";?{|^h6D$",
        "i3|?`Q",
        "z\\cx$",
        "P3e3j3",
        "C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/lib/engines",
        ";+e1u",
        "7:8r8",
        " LzsPZ",
        "sL R_",
        "}!JINq",
        "V~n\\h",
        "s@/XfTy",
        "2u5eY",
        ";+;9;P;W;c;p;",
        ">p\"R.nO",
        "51$*81",
        "8&qs1",
        "\\|(O~",
        "GJJ)%",
        "T3pP1&",
        "}|%JAS",
        ")N]W8",
        "24=4_4j4",
        "B&eY*",
        "-kVhYU",
        "^bT-r",
        ":loD:",
        "N=_>T",
        "LY|hJ",
        "!>}E7",
        "<!<r<",
        "\"7MHmvB",
        "_]^[3",
        "z8}#F!l",
        "Lz<0\"",
        "l {do",
        "5'8eA",
        "nu?p(\\",
        "\"6VqA",
        "uCPVj",
        "'\"'X'b'",
        "UhHr],",
        "k%iuW2",
        "W\"AT.",
        "j^Xf9E",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  362",
        "iVKh&",
        "qbzrB!@av}=p",
        "D8x/t",
        "9E:M:f;u;",
        "certificates",
        "RLY*5C0",
        "TVgh1",
        "Sof{O",
        "^CZ>|",
        "{I#q;",
        "8A8H8u8",
        "7W7n7",
        "=:=q=",
        ">V?e?|?",
        "WS9l$Lt",
        "ypgq0",
        "3]3j3u3",
        "&a^!{",
        "WHPh@",
        "OnBeginExec custom action end.",
        "m$1DDX_",
        ".\\crypto\\x509\\x509_req.c",
        "vQ/[d",
        "UnVtrd",
        "lW{=~",
        "!x#6DpX",
        "4$6h:",
        "#H\\fI",
        "8rH/'4",
        "=,=Y=",
        "&y]D>",
        "6A)LJ",
        "gie\"k",
        "S0SpS",
        "Ml.\\g",
        "}\\Imh",
        "5-5A5U5i5}5",
        "K9WQJ",
        "6<h(e",
        "\\%\\dz",
        "j:{v)",
        "b~Pm=",
        "P.LAG",
        "?)?;?B?I?",
        "wrong cipher returned",
        "3I(6y",
        "!%cm}~3s",
        "osAR7Pi",
        ">4nY]",
        "\"g1B*",
        "bO')`",
        "t1UVW",
        "l><Hl",
        "2000.",
        "u'0IhMi",
        "TZ'~kW",
        "CONNECT_ONLY is required!",
        "(@pILP]",
        "Enterprise 2015 LTSB N Evaluation",
        "T@PIn",
        "u/jAXj",
        "='Qf%",
        "'-l0 ",
        "=n=3C",
        ">6&n,",
        "G+|{e%",
        "<><M<_<r<",
        "d8' ,",
        "3\\$P3",
        "?0?8?@?L?l?t?",
        "`<a5+",
        "a ZAD",
        "7Ntl\"r",
        "<!<A<Q<a<",
        "htMUy",
        "|D3b>",
        "ssl3_get_client_key_exchange",
        "cY7.P#g,^",
        "{smg_",
        "~1ko[",
        "g5ho`",
        "rKBOY",
        "ab5:'",
        "?<?D?P?p?|?",
        "{_3W,",
        ">#Z&*",
        "2F2X2",
        "ds!rR",
        ">4:75",
        "TQ^wU",
        "0oN4 ",
        "4(nau",
        "?d.Iz",
        "%$khY",
        "pquwI",
        "4!5:5O5|5",
        "failed to get Verify Path for XmlConfig: %ls",
        "2!3;3",
        "1`2o2",
        "4+usP",
        ";c>+Z",
        "ASN1_mbstring_ncopy",
        "STLS not supported.",
        "eT)fc@",
        "EklOD",
        "PVSQSWV",
        "0W.:OY",
        "AllocateAndInitializeSid (Admin) error %u",
        "D}aoW",
        "9pq??",
        ".e<i~",
        "6]ndQ",
        ",O7~U'E",
        "gf9 Z",
        ">0>p>",
        "InitializeSListHead",
        "G(^>U;",
        "J>)ZG",
        "\"\\7`l",
        "`SVWj",
        "XGj\\i",
        "a]w]G",
        "@50WmTK",
        "fR9+6",
        "_0dl.",
        "|1y`X0",
        "2w#dw",
        "9nk[/",
        "x509Crl",
        "jIYf;",
        "W3Ddo",
        ">1>Z>",
        "242v2",
        "}*S:P",
        "T{0~=",
        "`]GP{",
        "4604E150-CB91-4B18-B933-D52005938042",
        "Qv)X0",
        "*i<W[",
        "gJ{SU",
        "6$6P6U6d6",
        "L;)9j",
        "1tZ{<",
        "G|tT5",
        "'^e`;",
        "^@R3Y",
        "xc}ti",
        ")_~6K&",
        "Vrt,v",
        "7I^rJ?FK",
        "HPpVe5",
        "RSvf[",
        "6$6(6@6D6H6\\6`6d6|6",
        "D$4hL",
        ":02@t",
        "CCxYn",
        "1*#5s",
        "3*3E3Y3m3",
        "fCG`}",
        "xHA2hY",
        "d6Se%j",
        "g<N'4n",
        "boost::filesystem::directory_iterator::operator++",
        "PBES2",
        "}`eW\\+",
        "_#_cj",
        "Failed to copy %s to %s. Error: %s",
        "(Z0% ",
        "lFhpQ}W",
        "0 0<0X0t0",
        ":KR*P",
        "LiQ|(",
        ">lD?f",
        "-c2u7R",
        "mQ}OGx",
        ")QZ^&1",
        "7Ti.qA`'",
        "ucV$%",
        "VWj.U",
        "7%edb",
        "&+E\"x",
        "329753F1DE5EF4F4B9821B6451C34764",
        "/kwgQKb",
        "hX-VY",
        "G:6$8q8",
        "\\%@^t",
        ".z)QI",
        "Eh5a=H>",
        "f~vwb",
        "Dv,20",
        "{pRx2",
        "->$Qr",
        "6RVzc",
        "GK76t",
        ":rzv\"oX",
        "G]3Te",
        "Ag#9[",
        "L<Su.h",
        "setext-miAuth",
        "5+626@6L6Z6",
        "=&>+>=>[>o>u>\"?'?,?C?",
        "L]4:D",
        "^L*)6",
        "J_KD%",
        "jurisdictionCountryName",
        "DecryptDataAccordingToUser failed. can't use key",
        "d?D{d",
        "nk{#'",
        "e('7T",
        "<f>x>P?",
        "keyCertSign",
        "57,Ng",
        "<E<a<",
        "z02s/R",
        "~tO&*\\",
        "GetEnvironmentVariableW",
        "I'^87",
        "ac-targeting",
        "6S.KF",
        "mJ5.To`s",
        "_A?+`",
        "1NJ0t",
        "6fP`1",
        "W}P;d",
        "0kwfJ",
        "^rPl4",
        ".?AV?$buffer@I@detail@v8@fmt@@",
        "sh-eR",
        "CloseServiceHandle",
        "<I=_=",
        "G{75$'J^3",
        "X\"f}@",
        "4,5?6",
        "e#xm1+",
        "_/vg,|",
        "Vh&Xq+*P",
        "o.Y6;",
        "!P]j]h!",
        "f=(5w",
        "Failed to SetPWInstall",
        ";Z1eGp",
        "Qes\\)",
        "h)0@E",
        "@E9m :dv",
        "@,cX_c",
        "B~`~0~f~<~^~,}",
        "@*2Li",
        ":yc+-}",
        "d1>*v0{",
        "E;l$0|",
        "z3eE_4q",
        "ES(xk",
        "3WOQ;",
        "BJ$BL+",
        "CyF|J",
        "2+y_{",
        "=7=S=o=",
        "\"qXJq",
        "This is a downgrade.  %s to %s",
        "22J&$",
        "DHE-DSS-AES128-GCM-SHA256",
        "liql\\b:",
        "CMS_SignerInfo",
        "p#Excn",
        "1+1>1b1",
        "[9B]S",
        "=`q:w",
        "file name is: %s ",
        "2F\"'=B",
        "[W]l$",
        "fNfGD",
        "q,W[O",
        "20igu",
        "*#&P3",
        "a)/a$",
        "/@d4q",
        "#jKD'0",
        "jdT86",
        "unsupported version",
        "<2aLr",
        "<4<<<H<h<p<x<",
        "221122171738Z0+",
        "(r_>H",
        "8&979V9]9",
        "G5fvJ",
        "BB*N.d",
        "3@4S4",
        "de,NC",
        "rPAu6",
        "FTE]$",
        "+tz'K",
        "[LICENSING] Using retail key instead of subscription key",
        "|/ruD0",
        "IY/AQ&",
        "b8h>.",
        "5EBQS4GN",
        "'ES/A!",
        "<H=l=",
        "bafBG",
        "SFENCE",
        "r`Z$P",
        "j$Yf9",
        "UpdateVsconfigXML:  Updated the vsconfig.xml with processes tag.",
        "FeatureIMSecurity:  imsinstall.dll is older than 4.5.0.0",
        "Set reboot flag FALSE",
        "jHFs%",
        "[/2dt",
        "-q$[v",
        "4~t^L",
        "'v|`j",
        "dihf|1",
        "h.g.S",
        "?n;x}",
        "wnEY[[",
        "recipientinfo",
        "(OTPRERP",
        " %s=\"%s\"",
        "=&Y5]",
        "R8TSr",
        "O|&O;",
        "L|Ap[5QYMU|",
        "T$,3l$$",
        "`vtordisp{",
        "131b1",
        "9*gmm7",
        "ANDNPS",
        "<\\q2?\"",
        "^4Gfx<",
        "FW\\|e",
        "DATATYPE_MISALIGNMENT",
        "camellia-192-cbc",
        "Zh<YT)",
        ".?AVVirtualProcessorRoot@details@Concurrency@@",
        "GetAce",
        "KFh#A",
        "(&78I",
        "F4WvO",
        "IsPEFileValidEx2: %s not found",
        "unsupported field",
        ")L!u=jv",
        "char32_t",
        "`VC`&",
        ":4:W:",
        "PADDSB",
        "p'ki}",
        "@'@8M",
        "@R>z-}5RVx=",
        "sno;l",
        "(<DFl",
        ".!.1/M",
        "'GIb\"",
        "Qn3cC",
        "B6s!7}mr\"",
        "D$0VP",
        "Failed to allocate memory for record string",
        "3Th7Z",
        "RMix{W",
        " FG*I",
        "Hjg{u",
        "r\"\"''r",
        "IZCJ_5",
        "Failed to open SC manager. error %d",
        "OM*$JG",
        "031D1L1_1",
        "[Kme|",
        "BIGNUM",
        "/Un5;O?9",
        "8!83858A8G8K8S8W8_8e8o8q8}8",
        "}6EC!",
        "fZbW_",
        "qw[<[",
        ":f@JAK@$",
        "< L2E",
        "N[H26",
        "ruRy+",
        "e%g-[",
        "Ph`t#",
        "FW|{Iubr",
        "t$$3G",
        "5-Cm3Q",
        "<Fa6U",
        "GetComputerNameExW",
        "Failed to allocate copy of string",
        "637lU",
        "A4u}uJ",
        "Timed out:  %s",
        "pbeWithSHA1And2-KeyTripleDES-CBC",
        "UHrc=s",
        "%k-$B",
        "&D-&d&~",
        "type not constructed",
        "(o 'U7fLOL6",
        "Rd*k/",
        ".w 6w",
        "Lu6uvu",
        "D{wGg",
        "4;4f4",
        "3Q3z3",
        "q&'L_",
        "!gXD)",
        "v2i#;",
        "]O{Cy' ",
        ".+2k=",
        "Jk@>s+",
        "FLDLG2",
        ">*>c>",
        "]q-a:",
        "$gv#O",
        "\"W6*?",
        "SSL_use_certificate",
        "t^>Ay",
        "wpBX:^",
        "R&ty-",
        "BAGg:",
        "0{Vf*",
        "i:ol2",
        "GOZ3D>",
        "A/A;A_A",
        "?-?=?J?q?",
        "5]6w6",
        "|G.t'",
        "rM\"gR",
        "5r%2]b",
        "N}g<a$+",
        "PeFzZ",
        "c\\LW}%",
        "`dsRY",
        "CRolloverFileInZip::Close:  zipWriteInFileInZip failed with error = ",
        "TX8Y`^",
        "SJq.]~",
        "DataStruct",
        "TWi%N",
        "UHU=b",
        "([zpH7",
        "Loading error information from msi database -- Failed to open view",
        "H[_;Rl",
        "K&:#I",
        "_&s?u{;",
        "pM1O@C",
        "Uy\\He",
        "(lIL7",
        "6!6l6t6",
        "F0qTS",
        "{6HoU",
        "ui level is 'Other' (not silent) -> launch message box restart message",
        "RRyy:",
        "0&171b1g1}1",
        "OnFreshAfter:  UpdateVsConfigXML",
        "=i 5l",
        ";,;H;d;};",
        "0R15u",
        "BUF_strdup",
        "error getting time",
        "api_ms_win_crt_time_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "RZ%Gi",
        "z\"[V`",
        "o4D%5",
        "/b\" /",
        "W5#YS~",
        "BAYa*",
        "3DKx/u",
        "`vftable'",
        "MFwlUS",
        "EC_KEY_print_fp",
        "&<vx2",
        "setct-BatchAdminReqTBE",
        "> >V>h>",
        "T$X_^]",
        "J4wzh0'",
        "Fbx)@(",
        "|Y!q0",
        "Vf-@<",
        "n,2!_",
        "ml-IN",
        "h\\WK~",
        "Ph(v#",
        "@vxZs7[",
        " !y0p",
        "FYwqEy",
        "gitl'R&v,",
        "ChCs[",
        "UpdateVsconfigXML:  Updated the vsconfig.xml with osfirewall tag.",
        "yGTCA",
        "G/>@Q6",
        "--nUE",
        "&`(8r",
        "jM\"={",
        "W\"=*I",
        "Op&SroG",
        "7*2P2*",
        "Removed ",
        "3Te=M:m&",
        "clTvP",
        "/\\0,5",
        "[ b6i",
        "jrjlj.",
        "6&6B6^6z6",
        "Ozs(^",
        "q28Cq",
        "4T#D4pp",
        "qmLPcZ",
        "oE-sUaC",
        "=%>E>",
        "OW xO",
        "R3E&6P",
        "6-6/7",
        "X #Fg",
        "cxG*gu",
        "ssl_parse_clienthello_tlsext",
        "S?=r]Lpy",
        ">~q;a*A",
        "vFO%d",
        "=sm)K5",
        "=pm g`",
        "7:=yq",
        "SEC_E_BAD_PKGID",
        "=`=j=",
        "QRq-!",
        "3)3B3[3t3",
        "4$4@4\\4x4",
        ":>;E;",
        "W/$i\"Y",
        "5$5,585X5`5l5",
        ">Y(=Q",
        "sWC$3",
        "Y25Av",
        "*tx1B",
        "protectME;",
        "0nbKG",
        "w]lP`",
        "\\$(SV",
        "CAMELLIA192",
        "sr1.T ",
        "FWRemoveAfter.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "{\\*\\company Check Point}{\\nofcharsws38645}{\\vern49273}}{\\*\\userprops {\\propname _NewReviewCycle}\\proptype30{\\staticval }{\\propname Classification}\\proptype30{\\staticval NoClassification}{\\propname ClassificationDisplay}\\proptype30{\\staticval [No Classific",
        "3A4M4a4m4y4",
        "9094989H9d9h9l9|9",
        "L[l?|",
        "s)4*(",
        "2&3+30353J3b3",
        "5(6l6",
        "}Y<#f",
        "^8g4F",
        "YcG,*g-/\"",
        "(LjHdAt",
        "=4=d=",
        ">+>V>",
        "EQ)ZF",
        ";eADm<",
        "l:2l}",
        "X509_TRUST_set",
        "YzaX]l",
        "vwoj|",
        ".\\crypto\\ocsp\\ocsp_vfy.c",
        "H0{#%",
        "8N9{9",
        "Z\\8[RB",
        "jTTN*",
        "4j Pp",
        "jDg$o",
        "B:Clw",
        "Unsupported SASL authentication mechanism",
        "sr-SP-Latn",
        "s/Ru^",
        "CertComparePublicKeyInfo",
        "b+N+G-p^",
        "%= L&",
        "3D$H3",
        "Mfb%h",
        "g2hvQ",
        "@G[g,",
        "8!9+909G9L9c9h9",
        "jfiO$",
        "#GY\"qLR",
        ",1,2,4",
        "<G\\H/Z$",
        "5)5K5m5",
        ";KVYT/M",
        "]LvC'",
        "{\\fbimajor\\f31544\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}{\\fbimajor\\f31545\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}{\\fbimajor\\f31546\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}",
        "GetSystemDirectoryA",
        "PPPSW",
        "*7g%`",
        "d:s3|",
        "t1tUd",
        "{`$aip",
        "Ei]l9",
        "c#{\".%9",
        "8W8>3",
        "GetNativeSystemInfo",
        "_.2We",
        "mK%V^",
        "F4^[]",
        "ECDH-ECDSA-RC4-SHA",
        "!,]dy-",
        "=~M$ @",
        "/rgLf",
        ": <'<0<7<",
        "GOST R 34.11-94 with GOST R 34.10-94",
        "$cy2]",
        "%qi\"K",
        "%ld bytes leaked in %d chunks",
        "0!0>0D0L0Z0",
        "\\zp!G",
        "'iR>#3",
        "6\"6&6,60666?6P6^6j6t6y6",
        "t)fpu*",
        "\\$\\3L$",
        "c`-+;A",
        "|IgTt",
        "prDaS",
        "CWeA5",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid4208764 connection of the Hardware Prod",
        "<.D^o",
        "!1]'R.",
        "2n%U;",
        "IX5W.",
        "6%6A6]6y6",
        "L-;N#q*",
        ":E<-s#Nt",
        "<KYMw",
        "k%2~S",
        "skY(R?c",
        "_B|}Q",
        "%~j$`!",
        "tZOUV",
        "Kyt?HI",
        "1G$k-",
        "FeatureAntiVirus:  CleanOldCache finished.",
        "]7x3Y",
        "HaQE8t",
        "boX5E",
        "%R\\w$}",
        "Ka0wU",
        "object not ascii format",
        ".3+lSr2;",
        "6,xP?H",
        "5U5r5",
        "hAp3fOk",
        "b/v\\w2y",
        "7i2nnhQ",
        "M.A?`U",
        "V3z5<",
        "\\C~CDCK",
        ")rSKs",
        "?,?4?<?D?L?T?\\?d?l?t?|?",
        ",c9nI",
        "PmxT}",
        "5y)Vs?",
        " 0x26",
        "].vjj",
        "mV=C.",
        "e9HwIQ",
        "Eom.#",
        "'JnjZ",
        "' ?'>",
        "Fq!w!",
        ">,>1>=>J>T>",
        "}iapR",
        "3$3,343<3D3L3T3\\3d3l3t3",
        "877pZ",
        "XWps.",
        ";E%=-",
        "I7Occm{",
        ">0xL/",
        "},22\\",
        "0 0*040>0E0L0S0Z0a0h0o0v0}0",
        "? ?$?4?8?H?L?\\?`?l?t?|?",
        "5>XR]",
        ".[[J&Ss",
        "\\zpeng24.dll",
        "l#omD{",
        "9D:h:",
        "Fc;a>s",
        "gF|PD",
        "8i;pm",
        "got next proto before a ccs",
        "%d\"f]",
        "bad version number",
        "$j=gSy",
        "fzhG=",
        "22R^m9",
        "$`t<+/O",
        "imsV7d",
        "5 5@5L5p5",
        "U3FK8",
        "ARRAY_BOUNDS_EXCEEDED",
        "zUPA.",
        "{w+.H",
        "A\"Tlh",
        "d.N9s",
        "o|ZmL",
        "sOje*.",
        ")pZ&W",
        "Q%gxv ",
        "Iz95:1<q",
        "$*6CF",
        "J8=/_",
        "kxTf=d",
        ".\\crypto\\x509v3\\v3_alt.c",
        "X`2~}X",
        "@hS)\"hZ",
        "1,1Q1Y1_1m1s1",
        "#0J0i0q0",
        "CVTPD2PI",
        "wm.:9>",
        ",eu.%n",
        "f35CY",
        "|,;.*",
        "-HW2Q",
        "H`$?h|",
        "jH&a4;",
        ";3tOV",
        "P#{.'",
        "}kn[?",
        "8(8H8",
        ")HcRNnI",
        "IT*CP",
        "><+Co",
        "vparams",
        "7)OF'",
        "VSInstallerLogoffEx: failed to load vsmonapi.",
        "y,Z9}",
        "`h`z8o",
        "~hcYVjRW",
        "|8% H%",
        "9:$!R",
        "`xmk<",
        "1)W*@ ",
        "\\n5b\\",
        "=!=:=S=l=",
        "FeatureTVDriver:  RemoveAfter finished.",
        "$k^?Q",
        "9hGw ",
        "WDqqN",
        "E=]^_[",
        "~JQ.g",
        ";kk*s:S",
        "%F;UC`",
        "pkcs7-signedData",
        "PKCS7_DIGEST",
        "lAfiW",
        "6&8&9f:F;",
        ">7>T>Y>^>}>",
        "\"jIP#",
        "8W<ap",
        "y{;kC",
        "QYsVd",
        "OCSP_REVOKEDINFO",
        "#rkjc",
        "ZW\"d+`N",
        "q.J*/",
        " |tyV",
        "3n{C+k",
        "Z+,ZE",
        "5uHYJ-",
        "Fhg M!",
        "MMMMM.",
        "-/Ojo",
        "iU#~d!",
        "1D2K2V2]2",
        "cmd /c \"del /F /Q \"%s\"\"",
        "W*92Y",
        "o^~j8b",
        "unsignedAttrs",
        "*'~=x",
        ";n`v\\Y",
        "f97tS9u",
        ".L/2s",
        "8MQdx",
        "2p|QM",
        "aBq8i",
        "Ij;:K",
        ";+;+N",
        "b1?7\\",
        "212k2t2",
        "(?MeJ",
        " cj+O",
        "4+4V4y4",
        "7pIg(",
        "h1a[\\|",
        "j4=/{",
        "dhW7@",
        " A$E<",
        "E^Aav",
        "(N})9",
        ">L,{C?d",
        "YxI^sW",
        "y>AB:",
        "F.jgYf;",
        "2M,6M",
        "!ic?&",
        "hv1Gq",
        "~&&O3",
        "tq%s%s*",
        "|mu+7",
        "?6?G?\\?a?",
        "hS3?5",
        "?456789:;<=",
        "Jd1-4",
        "?[f*Nl",
        "1T1t1",
        "0\"0O0h0z0",
        "Failed to expand path: %S for row: %S",
        "{Q;\\|i",
        "`V2%r",
        "HGO\"t}",
        "G^X-Tk7",
        "`8j6Njx",
        "3Oj$kj",
        "=,=,>",
        "5!545H5S5b5~5",
        "I(JCD\"",
        "|vg{~",
        "_I5Eg&",
        "C1A5G>@",
        "383B3G3^3c3z3",
        "/5(az",
        "wQJd/",
        "G'~y=",
        ".\\crypto\\engine\\tb_digest.c",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 and Bureau of Export }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid7480943 ",
        "90:X:d:i:",
        "]\"$1d>",
        "%_'Tl",
        "4x{Q7",
        "9D:l:",
        "failed loading public key",
        "y2<$y ",
        ";\"k\"W",
        "sBsEsHsL",
        "mQ`:%",
        "|qj0v",
        "=B=j=",
        "F&F.c0",
        "~mcyqt",
        "<$<<<A<M<R<f<",
        "i|Y@3",
        ";%;+;1;7;=;C;I;O;U;[;a;g;m;s;y;",
        "L!ys~<7",
        "(pY!Jae",
        "kGmG\\",
        ",vM1{X",
        "XpztF",
        "@60^F",
        "8/9I9",
        "D$H;D$Ls/",
        "!vOR2o",
        "*5W6e",
        "Hm,\"r",
        "R%)QB",
        "#~}g[*GA",
        "second number too large",
        "[\\ \\1",
        "NfHJ;Y",
        "I@O-g",
        "RegDisablePredefinedCache",
        "{\\*\\colorschememapping 3c3f786d6c2076657273696f6e3d22312e302220656e636f64696e673d225554462d3822207374616e64616c6f6e653d22796573223f3e0d0a3c613a636c724d",
        "4 4@4H4P4\\4d4|4",
        "0}ji.",
        "BOcS+",
        "edKqR",
        "NSLU}",
        "G;mF!",
        "L<Puz[j",
        "FeatureAntiVirus:  InstallShellExtension ended.",
        "Q:Bpi",
        "V#X~Fz",
        "3%ufZ",
        "<'.Kx",
        ";?a#l",
        "1CY_z",
        "v?%,V9",
        ".xZ\"a",
        "H)ICa",
        "w``u N",
        "YQy%x5x",
        "4 4)4>4W4h4q4",
        "8[&HZ",
        "}';\\~",
        "L-^7r%",
        "sr_CP_Left.png",
        ":\"8<S",
        "C=@^E",
        "J~L%4",
        "ABmsU)",
        "failed to get IPersistFile for shortcut '%ls'",
        "w=<'U",
        "{C8Ml",
        "CopyFileA",
        "E|.D:K",
        "GOST R 34.11-94 PRF",
        "realloc memory for szFileNamesExtracted, increase nMemAllocated to %d",
        "zonelabs\\VSSSOpro.dll",
        "amDwn",
        "Anti-Spyware",
        "\\zU|x",
        "~f>__",
        "I/>Zf",
        "`xAi)",
        "VZ<_y",
        "yC[AJ",
        "=F3G.",
        "TnQ[b",
        "\\ZoneLabs\\vsdrInst.exe -i ",
        "S`wI1",
        "J@$U{",
        "Eg^|t",
        "]Eyuh",
        "+}JOg",
        ";-4xa",
        ";%;/;;;G;^;",
        "*Fz:\\",
        "4.o)F",
        "=;DL@",
        "r&2u3",
        "VSCheckPasswordsEx()",
        "D},d!",
        "-z+%B",
        ";*;/;",
        "2S4L4",
        "rIzYQE\\",
        "\"heH/",
        "Axe;Xa",
        "t= eO",
        "identifier removed",
        "k9>Z=",
        "1wfq ",
        "=Y[QM",
        "`.qtY",
        "4'494z4",
        "g7x{V",
        "v?hz'",
        "wq?FK",
        "H#{;GGv9",
        ">u1bP",
        "upXP(D",
        "failed to set security info for object: %ls",
        "kae,nO",
        "<E<y<",
        "5cVk'2E",
        "]u;\"B-t",
        "+u%oj",
        "Jb{+Q",
        "=}Q%%",
        "3G0wZI",
        "U8KTW",
        ":2D^qM",
        "2#3P3}3",
        "%CsP{-S",
        "gl_dX",
        "4.595C5R5Z5b5",
        "*aM0M",
        "!tI)i",
        "H~%P<",
        "7a]N.M",
        "-V/?-",
        "q+*f0",
        "ZExG@",
        "\\par }\\pard\\plain \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid5917669 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\f1\\fs22\\cf1\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "\"{&GK",
        "]JBK?$",
        ";$<Y<",
        "?e+NiF",
        ">'>4>?>o>",
        "0>cxGl",
        "TmN63",
        "6{gM*",
        "Dx;|N",
        "`lW9FT",
        "020E0P0X0^0d0x0",
        "6$646<6D6L6T6d6p6x6",
        "q~]u@'",
        "h]TXmZ",
        "4ap4s[hH",
        "Bq{hGm",
        "?2?R?z?",
        "atlTraceSync",
        " {:02x}",
        "*8@_D",
        "OLD_POLICY_PATH.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        ")\")b)",
        "`$.y'",
        "978?[",
        "bKv_&C",
        "?^?QB",
        "(,Nj}",
        "- not enough space for locale information",
        ">'ObV",
        ",x_\\o",
        "o_!pC]&(",
        "4w0Q4",
        "RestoreDeleteFlag for %s service",
        "w%8RV",
        "opc2%",
        "ow:t/",
        "=%=2=F=Z=v=",
        "unloadZlcomm",
        "E|!QL",
        "3i{avV",
        "HhNhZ",
        "Q6/)mM] u|",
        "`N%+%",
        "FSUBR",
        "(+/V4",
        "Rv@y)3@",
        "clbR\\~Va",
        "5q/_[",
        "I3BDD",
        "nJRIn",
        "Y#e1e",
        "2N3h3",
        "mM<H]]",
        "5Q.}A}",
        "{w:|J",
        "g\"}IO",
        "7=~aY",
        "DSO_ctrl",
        "Failed to insert temporary row into %s table. Error: %d",
        "2*@aw",
        "='m@R",
        "7gOSBB",
        " 4Y-i",
        "dg=Ez",
        "GO-sK",
        "$;^p.",
        "`@-w4t",
        "<j'fSc",
        "cq-=y",
        "pUn8e~:E",
        "$0m\"nqH@",
        "x_cJ~",
        "0,1G1X1",
        "*7gf ",
        "kiRTZ",
        "8#99;D;",
        "oklY;^C",
        "\\securemote.reg ",
        "5@@(A8",
        "erJ]6",
        "7!8R8z8",
        "digestAlgorithms",
        "t<Sj\\[",
        "z=1u`",
        "9=:t:",
        ".@]|Gt0",
        "d'T\\(]",
        "4>WE(",
        "|>EE3J)",
        "@Uf>[5",
        " :@&)",
        "zi0h:",
        "\"4^[a+>sMNv;",
        "ClearAllUsersProfiles",
        "requestExtensions",
        "<\"<F<M<\\<f<",
        "< <$<<<@<D<X<h<l<p<",
        "3<3D3P3p3x3",
        "+*W9Xr2~",
        "j'hxy&",
        "Invalid flag configuration.  Cannot delete a fragment node.",
        "gp&ofx",
        "T#)#!",
        "17ihh",
        "~5}MB",
        "5kTk}",
        "ECDH-RSA-DES-CBC3-SHA",
        "p7+rp",
        "d&6T\"",
        "Failed to create WcaDeferredActionRequiresReboot global atom.",
        "by'H\"",
        "_,L{e",
        " )\"R$",
        "AAE/k Xa",
        "bg=XV",
        "ar-LB",
        "~7L!j",
        "cFbf^`\\",
        "@)5y.v",
        "fW#Fo",
        "$[I\\=",
        ",cN.-",
        "X5$\"n",
        "ASN1_CHECK_TLEN",
        "Yisbv.h",
        "?56dX1",
        "HQh~W",
        "sqUva",
        "fpd *",
        "`E6j/",
        "!iEZ*",
        "=5>u>",
        "e exception of (i) the license shall not be perpetual if the Product is designated for a limited time period only, in which case the license shall terminate at the expiration of the applicable period; and }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "l$\\VSUj",
        "aT0 ?",
        "0<14(",
        "5<5H5h5p5|5",
        "6'626{6",
        "0YLz7",
        "WqO|@^P",
        ";n;t;",
        "@`^%<+",
        "C-w_T",
        "L86VO_",
        "H<1;H",
        "y&b'yq",
        "JXTKyHf",
        "jv0c;",
        "XGkVB",
        "Rj6&*",
        "CleanAvsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "%u %s %X + %X %2.2X %2.2X %2.2X %2.2X %2.2X %2.2X %2.2X %2.2X",
        "SEC_E_MULTIPLE_ACCOUNTS",
        "to=8-",
        "|/ ay",
        "u0sySD",
        "i=E1Vi",
        "UninstallCreatedItems:  Removing registry key HKLM\\SOFTWARE\\CheckPoint\\LTA",
        "1=2n2",
        "uFQdk",
        "nuxB[tm",
        "nC=\"=",
        " DE t4+",
        "JZK]W",
        "W|hoP",
        "p1$7}J",
        "~dw!]q",
        "NK#}6",
        "]=hKI",
        "v%m{Q",
        "pX?e4$m",
        "!N. 0_6",
        "h{A#F4",
        "4 4(404",
        "Global\\vsmon_StatusInfo",
        "0`1P203",
        "C8=}O",
        "[.P7b",
        "2E2O293)5",
        " !\"#$%&'()",
        ",~4Ve",
        "&xtWGI",
        "Start verification... ",
        "SWj$3",
        ",1z;n",
        "^K\"}%",
        "\"41]>",
        "0p!`\"a",
        "a(eV;",
        ".!pkque",
        "@;Dl.",
        "uAl+Z]",
        "jUr2\"",
        "x.n]Y",
        ";i%^!",
        "9 z@tas",
        "oz,:z",
        "zM,Nz",
        "I(L?B",
        "X\\J-P",
        "I?tEa2",
        ".\\crypto\\pkcs12\\p12_decr.c",
        "(ly5Z",
        "qtGu.",
        "OCSP_basic_sign",
        "CndSxS",
        ".?AV?$clone_impl@U?$error_info_injector@Ventropy_error@uuids@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "f>{ #",
        "jA>z\\",
        "<|3`X",
        "}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ons as declared by",
        "Vd*hSJ",
        "tF*R<",
        " Hb^o",
        "Wi6e{",
        ">(>4>p?",
        "(Kz)LvhK:",
        "\\f`}y",
        "6'6-6@6L6[6a6t6",
        "n$#Fr",
        "zq+R>",
        "<ap(V.",
        "gOnZq(cf",
        ":S <[",
        "nK$!<",
        "1z9_Gr",
        "n W9F",
        "oyy^4",
        "RQg`0",
        "Check Point Endpoint Security",
        "audio",
        "Successfully extracted %s to %s",
        "EV3V%",
        "j0hg;",
        "ROUTER",
        "*0(@p(",
        "\\%)qO",
        "5tvil",
        "_!t1/\"",
        "^q*<3",
        "OnFreshAfter:  SetPassword",
        "KgY#,",
        "E$Oh>%",
        "CMPXCHG",
        "2!8BBi",
        "|5j{R",
        "9/S8j",
        "H|5S@",
        "8,808D8H8L8d8h8",
        "api_ms_win_crt_stdio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "SEl#g",
        "3QNo-K{fv",
        "qro}2",
        "<%<4<W<z<",
        "Qj Qh+",
        ")fW=:B",
        "c)(_$",
        "ZLCommDB.dll",
        "Nz=<y",
        "B_FZ]",
        "+iWE|",
        "\"%xnL",
        "}f2Rv\\",
        "h`DO\"4",
        " MSVC64",
        "[:&LI",
        "n%d%X",
        "@V378a",
        "SOFTWARE\\McAfee.com\\Agent",
        "lZ(2#",
        "PWD_HAS_SPACES",
        "?-?M?",
        "s{#UQ}",
        "CJu#d",
        "2 2$2(2,2024282<2@2D2H2L2P2T2X2\\2`2d2h2l2p2t2x2|2",
        "v#IPs",
        "~]ti\"kF",
        ")jAHY",
        "rnf;u",
        "v59^ijq",
        "D$Hh,",
        ":.:A:",
        "808@8P8t8|8",
        "(2!3;J",
        "CheckPoint",
        "D$ PWU",
        "ConfigureManualServices",
        "n~(`BH",
        "'Z0IL8Z",
        "%2S2l2w2S5w5",
        "\":J|^",
        "Dz8QQ",
        "1&111A1K1r1",
        "6$6,646<6D6L6T6\\6d6l6|6",
        "/=b%R",
        "-eC?N",
        "PVVj!V",
        ">*;p*",
        "6)r8X+",
        "aes-192-gcm",
        "3L$$3l$0",
        "X9$l9",
        "TWc.ld-s",
        "mM:[R",
        "u:zP>",
        "WVhx=M",
        "2d0-4s",
        "illegal object",
        "kdL!Y",
        "CEo~d",
        "L$$Qj",
        "@[vDZ",
        "G$wP40",
        "W/s_mNd",
        "!lj4}",
        "jquT!",
        "p]9xB",
        ";5;A;^<e<",
        "Tv0M$",
        "G:7[R4z",
        "dlKfr",
        "rrGt.",
        "A=_&f",
        "IP Address:%d.%d.%d.%d",
        "To encrypt:",
        "[|4#k,+",
        "gr3e#",
        "CollectBootStatistics %s.",
        "Ph||#",
        "6 64686H6L6P6T6X6\\6`6h6",
        "\\QN1E&r",
        "S1^^Z",
        " !\"SSS#S$S%SS&S'()SSSS*SSSSSSSS+SSSSSSSSSSSS,SS-.SSSSSSSSSSS/S0SSSSSSSSSSSSSS12SS345SS6789:S;SSSSSS<=SS>?@SSASSSSSBCDSSSSSESFSSSSSGSSHIJKLSSSMSNSSSS;OSPSQQSRf",
        "525Q5*6",
        "CMS_GET0_REVOCATION_CHOICES",
        "=#QvbOZ",
        "<7XQI",
        "\\lY|.",
        "]6j]r",
        "W+3QM}C",
        ".-?gt]",
        "G`XB=",
        "!BP\"[E",
        "8(888<8@8D8H8\\8`8d8h8l8p8t8x8|8",
        "$R';Z",
        "!Tnjh",
        "\\$,ff",
        "0o0;2A2O2U2[2i2x2",
        "z ?[,:Tou",
        "TPXv6$",
        "File exists",
        "tQ|Di",
        "2Q{%F(",
        "prJWMp",
        "G,jrhd",
        "?38sfn",
        "W[:pcM",
        "l3Ug`",
        "P&f+-",
        "[lZ0'",
        "sn0(u18L}",
        "d.otherName",
        "&lBslk",
        "CT Certificate SCTs",
        "GPGq@",
        "|DX:B",
        ": ;=;h;n;t;",
        "t/jih",
        "N~U`8",
        "0o0q1s",
        "y^i8Y",
        "]EBID7",
        "1`Q+0",
        "@NB-+",
        "4)X)E",
        "^Jl}nH[",
        "2f93t",
        ">.?y?",
        "b.r[Wj&",
        "!gdwI",
        "UQO+s",
        ":!:+:",
        "Jahc?",
        "`%|ot",
        "lmIJ;e",
        "M)NgNu",
        "D$,PU",
        "VSInstallerLogoffEx: failed. ",
        "#ct,K",
        "RHiur",
        "j<s+$",
        "jAjmj",
        "&o^.T.",
        ")d_Sb",
        "wp#yq",
        ":G;_;e;",
        "AECDH-DES-CBC3-SHA",
        "q.@^N",
        "l*~-<",
        "L[`H|C+",
        "d3F=C",
        "3W8(\"*",
        "0#1D1h1",
        "^?2-hG",
        "'c+`lYY",
        "t%HHt",
        "<&<3<T<g<",
        "LAE(.",
        "XDv'(",
        "}.3WE",
        "=|~hi",
        "CMS_RecipientInfo_encrypt",
        "Qg]?BV",
        "Process32NextW",
        "59v$a",
        "$Jn4V{",
        "l$XVW",
        "d||9(|",
        "z~6bt",
        "FWFreshAfter:  UpdateVsConfigXML skip",
        "8-9L9U9",
        "<%<><W<p<",
        ">W16p",
        "YKp03",
        ":':8:",
        "#DO;<",
        "=.a_t",
        "{6LPA",
        "R\\$R'",
        ",:beL",
        "kDR^NW",
        "UVWP3",
        "jCjlj(",
        "<O3kB",
        "Problem with the SSL CA cert (path? access rights?)",
        "E;,?_",
        "caught an error object.",
        "Ku\\Ule;",
        "e=Lo@",
        "CLIENT_SUB_TYPE is set, do nothing",
        "[D_=0b",
        "pz]d^",
        "405K5r5",
        "J1RwC",
        "'3g81D",
        "IsIXm",
        "Y}>y]?",
        "?{0O(=",
        "IE4~b",
        "<j|:N",
        "ZY(n7",
        "$\"9IP,",
        "dtls message too big",
        "<$jW*3<-",
        "ajn^K",
        "b^{vj",
        "L2T2h2p2",
        "&9]uE",
        "5 5(5,585@5D5P5X5\\5h5p5t5",
        "<$<,<4<@<`<h<t<",
        "Invalid socket argument",
        "Vf<4R",
        "&;`eb",
        ">cUq}Z",
        "e34Se",
        "Set dword key ",
        "spanish-venezuela",
        "u\"h$D!",
        "FVb+0",
        "i@sR(lu",
        "'*K)E",
        "#3#eO*fd",
        "wg\\Je",
        "*.tmp",
        "|m2B}",
        "HB N=",
        "GTkcU",
        "\"\\&f0:",
        ">u/h8f",
        ">%\\v7",
        "-h\\iy",
        "E#BgW",
        "3;89Q",
        "04<Lm1",
        "q&bt7",
        "iH'p<",
        "zGVN'",
        "t}k]i",
        "u}E{)",
        "Lapi-ms-win-core-fibers-l1-1-1",
        "9c;r;};",
        "TD0dz",
        "JTC3\\-",
        "copy file to: %s",
        "e/|G&",
        "q6au?|%S",
        "K\"pB\\",
        "|xlf{",
        "VZ;PCv",
        "3t$01",
        "I/O suspended during insert",
        ";=={n(Z",
        "X=R<O",
        "'!AuM!",
        ">?ON>",
        ";!<f<",
        "O#Dnt",
        "*U8K7mv",
        "0c`A@",
        "(UCBP",
        "2)@h1v",
        "gG^G0g",
        ":C#&/",
        "g9tCP",
        "AJwVA",
        "lH$2v",
        "$UNrf",
        "~!n8_v",
        "I8L! ",
        "ComponentId",
        "bEr(Y",
        "    Response Type: ",
        "meKx:",
        "P8+mY",
        "K$fhWFl",
        "uUSRQ",
        "Za\\G,#",
        "o(zx^",
        "3vt7a",
        "-Z#+\"1S;",
        "^ef[J",
        "S!-Ec",
        "171E1Q1",
        "*:6AA",
        "(:QtS",
        "XMM11",
        "D*1.*Dby$wM",
        "un)D ",
        ":pbQM",
        "22kj$,Y",
        "3]*!$ML",
        ">!K\\(",
        "\\Y>gdA",
        "NuLdF",
        "tbVWj",
        "4D2M$",
        "u] @G",
        "ecp_nistz256_get_affine",
        ".?AUIVirtualProcessorRoot@Concurrency@@",
        "{\\pntxta )}}{\\*\\pnseclvl5\\pndec\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxtb (}{\\pntxta )}}{\\*\\pnseclvl6\\pnlcltr\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxtb (}{\\pntxta )}}{\\*\\pnseclvl7\\pnlcrm\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxtb (}{\\pntxta )}}",
        "<cX%t:",
        "363H3",
        "?-?X?",
        "*6rY:!",
        "<x#'p",
        "p&c>Gox4",
        "WqUroS",
        "k2QU|s9U)",
        "ECDH-ECDSA-DES-CBC3-SHA",
        "181S1v1",
        "D$$taP",
        "d4FN(",
        "4V=`!",
        "wS[yvG",
        "9!9A9a9",
        "xi;5 ",
        "ln6/-I",
        "jqjlj!",
        "p03$B",
        "AOdmz",
        "WLAKl",
        "pO+v)D",
        "3I*U,",
        "\"BPTL",
        "u:T.gB",
        "Connection %ld seems to be dead!",
        "j*$*\"",
        "gost89-cnt",
        "Q;4nnE",
        "tcHtBHt!Hu~",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\json_parser.hpp",
        "3!3K3^3j3",
        ",Zn--",
        "<&<G<T<i<r<{<",
        "!#lVt~",
        "id-GostR3411-94-with-GostR3410-2001-cc",
        "%4I64dP",
        "L-4P{HX",
        "_.zj*rB",
        "icjckc",
        "BqV+[{P",
        "AFrwX>",
        "CJ$OE",
        "P,-[A",
        "!';ap",
        "Qg@`\"m5",
        "1-1[1j1r1",
        "e'8Mu\"",
        "f2~ab",
        ";&;4;A;`;",
        "rError",
        "g4l=uRW",
        "D*PV+",
        " w`vj.",
        "=^r\\\\",
        "5IUIeI",
        " 0x56",
        "yYmBZu",
        "dKp-L",
        "/1^*R%",
        "S!;N{p",
        "?#?m?",
        "^:YzQ",
        "6W7!9",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480\\charrsid2385027 Inspecting Encrypted Traffic}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid344604 .}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "25qsh",
        ":mXfC",
        "HXH^#x",
        "8$8,848<8D8L8T8\\8d8l8",
        "vUJVN",
        "U>D)!8",
        "e_QRS",
        "WIX_SUITE_COMMUNICATIONS",
        "Rn*-D",
        ";,)<Hn]",
        "ldexp",
        "G`=E.TH",
        "7}u6Qj%",
        " delete",
        "^iTz0",
        "MsiOpenDatabase %s returned %lu. hDb = %d. LastError: %lu",
        "36V6W",
        "<BH2/=",
        "RLg0K",
        "1AX:M",
        "ue*6\"",
        "perp^ox>L`M",
        "x )$h",
        "-SKF>",
        ";/I/'",
        "SHUFPD",
        "/q)cJ",
        "Ytw_X",
        ":0`dsv%",
        "mn-mn",
        "LPj>j",
        "6&t[S9",
        "tr&PC",
        "P~AeS~AeS",
        "RrIGII'",
        "VSInstallerLogonEx: succeeded.  Client ID: %08x",
        "39Lfb",
        "ivi`bfe",
        "dYjkff",
        "L$(;T$",
        "tV-(o'7j!",
        "J1dAFYCt",
        "2nFA&+",
        "I\\bt<=",
        "181K2E3",
        "i^!mu",
        "\\dingo.dll",
        "~1WPQ",
        "^2;8w",
        "CLIENT_SUB_TYPE=%s",
        "str_field10",
        "S7ae;'",
        "[mu~0",
        "lOF'R",
        "aJ!B_I",
        "g/V!<%i",
        "N mjN",
        "-F-f.",
        "0{&4u .",
        "[.=3b",
        "-]@jD",
        "Z5&B'`",
        "~1b$g",
        "OWK|8",
        "fE7;x",
        "McAfee Personal Firewall Plus 7.0 2006 with Internet Security Suite",
        "~vK@(@@",
        "LjBmH",
        "2 2$2(2,2024282P2T2h2p2",
        "7v8z8~8",
        "5y6C7w7",
        "o'(AY",
        "5+z(m",
        "?<?G?",
        "B6OUK",
        "6)5GR",
        "bhQ|9",
        ".o[dR[",
        "G<CEt",
        "sKk<}",
        "vp5!C",
        ",31dj",
        "+9+z|S",
        "\\7za.exe\" x -y -aoa -o\"",
        "7\"868",
        "1D,~BS",
        "t@UiQ",
        "%I7G+",
        "[bk8|",
        "R[6B&?",
        "n~}i|",
        "&}~^h6",
        "?B?v?",
        "V=84sY",
        "Y^@pD",
        ">(>D>`>|>",
        "AES-128-CFB8",
        ":Na*Np",
        "YKQz$",
        "%Q(ko",
        "Bl H/",
        "AU6S.X",
        "tVWjU",
        "SELECT `Message` FROM `Error` WHERE `Error` = ?",
        "1+1<1B1H1O1W1]1d1k1q1v1|1",
        "GetTraceLoggerHandle",
        "error_connection_hc.png",
        "4]O*Z",
        "@fDZ]\"",
        "b9k[U",
        ";';3;M;d;r;",
        "u4j_h",
        "ky-KG",
        "*wI2(",
        "+U~i!",
        "_,`m}E",
        "oQn|^f",
        "191L1S1r1y1",
        "`;@{B",
        "Installer\\Features\\3CEF7BE31A8A3AE4F8E4A8D671289E7F",
        "Failed to allocate string",
        "&8N{v)",
        "$hhO@\"C8",
        "iu+-,",
        "2$=*)",
        "wd+|X$",
        ";T}6Qk",
        "fT](l",
        ".\\crypto\\ecdsa\\ecs_ossl.c",
        "GQ<8sED",
        "Tc0wBxj\"",
        "aJ&^$",
        "XP31On",
        "TACACS UID",
        "CONF_modules_load",
        "\\><]zZ",
        ",KzZ6",
        ".?AVResourceManager@details@Concurrency@@",
        "Fw[Y)@",
        "QbA@6G",
        ">H?M?S?Y?_?e?k?q?w?}?",
        "%)+/5;=CGIOSYaegkmq",
        "]hT:j#",
        "^]K5r",
        "b)TuE",
        "jljqj!",
        "H\"`U'",
        "AFS:x",
        "\\[Y29",
        "n0npn",
        "jw0IX",
        "8(GlR",
        ",0>LB",
        "Sc/9#",
        "u-D<)I.",
        "jmjlj\"",
        "K{Hv*",
        "mime-mhs-headings",
        "J$JK7",
        "7,81868;8V8s9|9",
        "Check Point Secure Access is already installed on this computer.",
        "*|iKG@X",
        "7t3Mcrm",
        "data too small",
        "r(-\\B85",
        "|o;7L",
        "><8H0",
        "UAbbqJ8",
        "70787D7d7l7x7",
        "9T:c:",
        "NP87v",
        "JH;_v",
        "FiEn`",
        "CNXrq!m",
        "nUm1n",
        "%sAuthorization: Digest %s",
        "mcagent.exe",
        "f*lN3f",
        "L9krg{",
        "o?P`My",
        "PP^Al",
        "sect163r1",
        "RINGEMENT.  CHECK POINT DOES NOT WARRANT THAT THE CHECK POINT }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid11349575 HARDWARE }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420\\charrsid2646135 ",
        "A~|xy",
        "z1X<.s",
        "x`~@dz",
        "Q)=dqH%H",
        "8LEUq",
        "-)syQ",
        "PatchDiscoveryVPN",
        "%$(;@",
        "mBkVv2f",
        "(0XDv",
        "a^<eu",
        "zTB8M@",
        "+;uWz",
        "key expansion",
        "6!7&7Q7V7",
        "3v4|4",
        "_vmc_",
        "missing rsa encrypting cert",
        "1Z/!|5n",
        ">$?[?",
        "uOjZWV",
        "~Lq}Pg",
        "MakeTextInfoBlock: FileTimeToSystemTime error %#x for thread %#x kerneltime",
        "Deleted %s",
        "/>KO]",
        "3&4D5Y5",
        "X509V3 lib",
        "bf-ecb",
        "LT\"TW",
        "dtls1_write_app_data_bytes",
        "b>`>O",
        "eu-ES",
        "3]qL?4'%",
        ".b_p#",
        "Glp[~",
        "oCP>O",
        "Cancel",
        "060R0n0",
        "RELOAD",
        "q~/AmQ",
        "5avKr",
        "ECKEY_PUB_ENCODE",
        "f3x#37",
        "`A'\"ZA",
        "Mv#&wY",
        "H3`Oc",
        "BT8a7",
        "X76(u",
        "?D[(*f",
        "Not found ",
        "zS-G]!lZ",
        ")TNv.c",
        "1mbD6Ro",
        "YUh/1",
        "HHTps",
        "'`E f",
        "4\"4>4Z4v4",
        "w{8K&",
        "*ykDq",
        "`@jac",
        "ZC^p1",
        "|a7.1",
        "av3N`m",
        "A#vfh",
        "Fu?9l",
        "%s; code=0x%08X.",
        "T`+P{",
        "G K,N",
        "alH7M",
        "Private Key",
        "pok5PIu",
        "mr-IN",
        "CMS_EncryptedData_set1_key",
        "tO!Pa",
        "krb5 client init",
        "RR3oXN",
        "v;H2X",
        "%02d:%02d",
        "l4)'\"5",
        "Ia.{W",
        "p\"E*c",
        "D$$90",
        "CMS_verify",
        "DyQkv",
        "*d:WfU",
        "+{[[{_#",
        "212;3\\3&454P4",
        "k~8\"2*",
        "R9=a5",
        "O?}?J",
        "u@r2S",
        "PP@981",
        "&Oqjq",
        ";UPkuD",
        "]SO&y",
        "byH9a*",
        "]^n0m",
        "qYw+\")|;",
        "wnk\\*",
        ";|$0r",
        "CcU3T",
        "?[[IN?",
        "LGN*u",
        "u)T&1G",
        "p\\_tc",
        "vx!nC",
        "ASN1_TEMPLATE_NOEXP_D2I",
        "$PjQW",
        "|I&T1",
        "6(YQXl",
        ">u6oY",
        " ERROR unknown client type, set as ENDPOINT SECURITY type",
        "WU[U_UcUgUVT",
        "?U?[?",
        "                param=\"md5\"",
        "7$707P7\\7|7",
        "WIN32_SPLITTER",
        "bcrypt.dll",
        "0M4Me",
        "J52m\\HV(",
        "nvJ\"L/",
        "L\\q p",
        "9B:M:Z:f:",
        "$ZDjy",
        "D$ u,Wj",
        "=*M.:o",
        ";0;<;\\;h;",
        "6&Ou>",
        "L'_z/",
        "filename(",
        "O%p$Ve",
        "4!515Q5",
        "\"WJVJ",
        "'L_br",
        "~QP&nRC{",
        ")BwO[",
        "tlj*Yf",
        "/zmOv",
        "k>9SIH",
        "c7RMg",
        "l$$t:h",
        "Pjzhx",
        "\\;V7E",
        "Iy?Ii",
        "host unreachable",
        "different key types",
        "336LK",
        "DDDDDD",
        "D$TPj",
        "GWhC)x",
        "y9yj?",
        "S}Cz\\",
        "U1cXl",
        "PPPPPPPPPP",
        "L+4oJ",
        "n|(I{",
        "<ty+`",
        "?uv#w",
        "1F1DP",
        "8V+6~",
        "s.{nw\"",
        "95usu",
        ".t_kPl9",
        "TmA\"-",
        "engines section error",
        ")rtJG",
        "TS_RESP_set_tst_info",
        "KFdH-",
        "&:jIl9q",
        "?hd92",
        "9:V88Oc",
        "I+N1c",
        "dZ20Y",
        "OzNy1",
        "tlsv1 alert unknown ca",
        "AShlatqyk",
        "*D|9C",
        "D@[^c(h",
        "0N0p0",
        "FeatureAntiVirus:  RemoveAfter started.",
        "znS.:)",
        ".)R;/AX",
        "*Iok0",
        "95:`:e:y:",
        "wHHr_",
        "{Ac$a",
        "C\"juC]",
        "0W9:q",
        "+_#mS",
        "1p) l",
        "7>mQX h",
        "dh6&5a",
        "RVHkT",
        "D$H9N",
        "7/v0VgI",
        "WixQueryOsInfo",
        "%pt:gF",
        "W_rL/]",
        "failed to create directory",
        "~TwcL",
        "9 909",
        "`2.JQ",
        "pAC!t:",
        "87C8e",
        "des(%s,%s,%s,%s)",
        "gv\\5A",
        "53?ZS",
        "[%s] CreateZipFile: Error writing zip %s - GetFileSize %s",
        "n0~lv%",
        "4Zcwn",
        "vs x+",
        "IaY:j",
        "`H(hqA1p",
        "AACompromise",
        "YAuc{nv",
        ":*:J:g:",
        "4(40444@4H4L4X4`4d4p4x4|4",
        "~E>t!",
        "epklib_x64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "^bZI3",
        "StopABService_rollback failed",
        "FeatureIMSecurity:  imsinstall.dll is newer than 4.5.00",
        "626M6h6",
        "%15[^?&/:]://%c",
        "u*jnh,",
        "e,HKV",
        "G!uWr",
        "L$Dh ",
        "[[STORAGE1=%s]]|",
        "<vLj)",
        "9*9q9",
        "1z0eF",
        "]Lelqi",
        "%u00?a",
        "@(p'f",
        "Sectigo RSA Time Stamping CA0",
        "5b5(6!7k7]8",
        "Af5\"7CrO",
        "WxE-0",
        "[syg@",
        "|0{ [",
        "G+t|D",
        "s&qL0Fx",
        "vo&l)?~",
        "H+;C42",
        "L8&_)",
        "_^[Y]",
        "OPc4,",
        "ssl3_ctrl",
        "Plugins::UnregisterAM:  PluginsUnregister started.",
        "VSWriteKeyUninstallInfo",
        "ZAFrameWnd",
        "Internal error",
        "7$7t:",
        "h`!e''a",
        "rd4T;*",
        "#c6yF",
        "pzrLm",
        "[?mri",
        "=$=Z=",
        "(;'>|",
        "1^T4t",
        "3$4T4",
        "8[Y61",
        "9!919A9i9w9",
        "wwwwwwwwwwww",
        "{Q_)'",
        "E`DNc",
        "<!=\\E",
        "bI~,^",
        "ACsi*",
        "Vj3nyso",
        "Q#W.p",
        ",~1O(",
        "jBj{j",
        "winp95",
        "Administrators",
        "h{N+.",
        "geW4d",
        "UL_M=",
        "AddMitigationOptionsRegValue: value is up-to-date.",
        "4$5h5",
        ">,?1?6?;?C?Q?Y?",
        ".?AVCacheLocalScheduleGroupSegment@details@Concurrency@@",
        "4Et\"N>",
        "3sH?vx",
        "4I7z7",
        "ET}.Q",
        "PerfSetCounter32",
        "[R10D",
        "^.EId",
        "ju^l?",
        "TJJ&VT#",
        "ZKy(x",
        "0Y1*4)y",
        "N=AH$X",
        "1`b0n",
        "HEqpV",
        "BOOLEAN",
        " [`_P",
        "JUW ^1",
        "pU;\";",
        "!Ws6?!",
        "/[2}$",
        "]Fm9Q",
        "hOfbx#v",
        "-0>0K0k0|0",
        ".CRT$XIC",
        "O}FN3p",
        "Yal2=k",
        "=QM&&",
        "_T&0#",
        "guH9( ",
        "}$~>kO",
        "ssl2_read",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\InstallError",
        "R)b$Z'",
        "859?9",
        "eT2HHv>Cr",
        "6666666666666666jjjjjjjjjjjjjjjj\"",
        ".r,C`I^",
        ">8pSC",
        "2k'=+",
        " !W>h",
        "x!<#J",
        "l@AM#",
        "v&'q$",
        "U?)/17",
        "8MNix",
        "Fvu\"b",
        "5:5P5f5|5",
        "sv`b|",
        "]CC/e",
        "=j*Xf;",
        "p3Y/f",
        "N|]3Sm",
        "f!}Gj",
        "L+|6B",
        ": :(:0:8:@:H:P:X:`:h:p:x:",
        "0%1F1",
        ";/;V;c;w;~;",
        "file type ENG for certificate not implemented",
        "73bhP",
        "YF?0un",
        "@uA?k",
        "Y_^[]",
        "address family not supported",
        "A;f1I",
        "&#x00;",
        "sK.:/|",
        "t!65i",
        "bB&~>",
        "D|`tW9",
        "negative width",
        "k*Rg`#",
        "\"vAnnd>g",
        "ZOK.)dT",
        "J7\"Qo",
        "/L{uk",
        ":N86B",
        "<i)8)",
        "B8uh_",
        ")bLwR~",
        " cannot find EPS_R80 Version key -> R80.20 is not installed",
        "<Y=l=",
        "~HS{}a#F",
        "Ppe%f",
        "x5)7D",
        "I&s|XZ%",
        "CustomAction",
        "p/ lM",
        "wa/aG",
        "0S1Z1l1{1",
        "P`LdaJ",
        "DeleteUmsCompletionList",
        "H<@](",
        "[VSDATA] AddDataClient: no free client",
        "DzV|O,`x",
        "m/?sg",
        "B^#J(",
        "AHzjR",
        "WiGL!\\",
        "w\\Gf6",
        "RunClientHotfix %s.",
        ".n\"%;",
        "K*72-C",
        "o:+`O",
        "x.*z>",
        "+II?b",
        "{U7wv",
        "UX>`b",
        "CheckInstallConditions:  PreInstallCheck failed. Verify installation requirements and try again.",
        "T?ZLt",
        "CxhgV\"",
        "\\af0 \\ltrch\\fcs0 \\fbias0 \\fi-360\\li720\\lin720 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'01.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 ",
        "@v/M<",
        "aqH`%",
        "L@V:lI",
        "CreateProcessW",
        "l_Wi:!BR/8W",
        "kT2mB",
        "DS_CheckIfRebootRequired ended.",
        "X1EJn",
        "lc#Y0",
        "'BA;H",
        "Q,`:U",
        "(Bs;K",
        "+iN~{M",
        "Ne$vt",
        "p i\"K",
        "o]<{D",
        "A}R.:Dc",
        ">2>f>",
        ">N?X?u?",
        "%i2ePe",
        ">'>I>N>u>z>",
        "i$pok",
        "hzs!,",
        "Y>wwv",
        "&y413",
        "Of&2MfO",
        ":e0m<Im",
        "x,d`u",
        "`<Fh^",
        "Compliance.exe is not running.",
        "failed to find WSACreateEvent function (%d)",
        "X0OgL",
        "L(eM!v",
        ";C~|C",
        "OCgz8",
        "OZvmb",
        "?'?,?",
        "=E>j>",
        "fc\\j7:",
        "8A0w`",
        "1.1J1f1",
        "t'yD&",
        "<h,_{9*",
        "cj`~V",
        "D8,uRt",
        "<R67U",
        "jQ3#4",
        ".\\ssl\\t1_ext.c",
        "2(2,20242<2T2d2h2x2|2",
        "bOf~x",
        "5`[Lu",
        "4@=+%H\"$",
        "VVr+n",
        "VHYEe",
        "F.R#80\"",
        "9K04l",
        "^{:9P`",
        "^VBz+",
        "!<C&y",
        "&-P0%",
        "B@)Ea",
        "RJe(E",
        "$Hl$\\",
        "yVpR[",
        "9*9E9K9Z9y9",
        "l4*p|",
        "</@]p",
        "lSy{={",
        "bjiHl",
        "[h[5[6Z7_",
        "X&a!L",
        "lpzMRv",
        "=#=4=I=N=",
        "N|lF~j",
        "o2.6?",
        "}8Fd ",
        "kiBC]/",
        "E(T$x",
        "{e1G{l",
        "6w%Ia&",
        ":P.}h",
        "Found cached Discovery VPN installer",
        "G\"XjpD",
        "~O.MD",
        "U|%aT",
        "0^][_",
        "9;IR5yM-",
        "SSSSSSSSSSSSSSSSS",
        "+si&0D",
        "w55OWP",
        "4'|Bz",
        "2 2$20282<2H2P2T2`2h2l2x2",
        "P9~)}",
        "]u4@O:[7&+",
        "!/V]_IL",
        "n~^I\\",
        "*,!(A",
        "= =H=y=",
        "~(j,h",
        " +\"~W",
        "W;$BQ",
        "6*7c7",
        "jrr9$kd",
        "P!`?&-&",
        "A9Y!Pox",
        "A4F)-B;",
        "-\\D|N",
        "AO3I]",
        "N~`x;",
        "q=}o&{",
        "111D1I1N1S1k1",
        "uu9Kqo6",
        "invalid null cmd name",
        "80`xL",
        "Z|/cD",
        "uP9~$",
        "=O>V>`>p>",
        "Op`)Lz",
        "<>=R=n=z=",
        "Q~FM/",
        "l+/H!9D",
        "oL2(j",
        "cp_apvna",
        "Q\"{1Xc",
        "C;L92",
        "R7;~'D*K",
        "\"Mc2WE",
        "_J36_",
        "*.;;^5(",
        "sYSGg",
        "FTP: unknown PASS reply",
        "NETSCAPE_SPKI_b64_decode",
        "dX>}J",
        "Failed to opend DA registry key.",
        ",Yy hQ",
        "VC\\yE",
        "926GlKp",
        "Q72sN",
        "121N1\\1`1d1h1l1p1t1x1|1",
        ",bg\\*",
        "CYg($",
        "7vTfj",
        "iiLLu",
        "OwI,0",
        "$bA~}",
        "<'=@=T=h={=",
        "FSFmj{",
        "+ii4kyr",
        "x1V{C",
        "iX)(b",
        "Failed to delete the property",
        "BR#q4",
        "bytes_to_string",
        "%V)3k",
        "Js.f[\\.",
        "aM[dt",
        ">deNF",
        "@?vR_",
        "{4xP(",
        "RC2-ECB",
        "mJ-6g",
        "\"@gUR",
        "$[;ZOE",
        "dD1?[",
        ":(:.:S:",
        "f.EZ~",
        "AjIJ\\",
        "dDVL}",
        ":,P,lt",
        ": :`:",
        "}rGH/",
        "f3ikDo",
        "$e2A0O",
        "4lf%1",
        "1Y1c1",
        "1$2P2u2",
        "=`_k.s",
        "t-UWW",
        "oeo.Y",
        "?:zW,",
        "|utLr",
        "E6eB{",
        "<P=p=",
        "GlobalSign Root CA - R61",
        ",nN66NT",
        "not a directory",
        "u./~r!",
        "|`@zo",
        "X[m<p",
        "a2G=U",
        " Oj>W",
        ":5:S:v:",
        "@0RNJ",
        "E\"c<t",
        "%R*qJ",
        "+4V,s",
        "&o32M",
        "bad srp b length",
        "1/f-!",
        "L[8wq",
        "GetLocaleInfoEx",
        " D\"\"4",
        "Check for incompatible antivirus software is disabled.",
        "TLf%)",
        ">E[!7",
        "Q52(p;",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid11029351\\charrsid15169477 defective }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 Hardware Product or one of its component parts may only be returned to Check Point }{\\rtlch\\fcs1 \\af1\\afs20 ",
        " ;\"B@",
        "\"m8Ke",
        "Hv<KM",
        "wO5GB9",
        "A+-M^",
        "api_ms_win_core_processthreads_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "9C`u5Wj",
        "BN_to_ASN1_ENUMERATED",
        "[vRIz",
        "Y=qA>]9J",
        "RemoveOldFirewallFiles",
        "PRHelper.exe",
        "SEC_E_INVALID_PARAMETER",
        "$_c`#y^",
        "jF32m",
        "api_ms_win_crt_private_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "PKCS7_ENVELOPE",
        "j*\"*/",
        "N\"A\"Z",
        "/STq57",
        "d}~YA5",
        "848Y8",
        "+A8$]",
        "#0.|,",
        "4SxIB",
        "d8){$",
        "J^/qn",
        "mKLT!",
        "ControlService",
        "=_>w>",
        "]LA<`",
        "3$=I~",
        "I26+7",
        "Nd1xC",
        "X?^^t+",
        "=,=4=D=L=T=t>",
        "ChangeCharacteristics9to1 failed",
        "FwConfigChange",
        "u7\\$7A",
        "G[FWJ",
        "|GBG'GPGI",
        "fWO;]",
        "class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > __thiscall boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >::get_value<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct boost::property_tree::id_translator<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > >>(struct boost::property_tree::id_translator<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > >) const",
        ">$>(>8><>H>h>l>",
        "o@%s<",
        "6q8z8",
        "PLATFORM",
        "S-d[q",
        "<yh\"R+",
        "B_dSS8",
        "=Uc(-?#4",
        ":5:N:g:",
        " Ib<q$",
        "<$<,<D<L<T<\\<d<",
        "B>;+#",
        "YWhn.",
        "V&da&[",
        "+m,Au2X",
        "r`ySf",
        "y(3\\W|",
        "new major version newer then current file",
        "[OXV(",
        "2\"383@3K3a3i3",
        "^lW{1x",
        "p/C8N",
        "$p>S)s",
        "7l9l:",
        "em.c(",
        ">x<v`g",
        ";;vOz",
        "d`/36",
        "6lK+*",
        "`placement delete[] closure'",
        ">8$Vx",
        "&b6%G",
        "2i2hR",
        "ZcST'",
        "k.tA0",
        "YEi C&&5",
        "|fS[tE",
        "u!SSj",
        "6!;I<Y<",
        "RP93!",
        "'4/4f4m4",
        " ET+E",
        "%Pg+.",
        "){:N(",
        "db-UA",
        "g]>@T^",
        "72M+5",
        "> >`>h>",
        "6*686D6V6]6d6",
        "-e3,p#r",
        "SIG_CB",
        "W8b=z",
        "se6Gz",
        "EQ!+Gr",
        "onlyattr",
        "MOVMSKPS",
        "compatible",
        "?(?t?",
        "pVY(Ay",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\logger.cpp",
        "****************************** ComponentsBackup ended **********************************",
        "'v2zLI;",
        "X) V~",
        "/^\"K&i",
        "0uQ3B",
        "+'a52f",
        "h&ng(",
        "^)sZj",
        "QQWPQ",
        " fxTA}",
        "nJR>0",
        "~>rat(",
        "Xm07Wq,;]",
        ":7;F;S;l;",
        "\"%sUninstallSecureClient.exe\"",
        "3T$,3T$ ",
        "vNBjg",
        "w0$xi",
        "h?uScyj",
        "@^|^h",
        "P\"B=UFC",
        "z{Uw,&qn",
        "ie8y6K",
        "gMe[5",
        "[oHk7",
        "=]5o0",
        "n~KxzX^\"",
        "Hnm U",
        "HMAC GOST 34.11-94",
        "eLs];",
        "jVq^P",
        "|hvV@3",
        "3U]~b",
        "3UP_Y",
        "%%49Uj|h",
        ".+[|xY'^}",
        ":>L='",
        "O`4y;e}",
        "B%'+Lo",
        "&>zX:",
        "t$(#t$",
        "727U7p7",
        "W9`h\"",
        "'PdIw",
        "[i53z",
        "\"}OsA",
        "D=yP6+u",
        "AL;a}",
        "\\zonelabs\\featuremap.dll",
        "BgM`G",
        "Q>Q\\Z",
        "@gP?hg",
        "}\\(5l",
        "3YTV!\"",
        "1UN#v",
        "hxhx(Q",
        "Wqi$@",
        "Jp6CM|",
        "nUKh@k",
        "csQRl",
        "sk,Vr#",
        "K]I@\"a",
        ";Y$GV",
        "&lc)8]",
        "self signed certificate in certificate chain",
        "gZ7>Idnf",
        "`lnJ~",
        "/XhQ-1",
        "]WZRb",
        "1N2u2",
        "@kT>=[",
        "j_Fh6",
        "}jJm|l",
        "0M 2P",
        "PmwH{",
        "4N5Y5",
        "TIC{}",
        ":pFoh",
        "R;z[v(O",
        "unauthorized",
        "<\"=+=4=B=K=\\==>]>g>",
        "G1nt\\:",
        "Ob^QhN%^`",
        ";+;2;A;K;",
        "~7oMV(+",
        "=+=Y=p=",
        "{>a=n",
        "h[y3BK$Q",
        "e0\"|Q8&0",
        "'@Q}Xf",
        "h4$z3",
        "oA|[Zp",
        "T~f9X",
        "D$$_^]i",
        "?7?;?=?A?Y?_?e?g?y?}?",
        "8'979;:R:b:",
        "|YyXl",
        "CleanTrayComponent finished.",
        "{AC30BFB5-834B-46d2-B912-6CE71684EB2D}",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
        "YXJts",
        "0AXAv",
        "[VSSHUTDN] KillService",
        "jdh`h",
        "SE-IH^b",
        ">=a>3",
        "?#YAL",
        "|%j\\XP",
        "6U8w9&;q;",
        "Default is Windows 32 bits",
        "SUVWhl",
        "[VSDATA] tvfwFirewallAddXMLRulesFromFile CreateFile failed %d",
        "{g:m*",
        "Yc%Y%",
        ")n(cG",
        "h`4p;C",
        "p21w1",
        "failed to allocate data for stream",
        "dWdX+",
        "hK{RX",
        "uSdH/",
        "s6^N@Kd",
        "<(<0<8<@<L<l<t<",
        "X7R;$)p",
        "\"nK=u1p",
        ">rJ|f",
        "Bb[]{Gx",
        "##/#g",
        "\\@JWy",
        "F2UMCB",
        "NMWim",
        "hihna",
        "T!M-f",
        ":8:P:X:h:",
        "rv]$S6>,",
        "{3p+]",
        "|u6 ,",
        "MV6MG",
        "JP>3qJ(PW",
        "D$ PWV",
        " O\\Q(",
        "REBOOTPROMPTWITHSILENT",
        "wEs*t",
        "packet length too long",
        "%ODuW",
        "828N8j8",
        "KU;i=",
        "fQ_C3",
        "~cm<?j",
        "5<6i6",
        "mK~,0",
        "DkIPv",
        "gL/#.",
        "=!=1=X=g=",
        " 0xa6",
        ">$Lcu",
        "GZY%@",
        "'h#&q_",
        "WR?wg",
        "FrJi1_",
        "})v2>",
        "Gn$KdE",
        "230202160544Z0+",
        "/w73,",
        "jhjvj",
        "invalid null pointer",
        "NrV'b",
        "$9_}V",
        "=U=c=y=",
        "@x$ KrJf",
        "rxa!/",
        "qRBE|",
        "ulDS}",
        "t$Ux\"u",
        "kB(.zH",
        "9\\E-9",
        "X8jI8",
        "^{R)dy",
        "l]_16",
        "zu'9f",
        "8#UypH",
        "C-^X`q.",
        "<-=|=",
        " !pMy",
        ";-;^;f;o;x;~;",
        "NetWkstaUserGetInfo",
        "Ud8a-",
        "DS\\#9",
        "D$0WS",
        "fY/!$",
        "FWUpgradeBefore finished.",
        "K{!)*",
        "not key transport",
        ";&;N;e;o;{;",
        "Vhha\"",
        "&\"}0v/",
        "1ZGolo",
        "=>NOfLM;<",
        "l9;qq",
        "2c6ov",
        "Ms({b",
        "55<z+",
        "no value",
        "FWFreshAfter:  LoadVsconfigXML",
        "j}30U",
        "bZ[%a:,",
        ">\">5>R>f>t>",
        "v<vz-",
        "iK0z`",
        "OpenSSL EC algorithm",
        "7 7@7T7X7",
        "kuV4e{",
        "=?}=`",
        "5-dkgidQ",
        "0aU}\"D?d",
        "fg4{UCv$",
        "IS7;G,",
        "5m`sy",
        "eGR0E",
        "8JAg\"",
        "ZTg-/S[K",
        "&YBW;",
        "&|%CC",
        ",y4zl'Zs",
        "WSACreateEvent",
        "PVVj.V",
        "> >0>4>L>P>h>l>",
        "c]sZ#",
        "C(PX:v",
        "*>R0m",
        "2U{CP",
        "BD(R!%Q",
        "9&e~j_i ",
        ";-;[;",
        "failed to convert output to ANSI",
        "p@RvYqP",
        "e0exq>",
        "Needed: %I64d MB",
        "lj~Ia@",
        "e&5n7w",
        "1;VjeJY",
        "6IAjH",
        "j6hu:",
        "Md>ue8",
        "L>cxRR",
        "\\Mp@HG",
        "\"{ILl#",
        "unsupported pkcs12 mode",
        "[VSSHUTDN] VSUnprotectAllFiles()",
        "SOFTWARE\\McAfee\\McAfee Internet Security\\CurrentVersion\\Setup",
        "==\\>?",
        "&[2%J",
        "tid        User         Kernel (hh:mm:ss.msec)",
        "^-#bW",
        "invalid bmpstring length",
        "UyPiW",
        "A0}Vd[",
        "eG;$g4",
        "Q---n",
        "yhMjDI",
        "[x],mL",
        "D$(UV",
        "q3+h>",
        "'i_'Wi",
        "RrAd!",
        "/UZ.p",
        "svxsN[",
        "FRNDINT",
        "}oVYnP.",
        " 9P3FF",
        "J!Wo1_",
        "z:FPS",
        "t0I h",
        "FMM)MRd",
        "L$P_^]3",
        "=D#SP",
        "[2>Tr",
        "&w,q&%",
        "(@r:0",
        "encrypt error",
        "G4aeV",
        "><>D>L>X>`>",
        "iO5,wo",
        "^0c3W",
        "\"\"~Cj",
        "XP$=L",
        "8PdX6",
        "h{[Mu",
        "$d<)h(",
        "'0W)$\\",
        "CHv*V",
        "TUzUq",
        "^7ni|Y",
        "unknown module name",
        "Jxr1+",
        "o'Mh\"",
        "rfP\"x#'",
        "!ejot:h]~'",
        "jkjdj\"",
        ".\\crypto\\conf\\conf_def.c",
        ".  Assuming it doesn't exist.",
        "RSA_public_encrypt",
        "^_]H/?:",
        "&pxH.",
        "]$7An",
        ".\\ssl\\t1_lib.c",
        "T?lLy",
        "KRSBN",
        "7+828;8D8r8y8",
        "_lread",
        "`RR8KR",
        "vC-OM!f%M",
        "V|.i\\",
        "\"\"?t!X",
        "<1<Q<{<",
        "Y&!rO",
        "UhX!#",
        "{'v)h$",
        "%e\"7eOg3@",
        ";%'?Q",
        "9/9Q9i9",
        "PVSQj",
        "{S#EL",
        "D\\QYO",
        ":$:0:P:\\:|:",
        "878m8|8",
        "2&2P2[2d2&666C6N6y6",
        "90H$I",
        "mvT'V",
        "?0???",
        "Am6g;",
        "uiR\",",
        "A)AAAAAAAAAAAAAAAAAA",
        "FeatureVPN _FirstAfter",
        "/GK(D",
        ".vCyJ",
        "92:/n4",
        "Jta|8",
        "y;~(jv0",
        ".?AVOsVersion@@",
        "&\"i\\7",
        "\"vr+Npe",
        "Socket has been shut down",
        "a2d_ASN1_OBJECT",
        "0Z]Ui",
        "vW&z`",
        "GFWrq",
        "7>cmd",
        "bAj\"Zn",
        "7O7g7p7",
        "WWnd?",
        "DS_RollbackCopyToSystem32 started.",
        "9;9O9q9",
        "api_ms_win_core_datetime_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        ")j$RR",
        "qI$nP",
        " -setup",
        "le8Ek",
        "u@bAs",
        "SDK is not being upgraded, skip server checks",
        "%W&_pA",
        "D!T`|",
        "N*;-8Y&",
        "7n|z|",
        "`h7zN\"",
        "jWhTY#",
        "NQ*[or",
        "A`>6#",
        "!ZiVc",
        "u@2}-b",
        "-Lpqn,Y",
        "94989P9T9l9p9",
        "F ]sj",
        "91&~^",
        "en-PH",
        "7/7@7U7Z7",
        "vt`S9",
        "$Ti|e",
        "|B@P&",
        "l$X3l$L",
        "(PE\"ywp",
        "=|zEJ",
        "_hypot",
        "<D802",
        "            Not Before: ",
        "|LPoR",
        "OM@/@",
        "nZoG:#K",
        "5Rjat;h",
        "%HfoC",
        ";';\\;c;",
        "!VLT|_",
        "?#???b?}?",
        "[R2Mn",
        "gnuar",
        "mL05C",
        "MWC&)",
        "8GEKW",
        "2%3R3",
        "v<f>>",
        "(<<>;X",
        "D$0_^][",
        "UUN[>",
        "cWgfd",
        "-wW+*`",
        "\\WcFn",
        "Sm|&0",
        "7U#gy",
        "****************************** VnaUnInstall started **********************************",
        "J)!nAa",
        "IPSec End System",
        "8$8h8",
        "KkkZ(",
        "qR(gGK",
        "BeginSession",
        "crx%>j",
        "a'Ph<n",
        "Ly8t&",
        "b^R]k",
        "te>+w",
        "Setting 'PREV_BUILD' to %s",
        "Oh1:w0QT",
        "B+9XN",
        "D$Dh!",
        "=1^F{Nld",
        "WixShellExecBinaryId",
        "t~SXg^",
        "aAy@0",
        "VirtualQuery",
        "$d.QE",
        "R$u;2>",
        "Y!d{}aq",
        ";d$}v",
        "~h<u=",
        "Full Disk Encryption",
        "mv/:TM",
        ".Q:_R",
        "Create MsiDirectory %s",
        "certificateRevocationList",
        "0y02P3p0",
        "s,* xt",
        "fsrszs",
        "orig_len >= md_size",
        "wxL+D",
        "< <?<]<",
        "7;Gue",
        "CuO9>O",
        ")gX(a",
        "646W6z6",
        "#oCAo",
        "bsPuX",
        "[VSUTIL] GetCustomerNumberEx() returns FALSE",
        "949<9D9L9T9\\9d9l9t9",
        "15[2b0",
        "goQhU",
        "*k)\"@,",
        "<'<1<Y<",
        "EFGHIJF@",
        "L`W9^",
        "GeneralNames",
        ",~L|O",
        ">*$G]",
        "d2\\`E",
        "b<`+&",
        "0<\\|S/{",
        "_uQ2\\i",
        "fbNKs$",
        "Br]~j",
        "w{Z<6",
        "D4a]a",
        "BA>o)",
        "m /3a",
        "N t<Z6",
        "!\"^ cX/",
        "C;;Z-S{Is",
        "{}KsX<{",
        "8!8*818=849",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Miscellaneous}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "@8\"`H|M_",
        "8rLh2",
        "w&P@^",
        "ZhJ&%",
        "8'8F8",
        "&GJ)c",
        "TrueVectorIF::SetProtection(%d) failed.",
        "4)535>5",
        "=@=v=",
        "868720004",
        "=D~B3",
        "TVDIR",
        "1)2C2G2K2O2S2W2[2_2c2",
        "%qol9",
        "C]eb?",
        "nCq%p3",
        "R&W>Q",
        "}}q^}",
        "Nb?gc",
        "Q]9~0]",
        "!G}MC",
        "uYD[H",
        "OVeXH",
        "\\zonelabs\\FeatureMap.dll",
        "?CLuhs.",
        "ASN1_generate_v3",
        "9e7ef3f2d117d57859c6fffac327bffcfc793510d26726ce8b2f9ffcf6ecc98baf3efdfdbb4715f04d814765f890c644a29be408edf3181433567125272371be",
        "|&e5CE",
        "^~_L/",
        "Q59zJ",
        "VSINIT.dll",
        "uyKPw",
        "wO[dKZZZZZ_QD",
        "rwcRc",
        "CERTIFICATEPOLICIES",
        "ZlJuo",
        "4Q5l5{5",
        "Failed to select path %ls for deleting.  Skipping...",
        " 9Sm.",
        "7k8}8",
        "4*S%=v",
        "^yIL-&)S",
        "00080@0H0P0X0`0l0",
        "$YH]9",
        "unsupported elliptic curve",
        "5$5,545<5D5L5T5\\5d5l5t5|5",
        "mhO^Zg",
        "Ty9Kq",
        ":~(Rs#",
        "NT0`S",
        "7\"7&707<7H7T7^7b7l7x7",
        "E-mail Protection",
        "E^,jFe",
        "|Iy)2",
        "8cpn+P",
        "CC|i@h",
        "meta_data2",
        "'M(-(",
        "KTU;E@*=-",
        "[7+`_Q",
        "8 8$8,80888@8D8H8L8P8X8\\8`8d8h8p8t8|8",
        "aS%z3",
        "z7z8z9",
        ";;eni",
        "yZAGO",
        "qO3gxu",
        "PRODNAME",
        "Gym{_k",
        "%D*Y\"",
        "L$([]3",
        "[O@B8",
        "#4C:v!:",
        "iJl|d",
        ":Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday",
        ")wbddJ",
        "3L$83L$$",
        "jijmj(",
        ">$>,><>D>L>T>\\>d>l>t>|>",
        "caught an error not an InstError object.",
        "E^E_E`",
        "FTP: The server failed to connect to data port",
        "P[pR,",
        "{1P<W",
        "0H@BG",
        "unstructuredAddress",
        "^0'({X",
        "!<Qm02",
        "4)|&8",
        "LAOF=",
        "f(xy&",
        "CheckPoint\\ZoneAlarm",
        "bO~j(",
        "AQP2n",
        "-WC]p?",
        "6F7J7N7R7V7Z7^7b7",
        "y0#]R",
        "\\rsid10186454\\rsid10235552\\rsid10246648\\rsid10247180\\rsid10363572\\rsid10364615\\rsid10440212\\rsid10445011\\rsid10445028\\rsid10571992\\rsid10707243\\rsid10708013\\rsid10755641\\rsid10761031\\rsid10821911\\rsid10900124\\rsid10907595\\rsid10946130\\rsid10963403",
        "|e8d[.",
        "HcWvmaq",
        "U*RZ\"",
        "t'ru>",
        " 0xe2",
        "`0K)++",
        "?9P~_",
        "<$y&y(y*y,y8x\\",
        " X,H'",
        "kprUyG",
        "aHgB1",
        "n the original Licensed-server nor its License Key.",
        "Failed stopping Remediation Service",
        "020U0x0",
        "5WLNo&",
        "uf9V-;",
        "PMINUW",
        "DA@^}",
        ".GTN3",
        ">F0pux",
        "n\\ )[{",
        "SystemLanguageID",
        "T24~ ",
        "FeatureIMSecurity:  Error VSReadKeyUninstallInfo",
        "OnFreshAfter:  SetProductMode (again?)",
        "^Cf))",
        "no protocol option",
        "`` h ",
        "_~bDx",
        "C1\"PI",
        ")z:i*",
        "QU3P`H",
        "X\"T;=9",
        "^]V?v",
        "Tg^g=}",
        "SCLA3",
        "Hu*B7H",
        "1S1Tb",
        "recipient error",
        "O2ZVW",
        "4(5-52575?5M5U5",
        ":%;h;",
        "1Q2V3",
        "z%?,*",
        "&Jdqt6Z",
        "Ni_9~",
        "4MgfNI",
        "dYD@X",
        "{$|Iky[?",
        "D8(HXt:f",
        "z(c--@D",
        "; filename=\"%s\"",
        "error setting nbio",
        "T!Bpl",
        "GetSystemDirectoryW",
        "D$TWP",
        "W=QK^",
        "5pQY=_",
        "_.nM,!",
        "=]?9k",
        "id-Gost28147-89-CryptoPro-Oscar-1-1-ParamSet",
        "<<?1{L",
        "M%`K:",
        "l0- =",
        "$JpA+V",
        "SC_UIFRAMEWORK is set to false",
        "AAN+9\"",
        "!\"Yzw",
        "S7G2[",
        ";WSB:",
        ";1UiA4",
        "UN7H)",
        "koTIM",
        "FWUpgradeAfter finished.",
        "6]Wb\"",
        "]8kBgA",
        "N0E3|",
        "r*Q5[",
        "484j4",
        "l+;q}",
        "8;Wbr\"",
        "zCj T",
        "X610hc",
        "ated limits of Your Product license for which You have purchased and provided to users, according to the restricted, maximum, authorized number of users, computer instances (means a computing unit individuated by an instance of an operation system), or co",
        "QIxmBU",
        "W&]q2dH",
        "-5 g4",
        "[e2|p",
        "fffffffffffffffffdfffffffeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
        "=wA{i",
        "S/Je^",
        "%s\\PRHelperIsRunning value was deleted",
        "Upgrade",
        "s ~~7#",
        "PVVVVVVVVj",
        "#!w<Y",
        "rs.\"GaQ",
        "REGEDIT.EXE /S \"",
        "Cuf-`a",
        "t^`B_",
        "del NP",
        "WWW_<",
        "051Q1",
        "SUj>]x",
        "C!nB^",
        "[3Gjy",
        "3,383X3d3",
        "wqy=nf",
        "=X[:@n",
        "zoDIz",
        "req_info",
        "=u?DK6w^s",
        "f*IO^",
        "3CGC7",
        "s%Lt$",
        "mmk2Q",
        "P % S",
        ";p{`rO",
        "7#wes/",
        "?vG79#P",
        "Efs \\",
        "sC3pcG'd",
        "75HzpNv5&R'",
        "!pcR/w",
        "bO$V:Zs",
        "V((c&(d\\",
        "6'AGr",
        "S3}`qcT",
        "h?X@Z",
        ">@>J>",
        "5R6d6",
        "D?tG1\\h",
        ";4Mu<",
        ";!s~=C5",
        " ),OC",
        "0(090N0S0",
        "\\EKEk",
        "49WfU)",
        "PRFRiP",
        "y;yT8",
        "8RuTm",
        "s@P,'VjGVJHk",
        "VerifyVersionInfoA",
        "Pk\\s^",
        "Gc48,",
        "wOEO*",
        "=]>+?",
        "ttgM:",
        "3D$<1",
        "&?[8t",
        "D$$SUV",
        "gS[cRF",
        "OPENSSL_CONF",
        "i3<X'",
        "L$$3L$@3L$,1L$ ",
        ")!)a)",
        ":LA4(",
        "CLIENT_CERTIFICATE",
        "#aPma9s",
        ">%>B>S>h>m>",
        "]Fp`z",
        "0,xka@jKT",
        ":Z'td",
        "th-TH",
        "IDEA-CBC",
        "%N<U8",
        "4\"4/444;4B4_4d4",
        "&p^+C",
        "t.#4-",
        "6e6x6",
        "GNyR2",
        "GdND\"",
        "IlZ\"E",
        "CSeq: %ld",
        ".\\crypto\\bn\\bn_ctx.c",
        "020U0",
        "/6U!q",
        "Cjc*9",
        "sfx(D",
        "x%:vh*",
        "869W9{9",
        "Go>pA",
        "v_mmV~",
        "p:K|L",
        "\"*^iF",
        "_snwprintf",
        "ServicesActive",
        "Z*I4Z",
        ">_|wZ",
        "\\$ VS",
        "EPCBuild",
        "ERROR",
        "Klh1Y",
        "Proxy",
        "Failed to send SSPI authentication token.",
        "X]$C[",
        "C;`Gr",
        "f CMq",
        "A n_a",
        "{[u5X",
        "x{\\g_A",
        "COLLECT_DATA",
        "YBkf v",
        "(%d p:%x t:%x%s) ",
        "za;j4k",
        "P7QaX",
        "SXNoQ\\\"",
        "o)xf>",
        "8B}i,",
        "TMWF3u",
        "P0D4G8",
        "sj*Lw",
        "=A=q=",
        "2`A;/",
        "0m1#2Q2",
        "cZdK5",
        "G{1)Ub",
        ":i<=@",
        "kVB2z",
        ":oEyR",
        "nSF&~",
        "-/)+%'!#",
        "kgq,E{X",
        "[Wcmix",
        "WaitExclusive(0x%x)- 0x%x",
        "cC`Q4",
        "-0^m9bBORN",
        "=iMly",
        ".?AVregex_error@std@@",
        "streamed out file:  %s to %s",
        ".?AV?$buffer@_W@detail@v8@fmt@@",
        "<?xml version=\"1.0\" encoding=\"",
        "R)LLR.",
        "ox^^/",
        "qD#BJ",
        "#8IT8u",
        "6 696C6J6Q6",
        "_cDY[\\tl",
        "W)&$BMu",
        "\"$=\\&Fd",
        "e_;s;",
        "-i#@em",
        "InstallDriver: CreateFile(%s) failed with error 0x%x",
        "7.8a8X9t9",
        "(%JCa:",
        "1qlfj",
        "^(KML",
        "Djv;#c",
        "field too large",
        "S]}AR",
        "<,v$fQ",
        "~oa@<",
        "|5bVr",
        "P$Oh5",
        "vX}%7",
        "a<c^[",
        "C`Ua?l",
        "=?>.?<?{?",
        "%\\<-Q",
        "ECDHE-ECDSA-AES256-GCM-SHA384",
        "SM7ql=",
        "VfA4r=",
        ";(;4;T;`;",
        "t_ARkr",
        "g,S6|",
        "D$hSUW",
        "JN\\(h",
        "acGK@",
        "WcZre",
        "<T<^<h<q<~<",
        "<+<G<c<",
        "Js<Qv9",
        "6%7B7|7",
        "Di5g/",
        "B6'{'",
        "nc\\M,\\\\X",
        "DS_PrepareFACDriver ended",
        "%-'+[G",
        "-<-L-p-",
        "DK!B}",
        "[`cf6",
        "4wJ?2",
        "3L$@3L$,3L$$",
        "VE@V ",
        ":SoD*",
        "GetPrivateProfileSectionA",
        "?DW]tb(",
        "jzwc]",
        "'[C=d5",
        "9+9G9c9",
        "mQvymRtvmS",
        "/D<>CS",
        "regedit",
        "nMQ-h",
        "1*1O1",
        ";]-^8",
        ";1<|<",
        "d5p8X",
        "<3#n.(eD",
        "*h5\\4",
        "nb-no",
        "jzeji",
        "8 FA.",
        "Y;=N`q",
        "'k7?#",
        "gS@?t!!_",
        ":=@)6",
        ",Z(Avbe",
        "q:E8qL",
        "h4hTh",
        "`){)=",
        "\\f1\\fs20\\ul\\insrsid923653\\charrsid7500015  {\\*\\xmlopen\\xmlns2{\\factoidname PlaceType}}Center}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9056778\\charrsid15169477 {\\*\\xmlclose}{\\*\\xmlclose}",
        ">y^sZX",
        "extendedCertificateAttributes",
        "]i/Qa?",
        "%x%B] @&",
        "Failed to %s self protection",
        "-d-G,J[",
        "PMAXUB",
        "`(hdO",
        "YM[oV",
        "time syscall error",
        "6*EvH",
        "m=Glr",
        "uaD;5O",
        "64P[f",
        "\"`D@\"",
        "y6L4U ",
        "MAXSD",
        "?'?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "`.!#@",
        ":h [p",
        "Vm?,^L",
        "Xc7Ir",
        "@q|qBqZ8",
        ")b*IR",
        "fEA)s",
        "ctx->buf_off < (int)sizeof(ctx->buf)",
        "gw9\";",
        "failed to schedule firewall install exceptions rollback",
        "failed to get XmlConfig flags for XmlConfig: %ls",
        "h'J ^",
        "3/3R3u3",
        "&C::O",
        "DKw5B",
        "#KIAwvvT",
        "FIPS_CIPHER_CTX_SET_KEY_LENGTH",
        "q%[@/",
        "V$)azx",
        "3~1/l",
        "3|9S~",
        "DS_RollbackFACDriver started.",
        "CANT_GET_MUTEX_FOR_LOG_1",
        "1 1$1(1,1014181<1@1D1H1L1P1T1X1\\1`1d1h1l1p1t1034383<3@3D3H3L3P3T3X3\\3`3d3h3l3p3t3x3|3",
        "vtAlX",
        "=.>[>",
        "r3B-S",
        "]<[:(7'r",
        "Y}IXfW",
        "4sfgg",
        "lHs}8",
        "\\Logviewer",
        "UWL<0",
        "*#j(&",
        "oU'_h",
        "FlsSetValue",
        "=8=X=x=",
        "Yq.`s",
        "H6njZ`",
        "fieldID",
        "~PRm^",
        "IG5.%",
        "Cr(f=",
        "D$0Pj",
        "8'8\\8",
        "-0L-k",
        "z+~y!T",
        "CP7FFFF",
        "=OKHR/",
        "sFkFW",
        "$xaMuV6B",
        "qyH$3Z",
        "m\"5'}3",
        "=M{KH",
        "717M7i7",
        ")g|;?2c#",
        "mUmVmWmXA&",
        "Jd^uU p",
        "&7S$C",
        "]WWAW",
        "OK;6C",
        "7QPH(4",
        "V!\\m2",
        "b[MTQ/\\",
        "eZUd&",
        "~od~2",
        "CMPXCHG16B",
        "W?'K:#_",
        "3 fR[",
        ":8;R;",
        "9$:T:",
        "SelectionLanguage",
        "y)YLB",
        "<7l)s",
        "gfgNH",
        ")DY*,YK",
        "7^r^Tw",
        "9lA\\'qF",
        "N-YTr",
        "NIST/SECG curve over a 163 bit binary field",
        "0JoA8",
        "Xr^AP",
        " g89Q",
        "E1C\\e",
        "vhVj%Sj",
        "cNls6",
        "){<Ky",
        "8A8%CT",
        "gAl7<",
        "'0.A3s8",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477   ",
        "/c(1t",
        "ECDHE-ECDSA-AES128-SHA256",
        ":f.xj",
        ":D;K;|;",
        "buFb|D",
        "Hp);V",
        "Y8owF",
        "|hT@42",
        "'ZB&-",
        "9zn0*Hz",
        "]Msu>D",
        "9'9,919A9F9K9[9`9e9u9z9",
        "R;lOG",
        "=LY>{K!",
        "D$LVP",
        "GZ8xh",
        "X509_TRUST_add",
        "{8x`E",
        "$ud{_",
        "TCXWw|",
        "~+8#B'",
        "api_ms_win_core_debug_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "#@np5",
        "\"NXbs",
        "qE_>=$",
        "H9iyZ",
        "3,343<3L3`3l3t3",
        "t$@PW",
        "P8ySdp",
        "|*[6:",
        "S|\"p[",
        "+dzJ^",
        "HPG/pwK",
        "^c}PyW",
        "2!2=2Y2u2",
        "CheckTokenMembership",
        "5olM?>",
        "=#='=",
        "7+8l8",
        "26865D15C9687BD49B54A2EB08B51CE3",
        "http://s1.symcb.com/pca3-g5.crl0",
        "$8Ib\"",
        "9@Uw.",
        "944#j",
        "s~~Lo",
        "[@8'n",
        "No registered products, cptray will be removed.",
        "LYzZ+",
        "                operator=\"equal\"",
        ")111h1o1>5E6M6",
        "ASN1_DO_ADB",
        "5I@fd7",
        "&O37g",
        "ii*aX",
        "~c/<L",
        "PatchOldDiscoveryVPN",
        ">k{i{W",
        ">%.}[x]a",
        "py`W7i",
        "CyJpS",
        "7MM;hA",
        "ZdjSu",
        "enabling gina SDL",
        "7%7*7:7J7O7t7",
        "$:`t)T",
        "6WW+G",
        "I8Ttb<",
        "[DUMPFILE ERROR] error %x writing dump file %s",
        "Rq;8I^",
        ">VC<8",
        "{\"IPj",
        "?PWh ",
        "\"[sv<",
        "i+iKiki",
        "6 6$6,6D6T6X6h6l6t6",
        "GlobalSign nv-sa110/",
        "B}!K:",
        ")beAt*",
        ">'?I?w?",
        "ol}g];Y",
        "-$(+hF1",
        "q5hRt",
        "f+\"QQ",
        "!Hx,xY",
        "+QAOI50'",
        "RqH:Q",
        "`DmU&",
        "CM4@PQj",
        "k[^zc%",
        "*@W[aX3n",
        "RSRTRU",
        "VsDataInstHelperOpenDriver - DeviceIoControl(DIOC_PRODUCT_VERSION) failed. Err=%x.",
        "Configuring SmartDefense settings (2 of 5 tasks done)",
        "explicit length mismatch",
        "`8e?\\p",
        ",n|]A",
        "d>v[&",
        "Hy2B ",
        "8A9}9",
        "^cmwX",
        "4QwfsW",
        "5r516H6",
        "696u6",
        "3T$L3T$D3T$4",
        "; <a<",
        "h*U\\P",
        "4@tK9",
        " 0xde",
        "`=\\wf",
        "|78.P",
        "R&aIyL",
        "Sm&!vf",
        ">`Installing '%s' catalog",
        "`pF_t",
        "#\"t< ",
        "GIith",
        "%n#I^",
        "SHA512",
        "UninstallCreatedItems:  Removing registry key HKLM\\System\\CurrentControlSet\\Services\\vsdatant",
        "]FLl/",
        "8;aBE",
        "vi:*\\;1",
        ".\\crypto\\pkcs12\\p12_add.c",
        "=.#h>",
        "AiYHP",
        "8Daz9",
        "Ec.M6",
        "?$?,?<?@?P?T?`?p?",
        "~FCUuP",
        ")5f,h",
        "ZUw`wD",
        "5=5E5T5",
        "kpts`",
        "bad change cipher spec",
        "g.4Yhv{",
        "en-TT",
        "bg-bg",
        "[gY%MY=T",
        "!B+b`q",
        "ZCh:uJI",
        "aCfe4",
        "lQ5jO",
        "TaZZ|",
        "ASN1_TIME",
        "3'3Y3a3",
        ">8>D>d>p>",
        "lMRj{",
        "+!3HsX",
        "aOXdx",
        "464L4o4",
        "lGAIl!V6",
        "{@ih*",
        "mvez\"",
        "jjjfj\"",
        "|6E`F",
        "$-`T.",
        "Ct5x]",
        "hgv1=n",
        "U`Pl@",
        "Kq#j\"O",
        "@S~=I1",
        "1,1\\1t2",
        "X9.62 curve over a 359 bit binary field",
        "TaA=V7Z",
        "set-brand-Novus",
        "Ar0Ob",
        " X@[S",
        "k(k8kHkXkhkxk",
        "lRhn.",
        "?&?k?",
        "d~1.(",
        "=cAX6*",
        "4Dk,j",
        "d8f(M",
        "<\"=<=f=x=",
        "&)(kL",
        "C,[_^",
        ":v=,>=>",
        "=N>k>",
        "$s}d<",
        "WoVo\\",
        "hIT4P",
        "(,8Ru>",
        "np?z ",
        "H0I:i",
        "ZS?Mi",
        "MsiRestartManagerSessionKey",
        "T>TtV",
        "*A~:S",
        "Im&mDk",
        "..w\"E",
        "Ucvj>",
        ",D}DX",
        "5:5?5e5",
        "z><R?l",
        "WHs${",
        "NFY*#",
        "GetConsoleOutputCP",
        "'tQ)9",
        "k@_}%x",
        "X;3#qV51r1#",
        "4 4&4,42484>4D4h4",
        " z3JO",
        "m8E}2",
        "DV,0s",
        "^n'Y@",
        "Xp\\K!v",
        "3S2Z9",
        "Fg'?k",
        "}8nS#",
        "As<6Z#",
        "r2X#Q",
        "}!]0^Q",
        ">$>,>4><>D>P>p>x>",
        "wAX:i",
        "uo'KO",
        "yeP)b",
        "a~\\A$",
        "failed to get shortcut attributes",
        "o#3Nc3{O8",
        "@w082F",
        "Ignoring error in Rollback",
        ":\\:|:J;a;",
        "fMpP&A",
        "8JBd=",
        "RSA_padding_check_PKCS1_type_1",
        "1Jb\\W{",
        "e{8?9",
        "~4~B~Ned",
        "bAmrA",
        "V+3u6K",
        "7ieZAr",
        "LlFHt",
        "VWhh\" ",
        "5X5]5",
        "?f=u{",
        "LB@wR",
        "NJd4jB",
        "This installer database contains the logic and data required to install Check Point VPN.",
        "6*666J6`6",
        "\".}tOT",
        "#`cC# #",
        "failed to create output pipes",
        "/?LvN",
        "5[EDM",
        "O\"|b/",
        "?JVoQ\\G$/",
        "^q2~l",
        "dWqP&",
        "jCjsj",
        "trac.ddf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "M>BMZ",
        "'HtH2q",
        "F|'\\s",
        "9wcmL",
        "3`?Bh",
        "vb_`|",
        "KsF?M",
        "m,?aB",
        "BDsca",
        "<C 5'",
        "Y_GZDTkpQ",
        "cH)TzL",
        "Fxoahqc",
        "Eayv4",
        "BEOS_BIND_VAR",
        "0)1]1",
        "9(90989@9D9L9`9h9p9x9|9",
        "RPK'-",
        "6<v]{",
        " #x{r9",
        "x!T#h",
        "yXdWpJ",
        ",juKe",
        "Ze5WQ",
        ">w<K}",
        "q,]W$",
        "a%c%eK",
        "1+1=1O1a1s1",
        "id-smime-aa-smimeEncryptCerts",
        "ijC8I`",
        "7O7[7",
        "V,u/O",
        "<CONFIGURATION>",
        "8x'^(",
        "3Q#2?",
        "25cj=",
        "9)iM6",
        "2=3r3",
        "cdOA7",
        "T$X3T$<3T$83T$ ",
        "_____5",
        "=_N@q",
        "[LICENSING] SetKeyInRegistry, key found = %s, value not found =%s",
        "'<fb3",
        "^watI",
        "5QYt>",
        "*@9Cic2",
        "M;(IQM",
        "XlL\\m",
        ">=>R>b>o>",
        "Q1L$$",
        "UG&,m&",
        ".?AV?$moneypunct@_W$00@std@@",
        "a=j[y<$ib%",
        "=1#Kgd",
        "67p{y",
        "1.2D2",
        "P<I-S8T",
        "565E5h5",
        "Qfp([",
        "U_!_a",
        "R+CjqU",
        "a7Fpt|",
        "1]nKw",
        "n}\\0p",
        "XwOxd",
        "WHvr~",
        "4X4u4z5l6}7",
        "failed to create Internet shortcut",
        "DH-DSS-DES-CBC3-SHA",
        "STREAM_ERROR_FETCH",
        "%s was deleted",
        "}5Tv$",
        "}%c\"<:",
        "Oa.eqG",
        "Tyo0bDa_",
        "9!9F9Z9n9",
        "|p/O>",
        "4x+?r",
        "&Md>d9t",
        ".\\crypto\\bn\\bn_exp.c",
        "#m=m|",
        "xH@'4X",
        "B++]Ct",
        "CbCcCfCgChCkCm",
        "Mf7rX?]",
        "5fTFh",
        "0In*U",
        "JQDw?^",
        "$FFb?",
        "Y I\\$9",
        "AIErvh",
        ")@RM*",
        "IQKuE_",
        "\"h#}6*",
        "979W9w9",
        "9$9+9:9H9^9e9t9",
        "fwcpp.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "GkS/D",
        "!}iid",
        "failed to write create element action indicator to custom action data",
        "= =J=|=",
        "%swix%s.*.???",
        "B}-q$[",
        "FV%Rz~",
        "Hzex|N",
        "rCC?j",
        "EVP_PKEY_encrypt_init",
        "4F4v4",
        ")ejek",
        "@}!7W",
        "{Q~BJ",
        "_g$#e",
        "393U3q3",
        "?$?,?4?<?D?L?T?\\?d?l?p?x?",
        "8@Ly/L2",
        "Lx*9I",
        "dN@ff",
        "qo.EO",
        "d-Ui.",
        "wz_0]",
        "PKCS7_add_certificate",
        "rTp\"G",
        "aBgY%",
        "X]tB9",
        "+8b7+",
        "[=MXHy",
        "GetFullPathNameW",
        ";5<N<",
        "1:1h1@3",
        "aj}N[!T",
        "?dsVM",
        "<4Qbt",
        "DPF!<",
        "T|S8s&u",
        "k >Pi",
        "D_Zd@4",
        "0d0h0l0p0t0",
        "&S6d=",
        "_)QkMK;",
        "aG2hMw,",
        "BLENDVPD",
        "]PH3-",
        "5[fIU",
        "BQzb-",
        ">Gslt",
        "r. /H",
        "5mQk1",
        "^m}Uwb",
        "(o&$[",
        ">voj7k|?,",
        "=Kb2VsF$",
        "xpauE",
        "D$4Ph(]\"",
        "distpoint",
        "^tdzf",
        "4+5o5",
        "=m$-E",
        "R37cs",
        "k^.s(",
        ".oRl4",
        "==s7y",
        "****************************** SSOClean started **********************************",
        "qV8x[",
        "^c0\\[",
        "555e5",
        "wscsvc",
        "}eJ0Im",
        "&fwN~)=l~~t+",
        "tUL62F:N",
        "Tr1;s",
        "2K3[3c3",
        "p]-x(MUta",
        "VZ_4UK",
        "EjSp|",
        "+AIB\\",
        "8pp_h,",
        "Bm;YF",
        "key copied =",
        "[PERFMON] error %d getting ITVPerfCounters from provider %s",
        "GS*r~",
        "3\"4/4",
        "-!\\Q4",
        "f[R`1",
        "<:`C6zW",
        "Ss+;%",
        "1bE}$",
        "{:a(t",
        "9U9J6",
        "\\b9dI",
        "CMS_SignerIdentifier",
        "5 5$5(5",
        "oqNC:",
        "ZzNpDf",
        "2[2e2",
        "'VEF r",
        ")K/Bz7i",
        "p2b^L",
        "~h(p'",
        "bW2xGV",
        "*YY>S",
        "$PbTj",
        "0,040<0D0L0T0\\0d0l0x0",
        " sG17",
        "\"6vPaO",
        " yG-4>\\",
        "3Z2yd",
        "Registry",
        "%5nO%",
        "Going to create the file %s",
        "address=",
        "zCX*/*",
        "f,Wle",
        "%$%2%<%F$L",
        "l?ZCA",
        "(>R@4",
        "QBDte",
        "9r:~:",
        "zYDk0-B",
        "03[nS",
        "\\A<3YUH(3",
        "PEM_read",
        "RE#9>",
        "Helper::stopRemediationService",
        ",l>i%",
        "3 6LN",
        "[EW+$",
        "%FIdv",
        "Initializing",
        "b\"XxQ",
        "_@pu.Q",
        "/zQhyQ",
        "0&E~<",
        ":\";H;p;",
        "vsdata.dll.1",
        "3&303_3t3",
        "cgSp3",
        "Neon.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "Zo,a6",
        "n2SfV",
        "GetDiskFreeSpaceExW",
        "L5(Uu",
        "\",07j",
        "$CZM7",
        ">_jXI",
        ";aD7G",
        "za|{Dm,E",
        "PSHUFLW",
        "6E7P7",
        "293}3",
        "handle scv pugin file %s",
        ";$;.;2;<;H;T;`;l;x;",
        ".ex!k",
        ".?AVinvalid_scheduler_policy_thread_specification@Concurrency@@",
        "^_][Y",
        "G_\">I",
        "RTS1I",
        "gk%<[E",
        "3[B%J0",
        "\\ab\\af1\\afs32\\alang1037 \\ltrch\\fcs0 \\b\\f1\\fs32\\lang1033\\langfe1033\\kerning28\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext31 \\slink32 \\slocked \\sqformat \\styrsid13065977 Title;}{\\*\\cs32 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b\\f36\\fs32\\kerning28 ",
        "z=BsB",
        "T4[d*Z*",
        "9TyjF^",
        ":,:8:X:`:l:",
        "+WGq&",
        "hy-AM",
        "failed to columns for table: %ls",
        " 0x6b",
        ")h^H)DS",
        "b738I",
        "+ic%\\",
        "BASES_DIR_FOUND.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "219p}y",
        "(u!+}t",
        "y3+I5",
        "r[n+>",
        "JjGU*",
        ";!;1;A;a;q;",
        "<R=[=`=r={=",
        "*vJQdN",
        "-j/[L",
        "HeTV Z",
        "9Ls*a",
        "userCertificate",
        "IBd0`",
        "YK#6+%\\",
        "? ?0?4?8?<?@?H?`?d?|?",
        "e^Ba&",
        "y%d}k",
        "; ;@;L;l;t;|;",
        "X509_REQ_check_private_key",
        "\\drivers\\ccore64.sys",
        "Gq^<y.S",
        "lL;93",
        "-lMiQ",
        "1=HaS",
        "missing dh key",
        "9,9P9\\9d9|9",
        ",b%|Dz0",
        "U\\3ms",
        "Way|nuL",
        "'z]DT",
        "}fb9#M4",
        "4Y1(\"RB",
        "7ot'pD",
        "OpenProcessToken failed: %u",
        "@;4\\@",
        "msgsigdigest error",
        "{;hvi>i",
        "on.#m",
        "PostQuitMessage",
        "ENGINE_load_ssl_client_cert",
        "o_mz@",
        "$;>9cE",
        "=U0Rn",
        " #&U7",
        "|$H$t!j]hp",
        "6e)WlZ",
        "lhk,cO77",
        "SNhfah4",
        "{f]z=",
        "UCWSWcWsW&O",
        "failed to write application path to custom action data",
        "EGDl@/",
        "G=yUv)",
        "M+a$G",
        "z=\\s|P",
        "##D=lM",
        "\"bF]_RM",
        "olmcD",
        "wk:G}S",
        "o4 E3",
        "?cT+i",
        "SOFTWARE\\Classes\\Installer\\Features\\3CEF7BE31A8A3AE4F8E4A8D671289E7F",
        "<S:IN|",
        "HEVoZ",
        "MOVLPD",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regvalue.cpp\" line:  20",
        "lmguardsvc64.exe",
        "X509v3 CRL Number",
        "4)4F4",
        "s`6mB",
        "2UnDPw4I",
        "93v%.oI",
        "sect239k1",
        "<(<<<B<",
        "u`9L$$u",
        "8+G z",
        "EndpointSecurity",
        "44484P4`4d4h4p4",
        "QQQWPQ",
        "0fWjh",
        "RLVXQ",
        "f074481847bd804859b5e696007d4b4edfc150b12addbecba6b18b148a1e54d1bc81392f23b7f84137c2715a851dd0242a633f900710a218ed715505dfe56e86",
        "9{;k5",
        "}!O%\\[",
        "2J3i374X4",
        "|!1sb",
        "X'cCv",
        "d.x400Address",
        "D$DPj",
        " -password ",
        "X\"QIO",
        "v8>h2-",
        "x&2@@",
        "1F$F\"",
        "7#7D7]7",
        "URPQQh`ME",
        ">Fkf{",
        "u0AN[",
        "VhXt1",
        "3v:xRt",
        "tSj[h",
        "iC9UV",
        "rMInv",
        "0$^J&@",
        "runOldInstHelper;",
        "x%Jo%.\\r.",
        "3%3*3P3v3",
        "tls1_change_cipher_state",
        "]&Zn)",
        "JMS/c61",
        "]#ICM",
        "[VSDATA LOAD] SetEntriesInAcl failed: %d",
        "uq5}w",
        "0$000P0X0`0l0t0",
        "Hb^@D",
        ".$$BY00_W",
        "Ud;>6",
        "2#4]4",
        "Z';SPs",
        "(>ghIu",
        "x3+**",
        "[2pJ0 ",
        "}Ed'y",
        "boH8^",
        "oc+C;",
        "2%20292_2j2s2",
        "]czeN%?!",
        "e5Z`z",
        "Set string key ",
        "=<=H=h=p=|=",
        "3rZGv",
        "=\"=1=7=M=Y=h=n=",
        "            eventgroupref=\"%s\">",
        "vsutil.dll.1F357923_E5ED_4F4F_9B28_B146153C7446",
        "`i\"Jf",
        "(Ad:X",
        "=iZL#",
        "2^)mO`",
        "u<j]h",
        "3nSWRn",
        "?j*IRB",
        "\\DSR0A",
        "beS=l",
        "1prA$",
        "DNLdG&",
        "_Mde`",
        "wrong lookup type",
        "2-203",
        "4S5x5",
        "$_^[]",
        "Sf5I`",
        "_M%)]",
        "operator co_await",
        "1(1<1H1",
        "`Bw$Y",
        "tAF14",
        "O8I^=);!Y#l",
        "kiFTR",
        "\\`t|-",
        "nonRepudiation",
        "@8?tY",
        "\\5GW1R",
        "FAb b*b4",
        "A68Vo",
        "++S3B",
        "60FlnZ{G",
        "A3xeo",
        "p\"}sU:Z",
        "B/2Q-x",
        "xzgfdw",
        "*I.E2E",
        "H6:mlZ",
        "{AA.i2",
        "&?~YK|",
        "0GhN;",
        "api_ms_win_crt_process_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "[KG_V",
        "dU:6x,,",
        "Certificate",
        "pn=-A",
        "3f3s3",
        "yz0=~8",
        "g,r9.*",
        "PKCS7_add_attrib_smimecap",
        "@;e^U",
        "<tMJt0",
        "3v|eR",
        "peer key error",
        "o2 3L",
        "3^oK#J",
        "Ga`i,",
        "Nr&x=",
        "@%bQ]B",
        "5^n*]",
        "$5I*B",
        "v`aH3g",
        "?lQlP",
        "failed SysAllocString for name",
        "5+525E5",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\featureeap.cpp",
        "y2R<#",
        ";8\\!UU",
        "SEC_I_CONTEXT_EXPIRED",
        "2 q:O",
        "X){(a",
        "+E}\"Sj",
        "id-smime-aa-receiptRequest",
        "=Kxb$SW",
        "((((((((((((((+(",
        "o*$;8",
        ":1:@:_:n:",
        "7~voB|",
        "]#R#U",
        "        Validity",
        "DATABASE",
        "5 5$5(5,50545H5L5P5T5X5\\5d5h5l5p5t5x5|5",
        "J:o>u",
        "%sHWMonitor.dll",
        "-24bkX",
        ";?$A>r",
        "5.6F6a6l6",
        "Helper.stop() failed",
        "+>y#D",
        "IhC5L",
        "W2-NyTH",
        ",w&Z<",
        "u RP3",
        "6)6:6P6_6p6",
        "RR}:W'",
        ",%c OB",
        "(\"n-c",
        "R[6BT",
        "IM-tX",
        "gJ\".#i",
        "NrzMy \"5",
        "8 8(80888@8H8P8X8`8h8p8x8",
        "@~P;m",
        "failed to write delete value action indicator to custom action data",
        "+LVD6",
        "XxX5P",
        "zUO!Q",
        "u VWS",
        "YfyKz!",
        "b4N$q",
        "AUK0t",
        ">I?V?v?",
        ",,s?~",
        "WBbNnUB",
        "5:5o5",
        "0/0?0K0Z0@1'2.242:2@2F2L2R2X2^2d2j2p2v2|2",
        "temp file name length is zero. aborting.",
        "-0UpyPy`j",
        "|X~{+a",
        "yB5Ns",
        "5!Ooc",
        "uPQ'^",
        "\\system32\\",
        "= =?=S=",
        "_\"s^M",
        "tHSVWP",
        "\\`<;m",
        "N,<4uJ",
        "2o5u5{5",
        "s1m@P",
        "s?#O?;",
        "#UYk=y",
        "0,0O0d0z0",
        ":Z+yu",
        "&(j_h",
        "WH@1t",
        "A'qQU",
        "'w*:!",
        "JGXi|7",
        "aSd!R",
        "8y{ZW",
        "q'%Y,4",
        "9f:t:",
        "^gyU_",
        ",LCK7h",
        "<0<P<a<",
        "atSp'",
        "|E6-3",
        "DS_RollbackFACDriver",
        "NCkb;",
        ".rp*E@",
        "<+<<<M<e<o<",
        "4!5y5~5",
        ")/c)<$",
        "aes-128-cfb8",
        "kF_;(",
        "b!#\"D\"B%'h",
        "rEEYK+",
        "j|juj\"",
        "}R*$M",
        "Plugins::UnregisterAM:  Unregistering ",
        "OzM[hc",
        ";F<4=+?",
        ",!:_{",
        "8@u)@",
        "*U:TM,",
        "P'Gza",
        "nZ*8V",
        "!z!Yz-",
        "b&.9zM",
        "public key decode error",
        "hZ:>g;",
        "uW_W$",
        "+N(jq",
        "/=C}&=",
        "3\"5,5[6",
        "MUXH@${<!",
        "DEK-Info: ",
        "FW^dcj",
        "y\">,r",
        "DwpD0M",
        "WU)N0",
        "invalid digest length",
        "ilRdV",
        "]qC~a",
        "-?)dm",
        "qHDzH",
        "?b4^QQ",
        "Dl.\\crypto\\ex_data.c",
        " 0x1e",
        ">!>&>8>?>F>M>",
        "@( qB",
        "<&Q]}[",
        "<KAVFileProtectionON>",
        "8E0Tp",
        "YG%82",
        "kT8EE",
        "CONNECT responded chunked",
        "BN_bn2hex",
        "m2RAa",
        "+h,4M",
        "uN5P-",
        "omtiU.P/",
        "4ZMk..r7",
        "6d6r6",
        "x(j.dwo",
        "5(5@5E5J5e5",
        "t~;Kph",
        "vQ4;9",
        "CANT_OPEN_QUIT_EVENT",
        "b?l}5x\"D2",
        "dS0rp",
        "{Yr*a+",
        "GklUJ",
        "XV,m~S",
        "#X}HD",
        ",qwWb",
        "UninstallAV",
        "[4K:;",
        "112Y2",
        "u/^<P!",
        "ogC9w",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid5917669 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3875139 ",
        "t;(,FQ",
        "X8<^@",
        "%SS22%",
        "@+npm",
        "WTSGetActiveConsoleSessionId",
        "H*27k",
        "3@piU",
        "timeout.exe /t ",
        "Home China",
        "D2Bz!",
        "Unknown error",
        "xPS8h",
        "(P >;9a",
        "?/?K?g?",
        "atlTraceCache",
        "con_register_pis",
        "u:j]h",
        "Failed to read from ca script.",
        "/laYY",
        "xE0Y8K",
        "L%});2;",
        "-!__yF",
        "AR~EO3",
        "5S$a([0",
        "NO@o.O",
        "b]PKpq",
        "3&2Bhx",
        "=8=H=N=V=c=o=|=",
        "/^b:C",
        ":k2hu1",
        ";e3(_",
        "G{AW;",
        "sG7]Z",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid9516106 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 ",
        "FIPS_CIPHER_CTX_CTRL",
        "s$*G?",
        "Failed to stop service %s. error %d. Wait 1 second.",
        "Ph4)M",
        "j@k t]",
        "\"wQ2n",
        "OK#I>>",
        "8!:=;",
        "\\_n1e&j",
        "Vl|y(",
        "z-]hG",
        "2D2{2",
        "#v&i}",
        "MnlTP",
        "i40N ",
        "ADDAV",
        " 0x1d",
        "6sdl~s[",
        "1 141",
        "u`>36m",
        "4?5V6e6",
        "_Nhw=@z",
        ")0P45",
        "Ao>{k",
        "@53NH",
        "G:N)5",
        "O<S4\"",
        "TYM_Y2",
        "Ec]k4",
        "1XqXWwq",
        "IU'eE",
        "n_&bF",
        "nJz!W",
        "JP*hz",
        ")6AVo2",
        "7v8B9B",
        " N!c*",
        "S2izzH5$6",
        "YY'NN",
        "%gK>0",
        "c)`\\,F",
        "~s%:[2",
        "v+2}P!",
        "FLVQ$",
        "t5z~-",
        "W*17v",
        "~~UIE",
        "3yIg+",
        "`Rpx-",
        "Pd`;$",
        "v/hQ|",
        "khR^g",
        "|\\X5J",
        "/l}fH",
        "]zz\"s",
        "w6TRH\"$",
        "CMS_Attributes_Sign",
        "/'L0m",
        "GetSystemTimePreciseAsFileTime",
        "szZoneLabsDir",
        "al9?q",
        ".)kvT",
        "W5-:b",
        "JU7Y%%",
        "gS#.#",
        "0!050",
        "Delete file: MsiOpenDatabase",
        "647D7~7",
        "]P)P8@q",
        "2$8W|",
        "R6009",
        "5C@3YQ",
        "'VynL",
        "6m~}ZB",
        "/j*ti!",
        "7T/g_",
        "agFh&6k",
        "ekB7$I",
        "^(IP~",
        "q0@}Kc",
        "<4<@<`<l<",
        "\\:k;2",
        "Failed writing RTP data",
        "amfG.7T",
        "quz-BO",
        ")J bJ",
        ":%:8:?:\\:b:m:v:",
        "n`oF)",
        "0W7_e",
        "pxuT@",
        "~1Wwp4",
        "B>cxi",
        "WK`1ru",
        "M)'KR",
        ".\\crypto\\asn1\\a_bitstr.c",
        "U~fB6\"",
        "6,6<6@6H6`6p6t6x6",
        "NdO$4$",
        "Greater Manchester1",
        "*~K/4",
        "7(7,7<7@7P7T7X7\\7d7|7",
        "8\\8c8l8",
        "FWUpgradeAfter.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "Content-Length: %I64d",
        ">zZ>CY8",
        "Upl4w",
        "=U=\\=g=:?",
        "8t<t@t",
        "|<&`o",
        "tKgB!",
        "tff4&F3",
        ";!;&;@;E;V<h<F>U>",
        "P07Z\\+",
        "+)@tLT{vN",
        "brainpoolP192r1",
        "oA16)",
        "ZwOpenThread",
        "jAbJj",
        "BY_2(",
        "3s,CO",
        "kQAD&",
        "SCRemovePrepare",
        "S+'g>",
        "H?{!W",
        "<b{x7teo",
        "53Q+>",
        "CyCegV&A",
        "Bad file descriptor",
        " 9<.w-",
        "[LOGMON_PROXY] dumping ...",
        "6|6gJ",
        " refurbished and equivalent to new, and shall be warranted as new for the remainder of the original warranty period. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid5917669\\charrsid13774068 If a }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid11819894 hardware}{",
        "nqW4 ",
        "MPQOQJ",
        ".X=,o",
        "jAjtj!",
        "x\\pUd",
        "bC/z!B",
        "zp;bH",
        "FjTXF",
        "wCZWz",
        "OpenSSL 'win32' shared library method",
        "e!#DT",
        "bsdrT",
        "/{~I{#",
        "&BX3o",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 iolation.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "x4k&k5'a",
        "7Y#Vu+",
        ":o ].id",
        "AUTHORITY_INFO_ACCESS",
        "_XkNA",
        "j 4hb",
        "6LJBJ&",
        "k@rhoW",
        "NETSCAPE_SPKAC",
        ".rtc$IZZ",
        ":%:0:P:",
        "8ClnUm",
        "h%(%E",
        ":2;R;a;};",
        "asG/A~",
        "UxLxQ",
        "Y,){;",
        "[0j\\qA",
        "qz$l:",
        "not REMOVE=ALL, no need password",
        "0I0[0g0u0",
        "y}x}y",
        "? {qs",
        "z9hX:",
        "171t1",
        "8aJ['",
        "9)9B9[9t9",
        ")^-Do",
        "#L$(#T$,",
        "^XJ&}",
        "Z9@}n` D",
        "D$(Phl|",
        "SOFTWARE\\KasperskyLab\\protected\\AVP10",
        "<L=a=",
        "kJ)Q1e",
        "6R6\\6",
        "2'21282B2I2S2Z2d2k2u2|2",
        "L[57g",
        "3!4A4Q4q4",
        "_)eX'",
        "K7KW[w",
        "9UVh0",
        "7(8D8H8",
        "M/FB3",
        "9J9y9",
        "?91t$",
        "5748V",
        "1T2^2h2r2",
        "<EX%(",
        "G(\\N?yV",
        "mUGB(+",
        "88=>d;",
        "[,i33L",
        "_o&u@",
        "G]CQW",
        "l_& aF",
        "#Sectigo RSA Time Stamping Signer #30",
        "3D4J4",
        "[VSDATA] FreeDataClient: wait failed with process id - %d, and thread id - %d",
        "BiV=v-0\"",
        "logonToVsmon;",
        "bOcu?7B7,",
        "\\>F\\*r",
        "d6:e{",
        "vB:G) ",
        "r3e+-",
        "?<!9,",
        "?,?2?E?K?^?d?",
        "D$ Ph0",
        "%GHAU",
        "gstE^Mf",
        "[~MH-8",
        "QI3:BD",
        "IswRecursiveThreadSpinLock::TryEnter: _ctx.recursion_cnt = %d < 0 (owner_tid = %u)",
        "control connection looks dead",
        "h`?z`",
        "@|$.c{@",
        "0<0M0Y0",
        "~OUW3",
        "ybO0E",
        "tWWUU",
        "P-J8O8",
        "GZ&l#",
        "AES-192-CFB1",
        "B031k2",
        ",`.o&",
        "Rp<$;7",
        "-O0-V",
        "595U5q5",
        "2%383\\3f3o3",
        "LanmanServer",
        "\\lsdunhideused1 \\lsdlocked0 index 2;\\lsdunhideused1 \\lsdlocked0 index 3;\\lsdunhideused1 \\lsdlocked0 index 4;\\lsdunhideused1 \\lsdlocked0 index 5;\\lsdunhideused1 \\lsdlocked0 index 6;\\lsdunhideused1 \\lsdlocked0 index 7;\\lsdunhideused1 \\lsdlocked0 index 8;",
        "W1I{2hT",
        "QA<nQ@!",
        "Vj;K?",
        "U%2jV",
        "7!1Lf",
        "$34?>",
        "7C;:d;",
        "pl!$TN\">",
        "3|$,!",
        "Y?_&}",
        "W|/p.",
        "U82odv",
        " ]Y:w",
        "E*(Spa",
        "?:G/H",
        "Couldn't use specified SSL cipher",
        "w4;M]",
        "JO'}~^*",
        "'T1KIT",
        "j-91d",
        "AES-128-CBC-HMAC-SHA1",
        "FAC driver Uninstallation failed with error: %d",
        "table loaded, wrong version = %d, current version = %d",
        "JjlZf;",
        "OnInstallDriverBegin.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "float",
        "NVVd2",
        "RegisterClassExA",
        "c5s#Q1}f",
        "H>Jf3",
        "t]=A'",
        "bL;gd",
        ": :0:;:f:v:",
        "SeS>S:S6S4S2S1S/S-S+S*S)R(",
        ":S;3<",
        ")FBFBY",
        "kEe9|>",
        "\".C}f",
        "O'6\"A1",
        "j-h?w",
        "Oz>hp",
        "hE@Vz",
        "586C6",
        "'/PCX",
        "9fd%?",
        "b>Mdw",
        "< >$>(>,>0>4>8><>",
        ",C}T\"",
        "description",
        "Z8;)R!D",
        "e8,29",
        "k:(MW",
        "E\"JpR",
        "-td22",
        "%bl(h%N",
        ".?AVInternalContextBase@details@Concurrency@@",
        "Z,RY?#",
        "P=~~8",
        "/V_CJ",
        "6/797V7g7",
        "gE\\Y;",
        "|z`).jvT",
        "vy(<%S{",
        "zG(8j",
        "J'8't",
        "gobKp",
        "ri-*Ss",
        "7%7J7R7",
        "7'QOl",
        ",bZJt",
        "InstHelper process handle is signaled.  It died?",
        "Eijxf",
        "6km<3",
        "^MU[/",
        "W5;GU",
        "a*aq(S",
        "^0jMP",
        "5LZN.+",
        "ReleaseSemaphore",
        "2USb*",
        " ATAI",
        "l:uN^",
        "(<Iqt!",
        "Wk&fB",
        "Hkac{",
        "EUt:*",
        "Z?}8u",
        "$-}Hi",
        "~V$!E",
        "C/-%]Z",
        "Wx/pNMT",
        "lTxsK",
        "Br@2}",
        "n/D>[v$",
        "89z*;",
        "mHZ7?i",
        "1j}>?",
        "l==:^w",
        "V5e?:",
        "< <$<(<,<<<@<",
        "l\\IJ38",
        "SCRemoveAfter finished.",
        "sP/ J>/",
        "%Zlz?",
        "rP1S$",
        "9]op\"b[g&/",
        "|0m>k<",
        "H:-core-timezone-l1-1-0.dllapi_ms_win_core_timezone_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B31ixtxe2b.dll|api-ms-win-core-util-l1-1-0.dllapi_ms_win_core_util_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3abdcmc3v.dll|api-ms-win-crt-conio-l1-1-0.dllapi_ms_win_crt_conio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3aunl2qua.dll|api-ms-win-crt-convert-l1-1-0.dllapi_ms_win_crt_convert_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3glpulfxs.dll|api-ms-win-crt-environment-l1-1-0.dllapi_ms_win_crt_environment_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3iurqmcpy.dll|api-ms-win-crt-filesystem-l1-1-0.dllapi_ms_win_crt_filesystem_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3scnfeby5.dll|api-ms-win-crt-heap-l1-1-0.dllapi_ms_win_crt_heap_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3uuneguxg.dll|api-ms-win-crt-locale-l1-1-0.dllapi_ms_win_crt_locale_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3gtrmocu6.dll|api-ms-win-crt-math-l1-1-0.dllapi_ms_win_crt_math_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3-dhtxh0m.dll|api-ms-win-crt-multibyte-l1-1-0.dllapi_ms_win_crt_multibyte_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3q4wos0qq.dll|api-ms-win-crt-private-l1-1-0.dllapi_ms_win_crt_private_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3egmsyt8w.dll|api-ms-win-crt-process-l1-1-0.dllapi_ms_win_crt_process_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3s3w2ao34.dll|api-ms-win-crt-runtime-l1-1-0.dllapi_ms_win_crt_runtime_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B36lbqhfa7.dll|api-ms-win-crt-stdio-l1-1-0.dllapi_ms_win_crt_stdio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ixkjsdfd.dll|api-ms-win-crt-string-l1-1-0.dllapi_ms_win_crt_string_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B36all5l1t.dll|api-ms-win-crt-time-l1-1-0.dllapi_ms_win_crt_time_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3lxtlxxgx.dll|api-ms-win-crt-utility-l1-1-0.dllapi_ms_win_crt_utility_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ucrtbase.dllucrtbase.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3{42F41217-AF8B-33D4-9CB3-FF5F696BECBB}{E8E39D3B-4F35-36D8-B892-4B28336FE041}{A2AA960C-FD3C-3A6D-BD6F-14933011AFB3}{A2E7203F-60C2-3D7E-8A46-DB3D381A2CE6}{BC0399EF-5E9D-3C7C-BFF5-5E9A95C96DAF}{9FC931F8-9ED1-3263-A0F1-8ADE330D0ECE}{0200CF79-B9A1-3BE4-955A-29FA9D4B1A5C}ALLUSERSDirectoryTableDirectoryTable100_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "\\#'y#",
        "ASN1_TBOOLEAN",
        "%s copied to %s",
        "BQrr_",
        " /PlbD",
        "m[YIj",
        "2JJJi",
        "qnM,r",
        "Gf+~;",
        "/x52,G",
        "AM^}@~",
        "9]c\\\"",
        "h6l*yQ",
        "iii93U",
        "J|EV ",
        "^L5zf",
        "l1NEr",
        "FHPSW",
        "8r8|8",
        "it-ch",
        "pk_[<",
        "Zim'W",
        "u*97t",
        "595I5",
        "_A2s%*G",
        "e:xCpx!",
        "/i %s",
        "fC;\\Z86",
        "AAI9}",
        "L*%M^Qq",
        "F{]\"K",
        "Nog^/",
        "SrPH<j",
        "o1TJ0",
        "t2%=q/",
        "4o/Dv4",
        ".uen+",
        "<$(+m/#",
        "?a'bWk.dl",
        "t}P>7",
        "Looking for %s",
        "hB<RW",
        "H\"r}7",
        "D,Pk\\",
        "=6===I=V=",
        "uW['!",
        "\\lsdunhideused1 \\lsdlocked0 Table Columns 3;\\lsdunhideused1 \\lsdlocked0 Table Columns 4;\\lsdunhideused1 \\lsdlocked0 Table Columns 5;\\lsdunhideused1 \\lsdlocked0 Table Grid 1;\\lsdunhideused1 \\lsdlocked0 Table Grid 2;\\lsdunhideused1 \\lsdlocked0 Table Grid 3;",
        "(vA#z",
        "SAVK0",
        "o`'2W",
        "restart",
        "2YN^Z",
        "[VSINIT] %s: Wow64EnableWow64FsRedirection failed with error %#x",
        "F6FFFFFF",
        "uchN+",
        "5Vq@#",
        "%F,n/.",
        "L(ED)",
        "Failed to allocate memory for empty previous privileges.",
        "}K 'sxpb",
        "DEF_LOAD_BIO",
        "DP8Ll+O",
        "unable to get certificate CRL",
        "b_BY1t",
        "STOR %s",
        "TVdebugLog",
        "'8Pes",
        "vsutil.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "0^-P_",
        "aux error",
        "=7=n=",
        "g8hB$",
        "=@G,^",
        "DvYNs",
        ")mZ[BM",
        "B'M2].",
        "OpenSSL ECDSA method",
        "b.?)v",
        "<$<~<",
        "m-$9g",
        "]_]7<",
        "Failed to copy vsdata.dll.",
        ":46RC",
        "}&KlOH,*",
        "ED$LPS",
        "missing rsa signing cert",
        "D<L,o",
        "$BtrC",
        "jfjfj",
        "liI2\"",
        "SEC_E_LOGON_DENIED",
        "ND#j*",
        ".?AVScheduleGroup@Concurrency@@",
        "4SNGiK",
        "vOd;]",
        "encryptedKey",
        "VSd[x",
        "H:{v;*",
        "id-smime-mod-ets-eSignature-88",
        "~`[IF4",
        "[VSUninstallProduct] cannot log into vsmon",
        "TBWB'",
        "Y@'$7",
        ":,lI~S",
        "Pd%v5",
        "T#T+T3Q;H",
        "9P'5}",
        ")a&j s",
        "g4fUUV3e",
        ".?AVbad_optional_access@std@@",
        "=I>M>Q>U>Y>]>a>e>i>m>",
        "zBxrb",
        "n5Naf",
        "`EA!=",
        "ation] 3rd party or non-work related}{\\propname ClassificationEntries}\\proptype30{\\staticval 1}{\\propname Classification_1}\\proptype30{\\staticval X31rfml7dXVUd0JofmV/Y2d5I4V+iztXijgpnJidLiyQKTEsO4dfgZCBhY+bRDM6MjE8JF1dQkRZSEQ=}{\\propname lqminfo}",
        "2#353q3N4",
        "RemediationService",
        "4:4O4w4}4",
        "647?7",
        "2-e r%\"",
        "uM%o;",
        "*e},_",
        "P*KD@",
        "KgOz1",
        "7 WlT",
        "%Q<l ",
        "UI9 m[",
        "3[r=_0",
        "7Hc`;",
        "4xY&H",
        "XVm,M",
        "i\"w2K",
        "%\\>>L",
        "-eRr2",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Agnitum Outpost Firewall Pro 2.1",
        "hp76cL{\\",
        " 0xae",
        "54C0H",
        "lW*(%",
        "1 1l1C2s2",
        "h]T=!",
        "CertDeleteCertificateFromStore",
        "eLK(w",
        "^@Vg~jK",
        "J+:Q_qoD",
        "-<g3_",
        "G,x&*",
        "Unable to create Internet Logs directory. Check Windows directory permissions.",
        "\"(5?e",
        "U?-mF",
        "=$~!O",
        ")|/_R5",
        "jCjnj%",
        "{kKk<PM",
        "x4uXcA8",
        "<?K?i",
        "^b'la",
        "8<8D8L8T8\\8d8l8t8|8",
        "eoA1n",
        "iT~,t",
        "=4=W=v=",
        "ggP`&",
        "SSL_CERT_DIR",
        "d!0`!",
        "\"%\"|4>",
        "E4TF ",
        "#zd_:",
        "RguVX",
        "xoix*",
        "Invalid OCSP response",
        "}nKcF",
        "YXv@2",
        "8,888X8d8",
        "SEC_E_KDC_UNKNOWN_ETYPE",
        "Configure vsconfig.xml to remove ME protection",
        "q6QpX",
        "uCNMu",
        "'y.+|8",
        "Can't find procedure VSInstallerLogonEx in vsutil",
        "jj&uj",
        "7&8Z8y8",
        ">'?V?",
        "y($|c",
        "IGB\"@R",
        "ygG*!",
        "Iqt^=",
        "1MXd2*",
        "_kK<U[",
        "3>[vW",
        "z/$bL",
        ">2MG\"\\",
        "JG zH",
        ";+;7;C;O;[;g;s;",
        "xlky&",
        "2p<NO",
        "r4 ?;",
        "ut9l$$",
        "\"p)7cq",
        "zonelabs\\integrity.pem",
        "0BOB3ej",
        "<<?g`",
        ":S20t",
        "/v<:12",
        "O\"mFd#",
        "jLh<M",
        "0{\"]{",
        "Q0`0~0",
        "3D+z(",
        "SSL_add_file_cert_subjects_to_stack",
        "1P;Y}$E",
        "se4RD",
        "sect233r1",
        "{DqzQ",
        "~}/+5#",
        "\"_;537",
        "\"]4`#![BE",
        "<k47P",
        "&b_Xl",
        "X509_CERT_AUX",
        "7)7/747>7C7W7~7",
        "Trailer Field: 0x",
        "U/0aQ",
        "3i\"U6u",
        "8&vdva",
        "TN!J3",
        ")&2K*",
        "PSRAD",
        " 0xec",
        "ECDSA part of OpenSSL 1.0.1t  3 May 2016",
        "mwgz$",
        "l[R(m",
        "R9\"* /`",
        "KjlS+",
        "*|nCk4",
        "_2?&a {",
        "s+wDaJ",
        " value ",
        "Z9iHgV]",
        "GetLogicalDriveStringsA",
        "#:^gX",
        "ngJH0",
        "#=H`@O=t",
        "i3W6R",
        "Bb,AU",
        "tr^pY",
        "5MpjM",
        "S1\\`/",
        "T*_}x:",
        "UNPCKHPD",
        "gn$Sx*&",
        "C<A3_R",
        ">S}pI",
        "The Secure Client Could not be stopped",
        "&*,&qq",
        "F1t0w",
        "1oyOB",
        "C-I)Q",
        "kXvRJ",
        "MUd'=",
        "k>CHl",
        "dr, -",
        "\";(RM",
        "\\M0 =",
        "4#4<4U4n4",
        "\\]9ExHA",
        "eI}7d",
        "{}wFv$G",
        "yVK|;o6",
        "f=?&-",
        "x:^C$",
        "ahT>i",
        ">%3Qq",
        "^Lv!O>w",
        "!\\&jA",
        "4*Q~4+A?",
        "mE&'x$",
        "FXSUW",
        "Failed to install Checkpoint SecureClient 5.0 integration.",
        "InstallDate",
        "8G3ckb",
        "c{sv ",
        "'-r R2",
        "oDBi>g",
        "jQoB ",
        "Aizw+",
        "^m9&ts",
        ":!;';D;\\;v;",
        "rand2",
        "QTWKt",
        "8`9Z!:",
        "B]wZ ",
        "vu(1=W",
        "q~Elq-",
        "Reasons",
        "7\"83888I8N8V8[8f8k8v8{8",
        "OOVN;u",
        "5-6;6\\6",
        "`h3&(",
        "7e~&cg&k",
        "zEU4P=",
        "0yuzR",
        "9o}FC",
        "jJ`{VZ",
        "O{ bYl",
        "&nQ@t",
        "+3$E\"",
        "}bf=W2",
        "$11{r",
        "vE+Fmq",
        "NYU4|",
        "~RJN-",
        ":  error = ",
        "2 202",
        "[\"1Y\"",
        "T_'9AT",
        "ik3vX",
        "X5J2Zs8",
        ";;{9~",
        "failed to write uninstall change data",
        "][C!v>",
        "'FNq~r]",
        "[{Men",
        "aK/p|3Y",
        "8-989I9e9",
        "D$8j@P",
        "d nXo",
        ")G#<Yb",
        "pointer != NULL",
        "?UU)}",
        "Z+Mh=+",
        "5Xavl",
        "remove",
        "Y$F~%",
        "failed to find WSAEnumNetworkEvents function (%d)",
        ".}k}w",
        "Install previous firewall driver version.",
        "-Z?D~/",
        "p]A.C",
        "!wcYk",
        "3xQQh",
        "54sdi",
        "1K?+'%",
        ".WE6#.CF",
        "0[MQ!Odu",
        ":oG/M",
        "?YY<,",
        ",7]Nc",
        "1T1g1",
        "|UctvCt",
        "Config",
        "I5eoE1",
        "Nf!N<r",
        "xf5Z@CZ",
        "c82Bbu}",
        "@]^*;@",
        "NBqr[S",
        "n^XgMF~",
        "oke}\\",
        "oq~n9)",
        "8U6K^",
        "T_rGO",
        "7$w6w",
        "5+\"d@",
        "9V:h:p:",
        "(C$&*",
        "5OfVvi",
        "u}&by",
        "4&t=I",
        ",UeL`",
        "fx6znb",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 2. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "^bnE252",
        "%(9%6",
        "_?mImH",
        "-(!,^n",
        "#3 a/",
        "@w0522-",
        "Simulate a HTTP 304 response!",
        "d33kb",
        "Nm:2k",
        ",-./0123456789:;",
        "878d8k8v8",
        "2pxWwAJ",
        "NRp|<hQ",
        "jB9;N",
        "7TwEh",
        "rByEl",
        "SF]'q",
        "191N1^1c1h1",
        "Vjxh4",
        "TxXwz",
        "+wNXZ",
        "W}jX%wF<>R",
        "pre mac length too long",
        "\\B;,&",
        "VoC~,",
        "tJhpLM",
        "EPLauncher.exe",
        "K Kje",
        "[M1Fw",
        "E8#rj",
        "qm\\UH",
        "Iqc0I",
        "7*7F7b7~7",
        "5@'FW",
        ".?AVout_of_range@std@@",
        "Disables POST, goes with %s",
        "YzGM|",
        "4.{1k",
        "proxy path length constraint exceeded",
        "/*)v3R",
        "\\rLT\"O",
        "n?K\\E'",
        "SSL lib",
        "no matching digest",
        "&yk~>",
        "6|??SC",
        "tSDD?@",
        "%UMig",
        "=-(G;",
        "$ 2di",
        "354J4",
        "cx?7z",
        "fy^}pP",
        ")M; Xl",
        "5X,\\l",
        "rB{eJ",
        "H1&hC",
        "VCt;%d",
        "DzVYk",
        "data greater than mod len",
        "WSAEventSelect",
        "7G=M=S=Y=_=e=k=q=w=}=",
        "Jnq><$",
        "q<s~r",
        "aR$w9j",
        "3,3E3J3O3l3",
        "r9f;u",
        "Y5$L\"",
        "#!@dC",
        "/5fKlL",
        "sF)Dvh",
        "%aXq AD",
        "MIws^",
        "2%252",
        "q&Hg*",
        "fdKre",
        "`lnq@",
        "\"`bB303",
        ":.A5g",
        "3q3&484",
        "T$,SW",
        ":l;p;t;x;|;",
        "1=1B1a1v1}1",
        "]]$v7",
        "Wo'Hd",
        "`J<CY",
        "wrong pkcs7 type",
        "id-aes256-wrap-pad",
        "$$o0un",
        "8L3d)",
        "GetProtectedSymmetricKey failed. can't decrypt data.",
        "7fhbv",
        "[VSDATA] tvfwFirewallAddXMLRulesFromFile CreateFileMapping failed %d",
        "#S=bJw",
        "4282<2@2D2H2L2P2T2X2f2x2",
        "C`Mx:",
        "nsF/d",
        "ESS_SIGNING_CERT_NEW_INIT",
        "~LF|Z&|",
        "\\;Kur",
        ",Ga6U",
        "X$!rx",
        "626K6j6",
        "u:R\"pQ",
        "-LZwp",
        ">\">l>",
        ")\"RVU%]",
        "BWg8~",
        "CJ93&g",
        "-r!u]WU",
        "a<=~xd",
        "Xu~m,",
        "PWD_TOO_LONG",
        ">\">,>6>@>J>T>^>h>r>|>",
        "sOB<b",
        "}S`12",
        "'_ua#zC",
        "{{{{{{{{{{{{{",
        "PreInstallCheck:  PreInstallCheck finished.",
        "/\\A[B",
        "jejtj ",
        "1-1Y1d1p1",
        "> >0>4>8><>@>D>L>d>t>x>",
        ">YGT6",
        "FD9F@|d",
        "{+^N$",
        "mnf[!DK",
        "')I\"A",
        "E`,YR",
        "r YQ|(j",
        "r~o\\k",
        "cO^#m",
        "W2y~Y",
        "x_VFO\\>s",
        "C>'])",
        "SSL_peek",
        "_~^jA",
        "rmd160",
        "0 0$00080<0H0P0T0`0h0l0x0",
        "c`v9,[",
        "rD9fxOfBv6",
        "'Vur6;8",
        "T:&/&DJ",
        "^m-qK",
        "^X`[\"~n",
        "iup$C~g{@",
        "245\"m",
        "loadZlcomm;",
        "DF#NV",
        "qSBc(",
        "'Lf&m",
        "dx=gr@",
        "n)t| H",
        "'07?k",
        "u7:IYE",
        "3/l\\R",
        ";(;4;T;\\;d;p;",
        "H]S4&",
        "8#/a1",
        "?7?S?o?",
        "Microsoft Commercial Code Signing",
        "id-it-revPassphrase",
        ";5dNN",
        ".?AUTopologyObject@GlobalNode@details@Concurrency@@",
        "[!7Yj",
        "|(&?k",
        "KvhlT",
        "V2I_AUTHORITY_INFO_ACCESS",
        "WJ(#<J",
        "`sX.7o",
        "Qf'qrU",
        "7,8W8",
        "K#y.m",
        ";w!wx",
        "(lC>x",
        "PmQ6{",
        "Z!:Jy",
        "HV)L+",
        "rP\"zY",
        ".\\ssl\\d1_both.c",
        "a(kTP",
        "$5$<k<<=\\=",
        "_EafO",
        "9h9x9",
        "WSECheckUpgradeKey()",
        "E6A)R2",
        "W|t3e.W",
        "6!7D7g7",
        "\\Ey*5",
        "V4`T<M",
        "InstPrep's exit code: %lu",
        "I 8Ap",
        "pF$NX",
        "<,<0<4<8<F<X<k<p<u<",
        "''\\_E",
        "@QF`=",
        "K}RS5",
        "V2PgUV",
        ">G=dyc.",
        "hvDXo_",
        "|^vBD",
        "*J!v'd",
        "WriteConsoleW",
        "SkipFinalDialog",
        "ej,{b",
        "=sC..(",
        "%=.A#h",
        "sNN7y",
        "wlw7S",
        "=&>)`.",
        "}|~Ae ",
        "hvk;'",
        "]G>uv",
        "'M8)&F",
        "TQkk{",
        "=EYw?",
        ".8kFB",
        "0!0?0V0^0q0",
        "8,Z[.u",
        "g}t%_",
        "secretary",
        "setct-CertReqData",
        "4'535Y5m5",
        "se-NO",
        "181X1",
        "_/o|z",
        "nV18J",
        "-Fg%*.<",
        "@uL7V",
        "4ohEF",
        " 1@fX",
        "wy,60",
        "ZHHL+]",
        "~IMCvG",
        "t6^-U",
        "TxEo{",
        "jO^S2q",
        "<execute action=\"accept\" />",
        "PKCS7_ATTR_SIGN",
        "Check for incompatible products is disabled.",
        "I[6KtX",
        "e;s^7",
        "hN=1{E",
        "3 3@3H3P3X3`3l3",
        "Q\"!TJ",
        "3>4[4",
        "T)4y{",
        "Ignoring the response-body",
        "1EFz_",
        "ht$3)",
        "hp|>DYNd",
        "SEC_E_ISSUING_CA_UNTRUSTED",
        ".\\ssl\\d1_clnt.c",
        "GetStdHandle",
        "|#Z'b",
        "t`Oj/",
        "laF;3j",
        "ilnhq",
        "DES-EDE3",
        "s+rWla",
        "Failed to disable self protection",
        "failed to load library from %s",
        "XFKH0H",
        "<f=u=",
        "^ATK4",
        "I'46diUG",
        "api_ms_win_core_synch_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "4z51J",
        "D@)3p",
        ")G#}%",
        "a(Obu",
        "q2 8pM",
        "7J>k>",
        "wSk>B",
        "xg;5 ",
        "KGc2!Y",
        "C:\\ProgramData\\CheckPoint",
        "2 Cd&",
        ",http://crl3.digicert.com/sha2-assured-ts.crl02",
        "]+<5Q",
        "t0j^h",
        "p\"a:w<",
        "~)Byo",
        "2Z53(",
        "jrhHE%",
        "~Y14&",
        "l]aX)",
        "6uWYv",
        "vKNUmf",
        "1\"awiKwG",
        "5$5,585X5h5",
        "weq!E",
        "6X031",
        "s]O[n",
        "CnWat",
        "$T;rPoq",
        "NORTEL7INSTALLED",
        "WF`9S_w8Mo,y",
        "9,9B9G9u9",
        "tLxXj",
        "~<R'?",
        "4\"{??",
        "SK^'K=\"",
        "qK5)r",
        "X509V3_EXT_free",
        "*[RW\"",
        "<F1jR,cH",
        "WebUI html archive not found",
        "255F5",
        "rZI&s",
        "?\\m|f",
        "+X]c0",
        "uNh$X#",
        "f\"lP0",
        "r\"&1h4g",
        "0u[]$q",
        "YKHI5qt",
        "ECParameters_print_fp",
        "I?G'x",
        "tu*u@",
        "gFFbEF|&V3",
        "D2I_RSA_NET_2",
        "o* {J",
        "8^;u;.<",
        "cK=\"P",
        "ukzK%",
        "Connection time-out",
        "gco73",
        "mn-MN",
        "t$(UP",
        "D2LuR",
        ",wW-+&",
        "O-oW/",
        "\\sbasedon0 \\snext0 \\slink20 \\slocked \\sqformat \\styrsid13065977 heading 6;}{\\s7\\qj \\li0\\ri0\\sb240\\sa60\\widctlpar\\tx1620\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel6\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1025 \\ltrch\\fcs0 ",
        "cTUwnEM",
        "upwval",
        "CheckIfSha2KbIsInstalled",
        "$tg[GQp",
        "7,7m7w8",
        "YB[eLD",
        "boost::filesystem::canonical",
        "153f3muy",
        "vd$0K",
        "#.cAy",
        "?jc3m",
        "|8/\\,",
        "h[Xy0",
        "3Z5^ ",
        "2$2(2,20282<2@2D2H2L2T2l2p2t2x2|2",
        "7S7`7e7",
        "n5gKp",
        "Config\\config.dat",
        "a;,>%,l",
        ":+n1w",
        "5>6C6N698",
        "uR!C1",
        "Skip %d.%d.%d.%d for data connection, re-use %s instead",
        "2D~Sl",
        "a7e7c0000000360100000b0000005f72656c732f2e72656c73848fcf6ac3300c87ef85bd83d17d51d2c31825762fa590432fa37d00e1287f68221bdb1bebdb4f",
        "B&hP`",
        "?q9Y{",
        "_$u$h",
        "RAND part of OpenSSL 1.0.1t  3 May 2016",
        "zibIi",
        "'#QO2mc",
        "dpk}PC",
        " set CLIENT_SUB_TYPE Failed!!",
        "\"OX@,",
        "NjzNvE",
        "/0#xG",
        ".-.L9",
        "StopWatchDog",
        "yU#`8",
        "Common AppData",
        "xY({'h",
        "PAUSE",
        "1y9\"7",
        "qVEymh",
        "NtT-s",
        "9A[L)`",
        "\\_LJQ?",
        "l$$^U",
        "rBXu4iw",
        "{_:)L",
        "I2$!3{",
        "p+:N~",
        "vS\\aF< Tc",
        "atlTraceDBClient",
        "CE~_'",
        "L-`Ox",
        "W\\(&aj_",
        "5$5(50545H5L5\\5`5p5t5",
        "%sHotFixMonitor.dll",
        "-Z2?RL~h",
        "9A:J:W:",
        "/7%nF'",
        "VU}xn",
        "&O%nS",
        "<+<C<O<|<",
        ">NtLqW0",
        "G_@<!",
        "sRjj|&}yE",
        "F3y^|0",
        "FeatureAntiSpam:  RemoveAfter:  The uninstall is there and a log too.",
        "AWj-z3",
        "|y,kjS",
        "M'+1=",
        " FcN{",
        "'_/gG",
        "szOldPWInstall",
        "F:\\ckp\\src\\MSIUtils\\E86_20\\CMpub\\bin\\win32.release.dynamic.32.msvc141.mt\\Hash.pdb",
        "1^ZC+",
        "FAILURE_TO_SEALROOTPAGES",
        "3+4^4f4v4",
        "1?u3qO",
        "9 9\"9'9",
        ">\"PL6y",
        "s\"0vN",
        "uQ(9fK=:",
        "Lp}0D",
        "policyLanguage",
        "7Z8v8",
        "~sIPU",
        "cR/[E",
        "H^8 t",
        "\\KL'K-",
        "cA03h",
        "{<OoX",
        "0@yek&",
        "cR\\$,:\"%X",
        "fv,wo",
        "d;mn@",
        "Starting watchdog due to installation error from StartWatchDogOnFail.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71 with NoGracePeriod",
        "'.FB ",
        "cH13E",
        "vvHau",
        "f--,q",
        "4+hnA",
        "^60,n",
        "(f%5Q",
        "setct-AuthTokenTBE",
        "lkK^\"",
        "rcM)*",
        "DS_CopyToSystem32",
        ";i;};",
        "_eVvm",
        "PreInstallCheck:  Check for consumer software.",
        "site.png",
        "UDI{\"",
        "<3r-\\",
        "Vda~#",
        "^_(Aj",
        "k7oM(",
        "&9G&|",
        "AppendChildToParent failed",
        "%u %s %s %s",
        "9$9C9T9Y9c9y9",
        "#FmX);F",
        "F9;ax}:gnH",
        "\"*]5a]",
        "Ovr-f",
        "uB!!cB!!c ",
        "b`VjN\\",
        "a9Ss#",
        "u:*2]",
        "2WeMj",
        "lLlOlMlUlXlPlQ",
        "1&2E2Z2",
        "\\zonelabs\\avsys\\ckahcomm.dll",
        "|}%Z(",
        "Xvby@ ",
        "+<Xy#",
        "}^F_o",
        "pl-pl",
        "UU\\5~",
        "\\}\"Pp",
        "EyJp,",
        "?;sG<C",
        "M;G~c",
        "PSUBW",
        "?333333",
        "UnblockMessage",
        "#dXAz",
        "SEC_E_KDC_UNABLE_TO_REFER",
        "Bpy\"U",
        "!\"{<c",
        "RQy9%",
        "Y;<SX^rRm",
        "ardayz",
        "3%393M3a3u3",
        "|)PLj",
        "|~y/x=",
        "4iqnn7;",
        "9{S;]k",
        ")\"h=k",
        "2u13=",
        "C=9GP`",
        "xTnkJB",
        "skipped cookie with bad tailmatch domain: %s",
        "4M'(&",
        "Failed to set CustomActionData for deferred action",
        "setlocale",
        "uN=}O",
        "]Y8l*",
        "fz\\{vQ:",
        "uxeva",
        "+a3X^",
        "]v_\\y",
        "~_2>VQm",
        "Ph>.L",
        "1 1$1(1,1@1P1`1d1t1x1",
        "BlahO",
        "\\LZ6!",
        "7??tB?",
        "{uLU(",
        "L$p_[3",
        "0W1f1",
        "l0Xo5",
        "$nX0J",
        "/'/)/A/E/K/M/Q/W/o/u/}/",
        "<F=K=]=~=6>;>M>q>",
        "wffffffffffffgf",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\remove.cpp",
        "liKP2",
        "Qa2~*",
        "*oE+@",
        "kB#j.(",
        "?\\:n83",
        " oZGh",
        "cJM%|",
        "Content-Type: application/sdp",
        "Wh05#",
        "9R:C;{;",
        "tF~i:u",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13779108 under this warranty }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 shall be, at C",
        "#z=g|",
        "BEC86AE1-01DD-4170-BDC8-E7B1E7EC9F07",
        "(cX7J>j2",
        "JaaS(",
        "PMOVZXDQ",
        "5&?lr^",
        ";#;E;~;",
        "KkN^j",
        "3!3&3,3>3P3U3d3k3}3",
        "8(r49",
        ";4;D;H;L;P;T;\\;t;",
        "000004E4",
        "6=Py$",
        "v\\C/r",
        "Y&G0l'",
        "2[}xx",
        "`w}_4@c",
        ":#3sR{",
        "#ktj%",
        "iv too large",
        "949P9l9",
        "}#,9@",
        "2:osS",
        "6A?t+",
        "#LPT1",
        "%SYSTEMROOT%",
        "FKNjdB",
        "\\vspubapi.dll",
        "Y=6/^G",
        "{'M#f",
        "s>=vm",
        "dABnl",
        "9I`N}",
        "$);{G",
        "Yqw%_W",
        "tQpMeh_",
        "y@%:d",
        "short",
        "v]9v(",
        "VV6d./p2",
        "&b;HFY",
        "Failed to get previous size of string",
        "=MLU+",
        "secret",
        "RxVv;'AQT",
        "I2ikG",
        "d2i_ASN1_UINTEGER",
        "\\!e6{",
        "x.>e4",
        "\\f1\\fs20\\insrsid3017503\\charrsid15169477 or rendered unserviceable by one or more of the following: (1) improper or inadequate maintenance by anyone other than Check Point or Check Point\\rquote s authorized agents, (",
        "C!\"HK",
        "8-8L8",
        "FAILURE_WAITING_FOR_HELPER",
        "g_4;8",
        "KbgkI,",
        "AeoxV1",
        "R{q,'aN",
        "j>j&h=",
        "m4w$6",
        "5KhhkA",
        "ymy_W",
        "{hqEj",
        "vdFzm",
        "9D$ s",
        "CRolloverMgr::CopyRolloverBlock():  unable to write rollover file header",
        "wD9|R",
        "{@)!H",
        "ka[qV>",
        "41&GT",
        "<D<t<",
        "SYSTEM\\CurrentControlSet\\Services\\KLIF",
        "*:0@ ",
        "5xQJ4t",
        "4lBVLo",
        "tWv{NJMrh",
        "vP$nZ",
        "i,S)=q",
        "uSFk3",
        "J_7u*",
        "mzv`K",
        ")M:2\\",
        ";\";M;",
        "9!919F9R9X9b9t9",
        "?$?,?4?<?H?h?p?|?",
        ".#pH/",
        "v[i]r",
        "zszh.",
        "&XVb'",
        " c=4D",
        "X7NE5 ",
        "|Mg#eG",
        " ;ea;",
        "0'Eo8y",
        "V_']b",
        "b\"G3KLW",
        "3DB#ir\"",
        "e9&J)a",
        "KbB)_C",
        "~8pWD",
        "=3q=|n",
        "k1l2o*",
        "J=cST",
        "3o*S\\K4~",
        "unsupported or invalid name constraint syntax",
        "InterlockedFlushSList",
        "= =$=(=,=0=4=8=@=X=\\=t=",
        "(T!z=;4",
        "OniW*{O#9",
        "ECDHE-RSA-NULL-SHA",
        "Invalid process handle for [PID %d], error %d",
        ".2B2U2t2y2",
        "(YR|R",
        "E/euX",
        "y<@t;",
        ".?AV?$basic_memory_buffer@H$0BPE@V?$allocator@H@std@@@v8@fmt@@",
        "6WzEsH",
        "03{A0",
        "t.y%h&'",
        "DSA_SIG",
        "F~jpQ 5{K",
        "/g=%`",
        "1Jhjh",
        "\"8CGZ",
        "%PJ@%",
        "u3j9r",
        ";>;W;9<k<v<",
        "\":Dl,+",
        "8K^(B|./",
        "1mU;m",
        "CNBl=i",
        "obO~^>",
        "IA1MQ",
        "hU,M(iC^",
        "G6=iT",
        "8KNKl1a",
        "ewsdZ",
        "AEF/I",
        "u>.0I",
        "Nxx},:+0",
        " -dr \"VSTOR Installation\"",
        "Ps4'r",
        "=*=5=@=K=Y=e=",
        "oD&r;",
        "Too long SOCKS proxy name, can't use!",
        "72898",
        "sidebarButtonPressed.png",
        "<-(K@",
        "9&:Z<",
        "~NpSh",
        "6AL7\\",
        "mN#0!V",
        "eMgB=",
        "r`D46",
        "<MMMM`",
        "FvfwLo.",
        "NsVzOt",
        "ihHI9",
        "{ixzL",
        ")a!Cd",
        "=,=<=@=D=\\=`=d=h=l=p=t=x=",
        "1Z84L",
        "R2-Et",
        "*3@~4]2",
        "ZL-?/l",
        "QSRVW",
        "'P9M}#D",
        "bp5;->",
        "VB8+_",
        "m#Fw^",
        "})!g ",
        "E@Gx|",
        "47KKc",
        "3(333A3G3X3i3s3",
        "gTu|n",
        "###$D%",
        "Ze%A/",
        "_j(X0y",
        "3}Y>1",
        "Cbi'?",
        "loadVsutil",
        "xhuHH",
        "Ajkt[",
        "l*P69",
        "tF50XX7",
        ")D-Y+",
        "T':g!o",
        "responseType",
        "4w#LS",
        "5 6%656S6X6h6|6",
        "F4{!5",
        " kQh=i",
        "%@%H$N",
        "; ;3;I;R;];l;r;",
        "4V,;\"",
        "hQ\"Z.",
        "2 2$24282H2L2P2T2\\2t2",
        "<9=q=",
        "EWEgEwE",
        "k{\"_B",
        "hu9i@|",
        "1,1<1@1P1T1d1h1x1|1",
        "^'[DEh",
        "O\\a:L",
        "S>&eb",
        ":!:R:]:h:t:",
        "UWm[of",
        "121b1",
        " 0xad",
        "< <,<?<]<",
        "9E?| ",
        "PTIMER",
        "($K<3",
        "(x5~a",
        "0hppP",
        "9=0ei",
        "i#'M0",
        "unregConf.txt",
        "t$4EV",
        "D@bZ,",
        "3r~IS4",
        " thread=%lu, file=%s, line=%d, info=\"",
        "+E4PV",
        "RDv{7",
        "'kwLv",
        "gXJid",
        "?,?0?4?8?<?@?H?`?p?t?",
        "=l=t=",
        "WIA`I",
        "7q]4m",
        "~hF/a",
        ".-_v8",
        "$-!5v",
        "Nx*6m",
        ",a!{Y",
        "yc?0%g",
        "ef:6ak+.",
        ">8$4,8$4,",
        "vks:b#",
        "?3?8?m?r?",
        "mHtSE",
        "9}r6VB",
        "ISO US Member Body",
        "3 3(303<3E3J3P3Z3d3t3",
        "5v-Pdp\"",
        ".=X&b",
        ",Vy~~",
        "1sik!R>",
        "u[[),}i",
        "|:GjH*W",
        "tGk5Y",
        "MinConcurrency",
        "d<xcb<-",
        "1/1t1",
        "0&bN~",
        "$/1o;",
        "Sh0j#",
        "peNeO",
        "T7:Pp",
        ":F=X=",
        "R:C?jX",
        "|2=v)Ye",
        "0H(@g",
        "TD2KU'",
        "xJ;Vj",
        "}l-^I",
        "?}eY:",
        "rz!ya",
        ".*w\\WF",
        "?DelRegKey@@YAXPAUHKEY__@@PAD@Z",
        "l'xV}",
        "VTC-a",
        "5@'gQ",
        "U`w/o",
        "MC4hu",
        "Jf90u",
        "_*S4{",
        "NQn0z^s",
        "block type is not 02",
        "jnzSx",
        "+sBC;=S",
        "EPf0$",
        "?z7 p",
        "t,0L0l0f:;",
        "VwW]|",
        "! ;R>KT",
        "kYdvi",
        "[VSDATA] %s: OpenDriverHandle() failed",
        "hc7?]",
        "Kh|])m!`p=",
        "Bpa;!",
        "Could not create reboot file.",
        "6$7O7",
        "F`Dv7",
        "2;7r-",
        "X=qTi+",
        "K*~o)",
        "fp4[T",
        "Xb3bq2K\"R",
        "qkBWW3",
        "j,v\\]0-",
        "Product is whitelisted",
        "SetUninstallInfo() called",
        "'{ZfP",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid9971420 ",
        "WEK~T,E",
        ")M|jC4",
        "? ?$?(?,?0?4?8?<?@?T?X?\\?`?d?h?l?p?t?x?|?",
        "Xej&(",
        "guS)EI_4",
        "f=33wv",
        "KHKAk",
        "f;QPjA",
        "241126235959Z0",
        "Os?lyR",
        "dh*Q5BU",
        "^PQQQQQ",
        "vccorlib140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "~&DUyH",
        "QSn(>V",
        "^\\KSdIW",
        ">D?l?",
        "4wv,tq",
        "VyU~u!'",
        "&8\"S'%",
        "duVRb2",
        "u+~#o)>~B",
        "?R9T3%z2",
        "ib8\\x'*",
        "3nFUX$w1D",
        ":j'su",
        "_y&PE",
        " Gus?'",
        "lTG^\\",
        "L'5FOK",
        "QWxF]",
        "L$ Qhh=!",
        "/NvPIa1",
        "InstallFiles",
        "(m\\kp",
        "B\"Vzy",
        "Jgp-`",
        "E>9M:",
        "<E3.}",
        "t|mLfg9",
        "sL9\\$",
        "P!p<Q",
        ":%:5:J:[:e:w:",
        "ZfBP:",
        "(E~2=!",
        "4jl>]",
        "\\S%:0E",
        "<4TIj",
        "-,1`t",
        "k~^/h",
        "W'bsw'4>)I",
        "z|rxw",
        "conversion of data to type \"",
        "8!8A8",
        "94y=B",
        "]t:]1x",
        "Gc>UM[",
        "connect to %s port %ld failed: %s",
        "-Ioq:",
        "CleanupRegistry:  CleanupRegistry started.",
        "\\=(m{",
        "d\\{<68",
        "o!}>'",
        "MsiVerifyPackageA",
        "$g[i,j",
        "Qg](bOe.",
        "] xJM",
        "WbLna",
        "42fXO",
        "x%2g?",
        "Ur~@u",
        "^H@+O",
        "NkV|y",
        "l5s&[",
        ";(;4;@;L;X;d;p;|;",
        "___lc_locale_name_func",
        "l_3-d",
        "/eXNA",
        "`j5<P",
        "*-d%4m",
        "*\"*b*",
        "Vh@9#",
        "55=C<",
        ":{M:%.",
        "m[B/^",
        "7J5Y.",
        "H3pNP",
        "/=`OX",
        "Continue pending",
        "(\\uT>@",
        "o:}J0^",
        "qXLHt",
        "Stt2Y_C",
        "~|r,0",
        "TRMO@",
        "< 6:bkwR",
        "Fo.+:",
        "^xo80",
        "save failed",
        ";yO~v",
        "$vL\\QY",
        "9j?g\"C",
        "y*~UY^",
        "hsT<r",
        "whh \\!",
        "jxjwj\"",
        "smartdefense\\",
        "/QK!a",
        "~?t~r",
        "f}lzT",
        "'JclF",
        "@f^jV",
        "n\\\\6*",
        "LALZm0",
        "SchedXmlConfig",
        "2. ,^&",
        "{@I-|",
        ";#<9<c<",
        "vv1.{",
        "OEyUW",
        "}F>[?",
        "Drumd",
        "qD#BH",
        "TcpReceivePacketSize",
        "B~wN4.",
        "pLt~V",
        "u8=\\t",
        "\\iA;-7",
        "jgQtc5",
        "1xjE2",
        "%s\\system32\\drivers\\vsdatant.sys",
        "`h<p:",
        "EqWr8c+",
        "XUu;&",
        "=6('dH>",
        ".w-.kO",
        "D$X+D$@",
        "/2~Qr",
        "FHA/X",
        "QeK4?",
        "K\"jZ4g8",
        "`mPT%",
        "v(!X>_zXz",
        ">F>X>s>~>",
        "/mD7c",
        "Wgdw[0",
        "5?a<F",
        "uPVI2",
        "?>#C<J",
        "cmd /c \"del /F /Q \"%s\\Temp\\SCUIAPI.dll.upgrade\"\"",
        "r)`3-;",
        "*:fK3",
        "s9eByf",
        "3.405",
        "}(YH@B",
        "4 4$4(4,4044484<4@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "lhZ,E",
        "C,G}ie",
        "m_gx+",
        "|ZeH Q",
        "GSH]V]",
        "9JvVT",
        "}<P9!",
        "ConfigureClient:  Removed old integrity.pem file.",
        "j`ntv",
        "WbWpT",
        "p7!Ey",
        "=+=Fj2",
        "A@fw3",
        "gx3u+",
        "+A$+Y",
        "failed to fetch record from view",
        "}/z[\"Q",
        ">Gi.2",
        "4\\l<h",
        "REMOVE_SUB_TYPES=%s",
        "bvz]&/rK",
        "eI9r._",
        "7%777S7",
        "CZD/W",
        "e+ D\\e",
        "S<pe\"",
        "J2yZFO",
        "Z@*1sL'",
        "kZ q-_",
        "b}sA\\",
        ".5Fz$",
        "KR3qCc",
        "mmB7BOV",
        "LmK9#",
        "/WF+,%",
        "(2@|@n@",
        ",VG;8#",
        ".?AVspdlog_ex@spdlog@@",
        "&.'oT",
        "2p5t5x5|5",
        "7g8T9_9",
        "8':'`",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid15169477 Your sole and exclusive remedy, and Check Point\\rquote s sole and exclusive liability for }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid5186676 ",
        ":E:b:y:",
        "5>M^(R",
        "0NoW-",
        "py5OZ@j",
        "C'> wP",
        ":F;o;",
        "jnjmj",
        "CCCCCCCC",
        ")ik*5",
        "Hash.exe",
        "nVF%o",
        "1SKrV",
        "!T'%mA",
        "'KmD,",
        " =<>/",
        "%mf/,",
        "(T#4~",
        "7:8?8X8`8f8k8y8",
        "e'Zs$",
        "w;w'd",
        "{3@Bo",
        "W<\"u%",
        " 0xbe",
        "sJ4Si",
        "32G\"@Z",
        "db-!ID",
        "5B6_6",
        "3kE. ",
        "t$Ph\\",
        "r`f;U",
        "&ys#/",
        "7YF,7@r",
        "_get_timezone",
        "4CH-n)",
        "g{2<{",
        "w<]pg9\\",
        "X,n|T",
        "igP_OG",
        "OV36[x0",
        "_&8:s",
        "4rLmNX",
        "*]4Hv",
        "lSOIK",
        "+!L?UE",
        "GOST R 34.11-94 with GOST R 34.10-2001 Cryptocom",
        "EPWD is not running",
        "1 1(1<1T1`1h1",
        "ht*~Z-1kN",
        "_~.;N|",
        "D)Ux\\,@h",
        "7V7\\7z7",
        "4K89B",
        "orSY{",
        "ZI0Ac",
        "Done waiting for Remediation Service to stop",
        "4d\\zM",
        "-wWY3'",
        "^f@%C",
        "&[M;Q",
        "PKCS12_MAKE_KEYBAG",
        "<B<[<k<",
        "V:;s^",
        "hNe _",
        "is)#m",
        "6 6t6~6",
        "42536B6",
        ",Jsfz",
        "}zLvH",
        "I~nE7z",
        "AS#H6f",
        "h6b;i",
        "DYNQX",
        "q= u7",
        " H>rW",
        "R,mMq(^",
        "Failed to get current directory.  GetLastError() = %d, will use %s",
        "jjjoj(",
        ";P+Zb~e",
        ".B-r;",
        "o!{IZx",
        "9?dih'",
        "5%666F6r6",
        "ML9a\"",
        "=+=l=",
        "Nested Signature exists, but corrupted!",
        "/?oM~",
        "???Z?n?u?",
        "boost::format_error: format generic failure",
        "x8`]}",
        "5jJ*N",
        "O/}wr",
        "D-S+`",
        "%'kOj",
        ";%;+;1;7;=;G;Q;\\;d;k;s;|;",
        "PPSklI",
        "4N0f,",
        ")ugkC",
        "Expecting: ",
        "9^@uF",
        "*Am6?",
        ")PO>?",
        "uYe8w",
        "Ljr*]ea",
        ";S~(t",
        ";\"H GT",
        "A!\"HL",
        "-nqO@z",
        "<n(MTuA",
        "Illegal string size",
        "q8~*j",
        "6r5qx",
        "A WRVPU",
        "setct-CapResTBE",
        "SPYJn",
        "X~{[F",
        "%\\|}]l",
        "7g^tk~v",
        ")rD{p",
        "l GE0",
        ".\\crypto\\engine\\eng_cnf.c",
        "H6nK]G",
        "`]E!N",
        "> >$>(>,>4>L>\\>`>p>t>x>|>",
        "-~dBT",
        "5P5W5c5m5",
        "CSaFKR",
        "6:7S8",
        "Pzrp[V>Y",
        "idH7N",
        "$Of+x",
        "=F<-}",
        ":q/kW",
        "5H9hC",
        "w(EXP",
        "70|8<",
        "UUUU3",
        "_{i~|",
        "\"2:(,",
        "ySL}|T",
        "$-3+49",
        "xZCVe",
        "a={7;B",
        "AddToWinFwExceptionList:  Failed to load AddToWinFwExceptionListA function.  Error %d",
        "8\\eh3",
        "memutil.cpp",
        ")4auD",
        "R.@a;",
        ")'!lT",
        "<L}::",
        "]J/y:-Q",
        "vSS0%",
        "r|6f/@Z",
        "6\"6>6Z6v6",
        "{&{.{6{>{F{N{V{^{f{n{v{~{",
        "#0Q0a0",
        "jXObg",
        "?w<4-",
        ":Hp{=V",
        "9\"W*]",
        "m_Z-/O",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\fresh.cpp",
        "979B9I9P9h9o9v9}9",
        "60\"VZ",
        "4N2[4",
        "wu58\"",
        "CE{;H",
        "{'U,gOC-",
        "AutoReboot",
        "l$ )\\$D;t$,sS",
        "SKMC_",
        ">\"?e?",
        "Up@pz",
        "cg:,s",
        "failed to allocate output string",
        "UI7z%~",
        "4,555@5{5",
        "%KSWM",
        "0#Wl[",
        "<@1f6qd",
        "WxZoF",
        "1bo%P",
        "uuK1%v",
        ":iK0b",
        "un9D$$",
        "{\\fhimajor\\f31531\\fbidi \\froman\\fcharset161\\fprq2 Cambria Greek;}{\\fhimajor\\f31532\\fbidi \\froman\\fcharset162\\fprq2 Cambria Tur;}{\\fhimajor\\f31535\\fbidi \\froman\\fcharset186\\fprq2 Cambria Baltic;}",
        ")Aq5,C2",
        ">1V2d",
        "w0Je5",
        "CheckTokenMembership failed, err=%lu",
        ")S3vi",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData",
        "AddVectoredExceptionHandler",
        "W0ubk",
        "ub\\~z|",
        "3K43P",
        "n6fdqo",
        "}4L!G",
        "B7dMk",
        ">*R'7",
        "5?6I6f6w6",
        "OSxiz",
        "Inhibit Policy Mapping",
        "Nx'3U5",
        "ApPRE",
        "Wo-_d`",
        "failed to get first failure action type",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1132737 ",
        "4QqT h=\"F",
        "5'Eo8",
        "n}N#7j",
        "f@L=P",
        "%jXN6,",
        "=O?OAO",
        "\"<.41",
        "/l9d~",
        "IK=iqC",
        "9/pU_",
        ".NQ HT",
        "6)A\"%",
        "0v#UQ",
        ")WFR[",
        "`Jh1{",
        "g.A9%",
        "S$E_)",
        "Zx4dU",
        "8_9_2_0",
        "rqb{'",
        "%TLc^",
        "cA\"8a%C`",
        "%ow\\|y",
        "m/m%m",
        "jAj{j\"",
        "9JSf.:",
        "{{`1\"",
        "password",
        "IDEA-OFB",
        "PMOVZXWD",
        "7gFI*",
        "8(vEy+\"",
        "8#8?8[8w8",
        "$E8iA",
        "s\\V5g",
        ">pW9UKj_",
        "3T$P3T$03T$(",
        "LocalSystem",
        "=,=J=O=X=t=y=",
        "C2O!!",
        "6`59M",
        "(#d9XD",
        "4r_]Q",
        "&|g|4",
        "{WeS^>",
        "/<BJ]",
        "<|PRU",
        ";F$vj",
        "?KwL'S",
        "aF^=_",
        "G}#\"pf.",
        "t*vR7",
        "!){/S6",
        "sNV_F;",
        "6)3[P",
        "1WC|O",
        "axbb!",
        " ^lu 56T",
        "U;Q{'7",
        "6CE\"z",
        "~w.FLA-RV",
        "Sdk1\\",
        "t@VSP",
        "lC0SKi",
        "@\\#D$",
        "OJrLt",
        "9 9j9",
        "%>RTlq`Y",
        "{p 0t",
        "\"-x/c",
        "$]S21v.",
        "yg4vH",
        "6lfbM",
        "WSEIsFromTempFile()",
        "Web Server",
        "}Z1<O",
        ".rtc$TZZ",
        "&=.WT",
        "*^mSR",
        "P&*8t",
        "\\@X&Lu,",
        "YYYd#",
        "[DUMPFILE] exception zipping dump files",
        "\"ma_0",
        "2Kr^A",
        ":%EZq7",
        "5p5v5",
        "*Y>E8",
        "171S1o1",
        " FLD$]_#}",
        ".`Jc]",
        "MPXVULKORTZ\\",
        ":;P6b",
        "[({&3",
        "-z?$l",
        "N:g\\h",
        "wPD{b",
        "4P4m4z4",
        ";=PNN",
        "a(j?R&",
        "h5/p/",
        "LW3Z*",
        "e-[aYl",
        "U7VWVwV",
        "*JD\\v",
        "getSessionKey",
        "?P1$Fp",
        "tmAo]>LS",
        "=0J0U0",
        "H_c]+",
        "$O?7&",
        "D$$WP",
        "H[!nt!",
        "+D$<@P",
        "1%1*171A1K1R1g1l1v1}1",
        " [B>.",
        "wPE:M",
        "+!hKQ+",
        "989h9p9",
        "M(;L$0u%",
        "subject issuer mismatch",
        "o_,sJ",
        "%*sOnly User Certificates",
        "5UwL7r",
        "75t+M))",
        "mO.<.",
        "vi$@/",
        "+>0eH",
        "_HLLE",
        "extendedStatus",
        "9w,~J",
        "WY\"t!",
        " Class Hierarchy Descriptor'",
        "hUu2D",
        "\"jr9Z",
        "=KqW,",
        "n>(o>[-",
        "+,ts1",
        "-\"#j-",
        "z+T+O",
        "=z0Ah",
        "3,434?4I4d4k4w4",
        "YL?UX",
        "PH3e<",
        "/2`1<",
        "/_c2Y(",
        "cU\"y>",
        "X509v3 Certificate Issuer",
        "w`VUS",
        "0rwKM&",
        "R=__D",
        "55Rcm",
        "@J+h.\\",
        "D$(hH",
        "797j7",
        "<$=z=",
        "D$4PhT",
        "Rcl!8",
        "MDC(Oc",
        "/!dh;",
        "InterlockedPopEntrySList",
        "^%$F<6",
        "+]h\"t",
        "p:c85BE",
        "A|M'+",
        "A-F_;'",
        "~6'Y\\",
        "/xTRB",
        "21363a3f3",
        "failed to get target path for directory id: %ls",
        "M -)v)W",
        "n|%\\gf",
        "Failed to add NewService data to CustomActionData",
        " 0x68",
        "7.777",
        "L@ 'u",
        "givenName",
        "=tjQd/_t6",
        "> >I>y>",
        "P]5w1",
        "K(Y /",
        ":1:=:",
        "747@7`7h7t7",
        "DAAW_help.txt.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        ".-3UF",
        "FW>mu",
        "i{#wt",
        "cl~sJ'",
        "'$E6D1",
        "h}uQ;ik%",
        "Z\" !g",
        "&rI$(",
        ".)62_",
        "Knn*<R",
        "]%?DKU",
        "~oN2x",
        "$ucN&a:!9",
        "=4=H=r=}=",
        ">VsJT",
        "y,!A@-",
        "hN\"8h",
        "9;nqQ",
        "VWphew'C",
        "failed to get Component name for secure object",
        "^L7^F-",
        "&UZ A",
        "0Pl-:",
        "uI.V9",
        "q1e,Ud~",
        "Set OEM key",
        "5 5&5,5:5@5Q5W5h5n5",
        "InitOnceExecuteOnce",
        "heICT",
        "pCEVp",
        "17YoT#",
        "QAK4n",
        "REINSTALLMODE",
        "8>'G}bMz&",
        "kjsMC",
        "0j0z0",
        "*a*a/",
        "RichR",
        "S78M)",
        "[ 6 X@p@",
        "\\fs20\\ul\\insrsid2388238 DLP-1 Product Family}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid7224833  and Document Security Product Family}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 . If you are using }{\\rtlch\\fcs1 ",
        "]sboVo",
        "k/=8S=",
        "IL/Wq",
        "<+]80",
        "+de#T",
        "is-IS",
        "G3-AP",
        "@1D1H1L1P1T1X1\\1",
        "X(JG|",
        ":1;P;m;|;",
        "UUUUCU=",
        "bX-]i",
        "W707&",
        "/LOOKUP:",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid8791827\\charrsid8791827 The laws of the State of Israel shall govern all issues arising under or relating to this Agreement, without giving effect to the conflict of laws principles thereof. All dispute",
        "?ulQX",
        "Z2ICsk",
        "Y3<PU",
        "C6=<`cu",
        "$_W!s",
        "pF\"G9",
        "VjLh|2#",
        "mE=gq",
        "\\f1\\fs20\\insrsid6240750\\charrsid13256927 )}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2764809\\charrsid13256927  days from }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9651500 the date of }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "474l4",
        "c=#B ",
        "J?OA>",
        "tNWjW@h",
        "+l#6U",
        "s][*u^JUgI",
        "NREF_NOS",
        ">|Q9.",
        "4)484>4K4X4b4h4u4",
        "^k&:z",
        "^8]}$!",
        "qg,d8",
        "3!3:3S3l3",
        "X2$:8",
        "S*RlP",
        "problems getting password",
        "'4T}AP",
        "SAPI_VERBOSE",
        "UxZrTQ",
        "\"D00C",
        "V;d3x",
        "naiIx",
        "On.QFv",
        "^XUWt?",
        "jhjhj",
        "YL@Ut",
        "|Sp?s",
        "c2pnb304w1",
        " (FK%_7",
        "RC5!\"",
        "EA?DFC",
        "s?RDD",
        "jb4bh",
        "[t-Bo",
        "4 4@4`4",
        "Ob-^M1",
        "5b='o",
        "7.49.0",
        ";1;6;a;f;",
        "Tt0jh[f;",
        ".?AVRealizedChore@details@Concurrency@@",
        "58|q ",
        "0Eg>r",
        "Z-L\"7FdF",
        "Ss^p%",
        "clBg26",
        "H34k8",
        "StC\"W?",
        "ec_GFp_simple_group_check_discriminant",
        "lD{`L",
        ";c<s<",
        "u0h@M!",
        "eouzbZ)",
        "_M@,(N{",
        "[,_eA,",
        "#246V",
        "Ro|``z",
        "xfrirb",
        "2;2F2K2P2k2",
        "0`GnV",
        "X509_check_private_key",
        "(v!77s",
        "\\4S Q",
        "), description = ",
        "Free: %I64d MB",
        "~WmG9",
        "`r ii",
        " SecuRemote type found",
        "\\\\9i XDhlR",
        "3YdfE",
        "!WS![tZ",
        "!=kY$q+4<5",
        "=!=8>]>e>k>q>w>",
        "H1)M$",
        ".?AV?$basic_memory_buffer@I$0CA@V?$allocator@I@std@@@v8@fmt@@",
        "nL/k!",
        "Gko<e",
        "BqI`a",
        "CreateToolhelp32Snapshot failed %d",
        "rUg'm",
        ",#0Rm",
        "lc}YI",
        "3k3u3",
        "id-regInfo-certReq",
        "already connected",
        "4;4U4s4",
        "AES-256-CFB",
        "An error occured in the \"StopInstHelperSuccess\" custom action.  ",
        "=NKo&Jn",
        "_i*Jh#",
        "g']/yDz8",
        "bG5\"lP",
        "5$5l5",
        "pMR)|",
        "7y%@O",
        "U8QX/Y",
        "o,!N=?",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 1. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "q1A$b",
        "t$ WV",
        "l:q8T",
        "yQ-*h",
        "O??j|>",
        "cnw+k",
        "ePiJL!",
        "Version does not exist",
        "id-smime-aa-ets-CertificateRefs",
        "System\\CurrentControlSet\\Services\\SR_Service",
        "1K1Y1g1u1",
        "4jDU%",
        "112s2",
        "E74Gs8}",
        "jXO7O",
        "n1Wka-Fp-",
        "EC_POINT_set_Jprojective_coordinates_GFp",
        "06kn(",
        "V<Arg",
        "oO1jD",
        "h#Jn,",
        "cG'o\"zS",
        "{C>'3",
        "`lB'l",
        "g;5 $",
        "5yoxi",
        ";8XAC",
        "3j4c5",
        "1(2x2>4O4",
        "TMGYA",
        "mac_size <= EVP_MAX_MD_SIZE",
        "#XU5@",
        "D3PUv",
        "1]#_O",
        ")n`bq",
        "-QJ}e",
        "wJiu%&",
        "=&=6=s=",
        "TBN%`` ",
        "\"L {k",
        "SXRqI",
        "Cp<OV",
        "ukm`.",
        "zYuuz",
        "oEpZS",
        "Q]LIo",
        "Z`|nz",
        ";37vP",
        "/VE$R",
        "#W\\syh",
        "A]&!%",
        "/l}.aQ",
        " /%rz",
        "-\")!V",
        "s$1 5\"",
        "3.;t$",
        "525A5",
        "Ai4wN,",
        ";tiX1",
        "-#Z+-",
        "!W0!F",
        "{Bw=\\fR(tO",
        "CAST5-CFB",
        "GlobalAddAtomW",
        "CRolloverMgr::TruncateLog():  unable to set the new log file size",
        " 0xc2",
        "Sh#s'{",
        "YB,h~s",
        "fF@?sn",
        "4c[$ur",
        "M8id ",
        "*[,dU",
        "=^@l5",
        "U,PJk",
        "9B/w2",
        "C=9+.<",
        "/suw&=",
        "??ECl",
        ">;>c>",
        "1(2p2{2",
        "L~$G&g",
        "VPhXH!",
        "_Y@oP",
        "Vista",
        "$XD+O",
        ",`VVw",
        "-zah,",
        "~=F>&",
        "i/hL:",
        "b8OF:f",
        "protectionOn",
        "FYlz=&",
        "$3-3.3{",
        "5:5_5z5",
        "TrGUI.exe",
        "#R{aT",
        "-kE|88",
        "i/+pe",
        "'lZs@a",
        "KdB-q",
        "Zwt%'P|",
        "a4O|-",
        "veA(2",
        "d;IV ",
        "-Ge&Y",
        "rboZ~",
        ":,:8:X:d:",
        "2mIET",
        "9f2L+",
        "d)k;v",
        "E#Z&K'",
        "prime1:",
        "v_Q4a",
        "_XCkK",
        "  Trying %s...",
        "S11b?",
        "Incompatible Kaspersky Anti-Virus product found.",
        "ReadConsoleInputW",
        "l],EK+",
        "ix+H9y&",
        "Ty0\\H",
        "&\"ZMj",
        "pr\"/}",
        "cms_DigestedData_do_final",
        ";^<h<,=0=4=8=<=",
        "w3c2b",
        " .UD@4*",
        "*[2Jbr",
        "rG]${",
        ";_Yw`",
        "(RF,$\\",
        "KYO9Z",
        "lB>aF",
        "H`Ji&",
        "<4;v_",
        "%^'_~",
        "k3/+*U(",
        "[z6pk",
        "213+4U4",
        "?3?f?m?",
        "mC(CN",
        "icB:]7",
        "E*g2glf",
        "\\b\\i\\f1\\fs18\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext0 \\slink23 \\slocked \\sqformat \\spriority9 \\styrsid131787 heading 9;}{\\*\\cs10 \\additive \\ssemihidden \\sunhideused \\spriority1 Default Paragraph Font;}{\\*",
        "wzse9>",
        "Z#a2E",
        "FIPS routines",
        "DSO failure",
        "_|##t",
        "E@>E`\"",
        "p\"x!<",
        " 0xa4",
        "=#=S=l=",
        "}Ow1m",
        "+,o(B\"YS7",
        "&\" w\\",
        "q=Y)q",
        "Od?_!",
        "OUFa)T",
        "og8ttn",
        "Finished",
        "not connected",
        "T6(G<",
        " fGEA@.&3C",
        "KBtmi",
        "%L=hx",
        "pseudonym",
        "TS_REQ_set_msg_imprint",
        "UQhVZ",
        "s<^EE/@vw",
        "no matching digest type found",
        "+~\\gs",
        "rX_Z(",
        "5t5}5",
        ">N_n=W",
        ":#:':+:/:3:7:;:?:R:o:",
        "IR%>Wi3@",
        "#^.w*3H\">",
        "{%'{Z.",
        "^y=w)]",
        "|~>5k",
        "OEjz`",
        "bxD[R",
        "tvUUj",
        "V2Sdb",
        "2$2*20262<2B2{2",
        "92FXg",
        "E&0}M",
        ":*:>:M:X:h:",
        "bcrVN",
        "L>#lQ'x",
        "+sZwx",
        "zgm@Sf",
        "5$505P5\\5|5",
        "{9;ju",
        "k'$A#",
        "3\"373=3B3a3r3",
        "i{po1Fi",
        "V>=W!",
        "j#3a!'",
        "b>M4i",
        "x@4zG+",
        "MergeCommonBackup started",
        "pv@O=",
        "HbB80L7SY",
        "|!w8K",
        ".?AVbad_alloc@std@@",
        "E!@pG",
        "qc<%T",
        "HVD{'",
        "xry,H",
        "%;nh&{",
        "~m57A",
        "kc+@O",
        "YKe[h",
        "024Tv",
        ">9/u*h",
        "ERROR - unknown client type",
        "Custom action:  OnBegin: ended",
        "GfV_MI",
        "9/Y,N",
        "PbN\\//",
        "'-^.h",
        "20353:3",
        "J}`Sl0",
        "%u8 _",
        "5K=6Z:",
        "UX`O]Y",
        "=BMv\\",
        "DL_BIND_FUNC",
        "K-o]L",
        "d`Pu0p",
        "certificateHold",
        "__int32",
        "ECDH-ECDSA-AES256-SHA",
        "S}Do|",
        "f;l_b",
        "Create registry key for stop SBA service.",
        "jn#Xs",
        "ecc cert not for key agreement",
        "`DuH*",
        "9'9@9Y9r9",
        "O7>*i[",
        "CryptUnprotectData",
        "rkdwmH",
        "REMOVE",
        "~wugLM",
        "_^;D$",
        "g'wI6",
        "[+J'C",
        "Et S0F",
        "<2nx@",
        "[{-!P",
        "old SSL session ID is stale, removing",
        "RJ8>QSP",
        "WhL5#",
        ">=GDQ\\4p",
        ",OjFi",
        "&*='A",
        "%Ib$fW",
        "XZa5)K",
        "; ;$;(;,;0;8;P;`;d;t;x;|;",
        "$3-L)",
        "RM!vUK\\",
        "~KQx&b,",
        "SeL ez",
        "88taL",
        "cLiqe0b",
        "dLve)%",
        ":8;I<",
        "f8iT[wh",
        "netvna.inf",
        "5U!~^",
        "*8Vrmd9",
        "< <(<,<8<@<D<P<X<\\<h<p<t<",
        "vG)*A",
        "5`P$y",
        "RegOpenKeyA",
        "06^(c",
        "'X#-UG",
        "keylength",
        "PINSRW",
        "OCSP_BASICRESP",
        "0X<d7Q",
        "\"g_[B",
        "`managed vector constructor iterator'",
        "PSRLDQ",
        "1(&>Rl",
        "xrX!I",
        "9G:Z:",
        "+-G \"",
        "2]|egqbD",
        "H,`m@Y,",
        "`_0ZF",
        "eC?CG",
        "a D C",
        "b!F%j]",
        "B:iPH_(q",
        "7(8^8",
        "W8^(ue",
        "b&Q Gw",
        "!c5y}",
        "oe_P5N",
        "/1IF=",
        "'W>@7",
        "=Q-Qg\"",
        "MicAR",
        "B(:W)",
        "d@t6*",
        "W62Dh",
        "@kbl@",
        "SetCurrentDirectoryW",
        "Gh1=+",
        "lFa,`<",
        "PWIg }",
        "r6Q4L",
        "PVVVV",
        "irm`0",
        "jYp5|",
        "7^K@uALL",
        "]lc=R",
        "Ru1Vo",
        "`anonymous namespace'",
        "\"SH<\\",
        "[3VbV",
        "SgqC<%",
        "dd+?1G",
        ":x >b8o",
        "BXQyz",
        "6L7[7m7",
        "SHELL32.dll",
        "TXXMj",
        ">E?P?X?",
        "<aT\"h",
        "Q]70]",
        "rw-C?",
        "z\\,>od",
        "$(LZh",
        "* p| ",
        "2|dMaL",
        "eoNc?",
        "bFU7f",
        "3%AL\\",
        "            />",
        "5+525V5h5#6V6",
        "X509_PURPOSE_add",
        "81_L>",
        "s/4iZ",
        "=#=?=D=L=V=a=l=w=",
        "tSPqm#'-H",
        "I~./\"",
        "nK  h",
        "x`#1pK\\[",
        "F.081",
        ".Visual C++ CRT: Not enough memory to complete call to strerror.",
        ".>~w5",
        "JvmDS",
        "2\"2<2Z2",
        "P*@ps",
        "7dpd(",
        "TA!r|",
        "=|T O",
        "\"9&9*9",
        "$(S/I1(",
        "'C.*z",
        "6Y8@C",
        "sP^*[",
        "WKtlJ",
        "9`c$d",
        "S$ix-",
        "$hHu;",
        "zDI,e",
        "y*D.[",
        ",KM;'1",
        "ZwKiZwKi",
        "$Whh>",
        "\\zonelabs\\osfwrules.xml",
        "3:%FY",
        "m!Mhr7",
        "WY<+5",
        "2\"2z2",
        "tls1_cert_verify_mac",
        "_0P7d",
        "L$(QPW",
        "fP(=X|b",
        ";Z;e;",
        "{ak+j",
        "dm^w\\",
        "[#]Aq",
        "\"!'lb",
        "kew\\3",
        "<\\QLN",
        "y5 't",
        "(G%$^",
        "535:566C6f:t:",
        "p{k@e6",
        "TrendMicro Internet Security 2002 (All SKUs)",
        "CreateLocalCatalogXmlForUpdatingComponent(\"%s\", \"%s\", \"%s\", \"%s\", , \"%s\") - begin",
        "SSL_GET_SERVER_SEND_CERT",
        " oEl0",
        "Xm%vg",
        "dD'|:G;",
        "*&bF\"",
        "3Q$%GFL",
        "'lbAg",
        "o3;^1",
        "ebcmP",
        "5P5`5",
        ">.>3>8>H>M>R>b>g>l>|>",
        "2fM\\r",
        "6>mD9i",
        "vb3rW[",
        "(!,oi",
        "UTF8String",
        "Z\".w4",
        "sOO\"Q",
        "qn_+_",
        "DH-RSA-AES256-SHA",
        "VF>.}",
        "c-G]Y",
        "s->d1->mtu >= dtls1_min_mtu(s)",
        "e<R18F",
        "p3T9S",
        "=U`OB",
        "Rx{cW",
        "V2I_ISSUER_ALT",
        "It's a cached msi. No need to change registered package name.",
        "jz*YCa",
        "5%)&nP",
        "*9=HR",
        "*{aW(",
        "? ?$?(?<?@?D?\\?`?x?|?",
        "failed to execute view on ServiceInstall table",
        "ugoc&K",
        "t[OwC",
        "-eWl\"",
        "IsValidSid",
        "u-FS9",
        ")nI7_g",
        "!RA|6h",
        "P<fg_RrV",
        "(d/!m$",
        "+XI:]",
        "SetSCUIAPIMode",
        "#pot_",
        ">$lY~z",
        "0=1C1",
        "8,8<8@8P8T8X8\\8`8h8",
        "<0=<?",
        "5'6K6",
        "K4 G8",
        "XmSSd",
        "7$8P8y8",
        "`f!oX",
        "p5wEj",
        "__std_type_info_compare",
        "hxWO(Cg",
        "Netscape Revocation Url",
        "a |9u",
        "0/0H0a0z0",
        "_8Co_",
        "?4?M?f?",
        "tuyWY)",
        "1!111A1a1q1",
        "\\L*O|s",
        "Phl4M",
        "pj3f&",
        ";:PG w#",
        "qAhw0",
        "S~.?Wp",
        "WixShellExec",
        "no stream resources",
        "c`tI|",
        "6(60646@6H6L6X6`6d6p6x6|6",
        "KLKjJk",
        "Zm&~eN",
        "t{Y%,6",
        "brZfv",
        "777G7f7",
        "C0A05",
        "pp~.|",
        "4ga7j",
        "a?GDSZc",
        "8tO,n",
        "SzS%S.S7@@",
        "t$0j_",
        "v@\"bj",
        "4 4(444X4x4",
        "<&(EM",
        "*J72w",
        "_cIp9",
        "]KCH`",
        "<0<6<<<B<a<g<",
        ":^WRW",
        "M_4?d^",
        "WB^?$",
        "484X4x4",
        "t!t)t1t9pA",
        "q;4+W",
        "Ph8Y!",
        "&GSAn",
        "'m5/ZP",
        "mC.DN]i{",
        "SSL_CTX_set_client_cert_engine",
        "luNK}",
        "5-t.:",
        "%aM{,I",
        "gaz5Iv*D",
        "'!py8)",
        "SeShutdownPrivilege",
        "\\76QDb",
        "AA$VPyg",
        "+}q;'",
        "o$H D",
        "4)4.434U4c4r4",
        "%*s            ",
        "=:[(4",
        "\\%#R.",
        "':fp?|1",
        "=D>H>x>|>",
        "737L7e7~7",
        "DHE-RSA-AES256-GCM-SHA384",
        "*|YJZe",
        "\\w.z''",
        "PVVVVVVh ",
        "\";S$g",
        "xk_KZ?tEbgc",
        "\\opFzR0-",
        "7Xp+\\",
        "6,767C7J7Q7X7_7f7{7",
        "ouNjj",
        "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffffffffffffffffffff000000000000000000000000000000000000000000000000",
        ".Ifc0",
        "w`@L&",
        "j\\5rJ+",
        "Ds@~V",
        "sRm&2&c3",
        "2[gJ6[L",
        "E]er-",
        "r|RjC",
        "r{Dn`w",
        "aBN$;",
        "hh!Qx",
        "bL{y:",
        "}KK(*T3?T)",
        "&c P2F",
        "7&959f:u:",
        "failed to allocate target registry string with HKU root",
        "Removing old policies from: %s. Result: %x",
        "pq+WR",
        "1|f{'",
        "UM~m]",
        "l$hG0v",
        "amtkr",
        "+b03'",
        "d)paL",
        "((_Oh",
        ":\";H;d;s;",
        "@8Yp>",
        "33U6s",
        "b/h#yv",
        "|rKnB",
        "CMOVNS",
        "&nElHy",
        "6HRXILE:lJ\"",
        "7Ur-f",
        "^q]A$6",
        "\"6dDP<6|",
        "7,808`8d8",
        "failed to get XPath for XmlFile: %ls",
        "D&Z+:",
        "-iUYbM",
        "K}d(}",
        "Ioi&m",
        "}QTjo",
        "*.G]P",
        "Successfully copied %s to %s",
        "D$XPV",
        ";%;5;P;c;k;{;",
        "J6'4G>",
        "\"b?{c",
        "<-=2=S=X=",
        "http://sv.symcb.com/sv.crt0",
        "set-brand",
        "NvxK&",
        "Ag*g*",
        "Trend Micro Internet Security",
        "rJf;u",
        ",1}<jm",
        "CQo}%",
        "Yka|zl@j",
        "control command failed",
        "\\$0UV",
        "?,?v?",
        "0 0@0",
        "DSA_SIG_new",
        "9):J:e:",
        "Jw$BQ",
        "|:OMrx",
        "ot&cE",
        ",)!QbJ",
        "tVGb1",
        "OY)d'",
        "q+`}t",
        "A9zpd,",
        "3l~gP",
        "Rp[YG",
        ">,p/x",
        "162B2\\2",
        "???o?",
        "lTk;XNvB?",
        "a:#se",
        "VI)!=Q",
        "=_!OK@/",
        "'1+p~V",
        "#PhQr",
        "}1yYG",
        "A^)iT+",
        "N/vE@",
        "S`}PT",
        " 0xf7",
        "tqeO%",
        ".\\crypto\\x509v3\\v3_utl.c",
        "t881e",
        "<%ZDQ",
        "?4?:?d?{?",
        "76[+h",
        "`z'u`",
        "IO:(?",
        "? ?D?L?T?\\?d?l?t?|?",
        "(N#8F`",
        "17?*=id\\B",
        "9-929>9K9U9t9",
        "\"cz^i\\",
        "c0|XR",
        "%P|(4",
        "\\ux0>",
        "(/BaA",
        "Adding Symantec to REMOVEPRODUCTS",
        "XYs\"W",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 certain programs. The deletion }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid16665164 and/or restriction of access to any }{",
        "GjFh4",
        "zdq/1",
        "\\0,0@",
        ".I]RtH",
        "5d)TxBQ",
        "{S-sg6",
        "2D\\R@",
        "AL&=N",
        "(f+\\C9Z",
        "aes-256-cfb",
        "'TkWe",
        "{f6hO",
        "KcqxA",
        "|WwkM,",
        "x;(6D",
        "l$lVU",
        "cmd /c \"del /F /Q \"%s\\AdminMode.bat\"\"",
        "eRk~#",
        "B,g*02",
        "\"\"Df**T~",
        "1$'46b",
        " export",
        "D$DPV",
        "3-4`5",
        "uBvw<",
        "3}WH`F",
        "{u:@X\\",
        "LUla6X",
        "\"J@5C",
        "!*n)d",
        " M';M",
        "m' cD",
        "facsimileTelephoneNumber",
        "Stop URLF Service",
        "camellia256",
        "l;mec,",
        "U:iaX*r",
        ",X:2t",
        "zNs:Nj",
        "DWy N",
        "2`PZ2F",
        "L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "uF]ahd",
        "'0]dQ.",
        "9Cf:NA",
        "u4su%",
        "jOdT8U_",
        "ll`e|",
        "`#l`O",
        "<(=[=",
        "3T4k4",
        "d:Abj",
        "(3Qj6",
        "+<LJ$Y",
        "4)4.4",
        "6F6S6[6n7",
        "bad dh p length",
        "1+2R2",
        "L`ex5",
        "0z\\X~?SWI",
        "3*323",
        "XGl+|",
        "4Lx0~",
        "B<@fSco",
        "rt6vLQ#c;6",
        "^ _`_",
        " \"#$%&'()*+,-./012345",
        "1 1$1)1-1@1E1I1\\1a1e1t1x1|1",
        "j^gXM",
        ")K.EUv",
        "\\fi-360\\li5040\\lin5040 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'07.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "ysCM8",
        "M+a;e%",
        "(;J(?",
        ">%>e>",
        "FRB{y",
        "Cymz}l",
        "M,wK(",
        "T[vQ9",
        "6k+4y",
        "@ \"dV7[",
        "(1V+F",
        "y[r.R",
        ".3^r^",
        ":  Set DW value",
        "ea`Q4",
        "f5X^^",
        "5_H$&",
        "6!\\y}",
        "&y8l+",
        "hI$:8",
        ": ;m;",
        "99:D:S:a:p:",
        "x]G}c",
        "IZtME",
        "oZ(>F",
        "f]67/mc",
        "~j_(.>",
        "`S-|}\\",
        "pg+'mE-x~",
        "hcFmoxg",
        "J>WGwb",
        ",&v/a",
        "bIsUpgrade=%s",
        "}E@r\"",
        "/@+?7RG",
        "OS:I:ravpn_is_v1",
        ",name:",
        "H:!AnA",
        "??4_Lockit@__std_alias2@@QAEAAV01@ABV01@@Z",
        "v6Oe7",
        "}Z}=h",
        "w<O9(",
        "D`]UY",
        "`&J?y",
        "WX)F'v",
        "TSA server",
        ":BAD OBJECT",
        "K)V@<XZ0B-",
        "cms_Receipt_verify",
        "g+7j-",
        "859O9X9",
        "h&|L%\\",
        "O,F{f",
        "t and to provide Check Point with specified information regarding Your experiences with the installation and operation of the Beta Product.  The }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13173947 l}{\\rtlch\\fcs1 \\af1 ",
        "\"hh>m",
        "h+-[m",
        "'prB2",
        "wY{ny^",
        "E3E,B",
        "C ;Cw",
        "P3ol&",
        "bkc]Z!",
        "*s.q0\\O",
        "*ki5I",
        "]4h,9",
        "x%Ph,e!",
        "Inside...",
        "wI6^Sw",
        ":G:|:",
        "StopInstHelperCancel",
        ">^Q os",
        "jU)U2o~",
        ":!:C:c:v:",
        "yan=Z9:",
        "XdQI*c",
        "dmo7<",
        "1,Dxn",
        "{/coz",
        "HhAeh",
        "gJPj|",
        "9ax{kU",
        "seed-ecb",
        "(+#*;",
        "p4m[P1[[79",
        "RtlCaptureStackBackTrace",
        "ProductVersion",
        "7,7L7T7\\7d7l7t7|7",
        "J|oKZ",
        "[vOfJ",
        "Gzw1k? E",
        "sbSIc",
        "&@0&Q",
        "f&P2+T",
        "5sRy@",
        "H4s*B",
        "WgWO;a5",
        "{(X(}",
        "T$2Wu,",
        "?ibh;",
        "MAIL FROM:%s",
        "P^FvH",
        "DH-DSS-AES256-SHA256",
        "]B828",
        "AztQ*",
        "fD8Ra",
        "GetFileAttributesA",
        "i\"0lz",
        "createComment failed",
        "=V>e>}>",
        "GPv J",
        "/!Ns@f",
        "vt7\\n",
        "0x%02hx%02hx%02hx%02hx%02hx%02hx",
        "~_C2*",
        "J>%F%~%u",
        "NAME_CONSTRAINTS",
        "@Qw@N",
        "{IxT[",
        "InitializeSecurityDescriptor Error %u",
        "<;<G<U<",
        "n$lPmK",
        "2v2@6D6H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "M7lmx",
        " (8<q",
        "A\\p{1uc",
        "empty file structure",
        "lJ!0+",
        "E4\"jpj",
        "id-smime-mod-msg-v3",
        "?#?'?+?/?3?7?;???C?G?K?O?S?W?[?_?c?g?k?o?s?w?",
        "#sYtH",
        "km;c`",
        "jZ\":D",
        "rJBbY",
        "riwb{",
        "$Eb90N",
        "CacE+j-",
        "b~o\\k",
        "AW6Z!",
        "De-RT",
        "5Ei!m",
        "IC/?([",
        "nw$}@]k",
        "WixQueryOsWellKnownSID failed to initialize",
        "o%t6'",
        "%o;EQ",
        "/pSDr",
        "3D4]4c5k6",
        "RjUw&jWi",
        ">>E9xw",
        "dEVh`6S",
        "GOLCPCkC",
        "^BJq'Fqg",
        "wCZsS\"",
        ":\"}ZH",
        "YbNOlQ",
        "Failed to find files with pattern: %ls",
        "t$,9X",
        ">p}\"5",
        "O(hHj",
        "~B-~z%{",
        "tb9^4~]",
        ">65N^NO",
        "A%\"YO",
        "WFnjE",
        "|%wx-n",
        "%s\\%s_%s.log",
        "94;N<",
        " ]b(9T0K",
        "k(CeI.c",
        "9M5hik",
        "ofyVa",
        "Rv;nW0{",
        "$?J6s",
        "%8sIssuer Unique ID: ",
        "DirName: ",
        "95@(`",
        "WG9n*dU",
        "4A5s6",
        "8<8H8h8t8",
        "r`)LG",
        "cbihB",
        "a5/!x",
        "V,@',",
        "d9ES@`",
        "u>8|Qo",
        "blrGb",
        "\"a}{:",
        "c[-1]",
        "7!7D7g7",
        "nQML=",
        ".j1#G]",
        "Ckly}",
        "aUJo/",
        "JQQ11KLQQ11MNQQ11OPQQ11QRQQ11STQQ17",
        "90949@9H9L9X9`9d9p9x9|9",
        "N.`p$y",
        "wap-wsg-idm-ecid-wtls9",
        "Secure Electronic Transactions",
        "L$T$u,",
        "/:543G",
        "failed to initialize COM",
        "=;=H=X=c=",
        ">$>,>4><>D>L>T>\\>d>l>",
        ";#;(;-;=;B;G;W;\\;a;q;v;{;",
        "3/G~hA",
        "rnLrH",
        "Lm1D5)",
        "8bdf;",
        "DSA_sign_setup",
        "jHd6G/",
        "[v0Gz#",
        "BCryptCloseAlgorithmProvider",
        " ] PZ",
        "xfl;^",
        "F=|m{<",
        "P~obg",
        "Gj\"gUz",
        "4E4P4",
        "&w6YGJs",
        "y4CXm",
        "OgUI:",
        "D7(9zm",
        "vspubapi.dll",
        "*<nUBL",
        "[_&hc",
        ";}NJ:",
        "D$8WUVP",
        "$-HpT",
        "M>cVU",
        "aC(nk",
        "GetVersionEx failed, err=%lu",
        "WnSR6",
        "n>#dp",
        "{8tQACn",
        "Global\\tvperf_stop_coll",
        "~Yye*h",
        "6B2AN",
        "IM&X1",
        "&||#RV",
        "05lL!",
        "D7q/;M",
        "IiupF",
        ">\"?3?H?[?",
        "SPSVQ",
        "UninstPwdHash",
        "msvcr90d.cpp",
        "_~[OB",
        "4#x=M",
        "<#<'<-<1<7<;<E<X<f<t<z<",
        "3%,3>",
        "FFX~Y",
        "^_%<7",
        "~bkl)",
        "',Zj\\",
        ":#A\">*",
        "regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.",
        "mO%gQ",
        "&@k%b~Z=K",
        ".\\crypto\\asn1\\p5_pbev2.c",
        ")kB1f",
        "^\\0*1",
        "c9B9$",
        "1Aui4",
        "1$2@2K2\\2g2",
        ">;=aA",
        "093cW",
        "96:L:",
        "DrDhD7H",
        "FH]Ln",
        "2#2F2X2",
        "b$/fWQ",
        "q\\6\"L",
        "saSjI",
        "`vector constructor iterator'",
        "1 2[2",
        "*k<.l",
        "#W\"NC",
        "S2fg8",
        "Z!X@*",
        "CkD^s",
        "=$#]{",
        "j\"jBibh",
        "unknown algorithm type",
        "cEImU",
        "FeatureIMSecurity:  imsinstall.dll is older than 4.5.88 so (maybe) call old uninstall function.",
        "_mDPv",
        "87h,)",
        "mU1mj6*",
        "#eko&ZGF",
        "@1beL`y",
        "|&`($R",
        "(}c])",
        "^UVT8",
        "ECDHE-RSA-AES128-GCM-SHA256",
        "5B6V6",
        "vxye?k,",
        "NFvI\\_<?S:",
        "X8:gps",
        "Nb$$,",
        "5w7g%",
        "L%H3`",
        "edZc;",
        "3>C<M",
        ":);h;{;:<`<",
        "?~3*x",
        "b,VDr",
        "f5G$'",
        "5*575R5p5",
        "c'oYF*#51",
        "VLq1!",
        "DH Private-Key",
        ",IZWw",
        "EPAM_InstallRollback finished.",
        "%mM,'",
        "c5U8$",
        " 0x74",
        "dfQ;l",
        "}_Mv`\"T",
        " !\"#$%",
        " 0x16",
        "tO_3gp",
        "0kQm5",
        "bq^n%{",
        "k!3G/",
        "<8<E>",
        "+D$0P",
        "s1sMsQsApc",
        "~af*4",
        "e-gBK(",
        "C@w=v]f",
        "&kH@tv",
        "sww~^",
        "FoefX%uKuU",
        "Global\\vsdrvevent",
        "on^@3;",
        "$mecNc",
        "l!%Yu",
        "#D])G",
        "hcH&G\"y",
        "<z~$<A|",
        "engine routines",
        "x#=D>",
        "5#616J6o6",
        "&'()*",
        "M0Q0U0Y0]0a0e0i0",
        "CertEnrollProxy.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "mu]IE",
        "v^HRW8",
        "l8FT=",
        "9SxhXP",
        "c7060abb0884a4eff7a93dfeae8bf9e194e720169aaa06c3e2433fcb68e1763dbf7f82c985a4a725085b787086a37bdbb55fbc50d1a33ccd311ba548b6309512",
        "79482a9c0498f184b4bd2991deb58df7dfbb8ad755446282607d22d771db8b944ad79796a40fc3585ee62949606ecc458c15bc8a702910f808e8c66c69b9565b",
        "proxystub.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "K+;ZiX^",
        "V1Wz-",
        "u_j6h",
        "E6CrD6H",
        "=L%)q",
        "-dQ\"%",
        "p@4`}(e",
        "CurrentBuild",
        "8ho>8f",
        "a5EE/",
        "Za/-&",
        "I}Ac=cs",
        "YeS^f2H",
        ":ofhc",
        "pSourceFunc",
        "(~DeFg",
        ";\\$ wg",
        "LoadXMLDOMfromFile failed",
        "apinA",
        "8f9v9",
        "!uU|P",
        ";R9\\,z",
        "ARIB!{",
        ";%<u<",
        "=%=X=f=",
        "6l2vwL3",
        ".?AVunsupported_os@Concurrency@@",
        "V$pv$",
        "j@\\6'",
        "LM1X^",
        "W;u1>",
        "VZE%k",
        "setct-CertResTBE",
        "5K5q5",
        "O~^K4M",
        "yyb.O>",
        "9i+w%",
        "}A>rV",
        "w(lgh",
        "Bg*}x",
        "en-bz",
        "AUDC&",
        "yYP%`",
        "+7+YPs",
        "ZQBmo8",
        "9&:=:R:d:",
        "lF.j3",
        "5~!GFu",
        "FKS,5",
        "(3ZRRMj!nv",
        " ' Gsf$",
        "DWCV:",
        "hA$+;?",
        "Vd0:,",
        "NAOCRD",
        "\"xpy-",
        "K1^.e^",
        ":S\"4s",
        "-q,.o;",
        "PKCS12_SAFEBAGS",
        "lcO/<1",
        "/z.N-",
        "64686D6H6L6h6l6x6|6",
        "jojej\"",
        "u|QK&",
        "/L.()",
        "6S-[J",
        ")c9QLY",
        "NHt*>",
        "_{)IA",
        " y|GXf#",
        "D2I_ASN1_GENERALIZEDTIME",
        "><,<j",
        "1#2>2f2",
        "7(7,7<7@7P7T7d7h7x7|7",
        "z$Q;~a",
        "2@hab%o",
        "Zfnv!*",
        "^}\\c\\O",
        "6?u^i",
        "do_dtls1_write",
        "?~8 ^",
        "7Z1G1",
        "+\"+++p*",
        "3?&6P",
        "DW0;H",
        "eu\"7|6",
        "mJT61v",
        "(TRwH",
        "aICB@",
        "Yb-;s ",
        "R-6f#",
        "StopURLFService_rollback",
        "panP~",
        "keW%b",
        "q+&`>",
        "-S6,+",
        "/vRJo",
        "FC$N=",
        "#,v J]|",
        "Lt]fN_",
        "PSSSSSSh!",
        "szImsinstallPath",
        "BgYb)",
        "3_Q0K",
        "n+fuw",
        "3vs6a/",
        "Enterprise Evaluation",
        "DB'vyx",
        ")`m(t",
        "`z'LW",
        "f$SfJ",
        "081=1d1",
        "v^d{E",
        "0yPyAS",
        "m<*<z?",
        "8'8O8V8`8",
        "0h<F!",
        "bU]x-",
        "$cb~K",
        "6WoR:",
        "B7</N",
        "encode error",
        "[@ oZ",
        "xcIN/oF",
        "W$wEDuEDPD",
        ")W6o&",
        "urTAx",
        "\"VB~oM+qx",
        "4&494^4",
        "oA/[HC",
        ":2;C;",
        "8f z}",
        "[!+G-r",
        "}#Ik}",
        "B'KT#",
        "gsQr)",
        "c_}!6M",
        " X L86",
        ":%:T:t:",
        "'UXda",
        "udz{m",
        "yQf!o",
        "{a.(H",
        "-!=ZF",
        "lib(%lu)",
        "4&\\J^_",
        "1cXa;S",
        "=.=B=V=j=",
        "QuwiA",
        "#8L_q",
        "E[o6&G",
        "Bad argument",
        "?( M[+\\^1",
        "4$414C4L4V4c4m4r4}4",
        "[-&#Z",
        "L8\"jaL",
        "787<7H7P7T7`7h7l7x7",
        "Fs;&i",
        "P~tF1Z",
        "l$(GU",
        "IEd;S.",
        "#uDpI",
        "l%S%I",
        "_30-$",
        "4&7J9",
        "4L4V4`4r4{4",
        "ZWd8te",
        "[WinFW] SetWFStatusVista, CoCreateInstanceAsAdmin failed.",
        "destination address required",
        "::>s}",
        "ASN1_PRINTABLE",
        "certId",
        "pzh<<",
        "6E7y7",
        "6/Q+vv7.",
        "4fT#96",
        "(_kTn",
        "tc^'hf",
        ">$>(>,>4>L>\\>`>p>t>x>|>",
        "`\\jdn",
        "+ih4{",
        "@&\\L,",
        "fone|",
        "_pz9b",
        ")5m8%I",
        "=C#^FC",
        "vHf[>08:",
        "Q-2qH3=~d",
        "sptrv",
        "Mt+t%",
        "9%& y",
        "*U5lVBN",
        "C8Y9a^",
        "A.C>E'",
        "$M_\";aX",
        "CD$HPj",
        "id-ppl-inheritAll",
        "IRRx/5a",
        ",EKC.S",
        "Connection #%ld isn't open enough, can't reuse",
        "6O7U7j7w7",
        "Q\"4qu",
        "Internal Name=PiReg",
        "oQ+`$",
        "q_GF!",
        "Zmn!q3",
        "V3clN",
        "RSX*;",
        "too many symbolic link levels",
        "Bu6[ ",
        "NJ*Mq^",
        "^vFnC",
        "i2\\GA",
        "PbfHJJ",
        "ngrfW",
        "UNINSTALL_PASSWORD",
        "x~RMj",
        "\"pbbU",
        "|$HPh",
        "687>7z7",
        "::;@;D;H;L;",
        "zJs+[",
        "BV@;r",
        ":qoj8",
        ";,Nr/",
        "XMEZv1",
        "nXHXAa1W",
        "unsigned ",
        "wMDsJ",
        "+.rPm",
        "kkgSa",
        "&EP\"Q",
        "Sx\\wH",
        "`0jq2ZWx",
        "producedAt",
        "7\"7>7Z7v7",
        ";^;x;",
        "MSVCRT.dll",
        "=|$D)sH",
        "<*gk$T",
        "(-\\4pf",
        "IReB,_",
        "XsOM%",
        "Z9;|D*",
        "ssl_cert_inst",
        "S',]4",
        "WUF`m",
        "T9|x~4",
        "j?|tu",
        "E\"XEa",
        "fLp9q",
        ";5H_#",
        "=<kJ9",
        "=)=A=",
        "$PsX%",
        "L[E\"p",
        ">_pZh",
        "B\\~2m+a",
        "8d#FbbjaW[",
        "o\\Hpm",
        "x(8fb''",
        "O\\,R`,}",
        "O>:N}",
        "U.gbBKHS",
        ";Pk2$cH",
        "7odzgm",
        "3L$83L$",
        "dh_paramgen_type",
        "\\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext30 \\styrsid13065977 List Continue;}{\\s31\\qc \\li0\\ri0\\sb240\\sa60\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel0\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 ",
        "181v1",
        "U%f,'",
        "<Ucen",
        "K5%P_",
        "'`[Tl",
        "F_klj",
        "[6YZ&~",
        "Failed to copy ca script.",
        ";NGuOn",
        " ^j`-",
        "4l5r5H6\\6d6",
        "8]_Au",
        "QPhdn#",
        "+l.OyP_",
        "LAUT&",
        "? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?|?",
        "keyfunc",
        "D$ ~Mj",
        ";kb[,",
        ":9!,T",
        "pf&`r",
        "BSjJMI)",
        "=1>N>",
        "\\vsmon_disabler.dll",
        "(8]j$$",
        "}}1;(",
        "n.Z7a",
        "Uw,uyTx",
        "=#b =",
        " BC^MX",
        "'Y3+]=",
        "Direct3DCreate9Ex",
        "3%4d4s4",
        "[0k_|J",
        "kcEfrG",
        "og;Fs",
        "lAB=CY",
        "),)_o",
        "$ruA?",
        "@XLnx",
        "Invalid or truncated security directory",
        "+Xd/ne",
        "PEM_READ_BIO_PRIVATEKEY",
        "%Bm!C",
        "5$5,50585@5H5P5X5`5h5p5x5",
        "6 MQ&",
        "Everyone",
        "#aKwQUG+",
        "w}%SN",
        "qSI(q",
        "^kO7!f",
        "N-Qoptzi",
        "JG7H^",
        "%7W$v",
        "P%7Y*",
        "a@@)od",
        "jq]T$",
        "X_z>G",
        "BZ\"vG",
        "vybc&",
        "Z|/z1",
        "zO.u(",
        "@v:1Yc",
        "WfMfx",
        "INSTMLF.LOG",
        "lC9[;k",
        "7w^JkP",
        "SEC_E_SMARTCARD_LOGON_REQUIRED",
        "c'MkE",
        "070P0h0|0",
        "qYkLG",
        "m6/~M",
        "0jd@z",
        "1%Q+xj",
        "<( u8",
        "eu2[m@",
        "Z>/_k",
        "Chunky upload is not supported by HTTP 1.0",
        "TV_STILL_RUNNING",
        "BAA+H",
        "Helper::replaceOrAddTagIntoVSConfig(%s,%s,%s)",
        "1QO>8",
        "3`B%f",
        "SB$$B$",
        "S>]u2",
        "Wc-tF[",
        "{c+4,",
        "{NpSf=",
        "\\V@*?v",
        "\"[%Kv",
        "kneSCV",
        "Vj0XPW",
        "?6!?8",
        "api_ms_win_core_libraryloader_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "j?+;$",
        "PKCS12_BAGS",
        "b%b-b5bMb]bmbub}b",
        "8o>RT",
        "`I;#,3",
        "Could not retreive ISACTIONPROP1",
        "CollectBootStatistics",
        "X3`3d3h3l3p3t3x3|3",
        "\\drivers",
        "xUMJq8",
        "<v%Fe",
        "Failed to open view on Binary table",
        "X)eS^#",
        "r<`1yJ",
        ">H>R>W>n>s>",
        "qF~H0",
        "Dsu =",
        "Improper link",
        "6,6H6h6",
        ")In+,",
        "Q;''g?",
        "Fww@>k",
        "7\"707d7{7",
        "5u{`Ru",
        " yxYu$",
        ">#>Q>a>i>y>",
        "?eg]s",
        "cpVg0",
        "Der7(a_",
        "w)~xi",
        "eContent",
        "-(r\\M",
        "yl[~%",
        "bY74j",
        "cS8l;",
        "Dx@R]q|",
        "Ew8s&",
        "QSQ*xq",
        "y\"y&y*y.y2y6y:x>",
        "C\\_.2",
        "^yYbs*U",
        "R[u/_",
        "HQkw{:",
        "[WINFW] Adding %S to windows firewall exclude list",
        "R5,k>",
        "`TvCo",
        "wM-G.",
        "6 6&6,62676=6C6I6N6T6Z6`6e6k6q6w6|6",
        "QSj W",
        ">fP'y",
        "k_Zm}",
        "#D#'g",
        "1 1(141T1`1h1",
        "9D:H:L:P:",
        "D WARRANTIES SET FORTH IN THIS SECTION 7.1, THE PRODUCT AND ANY SERVICES ARE PROVIDED \\'93AS IS\\'94",
        ";*=1=",
        "UPxs8",
        "<9!or",
        "@G\"E`",
        "*JTh:",
        "Ix/_?DA",
        "C|x@o%G",
        ":1vlu",
        "F=+JP",
        "PADDW",
        "0&+h5c{",
        "5C#~O",
        "UpdateZoneAlarmXml:  Failed to load updating.dll.",
        "M2}|P%bM",
        "!C7`X",
        "*!4r5t",
        "yIPL`%",
        "9S^vm",
        "4,Gfb",
        ";/;=;N;f;l;x;",
        "V|[:3",
        ".(=Fv",
        ".?AVIRolloverFile@@",
        "s8#!\"'a",
        "u)8D$",
        "2#2D2",
        "8JFaR",
        "q f;&",
        "3e3Y5",
        "I |jm",
        "2Rzu2",
        "``gj]",
        "MdSPsz'",
        "vPp^c",
        "X,V;d",
        "lcmLp",
        "]1a9]",
        "f{>89",
        ";k8?p",
        "&6'&qY",
        "T$L3L$ ",
        "+wx2t",
        "a#?Of}",
        "hz[kU",
        "setct-PIDataUnsigned",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  provided}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid9391338 ,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "=!uR,=0",
        ":9:|:",
        "`hjz%",
        "'\\&)&U",
        "2%4G5",
        "zE(\\3",
        "1nE({",
        "}TBhB",
        "^d1JF",
        "Failed to get remove folder mode",
        "uEe.J",
        "c26\"7quW",
        ":H;f;",
        "Modification of %s not required",
        "K#W:HT",
        "eSvD2",
        "P3lX%",
        "mGX8m",
        "QQSVWd",
        ">5>N>s>",
        "2I2c2o5",
        "}:YS0",
        "D$dSUV",
        ";F<J<N<R<V<Z<^<b<f<j<n<r<v<z<~<",
        "=A5.1",
        "WSAStartup failed (%d)",
        "a1OP~l",
        "u5WVS",
        "CloseThreadpoolWait",
        "(6GI9",
        "3\\$81",
        "z^xxH6F",
        "SOFTWARE\\Classes\\Installer\\UpgradeCodes\\A3122864DEC94E444992B26D2D1900E2",
        "5(5D5`5|5",
        "2\"2;2T2m2",
        "8T9a9j9",
        "}#b%q",
        "yk ,>",
        "CoInitializeEx",
        ".t8wr",
        "Sy%{~",
        "$y85\\",
        "invalid or inconsistent certificate extension",
        "Z(1}J",
        "rAU0vH",
        "'nz^>",
        "?=OTf",
        "D$@UP",
        "S%LX/i['",
        "h.%2S",
        "pO7<x",
        "|$`3t$0",
        "7%8:8i8}8",
        "rx8cjs!",
        "B07+Z",
        "<]:lO",
        "I)|tlW",
        "x</'qQmA",
        "Authorization:",
        ")K$aL",
        "llL&*y",
        "/K$K*K1KBKPKTKZKzK",
        "Q<=2L",
        "****************************** UninstallSDL ended **********************************",
        "(yP9q",
        "'{nOv",
        "eeuU}U",
        ":&;8;Y;d;l;|;",
        "Pm*EMm/",
        "=!=-=3=7=?=C=o=s=u=y={=",
        "ex.a;Q",
        "SUPPRESS GO AHEAD",
        "*]Fj%",
        "G=y!j",
        "c5z3iH",
        "(h@M#",
        "~L2HM",
        "CNTs^/",
        "K4~Qg\\}",
        "X_C7d",
        "8Y9t9",
        "xQ\\$cQ*W.w",
        "!!(j:",
        "657N7S7{7",
        "p233Y",
        "IOca'D",
        "1$1<1L1P1`1d1h1l1t1",
        "b>=OW",
        "05KK3",
        "GQ/%>",
        "M!'F6z.R",
        "Fo.7C",
        "}4bY:e5",
        "RWYdo",
        "inzA]",
        "bI.3z",
        "`]^S@",
        "@zs4Z",
        "Bad quota",
        " reasonable assistance in its defense. Check Point has sole discretion and control over such defense and all negotiations for a settlement or compromise, unless it declines to defend or settle, in which case}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "\\zonelabs\\Fbl.dll",
        "3A4N4e4a5l5t5",
        "PRET STOR %s",
        ".RvT?",
        "Q>\\AC",
        "5Qv(K",
        "x]7R~",
        "_Q?:2",
        "!-5/1",
        "m&1(W",
        "dA7YK0VvL",
        "*16.}",
        "gt#p+",
        "/L$C,",
        "D$$9n",
        "version incompatibility",
        "P$Mg-",
        "=.=<=!>2>s>y>",
        "u/p\\\\fk\"61",
        "BC(bA",
        "zF_T3V~-",
        "mx]+b",
        "%NGkM",
        ";; 5l",
        "erroricon.png",
        "dhpublicnumber",
        "^`^]w",
        "0=KbH",
        "]%M*J",
        "mvDL%x\":4 PA",
        "'WP)[",
        "bad dh pub key length",
        "JatQ(",
        "Directory",
        "SEC_E_INVALID_TOKEN",
        "8o}>C",
        "_p|/sE7",
        "@jPvu",
        "[@@w}",
        "`9r1P",
        "Am-R<",
        "y;]V]",
        "Failed to kill process on time",
        "2 OzW",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 2.6\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Evaluation License.}{\\rtlch\\fcs1 \\af1 ",
        "'2)Lm",
        "R#{bB",
        "QuJ<(W",
        "|$$ff",
        "6O6{6",
        "/%}9jdn'",
        "7G7T7\\7o8",
        "associatedDomain",
        "EDI:%08X",
        "hZ\"t(",
        "m`/tw",
        "invalid trailer",
        "W)tr@j",
        "%!B#J",
        "kW!s=",
        "zw/zb",
        "SetNP",
        " 0xd6",
        "%|hReND",
        "UpdateProcThreadAttribute",
        "e$}2T",
        "BZt!zKA",
        "+a&,@",
        "L)Djf",
        "Software\\Policies\\Microsoft\\Windows\\Installer",
        ">+HqD{",
        "A#nip",
        "im;GPlz",
        "?L?a?~?",
        "u\\j.W",
        "Non Critical",
        "Qd<9m",
        "failed to create file for writing {} - {}",
        "Ody@c",
        "!r]BAN",
        "KFDeh",
        "GH<Rb",
        ")/S;b",
        "FWUpgradePrepare started.",
        "VUX,;",
        "^|}Z2",
        "F2faT",
        "zx9HD",
        "keDCB ",
        "`dynamic atexit destructor for '",
        ".Km5iX",
        "U|M^YGy",
        "]AdK!5",
        "sO8Ed",
        "w1nYH",
        "mLv'{Y]",
        "1fJgRw",
        "HjNN{[",
        "6'6D6U6]6",
        "[UNHANDLED EXCEPTION] %s %s in process %s",
        "wss}1i",
        "nNc5o",
        "pIXYw`",
        "RKe.g",
        "cAS(4",
        "SSPQSS",
        "Network down",
        "DriverProductVersion",
        "`p)>:?",
        "VR^J.LTT",
        "D$4SUV3",
        "invalid compression algorithm",
        "HyS=fU",
        "x8Xu~",
        "?'?@?Y?r?",
        "90**f",
        "5,;,?Vh",
        "^k!_6",
        "5@l%!1",
        "uo8~M",
        " +5(&",
        "T-\"6C2",
        "`Tx{2",
        "tP-Sv",
        "/z;m.",
        "bvz-o",
        "2H')>",
        "818n8",
        "#j\"t?",
        "[3|XA-",
        "failed to get server restart delay value.",
        "rw_f^/",
        "ST4 q",
        "z XX5",
        "pkcs7-encryptedData",
        "]&Baj",
        "TGj{ Y",
        "7 8(80888@8L8l8t8",
        "greement will terminate immediately without notice from Check Point if You (i) fail to comply with any material}{\\rtlch\\fcs1 \\ai\\af1 \\ltrch\\fcs0 \\i\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "WYi71",
        "/qB-}",
        "PrivilegeCheck",
        "ee/P'",
        "i~f7E",
        "8$8,848<8D8L8X8x8",
        "@6\\M~",
        "nwv8k",
        " 5\"$,",
        "aZ#Q!",
        "E,B^t",
        "@M7vl",
        "sZI(nk!a",
        "Invalid OCSP response status: %s (%d)",
        "Jks6p",
        "8@9M9p9",
        ".R5jP",
        "z!8c=",
        "`~AA4",
        "D$PWP",
        "~9:Mg",
        "yatSK",
        "xlr^'",
        "2>3!4",
        "jo6WI",
        "O)_RL",
        "S@U(yR",
        "RU\"XF$t",
        "D8(Ht",
        "464F4Z4c4",
        "D?Yc%",
        "fPDN)",
        "LVVAu",
        "NORTEL7LOCATION.7F579463_4BEF_48D0_80B8_41508273B36D",
        "Is a directory",
        "[\"M$_aN.",
        "i__QfI",
        "|Apj.=",
        "\\UVs}",
        "2D** p",
        "e@q%f<",
        "Failed to create record to format string",
        "FUIMd",
        "/1E^7",
        ".?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@",
        "<b%Dh",
        "N0[0h0",
        "Ms?Kb",
        "7#727I7R7e7p7",
        "PreInstallCheck:  Kaspersky Antivirus installed",
        "fm!Vi",
        "8 Wee",
        "etK2`N",
        "<e(%,x",
        "LSZ'lR",
        "kpn59",
        "z;RN0ac",
        "\\ ASL",
        "_ymMgk",
        "*l`\\%",
        "PARSE_BAGS",
        " w@t7J",
        "us:+ a",
        "qRWu`",
        "/h0Q-",
        "5HALR",
        "7h7~7",
        "m1jIi",
        " fTyW",
        "VR;YVBx_",
        "m;]|3=`W",
        "ByB[1",
        "_d@yN",
        "Ql[SmG",
        "S,BNN4",
        ";*;G;};",
        "[+s2\"",
        "9N4uU",
        "^S-R\"",
        "tG)&w",
        "l(}H{",
        "2$2,242<2D2L2T2d2t2|2",
        "Ngc;$",
        "EE1#C",
        "-O&d5(",
        "ryU.rkE",
        "pU4SZ",
        "5-VUZ0/",
        "3H6W;q",
        "(S?(M",
        "8J9b9",
        "q3:Ju",
        "d[=|d(",
        "+_*F)]Y",
        "Client CERT",
        "zKT`E",
        "G~)|~",
        "SSL_CERT_INSTANTIATE",
        "2=2s2}2",
        "Z8kMf",
        "5~Hvq",
        "y!G<7",
        "4 4(4,484@4D4P4X4\\4h4p4t4",
        "bC(~A=I )",
        "Got invalid RTSP request: RTSPREQ_LAST",
        "//Z|&l",
        ">2>l>",
        "@S5SX",
        "%%#.%",
        "CMS_EncryptedData_decrypt",
        "<48b@",
        "KR{!qQ!",
        "0Hy3=g",
        "b(TXh",
        "jm)RZ",
        "UUUUUUUUUUUUUU<o(",
        ";d22Vd22Vt::Nt::N",
        "{Zki(",
        "OTUkW-",
        "&-Xdx",
        "strtoll",
        "oy9\"\"n",
        "NC%I7",
        "iA-)K",
        "ghR]o",
        "GD9-B*",
        "0'Zz%",
        "P_v#&5",
        "<4<J<b<t<",
        "!yJZr",
        "*+*k?",
        "8o9r>",
        "Failed to disable self protection %d",
        "id-regCtrl-pkiPublicationInfo",
        "ANY PRIVATE KEY",
        "On0T&",
        ".kCv!Q",
        "DS_InstallFACDriver.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        ".?AV?$_Ref_count_obj@V?$output_string_adapter@DV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@detail@nlohmann@@@std@@",
        "MonitorEnableAsyncNotifications",
        "=7T(c<",
        "D3VH&",
        "CPINSTADDINT_",
        "prime-field",
        "bsTj#Gmn",
        "4*(~a",
        "Wz>pl.n",
        "PWD_ZERO_LENGTH",
        "x((Pz",
        "4g<^3;",
        "RdQZ+",
        "`~nJ(",
        "7'HP3b",
        "424r4",
        "|FG)1",
        " means the server or appliance (defined by the host ID identified by You to Check Point when obtaining the License Key) which enables the Product to operate in accordance with the Licensed Configuration.\\tab \\line }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "2-2G2i2",
        "rn1AH",
        "V'Z+`",
        "zh-sg",
        "/(frU",
        "YkJ0o",
        "fwn#R.",
        "t$$h\\",
        "nE_f)",
        "{{@JqvU",
        "3019)(V",
        "GC#gC",
        "_//sw",
        " |L~6",
        "SSL_check_private_key",
        "%Wl0%",
        "]!V9y*",
        "4psDf",
        "R@{yj",
        "3#W%Z?",
        "Z]Dam",
        "vi>-a",
        "2~[lM*Q",
        "Q0OUB#",
        "(b^@}",
        "7(7>7I7_7",
        "k|doJ",
        "RCPT TO:<%s>",
        "q1*l;+",
        "jq:o`@",
        "?,840",
        "xN6D*@",
        "value.byKey",
        ";]|_9",
        "o&p@G",
        "*A]G9",
        "<D\\?bX",
        "9B0uh",
        "sC9-W",
        ":U @&",
        "BbUL^",
        "t$,SWh",
        "sig_BIO failed",
        "g%AfT",
        "%s - the incorrect path",
        "RTSP/",
        "DIMDm",
        "Ogc3L",
        "%YgV#",
        "[X3B)",
        "TK-^~eX",
        "WIX_SUITE_EMBEDDED_RESTRICTED",
        "U_u]XI",
        "Q(?Rb",
        "a60+8",
        "RCz;7",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 3}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5010868 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        "n?1ES",
        "SSL_SET_CERT",
        "viqh37n",
        "O@7Ik",
        "YJ|)a",
        "k,/.h",
        "WIcmC",
        " *P'Bl ",
        "=O.'gW",
        "g`m\"x",
        "S:YK5",
        "hm(v\"",
        "7^pf5",
        "OIdLa",
        "OEM.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "8#8(8-8=8B8G8W8\\8a8q8v8{8",
        "`SlBL ",
        "2:3g3t3",
        "wz()s",
        "\\Dm=O",
        "+~V`B",
        "*B+Z,",
        "|YDln",
        "/}y{B",
        "szIclientType",
        "CBIf:]",
        ">*>o>",
        ")l^=&o",
        "*T{hgI",
        "w,Lbe",
        "J \"ilKK$&k",
        "_']r4",
        "R V`i",
        "Qf<,IRPk[Z",
        "i 1Rj",
        ")8A2@H",
        "V8fH}B",
        "WH*zE;",
        "blJ1U",
        "vSONhvC",
        "const",
        "IZvO>",
        "vy%?\"",
        "}ez \"",
        "l)Cbl",
        "E}sfP",
        "no]/NXM1",
        "u`=G}",
        "= =$=(=,=0=4=8=<=@=D=H=",
        "1(242",
        "FaP*9",
        "HJ<{.",
        "!;s>KE5",
        "WPnY%",
        "BjNb:",
        "K}1`U",
        ";f<u<",
        "J@_dm",
        "4^tAAu8zj]nr",
        "ssl3_client_hello",
        "/M. ^",
        "Azt>R",
        "y2Pk&",
        "0pp@5tqE?|sO541",
        "(=^&i",
        "$D%}5",
        "; ;$;(;,;0;4;8;@;D;H;L;P;d;t;",
        "xF'mN",
        "vM774q",
        "^gtQ}",
        "8$u V",
        "not uninstall case",
        ":X:c:h:",
        "WIX_SUITE_WH_SERVER",
        "<;<L<a<f<",
        "K'T|G",
        ".O>>Ey",
        "& }YA",
        "`{1PH",
        "?v36k",
        ">4?8?H?L?X?h?",
        "rLIiR",
        " n.k/9.",
        "yE0lm",
        "id-it-origPKIMessage",
        "uN!Jd",
        "DES-CFB1",
        "PCMPISTRM",
        "#C7S.",
        "J8bxe6",
        "TWaQG",
        "IsPEFileValidEx: %s not found, last error: %u",
        "vv{LFX",
        "E-t|B",
        "PVVSSV1W",
        "W%BSh",
        "aM@A0",
        ".nl6ZR]",
        ">*?L?d?",
        "M(cqQk",
        "OP4Z0\\*",
        "..@rg",
        "MN\"4K",
        "@i+z0",
        "B.@s#",
        "CPEFR",
        "6w*=f-",
        "0XS?=",
        ":$;L;t;",
        "F?61H",
        "?&$QVI",
        "r5f~^",
        "EXTERNAL",
        "1O1z1",
        "'u,ae",
        "P'H<(",
        "*J:z1",
        "*%xJ@",
        "6'696D6Y6o6",
        "s(*s9",
        "sv-se",
        "!~%cH$4",
        "ds087Z",
        "43585@5{6",
        "R87b`",
        "Y@PVW",
        ",R&Ab",
        "C{S)H",
        "?3{5k",
        "n\\%F%&",
        "cf[/c",
        "r9j2]",
        "Kl9qE?z:2",
        "1Wb2,",
        "0Y0m0",
        "<V>e>",
        "-.<p_c",
        "mx<0>",
        "tJ8!^v",
        "-a)01",
        "xV12<U_",
        "Tf~wU",
        "4_IIp",
        "notrayicon",
        "/IYx~O",
        "XN-be",
        "L_&~S",
        "TLSv1/SSLv3",
        "1s iF",
        ".v\"(t",
        ">>>a>",
        "bkM%M",
        "Pg1T<",
        "'Ten.",
        "A@;`w",
        "\\@l1X",
        "CT Precertificate Signer",
        "fZVO2+",
        "Jp6lT#",
        "=hLC|$",
        "}AyLr$",
        "Ua__b",
        "4)454W4s4",
        "e_?!/",
        "-:=<P",
        ")'+OX",
        "AtdpS",
        "t4j\\h",
        "x8vL=(d",
        "&O:Q'X",
        "6{LZ|",
        "sSwDl",
        "$6V)/.",
        "found scv plugin file entry - %s",
        "ue{+v",
        "GQ5OO^",
        "*wMnG",
        "^8(SU",
        "IC]Ogy",
        "C<DbC^",
        "*606K6b6h6z6",
        "LQb'A",
        "0O0V0c0h0n0w0",
        ")6<sOs",
        "i}yvM",
        "vb(#'dFb",
        " CM_&",
        "nr[Bf=n",
        "gDu|?",
        "4moR- ",
        "vtqck%",
        "&~[1N] `",
        "L$(ht",
        "=~?o8",
        "Y$HDY",
        "tz^2O",
        "3<YMz7t",
        ":8;<;@;P;T;X;`;h;",
        "|0KQ4",
        "\\Device\\Tcp",
        "A#LO-",
        "7\"7s7~7",
        "|PO:*;",
        "Establish HTTP proxy tunnel to %s:%hu",
        "ptxpi",
        "YH;bq",
        "3t$L3",
        "0f3u3",
        "}sx90G",
        "subjectUID",
        "LdrGetDllHandle",
        "%(Fg% Fw",
        "-UiC)6",
        "\"fs/fxxI",
        ">,S9d",
        "t1Ph ",
        "9(9:9I9[9j9|9",
        "MAX_INST_MODE",
        "x-sO/8o",
        "ZbYd^TG",
        "hr-ba",
        "]w,Op}(F",
        "*v];uC",
        "HgzXc",
        "r2e8^FmJ",
        "Ex%f[",
        "<h=q=",
        "#g)gSgWg_g",
        "dTYz#",
        "2G,xq",
        "Gbc$G%9j",
        "V+wU(H",
        "_>zgd",
        "83h}1=",
        "Iy_P?",
        "unknown cipher",
        "*CqmXb",
        "TBrz;",
        ";i4TvL",
        ";zCcT",
        "Z8(\"de$",
        "\"-c\"S",
        "ZQ[Tf",
        "@R6x\"",
        "dxuv2",
        "^uU}_wU",
        "8 8,8L8X8x8",
        "8ysX>pbq",
        "<(<.<7<",
        "i@o\"T",
        "2(gy>",
        "Z(kED",
        "8!8.8t8|8",
        "}&\\Kr",
        ";+8RxN",
        "D$(PS",
        "M58sPf1X.",
        "{v!#i",
        "'T%#h^ ",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  provided to You in association with this Agreement, together with the associated original electronic media and/or associated hardware devices (\\'93Hardware Products\\'94",
        "$wyIP",
        "J9@,M$l",
        "&/Y<}",
        "0(IT,\"",
        "Zp`rv",
        "E+&j(",
        ">L+AA",
        ";<<}<",
        "_fG~5j;",
        "GetCursorPos",
        "Vh4< ",
        "4?sBO",
        "0XNZQ",
        "C8cE5",
        "hHFvp",
        "^MVW<",
        "PiRO1",
        "Sng1^",
        "RmRegisterResources",
        "0B1K1S1",
        "C[/#N",
        "name=",
        "i36#5",
        "<&=M=i=",
        "^v=Nn",
        "k}I{\"",
        "<$|xy",
        "a:ptAOtX",
        "mSNHR",
        "82_`/",
        "1ZQw0",
        "/fs$J",
        "!R-e|_*",
        "J#U,A6",
        "!2\"3&A(",
        "?9|lj",
        "&22q2",
        "cbO':",
        "/\\0k&Q",
        "rLBdq",
        "/A5,b",
        "kigiI",
        "jljlj",
        "Check Point Mobile",
        " m~W8\"",
        "]]vcP",
        "C0Kg*",
        "eContentType",
        "!t_rA",
        "/H\\$r4",
        "Z!6\\!",
        "Error: MsiViewExecute Failed",
        "0i$WV*\"r+",
        "{+Lt(%",
        "}plg(yf",
        "w.Q>k",
        "&MX&D",
        "/(|A[",
        "5%F<(C(E5",
        "ury9v",
        "$67aOW",
        "l@vBk",
        "1M1P2",
        "UM -tA1D",
        ";\";\\;b;v;|;",
        "~eHvI",
        "1 1$1(1,1014181<1@1D1H1L1a1",
        "2K2i2",
        "=#===F=Q=",
        "CKCL&",
        "3g4z435x5",
        "!3Q^lc",
        "*yPowV ",
        "ES=jtc",
        "xRBa{",
        "C!im'",
        "cuGNN",
        "NfwvN",
        "'w fjF",
        "oW6fTy'",
        "TVDIR.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "%6&9,",
        "\\?Det",
        "P`snW",
        "7,^Zf/",
        "Recovery action changed to ACTION_NONE for service %s.",
        "uF/J9q",
        "t$ VU",
        ">=>I>S>`>n>",
        ".Uf5wpt",
        "0\"yThg;",
        ",u\"Q%",
        "f+oWt3",
        "x/R-e",
        "O_?h-",
        "#%%nkx",
        " deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly ",
        "K+?ga",
        "~~wa<(",
        "3So,K7",
        "JGJWJwM",
        " 0x11",
        "zF-]n_",
        "f9C@u",
        "aYc-?",
        "5 50545D5H5X5\\5h5p5x5",
        ";5;C;J;P;\\;h;v;",
        "R+ll)",
        ":%:A:]:y:",
        ".\\crypto\\asn1\\a_gentm.c",
        "I3ISIsI",
        "f7Sb ",
        "\\$4VWh",
        "x121Address",
        "&Lk|^",
        "4*kt:",
        "CQmk{",
        "cgx_z",
        "GYDA;",
        "L#e/\\",
        "~bp.]",
        ");)6%",
        "O{Wf5",
        "_qI:7",
        "l'6u'qX)",
        "0p7)ii",
        "jY:?X",
        "ZrreO",
        "<y^D#",
        "9(EP'@-",
        "K'HXb",
        ")QZ>&7",
        "]Z(=d",
        "tI*!G|",
        "'m2-5o",
        ")Wv{^",
        "0x0|0",
        "<Rn)<",
        "trac.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "/\\m]7",
        "4<%j\"3",
        "SdXk@+",
        "9l$4tg",
        "%,<M#",
        "e0b\\-",
        "\\PatchSBAInstaller.txt",
        "PD.ZW<B",
        "?j8gE",
        "http://www.symauth.com/rpa00",
        "Xm5Z!",
        "2{6ACh57",
        "%l6rT",
        "BfjEq",
        "5 5@5H5T5t5|5",
        "failed to free xml file element path in change list item",
        "kIfC6",
        "$xIPSI",
        "6X+^C",
        "bAnj*",
        "f9f\"dU",
        "BAYZ6P",
        " developed by You. You will not (and will not direct any third party to) modify Product or incorporate any portion of Product into any other software or create a derivative work of any portion of the Product. You will not (and will not direct any third pa",
        ":8;d;",
        "\\rsid11863023\\rsid11882048\\rsid11954918\\rsid11956587\\rsid12025417\\rsid12071538\\rsid12151078\\rsid12218863\\rsid12348673\\rsid12463000\\rsid12465679\\rsid12534751\\rsid12669413\\rsid12727327\\rsid12735761\\rsid12741513\\rsid12809063\\rsid12856742\\rsid12871618",
        "rLp>B",
        "\\v?K0/",
        ":mI5[",
        "2%2D3Q3u3*4r4",
        ";G~o%",
        ";^JA`",
        "AXVy)\";",
        "SoD!W",
        "QybKo",
        "232O2k2",
        ".?AVCRolloverFile@@",
        "lN!B-6",
        "1Z$u#",
        "iJ!@U~",
        "t~d&?",
        "=Q?Z?",
        "BAD RECURSION DEPTH",
        "1'111;1E1O1Y1c1m1w1",
        "M{0D-yi",
        "4$:7R",
        "oRk op",
        "?\"?3?=?c?",
        "0;|j_",
        "6I7vX",
        "klwtp",
        "SetDriverMode:  VSSetDriverMode failed.",
        "?w.Ce",
        "%>!Oe",
        "(hQOBI|Q9",
        "std::nullptr_t",
        "I~e?N",
        "do@72",
        "%ZYsq",
        "L,R=.",
        "#f/)PF",
        "gH;& SOwc",
        ".\\crypto\\asn1\\i2d_pr.c",
        "Z%023",
        "]0tzq",
        "X509_PKEY_new",
        "EVP_MD_size",
        ">7>G>",
        "lew%H",
        "HbH|5",
        "Tp3xj|S",
        "{QUWN",
        "hn!e!K",
        "4V4h4}4",
        "jAjdj!",
        "TfRy$",
        "Failed to seek to end of file.",
        "=2>>>C>y>",
        "AIl?O",
        "?Ul2&U",
        ":P:U:_:",
        "ns^l>",
        "s jqhh",
        "pWz-s",
        "6o=_G ",
        "*.bak",
        ";H28Vk",
        "y&OO0",
        "HP?Y2",
        "mYTYj",
        "l#J<$",
        "'C$xk",
        "\\zonelabs\\avsys\\ckahrule.dll",
        "eFY6$x:",
        "K|=l\\",
        "iF3h0",
        "KfcF#",
        "+ 6tI",
        "0L6R&_W7U",
        "Trust",
        "2,3R3}3",
        "EeDWg",
        "'%jeucSG",
        "<UZb5",
        "bO9\"`",
        "3NW&W",
        "011D1",
        "VKl*t",
        "[VSDATA] FwConfigChange: adding local IPs for adapter %d - \"%s\"",
        "Hold Instruction Call Issuer",
        "263L3e3",
        "oR=nx",
        "`.7%$",
        "ti&%.",
        "-=<=-",
        "en-ie",
        "PQp+|",
        ";<;D;L;T;\\;",
        "px?zGcu5",
        "EvG]`",
        ".)r]H",
        ";Zg?#",
        "[%s] CreateZipFile: zipOpen error creating zip %s",
        "F%@QD",
        ".\\crypto\\asn1\\x_crl.c",
        "Pjsj#",
        "~?ad)D",
        "9 979J9V9j9v9",
        "9:u03",
        ":c0g5q#",
        "DLXHM",
        ":B<S;;",
        "#6$7b",
        "Af;)Gp6",
        "xWW?k",
        "464E4W4x4",
        "uyGDx",
        ":N:h:",
        "^!^9^]^e^y^}^",
        "D$PPVS",
        "cpDeleteDigest",
        "3/4D4W4",
        "Z#I7tD",
        "ASN1_FIND_END",
        "id-pda-countryOfCitizenship",
        "L&W{|",
        "Lk`ua",
        "m!`BOA)",
        "p]MhKJ",
        "9':\\:a:z:",
        "c2tnb239v2",
        "B-B}H",
        "os5\\'!4",
        "~-=ej",
        "USERS\\",
        "W+)%f",
        "5~>3TN\"",
        "could not bind to the requested symbol name",
        "failed to add xml file change to list",
        "Y4E)EO",
        "V/4;>",
        "uk:IN",
        "D$L_3",
        "nM}M?c4=",
        "(TyaD",
        "n}X!L",
        "38*k$",
        "VH6V[",
        "aU2)>",
        "Failed to copy 'restart' into action type.",
        "Found Discovery VPN installer",
        "FsnvL",
        "6)7b7l7",
        "<+<5<\\<f<",
        "3cyb8",
        "!v%[~",
        "UpdateZoneAlarmXml:  UpdateZoneAlarmXml finished.",
        "3T$(3",
        "i9J6I",
        "e%m\"L]",
        "mb?Bi",
        "P-n]8",
        "Qh8}&",
        "Fx<UXznd$#$NW",
        "\\ZoneLabs",
        "n7VCsMb",
        "}x3+x",
        "5xtvHq",
        "o7_3v",
        "~QF/>",
        "\\$5Zb",
        "Q4At?",
        "3D$4!",
        "8#8-8@8S8u8",
        "3@qyA\"",
        "bvFAQkM",
        "=KOKP",
        "SUA94",
        ";\\^Yl",
        "J($\"?t+",
        "?'?z>",
        "UNUSED_9",
        "'pA8!",
        "2TT3@l",
        "\\system32\\ZoneLabs",
        "'9RF'%T",
        "[=<Uw)",
        "20t3x3|3",
        "C)9P]L2",
        "$J*#H\\\"",
        "([9Rn+Jo>",
        "`MaA'",
        "F><cu",
        ":;/:Z",
        "c7==H",
        "34567",
        "`14UA|g7",
        "\"m&tR",
        "vLRPhP",
        "1v%z%",
        "Vb;TcF^i",
        "\"u}-\"",
        "0nOBC",
        "&ol\\i",
        "yc7lg",
        "ssl session id conflict",
        " apply. You may be asked to sign a separate agreement pertaining to the Beta Product.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid3552546 ",
        "868720002",
        "W^O+X",
        "pkcs8 unknown broken type",
        "S&kcF@",
        " 0~q7",
        "y-68U\\I",
        "24#4/",
        "ENABLEPROTECTOR",
        "Fu YJ",
        "#d{3S",
        "SVWhh",
        "j\\D}tx{D",
        "~Qq|N",
        "WB1gj",
        "jyjxj",
        "=&=.=n=z=",
        "PZ]Mu",
        "6 6$64686<6@6D6H6L6T6l6p6",
        ";2@Nn",
        "+t(QN",
        "6eP$A",
        "s>,-s>",
        "~b^&$",
        "portgroup",
        "oFtgM",
        "X'ns7",
        "1\\[oKk",
        "5K$wt2",
        "[VSDATA] Loading driver from: %s",
        "j~}5q",
        ";$spt[",
        "Wfkv=",
        "e_l`|",
        "w`SHU",
        "TLS Web Client Authentication",
        "Ac(QH",
        "l($.I",
        "HC'$q",
        "Bc!! 0",
        "Vhd2&",
        "Certificate Sign",
        "DigiCert Trusted Root G40",
        "YOU55",
        "2 3x3",
        "DO_PK8PKEY",
        "unable to decode rsa key",
        "M8A+M",
        "(e9Jr\"h",
        "X+`*f",
        "customer number = %s, length %d",
        "K;^&i",
        "3V3\\3w3~3",
        "Plugins::Unregister:  Unregistration failed.",
        "^2<2{-gN",
        "R5O'rn",
        "l$ PW",
        "7Vd^b",
        "oJ]}7?lSUp",
        "3*4B4K4\\4",
        "engine is not in the list",
        "Ck(%Z",
        ",  @`",
        "wVg{0Z",
        "/q(?\\R~=u",
        "\"+8_8H`",
        "cXO!c",
        "H{$vKl",
        "9$:/:=:I:d:x:",
        "VA[Y-",
        "f`GXdf",
        "H\"tqj",
        "F9?!^n",
        "<*9[Bi^",
        "OCSP_REQINFO",
        "0%0:0J0Z0j0",
        "\\4'L4A\"",
        ";5;P;k;",
        "g{0JdcZ",
        "K.?28",
        "VsNoFileRedirect::s_DisableRedirect",
        "@ P0IG",
        "7)8:8r8w8",
        "Registry error:  Failed to delete value.",
        "6eR+co",
        "a>cav",
        "t4z$H",
        "z^)-~",
        "T4J:Q",
        "s)pPPSO)",
        "OCSP_RESPID",
        "9C:Y:",
        "XpnUo",
        "'NB2)E",
        "dA'(J",
        ";O@~jS",
        "jSh(Z#",
        "A.8[ ",
        "-7bg|4",
        ";I;$h",
        "knq|i",
        "=* G ",
        "ZwSetEvent",
        "?+?F?",
        "nr>E\"",
        "858M8~8",
        "0)020H0a0q0",
        "5R6`6",
        "BlN*?$",
        "8HE)M",
        "AG@GE",
        "%RrTU",
        "2#2f2x2",
        "\\smartdefense\\bin\\xpdrv.exe",
        "=,>D>",
        "6T6t6",
        "SecureFile",
        "\\IHjK",
        "hN/fq",
        "Signer",
        "d.extendedCertificate",
        "2,2H2L2d2",
        "TE_INSTALLED",
        "n=&NW+",
        "*v0dj",
        "1u%j~",
        "rc2-cfb",
        "``D^X",
        "c'BAi",
        "?S6gm",
        "\\{vH]",
        "$h%M`J",
        "?$?@?\\?x?",
        "Z?~N*PdK]fr~",
        "\\4]RH",
        "B+R*Uv",
        "Invalid TIMEVALUE",
        "ml%0m",
        "7BV\"y",
        "2,202@2D2T2X2h2l2x2",
        "@l%:w",
        "rxFcX23",
        "4O'cd",
        ">'|eJ",
        "Wh,e!",
        "JlZ)M!|",
        "qZJYOS",
        "B#%Dl",
        "ZSS$G_4",
        "OWTpm",
        "gN2o5N",
        "s,>T[iR",
        "u!IuL",
        "{h{h{h{h{h|h#",
        "]%[N\"i's{",
        "vbbwn",
        "*X\\k`'\\",
        ".?AV?$moneypunct@D$00@std@@",
        "ECDH-ECDSA-AES128-SHA256",
        "nMcepd'",
        ";$T9?",
        "8ZA(O",
        ":\":*:",
        "######'#",
        "?&?+?",
        "6 6(6,686@6D6P6X6\\6p6t6",
        ">0|HHP",
        "qz#=q",
        "securitypolicy/osfirewall/rulegroup[@name=\"protkavreg\"]",
        "#Li{I",
        "Is{6A7",
        "xi1YW",
        "E?qut",
        "5 6h6",
        "msvcp140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "RemoteProcessMemory::Commit(proc=%p addr=%p size=%d) failed with error=%d",
        "The driver isn't uninstalled, error code: %x",
        "Internal error clearing splay node = %d",
        "w!RE8",
        "NbK[T5",
        "(pPbR/;:",
        ";/;^;v;",
        "1 1@1L1l1t1|1",
        "7%7*7g7",
        "Le:gv",
        "I'z~n",
        "SvTsf",
        "\\ %ug]",
        "[LICENSING] beta license expired",
        "CPCompliance",
        "SELECT `WixRestartResource`.`WixRestartResource`, `WixRestartResource`.`Component_`, `WixRestartResource`.`Resource`, `WixRestartResource`.`Attributes` FROM `WixRestartResource`",
        "m'<6?",
        "oa4`D5",
        "]{cKUYe",
        "\\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid3737333\\charrsid15169477 HARDWARE RETURN PROCEDURES}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid16273898 ",
        "L}y m|=",
        ")4jMW",
        "m^)zK",
        "7(747@7",
        "5EI!5",
        "*Q0hs",
        "1Q4a4q4",
        "YIsW\"r",
        "C4nJw",
        "/lTO`",
        "33ubi",
        "3eoci",
        " Tsa+",
        "r9,>e",
        "h6)##{",
        "Jg7K4",
        "HH/m2",
        "@cWV^",
        "D?2H.",
        "77j6B9",
        "444<4L4T4\\4d4l4t4|4",
        "FeatureAntiSpam:  RemoveAfter:  Delete files in ",
        "=y=l=s=g<\\",
        "sect409k1",
        "545g5v5",
        "tfYzj",
        "4SWagu",
        "BH6d^",
        "syHtS",
        "oXTkX",
        "PRR3]",
        "O|Yq>",
        "Pb$B2",
        "!/\"(s",
        "server finished",
        "303g3q3",
        "Failed to set prompt record field string",
        "tIllw",
        "O,PsLu:",
        "4 40484<4@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "B25f/GP",
        "SKIP USER: Can't remove directory with RemoveDirectorySilently function. Error = %d.",
        "[THREAD] Suppress spew for AV service threads",
        "*Rls.bg",
        ":[;f<",
        "MbNX6y",
        "7 7<7X7t7",
        "caRepository",
        "GOc.l^fV",
        "dhM 5",
        "uoaA5",
        "{1.gCl",
        "FeatureIMSecurity:  There was no version information in imsinstall.dll.  Treating as standalone product.",
        "UI service will be stopped",
        "pNxlC",
        "[;]I!",
        "$q)\"?/",
        "\\S|P3",
        "invalid compressed point",
        "Hb/'1",
        "]@`#C",
        "hD`5{",
        "l,}A|",
        "161;1j1",
        "9?9J9O9f9",
        "e]6'*",
        "suppPubInfo",
        "pw,w2w6wHwNwVwlwzw",
        "5=Pwm",
        "[{-m5U",
        "MQ]sJ?",
        "(t3V>h",
        "e!)k;cb",
        ";';:;",
        "K9.)\"9s",
        "jZA(SS8",
        "4$4A4^4",
        "n]3sS",
        "failed to read attributes from custom action data",
        ",Y8c\\",
        "i(o[d",
        "P:!bxL",
        "HM^a(",
        "^3vmf",
        "SSL23_GET_SERVER_HELLO",
        "5S99:",
        "{13VkD",
        "75){J",
        "cms datafinal error",
        "VsDataInstHelperSetProtection - DeviceIoControl(DIOC_DRIVERCTRL/DRVIO_SET_PROTECTION/TRUE) failed. Err=%x.",
        ":#ItW",
        "D$,VW",
        "}7_Z|",
        "x*\\{I<V",
        ">4>P>l>",
        "q_w/!",
        "D/nqD1",
        "V4EBSy",
        "/7(-h",
        "`2RMZ|",
        "v^}tO",
        "79@0'",
        "rwdh;",
        "mM fd",
        "=%>*>s>`?",
        "NjF~S",
        "I/Q}n",
        "-O?l98",
        "P9Mwc[w",
        "2,3!616A6V6e6",
        ";Y<i<",
        "L}+bWz?=",
        "|@?D ",
        "]Xj{O",
        "[PK*o",
        "?y~zJ\"",
        "X?<ZEW;",
        "yF<~y",
        "r,7%6",
        ".\\crypto\\pkcs7\\pk7_lib.c",
        ":(:H:P:X:`:h:p:x:",
        "D$@Wj",
        "| lk!",
        "\"#,D|",
        "LXJdwc8",
        "[\\\"j7",
        "YYht6",
        ",$Wg&",
        "0UPO5{w",
        "Failed to determine user name.",
        "0 <%@UC",
        "-m,(t",
        ")GJ|_.",
        "@[[]Q",
        "Too many open files in system",
        "]v5a-",
        "Microsoft Smartcardlogin",
        "y6_g\"}R",
        "api_ms_win_crt_multibyte_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "-a>!<",
        "u3_y/",
        "wait for event timed out.",
        "x|rF>|G",
        "8XKh)",
        "chinese-traditional",
        "CyGCT#",
        "#jak{",
        "212Q2q2S3\\3",
        "XL!z]",
        "n5rpt'F",
        "304q4",
        "Sa`?yp",
        "OD:P7",
        " set FW_INSTALL to FW_INSTALL=%s",
        "]&&v ",
        "%!Qgl",
        ":C;T;",
        "-17T^",
        "z;u]L",
        "%2py8",
        "security",
        "A` m^",
        "Q<U^R!",
        "7'7@7Y7r7",
        "3<3H3P3",
        "ECP_NIST_MOD_224",
        "v]t|m",
        "no revoked time",
        "0>moT",
        "VJm2E~",
        "5l(ZO",
        "id-smime-aa",
        "&KEHiY",
        "failed to get shortcut target",
        "3#3C3S",
        "EqMD5",
        "`<}koA",
        "Found conflicting software file",
        "1L2c2",
        "KGQ[9",
        "oC26j",
        " 2-:_",
        ".?AVimproper_lock@Concurrency@@",
        "61$cg",
        ")na<0(",
        "GENERAL_ALLOCATE_BOOLEAN",
        "mq&cF",
        "nH0{_,I_",
        "aZC]0'",
        "`lBef",
        "SCUIAPIConnLogo.png",
        "sk9|$,w",
        "f.M\"-gZ",
        "\"B'9B",
        "]#PS'",
        "PEM_SealInit",
        "v.+q_",
        ">+>H>^>{>",
        "S>^!~h",
        "ri%dy",
        "b[BNU",
        "Nv[)'6",
        "+}&%l",
        "==v`';",
        "=ub\"%",
        "a6`-,8",
        "]6jk~",
        "P.QC>",
        "d8sg=G",
        "{KY#$>",
        "}<[gV",
        "Jt)1.D6",
        "7'797K7X7l7|7",
        "<\"n'9B",
        "=J0%<",
        "QxA;b",
        "mP&?~",
        "8\\=b(",
        "ReplaceOrAddTagIntoVSConfig failed.",
        "sg6Fn",
        "hC>FS",
        "g_:Z=",
        "9PDFo",
        "4'4O4w4",
        "???b?",
        "e~AE4Y",
        ":34|zI",
        "un;_T",
        "muZYd",
        "<3<}<",
        "Z[]e=",
        "F&I=JE)",
        "dz!<A",
        "SE4]$",
        "!NKNR",
        "@<QbX",
        "<\\<|<b=",
        "=ck$ ",
        "!m8hY_",
        "Gt;*:",
        ":J}f4-",
        "non fips rsa method",
        "=[J7b5",
        "E.mzc\\ ",
        "DYNAMIC_CTRL",
        "BQeqEx",
        "AddFilesTempDir",
        "]`e[wc",
        "%;N0#",
        " 4RBE",
        "JQMK?",
        "Sr:jA",
        "@#QSQ",
        "K>ruv",
        "\"{.|E",
        "Keg(5R",
        ">M(zMo-",
        "dtls1_handle_timeout",
        "yByBy2n\"",
        "SendInfoMsgToProgressDialog",
        "M8DT*",
        "Dl~9N",
        "8 8$80888<8H8P8T8`8h8l8x8",
        "Y!G+>",
        "u=_^]3",
        "2)2}2",
        "S7{$XO",
        "Bv5'5T",
        "7I#i\\",
        "Failed to fix DNS security issue. Error: %s",
        "xSX#50",
        ")\"I/)",
        "l|JT mS",
        "((q_IS",
        "R+i3(",
        "FHY<qD/",
        "I)yMQ",
        "6W6^618L8P8T8X8\\8`8W9",
        "rb+y]",
        "y[l[=Y",
        "#3[|\\",
        "Mi$iQaC~",
        "hi76oZ",
        "rc5-ofb",
        ".\\crypto\\pkcs12\\p12_crpt.c",
        "jlHPU",
        "&sFF0",
        "p$2iEs",
        "v@.&(",
        "@xDZ8",
        "!:$I%",
        "CANTSET_UPGRADE_KEY",
        "lYXAH}B",
        "hD7YX",
        "joa :1",
        ".\\crypto\\rsa\\rsa_eay.c",
        "[Self Validation] Dump on demand",
        "kTuTFN",
        "h+&gm>t",
        "KvKx*",
        "}r]DZ$[",
        "${II<",
        "Sygate Personal Firewall Pro",
        "0B~^@",
        "%J)(A@",
        "b7,[q\"",
        "X7,/YVd1",
        "4.43484H4M4R4b4g4l4|4",
        " is not extended if Check Point repairs or replaces a warranted product or any parts. Check Point may change the availability of limited hardware warranties, at its discretion, but any changes will not be retroactive.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "\"}!XQ1",
        "06ulF",
        "wM<z8",
        "t;l.*]",
        "t.J[R",
        "_DNwJ",
        "~/f UU",
        "=UE;<",
        "v/n(C",
        "#-s;l",
        "$%@I@",
        "/mJi5",
        "{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703\\'02\\'03.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li2880\\jclisttab\\tx2880\\lin2880 }",
        "|u6dM",
        "?6?K?[?`?e?",
        "^r#G_",
        "(9,:m",
        "DKudb",
        "a^c]0",
        "n'I+*",
        "GlobalSign nv-sa1907",
        ":nH-KH",
        "SOFTWARE\\KasperskyLab\\AVP6",
        "2weXl",
        "g+h&kGB",
        "~_q8Wf0",
        "HH=Hzu",
        ")2.)^",
        "(@mHP",
        "f6k&+D",
        "VTt{R",
        "tf8q~",
        "}r]1Iv",
        "aXh-p",
        ")[CqB",
        "whh\\V!",
        "~qc0>*",
        "pct}t",
        "A4TjM",
        "nYY{y",
        "|$ WSUV",
        "*6dlI",
        "dingo.dll",
        "F!iwD2",
        "o]~*M",
        "5/5K5g5",
        "J#U2I",
        "?E@X~",
        "Cw`z[",
        "0h2u2",
        "We are already in the path",
        "=)U{=",
        "WGM4J",
        "2G3\\3n3w3}3",
        "D2s9s",
        "jD^l_V",
        "#A\"ieS-z",
        "[LICENSING] Failed to remove Read Only attribute from License file. LastError = %#x",
        ".Dbf!",
        "D9iy|",
        "OD,WY",
        "F$)0*m!",
        "515A5[5l5",
        "fJ-+\\",
        "WS-=(",
        "Qv8`O",
        "9 :$:(:,:0:4:8:<:@:D:+;",
        ">6BAE",
        "W\\h5!j",
        "[:\\~E",
        "u.;nF",
        "SrmU|",
        "GV#U#Y#n\"",
        "<1<6<<<V<e<}<",
        "_fI|bs",
        "#jV.0",
        "090W0z0",
        "im&YU",
        ":wS8X",
        "&dyB>|",
        "XE-.H",
        ":'#:5",
        "\\J&,S",
        "g{XbN",
        "pyH@,l",
        ">[?f?k?",
        "expected '}' or ','",
        ">\">(>3>B>H>^>j>y>",
        "7&9L9\\9",
        "l_:`9/",
        "Q>9u:",
        "-a>!(J~BS",
        "b!EG~",
        "Streamed out file:  %s to %s",
        "~>Tz'",
        "F\\mie@k'J9^",
        "%VB%+C",
        "!S0A~",
        "I8s}5Yb",
        "G<@t*",
        ">,>0>@>D>P>X>`>",
        "Afzk-j",
        "OG=Sc",
        "i|?qco4",
        "pE1BsE",
        "3`CdGqA",
        "/xo*A",
        "O~JRd",
        "PM.eh",
        "LkRLYF",
        "YBL;|",
        "id-pkix1-explicit-88",
        "031W1",
        ">B>i>",
        "4#5*555@5T5c5",
        "kyP\\A(",
        "q[AOf1=",
        "0;2Q2",
        "We are not in the PATH. Will add ourselves",
        "N@c_/>",
        "?!c/0|",
        ";4;f;",
        "APM0123456789:",
        "t$4VVS",
        " !''e",
        "<B<F=X=",
        "'g)p,",
        "]_@`R(",
        "QHz!1",
        "&RUeF",
        "put_text failed",
        "Pyp]z",
        " 0x88",
        ">\"{/D",
        "fo-FO",
        "DH lib",
        "ogU8wp&B~",
        "Yh*:%kwr",
        ")@fc$",
        "AjVE5c",
        "HR&![",
        "]\"]B]",
        "Kxy]F#",
        " YfjW",
        "Sc7#Q",
        "Mjsd/vr",
        "S!HYa",
        "'#_XF?o",
        "BeSmB",
        "1RlmrZeb>",
        "AnBqnmm",
        "HH-43",
        "\" f>Am",
        "\"q}\"j",
        "`{?4!",
        "@Gj_(",
        "mbkDS",
        "do]Nb",
        "gu\"~o9",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\watchdog.cpp",
        "x0WVV",
        "X,OCQ!",
        "ATL$__z",
        "InstHelper is not running, will not be able to stop TE service (TESvc)",
        "6$63696D6S6Y6d6s6y6",
        "808I8b8{8",
        " A/EI,",
        "boost::filesystem::resize_file",
        "Y?Ca{",
        "saEY/",
        "PQPQh",
        "BXsC) ",
        "5A6j6",
        "fhMSd",
        "%P.<c",
        "q81HI",
        "SSL: certificate subject name '%s' does not match target host name '%s'",
        "zyU(6",
        "oei*6",
        "MP\"Lv/?yR",
        "0\"0^0",
        "Gf3.+",
        "CMS_RecipientInfo",
        "BPe<m$",
        "/~^y|E",
        "BITWRAP",
        "'enabled'",
        "_Kb6)",
        "5'6S6u6l7",
        "z,gwk",
        "INSTALLED_VERSION",
        "DR\\4>+",
        "a*uo*y",
        "Remove Framework3.0 registry key",
        "u+9w\\",
        "]1a4/",
        "G``S6,",
        ":}h&sc",
        "MU&\\;",
        "Ue++!",
        ";Py\\w",
        ";K;S;c;",
        "3I!r*?W",
        "`cHky",
        "9F:`:m:",
        "T9=p|MK(",
        "f]yZq",
        "Xi6$\\",
        "3^Vj.",
        "eX%Mp",
        "kJ)W$",
        "f\"_E=",
        "u|\"8&q",
        "{*=_g",
        "kR\\;T)",
        "3[~x?",
        "(*D+-",
        "ps2`A",
        "9#9,9",
        "g?AUv",
        "AES-128-CTR",
        "> >(>L>T>d>l>t>|>",
        "Wq0UN",
        "xIsl+",
        "#Jm:'",
        "?z>Ov",
        "A2+ L)`",
        "m+vVL&",
        "T:g$DC",
        "w;3Y@g3",
        "L6'[e&As",
        "C}f/+/D",
        ".\\crypto\\bio\\b_print.c",
        "QF%Po",
        "d>+!J",
        ",7JI`N",
        ";XKsL",
        "656\\6",
        "We are completely uploaded and fine",
        "JjK|x",
        "loading data",
        "H=$x'e9",
        "(-$iw*",
        ":/;4;V;j;~;",
        "bDisconncetdExist=%s",
        "Timeout waiting for block %d ACK.  Retries = %d",
        "898L8_8t8",
        "Y]\\O,",
        "Aw7s3r",
        "MDcF\"",
        "D$$U3",
        "=wx-P",
        "Qx*pzj&w",
        "k>v]f",
        "CONIN$",
        " V8fv",
        "2.2F2L2\\2",
        "1 2O2",
        "0'030f0l0",
        "-y?-SV",
        "o,7NL",
        "PreInstallCheck: Windows Defender is running and cannot be disabled",
        "GFgY)",
        "qOy)q",
        "&4%Z>",
        "Yp\\[]",
        "PUdG*Lw",
        "M4-D}",
        "*I\"Z]'8",
        "3*4B4p4",
        "[1=sl",
        "FW1}a",
        "bN0+O",
        "b%se(",
        "V=>+ ",
        "@+\\2:sP",
        "_$ztGyv",
        "<t[JQB",
        "U1x|D",
        "3\\$D3",
        "%<;L=",
        "wizbl",
        "8+9::N:h:|:",
        "bad srp n length",
        "hBb{7",
        "?YcFQ?",
        "'!UI'",
        "Pj8hp",
        "FixedMACBuf = YES",
        "de-lu",
        "@#o7x",
        "is(>h",
        "id-it-caKeyUpdateInfo",
        "UsW;]K",
        "1)#]XT",
        "{l([%<n",
        "PKCS12_setup_mac",
        "L%:h0e",
        "O^hXY",
        "le L%",
        "uS?\\*",
        "0Sm_Q",
        "$nsi{a@Z",
        "\"_#_$",
        "&+d} ",
        "SbvNeI",
        "mJa606",
        ",3N3'",
        "ProductModeAtInstall",
        "59lh~",
        "StreamIoControl",
        "#zw1yt",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5650206\\charrsid15169477 ",
        "cAy#h",
        "EPiJU",
        "&&&&&&&&&&&&&&&&&&",
        "rp:E#",
        "P}&^!",
        ".\\ssl\\s23_srvr.c",
        "o1'xU",
        "8\"9C9i9",
        ",y_#)",
        "9np4S",
        "UkY{V",
        "NBvo!",
        "P~jC-",
        ";L07z",
        "_a15+",
        "[SOry",
        "D44F2E",
        "2@2p2w3",
        "application/pkcs7-",
        "5`Esqi",
        "X,]qT",
        "b6[9b",
        "W47vr",
        "L{O#J",
        "vE'bZ",
        "\"A+X!",
        "al:3T}+",
        "lER}7D",
        "`bB\"(!",
        "g\\fU)",
        "1S3b3|3",
        "DSA-SHA",
        "\"}`57zS7",
        ">r8KM6",
        "private-key:",
        "5 5(50585<5@5H5\\5d5l5t5x5|5",
        ">83HmJ",
        "6\\sH>Z",
        "E;EU7",
        "pbeWithMD5AndRC2-CBC",
        "6_|i_c",
        ")O4ag",
        "H0blJI",
        "6\"6M6",
        "#0Twq8O",
        "no matching choice type",
        "\\,l,^.",
        ":-_4M",
        "meVp7",
        "Invalid IPv6 address format",
        "=.=[=",
        "<7s#g",
        "P^Rff",
        "ab\\`af",
        ":j/+}",
        "=JC-r",
        "<9)kXV",
        "?h_,H",
        "&_2%$.s",
        "+mL6i",
        "y=SurF",
        "length too short",
        "\\products\\",
        "\\test_file",
        "5;5]5",
        "+[lfzb o",
        "ebUI{",
        "SERVER_HELLO",
        "ssl_init_wbio_buffer",
        "wf}hmDm",
        "<P=7>m>",
        "CZ6HRHh",
        "E#q,R",
        "T$(3L$",
        "BD'in",
        "]=lIQ!A@Ux",
        "4P_85",
        "ASN1_STRING_encode",
        "U6H/5",
        "D$dVW",
        "n+[NkS_",
        "'-.wz",
        "AZ.<$",
        "\\?R:ry",
        "Hz1C?",
        "aj'pQ<F",
        "VerifyModifyPWD",
        "&kV|u",
        "=n?u?}?",
        "i <= EVP_MAX_MD_SIZE",
        "#?\">F$8",
        ":$:D:L:T:`:",
        "=(09]",
        "rB\"^y",
        "^5<4T0",
        "FeatureTVDriver:  UpgradeAfter finished.",
        "ggen.\\crypto\\dsa\\dsa_gen.c",
        "N&\\k|X",
        ".+SFf",
        ";m;||",
        "6<6b6",
        "8:8b8",
        "}cL:8",
        "2 2^2t2",
        "!VOD'b4!",
        "hvm'78{",
        "%lLFiW",
        "JWH>w",
        "tu2\\L",
        ";-;I;e;",
        "8lc@Uhn",
        "de-DE",
        "Lxv5OEFi",
        "A,<$,R%U",
        ".vy1;",
        "T g+w",
        "~.dFD",
        "35cC#E",
        "=AFs7",
        "N?d>qxG",
        "kwoRh",
        "RerlP$",
        "n_e$!",
        "^ok8Q",
        "kgef252mx9neega7nv958t26t80",
        "93$)NY",
        "?.V`8",
        "3L=RM",
        "q!zbY",
        "9 9$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        "FKK,U",
        "6>N(u",
        "}VHiB",
        "e,yiLa",
        "CMS_GET0_SIGNED",
        "iaI-w",
        ".\\crypto\\dso\\dso_lib.c",
        "|BBZpx",
        "esov~O~",
        "~kTXr",
        "%s - %s",
        "3f#Nc",
        "S#tt ",
        ";_vNs",
        ".\"aNn",
        "SEARCH",
        "8[u!f",
        "'b\"Ssfg",
        "p^-lv",
        "1nlq.",
        "  2009 Copyright Check Point Software Technologies Ltd.",
        "2$3?3f3u3",
        "CEX:5",
        "$[{5<",
        "N6)-3Ww?",
        "Z}`{6",
        "|2Z9=",
        "@ C|B",
        "*i:uh",
        "6Y$Ci",
        "R9;z'",
        "orGL`",
        "w11ba",
        "c;\\@S8",
        ">(>@>T>d>p>",
        "yj<^i0g/,",
        ">R4)`Ja",
        "8+:_:",
        "Translation",
        "S7~#N",
        "Dp7Z}",
        "]Z|)~",
        "7D8o8}8",
        "5sNyC",
        "2wiTJ",
        "uT*[19",
        "1$tKK2",
        "q|c8_",
        "'Q-fX",
        ";T^h<U_i=V`j>Wak?Xbl@YcmAZdnB[eoC\\fpD]gq",
        "`xTnLw",
        "0|nB|",
        "]F':$",
        "Failed to Set Property (of OVERRIDE_DISCONNECTED_POLICY)",
        "A_X&a",
        "RFC 5639 curve over a 320 bit prime field",
        "? Should You have any questions concerning this Agreement contact the manufacturer at Check Point Software Technologies Ltd., {\\*\\xmlopen\\xmlns2{\\factoidname Street}}{\\*\\xmlopen\\xmlns2{\\factoidname address}}5 Ha'Solelim Street{\\*\\xmlclose}{\\*\\xmlclose}",
        "t\\Q/$O",
        "The CSeq of this request %ld did not match the response %ld",
        "J t{Ee:S",
        "KiA4o",
        "X509_PUBKEY_set",
        "Q\\~oh",
        "Y\"8sS",
        "lf$6_",
        "Dhd[Q",
        "?xl'U",
        "ILC;P",
        "g4~pA",
        "failed to set text to: %ls for node: %ls",
        "Failed to find the Process address for SetEventGroupInVSConfigEx.",
        "#Lvio",
        "jR#,@",
        "}5=8B",
        "'}M97",
        ":>Dza",
        "'[!`_HJ4?",
        "LYo%l_",
        "3PJ}2E",
        "M\",yh%",
        "n!%4N3",
        "bg.\"0",
        "W/^?*",
        ">.a\\5",
        "'Zq^s",
        "6 7W7b7s7",
        "]!ra(",
        "}|R21",
        "u?^][3",
        "CleanLegacyFrameworks finished",
        "AppPolicyGetWindowingModel",
        "Y]zCO",
        "9(9C9Q9]9i9}9",
        "2'353A3K3",
        "e$dD^`kq",
        "boC@Z",
        "1F2b2",
        "J+&;F",
        " 7qIi",
        ":,>4><>D>L>T>\\>d>l>t>|>",
        "D\"DJ&sF",
        ":FmGT",
        "pvk data too short",
        "I>f.=",
        "00dPd|u\\",
        "PSRLQ",
        "1$1P1X1d1",
        "hK9^>!",
        "[O]O_",
        "C]lj$",
        "}OEk?",
        "ZoneLabs\\ZLUpdate.dll",
        "5,%(H",
        "t@+~ve",
        "6$='>",
        "G.\"tC}Z",
        "jwtJt}",
        "BOh.C",
        "634nSD",
        "^^Aqt",
        "1q5E5N",
        "zU5U<N",
        "-)QSeS>S:S6S4S2S1S/",
        "\"^a]a",
        "@mIn=ShYw",
        "00000000000000007777777777777777X.509 part of OpenSSL 1.0.1t  3 May 2016",
        "BPY#HT",
        " y`IK",
        "?STLSu",
        "+{&E?",
        "!l[)`",
        "YNY X",
        " !\"#$%&'()...................*+,.......-",
        "~ryBY",
        "%P=Eyn0r",
        "$*V\",",
        "$=':-",
        "lh^:e",
        "ssl handshake failure",
        "H#`YC",
        "ANDNPD",
        ">N?o?",
        "HkiPz,",
        "L;\"6'E",
        "du8SN",
        "(8yFmF@",
        "%\"l,\"(W",
        "X509_PUBKEY",
        "pk(Tjt5",
        "646`6i6o6z6",
        "sog ]",
        "C`bFy`",
        "[vtsjK",
        "kKkKl",
        "J.Q.g",
        "FWRemoveBefore finished.",
        "uk`ZR=",
        "RU&L`@,",
        "hSS5_g1",
        "=~mrK*\"",
        "\\mirror.exe",
        "yc8`X",
        "k`]Q|",
        "xi63-",
        "taI6u",
        ".GQ! ",
        "D$(_^]",
        "RemoveDirectoryW",
        "-=w:%Qx",
        "+(a<w",
        "failed to get object table",
        "f= t4",
        "#?1T4",
        "Vc(^]3",
        "SetThreadStackGuarantee",
        "8l86|",
        ":,VSH",
        "Y\\8`3\\",
        "[/IR_",
        "w-}>r",
        "jljoj'",
        "*7,%D",
        "Vwt+^(B",
        "Found connection %ld, with requests in the pipe (%zu)",
        "2&383b3h3{3",
        "MY'>f",
        "Mkd6?",
        "N<z/W",
        "JNeQF",
        "#L$ 3",
        "DAV%F",
        "id-set",
        "localeconv",
        "[3[K<i",
        "C!Uqf",
        "Dh8\\f ",
        "640)(\\:",
        "4 40484@4T4\\4d4t4",
        "secp112r2",
        "2<&va",
        "ZdKh,",
        "invalid modifier",
        "Au'r?(",
        "zh(q ",
        "2CHsd",
        "? ?>?R?",
        "2$2G2_2",
        "=)GQW",
        "T$dSU",
        "PKC}t",
        "1D1u1-2",
        "CVL:1o[R",
        "YC:#:S",
        "\\>2iRT]u",
        "tgyW9oH+_",
        "YHHfQ",
        "A-aE\\",
        "0*070T0",
        "M@3],3U(3}$",
        "RFSye",
        "151=1",
        ")RpYy",
        "[YXL3",
        "RUwL ",
        "@]_^[",
        "function not supported",
        "A#Flx",
        "unable to create socket",
        "HCoL?",
        "~Gx#O",
        "u#j`h`B%",
        "OnFirstAfter",
        "6 606O6V6i6",
        "Bdl@H",
        "Y'vV4",
        "K*=pF",
        ").IQN",
        "R`sE3",
        "Wj_h<",
        ">RBJiF(X]",
        "8wrG,|3f",
        "kv3q^",
        "MlHR1",
        "EiK:}",
        "ax9S[qGAx+k",
        "):o|k",
        "^H1T?",
        "fBzDu",
        "Hj{!E8",
        "o>Hqx",
        "?7Tf(",
        "%gBPQ]^&y[O!",
        "<J<O<T<Y<a<o<w<",
        "l?Gh0",
        "D$$UWP",
        "GetConsoleMode",
        "Ry<OK",
        "ECDSA_PKEY2PKCS8",
        "Ize3vpp",
        "d:zdw",
        "-k)uz",
        "mMD1Y",
        ";|$ |",
        "6+6K6k6",
        "eoKY<",
        "1-1i1m1u1y1}1",
        "KKl+h",
        "&^Nxd",
        "file too large",
        "Z:Z+#Z",
        "gCOk8:y",
        ":6;H;",
        "=>>i>~>",
        "p-_$4",
        "0p0?1",
        "2$2,242D2P2X2x2",
        "G7^B+",
        "C,n.v",
        "cO7Xv",
        "X0Y[2C",
        "<pT\\>",
        "]vB+_)",
        "F'm;q E",
        "encrypted track 2",
        "eq`8g_",
        "StopTEService_rollback started",
        "9Q\"OVa",
        "rfc822Mailbox",
        "OH}yjq",
        "oS9py|",
        " !\"#$%&'()*+,-./0123",
        "NCg7#",
        "O5I9}",
        "<:Co'",
        "<J=Y[",
        "policy syntax not currently supported",
        "jsF]c\"C",
        "not basic response",
        "x_d0[4M",
        "=3=L>",
        ":sYR>",
        "=.=d>",
        "2rQ=<R#s",
        "D$$PVVVVVVVj",
        "D$(VP",
        ")1ZbM",
        "1%SvS",
        "]~+T$4J",
        "5(616v6",
        "z(=n{xK",
        "l@(Dw",
        ">J?b?",
        "2$202<2H2T2`2l2x2",
        "_k=V=",
        ")|uq<",
        "6>]ER",
        "_bUGM",
        "oBF<?",
        "X*lh9",
        "7ZHpn",
        "base64 decode error",
        "o(f(O}F",
        "y 9wivK",
        "jcqc5",
        ".?AVThreadScheduler@details@Concurrency@@",
        "4#|G(",
        "<\"<I<",
        "4%468H8l8s8",
        ":4:^:q:",
        "@)w=+~",
        "6k^b`%G",
        "}.yW]",
        "KEbi@~",
        "wz`o[",
        "*-}99E",
        "2f2p2",
        "zt3BC",
        "i*p$p:",
        "9H9Or",
        "HeapFree",
        "PublicKey.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "&vvu&",
        "3dffs",
        "-'$mI",
        "#n;H>",
        "2A2I2Y2",
        "0$0,040<0L0\\0l0|0",
        "i|+~5",
        ",`<p4",
        "~mP!j7",
        ">|>l?",
        "OO]mPh",
        "([?n:",
        "6HV08+Y;",
        "MJl_c",
        "4vkJ?",
        "s3SO^U",
        "6x6F8S8o8",
        "Operation succeeded",
        "singleRequestExtensions",
        "iJo4=",
        "fa:Ba",
        "V-MxOo ",
        "'15p>",
        "fde_srv.exe",
        "*tL=+",
        "Failed due to unexpected CustomActionData passed.",
        "<sKiF59",
        "Npf[aCa",
        "type not enveloped data",
        ",nSy.",
        "sJm(I",
        "7\"MkL",
        "*fBm\"",
        "iC++fzUjm",
        "\"Yx~:",
        "}!7^7",
        "\"w3hr",
        "wf/5u;",
        "*%98+",
        "5(G'zpB7zO",
        "GOPHER",
        "Whh;#",
        "elEJ]}",
        "FWRemoveBefore",
        "Firewall driver exist.",
        "*Z[d)",
        "T!k!6cz5(",
        ":4qev",
        "rSAd*",
        "Y_D&X",
        "2#2*252f2u2",
        "<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`",
        "6(636U6~6",
        "E]NhH",
        "_0x z",
        "WShpMM",
        "UpdateVsconfigXML: SetEventGroupInVSConfig succeeded.",
        "software\\microsoft\\windows nt\\currentversion\\perflib",
        "Zw1:~\"",
        ":-MKBzX@",
        " R|Sh",
        ".2XD}",
        "W6$ag",
        "767j7w7",
        "\"!(]t",
        "4F)^{",
        "&C~if",
        "x]7,C",
        "cv|5m",
        "FIPS_mode_set",
        "{h_^][",
        ")|LW\",",
        "LusO-b",
        "I~3kgUg:",
        "-Kj[S",
        "g/R?;",
        "W.*\\V",
        "M.M3!;O",
        "\"_;F!",
        "]$VrN",
        "ZwFreeVirtualMemory",
        "\\bM#+",
        "]Q,/uwm",
        "peer error no certificate",
        "9Vyq\\",
        "5rqcfNPQ",
        "U%E,9h",
        "S\\@)N",
        "jGZ^gDnT",
        "cEdSU",
        ",/[xjU",
        "Z\\UI)d",
        "D&IVJ",
        "6q7N8U8",
        ".\\crypto\\rsa\\rsa_oaep.c",
        "Am7to",
        "U!jr1",
        "Pu!s.[",
        "iJ;Sgd",
        "(:p}N",
        "P$7!D",
        "{WTrQ!",
        "NI%LI/",
        "qJa4%",
        "@,\\80",
        "4m)-]K",
        "O6r(yx]",
        "k+Z6vu`",
        "7k5b%",
        "`)g_}",
        "ho~Os",
        "2 2(20282<2@2H2\\2d2x2",
        "0Ox;E",
        "Kwt>w-M",
        "^51,9XZ\\",
        "3k4Z5",
        "SOFTWARE\\CheckPoint\\TRAC",
        ".e#0?",
        "{%\"N.",
        "=Kx+h",
        "dwhM>",
        "z`S9-",
        "(zZ2k@",
        "r/|-C",
        "Vhn4^",
        "0$0,040D0L0T0d0l0t0",
        "v&a4JUdgiw",
        "failed to read port from custom action data",
        "K;{M*",
        "WbZ\\.",
        "r!EdrfK",
        "~o8AP|",
        "SU%Qy\\",
        "/}jN#",
        "53pu^[",
        "H-!W[",
        "SELECT Name from Binary",
        "End Point Security",
        "/P/Q^",
        "Sj)PS",
        "B)#~_",
        "Hj|FE",
        "gEVy[E",
        "T/qq.",
        "8 8`8",
        ";#;;;H;M;R;o;};",
        "3=ZcsEp.IAz",
        "c_-nAy",
        "`9uVw",
        "rsa_oaep_md",
        "5*5=5\\5y5",
        "j9xs5T",
        "jejjj#",
        "? - Help",
        "VersionAfter",
        "/Q6*xb",
        "o$^+$q2",
        "tried to use unsupported cipher",
        "$.p0T",
        "Z%`=D",
        "B-283",
        "7'7b7|7",
        "0 0$0(0,00040t0",
        "a^-0Hr",
        "WZ.KI]",
        "8F*LU",
        ".@[O|",
        "TPP@~",
        "L-#eS'",
        "teWSV",
        "=+=^=l=",
        "}*\\Lv",
        "Failed to resolve remove folder property: %S for row: %S",
        "FNG <P",
        "f_z8-",
        "YGK&{",
        "9w,~9",
        "7'8Js",
        "njsD(i<",
        "6rXK&AN",
        "calibrary.dll",
        "MLyd@o",
        "[hw9=",
        "Failed to  install product",
        "071f1s1",
        "a=-I/",
        "M`#B{",
        "+kDm,",
        "^g2*bMq",
        "I+-ns",
        "rP6g)",
        " 0x65",
        "$Q\"WO",
        "y,YoCf",
        "9F:e)",
        "^M9Zz",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 License}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid473743 .}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "4Q4V4[4v4{4",
        " 0\"y'",
        "6*8f61r#",
        "Z.;9V",
        "_wcsdup",
        "(SRN[",
        "Np_hHj|m,mz",
        "GD>UV",
        "868620003",
        "sb[JY",
        "q#7<x",
        "E-Y$]9",
        "H>,y]",
        "8v.I<`",
        "F,p(.I{",
        "@Yi(`Im",
        "|q0I:",
        "2e->~",
        "hI\">{",
        "999fb7b4717509af678b985ab0b6b4ae6f7ed9ba6c4170b06c788a705430adf71bad2b5b057d03606a1ed7ebf5babd7a41cf00b0ef83a6569632cd467faddec9",
        "J!k`ne",
        "].WJ%",
        "f1J_>",
        "P!q@wDiW",
        "+m Ar",
        "DYprn",
        "4lKaj",
        ")W2!]\\",
        "#wa\"+",
        "tOx;ZzD",
        "R1$\"mp",
        "1\\_Y}",
        "~v!2l",
        "j6M')",
        "?I@=cxc",
        "0F3hH",
        "6\"6,6<6J6Z6d6",
        "[B[%X",
        "q04}^]",
        "#QBS `",
        "Gs0gf",
        "auDW$",
        "I,\\rm",
        "vuBc)m",
        "H{o}<Pe=",
        "w[R5V",
        "+tI*w",
        "B|*2!E",
        "8#8-8:8N8\\8f8s8",
        "v@xFf|-",
        "aX+R7",
        "?Wth^",
        "m!o=6",
        "|>kmv,",
        "{\\U*4",
        "ev(<xc",
        "5CNy/",
        "2djfj",
        ">0tCe",
        "%}\"hn",
        "Failed to get active database",
        ";fwlp",
        "D$`+D$@",
        "2tk:b",
        "U0fE;",
        "0?0g0",
        ")L$Z(",
        "XJOVR",
        "H%TSXXG",
        "647[8",
        "g*.xs",
        "#Y*QD",
        "*X\\Dh",
        "T?GH$.",
        ")$>Lc",
        ")!<Vqp",
        "!\"s1[,",
        "<$q`2",
        "!\\[3CK",
        "5Fz\\@",
        "W?}Wm",
        "AxX4y",
        "D$8PWVSU",
        "BN_BLINDING_convert_ex",
        "<T<l<v<",
        "['~aQ",
        "uPFZs",
        "Failed to pWseRegisterPlugin",
        "SetPropInCachedMsi",
        ":,:1:",
        "freshestCRL",
        "z39Z<q",
        "QgHE,L()",
        "KGMGOGQGSGUGWGYG[G]G_GaGcGeGgGmGoGsGuG{G",
        "_7|sY",
        "wv.@J{",
        "$c%,\\",
        "6h0  ",
        "Ml`c>",
        "V|Y#0",
        "1Zx#>",
        "4V=:d",
        "4\\3\\[",
        "hNsh06",
        "5e&9D",
        "`U,!D",
        "bAplxP",
        "SLS`{",
        "W\"le,$",
        "read key",
        "@[/6n|",
        "xG,(!",
        "Uz\\x_",
        "1O1d1j1",
        "4|+< ",
        "iU8THO'",
        "z'8gM",
        "!I/[]",
        "}J<NI[",
        "9)g|wgiDE0",
        "8/8W8\\8c8j8q8~8",
        "+wVA/",
        "Dhq'R",
        "Nn^^%",
        "[etB{:",
        "M!2wv",
        "n(=!o",
        "yln$h",
        "jqm%^",
        "D$ hl",
        "X=\\16",
        "iJ@\"@'",
        "BFUa.X",
        "5&5B5^5z5",
        "j7{9Z",
        "svK7}",
        "PostMessageW",
        "g^;|c",
        "DWWh4o%",
        "> >(>0>8>D>d>l>x>",
        "8WKoK",
        "C5B:A",
        "b>'is",
        "v-hH3`p",
        "id-it-keyPairParamReq",
        "CMS_RecipientInfo_set0_key",
        "+ZRKr0r",
        "Q@G^B?",
        ".<6ku",
        "Sj)[f;",
        "sL*d=",
        "N.ZmM3",
        "7[ag;r,",
        "/C%<CcFw",
        "8+8E8",
        "ANTIVIRUS",
        "]Z2~^",
        "MaxNumFilters",
        "2=gVwJ",
        "8ZZ&\\",
        "(D4G}",
        "z2M;O",
        "epcginashim64.dll",
        "nf7\\Q",
        "|JzP6",
        "wwtX=",
        "IF-Z)",
        "FTP: command PORT failed",
        ">+ni2",
        "*;I%y",
        "Akgz0",
        ")nQU+",
        "tE$39",
        "3 3$3(3,3034383<3@3D3H3X3\\3a3e3",
        "5)6T6",
        "3E3f3",
        "3 4u4",
        "z[J,dI",
        "/d@?sd",
        "CMOVO",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2260672\\charrsid15169477 THESE WARRANTIES GIVE YOU SPECIFIC LEGAL RIGHTS AND YOU MAY ALSO HAVE OTHER RIGHTS WHICH VARY FROM STATE TO STATE OR JURISDICTION TO JURISDICTION.}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "'TGu&",
        "kTB%^!",
        "H4Oky",
        "UpdateVsconfigXML:  Could not set protection tag in vsconfig.xml.",
        " !\"#$%&",
        "CertOpenSystemStoreA",
        ";D$(v",
        "SOFTWARE\\CheckPoint\\Neo",
        "d%pTUG",
        "B7.,G",
        ",7A5Z~l",
        "Zh;,Zp",
        "CertGetIssuerCertificateFromStore",
        "n&FTrc",
        "s0I'?",
        "8-(vY",
        "ut8D$",
        "UPVSW",
        "{<n)T",
        "kE0$?",
        "J8T9\"",
        "_X_^[",
        "RT!h\\",
        "CHd1iHP",
        "F 6^Ugeh",
        "dtls1_read_bytes",
        "SOFTWARE\\MailFrontier",
        "ft]IZ~)",
        ">ah%J",
        "gB.Fn=",
        "Ifc.xF",
        "unknown cipher type",
        "7Y-%\"",
        "9`9^3",
        "XZyI&",
        "SM5JJ",
        "CANTGET_INTERNETLOGS_KEY",
        "?a'e2",
        "]U<4]",
        "t$0SS",
        "pZlNr",
        "?\\JFy",
        "s?yeC",
        "cj>PS",
        "mgEN@",
        "y:1Y5",
        "&,_k[",
        "7_uLL",
        "?3}cG",
        "CANT_CONVERT_TO_NUMBER",
        "no fips random method set",
        "\\_o_;",
        "+G!'tgC\\",
        "m/X~Aj",
        "dylR)nO",
        "rVK|Bp",
        ",?\"fQ",
        "0&1O1t1",
        "M'yBrlYKF",
        "}tt[M",
        "Gv'7*",
        "SnG}P2",
        "4S'o%",
        "}vI~>]",
        ";/;5;];c;i;o;",
        "G!X*Z",
        "9K8cf",
        ",i/,o",
        "9 3St[",
        "LIST \"%s\" *",
        "ww+*+Q",
        "@'NV(ob@ik",
        ";#FTH6!",
        "MoBJ!",
        "F$-$3",
        ";d?D=`wz",
        ";44h7",
        "#z,A;#",
        "5 5$5(5,5054585<5|5",
        "xVCiW:",
        "EU4RH=A",
        "8)808",
        "va!>_",
        "FwDgG",
        "vK<j!",
        "V:rrk",
        "p64jmB",
        "OTN>OV",
        "3XuD!",
        "VuiR|e",
        "license table current caller: %d",
        "v~{l#",
        "=6=;=H=",
        "aefr1",
        "b*pj+\\",
        "0G2gq'",
        "LDMXCSR",
        "X\"j%9hirY",
        "s>l{K ",
        "%p!8S",
        "http/1.1",
        "AES256-SHA256",
        "d.envelopedData",
        "whiO}",
        "ConvertStringSecurityDescriptorToSecurityDescriptorA",
        "0$030=0W0^0m0{0",
        "\\7}6yj",
        "d--y2F",
        "1@e3&R~,N",
        "R>/r9",
        "New file: MajorVersion %d MinorVersion %d BuildNumber %d RevisionNumber %d",
        "j%< r",
        "$imu3",
        "c\\D({",
        "BO/e?n",
        "n#)6W",
        "qoY~))V",
        "'.1V'",
        "T@?'\\",
        ">M'2W|",
        "Jpy,Q",
        "K4|A~M",
        "^|tS!",
        "b< Ujq",
        "9W6R|H",
        "et93&r$",
        "CheckInstallConditions",
        "9\"9'9N9s9",
        "m)gFfFP",
        "4` @ ",
        "7s8M9",
        "d[ZtsJ{",
        "aO-Gj",
        "{PZXw",
        "8bK[UG",
        "BF&F/",
        "8b<:P",
        "? ?`?",
        "BEz4(",
        "a5RRj",
        "%*sCPS: %s",
        "r2)[xg",
        "^0M-l",
        "0)131",
        "767e7",
        "{\"f*T",
        "#xBZO",
        "G~Nrx+",
        "d)\"=M",
        "8NB`2",
        "2]),ul",
        "xU/~!Y",
        "Service '%ls' does not exist on this system.",
        "*Bzpym$",
        "=F#%('",
        "9]lG#",
        "PKCS7_get0_signers",
        "Mv{%\\",
        "nJn^/",
        "PWnm<",
        "sG0nX|y",
        "l.e~(",
        "x>%1,",
        "WSJ:<",
        "<\"<B<b<",
        "405P5",
        "|f2~YT",
        "$ryO:H",
        " Type Descriptor'",
        "l=zKa",
        "G?\" $",
        "aes-256-ctr",
        ".?AV?$holder@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@any@boost@@",
        "s%Pp.}",
        "M(qx]",
        "H1%,v",
        "@oa1I",
        "1,1>1",
        "J~i#x>-Q",
        "4(444T4",
        "v.4uY",
        "'%l`=",
        "F6todW",
        "5zx[,^",
        "yJM!P",
        "5(6I6",
        "s]a7\"/",
        "hr-hr",
        "Dr;%wC{",
        "k1HncmX",
        "3$303<3H3T3`3l3x3",
        "IsRebootSuppressed:  SCHEDULEREBOOT=",
        "z>!t&",
        "@m;_/",
        " 0x42",
        "UniqueOrgId",
        "boost::filesystem::create_directory",
        "{RKwHgyIks!",
        "\\Ppbh",
        "<PQCk5",
        ":#g/q",
        "5YyC:@6",
        "N;TaRi",
        "L<Ze^",
        "I0Q:A23",
        "l48N6",
        "iiaVm",
        "=wb'O",
        "3T$03T$(",
        "Hq.|@a",
        "=fG'B",
        "unvk.#CI",
        "6h})4",
        "[vD<v",
        "<L=l=",
        "7&>&A&C",
        "CollectBootStatistics starting.",
        "mghj$",
        "JA[d81",
        "0\\avc3_sig\\avcuf64.dll",
        ",r2fcy",
        "CD$dPj",
        "2ZS6:X",
        "3!3,323H3h3n3",
        "EqeXe",
        "#B7<}/",
        " P!egl",
        "wJXGj",
        "_?fI[",
        "$m3i/zZ",
        "data_plus_mac_plus_padding_size < 1024 * 1024",
        "?34P4v",
        ";X5YO",
        "dsa_paramgen_md",
        "BLENDPS",
        "xtp]^&",
        "LOOPNZ",
        "HXJa3",
        "<0===w=",
        "fCs[*",
        "X$ye)",
        "kNXeg",
        "a8jTVC@",
        "w49)6_:",
        "Failed sending CONNECT to proxy",
        "NJ.|*n",
        "6<Se#?",
        "EC_POINT_mul",
        "2T2e2",
        "smartdefense\\bin\\AppUtils.dll",
        "+_r}I",
        "FTP: couldn't retrieve (RETR failed) the specified file",
        "%>FTj",
        "A|nuF",
        "pPb%H",
        "signing not supported for this key type",
        "|%x :@%3",
        "WgoF/",
        "l$DUQS",
        "TRYki",
        "S9v.i",
        "~^TBbJ",
        "nfa~Rp",
        "eej+T",
        "ZLz~vK",
        "kzfX@3",
        "#)OyI",
        ";O!G}",
        "lI8O.",
        "Xf(||",
        "ddRNAG",
        "8a,|M",
        "8 8m9",
        "set %s",
        "OxQcM?6",
        "fo?S5$lmc",
        "HeFqATJ",
        "k.]um",
        "invalid null argument",
        "F:\\ckp\\src\\cpopenssl\\E86_20/preCMpub/ssl/private",
        "3=>X(d",
        "w:1YI",
        "A 62A@~",
        "sjw*]",
        "=pwnH",
        "EH/#O",
        "5S5Tj",
        "mhrK7>$k",
        "[UJ{98-?",
        "[L:B}",
        "stW_w",
        "MX Nh",
        "x^FmC=6",
        "T`@Z.",
        "6#637>7<8",
        "=$=D=`=|=",
        "|G1G+",
        "L$8QPW",
        "9>9V9",
        ">J>r>",
        "?$?,?4?<?D?L?T?\\?d?p?",
        "cD`XJ",
        "xyLlw",
        "}9lA`",
        "3vlP}b?",
        "DS_PrepareCopyToSystem32 ended",
        ".DQ.Z-",
        "?Sp&!",
        "nx8XH",
        "@Dyc<",
        "InstPrepErrorCode",
        "IWq_vT",
        "(;\"%[FSh",
        "ns-ZA",
        "|$03L>",
        ",$S=0-",
        ",iqXzb",
        "?[Sx+",
        "Winsock library is not ready",
        "1z2c314?4",
        "CMS_sign_receipt",
        "0he}&z",
        "AOTOL",
        "sk159373",
        ">Ss@Y",
        "nb!pf",
        "9w?Bs",
        "%F*1\"",
        "94:K:b:v:",
        "#I^!T",
        "bxhiH",
        " [_^]3",
        "Yqz8]?",
        "3~#*$",
        "jAjej(",
        "wap-wsg-idm-ecid-wtls1",
        "OnRemoveBefore finished.",
        "kiTj.b",
        "u jShT",
        "/^R\"x)vZ",
        "Installing components",
        "lmguardsvc32.exe",
        "CN{i[|",
        ",{}LcYw",
        "#n2HY",
        "Error: There are no manual services configured",
        "w.$*v>",
        "2r{(j",
        " {!OM=",
        "yy4L`'",
        "MF!E?L",
        "Y5OFH",
        ",OEcx>S",
        "S*\"qkQ3u",
        "\\(b,:2",
        "Ki-cw",
        ".{~Um",
        "SignalObjectAndWait",
        "AeAQ ",
        "n3l$(",
        "5x3?h",
        "\\o\\:W",
        "<-0V$",
        "@gbkf",
        "gkTH$",
        "gy{B_cs",
        "}sroe",
        "[VECTORED EXCEPTION] The object invoked has disconnected from its clients.",
        "\\rsid9508190\\rsid9516106\\rsid9523028\\rsid9533499\\rsid9586238\\rsid9588218\\rsid9593600\\rsid9633826\\rsid9651500\\rsid9832050\\rsid9841765\\rsid9843574\\rsid9905346\\rsid9918944\\rsid9971420\\rsid9990548\\rsid10102966\\rsid10172000\\rsid10176163\\rsid10178046",
        "'N)<)=",
        "AUmX{",
        "J#@qv",
        "s/Q,B\"",
        "::;T;",
        "TW/*eC",
        "AgHDu",
        "*xj[:",
        "zT]'e",
        "ss&eu~'",
        "6I6^[W",
        ")Xofy",
        "kisRz",
        "LOG_CONSTRAIN",
        "HO#U=",
        ":O^{Io",
        "Z-v*-",
        ",v]`'`+",
        "Btl'F",
        "'82;?H",
        "=0=@=D=T=X=h=l=|=",
        "$F<^,7xh",
        "v6y\\F",
        "/=/;A;0;",
        "K~6OI",
        "8I$zb",
        "@|%u:",
        "Qk1\\2",
        "Remove component registrations",
        "JW;R6",
        "vbwbxbyb",
        ".1<Yw'>`",
        ".?AVtoo_few_args@io@boost@@",
        "CANTSET_INSTALL_PASSWORD",
        "dingo_old_installed_path",
        "Rb^LDh",
        "yp\"j+",
        "}ijIN",
        "W@$sg",
        ";6o\"'P=]",
        "=RpMT",
        "]]@vVL",
        "Time Stamp signing",
        "sect193r2",
        "OUT_OF_MEMORY_1",
        "QJs(VC",
        "X,TW;",
        "9U^cf",
        "index too small",
        "hem]Ts",
        "7O7Y7b7",
        "Q7eFS",
        "@udxM\\",
        "-mD[[",
        "Lk[WHSA",
        "EPAM_CheckUpdSrc.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "FU>*Q=",
        ".t>'Y",
        "fvm7,V",
        "]IGb:",
        "<$=T=",
        "=b=v=",
        "P&Y2}x",
        "`bYIbK",
        "0y~['o",
        "KJ>8w!",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\upgrade.cpp",
        "gRIwf",
        "qGf`7",
        "StB/J",
        "gyahe`R",
        "UninstallAV:  UninstallAV() in vswmi.dll succeeded.",
        "P$Q<D",
        "G46f!",
        "<;u R",
        "f)8B>",
        "Tj1V\"",
        "O#_L&Nj",
        "y5^M^",
        "pr%F>ai",
        "-s[MI0",
        "`k8pw",
        "b33q*",
        "rgt30H}",
        "y0[Y\\m",
        "setCext-setQualf",
        "+$9QZIBLg",
        "W0Imqj[",
        "jmjvj",
        "!Xd4_",
        ">[4Gq",
        "2M2c2",
        "o,Q 4",
        "B\"C:CBCrC",
        ".?AVWaitBlock@details@Concurrency@@",
        "KAX!;/",
        "switchState",
        "xM~R=",
        "1vFA&=",
        "9g,P|",
        "IkR>-",
        "#;JMRr",
        "new-zealand",
        ";U=zC",
        "5(5s5",
        ":1:U:",
        "';,Oy^",
        "?$?,?4?<?D?L?T?\\?d?l?",
        "])V=]",
        ")N{N2",
        "cms_RecipientInfo_kari_encrypt",
        ":#:/:;:G:S:_:k:w:",
        "Y%WCB",
        "\"?m@pK",
        "8$8,848D8L8T8\\8d8l8t8|8",
        "vki]I",
        "2#222j2",
        "3J4s5y5",
        ">&>K>P>]>s>",
        "\"-E3f",
        "X&Nl)K",
        "!>a`Bz",
        "5(5,5<5@5D5L5d5t5x5",
        "ZLcr?",
        "d]A=z>",
        "epam_svc.exe\" --install",
        "e&Nl4{",
        "Q[%lL",
        "t$lVV",
        "#mJFd",
        "atlTraceStencil",
        "!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!",
        "No instances of VNA exist.",
        "lrcxu",
        "RegisterSecureAccessDSM:  Update SecureAccessDSM CLSID registry failed.",
        "Failed to remove reparse folder",
        "0,0004080<0@0D0H0L0P0T0X0\\0`0",
        "1d>i:",
        ",+wwo",
        "mag]%",
        "UhW2t",
        "\\zonelabs\\vsdrInst.exe",
        "5#666k6r6}6",
        " 0xf4",
        "I, x|z",
        "=JLZ%",
        "hV1XXi+",
        "wsprintfA",
        "/aUIYyH ",
        "0<9%:",
        "I{.X-",
        "FWFreshAfter started.",
        "jMdz2&E",
        ":.j%f|",
        "}bCQB",
        " Vgcc",
        "0.1g1",
        "~j>l>n>U?",
        "'O/{J",
        "c@<}j",
        ";[emxc",
        "DWkH/Q4N",
        "bblr7!",
        "-6IVsS",
        "j,no,",
        "\\)[Hb",
        ":!?(}",
        "]\\E`x*",
        "\"29.m>",
        "0S1X1]1b1}1",
        "T#2lc",
        ";#<2<E<Q<a<r<",
        "s3o'1S",
        ":#:1:H:",
        "6!GHc",
        "=:=V=r=",
        "M(+Q+",
        ",[s1mn",
        "22tGp",
        "O2b5m",
        "n.xG-l7",
        ";.i2s",
        "9?:f:",
        "3$383C3W3o3",
        "y;ZMO0z",
        " YCuK7",
        "going to run ChangeCharacteristics9to1",
        "5A5qU",
        "~0A:\"",
        "MSia9",
        "/^<_sq;",
        "|w-S+'",
        "Accept: */*",
        "p/>5b,k",
        " nrF;",
        "~1?b?",
        "e!De.",
        "u}bXs",
        "Q_W]#",
        "USERPW",
        "y_'?N3z",
        "S,B).",
        "%=!-Z+a~",
        ".?AVscheduler_resource_allocation_error@Concurrency@@",
        "i3!O3zg",
        "Check Point Bitlocker Management",
        "8]~>SS",
        "h_za&T",
        "<S<m<|<",
        "J\"{!Fv",
        "gN75T",
        "<IIZ5p7",
        ")au1VU",
        "/2xX;m#",
        "t$,WSU",
        "EC_POINT_get_affine_coordinates_GF2m",
        "eiIj]cYum\\Q1I",
        "_dC%2`",
        "z0?2b",
        "=8=T=",
        "0p1t1x1",
        "USER,%s",
        "<6 RU,",
        "O}P^MQB",
        "Zg\"9J",
        "\"q%Cu)",
        ",7}f)(",
        "DOhmH.",
        "=$=,=4=L=T=d=p=x=",
        "fQ}lof$m",
        "?`z:;",
        "1gRiN",
        "181@1H1P1X1`1h1p1|1",
        "_strlwr_s",
        ">0>U>x>",
        ":3;Z;",
        "VkBqQ",
        " hr~I",
        "{w8GdpVhO:z",
        "german-luxembourg",
        "9ZA$s2",
        "~tu~fm",
        ";&&p+",
        "CryptCATAdminReleaseContext",
        "|$(3x",
        "<H=h=l=p=t=x=|=",
        "mTC@66",
        "Jyv-D#",
        "ewh/?y",
        "{h;a+",
        "Lo#l>g",
        "*$WD>",
        "3.4.5H5",
        "Unable to send initial SOCKS5 request.",
        "}5b8P",
        "Yrhs6",
        "yr{T.",
        "u=5+id",
        "sNi3>a",
        "vi:\\]3",
        "\\$8hC",
        "OY@%lN|A",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "o3`oq",
        "ocibO",
        "wV4K3",
        "L$ SUj",
        "IA&`-e",
        "[Uninstall]VSTerminateTVService/OpenProcess failed (1)",
        "Y}Urj",
        "9$9D9P9t9|9",
        "^2m@/",
        "WjhZ6",
        "U,nL[",
        "}LT4xt",
        "tV;A#",
        "sl+I8",
        "VS[$d",
        "`.Jw<n9",
        ",n#]0",
        "C2nqG",
        "i&hli",
        "SS%{5",
        "SAO_9",
        "\\ZoneLabs\\05D20DB2.key",
        "}u;le3",
        "A0f0l0E1m1",
        "ckpg2'",
        "C r:j",
        "<^oj3^|",
        "]gn73tMH[",
        ";:#_|",
        "0,0<0K0",
        "FwComponentInstalled",
        "&an2C5b/",
        ";;;A;G;",
        "j+'B(c",
        "RAIm6>",
        "mgOX)",
        "|W35G",
        "j?zvT",
        "zWT9<",
        "Ef,G<",
        "X@yR:S",
        "rf8#n=]",
        "c2a`*",
        "F.S:1",
        "peer error unsupported certificate type",
        "8*898d8k8",
        "^RuV!",
        ">nHkL",
        ".\\+&b",
        "6HFdP?D",
        "0=S4_Vh",
        "key size too small",
        "3C3S3[3k3",
        "]ME<K",
        "031O1j1y1~1",
        "UbRfU@",
        "<\"<C\\",
        "a:}Fj",
        "-&?~'",
        "#- S(K!",
        "DR^H1",
        "open %s failed.  LastError = %d",
        "6tngx",
        "gg.5O",
        "1v9vUv",
        "4C6Cdi)",
        "BdWKT",
        "EC_POINT_oct2point",
        "ObsiP",
        "ZTmT-TmU",
        "Y/\\D-",
        "T[av(",
        "y?][_",
        "cannot disable PPL",
        "Ai/hN",
        "*-vf*u",
        "+Rb1=wj",
        "54Q4?",
        "jcS??",
        "3z}Fi",
        "7x:I*",
        "c@(#Y",
        "B@!Nx",
        "RKGu4",
        "Wh%,2",
        "_&S7^",
        ">0/r*C|`S",
        "uK5AM+",
        "njddi",
        "5T{`PcC",
        "]GjwX",
        "As\"\"O ",
        "#|o%1aC",
        "muSN\"",
        "!L7-']",
        "PHSUBSW",
        "wNc?=@J",
        "00-0C-29",
        "4#[G&_",
        "0/0B0G0\\0",
        "REMOVELICENSE",
        "7b7V8",
        "UpH|p",
        "_>}lt",
        "Wknl#",
        "]/sd$S",
        ",BKzv*Z",
        "6Kr9}",
        "Value",
        "&iz'S?",
        "+4/V#",
        "d|@UCu",
        "H6d$u",
        ".\\ssl\\ssl_sess.c",
        "644<l",
        "0?0J0g0",
        "*.xml",
        "O}aPt",
        "by71j",
        "Ce)<a!",
        "=!=>=t=",
        "invalid codepoint, stray high surrogate",
        "-exb!X,",
        "Fhf\\F",
        "e'p~o",
        "516:6G6_6p7",
        "GWOIz",
        "OCSP_basic_verify",
        "T$<3l$ ",
        "6]&)#0",
        ")Ya94",
        "yq'h3{",
        "A6uqjyg",
        "*gJ~[f$V",
        "N(;O(t_",
        "stopVsmon timed out, trying again.",
        "*`G;G<Pv",
        "8,889`9r9",
        ")=,}z",
        "8Gt^Iy",
        "IgEgFgG",
        "gI]Ua",
        "z)JW0",
        "D$$PS",
        ".?AVUMSBaseObject@details@Concurrency@@",
        "<x?|?",
        "-3+jo?",
        "Failed LookupPrivilegeValue",
        "lru,$u",
        "X509V3_get_string",
        "2vGK@",
        "Z>$@f",
        "000D0X0l0",
        "<I+$f",
        "npD~b",
        "Td|v{_",
        ",]:P(",
        "]KQ[Zi",
        "|+)Ynr",
        "/E`75",
        "4jeFM",
        "list error",
        "t-iQR",
        "P@>OP",
        "AES-192-CTR",
        "_<_KK",
        "1:B(_*Z",
        "TgDb)!",
        "V\\a25",
        "'bp'G;",
        "S38Oh",
        "'2LNrc",
        "qK-M\"",
        "646@6`6h6t6",
        "rgy+;\\*",
        "8c8*mnD",
        "~OUV3",
        "sxs.dll",
        "8H:H;H?H@HAH",
        ")(537f@u",
        "F>F h",
        "&\"wLGq",
        "CCAia",
        "],9R|",
        "+/;~XK,",
        "#!rb2",
        "zzN1;N",
        "Sending message to process id 0x%x",
        "imLGA&-",
        "}77`e",
        "Z\\hR|",
        "2|f7&",
        "V1,v8",
        "boost::filesystem::equivalent",
        "8:!tB]C:2B2",
        "J-EEH",
        "=F=K=`=",
        ";$;C;];x;",
        "'G{?&",
        "{Rww)A",
        "g~.4<",
        "<r%3w",
        "le=j[",
        "wt-Wo[",
        "AES-128-CBC-HMAC-SHA256",
        "vVa5)9z",
        "vvLio",
        "7W8{8X9",
        "Qm>LER",
        "l6MzI",
        "6`t>}",
        "5S=F4",
        "S$UqW",
        ".2\"(?k$",
        "Got unexpected smtp-server response: %d",
        "unknown module",
        "1f-%\\",
        "EBX:%08X",
        "9(9H9x9",
        "A'zj;",
        "S<=uO",
        "DSO_merge",
        "SetLastError",
        "6=7J7Q7",
        "RoI=K",
        "*rTEYzX",
        ")s]P_R",
        "generate cryptogram",
        "} jZa.",
        "ni4&s",
        "$]&]1",
        "iJjZH",
        "*M,UG}>",
        "q=R|O",
        "RSA_padding_add_X931",
        "<PW_u",
        "9WAWIWjW",
        "<><D<Z<",
        "\"TKRm",
        "pp:k1",
        "SOCKS4 communication to %s:%d",
        "9:*ZFr",
        "failed to create an instance of IUniformResourceLocatorW",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid5013025 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 .8}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "SSL_use_PrivateKey_file",
        "RSA_EAY_PUBLIC_DECRYPT",
        "< >\\>",
        "l$(CU",
        "as&++",
        "]ud8!",
        "848<8D8L8T8\\8d8l8t8|8",
        "onez\"",
        ")p`!v",
        "\\PkS0",
        "/54]x",
        "dR.*9",
        "%2.2X ",
        "2y3D4Q5",
        "PKo[/",
        "%\\%vj",
        "~T{QN|6W7p",
        "\\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid5186676 hardware components of its}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid1927571 Hardware Product}{",
        "dtls1_get_message",
        "kr[*<",
        "M$evd",
        "]YSB=|",
        "Tyx~G",
        "<^(QmIv^<,J",
        "{,l-\\",
        "T@^#k",
        "83DA&",
        "xkDCw",
        "MOw.,",
        "Vd}}2",
        "u=jrh",
        "00-00-44-45-53-54",
        "'l_OZ",
        ".&>-RUd{",
        "{\\fdbmajor\\f31523\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}{\\fdbmajor\\f31524\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}{\\fdbmajor\\f31525\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}",
        "l%kmW",
        "p8V;~",
        "$Y$y&y:",
        "Bdj-Z",
        "eO?e'",
        "j~6KY",
        "Could not read MaxNumFilters registry value, it will be manually set to 14",
        "u#f9X",
        "3>}&mC",
        "<$<,<4<<<D<L<T<\\<h<",
        "EPWD;EpamService;TracSrvWrapper;gwcc;CPEFR;CPCompliance;EpabService;TESvc;RemediationService;Full Disk Encryption;Check Point Bitlocker Management;",
        "090>0\\0e0",
        "t&hPh",
        "3!s2Q2",
        "?*?f?",
        "<bx(x",
        "j MIl.",
        "GKj?R",
        "&sDf ",
        "sg<]]i]",
        "SSL_ERROR_WANT_WRITE",
        "%MvozB[",
        "K0/7B7",
        "1{2\"3",
        "Failed to get handle to SCM. Error: %ls",
        "0&0z4691<",
        "bCollectPasswords",
        "gFvvq",
        "3z2(e1",
        "E2yeG",
        "oWdw;",
        "@2\\s_",
        "`@w;C4^]",
        "e-r9z",
        "+S<T&",
        "fnS<.NNJ;~Yn",
        "rtUj~",
        "puuA-",
        "secp224k1",
        ";>-z-",
        "[p>b?",
        "b5N9A",
        "[Bp#>",
        "G F3{e",
        "Fjjy}",
        "\";HP\"3S:.+!",
        "1Ft$*",
        "W#$y>",
        "_Xan\"L]>",
        "TNbG.",
        "nSFHc",
        "EqZPjq",
        "rp7f`",
        "aM':w",
        "dRs@H",
        "GF(2^m) Multiplication for x86, CRYPTOGAMS by <appro@openssl.org>",
        "c#j` ",
        "RV3B3",
        "],]H]S",
        "K@y9^",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\AeDebug\\AutoExclusionList",
        "0c~LR@.",
        "y44q=",
        "Finished extracting support files.",
        ".?AV?$bind_t@XV?$mf0@XVCRolloverMgr@@@_mfi@boost@@V?$list1@V?$value@PAVCRolloverMgr@@@_bi@boost@@@_bi@3@@_bi@boost@@",
        ")L%.=",
        "9Gh6:",
        "aRaz|",
        "H24,t=",
        "FeatureSC:  Setting dingo upgrade parameters",
        "=E=D>s>y>",
        "cyE_u",
        "^'*XB",
        "FeatureSmartDefense::Install",
        "K*M,O9P&",
        "FFREE",
        "`1<[8",
        "X0(FN",
        "\\c'\"pv",
        "5NU}^",
        "ir|p,",
        "0>,SC",
        "jejlj\"",
        "<xt\"<Xt",
        "h\\44Q",
        "{=A>\"+",
        "9BQd*",
        "^<0)[",
        "!h>235I",
        "MsiDirectory: %s(%s)=%d",
        "D$@1F",
        ";T_!A",
        "^k|6<",
        "dWj7n",
        "neTLg",
        "i{+iW",
        "D$$_^[",
        "#Cr^6",
        "1d2h2l2p2t2x2|2",
        "L;A%2",
        "PSQnM?oR",
        "k;Re+g",
        "DUj-m",
        "/i~%NN",
        "z@||)",
        "]P4?h",
        "MdTRZ",
        "W@Dqjs",
        "3u8G0",
        "F4_^[]",
        " \\\" j!Ac(P(",
        "/o'V=",
        "%!_sm",
        "!s!FeY",
        "u*jIh",
        "e.@V*oC",
        "x1|gV",
        "GhQbD",
        "sZ\\Z)",
        "1H^t!",
        ")<\\u1",
        "X Ev._",
        "ZSQJt",
        "i jtr",
        "^:UITWB",
        "g-ZOx",
        "T$h3T$ ",
        "Z8Ycp",
        "GMnvsE",
        "nStf,a",
        " <0<6",
        ">te5YJ{",
        "CryptSetHashParam",
        "lstrlenA",
        "\"%sTracSrvWrapper.exe\" -clear_sso_cache",
        "y`KO9",
        "Gm{%R",
        "}mnMr",
        ".\\crypto\\x509\\x509_att.c",
        "#5SyI",
        "=V>e>",
        "r!YrH",
        "Ji>2<",
        "SZ.gk",
        "Error: Watchdog registry key does not exist",
        ".\\crypto\\x509v3\\pcy_tree.c",
        "U7z:C",
        "8'8-888}8",
        "OTPTR",
        "<5<w<",
        "MakeSelfRelativeSD",
        ")f=QW",
        "i;OqJ",
        "AFmL9",
        "EVP_PKEY_GET1_ECDSA",
        "XKt]*Zh",
        "3?SQz",
        "1E/~_",
        "uK./Sn&F",
        "CMS_IssuerAndSerialNumber",
        "4;4c4",
        "728~8",
        "~]O}c",
        "|v_`=",
        "]MNM@N(Ah",
        "A%$gO",
        "S<T8@d}f",
        "_DH{pou",
        "Z=\"giC",
        "J]]x+",
        "SSL_SCAN_CLIENTHELLO_TLSEXT",
        ":X;(< =2=8=",
        "&t&pM",
        ":\":*:1:::",
        "64F4Z4",
        "WU'6z",
        "]Z(Rl5",
        "cBXO'",
        "CtTC>",
        "pGCu$h{E",
        "n?eu|",
        "RKYe)",
        "X>flq",
        "j':1P",
        "5b,9y",
        "!<R6B<",
        "UgxZa",
        "rpSlO",
        "A\"4O\"j",
        ":^utA",
        ">&w)]ovq",
        "V*mV?Jv",
        "3@G\"W",
        "MsiRunningElevated",
        "*a*]'",
        "g3[Ub",
        "S!rU7T$",
        "Xw`;d;f;g;i;l;",
        "jZ_f;",
        "                     ",
        "Jeq7{",
        " subject: %s",
        "tvAltDirForInstall",
        "RI;^1",
        "YdHO'",
        "*1jp/_w",
        "chunk reading DONE",
        "rc5-cfb",
        "f@>l%Zb!",
        "6Hj_{",
        "ZI5O1",
        "Jy\"e/",
        "##1Dh",
        "svbJ$%",
        "PKEY_RSA_SIGN",
        "}]^+i",
        "g2rpDo",
        "((rU;N",
        "Ng]u.",
        "l:@=c!m",
        "?Rj2?",
        "$Y|(_",
        "OV,ZU",
        "fgzz9",
        "aUM`>",
        "ikJmKmLm",
        "4g5}5",
        "w.}'t",
        "\\3j3E",
        "dLftdphTi",
        ">&?A?\\?",
        "*$%ZW",
        "8 8$8(8,8084888<8@8D8H8L8P8T8X8]8a8l9p9t9x9|9",
        "_\"bl6",
        "w}|8R",
        "enk}a",
        "X;@+}",
        "%eR3~",
        "x/hGuE",
        "S[nbE",
        "t$,ht",
        "WBzIE",
        "ri_w;",
        "entering...",
        "\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 1;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority34 \\lsdlocked0 List Paragraph;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority29 \\lsdlocked0 Quote;",
        "XLCTk",
        "C))M{",
        "j1#fw",
        ")&W:vY",
        ".}TB(z",
        ",(Y6?",
        "CANT_OPEN_FILE",
        "Software\\Zone Labs\\MiniLog",
        "I6pIR",
        "[9a IF",
        "=$=D=L=T=`=",
        "7tu$c",
        " \\x[aL",
        "<dwoy",
        ">U~Qy`V",
        "~Z:d/",
        "Y2+S4#",
        "VVMQ8",
        "wE-[<",
        "Qb<rl",
        "Aw.?L~ZP",
        "@|5tu",
        "8z[\"]",
        ">=umF8",
        "login",
        "1 1(141T1\\1d1h1p1",
        "F)F*F+",
        "4RH\\s",
        "i8I5O+",
        "rYf;u",
        "<KoWln",
        "regex_error(error_badbrace): The expression contained an invalid range in a { expression }.",
        "8494:",
        "message size",
        "dhSinglePass-stdDH-sha512kdf-scheme",
        " 39)?I",
        "22yL3",
        "^lQ#H",
        "}XC57",
        "qO*_[",
        "9:9b9",
        "(Unknown)",
        "n81_I%&",
        "z+,jX",
        "wwpiR",
        "m)~^f",
        "^s`Uc",
        "*Vt#;c",
        "vEC7X",
        "R&hH p",
        "GetTickCount",
        "\"]YJUb",
        "`-'IMI",
        ":zM=m",
        "wDq,5I2",
        "Failed to kill process [PID %d]: error %d",
        "PerfGetCounterSetsAddr",
        ":T=q%",
        "6No&}",
        ".sv+D",
        "Fr(9M",
        "9&[X~2",
        "UI_get0_result",
        "32ZV2",
        "*NK)Y",
        "q3cu7g",
        "au!d0",
        "rk,0S",
        "F;w(|",
        "(nTY\"N",
        "f )G=",
        "oh{{b",
        ">p;fg",
        "t.fypJ",
        "Z+b9-",
        "{~nzE",
        "7'7C7_7{7",
        "1nLc*UM",
        ";0<4<L<h<l<",
        "'7ab,V",
        "hMQ..",
        "IqYw<",
        "}nZzg*",
        "failed to schedule firewall install exceptions execution",
        "snan)",
        ";';[;",
        "!JT<sQ",
        "sDPRe",
        "RbuEe",
        "+;RRV",
        "[DUMPFILE] no dbghelp.dll found in %%PATH%%",
        "dh_rfc5114",
        "q|W3KH",
        "G\"zx{",
        "1>U$B",
        "%@FDs",
        "retrieved UI_Level property: %s",
        "iik(8r",
        "267iy ",
        "l6qnk",
        "T0wd')",
        "$`K?i",
        "7=X@iK",
        ";lSUG",
        "_or5pgj{_S",
        "5ptWD",
        "?%?R?\\?h?",
        "Z}[k\\",
        "sYtxZ",
        "keyCompromise",
        "Yk5Yk",
        ";'F7G",
        "%'5s,",
        "Got an Init event -- helper is running",
        "vPeLt",
        "%@xMWS",
        "D7uxe-;",
        "bad dh g length",
        "x<yxK",
        "< <<<X<\\<d<h<l<p<t<x<|<",
        "> >(>D>`>h>l>t>|>",
        ")Wm C",
        "application verification failure",
        "26zvr",
        "~(k5|",
        "<KZQP",
        "ZyWnt",
        "CheckForReboot:  CheckForReboot finished.",
        "PKEY_RSA_VERIFYRECOVER",
        "5Lh5y",
        "vL+Ze",
        "}Nmmn",
        "I^#N#",
        "/G|G{",
        "?GOpu7",
        "3+3G3c3",
        "ComponentsInstall",
        "MO3Rrm",
        "<'<C<X<q<",
        "2$2D2P2t2",
        "^][_Y",
        ":P0l0Y",
        "?5?<?E?O?\\?",
        "CMS_EncryptedData",
        "r2P]~b",
        "(\"dAxJ",
        " faulty unit to a location Check Point designates, and provide courier name and tracking number }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid8868444 to }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13200219\\charrsid8868444 ",
        "y1\"\"m",
        "W|W2W6",
        "Z>?hoL",
        "\\$$UVWS",
        "PFmoT-W",
        "gu3tS",
        "PJN_Sj",
        "ilA{Et",
        ": :(:-:6:J:T:^:h:p:~:",
        "=&5ue",
        "PKCS7_RECIP_INFO",
        "I74dj",
        "VFo?$f",
        "TrueVectorIF::LoadVsutil(%s) succeeded.",
        "ENZ%yp#",
        "}4s4{5",
        "h^Ai50",
        "MOVQ2DQ",
        "(5JO\\E",
        "jqA62{",
        "\">Rg*",
        "t UWVS",
        "1C223Z3",
        "''LUl",
        "ImportTablePatch('%hs', '%hs', 0x%x, 0x%x) - not found",
        "mIm\\m",
        "6|7+bQ",
        "iclient.exe",
        "B@;LZ",
        "L$,QU",
        "?!?&?C?r?",
        "9%qsm",
        "r-Ez:",
        "4:4h4s4",
        "rv#&Z",
        "lo.eQ",
        "tev!!",
        "KOm]#g",
        "9|$ t",
        "}/(U-",
        "M|=Cw",
        "Fy#WA",
        "@f91t",
        "7G7f7",
        "securitypolicy/osfirewall",
        ">]%Y3$",
        "V`3@U",
        "FW_INSTDIR",
        "YHERf",
        "2c5i`",
        "eWM'b",
        "PM8&$",
        "*(7G^",
        "566H6",
        "oV\"R1",
        "@n;R*",
        "iO~bM",
        "Z}WNH O",
        "d_!tCk\"",
        "I;~E5K?",
        "wK2$,",
        "{c7#7X",
        "{.p^+",
        "ck;CF",
        "Y].g$",
        "u>>9^l",
        " does not exist. Refer to ",
        "):3UC",
        "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz./",
        "ec_GF2m_simple_point_get_affine_coordinates",
        "[LICENSING] Can't get file attributes. Last Error - %d",
        "FsT(y}C",
        "^T~KK",
        "`sEDZe",
        "2?3R3",
        "ewtQq",
        "2-4w;",
        ".DVY3>3",
        ":YvSSg",
        "AR6`u",
        "28Q52",
        "FET9U",
        "}c\"E5k",
        "h)pxX",
        "n$K_6",
        "s authorized agents to perform such acts, or other unauthori",
        "W0% ]wf}#",
        " 0xeb",
        "X*8,!",
        "8lFzt",
        "OGL}z",
        "_^2-N",
        "ur-Q{",
        "[BX+SI",
        "jU9v]",
        "H?ZV3^",
        "5 5(5/5X5",
        "cYN\\S",
        "Xi,R0",
        ":aZg_=",
        "L(@T}",
        "{\\s47\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "2$2H2T2\\2|2",
        "(l&@&t&x'",
        "*\\2*U\\e",
        "<\\-f~\\",
        "w>9/:",
        "hy-am",
        "FzrkP",
        "-D;Fm",
        "k35*abk L",
        ",V?Q*",
        "djCB[",
        "9-:B:S:",
        "Uu9i'^(",
        "kml>d",
        "]uEdFH",
        "location",
        "  CAfile: %s",
        ">@?Q?]?",
        ".\\crypto\\ec\\ec_mult.c",
        "EXP-DHE-DSS-DES-CBC-SHA",
        "kNj(@=",
        "^e[S|m",
        "PLnnWz",
        "H7~Z9",
        "3b3<d",
        "*#5zK",
        "ZpS<s",
        "dGD>}f",
        "Z?=8]",
        "M6WYI",
        "nMI W",
        "SSL_set_cipher_list",
        "[)h#W",
        "|]4s])",
        "[f(i|g",
        "G(&8V",
        "x-6mT",
        ";Bc86x",
        "jFw=1uum",
        "Sh@9#",
        "~;POpu",
        "$c*?p",
        "u!!5Ta",
        "/2,`J",
        "\\rsid1591330\\rsid1709207\\rsid1729076\\rsid1770820\\rsid1771934\\rsid1786542\\rsid1787718\\rsid1841191\\rsid1926352\\rsid1927571\\rsid1987746\\rsid2035102\\rsid2052232\\rsid2098365\\rsid2103809\\rsid2115261\\rsid2260672\\rsid2317119\\rsid2385027\\rsid2388238\\rsid2566336",
        "Yn^G%",
        "^B7\"i",
        "DeleteFile:  Deleted ",
        ".i[DZ?",
        "hk})I",
        "r}Eob(",
        "IegE[5",
        "M\"K\\u",
        "YSAZ[\"",
        "j jpj!",
        "Process32FirstW",
        "9 9$9(9,989<9@9D9H9L9P9T9X9",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477 Prem}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid815761\\charrsid15169477 ium Ons}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 ite a}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "?2?U?x?",
        "WIX_DIR_PRINTHOOD",
        "capsule.ui.exe",
        "4\"\"t@",
        "<f#5~k*h",
        "Hm 8T",
        "B)~jH",
        "= =4=<=P=`=h=p=x=",
        "S3UHASA",
        "rit7%",
        "<Lg<p",
        "d.originatorKey",
        "\\par 2.7\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Disabled License-server.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "InstHelper is not running, will not be able to unregister client",
        "l5T`c",
        "Mu+O,`",
        "4ydPR&",
        "8GC7Cs,N",
        "a<Hb`",
        "cBlf!",
        "5&1\"1i",
        "0{(Rq",
        "I:|in=",
        "1\"2r2",
        "j\\hTY#",
        ")t$D+",
        "=W]/]7",
        "+u2glf",
        "x^~b<b8b6b b2b0`.",
        "f^]zL7",
        "M}0B}",
        "\")w('",
        "+ax\"!,",
        "%@\\l2",
        "zsRT-",
        "!85:\"",
        "=P:@^",
        "7A8\":g:",
        "CQxhT",
        "z\\jW4nL'z)",
        "F} P`",
        "h!x\"%",
        "pF:ck/aG",
        "U9x+i(",
        "}Vl/*",
        "3(32363@3J3N3X3b3f3p3z3~3",
        " oHg#",
        "failed to remove application exception for name '%ls', file '%ls'",
        "WhP|#",
        "'QTSc",
        "[LICENSING] SetKeyInRegistry, key not found = %s",
        "~B1FZ",
        ",!*PV",
        "id-alg",
        "keyBag",
        "3p|mM",
        "X!3qg",
        "G=j4p",
        "wr/>A",
        "azES,",
        "atlTraceTime",
        "t$PWS",
        ".m1LRn^",
        "3\"3e3",
        "BI_c-a#L",
        "wRuk]",
        "i@r&)",
        "jAjjj\"",
        "(({}M",
        "e+N--",
        "CreateWindowExW",
        "5L1{^%",
        "jfG1G",
        "K`WEK",
        "u-):.e",
        "@Vs\"~",
        "=8=R=t=",
        "hGXu(\"",
        "{3!yV",
        "GetUserObjectInformationW",
        "Registering file name %ls with the Restart Manager.",
        "Kerio Personal Firewall",
        ">B>]>k>w>",
        "!|;R#",
        "yN*PL",
        ";mc7u",
        "$@_;e",
        "c's%z",
        "$tpv6",
        "@]kx,",
        "&pW~KS",
        "9B}|cy%",
        "P Q R T",
        "MfSxE",
        "SedTjOa",
        "wFJDw",
        "~=Aj1",
        "lXeAzNA",
        "1(343@3L3X3d3p3|3",
        "?iTS#l",
        "{\\c(H",
        "+zYgK1",
        "c2*xqu#",
        "*1}9)",
        "L0$H>xu",
        "\\ZoneLabs\\vsdrInst.exe -g ",
        "VASyu",
        "a88g]b",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386\\charrsid15169477 ",
        "4D5d5",
        "~n/*K",
        "/2v'94fVD",
        "'Hp.E7",
        "N:95TS.",
        ",Z{^p",
        "<<n'~5hA",
        "\"IPdp",
        "xM~OV",
        "!.g+-D",
        "%|UD~I",
        "bCFuX",
        "zl*6S",
        "Fii,bG",
        "DA_PrepareStopCPDAService ended.",
        "y6SXl>O",
        "k&|sx",
        "N2222zt",
        "%RL(v1gWn",
        "$$lGy",
        "i5&w~-",
        "#D,7T",
        "H@S_&L@",
        "F,u&j",
        "LZXx-R",
        "l).(JY",
        ".\\crypto\\x509\\by_dir.c",
        "postalCode",
        "2$2D2P2p2|2",
        "{VL m",
        ":2;j;",
        "\"+Z)E",
        "ben;&",
        "v<DdG",
        "((((((((((((((((((<(A",
        "DodPD",
        "=%XWw",
        "!9LNZ",
        "yd#Sb--",
        "t!h4A",
        "5?_Ih",
        "{i;g4",
        "Na-~4V",
        "MJ:k5",
        "Wv@e.",
        "TS\\D3",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        ":E#?^3S}N",
        "Ez_L8",
        ".?AVimproper_scheduler_detach@Concurrency@@",
        "T$0jZ",
        ",:?xd",
        "5BW\"@",
        "jAjwj",
        "h MZ3<",
        "Bg`&X",
        "ut/ZF",
        "|$ t#",
        "Ds,]JaF",
        "O0TvZ",
        "D2acq",
        "MxSU:=",
        "6I6 nB",
        "xSvNg<",
        "d$FsC",
        "NB'os8c",
        "}5Jf}",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\defaultpolicies.cpp",
        "isSDKUpgrade: Kaspersky SDK is up to date",
        "2(242T2`2",
        "IO)$;",
        "Ueq0E",
        "h[r+g",
        "\\rsid8868444\\rsid8979425\\rsid8983224\\rsid8989067\\rsid9000788\\rsid9048298\\rsid9056778\\rsid9068002\\rsid9133137\\rsid9140702\\rsid9196264\\rsid9202780\\rsid9205239\\rsid9245012\\rsid9252096\\rsid9264333\\rsid9312430\\rsid9391338\\rsid9398143\\rsid9445038\\rsid9462072",
        "EX*> z",
        "ce;w+",
        "1 131d1o1",
        "dspx*",
        "9$9D9P9p9|9",
        "U:<L.",
        "Kaspersky Internet Security 6.0 (based on version 6.0.0.303)",
        "huy<N{",
        "/7%<xKJn",
        "t_%+t",
        "#lZ(I1",
        "Can not set SSL crypto engine as default",
        "(4Cjt",
        ">'!|+",
        "`.Y^4",
        "<;?Z?",
        "g`5_s",
        "j}5dj",
        "(6Ph-",
        "ZN/HQ",
        "||7b'",
        "om1Hz/",
        "qM[T=Z",
        "lYzOe",
        "$B/]~j",
        "=q?q<Q",
        "psk identity not found",
        "BIO_nread",
        ";(;3;>;L;S;Z;a;~;",
        "W.,97",
        " ikO`",
        "CVTTPS2PI",
        ") 7@B",
        "l-)44/",
        "qwItZ",
        "NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT OR OTHERWISE,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9140702  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 NE",
        "?Pv\"5",
        "J `}9",
        "0-Y+h",
        "W0-&{9p",
        "n T*:)",
        ":N;Y;^;",
        "xt~M;",
        "u>PVj",
        "Snkj]",
        "ulj\\h",
        "FCKy{-",
        "it,-P",
        "?&?0?M?T?`?n?",
        "=98?SLv",
        "75)Wl",
        "dynlock",
        "e/KL&V",
        "4M>Xn",
        "C.(Q|",
        "1S1c1v1",
        "`;cSJYZ",
        "OBJECT DESCRIPTOR",
        ".?AV?$codecvt@GDU_Mbstatet@@@std@@",
        ")QvnA",
        "i2B['2",
        "{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'08.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li6480\\jclisttab\\tx6480\\lin6480 }",
        "T<}7&3",
        "*?6|7H",
        "9Lst(c",
        "vsmon",
        "s@v+e",
        " 0x9d",
        "0pT`V",
        "Eg*Y\\",
        "5wB&G",
        ">_&X5L",
        "^1RxN+2",
        "9\"(fm",
        "Configuring VPN settings (3 of 6 tasks done)",
        "oOYQ9",
        "w39 B{",
        "2X2p2",
        ":g;~<",
        "bb]Q[",
        "T@mv*",
        "\\vsdrInst.exe.delete",
        "!,AOy",
        ":W;o;",
        "8 6<dZA9",
        "|dj77/",
        "8/Zd1",
        "#uA;\"",
        "QF.{:",
        "#'>Y|",
        "D$ tJP",
        "2n_GTfuP3y",
        "}~mQE",
        "type not digested data",
        "{\\listoverride\\listid-119\\listoverridecount0\\ls3}{\\listoverride\\listid474762581\\listoverridecount0\\ls4}{\\listoverride\\listid1099259507\\listoverridecount0\\ls5}{\\listoverride\\listid1263226230\\listoverridecount0\\ls6}}{\\*\\pgptbl {\\pgp\\ipgp19\\itap1\\li0\\ri0\\sb0",
        "ml'Px",
        "&]7.^",
        "SECUREMOTE\\",
        "set %s=%s",
        "K @m9",
        "=XVY1",
        "rH0`'",
        "get_xml failed",
        "Gy<TvC",
        "t j_h",
        "G*t1i",
        "a|Vt=",
        "14283?3V3",
        "NIST/SECG/WTLS curve over a 163 bit binary field",
        "p6!mK",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Licensed Configuration\\'94 }{",
        "4tcbc",
        "Ev);~",
        "t$ V=",
        "@}{\\HJ%",
        "PSw]m",
        "nF7\\zY]",
        "L_HG\\",
        "6JTR-",
        "%}Y}+",
        "wbf1w)",
        "#rD)r",
        "838L8T8[8q8",
        "wkS!qa",
        "H{EG^",
        "A<?S?",
        "N 5>Q9",
        "t'UJ}",
        "9,5}4",
        "X\\Ef9",
        "D#2Bj",
        "of{>84",
        "L2lz~$",
        "cJ^Ww",
        "y4eL3",
        "secure device signature",
        ">\\?Pb@",
        "-f3F2",
        "868H8c8",
        "#ex,?",
        "366Hv0",
        "D$DPS",
        "*V'!p",
        "pk[djF",
        ";@;P;\\;|;",
        "SchedXmlFile",
        "7#8N8y8",
        "3 3$3(3,3034383(=,=0=4=8=<=@=D=H=L=P=T=X=\\=`=d=h=l=p=t=x=|=",
        "af-za",
        "Y@7;Z",
        "Z *$?",
        ",6:\\r",
        "EC&tY$6P",
        "[VSReadUninstallInfo] Could not load the map from the mapped memory.",
        "Re-using existing connection! (#%ld) with %s %s",
        "\\zlavscan.dll",
        "9fvLrH$",
        "{T#~h8",
        "F}3:@",
        "xl&}6",
        "LFYipt",
        "x4<lLj",
        "\\dhK$6Q",
        "o [W:",
        "V{[G<",
        ".?AVCheckFile@@",
        "jbv#$",
        "TI:S(Y",
        "JC*5}",
        "9w(u$",
        "l0[<T",
        "${GVu",
        "no key or cert",
        "h b+J",
        "j\"[VWWWW",
        "4=U36",
        "%ev&j%",
        "?sAsTs",
        "$|[X\\~O",
        "err asn1 lib",
        "GLl&g",
        "%*sExplicit Text: %s",
        "X`]Kp",
        "/3E_E",
        "7*qtS",
        "|'9Xq",
        "tJSF-",
        "-5:%:",
        ">&>0>5>:>s>y>~>",
        "N|%hWM",
        " %X `)",
        "h~2xca",
        "]9m0<",
        "K@Hf2",
        "@JT;ig",
        "G~cGb",
        "jI].m",
        "[Q\"kr",
        "/8L0*",
        ",1XB%q",
        "|c>,l",
        "fr'Q8",
        "Ph<d#",
        "K\"GmM",
        " 0x78",
        ";0<L=",
        "q4eh8f<",
        "[hyN~",
        "8+929=9K9R9X9s9z9",
        "282D2d2l2x2",
        "teOWx",
        "{f@Un",
        "?.?G?`?y?",
        "[=_`V",
        "Y*TY{Z",
        "NudwP",
        "ZK>j7",
        "-W_Rt",
        "h2_9T-",
        ",O8Cp",
        "989T9p9",
        "zDBtA",
        "8rraU",
        "RSA_PSS_PARAMS",
        "=#7Y;",
        "A2Pbsm",
        "Too many open files",
        "Pjrj#",
        "$3gtk",
        "}ZH^&",
        "!$M H",
        "f^k4T*",
        "i%q'V(Ee",
        "@B& 4",
        "56{Dx^",
        "xe<N`",
        "6.VF~v",
        "messagedigest wrong length",
        "Warning turning protection off failed.",
        "2%3U3z3",
        "7=tVv!E",
        "j:cm\":S",
        "6/Y8g",
        "G08Q0",
        "L@ )X",
        "5Jqb5",
        "B!K}]",
        "?xv>{j",
        "pvo&q",
        "7Y8b8p8",
        "RJV% ",
        "MOVZX",
        "9l\"n#",
        "^:fj|&-?",
        "/lN^8?|",
        "1/1[1",
        "JNz]a",
        "Ry-I_",
        ";:;j;",
        "T_^[]",
        "N0W8y",
        "seed-cbc",
        ",ZWi;R",
        "!mr56",
        "#m-)a",
        "pvlE(",
        "|v3m~",
        "AC4tS",
        "d:.Lx",
        "d2i_TS_RESP",
        "H0u1'",
        "6nu9d9",
        "machine",
        "void __cdecl boost::property_tree::json_parser::read_json<class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >>(const class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > &,class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > > &,const class std::locale &)",
        "oKs\\[",
        "*~`DR",
        ",2^Y!i8*",
        "kG3 &",
        "Suite B: curve not allowed for this LOS",
        "l<-8V",
        "h7)^d",
        "|{@w#",
        "LOGUPLOAD",
        "\"G4]h",
        "Yvc\\+y",
        "VPNInstalled",
        "SSL_read",
        "$Dl9Z",
        "='>4>=>J>q>w>",
        ">%NZn]",
        "f5w5x",
        "X/[zp",
        "no time stamp token",
        "O$+F +O ;",
        "-N3.~w",
        "3)333=3a3k3u3",
        ")W)U(",
        "cOSJ;<xW",
        "a7N!M",
        "hqNMSu",
        "3H3P3",
        "x'#W!",
        "REGISTRYFILE",
        "])4l\"/",
        "YqYxY",
        "aQ)YZ",
        "98s\"3",
        "HeapDestroy",
        "({v(On",
        "dNI]R",
        "GjBpz",
        "\\fs20\\insrsid8673032 )}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid13256927  }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032 s}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid13256927 ervices}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "gO7X2",
        "$k9Ll",
        ";Z (=9^",
        "yAP*A(Z",
        " T%hx",
        "`K(GR",
        " ?+KS",
        "=J.\"[",
        "%ng>N",
        "CryptMsgClose",
        "5Tvc[",
        "?zr+z5/^p",
        "jkMs ",
        "05At=",
        "TFTP: File Not Found",
        "b`TBFRoM",
        "$ZE],",
        "5$5,585\\5d5l5t5|5",
        "illegal boolean",
        "ReplaceOrAddTagIntoVSConfigPath(%08x)",
        "w<hMQ",
        ".ulXNb",
        "*I.ik",
        "GE\"t[",
        "XiZYK",
        "rtR0z",
        "yvK)M",
        "><>D>P>t>|>",
        "G~@@f(",
        "{3}?Y",
        "CTFLT",
        "S1-({h?",
        "[r@(6",
        "%UOCE",
        "FN,q`:",
        "sRV\"e=",
        "Self protection disabled",
        "y:ej~",
        "_.7Gx",
        "zI^5fZq\"",
        "vkz?d",
        "PuT9H",
        "n'8w%2",
        "D4&b?",
        "=!;fJ",
        ";6;G;\\;a;",
        ")JOM|",
        "i6PwC#",
        "pn]<&",
        "0_|</",
        "07Su:{",
        "i|A'R",
        "]eEm%",
        "0Yzr9!%",
        "u7hx'",
        "2#2/2=2T2[2g2t2",
        "wD-G(",
        "5&565=5D5K5R5Y5`5g5n5u5|5",
        ">q8=:$",
        "E7X=H",
        "i+s_a",
        "5;rHC",
        "e$m&^",
        "64eJR",
        "3&p0N",
        "WReRh",
        "j0}n#",
        "D$@Pj UW",
        "li4PC",
        "\\W^Mt@A",
        "636V6",
        "failed in setting SelectionLanguage",
        "Zl:S1b\\",
        "zF[=[z",
        "JFG`\"0]",
        "ndIvl",
        "[Sexn/\\",
        "du{u.joT",
        "6-6I6e6",
        "qZF@'",
        "%Zst=;",
        "=67@yP",
        "eo3lP8",
        "8[+L4",
        "X^G|8",
        "\"\\5S\\",
        "vQ[.j",
        "j\\>Y(",
        "mM%Ktc",
        "JP20A",
        "Sp1iDI]",
        "5$5)5H5X5n5u5",
        " 0x2b",
        "7F5M?S]",
        ",G,g,",
        "txz!j",
        "1d/=I",
        "8F8K8P8Z8",
        "Jswm`",
        ".;XGrP.}",
        "8`myt",
        "SQf>C^",
        "Unsupported protocol",
        "ti.:K|",
        "{{48\\",
        "Brur1",
        "E%z9$",
        "n7N|u:?",
        "4+4A4N4\\4j4u4",
        "#pyn[",
        "T9QM|",
        "_1K%j",
        "fREHr",
        "; 7|Q",
        "=Z>e>",
        "6dtO(k",
        "l$tUh",
        "RtlSetLastWin32ErrorAndNtStatusFromNtStatus",
        "7!717A7Q7a7q7",
        "wVA17",
        "YYTXG",
        "3Na7p|[",
        "pa-in",
        ",+NX\\",
        "^Tmem",
        "FNQJ\\l",
        "9p^3v",
        "failed to find WSACloseEvent function (%d)",
        "eSELECT `Component_`, `Directory_`, `Name`, `Target`, `Attributes` FROM `WixInternetShortcut`",
        "G.O'_x",
        "G~XF[",
        "Xy5_ ",
        "{&}`5!",
        "6t%UW",
        "D$8hH",
        "D(Bag@",
        "?e;Pc7",
        ".A&;U",
        "|%!1HL",
        "Wo7md",
        "a<LG9lLB",
        "-v_`H",
        "3 4F4K4]4u5",
        "zqr2v",
        "#1Hi7",
        ":ZJ0E0D",
        "O_v;[",
        "0(000@0U0\\0",
        "_-=62s^",
        "9N9y9",
        "nke6m+",
        "and such nonconformance can be verified by Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9202780\\charrsid15169477 , }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 Check Point}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Agnitum Outpost Firewall 1.0",
        "Y2cF\\",
        "jGhp*#",
        ")jxXC",
        "g/%9(",
        "iG$%3",
        "u}Ep>",
        "+ZAN?m",
        " Base Class Array'",
        ")X Y N",
        "u28C`t",
        "oP `^",
        "6+6D6]6v6",
        "id-smime-mod-oid",
        "About Zone Labs Integrity Agent",
        "&i!c|",
        "I-d(u",
        ")d!XR",
        "\\r2B LczB",
        "ZoneLabs\\ssleay32.dll",
        "dAgO+",
        "etM(5d",
        "kEOi\"4s\\",
        "[5r6Fk",
        "b76fC",
        "E~4RT",
        "n4n6a",
        "[LICENSING] LteCheckRun: NOTICE corrupt key %s attempting repair. modedate: %d",
        "%*sHash Algorithm: ",
        "hb`xH[",
        "t|/d\"S",
        "<\"=-=7=K=[=",
        "SR4DF",
        "HYWaP",
        "^F(/Ja",
        "b&m69RS",
        "gITL`",
        ">LQ]V",
        "t*N6u",
        "dUVP]",
        "4 4$4(4,4044484<4@4D4L4P4",
        "Uevozw",
        "040<0D0L0T0\\0d0l0t0|0",
        "l$43T$",
        "ruBE#[",
        "O9]%y:",
        "pO)OnKBK",
        "]vWgR",
        "4Vr#[",
        "}?NwL?;P;?<",
        "9&909B9L9^9h9z9",
        "r$SCsAx/q",
        "SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "aGpd0",
        "Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0",
        "#]LyG%",
        "T:&cq?",
        "SzR`F",
        "RfxFiles",
        "))TUe*KY",
        ".~0&XW",
        ".?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "9K9w9",
        ")Bh~r",
        "P;b8A",
        "?E?j?",
        "3!Suj",
        "Y@|sVv",
        "M/k'`h",
        "aJ^9Q",
        "Lc,V<",
        "Mb5J_{Y;",
        "X=xhf",
        "AL]App",
        "=L=t=",
        "~'bWR",
        "= =(=0=8=L=T=h=p=x=",
        "IKxC2^",
        "<n<x<",
        "9{=\"Fa",
        "Y2R:@",
        "TnSo(",
        "cUX(uM",
        "Z7l<)E2U ",
        " GSS-API integrity",
        "GC-LM",
        "permission denied",
        "OwtEc",
        "6&626A6T6s6",
        "excluded",
        "+XG(A",
        "K-233",
        "E]Eu(m",
        "&ADGo",
        "jAqegf#",
        "bSQ/1;",
        "=&>B>P>`>f>",
        "/@A|+",
        "W|e.Q",
        "PcSda",
        "J1lex.",
        "iT%Ix",
        "'0-t3Mg",
        "ONp;r",
        "X=s*O",
        "$!.rl\\",
        " 0x8e",
        "767\\7",
        "81888D8r8",
        "Gcw>t",
        ";&^}\"",
        "bH?-k",
        "uv%@g",
        "](%EP",
        "A:P a",
        "gtW*d",
        "mgP$j",
        "`eh vector destructor iterator'",
        "Ue.Et",
        "Bg!U/E",
        "<wJ&F_",
        "c1BWj",
        "eX_QF",
        "Zo]x_",
        "2jrJ}",
        " KUS)m",
        "`v7Qx",
        "GetLongPathNameA",
        " 0xa1",
        "%WfOc",
        "SWPPh",
        "rz7~dHeB",
        "=CT/DI",
        "jkjyj",
        ".su*H",
        "P~35C",
        ":gx#o[",
        "CUu6!]",
        "nwE^o8",
        "<F\"a.",
        "FxsrY",
        "hjAg>f",
        "J)F,Q",
        "O{%T<",
        "w{7-.",
        "0!N?d(X",
        "2=2I2",
        "1F4X4",
        "bCr#=",
        "~|sYT",
        "0 0$0(0,0004080l0p0",
        "A)\"y!",
        "v|8D[",
        "p<[sf",
        "B6|_\\",
        ".?AVinvalid_oversubscribe_operation@Concurrency@@",
        "5 5[5g5n5w5",
        "?`G:o%",
        "t:8z4",
        "j uH3y",
        "=^>N@",
        "tMBa2",
        "ZX!4%",
        "pu>?R|<",
        "C9WdFC",
        "p0^3d",
        "wTJ^{",
        "'3smq",
        "+oTQq\\ e[]q",
        "Check Point EPS Installation Helper",
        "%\"IL4V",
        " a+'B`",
        "8\\V^>",
        "yzel9",
        " filename=\"%s\"%s",
        "*'f9`C'1|",
        "Li<R7",
        "^jcRb",
        "9#9f9s9",
        "]^:^G+",
        "PKCS7_set_content",
        "O*KzFU",
        "`BF)fZ",
        "&|NTa",
        "CLDzH",
        "iW @?F",
        ";8<P<",
        "9~Map",
        "Le)K^,e6",
        "dU1px",
        "*8\\a89",
        "q<sN)#",
        "\"+b!V",
        "}x)hDz",
        "m-xJ;{",
        "T-,1n",
        "setct-CapRevReqTBEX",
        "a_\\$uF",
        ":=:e:",
        "XSNK0&",
        "%W1b8",
        "?gWPi",
        "*k~kN",
        "id-GostR3410-94-CryptoPro-A-ParamSet",
        "=(>F>",
        "#gGM=:",
        "id-smime-mod-ets-eSigPolicy-88",
        "Z/g%H",
        "TrL*b",
        "wrong ssl version",
        "797i7",
        "!pm2;n",
        "szValue",
        "sM{4}^",
        "DM\\xl",
        " 0x2c",
        "?DxO)\"",
        "l/2;$",
        "F.jXZ",
        "{Z7>TD?c",
        "dJT07",
        "S,(5HyA",
        "MuQ|3",
        "g-W3q",
        "Stopping %s returned %d",
        "?;?x?",
        "3(4c4",
        "StartInstHelper",
        "N8$CN",
        "Duration",
        "839I9",
        "t=$yK",
        "9wLt7",
        "SetThreadpoolTimer",
        "B1\"g-",
        "Failed initialization",
        "+tAMG",
        "SYSTEM\\CurrentControlSet\\services\\",
        "siqD(y",
        "~$xUkD",
        "2P\\pr",
        "PeekConsoleInputA",
        "hkiGX",
        "P8%O+",
        "a!NsF",
        "6Jp8X",
        "giv,9",
        "Q=<Ne+9n3q+",
        "#X\"(ZF",
        "!}FfX",
        "f!Mfd",
        "S`s9z",
        "[d_rJ2",
        "could not unload the shared library",
        "*v`t{",
        "|-(-S|",
        "p<l1[",
        "JIu)o",
        "0.Oyla",
        "8&858?8Y8`8o8}8",
        " 0x77",
        ".C.;yVh",
        "/r16Y\\bxQ",
        "'`Var]",
        "PSh@I!",
        "Hello request",
        "OPENSSL_finish",
        "aN$Ng@R",
        "c\"haN",
        "boost::filesystem::read_symlink",
        "FAILED_TO_LOAD_DLL",
        "H16#+",
        "pwMt?",
        "uX9^\\",
        "1qPh;K<",
        "tolower",
        "oQHkP",
        "yQ|#u",
        "<<<B<a<}<",
        "KTooq[",
        "hmg'K",
        "m)T;K.",
        "$bPfiy",
        "TwgT[",
        ":5rfR",
        "CHj=(",
        "ForceRebootDialog:  ForceRebootDialog finished.",
        "><y:87a",
        "A}ih_Nx",
        "X5fh ",
        "FW>b ",
        "e;~A5J",
        "k/8A9X[",
        "Vfyqk",
        "#p(LE0X",
        "H#@cD",
        "`g[bf",
        "y@I\\6",
        "DHnjs",
        "{_I+S",
        "rKf;u",
        "w8H6!/",
        "yv1qC",
        ")ZQ[4",
        ".\\crypto\\pem\\pem_pk8.c",
        "5iS]K",
        "Itbfc",
        "UK{Ac",
        "ZQk\"]",
        "VcQB3",
        "697G7]7",
        ">XT`1=Bg",
        "5=5t5",
        "a$7!8",
        "pOSOnOrO",
        "hGS0[s",
        "\"|J\\(",
        "d$l_^[]",
        "T!7k1",
        "wmQIJ",
        "!UU,u",
        "failed to open ckpOldGina value",
        "0#0)0.040:0@0E0K0Q0W0\\0b0h0n0s0y0",
        ">/!go",
        "dg|uC",
        "[2m}f",
        "[*;RH",
        "Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.",
        "'ZG?C{m",
        "3TP4 LD",
        "Ty~lW@",
        "(t>G1",
        "5P5\\5b5v5",
        "bu\\>x",
        "L Cg&uk",
        "d\"Erf",
        ";(;0;4;@;H;L;X;`;d;p;x;|;",
        "!E/O-",
        "yvlNcG",
        "EVP_DigestFinal failed",
        "o@fEf",
        "I5-Zw",
        "8hdn%",
        "7$7+797?7M7S7]7|7",
        "6+7R7",
        ";*}(Dw",
        "gpiT[?",
        "9xsqV`o",
        "%Pj1U",
        "mhlwf",
        "egH{b",
        "%KH m",
        "en-au",
        "EUz\\1",
        "}U;s[",
        "LX-%j",
        ">8>X>x>",
        ";.;u;",
        "An|;pT",
        "&uYI)F",
        "m5zz\\",
        "b5rw5mB3tf",
        "mR!RC",
        "<GE\"s",
        "c+C*{",
        ".\\crypto\\x509v3\\v3_lib.c",
        "=_w=d:",
        "k/xZO",
        "Y;9#Cz",
        "1@1q1",
        "3.4]5a5e5i5m5q5u5y5}5",
        "7'7.757?7H7}7",
        "=&qz\"7",
        "partner.manifest.xml",
        "TAa4Zn",
        ">(`1Yg",
        "&>f*5N",
        "2#2K2",
        "9\"9/9",
        "Failed to Set Property (of INNER_MSI)",
        "u)jAXf;",
        ";V8s ",
        "ot$0f",
        "~S<l}",
        "(=>?@AB?C*",
        "T=:=\"3O",
        ",vmg8",
        "P+/mX",
        "_+3on9r}",
        "[Registry] RegCreateKeyEx return=%d for path=%s name=%s value=%d",
        "8|?&kNk",
        "3lZ]/",
        "3T$D3T$<3T$(",
        "[VSDATA] AddDataClient: DeviceIoControl(DIOC_PRODUCT_VERSION) failed. Err=%x.",
        "SSPI error: %s failed: %s",
        "&uD4<",
        "3r%{l)",
        "1O1d1",
        "{AVs[;",
        "C)=WY",
        "O\\jb#",
        ":':A:k:",
        "89e\"E+",
        "+>q=)>",
        "#t{_/",
        "e#$HD",
        "i^s4$",
        ":JJhza",
        "dwPubKeyLen",
        "{\\fdbminor\\f31563\\fbidi \\froman\\fcharset177\\fprq2 Times New Roman (Hebrew);}{\\fdbminor\\f31564\\fbidi \\froman\\fcharset178\\fprq2 Times New Roman (Arabic);}{\\fdbminor\\f31565\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}",
        "\"pZ8\" 8",
        "4L<LDL",
        "cryptocom",
        "151>1C1",
        "RY]yM",
        "&mr|D",
        ")k#Z' ",
        "kVy&wU",
        "V\"ie<",
        "1S2q2",
        "N(C[S",
        "8qs6^v",
        "EoRnn7",
        "fp}TF",
        "g-D.e",
        "Fg7*K",
        "b\",h+,",
        "successfully load CRL file:",
        "seeAlso",
        "server response parse error",
        "869E9",
        "signatureAlgorithm",
        "/~*\\-,",
        "fclose",
        "5gG!T",
        "'+jW6",
        "vj<T6",
        "j2`{bz",
        "5Y21j",
        "VA3_%",
        "P7IG:z",
        "}$1BJ!",
        "HXdbD>",
        "[6vgS",
        "\\database\\",
        "#7gqnM?",
        "!6!b!",
        "Q}cr?",
        "name too long",
        "GfL_+M=",
        "r4{^_",
        "9 9=9H9^9",
        ";:tT3",
        "iatyb",
        "i9p\"a",
        "WnkDb",
        "3mOt]",
        "i[idbi",
        "T$p3L$(",
        "PVh$0#",
        ";svLaw",
        "j{3UM",
        "GetModuleFileNameW",
        "KrcB+",
        "; ;8;<;T;X;`;d;h;|;",
        "!:(7=CT",
        "B 1vI",
        "H9L\"it",
        "T2q3~3",
        "xm#.qTTm",
        "{Wfoy7",
        "n9&WO",
        "ky-kg",
        "4QJd^",
        "_4Dp:",
        "9FP|5j",
        "9i'mLC",
        "upS3&",
        "Failed to kill process handle: %x",
        "Subject: %s",
        "![\"ko?2R(",
        "2N2l2",
        "7tSXr?",
        ".?AV?$basic_memory_buffer@_W$0BPE@V?$allocator@_W@std@@@v8@fmt@@",
        "^ n<l",
        "=C3`)Cn",
        "+jBq<",
        ",242@2M2T2]2f2v2",
        "oPm+3+",
        "- unexpected heap error",
        "tzK/sa",
        "DeleteCpdaService",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566\\charrsid12218863 {\\*\\xmlopen\\xmlns2{\\factoidname place}}Latin America}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566 {\\*\\xmlclose}, European Union and Asia Pacific}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "[W0(8",
        "yax?Z",
        "95:f:}:",
        "VIR2?3u",
        "i2d_PublicKey",
        "0]-Q]",
        "VvRvQx",
        "~^o5m8N",
        "70?(0",
        "u7*8AiFa",
        "u*jXh",
        "K7jsx",
        "=B+c/",
        "&jah0",
        "{72?.y",
        "SSL_write() error: %s",
        "-cI0-9",
        "N{k8\"",
        "*uUmCG",
        "!Tbv[",
        "qUgHe$",
        "VmZz8",
        "RRWVQ",
        "Wo6dsHt0",
        ")(J J!T",
        "8!818A8a8",
        "Software\\Cisco Systems\\VPN Client",
        "TgF.@",
        "lT^~<",
        ";.HG:+7",
        "'yek?N",
        "StartInstHelper custom action finished.",
        "6 6@6`6",
        "no proxy cert policy language defined",
        "ssl3_change_cipher_state",
        "wl!!A",
        "3P'6#P$",
        "KY`}p}",
        "O2WBPU",
        "-d3L8",
        "jeVsT",
        "&&k%D",
        "5+Vl)",
        "v\\d@T",
        "515x5",
        "/fD#V",
        "uxmLta",
        "414c4",
        "K.cpI",
        "0.1>1V1",
        "5(5/5@5j5x5",
        "XQ py'",
        "Zh9vQ",
        "m^^;aU",
        "Ecn#d",
        "GOST signature length is %d",
        "EC_POINT_new",
        "Cq6\"QWR",
        "3Zm_9i",
        "Load file into cache",
        ".?AVICheckFile@@",
        ";OId,%",
        "1Z3t3",
        "nl-NL",
        "failed to schedule RollbackServiceConfig action",
        ": :,:4:L:d:x:",
        "1{z/!%K",
        "-A(#8",
        "mH|)?s",
        "Sl/|c",
        "\"IWE0",
        "Frf.<r",
        "Installing firewall exception2 %ls (%ls)",
        "X\\nhI`",
        "C1zfR\"",
        "L$$QP",
        "bLmT'@",
        "uX3S-",
        "IsBinaryExist failed to Open View \"%s\". Result = %d",
        "*<24Y",
        "jojij",
        "i2d_DSA_PUBKEY",
        "klKtu]Ox",
        "@|RdgohK",
        "Z%B2x/kMb",
        "1$2I2}2",
        "6g[agI",
        "gDia&",
        "\\M\";`",
        "I)[C}o",
        "PhL)M",
        "NEs1}",
        "G8TeQ",
        "6)6E6a6}6",
        "nfy-^FL",
        "mycW${",
        "*3<\"u4",
        "'1$X,",
        "5 5$5(505D5L5T5\\5`5d5l5",
        "9V(~Bj",
        "!J*B\"&",
        "*SG9QG",
        "IXJX&",
        "-Q\"#{",
        "%AH\"-",
        "=$=4=8=H=L=P=T=\\=t=",
        "8!9J9",
        "?N?m?",
        "210101000000Z",
        "L;|fh",
        "*dj&N",
        "RFC 5639 curve over a 384 bit prime field",
        "RSA_padding_add_none",
        "7+7c7",
        "4z5S6",
        "8dD9_6",
        "C>8$2",
        "20$B?",
        "3vFIp*",
        "+bh])6",
        "8|~LX",
        "808D8X8l8",
        "NKC<XL",
        "5n]e(",
        "3$3D3P3p3x3",
        "P<u&rj",
        "'!ugr",
        "b_\\A)Q",
        "s/lQh",
        "^K={v",
        "EFRREGDBPATH",
        "q@,(.1",
        "l0rY\\",
        "ecdsa-with-SHA512",
        "SSL certificate status: %s (%d)",
        "Ag) gg",
        "]d0pN",
        "`Szm4`",
        "zp\"P0",
        "x\"{:%",
        "L!;YHd_",
        "D$DSUVW",
        "/Jh;p",
        "6\"7R7",
        "0vU'A",
        "Pso3;<",
        " b:gUM",
        "gejp]<",
        "'}*}N",
        "34`V;",
        "{HU'u%",
        ")'Gq#2",
        "X\\]a_",
        "Lh'i{",
        "tDEu>",
        "2 mmm",
        "=n'M.Emg",
        "m< LP",
        "#T$`#",
        "6*7S7",
        "uSSSSj",
        "missing asn1 eos",
        "nP|mE",
        "0([u4",
        "Fi$$`-",
        "ko3&\"",
        "VO2O:Lj1",
        "0G~=l",
        "\\system32\\zonelabs\\vsmon.exe",
        ")EyB#",
        ";7,G1F",
        ":;;G;b;",
        "msExtReq",
        "NENYN}NjO\\",
        "6:6V6r6",
        "6)7J7",
        "C-i+y",
        "5z0Qc",
        "u_%[l",
        ":Check Point Endpoint Securit",
        "FI56n",
        "O/2|af-",
        "u jUh",
        "%s\\Temp\\%s",
        "GSSAPI handshake failure (invalid security data)",
        "@-YdB",
        "2Vn\\S",
        "4]9y(.",
        "([Q`QbQdQgQjQlQnQy|T\\",
        "=4fZv",
        "1!1-151G1R1Z1b1j1s1|1",
        "Kw@Hv@",
        "1\"fflQ",
        "QbL'|",
        "6<BU`",
        "%W1L%;",
        "u1TZ^",
        "Iv}_tL2",
        "=dViM",
        "T9:,I",
        "~8#\\j\\",
        "6p8Q)",
        "=+SQ\\c;",
        "t81f\\:",
        "destinationIndicator",
        ")Bh7+q",
        "OEMTLEN",
        " yK,\\",
        "aV/gW",
        "cZF*k",
        "vsmonapi.dll",
        "Telemetry was not sent. Curl error: %d. Telemetry event was stored, retry in 3 secodns.",
        "/zP~9",
        "m`Egw",
        "UninstallCreatedItems:  Removing registry key HKLM\\System\\CurrentControlSet\\Services\\vsmon",
        "1I&Xi",
        "+@/eq",
        "SELECT * FROM `Upgrade`",
        "K\")_JX",
        "b~{[%",
        "\"P{]v",
        "`9@=c$^g>*>",
        "sjs=$N",
        "Range: %s",
        "zcec7",
        "sslv23",
        "U}EYk[y",
        "gO\\D\\",
        "8bnUIK",
        "r08\\c",
        "+Wt5`",
        "HZYZYRE9",
        "yBYF\"",
        "N^*=P",
        "IsStandaloneMode: RegOpenKeyEx failed: %d - assume this is NOT Standalone mode",
        "3>3j3",
        "r|]#<",
        "mk,bmp",
        "O$kNdf",
        "@.reloc",
        "5:6G6",
        ";6<G<w<",
        "@ChJz",
        "Z<2yT)",
        "uy2=M",
        "unexpected message",
        "void __thiscall boost::property_tree::json_parser::detail::source<struct boost::property_tree::json_parser::detail::encoding<wchar_t>,class std::istreambuf_iterator<wchar_t,struct std::char_traits<wchar_t> >,class std::istreambuf_iterator<wchar_t,struct std::char_traits<wchar_t> > >::parse_error(const char *)",
        "gaw\"k",
        ">3s:!z",
        "_6,\"Z",
        "B9E?F",
        "<}MPi)",
        "ZJHAD",
        "yLBpg,",
        "ssl_method",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\bootstatistics.cpp",
        "_*FLj",
        "*T{:=",
        "'0$CR",
        "d3I,+",
        "h8hXhxh0`",
        ")\\JRH",
        "9zDJk",
        "P)_u[j",
        "H1=&R",
        "]hKLG@",
        "EwX]{Gd",
        "MmdiU",
        "Content-Range: bytes %s%I64d/%I64d",
        "Check Point Endpoint Security Bitlocker Management",
        "j\\%s^",
        "J7_jk",
        "c4N:,",
        "8pRl/u",
        "M:cnc",
        "GetCurrentUmsThread",
        "sow*IP$",
        "3F4v8",
        "Y16,7",
        "Ri6hFX",
        "9Jzj*",
        "g{t:m",
        "8;[2iv",
        ".YIJ ",
        "XLmG7",
        "qq$AT",
        "2#3c3",
        "y<\\88O",
        ":o_&X",
        "@RxT}",
        "h5gxi3",
        ">)>^>",
        "D$(PSh",
        "Zxz]{",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 9.1\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "n^PR_",
        "cZy~n",
        "?V1hc",
        "SOFTWARE\\Classes\\Installer\\Products\\",
        "RRsv$",
        "07,}v",
        "5$m09",
        "tUSUW",
        "[sjje",
        "08*.Ig",
        "m@Y^=",
        "QK'O*a",
        "ng#9]",
        "QueryServiceStatus",
        "8(8/8",
        "E0b&n",
        "ECDH_CMS_SET_SHARED_INFO",
        "55!D#",
        "procutil.cpp",
        "vTcc=",
        "^c(1u",
        "nbX\"t",
        "323Z3",
        "'J+vLL",
        "~ss\\R",
        "sMQ'Y",
        ":IQ#4=",
        "jb{ET{",
        "`S>+/",
        ")9%s=i,8",
        "T+T7#z",
        "QMh_;pQ",
        "{^XRro",
        "gnnXE",
        "(B%Uh~",
        ";i(vA",
        "oZ#MyQ",
        "^!Jd$",
        "GlH%X",
        "Signature Algorithm",
        "y}\\)J8",
        "T/`$@",
        "QWo?n",
        "|b,rM x",
        "t$8UWWW",
        "~bZ{k",
        "%]kuc",
        "extendedKeyUsage",
        "!u)mf",
        "4 4$4(4,4044484054585<5@5D5H5L5P5T5X5\\5`5d5h5l5p5t5x5L6P6T6X6\\6`6",
        "#e@Nj",
        "1(2(3",
        "Failed to retrieve Composition state",
        "2,4;W",
        "o\\43#",
        "`b;BDxMc",
        " 4e|5Y",
        "t?;w0t",
        "<f!rt",
        "1&QV(",
        "Upgradeability enabled. Going to stop all drivers.",
        "aI); ",
        "U\"=)c",
        "  replacing by %s finished with errorCode: %d",
        "G:i]&",
        "NO_INSTALLFILES",
        "%8;VUN",
        "&ixf=",
        "w-4Q4",
        "&CJHP84",
        "445e5",
        "u[56F",
        "\\\"j&PL",
        ".?AV_Locimp@locale@std@@",
        "bSFH:",
        "nAt=W",
        "bZKMF",
        ".oj&r",
        "<=Q4=[",
        "cmd /c \"del /F /Q \"%s\\System32\\epcginashim.dll\"\"",
        "Failed MsiDoAction on deferred action",
        "JF7w,",
        "Too long hexadecimal number",
        "Services to be reconfigured to manual start: %s",
        "[$,C)m ",
        "ZS\"^p&",
        "|7Urdsh",
        "j#wAT",
        "Resolving timed out after %ld milliseconds",
        "SEC_E_DELEGATION_POLICY",
        "WWWW-Wu",
        "2\"=7B",
        "ENCRYPTED",
        "\\p]C`xS",
        "CANT_GET_PROCADDR_SEALROOTPAGES",
        "[VSDATA] FwConfigChange: ERROR! dataclient is not initialized",
        "}TIR^r^",
        "&_6IH",
        " iciNWq",
        "282Z2",
        ">F?P?b?",
        ".3szAh",
        "4&+=F",
        "TXT_DB part of OpenSSL 1.0.2h  3 May 2016",
        "QX~er",
        "s3l1p",
        "\\bin\\SR_Service.exe",
        "Bp1/'",
        "W o/{[P",
        "J9W7?",
        "api-ms-win-crt-convert-l1-1-0.dll",
        "&ZaF.\"V",
        "kXTLDa",
        "uK-N|",
        "7:7u7",
        "Keep user configuration files.",
        "2F`'z",
        "V79_O",
        "4L4Q4V4[4c4q4y4",
        "I)t4:",
        "-'j'mvi-",
        ">y=pSUo",
        "~-R`$",
        "i$+j<",
        ";%cpIT",
        " ?ko~r",
        ";!;=;Y;u;",
        "tnSMD",
        "Old Updater detected",
        "CANT_FIND_VSINSTALLERLOGOFF",
        "3T$<3T$83T$ ",
        "va\\K][",
        "vxuYj",
        ".\\crypto\\x509\\x509_v3.c",
        "NfY4=",
        "O:4Gn",
        ":_+Z7t",
        "Y_a+%wtl",
        "3n<Ok{",
        "t$:wT=",
        "P>,~0",
        "9):F:",
        "wW<La}",
        "#.:e@(",
        "60777F7T7k7r7",
        "?u(|:",
        "eventObject",
        "t\"R}'",
        "INSERT INTO Binary (Name, Data) VALUES ('%s', ?)",
        "nxBbe",
        ".\\JpI",
        "3!ZEip",
        "{NWX||",
        "22282K2a2j2u2",
        "U-%-v",
        "[{:y)",
        "+WDi2#",
        "5 585<5T5X5`5x5",
        "IE9#6qTw",
        "-+`g}",
        "e9e.w",
        "BGLY{%Q",
        ",kkX-=",
        "D^_bS<",
        "C[r,9A",
        "M{x[O",
        "@kY/\"",
        "Port number out of range",
        "D$4PU",
        "xz}xzx",
        "SetProductMode:  SetProductMode finished.",
        "OnmgR",
        "ExtractExternalFilesToTempDir",
        "E<GuF|",
        "yngtJ",
        "CRolloverMgr::TruncateLog():  unable to get file size",
        "^r7$G",
        "?C59[",
        "/cUpgre8",
        "1rj4~ ",
        "*>|=\"",
        "z^nyu",
        "Sectigo RSA Time Stamping CA",
        "!pZQhh",
        ".icC${B",
        "getsockname() failed: %s",
        "w9yd$",
        "g^Oel",
        "8A fHi",
        "``(]y",
        "9j9Zh4",
        "0$0P0d0",
        "+|u&u+0",
        "PLSmSP",
        "WGn?-+",
        "c+c5c=",
        "V^p&o@",
        "<C;+;k9s|6;",
        "s[#%s]",
        "aB6kG",
        "9,949T9l9x9",
        "Mij'sS",
        "__w64 ",
        "4f:w:",
        "@7_!!",
        "Insert file: MsiViewExecute",
        ":$:<:B:O:_:}:",
        "H;Z;)",
        "ASN1_VISIBLESTRING",
        "E3m\\Vg`",
        ";`1)O",
        "Ya58T",
        "unsupported recpientinfo type",
        "xdsHr",
        "(|{9p",
        "not supported file type '%s' for certificate",
        "XI68l",
        "H]?0n",
        "<to@^",
        "\"/#p*",
        "@D<o@Z",
        "QqCmr",
        "3dR`@",
        "bn error",
        ":';M;h;l;p;t;x;|;",
        "Qh\\PM",
        "protocol not supported",
        "&c-Sz",
        "l-gq 7",
        "=\">7>^>",
        "oD $1",
        "es-PA",
        "3YqU:",
        "Y!Wxjo",
        "result too large",
        "`non-type-template-parameter",
        "7 7&7,72777=7C7I7N7T7Z7`7e7k7q7w7|7",
        "cPBXUo",
        "-4S94",
        "~2S)<",
        "8;8E8\\8",
        "exceeding max licenses",
        "/$|1,",
        "&?6$F",
        "('J$\"m",
        "@Cd:c",
        "Kaspersky 6.0 (based on version 6.0.3.837)",
        "setAttr-IssCap-Sig",
        "Symantec Corporation1",
        "bv23~ec&",
        ")<V5ai",
        "U\"UGm",
        "RANB\\",
        "ESz^?*",
        "jujuj!",
        "=a?'A",
        ")NZ6o",
        ";_OiQwu",
        "xm9f6",
        "fL#M=",
        "5zZ>/a",
        "K~Ys`",
        "ly(O}",
        "60656",
        "O74Ad",
        "Not detected",
        "x|6_X",
        "PJ2:MS",
        "$hLUe",
        "HZ48G",
        "AzKNKU",
        "issuer capabilities",
        "3eAD2",
        "noRevAvail",
        "BN_mod_mul_reciprocal",
        ">$>4><>D>L>T>\\>d>l>t>|>",
        " All rights reserved.",
        "RbS\"T",
        "memcpy",
        ";hiMx%B",
        "9?9J9\\9g9t9",
        "yBZc`F7]",
        "wL40Mg",
        "IEVER_LESS_THAN_4",
        "Couldn't resolve host '%s'",
        "AOhIw",
        "2<2A2K2",
        "%4I64dT",
        "S0t%GN",
        "b>F/!l",
        "1C2H2",
        ": :4:8:<:@:D:H:L:P:T:X:\\:`:d:h:l:p:t:x:|:",
        "d>$HJ",
        "21}zP",
        "/dHlg",
        "\\'S~d",
        "@rn=$3MRI[",
        "2BXK8",
        "mdj6F",
        "uT(jn",
        ">`8Iw",
        "K\"`&u",
        "klbackupdisk.sys",
        "=2=U=i=",
        "#\\))j5",
        "*5?5#)",
        "\\wc?P",
        ".)9oR",
        ")H^Sq\"",
        "%~w(J",
        "616Q6a6",
        "_jyte",
        "7K7M8O9j9",
        "!(gBLJ",
        "[#,StZ",
        "* ZWDZ",
        "1,\"as'",
        "|*O1o",
        "!V>uA)",
        "pxPh+?",
        "5<NPv\\~(",
        "#Bu)c,",
        "91;h;o;t;x;|;",
        "-OGNa",
        "a2K~Z",
        "_OJ?A",
        "Xtqyg",
        "pagerTelephoneNumber",
        "7q&m*a",
        "P'URS$",
        "a6lAW",
        "failed to set string string into error message",
        "*_on_demand_*.*",
        "H<~lR",
        "%m#,[",
        "ZcD93?M",
        "n3U1#",
        "v#4g(_R",
        "Qsyz{",
        "V(gmY",
        "=e.W[",
        "N1[xV",
        "S*3!m$o~",
        "\"bXyWyj",
        "S/k/U",
        "mR.IE",
        "5\"VQ7",
        "=\"=&=*=.=2=6=",
        "krb5 client get cred",
        "^;`\")6I",
        ":''[w",
        "WzPWS",
        "Muz\"}",
        "5689811a183c61a50f98f4babebc2837878049899a52a57be670674cb23d8e90721f90a4d2fa3802cb35762680fd800ecd7551dc18eb899138e3c943d7e503b6",
        "PKCS12_verify_mac",
        "P5(e~",
        "TMJ\"pi5",
        "OnUpgradeAfter:  Unregistered SecureAccessDSM.dll.",
        ">&B@(e",
        "\"Y.1%",
        "`UuUUU",
        "?]G[yu",
        "+F86\\",
        "ikuvG[",
        "F7Et7",
        "2<2H2h2x2",
        "tOf90tJP",
        "stopVsmon succeeded.",
        "lE0UlT:",
        "id-qt-cps",
        "hAgw$",
        "^.a.f.g.k.o.q.s.y.",
        "i;qo-",
        "bk]9p%D",
        "*Je8b",
        "id-aca-accessIdentity",
        "FAILED_TO_COPY_DISSCON_POLICY",
        "2*2A2",
        "FkE^`",
        "&ys7Quz",
        "WD_RemoveWatchdogService started.",
        "&Faf:",
        "S2I_SKEY_ID",
        "fBV\"=$",
        "oT$p1",
        "n4\\48v",
        "h@ O6%L",
        "b`iRK",
        "6k$4`b",
        "xKGkS",
        "des-ede3-cbc",
        "~^_t3i",
        "/@+`h8",
        "Iz'Ks!",
        "}q{D0",
        "^EuH,I)",
        "5N,N'",
        "JV-R1f",
        "+fxMl",
        "jO)}\"",
        "RUbUHF",
        "put_validateOnParse failed",
        "B=!&|",
        "-w-S!j",
        "w(j]zq",
        "i8Ixq1",
        "(+nxe,s",
        "D$4Ph`:!",
        ".(m*8",
        "J;'6s",
        "8H9l9",
        "636V6y6",
        "?'?u?",
        "ul;qI",
        ".YPbz",
        "\"*0D`",
        "PWjUR",
        "|f}h>",
        ",:e{I@S",
        "Fo?#q",
        "bd<vH",
        "6l.zm",
        "3T$D3T$",
        "NXEI{",
        "l)~Ur",
        "DrDhD",
        "#vOS{>",
        "id-smime-mod-ets-eSigPolicy-97",
        "ConvertSecurityDescriptorToStringSecurityDescriptorW",
        "'A\"?<j",
        "6k[8_Nv:",
        "/X>bCk(",
        ";I;798",
        "ZrTSeV",
        "S>8]1J",
        "Failed to detect WIX_DWM_COMPOSITION_ENABLED",
        "%s service has been started.",
        "Mjv<K",
        "    <protection zlcommdb=\"true\"/>",
        "naA6l",
        "l}]W-",
        "invalid init value",
        "6%6.6U6Z6`6j6t6",
        "/28taD",
        "7e8k8",
        "M-1bX",
        "83kn4",
        "[K]taM?",
        "SetThreadPriority",
        "9Ra%u",
        ":K:R:X:v:",
        "k,[hf&",
        "originator",
        "&kFKR",
        "=L=T=|=",
        "N'Z(e",
        ".fVTZ",
        "bignum too long",
        "&,GCT%",
        "v2jz{*C",
        "gD,(,",
        "~h1[W",
        "jqjej!",
        "9b*M?",
        "MEDIUM",
        "li!i>",
        "WLWTU_Y",
        "42*N{",
        "'0QuD^",
        "Tj^*~A",
        "U3nvR",
        "DF)TC",
        ">i>s>",
        "!wH]8jH;v",
        "2u>ukw",
        "K?>ht?",
        "}QnJ9",
        "K R|FX4,hg&CV",
        "VgsEW",
        "151e1",
        "DHE-RSA-AES128-SHA",
        "i[\\JB",
        "O$?*P2",
        "ver.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "8O&Kl ",
        "?Wra~W>",
        "~0WPQ",
        "{]V[.",
        "u2 Un",
        " ?%t7Q",
        "=x)D%I",
        "CAQuietExec64",
        "=>>`>i>",
        "M !08",
        "S$0w{SK ",
        "x\"B''jw\"",
        "|svtQr",
        "7m;kG",
        "?gnOR",
        "av!2<",
        "3JigA",
        "[WinFW] SetWFStatusXP, failed to get domain profile, error=%x",
        "=)=B=K=_=p=v=|=",
        "%yhyV",
        "j(P;.",
        "102<2",
        "bN(^q",
        "lL?/0",
        "q\"(>d<",
        "LG2je<",
        "by,W'4'`",
        "eU(B+",
        "0#p& E(",
        "5X.$;tf",
        "kwQk,-",
        "+$M||U",
        "+*4mm",
        "Failed to rename %s to %s.",
        ":1:B:O:e:s:~:",
        " ID5wpV",
        "8$8*878?8E8Q8V8\\8`8d8h8l8p8t8x8|8",
        " ^P 9",
        "\"_vkh",
        "^aP1g",
        "7E8a8",
        "EmY04",
        "KAPY5Z3",
        "Zg\\s_",
        "hacq\"",
        "EPAM_CleanOldRollback.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "'X\\ _",
        "u`RuVu",
        "C2YI0.",
        "w].*uN",
        "?N?X?o?",
        "Couldn't bind to interface '%s'",
        "Helper constructor: CreateFileMapping returns %x",
        "[F?;\\",
        "+6B 7",
        "ID,'?i\\",
        "5H&c;O",
        "7<8j8",
        "u\"j j@h",
        "AGHAUHN",
        "InstDll::~InstDll",
        "0M,{e|",
        "Q-N9YD",
        "3QhS^",
        "[R12D",
        "]<D~jV",
        "?:Q i",
        "x?mU`",
        "k[Bh:|",
        ";>#oU",
        "~EvrlO",
        "cT.}C",
        ".f{/8",
        "\"FpLv",
        "m=2'E",
        "-sHIq",
        "Zk||yN?y",
        "19wdT",
        "BW6\\M",
        "\"%08p\"",
        "?gj]+B",
        "camellia-128-ecb",
        "\\63$V0",
        "id-GostR3410-2001-TestParamSet",
        "\\WatchdogAPI.dll",
        "4:5P5",
        "\"36>#",
        "RVV)<kB",
        ">@?d?}?",
        " 7LX6",
        "|NYKp",
        "G12a\\",
        "b!sz,",
        "Z!PM,",
        "7*7C7\\7u7",
        "_dMpv",
        "G_6a\"",
        "}a6+#",
        "/omK0J",
        "/_I{L",
        "Cannot set value",
        "ZoneLabs\\vsdb.dll",
        ".^i`f",
        "XsODy",
        "cms_EncryptedContent_init_bio",
        "Gor$h",
        "uTSVPFD",
        " SEND",
        "kp8`nMV",
        "baP9!7",
        "=0\\eLY",
        ">I>S>{>",
        "5lHH?",
        "n8#k8",
        ";+`H<",
        "X9.62 curve over a 304 bit binary field",
        "[DUMPFILE] %s not found, trying from %%PATH%%",
        "Suite B: certificate version invalid",
        "\"6mXWd",
        "#7d5by",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\McAfee Personal Firewall Plus",
        ";H<-W",
        "M`.\"g",
        ">9>U>q>",
        "uLl1H",
        "TVgxoD",
        "8B8U8",
        "6DjkF",
        ":_k3$",
        "shared info error",
        ".?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@",
        "a\"Aj6",
        "sg(bZ",
        "]?N[jo",
        "<1<O<",
        "29=D~",
        "a{6S{l",
        "i2[WX",
        "k+uCw",
        "{Rzj\\\"",
        "YzC1p",
        "P!Tmr",
        "GXSUV",
        "P68? t",
        "wd:A0\\",
        "GxQ/{",
        "unexpected eoc",
        "t5a&]",
        "=ZVc,",
        "lstrcmpW",
        "CommandLine",
        "B?KZV",
        "xDe_M",
        "}yB8Z",
        "Vh8XG",
        "<>=F=",
        "zW|q&v9u",
        "$Ed5B@",
        "Wvrnn",
        "9miSY",
        " 0x41",
        "])rbX",
        "B{M:M >",
        "^Gl+V",
        "~3o@r",
        "o[9kPl",
        "I^gBJ",
        "\\oY-p",
        "/Bb!A",
        "*p;0y",
        "s-7r~",
        "a. L)",
        "TGw!x",
        "Failed to resolve \"%s\" for SOCKS5 connect.",
        "zk4F[\"{",
        ";-^G-",
        "a46@X",
        "E#]_^[",
        "deMot",
        "1C9{<",
        "Any language",
        "l2/x5.",
        "sx6AVx",
        "#48k&",
        "|uq6)",
        "FXP:U",
        "k';bwW",
        "epQ@k=",
        "z&>w!3",
        "Pf(!l",
        "QyL%sC",
        "Cy\"?K",
        "=.=H=_?k?r?",
        "U(GQ3",
        "8;9@9D9H9L9",
        "%*s<EMPTY>",
        "Pgua?-",
        "6\"6D6",
        "N \\oe",
        "J?&zb",
        "ImportTablePatch('%hs', '%hs', 0x%x, 0x%x) - different original 0x%x!=0x%x",
        "btdN|'",
        "`U`fs|a ",
        "C+PjUW",
        "3$4D{",
        "+(Eco",
        ":SeT^",
        "critical",
        "\"rL#D",
        "*|)(#pG",
        "78>e{",
        "+P'U!",
        "SF/jN",
        "k2%H/",
        ".G gP",
        "&ee(i",
        "xZ=%7",
        "H'pGi",
        "dm$6ti",
        ">9yl\\U",
        ";>K0W",
        "BJ<=Yw",
        "5.xQ<",
        "X-]wX",
        ": :$:(:,:0:8:X:\\:`:d:h:l:p:t:x:|:",
        "mLs! ",
        "103w3",
        "h@]>7",
        "\"\"%lp",
        "Mo9X?x",
        "M[O^9",
        "XRAdT",
        "Qg&L.b",
        ">C,D}",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\msidirectory.cpp",
        "jz}L4P-w",
        "%u/)^*w$",
        "O**DC;.*T",
        "pH+F<Dzyd*",
        "|?Rg{",
        "?d/t/]",
        "SHA384",
        "k%+Z\\v}",
        "CMS_add1_ReceiptRequest",
        "47|oln",
        "4K|nhMeih",
        "K ZvsW",
        "Whitelisted in dev",
        "222R2z2",
        "ujU:N",
        "sW.,b",
        "zedv5",
        "WEKsQ.CO",
        "GCBx5g",
        ">:?h?",
        "t%roT",
        "U}Z\"e",
        "5>9Mc",
        "RegisterSecureAccessDSM:  Failed to register SecureAccessDSM.dll.",
        "[[X~+",
        "CryptCATAdminAddCatalog",
        "}D_EJQ",
        " 7I\"P ",
        "$_vIV",
        "obqbsbubwbyb{b",
        "3:3\\3",
        ".eEs(}",
        ":@! y",
        "!7iMj",
        "9BSVD",
        "+\\_w p",
        "PMOVSXDQ",
        "ydWRkC",
        "ExecFirewallExceptions",
        "<:Y6Y",
        "i 9@$",
        "yGaLX",
        "`j^QG# ",
        "Em[Aj\\",
        ":RJQM",
        "=;>D>Q>",
        "holdInstructionNone",
        "M*+0-4-",
        ":!;K;",
        "py>+ol",
        "<o;U.",
        "u@r)X",
        "L)mN|",
        "quz-EC",
        "1$v\".",
        "@o[M,,",
        ";c;k;",
        "PhlU\"",
        "050V0s0{0",
        "Tr@^Qe",
        "0$0<0N0c0o0",
        "S&)%.e",
        ":YMew",
        "%<]Xa",
        "pki2v",
        ">1>6><>F>L>T>l>",
        "$3A3Xt",
        "Is\\U7",
        ">,>5>N>",
        "insufficient winsock version to support telnet",
        "%D3zg",
        "4/4I4c4r4",
        "F\\[N59WfJ",
        "dwmapi.dll",
        "8r\"gv",
        "$wrYw",
        "3Q3a<",
        "method not supported",
        "|(sHW",
        "3!4A4v4",
        "s8BR-",
        "fZ{.`",
        "w]Kg;Z",
        "K9r@5a",
        "a5]#&",
        ")UC9PL}-G",
        "ytn&B9",
        "v9Wwd`",
        "7msVqTP<",
        "vU}\\x{-u1?",
        "m k<Eh_w",
        "9#9)979F9",
        "}\\:dx",
        "7K`y/",
        "1cG85",
        "9)9V9d=",
        "0$0,0@0H0P0X0l0t0x0|0",
        "J2/0'HO",
        "rnZ;S-",
        "SEC_E_DECRYPT_FAILURE",
        "fB>@Y",
        "E86_20_scenario_2",
        "\\sxqfV",
        ")Bt,Sf",
        "SavedProductMode",
        "b@E\"r",
        "=PN>S",
        "d!Uc6",
        "^aa4/o",
        "|[ QN",
        "KemYb4",
        "FeatureVpn::LoadSettings: finish",
        "pc(x>",
        ")qxdPdP",
        "S#5A$",
        "mfr\"0",
        "Q4\"-0",
        "V,w=9",
        "0GeU`",
        "\"p:*d",
        "8#9j9",
        "(%iSrT",
        "}k+#e",
        "h'4Op",
        "^!TBi",
        "5` ;&",
        "ZoneLabs\\VSSSOPro.dll",
        "E`|\"1",
        "OK._R",
        "}2IbrM",
        "ASN1_get_object",
        "0M<r3",
        "fznyA",
        "#4Z.}",
        "B\"iF'",
        "3=4Z4",
        "484P4T4d4h4t4",
        "bNNW^",
        "*]G_x",
        "M<MZj",
        "Content-Type: %s",
        "k q4m",
        "XJ0yj^",
        "`?UZK",
        "~_;zk",
        "Do'Alk",
        ";eC\\g[",
        "-1SLxxH",
        " d(2MW",
        "u~fim",
        "gpZXZ",
        "\\_&5Q",
        "sma-SE",
        "^_:5(",
        "qp&}*",
        "failed to set authorized app name",
        "V$.^Q",
        "=_Ip0N",
        "F-Secure Internet Security 2004",
        ")$iHk",
        "&5msw",
        "FQ\\t89",
        "5>f4G",
        "q;JMa",
        "b&oL;",
        "k:*1%|",
        "3d0 gx:W",
        "CfSu0",
        "qFPI ",
        "nQ=bK",
        "CS>QW=",
        "8?9E9K9Q9W9]9c9i9o9u9{9",
        "^g;a!+",
        "U)2ZG",
        ">,?|?",
        "9?9i9u9|9",
        "0#H\\,@",
        ":?*>h",
        "4*5j5",
        ";9<@<",
        "9~8~R",
        "\\f1\\fs20\\insrsid3737333\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 ERROR, DEFECT OR}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3737333\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "uLImhn",
        "A<*b%",
        "n\"dX~",
        ".pR{K",
        "jH*AO",
        "/KQadA{",
        "@%Bk~",
        "Failed to retrieve temp file name",
        "(rEk#H[",
        "l?F&v",
        "<\"=1=@=O=^=r=",
        "8F8U8j8u8}8",
        "W28&5",
        "6}K\"F",
        "1JQXU",
        "EFT)f",
        "&\\t@A%",
        "4]D{{",
        "u3sf;",
        "%;uqa",
        "Gw|fj",
        "X,u'#}",
        "V3_ADDR_VALIDATE_PATH_INTERNAL",
        "cpDigestUpdate",
        "srtp protection profile list too long",
        "IFR{s",
        "tKrrc",
        "r8B2g",
        "Ii*eb",
        "5i|Z`",
        "/|k$c",
        "eZ{xv",
        "HErIe/",
        "X'_xM",
        "v7$~ZG",
        ",*-)l",
        ">.%CgO",
        "0%D!;",
        "]4rM+",
        "6]6c6i6p6",
        "sS;xTD",
        "\"}Db}E",
        "f-w3%",
        "8w5Vj",
        ")1Txu",
        "z7+M2",
        "R. Cok",
        "fNxo,",
        ":hZfD",
        "GL=Nm",
        " }e>h",
        "{3\"kj.",
        "cd6K:",
        "!$,%==",
        "Y;suQ2",
        "4jI[aM",
        "issuer",
        "pcVsxr",
        "^=u<,)@",
        "failed to open key (%d)",
        "P._ =",
        "v[T-m",
        "Z:Q\"yp",
        "crlTime",
        "`ge:&",
        "R.}J`",
        "d|t/*O",
        "j#ncN",
        "5{*\\(8Y",
        "lastModifiedBy",
        "RLAbe",
        "p@usG",
        "hAaq82l",
        "OgS?d",
        "Ju6#)",
        "C?+lx",
        "sz{kG",
        "*OhB#",
        " (?/v>",
        "0/0O0o0",
        "w@RR:b",
        "9_~z2",
        "G5T0@",
        "i%7z_",
        "4l9yMB",
        "8$8+8K8W8^8",
        "$aXgu",
        "ea(;q",
        "'&h[{",
        " 0vug@",
        "pb{>C",
        "ec_GFp_nistp256_point_get_affine_coordinates",
        "8(8A8Z8s8",
        "s<y`<",
        "blLgf",
        ".C`;_",
        "Z=H;j",
        "m:|@i",
        "!Bg LE",
        "949@9`9h9p9x9",
        "@(j)g",
        "~Z:Y|/@",
        "?6?=?L?U?",
        "/A$b%",
        "5F5b5",
        "b=Z\\}",
        "'h+LK",
        "pt=?`}",
        "CRolloverFileInZip::Open:  PopulateZipFileinfo failed with error = ",
        "-I49gT",
        "3;4v4",
        "jcn,2",
        "]o]'Q,",
        "\"ffdhb",
        "Ck`+9",
        "IgQ]k",
        "H'E*Y",
        "CAMELLIA-192-OFB",
        "Upgradeability disabled. Going to stop epnetflt.",
        "L|S\"_%",
        "rsIKf",
        "n|s,H",
        "-*j,x",
        "Auu8B",
        "9X9}9",
        "5P [u80J^",
        ")?,&i",
        "Custom action starting.",
        "yMG{a^",
        "d=q]I",
        "<K3Us",
        "+\\al=",
        "f/oRSGRPv",
        "{gfVw",
        "<&<B<^<z<",
        "p3S[-",
        "7%+hg",
        "g1(mV",
        "6Kc>Fq$",
        ",K zz",
        ">.NE-Q",
        "yxsk\\",
        "6f7k7",
        "<zQ}<",
        "2QFwFj",
        "EEYp.3",
        " NAME",
        "xP*t'",
        "wNsdifx",
        "4!L2`",
        "{@MLq",
        "JA`DL",
        " 0x6c",
        "808R8}9):;:",
        "J-)aLU",
        "7' Sq",
        "K8CL^",
        "Ph|>%",
        "D?&&O",
        "P!mAo",
        "`<@v>kNH",
        "LR\"8* ",
        "CONFLICTING_FIREWALL",
        "7&nVN",
        "2cq\\x",
        "PBE-SHA1-RC2-128",
        "u#J-]",
        "D+|:p",
        "`#Sg9",
        "XSmA/",
        "mVmvh",
        "OCSP response verification failed",
        "sz:1W",
        "=I>m>",
        "BIO_gets",
        "te,da-",
        "%*mcD",
        "+oE#04",
        "u jRh<",
        "PREFETCHT2",
        "tvU-@b",
        "wZt{8$",
        ":T{$p",
        ")vx'<",
        "d2i_SSL_SESSION",
        "343<3D3L3T3\\3d3l3t3|3",
        "|5^CY#",
        ">PuhAD",
        " ^mLZ-",
        "u&xg3b",
        "Configure vsconfig.xml to protect ME",
        "_'Vi ,",
        "n/cH1fE",
        "e]^c}",
        "LoadLibraryFromDir - alternate path: \"%s\" 0x%x",
        "J:2L0",
        "u<hxW!",
        "Ip]79",
        "+3\".^ad",
        "7$kNh",
        "0(0Dw0#6",
        "vOB9`",
        "<><g<",
        "Zw\"FWV",
        "{::,ce",
        "u-jAXj",
        "L$$_^3",
        "?2?Y?",
        "D$ _^]f",
        "SOFTWARE\\KasperskyLab\\Binaries\\KAVSDK8.9.2",
        "jA?I[",
        "w>-v!",
        "4.454L4b4",
        "h[cLla",
        "mkzF$Y",
        "S Fi(",
        "[GK] ",
        ".F~NF",
        "w$}_%",
        "h,2a@",
        "C'5e#",
        ",s59@9",
        "D$0PU",
        "V/MHb",
        "\\~I4%",
        "#}]'Y|",
        ">7>S>o>",
        "|8w|m",
        "qe\\c[",
        "e?;-z",
        "kPFYV",
        "97:g:q:",
        "6&7e7",
        "api-ms-win-crt-heap-l1-1-0.dll",
        "Q)MJt",
        "RVq.'",
        "X J$V",
        "~6UVj",
        "FdUK=",
        "@05Efj",
        "Zbcd8#8e",
        "\\Dk-OXM",
        "no ciphers passed",
        "symname(",
        "WhWj+",
        "7j{ji",
        "Lapi-ms-win-core-datetime-l1-1-1",
        "iUoi=",
        "CW]*q",
        "GetProcessId",
        "VKzsKK4",
        "K]XK~",
        "lt<I'#",
        "l@TP{&",
        "9Ec*JDC",
        "D\"\"fD\"\"fT**~T**~;",
        "Q|uqY",
        "jLiZq",
        "Microsoft Visual C++ Runtime Library",
        "nh=Bv",
        "AXNCr9j",
        "b75+E*g%",
        "YL|IX",
        "t$dW3",
        "HHRK{",
        "IY[(}",
        "K59Bh&-",
        "dKb'a7S",
        "LdHHT.Q",
        "dbAd%B",
        "c;}cT",
        "W S;}o",
        "/cmD1",
        "{{{{x",
        "7EBp1",
        "F<k_5",
        "6y5/B0_",
        "i p{a",
        "9>BcR5",
        "(uY;?",
        "7\"^nnH",
        " -C8t0q$",
        "`#9)]",
        "ORg[k*7",
        "<(=d=",
        "Kww_____",
        "v<Q<a6",
        "PXTMu",
        "&N3)s",
        "%(=x)",
        "$Qf'*",
        "{5'n^",
        "yGtBO~",
        "!{&Ib",
        "H<zwu",
        "dN<bw",
        "zLgq1a2Q",
        "=2'fi",
        ".RUw9",
        "['C#A",
        "ql B'3",
        ".11VF",
        "yB'~-",
        ".92Zx\\",
        "AYLW@Q",
        "?*T?mSL",
        "Vhd1&",
        "qC;6F",
        "failed to get property from WixCloseApplication table",
        "HlBm-",
        "kb4D;",
        "=,=@=O=",
        "R93#p",
        "7q1yk/\"3",
        "\"K+]f%",
        "Wr,.@",
        "6X6#4%>",
        "_CPmbq",
        "/03070;0?0C0G0K0O0S0W0[0_0c0g0k0o0s0w0{0",
        " 0x97",
        "[W:Y>&",
        ".?AV_AsyncTaskCollection@details@Concurrency@@",
        "/OC[/",
        "//p_U",
        "D$,V+",
        ",e'JIU",
        "SSt9u",
        "p&h`K`",
        "lLH1s[",
        "F d.}",
        "Vm1;oV",
        "LOGON_TO_VSMON_FAILURE",
        ")x%!J`",
        "q^{DT",
        "U@tAu",
        "NAOHTS",
        "q*z)^",
        "S=^uk$",
        "+'D_/ix",
        "x\"oI\"",
        "D$ jPPh",
        "4k4p4x4o5",
        "Nc#[W",
        "2F0mP",
        "aD)>3",
        "j/0`rk",
        "s6*PBV",
        "NUMERICSTRING",
        "Fr|#84",
        "I\\TVY",
        "981G'dc",
        "T+:{f",
        "D$01F",
        "Invalid argument",
        "4#4T4",
        "\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp2\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp29\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp19\\itap1\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp2\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp2\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp19\\itap1\\li0\\ri0\\sb0",
        "XY,S^",
        "qEa&b",
        "+8V]S",
        "%4tw)",
        "?@b(\\=",
        "L$)b5",
        "w7Z{S9b?",
        "-K|[ ",
        "hEu-2",
        "W\\(*+",
        "8@9B%Y,",
        "@QFQKQRQ",
        "Tc%W.",
        "=FGI6z'",
        "@4G4P4Y4",
        "\\+y^8",
        ")^cN]s",
        ":,:B:{:",
        "|/nK,",
        "\"pro\\,",
        " %`uU#S",
        "^50pX",
        "t=0^6",
        " 0xf0",
        "(BA#q",
        "txMhv",
        "=#=4=<=B=M=]=l=",
        " ~<9g`",
        "KF@51",
        "\\n!#<",
        "3T$D3T$L3T$ ",
        "1?1_1u1",
        "E#ARH.",
        "a\\CheckPoint\\Endpoint Connect\\",
        "reboot_file.log is still pending for deletion poping up a message to the user.",
        "[J(KB",
        "0;I;9{",
        "|HC}I",
        "OY(v_",
        "ec_GFp_simple_group_set_curve",
        "=sJMl&G]",
        "identified-organization",
        "3%313B3_3d3",
        "\\)KEJ~",
        "9l8j_3",
        ",./2hf1",
        "NK%lz",
        "<?=N=q=",
        "=(=,=0=H=L=P=T=X=l=p=",
        "R0i3H",
        "T/:GLG",
        "]7<wC)",
        "aWWKo",
        "SCRemovePrepare started.",
        "8d7pt",
        "pG?&Y",
        "x509_crl",
        "310107120000Z0r1",
        "~f4XS",
        "._Qy-",
        "[pH(Ys",
        ")I$Ib",
        "%5lu file=%s, line=%d, ",
        "1>W0+",
        "E?g|g",
        "[e\"Ed",
        "default_algorithms",
        "{^\\I+",
        "0@g,`",
        "#L>AM7",
        "1Jy/Q",
        "~1PVW",
        "364C4",
        "\\,Vwmy",
        ")EFgKI",
        " ^|<7",
        "+fpM$w",
        "4n9;Y",
        "=g>z>'?:?",
        "2uOWkx",
        "QXZA#N1I!",
        "8&f>M",
        "TXOGj",
        "@X]Z9",
        "!_/$2jR[",
        "e!ix7",
        "3JP+h8",
        "$DrYD",
        "6VwJ?>",
        "QoB=(",
        "QO?w!",
        "()mrRz",
        "Z5:p:V",
        "cehP(",
        "Z:TmO3iK",
        "dn>33",
        "S/o?>",
        "a]o$GL>uK",
        "686=6F6b6",
        "=(iHR",
        "OgjVu~",
        "}^1pE",
        "l20N6",
        "k/xvC",
        "sd`h-`",
        "yFS0&",
        ",I,I-",
        "141_1",
        "B/s*C",
        "&<X!2",
        "(c5dF",
        ".30aA7",
        "S7o|gL",
        "9j9-9.9F9G9c9f9h9j",
        "%N%!u",
        "CMOVNO",
        "(M/#Mw",
        "S{=>im",
        "+{9]1",
        "Em(K@~",
        "qj_W\\",
        "AYi _$",
        "W.#d9",
        "gECbn",
        "KPaf',?",
        "*u{qr",
        "Zu/v<",
        "jAjoj#",
        "GetIfTable",
        "8 8[8",
        "RN6EO'",
        "RO(o[%",
        " JL%(",
        "z;$@F",
        "vl$e9",
        "CCYs2",
        "^j,E,",
        ".?AVcodecvt_base@std@@",
        "Ir{yyZ",
        "jbktgj",
        "_nextafter",
        "reasons",
        "Ii8G,",
        "ELN.Xz`",
        "L}FF8",
        "4b0Ei",
        "}F/Jr",
        "-1Fx2",
        "o{\"/'O",
        "e{|X'",
        ";P@|;",
        "_d<-i",
        ":M:T;q;",
        "[r'i?",
        "Va;Vt",
        "V]2sx",
        "c:tWr",
        "READ_N",
        ">(;X}pvA",
        "ilY#3",
        "|g2]d",
        "o{vjn!",
        "HR6~!A",
        "t#=B'",
        "050Q0m0",
        "{\\f40\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times;}{\\flomajor\\f31500\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}",
        "OpenFileMappingA",
        "8KWym0?",
        "JOn<#",
        "argument not found",
        "SXR,fQ",
        "_GoRd0",
        "9%QVE",
        "&%Otl",
        "V9Y5m",
        "t7#wf",
        "C.}Y3",
        ": :,:L:T:`:",
        "br+#b",
        "k@ykT",
        "[LICENSING] LteCheckRun: NOTICE corrupt key expired",
        "r|cAy{",
        "VH%LacM",
        "J0X0\\0`0d0h0l0p0t0x0",
        "PkS>&",
        ".?AVbad_array_new_length@std@@",
        "~CrG%",
        "m=r+w",
        ":bB>w",
        "8&9S9",
        ".RpHm",
        "WH(}clZ",
        "8+GWg",
        "9#:A:Y:",
        "!PDv`",
        "S&}^$TwJ",
        "gzdnI8",
        "9Z}02",
        ")Ik9K",
        "L$hVW",
        "Q]Y=h~c",
        ":]$:[",
        "; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\\;`;d;h;l;p;t;x;|;",
        "m%Huzml",
        "Q`bb{b",
        "KKSK[KMN",
        "OiEO<",
        "S|,wT",
        "~{z1o",
        "[oNY\\",
        "V+**'Jg",
        "9 9,9L9X9",
        "ez-v}",
        "=)Gsk",
        "GlobalDeleteAtom",
        "tw[0*]",
        "5na9Ym!",
        "d*l\"w_",
        "PSUBUSB",
        "0!0:0I0f0",
        "/qdG/",
        "%ZgeJ",
        "iiS!c",
        "2,2E2^2w2",
        ".9Au6",
        "Authority Information Access",
        "M>'Ld",
        "X.509 part of OpenSSL 1.0.2h  3 May 2016",
        "ADDSC",
        "8!818A8S8",
        "q~pNc",
        "2\"2>2Z2v2",
        "ZeLqyp",
        "G<`pA",
        ":5ofUYBK",
        "Q~L*j",
        "e,RdV",
        "MinghuaQuw",
        "A!|{=",
        "TS_ACCURACY_set_micros",
        "EPAM_Uninstall started.",
        "Bf98u",
        "8$8,84888<8D8X8`8t8|8",
        "PhH0 ",
        "@!c00",
        "q$)M:&:`#a",
        "iT10L",
        "aes-256-ofb",
        "E))1Q",
        "cU1']C",
        "`%WJ7",
        "#&* ,",
        "m.JK*",
        "$p^2j",
        "d/>`<z",
        "{&jWL",
        "_{g{g",
        "y\"3PPL(",
        "ConfigureClient:  Installed new integrity.pem file.",
        "PkH%\"9y",
        "X,=Ex",
        "t0ijP",
        "T\"PDf",
        "oF*TT",
        "x&JNBM",
        "/ID63(",
        "-9~TG",
        "6[$|V",
        "ci%u%%",
        "MZ^ST",
        "ec_GFp_nistp224_points_mul",
        "+wR*M=",
        "> >2>D>V>",
        "RDn-o",
        "343<3L3T3\\3x3",
        "mN3?=i",
        "\"(&ej",
        "VOmZh",
        "_(!xJg",
        "t=SOG",
        "j/I[`",
        "yh--9",
        "<I=\\=",
        "szw9y",
        "UQ~iG",
        ")l$$+",
        "XSJnm",
        "6(6,6064686<6@6D6I6M6`6e6i6|6",
        "MRzzW",
        "2)nR!",
        "copy userc.c to safe dir",
        ".\\crypto\\asn1\\a_utctm.c",
        "ps#de",
        "6*\\?9&",
        "k3P{a",
        "r0Z_R",
        "\\:>M=",
        "2@4D4H4L4",
        "^1Iw,",
        "=&=:=M=",
        "iG;?n",
        "![CDATA[",
        "3m/ku",
        "xMN|6R",
        ";6N MBv/",
        ".l#Kf\"",
        "GetFileVersionInfoW",
        "CiRTr5w",
        "\"u6\\@",
        "I&1mk",
        "(Nc(x[",
        "+1>=409",
        "1$1F1X1q1",
        "Ji]*&",
        "]/+5U",
        "?4@9-GS",
        "ZxA-Ns",
        "'C||my",
        "USXlB",
        "m%XmJ",
        "F4_^[",
        "%u, pHdrDOS=0x%p, pHdrNT=0x%p, pImCert=0x%p, dwE1=0x%08x, dwS2=0x%08x, dwE2=0x%08x, dwS3=0x%08x, dwE3=0x%08x",
        "VYso'",
        "7fNx)",
        "W0m;k",
        "ci`&2",
        "Helper::stopEFRService",
        "G^T9U",
        "L5RpVY4",
        "dnh@N`",
        "$t-JapT",
        "%o;1$Av",
        "TT1W\\",
        ":z8cn",
        "1W2r2",
        "retrieved SDL_ENABLED property: %s",
        "tvvectoredcode",
        "arOVQTu>0-",
        "SwitchToThread",
        "vsdatant.sys is newer than vsdata.dll.",
        "&k)Q53k",
        "6Ma3&|",
        "FeatureVPN _FirstPrepare",
        "&ApHi",
        "eCt {,",
        "z0&GU",
        "r;.\\S",
        "7{}4Fw",
        "(sHxG",
        "x;**8MCD",
        "S\\NFn",
        "?sF9#",
        "P@VtG",
        "@Ci*PO`",
        ".0%1o1",
        "id-mod-cmp2000",
        "<H(h\"",
        " 0xc8",
        "r@i[$_",
        "/Ka^X",
        "`GZ$O",
        "t^,&Vm",
        "~+bsa",
        "Qz4#n",
        "a|why",
        "/pOA0#",
        ">mA)c4&",
        ")n^)'",
        "Te>j\\",
        "SRSRSR",
        "lz$N-",
        "Mu7uGuHuI",
        "ji\\is",
        "S<x5p(",
        "080D0L0d0l0x0",
        "k2H*M",
        "Failed to terminate process, error: %d",
        "CryptAcquireContextW",
        "engine_id",
        "CRolloverFile::Read:  invalid file handle",
        "uDO$&",
        ".IG4Hh^",
        "3T$@3T$,3T$ ",
        "ms]h7g",
        "/fwd-|y",
        ")}*%l",
        "=!=,=<=G=W=b=r=}=",
        "_~8O>}",
        "Version already exists",
        "6+7A7W7`7k7s7",
        "U9# Jr",
        "UKz!6",
        "K;4-/",
        "&2+t`s",
        "LIBKeTN",
        ",H$o7",
        "+Vq/E",
        "nZ2jhd",
        "WatchdogAPI.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "3[4m4",
        "GetCustomerNumberEx() set buffer = %s",
        "8&8:8N8W8",
        "r\\t z",
        "7$8A8",
        "w5wuw",
        "O=7nWGA",
        "@.Q _nw",
        "==IT&",
        ".\\crypto\\dsa\\dsa_asn1.c",
        "))HP'",
        "\\'8s6",
        "hph@V?",
        "lv(H-",
        "@8?z:/",
        "N5w?l",
        "9o>'[J",
        "B92vc",
        "Invalidity Date",
        "enc_data",
        "D$8h,",
        "EN;o:,s_F",
        "?X=~j",
        "Gr!lqI",
        "OO/!eX",
        "v}VZA",
        "s{;Y?",
        "\"MW-k",
        "D\"/c-UJ",
        "setct-CapTokenTBEX",
        "StopRemediationService started",
        "A($P+d",
        ";X}#x",
        "=.=B=V=i=s=",
        "Hl\\5nR",
        "id-GostR3411-94-with-GostR3410-2001",
        "F&.2KlXK",
        ".^.P5",
        "1iU2#",
        "ec_pre_comp",
        "Ocy\\$o",
        "\\ltrch\\fcs0 \\fi-360\\li1440\\lin1440 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'02.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        ".rH|i",
        "id-GostR3410-2001DH",
        "X509_STORE_CTX_purpose_inherit",
        "pojp\\]2@",
        "3WcA%",
        "y8v;Cvx",
        "bV5M]",
        "FILE pointer",
        "'1in6",
        "VVHW-",
        "c?z>'9M",
        "_p0qu",
        "rSiY3",
        "\"6J[@",
        "4)~'\"",
        "WMU@|",
        ",-Sw~fh",
        "LqaHi",
        "<Uk-H",
        "Yheu_",
        "noticeNumbers",
        "*(e 2",
        "(3hIq",
        "IVI^qz",
        "c@DAhXY",
        "V.jXP|",
        "= =A=K=}=",
        "%&^j*",
        "ECDH-RSA-AES256-SHA",
        "</rules>",
        "0h|QT",
        "nB^=a",
        "m`= M",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1377203 P}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 arty }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1377203 V}{",
        "DWD=kKx",
        "LkMyd{>",
        "(,i~=(",
        "(u]sIZ",
        "PhGyu",
        "'|E{g@K\\s/",
        "^0`A\"",
        "list<T> too long",
        ":8:P:h:",
        "\\k{XR",
        "nj.0A",
        "91999?9M9Y9h9m9",
        ">7?D?s?",
        "k\\p,c",
        "7/7K7g7",
        "Gk_,;",
        "BEOS_UNLOAD",
        "!F'C{",
        "]kjV5",
        "setct-AuthRevResTBEB",
        "*+@$ro",
        "5:6b6",
        "nT]^'u",
        "XO9^k9",
        "0a061H1",
        "9$:*:",
        "cD?tZ",
        "%-=SWW",
        "MergeCommonBackup iterating via common backup folder failed, error: %i",
        "DLFCN_UNLOAD",
        "NFLOW",
        " Delay=",
        "+pK`c",
        "Maximum file size exceeded",
        "{s*kk",
        "g v9 N",
        "9~0u$j",
        "b`6dD",
        "TC~t$u",
        "vSCd0n",
        "+#.fqm+$i",
        "pnXC<",
        "J:ggY",
        ";\\<`<d<h<l<p<t<x<",
        "invalid pss parameters",
        "ei^Ya",
        "No such device",
        "8 8$8(8,808 <<<@<X<t<x<",
        "5<[A#",
        "Opj7*Z",
        "9|,#6u",
        "?/DY3{",
        "X)SNOB",
        "<m]]B",
        "1EXv2",
        "xR<R<T",
        "ExE(;2D",
        "j][f;",
        "RC4(56)",
        "(2=m**",
        "o~;$f",
        "FaWV,",
        "Z,A*b",
        "pp),%",
        "&3Z9_",
        "ChangeCharacteristics9to1 started",
        "w&~rR",
        "7nY7m",
        "S8tjM",
        "%4I64dG",
        "K;f5$",
        "FeatureAntiVirus:  FreshAfter started.",
        "int_field7",
        "D3N39",
        "jCxVO.",
        ",8d''",
        "i8Oo@",
        "< clN",
        "4D7o(flo",
        "W1C0W9",
        "MsiDirectory: %s(%s)=%s",
        "I>&8K6",
        "]cE>X",
        "ChangeServiceConfig2(SERVICE_CONFIG_FAILURE_ACTIONS) failed: %d",
        "+-&nx",
        "~@nZ)",
        "RSA_PUB_DECODE",
        "Kx^sp",
        "9U9U9",
        "m\"q?R",
        "!:tnXI",
        "iv%p>",
        "t!=LVA",
        " ZY<c",
        "9=9W9",
        "libutil::CalculateHashString",
        "\"AJeq",
        "CreateFileW",
        "Dgbi!5",
        "`0<F5",
        "LLLLX",
        "yoJ{7",
        "AJNz5x",
        "\\t]o|",
        "DYp%Cd4",
        "0$010:0V0",
        "x`_.c",
        ")GNe(C",
        "+'j>xXf",
        "set-policy-root",
        "[%s] CreateZipFile: Error %d writing zip %s - zipOpenNewFileInZip %s",
        "@os8Q",
        "PsApi.dll",
        "PBGn\"U",
        "mq6&O*",
        "N > in<",
        "Kw@!V",
        "Process32First",
        "L64HZ",
        "dvFl%",
        "hzDyF",
        ":@=H=L=P=T=X=\\=`=d=h=l=x=|=",
        "0h0m0",
        ":);/;5;;;A;G;M;S;Y;_;e;k;q;w;};",
        "=8=@=L=l=t=",
        "xS!Db",
        "m>lsA",
        "=tlf%",
        "i~so@",
        "<QgrV",
        ".BRXL",
        "Crypt32.dll",
        "WZgFW",
        "~h~*}X",
        "> ?0?",
        "Removing consumer product from %s using INSTALL.LOG",
        "gyE{C",
        "ZI;P,",
        "=7>?3",
        "! Fcy",
        "gHX\",",
        ";JL'aj",
        "CVTTPD2DQ",
        "9?d=E",
        "_.)V#",
        "Z+'lI",
        "WWw>Dor",
        "X509_INFO_new",
        ":I>nXF",
        "YYht\\",
        "9 9@9L9l9x9",
        "yaXYkM",
        "i^>0 ",
        "new build number newer then current file",
        "BLfUi^",
        "hqcDf",
        "<2fT[J",
        "i2\\AW",
        "CP-aE",
        "PFRSQIT1",
        "Xaq(\"jC",
        "F0K2{2",
        "z9Q=e",
        "nCtI#",
        "YDV\"21",
        "WcMnF",
        "g/ g:",
        "f>F$A",
        ".27\\G",
        "I&{lEAX",
        "7.n@n",
        "-'Z&eL",
        "txP9J",
        "7cu.{",
        "AO?gl\"c",
        "!l\\ZM",
        "6SuX~",
        "Jd8Jd",
        "3D$03",
        "LwM-a",
        ";E;y;",
        "}:' $",
        "FAIL: Can't open profiles path",
        "@FEJJ",
        "Content-Transfer-Encoding: base64%s",
        "><>D>L>T>\\>d>l>x>",
        "]E6PU",
        "O,;EL",
        "%s:%d: rec->data != rec->input",
        "BUF_strndup",
        "'p6a-",
        "090p0~0",
        "_][^Y",
        "oe*HO>",
        "R9yUB.C",
        "}0'C@",
        "ZVZ ;",
        "DX^[w",
        "{rB7V",
        "~$4.8",
        "BA0EHN",
        "8=zVUi*N[",
        "0R1e1",
        "6$6*60666<6B6H6N6T6Z6`6f6l6r6x6~6",
        "203H3y4=5",
        ":::V:r:",
        ".mMyCF<",
        "}ed/r",
        ",I$$%",
        "(#yg]bA",
        ".%.-[N",
        "D2I_X509",
        "vnysU",
        "I;{E4",
        "PKCS12_key_gen_asc",
        "3v*S1",
        "%1SyZ`h",
        "EPAM_App.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "UninstallCreatedItems:  Removing registry key HKLM\\Software\\Zone Labs\\ZoneAlarm",
        "BIO lib",
        "%:::?:",
        "F$F,F4F<FDFLGT",
        "j:jxj",
        "PiRegiter [/?][/d][/o] <DLL Full path>",
        "}JJ.,",
        "x4~y&",
        "qQkQq",
        "9$9,9H9\\9l9t9|9",
        "%s: %s,",
        "h^)!A",
        "Xw&P]4d",
        ")`xIj(",
        "7FasQ",
        "({`5q",
        "8KwWp",
        "%Zr`1",
        "r}k!5A",
        "H4e7,N!B",
        "n/q* ",
        "W[kwO>r",
        "e;T'<",
        "Azp7mf",
        "1.1g1",
        "+$j!u+R",
        "4;a7>",
        " _F(zRb",
        "aZ-\"o",
        "_fj):",
        "1jXtt",
        "gV;,;",
        "x~n6X7",
        "ojpE;r",
        "h~ln[",
        "g.aBy",
        "INSTALLED_MODE",
        "(E,Cb",
        "F)@l;",
        "V^mth",
        "/HLTRJ",
        "y!>d]",
        "kJgaFZ",
        "4o8}8>",
        "+Ll/\\",
        "242C2r2",
        "YZ2nU",
        "~&?U9",
        "tmXM1",
        "E0el+",
        "u7kK<",
        "pZg>4",
        "{_7&r",
        ":U~u +",
        "CMS_OtherRevocationInfoFormat",
        "r6f;u",
        ":]<lLs",
        ";\\PIj",
        "z/v\\\"K",
        "MYNIy",
        "$=e>S",
        ";t$4r",
        "l.lUh@",
        "!W'5H",
        "CreateInstallMutex:  Created an install mutex.",
        "2I:E(",
        "#>ml1",
        "D$HPj",
        "ZL1d`",
        "CpzKP",
        "K#CMQg",
        "StM\"Y$",
        "UCLqTC",
        "PO_]Q",
        "streamed out InstHelper.exe to tempfile.",
        "\\zlunwise.exe",
        "(Tm^<",
        "CANT_READ_PATH",
        "mjCP1G",
        "+78!\\pn",
        "h]^Du-vp2",
        "XQFIm",
        "px^XKx",
        "y1Phx.",
        "?)A[}",
        "`Logr",
        "&WPicWp",
        "???i?{?",
        "%s PRIVATE KEY",
        "'$RQJ",
        ";C1'>",
        "4Kfr\\)X",
        "2o5u5}5",
        "TM{W}Y8",
        "Y?'>DCj",
        ")eg56",
        "U>MUL+F",
        "<$zwj8",
        "(_^][3",
        "6J6q6",
        "^$Jp|",
        "scG|G`o",
        "s8U0w",
        "!rObj",
        "ZXTfh",
        "m61Li^i",
        "UPGRADINGPRODUCTCODE",
        "c&R=F",
        "Eo_'E",
        "Hr&~Q$*",
        "Ea/Eu",
        "Datacenter",
        "dBoM_",
        "yk{+ubTi",
        "Cd 1j",
        "&>sShb",
        "/q\"ms",
        "\\$%#,",
        "#|L}o.o",
        "<\"&Fm",
        "0f6RZ",
        "Mailbox UIDVALIDITY has changed",
        "UQvn;",
        ";B;L;R;",
        "X_?/Lw=y",
        "LZJ@v@Ha",
        "cant pack structure",
        "=F^v~",
        "C(|@VOq",
        " (unknown response type)",
        ".yU?? @n+",
        ",`zlg",
        "=]l2hyy",
        "d},jd",
        "iJ3-=1",
        "8cW$\\",
        "1cM\\X",
        "0yUbw",
        "6!7&7-7F7a7k7y7",
        "?n$:&5",
        "Bb;mMD&",
        ",IE,oS",
        "[Ml78",
        "Sf^sE5",
        "s\"w`kb",
        "8\"tDB",
        "WixQueryOsDriverInfo failed to initialize",
        "<$<,<4<D<L<T<`<",
        "=S^v'",
        "EWFUq",
        "9#\\zH",
        "#[qv`1)",
        "_!ITz",
        "r\",g3k%;",
        "y@M}i",
        "(LInkHO",
        "0Z u#-",
        "5@'4-*",
        ">A>I>X>",
        "ed in, under the control of, or a national or resident of {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Cuba{\\*\\xmlclose}, {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}North Korea{\\*\\xmlclose}, {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Iran",
        "00d0c9ea79f9bace118c8200aa004ba90b0200000003000000e0c9ea79f9bace118c8200aa004ba90b6c00000068007400740070003a002f002f007700770077002e0063006800650063006b0070006f0069006e0074002e0063006f006d002f00730065007200760069006300650073002f0063006f006e00740061006300",
        "xa(\"Q3ACgM",
        "Yb~Rq",
        "rHSPV",
        "R|!TO",
        "\",(QJ",
        "EZ\\j( #",
        "bDVU|D\\",
        "OCSP_parse_url",
        "3T=R*",
        "\\G#|n",
        "i3OWH",
        "-oyD*N",
        "4 5C5H5d5i5",
        "_CxxThrowException",
        "5'p#=",
        "LuUNn",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{6580C5A3-2336-4EC5-85F1-3448C5F6208A}",
        "Rf%;m",
        "~N*xd",
        ",FFeq",
        "The de-registration of zlscv.dll was successful.",
        "i_kEl4",
        "?thlp",
        "[~ %X",
        "{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'04.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li3600\\jclisttab\\tx3600\\lin3600 }",
        ";5;u;'<:<T<[<d<}<",
        "1,101@1D1T1X1h1l1|1",
        "; ;,;0;4;8;<;@;D;H;L;P;T;X;\\;`;d;h;l;p;t;x;|;",
        "bb@/\\",
        "7 7$7,7D7T7X7h7l7p7t7|7",
        "AZH6V|",
        "t%f98t P",
        "eRz5P",
        "8 989T9l9",
        ";&;?;X;q;",
        "ctx->buf_len <= (int)sizeof(ctx->buf)",
        "des-ecb",
        "Em\"~=YU",
        "t$VVh",
        " )XHQ",
        "9O:U:Z:u:",
        "h+'p[~8{",
        "|G9|y^nC",
        "#0DU;p",
        "EB<evQ:",
        "OiB^Q",
        "3@4d4*5v5",
        "6(6>6k6",
        "C$Bo*",
        "+>3Oi",
        "?<'UT}",
        "crlNum",
        "FWFreshAfter.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "Ii>8;:",
        "3V3i3}3",
        "~q(t)",
        "[`tF7M ",
        "lvUI4",
        "/7>,?",
        "?Zfj@",
        "I>-5-",
        "[+?zN",
        "Q#QPg}",
        "cU3LV6",
        "R[eKU",
        "W-!~U9",
        "4Mu*dI",
        "T$D3T$4",
        ",Q|b|",
        "<assembly xmlns=\"urn:schemas-microsoft-com:asm.v1\" manifestVersion=\"1.0\">",
        "1$181",
        "7r.Sc:",
        "t*WVh",
        "DH-RSA-AES256-GCM-SHA384",
        "$yEEa",
        "oRLb4",
        "#TwF\"",
        ",l}]3A",
        "$HxY+i@?",
        "utuHWd",
        "55Pn1F",
        "}bfT2",
        "JBXmf",
        "4T4Y4l4",
        "$)9cS",
        "5QR8kP",
        "1stw|u:",
        "tkeF!",
        "{BCBc[",
        "2C;}l+u",
        "|YDQ3",
        "nNK/M",
        "ou to provide policy management for Your own operations.  To the extent applicable, You may reproduce the downloaded or installed}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\delrsid16059775\\charrsid15169477  }{",
        "[ADAPTER] NdisQueryWirelessConfig: Failed on CreateFile with LastError %d Adapter Desc:%s",
        "s,pk[",
        "tTLf;",
        "R2Y\"qX",
        "VR&'0+",
        "\\0nn1",
        "xDEr.",
        "SYSTEM321",
        "!`aA>",
        ">3>O>k>",
        "MsiStringToClientType",
        "9E$WWV",
        "M~bh9\\#",
        "#o&t^",
        "mS$9Lc!",
        "v# rh",
        "eMuo5E",
        "BEOS_LOAD",
        "2#;SP/",
        "8X9\\9`9d9l9|9",
        "9/9K9g9",
        "KHqr=",
        "SCUIAPIEndpointBannerBig.png",
        "MkKr7q|Z|",
        "(;se+u",
        "=n08j",
        "Tl;{>o",
        "fb6d2dd99bb07b55e5ccf68942bd0877b23c77b908e8db5f9db7f024d9239010f35bd4bbe2fcae387bfff9e2bc289f2fbe24cfaa301468dd8bd846dbb4ddf1c2",
        "%^Gk ",
        "Tmu]{",
        "E@D3\\R",
        "<8bunz8",
        "dF\"Wv",
        "OCTET STRING",
        "4'iY:",
        "637v7",
        "QUo:B",
        ",<S#$",
        "9 9$9(9,9094989<9@9D9H9L9P9",
        "clqP*",
        "Nx}O4p",
        "Qdd<5",
        "O9okn",
        "a/[OOH\\",
        "!}cl ",
        "-mEqs",
        "v2U7TW",
        "gz|$B",
        "h=|e*",
        "t$,h8",
        "8$:@:",
        ">/>;>I>",
        ":52$,",
        "9%2=4J",
        "6lN[o",
        "|- bD",
        "@K?Z'",
        "MMBF0",
        ",v0)T",
        "4vpjT",
        "|6':6",
        "1&2>2",
        "545@5`5p5",
        "8 5,c",
        "OsPlatform",
        "oN?MM",
        "?$?,?4?<?D?L?X?x?",
        "NQ(]I",
        "8Z)P=",
        "GetCPInfo",
        "qNK{L",
        "Wa @g",
        "j`-j`",
        "h6<W\"9#\"",
        "|8gT_",
        ">>ws=6K_?0q\"<$",
        "ooN`e",
        "NOTICEREF",
        ".\\crypto\\conf\\conf_lib.c",
        "XJUis",
        "`27)#",
        "<$<3<V<h<",
        "KXWK(F",
        "{L4-Gw",
        ">@PWV",
        "MFO&O",
        "/J9E_",
        "%&krd",
        "CreateRemoteThreadEx",
        "`dG.|",
        "RCev>",
        "@[x Q",
        "%zl<Ar",
        "IC=Jr5*^L",
        "D$HPSU",
        "):,0*m",
        "wVfU~",
        "Of0oT",
        "t8Vj!^f90u&f",
        "v9rol",
        "2Uj0QO",
        "Fab,;$Pb",
        ";\";>;Z;v;",
        "@ibZK",
        "/'pJy",
        "U{0Im",
        "~a=i=q=y=",
        "zV<&C",
        "i<JC[",
        ")A_?h",
        "JujNIX",
        "OhWeX",
        "#)^LBEt",
        "lh!tS",
        "5M'U*",
        ";,<H<T<t<",
        "no lock available",
        "T&cO#",
        "Nyj6%",
        "5>6H6e6v6",
        "PWWWWWWh ",
        "5/JWVCc",
        "*l.M(",
        "3?4^4i4",
        "InitializeSecurityContext",
        "`$uTE",
        "skM\\}",
        "vyLHP",
        "=(=0=4=@=H=L=X=`=d=p=",
        "3*3/3Z3_3",
        "NPX${T",
        "ur9,~",
        "D$9+A",
        "A5(f%",
        "3 6C6",
        "4{5jt:",
        "t%3}Nq",
        "+ DPd",
        "u?uUOs",
        "2\"313A3W3]3e3",
        ">vt,a",
        "fQ8G65>",
        "=],>R",
        "V]20-",
        "m4%_:",
        ".^W#Q",
        "5h5r5",
        "[VSReadUninstallInfo] Can't open shared memory mapped file",
        "<G=b=",
        "zJ(21?.",
        "protectEPAM",
        "l$L3l$",
        "JLfX\"",
        ";H^#(W",
        "E=*29",
        "X7.A`",
        "#vF13",
        "~I%Qn",
        "3)YKz",
        "W?>NC.",
        "failed to write shortcut path to custom action data",
        "E)S@!0",
        "PKEY_DH_DERIVE",
        "HFB=,",
        "0E}mj",
        "9Ja~f(",
        ";d2By",
        "z>d.v",
        "nz#Nn",
        "t$8hD",
        "INVLPG",
        "&y7;(",
        "oeZ1K",
        "lFn`6",
        ".\\crypto\\dh\\dh_key.c",
        "2b<?[",
        "gG>t^",
        "ji[o:",
        "!lV{y",
        "SICbhq_B+$9",
        "H/rBQ ",
        "yu@u#Z{",
        "F!fMq",
        ".CRT$XPZ",
        ",oB+V",
        "gl\"eK",
        "-!Vh6",
        "]`6~i",
        "[VSLoadVSMonAPI] GetProcAddress failed",
        "n?xs.",
        "nJT\"+}",
        ".Ep$WU",
        "m_:GKfI",
        "5HIrb",
        "0[eV=",
        "6ME 0",
        " /G^\"NG",
        "y!6HMR",
        "WBN*P",
        "|E4Ge",
        " 6ON!",
        "p0/R6",
        "*c'Jz",
        "5#5)575G5a5",
        "iM#<^",
        "Eu#hQ",
        "; ;$;0;4;@;D;P;T;`;d;p;t;",
        "3^vc9",
        "=F=q=",
        "hL~`I*",
        "6uQx :",
        "GOST94-GOST89-GOST89",
        "P@8P@",
        "4$474j4y4~4",
        "P3Z$%",
        "'j*<TB0?5",
        "\"c%O/)",
        "sZ#c-uV{\"",
        "B8B99520-057B-408D-9D23-883A78495679",
        "Failed to create directories to target {}",
        "h2TJ=3",
        "2HH=Hzu",
        "525=5L5R5X5e5k5q5|5",
        "374a4",
        "1F1N1U1[1c1i1o1",
        ">)?u?",
        "_N-R2=Zlt",
        "H f+;a",
        "6A687U7m7",
        "L$p<3",
        "mom$l%m",
        "Check Point shall have the right, but not the obligation, to defend or settle, at its option, any action at law against You arising from a claim that You",
        "im622",
        "%|2*E",
        "f`f g`i i x",
        "mI]LF<",
        "k%$.QR?",
        "5KcC8",
        "EoFg;",
        "\\vsdb.dll",
        "Please URL encode %% as %%25, see RFC 6874.",
        "o|3Ma?",
        "~0\\K ",
        "Wednesday",
        "/M8bF0",
        "\\z?Ic7",
        "W@B__",
        "N6vD<",
        "\\oL3le",
        "h| U!j#",
        "g7I_Oo",
        "6,61696A6H6M6R6Z6`6u6",
        "UTyX5uu",
        "%isG*F",
        "exists|is_symlink: %s",
        "a+6g*S",
        "M[6{l",
        "l/K(ruo",
        "OpW_\"~g",
        "UNKNOWN_PRE_INSTALL",
        "acm%X",
        "j p'8",
        "2,2H2d2",
        "J`V3o",
        "8\"959",
        ":F:j:",
        "]m>gK",
        ")}|!\"",
        "'!)^j",
        "T$83l$",
        "ylk)@:Zu",
        "no private key assigned",
        "px}]rf",
        "303L3h3",
        "-LYzv",
        "~+7Y6",
        "9]`l=dP",
        "?9?5O",
        "@7>7m",
        "vk.U|",
        "6MU{?",
        "unknown option",
        ",ZM'\\",
        "E%bw4",
        "X0-XqL",
        "wSbNDX(",
        "Zf>c_",
        "OG<Wl^",
        ". Sleeping ",
        "EL.3o7",
        "Pkj.j",
        "]uOA\\",
        ".Nt.>",
        "0-{-sO<",
        "JUmz+[",
        "6,646D6L6T6\\6d6l6t6|6",
        "j:jlj",
        "no certificates returned",
        ";_cx-",
        "ww<(C",
        "u/l5b5",
        "G+tKo",
        "xu]8\\",
        "7Nq @",
        "*/)j3",
        "~2cBZD",
        "m}p40W",
        "YRDtR6:",
        "FG$sk",
        "9F;X;x;};",
        "3(303d3l3t3",
        "*_full.dmp.zip",
        ";}<n2KTd",
        "M .ph",
        "| 7G)",
        "TrGui.exe",
        "Ow4kkF",
        "W3dpDY",
        "#N#t\"vF",
        ";ED}x",
        "6^7mve",
        "eb8v:}U",
        "G6ngF",
        "Cniqrdm",
        "EncryptClientHeader",
        "VqY+:",
        "Uv&,-!",
        "failed to get timeout from WixCloseApplication table",
        ">vjF(",
        "l5BmI",
        "K?u4?>",
        "9qz%l\\",
        ";&/*8",
        "8u[F4mX",
        "    Produced At: ",
        "d0{iC]",
        "%RFeN",
        "9\\iz~",
        "Warning: QueryServiceStatusEx failed (%d)",
        "@pRdb",
        "t^2_7Ux*",
        "P-3+g",
        ": Xnh",
        "p-Ws}",
        "L<pkp&1",
        "a#*i}",
        "Z8\\.%",
        "ENTER",
        "retrieved SC_UIFRAMEWORK property: %s",
        "OZO<H",
        "5/Y=wO",
        "8,9b9",
        "F:!!N",
        "VMXOFF",
        "-k_F:",
        "%YU!7c",
        "TS_COMPUTE_IMPRINT",
        " cy=Z",
        ";QjJ3",
        "*.txt",
        "VicRl'",
        "8Ba!]",
        "#(sH/|",
        "W:ze21",
        "U =.e",
        "cipher code wrong length",
        "~T>l:",
        ":':<:N:d:",
        "aZtet",
        "ns~1S",
        "YjKo5a_",
        "rOPeFq",
        "\"u9fE",
        "RR&ylDE",
        "D$4U3",
        "5)5B5[5t5",
        "I5aJk",
        "xn:kw",
        "6C=.5/",
        "associatedName",
        "De@1G",
        "3bgcy",
        "ozAeDuZ",
        "0.0()",
        "wv5'u",
        "eI*7T",
        "Fq<b6",
        "W~9)3",
        "dbFK:",
        "setct-AuthRevReqTBE",
        "ei 6/",
        "a<[J.",
        "H6J L3F",
        "xAe?vh",
        "'lVECW",
        "mR4(;z",
        "@4:2,~",
        "invalid section",
        "<==F=",
        "2[4c4i4",
        "w# tRZ",
        "<plugins>",
        "<L=S=_=t=",
        "_rUJJv",
        "!D:muO",
        "<\\R`k",
        "$=%5:o",
        "Z*EB-E",
        "DIR_LOAD",
        "\\D<I*&",
        "CQz9zA",
        "j}kl4#",
        "]C|-5",
        "$f(Gm}w",
        "&)ee8#",
        "0%2<2",
        "#>hTs>",
        "2T$XU",
        "\\9w\"s",
        "L$<SU3",
        "2Ht\\l",
        "3vSKH",
        "+TplT",
        "1p2|2",
        "9(9,9094989<9@9Q:X:",
        "Kn?l$i`b\\",
        "~'3YF'0",
        "8|_|\"\"`\"",
        "jrjkj!",
        "b?2? ",
        "C]m[U",
        "7?8J8V8g8",
        "@`WlU^\\a:",
        "x``:[",
        "tMYxA",
        "]0`gq",
        "1,101<1L1",
        "6'6H6`6",
        " 0xd1",
        "0@1M1Y1",
        "[n!KT",
        "<~[Yp",
        "y}*g15",
        "JE&u{",
        "d-sLg",
        "P.c(X",
        "ChY'Mu9",
        "<CeJ[",
        " 0x3f",
        "_y!.P",
        "sqG!#",
        ":@\"Wa",
        "[S]fcE",
        "\"lw[W",
        "loadImsinstall;",
        "Qh ~&",
        "xVP87)",
        "u.ip%",
        "n55Yh",
        "d/ndn",
        "1$1,181X1h1",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 2.\\tab LICENSE AND RESTRICTIONS}{\\rtlch\\fcs1 \\ab\\af1 ",
        "!1MbH)",
        "A$gNv",
        "fY'|0l(m",
        "K,Af7",
        "7#7)737>7a709F9z9",
        "\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 4;\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 4;\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 4;",
        "idUG)J",
        "]3Ko?",
        "$ytcZ",
        "OpenSCManagerA",
        "3h:H6",
        "SING error",
        "TYLv+",
        ":!nQu",
        "^/uql",
        "uG6AC2&e_ ",
        "AlgorithmIdentifier",
        "\\l.=r",
        "fE$D-~",
        ";TfO=",
        "Insert file: MsiRecordSetStream",
        "mCKW0",
        "m&k81",
        "Added",
        "^0\\QK*u",
        "Z_M:V",
        "l\"Z+3gZ*EIa",
        "3Q3vb",
        "qAC</",
        ";8;@;H;P;X;d;",
        "ENGINE_load_public_key",
        "hW^QH",
        "CRolloverMgr::TruncateLog():  unable to acquire truncatation",
        "`zPtL",
        ";,;Fm",
        "^]OBB",
        "Sh g#",
        "*Rdi]",
        "0AI[{.a",
        "OS4WoF",
        "OpenSCManagerW",
        "MOVZXDW",
        "3<3D3P3p3|3",
        "1\\>\\K",
        "Global\\WixWaitForEventFail",
        ".S3''",
        "2H=<L(",
        "v1rue",
        "$N1s)",
        "d=w#FNL",
        "9R1^$|&",
        "WgyfgW",
        "Diffie-Hellman routines",
        "MM3c#",
        "<tvp6",
        "t}c';A",
        "(a!oZ",
        ";-=.}",
        "IncreaseFiltersMaxNum",
        "9XF6'",
        "/A#=D",
        "BMM?m",
        ";3;`;",
        "B!$j;T",
        "dw+-b!",
        "?c mz",
        "cB/:Xj",
        "D}j-)\\",
        "|M9x.?.",
        "failed to get security info for object: %ls",
        "B!2FP",
        "wphC^",
        "< <(<0<8<@<H<",
        "@]L?T",
        "L$$;A",
        "edr=f",
        "UG'LX8r",
        "R-M s",
        "fv<u@",
        "rkt-z",
        "939]9e9y9",
        "A!*iF",
        "NNFu>",
        "S9Cr9",
        "RsM:+",
        ";!;#;-;9;E;S;Y;_;q;{;",
        ">Z>z>",
        ")><zu",
        "`:SW`",
        "8#YWZ\"",
        "1R1T1\\udj",
        "-0dye2Ea",
        "s'v,J",
        "\"u3|!",
        "VPPW\"",
        "ou*&3y",
        " NYXvA",
        "xQLoE=!",
        "%2J3U_",
        "!t^R8O",
        "RollbackServiceConfig",
        "aUb0r",
        "JVSs2<",
        "5$5,545@5`5h5t5|5",
        "libutil::writeWholeFile",
        "tfph:",
        "77U)&",
        "8; @3",
        "V2*&u",
        ";g2k;x",
        ":;Cl(",
        "LoadSignedLibrary: %s not found, GetLastError() = %d",
        "4q[z/",
        "KV]9K",
        "Z%iOA",
        "nf4&E-_#",
        "\\I#x ",
        "y2mcG",
        "Pf>0W",
        "ve`ng",
        "%uwe4",
        "9Jrbk",
        "A-zYP*RS",
        "72=:\"",
        "VwsvU",
        "CONF_load",
        "IXH\"3+",
        "e|\\N2",
        "#L$ #",
        "bIJL'q",
        "A8EEK",
        "f8-f'D~a",
        "%7$W[Z",
        "^M*~[",
        "`N@}k",
        "iW_MDH",
        ".*%T\\",
        "GYydJP9",
        "#;w5tLR",
        "([jL?c",
        "t$PWP",
        "!4RL4",
        "*2yWDL",
        "sK=*v",
        "Ct3E\\",
        "gethostbyname addr is not af inet",
        "=DjH2p",
        "Dl,ie",
        "dxj_]k",
        "=1>f>",
        "(V,{#",
        "O:)-~",
        "DN@\"r",
        "I0Wn76s",
        "&tD\"4:",
        "CRgPZ",
        "9r}u]L",
        "GJveA",
        "6JXi4",
        "P)$tr",
        "NU53ft",
        "c09l/",
        "&KgJh_",
        "#E4/7",
        "kH_{I",
        ";z\\S0",
        "tJ_^]3",
        "8C9J9Q9[9d9",
        "PSGControlAPI.dll",
        "OnBegin started",
        "]P\\0N",
        "FZ+|%",
        "X;/$@",
        "8 919Q9Y9p9z9",
        "<`&#x",
        "UUckv",
        "0\"b] ",
        "}\"Vq*?",
        "ecdh_kdf_md",
        "'[xJe",
        "PMAXSB",
        "\\[=]Tr",
        "1J;7+6H,",
        "{2~J?5",
        "kR<['.%h",
        "60?0f0k0q0z0",
        "y{{th",
        "D$(3|$",
        "Cw91^l",
        "Trpsubs",
        ">'?O?",
        "q*)\"##",
        "w.p2$H",
        "uX60t",
        "JXmh ",
        "?ko[iS",
        "/-]54",
        "6/6=6F6Y6e6j6o6",
        "T}`}<}B}L>",
        "Unknown exception caught in InstHelper",
        "<(<J<d<",
        "DE<>k_-",
        "@bj_P",
        "LY.>7;",
        "T3\\=\"",
        "k%Qpy",
        "+gwm&",
        ",!W,MCe",
        "FqJ`M",
        "x_x<h'}",
        ":9:F:",
        "CHECK_POINT_VPN_CLIENT",
        "*Cvgs",
        " +ZH/",
        "/e7Ti",
        "O_s$w++",
        "|T3p&6P",
        "Q:Z{=[",
        "M{amV",
        " 5|Ii",
        "tihl+$",
        "^Z\\>@",
        "Q~:5r",
        "6oCr\"Y",
        ")0P=w",
        "THNQa",
        "\\t3:r",
        "(gU]'T",
        "d\"*OZ",
        "0 0(0@0P0T0d0h0l0p0t0x0",
        "/1Tae",
        "6y,,|F",
        "_=}aPK",
        "xBvwlG",
        ",QIud",
        "INI=m",
        "uEcc#",
        "Zyz(J",
        "gost2001cc",
        "u?xzu$",
        "}NECb%",
        "4X5k5",
        "}xb!8",
        "Vb:{?",
        "byh<d",
        "Mr~*h",
        " 0x38",
        "c1(Tn<",
        "_arM\\",
        "2ZuYKXO%",
        ";.;y;",
        "3$34383L3P3`3d3t3x3|3",
        "Cf:8/",
        "E=chf",
        "I%uJdx",
        "=[>b>n>x>",
        "6-7C7a7",
        "v?Dp*",
        "<P*Yn",
        "Zp$*%",
        "\"Q})|<",
        "cv>:+XS",
        "K{bub",
        "yDXto",
        "^'f\"/",
        "HP;HL",
        "j:Xf;",
        "J}DoZ",
        "X9_62_CURVE",
        "V>+wf?",
        "t*@GSR\"f",
        "6@7]7",
        "y/2;k",
        "dO;bNP",
        "#hcU)",
        " MRiV",
        "SEC_E_CANNOT_PACK",
        ":!:@:O:n:}:",
        "CihHY",
        "failed to process XmlConfig changes",
        "[3d:$",
        "[ShP!",
        "gostr3411-94",
        "llEH+",
        "3WVVx",
        "wXs'\\p0",
        "]G7n \"",
        "sequence or set needs config",
        "sd_install.bat",
        ">RqoNP",
        "=^W1g",
        "tag value too high",
        ">=$ZY",
        "dG,\"H",
        "8 8(808<8\\8d8l8t8|8",
        ";z8OKo",
        "GfJrp",
        "hApWO",
        "~d_!(g",
        "StopTRACService",
        "Failed to open/read local data from file/application",
        "N{)y8N&",
        "F:\\ckp\\src\\cpopenssl\\E86_20/preCMpub/ssl/cert.pem",
        "wJ5Yf6@",
        "v^FES",
        ":K:u:",
        "IR[cyq",
        "T#pqD",
        "=jCu~",
        "w>\"gw",
        "wf.fi",
        "m5+*`",
        "CMS_OtherCertificateFormat",
        "CheckForReboot:  Suppressing reboots.",
        "9):D:Y:",
        "0O0~0",
        "ha)B6",
        "5eelVP",
        ":.:::O:\\:",
        "OBJ_NAME_new_index",
        "fMfef",
        "D$0PhX[!",
        "E\\)X#8[ ",
        ".080b0r0",
        "R)g-J^",
        "\"#ORTb",
        "GEL1 Y",
        "]7H5Ow^W[?i6u",
        "/!-9q",
        "\\$TUVW",
        "`Kp{j",
        "3%4[5",
        "0T3,K",
        ".-tR%",
        "X]dO{f",
        "1C1J1Y1c1}1",
        "$qok6",
        "hma6f)",
        "pg}gX*",
        "P5-yBI",
        ".x&Wx",
        "f~-O9",
        ":);g;-<m<",
        "r\\>ua&A",
        "17FqP,J",
        "3|$<!",
        "<A<H<",
        ".:]Xw",
        "zWp9dyH",
        ",&fT%",
        "co3_7",
        ":Rw+3",
        "=$=0=8=\\=d=l=t=|=",
        "Xidpr",
        "WhL0 ",
        "8B9H9]9i9",
        "?5?C?]?",
        "K_E_.",
        "sg[0,",
        "2`RL<",
        "j]uUc",
        "5+rwI",
        "Check Point Endpoint Tray Application",
        "'o35u",
        "nK0N?/",
        "Ja=IB",
        "7^8$L",
        "\"_;t[",
        ".j&\"!Iq",
        "-,HS8",
        "x5aJa",
        "*Ds}*{",
        "e)' W",
        "]a|V.^",
        "jjjkj&",
        "e90#Mx",
        "failed SysAllocString for port",
        "CxhN\"",
        "FuDE&",
        "qIjXL",
        "9cPJ|",
        "k`>lr",
        "a-kvSR",
        ",q^vG{",
        "uninstallAV",
        "161^1",
        "T#~On8",
        "+_U~YIr",
        ",%_.O",
        ">.fSg",
        "Qto\"%",
        ",3#z(",
        "[!y/}",
        "34l~<B2",
        "[N}*^",
        "D$TQP",
        "VERSION.dll",
        "-*DG6",
        "Qf=ZI",
        "attributes[0].name failed",
        "A}82!z",
        ">3FF<A",
        "J\\}h2",
        "OCSP_CHECK_IDS",
        "7$747p7t7",
        "TaKyQ",
        "{Cc+x%6w",
        "J&>[@",
        "W9;)u",
        "ZarOx",
        "Wht:!",
        "Qbz$`",
        "/x\\=<l",
        "bn pubkey error",
        "z_[k[",
        "I|K\"Nw",
        "QjB&a",
        "P2]LZ",
        "3,E@m",
        ";8<j<",
        "T<]/6",
        "989{9",
        "7%U&p",
        "o,be[",
        ":Qh!s[6",
        "t%fM&t",
        "A required function in the library was not found",
        "[,&,|",
        "CMS_KEKIdentifier",
        "|y'um",
        "O5_F:",
        "ZA( u",
        "0H{A,",
        "NP4~Bh",
        "\\FX*M",
        "YZU':",
        "R66l$",
        "\"mqA1",
        "[LICENSING] NOTICE corrupt beta key %s attempting repair during update (modedate: %d).",
        "\\/H~X",
        "+X FIdt!",
        "Y^m$++Y",
        "g8}gT",
        "RT%!?6R",
        ">,?3?Y?_?j?",
        "HyU!;H",
        "jxjej'",
        "*/}I\"",
        "O;(I@",
        "Z}T|D}",
        "JY8jZ",
        "cIfHr",
        "|${MW",
        "=M=T=[=b=",
        "s~0kD",
        "+Bx*K",
        "JgwHO72!",
        "YZ\"#Bi",
        "D$,SP",
        "print",
        "7 7$7<7@7X7\\7`7d7x7|7",
        "2b!<Og",
        "!KT'W",
        "%\\O##",
        "aF)QU",
        "IJ .$V",
        "@]Z~B",
        "error setting encrypted data type",
        ":Q:g:s:",
        "+V`Ja",
        "\\:s,\\",
        "e3-IX:",
        "#+UON",
        "wt>x@",
        "$?Z^=",
        "*{E#n",
        "ynL:D%2 ",
        "80-()Y",
        "898U8q8",
        ";/;8;Y;n;",
        ".?AVgeneric_error_category@detail@system@boost@@",
        "missing ecdsa signing cert",
        "\\$@3L$@",
        "oYUO=e6{wt",
        "4?p<p ",
        "t|\"vn",
        "yH8W`",
        " 0x3a",
        "bn-in",
        "|DErv",
        "SMIME-CAPS",
        "{9c=.",
        "8L';0",
        "\\MPO]",
        "ip:aj\">A",
        "PQUu<P",
        ">F>M>X>k>r>",
        "(p(cR",
        "t;;3t",
        "%NK| $",
        ")Qc43R\\Z",
        "slsQL",
        "0<<4<",
        "=3=8=W=h=w=",
        "Asn1HeaderLength error: block length < 2",
        "3L$@3L$,1L$$",
        "ClKlSl",
        "{cf]I",
        "6z4X~",
        "{9l@tyy",
        "r:<ce",
        "h0f0?",
        "s$s&s0s:s<sFsHsTs^sjs",
        "(~\\ `",
        "P>9;2",
        "ugHV>",
        "@zg}#",
        "323R3r3",
        "{+r]Sw+",
        "flOb,",
        "-Uq%\\",
        "K94- ",
        "TVDB3",
        "LZ(l`",
        "Y{`ed#;",
        "&II#qM",
        "CPz1:87",
        "ojKLC",
        "<)<`<",
        "b!WRN",
        "5fv*lyX<",
        "1DLk2",
        "tj*aWw",
        ": y}:.",
        "{qSiCV",
        "failed to delete child node: %ls",
        "j0^f;",
        "M=$4f",
        ">L*wM",
        "y5Ckj",
        ".?AVFreeThreadProxy@details@Concurrency@@",
        "'M9q*AR^",
        ">$>(>@>P>`>d>t>",
        ":I#dU",
        "?W#>c",
        "nSTkx",
        "9!:B:R:g:",
        "7B7R7a7",
        ".?AVplaceholder@any@boost@@",
        "o4V&4",
        ";Z5Lt",
        "8*g7Q",
        "(k`O^",
        "lea@n",
        "m{nFx&>",
        "@0 #'",
        "IGN!G+",
        ",Zb:G",
        "<_-5 \"",
        "q{RfKB",
        "aCA[t",
        " \"%s\"",
        ".\\crypto\\pem\\pem_lib.c",
        "oSJO>",
        "0y1!6V A",
        "2(3,3034383<3@3D3H3L3P3T3X3\\3",
        "? RQ%",
        "SCHEDULEREBOOT",
        "tDHlOS",
        "{D,Ar",
        "AE0zH3",
        "Pz.^\"H",
        ",he})",
        "Mg{:1",
        "ql!@b",
        "^#mj1",
        "=gf/<",
        "$U;a:",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid4272055 {\\*\\xmlclose} }{\\rtlch\\fcs1 \\af1 ",
        "0*\"\\LXG[",
        "Y$7%'G-`",
        "?5VHl4q",
        "CallStackHash",
        "_[^]Y",
        "SBR`r@F)nI",
        "YhR9f",
        "v :e5",
        "F=ref",
        "cZgP4",
        "N@OGM",
        "&oBG ",
        "h+EKn",
        "ProductCode",
        "3q`.CK:/y\\",
        ".srNP",
        "|>B YC",
        "WHuHar",
        "[W-cuk",
        "jejtj",
        "advapi32",
        "BZ1(c",
        "tBj?S",
        "Dealing with config files",
        ":D^Jq;q",
        "{l{!XQ",
        "RPWVS",
        "GEw8Lg",
        "=*>T>w>",
        "Accept-Encoding: %s",
        "8muXFkK",
        "2<2D2T2\\2d2l2t2|2",
        "u:9C@tB9G@t=",
        "@X0@E7q",
        "D$$PW",
        "7fYSQ",
        ":/:7:<:s:z:",
        "!Srda",
        "vW,(;x",
        "Em&ig",
        "YToQtD",
        "<\\=j=~=)>",
        "Firewall",
        "\\X~;}",
        "4svBz",
        "6r=_^",
        "ss=;}",
        "r4}WN",
        "03.*E",
        "c3q/`",
        "o}:1KW",
        "mHBs0a",
        "kuE/a",
        "4w^?~",
        "4*uMZ",
        ",10141@1",
        "jCjyj",
        "D$$_^",
        "212M2i2",
        "~6q#/",
        ";llUy",
        "#P$ng",
        "%QS]<o",
        "tAi!+",
        "f(i7/",
        "OX8q<",
        "brHX3",
        "c\\1;4Hx",
        " /F /S \"",
        "8qpp(",
        "Se*`8",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\f1\\fs20\\insrsid15807945 ",
        "is-is",
        "w69Fr",
        "o('Vd",
        "x`$k7",
        "[miBQH0dEM",
        "J%%oJ%%o\\..r\\..r8",
        "CompStartComplianceService started",
        "9,989X9d9",
        "directory_iterator::operator++",
        "!DE{a",
        "1<2j2",
        "Ey<c`_:$",
        "Fd-s,",
        "p sE'H2",
        " 0xb3",
        "RSA_padding_add_PKCS1_OAEP",
        "<6<R<n<",
        " 0x4d",
        "FS%_y",
        "dsviewer.exe",
        "50585>5H5N5X5^5h5q5|5",
        "{,G}kg",
        "$,&s )",
        ":\\fvf",
        "@EW.je",
        "j|jsj'",
        "@ER+%",
        "A#![;",
        ":3-GB",
        "pU~m{",
        "A:qEE",
        "0%c%d%e",
        "={{,Q",
        "\"7`s]",
        "SetEnvironmentVariableA",
        "'$$uM",
        "\"+S(!",
        "Fu6dY?L",
        "oL1#ICb,",
        ".?AV_Generic_error_category@std@@",
        "nt%CI",
        "d2yz!",
        "n\\^sN",
        "< W&P",
        "ECP_NISZ256 for x86/SSE2, CRYPTOGAMS by <appro@openssl.org>",
        "eu9v!_",
        "X5J)B",
        "drx(\\7V%]|",
        ">2.9u3$",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\event.cpp",
        "Request Extensions",
        "lr,b/4Y",
        " !\"#$%&'()*+,-./",
        ",E+M)",
        "CLfz:",
        "/~1PLQ",
        "+3#@T",
        "F;0F}T",
        "ar(~S",
        "ot}i4x",
        ".rdata",
        "< <&<0<;<P<x<",
        ";[b:g",
        "W\"^KN",
        "#zY<{",
        "sS;T;u",
        "sNr<o",
        "UQ9Y.",
        "cdugL=",
        "Failed to initialize.",
        "7lVmc",
        "O _^[",
        "D$ t&",
        "WBYTE ",
        "p90{;",
        "+ttaFj",
        "4^<SA",
        ",:fl\\",
        "\\Products.json",
        "EORH2",
        "{L@#x1",
        "= =(=0=8=@=H=P=X=`=h=p=x=",
        "<d=j=p=v=|=",
        "dNrP'HG",
        "x[}5,",
        "rZf;u",
        "Zg83Xd",
        "l9BwD",
        "=JpXT",
        "6&7[7",
        "6e5tx",
        "$-S;b",
        "$lBg4R",
        "6fk{1",
        ";|$(uh",
        "StringFileInfo",
        "Kiqs`",
        "gfIga",
        "R8qoH",
        "TAly~",
        "]E{ }",
        "expected ' or \"",
        "0-1115191=1A1E1I1M1Q1U1Y1]1a1e1i1m1q1u1y1}1",
        "*\\r(C",
        "9,?0?4?8?<?@?D?H?L?P?T?X?\\?",
        "qp# {%",
        "z8)R9v`",
        "^eM48|",
        "ODN]e8k:",
        "7$7,747<7D7L7X7x7",
        "br#uf",
        "4WqvS",
        "jjjjjjj",
        "L6Lz%",
        ">$>3>>>N>|>",
        "WwN)$",
        "Custom Actions did not require reboot.",
        "4?D?P?\\?h?t?",
        ">,}bJ",
        "THREADING",
        "x+S4G",
        "W.JbY",
        "Qy*$ UR",
        "u '\"{",
        "Gzdbb~",
        "D}bybfxb",
        "R+|S_",
        "jrZ/(Dt",
        "p~w0l",
        "U7,7y",
        "`QNPAP",
        "PKCS12_SAFEBAG",
        "SVWh KM",
        "wGo;H",
        "5 585<5T5d5h5l5",
        "PFRSQRT",
        "OR!y~",
        "iE{X0z",
        "@D.H4",
        "\"ZX`<",
        "\\]C!&",
        "Y@WIJ",
        "NZ/7l",
        "(-Jnb",
        "Fs]:lX",
        "K~X]0Z",
        "CONF lib",
        "pbeWithMD2AndRC2-CBC",
        "d)y%6",
        "#zZ}b",
        "jQEQb",
        "0tXXt'(",
        "626K6d6}6",
        "l&)@G",
        "pm*_W",
        "^dHV:",
        "h6g!VS",
        "    Next Update: ",
        "-U$-TB^",
        "bad data returned by callback",
        "cs)$Wi-~l",
        "7X7j7",
        "{x*Aj",
        "error setting fips mode",
        "?:#;#w",
        "_t^PVj@",
        ",-e{|]",
        "MIVvk",
        "SystemInfo",
        "jurisdictionStateOrProvinceName",
        "+;=s|}",
        "mac verify failure",
        ";6;O;h;",
        "cS|ff}",
        ":aks]",
        "#}0O?",
        " NbhE",
        "-hDq+A",
        "M(;L$$u!",
        "jHd!l",
        "failed to get install state for Component: %ls",
        "mime parse error",
        "eY,bx",
        "SXNETID",
        "es-pa",
        "8~DzO",
        "Z)9:I",
        "g^<;}",
        "Ag{L;O",
        "j{U5z",
        "v=s8_",
        "setEventGroupInVSConfig;",
        "]'t+d",
        " YF*P",
        "bad message",
        "'_@g;(",
        "010B0W0j0",
        "J#^\\=",
        "$x[fo",
        "tv_L+",
        "75Ax@",
        "KC+J?AYN4",
        "pi6!g*",
        "5%5E5e5J1Jk",
        "^SG+?;",
        "L*2B\\",
        "c^3<>",
        "AkVWA-5",
        "&4avl<",
        "C;Jv^",
        " You acknowledge that the Product contains cryptographic features and is subject to international and local country laws governing import, export, distribution and use. The Product is subject to export control laws of the }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "DA_PrepareStopCPDAService started.",
        "Vj`h$<#",
        "~sSrJ",
        "+ip@)",
        "G6IF+Ob:?u.",
        "JRKRk",
        "l$hVW",
        "#Ig-V",
        "F1qiO|",
        "2R:;S",
        "q0Wm0",
        "Invalid parameter",
        "?v$N3",
        "i4oA^",
        "181\\1`1d1h1",
        "8+8J8T8d8m8",
        "`xBRSL",
        "=UL,1",
        "26^?6-",
        "tChCsC{C",
        "4!iFB`",
        ">`5b*",
        "Server",
        "kp!%M",
        "4 4$44484<4@4D4H4L4T4l4|4",
        "%dv~!;",
        "Cu-B@L",
        "#+cx&",
        "Co`_?v",
        "too many files open",
        "_2bDeleted.tmp",
        "5]Y\\7",
        "^,^w$",
        "Microsoft CSP Name",
        "#c'j*",
        "XhG&kI.",
        "0,1_1",
        " :(lV",
        "{.Pyc",
        "Q;!r.",
        "Mi_mI",
        "t?h@%",
        "DE&iw",
        ".M;a4p",
        "]V-Eb",
        "W8^&un",
        "iKja2l4",
        "5D4N_}",
        "SEC_E_NO_IP_ADDRESSES",
        "m[w\\g[o",
        "\\OR\\k9",
        ".)3 6",
        "gvV#o",
        "4,?D+",
        "c]C$n",
        "4<;a;2<",
        "<4eag",
        "2S2!l",
        "rI4#\"Wh3#}V72",
        "T+_qX(",
        "xf\"^!",
        "8\"868C8",
        "h,'\"h,)",
        ".?AV_Node_if@std@@",
        "RfB|J",
        "/3}JH=",
        "_seh_filter_dll",
        "~v/56.",
        "xCc(R$",
        "SzC#s",
        ",X>C`",
        "`IzL0ee",
        "ftp@example.com",
        "7F7X7",
        "L%5Vqb8",
        "9:Ic%",
        "bpFVu",
        "D$$PWj",
        "3|5k]",
        "Found Discovery VPN upgrade product code",
        "\" `t+6?",
        "oD$`1",
        "Msi Database Error",
        "iw|HY",
        "CMS_stream",
        "After %ldms connect time, move on!",
        "I;%%%+y:D",
        "$O\"Pl",
        "8$9I9",
        "2?3I3f3w3",
        "^Rw{(",
        "b^+Kk",
        "2i^X&",
        "Vh`eo",
        "]n79R/Q-0",
        "Wh,R!",
        "8YK|(",
        "n;)7Z",
        "Informational. Status=%d",
        "&Z?kb",
        "LS73;*~",
        "ECh@ZV",
        "^nW#^(",
        ".C%!S'MFt",
        "[SX# 1(",
        "FZ2m:",
        "WIX_SUITE_COMPUTE_SERVER",
        "FzA#h",
        "Strong Extranet ID",
        "2\"y>7",
        "\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 2;\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 2;\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 2;",
        "u5l5ni",
        "    Revision=\"",
        "<;<G<O<",
        "SAw`l",
        "}7HQe",
        "r@=8>",
        "t)1i/K",
        "3n^gQ",
        "&C!mfo",
        "7xi``",
        "/(?1w",
        "ON'PK",
        "kDgGN",
        "first QueryServiceStatusEx failed: %d",
        "3I7/d?s",
        "/ht\\w",
        "wAy#w",
        "B\"x*b",
        "9G\\`i",
        "!]d'P",
        "9G;c;j;",
        "d2i_DSA_SIG",
        "='>#?D?]?q?",
        "ys)RL",
        "k]x|[",
        " xe7{",
        "(+YQCW",
        "X(m8:i",
        "serverAuth",
        " SSL certificate verify ok.",
        "- not enough space for _onexit/atexit table",
        "r_4'e",
        "VzK9/",
        "t5rd7jzI",
        "8]Vc2",
        "92:b:",
        "HWuSmzd5",
        "2Z#@dkh",
        "\\lsdunhideused1 \\lsdlocked0 Table Web 3;\\lsdunhideused1 \\lsdlocked0 Balloon Text;\\lsdsemihidden0 \\lsdpriority0 Table Grid;\\lsdunhideused1 \\lsdlocked0 Table Theme;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority1 \\lsdlocked0 No Spacing;",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\UIFramework",
        "t,,X.",
        " E 9(E",
        "^m,TQ",
        "0<0H0h0p0x0",
        ":5:K:S:Y>",
        "_aUks.Jo",
        "_b,8WZB",
        "ucMpj",
        "B,{M[",
        "ec_GF2m_simple_group_check_discriminant",
        "CMS_DigestedData",
        "323C3N3b3s3~3",
        "<U\\sg\"",
        "-----------------------------------",
        "NNq{98q",
        "PublicKeys",
        "*#UcO",
        "br#n46_9",
        "msvcrt.dll",
        "wHqdH",
        "qNN'-",
        "I/rVx",
        "kY/D>",
        "'J>:8G",
        "=\"='=-=3=9=D=I=N=^=c=h=x=}=",
        "nr6^r",
        "b'v6Q0q",
        "2&4G4b4",
        "9R:^:",
        "e[&oe",
        "7I+Ek",
        ".[8V]/nl",
        "Vsdatant_epk_win7.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "n\\^TlF",
        "~;G; @",
        ",4$p.",
        "&'P&h",
        "[/(&?",
        "F4PVj",
        "~q<N_",
        "SVWj83",
        "^%I\"$",
        "@L@|5",
        "z^p7A",
        ".1'ge,w(",
        "`f^|r",
        " =R)(",
        "x2SUi",
        "Y+~M;a",
        "&fYK-b",
        "L$D_^][3",
        "QUARANTINE",
        "i.y;?",
        "9:9R9j9",
        "ZDX*9\"",
        "x%KzB",
        "vs=r4",
        "Change Characteristics KeyValue ",
        "B%F=r",
        "Content-Range:",
        "Qg.R*",
        "'DI\"x",
        "}<z(j",
        "uZv%]",
        "giF%5",
        "Fya1pck",
        ",$=`(f",
        ";n8k9<*(",
        "L$DWU",
        "UNPCKLPS",
        "CleanUpInternetLogs:  Deleting ",
        "{3Mx$",
        "#4@.JAe",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{8315396A-5EA1-419D-BEC4-978284BDF556}",
        "7j+PDq",
        "DV\\0z}+e",
        "mvrB=",
        "33^8-",
        "Fg:9uo",
        "3 4%4+41474=4C4I4O4U4[4a4g4m4s4y4",
        "1n~#L}a:",
        "NT, TO THE EXCLUSION OF ALL OTHER TERMS. THIS AGREEMENT SUPERSEDES ANY PREVIOUS VERSIONS.  IF THESE TERMS ARE CONSIDERED AN OFFER BY CHECK POINT, YOUR ACCEPTANCE IS EXPRESSLY LIMITED TO THE TERMS OF THIS AGREEMENT. IF YOU DO NOT AGREE WITH ALL THE TERMS O",
        "If@n.{",
        "faOD\"zCHg\\",
        "(,pX!",
        "O+PkQ",
        "|>M]X%0",
        "s$K;W",
        ";;s)Q",
        "4|8/5",
        "hb?O2",
        "jjjmj",
        ".\\crypto\\asn1\\a_i2d_fp.c",
        "l$0WU",
        "xg%/l ",
        "DoMqc",
        "tzfAZ",
        "N#4IXJ",
        "VsDrInst",
        "1-i|$Vf",
        "PGjneYbJOD=",
        "LdR.k$",
        "Y zGQ",
        "(Dokk",
        "h*`}K",
        "D$,PVU",
        "0(0H0P0X0`0l0",
        ";V#k8",
        "Failed to run %s - error:%d",
        "f&&+!",
        "7\"8,8c8",
        "zY~*d",
        "\\GyDv",
        "hbvElS",
        "X6\\}Gg",
        "41aZ3",
        "4&42484<4I4",
        "7@8E8J8",
        "4z4Md",
        "@`QM(7",
        "$\\(9z",
        ":8UHO",
        "proxy",
        "; ;$;0;8;<;H;P;T;`;h;l;x;",
        "|Z6hV<v'",
        "|Ex5*",
        "b'HU@",
        "0|P82",
        ":0:8:@:L:l:t:",
        "w`elT",
        "{mTniAt",
        "Y:?tx4",
        "EO+HG~lA",
        "KCD'u",
        "w!w]g",
        "bR{ZkKc",
        "[LICENSING] run out of memory in LicGetParametersFromBuf ",
        " Error=",
        "NZJ<U;",
        "55 [R",
        ",F0c|v+",
        "3zK'F/",
        "7=p8o",
        "r~||r",
        "%^7')",
        " O)u}",
        "Logging",
        "p2I~(",
        "ON0q19",
        "9(9,9@9D9X9\\9h9p9t9",
        "mX2~'",
        "M5rghR",
        "The registry key is not open",
        "(kxmq>",
        "~F(iG",
        "&@ZJ\"",
        "CZ/0L",
        "ew ?SV",
        ":}!5Mi",
        "; ;,;8;D;P;\\;h;t;",
        "Wk'Du~",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 3.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "D$ UV",
        "ContextPriority",
        "R1,m}",
        "Ke iP",
        "Qhx|&",
        "Oi|{`ox",
        ".B|i2Q-",
        ",IbzH+",
        "p3(AR",
        "101I1b1{1",
        "K#B?`",
        ".\\crypto\\ec\\ecp_oct.c",
        "Cannot open vsconfig: getlasterror = %d",
        "9F/I\\",
        "D$8PS",
        "Bad optional access",
        "%&DCpPH",
        "kk-kz",
        "D$$VWh",
        "S`H@Xg",
        "mCWbV",
        "C8n1F",
        "~Ji%P",
        "AES-256-OFB",
        "[VSDATA] FwConfigChange: got %d adapters",
        "Fg.]W",
        "U\\5hK",
        "zW&{]",
        "~.LwG",
        ")\")j*",
        "(%`B ",
        "#'yr c",
        ":R\\I(",
        "]m[HY_`",
        "<'>50",
        "<1<N<t<",
        "`*VT,",
        "oTU*z<",
        "invalid parameters",
        "ssJ (",
        "g:@|U{9IW)_",
        "YK-->MZ",
        "_;.)j]0",
        "@M2=!",
        "jdD4Wl",
        "D$Hj P",
        "CB{Ak$~F3Z\\",
        "Pj>~,",
        "LTu*7^",
        "ZOC0p",
        "9H1hr",
        "]K#9h=",
        "LocalPackage",
        "l\"T4E)",
        "\\zonelabs\\zlmcp.dll",
        "L*mi20",
        "U U2UCUlUvU",
        "jY-xY",
        "rc2-cbc",
        "pZUa\\",
        "CMS_add1_signer",
        ";3;t;",
        "t#SRU",
        "Fh(;#",
        "OP`+S",
        "DriverOpenProcess",
        "Oc@q?",
        "<Cz]a",
        "]$duw",
        "ECKEY_PARAM_DECODE",
        "MdUEdF",
        "^Y0gq",
        "ASN1_COLLECT",
        "short header",
        "#yu2[+",
        "NHo=e",
        "{,qd-",
        "&)uE8",
        "BN_EXPAND_INTERNAL",
        "G^ogX",
        "7o\"m/",
        "HlfmA",
        "52Ug9",
        "?ZW5@zF",
        "M'L/d",
        " ^d2(",
        "b*lo?",
        "(!$td",
        "D$*j.P",
        "rlf;u",
        "Sn':dU",
        "686T6p6",
        "G,uD&vO",
        "?Q<ks",
        ".>*fY",
        "(^>:p",
        "A\\.XY",
        "&EEP<L",
        "Z%)'\"z",
        "p@b)q_",
        "):$g%",
        "I\"4V[+",
        ".SX2E",
        "c!e'eSd",
        "<icR6",
        "c'o\\X",
        "PKCS7_verify: bad signature",
        "B6z7/",
        ":(:,:<:@:P:T:d:h:x:|:",
        "D$(Pf",
        "Jb\"uo",
        "\\TX55Z~",
        "(%_?&",
        "J<^+?{*",
        "_Y?|o",
        "qJ ;EE,",
        "(VKNdkG",
        "V!XHa ,",
        ",KV[i",
        " 0x4a",
        "lJURs",
        "l='@A",
        ":#:?:[:w:",
        "Qj Vj Vh",
        "eiA3PM",
        ";j8Uj",
        "oLltvu",
        ">L}C}",
        ",#'yhd",
        "Ura.0",
        "%I : %M : %S %p",
        "wyo_f",
        "H*^uy ",
        "CommitActionC.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "869H9",
        "se-FI",
        "o.9pK",
        "7=g0z",
        "+6/#Hm",
        "WU6%)c",
        ":5;E;",
        ";%;+;1;7;=;C;j;",
        "Pj Ph",
        "cCa:Kn",
        "^A\"(bk<",
        "~_y-P",
        "7-n;Z",
        "b=KVi",
        "Akj@x",
        "Niv,8",
        "not pwri",
        "Started up -- initializing",
        "4 4,444h4x4",
        "h/]`'",
        "MergeCommonBackup failed",
        "m\\~!O",
        "j;/C:",
        "dG6jD=F0Q",
        "DHE-RSA-SEED-SHA",
        "s{#?89rv",
        "+z<<k",
        "jAjsj",
        "d:PcT",
        "drivers\\vsconfig.xml",
        "F(\"Y,",
        ")`3m){",
        ">^g(2`L",
        "lhJ(l",
        "<?qi<",
        "iE*bp]C",
        "0<@)^",
        "'AYWK",
        "algorithm mismatch",
        "{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713\\'02\\'01.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li1440\\jclisttab\\tx1440\\lin1440 }",
        "english-trinidad y tobago",
        "MVJTA",
        "MwmhL",
        "Location",
        "RemoveDirectoryA",
        "\"RP`J",
        "6 6$6,6@6H6P6X6\\6d6x6",
        "7\"8T8",
        "FsiZDG",
        "%oop+",
        "0/0B0f0u0",
        "eknpQ'",
        "zzqt7",
        ":/;I;",
        "Nested\\EP_VCRedist",
        "I9*{I",
        "3>Fd;/",
        "U(Px(",
        "c%]P5",
        "fSy4a-",
        "3j\"'L",
        "kF4#Y^",
        "jAjY|",
        "Ve {P",
        "}15dX",
        "Cw<3H",
        "#KYbg",
        "heJ,X'",
        "$2Iv ",
        "%!3Ca[",
        "6w\\|P",
        "Jszde",
        "G`>qCB",
        "8&9M9b9t9",
        "2`vsU.",
        "0\"080l0",
        "Z'cT!",
        "$~*:=S",
        "spanish-colombia",
        "3U=R]",
        "]_m#0",
        "<sG`EP",
        "y(kw-r",
        "=!>'>U>",
        "zMW8\"=",
        "5 6H6",
        "Y996n",
        "tGpxB",
        "h}-[l",
        "0_/_#",
        "3$4I4d4",
        "#NDF/l",
        "_c9axV",
        "responses",
        "BT^[`",
        "(5P@ ",
        "s\\iq#",
        "'rtx<",
        "The USERTRUST Network1.0,",
        "=5=N=g=",
        "nce6V",
        "59kmk",
        "4:4N4d4}4",
        "ZyNaCT",
        "PRODDIR",
        "'a\\K|",
        "NF3d$e",
        "@`2-q0",
        "HW\\kF",
        "Lyn<f&?",
        "E~i;2{",
        "SSL_RSA_PRIVATE_DECRYPT",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7224833 s}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 , i}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238\\charrsid12465679 ",
        "2`EI+",
        "jvo,q",
        "ZIo|:.EW\\",
        "OK963",
        "64?{6<",
        "9~x~'",
        "User was rejected by the SOCKS5 server (%u %u).",
        "uy_Tk^",
        "I^e_h",
        "sb57K",
        "-Uo9v",
        "'aS$e",
        "L$(_^",
        "tIIgb",
        " VrG7",
        "`bkU(",
        "quz-pe",
        "]2?S@#",
        "OU/D`t",
        "nY'O_",
        "U0[<?e",
        "/XLe&j",
        "jO-O-/y",
        "xXCXe",
        ",Zl2B",
        "M@O<]&",
        "dDpFe",
        "t$,QP",
        ".MX/0",
        "h,Q#WCvQ4",
        "xpRGf",
        "VXo=H^",
        "Endpoint Security.",
        "UnblockProcess",
        "d>]j9",
        ")\"\\U>",
        "l&,gq",
        "pmSnNg",
        "LQUfz",
        "JIBhOg",
        "SETNZ",
        "e2iu&",
        "2 2@2H2T2t2|2",
        "$\\6PX",
        "SR\\a%",
        "`r9`a",
        "B_'TF",
        ":|@f7",
        "SdPX ",
        "SMo^E;",
        "?(?t?{?",
        "HFF9/n",
        ">b ~+",
        "iU*/z",
        "jwE!k<",
        "P.[A\\",
        "0G$ LM",
        "PreInstallCheck: Required Disk Space needed for chosen blade configuration is: %I64d MB",
        "argument is not a number",
        "6%6m6",
        ":$:,:4:@:`:l:",
        "s!/!R",
        "=!=A=Q=a=",
        "p not prime",
        "8(\\1I",
        "A9}ej",
        " ra^#,",
        "X${\"X4{BXD{bXT{",
        "CONF_parse_list",
        "6!7g7",
        "OnDriverStopFailure executed. Going to stuck installation forever!",
        "<-<><F<N<",
        "failed to create an instance of IShellLinkW, skipping shortcut creation",
        "D$(UVP",
        "ssl3_get_client_hello",
        "`iiQ\"",
        "sct;7I",
        "4b8Ri",
        "**@xo\"4",
        "HdZi@",
        "^'~Tt",
        "3T$$3",
        "0:0`0",
        "LoadDisconnectedPolicy:  LoadDisconnectedPolicy finished.",
        "cc3P`",
        "api-ms-win-core-file-l1-2-2",
        ">?vd}eb",
        "ojF$a",
        "k~iYc",
        "717E7",
        "273`3",
        "#2'JF",
        "VQe*oV",
        "\"Y}<0",
        "\"<FHFRF",
        "0>1o4",
        "~~fJ=",
        "Lp[>Z",
        "?!e>V",
        "1{#z,",
        "A)67C",
        "iBP9l{",
        "CYKl^",
        "OLRQO",
        "UfcR~",
        "failed to get proc address, error %d.",
        "51-tX9",
        ".\\crypto\\dso\\dso_win32.c",
        "klupd_klif_swmon",
        "=>>W>",
        "bLk-6",
        "nAi|?",
        "U,?JL",
        "GetWindowThreadProcessId",
        "failed to intialize WOW64.",
        "R},mO",
        "F PSh",
        "d2i_AutoPrivateKey",
        "YyYwV",
        "3QnuG",
        "$ViYr,",
        "6%asa",
        "(HX=ag!",
        "vxCMe",
        "lcX`9",
        "M<8r=?j/X",
        "909t9",
        ":0:@:D:T:X:\\:d:|:",
        "|PyB^o",
        "jdjxj",
        "}ERe8",
        "RegisterScvPlugins",
        "HHtVHHt",
        " KwUB",
        "FWFreshAfter:  SetProductMode (again?)",
        " !\"#$%&'()*+,-./01234567",
        "~HH3Ol",
        "XVd&s",
        "AES128-SHA",
        "0iRL|d",
        "2.3p3",
        "g.Jd5y",
        "%,=WGv}>",
        "Yt6N-",
        "1TClXDi",
        "EC_POINT_dbl",
        "/IXZT",
        "KuV_j",
        "?yD#t",
        "!)0Zb",
        ";<<C<O<]<t<{<",
        "ff UF",
        "Start pending",
        "2}zn*",
        "ssl2_peek",
        "1xCy_uN",
        ".,NON",
        "D$ ;N",
        "MOVNTDQ",
        "<,z[C",
        "Y\"[@>9",
        "jCFOS9]f",
        "?/Bokx",
        "just called DllUnRegisterServer() from ",
        "C=qqf` ",
        "'nnWV",
        "QJ'~-",
        "O+ny6(",
        "1R&&w",
        "1?+RJ",
        "~U(52o",
        "1B2y2",
        "V2I_BASIC_CONSTRAINTS",
        "nNRwz",
        "Wewi|",
        "i)?jWe",
        "!eqpF\"",
        ">tZ[2",
        "Failed to save value \"Action\" into registry. Error code: %ul",
        "72~]c(",
        "xL\\~n",
        "De&CG",
        "RpcRevertToSelf",
        "F>xn~<",
        "?#?)?J?m?",
        "WaitGetNewMessageToClientEvent",
        "<h<m<",
        "RegKey::GetValues()",
        "9$9,949D9P9p9x9",
        "4_a+7",
        "vRKj10",
        "$JI&K",
        "*8$l,",
        "(NONE)",
        "6_Ec3",
        "h3BR-2",
        "}_hTv%",
        "Mv}~z",
        "R5N7_9_k_~",
        "t:Sh ",
        "F8~?kA=/",
        "The requested document is not new enough",
        "u&9D$",
        "mac verify error",
        "QL!4\\",
        "hiV6fj",
        "qrqy2",
        "\"zP8]",
        "!CTv^",
        "!^aW{",
        "Management",
        "JX_;&",
        "SetFWStartup:  SetFWStartup finished.",
        "D1\\TO",
        "5>*Qq",
        "failed to set authorized app remote addresses",
        "V]^VT",
        "~~cK6AX",
        "ie']p",
        "{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}{\\*\\xmlopen\\xmlns2{\\factoidname place}}U.S.{\\*\\xmlclose}{\\*\\xmlclose}",
        "EGj5]",
        "surname",
        "i}N7Q",
        "OaoG3",
        "~?CR#",
        "?17=,",
        ":lKIM",
        "k?yJp",
        "PDQD%",
        "&BOAL",
        "J}V[B",
        "Rv-Vo\"6?",
        ">5?X?{?",
        "ua77z",
        "gP^eG",
        "Hcm!{7",
        "'F?>O",
        "4(XmN",
        "' @-O2Yu",
        "Tnz&k@",
        "i-K0+",
        "A6x<X/4",
        "t=d`G",
        "XsQ<p",
        "1f2m2",
        "<A=Z=",
        "EP_VC",
        "= =2=E=_=n=",
        "<2<K<d<}<",
        "<}I*=",
        "\"&*8W",
        "G3Ev@",
        "2f3s3",
        "ZN,dl",
        "OCSP responder",
        "null is wrong length",
        "KDMFSq",
        "8qf\\zR1",
        "5`6+7&8Q9",
        "HI|&Q,",
        "=~%UB)j",
        "=P,obE",
        ":0:4:L:P:h:l:",
        "]55@ ",
        "Q}mMwW`s",
        "S}r_4",
        "5Ey,MY",
        "4 4/4=4K4S4_4",
        "<e<;=H=",
        "Nc1RF",
        ">7@(_",
        "GW~r\"h",
        "3Ckyt<",
        "0&Z~_",
        "=_WK,",
        "*$J,V",
        "nnnnnnn",
        "[\"aY<",
        ".delete",
        "}-tssU^3$",
        "[){,!",
        "?WYt-",
        "H`XT_",
        "WX(_o|",
        "2F3\\3",
        "F|\\j-",
        "tccqX",
        ":(:D:`:|:",
        "ur-pk",
        "_V<m<",
        "unsupported encryption type",
        "_uE&~W",
        "lgVwdJ",
        "Helper:stop() -- InstHelper.exe is not running.",
        "Qj:@+",
        "8#8(888=8B8R8W8\\8l8q8v8",
        "PK6co",
        "[4?$CO",
        "+uzui",
        "*>_=a",
        ">ZL`'W<OHi",
        "?O(]4Z",
        "m/J/sH",
        "[VSUninstallProduct_logon]",
        "<-=l=",
        ">7%x`",
        "9)/?L",
        "Microsoft Server Gated Crypto",
        "Failed to set record.",
        "9<9D9h9|9",
        "(E9ztmo",
        "kGd:l",
        "YlB:D",
        " Complete Object Locator'",
        "2.>HG",
        "DSO_pathbyaddr",
        "EVP_PKEY_sign_init",
        "I]2k7",
        "\"\\FW?",
        "8G9Z9",
        "aZaaafata}a",
        "Cw;5k",
        "6 6$6(6,646L6\\6`6p6t6x6|6",
        "UN<j,",
        "$F#3h",
        "`,Wf~",
        ">DT`[",
        "U}[m@%3",
        "Z,)iS",
        "6H7*8a:",
        "G:/q4",
        "aes(partial)",
        "n9k;qL",
        "=xzD5",
        "Z+op~",
        "3&484^4",
        "!TgAv",
        "sm_P1",
        "Dl2Ka",
        "7PlTO",
        "+TjUF",
        "0-0m0mgc",
        "tpl'}G",
        "rR'OZe",
        "?A20&",
        "V=FjGF$",
        "A0y/{",
        "),>5_Xk!",
        "6\"6.6;6E6k6z6",
        "5#5@5]5z5",
        "Qj$V,#",
        "1+c4!",
        "so<n7",
        "!9wR[R",
        "ny'nm$3Z",
        "65a9`wd",
        "yw-C1",
        "5&HLY",
        ";af0T",
        "6 6$60686<6H6P6T6`6h6l6x6",
        "ltF@y",
        "reading property file",
        "huuku",
        "x4p9K",
        "dlCz ",
        "ibOJ}B",
        ".\\crypto\\evp\\p_lib.c",
        "iz-)0",
        "nPV6z",
        "g\\.h7",
        "8*82888",
        "ECDHE-ECDSA-AES256-SHA",
        "XWW25K",
        "9&9-949;9B9I9P9W9^9e9m9q9u9y9}9",
        "Q}QgQh",
        "#I}r[aj",
        "&)m+2",
        ">6>C>W>^>",
        "$6$^!V",
        ">'>->;>G>V>[>",
        "[INSTALLER] MSICreateXmlForPlugins:  Directory: %s File: %s",
        "SHGetKnownFolderPath",
        "7$7,747@7`7h7p7x7",
        ")S(&-:",
        "TyZsK",
        "VZ@EBj",
        "r0iXy",
        "B|Sgb",
        "3\\$83",
        "8:D:N:R:\\:",
        "`V/c7?R",
        "X@v4Q",
        "Lrny#",
        "QBx? i/Y",
        "!,pbVJz\"",
        "b1b=bQb",
        "\"997#e",
        "KA\\??",
        "D/0uf",
        "9-9I9b9{9",
        "sU_Fj",
        "4,A:d",
        "=IZ6kg",
        ":/0~g,",
        "v{Z2\"",
        "]}PdY",
        "Ur R|",
        "/wA^HAK",
        "xepio(Pp",
        "P,@:4",
        "@sMCvy1",
        "K3<rv",
        "H+lAV",
        "sKdpL",
        "SC_UIFRAMEWORK is set to true",
        "id-regCtrl",
        "\\KJ&i",
        "w!1~]",
        "%dKOp",
        "- not enough space for arguments",
        "3L$ P",
        "RtOE#u",
        "2<2D2L2T2\\2d2l2t2|2",
        "vi5^Q0O",
        "-NE~G16",
        "uV<uDk^",
        "gW77g",
        "X60Tt",
        "LZbj7",
        "a~,e_b[",
        "CCCCCCC",
        "8z5k:",
        "<DtB<[",
        "g\"v:^ L",
        "VZB,|",
        "UNUSED_2",
        "$,qF`R",
        "r\"\\Xy",
        "accessVsdata: %d ,accessVsDR: %d ",
        "    This Update: ",
        "zRKWiA",
        "b#I:!(N",
        "EFDO_E\"|>",
        "[2jQJ",
        "AR/Rh;",
        "self signed certificate",
        "D$<PS",
        "C\"uyi",
        "W&Nk=",
        "7P+}i",
        "}cO4n*[f",
        "c1?c$",
        "dXk\"Z0",
        "UiUIViW",
        "V?R/c",
        "\"MeQCOc",
        ".rsrc$02",
        ".?AVimproper_scheduler_reference@Concurrency@@",
        "/TE-xQ+",
        "XMdl8Q",
        "9|!eN",
        "logonVsmon",
        "T W YLJ",
        "$7mOW",
        "Reading properties from file:  %s",
        "JOQ,zc*S",
        "`Xi@R",
        "c53v}",
        "zauninst.exe",
        "R1wOo",
        "_B*VJ`",
        "f>9Q_",
        "lsVXz",
        ">`CommitCAScriptCleanup",
        "*/D^Rb",
        "~2.`Yr",
        "stomization may not contain any reference to a competitive gateway or to Check Point products or services without Check Point}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid9391338 \\rquote }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        " /~OW",
        "VjDhD(",
        "operation canceled",
        "9kf`G",
        ".JK:@|",
        "S)sL_",
        "?3mW,",
        "CSkkc",
        "? ?,?p?|?",
        "PHAbz",
        "2C2V2z2",
        "dIdQdK",
        "@#b#B",
        "CZ6Y{",
        "o7<W6",
        "WCtmvVRP ",
        "G\\vE+",
        "XF\\D$",
        "SELECT `Directory` FROM `Directory`",
        ",r?\\Za",
        "<source>",
        "7F9kp",
        "sa6=n",
        "1vRVL",
        "2+<7vn",
        "$q[agN",
        "585X5x5",
        "3L$P3L$43L$ ",
        "XPath",
        "hJ$xRc",
        "GpR|R",
        "'#wf_",
        "{}LR^",
        ">??Z{",
        "uj^v3",
        "^}%aA",
        "OLD_RSA_PRIV_DECODE",
        "6(6-6F6K6d6",
        "Ht77M",
        "NT'[f",
        "l~gZk",
        ">$?4?@?`?l?",
        "&\"<D6~%",
        "javaw.exe",
        "$Wl[z",
        "SYrwL",
        "Pd5_Ti",
        "z\\t+2~",
        "b%zs.",
        "failed SysAllocString",
        "GetFileSize",
        "__int128",
        "V|7F&k",
        "f58]B",
        "rtU^1",
        "\"Vz 9N ",
        "0!0q1",
        "O8)cg",
        ">S>c>",
        "*\"g*d",
        "<tGVg+U",
        "xZCI)`",
        "^Ek!8",
        "HADDPS",
        ")W%x_",
        "X8q1zu",
        "7 707H7",
        "BIO_callback_ctrl",
        "Encipher Only",
        "\"Fe V.",
        "z#QLU",
        "SetFileAttributesW",
        "m 6;H",
        "tSdy\"",
        "=ws}M33:\\G",
        "b9!asu",
        "V;V<a",
        "m#\"d7Lx",
        "gk~J+c:",
        "INSTALL_SC",
        "pyUs5",
        "fr-ch",
        "CuH\"6",
        "CertCreateCertificateContext",
        "gU%6.'",
        "fNXT=.",
        "T61STRING",
        "SPNEGO handshake failure (empty challenge message)",
        "TIMING MARK",
        "4G7LE",
        "uz\\&d)",
        "g_>bz",
        "8y\"?<N",
        ">zJ1X5~",
        "? ?(?@?P?T?d?h?l?p?x?",
        "cS0W?+",
        "MonitorGetDWordValue",
        "NM9w(p`",
        ":LCWP",
        "M/M<MJMQMUMa-",
        ";BUZs",
        "% R$}T",
        ":xK7H-N[t",
        "@a%}S",
        "|u[,)",
        ";3h@y",
        "XvKW(",
        "FDIVP",
        "(Kd][$",
        "YYOwN",
        ",t@-0",
        " 7!jz",
        "F/8<h",
        "OhX:r",
        "0]DoI",
        "SpR;f",
        "1j3d9",
        "9S:q:",
        "aJ2s\"",
        "tejqh",
        "S2rk*",
        "}HG*'",
        "obPC/",
        "ClHDSXZ",
        "545fb28d07d205d20e8ea071b283369834296bdaac75d256cb37eb0bee740bbe278cad253b8bbfcf69eca23973d939b97891c6ce2cecd8da8e2d343578f6648a",
        "; ;,;H;h;",
        "&(.p/",
        "E$;EDu",
        "MOVDQA",
        "\\drivers\\",
        "|ROU#",
        "9|?CN=`",
        "3AQe|",
        "&fEDI+",
        "9#9[9",
        "0)0)t",
        ":E;X;",
        "[y.q1",
        "id-aes192-CCM",
        "1Qb!0pnNA)",
        "4f5`v",
        "&)vu5",
        "~KX)%",
        "C`_\"s",
        "]Az$\"",
        "Fc7zF+Sk",
        "c*-du",
        "[Bxn ",
        "1%1I1i1",
        "~QQ]wp_",
        "w*8k+",
        "<pnkO",
        "~ezV|",
        "96JFj",
        "JmqOs",
        "~NILQ2",
        "x@IQ&o;U",
        "pBZSdN",
        "u\\|ae",
        "x48Ci",
        "e|m?lq",
        "UubsC",
        "OpenService failed (%d)",
        "}DUHZB",
        "PEXTRQ",
        "w+R.PF",
        "y_Yd]Rz",
        "qZs7z",
        "id-cmc-getCRL",
        "|$,t4",
        ",IeJ;",
        "b\\uZ]vO",
        "V)\"nl",
        "gKyA5",
        "FLT_OVERFLOW",
        "EVPHasher() bad md_type",
        "I,tv[",
        "nL=S;H",
        "fnVa')",
        "K!UhV",
        "1P3--",
        "3(3Z3p3",
        "5'656@6",
        "0 0$0(0,0",
        "?N9y|",
        ")>6j`",
        "Eu`)@",
        "jnW_t",
        "Qt&dc(",
        "u-G;}",
        "vi{y:",
        "3w~$RPRr",
        "6,606H6L6P6X6l6p6t6",
        "*GJ)f",
        "[gg!z",
        "G#.S)B",
        "ncR.Y",
        "crlBag",
        "JDH[Bv@",
        "77dY(o",
        "<1<M<o<",
        "Iwl`I",
        "+FOKK7",
        "7s7g8",
        ".VLQl1",
        "{yq6y/",
        "Dhk.H",
        "CYjUt0",
        "j|qCb",
        "xqoX(1M",
        "[l#dX",
        "1EfDm",
        "xk=`Be",
        "<jA>S",
        "\\oe'L",
        "GXc WM",
        "s1UEnEX)%N",
        ".I+g6",
        "Global\\vsmon_unique",
        "s\\j\\V",
        "6ox4E",
        "jejwj",
        "h8?ve!",
        "f9:t!V",
        "8x25_m]",
        "|K:ae",
        "r5f;u",
        "{3L;E",
        "<2RLS7",
        "h^/N=",
        "bB:kM",
        "ZKX^Kc",
        "5O/Gvj",
        "integer too large for long",
        "%s service - stop requested.",
        "r3x$+tx",
        "rsaesOaep",
        "(\\P'{",
        "j*E0{MU",
        "(&xDF",
        ":Q!lK",
        "-P-F[",
        "k\\b[m",
        "Ps,:f[",
        "Running",
        "%?g\"y@",
        ".\"_.}m{p*",
        "5Kqxe",
        "a1FRX",
        "An older version of the client is on the system. Attempt to use the existing vsdata.dll",
        "UX\"4f",
        "CollectBootStatistics No requested events found.",
        "mbCoS",
        "',flN",
        "Z0X0V",
        "zv,&y ",
        "/5ksS",
        "`YY-Rc",
        "=gzOF",
        "OL8}W",
        "&]R8G6",
        "j:'$rx",
        "[zD,!",
        "aejke",
        "3DyJ3",
        ".,^5S",
        "w;efZZ",
        "__stdio_common_vswprintf",
        "b)1iQ",
        "Content-Type: %ssignature;",
        ")TA!c",
        "s['k_",
        "t$$UU",
        "8o9t9y9~9",
        "495O5s5",
        "63*\"Zg",
        "a'H66h5",
        "nGqj7",
        "S6^^x",
        "4>i/w",
        ":zn5r",
        "7[8q8[9q9",
        "yW6$Q",
        "aH5co",
        "eL)'fy",
        "Bq8z>",
        "\"^rgyA",
        "registering NP.",
        "l+]!G|",
        "se-SE",
        "cg,~1",
        "B3oU>",
        "\"0G4R1C",
        "+BB:A",
        "Efw5m",
        "+HpXhE",
        ".=QrYG[g.",
        "=JGA\\5W",
        ";'<C<",
        "OV/?O",
        "|Wfk!",
        "m|StbT",
        "5x6H7",
        "Got a message: ",
        "\\}y{1",
        "format error in certificate's notBefore field",
        ".x]JR/",
        "gT1G0F",
        "383@3r3z3",
        "JL\\y7~",
        "AVNn-",
        "P0LlQ",
        "\"m'K%",
        "uac6.",
        "wYk{8",
        "`yA\"S",
        "+5*.p",
        "8J`(2",
        "'2 &p7",
        "\\s9/R",
        "36%K7",
        "I+-IU",
        "^W[^7",
        "]c7os",
        "pkcs7-digestData",
        "CANT_RESTART_CISCO_SERVICE",
        "{R4%q",
        "`WvEH",
        ".*,Z]b]",
        "uT9D$",
        "Wy5Y3WSQW",
        " 0x99",
        "^KES]",
        "GlobalMemoryStatus",
        "_.,S2F{",
        "/+<N4",
        "YF::i",
        "&I:s+",
        "Z1.Nn",
        "Rg)GXK",
        "d(dFI",
        "\\u%04x\\u%04x",
        "j%QUE",
        "ahKi0A",
        "'*gc&",
        "Registering process name %ls with the Restart Manager.",
        "#\"XG'",
        "/Uwu+",
        "9Y9k9",
        "Vh,]!",
        "/Muwd",
        "55s2)o",
        "!,B`vP ~",
        ".\\crypto\\asn1\\asn_pack.c",
        "6*7K7e7",
        "1-121",
        "32-bit MSVC redistributables were updated before this installation and reboot is required",
        "i~:*qr",
        "C Z8E",
        "KwJd5",
        "ET6sQ",
        "6(6@6V6x6",
        "!jx/$!n'",
        "14u5f|+",
        "}(90r",
        "dvOl6'",
        "EI[}eH",
        "}r@qQno",
        "K|bRIO*",
        "<0|u{",
        "p9)k8",
        "Ve5I>4r",
        "7q)Ap",
        "U^K4A",
        ">,>H>d>",
        "UI_dup_error_string",
        "}&j QR",
        "T$H#L$",
        "gCh@'",
        "j^+[8\\",
        "j*5^C",
        "10151B1`1m1",
        "7e8s8",
        "E8qb?|",
        "BfrBF",
        "PmL:Y:",
        "@1aKe",
        "fxYO5",
        "}ED$c",
        "0qRIitM",
        "Q}R2$!",
        "N1.-6k",
        ":3;g;o;",
        "0x%-8x %02d:%02d:%02d.%03d / %02d:%02d:%02d.%03d",
        "?5?N?g?",
        "Z*upw",
        "0'-<K",
        "]^_gn",
        "smartdefense",
        "Failed to set record field 0 with '%ls'",
        "Ef+Ug",
        "0)00080",
        "lTdN.",
        "fnbl,",
        "jip07",
        "],K'xqs",
        "(%v(E",
        " 'f\\:",
        "RdjgR",
        "$Jgjc",
        "UY$8?",
        "zA<>yU",
        ",eCV#",
        "Sg4.\\@",
        "Wi/jz",
        "6(7,7\\7`7",
        "/!:l#",
        "-,x*-9+",
        "0$0(00080@0D0L0`0h0p0x0|0",
        "n,X9*",
        "bad q value",
        "retransmit:  message %d non-existant",
        "5W2fa",
        "&K`ii",
        "263H3_3j3r3",
        "PSHUFW",
        "1L1u)0",
        "q+iXr",
        "pl1PHl",
        ">#>O>t>",
        "$T<!&",
        "$Q$:C",
        "Failed to unregister %s, reason %ld.",
        "Q6:RZ",
        "M!gtb",
        "a>_7%",
        "%~O&C",
        "GuI*w",
        "0oN)tK",
        "mMr9@",
        "authority and issuer serial number mismatch",
        "failed to get shortcut component",
        "UninstallAuthentication",
        "`hGc9",
        "~4Hl}",
        "AOU-u",
        "GwM|mx",
        "^@!x9",
        "\"H$+e",
        "D$$PV",
        "##uxv",
        "kAyFF",
        "C$F;w",
        "vs?2\"",
        "ZiqfDT",
        "Qh(!#",
        "~@%0MRG",
        "PDIGB",
        "} 5}G",
        "4saFXv",
        "rJ,6Cl",
        "?(?,?<?@?D?H?L?T?l?|?",
        "LOQX&",
        "c&vD3>",
        "?4?[?p?w?",
        "B_l\\@Gy",
        "DeleteFileW",
        "precision is not integer",
        ":.x$'",
        "NF]JyCY@mq5",
        "Vhgl%",
        ")-&Oa",
        "dnHG4",
        "U>5s@t",
        " 0x5d",
        "%s$R$",
        "JRhd@",
        "yUTUK",
        "L$(UWQh$",
        "__unaligned",
        "ASN1_i2d_bio",
        "9 9$9(9,94989@9H9L9X9\\9`9d9h9l9p9t9|9",
        ",g0tc",
        "6_lX~)",
        "+&&LN",
        "saSCc",
        "+b%3X",
        "\\regedit.exe /S \"",
        "Failed to extract %s to %s",
        "_r{]]",
        "VjM<wX",
        "y`#Rt",
        "E{gA)*K",
        ",6u)^Mn",
        "O XhG",
        "P%E*G)%(",
        "PnG_%",
        "SeBackupPrivilege",
        "?l?n>s",
        "<'<C<_<{<",
        "o4X}\"L",
        " >6VK",
        "5(585<5@5D5L5d5t5x5",
        "@zK4D,!",
        "CMOVS",
        "'glryRwwV;;",
        "9L,>I",
        "4e7hi",
        ",D~[(",
        "\"Ns*F81",
        "zvdHC",
        "i\"TfU",
        "error in nextupdate field",
        "QSUVW",
        "root ca not trusted",
        "D$,1F",
        "5@gzR",
        "03Q1q",
        "s8}L0",
        "717Q7q7",
        "=(=,=<=@=D=H=P=h=x=|=",
        "'4osN",
        "8:i?=",
        "|&VvL",
        ";(;7;A;o;",
        "j(~kP",
        "LD26P",
        "n<=n,J",
        "Dzl)V",
        "t$,VP",
        "protectEPAME2",
        "]~^Mc",
        "t\\lHBW",
        "Z@gis",
        "7fsex",
        "0K#3\\",
        "QH-<-",
        "m,j<~",
        "GT=drGU",
        "Ds*|V",
        "\\0F)1",
        "{Gr64",
        "5,505@5D5T5X5h5l5|5",
        "n:\"ml",
        "56*tM6X",
        "{~:,wF",
        "686K6U6",
        "C&>L{",
        "Big Number part of OpenSSL 1.0.1t  3 May 2016",
        "6(646T6\\6d6p6",
        "j)l)q",
        ":)+($",
        "[q,toT",
        "|EOGr",
        "1v&b/",
        ": :,:<:L:P:`:d:t:x:",
        ";-<b<r<x<",
        "#XN Ha",
        "HK+~D?~",
        "+][wo",
        "zx5rE",
        "Q^=w\\",
        "3L$01L$(",
        "Hk,uDu",
        "70787j7",
        "pAR/u.",
        "4.5<5J5",
        "ScvProxy32bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "S4efH+n$",
        "(|~P1",
        "97ucQ",
        "8[,H-",
        "P7B1*",
        ")65ct",
        "C]\"~!",
        "X509v3 Private Key Usage Period",
        "17VM+&?Y1>",
        "~Zv,Q",
        "YO1|3",
        "CNwXr",
        "-gW<o/<!",
        "|RoFvN",
        "JIF8!O",
        "_p&V)",
        "_A_SN",
        "<Y<w<",
        "(;3<g",
        "`!eIb+",
        ">%>Q>",
        "=!=O=",
        "DJC?`A",
        "NdJTZ",
        "d=x2\"",
        "a]f_3W",
        "=V>`>u>",
        ";)<7<M<",
        "id-smime-aa-contentIdentifier",
        "Pk<}Q",
        "0=iiKCfC",
        "o7f?Ap~",
        "*|2xw",
        "'.2(O",
        "~FY=3",
        "@S2zum",
        "KQ?~'",
        " means You indicated in Your purchase order or in requesting the License Key that You intend to use the Products on Your own behalf, or You obtained the products from a Managed Service Provider, reseller, vendor or any other intermediate supplier.",
        "H2pvBZCI",
        "j'S.Y>",
        "6K7a7",
        "`DW\"-",
        "#sqwG4",
        "@uJF*V6&\"<@^",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\RegMonitor\\1.0",
        "oVf+;",
        "b4(YqL",
        "q9:F[kN/",
        "RU6I2N",
        "EzZy_",
        "S_pS.+4",
        "e]y,/2",
        "?$?0?P?X?`?h?t?",
        "WIX_DIR_COOKIES",
        "\\fi2$",
        "PMOVSXWD",
        "'4~8+[o",
        ";.<H<[<d<j<",
        "\"ri-B",
        "error setting cipher",
        ">Hf\"z",
        "# cjz.",
        "SEC_E_CONTEXT_EXPIRED",
        "InterlockedDecrement",
        "?=IzA",
        " uo X",
        "e*s5YYx",
        "E(|xY",
        ";F;};",
        "I@r@a",
        "D$ h ",
        "x=[F9",
        "'oFpF",
        "1$}nC",
        "qz~x4",
        "ACCESS_DESCRIPTION",
        "h\"v}>\";",
        "*;,h8",
        "3pqPpU",
        "ilY*-",
        "?e9Eo",
        "Upr=l",
        "VS{#o",
        "Mz/#>",
        "4M^o2",
        "!hqTU",
        "t$ h(",
        "=+=2=7=V=f=t=",
        "A3&#),",
        "MXbfiy{o",
        ",]5Hf",
        "SOFTWARE\\Classes\\Installer\\UpgradeCodes\\C54844634E77F0442BFCB263CEDF78EF",
        "&/D;a",
        "|0zgR",
        "Removed key ",
        "XL%5I",
        "9'(9z",
        "PB#[y",
        "ssl_verify_cert_chain",
        "Csf]}",
        "(`$|w",
        ", Tel Aviv,\\~67897 {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Israel{\\*\\xmlclose}{\\*\\xmlclose}.",
        "h=mwy",
        "!{BfN",
        "?1?R?",
        ";;;P;Z;",
        "\"b\\v% @",
        ";6q&;+",
        "G:g3h",
        "t|hp9L",
        ">*RIw",
        "I!5*O",
        "D#+Y ",
        "Kfr.u",
        "hYZm5[",
        " EEXr'~",
        "<iCEE",
        "Invalid seek",
        "Np/xv",
        "pD$yA",
        "UBZZUb-",
        ".NPqw",
        "L7=^;0+",
        ";T$,s=",
        "}ilvMg",
        "SEC_E_ILLEGAL_MESSAGE",
        " o)+$",
        "`_O/<O|N[S}",
        "aRecord",
        "IlA)]",
        "v6RA9",
        ":v9/\"x*",
        "~HVt4x",
        "`)Z;fq",
        "o[5Dw2/B9|,c",
        "_<&a`",
        "kHi!o",
        "\"$dV;",
        "r7,Fd",
        "pHl\\tHl\\t",
        "%6%-/",
        "*:H7Y",
        "e]3XgEZP#t;",
        "jpjgj",
        "79D;>ACG",
        "P912I",
        "j]*WZg",
        "WhlM!",
        "3h4l4p4t4x4|446",
        "[VSDATA] FwConfigChange: skipping adapter %d - \"%s\". No IP configuration",
        "aECDSA",
        "zB'd77",
        "};#mD",
        "FQI|H",
        "#v729",
        "V)PPV~T",
        "1\\j$T",
        "ImGe]d",
        "CXM\"\\",
        "JK\\=4",
        "O&\\k*",
        "+ 1I.",
        "eBGWvH",
        "I|79E",
        "7fFIJ",
        "3NTrE",
        ":#:/:U:a:o:",
        "989S9",
        ".?AVnoncopyable@noncopyable_@boost@@",
        "(#}uG}",
        "J-uOkA",
        "2!2>2",
        ",b1~K",
        "^7NYs",
        "0^dP#=",
        "=#=?=[=w=",
        "G_tR%5",
        "t%SRV",
        "8`pf]",
        "N2Zm&",
        "%UE&L",
        "EPS upgrade product code is not found in the registry",
        ".?AVThreadInternalContext@details@Concurrency@@",
        "F Y9V",
        "GetACP",
        "sd{@c ",
        "<Z_{W< ",
        "f8dq6(",
        "Fm2l3",
        "3y@Bh&",
        "gW#}_",
        "2D3!4?4X4c4{4",
        "=H>b>",
        ",IX d",
        ".D'4.",
        "_]^[Y",
        "?oSWb",
        "EC_GROUP_check",
        "5qeD0",
        "70{~O",
        "`oY/)",
        "$>}}%L",
        "\\Py%Y4",
        "1)20292c2v2",
        "7XUa+Em",
        "G(]0E",
        "u SVW",
        "jnj{j&",
        "G849*7",
        "d>e@/",
        "not a stream",
        "7$8(888<8L8P8\\8l8|8",
        "v/U)z2",
        "r\">Lw2x",
        ";M<q<",
        "error number %ld",
        "1(1L1d1",
        "p~iJ)4",
        "7GZ.W",
        "@d.bH",
        "0!040o0{0",
        "vK5\\ODg",
        "=aW;j\"",
        "\".z7M",
        "SCRemovePrepare finished.",
        "=4>T>t>",
        "(*</Q",
        "[,q=Rx",
        "5%5b7",
        "setEventGroupInVSConfig",
        "Ex#XFB",
        "sSRN'7",
        "DS_InstallFACDriver",
        "SSU1'",
        "U\\}z(",
        "wq`r!@k",
        "gQ=7u",
        "?U2[8",
        "`fF$H",
        "<MY1@",
        "*[[b_%",
        "lstrcpyA",
        "[|_g[&",
        "\"eZ%ss",
        "'>K?2w",
        "B\"8A`",
        "g?yl'",
        "7g9m|",
        "8(8H8T8|8",
        "Zn]NQ",
        "r.p'b9",
        "DHE-RSA-AES128-GCM-SHA256",
        "7 7@7H7T7t7",
        ">mz,<",
        "kxbeXB?^",
        "_76n,",
        "45w_%4Tr",
        "text:",
        " /Uop;",
        "CB^tl;ce",
        "z'(Dl",
        "9@)Xe",
        "[ovlW",
        "3x9m1",
        "jdjfj*",
        "*<UF)",
        "p^T|>",
        "j\\nF)",
        "<VdDo[",
        "Cz0m'",
        "%hS4Z",
        "bLx[os",
        "X_wJM",
        "oXF,*b",
        "wrB-/",
        "rFntz",
        "D%u6'",
        "Ku;/#",
        "sWixRollbackInternetShortcuts",
        "oYv<<rBK",
        "^#\"\\6",
        "A<,>)",
        "((28iyg",
        "N(@Wj",
        "cj?=O",
        "N/rUR",
        "weNt4",
        "g3%<&l%",
        "~<on)",
        "z3x@~",
        "DefWindowProcW",
        ";!\\m!",
        "8M;M<M=M>M?M",
        "p\">4G",
        "4c8.W",
        "787D7d7p7",
        "|9X`:",
        "3(5(6(9",
        "V.y`q?",
        "loading defaults",
        "i*B[N",
        "0#0V0b0{0",
        "4[5d5",
        "=>%'$yrn",
        "4ew\\8$",
        "7$~y,b",
        "k*jBl",
        "\"[ed4",
        "(Z?on|",
        "5=5E5M5U5]5e5m5u5}6",
        "VSInstallerLogonEx: cannot log in",
        "english-caribbean",
        "]?-LHx",
        "E,\"15",
        "}]+[s/",
        "}IW^I",
        "C6\"#}",
        "AoiXI",
        ":6XZZ+",
        "Ds xG*",
        "n''sM1",
        "CloseApp enumeration error: 0x%x",
        "7(7<7O7]7h7x7",
        " lGKF",
        "8kZ\"@c",
        "OO h-",
        "/$(OF",
        "cHWAVh",
        "*.rdb",
        "<_db.",
        "Z5s39",
        "@tITKO",
        "GE{|T",
        "rb8f=#",
        "~D/e(",
        "[b#*2",
        "@W}dk",
        "%0L0r081_1",
        "'-8Po",
        "6W4~SK",
        "uo/&k",
        "<?xml version='1.0' encoding='UTF-8' standalone='yes'?>",
        "UninstPwdSalt",
        "Bde4oK",
        "Sg}em",
        "fN\\r$r^`",
        "211117131908Z0/",
        "= =8=<=@=",
        "`G,U)",
        "y[+~Y",
        "CAS}zZ",
        "EDu+@",
        "`bADad",
        "(e[>t&",
        "n!i|\"",
        "e2O8g",
        ":HvJvLvNvPvRvHu",
        "E+qBa",
        "AwB,H8}",
        "{I9gqr-'",
        "YK_U@m",
        "bsn7jd",
        "LDrWF",
        "xyc%*+",
        "Fv{;Q",
        "-O;gyUl}N.",
        "363I3a3l3",
        "M/f8r",
        ")B5o&",
        "mVSfAil",
        "TzFw[",
        "oZ\"'nx{",
        "hiNJn",
        "}&[#$]wi",
        "1'2I2",
        "UmsThreadYield",
        "a\"n&:>",
        "g2yc6",
        "Al+H\\",
        ">ef> ",
        "ZKVKq",
        "x*SVW",
        "t$$QRP",
        "9\\)t8Pxyk",
        ":KbBz",
        "F`F>!",
        "v6_\\J",
        "u#S89",
        "c3]/el",
        "s|8Ws",
        "X4(J=",
        "n%]FW[",
        "yQ26Y--",
        "MAIL FROM:%s AUTH=%s SIZE=%s",
        "QeajL",
        "+bX9qW3",
        "[=]z@",
        "(H';wypP*",
        "@l'f(9#D",
        "S`r+-=",
        "$=Qh13g",
        "CHa-c",
        " This provision applies to Product acquired directly or indirectly by or on behalf of any Government. The Product is a commercial product, licensed on the o",
        "/)/i/",
        "\\zlxeap.dll",
        "'M(]~$",
        "nSw}Z",
        "3F<8eS",
        "|>]yIx",
        "X5O.F-",
        "414I4",
        "JHEmo",
        "s}0K0gN",
        "<@rQ.",
        "0,0C0X0o0",
        ";m{0q$[",
        ".^x\"dP",
        "EpabService",
        "Jt*E3f",
        "int_err_get (err.c)",
        "TS_CAM_UPDATE",
        "r$|#QS",
        "HuH7c",
        "A>XX6",
        "J~QqC^",
        "J \"}R",
        "W8H{ 0#",
        "2O3c3",
        "Q<9#1H",
        "+r@aM",
        "wc1UN",
        "XX!)r",
        "aXG:EQ",
        "POP3.",
        "yB/hy",
        ".data",
        "INST_TASK",
        "^\"K$R",
        "jTMUkP",
        "LE`_$",
        "RegQueryInfoKeyA",
        "2\"3p3",
        "failed to retrive file version info.",
        "MD1|h",
        "$W}+`",
        ".0?k9",
        "@GKNfTk",
        "Uhh-\"",
        "FSsx$",
        "IGJGKG",
        "dicN`",
        "appendChild failed",
        "9C:I!",
        "ZL\\?Y",
        "uy5w,5(",
        "5 5&505B5H5^5j5y5",
        "!_M/U",
        "A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.",
        "9#DnUN",
        "Q^hdm",
        "\\`i&_g",
        "Xk!(Up",
        "error setting certificate verify locations, continuing anyway:",
        "!E#T?",
        "Yzr\\I",
        "7I-|e+",
        "FormatMessageW",
        "Helper::stop() -- returning true",
        "7+7y7",
        "EnterpriseChecks_Disabled.bmp",
        "#;v-T",
        " jv%Q",
        "2]$QDD",
        "7!YRL",
        ")L.-M@",
        "33j9BAp",
        ".!.a.",
        ":v?y86N",
        "\\Ypqa",
        "i2d_RSA_NET",
        "@vu.{",
        "8)9$:*:N=l=",
        "A,W$L",
        "Tm!Y.|)",
        "EpLqWI",
        "!g!HV",
        "IAIRVJ",
        "~';_t|%3",
        "oCs?6",
        "invalid label",
        "Wait complete for event (only):  %s",
        "sGqRn",
        "~t&s0Tw",
        "G'as)DK",
        "+}2v*",
        "B!F\\(",
        "^m07y",
        ":X<\\<`<d<h<l<p<t<x<|<",
        " 6XVk",
        "protocol_version",
        "invalid inheritance",
        "aIGwi",
        "l>-T{",
        "mOuT=",
        "uqg?[z",
        "]vRbk\"",
        ".K\\]&",
        "`-Ss+",
        "9D$$u0",
        "?3?C?S?",
        "l~C\\Z",
        "=#>U>",
        ">o$m ",
        "^j/c1",
        "jpjvj",
        "f x(_",
        "~Py:0",
        "#E(zG",
        "keepalive",
        "0F0i0",
        "SVW8A",
        "\\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid6823349 \\chftnsep ",
        "Product for the purpose of connecting only with a duly licensed Check Point product, in accordance with the functionality, as described in the accompanying documentation for which You have paid the applicable fees to Check Point, and only within the desig",
        "\\drivers\\vnasc.sys",
        "uHjIht",
        "'^tOmd3",
        "*Bk'[F",
        "1;rt6>?D",
        "ypn0D(",
        "CopyRolloverBlock() failed.  Deleting zip file, ",
        "#%xZx",
        "182=2B2",
        "9!:I:p:y:",
        "d}5me=C",
        "Z8Q9w",
        "MR-=I",
        "I@Vp/>",
        "rJ(U0",
        "mbSz^",
        "x|jR4",
        "m=yNqpz",
        "=vQvev",
        ".IMg\"",
        "H+:Vm",
        "The string is too long",
        "4QwV8I",
        "S_OSq",
        "'QZ#&*",
        "`f4N!o",
        " RTSP/%d.%d %3d",
        "A<lt'<tt",
        "fMB6[\" z",
        "eXRs&",
        "9MJ)JN",
        "\"3:9\\",
        "VD`rk",
        "n2/v3",
        "friendlyCountryName",
        ".\\crypto\\pkcs7\\pk7_doit.c",
        "VsNoFileRedirect::s_RevertRedirect",
        "L$HQW",
        "[KO$>$-",
        "7L7g7{7",
        "bcrypt.cpp",
        "~N,1\\a",
        "UOUUUUPO",
        "+TWxYm",
        "LLLLLLLLLL333",
        ":0:L:h:",
        "7!7'7-73797?7E7K7Q7W7]7c7i7o7u7{7",
        "65PE#:",
        "\\sa?O}}]P",
        "$NGKJ",
        "c{NWA",
        "_DT\\O",
        "n5U&'",
        "EC_POINT_get_affine_coordinates_GFp",
        "'6%4T(",
        "KPkG}",
        "o-dvQ",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  28",
        "|SSWVV",
        "k]j{mb*Z",
        "0D0R0`0n0s0",
        "xwpwpp",
        "0;2r2;4",
        " e~rn",
        "0$)~Q~",
        "u/RWQ",
        "W;()f",
        "LOCK ",
        "<0<7<F<P<j<q<",
        "8$808P8X8`8l8",
        "INSTALL_EAP",
        "QXUbCTC,",
        "w+bXBa_",
        "4R]0Sl|",
        "\\f1\\fs20\\insrsid5000668\\charrsid15169477 T}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 o provide Check Point or its partner with sufficient and safe access to your facil",
        ")x;9T",
        "xx1Hz<q}",
        "&Ro3m",
        "/p,$^*eX",
        "wjEO HgN",
        "rr[$rt-",
        "aNsU\\b",
        "failed to add data to rollback CustomActionData",
        "J|&79:hJ",
        ";kLyZ5",
        "`&RlFg",
        "QpC3]",
        "< <$<(<,<4<L<\\<`<p<t<x<|<",
        "#cJKW",
        "r4zyP",
        "#[}|[v`#",
        "F*}GQ",
        "U2$Eip!g'",
        "$L^207)G?",
        "OVg_FzD",
        "384c4",
        "|YOv.yJ",
        "5F5S5g5",
        "5$5,545<5D5L5H>L>P>T>X>\\>`>d>h>l>p>t>x>|>",
        "[y=&\"",
        "|6Zq-J",
        "2gg\"e",
        "%.Udd@Z",
        "(t3F]&^H3",
        "5..h/^",
        "4d/#n)E%o~",
        "o&{-H",
        ">_Z\\xS",
        "\"jPzI",
        "fqt_j~",
        "-http://ocsp.globalsign.com/ca/gstsacasha384g40C",
        "X!S6w",
        "=NmBG",
        "@lZ*Y",
        "|8>hg",
        "=0>P>x>",
        "D$<SP",
        "y}\\J_^",
        "YVG=Z",
        "k-c;/H",
        "%WdS[",
        "[mb]X",
        "nonce not returned",
        "ucHr!",
        "v/Z c",
        "9jrU`",
        "INT_OVERFLOW",
        "!#8-0",
        " !\"#$%!&'(  )***)+ ,+-./-",
        "SealRootPagesInStoreDBs",
        "{khe<",
        "LSSc?zR",
        "}BM> ",
        "U:o7}9.2",
        "!XC)(,=-",
        "TakeOwnershipOnFiles: failed to take ownership on %s",
        "I8A.f",
        "@rG`+{",
        "failed to set string in record",
        "W>v<`",
        " Base Class Descriptor at (",
        "MWX_8Y",
        "}Q^!c",
        "9J1.4",
        "#yQFN",
        "R6016",
        "Vh4T!",
        "ssl3 ext invalid ecpointformat",
        "NISTP256_PRE_COMP_NEW",
        "99JNH",
        "Vjbh@",
        "Plugins::UnregisterSC:  Unregistration failed.",
        "2s/PFY",
        "Y^?sv",
        "Name=PiReg",
        "gT4X>E{",
        "Number of redirects hit maximum amount",
        "Ut#KMN",
        "5lq@|",
        "Od_^]",
        "HZyaLX",
        "SSL_use_psk_identity_hint",
        "Za@{}P",
        "606@6L6T6l6t6",
        "Cu&#'",
        "+h 9GfP",
        "b0?xc",
        "Shxo%",
        "cTP9G",
        "8B8r8",
        "? ?8?@?X?`?t?",
        "/g c4",
        "3 3$3(3,3034383<3@3D3H3L3P3",
        "setAttr-IssCap-T2",
        "NcZX!Z",
        "h,'qO",
        "_6m;{N",
        "PtC|w",
        "Found FDE InstallProperties",
        "-3n<_x",
        "ComponentId Value is %s in Subkey %s ",
        "#SbP-",
        "chinese-singapore",
        "2]b+^",
        "vk~;j?",
        ".^{b7",
        "\"~|$z",
        "SSL: couldn't create a context: %s",
        ";M<[<x<",
        "pE<je",
        "I=R{]",
        "#0alk@6:",
        "tmZIq",
        "PKQQ>9",
        "t[aOBg",
        "5>mn8",
        "Bsv[S",
        ";-<T<",
        "4RZ X",
        "ar-MA",
        "bO=T~",
        "b}RB2+i2x",
        "p4q}C",
        "OBJ_add_object",
        "$NXeFz~'",
        "ZoneLabs\\zlquarantine.dll",
        "sN?ak",
        "xyu1i",
        "s4mkZZiQ",
        "Ebqxy<",
        "LkvMN",
        "QA'1>('",
        "$vnsE",
        "+S=fxy",
        "!expected_len || s->s3->previous_server_finished_len",
        "GlobalAddAtomA",
        "failed to set hresult code into error message",
        "4*4/4=4",
        "555>5G5",
        "Gy9LV",
        "(}eC]",
        "j Pj@",
        "}Qs`?Z",
        "U0q#,",
        "B^R@T",
        "1'1C1_1{1",
        "F4rY1",
        "EnumWindows",
        "#I$I6\"f",
        "+-qHX",
        "8`<x4",
        "U0PEv",
        "PFMAX",
        "BAM8/",
        ".rdata$CastGuardVftablesA",
        "JXe)g",
        "\"9\"a\"m\"",
        "RDO:6",
        "Tde~\"",
        ".?AVscheduler_worker_creation_error@Concurrency@@",
        "u:3/5[",
        " x+dY",
        "!f(Xu",
        "Q0,jU",
        "__DT)k",
        "|S)M=",
        "41s&w~R",
        "fE.n}(I",
        "5,5<5@5D5\\5l5p5",
        "|n.:!/",
        "899|9",
        "<|Mw{",
        "CLIENTUILEVEL",
        "kGr{d",
        "1PrSr%",
        "5_96*V",
        "OM4i$",
        "&1Ts(",
        "XZ@>x2",
        "vJt^`",
        "tVVhdY!",
        "1WE~2",
        ":6:F:`:f:",
        "failed to add app to the authorized ports list",
        "%&lvb$",
        "FKy{p",
        "CGfl49",
        "=/=b=j=",
        "unknown SecureObject.Table: %ls",
        "lre'b",
        ".\\%/e~",
        "X9.62 curve over a 208 bit binary field",
        "DISABLEVNAACTIONS",
        "PreInstallClean:  file: %s, found file = %s, ref count = %d, fileRemoved = %s, reg value removed = %s.",
        "ptU5}",
        ".fV]G",
        "A1-GC1",
        ">~$+t",
        "*OhM+;",
        "5*575",
        "T$I@7",
        "q2g#]",
        "vg$=i+",
        "SSL: couldn't create a context (handle)!",
        "OO!OBn",
        "[SAPI] ",
        "$sSKW:",
        "t7)F3&",
        "bsx_\\3",
        "718;8X8i8~8",
        "&,00Y5",
        "5;`Jd",
        "UYhW\\",
        "klwtp.sys",
        "343M3f3",
        "5:C/L",
        "<#<)<:<K<U<c<~<",
        "l8RtO1:q",
        "y{({ ",
        "[] l.)",
        "RK\\+t",
        "Py Ni",
        "DS_CopyToSystem32 started.",
        "KkF[v2",
        "<f(w2",
        "\\H'FBa",
        "9>5i%LC",
        ",,LrX",
        "0V1e1m2",
        " @1#y|T",
        "n}ix2",
        "ms'ekE",
        "PBE-MD2-DES",
        "$kNgm",
        "MS_<#",
        "j|hDx#",
        "@)^ef",
        "&yQ+ONf;",
        "8p\\8N",
        "GrEUHUN,+",
        "T~FbT~Fb",
        "2IO/G",
        "FEW7s",
        "YKtuJ",
        "1T<~{E*",
        "QueryCredentialAttributes",
        "7\\7U5y3",
        "yM[?oC",
        "CVPND",
        "17wJY",
        "pwWvK",
        "7Q8s8|8",
        "*x!Js",
        "Qe\"Fi",
        "1b4R0@",
        "a/#b;",
        ");(;0",
        "=*H^M",
        "d,(~|",
        ")RT)+",
        "<0w{H",
        "R6<?R",
        "qb9Rr",
        "XZ9Ct",
        "8?;`/",
        "Uhp!#",
        "Gxa\\I",
        "S1tmq",
        "J}=zX",
        "Failed writing header",
        "DosDeviceC after the strncat: %s",
        "u!Txn>W",
        "==>z>",
        "JJ?dXOq",
        "gXg[;w",
        "CA Issuers",
        "wizp{",
        "bi0k`",
        "j--r=9",
        "reset= 30 actions= restart/500",
        "FAIL: Can't get process token",
        "DXJB<",
        "|Hp*q",
        "kX+]n",
        "Vh@D!",
        "Y__^[",
        "{~R!/c",
        "%sHP `",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\SharedDlls",
        "%!ey8",
        "=6=R=n=",
        "h}qoxa",
        "?w3tp",
        "testkey",
        "~#AtH",
        "PBE-SHA1-RC4-40",
        "0I)\"Aw",
        "\\zonelabs\\upd_core.dll",
        "yr5M!?",
        "UP1?zX'D",
        "n@D50",
        "c;xxh",
        "\\PKdz",
        "L$<[_^]3",
        ",nPE,",
        "@:X%U",
        ":U*Gt",
        "J u%D",
        "5Ku|v",
        "f*#b,ZN:",
        "H;_Xl",
        "a'cI<I",
        "=1:2Sr",
        " 0x36",
        "j Pj Ph+",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 .4\\tab You warrant and agree that You are not: (i) located in, under the control of, or a national or resident of {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Cuba{\\*\\xmlclose}, ",
        "NR-F'",
        "i,hqY",
        "q\"q&q*q.q2q6q:qBqRqVqZs^9m",
        "y+hL`",
        "\\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid9252096\\charrsid15169477 X}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid3737333\\charrsid15169477 CLUSIONS}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid526510 ",
        "DxP~?c",
        "7Y8v8",
        "%y{\".<",
        "X509v3 Policy Constraints",
        "(i$hS",
        "g.!\\Z",
        "http://ocsp.digicert.com0\\",
        ";|$Lr",
        "EE;Paes",
        "|aTXe&",
        "zfThP",
        "G7v%B",
        "u@uAuBuC",
        "t$TW3",
        "9IuM)M",
        "mBDT{",
        "T{,-@v",
        "A~9Pyzaf",
        "Iu%IW",
        "id-smime-aa-equivalentLabels",
        "wBQrX",
        "TLSv1 part of OpenSSL 1.0.2h  3 May 2016",
        "[END EXCEPTION]",
        "R=dI|",
        "s'!WasR?",
        "[N3r@",
        "@)-N|",
        "8,*iuU`",
        "#GST}",
        "#4Z1C",
        "&tf1\"w",
        "].Y\\fq",
        "Failed SetEntriesInAcl Error %u",
        "*,w#aP",
        "<&<C<z<",
        "M,WQS",
        ".?AVstl_condition_variable_interface@details@Concurrency@@",
        "u(jOh",
        "(bs{V",
        "OR#y~",
        "Nf?R$",
        "9TVMh",
        "og_Y ",
        "Um_WxCg",
        "Rs|d.%",
        "<4<d<",
        "SchedFirewallExceptions",
        "B[.cf.",
        "\\u%04x",
        "QnC3{",
        "777S7o7",
        "(J#=1l,",
        "'v+'Y",
        "2:>1\"",
        "SVhH? ",
        "Delete in-use files",
        ",#:{-",
        "(#6[$v!rOJ",
        "{CLo:",
        "m-0ye",
        "334@4X4n4",
        "s74z^",
        "AUTHENTICATE %s %s",
        "9TWyg",
        "i2\"KgD",
        "F5[Z2",
        ")8bdf:*E-",
        "H8a2e",
        "j9l7I",
        "T|'b\"@a3B",
        "Odww+-g..^88",
        "TIbQD",
        "jyS(_",
        "W+SiY]Q",
        "$:o$qx+",
        "D$/Pj",
        "'8'Y&}w\";&u'",
        "j>nZ3",
        "PEM_X509_INFO_read_bio",
        "/h2tM",
        "`b#DM",
        "qnXE[",
        "4~<zv",
        "?{yh=",
        "N]SI.$",
        "+fNMl",
        "?:?t?",
        "=$%!e",
        "g\"`,q",
        "2$2,282X2d2",
        "AcAjAkApAuA{z",
        ":0.fK",
        "aY=&4",
        "Ymaub*",
        "^NGFnl",
        "Wd(~5+~",
        "/9.@1S",
        "l#T}[E",
        "X12w0",
        "<u?F'm",
        "; ;(;0;8;@;H;P;X;`;h;p;x;",
        "HKgxM",
        "7:7V7r7",
        "EKv2D",
        "\\^9$p",
        "estQ4O*",
        "name.fullname",
        ":$:,:4:<:D:L:T:\\:d:t:|:",
        "~<^Vx",
        "FNINIT",
        "invalid object identifier",
        "%E8cp#",
        "Q{A%&",
        "l</Yt",
        "6Xx\"2&",
        "/_[FlzJ",
        "R4:Qqh",
        "JC3^O",
        "/*+xPJ",
        ")iul{",
        "I*,(sB",
        "l:D7I",
        "nn-no",
        "#w[}+",
        "T$x3T$@",
        "H+5 )",
        "AppEvents\\Schemes\\Apps\\SR_GUI",
        "QEOjVe",
        ";c%g`a",
        "'jOr:['MJ",
        "7:N-S",
        "':>Zv",
        "7 2P1",
        "<A<v<",
        "0l>WQ",
        "KhRDy",
        "D!B6P",
        "E@s[a",
        "tn98x",
        "e1!>v28",
        "/.Dy=>",
        "CANT_STOP_ATT_SERVICE",
        "C4}J9",
        ">SKc,",
        "9'9=9C9",
        "1wQ(P",
        "0_bRj",
        "4*5Z5",
        "Ve;lR7+",
        "sdjEhX",
        "0j\"aI@",
        "Nn))h",
        "CWkK$k",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\json_parser\\detail\\write.hpp",
        "~8%X4",
        "nkb(Jc",
        "BaMH\\QjN",
        "UninstallFW:  UninstallFW() in vswmi.dll failed.",
        "1.2.840.113549.1.9.6",
        ";D;U;^;z;D>h>C?]?",
        "q8B}[:",
        ":!xNy`",
        ".?AV?$collate@D@std@@",
        "dFOM[",
        "0(00040@0H0L0X0`0d0p0x0|0",
        "0V2h2",
        "H]+E\"jZ",
        "ExecXmlConfig",
        ":A:F:s:x:",
        "mV?(X.",
        "8:8[8b8",
        "QX{v%-",
        "9#TIv",
        "54686H6L6X6h6x6|6",
        "9#:q:",
        "X)f`|",
        "5[&Prt",
        "c!-cx",
        "RegistryFileExecute:  RegistryFileExecute started.",
        ";v]-e",
        "q1GYf",
        "-VQ~8",
        "jQm2+c",
        "\"8%]z",
        "6$GG9J",
        "[.q\"_*",
        "b/n26@",
        "1g3\\.",
        "rI`z&",
        ".jy>5w",
        "9^Bpe",
        "9(0KG",
        "Dfw't",
        "Lledf$",
        "7?8e8x8",
        "G2NJ1X",
        "`Ep\"J!",
        "1}0-I",
        "CANT_STOP_NETCFG_SERVICE",
        "#)a5T",
        "Could not set TCP_NODELAY: %s",
        "Content-Disposition: form-data; name=\"",
        "y!B4h",
        ";*<V<|<",
        ":,;0;P;p;",
        "?~dBZ?",
        "K:N*m<N",
        "^chFc,",
        "gx$/0C",
        "Failed to receive SSPI authentication token.",
        "wtQQSWP",
        "FeatureAntiSpam:  RemoveAfter:   cleaning files in",
        "s:{{Rj",
        "G^.da",
        "jjjkj",
        "OIZ1J*/",
        "VCITs[",
        "2{khJ",
        "]z.DD{",
        "cw1|T",
        "1>1r1",
        "1Sps+",
        "w%' i",
        "Delete file: MsiViewClose",
        "LP.I5",
        "7C:A<",
        "5>b$D",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\preinstclean.cpp",
        "OUT_OF_MEMORY",
        "k&Oa\\jH",
        "MZ>?PR",
        "~ \"FK;",
        "?JNni",
        "3 gqB",
        "EncryptMessage",
        "2.3m3",
        "SvcKba",
        "{l_~H",
        ">{COSc!",
        "H^P{(",
        ",A#+s",
        ":Sc>W",
        "BJ[qA",
        ";$;*;0;6;<;B;H;N;T;Z;`;f;l;r;x;~;",
        "FWUpgradeAfter:  Register plugins",
        ">7>F>y>",
        "Install",
        "5J7i7",
        "k7R2t",
        "9](SS",
        "b9mDY\\$D",
        "Yd9(`",
        "<#<'<+</<3<7<;<?<N<",
        ">;?D?~?",
        "uWKL5",
        "W({N$0",
        "By$O6!",
        "33333333)\\",
        "+Vw|bG",
        "Reboot was not required by custom actions. Cleaning MSIRUNMODE_REBOOTATEND",
        "epX*d",
        "2!aFj",
        "%s\\Microsoft\\Windows\\Start Menu\\Programs\\%s\\%s",
        "kze$0",
        "!R9>$&$km",
        ".*(6&",
        "Q*r@b",
        "P/@,F",
        "I0@r[$R$p+b",
        "z^^z%",
        "fH**;d",
        "~r+z4N",
        "n`IH)",
        "caIssuers",
        "#RgU]$",
        "1&Qr&(",
        "7&7J7}7",
        "^O=;(",
        "DS3)](!C3",
        "RegisterSecureAccessDSM:  Updated SecureAccessDSM CLSID registry.",
        "Zsjc2",
        "Z5AkK",
        "\\1d1p1t1",
        "Process limit reached",
        "MO$-KM",
        "$&YL[",
        "Failed to read insthelper.exe. Error=",
        "%SN^8",
        "l1shoe",
        "D$lPh",
        "vz8t6",
        "BfXTo",
        "\\$ 3D$",
        "RC5_CTRL",
        "fY-N3",
        "x1f34",
        "6,646<6L6P6`6d6t6x6",
        "0S1X1c1",
        "s warranty for Hardware products is described in the Limited Hardware Warranty page attached to this Agreement.",
        "DefPolExtract started",
        "FileVersion",
        "P_dv ",
        "yV\"dG]",
        "?n![MP",
        "Failed to acquire credentials.",
        "NV$8W",
        "{Z6M=",
        "init failed",
        "'Z=9Q=",
        "2z%(5",
        "?X?j?",
        "7iQ8L(",
        "Rewinding %zu bytes",
        "PPqEe5FnL",
        "$e4L]",
        "|@7;~",
        ">9>U>",
        "o~Z u",
        "@]wu'",
        "m0qc0r",
        "D:(A;;GA;;;WD)S:(ML;;NW;;;ME)",
        "~(!tU",
        "CY0>|",
        "lRBztE",
        "HJq\"^",
        "CMS_RecipientInfo_kari_get0_orig_id",
        "?\"?&?*?.?2?6?:?>?B?F?J?N?R?V?Z?^?b?f?j?q?",
        "CSzg;",
        "03^R\"",
        "2b3N|",
        "<N'qX^",
        "dh$rMi",
        "##k^c~",
        "bad type",
        "Udc*>",
        "JJVjj.",
        "A#3'~n",
        ".NET Framework",
        "strrchr",
        "xp9&3",
        "2?*8|J",
        "Y'PU69",
        "g=#3&N+E> Q",
        "S<on u",
        ":]://%[^",
        "4\"#M~",
        "_t'fr",
        "aM.rk",
        "jXP| ",
        "; ;(;4;T;\\;h;",
        "n-wiv",
        "a!jo^",
        "3jgeQq",
        "SLw&89",
        "JUQEIUB9",
        "VhHXG",
        "nfmUM",
        "PV~3P",
        "LCme#",
        "N(.66",
        "i`vLX",
        "tI9{C59",
        "TVDBPj",
        "T$D3L$0",
        "X)I#}B+T",
        "4>xyw",
        "failed to decode string into stream",
        "RPWVhp]!",
        "$FzSN",
        "QRM{r\\i",
        "ZT2:Qv",
        "/k~jI",
        "}%J|B",
        "5T5v5",
        "p %6Y",
        "wo[ko",
        "e&DB$Wy",
        "Zr^.AN",
        "6 B_q",
        "XSm!YO",
        "IV#i ",
        "bnir.",
        "Dq)u|",
        "c}7'd",
        "mS8Z[",
        "S;]lqv",
        "@^[_]",
        "<&<,<\\<",
        "['tAh",
        "[PDF,",
        "\\sbasedon0 \\snext47 \\slink48 \\sunhideused \\styrsid15298478 footer;}{\\*\\cs48 \\additive \\rtlch\\fcs1 \\af0\\afs24 \\ltrch\\fcs0 \\fs24 \\sbasedon10 \\slink47 \\slocked \\styrsid15298478 Footer Char;}}{\\*\\listtable{\\list\\listtemplateid211312800\\listsimple{\\listlevel",
        "SILk%",
        "d4\"\\4X",
        "o^#R*O",
        "p[B.d",
        "rvcV6",
        "1\"2O2|2",
        "252N2S2Y2c2i2q2",
        "jwjxj",
        "wrong certificate type",
        ";V$^t",
        "ALERT_ANALYZER",
        "mONi;",
        "NO X509_NAME",
        "566P6h6",
        "qRKLj",
        "E@~Uu",
        "z<ti?14",
        "{E^@}/",
        "5yJ6%",
        "qBbwcG\\VU",
        "2a~OK",
        "$H*P?dvH",
        "CANT_GET_DATABASE_HANDLE",
        "p+J\"5J",
        "failed to get handle to kernel32.dll",
        "&;8c~,",
        "^U]%a",
        "8!'Ng)",
        "},C';i",
        "mH?c)",
        "B 12C",
        "iqmp not inverse of q",
        "Xr2{L",
        "FDE_Rollback starting.",
        "j*bch",
        "au<+FW",
        "Un-Xs",
        "'3y7^?",
        "=0=P=\\=|=",
        "<e=crE",
        "$!2euV",
        "*k#vP",
        "[aDnY5",
        "T Vlm",
        "^i\"vj",
        "{9x\")",
        "747V7",
        "Rx5R?q",
        "@R64.!f",
        "55xipP",
        "vp`N]4@",
        "F?uQV",
        "Time-out",
        "v.PB#*Wx&",
        "8q~ !",
        "reject",
        "RegDeleteTreeA",
        "l7LS_",
        "QOeO)",
        "Xd=+'v",
        "could not load the shared library",
        "40494U4",
        "h${gx",
        "<5[,.",
        "eu!eE",
        "c y{`",
        "xjvK0",
        "hqg\\&",
        "_updateStatusStr@12",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\preinstcheck.cpp",
        "Gjvvk",
        "OCSP_sendreq_bio",
        "000b0u0",
        "Y0R4,m",
        "6B)3D",
        "Failed to open CaScript: %ls",
        "h2]H>j",
        "001>1X1",
        "3ekkA",
        "J(24-",
        "(87g^",
        "@l5Kak",
        "Q=DT,T+ac",
        ":c|w{",
        "[``]QE",
        "tls client cert req with anon cipher",
        "en-gb",
        "G8sc.4",
        "P>e% ",
        "^Im~:",
        "es.es",
        "&S~*#",
        "|brrp",
        ")0. )",
        "tx$OI",
        "#\\$,3",
        "nsSslServerName",
        "4-0=Z",
        "7RIQ[",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 P}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477 roduct }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 once TAC approves the RMA}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "q$d1x",
        "_;74-",
        "3Ul,q",
        ",d)Eykd",
        ".i\"JB",
        "H1MrS_)",
        "fj5fF",
        "U7-Mx",
        "mn`I:T`H",
        "=?g#,",
        "RLGl'",
        "std::nullptr_t ",
        "W3uHxW",
        "!>bH)",
        "/iTGw",
        "4#4.464Y4~4)535W5",
        "Gf0f>",
        "secureobj.cpp",
        "G!UZ@",
        "Nn;Pf",
        "{[puP",
        "4.5.88.0",
        "5P2F;G",
        "$]T,6s",
        "TNo^<",
        "DKfXu@",
        "4*CH3",
        "^mKkE",
        "Z3D`uR",
        "CId{r",
        "\\lsdunhideused1 \\lsdlocked0 Table List 8;\\lsdunhideused1 \\lsdlocked0 Table 3D effects 1;\\lsdunhideused1 \\lsdlocked0 Table 3D effects 2;\\lsdunhideused1 \\lsdlocked0 Table 3D effects 3;\\lsdunhideused1 \\lsdlocked0 Table Contemporary;",
        "&qL[E",
        "$tXfx",
        "2&a!$P",
        "-~qy/",
        "# 7j=X",
        "k5(t[",
        "CAMELLIA128",
        "L,OJN",
        "\">KpI(",
        "-gb1U",
        "zh`)Z",
        "I)nS9%>",
        "'OK:|y3",
        "HbR*'",
        "R33}|>",
        "+(#E%da",
        "RbL!#",
        "&rjd))",
        "7$7+7K7Z7d7q7{7",
        "Y'SIDu",
        "q[S:2",
        "bind() failed, we ran out of ports!",
        "aNbNc's9>l",
        "4uF+Ju",
        "!(meth->ext_flags & SSL_EXT_FLAG_SENT)",
        "atlTraceWindowing",
        "\\q;DB",
        "~y}~~",
        "1NZ29",
        "Yc*ccd",
        "unknown signature algorithm",
        "r=i:L",
        "t/h8WG",
        "&JY(o@B",
        "Fp;C!",
        ".\\crypto\\engine\\tb_cipher.c",
        "`vl%2",
        "Yo')Wi",
        "pqualid",
        "<'<D<u<",
        "8D;W;u;",
        "dIpf0",
        "L1VtV{",
        "AES-256-CFB1",
        "PCMPEQD",
        "$o$p+",
        "Removing registry key HKLM\\SYSTEM\\CurrentControlSet\\Services\\vsdatant",
        "FeatureVpn::SaveSettings: finish",
        "&050e0",
        "f!Z51",
        "94Q7b6",
        "8r6f)",
        ":G;L;R;.<4<O<",
        " kE0`",
        "ebd/p",
        "D$$PSV",
        "ujP$Q`",
        "8h0_os",
        "STARTTLS not supported.",
        "9<:u:",
        "09MM=",
        "plJmm9",
        "D$$PVh",
        ";;&%^,",
        "oTvK*='",
        "A$mGY",
        "~{G*N",
        "PEcHx",
        "Gg.!!",
        "bio write failure",
        "}[xCF",
        "A`x=%",
        "4'|`lG",
        "a&hs4",
        "VX2VP}",
        ">D>t>",
        "1)152",
        "B(\",Gm",
        "Installer\\UpgradeCodes\\A3122864DEC94E444992B26D2D1900E2",
        "A !\\NU",
        "_b2xx",
        "%u %X %d",
        "%3ZP%",
        "7-#<qV^",
        "msi.dll",
        "Removing registry key HKLM\\System\\CurrentControlSet\\Services\\SR_Watchdog",
        "9\\:s:=;n;",
        "&bsVJ",
        "cVgey",
        "efSS=",
        "tm%DE",
        "i-|a/",
        "_register_onexit_function",
        "7/'@%]",
        "K$&{@",
        "J7n3slV",
        ".?AV_CancellationTokenRegistration@details@Concurrency@@",
        "J\"*BG",
        ";MV'^$?&vw",
        "=N=~=",
        "je_Qen",
        "0!1T1",
        ";);5;D;W;v;",
        "k>3VDY'p",
        "3)3e3",
        "WIX_DIR_CDBURN_AREA",
        "e&,'X",
        "ys9w$",
        "TZ2 S",
        "6,f)c",
        "U*?8%",
        "Could not remove the symlink (FD)",
        "Upgrade process. Driver version differ.",
        "nrDAH",
        "9(lg;",
        "JIZ/eI",
        "`3/~Rm",
        "_<9u=",
        "|$,UPW",
        "%u 0x%X",
        "=&>7>",
        ",|.D|%",
        "R C3E",
        "79NWp",
        "ssl_get_sign_pkey",
        "PFSUBR",
        "6Q8l9",
        "{n7GH",
        "TD4!a",
        "VMS_LOAD",
        "^6{Ol",
        "~(dG|",
        "606I6b6{6",
        "@zacC",
        "ny>GZ",
        "*?u*cJ",
        "X`Er\"32/",
        "343^3j3",
        "t$$PU",
        "\\tz+ ",
        "P2#>{",
        "s,:vE5",
        "8)!)J",
        "no such process",
        "[1@{d",
        "$LT[M ",
        "<5=f=n=",
        "(z~wL=hh",
        "7&wlK",
        "t$0SSS",
        "~$0]F",
        "UwCA/s",
        "X509_VAL",
        "[{^AM",
        "FLDLN2",
        "BN_mod_exp_simple",
        "Mk.\"W",
        "~R&mY",
        "U[r&s>",
        "^Z73e",
        "![it ",
        "FDE_Install starting.",
        "^01?H",
        "8B9Q9",
        "!Y13t",
        "l|J}\\",
        "$0yjzs",
        "3|w^5",
        "ENGINE_ctrl_cmd_string",
        ".0M0r0q3",
        "&rn.z9",
        "v0\\!b",
        "t-.rS",
        "Wvqvp",
        "z:{WF%",
        "Pr7=-",
        "ml$r;9",
        "z+[d-",
        "chy/8P",
        "/`iik",
        "phEfX",
        "0UPHZ",
        "BF-CBC",
        "unsupported method",
        "_cexit",
        "Y{2v=",
        "5:5u5",
        "}#ofz",
        "9#9(989=9B9R9W9\\9l9q9v9",
        "VGK-a",
        ":s;x;",
        "t>U~y",
        "CfkyE",
        "=(=9=N=S=",
        ":&:B:^:z:",
        ":L;_;o;v;};",
        "sDnmR",
        "ecdsa-with-Specified",
        "_,svY",
        "]_y+0",
        "uvE1s):Q",
        "Public Key",
        "n3L$L",
        ")=y'%",
        "n6%;x",
        "yl]bKr",
        "gV9:XTU?",
        "nQRj.",
        "~xfd]T",
        "eF25+",
        "X.GTm",
        "pJ-oh,Zy",
        ":::h:w:",
        "kA+/q",
        "?z yz",
        ".<%K[",
        "U{sYy",
        "; ;$;(;,;@;D;T;X;p;t;",
        "<&bib",
        "#xR:^\\",
        "FINDDISCO",
        "\\paperw12240\\paperh15840\\margl1800\\margr1800\\margt1080\\margb360\\gutter0\\ltrsect ",
        "A8YD/",
        "VoSA&?gQ='W",
        "vcrCx",
        "$*5\"t5",
        "npnBzC6",
        "Zonelabs\\ZoneAlarm.xml",
        "rb&Lry",
        "m)QGR",
        "tGa6d",
        "jCjoj(",
        ".X_6BT",
        "<C(wt",
        "yk1\"7",
        "data not multiple of block length",
        "9\"9)909|:",
        ":;:b:",
        "_sO1c",
        "T9?.]",
        "SDL is enabled on Vista eraseing epcginashim and marking CPEPC_PLAP to be delete after reboot",
        "p'@A[8k",
        ")B$vU",
        "UNDEFINED",
        "3|3Wf",
        "5'555B5P5[5",
        ">->E>P>g>z>",
        "Sv')(",
        "-AB2K",
        ",Uil*",
        "$n+e+3",
        "<4=@=",
        "ajE(_7",
        "t{j UVW",
        "^I<Doo$9",
        "x %Iu8",
        "$O9Y5",
        "(($tB$",
        "L]sJ4",
        "v!Wkf'pV",
        "\\3&^f#",
        "PKCS#3 DH Parameters",
        "VsDrInst_win7_64.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "]V}WvB",
        "e}$t2",
        "D[Hm>",
        "1H2h$",
        "G``d'=",
        "-#d#/",
        "`vysM",
        "^@g?R3C&6P",
        "S_w}?",
        "[`XbQe",
        "d2qKn",
        "LS7iL0]yh<1",
        "n+=*3",
        "<8<X<",
        "\\6pPNb",
        "r(r-!",
        "\"ffh-",
        "v6j2j",
        ">Mvle",
        "?xqwo",
        "stoul argument out of range",
        "PVVVh|",
        "UNKcG",
        "O'$c`",
        "3$3,383X3d3",
        "+V]lm",
        "oSm|6",
        "hAkAS",
        "EVC1S",
        "Y:bK@",
        "watu=",
        "FvD.q",
        "M/yI`",
        "RSA_print_fp",
        "Xw<_A5",
        "=^O7c0",
        "6~/.J",
        "5$9)9.9M9",
        "wN?7O",
        "96^Mr",
        "EN39ly",
        "` zuf",
        ";_1\\)",
        "DestroyEnvironmentBlock",
        ">??Q?",
        "~KR=f",
        "? ?3?_?d?m?",
        "ECX:%08X",
        "M,9:_T",
        ".?AV?$moneypunct@D$0A@@std@@",
        "V42@6",
        ")Y.o9",
        " g<OB",
        "v9:F2",
        "525D5n5",
        "=dddddd",
        "FwDriverExists.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "*QMm'",
        "q}89-_M",
        "e$qCiy",
        "p]<9(|",
        "9Sd9}uq",
        "KGXZ5",
        "V>M^V",
        "2.3E3r3",
        "-y%'QC",
        "xNjg;5",
        "x+qtR",
        "t00Vs",
        "6@?xR",
        "#^4N,",
        "sRj\\V",
        "#!)#f",
        "Ezwpk!",
        "CONSUMER",
        "XC`5A",
        "brainpoolP320t1",
        "moJ];",
        "&e7`R",
        "rw.(5#",
        "U^*^+tx",
        "\"-\"/D.E(",
        "CGpq8",
        "Failure when receiving data from the peer",
        "kIs\\Q",
        "657B7R7o7u7{7",
        "hD?$[k",
        "7 707@7D7H7`7d7h7|7",
        "ekDyM",
        "Nu;j<",
        "IyZBD",
        "F0JNDB:W",
        "(F,8^^",
        "bJ3|W",
        "aE\"ZC",
        "gce8K",
        "V.9At",
        "xy~uh",
        "%uP/y",
        "QoSR<",
        ".Ak<F",
        "[LICENSING] NOTICE: trail key too long, considering it invalid",
        "aHSi#3y",
        "}V#c\"\\",
        "Cc2hZ$",
        "mr-in",
        "+v.Nt&",
        "D$4WPP",
        "p+EsJg",
        "t[malU",
        "\\system32\\Zonelabs\\Updates",
        "F)bLi",
        ",)Gpb",
        "/UESn",
        "Ih;S7",
        "GetObjectA",
        "z]R7XB",
        "FPREM",
        "S$fTk",
        "h:;/m",
        "invalid encoding",
        "W~0Ez",
        "t+SWP",
        ".\\crypto\\x509v3\\v3_bcons.c",
        "}t. l_r",
        "$Fs4LO",
        "8 868>8L8t8",
        "TS_TST_INFO_set_accuracy",
        "\"7a5Ha",
        ":1:Q:e:",
        "B=3%:",
        "3\"t@M",
        "$#T+0",
        ".d}-l",
        "4j6fsg1mrgxh8g7a1fxksw5v1g0",
        "TKcJqE>",
        "?H#7%W;]^",
        "fAZ:[/",
        "9+9:9%:",
        "Hf/\\3",
        "2iYY,",
        "k8u %",
        "uivAu",
        "}\\QhL?",
        ".Hc.[Cm",
        "|VqeP",
        "s*?Jp",
        "9FGo^pNJ",
        ">8>D>L>t>x>",
        "I4UA1",
        ".?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@",
        "?#?3?9???",
        "JXJ2Iwe",
        "9b!';",
        "D$(_^][",
        ">8>D>d>l>x>",
        "Kaspersky Anti-Virus Personal",
        "'OS+<",
        "~l1tY",
        "DTLSv0.9",
        "^^UtB",
        ",a`SZ",
        "w>#=5O",
        "0Z^u^d",
        "mAec>{",
        "gu]lE",
        "^c{J]",
        "TS_RESP_CTX_set_certs",
        "nMk`p",
        "<-<I<e<",
        "BN_div_recp",
        ":,:4:<:D:L:\\:d:l:t:|:",
        "<,<H<a<}<",
        "H26F:=",
        "878=8C8I8O8U8\\8c8j8q8x8",
        "S>W>2>",
        "mc&Ps",
        "l/N>A",
        "UpdateVsconfigXML:  Updated the vsconfig.xml with protection tag.",
        "0*1L1R1g1m1",
        "MergeCommonBackup restore policy from backup: %ls",
        "]E()n=^",
        "D$(9Y",
        "5zsEV",
        "trac.defaults.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Pk_8G",
        "Ov^ ]_",
        "qD-7@",
        "b$$FFbb$$F",
        "E*iL[",
        "/t|kH;",
        "`aq66W`",
        "\\/mv/",
        "yQ/NA",
        "\"<X|.=",
        "=]>b>l>q>|>",
        "BlY,S\\",
        "SetNPVersion: Network Protection registry key does not exist, version will not be updated",
        "c{jxBC",
        ".?; zQn",
        "E10b/",
        "qQ7E4v",
        "nsRenewalUrl",
        "IuR'-dY",
        "XxOhOz",
        "jAjrj ",
        "9^8* ",
        "RSA_padding_check_none",
        "* >=f<k\"",
        "unknown ssl version",
        "M]$x\"}",
        "<SZr#'",
        "CertFreeCertificateContext",
        "lk!8AO",
        "liP|k",
        "BI\\1/Wk",
        "-?Ylz!",
        " parg",
        "KB%h,",
        "}zHx=[IIDQB",
        "Qa6f^",
        "|5=PN",
        "3$3*30363<3B3H3N3T3Z3`3f3l3r3x3~3",
        "LE-t.>",
        "DisconnectedPolicy",
        "#0S\"3",
        "~k;9X",
        "getCustomerNumber",
        ")MRYRaRcRiRoRsRvR",
        "ww{2[",
        "@3+..",
        "~LlE\\",
        "101K1f1",
        "=Q`K:",
        "R,7%fP[",
        ";`Ru|",
        "x]SVW",
        "5]6|6",
        "DY2.F",
        "~;Vm!",
        "I[Wg]",
        "KzRi)",
        "j!Yj$f",
        "Xl*5Q\\",
        "<DsFsHsJsLsNsPsRsTsVsXsZs\\s^s`sbsdsfshs",
        "+SE#LB",
        "pe`ir",
        "Mobile",
        "tCN`&",
        ",^XFs",
        "vmE&R",
        "R`<Q)",
        "{/F4H",
        "9):D;",
        "?\\S%'",
        "FF\\`E",
        ">{NAUV",
        "&Gp`8hv7",
        "##############################################################################################################################1|",
        "\\i0lx",
        "4umTvE",
        "6D~>=",
        ":(:0:=:F:Q:Y:c:k:v:|:",
        "P|09_",
        "]N%=d2",
        "gv%&?",
        "_EOga",
        "(>pqJ(PU",
        ".\\crypto\\ec\\ecp_nist.c",
        "Qe}MQ-",
        "220406074158Z",
        "length error",
        "R8>a0\"",
        "ext-ms-",
        "(*'*g",
        "6kumU",
        "#<?tY",
        "{(bE7",
        "1/_p)",
        "YYF;w,|",
        "566H6F8Q8b8k8w8|8",
        "4#4?4[4w4",
        "UuidCreate",
        "vE/A#^W",
        "[VSDATA] ClearAllDataClients() denied.",
        "C>r<)",
        "(+QE:",
        "<0;R2",
        "2=e#K",
        "ec_GFp_simple_point2oct",
        "M2Lb,\"",
        "`3@}w",
        "Vjmh`",
        "909L9l9",
        "p3o=0",
        "u:_^]3",
        "._CY,",
        "LySy=",
        "tvdumpflags",
        "Failed to update manual services",
        "XL\": ",
        "Z$Z4ZDZTZ",
        "_4dSr",
        "2E2a2",
        "@OtVO",
        "Biometric Info",
        "6:7?7G7+8\\8m8",
        "<0<I<X<u<",
        "$bd(&L",
        "OpenSSL PKCS#3 DH method",
        "J#;=s",
        "\\q8Gv",
        "+Z%dA",
        "=(>k>",
        " 0x40",
        "wm_!`",
        "patch",
        "X'!EB&",
        "HTTP response code said error",
        "oc$tK",
        "Z'EZ*",
        "t\"2u3",
        "other",
        "mmhkO\\",
        "[m.v*yM",
        "l\"C(X(",
        " 1f&g.",
        "FileHash_DYN.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Y6c7m",
        "hDS=c",
        "gyo_k",
        "9Y6\">h",
        "h r]|`",
        "%wn\"ga",
        ":UGo<",
        "7? ;~I",
        "^\"c8j",
        "PUBLIC KEY",
        "J$N\"e",
        "RSA_padding_add_PKCS1_OAEP_mgf1",
        "VG(Gz",
        "i)nDGc_",
        "yW>aF",
        "`8W)d",
        "KuK%KUK",
        "I&zg`",
        "XRX)z$=",
        "::;^;",
        "Hk\\p~8",
        "XIu!m'",
        "CANT_WRITE_TO_FILE",
        "3x&'tY",
        "1J1t1",
        "`nsoN<]",
        "^!R`W",
        "~k9Q~",
        "fRHI<q",
        " S'-s",
        "Af3xk",
        " 0x2d",
        "Jp.8\"",
        "6b6l6",
        "8;)S$&",
        "xo\\oD8",
        "]Bm5q",
        "@SdeR",
        "r;i!w",
        "~~z}~",
        "S<]o;",
        "$Rb$O",
        "BoMAm",
        "Q:)@iH",
        "$2\"3-R",
        "2~:++",
        "Lnaxy",
        "=.>G>g>",
        "lpcaV",
        "ULo}p.",
        "do not show the reboot message when in SCUIAPI. set status to zero",
        "WV6/u",
        "0?8?5",
        "|,jfj(",
        ";},`@",
        "\\handlekmsg.exe",
        "6l8p8t8x8|8",
        "Tx:<%",
        "IFl@v",
        "W\"/ (",
        "+M;tsQ",
        "wevtapi.dll",
        ".\\crypto\\mem_dbg.c",
        "=D=k=",
        "ExtractExternalFilesToTempDir ",
        "<=nG*h:",
        "NMD/#",
        "8] j0",
        ">_FU+",
        ".~$ujo",
        "IzI,}",
        "PMOVZXBW",
        "|mU)D",
        "CC&dH",
        "gWwr'",
        "2o tT",
        "*>^Qn",
        "/I~5i",
        "dGQ8]|y",
        "T/V$)a",
        "`@$epT4d",
        "0wrb9",
        "\\y]Ib",
        "`s@ur",
        "1_J$)c",
        "iG89.",
        "Uf'b\\_@",
        "<%y+G",
        "?!c64",
        "w4fSD",
        "&<%g;",
        "Extracting %s from Binary table",
        "{RMTR",
        "U0Y3m",
        "O`|;R%",
        "E[Q4 X",
        "t?+t$$F",
        ">oM,i",
        "+LVvuOx39]O#2",
        "4_5f5`6",
        ",){[mR",
        ";gc;s",
        "D_L^<i",
        "*lk\\z",
        "P(d8G",
        "3'3C3_3{3",
        "NHEz$",
        "34WKY",
        "B:#iQ",
        "S{qDh~)G",
        "`J`*a",
        "t4SWV",
        "0Ov80j",
        "bFcSn",
        "+N@2.h",
        "=5H,-",
        "010Q0_0i0",
        "]kQes",
        "$gk@r",
        "u<SAWD/",
        " '~PiGB",
        "m~h:O",
        " 0xa0",
        "5%5)5A5",
        "3(CI\\",
        "BVt\\P;",
        "7Nty_",
        "F8USV",
        "C\"@x-",
        "secur32.dll",
        "?!?*?r?",
        "psj&8",
        "Ir/fa,",
        "NP&Bz",
        "aSTqqk7Pdz",
        "+M@O,",
        "9t}~(",
        "_~L%-",
        "ec_GF2m_simple_group_set_curve",
        "WJz'0",
        "ZC!lX%",
        "PJg1Tk'",
        "uFZCj!G",
        "timed out",
        "?U?k?",
        "XrPch",
        "0U<56",
        "8%8X8d8",
        "lR8BI!",
        " 0x6f",
        "D$$PVj",
        "5{[Wg=",
        "D$H9U",
        ";/4b^/",
        "313Q3q3",
        "$4GV.Y",
        "lm,R#",
        "ALimx",
        "=\"=)=0=?=O=e=",
        ".H=u$9",
        " set FW_INSTDIR to fw_instdir=%s",
        "v>=KVU",
        "7H7^7n7",
        "E[uN6",
        "UzudS",
        "ios_base::failbit set",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078  and}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  provide the courier name and tracking number to TAC befo}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607 ",
        "?$?0?P?\\?|?",
        "]b{Fc",
        "id-aes128-CCM",
        "jIrH_",
        "0O0Y0c0r0|0",
        "8 8+8;8F8V8a8q8",
        "Gdf[om",
        "Z|]&70",
        "4DE3ff`e~",
        "4 4<4L4X4x4",
        "N)!5-",
        "invalid CA certificate",
        "Vr&Ub",
        "HwN_?=",
        "y?SHM",
        " )^Le",
        "FKSVP",
        "c{hto",
        "R+#?,",
        "t(e0:",
        ">#?(?1?M?o?u?",
        "9*c!>",
        "7 7(70787@7H7P7\\7|7",
        "&Z^9YEO%*+:",
        "\\ckpNotify.dll",
        ":9:C:M:W:a:",
        "CB5Gr",
        "3L$L3L$",
        "#zB=`/",
        "3\"3.3N3{3",
        ":?_ x",
        "fue*^",
        "fB/#R",
        "]LqsK",
        "jUouU",
        "JLe3e5q7q1",
        "4IL=|t",
        "d=%-2d hl=%ld l=%4ld ",
        "Rz4]x9",
        "r*IO;",
        "<L#~a",
        "&=!,N",
        "pLT,Av",
        "8;8Q8b8g8",
        "ULl7/",
        "m8HY['",
        "jgyCL",
        "3$8^X ",
        "jrjkj",
        ";^PuI",
        "b<bHbL",
        "TRUSTED CERTIFICATE",
        "p]iy=b[",
        "ZGj4p",
        ";u8OZ",
        "'$]J\\",
        "]vFUHt",
        "EC_GROUP_check_discriminant",
        "-h.P{",
        "$OFX)",
        "ljLRe",
        "%*sSignature : ",
        "21#42#",
        "C&;h6",
        ".9P;$",
        "2up+0@*W",
        "english-nz",
        "LMWoggP",
        "OWW4.",
        "LKQzy",
        "):^Nm",
        "holdInstructionCallIssuer",
        "*;b$Z|W",
        "@B@AhA",
        "jI@#O",
        "iT;UW",
        "L'1t?",
        "\\par \\tab c. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5000668\\charrsid15169477 I}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 nform Check Point or its partner of changes in the Hardware Product physical location}{",
        ">,Y?n",
        "t/W8\\x",
        "r.Hfx",
        "<<<@<D<H<L<P<z<",
        "#X;\\V",
        "80888@8H8T8t8|8",
        "~%k/T",
        "22222222222222222222",
        "XSK'Um",
        "^I}S3x",
        "EVP_MD_CTX_copy_ex",
        " nYXL{",
        "1f1u1",
        "ntXSx",
        "5#5S5[5",
        "+j\"h\\",
        "ULWR8",
        "WE(j)t",
        "uL!E1",
        "EC_EX_DATA_set_data",
        "bKsmY",
        "V<c/xb",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<unsigned long,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,unsigned long>>(const unsigned long &,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,unsigned long>)",
        "1 10141@1P1`1d1t1x1",
        "c`Vd\\",
        "qhgK8",
        "0,'7<",
        "tt-ru",
        "RSA(512)",
        "<tM+x",
        "YYatus",
        "There is no Binary table.",
        "C\":LAG",
        "t2bh=F>",
        "]BJ0#(M",
        "0<1y1",
        "ULU+}",
        "oGSc`",
        "m}&Uf",
        "#r'21",
        "operation in progress",
        "<+3|@",
        "\\T7,8",
        ">6?C?_?",
        "S`O7w",
        ",~RVw",
        "Q-+gQ",
        "\"|q0\\",
        "cv4%D",
        ".!}I40",
        "096d(",
        "A~kty",
        "lYN$<",
        "7M8j8",
        "ts datasign",
        "KmaO(]v{<I",
        "|}[`2R",
        "Deleting %s",
        "^vTT%",
        "unable to load ssl2 md5 routines",
        "=*=C=\\=u=",
        "5}K^8B",
        "I_L~<lj",
        "saL<?X",
        "mn%^x",
        ":5uoR",
        "}R>Ho",
        "l`!'dy8p",
        "\"UZhs2",
        ">x>Cj",
        "FTw('",
        "rzmFs",
        " ^Sg|",
        "5V1}~s",
        "IdGk[n",
        "z{{wo&P",
        "_cabs",
        "C/PjSW",
        "444M4f4",
        "dd#Y]n",
        "3L$P3L$03L$(",
        "WG4>z'v",
        "q[ @=",
        "a[}lLo",
        ")-{Hcy",
        "#;(+A",
        "oIO9ns0N",
        "H<m7O",
        "|pS-6",
        "TMx N",
        " 0x1b",
        "W14%9",
        "$1u1#",
        "5]\"g1",
        "id-smime-aa-contentHint",
        "}iXs*",
        "encryption",
        "uninstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        ";ch4j",
        "Conversion failed",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7743908 at }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 Hardware Product. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 A }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "x#yCy",
        "[\\AXvl",
        "9Glr476",
        "C<ND|",
        "]`7fO",
        ":1:C:U:",
        "<.<9<_<",
        "9Cb)y",
        ":Ay=3=",
        "1!1'1-191C1E1K1]1a1g1m1s1",
        "uninstallAS",
        "b]+i,+",
        "2,2>2J2o2~2",
        "FindFirstFileNameW",
        "L$0;J",
        "}(xYex",
        ".?AV?$base_from_member@V?$shared_ptr@V?$basic_altstringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@io@boost@@@boost@@$0A@@boost@@",
        "RemoveFromWinFwExceptionList:  RemoveFromWinFwExceptionList() failed.",
        "oEK`^p",
        "\"=\\vr",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\InstallError\\InstallAttempt",
        ":kuLZ",
        "lTi5^",
        "ZZ:NV\"R:R-5",
        "6P6_6",
        "cd}M`",
        "-?MKP",
        "EC_GFP_SIMPLE_GROUP_SET_GENERATOR",
        "EcWe'",
        "J&3olM",
        " (0YBC",
        "{~LX=",
        "5e6Q7d7",
        "[@|Dz",
        "CANT_STOP_IMC_SERVICE",
        "KJ6 Urr_",
        "hqArI",
        "&z5ln",
        "T3+9B",
        "D$<9l$",
        " You in Your purchase order, or request for License Key, and upon which the licensing fee was based. It is a violation of this License Agreement to create, set-up or design any hardware, software or system which alters the number of readable IP addresses,",
        "wL|I&F",
        "B9LX)",
        "d.8\\c",
        "u0KURUq",
        "o&cOXk",
        ",JKj]",
        "tvdebugflags",
        "d(wirg",
        "D)1[@",
        "****************************** UnloadGUI started **********************************",
        "cUJSK",
        "CV=~/*",
        "\\858|$",
        "SEC_E_UNTRUSTED_ROOT",
        "p<3n|",
        "umr^b`",
        "PRODDISPLAYNAME",
        "U'vq0",
        "-w}#i",
        "9T9[9",
        ":U:g:",
        "~gwM=$",
        "[v^Z(",
        ";\\^X[E",
        "regex_error(error_ctype): The expression contained an invalid character class name.",
        "3POSQ1{",
        "dY`z5.",
        "#lFcs'F",
        "=+;+$",
        "g+fB@",
        "G(/VO",
        "ayT)(7",
        "e^q{K",
        "7WNNc",
        "6%6S6j6",
        "})C]q",
        "JT<>A?u$h",
        "gl-ES",
        "3/twX",
        "digest error",
        "j>Ai#5",
        "f$U]#",
        "L$XSU",
        "QP\"#R=",
        "OB'mQ",
        "/propertiesmap/key[@name='environment']/tDWORD[@name='EnableCleanup']/text()",
        "Internal Error - invalid value for NO_OFFICE_MODE property value is '%s' -> return false",
        "*y%[Vl",
        "6hU}8",
        "?^/sZz",
        "2*d!c0V",
        ";h<>=",
        "FdP4@t",
        "CANTSETKEY",
        "uUdc{?",
        "9T9]9f9o9",
        "5;&PG",
        "rqEW:",
        "SOFTWARE\\McAfee\\McAfee Firewall\\CurrentVersion\\Setup",
        "<$<0<<<H<R<V<`<l<x<",
        "x;ZLQ",
        "[VSDATA] FwConfigChange: local IP count: %d",
        "_LsbA2",
        "(?G !",
        "F(!W$",
        "8^8n8}8",
        "AR`)|HF",
        "ECDH-ECDSA-AES256-SHA384",
        "/UO%bC",
        "Wk3VV",
        "HARDWARE }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420\\charrsid2646135 ",
        "IF$>&",
        "_=mdrgI",
        "9j9%&'8)",
        "u*vWe",
        "K&!4Z=sKBf",
        "_?Si\"U",
        "'[NBpP",
        "]p)?teL",
        "rU|\"c",
        "@'b?H@3",
        "U:6CI",
        "\"MXJl'",
        "M/IHSJ",
        "^^?0p",
        "F5(k<=%",
        "bj\\T[",
        " -9A(",
        ";2<c<",
        "@nILS(]p",
        ".8\":\"",
        "BbeLL",
        "79HDO",
        "GqH+/",
        "b7yW#",
        "Jo$]Pv:",
        "Y*03bx",
        ";I=Y=",
        "User cancel",
        "9|ioFWf",
        "Ey!.C",
        "91989P9w9~9",
        "cpDigestEnd",
        "@h@-)",
        "L4T4\\4d4l4t4|4",
        "5B6b6y6",
        "'>r;;g",
        "        <requestedExecutionLevel level='requireAdministrator' uiAccess='false' />",
        "CAo'`",
        "LM/A`",
        "=n>n?n",
        "4CNd[z",
        "3!343H3S3b3~3",
        "1,191F1S1q1}1",
        "}Xe+N>:",
        ".S]P@Rr",
        "wcpK}",
        "TQWt8",
        "mllt:",
        " 0E0z0",
        "9^Z%a-",
        "0 0$0(0,0004080@0D0L0`0h0|0",
        "t$,h`",
        "PCfBr,\\EA:",
        "egwCn",
        "DasZ\\j@i+K ",
        "C-8X^",
        "X>l+0",
        "J.}kE",
        "5@m/n",
        "0H1`1",
        "v!AN%",
        "qBS&p",
        "22mQz",
        "BW!a6A<",
        "\"$0P\"",
        "#\\>/a",
        "%02X%02X",
        "9$9,989X9`9h9p9x9",
        "VstFOq",
        "<N6x+",
        "O8G*&",
        "\\LS@.$",
        "}+-j'",
        "WjtbGy&~",
        "SSL_SCAN_SERVERHELLO_TLSEXT",
        "R$U4S",
        "q M,L",
        "50575K5S",
        "&'xUEFORq",
        "I*AU%",
        "X4zf^)",
        ":}:s;",
        "il'Zhy",
        "2f4X?\"T@",
        "_^][Y",
        "5GlLV.",
        "]nL&fTq",
        "%s------%s--%s%s",
        "gFkfMK",
        "8z]q\\",
        "Ha3gP",
        "gk6LV",
        "FxUEI",
        ":!4)d",
        "rsaOAEPEncryptionSET",
        "ptObY",
        " \\Unu",
        "\"~tPS@",
        "DDWDqs",
        "Di+ t",
        "*QK#:",
        "NCONF_load",
        "(G#91",
        "<[vPI",
        "Rt!`3",
        "KhzDz",
        "&I\\1[@",
        "Vp2r\"i",
        "6]fC[",
        "[WinFW] GetWFStatus, CoInitialize failed",
        "NAN(SNAN)",
        "jrjvj",
        "Q5G[e",
        "EB.GH",
        "t$4UW",
        ")[(s\"O",
        "6C8%#/L",
        "O44h\\",
        "404L4h4",
        "q|<l$",
        ": :(:@:P:T:d:h:l:p:t:|:",
        "XF]Ie0",
        "k$t\\I",
        "w_m8RN}",
        ">5_i]",
        "OcQ4N",
        "s95\"g",
        "rfs!'",
        "v&6Lo",
        "9FeDWp",
        "URLFextractUCP ended",
        "aC#47",
        "*Ev5eM",
        "t)Q<!}",
        "5u9TF",
        "c>c&w+w/t7",
        "9>QpS6",
        "6J6h6",
        "'~Cdc%K",
        "'5:E@E",
        ")ZJgJ",
        "e?'Mj",
        "1}7*SS",
        "3Jn5/M",
        "(DigiCert SHA2 Assured ID Timestamping CA0",
        "al3GT",
        "s\"kc*'",
        "t\"kj@",
        "stream timeout",
        "dpQwYf",
        "?5?M?",
        "Yg$$9uS",
        "+?W9n",
        "0#0(0.040:0?0E0K0Q0V0\\0b0h0m0s0y0",
        "ft&9q",
        "5#iHA",
        "A*}-#6",
        "Gc}jn",
        "$2YD^",
        "/$Atm",
        "keyAttrId",
        "@SSSS",
        "U1N,5",
        ";#<8<G<S<_<k<w<",
        "WIX_SUITE_SERVERR2",
        "l(l8lHlXlhlxl",
        "WIX_SUITE_BLADE",
        "g8y0y",
        ", <^w",
        "(P4V#",
        "~xEI8",
        "lZ>4n\\d",
        "l]w.wA",
        "\\$XPW",
        "invalid directory",
        "%#2t8",
        " %Afm",
        "=q={=",
        "253A3L4s4",
        "4(4,40484<4D4L4d4t4x4|4",
        "767D7I7U7b7",
        "L#KWJ",
        "^ '>g",
        "5q$4X+",
        "?+?V?h?",
        "ZG\\k+",
        "z&\\H6",
        ":r:]?4",
        "CZ! >",
        "D/\\6jP",
        "..6P6X6j",
        "6LgpKc",
        "\\z%4O:",
        "Ylc|q",
        "vLwOpv",
        "j:^f;",
        ": :0:<:\\:d:l:t:",
        ":#:3:C:S:c:s:",
        "cpbcrypt",
        "1R hw",
        "*J~=B",
        ".?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "~T/D*G|",
        "[%,&D",
        "mob_about.png",
        "\\smartdefense\\sd_uninstall.bat\" YES \"",
        "HwtXF",
        "dy#[Q",
        "setct-CapReqTBE",
        "P[e[w",
        "c#\"(0<3n",
        "W:]|B",
        "j_yq>^F",
        "s#EYzY",
        "v5>2^",
        "f\"5;E",
        "EPAM_Uninstall finished.",
        "=#=/=;=G=S=_=k=w=",
        "&IXpn",
        "^@w9v(.S",
        "lL&Tw",
        "\\4blu",
        "/X-F]",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\ds_fileaccesscontrol.cpp",
        "(@k071",
        "5;5W5s5",
        "y7*N:@",
        "*)c=-_",
        "Helper::shutdownVsmon: start waiting for vsmon.exe to die.",
        ":(:>:[:",
        "K\"hGb<",
        ":%:+:5:?:M:S:i:",
        "v@vZe",
        "dOsgmA",
        ":39}4YS",
        "WP^tcrf0j",
        "DO03Q",
        "'m+'e",
        "/95m*S",
        "Pj]h<",
        "2xj]C",
        "3Bm:1mS",
        "O23:(",
        "n#.\\U",
        "lJ5wl",
        "p#7pD",
        "cXZ_l",
        "RU&j)",
        "jCjgj*",
        "OIur~",
        "ko6@)",
        "cpnqd9",
        "network unreachable",
        "8\"9=9S9i9q9",
        "<4w$o",
        "~GAFpo",
        "faB@:",
        "g--kx",
        "|y9lW",
        "Q$j?\\",
        "]X'7fP",
        "Zx;na",
        "EP1.Pi<~9M",
        "PREFETCHW",
        "zkx3:",
        "M^6l/",
        "-IY3|R",
        "G &*J",
        "5V7b7",
        "xNRHp%",
        "P:7.2",
        "Jk,9G ",
        "D~;r1@",
        "6c=}5",
        ">cKup",
        ".\\crypto\\cms\\cms_env.c",
        "ZjII?t",
        ";\"lY7",
        "vRGvw",
        "no port specified",
        "d-dEU3D",
        "kq/&L",
        "<++!H",
        "3 303@3P3`3d3t3x3",
        "7F7h7",
        "N:p0-B",
        "Oo\"1p",
        "i$XDs",
        "\\I1Li",
        "SendInfoMsgToProgressDialog: Failed to create Record",
        "tD,iy",
        "u%cL]",
        "N-{U~'(",
        ";type=%c",
        "'Z+.\\",
        "l$$t9",
        "t\"Phd",
        "tMhxW!",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  This Section shall only apply if You are licensing the Pr",
        "{Q{)rI&",
        "8|UXva",
        "%6#GT",
        "))[pD",
        "0=H R",
        "fZ&iW",
        "InstHelper.exe: RemoveKlif",
        "d<$$$M",
        "WfQ~}",
        "]w~aeo",
        "U=ap5",
        "?lDq_",
        "\\b\\f1\\fs20\\insrsid7565078\\charrsid15169477 Advanced Replacement}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  Service, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 You will }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "Izj\\ri\\",
        "SSL: Certificate issuer check failed (%s)",
        "9M9c9",
        "TsgE~",
        "Ep_Core_Inst.exe.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "UW&=P;",
        "l0=Ys",
        "INVALID_PRODUCT_NAME",
        "S$:,e",
        "mS Es0",
        "Kovic;T",
        "&?Y$@",
        "575d5",
        "0Vi{l",
        ">(>3>B>^>",
        "ZQ^M8^",
        "<.BL(",
        "D$`PWh|",
        "0T|SB",
        "AtJFe",
        "td7oV",
        "=->K>T>_>f>",
        "<NkAC",
        ">_^QE",
        "`Zb6nb",
        "OCSP CRL ID",
        "q3[s*",
        "N].EE",
        "? ?(?,?8?@?D?P?X?\\?h?p?t?",
        "fy0|+w{",
        "AW)W?",
        "7~#B@",
        "Q:vH3",
        "'U4$Ds",
        "w%jDY",
        "L<R.G",
        "jhjlj",
        "\\~ DjW",
        "G@pp,",
        "\\z%.1iR",
        "T`,y-",
        "01(-=",
        " EPS_R80 is installed -> abort installation",
        "PKEY_DSA_KEYGEN",
        "E0]&-",
        "xxd\"h",
        "415t6",
        "727d7",
        "cChgg",
        "4pM[8wG",
        "]JXd,",
        "U2\"T?n(",
        "2<2X2",
        "g>o{,",
        "qqW{4",
        ";X<d<",
        "o~q~s~u~w~y~{~}~",
        "F5@kv",
        "w_xtrS",
        "r}&zm",
        "message digest is null",
        "T$H3H",
        "K&!w)",
        "%L-rqou",
        "ewbpj3kbxpfu5w47gaga0e186c0",
        ",C-K#",
        "pA!k*1",
        "Ln)6,",
        "<+<C<",
        "&Rv5E",
        "_full",
        "`GE<R",
        "?:q:)",
        "[1Pv4p",
        "2OVG2I",
        "?M;!{:V",
        "p%Oyj",
        "c]ZPh",
        "HELPER_NOT_RUNNING",
        "1\"v m",
        "Rw{)r",
        "]|+R%B",
        "=QL>%",
        "s1mly",
        ",'ZJ|",
        "OS GL",
        "j]hyP",
        "(LevM",
        ": :::D:g:q:x:",
        "|A}stO",
        "FBdd~",
        "Attempt to register:  %s",
        "F5_#i",
        "h2AneA~",
        "!8\\_Zb",
        ">GP[6",
        "{=>`5",
        "\\8)/<",
        "gdgAt6mHS",
        "Rw1N]",
        "QSVj ",
        "INSERTPS",
        "{kj,|?",
        "PH3}R",
        "WhTU\"",
        "Z^l_;(",
        "WWCZT",
        "GOI;U",
        "j*:kt",
        "6.LpfK",
        "BN_to_ASN1_INTEGER",
        "\"{kVA",
        "9p#cT",
        "sslv3 alert no certificate",
        "0D+<#*",
        "5*6G6",
        "$bwh!",
        "bad exception",
        "y/ZVI",
        "]CL 4",
        "=JBYi",
        "1iETW",
        ";\";*;8;A;G;",
        "SYSTEM\\ControlSet001\\Control\\CrashControl",
        "8HJZTo",
        "\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List;\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid;\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 1;\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 1;",
        "yhI[&\\",
        "'mr;q{",
        "sb11Sb11S*",
        "GJP&Z",
        "* TDM",
        " yvPM",
        "CreateDirectoryExW",
        "This is the same version upgrade.  %s to %s",
        "%2d/%2d/%4d %2d:%2d:%2d",
        "879j9",
        "\\par 2.3 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Managed Service Provider Restrictions.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "EX[r8",
        "HI8:,",
        "$O]wI",
        "juY+\"",
        "A.(GX",
        "yw#z4",
        "m%~i{yw",
        "i.{I(mkd(:5",
        "Rp+2fh",
        "`W\\iS",
        "!L^TU;c\\",
        "t.]_/P",
        "vcruntime140.cpp",
        "`emzj.7[",
        "Vu$HjS",
        "GetModuleBaseNameA",
        "start",
        "'*G]f",
        "+&e5e",
        "_[^]3",
        "n|sxM",
        ">#>)>/>D>`>d>h>l>p>t>x>|>",
        "\\ZoneLabs\\kl.pbv",
        "pkcs5",
        "application/x-pkcs7-mime",
        "l:0,o",
        "_2M,J6*Y",
        "MultiByteToWideChar",
        "w}eS;",
        "<!<I<",
        "q not prime",
        "8<9F9}9",
        "193x4",
        "Copying policies from: %s to %s. Result: %x",
        "j78fk.x",
        "l3^>=",
        "(/'2t",
        "SUWjNh",
        "jG5-'",
        "%=*K<C",
        "(T5/RM}",
        "-cb}3|",
        "vQOxM",
        "yF7|E",
        "EXPORT56",
        "aiVfr5a)!",
        "eld!]",
        "<<zxe",
        "qU&kp",
        "Wz|c[5",
        "I2IRIrI",
        "=(Cb6",
        ":FP|6",
        "DisableProtection returns %d.",
        "Tbi}w",
        "/N+h3",
        "7%rT=",
        "9d9i9",
        "A<kue",
        "Zpeynw",
        "dGzWG",
        "id7~4",
        "h(yt]r",
        "DHE-DSS-AES256-GCM-SHA384",
        "^Ww>Zv",
        "HRB91r",
        "SwH\"3",
        "\"%s\\Temp\\vna_utils.exe\" -d -ap vna drv unload",
        "t$,_[",
        "0Bx?f",
        "U0JZu",
        " $G\">",
        "!{aHq",
        "en-AU",
        "1}0p07P",
        "-jGbI@",
        "b3?.>\\",
        "';b1[",
        "vb6P[",
        "ApnmW",
        "*BL|=",
        "&uQ;-",
        "d_heI",
        "failed to get firewall exception remote addresses",
        "OHt/f;",
        "yn/0l",
        ":$;;;U;l;s;",
        "TPF'n",
        "4,z`v",
        "!54Nw@~",
        ";5c]`",
        "b('I4",
        "spL6}",
        "QP%3d",
        "unknown client_sub_type",
        "qN_T7R",
        "Delete file: MsiViewExecute",
        " `Vp#m",
        "\\K\\XQ",
        "<ASN1 15>",
        "Aco<I",
        "T,KB%",
        "5`W<nk",
        "\\(HS/",
        "LEIPjr/",
        "a1Ld=",
        "QP>Q=M",
        "jAjdj\"",
        ">$vRB",
        "\"\\$';T$tr",
        "Custom action was told to rollback a 64-bit component, but was unable to Disable Filesystem Redirection through the Wow64 API.",
        "RSc'@3",
        "Helper::stopServices",
        "=%=>=E=Q=[=u=|=",
        "TraceEvent",
        "1!1A1Q1q1",
        "+A$tp",
        "[*v[[",
        "jAjfj\"",
        "g,,7l0",
        "xdigit",
        "-~)]O",
        "8:k%=`",
        "\\f1\\fs20\\insrsid11543880\\charrsid15169477 Check Point}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11549003 \\rquote s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11543880\\charrsid15169477  {\\*\\xmlopen\\xmlns2{\\factoidname place}}",
        "<]Q60",
        "LTQ+V",
        "9vdtG",
        "1QOQXQ",
        "eZP\\e",
        " Q@A&`",
        "WD_StopServiceFromSCM ended.",
        "Edk4_",
        "^J7Cb",
        "%aQ``",
        "Kmxk%",
        "lZSr?",
        "VAD19",
        "jpjwj",
        "> >$>(>,>0><>D>L>P>T>X>\\>h>l>p>t>x>|>",
        "203O3",
        "Mdqf<",
        "-b;Yu",
        "~9o]3",
        "!>{J-",
        "Pzc]o",
        "@H4TX9X ",
        "GJUrD^",
        "5t9cC\"",
        "NRDr6",
        "*!nbo",
        ",fPE$",
        "Skipping shortcut for null-action component '%ls'",
        "0.1v1",
        ")0)2Q",
        "`jG%q",
        "TRrGn",
        "checking file_name=%s",
        "@2D2H2L2P2T2X2\\2`2d2h2l2p2t2x2|2",
        "t+IP$[O",
        " 0xd7",
        "q%G9_",
        "jrjnj",
        "v$SKq",
        "1/<u tt",
        "2C#uA8",
        "1Sb0{<",
        " 0x7a",
        ".?AUITopologyExecutionResource@Concurrency@@",
        "aes iv setup failed",
        "aGOST94",
        ">$>0>P>\\>d>",
        "+Tgmg",
        "=Yi+%em",
        "v9]@?",
        "r_(o;Y",
        "+r!B%",
        "X509_CINF",
        "HNWc&",
        "9):p:",
        "4)4:4D4f4w4",
        "~C@r8p",
        "keY{5",
        "E+L1Y",
        "Unn\"]",
        "]qHs^5",
        ".\\crypto\\err\\err.c",
        "should retry",
        "g~OdR",
        "\"M5fi4W",
        "bKbSb[bcbkbs`{",
        "d.authenticatedData",
        "-;Qd~",
        "\\Tt3j",
        "C2[>g",
        "PreInstallCheck: Overhead Disk Space needed for logs etc... is: %d MB",
        "IS_MAJOR_UPGRADE",
        "~[#6c",
        ")!)q)",
        "[A#*[",
        "J?=Gt",
        "<k1hs ",
        "(mmJt",
        "ImLgA",
        "xE3(|",
        "soft_load",
        "0@0E0O0",
        "K(4!x",
        "vCX:Vw",
        "\\b\\f1\\fs20\\insrsid2708596\\charrsid12809063 T}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid815761\\charrsid12809063 ECHNICAL}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid815761\\charrsid1468885  SUPPORT CONTACT INFORMATION}{",
        "3(424A4L4\"5g5",
        "ly(.6",
        "8KBA|",
        "k@\"?N*",
        "et-ee",
        "3J7tV",
        "LTM\"j",
        "UWUgdUF3",
        "4b4m4w4",
        "6DKF;",
        "\"a[qrV",
        "iFyr4",
        "tmpnam return %s",
        "|=7hX",
        "SEC_E_KDC_INVALID_REQUEST",
        "!!!!!!",
        "7p8t8x8|8",
        "1Bt0d",
        "sRKH!",
        "~2taB#",
        "*ee}|9",
        "P_5`+",
        "Schedule Delete: ",
        "/\\d\\\\",
        "j5<9A^",
        "OSw\\`R",
        "3fG=kd",
        "](`wK",
        "0k+p_",
        "@I aWu",
        "1*2q2",
        "l$4US",
        "jo8,`",
        "{k:)99'",
        "=fS\"A",
        "/1bcIS",
        "vnaap64.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "zMurdv",
        "sms-FI",
        ":';Z;o;",
        "~DKOa",
        "XTHC+G",
        ",N ]F",
        "Vl0t_",
        "=Zp^A*",
        "put_resolveExternals failed",
        "o\"?v]m",
        "wP\\ZH7G",
        "oq(7C",
        ")9~[qg",
        "\"4N28",
        "(:Sy&aM",
        "D$4Ph(",
        "rSfmM",
        "?(?4?J?]?p?",
        "cW$Tp",
        "%_T== y",
        "t$D3l$",
        "0t1{1",
        ":48F;|",
        "%QO&{\\?",
        "MsiLogFileLocation",
        "Error restoring registry settings.",
        "vthvN",
        "mirror.exe is in Binary table. Extracting to %s",
        "nKe,p",
        "abort",
        "vj$+^+",
        "Ec;}G",
        "}xJGF",
        "%]\"'3",
        "2Pf*a",
        "P1jEU",
        "\\MlfHook.dll",
        "){<!cg'",
        "7\\j(n8",
        "='>9>?>G>`>",
        "~Jg\"+",
        "z+'y'",
        "3tM0`",
        "F9*OV",
        "i0P^\\j_`",
        "?\"?)?0?]?",
        "7(838=8B8Y9~9",
        "9BxlK$:{",
        "P=+e+",
        "1)1=1S1f1",
        " 0x45",
        "zj<jr",
        "CKe=C=",
        "4uTC5",
        "?2-~wx",
        " subjectAltName does not match %s",
        "6$6(646D6T6X6h6l6x6",
        "$+r,NG",
        "INVALID_FWSTARTUP_VALUE",
        "4s#uPu",
        "w>AT%;_",
        "MINPD",
        "id-Gost28147-89-CryptoPro-A-ParamSet",
        "StopNetFltDrv failed, installation will be stoped",
        "t$43\\$@",
        "The MsiRestartManagerSessionKey property is not available to join.",
        "]^RIA",
        "=N>t>",
        "cElb(",
        "919A9v9",
        "la[w_",
        "w]TwA|",
        "<H%*n",
        "_j;Xf;",
        "3a|0B",
        "MN2N}",
        "{azxYj",
        "S)$f,",
        "PT5Poy{",
        "D$,IBE",
        "394?4i4o4u4",
        "tr-TR",
        ".5RiM",
        "h!#(h",
        "[Qi*W",
        "fn$kA=",
        "P-192",
        "X&[Pf",
        "`~R )/",
        "\\%Jk-",
        "qY,6.",
        "]Ipj[",
        "K.\"iZKPD",
        "j5L$X",
        "Lj&&lZ66~A??",
        "d.issuerAndSerialNumber",
        "8*858N8`8p8",
        "L|vO3\\",
        "J*nD_*u",
        "\\KL6x",
        "!#5` ",
        "Z*SZS",
        "^n1Q<",
        "|9QgM",
        "<0|&<9",
        "UV4g&",
        "1/u1s|",
        "j-C^$",
        "5a7\"*",
        "WMp~7",
        "!wg;!K5B",
        "%255[^:]:%d:%255s",
        "aad:\"",
        "1C2N2W2f2q2",
        "2(282<2L2P2T2X2\\2d2|2",
        "AU'lf`Y",
        "jWYCtjG",
        "D$$j P",
        "Fa'3O",
        "NULL-SHA",
        "BszkA",
        "la\\%dX^",
        "Salford1",
        "u!6A1",
        "S]h\\SU",
        "FDhV)",
        "&Ia*g",
        "-l4,b",
        ":2:R:r:",
        "a=<Jf",
        "3q@$yS",
        "<L<Q<l<:=|=",
        "=*T#m0",
        "IW;fh(",
        "BladeFoundation.dll found in EPAM folder",
        "RSA_padding_check_PKCS1_type_2",
        "<s!\\T",
        "\"?_w_",
        "UHGVJ",
        "\\nt~G.",
        "\\['[8",
        "?RbSQ",
        "8K9Q9e9C:J:",
        "no dsa parameters",
        "K#d\"T",
        "aaU`)n",
        ".?AU?$error_info_injector@Vtoo_few_args@io@boost@@@exception_detail@boost@@",
        "\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 6;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority19 \\lsdlocked0 Subtle Emphasis;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority21 \\lsdlocked0 Intense Emphasis;",
        "$1pc0",
        "HVqyZ",
        "=)=E=a=}=",
        "<!<1<><V<_<o<v<",
        ";'G.A",
        "181H1P1l1t1",
        "a\\X[8",
        "7`-63",
        "HMe#t",
        "gh{$~",
        "F4J%c",
        "bad pkcs7 type",
        "ZrR3t[4)E",
        "gQ~e6",
        "failed to write exception attributes to custom action data",
        "rC?W(",
        "M{$!w!",
        "N><m\"JS",
        "qGcOM(",
        "L'R;Ba",
        "5#e.7",
        "|`bT2mB",
        "response",
        ".RB-b",
        "YTA8{q",
        "%zO?<",
        ",/+pW",
        "\\{K[*J",
        "G@WVPR",
        "Z_UxF}E\\|",
        "9(90949@9H9L9X9`9d9p9x9|9",
        "?b,KP",
        "TQX}tk",
        ":*VP,",
        "ncUq4",
        "L$8SUW",
        "w;)^S\"",
        "O[.<V",
        "tc9nlu^h4",
        "YCq:{",
        "9 949H9\\9p9",
        "U$T5zM-",
        " 0xff",
        "y*S [",
        "|'x=ar;W",
        "V(>nFFs",
        "<5<N<g<",
        "/DEFINE:",
        ":cQ'^1",
        "C;^8u",
        ";*;0;",
        "!7JYf!",
        "[MLsC",
        "o*&9t",
        "4f6v6",
        "index %d",
        "0+hNV",
        "TLSv1.1",
        "u(eD~",
        "r-Dq~",
        "unsupported kek algorithm",
        "?\"?+?0?B?K?P?b?k?p?",
        "Wrong usage",
        "sOuZk",
        "^$zm0",
        "w5lMNv",
        "\"|LEmZF",
        "95N7q",
        "y Mst",
        "f~HcE",
        "5Z^wQA",
        "h`cte",
        "]cma/k",
        "7c}:i",
        "N\"e+si",
        "W}tKF",
        "Y*,}l",
        "rEEGw0",
        "ad.checkpoint.com",
        "McAfee ISS 2003 Internet Security (All SKUs)",
        "?\"?C~",
        "INSTPW",
        "333U3h3u3",
        "3z/}W",
        "giGWx",
        "b[uQ#",
        "2Ucu,",
        "}-'~pK",
        "a,$'&",
        "g:S,j",
        "ZgAh3lV",
        "iYpt*4$",
        "BqnHI<",
        ">9]<1o",
        "x3<hT)Ss",
        "_88gE",
        "9R9Y9e9o9",
        ".2\\Ao",
        "9!Ype",
        "LangPack1.xml",
        "JG`w+",
        "zs5Prr",
        "++eSg1",
        "2$b3=",
        "!eGZ5",
        "708D8\\8h8",
        "Failed to write data to ca script.",
        "Salt Length: 0x",
        "<g>!W",
        "@B|\"y",
        ",e2u%",
        "@j\"7t",
        "QWuAg!",
        "2sRuc",
        "|FAa=O",
        "Failed to run MsiGetProperty to retrieve SDL_ENABLED. Setting to disabled as default.",
        "JL]1BZy",
        "api_ms_win_core_synch_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "z:{Y{",
        "QmQbh",
        " >nrx*",
        "^mK8R",
        ",gJ-5",
        " ABJ^",
        "ECDH_DATA_new_method",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\stopallservices.cpp",
        "%u %i %i",
        "DW+(p",
        "Helper::stopCPDAService",
        "OhLq&",
        ") J-f",
        "c&|tk",
        "{w`R`y",
        "The driver is not installed. Most likely it was removed by a previous uninstallation attempt.",
        "ar-sa",
        "]c*`0",
        "94;K;",
        "8KKxA",
        ",qED*",
        "DLEkx&",
        "A/(}[",
        "_v;5P",
        ".ZV-,D",
        "w.,WC",
        "certBag",
        "tf6)^",
        "-/&6W",
        " 0x67",
        "CryptHashData failed: %d",
        "O<bDV",
        "CMS_get0_content",
        "nn.WDpy=",
        "7F>gL",
        "DTf@+",
        "uL-=MW~",
        "l7-_69",
        "FWRemoveBefore started.",
        "7#yx0",
        "huw6s",
        "K\\}xO'",
        "t-<A|",
        "yTXAO",
        "l+g0W",
        "~ah!T",
        "oyX'A",
        "ja4lC",
        "'@L{MR",
        "tJyH|",
        "2v~E{H",
        "TrAPI.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "EPAM_Data.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "R!b2Z",
        "EbD(FWJK",
        "calling PiReg.exe -d with %s",
        "srePostpone",
        "xw2gr.8",
        "<,<a<",
        "vzQ#j",
        "\"@.Ms",
        "717b7",
        "P\"!Z(",
        "o7|Gk",
        "YM\"0{",
        "yJZlZY",
        "dKu%|nI",
        "mkp\\Us",
        "<4E87",
        "unsupported mask parameter",
        "[LICENSING] license revoked",
        "4$4)4.4I4",
        "[YLZ&<",
        "Acceptable OCSP Responses",
        "(Sbvc",
        ";22dV::tN",
        "rg7\\#-d*",
        "CONF part of OpenSSL 1.0.2h  3 May 2016",
        ",N#k|z",
        "<Eo!4",
        "aLwY7",
        "lust|",
        ".uMv\"",
        "]1qkME",
        "ST!r_",
        " 0x44",
        "k|YtT\\",
        "|!X<<.",
        "\\bin\\SR_WatchDog.exe",
        "r*v.`",
        ")*D.3b5i",
        "v~1IT",
        "' !QZ",
        "u;v+]",
        "@MMKT",
        ">sT5N",
        "'Z>1OF",
        "wWPTK1",
        "!\"BbA",
        "Connecting to hostname: %s%s%s",
        ":7:A:J:",
        "bt^DN\\",
        "2NP&g",
        "nCceWE",
        "id-regCtrl-oldCertID",
        "TrueVector engine: Driver API level older than vsdata API",
        "<6aJFO",
        "PVVj;V",
        "CU'`4Czd?",
        "'j:La",
        "5j%9+",
        "a9iJ,",
        "~|tDW",
        "3OcQ;",
        "kMM0m",
        "<@t A",
        "ozFN;4%",
        "Y]ryR\\",
        "Z!j7\\{0",
        "dal4Pwh",
        "Failed to allocate path to ca script.",
        "n$XbR",
        "&zwkrze",
        "RegUnLoadKeyW",
        "1>2_2",
        "9$9,949<9D9P9p9x9",
        "`QuLY",
        "ut\"mi",
        " Vq\\O",
        "Kb1d&|",
        "7\\bwL;",
        "hP@Zk,",
        "PSWSS",
        "P^GE7",
        "5RWn ",
        ">$>,>4><>D>L>T>\\>d>l>t>|>",
        "@vP8/",
        "t].g=",
        "tkD#X",
        "SOFTWARE\\KasperskyLab",
        "o F36",
        "jnEp6",
        "Helper::RemoveKlif",
        "Dq '6",
        "X2S\\~",
        "bad allocation",
        ";mode=",
        ":\\:j:",
        "CONF_def part of OpenSSL 1.0.1t  3 May 2016",
        "/Ik88~",
        "26>)8",
        "&c5LXF",
        "82=?|",
        "DH-DSS-CAMELLIA128-SHA",
        ".\\crypto\\cms\\cms_dd.c",
        "t$0PV",
        "&d-< ",
        "\\9tBD",
        "_s'|@",
        "==G-8",
        "uI<5t",
        "5#5)5/555;5A5G5M5S5Y5_5e5k5q5w5}5",
        "Successfully installed catalog file %s",
        "v`e78",
        "IvGMW(Z",
        "8U\"@?",
        "D[.?.$",
        "hcSsJ9",
        ";3^ST",
        "&].LAs*",
        "HnDm{",
        "gP<.d",
        " PYW*",
        "7*818",
        "hUW*s&",
        "r*uw<",
        "__fastcall",
        "`y0<8",
        "mu\\$+",
        "%s\\CheckPoint\\Endpoint Connect\\",
        "6_dfVJN",
        "l/C#I",
        "|$4;D$0|*",
        "V2I_ASIDENTIFIERS",
        "encryptedContent",
        ";binary",
        "67\\q3",
        "}?x1;",
        "!!haT`7",
        "CLIENT_NOTIFY",
        "7 7$7(7,7074787<7h7",
        "U2*5*",
        "n(YiF",
        "R~8aa",
        " 0x23",
        "{.;oh",
        "H*j)xs",
        "-Qrif/",
        "`3sEbm",
        "xQ^,q",
        "{n,TO",
        "545<5D5L5T5\\5d5l5x5",
        "?&UiBt",
        "u%#2J",
        "<){71",
        "2?3o3",
        "1I|V7",
        "+%D|UB`]X",
        "? ?$?0?8?<?H?P?T?`?h?l?x?",
        "-C?^gzWQ",
        "ct+ol|nl0",
        "Server 2008",
        "hJ9,l",
        "fM#*7",
        "~Y WX",
        "CuJ\"}",
        "jsjuj ",
        "C47gj",
        "Uninstall Password not found exiting %d",
        "To:x^",
        "StopCipollaServices finished.",
        "b(P|9^^",
        "9Y:k:V<h<Y?k?",
        "k((nw",
        "`dub`D",
        "{\\f436\\fbidi \\fswiss\\fcharset177\\fprq2 Tahoma (Hebrew);}{\\f437\\fbidi \\fswiss\\fcharset178\\fprq2 Tahoma (Arabic);}{\\f438\\fbidi \\fswiss\\fcharset186\\fprq2 Tahoma Baltic;}{\\f439\\fbidi \\fswiss\\fcharset163\\fprq2 Tahoma (Vietnamese);}",
        "y\"dw2%",
        "|CG'D",
        "%.0Lf",
        ".MAC<#",
        "rgNOr",
        "HSmlY",
        "4f5x5",
        "hX|hm",
        "WV$.1L>",
        "$RL*G[",
        "1*eoj",
        "^#+\"[",
        "VZeh^",
        "id-cmc-revokeRequest",
        "C(@`V",
        "6,646<6D6L6T6\\6d6l6t6|6",
        "g]d.Hm",
        "Cn2g>",
        "6V6d6",
        "`G{t/",
        "sRLlLtL",
        "2jJ|(",
        ")YWa'",
        "ua9|$Du[",
        "UninstallAV:  UninstallAV() in vswmi.dll failed.",
        "9(9<9D9L9X9`9",
        "J'mgW1K1",
        "failed to get file path from formatted string: %ls for secure object: %ls",
        "m~Vc\"",
        "calling net start TracSrvWrapper...",
        "-K-/M",
        "-Hl$y",
        "tCx$y[b",
        " &Q0<E",
        "H{V+\\^",
        "lbDK_",
        "GetBladeRequiredDiskSpace: MsiViewExecute failed on Component: %s ERROR: %d %s",
        ":8:D:d:p:",
        "2VDz:",
        ",gQ<Z",
        "RA?qba",
        "zj2By",
        "V:#.r",
        "VX9^`tT",
        "sft6{",
        "?s)N<",
        "BE^>d",
        "=iyE70`",
        "(gAk5",
        "wz0@v",
        "?6CWi",
        "aJGe{+1",
        "pkcs3",
        "|$HVW",
        "des-ofb",
        "tSav1c",
        "IsDebuggerPresent",
        "UD19o",
        "jpB|i",
        "\"ykU ",
        "ProcessPemFile Found pem file in Temp",
        ">'L0d/f3:",
        "mX-6V.",
        "6c7s7",
        "Qc5dhm",
        "e\"e&e*e.e2e6e:g>3kV",
        "5H#TF",
        "Si{!s",
        "3K4j4o4",
        "wXh*h",
        "`Vug6",
        "retrieved DEAFULT_VPN property: %s",
        "Plugins::UnregisterSC:  PluginsUnregister started.",
        "#k+[,L",
        "failed to write file indicator to custom action data",
        "[IXV*[",
        "too long",
        ":r<M&c",
        "3$3,343<3D3L3T3\\3d3l3x3",
        "V9djP",
        "Y$m7O",
        "<=&z(Z,",
        "r/9~I",
        "NSzL^",
        "%02x%s",
        "nV0bR",
        "|_{Wh",
        "rN\\$,",
        "e oF=",
        "F;nnz",
        "7[z=c",
        "ww_Zwhr",
        "282@2L2l2x2",
        "setAttr-T2cleartxt",
        "f.oU[",
        "s?;W.",
        ":N/s ",
        "wquzL",
        "MeXF2",
        "(QPek",
        "2a2n2",
        " RmDZ",
        "%hA8Z",
        "1UTGf",
        "tFPtPW",
        "ZV9^c",
        "*'*G*g",
        "WeeD3",
        "KavRM",
        "*6n^N",
        "'gHGN",
        "_]2?O",
        "1(10141@1H1L1X1`1d1p1x1|1",
        "nZ.H<",
        "7Tz:X",
        "u%jU=",
        "\\dVlt",
        "|9ba/",
        "*(bxF[",
        "7@7D7H7L7P7T7X7\\7`7d7h7l7p7t7x7|7",
        "g8`|A",
        "%33Oi~",
        "OCSP response has expired",
        "1&Fn!",
        "wg{cn{4",
        "a<fmM",
        "C759f",
        "`[.o<",
        "=,>{>",
        "/NAxD",
        "<Z<u<",
        "ZteWI",
        "zM U$",
        "7Q|NbU",
        "aRV}HK",
        "Z6Y5m",
        "iHP*W",
        ")B-q0G",
        ";^W@%",
        "dn_@R!q_*",
        "+%y/z",
        ")(dEI",
        "\\Zonelabs",
        ".k)`J",
        "JV:7%X",
        "9J0wI",
        ", iYWx",
        "/F{sa)",
        "9+Q(^",
        "keUZst",
        "3)3=3",
        "SKsZW&f",
        "959Q9m9",
        "key type mismatch",
        "y6l}]Z",
        ">O?k?",
        ";V<C=",
        "1THu3A",
        "9)|nU",
        "ark*a",
        "ITZ,D4",
        "id-GostR3411-94-with-GostR3410-94",
        "CharLowerA",
        "-.BZ:",
        "|0HvD+B",
        "gp0$%",
        "l$$VW",
        "13Oj7X",
        "BRF|6-",
        " 0xc7",
        "IIJ(=",
        "`EmT8(",
        "-6WWp",
        "=uhkF",
        "uo'Q),X,",
        "TLS Web Server Authentication",
        "#&#*,#*,#*,13",
        "key_enc_algor",
        "9Xd_TS",
        "041M1E2K3",
        "[VSUnloadService] cannot log in",
        "=$8vug",
        ")Y;3=-Ys/",
        "N~8V$",
        "_i4)[",
        "w/yJM",
        "fF47W",
        "[LICENSING] beta license expired - run time out of range",
        ".\\crypto\\rsa\\rsa_none.c",
        "h-Tnq",
        "txk--o",
        "4/494L4e4t4",
        "/5,yFb",
        "j}jzj\"",
        ",\"#'+",
        "|-5(z",
        "sk6Z.",
        "jcKIO[",
        "EY*<UV,w",
        "P?OQ)",
        "Lkg#A",
        "3$h~7y",
        "L$D3L$(3L$03L$",
        "0a!(R",
        "<)<E<a<}<",
        "&z>HLv-",
        " WPQU",
        "%&TjmJ",
        "m!t}Bn",
        "3J;wQ",
        "U+:3n",
        "<#=o?",
        "> ?6?F?",
        "iA$EV",
        "uKJ[5B",
        "788P8",
        "PHD\"E(",
        "k-Bl$",
        ":AM:am:PM:pm",
        "A(EO{(",
        "%>7:{",
        ".4*Sy",
        "eSj>j",
        ";$;,;8;`;",
        "9t$,v",
        "9o]Hv",
        "|'@|-KMdDh",
        "GetThreadPriority",
        "tNw^\"f~",
        ",!,-JS",
        "{g `KW",
        "IF5]P",
        "&Glp^%\\V",
        "jvxl>",
        "`8u,Ah",
        "2`N='",
        "969C9",
        "CgSCLS",
        "e]j]s]",
        ";\\v,=",
        "<c7G0",
        "'}r8$x",
        "HYd{>SF",
        "-r@?l@",
        "?9?U?q?",
        "#hTl*",
        "OCSP helper",
        "lM(Wz ",
        "kO4cw",
        "){>T'3",
        "#AKX:5",
        "RI!E7",
        "\"Q3b ",
        "01080G0T0",
        "kDyt.",
        "[HUn@`E",
        "S+R@U(",
        "l%{^<\"",
        "south-africa",
        "w=r<N",
        "6,!%z",
        "~~20e",
        " 6@3@",
        "?]tfS",
        "8XEg+",
        "7qb-(@z",
        " bytes",
        "O Aj\\1",
        "S<)\\b",
        "ASN1_ENUMERATED",
        ",+ZWbW",
        "\"uJdR(o ",
        "@A?$'5H",
        "7\"737>7",
        "Z9WHQ])y",
        "dG:W'",
        "U;fr8B.",
        "V+S~\\",
        "NDyZ%G(",
        "2RvGy",
        "[HGo^d",
        "Vp}\\;",
        "8#9^9",
        "z?VD<",
        "!b&x'Wo",
        "Ab ~d",
        ".!jlj",
        "z8LJ-",
        "878I8d8x8",
        "UMF u",
        "s5qcv",
        "5%595V5`5n5s5",
        "setct-PCertResTBS",
        "%X`!8/$",
        "rztf-Y",
        "NKog#l",
        " SSL certificate issuer check ok (%s)",
        "\"&<wJ",
        "Sj7do",
        "ssl session id is different",
        ".\\c5B5\"i",
        "yzp:c",
        "Qh,\"!r",
        "GSSAPI handshake failure (invalid security layer)",
        "I7!DU",
        "xbg:J",
        "4>4k5",
        "publicExponent:",
        "A(;A,v",
        "gZ'qk",
        "4+-i!",
        "][_^Y",
        "(wT:A+",
        "Kh;2m#E'",
        "4!4-4i4",
        "11'0&&U",
        "L-Jnw",
        "U3H]Wh",
        "W9CG0",
        "^w&Af:",
        "uLgE{f",
        "O_Db:+1",
        "}2woV",
        "3?w)EA",
        "hU}UupU",
        "dJ&\"]",
        "on of this Agreement, You agree to cease all use of the Product and to return to Check Point or destroy the Product and all documentation and related materials in your possession, and so certify to Check Point. Except for the license granted herein and as",
        "lukRs",
        "{%`YeT;`",
        ">AD?r",
        "w1V4{",
        "zDQ<c",
        "U9f<>",
        "bh0%a",
        "IYo<LP",
        "pgV8\"",
        "jAjej+",
        "c2tnb239v3",
        "f8nY8",
        "cP_`6",
        "k0Kt|x",
        "lBq}+YV",
        "M;;va",
        "4Q0Av",
        "eT}s9",
        "Q2=!Q",
        "9.u@h",
        "8P8s8",
        "S;'lVgt",
        "gHBe-",
        "I}dth",
        "T@4dK/",
        "7C8v8",
        "OFhAsyu",
        "6G7]7",
        "CRolloverMgr::CopyRolloverBlock():  rollover not in progress",
        "-%=N#A",
        "^[fJ@:",
        "B2I_RSA",
        "9h_7#R",
        "ac-proxying",
        "hl~~`",
        "RMTps",
        "1o>uy",
        "C]c&Jqa",
        "\\!7Ln",
        "\"S;]{w",
        ")z7:s)G",
        "pilotGroups",
        "\"YOmFV",
        "78RkRr",
        "eM<[Zc",
        "72777s7",
        "2A2a2",
        "&-M4&",
        "LDAP: cannot bind",
        "<v{K\"T",
        "u}jr1",
        "`3/7$S#",
        "pIww(",
        "6y*b&r",
        "T@OOpS",
        "}\"zRRA_k",
        "msCTLSign",
        "y1o$q1",
        "o74Q!",
        "e$zpt",
        "=/!{7",
        "ANDPD",
        "es-GT",
        "r}u?k",
        "<^:IO,",
        "qnhHoR",
        "6GsJ:'",
        ";K&TZ",
        "guqG5l",
        "/e)iez",
        "7#878S8",
        "],WcV*",
        "&a+28aw",
        "xHG{W",
        "0H1O1V1t1",
        "=dnVH",
        "J?/^F",
        "Z0EI4&",
        "camellia-256-cfb1",
        "ewx?UY",
        "D$(PQW",
        "\\bin\\dingo.dll.delete",
        "\\zonelabs\\UpdClient.exe",
        "3'4_4v4",
        ":%:>:W:p:",
        "inappropriate io control operation",
        "m)~ET\\D",
        "\\p6>y",
        "$cHoB",
        "T9NES",
        "?&?;?@?",
        "GEOMc",
        "\"!|XK8t",
        "@Ph$.!",
        "333A3",
        "%yXvcA",
        "C~l2I",
        "`N*\\u *",
        "c_OQ*:",
        "Bt6!H",
        "zD)kQ",
        "![)mVN}+",
        ",'-'r",
        "y($!L",
        "'vk]]",
        "'Aoh]",
        "sCxS ",
        "BKNAc",
        ";0;8;@;L;l;x;",
        "xj`$C",
        "^$ioG",
        "jBjjj",
        "SSL: couldn't get X509-issuer name!",
        ": :L:P:T:X:\\:`:d:h:l:p:t:x:",
        "SK?Nv",
        "?9~(t",
        "DY*n<>U",
        "GHB4Ec;",
        "\"|`L-",
        "ynY~`",
        ".\\crypto\\ex_data.c",
        "nq:\\_Wc4",
        "RfiI z",
        "WliJn=",
        "]37o`",
        "}O&^g!",
        "j4z8$",
        ":9>~6",
        "bOjluz",
        ";7uE;",
        "Superseded",
        "4C5f5p5",
        "3G3k3w3",
        "xAsX[",
        "ynj/&E",
        "C,4lG",
        ".9/7B",
        "p!nU[",
        "3!~1d",
        "id-smime-aa-encrypKeyPref",
        "f0_JA",
        "-/}gZK>",
        "Plugins::Register:  PluginsRegister started.",
        "V<)rkG",
        "<pK\"z",
        "7X;ExN",
        "\\$(j:U",
        "')X@9",
        "Z^v;zsY",
        "pbeWithSHA1And40BitRC4",
        "uEaX6",
        "[Self Validation] No patch",
        "K$=c0",
        "GIf\\bW2",
        "\\(Q|Q~x",
        ">>>C>H>m>",
        "jCjwj%",
        "6,6;6V6h6",
        "x?00W",
        "s^X8M",
        ":{:6;",
        "9 9D9",
        "62bp7",
        "JOB[E",
        "^7`)2",
        ",ZmV%",
        "lwhW!",
        "ct is licensed to You based on the applicable Licensed Configuration purchased, as set forth in the Licensed Configuration definition in Section 1. The License permits the use of the Product only in accordance with the Product spec}{\\rtlch\\fcs1 \\af1 ",
        "AddForceFieldEntries added '%s' .",
        "}x-<q",
        "NJ6dT",
        "PE\"rY",
        "StopEFRService finished.",
        "7f7v7",
        "<>>T>",
        "B%fW$3",
        "sr_VPNClient.chm",
        "< <0<4<D<T<X<h<l<|<",
        "qjg9&",
        "wNFv^",
        "[d4?1",
        "E(\"f@",
        "zbieG",
        "%h\"csi-",
        "ENGINE_by_id",
        "L%N`*7# ",
        "7aZ4n",
        "s{)! ",
        "About to install VPN (Secure Client or Endpoint Connect)",
        "]\"*{0",
        "CONF_load_bio",
        "+qfZk",
        "int_dhvparams",
        "1(A/S.",
        ";5<C<c=+?",
        "i;U(@",
        "yZk0!",
        "Kn%VJN",
        "i2d_ECParameters",
        "H3xS2\\:",
        "|7p;<",
        "WVVVVV",
        "`\"qat",
        "W_{^P+",
        "`8-~@N5",
        "O{rAD",
        ",Y>IJ",
        "*>Ok1.",
        "U&a1y(e*\\H",
        "}lLg9",
        "b@J L",
        "<qCih",
        "-v!HtR",
        "szUpgdPW",
        "XmO!`",
        "?$?<?L?P?`?d?h?p?",
        "timegroup",
        "u.f9X",
        "KE%-=8",
        "zX%}XEiF",
        "jH^`pu",
        "LNaraw",
        "Il|<d",
        "n?Pgu",
        ">*>]>",
        "Sm:)G",
        "213A3",
        "v<0,4",
        "8f9t9",
        "^\\oDQAn",
        "0z8&!",
        "q87{G",
        "yUSIY",
        "4D]d:]",
        "n,Ejn",
        "kGo/F",
        ".\\crypto\\engine\\eng_table.c",
        "%0$j-",
        "L_+M*h",
        "l$0VW",
        "/EN'HddPKcqU",
        "O7Sl?",
        "{1~\\8",
        "mzm^p",
        "7n@@W",
        "Jz)apL",
        ">M7OL9",
        "nuYL|",
        ")`jc-",
        "GG8qcRf",
        "2DOL6@(",
        "ec_param_enc",
        ";m9->a",
        "jB8:M",
        "HQm 3",
        "WedCU",
        "7{M1[",
        "ec2t \\u",
        "getProductModeFromLicenseKey;",
        "\" /passive /norestart",
        "\\uXOz",
        "FU{k\"y-",
        "U'C#v",
        ".\\crypto\\x509v3\\v3_ia5.c",
        "Wv.~B",
        ":,:0:D:`:d:x:",
        "7>Z[2O",
        "K50i&",
        ".-6RW",
        "Failure occured while processing WixInternetShortcut table",
        ".=%MN",
        ",Uo>7E",
        "ypz8{",
        "00qlm5",
        "CreateEventExW",
        "DH_PUB_DECODE",
        "d{CY6",
        "\\rT%A",
        "YYh0!",
        "hbS.m",
        "gVyJ=",
        "`%dE~",
        "\\XVJ$n",
        "X(]!*",
        "?\\?a=f",
        "{d}R ",
        "[EM=I.",
        "e}rnu",
        "InstallationFinish",
        "Q@El3",
        "<,<F=^=",
        "s262Y",
        "$k~Sn",
        "!k{H7",
        "qTwZ8bO",
        "8./(O",
        "dual ec drbg disabled",
        "9Ppk!",
        "9[^O+h",
        ",a*]d",
        "EC_KEY_set_public_key_affine_coordinates",
        "~.^!rx",
        "#pAZw",
        "unspecified",
        "'90I#",
        "kn'jY7",
        "m>4/>",
        "5'\\ADBzNn",
        "-8RQ|e",
        "\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 2;\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 2;\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 3;",
        "?(???O?\\?b?o?",
        "5<5l5",
        "o[Rgg",
        "5tHf{",
        "EndSession",
        "EFK[^",
        "0C59d",
        "L($I6q",
        "xFC*t",
        ";$;(;8;<;H;P;X;l;",
        "w+cwqa",
        "6$616K6a6o6",
        "G9&/Y",
        "fN8u-",
        "}?K~)",
        "SUBSD",
        "7V.?Ad",
        "f);ND3",
        "~\\\\UuA(w?",
        "FD*{x",
        "/l#E'",
        "\\vsdata95.vxd",
        "N7=@w",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\UIFramework\\3.0",
        "+mhB$k",
        "}~c~n",
        ">#o[JP",
        "?#?1?D?o?",
        "2STH{b?)O",
        "janetMailbox",
        "IWtTi",
        "'\\9'm",
        "3+333<3E3V3g3",
        "%*sOrganization: %s",
        ")YE}E",
        "0qyQ~",
        "/K_LU}",
        "^;p6p",
        "@ j{*$`",
        "6<6C6W6|6",
        "_tlX3",
        "9):;:^:c:y:",
        ":'a<^",
        "oR~+M",
        "\"'&pb",
        "%m,<*",
        "5#6m6r6",
        "h\\}+X",
        "L3;W=",
        "&h\"YR",
        "SELECT * FROM `Property`",
        "F@SA?",
        "465Z5",
        "1S!D5L",
        "3)4V4",
        "pD%e|",
        "00d0c9ea79f9bace118c8200aa004ba90b0200000003000000e0c9ea79f9bace118c8200aa004ba90b46000000680074007400700073003a002f002f007500730065007200630065006e007400650072002e0063006800650063006b0070006f0069006e0074002e0063006f006d002f00000000}}}{\\fldrslt {",
        " /&uye,",
        "y$\\a8",
        "RSA-SHA256",
        "i9l&y",
        "?\"_^t",
        "748t9t:",
        "R n=X",
        "VJAT*f",
        "7^RPmnf",
        "\"J+QQ5",
        "certificate not trusted",
        "5\"52575<5L5Q5V5f5k5p5",
        "}a9AYRn",
        "'VHJj",
        ":]/0bIL",
        "3'4_4",
        "A_y}3",
        "\">*EHy",
        "DdOEc",
        "c>(0t",
        "%h1q@",
        "dqR{q",
        "gRh,H(",
        "tz0g-",
        "_#)<=x[",
        "mmD>c",
        "7[sjsG",
        "RQ.oY",
        "KsHY*nQ",
        "4*4N4e4j4t4",
        "{WC]R",
        "C$B4C-C",
        "4,ihj",
        "\\=}k)4v.%",
        "P~5UC",
        "a-s!h",
        "?><p+",
        "Failed to open a view on the RestartResource table.",
        "x6-r`L",
        "MMMML",
        "GetBladeRequiredDiskSpace: MsiRecordGetInteger failed on Component: %s this is due to MSI_NULL_INTEGER",
        "7G-fM",
        "3(4c4r4",
        "0tr)i",
        "DQWORD ",
        "\"opQ`",
        "KD@3EuK@",
        " _^]3",
        "!!pB+",
        "5B6Q6",
        "!%'()*+,-./0123456789:;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_abcdefghijklmnopqrstuvwxyz{|}~",
        "<D0i^",
        "?f?=u",
        "^wQ-?",
        "If,Q>f",
        "yb}+Ag",
        "4:4T4z4",
        "8*8;8L8\\8x8",
        "+J#9ym",
        "]j8x9`j",
        "xh-ZA",
        "Uk/@C,(",
        ";C*6;",
        "l8XV69",
        ": :(:4:T:\\:h:",
        "5'6L6",
        "eDVNVP",
        "iUQ-C9",
        "}VwEGV",
        "-/3>L0",
        "{y9G`z",
        "SI+; ",
        "Failed to stop Watchdog",
        "KPgm8",
        "\\red0\\green255\\blue255;\\red0\\green255\\blue0;\\red255\\green0\\blue255;\\red255\\green0\\blue0;\\red255\\green255\\blue0;\\red255\\green255\\blue255;\\red0\\green0\\blue128;\\red0\\green128\\blue128;\\red0\\green128\\blue0;\\red128\\green0\\blue128;\\red128\\green0\\blue0;",
        "RevertProtectionPPLProcessByPid",
        "/r\\Mwc",
        ",lWgB",
        "S^~ZM",
        "AES-192-CFB8",
        "2n~P#O",
        "l$LSj",
        "/9jIs",
        "PSK-3DES-EDE-CBC-SHA",
        "lvWx5SqS",
        "7Xe*f|bP",
        "%AdZ:",
        "$mkfjPXG ",
        "'+<+R",
        "2~W6#",
        "Aq=~B",
        "O\\X}/",
        "[o~4 ",
        "mime-mhs",
        "I #. ",
        "#4EkBV",
        "l$$t3j",
        "WjxhP",
        "unwise.exe",
        "wSVZF",
        "747@7`7l7",
        "ZZJ@f",
        "q}d0f",
        "lp+uL",
        "K{J45h",
        "_=@XrI",
        "SUPDUP",
        "zd;T0",
        "7=\"8Q",
        "4*5Z6]9",
        "tls rsa encrypted value length is wrong",
        "9$R<d",
        ":i`!E",
        ".^>@U:",
        "VG6y\\",
        "NnrW' ",
        "Nmu.{-",
        "tvi9k",
        "APVlS",
        "+[DGu",
        "\"b2R%",
        "]9vY}",
        ":$:(:8:<:@:H:`:p:t:",
        "|To?`5E",
        "jbTZ*S",
        "(f4jO",
        "\\\"pWI",
        "TS_VERIFY_CERT",
        "U^JL.hU1",
        "=}SHyJF^",
        "4D4H4",
        "Finished scrubbing system ...",
        "3aJwo",
        "lWcL#",
        "|aCGL",
        "HY9+E",
        "CZb#?",
        "/'Kb>a",
        "QVVVj",
        "s!E|7{A",
        "lK\\j-L",
        "*bqvq",
        "K(zDe",
        "1T3{LH",
        "CPDA;",
        "5:5V5r5",
        "8[u'f",
        "*1J#\"",
        ";;9K=",
        ")^o:Z",
        "l#z\"U",
        "Qd?&5",
        "k\\77x",
        "HZgaM",
        "b=>)BD",
        "jhj{j",
        "EVP part of OpenSSL 1.0.2h  3 May 2016",
        "ya#*Z",
        ",4f`e3R",
        ")+atZ|L'",
        "WXv@/",
        "aqc1Z",
        "lPND$_",
        "w6t&=",
        "Eror TID key could not be obtained %d",
        "614F8A1319EB85D40AD5E8F68E1469A8",
        "w#|rr",
        "cz2x=!E",
        "efE7r",
        "T{*(m",
        "FWJ$v",
        "~+{d\\NK",
        "8 80848D8H8L8P8T8X8`8x8",
        "jJmjT",
        "\"$1bB",
        "B2]of",
        "OLDPRODUCT",
        "5Idk8sI",
        "xQ:J9",
        "JSRwp",
        "2$cj' ",
        "jljmj%",
        "oms{i",
        "GetDesktopWindow",
        "<6C%(x\\",
        "5sJZDv",
        "/Dcp)",
        "jw`[B'",
        "*R7r,M",
        "c,|gdt6)L#|j~,",
        "`C-^(",
        "!pTMRv",
        "nLs$G",
        "K'zE%",
        "}2}js",
        "3?3M3\\3i3t3",
        "crt_term_",
        "6(-c]",
        "n}G>Dz",
        "L/^R(",
        "Li~,K*",
        "/0>I:%o",
        "5'525=5I5",
        "j4OYf",
        "%s %s%lu (%s0x%lx)",
        "eVh)'",
        "FV*2c",
        "usH49",
        "7g\"'k",
        "Jj{{.Q",
        "pM,yO",
        "kI>n~nQ",
        "oTD>A",
        "uninitialized",
        "h0Lfx/",
        "<%<-<}<",
        "4?v_z~",
        "q0Q1D",
        "tKdov",
        "D$ ;\\$4",
        "1Y2e2",
        "qCZ[(",
        "Aub]c2",
        "4J4a4n4v4",
        "DX|F5",
        ";8<G<",
        "364D4",
        ">Kdz#",
        "\\OqTh",
        "=,=E=Q>d>{>~?",
        ",v}Ol",
        "eC,)EB",
        "WVUUU",
        "9H<]<b<",
        "szInstPW",
        "A|-3u",
        "it=.0+N",
        "}t_c,",
        ":\";8;\"<",
        "Hu:}Bq",
        "=}O[]",
        "Y+V58<5$",
        "\\ZoneLabs\\zlupdate_adaptor.xml",
        "3@4J4e4",
        "X'ys)",
        "6<6b6{6",
        "]>/A0",
        "A9u)*MHA",
        "EP&A@",
        "}=sVL",
        "uy1d>m",
        "J[_Tw'Vg",
        "Mm+3-x3",
        ";}=}>7?Q?",
        "2'202Q2",
        "/?ghj\"",
        "-vhnk(",
        "Products still registered, cptray will not be removed.",
        "[|9dtcs4T",
        "t03gt",
        ">ODd2,",
        "#&95k{",
        "z\"8h]",
        "KNAsD",
        "B[.\\[",
        "U_9-W",
        "<w\"EJ",
        "XfXJ@",
        "FW_DOS_DEVICE_C",
        "4'4[4l4",
        "PKCS#3 DH Public-Key",
        "#aB6\\&",
        "W(b$?",
        "mx:a/",
        " 0x82",
        "Xw,y2vK",
        "!hcK+dbF&",
        "Ib?6T",
        "5/nf476S",
        ":8:Q:j:",
        "ECDSA_CHECK",
        "Pwk/<)",
        "D'7zV",
        ":0:W:n:",
        "969[9m9",
        "j&18SWR",
        "k: zr",
        "8<n~];W",
        "|ae`f",
        "ASX7:B",
        "k^JOb",
        "jnjnj'",
        "]ZL\\9",
        "jxYf;",
        "STREAM_ERROR_VIEW",
        "BB\\(m",
        "NQPBrNoZdm",
        "yYzB]",
        "SD9,!>",
        "[Pp1v|",
        "{R68<C ",
        "4Q;@;",
        "4nt}m",
        "h.Q=A",
        "unknown digest type",
        "Tzff/NRy",
        "iY7x)",
        "y\\)ye",
        "Fu4d0R[WU9 ",
        "i4/QK",
        "$0TJdJlJtJ",
        "0v8om:#",
        "W`|,vl",
        " c:D[",
        "7c@z3E",
        "J4ppZ",
        "O07>@",
        "8rgk?&",
        "0YkRH",
        "4I4v4",
        ".o?U|;",
        ";!<7<?<F<U<q<",
        "</<K<g<",
        "api-ms-win-core-sysinfo-l1-2-1",
        "SI!mb<",
        "Iy_}z",
        "+GQ@h",
        "CpGxY",
        "g%/V,B",
        "zRF%H",
        "FXu\"j)j",
        "~Q-~7~k",
        "5h6l6p6t6x6",
        "U-GHj",
        "o!>R&",
        "WUI.3EB01D56_A355_4609_8CD6_3EA431E07494",
        "tsa name mismatch",
        "Uninstall all drivers.",
        "C9,OW",
        "0a_mZ",
        "RSA_padding_check_SSLv23",
        ":1m}x[",
        "SETNO",
        "^gumBX",
        "parameters",
        "iz_X,",
        "p=S:Bk",
        "lt-LT",
        "=%)qF",
        "Im4);/",
        "D]{VV",
        "DM?[U",
        "CA2Wk",
        "%nks<",
        "failed to process terminate exit code from CustomActionData",
        "Mzr1;",
        ",--Xe,Me",
        "f8{Mr",
        "o{=Ir",
        "!+{KD",
        "bad message type",
        "%J*^#G&<",
        "rcG5Kr@6",
        "%/mIw",
        "{L2~#w",
        "B-g]u",
        "!(qzNO",
        "i|>.Rb",
        "T#) D`0",
        "u%V#J#",
        "CreateEventA",
        "`LiKU",
        "t{rRh",
        "/h|4X",
        "Y^(I'",
        "%}4V#",
        "U>8OLw",
        "}0fKe",
        "4_uX?",
        "_5qpY",
        "D)Koc",
        "tmJ3L",
        "D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "L6<\\]",
        "_s=L/4z",
        "XKiNP",
        ">]\\)OI",
        "~M$xx",
        "$2Og9YtTb ",
        "W2ICB",
        "mob_ConnLogo.png",
        "URYQ#",
        "SC_UIFRAMEWORK",
        ";@_~0",
        ".et:M",
        "4%2Oh",
        "ssl3_setup_read_buffer",
        "uUM6]",
        "appending...",
        ".q2&G5M",
        "l{6K^",
        "ekM!d",
        "ERE-)",
        "rM^*G",
        "IR`)Q",
        "4?q%g/3",
        "uBSSSSRQS",
        "5RFAO",
        "? ?$?<?@?X?\\?`?d?h?|?",
        "gpfJ\\",
        "v9{io",
        "5*:2:",
        "PCehL",
        "gCFjG?",
        "839V9",
        "5O6Y6_6x6",
        "j\"J>&e",
        "#6gNwU'+",
        "hck%F",
        "UHIzB",
        "^<2yh",
        "JOU+4",
        "b<@?`",
        "Z@Glcd",
        ".\\crypto\\bn\\bn_gcd.c",
        "4:5a5z5",
        "T`ydL",
        ":_=O>",
        "-]xo`+",
        "K(]R|d",
        "626B6J6Z6",
        "+POi|",
        "+AHVj(",
        ".?AVHashDB@@",
        "UDEeEDxU",
        "#Lvr~R",
        ".\\crypto\\x509v3\\v3_sxnet.c",
        "4@4G4",
        "fosx>",
        "D!Q4m",
        "kt;N\"%",
        "LoadLibraryExA",
        "statusBarGreen.png",
        "1UtAT",
        "l~x.S",
        ">[U6d'",
        " o~V&r",
        "?\\IByGU",
        "i1iZU/L",
        "x8-,B",
        "X<n`e_",
        "odPtC",
        "OP}@)+",
        "@(h9C",
        "https proxy request",
        "MrIis/n",
        "!P)|p",
        "SPSSSW",
        "I'Lz(",
        "T-&sK.",
        ",1}IA",
        "1+y$8u",
        "EYh*7",
        "!m)m1m9mwm",
        "7YFv7",
        ";!;A;Q;a;q;",
        "2*2C2V2",
        "6 7M7",
        "]V-$V,",
        "<I>Q>|>",
        "%VDqi",
        "}Mf-c",
        "t#Z/bw",
        "UninstallFW:  UninstallFW() in vswmi.dll succeeded.",
        "D$4_^f",
        " Xna_",
        "# oG8_(",
        "vZM4i",
        "gO#ic",
        ".U<UhLa",
        "171+8[:",
        "391<%:M,",
        ";%;c$",
        "):7MO",
        "+[+n&^M!^em",
        "version",
        "[)!Y:",
        "nX(z|7",
        "vHdL's",
        "#p#>U5",
        "W,4Gr",
        "T7IX3CubY",
        "cnG2]?",
        "k1aI1",
        "pkOW]U",
        "cms_env_asn1_ctrl",
        "S.~SJiE",
        "=X>p>",
        " ^H'>",
        "73~):",
        "-{+'8",
        ":-;4;;;N;a;t;",
        "5E5N5W5",
        "K7jP!",
        "service %s is already running",
        "\\,X /0",
        "jojxj",
        "0s1YrS",
        "c D W",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid3545685  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 support options Standard, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "\"Lm2YZ",
        ";pH\\%?",
        "Po}Uo",
        "n.XFY9n",
        "IzaPO",
        "FUCOM",
        "Nnt_cP",
        "v,%@}",
        "Ld V$L%",
        "CK0gal8O",
        " k0P*",
        "6vAI|",
        "Db q!hp",
        "X0YpY",
        "\\fs20\\insrsid10178046\\charrsid13256927 ,}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid13256927  }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid14361226\\charrsid13256927 as provided by Check Point }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "The driver is successfully installed and started.",
        "Io$tX",
        "AM_INSTALLED",
        "WJ3{F",
        "AIF_s",
        "_BTpJ(",
        "U?n?p",
        "h3fI+L,",
        "VerQueryValueW",
        "@<jKcA=",
        ">DEhD",
        "#:|2k",
        "t1+0y@:",
        "E9Tz)",
        "ITU9}",
        "VM,aa",
        "lstrcmpiW",
        "0!0G0",
        "X+Bt=",
        "}V*aiC",
        ": whd",
        "<%=>=D=N=X=p={=",
        "RfS9_X",
        "kuZ#oA",
        "0hVT3",
        "Failed to create the UI thread.",
        "X9.62/SECG curve over a 256 bit prime field",
        "RC4(128)",
        "1)VFd",
        ";iW)Sw",
        "lT\"wr",
        "&$1!@",
        "0'x4~",
        "copy SCUIAPI.dll to temp",
        "H=D~k",
        "?VKq7",
        "CheckPoint\\Endpoint Security",
        "Bj~qzF-",
        "s]_lv",
        "3TFH8",
        "k~~hrH\"",
        "FaultOffset",
        "WDp=\\Ya",
        "DQ@[C0",
        "\"g6-@",
        "1{(wf",
        "COZls",
        "|$0Pj",
        "^-^5_=",
        "Update shared dll counts",
        "in?U/",
        "mN<)u|",
        "New PATH is: %s",
        "+H+uU",
        "rQQPOhm_",
        ";#;K;",
        "MinghuaQu",
        " 0xe3",
        "kM$,M",
        "1\"WZ=z@}",
        ">(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>l>p>t>x>",
        "xsi\";",
        "hong-kong",
        "OnInstallDriverFinish.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "ssl_sess_cert_new",
        "We 0&",
        "!Ft^I",
        "D`Fxy",
        "]yWS5",
        "supportedAlgorithms",
        "PF2ID",
        "{,a3B",
        "&N,9Hi",
        "%Z^iP",
        "l7H4h",
        "{\\bYi",
        "mw,Bpn",
        "}nDo;",
        "OFD}M",
        "X.&A\"Q",
        "DeleteCriticalSection",
        "gf}&b",
        "=*=Z=",
        "BIO_ZLIB_READ",
        "b7!;8",
        "GT2,a!&%",
        "G#ZM@",
        "(P<CR",
        "pq(%x?",
        "`bso,",
        "W%]s&3",
        "+y-r%",
        "j-.B!",
        "<$<D<P<p<|<",
        "^((+/",
        "8~h:|}E",
        "/Qit7",
        "O8zr&",
        "8<8c8",
        "\\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420 AS STATED HEREIN,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid9971420\\charrsid2646135  CHECK POINT MAKES NO WARRANTIES WITH RESPECT TO any }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\caps\\f1\\fs20\\insrsid11349575 ",
        ".?AVInstError@@",
        "5Digital ID Class 3 - Microsoft Software Validation v21/0-",
        ".H,lU",
        "0Gljs",
        ":':2:8:=:J:P:Z:h:t:}:",
        "k<!c:",
        "7WW;R",
        "2u'T|",
        "OMy^r",
        "s)g!V",
        "[k=;|L9YhM",
        "CreateFileA",
        "YtSu;",
        "9-:9:a:t:",
        "T<:k/",
        "-[gGiW~",
        "6<Ln6",
        "yWd=<",
        "D7T+I",
        "l:+#G",
        "u2eH)",
        "expected ;",
        "yNfJr",
        "-6X;q",
        "ge]2y",
        "Z]hd<",
        "L6s(J3",
        "md_size <= EVP_MAX_MD_SIZE",
        "vA@E$",
        " ^fmVR",
        "attributes[0].value failed",
        "boost::filesystem::current_path",
        "U%}4#",
        "BK\"a#",
        "SSL_set_session_ticket_ext",
        "\"T hnuuU#R",
        "8!8`8",
        "_vAgp6L",
        "M[S_<",
        "QDAY{",
        "F`PVj",
        "AA}_&",
        ":=;a;l;",
        "&Euu'",
        "UrlfUcpArch.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D",
        "w^\\Cu_",
        "rC6NH",
        "Yo<4M",
        "emailAddress",
        "bD`~`+N",
        "NPJi2%",
        "sect409r1",
        "b40Y_b",
        "qgw]x",
        ">Yml]+HWb",
        "d6Z9B",
        ",X)DDr",
        "2+3A3",
        "_Bb]H",
        "-<27t",
        "NFkzy",
        "Uo$Ti",
        "iq#r\"ShE",
        "\"2sscj.",
        "AF\\mL",
        "T#<'*",
        "Wm+-B",
        "a`vn+",
        "70503",
        "|>WS1",
        "v't^2",
        "qPA(x",
        "IpxGK.",
        "O gNx",
        "8 8X8",
        "3$3,383x4",
        "* )<[8",
        "b~J[g&",
        "z> FWD",
        "$t[gr",
        "t-jgh",
        "[tuYu@",
        ",3Z1_[^8_5\\.",
        "GB?qoQ",
        "UCdED",
        ",B3?w",
        "}}OP_",
        ">>]]||",
        ">/?5?u?",
        "M^)4j",
        "!<wD\\",
        "t]\"/9~",
        "05VhU",
        "c*{:8",
        "708:8W8h8}8",
        "1?eu0",
        "Nbv2G",
        ".%v^tcV",
        "_< ~B",
        "y;v#m;6K",
        "@.data",
        "yh%U;M",
        "xOqKI",
        "'oQIg9",
        "t2:O^",
        "D$4PS",
        "AESNI_INIT_KEY",
        "0&000:0D0}0",
        "'L[t]",
        "P\\a[l",
        "l@Y[S;S",
        "Kvh5s5",
        "#1K3t",
        "Y{[Bb",
        "=3333w",
        "=}hth",
        "83q.|",
        "[IsServicePPL] QueryServiceConfig2 failed: %d",
        "iiW 2A",
        "*kw\\_",
        "]2I0D",
        "eaN4KQ",
        "~m)rZpo",
        "B>rmL{1{",
        "OpenSSL SSL read: %s, errno %d",
        "sslclient",
        "`!M!v",
        "pt]z6",
        "{:|&'",
        ">!c$o!",
        "8H`gZ",
        "mrA^`",
        "jKBZ(B",
        "111Q1a1q1",
        "[5<c3UN",
        "-6_Y[[7",
        "NK1SCd~",
        "tbnJ4^",
        ".gF0XD",
        ",%]RXr",
        "ZELiy",
        ">L|c ",
        "CuzFno",
        "r'+n\\",
        "m<L~R.",
        "yVx#k@sk?eY",
        "}zT5q",
        "uJjc'",
        "2]#k_9{{",
        "W&Z9ixF",
        "ENCRYPT",
        "(Mi)A/H",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid5000668\\charrsid15169477 ,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8128984 and }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "q]T>pq",
        "=(=.=;=D=N=X=c=i=u=",
        "installProduct",
        "ca-es",
        "K9@&_",
        "7*707C7I7p7v7|7",
        "Caller must register CURLOPT_CONV_ callback options",
        "Q3`bS",
        "#vi,b",
        "t;oO@",
        "CgzMS\\",
        "><>E>l>",
        "curVer is one that requires uninstall info",
        "?G?t?",
        "]BP9ro",
        "~.r%[",
        "-HUMp)E\\",
        "6Lw$!",
        "8\"8(828D8V8[8c8o8u8",
        "<D4$v7",
        "No locks available",
        "p}An4",
        "ejj:H+",
        "&Sn+S",
        "L;oUw,",
        "3MQy_",
        "Y&wJ,",
        "]FB;b#",
        "R_79B",
        "PcgL0J",
        "4$4,484X4d4",
        "CryptDestroyKey",
        "~sb($z",
        "X509_REQ",
        "ZB%DX",
        "[VSINIT] VsWow64EnableWow64FsRedirection: Wow64EnableWow64FsRedirection failed",
        "HTTP/1.0 proxy connection set to keep alive!",
        "hJfq=]9<",
        "=ky75",
        "]~Iz<",
        "^%`EE",
        ":<M]mO",
        "to3No",
        "vb3nFsm",
        "Rby}7",
        "I=:lm",
        "2GufY",
        "4K4P4o4y4~4",
        "6/7v7",
        "Found Check Point SBA installer",
        "B/c%_yNQP'",
        "445C5]5{5",
        ",e_ER ",
        ">M~/o",
        "eMfmf",
        "<*<f<t<",
        "6rA4>m",
        "SSSSSSS",
        "7H7S7g7q7w7",
        "ieE*tfd&",
        "</<P<y<",
        ".mY_jY",
        "F{B,%",
        "aEFlS ",
        ":V:e:",
        "rlx- ",
        "C#p0+",
        ".q1,0",
        "1E1k1",
        "`,r-~",
        "^bC/o",
        "XwWO8(",
        "%h)Q]",
        "=$0\\q",
        "XX&{E[, ,,",
        "D4G(D",
        "#+%]\\j",
        "id-cmc-transactionId",
        "0#6c/",
        "SVWQQ",
        "L<X=<",
        ";B(iVY",
        ".?AVCFileMonitor@@",
        "Unable to determine the version of %s",
        ")101X]",
        "}X/8O",
        "\\ZoneLabs\\DisconnectedPolicy.xml",
        ":gj0*<5#",
        "L$(WQ",
        "5!565B5T5",
        "xn>%T!",
        "qk:&U8",
        "Rkq]n",
        "*AY\"!F",
        "zU>(v+Se",
        "sl;Y@>/.",
        "afKQ6",
        "{RL~a",
        "we are done reading and this is set to close, stop send",
        "5X6t6",
        "H>E8.b",
        "SCRemoveBefore finished.",
        ">&?H?h?~?",
        "kdDj~A>",
        "Iqy/h4",
        "zF8U=",
        ")Ignb",
        "_rNA5",
        "\"{Z$.",
        "<J4|Ft1",
        " -`2(",
        "w)WRV",
        "tlsv1 unsupported extension",
        "tB{&wNC",
        "@)p8+!Dm=_",
        "x~~zx}~zy",
        "qFMvn",
        "Failed to get data for property '%ls'",
        "&DO9z",
        "5I5^5i5",
        "X[}pJf<",
        ",'nU4Q",
        "kY+yB",
        "3_2TH",
        "ENGINE_get_digest",
        "Mph.t",
        "6&6-6H6Q6a6n6",
        "McI7ft=",
        "t$@VU",
        "C<fJ.I",
        "5E}Mys",
        "TFKr$",
        "1}>iY",
        "T0a$8Q",
        "I\"{c$",
        "\\par Check Point Software Technologies Ltd.",
        "-a]f9",
        "oF(UJ",
        "vM5 p5F",
        ",g= B",
        "!xqn=",
        "LFT4f5Uf\\a",
        "SNE->",
        "-Z;=\"d",
        "Y`Cy&",
        " #VJY$^",
        "UTHD{+1",
        "G[2C7a",
        "7\"[JHc",
        "uvVcrdu",
        "qbt>Z'&",
        "U4ZE&",
        "3yrH|",
        "P`Gxz",
        "4f,Ti2i~z",
        "<0=+?[?",
        "\\par }\\pard\\plain \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\f1\\fs22\\cf1\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "hEM]f:",
        "kElDx^|",
        "HTTP 1.0, assume close after body",
        ":.:G:`:y:",
        "VrfGf`",
        "2x=nh",
        "r`oU5",
        "j`F{w",
        "2a!bX",
        "rK/+M\"",
        ":TYA=",
        "=EzjUc",
        "n5-ln9O.I",
        ";N\\u\\W",
        "error instantiating drbg",
        "b&bSDM",
        "OL}W9",
        "RegEnumValueW",
        ":4;j;",
        "ec_GFp_simple_set_compressed_coordinates",
        "\"i};.A",
        "]F1'4",
        ".FYX|",
        "@rx^v",
        "k&$,1$",
        "1070J0R0]0",
        "iiq:4",
        "/sd)f]",
        "BVSFZ B",
        "=Z>q>",
        ".SX[*",
        "IP$4&",
        ":]9KJ4",
        "_v.50F05011_FC3E_4209_A92A_9D8DF4E71D10",
        "W/wLx",
        "P^e.[?",
        "iMj6g",
        "1!CD7P",
        "AUl1:;",
        "=\"=(=.=4=:=@=",
        "H{y)X",
        "Uko@ ",
        "p#Emk",
        "input not initialized",
        "PWY}418Sp",
        "PIdWX",
        "R#y0;",
        ":C;a;",
        "TS_RESP_CTX_add_failure_info",
        "T;R&Pm",
        "D$(SUVW3",
        "t5R`@",
        "U&YxD",
        "oq3eq",
        "*Ss&O",
        ",-w8A~k",
        "u9VU9",
        "Excessive server response line length received, %zd bytes. Stripping",
        "NTLM handshake failure (empty type-2 message)",
        "1n)eu",
        "byXlG",
        "c;CJKvpG-",
        "t$4Ph",
        "VfAi^",
        "P2g;%",
        ";,|?Z",
        "PKCS5_pbe_set0_algor",
        "cmG<Fa{",
        "9%9v:",
        "r(>QJ",
        "ASN1_item_sign_ctx",
        ">V?h?",
        "UhT-$",
        ":M:~:",
        "Zv3o?.",
        "G=viY",
        "1K4(p",
        "kx2yKXQd",
        ";8;?;D;H;L;P;",
        "Out of memory",
        "UIR`j",
        "ISTIj",
        "pYvFWV&Z",
        "'g'g'''",
        "W\\cqIR",
        "Saving backup data: \"%s\"",
        "pwV*Ir9",
        "list_of_files",
        "246%&",
        "w+-*w",
        ")Bxc_",
        "wX7pY",
        "Abe%Z",
        "[1J($,",
        "Yx/n#",
        "id-smime-alg-CMSRC2wrap",
        "IYp k",
        "31383D3Y3`3",
        "2i0GAE",
        "|$\\UWU",
        "X9.62 curve over a 192 bit prime field",
        "liyPeA",
        "/^^3&",
        "=Pwle",
        "GetFileVersionInfoSizeW",
        "%1hW/n",
        ",.)KW",
        ">Vv*}",
        "w|Jmq",
        "iWlW|",
        "__b2>",
        "brainpoolP320r1",
        "::A|B",
        "NETSCAPE_SPKI",
        "435U5",
        "RtlImageDirectoryEntryToData",
        "%*sNo Rejected Uses.",
        "?5Wg4p",
        "S/B3W",
        "_tcPVj@",
        "error loading CRL file: %s",
        "@-yNy",
        "QT\\KD",
        "OeR1E+tV",
        "2Pj@`",
        "EnumProcessModules",
        "CAQuietExec64 Failed",
        "d%,sM",
        ">$>,>4><>",
        "5G_\\X",
        "2Q1;?",
        "xIV91",
        ";?KqO",
        "lgz^O2/",
        "fPT:60",
        "Microsoft Extension Request",
        "#hQ/@:",
        "dDTdfe^",
        "EC_GROUP_new_by_curve_name",
        "K$Z+A",
        "$6xlY",
        "dX[^#y",
        "WCBd'E-",
        "}Ic\"J",
        "(gg'7E",
        "6#6,6T6",
        "pRsq#",
        "-$8!E",
        "HAh:g",
        "R?{7Dg",
        "767H7",
        "'}TLE",
        "cF6b)",
        "!q*0@",
        "xvKF;",
        "v>0Xa",
        "k`m<<",
        "Connection:",
        "Failed to get recent socket",
        "WD_ExtractFiles ended.",
        "(F3/C",
        ". If the Product contains any encryption device You must contact Check Point's export regulation information page (checkpoint.com) for specific information. You agree that You will not ship, transfer",
        "1L~Pd",
        "-:i%iV",
        "&2NfN$L\"",
        "zFD~s]",
        "RSA_NULL",
        "1Gw7G",
        "=)O<C~",
        "UK@2F",
        "!4-oS",
        "2@3i3",
        "KatN,",
        "9cn\\\\",
        "%p<IKN",
        "@*XWO",
        "ISDOWNGRADE",
        "8,808<8L8\\8`8p8t8",
        "Rt\",L",
        "p3'Cg",
        "_/O`j",
        "YVav*5+NFa",
        "q.<Hz",
        "W]\\U*{ou",
        "Wp9&8",
        "a~UI-",
        "}1yqP",
        "%~P\\)",
        "?$?3?B?K?h?w?",
        "UdAnQ",
        "Camellia(128)",
        "4/5<5D5T5x5",
        "~K-}F",
        "G7Bl/",
        "1(1:1I1s1~1",
        "PROTECTION",
        "#0nrp",
        "I{uj]",
        "z#CY(",
        "Existing condition: %s",
        "(ZccPS",
        "1O]{K'",
        "Vz$/eiN",
        "CANTSET_DLL_COUNT",
        "0<3m3s3",
        "}xadb",
        "8nKL#",
        "Protocol is unsupported",
        "rnM8M[",
        "$NLoi",
        "lQp*n2",
        "9m\"kQZ",
        "english-ire",
        "F(I_:",
        "CMS_encrypt",
        "XY<#t",
        "t jvhxE%",
        "fdm`?7",
        "3T$D3T$03T$(",
        "b><D3",
        "H*RR`",
        ".!.d(",
        "Sb'/x`",
        "=yD>T",
        "v?\\X`",
        "#=lN8",
        "StopNetFltDrv",
        "~,u?k",
        "`\"/!d\"",
        "\"cnxMu",
        "xn:]B",
        "]i5YTQ",
        "setProductMode",
        "0)0j0",
        "n\"oN/",
        "9#9%9)9/9=9A9M9[9k9y9}9",
        "CfbY9",
        "cqru&",
        "E}m1Yx!",
        "k#v}bM)+",
        "7{8@;",
        "pp[JR",
        "uO?BL",
        "FBay$",
        "OpAfC",
        "al)>7X;a",
        "!Z[q\\",
        "r4c1N",
        "PR@BJ@",
        ":-;U;u;",
        "%-Qt'!",
        "y1jkO",
        "+(5L>m",
        "9s;s=s?sAsCsEsGsIsKsMsOsQsSsUsWsYs[s]s_sesgsksms",
        "__ptr64",
        "'`}o\"",
        ";H<f<n<",
        "ZO]z_",
        "7&2Z`",
        "0[b98?",
        "II6(a*",
        "qfTQLBPk",
        "DYNAMIC_SET_DATA_CTX",
        "FW_MD5",
        "K32GetModuleFileNameExA",
        "[LICENSING] NOTICE: corrupt expired beta key %s attempting repair during update (modedate: %d).",
        "zbazVv~\"",
        "Yz:U:",
        "}7mm '",
        "L$P3l$,",
        "RWQSV",
        "J}h}j}p}r}",
        "j_UW%U",
        "\\ \\`\\",
        "P9J53",
        "3&454a4",
        "}!j S",
        "RG:rN",
        "0=WEH",
        "-*j8.",
        "kUn8k",
        "H(0#}{",
        "4%%X^t",
        "t$(Ph",
        "Ch*Ei$",
        "WixQueryOsWellKnownSID",
        "n)_:,",
        "*<v3I",
        "C[]gQ",
        "~|D75",
        "@v^vyve",
        "\\F|t|",
        "4b4n4t4",
        "081j2",
        "issuingDistributionPoint",
        "a%u\\k",
        "protocolgroup",
        "P\\uqa4",
        "/7xRx",
        "u]h$)",
        "UHBLR",
        "*/J)V",
        "t<ZyM",
        "nj!)q0",
        "Mq\\bd",
        "ao?,i",
        "q]ISG",
        "<.V#t",
        "a8Y)9",
        "Usf>y-",
        "_<[]_^",
        "4 4$484<4@4D4H4L4P4T4\\4t4x4",
        "SMIME",
        "[DUMPFILE] dbghelp.dll missing or not loadable on this OS, unable to write dump",
        "uCQVR",
        "kE]b9",
        "(+y(t",
        "f+NdfI",
        "<%=k=",
        "4$4,444<4D4L4T4\\4h4",
        "9KKf-X",
        "2'j*h/i",
        "Mask Algorithm: ",
        "*hc4!",
        "da*.ag",
        "gjG{q",
        "Ov6V~",
        "L$0Qj",
        "?XR:z",
        "?.Z,A",
        "K*5>|jP?*",
        "b/Ni#y",
        "6ZPsK",
        ":-\"w5",
        "t the Product will not be shipped, transferred, or exported into any country or used in any manner prohibited by law.",
        ":#:):P:|:",
        "]8,7]",
        "/i@a}",
        "??cFw",
        "$-h)*",
        "|%?+=",
        "6enK4",
        "OzroG",
        ")`CHRi",
        "9;w4Y",
        "3\"ghhi",
        "TvaPz",
        "command not supported",
        "Event/EventData/Data[@Name=\"BootStartTime\"]",
        "aZx>QYND",
        "1x=K%L>~",
        "O>Ol1",
        "<d7]O",
        "twH^f",
        "TOQ4RV&",
        "y$8\"B",
        "4gC<'",
        ".#q9P",
        "<|xp,",
        "@<^-/",
        "7ME&p",
        "HELPER_FAILED_TO_START",
        "I/d/O",
        "&1eeY",
        "pI%VNFh*",
        "mime-mhs-bodies",
        "sslCA",
        "NK&i9",
        "'nba,",
        "Jrpy=",
        "me&(3",
        "DKX?5",
        "/9gV*",
        "}`OYTNhw",
        ".\\crypto\\x509v3\\v3_cpols.c",
        "54-55-43-44-52-00",
        "9uKtE",
        "\"]g5u",
        "DSAparams_print",
        "5'u)u",
        "n Uf;",
        "#&s[]`M",
        "-49ov\\",
        "fN]V\\",
        "P/WG)",
        "%*sNumber%s: ",
        "y/5ng",
        ":9C70",
        "_izVTX",
        "D$0PV",
        "TTLSu",
        "bF1A1",
        "rgv\"`)",
        "3h]5:",
        "ab?!}",
        "2v3~3",
        ":0:8:@:H:P:X:`:l:",
        "4_(V%(",
        "x5pG4",
        ";A:AD",
        "U|<33E",
        "7/898",
        "1iNjY/s]W",
        "l$ Pj",
        "Failed in QueryServiceStatusEx, error: %d",
        ">7>3?x?",
        "des-ede3-cfb",
        "tz&}<",
        "9ro\\_",
        "1vv2Io",
        "e?2=+^-",
        "g{>Rq\\",
        "5VSwkm",
        "pbeWithSHA1And40BitRC2-CBC",
        "6:*2)>>",
        "\\e:Hafo",
        "zW_Q4",
        "[e.[J",
        " M)6f",
        "$q'ka",
        "Failed to find procedure DeleteFolderAndFiles to delete:  %s",
        "english-us",
        "UX+WVn",
        "d7jXa?",
        ",w)M(",
        "8!8(82898@8U8Z8",
        "DG45l9|",
        "xk79\\k",
        "l$ph@M!",
        "d&Y6G",
        "nCj^:&",
        "ai}r9",
        "TdiEnable",
        "h9ebka",
        "oy/I1n2",
        "F#m#.>",
        "\\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 f You are a Standard User, the Products are licensed to You solely for use by Y",
        "&:N7N",
        "p9;M-",
        "_Knr8_x",
        "Yuw2+",
        "GlPFE{",
        "<]=d=v=",
        "{Mr88",
        "list cannot be null",
        "k)l:2",
        ",aP/@",
        "7~8DF",
        ";%<*<9<H<M<",
        "K;54.v",
        ":(]!K",
        "t\"QRU",
        "UI_ctrl",
        "03eQ7&",
        "Ph E%",
        "{!M'T",
        "!~XW<",
        "9/:k:",
        "Y.x-(",
        "^wsP2",
        "urin4",
        "N%JG;",
        "['Fy#9};",
        " Y}~v4",
        "Z#V1O",
        "d<k;z",
        "rQ*LM($Z+",
        "~BN^(",
        "i&n)F",
        "c&jT*",
        "f<]GX",
        "ALL:!EXPORT:!EXPORT40:!EXPORT56:!aNULL:!LOW:!RC4:@STRENGTH",
        "!%'C%",
        ";{5\"w",
        "CAMELLIA-128-CFB8",
        "9E@>4+b",
        "%12sUnable to load Public Key",
        "mk-MK",
        "yVG<Vf",
        "8#JtL",
        "PVVj V",
        "nV3ks",
        "]H<hp",
        ">9o'6$B",
        "D\\X1k",
        "pbdr`",
        "-8@F_",
        "ctrl not implemented",
        "CVTSD2SI",
        "3'3H3l3",
        "\"Rx44",
        ",HOr6>",
        "Z!r\"+",
        "0$0_0f0r4#8d8h8l8p8t8x8|8",
        "|(SzT\"",
        "}nl-k",
        "-J2Bi",
        "RP;K$",
        "=_=v=",
        "0/xC'",
        "7.7I7d7",
        "5#YKJ",
        "OQp1>@",
        "L`9Ik",
        "l=mRnuJ",
        "[1L:}",
        "}M0[V",
        "~<3n0:",
        "+''m$",
        "SSL_ADD_CERT_TO_BUF",
        "J-~#:",
        "Connection",
        "6G6M6]6y6",
        "7)>d2",
        "xrmyqcN",
        "L@&Po",
        "1\"1Y1",
        "Em$R}",
        " means the code provided to You by Check Point, which enables the Product to operate on the Licensed-server or appliance for the specified Licensed Configuration.",
        "A,{e/",
        "vKxfq/L1",
        "\"K74t",
        "n.7n#",
        ">*>0>;>J>P>`>o>u>",
        "V~#IY",
        "Failed to MsiViewFetch(hViewShortCut) with error number %d",
        "!9x)MH",
        "^:<Rn6",
        "S?Ypb'",
        "?>zI+n",
        "Pd*W e",
        "}2H1hK",
        "88/2v",
        "]!+oi",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 P}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918\\charrsid15169477 roduct }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "_Y&V6",
        "{B}LB",
        "r`IJ5",
        "~YXt\\",
        "s3@Ws6^",
        "\"eeBDB",
        "invalid asrange",
        "Xn6sb",
        "f@5V>",
        "y!ZIH",
        "TTi!\\",
        "9=jkx9",
        "@^e5E#",
        "T::=(",
        ".?AV?$_Ref_count_obj@V__ExceptionPtr@@@std@@",
        "&+j57",
        "{?%V%M",
        "'8zK(DT",
        "h%Z%j%z+",
        "/GI7$K",
        "vista - installing NP and PLAP",
        "666666666666666666666666666666666666666666666666\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\",
        "4:5U5",
        "g`DxTMZ",
        "yWkQH>6d",
        "within five (5) business days of the arrival of the RMA, or pay }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12926876 the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 standard Check Point list price of replacement ",
        "<.<J<f<",
        "zt^T\\",
        "`ur0&e",
        "VN{VK#&",
        "BH\\6W(",
        "an7our",
        ">5>R>u>",
        "JUS&;Q",
        "\\bWBR\\",
        "\" `\\Y|",
        "OBJ_nid2sn",
        "D$0jPP",
        "/xr0gT",
        "9%RA@",
        "CRolloverMgr::WaitForRollover():  wait result = ",
        "K)'vu",
        "b*fir(W",
        ":<:D:P:p:x:",
        "KwGqc`",
        "`UD_[",
        "BBUa2",
        "A?a0p",
        "X:pWG",
        "KqJGNv",
        "D/nQ%<",
        ";o1{sj\\",
        "yz*k%S",
        "9f;u;",
        "PI2FD",
        "Server:",
        "ijnZu",
        "7&bT:",
        "on?g,",
        "X@Xqf",
        "}7I<A",
        "~ ;/[",
        "6,7Y7y7",
        "5zl\"r",
        "o5Nv7DU",
        "BHvT*@",
        "6B.Sr~",
        "X#(<{",
        "'R 1/",
        "Ez%}Q",
        "73>;*1<",
        "a=1KFm",
        "ki{+'",
        ":A:a:",
        "FTM&L",
        "1$1@1`1",
        "rEgg}+O",
        "EC_POINT_set_compressed_coordinates_GF2m",
        ",|mx}!",
        "=-E?copC",
        "JCcBa",
        "y('-VE",
        "$(t#p",
        "~#Uj O",
        "DRfl\"",
        "InstallMsi(%s)",
        "$[y%X",
        "4O(L:/",
        "Ef%Qo\\_",
        "D/*.qK",
        "\\;dS#i",
        "?>[kH",
        ".+0R;",
        "\":}Bz",
        "unable to find public key parameters",
        ";i<v<",
        "=X>u>",
        "2V3u3",
        "`a/eE",
        "/8l]m",
        "<9<\\<",
        "x>e%a",
        "SKIP USER: Can't get user's appdata",
        ">@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "&,|wn",
        "Z^'X2",
        " ui level == 2 -> Silent",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{0D48BC29-1FD5-4491-BD55-D4279D109B37}",
        "$i.ve",
        "jAjhj(",
        "6e{oKX",
        "failed to write shortcut attributes to custom action data",
        "A:K?P",
        "Lyv(}",
        "Jib3Q=",
        "?N19V",
        "|/?LP",
        "hanT4u3",
        "H!mj<",
        "ww.5R)}I",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Watchdog",
        "CD$$j",
        "ly(6eb",
        "xkh)U",
        "*g9r}",
        "Entering %s in %ls, version %u.%u.%u.%u",
        "GetModuleHandleW",
        "-DJnisl4",
        "U2b+G",
        ">#>*>6>B>a>k>w>",
        "> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>l>p>|>",
        "$J}l!",
        ".SY5(",
        "\".-!S",
        "x6Ji0Q",
        "passed null parameter",
        "]WaSL",
        "gggggggg",
        "N:#Bp",
        "PUNPCKLBW",
        "3S4b4",
        ":5:9t ",
        "Z2\\{'",
        "EV:KZc}",
        "G]=ga",
        "}Xv@}W",
        "AH'%b",
        "5@Z5~",
        ",}V'>",
        ">RGj=",
        ">Zwq ",
        "5'505J5U5a5r5",
        "SOCKS4 connect to %s (locally resolved)",
        "Zp?F_",
        "7D>\\>b>h>n>t>z>",
        "&L:m-2",
        "Ywo`iD",
        "7agclXfnjc",
        "m,G:E",
        "failed to read shortcut target from custom action data",
        "|Ll{f",
        "Installer\\Products\\3CEF7BE31A8A3AE4F8E4A8D671289E7F",
        "Kc(gb",
        "db)WnZ",
        "^/Q2f",
        "V3_GENERIC_EXTENSION",
        "$-[fn",
        "$MUtU",
        "LAd)G",
        " 3HA@",
        "\\$dJ4",
        "Version: '",
        "Xbi=h",
        "qL2~W",
        ";:;b;",
        "responseBytes",
        ".;p-f",
        "AES-128-XTS",
        "Plugins::Register:  Registration successful.",
        "SN]Qs",
        "logoffFromVsmon;",
        "=<>b>",
        "szOutputXML",
        "Gt$ez\"*",
        ",303@3D3T3X3d3t3",
        "zaZ~~`*",
        "'K9Gb/",
        "Q1TQzo}",
        "10181L1T1h1p1t1x1|1",
        ">(/cx{$",
        "UN_NO",
        "DI%-;",
        "5Q1)]z",
        "1M1U1e1",
        "?(aXO",
        "WARNING: failed to save cookies in %s",
        "W6U5TIw)$",
        "p;(Q*",
        "069uB^",
        "ddddddddd",
        ": :<:X:t:",
        "Zy[sZ",
        "E\\N\\}L#",
        "Rp@umR)",
        "495M5T5v6",
        "G]B0(q",
        "8$8;8K9{9",
        "d;FOz",
        "getsockname() failed with errno %d: %s",
        "v[t9J",
        "DP&0F",
        "8*8J8j8",
        "-s<c&*",
        "Gkcuh",
        "OW3A[",
        "z~:BY",
        "gw|TNy;",
        "8B9w9~9",
        "6<z _",
        "tP<KtL",
        "fEkV9",
        "Ph JM",
        "(lOCk",
        "61686A6J6x6",
        "y8|7y8:",
        "=$>4>E>d>l>x>",
        "6ZlZ=",
        "-*RdE",
        "a&hQ0",
        "x0Ik3",
        "EVP_PKEY_derive_set_peer",
        "na/?V",
        "2<#>C",
        "`KZ'B",
        "b!ao$",
        "()$^.*+?[]|\\-{},:=!",
        "tbh0LE",
        "`9@ @",
        "%&bpb",
        "E~GKz",
        "\\dpQ_",
        "zP04D",
        "gD{D>",
        "e|{FP",
        "=,o@6",
        "/(Pn~",
        "Tj}>Ej",
        "mdD32`",
        "HWZu'[",
        "_iSS7AV",
        "zc|By",
        "WRB,\"M",
        "(9/6{(",
        "Rc$c4cTid0",
        "+l-aW",
        "PreInstallCheck:  Check for new version.",
        "RSA_setup_blinding",
        "L$ VW",
        "[Z|^ ",
        "*#gR)i",
        "![oWP",
        "q2;6d",
        "; ;*;4;>;E;L;S;Z;a;h;o;v;};",
        "rsa_keygen_bits",
        "<+g\\\\",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 H}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477 ardware }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 P}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "}\"L(r",
        "9@9H9Z9g9",
        "GrZJis",
        "FIh%myy",
        "epnetflt",
        "@v H4",
        "\\-:WT",
        "9g?y;",
        "}OgkpgW",
        "(>m}U",
        "),)l<",
        "V9ZQ~",
        "Vqnz\\}",
        "==>C>",
        ".?AVbad_format_string@io@boost@@",
        ")mz*R",
        "JL\"XS\\",
        "0P1U1Z1",
        "9#9J9_9o9|9",
        "xwvRc",
        "0<0D0P0t0",
        "uffffffffffffgfv}f",
        "}JjE|5",
        "E<% @",
        "Mtd|w",
        "4lu2DT",
        "****************************** MsiCleanAll ended **********************************",
        "pp|B>>q",
        ")M:#N",
        "y@{.M",
        "rnrpf",
        "AN2M&",
        "{\\fdbminor\\f31566\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}{\\fhiminor\\f31568\\fbidi \\fswiss\\fcharset238\\fprq2 Calibri CE;}{\\fhiminor\\f31569\\fbidi \\fswiss\\fcharset204\\fprq2 Calibri Cyr;}",
        "bBWSX",
        "(Bkzur",
        "NGm `",
        "Aw_EM",
        "Mail.reg",
        "9<<&6",
        "7\"@+l",
        "346\\)",
        ")3oPQ",
        " 1i4YT",
        "X509v3 Issuing Distrubution Point",
        " \"~_j",
        "i| QE",
        "PBy?\"",
        "U{h^^",
        ">dAE]4",
        ",#$FZ",
        "FQMOA",
        "=~0\\Z",
        "6%656E6U6^667D7]7f7",
        ">\\>z>",
        "FWUpgradeAfter started.",
        "\\U(`h",
        "f\"-y+",
        "#~K*A",
        "2%2\\2c2",
        "Rn\"_V",
        "ENGINE_ctrl",
        "B zJ1",
        "Error: ERROR_BAD_QUERY_SYNTAX (%s  section)",
        ">/GBN)a",
        "certificate signature failure",
        "7$7,747<7D7L7T7\\7d7l7t7|7",
        "fhE:4",
        ";0;G;t;",
        "G4vX!s",
        "%[>?>",
        "\"*mm~_",
        "f'|AG",
        ";JJc#5",
        "[<b18",
        "-'/$ ",
        "CertDuplicateCertificateContext",
        "oVIe-={",
        "x\\p/L=9R#",
        "Language",
        "6LnzQ",
        "0a<bq.",
        "8_Gi[p",
        "N4I<d",
        "'5R+[ ",
        "=JW9z",
        "$2U2Q",
        "<url> malformed",
        "-y.:@",
        "#\\-Mk",
        "huVCDPf",
        "4,qL\\C",
        "CompPrepare ended",
        "0>0a0",
        "4t1c@",
        ",_j(1q",
        "_JUb|",
        "*Z)WW",
        ".-:ql",
        "5-686?6J6r6y6",
        "?[L!>+",
        "`pJtUZ",
        "yOl~4nY",
        "lzpca",
        " nG_r>",
        "g1'/$2q",
        "e1qw_",
        "c2u=[",
        "<hrDE",
        "IVeFP",
        "t&WSSV",
        "}m6L^",
        "Kf<BRi?<",
        "WWW-Authenticate:",
        "9$9?9E9P9",
        "'9T$$",
        "g9a<6",
        "Dealing with support files",
        "-%\\peJ",
        "ByCi@1",
        "GetFileInformationByHandleEx",
        "9\":4:",
        "9LZO4",
        "dCefb",
        "eKawM",
        "]yL0:?",
        "RRRRR",
        "E'pHD",
        "{fc?{",
        " N7T7",
        "\\LrSy",
        "_&7 VS",
        "z}l0f|R",
        "E( uU",
        "N*S4v",
        "9fzk(",
        "#-/(F. ",
        "!%tCJ",
        "7,7L7p7",
        "PUNPCKLWD",
        "w~\"Ae",
        "j<t=X[",
        "public key encode error",
        "P]QD<",
        "``jJR",
        "}uj~a",
        "CDataMonitor_Task",
        "W.Fp$",
        "u :T\"",
        "k3`Xi",
        "DYjEF",
        "Cj!@|",
        "Q%GeH",
        "No connections available in cache",
        "FZttig",
        "HashDB",
        "cpopenssl.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "*8C'>",
        "Gd][g",
        "Oo1MI",
        "\\sbasedon0 \\snext33 \\slink34 \\styrsid13065977 Body Text;}{\\*\\cs34 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs24 \\sbasedon10 \\slink33 \\slocked \\ssemihidden Body Text Char;}{\\*\\cs35 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs16 ",
        " AdPn?",
        "i6327`",
        "$Sf#]:",
        "N\"=}W",
        "Cghg~",
        "4hR^)",
        "kpY$#",
        "D`D?TI",
        "/8q#(",
        "`0,~i",
        "EPAM_Uninstall",
        "c}0>8",
        "hx8KV",
        "Loading Secure Access policy information",
        "+q$3Eqa",
        "rA9}s_",
        "Lg%^ay",
        "oo1,ns",
        "CMS_ReceiptsFrom",
        "ypOm%I",
        "r:@K(=",
        "+[F0k|",
        "p/}L/",
        "PVVj'V",
        "~{rTX(",
        "<$<,<4<D<L<T<d<l<t<",
        "9=9s9",
        "141210000000Z",
        "cFX1}w-c#o9",
        "zonelabs\\plugins\\plg_*.*",
        "|\"'[_",
        "G5(BY",
        "GX/*K2",
        "w/*x-",
        "677J7",
        "Y\\URpm",
        "5TCf!",
        "w^_oD",
        ":^2qu",
        "Ls$AE",
        "A\\T4p",
        "version='1.0'",
        "}:m]_",
        "6^D;mz",
        "proxy.png",
        "/k\"]=",
        "&l,lI",
        "b4>4)",
        "=Z>|>",
        "U!0Xj",
        ",P<bfs",
        "T$h3T$T3T$`3T$4",
        "QN{>}",
        "ZP+5_",
        "7)7S7W7[7o7",
        "1_2i2",
        "vz,+lI",
        "J,J8JPJdJpJ|J",
        "curl_easy_setopt",
        "InstHelper is not running",
        ">Qf;V",
        "ssl3_read_n",
        "AQysLO",
        "M]E;^e",
        "id-alg-dh-sig-hmac-sha1",
        "RwiA_O",
        "j40R; NS*o",
        "79\\@!3;",
        "yAIx<d*",
        "e'*`}v",
        "MDTM %s",
        "<'=.=",
        "+z]\"I,",
        "_1L9NjN",
        " issued by the Department of Commerce, International Trade Administration,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7480943  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "(sQ!&",
        "?k<C\\T/I",
        "1,kkT",
        "[nrVm",
        "n:h*y",
        "?!?1?A?a?q?",
        "Remove UIFramework1.0 files",
        "]]G%%s",
        "Removing HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\SR_GUI",
        "N`YclX",
        "mhswq",
        "9Ww|\\1",
        "@*fj(",
        "aypZ\\",
        "PUShxI!",
        "a)1K$n",
        ",wiWY",
        "U|bT@j",
        "6Y#Qc",
        "=>=k=",
        "W;X%c",
        "package contains new SCUIAPI.dll need to reboot.",
        "SYn,3",
        "7p8&%,~",
        "WSAIoctl",
        "XF4c'",
        "@KrnD",
        "(c%@N",
        "=C/=Z",
        ">_>f>",
        "?J`D0",
        "yt4A-",
        "9$9v9D:J:T:_:h:m:s:",
        "nsCaRevocationUrl",
        "eFW;LWM!)2J",
        "O) 6b",
        "6q52T",
        "wc?)OEe",
        "#Xz@4x",
        "D$,SU",
        "+tB^B<",
        "[O4ge",
        "?$gv;",
        "TlsFree",
        "VersionMaxInclusive",
        "str_field4",
        "December",
        ")1bf?",
        "r$- U",
        "T%56N",
        "9T)Q^",
        ")bCGg",
        "60>0E0r0",
        ".?AVExternalContextBase@details@Concurrency@@",
        ";j,Z4aRn[@",
        "j4pH#3",
        "Z>@O ",
        "5Sg=S",
        "YMn}t",
        "~#_%O",
        "7H7t7",
        "7#7^7j7q7z7",
        "qAi_HX",
        ";l;u;y;",
        "={)u*M`e/",
        "Qe]7<",
        "VdzNd?",
        "H#VNlh",
        "2&/q(@",
        "X?K}5",
        "W0.=b",
        "RRQ64W",
        "?'?9?n?",
        ";Z;w;",
        "62FhA",
        "SO7an#",
        "file_digest: Can't open %s",
        ")J+C\"M",
        "of`fu",
        "mnDJg",
        "r3'/+",
        ")6$tw",
        "smime text error",
        "0'0,010L0[0f0k0p0",
        "StopNetFltDrv_rollback finished.",
        "-n6:26",
        "(;ny:",
        "fX38C",
        ";#;+;",
        "t%\\h)",
        "mFWM&",
        "clientAuth",
        "5~FJS",
        "QSVj,",
        "r3YF%",
        "QZb!A",
        "5y)Xo",
        "P:2u{C",
        ":^pa=",
        "Couldn't read a file:// file",
        "RSA_padding_add_SSLv23",
        "XBKR+",
        "A2AbArGz#",
        "U}UJb",
        ":]WA[<",
        "tad_[tue",
        "B]?,x",
        "dz;`&4",
        "YQUsp",
        ".RhG4",
        "=9=B=M=",
        "VZPRoVep",
        "aes-256-xts",
        "~V<Fl",
        "NR:Va",
        "E$ow.",
        "wcascript.cpp",
        "GGh*W",
        "[VSDATA] DriverXMLCtrl():DeviceIoControl():  FAILED with 0x%08X",
        "Y\"A~@x",
        "SRTP_AES128_CM_SHA1_32",
        "cY! #I",
        "^WxhND",
        "H5x*U",
        "ssl3_send_client_key_exchange",
        "}fgnn",
        "Koy8,h%",
        "?X&eB",
        "?}OS#",
        "Lo_YoT",
        "0pnvW",
        "X'2=P<",
        "=X?\\?`?l?p?",
        "ir\\my",
        "EVPHasher::Update: begin after end",
        "6$Wm5",
        "Z&q}[@Y",
        "KqhMj",
        "You must uninstall Zone Alarm Client before you can install Check Point Endpoint Security VPN.",
        "id-aca-encAttrs",
        "{[hjI",
        "Z~KV%",
        "R80 Case - exit installation",
        "P!RI|(",
        "SSLv3 part of OpenSSL 1.0.2h  3 May 2016",
        "'E1QH@",
        "b?SAI",
        "t$$WWV",
        "dhSinglePass-cofactorDH-sha512kdf-scheme",
        "\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 5;\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 5;\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 6;",
        "^w/tV`e",
        "I\"I)I",
        "3wI.\\s",
        "\")A`!",
        "<D<P<k<x<",
        "Ghl`ow",
        "<`}>($",
        "wG(x&",
        "rCUVQPh",
        "$of=t",
        "excluded subtree violation",
        "FeatureVPN _RemovePrepare",
        "?-p$a",
        "M0cq%",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7943135 {\\*\\xmlclose},}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477  it becomes subject to regulation by agencies of the ",
        "9,:D:K:S:X:\\:`:",
        "<\"<8<X<^<",
        "<T^vc",
        "mw.#h",
        "Mm7rS",
        "0Q1`1",
        "r[6Ej=",
        "at,NN",
        "*ddz~z",
        "Y%qOA",
        "failed to add security info data to rollback CustomActionData",
        "/jQu),",
        "JhlJ/",
        "iNlk_^",
        "@TxQy",
        "6 6,6064686<6@6D6X6\\6`6d6h6",
        "+{>}w",
        "jf'm|",
        "DF928D60-9A93-46A6-B602-3186E4B4CF33",
        "t}RfI",
        "w!2PAVMp",
        "Dmwug3",
        "Idz4B",
        "k[cZf\"",
        "Check Point Endpoint Security Anti-Malware",
        "XV\\fkk",
        "6 6$6(606H6X6\\6l6p6t6x6|6",
        "t<l4xn",
        "]Q+te@J\"z",
        "N|?1u",
        ")r;+^KT",
        "Tm?b.O",
        "#Zi;P?o",
        "gDVL$",
        "0]_^3",
        "Name too long",
        "nyl\";}",
        "^I8=),",
        "+)(6\\PI",
        "b|Z1R",
        "`IJS~28 ",
        "/////////////////////////////////////////",
        "^-n.6",
        "XBV6'",
        " :M?B",
        "4\"474>4D4V4`4",
        "@T8GY",
        "Y\"u)U",
        "^QO#A",
        " ~td.-NI",
        "Miv7qL",
        "a7mhkz",
        "9.-z[0",
        "tXz#xN.",
        "4h2uT",
        "7$7,747@7H7|7",
        "\\$,UVW",
        "L:%A+",
        "9 ^0edb",
        "+C/WgS",
        "&%x0b",
        "+QuN+",
        "0=0I0r0",
        "vsinit.dll",
        "PQVUS",
        "+0O0s0",
        "Can't open property file:  %s",
        "{\\flominor\\f31555\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}{\\flominor\\f31556\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}{\\fdbminor\\f31558\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}",
        "WCXr/",
        "=;>C>S>~>",
        "n\"rq<",
        "Cant' get DA location from registry. Error: %lu",
        "@^_C\\t`",
        "Microsoft Individual Code Signing",
        "S\"BPw",
        "Em?ml",
        "z7.[u",
        "X\\Z`1az",
        "required cipher missing",
        ">W_2h:",
        "X$a1Y",
        "DGcsm9}",
        "lq](U*",
        "zVln]",
        "141@1`1h1t1",
        "PADDD",
        "YG9!i",
        "5Z5g5",
        "(8t?g",
        "K.==O",
        ":':1:N:U:a:o:",
        "B-V@3",
        "~uyu ",
        "K&2~|P",
        "ex_data",
        "oVg8p^g",
        "mT)*D",
        "pU?cJ",
        "7-I$g",
        "sT+'9",
        "CreateInstallMutex:  Install mutex already exist.",
        "8&mHc",
        "7.8L8T8m8x8",
        "<$=L=",
        "'1ZC+",
        "Error %lu acquiring context",
        "iZ_QF",
        "AY%uVz",
        "$tjeb",
        "#e!?F",
        "Vwq$Kg",
        "?E8\"^ED#",
        "; ;0;4;D;H;T;d;t;x;",
        "NoLlS",
        "/w_524V",
        "DTLS1_SEND_HELLO_VERIFY_REQUEST",
        "-9Lt_",
        "88z7 ",
        "Q3i;w5Z",
        ",-o!z%bE",
        "W4sv@Ge<",
        ">$<CO",
        ";`=d=h=l=p=t=x=|=0>",
        "7.myO",
        "KTi}:",
        ";1;j;",
        "VfIm]T,",
        "illegal null value",
        "[0y)m>uG+K",
        "Fe}O\\",
        "\"cD>&",
        "_}1Sw",
        ">Ba_T",
        "5Y6'7",
        "II9Irp",
        "RPWAC",
        "J#0S.",
        "_^tT)",
        "URLFprepare started",
        "width is not integer",
        "U6/s#",
        "command takes input",
        "isupper",
        "?C,&k",
        "9!989i9",
        "~j.E\\",
        "lvpC ",
        "W82_w",
        ".rgy@",
        "x%CCT\\iu",
        "*J+%Q",
        "O8SmpN",
        "\"^}^~)^",
        "r=_@5",
        "^QdLej",
        "< <,<L<T<`<",
        "63m;?f97",
        "  %% Total    %% Received %% Xferd  Average Speed   Time    Time     Time  Current",
        "`f!&(",
        ":YS5[",
        "0[a^I",
        "4%4A4]4y4",
        "key usage does not include certificate signing",
        ")jS5 ",
        "'RD*Fb",
        "\"p{a%f,",
        "=B>J>O>T>Y>^>e>s>|>",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2103809\\charrsid2103809 State of Israel and the}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2103809\\charrsid15169477  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "Can't find procedure VSInstallerCancelEx in vsutil",
        "SyMR=",
        "D$4HP",
        "7d#SY",
        "1!1L1]1",
        "4XO#Q",
        "}B3m[c",
        "()w$M",
        "*T3w(",
        "hatD7\"A",
        "GFLfL",
        ">#?Z?",
        "rig#C ",
        ".\\crypto\\ui\\ui_lib.c",
        "EKARl",
        "uleV=o",
        "CryptDecrypt",
        "WW9L-",
        "ASN1_IA5STRING",
        "kw75A",
        ":\\O)d",
        "4_GPb",
        "?G?l?y?",
        "$6P/R\\#",
        "9A9U9",
        "5[?4`?",
        "7J7Z7b7r7",
        "8A7`R",
        "t h,cG",
        "#g\"v{A",
        "7TMz)",
        "B3M'J-",
        "P89w@",
        "S_m#O",
        "O?{80",
        "(oN=*",
        "i<],Z",
        "8(8y8",
        "mFT0+y",
        "g #P}",
        "262h2",
        "lQ{2iM",
        ":'m?O",
        "/%.-9",
        "IsBinaryExist failed to Execute View \"%s\". Result = %d",
        "VsDataInstHelperSetProtection - DeviceIoControl(DIOC_DRIVERCTRL/DRVIO_SET_PROTECTION/TRUE). Result=%x.",
        "3qNWf",
        ")Y)m)",
        "5+646W6",
        "^2hT?8",
        "!bW'O",
        "=J>g>n>w>",
        "RichP",
        "ja2Hg",
        "7$7)767]7",
        "*^#^c^",
        "*OoD<",
        "f9F@u",
        "=$=0=T=\\=d=l=t=|=",
        ",mT&F/[",
        "priv [ %d ] ",
        "^%zB]",
        "/qve!",
        "?E?s?",
        "!D\"2'",
        "6o6]&",
        "\"lgUjz",
        "r=/D1",
        "r z`#",
        "zb5vQ",
        "0%T_P-",
        "<+=F=B>",
        "VS.[215@OT",
        "`tMhI",
        "R%[7q",
        "SB3u*",
        "ob(E<$",
        "VQl`U",
        "g 2#W",
        "EXTRACTPS",
        "5*6B6}7",
        "$bpj'",
        "-fS(xay",
        "d2Ef@en",
        "we~nb",
        "tOFA\\",
        "r1ok~",
        "|CmC?",
        "v2iG9",
        "StopTEService_rollback",
        "V(w[\"",
        "uvQs@",
        "}pmh ",
        "sIuB.&C",
        "V$69hg9",
        "4LS=~`",
        "e|F#z",
        "),Y-j",
        "WindowsSecurityMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "X/#u):",
        "KfQW4T",
        "hH|v8w",
        "9D:H:L:P:T:X:\\:",
        "3au<B",
        "\\pl,R",
        "IO1(O",
        "bcdefghijklmnopqrstuvwxyz{|}~",
        "SSL peer certificate or SSH remote key was not OK",
        "c2pnb368w1",
        "cipher",
        "!L/E0h",
        "{Uua=+.W",
        "6=7_7i7",
        "!<6Z+",
        "-=#1e",
        "8C78B87BF88E98E4689D6F4CDEB07673",
        "F(;G(u",
        "`M!L#k",
        "89Q>Q",
        "Wr0>Q",
        "L.oIq$X",
        "WkAqS",
        "kmV_v`Fh",
        "3 3(3<3L3\\3`3d3|3",
        "P|A^7Y",
        "oM*kB",
        "KN0.%.",
        "V(hGZe",
        "called a function that was disabled at compile-time",
        "(]8 p",
        "?(?,?8?H?\\?l?t?|?",
        "t`={,",
        "`\\J6?1O",
        "v<g{eW",
        "ot$ f",
        "JmFl]p",
        "P4YA\\",
        "`fpQh",
        "k#.cb",
        "]H7sx",
        "daJv8B5KO",
        ">$>9>L>w>",
        "=&.{f",
        "'rsdFk",
        "oWZ)-[T",
        "L`<DXwy^+",
        "213c3{3",
        "-x\"T_",
        "T!+W8",
        "Z#-@J$M",
        ">$>)>",
        "/3us:",
        "D0reV",
        "curl_easy_getinfo",
        "7$7<7",
        "&)t-({<og",
        "uh+Z ^",
        "`z!b[6C",
        "wVz9EN",
        "](?6l",
        "2E09[A_",
        "bYsKb",
        "hcoCv",
        "hp7t`uVFuS",
        "failed to allocate memory for service failure actions.",
        "_on_demand_",
        "H{}87",
        "HwJEq",
        "v#J]\"",
        "*wq.V?h!",
        "GK [\\",
        "247m7",
        ".WpVI",
        "Dy8BW6Pn",
        "\\#gwa",
        "JW#rN@",
        "id-it-subscriptionRequest",
        "Z8=LIB",
        "6(2)}",
        "|X/ply",
        "t3[_^",
        ">C>s>",
        "FYL2X",
        "cf/dhlL",
        "3h4=!",
        "NY|>u",
        "jqjpj",
        "8qu$x",
        "NWoM#",
        "9l:p:t:x:|:",
        "j%lVr",
        "IswMultiReadSpinLock::InternalLock - timeout",
        "l|xuf",
        "No OCSP response received",
        "y&Hc>",
        "/CjBk",
        "^^i}w",
        "Id\\xsZ",
        "6d)S;#",
        "Not empty",
        "5.pKC",
        "FORCEREBOOTDIALOG.7F579463_4BEF_48D0_80B8_41508273B36D",
        "9yaVQ ",
        "}cWE#j",
        "I!sw;",
        "ozLI$",
        "zMI:@",
        "O$+[2[",
        "J89X'Z",
        "b9KH\"T",
        "6VjkK",
        "E>^kR",
        "invalid salt length",
        "8@'q]/",
        "ZzLJJ",
        "Vk7W`",
        "pkcs7 parse error",
        "n@'Zt",
        "\"6!Mgjh",
        "b)H`dz|",
        "YG7@OT",
        "J3aJ-",
        "$djhm",
        "request not signed",
        "%'>( 0",
        "h6WJuQ)",
        "\"0R&5Y:",
        "m&_u>",
        "Of'vj",
        "{OZgf$",
        "%iZe;",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\BackWeb-4476822 Uninstaller",
        "SuppressObfuscation",
        "14}NJ",
        "`[btO*",
        "Ub)d|",
        "t$<WQR",
        "dJ(x(h*S",
        "m69H4",
        "sect233k1",
        "?1?l?x?",
        "g*<;B",
        "[FjWg",
        "Rn:)a6",
        "80:ft",
        "566E6F7U7",
        ",'a.\\",
        "?il=z",
        "_FAyZ",
        "HZl\\\"{",
        "X+0h\\",
        "WriteFile",
        "*9N~g",
        "%s returned %d",
        "y00br",
        "\"XTNY",
        "%?|+lX",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480\\charrsid2385027  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480 C}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480\\charrsid2385027 ",
        "yX \\-",
        "wW9,,++",
        "I4m<P",
        "F8)~*",
        "3].*pX-",
        "J&VX8#",
        "[=QP>",
        "B.`i)",
        "`4Wvu",
        "^I[ZQUI",
        "Z<}a>",
        "6}%761",
        "D$dUP",
        "dHu\"l",
        "NX9^`t1",
        "<$<,<4<<<H<|<",
        "2G.V8IS",
        "uWOr:",
        "3U{vm",
        "md5-sha1",
        "lDaY5",
        "8Ird,B",
        "`_7+Q",
        "F`z=I",
        "a+n$n",
        "434O4k4",
        "U(=]S",
        "luwxn",
        "BLENDVPS",
        "j\"~t_",
        "%%48>",
        ":5:U:u:",
        "Y?v_K",
        "ml_)h",
        ";P5&d",
        "SVWj.",
        "!z--Ls",
        "~,WPV",
        "1HZ&+Y",
        "qK($@s",
        "\\Bo2~",
        "s(;rz<E",
        "z2-#O",
        "cC'a$Mlw",
        "public key is not rsa",
        "failed to remove open port %d, protocol %d",
        "getpeername() failed with errno %d: %s",
        "PlEW@nQ,",
        "VnRA+? Aur",
        "w[ju@",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options",
        ")[cac",
        "%5D}r",
        "ServiceControl",
        "\\zonelabs\\Scheduler.dll",
        "_VO2J",
        "veMBU",
        "Gqjn<",
        "vUJ<Z",
        "#t;y*pb2[",
        "DH-DSS-AES128-SHA256",
        "JL_YYd",
        "uB~T:h",
        "B=(vU",
        "%0}1Z1e",
        "2B2_2|2",
        "!I@I%8Q",
        "^o>v]",
        "t4cv\\",
        "@3n2?",
        "aTfu]",
        "X~ssV",
        "Fx6i=8yA",
        "8<8`8",
        "Rfr6w#",
        "%yI{I",
        "A\\vsinit.dll",
        "BN_div_no_branch",
        "AeZe!",
        "0I>**",
        "GfPdd",
        "hEsFT",
        "Lj/N(rz",
        "ewr's/",
        "Ab0#][\"",
        "IW0rOp",
        "653QQ",
        "_L'8$",
        "[[UrlfUcpArch.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D=%s]]|[[INSTALLDIR.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D=%s]]|",
        "u\"jPh",
        "m^=_~x",
        "u3h(\\!",
        "D$h}n",
        "}&sGx",
        "9_!X-N",
        "VF=e-",
        "5#5g5q5",
        "q4ifjN",
        "$2u( ",
        "W\" !CB]",
        "!#siH",
        ",QoT8",
        "mQ5}:",
        ";x\"A2",
        "tbiW'",
        "0@'d3",
        "9a%}2ZC]",
        "WSAEnumNetworkEvents",
        "0g7F*@",
        " ,:s@",
        "invalid seek",
        "u<k'^",
        "Z!(hp",
        "Ru;t'",
        "Srzr,1",
        "tF44 ",
        "A0>X25",
        "9#9(9|9",
        "5n5}5",
        "!=/JP",
        "@RxY\")",
        "Ignore %I64d bytes of response-body",
        "O#M/{",
        "6G7Q7n7",
        "9Wi}I",
        "SA0h[",
        "8uM;6\\",
        "$q]Uo",
        "O*uXv",
        "ZQ-(\\",
        ":;9LI<",
        "NbIs7",
        "Pe4nI+",
        "UCss,!8",
        "Eqgcl",
        " <MAuf",
        "-jg^\\",
        "O*~b)+",
        "5+vr!",
        "ptA04-X",
        "% =\"o ",
        "(EW*0",
        "IKR;6^",
        "Failure while prompting user to continue to close application.",
        "iS'Q]",
        "]ac'-B",
        "$AtF_^",
        "< <$<0<8<<<H<P<T<`<h<l<x<",
        ".\\crypto\\evp\\e_rc2.c",
        "383D3",
        "t4kiw",
        "HY,8(*0",
        "+A$+A ",
        "5$50585l5|5",
        "upgradekey ",
        ":0:P:p:",
        "*a{J)U2_0",
        "Ln>:\\",
        ".KAdzF\"",
        "BT]B'",
        "y(y8yHyXqh",
        "ykhh%",
        "CheckForReboot:  CheckForReboot started.",
        "(`[#c",
        "4(4D4`4|4",
        "Error while waiting for server connect",
        "!1W_MEVd",
        "ssl3_read_bytes",
        "PDEST",
        "VMLAUNCH",
        "7*KAV",
        ":a'>?",
        "kJ,>b",
        ",d#:UV@>",
        "u(F$v",
        ")4^d<",
        "P]@J37",
        "]E^s%~",
        "`*&qRG",
        "i 42CgN",
        "3iMO2",
        "setct-CredRevReqTBEX",
        "RC4-MD5",
        "DgvN}",
        "CM#!O]j",
        "WdEsSXA",
        "OcL;2",
        "ECP_NIST_MOD_256",
        "AEq8l",
        "7f;'U",
        "$zA8 ",
        "Illegal or missing hexadecimal sequence",
        "]|;sy",
        "t0GKU",
        "p?I}d",
        "<-^mX>",
        "client_sub_type is already in the registry with a value of '%s'",
        "Ph`K!",
        "t$,Vh",
        "3Wk1^",
        "e6~GZe",
        "Balloon Text;}{\\*\\cs41 \\additive \\rtlch\\fcs1 \\af38\\afs16 \\ltrch\\fcs0 \\f38\\fs16 \\sbasedon10 \\slink40 \\slocked \\ssemihidden Balloon Text Char;}{\\s42\\ql \\li0\\ri0\\sa180\\sl280\\slmult0\\nowidctlpar\\wrapdefault\\faroman\\rin0\\lin0\\itap0 \\rtlch\\fcs1 ",
        "TO;Rts",
        ";3X&'",
        "7_|s;",
        "y^WX1",
        "^m|Xp",
        "PMoH_8",
        "0[h9^",
        "?h3F=",
        "b{J8/H",
        ",)c{G",
        "I7j@k",
        "~jP%Yp",
        "SQJ\\g",
        "LeuU#",
        "Subject",
        "RU9FAl",
        "O,QPU",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct boost::property_tree::id_translator<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > >>(const class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > &,struct boost::property_tree::id_translator<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > >)",
        "tIT(G",
        "STR_COPY",
        "8 8,8<8L8P8`8d8t8x8",
        "up.=1l",
        "dtls1_accept",
        "SolUJ",
        "= >%>+>1>7>=>C>I>O>U>[>a>g>m>s>y>",
        "ckpginashim.dll",
        "TN?tj",
        "des-cfb",
        "<+,E9",
        "> uspm",
        "(z0*!",
        "Ht$;}",
        "vJBA>",
        "9k:p:u:",
        "PreInstallCheck:  Check for SmartDefense, Secure Client and Endpoint Connect conflicts(has to run after APPSEARCH",
        "failed %d",
        ">[~G-",
        "u*qktJV",
        "ROW\\S",
        "MvNvOvI",
        "D$03n",
        "4&4+404i:h<p<",
        "F4yl]",
        "| ?rd",
        "5,\\l1j",
        "bn dec2bn error",
        "R3H3O",
        ";/;C;W;k;",
        "DI,/'",
        "M/pC%#v3",
        "EXPUNGE",
        "(=3G?",
        "i_^+Nl",
        "x\"(-,",
        "Error: %d",
        "D$DPWj",
        "id-camellia192-wrap",
        "2+3h324",
        "~Q'*C",
        "ES!79",
        ",_42q",
        "R>2'H",
        "2{Jff3",
        "5M6^6",
        "253m3",
        "61ytjH",
        "?@SDC",
        "TsU8!",
        "D\"^$]",
        "JDsY,",
        "MNAG`",
        "Sl<W\"Y",
        "9+9t:",
        "<$=K=U=z=",
        "2t`eb;",
        "fe`n5",
        " q#p*0",
        "0O/l$6r",
        "FeatureIMSecurity:  RemoveAfter started.",
        "-?V>Z*",
        "SliL*",
        "$|OKlM",
        "J[Qz(",
        "{{{{{{{{{{{{0",
        "QYSYTYU",
        "EjE[Ei",
        "McIC\"",
        "#ZvLIb",
        "cipher has no object identifier",
        "9H:l:p:",
        "^P/I|",
        "Gt'YRRj",
        "uninstallAV;",
        "Qs.AB",
        "kUG^u",
        ",KfY,}B",
        "+>eIe",
        "xkf?Vu",
        "C'>XC",
        "qtO$Bio*",
        "yFOq3",
        "h~a?}j73",
        "jhjej",
        "Jm=<N_",
        "v2(Kw7",
        "Registry Registry error:  Unknown error.",
        "#u_V0",
        "g^aj<",
        "B7wmt",
        "DJCre",
        "szPluginPath",
        "e\".oq16",
        "q#Dl@{3&",
        "UnregisterWaitEx",
        "?pJ!f",
        "aT2}Y",
        "L_b[Y",
        "FreeSid",
        "515M5i5",
        "&rcnE",
        "J]!&mC",
        "#!W~C-",
        "aS#7&!<`MM",
        "SetEventGroupInVSConfigEx(\"%s\", \"%s\", %s, %d)",
        "# ooE",
        "69\"Yj",
        ".\\ssl\\ssl_rsa.c",
        "58zLv",
        "'b{d`",
        "'h:S/",
        "WoC R",
        "848J8`8v8",
        ":\"; <E?",
        "Z2\")u",
        "T$1{w-=",
        "'eGE(",
        "setct-BCIDistributionTBS",
        "4B5V5",
        "VSInstallerCancel: failed. ",
        "9}Z<Y",
        "HyxnL",
        "pW_0yG",
        "<Q6.v",
        "l[=%@'",
        "X509v3 Policy Mappings",
        "(HN{^[",
        "3[}!f",
        "Fhh>3",
        "`8gm(F,",
        "8%8@8[8t8",
        "MI{R'",
        "> >(>0>8>@>H>T>t>",
        "fO2o{r",
        "L$8_][3",
        "Rf1Oo",
        "8{tIj",
        ")&DyWE",
        "FWFreshBefore started.",
        "Upd_MergeConfigurationFiles",
        ";*;F;b;~;",
        "X<B?y",
        "gvB0\"8",
        "_9Vg<6W",
        ">,>0>7>I>M>T>c>~>",
        "I\"EC/",
        "-eQh^",
        "0~<c0",
        "(hQ|)",
        "S'2Cy",
        ">.>^>u>",
        "XSIV+.",
        "LD2VrG#\"",
        "t/.rG",
        "r0%@,",
        "fm5[c",
        ":dEb2",
        "SetPropertyNoOfficeMode enter...",
        ":'std",
        "\\cGr)",
        "2!212Q2a2",
        "PWUVS",
        "Thursday",
        "`^h/8%",
        "797U7q7",
        "mB($T",
        "-vzsP",
        "G+.1'",
        "epam_svc.exe\" --update \"",
        "mv5xP-",
        "@I(m/",
        "#)u:X0",
        "Transport: %s",
        "kPaOc6Y",
        "H[^LF",
        "W\"#m{",
        "IC@AM",
        "m6-D3O",
        "zAy*b",
        "}PXy|",
        "3D$ 3",
        "F\\N{`pG",
        "^gApK",
        "Kaspersky 6.0 (based on version 6.0.0.303)",
        "lh+Kd",
        " Rp8Q",
        "Global\\vsmon_Live",
        "D$8_^]",
        "CfQs(",
        "Couldn't open Secure Uninstall registry for reading",
        "94+)\"=ho",
        "%6p\"F",
        "t$$htp%",
        "K|;y\"oE$a",
        "6[6`6k6",
        "'id' or 'name' missing",
        ")rsELG?",
        "~2v-O",
        "failed to free xml file change list item",
        "+-(l`",
        "V'9#t",
        "j~jsj'",
        "+dYA& ",
        "t$HSV",
        "IJSnj",
        "4#o2%",
        "9p(:[",
        "NX2xvY",
        "9IHq%",
        "\\[Z\\UN",
        "q*RF|",
        "|R>**kZ",
        "L?2i[",
        "i}t*9",
        "7;7B7N7\\7u7|7",
        "\"_7u{",
        "KJOz?oeK",
        ":+;+L",
        "u&I,Y ",
        "4.5M5l5",
        "~6_wLsl5",
        "pilotObjectClass",
        "rL(tE",
        "D$@QP",
        "Q%;M:",
        "pkcs12 pbe crypt error",
        "yF>(C",
        "r.<$hW",
        "s1R(i:",
        "}eI\"\"",
        "id-aes256-GCM",
        "/050?0",
        "Hpgf$",
        "@h\\;#",
        "_-,X,",
        "tCzg.",
        "^S/x^",
        "Sl/f.",
        "B'(vz",
        ";&<7<{<",
        "d|\"`+#",
        "9QSUVx",
        "3 3$3<3L3P3T3\\3t3x3|3",
        "1\"1Y1_1d1r1w1|1",
        "o\\*F>L",
        "*)2<xD",
        "9oC>=",
        "=#=ngo",
        "L$8;Y",
        "u@meI",
        "1Ior%",
        "GKMFw\\",
        "&*O~OEJ",
        ";0;@;D;T;X;\\;`;d;h;p;",
        "y~+D1",
        "xN>ao",
        "Lc&'z",
        "E/>Za",
        "setPWInstall",
        "4QrOaZy",
        ".\\crypto\\x509\\x509_cmp.c",
        "F]J]N]R]V]Z]^]m_",
        "(Z[;K",
        ",efRe,",
        "Qc9a8",
        "c*'Ss",
        "<,<8<`<",
        " Jirw",
        "@s~ChL",
        "Y~0Z=",
        "JC3dt",
        "p]X:q{>",
        "vqJ',",
        "q>hKA",
        "Nf`6R",
        "=@=b=",
        "Z|2${P",
        "4wqJ.",
        "D4?4D",
        "1&aUS",
        "*CS:n8",
        "h'fMP",
        "-'7n;RRN)",
        "D~6]()",
        "VjFhx",
        "p\"pjn`",
        "*t`X#",
        "Eub'z",
        "`?L9q",
        "b#QW~z3",
        "GlobalAlloc",
        "z,<eN",
        "3&3?3X3q3",
        "iI^5]dB",
        ")Z!!H",
        "8!\\uH",
        "e7]*N%",
        "14\"L$",
        "XA{#gJ",
        "PCMPEQW",
        "fF@9X",
        "wmoqK",
        ">^{$dR",
        ".\\crypto\\bn\\bn_add.c",
        "CleanTray30Component started.",
        "rr/Shuc",
        "s;lC|C",
        "bN9p&",
        "|R.C:=k2",
        "pfc$y",
        "_EUm:",
        "p-75wq",
        "c&'6|",
        "\\Fla:",
        "'SPSWgf<Jo",
        "QVVPf",
        "2&.&m",
        "upgrade, ISACTIONPROP1=%s",
        "1>RO?",
        "uxa6 ",
        "eiD.N",
        "M<LnL",
        "SHA512 block transform for x86, CRYPTOGAMS by <appro@openssl.org>",
        "%rdn_19",
        "llJ?=",
        "?1T3%",
        "x:l~M[\\",
        "t h,[",
        "4M4u4",
        "3-484H4s4",
        "@j5s2",
        "e|j?^9",
        "server response error",
        ".CRT$XCZ",
        ";0;P;p;",
        "F_C)x;",
        "Z'-3HQ",
        "aA7(|1",
        "not enough memory",
        "'`D<M",
        "h3sa8 ",
        "sI74y",
        "eYr,:x",
        "iBQ\"R",
        "__cdecl",
        "G$OhN",
        "pNSH1ELRS",
        "AeH^KN",
        ",4W,N",
        "!jvgT(",
        "1#IND",
        "u jrh",
        ">&?T?|?",
        "ZGKn\\",
        "vLRQhX",
        "mo7~nT",
        ">$>*>0>5>;>A>G>L>R>X>^>c>h>o>u>z>",
        "'h\"$C",
        "k)Cn\"",
        "WUJo9a3h",
        "SGv5N",
        "aN]zz",
        "\\AfM-",
        "0^vn7",
        "1 111:1y152:2I2R2o2{2",
        "x}<^i",
        "Pm:#4",
        "tQT[f",
        "o\"ErA",
        "value.unknown",
        "SmK8F+",
        "<-JbA",
        "Interface Version=0",
        "\\c~f^",
        "9Q9:y",
        "NO'nRF",
        "sr-BA-Cyrl",
        "CZd=xA",
        "fLYny",
        "YE*X9#",
        "M%[-%OYa7{",
        "jAZjX",
        ":\":(:0:5:;:C:H:N:V:[:a:i:n:s:|:",
        "DHx_?",
        "1I2s2",
        "~sgDv*",
        "z.Tne",
        "CQzjI",
        "d|UHETV",
        "\\IgYV",
        "?4?I?V?_?d?w?",
        "*1+[R",
        "`!# eB",
        "Ep.Oq",
        "H7NrI",
        "&Z,?f.",
        "[VECTORED EXCEPTION] remember %s",
        "787P7s7",
        "$QMW\"",
        "03H+N",
        "wEKF{$",
        "MMPXtX~",
        "1i6SK?",
        " 0x83",
        "TDTfL",
        ".m`}?",
        "k*tkR",
        "r#~Y)F",
        "zt<c\\",
        "BOUND",
        "6%_F)\\",
        "TU?Qa",
        "L`L\\Id",
        "3)3.333N3",
        "SE^EQU",
        "u0Ay%",
        "r4Q.z",
        ";\"Sj*",
        "sXpkUC",
        "L<^k4kp",
        "_W4ME5",
        "6IM%P",
        "8X('n/.",
        "@G\\ %",
        "5;\\4eC",
        "[I|Bas:",
        "Vh,T!",
        "E:0ZO",
        "QF+!@",
        "Fg4o8",
        "Z&#Yw",
        "psk no server cb",
        "<!<+<s<z<",
        "H[kDy",
        "&9kZ?e",
        "VersionNT is: %d, Kav drivers will not be installed since SDK the same version.",
        "?<Kvg",
        "b#C`bv",
        "t``P08_",
        "`Npu>",
        "w+10r",
        "pE]>Em?",
        "v=W[&",
        "\">;JV",
        "z[trm",
        "ssl_parse_serverhello_renegotiate_ext",
        "KlifLoopbackFsctl",
        "EU/77K",
        "i}F[F",
        "/o=|w",
        ")\\&t!",
        ".UjQ{>U",
        "mq{)Z",
        "viv. 6",
        "J9+gC",
        "|$T3\\$(",
        "J(3|s",
        "u5l$p",
        "G$Qxb!",
        "p?v5o~",
        "4t=<V",
        "BA_TA",
        "1EN-27~]",
        "131h1",
        " 0x9f",
        "OHG:.",
        "{_<>F",
        "SVjA[jZ^+",
        "Q&n{-w",
        "~kou_",
        "v7 'W",
        "7D7JM",
        "YZ0]}",
        "WP94?/$f!T",
        "3hi CV",
        "cA%ZqwAX",
        "WlH8B",
        "set-addPolicy",
        "/\"rI:H\\",
        ";E]bdx",
        "n@f3u",
        "SE?,9",
        "2F2a2",
        " 0x52",
        "SOFTWARE\\CheckPoint\\EndPoint Security",
        "K[qZ>",
        "B5jz.",
        "p_?! _",
        "lR[\"K",
        "`guCZ~",
        "Y&.i2,r?",
        "Okpi-",
        "3-4F4a4w4",
        "o DKS",
        "IiRQNV@<",
        "SCRCo)J~\\",
        "0c/}_",
        "/r<t{M",
        "Failed to get InstPrep's error code from registry",
        "M#mBO",
        "qGvu{",
        "%8b l",
        "1!2:2b2",
        "K|ryD",
        "OR'[j@",
        "QnSj \\",
        ":kk\"g",
        "R2Zq9F",
        "7-ZA#",
        "8d*Ix",
        "m}V/||",
        "HxqQ.p]N",
        "::f*7 ",
        "=XQX),",
        "jejck",
        "-bVW<",
        "8=809",
        "i?]aP",
        "%G0\\4",
        "INSTALLDIR length is %d, do nothing",
        "n=F!F",
        "9+9O9f9",
        "FDE upgrade product code is not found in the registry",
        "\\$PUV",
        "qw>`E",
        "?;aYV",
        "o$x*,",
        " WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED. CHECK POINT DOES NOT WARRANT THAT THE PRODUCT WILL MEET YOUR REQUIREMENTS OR THAT ITS OPERATION WILL BE ",
        "3L$<3D$@",
        "220511000000Z",
        "retrieved INSTALLDIR property: %s",
        "An>Xi",
        "<f$</",
        "dxVxWxXxSx6&|GI",
        "zQLK,",
        "cCmEV",
        "=F=b=p=",
        "C@QVLE",
        "3L$D3L$",
        "^h:'_",
        "%.Bwmp",
        "[Vb$`",
        "/m=YV}",
        " D aD)",
        ">D'-qQg2t",
        "`3SbE",
        "GetTimeFormatW",
        "@B3\\|",
        "<\"<F<R<p<{<",
        "i}r,#",
        "90B]O",
        "9z, *X",
        "yb9FAhjzg",
        "6A%{&@",
        "{M=fc5",
        "g1V\"^F",
        "EC_KEY_copy",
        "727L7",
        "pgDu8",
        "5A6a6",
        "= >/>8>",
        "JiVDR",
        "5=~_E",
        "f?pf)",
        ".n(-.",
        "*gJ]hC",
        "9\"9K9R9",
        ":4:D:L:T:d:l:t:|:",
        "8sOns",
        "failed while looping through all apps to close",
        ":MHMp>x",
        "D4F3u",
        "*%dMQ",
        "^]H~Z",
        " b@_;",
        "Pqu})",
        "N-U(|2",
        "BWr9uf",
        "m`EQ`\"W",
        "36k$#",
        "8@tQf",
        "Wun3%",
        "I`@yC",
        "S!P5_",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 4. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "2!wS4",
        "m0k0$",
        "At''=h",
        "\\Eq<-",
        "C2S?@5",
        "$um}a",
        "7?7Q7x7",
        "kg8!)",
        "h&c#_",
        ")L.4~'d1}",
        "EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)",
        "}GI?C",
        "N,'@%",
        "SaveVpnRegistry()",
        "4 5$5(5,50545",
        "ud9D$$uP9D$",
        "failed to set exception remote addresses '%ls'",
        "^,3/h",
        "T`T^$",
        "ECDHE-RSA-AES256-SHA384",
        "Inherit all",
        "t;[H~",
        " ohz(",
        "t$8SP",
        "rwvbw",
        "Y{~H~",
        "[VSDATA] OSFWCtrl: OpenDriverHandle() failed",
        "8yB\\B|Z",
        "r,C.Kh",
        "&2c8-",
        "6gFpn",
        ")Vwp`",
        "l:o\"1",
        "BC`?)",
        "O$&H@",
        "gDNvCT",
        "</t8<\\t4",
        "7`{@o",
        "MASK:",
        "failed to add ACLs for object: %ls",
        ",>.-j6",
        "invalid UTF-8 byte at index ",
        "be-by",
        "$jypi",
        "y&QT^#",
        "i_\\OB",
        ";0D2p",
        "|GFZ#",
        "HFG_j",
        "BOEXr",
        "_stricmp",
        "6'7Q7",
        "A9m(nl",
        ";D$,v",
        "! !K+hcF&db",
        "$+n>K",
        "lOlol",
        "SEC_E_PKINIT_CLIENT_FAILURE",
        "<M<h<",
        ">MPoT",
        "7&888r8",
        "N4S$K",
        "Hy>;6{O",
        "2Q\\cg",
        "SEC_E_NO_TGT_REPLY",
        ":0:L:_:e:",
        "?7lR7",
        "304Z4b4",
        "l2s\\0|",
        ".?AVsystem_error@system@boost@@",
        "_#6N/",
        "E<PUj",
        "pjH\"~H8",
        "Failed to logoff from vsmon as Installer.",
        "P\\*9ep",
        "D(':{",
        "8uK&R",
        "nchOBt",
        "@[A3Gh/",
        "0d:2b",
        "nmQLZ",
        ":VT^%",
        "D$T_^][",
        "1(1K1k1",
        "{6eba",
        "8$888L8\\8d8l8|8",
        "9J:~:",
        " 0x9c",
        "dphpz",
        "B$L4;",
        "unsupported data type '%ls' in column: %d",
        "1BQnY\\",
        "\"!GDD",
        "+\\\"e6",
        " 0xba",
        "UK4H0@;e",
        "d#Jr6O",
        "SOFTWARE\\Data Fellows\\F-Secure\\Anti-Virus",
        "gq1=w",
        " /f /r /c \"EPS installation finished successfully. Rebooting...\" /d p:04:02",
        "x. Er",
        "g}U)D",
        "C,@.ty",
        "uDY9B",
        "5Xp1F",
        "<k+3A",
        "H@XgZ",
        "$by,3I",
        "}GNRa",
        "eNe$1",
        "FnGBt",
        "xQ?1=",
        "&e\\;:84",
        "535O5k5",
        "2ieO=",
        "?.gXq",
        "[dI@l+",
        "C-$+{",
        "Mic3a",
        "Finish",
        ":A:Q:a:",
        "E(<H_/\\`",
        "PKCS12_unpack_authsafes",
        "u_PPP",
        "S/!!\"",
        ".?AVerror_category@std@@",
        "`=&7zo?",
        "{!Rlew",
        "UpdateVsconfigXML:  Could not set osfirewall tag in vsconfig.xml, use default.",
        "<R<{<",
        ";tO0F",
        "/:7/V",
        "cryptopro",
        ".f9{cc |u}~",
        "/6` U",
        "gqK+A",
        "6/6H6}6",
        "Failed to concat filename '%S' to string: %S",
        "S\\&XY",
        ".?AVios_base@std@@",
        " ;(Ra.",
        "h5?b:",
        "egog'",
        "8 8@8H8P8X8`8h8p8|8",
        "Z9;\\;B",
        "FMULP",
        "fREt8",
        "nP)4Z",
        "00-05-69",
        "SKJ2@",
        "ssl_add_serverhello_use_srtp_ext",
        "ssl session id has bad length",
        "2F=xa",
        "RXb_j",
        "QSeA~",
        ":2;=;D;e;",
        "e^fNP",
        "nw~2t",
        "2*3@3J3m3",
        "P</$vw",
        "<'NwQ",
        "bw0w%v(",
        "type_error",
        "BH\"*?",
        "5<6@6D6H6T6X6\\6`6d6h6l6p6t6x6|6",
        "Error 0x%x: %s",
        "G^?rO",
        "j%:i~",
        "*PYW}]",
        "LsM{m",
        "anyExtendedKeyUsage",
        "%~4d7",
        "~h\\2c",
        "QQVW3",
        "3333w!",
        "Jsq8B",
        "Fm.*-(`",
        "RT\\tMR",
        "_^k%;O",
        "UninstallFW",
        "en-nz",
        "Host: %s%s%s",
        "PVhpJ!",
        "1\"uSc",
        "illegal empty extension",
        "f4NhV",
        "BXgEc",
        "Avsys\\reg_data.xml",
        "3Z3X2\\`",
        "<20C1",
        "onn`Q",
        "gefZr",
        "zTr {",
        "CW,3y",
        "Nz{{k",
        "mg`BM*2",
        "B?(@h",
        "eu-kC",
        "[-oD)",
        "=Y!OMA",
        "F C24di3x",
        "2=g2h",
        "!Udn|",
        "D$dPj",
        "=8>C>^>",
        "id-smime-aa-msgSigDigest",
        ".GvIg2",
        "UFmi[c",
        "QX~ A",
        "3DCompliance.exe",
        "m#yJ4(",
        "/O*D]",
        "9Y|/J",
        "[TMPR",
        "8#*,#*,",
        "VSConfigPath: %s",
        "cMSf:",
        "31/~OQY#x",
        "user guide and local laws as applicable}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 .}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238\\charrsid15169477 ",
        "Sl]=y",
        "krqJJ",
        "[VECTORED EXCEPTION] The RPC server is unavailable.",
        "2$ MQ",
        "cenewlogo.png",
        "1F2v2",
        "rff;U",
        "H6,5f3o(",
        "\\(&O[",
        "H,jgy'",
        "G3x9'4",
        "~#cL1a",
        "nY0`>ky",
        "i'Z?P",
        "s#1*m",
        "5>hS1K",
        "ZoneLabs\\avsys\\install\\udinstaller",
        "7 8R8w9",
        "M|>sj",
        "&,4Y]",
        "Bt@\"}",
        "l!ub+e",
        "Np4Dw",
        "*L650",
        "WrReI\\JU",
        " $n;C",
        "rq y8",
        "{{{{{{{{{{{{w",
        "GetBladeRequiredDiskSpace: Blade Required Disk Space will be calculated according to features:  %s",
        "6A[8G?",
        "8uCkx",
        "^X3/-X#",
        "7EJ3C",
        "'[O2O",
        "TE9u}In[2)T",
        "#XP8x",
        "syr!8T",
        "?j%Zl",
        "j9f7'",
        "z^+6&\\",
        "6)7[7n7x7",
        "aB6^!",
        "0L0q0<4",
        "z/$GV",
        "Fb`neRK",
        "GSSAPI handshake failure (empty security message)",
        " -config ",
        "=)=Q=y=",
        "{{-/(j",
        "Fi4&;",
        "|BN#(xC",
        "Y OR ON BEHALF OF YOU SHALL BE CONSTRUED AS AN INFERENCE TO THE CONTRARY. IF YOU HAVE ORDERED THIS PRODUCT SUCH ORDER IS CONSIDERED AN OFFER BY YOU, CHECK POINT'S ACCEPTANCE OF YOUR OFFER IS EXPRESSLY CONDITIONAL ON YOUR ASSENT TO THE TERMS OF THIS AGREEM",
        "$TH/<cu",
        "]COjb",
        "mt48iC",
        "Je69h",
        "3?4P4",
        "81878A8G8Q8f8r8",
        "w}MGC:",
        " @ bdO6lg",
        "YAxLP",
        "U2UV_",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Device Agent",
        "(E? {I",
        "E\\7iwb",
        "'A}lm",
        "lOz=e",
        "{V `w",
        "&(B9Q",
        "pD\\a.)PI",
        "|h`fc;",
        "DfTLbS",
        "#@sn ",
        "h{=@s",
        "?$ _^",
        "Can't open %s for writing",
        "[N{WE",
        "[y1tj1",
        "zwRDI&fQ",
        "/T{8]",
        "m=EA7t0A",
        "z~-3/",
        "CJtBpl",
        "\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid15298478 ",
        "`q+vP",
        "*Q/U=",
        "22@T\\/",
        "X<ruS",
        "VruPv",
        "~Vuw;",
        "bx jGY2",
        "z\\+xuV",
        "G!:x`R",
        "m:%X&",
        "CreateFile {} for reading failed {}",
        "jKhd$#",
        "9+:^:",
        "suWLTfz",
        "080Z0j0",
        "jVlT<f",
        "=gd}v",
        "RJ45\"PFn",
        "4ZPWK4i&0l",
        "2@$3<",
        "\"LOfL",
        "ec_GFp_mont_field_encode",
        ":6;.*u",
        ":S;]<|<",
        "Wfz+fZ",
        "L\"CRdS>%",
        "t=?E4S",
        "l+);N;",
        "u@hll#",
        "#O#4y",
        "I=J4\"\\",
        "2V3[3b3h3v3|3",
        "g4M_Y",
        "IsProcessorFeaturePresent",
        "L]?YbI",
        "e8{Dh",
        "BO^uS",
        "fil4Z",
        "/PjSW",
        "H'%P%&E",
        "sl+hrG",
        "]yFPTh!",
        "    <security>",
        "> >,>8>D>P>\\>h>t>",
        "g\"IWI",
        "3q 3?",
        "\\pD7Q",
        "method",
        "x^53X%}F",
        "SROL_",
        "mC>}?",
        "C%]VU",
        "Xe9EK",
        "4&fP8CU",
        "Ac,ZpC",
        "b8g:!",
        "q4EESS4",
        "g:M3/|J3",
        "*xEU;",
        "=3=L=`=",
        "LN={W",
        "ro\"gOh",
        " WITHOUT WAR",
        "242;2\\2",
        "&zI)|",
        "jujuj",
        "Req(5",
        "#i~IJ",
        "i+\"8Q7",
        "\\|<=go@",
        "RunClientHotfix starting.",
        "2;?3'",
        "insertVsmonDisabler",
        "ext-ms-win-ntuser-dialogbox-l1-1-0",
        ")cQXo",
        "6Ag,Y\"",
        "=6=H=a=t=",
        "t$$j\\V",
        "Xcx'K",
        "Fvz;{",
        "jAjgj(",
        "D$81F",
        "l*iv\"/c",
        "Successfully turned off protection.",
        "iCDC\"",
        "%070C0X0j0",
        "'2QQ_",
        ":$:W:]:",
        "eT9x/",
        "kB!;^",
        "g2w&XK",
        "WixShellExecBinaryId is %ls",
        "=Sp&i",
        "\\zlscvins.exe",
        "q7zs\"",
        "!(\\^A",
        "Yy;Ua",
        "hbn=4N",
        "ofj\"o",
        "q3>\"j%",
        ":2:_:",
        "DAm11",
        "1*1I1",
        "ZHDLe0C",
        "malformedrequest",
        "\"-Z6q",
        "=)D:1h",
        "@>mPgt",
        "\\!bjE",
        "ldBFB",
        "001u\\",
        "5?5g5",
        "UPGRADEABILITY",
        "0y/6G",
        "FU-g6",
        ";fD4~",
        "KbM8POr",
        "MsiRecordSetString failed with error = %d",
        "failed to load XML file: %ls",
        "s7B,8",
        "++M2KS",
        "(CN3N}/",
        "{=VZNJ",
        "lOGhk",
        "english-uk",
        "e\". /",
        "W)n'v",
        "k._OD",
        "7)7E7a7}7",
        "*WvJg",
        "2?Ggro",
        "ycMjN",
        "_nU=0",
        "FICOMP",
        ".rFe.",
        "4;svelbt",
        "Z()wI",
        "c.b=R",
        "_]0 <^",
        "tOKXf",
        "$eh9S",
        "ntdll.dll",
        ":#:F:",
        "qRWU^",
        "YN<mz",
        "r8oYKv",
        "@$$.+(",
        "CO>9\"a",
        ": EQd",
        "3 3&3,32383",
        "xPL\"^",
        "`m}J|l",
        "8;G)0k",
        "pS?3xo",
        "|E0u<",
        "e@,&,}",
        "8[#=gB",
        "?3?:?",
        "Z|I6I",
        ";$;,;4;<;D;L;T;\\;d;l;x;",
        "q.Qc^",
        "e}9a r",
        "[^b;I",
        "Tcm.S",
        ".\\crypto\\asn1\\evp_asn1.c",
        "2ryx\"",
        "c3k[#-",
        "z6rEt",
        "/'/G/g/",
        "t=Eze",
        "MpC)E",
        "GU _Li",
        "9.:6:",
        ")bEiJM@",
        "{b`6Bi",
        ";b%e-",
        "v `dQ",
        "Inside",
        "Z?I9p",
        "~u7Cb",
        "_stopSending@4",
        "r8UE@",
        "!,Ka.",
        "OSEl3",
        "5$5@5\\5x5",
        "FeatureSmartDefense::UnInstall",
        "D8s,3",
        ")dz}V",
        "#zq|V",
        "IpCqU",
        "v1 KfD.",
        "&4(2Snk",
        " _.t.B",
        "'(89y",
        "Z!`:WR",
        "2(2?2J2R2m2",
        ")tYYgr",
        "^]`<u",
        "z@Fr,*",
        "T`Tb.u,",
        "BE7;9",
        "9D9j9",
        "3?ps1cVhO",
        "CL|1[I{",
        "Di?nD",
        ">H`bi",
        "G 6(N",
        " enter into a licensing transaction with Check Point at the end of such evaluation period, or in the event that Check Point advises You that discussions with respect to a licensing transaction have terminated, then Your rights under this Agreement shall t",
        "\"r^w=",
        "4C0#Q",
        "u!)FsorsK",
        "jJiBwy2S,",
        "YaPmh",
        "v%Gu7",
        "U9n\\1",
        ":&:2:9:L:]:",
        "Ud/T`",
        "ahs~w@jd",
        "2B:\"i",
        "J2I0IFR'",
        "B2mR*",
        "%id*|3T3qgO",
        "3P)}c",
        "Pkp.'|",
        "_SD|;",
        "US>@o",
        "undefined generator",
        "<b<i<",
        "\"u/PV",
        "k,Fbx1",
        "aHhO_0",
        ".?AVsystem_error_category@detail@system@boost@@",
        " {L@Z",
        ")4b|R",
        "wBCUEM",
        "(9_fst4",
        "`KYl2",
        "dmdName",
        "3Qf$]",
        "NCONF_get_section",
        "7!'?_",
        "9E52B",
        "N`*8y",
        "8n9H:y;=<",
        "O=1}rS",
        "l-p^)",
        "KrV V^",
        "? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?",
        "4[,Ox",
        "4{M'cx",
        "JD;NDu",
        "5I5`5",
        "Za6'C",
        "Connected for transmit",
        "]M\"-H",
        ";vZ[C",
        "8&858Z8|9",
        "Xg8[-",
        "FD<EF",
        "JmBy,f",
        "dFRQu",
        "{Gm(@",
        "6#6-6F6Q6Z6a6q6",
        "1vya,P",
        "|(%QS",
        ")T|^'8If{",
        ":(:0:<:p:",
        "4 5O5}5",
        "v#7oyn",
        "XrIvh",
        "ZKKxwy",
        "]p_L$",
        "ITt4$",
        "ssl_client",
        "7?7F7R;",
        "sFr!u",
        "t$LSV",
        "KkZaFo",
        "(H@.Aj",
        "SetSecurityDescriptorGroup",
        "{#X)r",
        "_s2X.",
        "J@RA [",
        "IqbbZ",
        "CP tj",
        "6 6(60686D6d6l6x6",
        "HP=fG",
        "> I.@g\"",
        "=,?3?",
        "jx`Tyyg",
        "L{=)?",
        "rlk| ",
        "V|4B/iJ",
        "U$0~PX",
        "CMOVG",
        ".U\"X;",
        "An invalid or inactive handle was supplied. ",
        "PKCS12_set_mac",
        "Mq3C1",
        "p9X7b ",
        "3+3F3P3Z3b3q3",
        "0!1L1w1",
        ")<f>z]",
        "`@ `QE",
        "wk8VnZ",
        "\"P4m[",
        "O,|({",
        ".B2uw",
        "FD_^][",
        "1TPEP",
        "Failed to save value \"VersionAfter\" into registry. Error code: %ul",
        "CVTTSD2SI",
        "k#vd>",
        "203@3`3|3",
        "<.<e<",
        "C6H:y",
        "zaRich",
        "u\"7Mh",
        "7.t=$",
        "zO&P-%",
        "2<GK>",
        ">T?z?",
        ":=/P\"",
        "Hsf;G",
        "2IQlL",
        "6$646:6@6O6]6g6m6",
        "!S;(N",
        "v$*s;2",
        ",|Su ",
        ".\"%<l",
        "6\"6/6S6d6|6",
        "qpp,P",
        "B.1eG",
        "MYl-Z0",
        "9 DXT",
        "Uzsh-",
        "RunClientHotfix",
        "AMRebootFlag.pending",
        ".g+|$",
        "5_BW\\",
        "TLS1_PREPARE_SERVERHELLO_TLSEXT",
        "VSPWInstPasswordRequired",
        "2~\"pI",
        "M8f+#g",
        "8Hf+lF",
        "UILEVEL",
        "@)M{0",
        "n;3S-",
        "d}7]tl",
        "CoZavW",
        "9zh4w-",
        "4F\\.,",
        "w?&o6",
        "a-!;@",
        "IGVe!",
        "5[+OL",
        "6~.:i /",
        "<Oou7gIt",
        "OCSP Response Data:",
        "OBJ_nid2ln",
        "fdvgYKF",
        "You should always register the Hardware Product in your {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname PlaceName}}Check{\\*\\xmlclose} {\\*\\xmlopen\\xmlns2{\\factoidname PlaceType}}Point{\\*\\xmlclose} }{\\field\\fldedit{\\*\\fldinst {",
        "MC`.A",
        "n)yCQ",
        "ASN1_BOOLEAN",
        "D$8Ph",
        "FIPS_DIGESTINIT",
        "515Q5q5",
        "mkCRr",
        "m~:\"@w",
        "tEn&7S",
        "_}<a`}",
        "tXDBC",
        "O?x8{ ",
        "xod(IU",
        "B2I_DSS",
        "read only file system",
        "ph[;|",
        ">`X,2iM",
        "Transferred a partial file",
        "#UR2y.A",
        "LvxX6",
        "VKuvu",
        "M%EkSg",
        "?/0>2",
        "6[yzu|Q",
        "aesij7W",
        "$KeV_",
        "<*=!>",
        "p1C5r",
        "eov!{",
        "5]\"xG",
        "4<*'r",
        "bL%d&",
        "NU~Mu",
        "CdH]m",
        "4F5X5",
        "BpbrMs_9",
        "8@n95Y",
        " d(Ly",
        "I`9|1",
        "5*5F5b5~5",
        "so6imr1",
        "gV+b%",
        "0I$8H",
        "SNAN)",
        "D-q9r",
        "eq64{8`",
        ")I4:.GG",
        ">KEZ$",
        "f-z;+",
        "9l$4t",
        "l$,VSU",
        "WX`8*",
        "s}C/i",
        "m]-|!",
        "r6\\uC!",
        ":5sIv",
        "****************************** CheckUninstallPassword started **********************************",
        "_4#,`",
        "!,%,d",
        "o - Output cpmd5 value",
        "H&|!.\\v3",
        "INTEGER",
        " 1<;4",
        "v_J;~",
        "q8',]",
        "21Q@$O0Y}",
        "-mm=~",
        "H64T;",
        "AZ:XwPh>>",
        ".}^=V0",
        ";~z $",
        "MAQp{",
        "DSA_verify",
        "$Wt;r`G",
        "#?s9V",
        "y](aZ",
        "boin`",
        "^o 5+ukb6o",
        "0EM!X",
        "F(WSV",
        "RSA_public_decrypt",
        "AES-256-CBC-HMAC-SHA1",
        ">.???o?w?",
        "b2I@C",
        "qt=WQ",
        "3{VO|",
        "A\\:#-",
        "GOST 34.10-94 Cryptocom",
        "1$1,1`1h1p1|1",
        "/l'qlH",
        "N'|T2f",
        "{\\*\\cs21 \\additive \\rtlch\\fcs1 \\af31507\\afs24 \\ltrch\\fcs0 \\fs24\\loch\\f31506\\hich\\af31506\\dbch\\af31505 \\sbasedon10 \\slink7 \\slocked \\ssemihidden \\spriority9 Heading 7 Char;}{\\*\\cs22 \\additive \\rtlch\\fcs1 \\ai\\af31507\\afs24 \\ltrch\\fcs0 ",
        "_ax)\\",
        "a2i_GENERAL_NAME",
        "?6?F?M?U?_?",
        "h0=D3",
        "[]Q=F",
        "uFj4Ym",
        "iFcm^Lg",
        "9J9^9",
        "62^vq",
        "&tQwLPp",
        "1>?`Qz",
        "K[yTQ",
        "cT>Fg",
        "jYbI;",
        "5!5)51595A5I5Q5x5",
        "p3|-&",
        "`e!J/",
        ":&;2;M;",
        "@;D$0",
        "9()y'",
        "N%bdr",
        "^N8pnU:",
        "T$(t4",
        "h\"i25",
        ".?AV?$codecvt@_WDU_Mbstatet@@@std@@",
        "i-,bcL/+37",
        "[Registry] RegCreateKeyEx return=%d for path=%s name=%s value=%s",
        "'{>:\"",
        "FB%7g",
        "iLKe+iqG",
        "=%=A=]=y=",
        ",?N:D",
        "?-?4?f?o?z?",
        "4w5{5",
        "EVP_PKEY_copy_parameters",
        "bde@P",
        "G+:(a",
        "MergeCommonBackup handle common policy: %ls",
        "=W=/>",
        "s7iFs",
        "~c{HZ",
        "xPcre<",
        "****************************** VnaInstall ended **********************************",
        "InstalledMode4Vsdatant",
        ">$/tF",
        "/oFw@",
        "WM=lkt",
        "JA'2Zb",
        "$R`91",
        ",N<+)",
        "V#(.H",
        "PKCS8_encrypt",
        "Gf}SxT",
        "g#GWb",
        "rsadsi",
        "DTLS1_ADD_CERT_TO_BUF",
        "5K5k8P:",
        "S-*=yTB",
        "EGj((",
        "bvhdj",
        "5d&s|",
        "P~1v~",
        "Cqqttvvww",
        "M><|60",
        "OpenProcessToken failed, err=%lu",
        "w`z6TP1\"",
        ">i:] F",
        "UpdateZoneAlarmXml:  Nothing to do. No update key files specified.",
        "fOykL",
        "Failed to run MsiGetProperty to retrieve SC_UIFRAMEWORK. Setting to NO as default.",
        ":0:]:z:",
        "vI6m_",
        "Lp\\|rJ8",
        "RmIV^",
        "ssl2 connection id too long",
        "F/G2U",
        "r:wKz}",
        "})Toh",
        ".\\crypto\\stack\\stack.c",
        "{>07D",
        "GetClientTypeFromRegistry",
        "|b:bz",
        ".?AVMultiWaitBlock@details@Concurrency@@",
        "SRP-DSS-AES-256-CBC-SHA",
        "TG7Tm/",
        "?4?@?`?h?p?x?",
        ";+;>;",
        "1)\"f.K",
        "Y?GAv63",
        "'/#:^",
        "\\.sE=1VBa6",
        "V2$q45",
        "Warning: failure during InstHelper stop.  Continue ...",
        "KFHUEDM",
        "d%AKGc",
        "Y*{!LZhM",
        "XBBDc",
        "hylR*",
        "/evEubd",
        "t$TPVQ",
        " u7XB",
        "fCsdB",
        "9$9,949@9`9l9",
        "JrnAg",
        "failed to write VerifyPath to custom action data: %ls",
        "9 909@9P9T9X9p9",
        "34P#L",
        "8bY)0",
        "U[@,C",
        "CYY;_",
        "[1)a'v",
        "C*2XVj",
        "Lt+9?#L",
        "bad srp parameters",
        "Ds{RY",
        "5B5N5c5",
        "setct-BatchAdminResData",
        "aRev}",
        "Failed to take ownership on %s. Last error: %lu",
        "Qu`]^",
        "M6_/6ft",
        "\"5|xK",
        " v8tXQ2Ns\"",
        "TrueVector driver: Data thread not cleanly stopped.",
        ")uf8D",
        "~A=0tv8",
        "(Y L\\",
        "uN<=t",
        "DQoF~",
        "Y{3xG",
        "<ZY08$_",
        "Ob? d",
        "Wj!Z:\\&",
        "061v1",
        "6 6?6j6",
        "g..N8,!",
        "m|>H)",
        "^Mx7rr",
        "DO_DSA_PRINT",
        "failed to find any nodes: %ls in XML file: %ls",
        "oo;X:",
        "CryptReleaseContext",
        "compression failure",
        "2o'j/",
        "rRd;U",
        "Vop`}",
        "*HtVG",
        "070e5-6",
        "ZwWaitForSingleObject",
        "|5H@^",
        "142r2",
        "_T7*Q-",
        "W#/TB",
        "kDr4w",
        "M9@mZL",
        "TRG7ts",
        "3L$@3L$",
        ":Blowfish part of OpenSSL 1.0.1t  3 May 2016",
        "6!6'6.666O6",
        "\\*dma",
        "3/3T3",
        "failed to add/update port exception for name '%ls' on port %ls, protocol %d",
        "r<{E\\];",
        "setct-CRLNotificationTBS",
        ")F00S2",
        "XKfVv",
        "Hhf)n",
        "i2d_SSL_SESSION",
        "|Bzn|/=L",
        "F[.\"D4",
        ".,#pq",
        "`x&0 w",
        "}U&)Ur",
        "b7w5QVU",
        " ']+i",
        "2{P<f",
        "jzr967#DK",
        "unsupported type",
        "uEY7A8F6",
        "FGWm;",
        "ln2=j$2",
        "LkLCL3,9",
        "RKRPf",
        "2#2)2.242:2@2E2K2Q2W2\\2b2h2n2s2y2",
        "0LE_XY",
        "vt:|rXp",
        "X509v3 Certificate Policies",
        "%WX4:S",
        "y4ztz",
        "d.uniformResourceIdentifier",
        "aes-192-cfb8",
        "union ",
        "BLOCKINGERROR",
        "Gx:,i&",
        "BtKU/7",
        "3$303B3",
        "q-`4x",
        "Failed stopping Services. Timeout reached.",
        "#Iq \\",
        "N/\"z~",
        "= f[~",
        ">We<QB",
        "7c6P~",
        "S1~N=",
        "vbm;/<SO{",
        "G,ZG/",
        "^pSYy)",
        "+28Xz",
        "im9`d",
        "9.9J9f9",
        "sVz<hK",
        "Qv;+.l&qo",
        "eeR,K<",
        "B!UI,",
        "3P+np",
        "HPV;w}",
        "?'?4?>?",
        "?B?%A",
        "4K3Oc",
        "QQdT2Vn",
        "%ZM&c",
        "%Y_9-",
        "909L9R9W9h9z9",
        "YG]11",
        "jAjoj\"",
        "2N1F1^",
        "ucrtbase.cpp",
        "x8$$c",
        "|K|}y",
        "V,Qd.",
        "2D2V2e2",
        "42(1z",
        "xd\"41",
        "P~?\"p",
        "1 1$1(14181<1@1D1H1L1P1T1X1\\1`1d1h1l1p1t1x1|1",
        "!Nb[\"",
        "zuo:g",
        "rMsB7",
        "%!+1'",
        "3w~9g?",
        "0yYD5",
        "Vct#<",
        "C!p8y",
        "v@b0|zO",
        "[OeXC",
        "[si}?",
        "cAnYu",
        "*KQQ(>",
        "Another instance of the VNA already exists. Removing all instances.",
        "3!3A3",
        ">O>Y>",
        ".\\crypto\\pkcs12\\p12_utl.c",
        "wlfBsv",
        "_NuwM",
        "FzjuH",
        "De+x8Ch",
        "=20!N",
        "43^\"X",
        "%m:)L",
        "l+[6P\"",
        "CreateDirectoryA",
        "Xj]9J",
        "Vj0U3",
        "L$ QVP",
        "S-'2D",
        ".eU1>",
        "Failed to set SIO_KEEPALIVE_VALS on fd %d: %d",
        "gu;]lt",
        "^on]zgo",
        "1 1%1+11171<1B1H1N1S1Y1_1e1j1p1v1|1",
        "INT_RSA_VERIFY",
        ">bB>w",
        "$I& 0",
        "h(oSB.J",
        "Y;BwyNA^",
        ":  Set string value to ",
        "7&RL[",
        "Iv-.h",
        "GENERAL_NAME",
        "5\"5'5V5i5",
        "jIP9SMd'",
        "(,7l_H",
        ">*Z`D",
        "&;-jVM",
        "ds$o99",
        "SDDH3",
        "P ]T3",
        "4?xrh",
        "RegDeleteKeyA",
        "OCSP_CERTID",
        "Je)[vMf",
        "/ctZb",
        ",H0cNM0f",
        "AY*)#",
        "6y#G2",
        "b8KN8",
        "kf\\=g",
        "f1KY\\",
        "WcU+?",
        "0$040D0T0d0t0",
        "(td<D",
        "Can't find files at pattern: %s",
        "Flags:%08X",
        "DM1-_;",
        "Jpj,K]",
        "HJ@-e[",
        "8AcLj",
        "\"{zd<",
        "l.2EB6",
        "L$(QP",
        "r>xpo",
        "D'i1H",
        "\"`$#3-F}",
        "#$[,.",
        "mT\"O;",
        "<)<B<G<L<i<",
        "!ye?D",
        "P=*wy",
        "_FCJr",
        "Failed to set force_policy_reload value to registry",
        "[s\\R,",
        "PolicyStorageUtils",
        "UI_f%",
        "rzgKs;",
        "MsiGetProperty: %s",
        "&$e.6",
        "cE#a+",
        "D$$WSP",
        "~Yob[<",
        "G1%e,",
        "}hy#rh",
        "D'dE*EGEOEYE]\\",
        "TgDg|",
        "!xc|o",
        "Binary ID cannot be empty string",
        "Not PATCH or MSIPATCHREMOVE. Adding CleanAvsys.8792D4CE_35B7_41EC_AEEC_B7D5617B0989 row to RemoveFile table",
        "tA:yY",
        "8!9)9':0:Q;Y;",
        "ECDH/RSA",
        "< of3UA",
        "WD_InstallWatchdogService ended.",
        "failed to get user to configure object",
        "DNgwyx",
        "u4j_h$^\"",
        "OnInstallDriverEnd",
        "3Zfkx",
        "~B6O.F",
        "Va72DM",
        "t{$ec",
        "6!616A6Q6a6q6",
        "Vx^%T[#",
        "677?7{7",
        "tbsResponseData",
        "{t(@<",
        "r/_>5",
        "K8d#+",
        "V0bMK",
        "RdXSoB",
        "S'/#v4",
        "\\OB!R",
        "<1@i$",
        "cleartext track 2",
        "?1?F?X?",
        "/Jq=*f",
        "3]}bH",
        "f%63\"g",
        "a*_5S",
        "Ey:8=",
        "YPk&h",
        "@N.a4",
        "5(O+.",
        "2S6S8S@R#h",
        "h]4To_'",
        "BQE9%",
        "Missing root certificate",
        "C5\"P+Lf",
        "YE,iq",
        "{Kr(,",
        "~)[ek",
        "laat3",
        "(y!3*l",
        "(=1Yl",
        "67HaH",
        ";x631t4(",
        "W:`Gz",
        "Ox)RT",
        "F PVW",
        "^\"Ctf",
        "-S`<NC",
        "_4dS+",
        "**a('",
        "4c``TC@",
        "uc6%[",
        "=J]QK/",
        "8MFP[",
        "H!n.!\\",
        ":9* (",
        "Mrp|QC>",
        "QSSSS",
        "9*4n@",
        "EFU1(",
        "_16Y&,C",
        "0~,A_",
        "jhjwj%",
        "Zp^qe",
        "pG#[p",
        "z$za=",
        "Identity",
        "%N_M&",
        "25O`t!<",
        "qkK<x@wT_",
        "6$6<6L6P6`6d6h6p6",
        "2 JO)",
        "failed to convert into string property value: %d",
        "vnaap64.sys.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Fmp^J",
        "En'W4{",
        "~ggfl",
        ",yCgt",
        "9.u\"AJ3",
        "9jd48",
        "o5%(Z",
        "cbKK>",
        "n?VME",
        "] cPs",
        "%FWnWQ",
        ">4$8,@",
        "O.djOQ",
        ";]:=W",
        "\"Hy4L",
        "9V^q)z",
        "K?rJV1",
        "jwKBba",
        "%kYXd",
        "0y`}+",
        "7ZPyvsi",
        "A F0:==",
        "9>~7f",
        "S~U=!",
        "<xmlattr>",
        "yQ{kp",
        "id-it-unsupportedOIDs",
        ">J~Bn",
        " bK?^",
        "h<4<\"",
        "{-]^4'",
        "WD_CheckFolderForZAUpdates started.",
        "SEIrUR",
        "u1=*}}",
        ")Q9|pw!,",
        "'HR@MHK",
        "deque<T> too long",
        "\\Y\\'RF",
        "~1>< ",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93License Key\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "D$,UWP",
        "OSMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "Failed to get ProductCode.",
        "3]Py-",
        "03V@MX",
        "rYq~M",
        "_\\PpC",
        ":>cF'",
        "wc*)3P`$5)",
        "rNVG}",
        "J5*tju",
        "p6MePH",
        "y/Z_p",
        "Failed to delete %s because file does not exist.",
        "6Xr{wZ",
        "/ 1{1",
        "XW ab",
        ";\\$ v",
        "@K#8k",
        "C\\g~(",
        "8 8<8X8t8",
        "7$737:7",
        "f%<eG(",
        "D$(PhLA%",
        "Ev3)N",
        "ASN1_GENERALIZEDTIME",
        "Exception parsing log file",
        "zcH1-",
        "z7F+Z",
        "State_NotRunning.png",
        "!S>*\"",
        "gTj4$",
        "#bnms",
        "DSA-SHA1",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UpgradeCodes",
        "n4rcYpD",
        "8f9u9",
        "4 4$4(4,4044484<4@4D4H4L4P4T4X4,6064686<6@6D6H6L6P6T6X6\\6`6d6h6",
        ";jb-(Vv",
        "y@6.jJ",
        "?0WK3",
        "FGAIS;",
        "ipM{'",
        "sl?8z'd",
        "jA[f;",
        "T)5.K",
        "e)!,Ej",
        "FAILED_TO_LOAD_VAINSTALLERLOGON",
        "v^[zT",
        "str_field1",
        "K+l($9Ov",
        "I#2`c",
        "aKRB5",
        "G3J~_",
        "\\<K\"+",
        "wA0Ff",
        "y&=={",
        "Oye|k=",
        "`.C?v",
        "TiT)UiU)Uiv",
        "hsTBXUmP",
        "[u(d+",
        " fs*Z.i",
        "b*_#p5",
        "9dq4ay?h",
        "4n;n<",
        "D$.lx",
        "c~TCz",
        "t$8VU",
        "d!_]LDV",
        "'w^~G",
        "DO_PVK_HEADER",
        "0q0S1",
        "563sk",
        ",4bK`",
        "=-=Z=",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\Framework\\Adapters\\ZIC",
        "ZKI:^",
        "Uw7v*",
        "234$5!6&&6!7%8945(:",
        "&[!9>/",
        "I}W}w",
        "IA+FL",
        "\\|?8p",
        "%s\\SysWOW64\\CPEPC_PLAP.dll",
        "s-Zlmb",
        "+_9rj=",
        "^5k=P",
        "kb is installed proceed installation",
        "\"WAD8",
        "zi-Q,",
        "3P?SK",
        "_B9oc",
        "^Bu`p",
        ">!>%>)>->1>5>9>",
        "7RJW[",
        "~<a$=",
        "R30Vf",
        "X\"(/6,",
        ":g;o;",
        ">&769l'",
        "2C1K3",
        "|`cL5M",
        "&I')(",
        "6F7P7Z7",
        "&QP[]",
        "5(j6X",
        "soWfl",
        "q76T4",
        "hJ7kP",
        "YU)m5",
        "/&>LJ",
        "z'bIW",
        "NoRemove",
        "Shutdown started",
        "e^S+W",
        "1]w1}A",
        "STRENGTH",
        "Ik$i>",
        "0;pz)",
        "PEM_ASN1_write",
        "CQ[za",
        "1(3Z3`4",
        "SYSTEM\\CurrentControlSet\\Services\\SR_Service",
        "0.{f>?",
        "&?l!f0",
        "FETCH",
        "U^f]2",
        "2 2(2,282@2D2P2X2\\2h2p2t2",
        "3 3(3,3@3D3X3\\3p3t3",
        "ASN1_item_verify",
        "InitializeProcThreadAttributeList",
        "G.FdR",
        "C@Wg3",
        "'&_^F",
        "O:OZOzO",
        "REPNZ ",
        "t O(*[2",
        "?'A'V",
        "g;;aNl5",
        "j^=P_",
        "oe6y,r",
        "E~4[/'}",
        "1Z$evJQd",
        "wf=]6",
        "`lcK6:",
        "v*x^J",
        "?>?}?",
        "W%);&",
        "}r?}Y",
        "U Rsy3$",
        "GY3,b",
        "u!pR>",
        "(ytF1",
        "X|F?W",
        "I53<5",
        "2*3^3",
        "@|gH$",
        "gb&ay&",
        "Ck-Z5h",
        "boost::filesystem::remove_all",
        "_%_IR",
        "$cKys",
        "GZkD8",
        "G9%^5",
        "T^4>:;",
        "3JgB'",
        "7.7N7d7y7",
        "^U$B8",
        "!_UVC",
        "QQPSQh",
        "TfC(>h",
        "3g[3$",
        "IIDn~r",
        "+$Vg!",
        "~ezb^h/",
        ",<& *}",
        "]ws@q",
        "(P2i[",
        "D$,UP",
        "304A4S4n4",
        "}awpn",
        "_D%ET",
        "&w>W%",
        "oX>PS",
        "= =,=L=T=`=",
        "617>7s7",
        "=>>n>|>",
        "&8Mg-cd=@",
        "q1rj),",
        "id-smime-aa-encapContentType",
        "@3A'f",
        "invalid mime type",
        "?(FN\\",
        "K\\)_u2",
        "VSTO Redistributables",
        " 22Ve",
        "xs\\`Uh@",
        "(f*()#",
        "4 5A5c5",
        "M<+?$n",
        "!4)\"d",
        "[LICENSING] NOTICE corrupt key %s attempting repair. modedate: %d",
        "HTTP/1.1 proxy connection set close!",
        "*9T%Q",
        "==Or;6",
        "RWSQPU",
        "\\X^Mo1|",
        "3b4x7",
        "pl4~(",
        "\"%sPiReg.exe\" -d \"%s%s\"",
        "s<eT3*",
        "^z^{^|^}",
        "NoKeep = NO",
        "3l$H3",
        ":)Z=*i",
        "};mnQFf",
        "(KKjy",
        "[+z#**",
        "\\WJ~[",
        "Mx1^`i",
        "E'.?;",
        "OCSPSigning",
        "!'pP9C",
        "f'g{=?",
        "t8w^6",
        "fsav.exe",
        "\"!K5P",
        "f@v6Q",
        "x}axI",
        "J)x'=D",
        "!Z!@je",
        "DTucz",
        "t:_^[",
        "DaGeNr@",
        "lJ^|^ ",
        "setAttr-Token-B0Prime",
        "sU\"yB",
        "Yvp0`",
        "(6E]@ArZ",
        "[e IA",
        "(%Z*`1",
        "7JE\\W=l#",
        "5X^H^-Ie",
        "v\"@7d",
        "=#uXP",
        "jei?},h",
        "Z2Q,E",
        "Failed to write data to new temp file: %ls",
        "YKJx,t%",
        "DB)s;",
        "_updateArrStatusStr@16",
        "l~y.)",
        "-G$6 ",
        "5(]&_&",
        "Key Agreement",
        "0#1x1",
        "ssl_parse_clienthello_use_srtp_ext",
        "[X#ih",
        "Bd+H<",
        "Pk+@oH",
        "kB)]BX",
        " >j/+",
        "`E 8=M",
        "(+@FI",
        "Lvb7d",
        "q;,fc;",
        "G<8We",
        ".]~j=2",
        ":5|uu",
        "RunClientHotfix InstPrep's exit code: %lu",
        ";zV:7",
        "}/bHY",
        "xDu#h",
        ".\\crypto\\ec\\ec_key.c",
        "696R6W6k6z6",
        "~|DH`",
        "moH#j",
        "line ",
        "6=6M6U6e6",
        "E_vQE",
        "1bM6u",
        "lV}=e",
        "bignum routines",
        "h#KJ:k",
        "7{-~N",
        "587\\7`7d7x7|7",
        "_waUP>F",
        "\\DX_I^",
        "')b&wR",
        "PhP8M",
        "i(thj9",
        "Q;OYM",
        "0 0$0",
        "tIAG[",
        "8pV3O",
        "f:rHy-",
        "x(8op",
        "5*5:5C5t5z5",
        "Mn2f7",
        "r5E<W",
        "\"{7 1",
        "gxi>$",
        "PMULLW",
        "~vE)`",
        "ho6Ub",
        ":\"IxV",
        "7),>C",
        "pJon9.8=",
        "rB2pBB",
        "343DwE",
        "~SxN a",
        ")\\wb&",
        ".._hi/",
        "6O6a6",
        "4;5M5",
        "Hc!1.",
        "0;1R1\\1l1",
        "sgQp ",
        "1+2b233{3",
        "KP{h-",
        "+gYg+",
        "& %1.",
        "il'%l",
        "C2EU{",
        "K[kGe?",
        "domainComponent",
        "?]PQ?(",
        "/t=j/U",
        "]Cn#Y2",
        "c7y K",
        "pi,[wJ",
        "NAg=|",
        "5Lv-m",
        "Z033WX",
        "(4<i8",
        "k8gsv",
        "=E=Q=a=q=",
        " gBUz",
        "ZdQeh",
        "3\\323r4",
        "&y|Zt",
        "2#2*21262",
        "%33333",
        "aYNA{8",
        "s}kP6",
        "OkrwZ",
        "failed to add temporary record for custom action ",
        "B zn6P",
        "tbUPS",
        "FlFK'",
        " ep7>",
        "If.0g",
        "OnFreshAfter:  setProductMode - default is Integrity (Check Point Secure Access) (7)",
        "]yvW ",
        "q\"w>s",
        "PKEY_EC_CTRL_STR",
        "C:&k~",
        "Failed to get the MsiRestartManagerSessionKey property.",
        "Y4_ok",
        "4LU.F|",
        " HAJh",
        "mUcOb",
        "8G2bD",
        "IQCI?",
        "WZ:k^",
        "v`WUS",
        "7b7l7z7",
        "VZl&3",
        "G'|QU",
        "*-&iD>",
        "uD|z,O",
        "RlYFp",
        "ik;GH",
        "EOC2 ",
        "isOfficeModeIsDisabledInRegistry",
        "Z6utt",
        "3!4)4",
        "oZ|9%",
        "DZvSF{v",
        "x9=;,)`",
        "ntlocal:Unknown",
        "QRg&4L",
        "D~)?:",
        "2#2;2C2S2}2",
        "W8K\\Y",
        "#:l\"$F",
        "w,r4r",
        " qJQ]H",
        "Yd:OX",
        "a{jl]",
        ": :4:A:V:j:w:",
        "=$=0=P=\\=|=",
        "0YE\"s",
        "Ni&F2",
        "$Ev0<p",
        " will not ship, transfer, or export the Hardware Product into any country, or make available or use the Hardware Product in any manner, prohibited by law.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14296673   }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "%f]6|",
        "failed to schedule firewall uninstall exceptions rollback",
        "rIs]`3",
        "VersionMinor",
        ")|z@^",
        "H6izt",
        "\\}IBQ",
        "^RD _0",
        "tFwIu",
        "`>^mi",
        "z;gbY7",
        "R%bAM}",
        "i:Eo 4",
        "=$=,=8=X=`=l=t=",
        "\\c,Ie",
        "7YzOg",
        "*Ax5c",
        "^t)K1-Fz^",
        "S:mU+",
        "@{o5E",
        "%,Hs8%",
        "aw,H^D",
        "DH Parameters",
        "JQ[8TN4",
        "n;c' y",
        "t4Vj!^f",
        "WIX_ACCOUNT_USERS",
        "0y`K|n",
        "d([S;N.",
        "i&< 0",
        "8Qpx{",
        "g*jYtm",
        "!KFHI",
        "twx}m",
        "=Z 3]5",
        "Q$M{H",
        "PROXY_CERT_INFO_EXTENSION",
        "fEfMf]faf",
        "1(/mT",
        ";_R\"_Ds",
        "?69.~",
        ")xE}pj",
        "x8\"7{",
        "? ?@?L?t?",
        "_?{0$",
        "Ta@eO",
        "CMS_RecipientInfo_decrypt",
        "D+.$!",
        "]at]q",
        "7\"839",
        "w73Fe",
        "7:tr@",
        "1+2u2",
        "-jlGO",
        "GJ~Pw",
        "a+F\\=",
        "D$$P@!",
        ";/>.+.",
        "signature malloc failed",
        "6>vi+",
        ":9Bx.",
        "\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 6;\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 6;\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 6;",
        "9?:O:",
        "M:18rp",
        "aS~#4",
        "YGqSL",
        " 2sE5A",
        "2?63H",
        "z#|C*",
        "nTJ(U",
        " anH<",
        "9q(,p",
        "J2%,t",
        "9>9{9",
        "=\"=)=0=B=I=P=f=",
        "failed to get XmlFile record Id",
        "8i62F",
        "(U.,Jg",
        ";*;b=",
        " D3?2",
        "?O3kE",
        "CAMELLIA-256-CFB",
        "9+9a9",
        "yKGGgR",
        "=`KL4",
        "PSSSSSSh ",
        "<<#Rr",
        ":r|xB",
        "LrPdo\"*",
        "(d)&3",
        "c_vVmJy",
        "FGL@'",
        "#1:h<W",
        "Ix$pP",
        "5L6g6",
        "7qOxR",
        "MY[Yl",
        "I\\v%(",
        "6;6W6s6",
        "/dS:7",
        "Ka/DL",
        "2(lcD",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 INDEMNIFICATION}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "2B~X9",
        "u4gC<",
        "4=4h4",
        "?[s~A",
        "L6]y_r",
        ".en[#4",
        "\"Qm!R",
        "2H3T3p3",
        "N2Y~),w,",
        "proc2utl.cpp",
        "Don't know",
        "<jhh;g(+To^",
        "dirname error",
        "x\"mFJ",
        ";Q(mH",
        "\"TOPKY",
        "bz\\=n=",
        "fP%,,",
        "u8_^]",
        "3'4w4",
        "Failed to MsiDatabaseOpenView (%s section)",
        "EYnSK`",
        "Failed to parse FETCH response.",
        "6<6m6",
        "OCSP Request Data:",
        "8M8|8",
        "~j=FPN",
        "4`<r02",
        "1#1/191g1r1}1",
        "$!3(O",
        "zh_\"`",
        "+[S_4",
        "SU3EGP",
        "Vk](i",
        "hH%JmD",
        "7#7E7R7r7|7",
        "i!pi?",
        "pwinstset ",
        "Policy Qualifier CPS",
        "\"KS6/",
        ";Sm1!U",
        "E\\C=b",
        "$T.9j8.",
        "LbPlHc",
        "@[2T)",
        "IsInRemoveCase",
        "eeX;e",
        "@b`Hp",
        ";8;`;",
        "UZe-M",
        "Z_ fh|",
        "tsF39M",
        "\\K8!Ec^",
        "TjiBp\"",
        "P*_fY{",
        "c2M,J",
        "X02UP",
        "m8!g{",
        "B,%&U|[",
        "SUPDUP OUTPUT",
        "SEQUENCE",
        "s69~4",
        "Ybv\\8y",
        "Lh64#",
        "hE11;",
        "3-Emk]",
        "|SqYc^",
        "%+76k",
        "^vJtOEIjB",
        "p60sx",
        "t5H*h~",
        "*R1MC",
        "C:y\\L`",
        "VjQh(Z#",
        "/{u^U?)h",
        "<9=M=b=h=",
        "ZlD=g",
        "f CCZ",
        ")rROPa",
        "yW,O!",
        "<8tzt#j",
        "O9qMI",
        "OnUpgradeAfter started.",
        "9nTt!h",
        "Mwx}n",
        "&RaWN",
        "SYSEXIT",
        "R?R:^",
        "8,989",
        "m;(<3",
        "S2wJcl%",
        " 0x2f",
        "QZe(b",
        "M9<\\A",
        "8=a:&",
        "su<fS",
        ">`yEj`",
        "1!3'3",
        ".+tpS",
        "<_w1zI",
        "7jOux",
        "h&Fm]k~",
        "K)JA?",
        "}5Q8:",
        "o\"dB\"\"",
        "Z/WZF",
        "OnFreshAfter",
        "iz#%)~",
        "|/wR;}",
        "<-<Z<",
        "!a#)B",
        "~I:@k",
        "m!kq]",
        "nsComment",
        "Nmypk",
        "4Y+&J",
        "#-'-+-/-3-7-;-?-.,",
        "IAprP",
        "Bp#KzBg` o",
        "wF-:&Bn",
        "RunClientHotfix InstPrep failed to complete in timed manner.",
        "b>PL%:",
        "2!3>3V3^3y3",
        "6XJ?B",
        "L$(;L$$r",
        "2 2@2L2l2x2",
        "stateOrProvinceName",
        "%.|cd",
        "WfIM\\",
        "E=QHV",
        ":6;E;",
        "zNoB!",
        "zO\"aT_",
        "NO|%v$",
        "Of)s$",
        "(dR& ",
        "1U2%3C3",
        "lxk{u,",
        "8^(u!h",
        "5^Hz*",
        "M?45^",
        "&>DH[",
        ";>7j!!",
        "au91J",
        "F<PVj",
        "Id4J{*?",
        "m@x!l",
        "Ehd$d@h|",
        "`[g'2y",
        "-.*zk;",
        "?4%3e",
        "!fCXcA",
        "CRolloverFileInZip::Open:  Close failed with error = ",
        "4)4B4[4t4",
        "[W&Os",
        "N>,3=",
        "~9$@#",
        "\"]I]-]U]}]",
        "80888@8L8l8x8",
        "80k\\#2r",
        "Q'8Pm",
        " Ex%-",
        "Liz9Hj",
        "3^SS/",
        "des-cbc",
        "X>7zH",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\deviceagent.cpp",
        "DQ*cl",
        "+p'xN",
        "|Ov^+",
        "e*g:/",
        "Going to stop URLF service - gwcc (TIF.exe)",
        "McAfee ViruScan Pro v7.0 VirusScan Professional Edition",
        "Configuring Antivirus settings (5 of 6 tasks done)",
        "mQ=K_#o2",
        "4*4/4H4M4_4d4t4y4",
        "P9y$:",
        "iC(t[",
        "Illegal port number in EPSV reply",
        "+Aj6:rR",
        "Z6~4_",
        "'i+PJ",
        "</wgg[",
        "hQ0sM",
        "AddMitigationOptionsRegValue: registry key already exists.",
        "LEc`N",
        "DDDDDDDDGD\"b=\"",
        "OT%]l",
        "2BM@:#",
        "!KCVH",
        "FAILED_TO_SET_ICLIENT_TYPE",
        "# du?",
        " 0x7d",
        ".\\W^Wt",
        "!q#mQ-",
        "QUf)4",
        "iTu H",
        "+,0%k{",
        "jqjuj",
        "L$4_][^3",
        ">(>,><>@>d>h>x>|>",
        "__uncaught_exception",
        "iA9w,",
        "gkm{C",
        "Failed to save value \"Duration\" into registry. Error code: %ul",
        "EqFz`",
        "ny3j7",
        "q DfC",
        "8Z8*9Y9d9",
        ".?AVCRolloverFileInZip@@",
        "D$4;G",
        "}U3T|",
        "ETe7Gv ",
        "*%;xU",
        "%p!9C",
        "]@ ]}",
        "'K3+D",
        "[U<*{`",
        "rLGQr1",
        "2 2(2@2P2T2d2h2l2t2",
        "1.jNj",
        "HB1Dc",
        "6&a<l",
        "0v-|aCK",
        "p}CHW",
        "*~~;*",
        "+9,[.",
        "Folder %s does not exist! Error: %x",
        "?2$&G|",
        ",-E#e",
        "Expire date",
        "+xz!@2NQ",
        "=#M$;A",
        "MwmhX",
        "XXrV6a",
        "he-IL",
        "=c0[{",
        "4x<PJ",
        "=a[%5",
        "n]}1E",
        "nMe0T",
        "\\t16N^",
        "uninstalling gina",
        "3TQPT",
        "9wE|E%",
        "l=%PYU",
        "(gl /R",
        "Vf0J^",
        "j[XY{",
        "TaI`t",
        "QEvey",
        "*z<wq",
        "kvRTL",
        "}2-/Q[D5",
        "UPuS:.0",
        "`,J7^y%s",
        "DzP_q",
        "Kce75",
        ";INi ",
        "FeatureSmartDefense ADDSC=YES",
        "\"rSRT",
        "AMm $GS",
        "PABSW",
        "\\AUEc",
        "BNO'9s",
        "zKx\\Q",
        "`*XN>m K",
        "{::1}",
        ":1I/h",
        "f|}I/",
        "YO([f",
        "90FA'",
        "[FE'M",
        "Failed to get remove folder identity.",
        "jjJGe",
        "BPR}r",
        "LoQ?QO",
        "Ej(X~",
        "Syo50",
        "=sc~g4",
        "(+{Fv,",
        "]%y&e",
        "D2dZ?",
        "module=",
        "MergeCommonBackup GetPacAndSid failed",
        "PEM part of OpenSSL 1.0.1t  3 May 2016",
        "ZH|\\;",
        "TFTP: Unknown transfer ID",
        "+Du95",
        "<f`Qy",
        "h\"rB4",
        "]'#'pb",
        "MoveFileExW",
        "3E5K5",
        "646<6D6L6T6\\6d6l6t6|6",
        ":$;T;",
        "GhLuQ",
        "C&C*C0C>UG",
        "^E3Vx",
        "|D7JKha$",
        "s9|\"tQ<",
        "%vEvUvuv",
        "`13KX",
        "+d+W4",
        "Crv0'",
        "Q/f?F#",
        "0[eB`",
        "Restored vsmon.exe.",
        "5Ef8:J",
        "SETQS",
        "*uq05",
        "u-PFd",
        "GetExitCodeThread",
        "sv-fi",
        "F&b|Wk",
        ":G#&&",
        "[7@A~",
        "040904e4",
        "x(9``",
        "protectEPAME1;",
        "A_}Uo",
        ".'.G.g.",
        "\\ q,!\"!'4",
        "MjjHd",
        "q*mqo`",
        "}^f_7",
        "<'V;F",
        "|V-wn",
        "?e{\"9",
        "u$9GHt",
        "?!?9?A?\\?{?",
        "mSO1*",
        "T@F$7S",
        "hn~lN",
        "$i:6k",
        "7y@&c",
        "ssl ctx has no default ssl version",
        "%MvlTgx5",
        "`P&].\\",
        "1#QNAN",
        "53L`b=",
        ">,>J>Z>",
        "Z&rQv",
        "connect",
        "DiBjR)P",
        "EF-LF",
        "8:f.p",
        "D$03L",
        "UnN^`",
        "#idah",
        "-(@C3",
        "1#262s2",
        "puf:l,",
        "RevertToSelf",
        "XP~KG",
        ".D_M}v",
        "!#sx|",
        "7d*mu",
        "f@*Y4",
        "CKp/)",
        "&6Y:-a",
        "hje9WAx'",
        "0'1:1G1S1[1e1o1y1",
        "B5N5Y5",
        "%qCoIv",
        ".?AVUMSFreeThreadProxy@details@Concurrency@@",
        "zA`a;",
        "|[wms",
        "m*l7[",
        "PKCS12_pack_p7encdata",
        "4[8o7?",
        "Godu<",
        "[u![:",
        "n+}F+#",
        ")Y<_kT",
        "blSGdG",
        "2;2E2",
        "FtS8E!",
        "3<4{r",
        "\\drivers\\klick.sys",
        "0,7E#K",
        "j\"^f9q",
        "n.+?yH",
        ")1.1TF",
        "TlsSetValue",
        "F1+vk",
        "i3XA7",
        "2O&pR",
        "<2V$i!",
        "k552.",
        "xRv\"3(b",
        "l.|k<(n",
        ">J?a?",
        "E\\$]8",
        ";7<p<",
        "!+f.>i",
        "[5fNS",
        "GrN</",
        "Product",
        "GDQ6<",
        "3/3K3g3",
        "3WO+n",
        "D%at%",
        "44;|H",
        "Tu:qa",
        "959=9S9q9",
        "F4_Y!",
        "/vE3TX",
        "^9{0z",
        "D@$S&",
        "aGt?u",
        "Can't open view to update properties.",
        "dlq=%",
        "lZ[ZXr@",
        "*0U0&1n1",
        "!B9./",
        "`^/z`<",
        "Wj\\_f;|A",
        ")9e@g",
        "-K~E1",
        "AVINSTALLED",
        "7owh&n",
        "q8uf6",
        "G`?hX",
        "va8Iq",
        "$M`/`d_",
        "iZ/je",
        ":o5.Tix)An|]",
        "Zxc~n",
        ">2?K?R?r?",
        ",%e,p`",
        "j Xm9",
        "N6J>a",
        "regex_error(error_brack): The expression contained mismatched [ and ].",
        " 0x2e",
        "j}Waz",
        "B8o,mh",
        "c\\yIYT7KT3",
        "bjv0:",
        "TG?uR",
        "\\&HMB",
        "Xrks[",
        "}8<\"2",
        "XJ11n^3r",
        "4L5P5T5X5\\5`5d5",
        "AuvLY_MZTp",
        "8COuR",
        "|O)[x",
        ":4;C;L;Z;",
        "can multiplex",
        ":!:.:7:=:",
        "*:E'q",
        "SPBgU",
        "rDoJ^",
        "KZq->U",
        ";(;.;>;L;S;",
        ")ro\\b/WDh",
        "Ss&=c",
        "`{)hHy",
        "0$0,0<0D0L0T0\\0d0t0",
        "6A6^6q6",
        "<REr}e",
        "!9_(Dn",
        "+SSEK",
        "1%kO&",
        "yU3&t",
        "ASCII",
        "t/HHt",
        "+p=5q8",
        "B7@,(=",
        "j%[iwjFg",
        "W6WVWvW",
        "}g4=M",
        "W?WJWnW|W",
        "xV6&[",
        "(rlEw",
        "|!n)i",
        "JE>}v",
        "OCSP_RESPBYTES",
        "<-`tj",
        "xWjpn",
        "T2^)s*",
        ";!;1;9;C;K;n;x;",
        "SITv>",
        "nR;Uz&|E",
        "Mr4CP",
        "e0x9It",
        "error calling QueryDosDevice",
        "^l[ a?",
        "b3j;pw=",
        "<>5sU",
        "J;`z]",
        "7SB>I",
        "\\;2XI$cC",
        "FileHash_ST",
        "a{\\_(",
        "K=>?\"",
        "reuse cert length not zero",
        "ga<WhH|",
        "7fn+{D",
        ">=ih8",
        "7$8D8",
        "KmU.`",
        "dv/i1[{V",
        "kd,!T#y",
        "6)657",
        "3t$83t$(",
        ",:6V0",
        "VWpPc_z",
        "tJh T",
        "<BDAVRegProtectionON>",
        "QGiDXY",
        "Could multiplex, but not asked to!",
        "O*xxbW",
        "18*b_",
        "a s4B",
        "Ko-h,:",
        "Su'NR",
        "wyER$",
        "^&]>6",
        "+o/3DOD",
        " Jea-",
        "1$tP<.1",
        " \\M<G",
        "A>VX\\",
        "jq2b-",
        "SETBE",
        "mOYC1",
        "6@QZ3hI",
        "h%:n*_\\",
        "'Nr.8",
        "QO\\iysey",
        "3C]q:",
        "JyPH2Ps",
        "y2jxn",
        "CUEBbc",
        ",\"+Vf",
        "?{bP(",
        "cS@[n",
        "n!WXP",
        "4se`K",
        "IP:IL",
        ";kOY*",
        "AsW>+B",
        "^{Z!n",
        "HV\\^n&",
        "^X7j{E",
        "c[G(gL]h",
        "Command string must begin with quoted application name.",
        "1X1w1",
        "KEE_iZ",
        "sXz[H",
        "V6GIL",
        " dhY!",
        "_(rq}",
        "U(4N'",
        "f_c/.",
        " TqJ7H=",
        "0YO)*;",
        "0QNA*",
        "Tg`N8",
        "8$9L9~9",
        "?dBvW",
        "xK;5X",
        "9C;tu",
        "Y=p-MPem",
        "7,747@7`7l7",
        "DQ*LM",
        "sha512WithRSAEncryption",
        "2`qh!",
        "=+=5=",
        "EIp8s",
        "%I9kh",
        "failed to write action indicator custom action data",
        "Sz!{u^z",
        "x-eoS&",
        "96<c>",
        "j?fs:",
        ";t$,t(V",
        "enterprises",
        "g8e4lu",
        "60E0d0",
        "]09>X&%",
        "_savefile",
        "UPDATEURL.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "oeiql",
        "?/?<?L?v?",
        "4C5H5S5>7",
        "\\6`6d6h6l6",
        ">B>a>g>u>",
        "5ZDV$Q",
        "~'gG8 ",
        "O`}HF",
        "989>9K9R9a9m9",
        "7'767a7h7",
        ")e/VK",
        "o+9Fy",
        "rNOzE's",
        ";b}d'",
        "5?1y~qMSM",
        "dsaEncryption-old",
        "Bh'g$",
        "?!?4?>?s?{?",
        "\\AM2Signatures.exe",
        "OCSP_RESPONSE",
        "o'ogo",
        "UpdateEnvironmentVars: UpdateEnvironmentVars End",
        "86.20",
        "\"]Kdfa",
        "???v?}?",
        "/$=Zrk",
        "}}s@t",
        "<tX5U",
        "Vk<1Mb",
        "SSLv2",
        "IB9_QL",
        "#4|Ck.",
        "Hb}rz",
        "IAz(S",
        ",`s3&",
        "%WXLTE",
        "Oe73o{ ",
        "(4Y)TAY",
        "MXd~~RZ",
        "es-py",
        "uI]A8",
        "Failed to connect to %s port %ld: %s",
        "SEC_E_SECURITY_QOS_FAILED",
        "_)_U_",
        "}:!Du",
        "4D4N4Y4c4v4",
        "pZbE(I",
        "=fRS?r5",
        "[O1X<",
        "0A1T2",
        "Cnl99d",
        "'%=CT",
        "u!j0^f;",
        "00L1^1",
        "9{uTf",
        "? ?+?",
        "6|K.4&ut@AELW",
        ")m.XT.",
        "B_y4y",
        " D6>4",
        "CertIsStrongHashToSign function not found in Crypt32.dll. SHA2 signature is not supported",
        "bEE+w",
        "`vbtable'",
        "p;ii3W",
        "NSN|ET^",
        ">WqK}?V",
        "I[lcg|",
        "U@t T",
        "\\F{~t",
        "<Ya< ",
        "2222r2",
        "<unknown>",
        ":#;3;T;",
        "u G;>|",
        "4,444<4D4L4T4\\4d4l4t4|4",
        "a1a82fe353bd90a865aad41ed0b5b8f9d6fd010000ffff0300504b0304140006000800000021006b799616830000008a0000001c0000007468656d652f746865",
        "7[YQw9",
        "Scheduling firewall exception (%ls)",
        "Smi*m",
        "0@0N0c0l0~0",
        "RWR?[",
        "IlJ(*",
        "tQ_^][Y",
        "RC2(40)",
        "&>V9<",
        "HHhmH",
        "%#,X~",
        "jBjxj",
        ".\\crypto\\asn1\\asn_mime.c",
        "pqRN ",
        "y7MN^n",
        "*~gVQ",
        "d.rfc822Name",
        "cY7fst",
        "            <itementry",
        "i72nQ",
        "P\\T9y",
        "$i1pl",
        "7)>0'",
        "`[4W^",
        "q^ dh",
        ">?V-eY",
        "zo{$T",
        "4:d2b",
        "~@NSv=",
        "Y8=(e",
        "k$5|;",
        "7)7/757;7A7G7N7U7\\7c7j7q7x7",
        "040P0l0",
        "r\\]r_`Q",
        "mDXD[A",
        "gUDnm'C-",
        "NbP<f",
        "~y74M",
        ">N>i>",
        "212D2X2c2v2",
        "W4qnC~tP",
        "n,pIN",
        "FWge5",
        "o@gQ-",
        "unable to find mem bio",
        "iP@mE",
        " XoWJ",
        "5E6m6",
        "m$?_\\8",
        "PiReg",
        "?]4e!",
        "~*KV%ul",
        "gq/2_",
        "ContextStackSize",
        "8bym'7",
        "RbD{G",
        "?z+S&",
        "GN;|$",
        "api-ms-win-crt-runtime-l1-1-0.dll",
        "9\\$ ~D",
        "\\lsdunhideused1 \\lsdlocked0 List Bullet 2;\\lsdunhideused1 \\lsdlocked0 List Bullet 3;\\lsdunhideused1 \\lsdlocked0 List Bullet 4;\\lsdunhideused1 \\lsdlocked0 List Bullet 5;\\lsdunhideused1 \\lsdlocked0 List Number 2;\\lsdunhideused1 \\lsdlocked0 List Number 3;",
        "<&=T=",
        "/hatSa!QRsoC",
        ").Yr.",
        "wuAm!&",
        "Local Interface %s is ip %s using address family %i",
        "EHK/\\",
        "algorithm",
        "wt6K5",
        "#DmN~",
        ";~v=3ZA",
        "iIlkX",
        "/r>=h",
        "L&3n,D",
        "*BJ:M",
        "HU|OoWW",
        "jLYf;",
        "4;t_aB",
        "`Om8y",
        "Xu*f;",
        "}IW_S",
        "q-P6!",
        "FreeEnvironmentStringsW",
        ",m4@B",
        "8)<zY ",
        "upgrade",
        "BC (default)",
        "L$X^[3",
        "he^OL",
        "nN2&F",
        "t,F@W",
        "v&%i}",
        "D$HPh ",
        "sd)DyJc",
        "t_Vh$",
        "MWgZU",
        "CSeq cannot be set as a custom header.",
        "?ke$n",
        "EX\\\"r",
        "=W5DR",
        "=p^${",
        "o;ASe5",
        "e'0Fv",
        " ^][Y",
        "uVhx*",
        "5WQ+0",
        "2'3O334W4",
        "4+5N5q5",
        "9Qo|x",
        "86P89",
        "P&^R2",
        ",cf'!S;&+6",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\ProcessMonitor\\1.0",
        "\"@k5z-[",
        "4mX$Vz",
        "CbbR,",
        ".6\"lU",
        "(~es\\v^",
        "Wait timeout",
        "KYjDb",
        "api-ms-win-core-localization-l1-2-1",
        "urP#D",
        "{=P9)",
        "!w~qU",
        "Vq[s!L",
        "!GpmP",
        ")k>%0",
        "aK!`Wb",
        "^:2j[",
        "CLI_help.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "RS7D6|S",
        "Wh[Ev",
        "2%JfI",
        "?(E8B",
        "OKy~y<",
        "_c_exit",
        "?DOg\\",
        "CLBiN",
        "QngPgl",
        "}D\"pN",
        "[lJ,9",
        "des-ede3",
        "0;1r1",
        "d,b@;",
        "8df)p",
        ")*hJx",
        "{^xG*3y",
        "384S4v4",
        "]!]%])]-]",
        "P#I`h",
        "v)FGM",
        "XC=>o",
        "[ [![\"m",
        "Xju{k",
        "Bh;+j",
        "6H6c6",
        "i@Ixv",
        "gyR\\O",
        "<0|O<9",
        "UL1i>",
        "?aX~\\",
        "Netscape Comment",
        "#go+cC]V",
        "M8% 2",
        ">}u:_",
        "receipt decode error",
        "ar!yw+",
        "@kH1b",
        "Vchn~",
        "bY!V}",
        "6D6Z6m6",
        "DS_UninstallFACDriver",
        "vcQHX",
        "~]jxh",
        "PKCS7_dataDecode",
        "HYd+5",
        "@>eBo",
        "YR1ah",
        "AV/-iI",
        ";RORH",
        "ir!~aHG)Z",
        "bEt27",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Government Regulations. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 You agree tha",
        ".?AV?$basic_oaltstringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@io@boost@@",
        "NVaD\"",
        "MQn(N l",
        "'JKYb",
        ";} s(V",
        "b)+]H",
        "ewv{]",
        "8)*yb",
        "Prerequisites installation Error: %d, %d",
        ";\";k<r<",
        "kA]@/s",
        "Ky)w \\",
        "[VSUninstallProduct] cannot force shutting vsmon down",
        "8 8q8",
        "jE@_+",
        ":Q-1[z",
        "*:j8{",
        ":):I:V:j:o:",
        ":(;c;",
        "DES-EDE3-CFB8",
        "1L8T8",
        "ImFkE",
        "-G(xPp",
        "s@PD),",
        "@UixJEdb",
        "VCLUD",
        "3+Z%-",
        "0Qt;s",
        "T>+91",
        "5d.HZ",
        "< ='=0=9=",
        "=&=:=O=j=v=",
        "D$0VW",
        "1,101H1X1\\1p1t1x1",
        "vcruntime140d.cpp",
        "Done waiting for EFR Service to stop",
        "|}Dn(",
        "$S6#;l",
        "{NK'*i",
        "XRfpu",
        "5w^NUz",
        "J~.~2Se",
        "^]_[3",
        ".?AV?$collate@_W@std@@",
        "8!gAm",
        ":6:~:}?",
        "(j(_-",
        "2 2,2L2X2x2",
        "P|(>4",
        "/`\\jS*0",
        "rr`rg",
        "{wGDi:\"",
        "#F2d\\F",
        "5PuQ,",
        "V2I_POLICY_CONSTRAINTS",
        "ComponentsBackup",
        "*M:\\r|",
        "DipP'",
        "xYb03",
        "YR v'",
        "606<6\\6h6",
        "j(|E1",
        ";-_To2)(",
        " smime-type=%s;",
        "L)hSh",
        "I 'a:",
        "*[$*u",
        "O:{i[",
        "failed to query value (%d)",
        "K-283",
        "]z^z1",
        "Ova'h))",
        "+O{0q",
        "ct0)>",
        "\\J5zp",
        "VZrZ(",
        "9W\\Lo|-5a6`x",
        "F:?\"~",
        "(Pt6)",
        "LfIg_",
        "DEFAULT",
        "XQO#y",
        "r$^Gmg",
        "]txS<[d",
        "k]m\"$",
        "AZ#Lj^Y ",
        "P1d/E",
        "}m,h'*9",
        "]nbgI-",
        "keyDerivationAlgorithm",
        "]9F^s",
        "'!vG0",
        "\"6\\.6y",
        "yia]Ni",
        "a&Zb@+U?",
        "xfG*,",
        "7:\\Te",
        "IsWindowsServer returned (%d)",
        "h|1y,t",
        "9~4~r",
        " 0x4f",
        "~gP2a",
        "DKE+JK",
        "3e/dG",
        "QN:2K",
        "unProtectME;",
        "EPS64_DRIVE.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "=!>D>o>",
        "V2.O}6",
        "I$(#e3Qm",
        "#k8~<",
        "*w{7KL",
        ".?AUIAtlMemMgr@ATL@@",
        "?PWh$",
        "0(0A0Z0s0",
        "IcMhp!gr",
        "[LICENSING] old license - check for refresh",
        "Ye=rV",
        "Tupa4",
        "p+>Mo,<",
        "l<n6#",
        "}Kr\\n",
        "value.x509crl",
        "'|ZPyutZ:",
        "V.^eg",
        "2fo)&:,",
        "9>9E9N9W9",
        "america",
        "{+'tz",
        ".$(^.",
        "$&#~Mn",
        "}[rHEi",
        "LCMapStringEx",
        "\\k`[p",
        "jOC+n`",
        "JXX32",
        "hk2xn",
        "!gC\\S",
        "\\$$PU",
        "PFI&vE",
        "%?p#T)",
        "$FB6xC",
        "141@1`1l1",
        "PackageName",
        "BAi:IL`",
        "\\S4~:",
        "il`r+p",
        "[kzI`",
        "b>k4K",
        "6(7s;O>]>k>y>",
        "7\"8w8",
        "{l/1)",
        "checking FileName=%s",
        "D2I_ASN1_INTEGER",
        "]ti\\ME",
        "t/9G\"",
        "}n5R ",
        "uahlcG",
        "punct",
        "=-=J=",
        "=TG=h",
        "=0;09",
        "HR@5b",
        "cef+6",
        ")6(x-",
        "MGorx5",
        "0,3I3",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\UIFramework\\2.0",
        "(E4gPw",
        "8n9W:",
        "2.3g3",
        "Az'HA",
        "xq:Zu.^",
        "*ZH-J",
        "ShB@L",
        "Rfc8*",
        ",JE$:r",
        "Sfe#k",
        "MsiDirectory %s = %s ",
        "]B9mb}",
        "ENABLED",
        "<5?|}m",
        "dz`{V=",
        "neu?)]",
        "#/0=w",
        "9aiHH",
        "&#@6,",
        "Z)%H4",
        "SSL_SESSION_new",
        " 4Bp(-",
        ",VE@>",
        "]Wj4s",
        "SRDIR",
        "K*924R",
        "?.P!q",
        "?-#NK",
        "$9BIJzo",
        "d/fSF)",
        "1De4&",
        "hVs!F:Bk9S",
        "jH2V\\",
        "zd?%!",
        "4O4j4",
        ">Z/C.pt",
        "cs(cF7",
        "lEwJ'",
        "h*ghr",
        "Ssj6:",
        "6B6H6N6T6Z6`6g6n6u6|6",
        "Resuming I/O",
        "z eGP s",
        "zh-CHT",
        ",gX.Q",
        "8!9l9",
        "373J3",
        "s?O^T",
        "XJ1fsJ",
        "6-6/7J7e7",
        "2<2{2",
        "8(80848@8H8L8X8`8d8p8x8|8",
        "5>r+Kr",
        "iZZ[(",
        "3 4o5",
        "?/=)7",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 icense shall be in effect for a limited period as determined by Check Point and certain other restrictions may",
        ";$;-;h;",
        "7JautL",
        "PhP;!",
        "{s{v=",
        "H<O+W;tJ!",
        ")YpCy)",
        "~x).~",
        "invalid digest type",
        "e!>*YI",
        "\\zonelabs\\vsavpro.dll",
        "M_C/|",
        "WjxhX=%",
        "KB3033929 is not installed",
        "kicn>G",
        "N?l@Mafj",
        "zed repair, installation or opening or other causes beyond Check Point's control, (4) unreasonable refusal to agree with engineering change notice programs, (5) negligence by any person other than Check Point or Check Point's authorized agents, (6) misuse",
        "EIA;x!",
        "X[6%Y",
        "$uTI  5",
        "ls+34",
        "vLxCe|",
        "9W#]O",
        "+q#xHL@",
        "ERa9b",
        ".PidATVht&",
        "all_proxy",
        "Ty1=g",
        "hPgY~",
        "D>RVh\"|",
        "uXpZ=4h",
        "gYD>9K",
        "`z[e+",
        "vw<`%",
        "{r@8\"Cr",
        "E;$v&",
        "5?`NR",
        "_-(9p",
        "7M{a}",
        "@FTwR",
        "%sAuthorization: NTLM %s",
        "9#:*:",
        "potRo*",
        "{^fQ=",
        "(@$J}",
        "xx]$.",
        ".\\crypto\\bn\\bn_rand.c",
        "W*i<m",
        "EY7F\\v'",
        "#5*/Q",
        "%*sTimestamp : ",
        "/2g?V{Y]",
        "~(1E3",
        "Product mode is ",
        "TnEZM>",
        "09 44#`(",
        "/s;>m",
        "h][.|",
        "3Nfa=",
        "tftp_rx: internal error",
        "l@Xp/",
        "gc&&8",
        "1uzH\"q9",
        "AqkOh",
        ")UGJ*w",
        "0Uq,LJR",
        "t[>0\\ej",
        "?fc$F",
        "(C?hAf",
        "PFPNACC",
        "=1+U/",
        ":;7>B{]7.",
        "jAjgj*",
        ";B<J<+=K=U=",
        "DH/DSS",
        "121N1j1",
        "Y?'O75",
        "ko-KR",
        "[m3uL",
        "@j'?.",
        "^R2ov",
        "Eo'B%",
        "(jxVR",
        "XhRgN8",
        "]LG&p",
        "?P?^?l?q?}?",
        "ndMnUCP",
        "KJa\";",
        "        <requestedExecutionLevel level='asInvoker' uiAccess='false' />",
        "3G0%d;O",
        ")iDDu4",
        "+z/4#",
        "^YG]>",
        ">t3wZ",
        "[ApTL",
        "c%b(_3",
        "VEQ~f",
        "PKEY_EC_PARAMGEN",
        "6A6~6",
        "U&:Lv",
        "^mgyy$sUx",
        "pPny(+",
        "@\"X;w",
        "X1iK\\0",
        "RfkPa",
        "v\\3r9[l",
        "9(jop",
        "Ub7vt",
        "ZFcI~W",
        "double",
        "ti5UBUm",
        "M=UTR8Ot",
        "Netscape Server Gated Crypto",
        "5!565|5",
        "RSDSJ",
        "9+t@f",
        "jCjzj%",
        "4>]7:",
        "bgAv&",
        "-M1}v",
        "8- ?*q",
        "7\"Gg\"s",
        "s\\\"KF",
        "4$4(484<4@4H4`4p4t4|4",
        "Construct a Helper object",
        "D$L_^]3",
        "fVtI<",
        "0}:}Z\"",
        "XkF(=",
        "EvtClose",
        ";osuu",
        ";ji:Il",
        "inc9U",
        "6v>gh^",
        "sX/_Q",
        "B|#;!",
        "SetEndOfFile",
        "1-242",
        "r(ZY~",
        "PhR`Cm",
        "A2BJ_SM",
        "ULjQD",
        "3d4k4",
        "0v:z:~:",
        "SwiRX",
        "StopTEService started",
        "eVF-j",
        "36lIs",
        "z)LO<^",
        "hlKSG`",
        "connection reset",
        "+`;,0d",
        "3Y;B2",
        "RVDdrxQ",
        "_&Mdz",
        ",yFKp",
        "x}Wsv",
        "%&jve",
        "_netrc",
        "`Ot0$",
        "nDd2Z",
        "1qMXf",
        "\"M=4'",
        "u~Dx>",
        "dth_n",
        "Tkl}r7",
        "uK;G,R",
        "pS|gH",
        "^r{)2",
        "\"0U0r0",
        "t$8SS",
        "bad packet length",
        "|Zpcet<",
        "5r \"h{",
        "\\j5#R3",
        ":$:/:J:s:",
        "ONiiD`+",
        "Ne7A:",
        "%N\\J8;",
        "Qp8!G",
        "3*4q4",
        "Wy8P_",
        "7iXlC",
        "\\n.v/",
        "epab_svc.exe",
        "qK8!6\\(",
        "XM#bj",
        "ChfM(7",
        "s#05VY",
        "\\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext26 \\styrsid14842029 Normal (Web);}{\\*\\cs27 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\ul\\cf12 \\sbasedon10 \\styrsid395593 FollowedHyperlink;}{",
        "t$0hT",
        "waiting for vsmon to shutdown.",
        ";W<j<",
        "rK.5Y",
        "@*Gp{",
        "%o9dr",
        "1(2;2^2",
        ";5;O;",
        "q6sx\"=`",
        "{u/1;",
        "m91[E",
        "JG)>e",
        "3X^ao",
        "RwSBH",
        "xg8ik",
        "xzdD]",
        "}t ; ",
        "nUPl*",
        "Y/0|\\",
        ";SWfZ",
        "failed to get xml file for XmlConfig: %ls",
        "JxDh#",
        "s(}v3",
        "NF)4+",
        "EC_POINT_make_affine",
        "?m,mI",
        "pKcT%",
        "5'}vk",
        "failed to get component name for XmlConfig: %ls",
        "mantispam.exe",
        "pYvh]",
        "/bz}/",
        "{)&a0",
        "^OguI",
        "*i*>7",
        "2 2C2",
        "o.F`o",
        "Te*n{",
        "\\maV\\",
        "W\\f|0G",
        "18'Zn",
        "4<4_4",
        ")5Ok)",
        "0F4X4",
        "& .uz",
        ":v3\"%",
        "d^EGzI",
        "smEK9",
        "moeoX",
        "vM$4)k",
        "wtP)-",
        "n!,Ia",
        "0k173=3K3Q3W3e3t3",
        "_S lKS",
        "vgMR4",
        "Y;hOY>S",
        "+x&G,",
        "$ aQJ<fN",
        "F.^][",
        ":';v;",
        "LC_COLLATE",
        "!fuf?i",
        "J|vfT-",
        "[F ]Z",
        "~!WSU",
        "Y\\??G]C|/(",
        "O<goC!",
        "ecgroup too large for cipher",
        ",Z6/6",
        "Oo=qT",
        "EVUuuK",
        "]Ut4d\\t",
        "SRP-AES-256-CBC-SHA",
        "the process id of TrGui.exe is %d",
        "869Z9",
        "2&pON",
        "_d&YX",
        "groups",
        ")od[\\",
        ")\\V*>D",
        "r)W&G",
        "-h63@",
        "HmqbAQ",
        "<{#FX",
        "MS}*4U",
        "n33?f",
        "?j|mp",
        "D~bLv\\",
        "keM\\T",
        "6UxR2C",
        "j\"^f91j\\^u8",
        "=M_SKDYI",
        "Pj Vj Vh",
        ":R:\\:",
        "Kerberos",
        "/X#uy",
        "dh]#n",
        "`mS%1",
        "6ij6i",
        "pg9G eA",
        "&!iNsYX",
        "4\"434>4R4c4n4",
        "IPClL-",
        "Ylhqk",
        "sJKyB",
        "6&7`7",
        "LnpgO",
        "ASN1_D2I_READ_BIO",
        "6>1E#F",
        "+'.J,<",
        "l$$@P",
        "858:8n8",
        "iRgvy",
        "EBJJI",
        "ZAMailSafe",
        "; ;,;<;L;P;`;d;p;",
        "Home Basic",
        "acgii",
        "FHj P",
        "fiDm7U-r",
        "J[^5H5",
        "S/MIME signing",
        "Wcm?5=",
        "H5b+JH)",
        "M/Kgx",
        "8/979",
        "c7aoc",
        "L+XJE",
        "f8O\"'",
        "D$$SUVW",
        "u#R<=",
        "&$(QhG",
        "+N7IacH",
        "rEk~MG",
        "*8Iio",
        "+Yx.u",
        "0$0*00060<0B0H0N0T0Z0`0f0l0r0x0~0",
        "2A2K2Y2k2",
        "3S+=g",
        "7:den\\",
        "2%2b2",
        ",-A' ",
        "*abwD`i",
        "DEFUQ",
        "Cq?a%U",
        "k4ZEH",
        "ypY8Ui",
        "XEnW\\I",
        "z6^K4",
        "StopABService finished.",
        "Configuring Firewall settings (5 of 6 tasks done)",
        "PSF$J",
        "F\\@uF!F",
        "5K6Q6W6]6",
        "h@uG<",
        "QK$+Ty",
        "\\=},xZ",
        "jWG7xE|",
        "xO%%R+",
        "B'D7{",
        "D#(Eq",
        ".-}ew",
        ";zvvN",
        "#'}Gp)>",
        "JHlz;,H-",
        "Ttd[jI",
        "7f8v8",
        "1{2)3",
        "Dq=lA~8",
        "]$g\\cZ",
        "c&xay",
        "]CFu{",
        "HJ&#U3",
        "(YXP9",
        "<%d %s %2d:%02d:%02d.%03u> ",
        "AsnD:",
        "HwwJ&",
        "`xY9&o",
        "WeSaH",
        "Wm-+n",
        "name.relativename",
        "tO&/L",
        "ssl3_get_certificate_request",
        "SWf9M",
        "!:mhqasE",
        "DuplicateFile",
        "%o|qC",
        "r:Ve;",
        "oY{q4",
        "7!8(8/868P8_8i8v8",
        "3KH:KcH",
        "(qr_`",
        "-p66E",
        "jfjvj",
        "FOQDh8",
        "4rN+=",
        "g_Ed#",
        "V8k`&E}-",
        "<lV/CI",
        "=2>[>n>",
        "ssl3_send_client_certificate",
        "[EXCEPTION] SEH exception caught in UniversalThreadStart. Dumping as 2nd chance and terminating the process. The dump's .ecxr stack trace is valid but C++ objects have been unwound.",
        "%h%:%B%H%N%X%b%h%l",
        "expected 'false'",
        "TS_ACCURACY_set_millis",
        "McAfee Personal Firewall Plus 7.0 2006 (All SKUs)",
        "d%M1l",
        "YCRO?",
        " i02\"",
        "zXWgW",
        "~v?@R",
        "1H1}1",
        "04%]i",
        "OC?TW",
        "$RBf_f",
        "}Aj!.",
        "Hash Algorithm: ",
        "#'Cej",
        "Z3e4mm",
        "v[F\"+$+",
        "LIV;~",
        "5E+>V",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477  Point will provide expedited replacement }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7438025\\charrsid15169477 of a new unit }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "CVW-p",
        "@GBGFGHGJGLGPGXGZG\\GfGhG",
        "eH4-u",
        ">P>g?",
        "CryptGenKey",
        "[VSINIT] %s: Wow64RevertWow64FsRedirection failed with error %#x",
        "0!0&0P0V0\\0m0",
        "W4+-A",
        "SSL_CTX_set_purpose",
        "NQ@\\=",
        "aoNhK",
        "ws:Ds",
        "a \"et",
        "<$=i=",
        "3=K/y",
        "\\LX6o-",
        "/2/B/N/T.eY",
        "7!8-8A8M8Y8y8",
        "3,3<3@3P3T3d3h3x3|3",
        "\",g]hHJY",
        ".tY^ ",
        "ewB<S",
        "error converting zone",
        "8 8(8,888@8D8P8X8\\8h8p8t8",
        "LS {De",
        ":A;d;",
        "':wr:_",
        "PSj W",
        "7&7B7R7g7n7x7",
        "T8w-~|",
        "8eEg1H &",
        "/P2\\]w",
        "c-14z",
        "*mE1_T",
        "]Bc$nL\"",
        "#6&Ll",
        "Js$5*",
        "L6vOLh;4Um",
        "!jI$_ ",
        ")[Bm5b\".",
        "?u=|,",
        ">SX;|",
        "aqiO0",
        "qhXr1",
        "AaErE/To",
        "F,N [-",
        "\"}*CW",
        "l,*VZ",
        "x[~{D",
        "notAfter",
        "3L$,3L$",
        "CCCCCCCCCCCCCCC",
        "~y<l#",
        "%NY}y",
        "RCJJzD",
        "jxjhj ",
        "issuerKeyHash",
        "CO*BX",
        "Yw8 P'Q",
        "hilBo",
        "949@9D9H9L9P9T9X9",
        "T$ ;T$",
        ">!:4@",
        "627953556C12874409D6C8324F56B380",
        "W5T'o",
        "}cmMeE",
        "um`+X|}",
        "^dn@R",
        "Q}c=\"",
        "DuplicateToken",
        "id-pkix-mod",
        "05BGy",
        "rbrcrdrerfrg",
        "UaTIhy",
        ":_k{g",
        "-Yc.0",
        "wor_jd",
        "Accept-ranges: bytes",
        "D$ ;D$",
        ":C;M;b;l;",
        "GRIL/",
        "d######'#",
        "#H@FKQ",
        "/]M!&",
        "bJ$E.",
        "-Lb)j",
        "(T#F*",
        "      </requestedPrivileges>",
        "HtzGo",
        "?o<;V",
        "pv_y8|Vy8:",
        "Q;6-\"",
        "1,181X1d1",
        "g48/9",
        "iZc6}3",
        "1+1E1g1",
        "D$0SP",
        "_cr3a",
        "qh8[OvM",
        "L$ u'",
        "6}7V8",
        "X509_CRL_INFO",
        ".o%7|5",
        "JmlrA",
        "%NmYB",
        "nsCertType",
        "o'!;vL",
        "nKxZY",
        "%+t^Y",
        "0jrhs",
        "UC@zAq",
        "YKh*6FR",
        "SSL_use_RSAPrivateKey",
        "656]6",
        "V)XQh",
        "ZR*FB(`8*",
        "~g9on",
        "c'JC ",
        "|X(Md",
        "NYfFw%U",
        "2(242<2E2a2u2",
        "8}/?f",
        "9;9K9",
        "^ews5",
        "j`c7n",
        "Software\\Zone Labs\\ZoneAlarm\\Registration\\",
        "WGM}h",
        ")KRC:&",
        "6#-1n3&Q",
        "N+AZ!#",
        "J\"YL\"",
        "\\`8w0",
        "RC2-40-CBC",
        "q>^F10V",
        "%# 58&",
        "j/vo>",
        ".X)EI",
        ".\\crypto\\bio\\bio_lib.c",
        "Y`y<CyP'",
        "nUGQe",
        "UZ*E ",
        "<-MYa",
        "Xni9VI",
        "e?_r=D5",
        ">f-V|",
        "_-x=Q",
        "0m\"9r^_E",
        "*#hHcfUR",
        "Unsupported table %s",
        "@y1&RDF",
        "VLQqv",
        "z0zP}p=h?H",
        "`M`=`(",
        "t#9^$}",
        "V]DT]F",
        "+ephr",
        "7,787X7`7l7",
        "'2Dndi&",
        "bOm/Lm",
        "VWh k#",
        "8(9<9[9b9p9t9",
        "k19-7",
        "[\\XT=ez",
        "y.m>Wl",
        "WF1C6",
        ")DZT:w",
        "fT[<7",
        "X2Xd)",
        "Jq'n?j./N",
        "Yw/I(w",
        "&wW,N<H",
        "C!'#KB",
        "V[i$T1",
        "s$_^[",
        "S>@MR",
        "5<4\"z",
        "%*sRelative Name:",
        "]B%C%",
        "9p u\"",
        ".''Dv",
        "f>Nl}*",
        ":)X)1",
        "CcQ$$",
        "https://sectigo.com/CPS0",
        "QL^8P",
        "ssl->sid_ctx_length <= sizeof(ssl->sid_ctx)",
        "~|Mn@",
        "*%!'_",
        "PEXTRW",
        "zQ?[*C",
        "iPGQ1Cf[",
        "-jd_;",
        "HMWHL",
        ";0H0j0",
        "70787@7P7\\7d7|7",
        "L7L8L9L:L;L=L>LALBLC",
        "252O2i2",
        "`3h3l3p3t3x3|3",
        "WzUWqd",
        "h<)`u0=",
        "R||@\\07l&",
        "i$J9%J yO",
        "IncreaseFiltersMaxNum started",
        "t_uG$",
        "h4aO!",
        "tr@#Q4-",
        "xz>BA",
        "s(Fdi",
        "~:yjF",
        "8r^(>",
        "i&+J:",
        "Ex kq",
        ")EU`Y",
        "3T5X5h5l5x5",
        "E#x.>",
        "PCNd~",
        "=1(x9",
        "5/6@6",
        "kN-<.WS!",
        "DBv8UF",
        "@\\mWm",
        "<A<M<w<",
        "!Rqyo",
        "*4z[X",
        "GraXr",
        "6%6@6G6L6P6T6u6",
        "k.t!^pv",
        "hmacWithSHA384",
        "_7)=;",
        "IPSec/IKE/Oakley curve #3 over a 155 bit binary field.",
        "pfpDT3D",
        "Inappropriate I/O control operation",
        "]+B?G",
        "`)AHW",
        "M/y/HV",
        "ssl_add_clienthello_renegotiate_ext",
        "7]7j7",
        "#[.+ ",
        "Failed to load the existing window manager APIs.",
        "#~Y`\"uA",
        "{#\"Y.\"d",
        "505F5z5",
        "unknown state",
        "5@6J6T6^6h6",
        "'sSK'",
        "?6\"~ONV",
        "GetProcessWindowStation",
        "o]r_8",
        "[VSINIT] VsWow64EnableWow64FsRedirection: bWow64FsEnableRedirection = %d, dwWow64RedirectionLevel = %d",
        "YO?q7",
        "kN2kM",
        "ap}qd",
        ";';,;2;:;?;E;M;R;X;`;e;k;s;y;",
        "QL]hm",
        "0&010u0",
        "G7OTF",
        "cXd0P0",
        "$0`C(",
        "3.[Rd73",
        "< 19-A",
        "67w+0U",
        "c<eBB",
        "SCOr%F",
        "%t:_c",
        "YnFpW",
        "^ACr~",
        ":@;D;H;L;P;T;X;\\;`;d;h;l;p;t;x;|;",
        "kj-j.?",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Framework",
        "Event/System[EventID=100 and TimeCreated[timediff(@SystemTime) <= 7776000000]]",
        "Xu9lN",
        "(p+ke",
        "e\\?*#",
        "`g^N0;;",
        "iWFru",
        "D$TSUV",
        "[PERFMON] Performance provider load",
        "-D+v-%",
        "-\\AgQSHEM",
        "[INSTALLER] MSICreateXmlForPlugins: Success.",
        "W6/&-",
        "/l~ft",
        "3A3W3x3",
        "+{myj",
        "x'a0+:",
        "S:#w9~\\K",
        "+nbw|",
        "XJ:eb",
        "j\\DJ>",
        "t?hd?M",
        "R[yod",
        "6IiIRHQ",
        "4D4w4",
        "sA|$Y",
        "9qmBR ",
        "8qj6j",
        "\\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid7565078\\charrsid477636 ADDITIONAL}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid7565078\\charrsid15169477  RESPONSIBILITIES}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078 ",
        "Q0A$0{",
        "error in received cipher list",
        "UZNC7",
        "j|?j3",
        "[|Q:!p",
        "BREAKPOINT",
        "LSL{v$",
        "7p5FEd",
        ";D$$r",
        "7HhAh9",
        "wJ5j*",
        "4<M_\"",
        "x(E-i",
        "69UU(\\",
        "* 3c,",
        "8!919A9Q9",
        "UvT5bs",
        "sO3T}",
        "?X@{W;",
        ":#;m;w;};",
        "G)Uu7/,",
        "RpZG]",
        "<|Ypur",
        "MA/iQ.",
        "5MsJE| 0",
        "?6?^?",
        ";F<X<",
        "_configthreadlocale",
        "FeatureSmartDefense INSTALL_SD=YES",
        "}x?\"$fZ",
        "StopNetFltDrv_rollback failed",
        "2{$ZkKqN",
        ":*JgMJ",
        "?V8Wa",
        "*@u[d",
        "Wf!90",
        "5Abb {8",
        "Auw')r",
        "{Ut;/",
        "-udy~",
        ";As'm&",
        "r!m2\"",
        "85?jg",
        "|9YjJ",
        "-[%NY",
        "Pxtxt",
        "7!L;qW",
        "ER8k:J",
        "@SuE&",
        "getaddrinfo",
        "invalid fill",
        "|\\l4y",
        "[VSSHUTDN] LoadVsdataEx() : ERROR getting log directory",
        ";p<o8",
        "nrx`v",
        "cQ>Lx",
        "26*#U-",
        "SF4F{OF",
        "_#N*p",
        "}~[_M",
        ">(?0?8?\\?d?l?|?",
        "rWJoS",
        "<sGCY",
        "Xz3-P",
        "k,7;oa",
        "T8GDIu",
        "CO5t)w",
        "lT|!#",
        "QT^&#",
        "-)ZiU",
        ".1>K#",
        "KF}aC",
        "MN9U,",
        "F7aqy5",
        "&TplY+",
        "e}gi~)",
        "-#<&U",
        "?T`aXwM,!",
        "7no^`",
        "9ktTx",
        "****************************** ComponentsBackup started **********************************",
        "-Y}GnS",
        "3#G[!",
        "uzxT6",
        "H]js7S",
        "_i>guu}~",
        "hQ^k2=",
        "}.Sn+^",
        "{g;\"D",
        "AE,3a 07",
        "Q#82-",
        "bE4E2?e",
        "tH9] uC",
        "k6{D8",
        "setct-AcqCardCodeMsg",
        "gDj=z",
        "Y_x<u",
        "Uvpvqv",
        "<5=a>u>",
        "\\rsid8146636\\rsid8149378\\rsid8153103\\rsid8199788\\rsid8205679\\rsid8328824\\rsid8463807\\rsid8465078\\rsid8486207\\rsid8532521\\rsid8542731\\rsid8547233\\rsid8552351\\rsid8607116\\rsid8657300\\rsid8673032\\rsid8728152\\rsid8732435\\rsid8732807\\rsid8791827\\rsid8812086",
        "0t*JX",
        "&c]o<Z",
        "tkon/V",
        "O$wKz",
        ">Z%yW",
        "9 9@9H9P9X9`9l9",
        "-P1;[",
        "8l~;\\",
        "=>/P~h",
        "4|cx-",
        "Dc\"@w",
        "._{6|",
        "2(2H2h2",
        "uN%+>@<",
        "8*9I9f9",
        "f~#3w",
        "NMMooNOMx",
        "MyPqB",
        "Po.==*/",
        "G>YRt",
        "l{FDfc",
        ">s(0;",
        ">'?\\?",
        "202C2V4v4",
        "END OF RECORD",
        "8048>",
        ":S@mG",
        "ERIk\\",
        "7E7`7",
        "interrupted",
        "3U3=4",
        "u!_^][",
        "TL9_fu",
        "O{zv*dC~",
        "93~F }",
        "y14UJ",
        "`XM]&EN",
        "nK%e&",
        "3>@!9",
        "(-\\-6",
        "y1D:}",
        "|) =}km<",
        "kGd$l",
        "4|{Uw",
        "\\C^&r<",
        "&<cD:",
        "Yj4PC",
        "(AAls",
        "xA}/k",
        "^fnMhg?Y",
        "w <eN",
        "~(1D5",
        "\\E^P&~",
        "?8?<?l?p?",
        "o|2$r4|",
        "~M&r2",
        "CRolloverMgr::TruncateLog():  zero file position",
        "_DRo*",
        "fWJzn",
        "h/a:ur9",
        "dK<$sP",
        " ]fvIE-",
        ":!<P<T<X<\\<`<",
        "0Z(>/+",
        "X.}-k",
        "~r#6B-",
        "-s.r&'",
        "}^Rg~",
        "[~e/_v",
        "qg[J1,",
        "+ZwXa[",
        "8|=g3",
        "2jt0pW[p",
        "u)8\\$$u",
        "9D]rl",
        "@+sJp",
        "uy~kv",
        "liu>3",
        "/p[1cu",
        "S/MIME Capabilities",
        "_zN]YQd",
        "464=4Z4a4|4",
        ":E;K;Q;W;];c;",
        ".\\crypto\\dh\\dh_pmeth.c",
        "2uLgR",
        "-]X\\b",
        "tV!N5.p",
        "jthX=%",
        "!AdMR[",
        ")xW$q",
        "WoIS/'Vf~",
        "KS)7l Q",
        "bn decode error",
        "@)]R}",
        ",,Ffk!",
        "[VSMON_LOAD] StartProtection %08x",
        "Df9K^\"",
        "fLb:;",
        "1yndd",
        ":Oy9hU",
        "Plugin name is too long",
        "s`||:Y",
        "_vH@3",
        "YA{Z1",
        "ssl session id callback failed",
        "!;)\\0",
        "k!;d_/y",
        "5i9z9",
        "uurC=F",
        "oD1ur",
        "CheckRelatedProducts: CheckRelatedProducts End",
        "Q|9iYM\\>",
        "MwmhP<L",
        "XA(]SUC/?",
        "/0C2X2f2",
        "5rUXM7",
        "U\\%!.",
        "ZoWPk",
        "=}A++",
        "Enter ",
        "R{d'_",
        "dJ'Y1",
        ":nt0ti",
        "/\\p]*",
        "5#m&e&",
        ">0a[v",
        "C1A5G",
        "^J(WNS",
        "{z2d8",
        "y>$85",
        "joint-iso-itu-t",
        "expected <",
        ";$<A<q<",
        "PJPz/",
        "3T$X3T$x3T$83|$D",
        "]6|V2",
        "oVJ_K",
        "<Zi}.:",
        "cmd /c \"del /F /Q \"%s\\Temp\\vna_utils.exe\"\"",
        "G&z^S",
        "turn protection off",
        "Create MsiProperty %s",
        "595_5",
        "U0_'r",
        "Q[':o",
        "!)=?C`",
        "WixRollbackFirewallExceptionsInstall",
        "l~k5GU#~",
        "w95d*#",
        ")hIK1",
        "Ib-4l",
        "nUAp?h",
        "[VSUTIL] : MakeVsmonPath:   GetSystemWow64Directory failed with error %d",
        "Fz,Og",
        " G$npX",
        "PFRCPIT2",
        "q>!s/",
        "%C@alV",
        "PwD|\"M|",
        "$*/T(",
        ":=:B:Y:p:z:",
        "t$@h@^\"",
        "NecXPz",
        "JV .Jo",
        "[n,?';",
        "{-cJ(>",
        "cfNO8",
        "?Hgb/N",
        "\" to data failed",
        "nuB/RK",
        "xOU|_!",
        "M\\Avq",
        "L\"\"`N$d",
        "0,0<0@0P0T0X0`0x0",
        "gq7(@",
        "yIr~>",
        "OmKl_",
        "oZ~=?",
        "=>`ka",
        "W8fk5R",
        "R @.+",
        "4 4,4L4T4\\4d4p4",
        "}'8wu",
        "kG1D ",
        "t}hd'",
        "[BHH5",
        "=0=4=d=h=",
        "zpL2'",
        "Ready to accept data connection from server",
        "EYmY#",
        "D[\"1)%",
        "=%=,=;=H=v=",
        "3]\\\"z",
        "&%bTd8",
        "H)p.y",
        "=NYiD",
        ">4?D?",
        "\"(6Ru",
        "31Nf[c",
        ">&?6?]?~?",
        "GOST R 34.11-94 with GOST R 34.10-2001",
        " but no more than}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6240750\\charrsid13256927  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9651500 one hundred and twenty (120}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "4iWm=",
        "isj {g",
        "K%kw^",
        "E]$t6",
        "5#`!x",
        "]-sTkj",
        "2KqOH",
        "{\\f58\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}{\\f59\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}{\\f61\\fbidi \\fswiss\\fcharset238\\fprq2 Arial CE;}{\\f62\\fbidi \\fswiss\\fcharset204\\fprq2 Arial Cyr;}",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566   }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5905555 For }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566\\charrsid1468885 the {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States",
        "E6%mJ",
        "6|@Nf",
        "T$lY|",
        ",4C3Y",
        "<~w_C",
        "*%\\dg",
        "=7sBaT",
        "g6\\t+",
        "q7l[_",
        "tls1_set_server_sigalgs",
        "Features",
        "cBD4!",
        ".#\\oxW",
        "t6N%1",
        "-_HP3L;",
        "oO6.z",
        "jps-{",
        ":3A*|",
        "1+10171@1E1q1",
        "E=.yV",
        "FORMAT",
        "xGYF#",
        " X{^VW5s",
        "- unable to open console device",
        "BF'/T:",
        "huLVd",
        "dQ|+D!=&",
        ";l[Z+r",
        "RHoDE",
        "X-'hE",
        "productName = %s",
        "=&>^>",
        "ZTwA1H",
        "|01};",
        ")Zn9Fq",
        "bXHVq",
        "<9B/_I ",
        "t.&7O",
        "7?8N8a8g8",
        "u(jrh",
        "\"TT)r",
        "j-#Eg",
        "m8koh",
        "kVJ]k",
        "2SjEc",
        "v#&W*Sy",
        "CWg8U",
        "9l@eS9",
        "CRYPTO_get_new_dynlockid",
        "*u.YSYb",
        "\"lif{Q",
        "8uOuo",
        "dsa_with_SHA224",
        "(#3x+~O",
        "\"7g[>M",
        "3JY,.",
        "5<q7BTc4H\\uU",
        "$E/U<)[",
        "6+6=6G6i6",
        "*Bl)k",
        "+,7P0",
        "3~(XD",
        "could not set time",
        "<8<P<",
        "virtual ",
        "Do!2-",
        ",rCHg",
        "cessationOfOperation",
        "85@5D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        "3s){h",
        "~KUSW",
        "|#p.b",
        " r*|:",
        "5g!iv",
        "\"b|ZcO",
        "*DTYyx",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11555386\\charrsid13701052 ",
        "K,k3A",
        "4QT^a",
        "=0*at",
        "Plugins::Register:  pWseUnregisterPlugin  Error code is ",
        "brainpoolP256r1",
        "8Y8g8",
        "spwjD",
        "v>$AK",
        "k6bLq",
        "4<v`|pTbZ",
        "e#d^o",
        "f{F[+J",
        "wRp,?5",
        " HA}%58",
        "3J[ww3",
        "]i1YO",
        "JP|bj6",
        "Mj'-f",
        "Acr2Xc^",
        "G/hf{",
        "h1(hPd",
        "1;EcF~",
        ";9<n<",
        ">W>i>#?`?z?",
        "w2)r&m",
        "qsb9'",
        "LTS),",
        "[3L2@/~gBA",
        "SVWjA_",
        "=*=O=;>A>F>d>j>o>",
        "dhKvA",
        "'6ogA",
        "VcJ=2",
        "FormatMessageA",
        "^9}D0R",
        "Y1t\"k",
        "CxIx^",
        "8,W>T",
        "succeeded",
        "0ESIem",
        "m:<rq",
        "encryptedContentInfo",
        ".?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@",
        "2&242:2M2]2",
        "Bcnr0S",
        "$:I(~",
        "9%:O:y:",
        "ECDH part of OpenSSL 1.0.1t  3 May 2016",
        "031Q1r1",
        "1+1+3=3q4:8",
        "9&\"<`",
        "REST %d",
        "5}l'W",
        "$u-`/RZ&",
        ".?AV__non_rtti_object@std@@",
        "T9IK[R",
        ".?AVProdConfig@@",
        ",9qdb.",
        "DERi'",
        "\\@cXpu",
        "`ef_sF",
        "PNrF9",
        "(Zp7rL.L",
        "%s:  Begin install of %s version %s from %s to %s.  Existing product = %s.  Existing version = %s.",
        "zlclient.exe",
        "949X9u9",
        "|G__@",
        "\\Um}m",
        "BJpQnz",
        "missing rsa certificate",
        "6AXY,s",
        "D\\(!k",
        "ZLONG",
        ";4;d;",
        "9IeK(W!Q{",
        "H$$lH$$l",
        "c!6:s",
        "sZMW0",
        "KtmE}E",
        "VNA_INSTALL",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{51C8741C-4A91-42A6-B6A2-CB891F7398A1}",
        "WUii2",
        "invalid x931 digest",
        "1cgjsb4c9645cmmh7xixxa0mu400",
        "nC%=J",
        "x|wpRF ",
        "HyAUL",
        "1Ucb=q",
        "U52\"0R",
        " fail to set NO_OFFICE_MODE",
        ".\\crypto\\x509\\x509_trs.c",
        "ASN1_STRING_TABLE_add",
        "9'9D9O9V9t9~9",
        "3b4}4",
        "`.qF!",
        "s<D n",
        "hc$=K",
        "v*m-@",
        "UuBz56",
        "y#CLLL333",
        "dYl;_",
        "Y2<GAh|a",
        "b>pjI",
        "G_[Z=",
        "0$ww,y",
        "SUPPORTDIR",
        "ID19cx",
        "ydxoZiE",
        "y)~N5",
        "0w70/&",
        "t&+l$",
        "*QBIm5",
        "VnE:C?",
        "ntdomain://%s/%s?%s",
        "jR&i?",
        ">PX)s|",
        "KY[vC",
        ".i?-tHbz",
        "\"xNj08",
        "U8v/z",
        "rZTUJJ^dI",
        "` u/Xl",
        "IN8Ua",
        "8'] 2",
        "_E(r=",
        "#+I{~G",
        "5rz(|",
        "H\\EBE-",
        "o7kmc",
        "m{rn/g",
        "`5/Y/",
        ".f_]19V",
        "p_zN4M",
        "D&/tVUk^",
        "[PaH!",
        "01;_hO",
        "id-smime-ct-contentInfo",
        "g[O!_",
        "889P9p9R:",
        "Xf=3l",
        "bG1bt~W",
        "],/ap",
        "JJKjK",
        "Y^Kv\\3",
        "(nZ~'G/c",
        "CxqVB",
        "QK%K5",
        "mJb18,1",
        ")>j97",
        "y~t_[b",
        "9wVY1",
        "m#7UWC",
        " Bl'-",
        "OROC[",
        "91TZ%",
        "#jAK@",
        "#22Gg",
        "7`6t,u<",
        "cpOq6",
        "b^G*WY",
        "%\"e;|",
        "ifw2B",
        "7R5h{",
        "setDriverMode",
        "o$&UG",
        "546O6w6",
        "i\\\"::",
        "AddMitigationOptionsRegValue: value was changed.",
        "6 6$6(8,8084888<8@8D8H8L8P8T8X8\\8`8d8h8l8p8t8x8|8",
        "Mey4=",
        "$6.:$6.:",
        "/e.Y|",
        "OHldLj_",
        "7$717A7",
        "L0286",
        "=|03g",
        "ZBCTru",
        "y#~.9",
        "P.{La",
        "1h$aI",
        "sN\\F7",
        "Q^yaE",
        "securitypolicy/osfirewall/rulegroup[@name=\"protkavfiles\"]",
        "HP4%Xs?F ",
        "Vv\\.gd",
        "8\"9r9",
        "veqSq",
        "StopNetFltDrv_rollback started",
        "331#|V",
        "0v7<^",
        "ProgramFiles(x86)",
        "?2?R?r?",
        "] YwVG",
        "!\"W9G",
        ";5<V<",
        "f9.>;",
        "NISTP521_PRE_COMP_NEW",
        "S^cNc",
        ",{e~i",
        "D`5\"ie",
        "$IX)!",
        ": :(:4:T:`:",
        "VL|KE",
        "W=X=Y=Z=[=\\=]=^=_=`=a=b=c=d=e=f=g=h=i=j=k=l=m=n=o=",
        ".&$G>",
        "D2\\0`t",
        "aZAbyN:J",
        "Heap32Next",
        "?An+k",
        "TqtAu",
        "3u7KA",
        "d>'Ol",
        "BGH+>C",
        "nr)f^",
        "0#0t0",
        "Z1qY^",
        "=(=A=Z=s=",
        "4 4/4>4M4\\4k4",
        "2o^z&",
        " 8FTd",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 d the required hardware to the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13200219 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 \\rquote s physical l}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "#iIjK&",
        "lastUpdate",
        "7!7U7d7",
        "#VTV:",
        "g;io?",
        "<'HGe",
        "Ca_Z,^%",
        "{$V'%6q",
        "6#7m7",
        "QU$ab4",
        "33Roh",
        "*EN*u",
        "3X4gIQ",
        "priv:",
        "b*YaI",
        "6\"6.676<6B6L6V6f6v6",
        "Deleted contents in %s",
        "BFlsAlloc",
        ")Z;J-z",
        "sha384",
        "!Xx'?",
        "rv(&p6r",
        "_YHThD",
        "@;2]-",
        "[O7xo",
        "2=[+:",
        "G'h /~",
        "!4Qr3h;",
        "u98D$",
        "AX~/Z",
        ", are available }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid4602388\\charrsid13256927 for all }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid4602388 Hardware Products }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032 pursuant to a }{\\rtlch\\fcs1 \\af0 ",
        "HN#bq",
        "unknown extension name",
        "w0#ah",
        "_R*ruc3",
        "NkHf)",
        ":2:9:Q:x:",
        "?M0XH",
        "X+!hp",
        ",tf-),",
        "w}>kh",
        "Z1[q[",
        "0kYf=",
        "brDVr",
        "X9%BP",
        "jh KZ",
        "p(2n2x",
        "oUEPH",
        "d$oy2N^#>[",
        "H2,khd",
        "t 4Rx",
        "m8OKr",
        "X?-U\\7",
        "<5<?<v<",
        "\\$(VS",
        "tUQSPj",
        "pqAA-",
        "]5-9-",
        "priv_key",
        ">.>I>i>",
        "[[:xdigit:]]{8}-[[:xdigit:]]{4}-[[:xdigit:]]{4}-[[:xdigit:]]{4}-[[:xdigit:]]{12}",
        "USQDe",
        "vsdatant.sys.cisco",
        "d!m#y",
        "NWarf",
        "ch?A\\G",
        "^ri#ta",
        "RZu~\\",
        "hzgl\"",
        "y9M5b\\",
        "pkcs7-envelopedData",
        ".fK*z",
        "s-\"=@9",
        "yquXG",
        "c}i\"m@",
        "/d\"-7~BR",
        "Failed to add row to remove all files for WixRemoveFolderEx row: %S under path:",
        "M~ODn",
        ";8wb5",
        "Vtcu;",
        "4O5Z5",
        "{Kf?[",
        "O{r >4T",
        "SQBQ|V",
        "$Mqh:wJd",
        "6M0YG",
        "=+1 z",
        "= =(=L=T=d=l=t=|=",
        "Z\\B{(),4",
        "NKGsl",
        ",QWZ4U",
        "!%$0&",
        "6(6H6P6\\6|6",
        "e=]uu",
        "`eS:_7~",
        "no space on device",
        "cp'$J",
        "7\"rB2",
        "RYP3t",
        "p<ptPz",
        "SendInfoMsgToProgressDialog: An invalid or inactive handle was supplied. ",
        "hG4$)(<",
        "%e; T__",
        "]@gEN",
        "J?3L*",
        "*&nNZ",
        "505:5S5",
        "p.pNpuv{p",
        "EKdje",
        "36;<n,O",
        "=&>8>",
        "SEED-ECB",
        "7vuJi",
        "ASIDENTIFIERCHOICE_CANONIZE",
        "je9s9",
        "U*%o/",
        "Udrjz",
        "=e=o=t=",
        "={=v>",
        "bAx1Te",
        "unhandled critical extension",
        "(i1a/",
        "$_2m7",
        "BG PR",
        "%*sSerial Number: ",
        "0\\bO&L",
        "9#wAT",
        "%s:  %s",
        "header.png",
        "dDBU#$",
        "1]>W\\",
        "groupmonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "signed-receipt",
        ":\":&:0:<:F:J:T:`:l:x:",
        "LQWRJ",
        "Jfl9oF",
        "dLK\\b",
        "'C(-Q",
        ",!wMK",
        "xKLI+}",
        "J\"%*%4%z%",
        "191G1",
        "K>iT8*d",
        "jb2l!-(",
        "TGE6x_",
        "!z0@;.",
        "040;0@0E0L0W0l0s0",
        "OyY+lk%",
        "[INSTALLER] %s",
        ";$;,;4;@;d;l;t;|;",
        "62hBGl",
        "0;0V0",
        "%pa?.",
        "9F!&f*",
        "yB|4}",
        "IM`kMk",
        "+A\\+D$",
        "EsdqQi",
        "?l)c;|Q",
        "D>Zh:I",
        "(g\\YCF",
        "XYfxf",
        "HWMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "):k^s",
        "z|9<,",
        ".nReMo",
        "t:Sh\\",
        "_65gsg",
        "rP8)@",
        "Uploaded unaligned file size (%I64d out of %I64d bytes)",
        "0/1a1",
        "1b!a<",
        "Ekrol",
        "n)oVl5~D",
        ">4?P?f?t?",
        "i`IIi",
        ".?.s\"A",
        "dTn#n",
        "9^\\t|",
        "|W8A=",
        "LocalKeySet",
        "jEGoE3)VxN",
        "h>'<d",
        "4V4h4",
        "@X]>m]",
        "p!\"bz",
        "[VSSHUTDN] CallClrDataClient()",
        "\"{Ph$",
        "zHruN",
        "jEV`*",
        "ZdebR\"S",
        "Ln!)m",
        "5 575A5g5",
        "\\k~J[",
        "ENGINE_finish",
        "1V2h2",
        " {AqF",
        "`q%=K^g",
        "P[X<p}",
        "CBCRCxC",
        "Fv'C=",
        "3G1xl",
        "D0H0L0P0T0X0\\0`0",
        "1-1Q1u1",
        ":#;3;;;K;y;",
        "W}Sil",
        "e~C&A6Y) ",
        "l$03,",
        "j /|z",
        ":F;b;",
        "(8 ]F{",
        ") c;M3,",
        "[mP@x",
        "YA/<V",
        "X&l\\&",
        "F0?Ey~",
        ";&<5<M<~<",
        "PUNPCKHQDQ",
        "(rVGZu",
        "*$\\}sDNL",
        "|$1qM",
        "rnvhh",
        "r5Hea",
        "C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/ssl/cert.pem",
        "`nSoz",
        "remove_all",
        "^&a%P ",
        "ldo7(",
        "Seed:",
        "='-[:",
        "error loading section",
        "U%J$L0",
        "_&7Bb",
        "K32EnumProcessModules",
        "W:9Hc5",
        ";$;,;4;<;D;L;T;\\;d;h;p;x;",
        "no key",
        "q5@~G",
        "94y!L",
        "`B{/&",
        ";V{\"[",
        "/bdvJLe",
        "X5ur$:",
        "494m4",
        "B:$W1",
        ".?AVmessage_not_found@Concurrency@@",
        "Lp{Hh",
        "?A8q'f",
        "DISABLE_GATE",
        ")8~3D1",
        "MULSD",
        "2!2;2",
        "KGv'2",
        "u?=d7",
        "v;\"MBD",
        "H(t 9",
        "`YqlE",
        "public: ",
        "5)5.5[5a5f5q5{5",
        "7 7(7@7H7`7h7|7",
        "(A.c]",
        "s->d1->w_msg_hdr.msg_len + ((s->version==DTLS1_BAD_VER)?3:DTLS1_CCS_HEADER_LENGTH) == (unsigned int)s->init_num",
        "<E<w<",
        "2U9+{",
        "pz@t#",
        "R*Fv'",
        "4J|g$>\\0",
        ")}N}fym7-",
        "A\"]D.",
        "K,JJ\\",
        "WWWWWWW",
        "_{uBC",
        "3E3i3",
        "9O|8-",
        "_^[h8",
        "{KhtN",
        "~n}d@",
        "9>x2-",
        "9{W~&",
        "ukOW$X.",
        "$M[dNB",
        "xU/pl/Q @>",
        "CopyPoliciesFromOldDirC.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "StopCipollaService_rollback started",
        "unknown version",
        "555<5@5D5H5L5P5T5X5",
        "Iq!Y1",
        "A\"<+y",
        ")l{V~|",
        ":2bq!",
        "id-qt-unotice",
        "RD)EH",
        "3F3U3c3q3x3)484F4T4[4",
        "iw.X6^3",
        "0$0(0,04080<0D0L0T0\\0d0h0l0p0x0|0",
        "cs-cz",
        "Je!e5",
        "0[0e0",
        "<W=5?Y?w?",
        "CompareFileTime",
        "^OEtw",
        "Failed to set value on key:  ",
        "[$~6/",
        "0\\0u0",
        "uiAi.",
        "+i[9>",
        "}o8s#",
        "4V5e5",
        "'V=F@Zi",
        "Vjbhx",
        ">U?~?",
        "%=|32_",
        "RvZ!T",
        "Ov>.N",
        ")cKA1",
        "bb-qh",
        "CdE\\_",
        "IXPZE",
        "|J.Y#E",
        "by~]L",
        "\\CHECK_POINT_VPN_CLIENT",
        "jhjsj",
        ";?IU\"",
        "Remote error",
        "wo/b~U",
        "bOi<a",
        "VZ9yU(K",
        "%*sCertificate ID:",
        "g&QEw",
        "2!,1?",
        "Cached msi of Discovery VPN (",
        "CleanUIFramework started",
        "d.data",
        "ALLOW_ALERT_MODE",
        ">8>O>s>",
        "_yF+_g",
        "OhLn>",
        "5U7Gt",
        "3uaqs",
        "&x<8G",
        "r0eJUw",
        "?1?@?",
        "HSRl0",
        "-nfYCk",
        ",+-j\\",
        "6 zWQ",
        "@i<!k",
        "x*z5h",
        "BINARY",
        "7$7,787X7d7",
        "9::o;v;",
        "D$$SU",
        "QtExecCmdLine",
        "7K6Lz",
        ">|$RB",
        "B(*!_",
        "VmE'G'",
        "Ms,Yw",
        ".CRT$XTA",
        ",={YD",
        "1mKKR",
        "}zaX*",
        "%c%.e",
        "{:vdr",
        ">0`tj",
        "c8\"Ju",
        "gAq@H",
        "3 3.3",
        "Cannot pause RTP",
        "^W/Y>z",
        "lYK]m/",
        "5mdpy",
        "Ca>MF*d",
        " z6zf'",
        "*gjgTb)",
        "0'0J0m0",
        "953V*",
        "The registration of the zlscv.dll was not successful, reason unknown, possibly failed to create process zlscvins.exe",
        "p|R8R",
        "%>@R;bh=m",
        "TKH9dd",
        "fsX>ubQ63",
        "`.rdata",
        "p@s%\"W",
        "GOST R 34.11-94 with GOST R 34.10-94 Cryptocom",
        "90mY;&",
        "calling QueryDosDevice...",
        "NQH v",
        "tSHT>",
        "@g6qa",
        "3Aiun",
        ">kz-[V\\",
        "aR[nz",
        "%\"{Cl ",
        ";.;=;B;X;g;l;",
        "fa[]k",
        "nsSGC",
        "%.*tpx",
        "d=gK,]y",
        "646<6H6h6p6|6",
        "s7IH+",
        "=L=T>",
        "^t+JG4?",
        "VnaCleanWithDir",
        "b8FY#})7",
        "{{4c7",
        "bP!mW",
        "nJaZI",
        "nd4?;",
        "ak_9/Hnm",
        "PODG)",
        "1ikyg",
        "Ramat-Gan1",
        "^-\\pg,!",
        "CPTray exist in Windows Run key.",
        "szRepositoryDir",
        "xy|\\|f",
        "z\"<u>",
        ":Y ; ",
        ">C?l?",
        "8&v&M.9",
        "?zj\\#",
        "+]`f=",
        "Turn off protection with shutdownVsmon",
        "Ns.y]",
        "KP%=|",
        "[B[+f*",
        "4&48445>5C5c5",
        "@{|j'",
        "/HG8A4",
        "vO:m+",
        "HO:Dk",
        "LK)5'",
        " w?8y",
        "`oiGf",
        "ZXCq&",
        "Failed to get the MsiRestartManagerSessionKey string length.",
        "DlZ=e",
        "h.QH:",
        "v%A\"8",
        "8*I\"^",
        "RMV!V",
        "jXRSh",
        "#N/_X",
        "ckpoldgina is empty",
        "C06FDE9E-2AD5-4DDE-82FC-3AB5CD17934A",
        "9\"9-9P9b9n9",
        "qy&V6",
        "anonymous",
        "PVM9T",
        "5utCy",
        "Y\"5sKJ",
        "3(yp~p4",
        ".|?V}",
        "jAjfj",
        "T$,9t$8t",
        "oWshl",
        "InstHelper is not running, will not be able to stop EFR service (CPEFR)",
        "lh $)V",
        "7#7(7g7",
        "051>1D2L2~2",
        "unexpected record",
        "909@9P9V9a9l9}9",
        ",sxO&",
        "t$ Pj",
        "kSR`Z)",
        "dso not found",
        ">&>`>",
        "9H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        "L=O|`",
        "exiting...",
        ")0'0%",
        "rU$WJ",
        "^foff",
        "@ph|3",
        "|rQ-X",
        "x<x/'2.",
        "z**iW",
        "z,0A}",
        "PH(&i",
        "[Q_|E&_",
        ";l)vx",
        "131a1",
        "RVpn;",
        "}!DRZ}Z|",
        "Hb|Jf",
        "qrRk7`",
        "ZMZ-*",
        "2-3V3`3",
        "H}7[>",
        "*;4C\"",
        "tUW5;V",
        "Msxml2.DOMDocument",
        "4'444",
        "$/$%;z",
        "4(4H4T4",
        "kTDW3",
        "?d?{?",
        "#&I2!",
        ",zkRb",
        "Killing process %s",
        "B%E&H",
        "\\1=N8",
        "RegQueryValueExA",
        "[*8$!",
        " N3`{A",
        "    Data:",
        ": :4:8:<:@:D:H:L:T:l:p:x:|:",
        "w-U<ab",
        "\"LeMC)",
        "+YGf3c",
        "WRJr=",
        "u;z0TVxf",
        "DVQ6I",
        "BHVji",
        "p8m!J1",
        "R89`N8P",
        ";yFY&",
        "6+8bF",
        "/?5@$",
        "36p,u_#",
        "`Y(_#t",
        "(d^^D",
        "='>x>",
        "'j0rS(",
        ":mErO",
        ",O.vk",
        "~WA~2vb",
        "ts:MN",
        "g@RaN",
        "~8{PAa",
        "|dr?_:2",
        "9TMQ;",
        "H/3@*W*{",
        "^@Va{c",
        "^\\,[o",
        "WixExecFirewallExceptionsInstall",
        "U.Bmx",
        "qKx d",
        "C:\\src\\wix38\\build\\ship\\x86\\wixca.pdb",
        "k}J;[}",
        "z*rog",
        "2 3P3",
        "failed to write exception target (application) to custom action data",
        "v(#$8",
        "j-ZCf",
        "0M1^1q1",
        "xnVNz",
        "9D:[:",
        "4u5p6",
        "Ztu^{",
        "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        ",H7xp",
        "Xabaf+",
        "\\@c'Y",
        "6\"666H6",
        " 'y:#",
        "v^1AR",
        "FX?I6",
        "^aMTWf&6",
        "S<Bqv",
        "Xdpyf",
        "<5<@<K<",
        "565O5h5",
        "Qa;y{",
        "k15KNb",
        "[YC4k",
        "ok,>j<",
        "O_oJ&",
        "]AQNt",
        "a?E-b",
        "_#dp6",
        "J0g*&",
        "&*1;x|",
        "bfjMjUj]jelmf~\\",
        "_z,gF",
        "%Ml9h",
        "1%2W2j2w2",
        "rO|Sv",
        "Z;%QH",
        "FLE02a",
        "  </UpdatePackage>",
        "U=L,R{",
        ".?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@",
        "CsA$rH7",
        "1%1I1T1Y1^1y1",
        "o\\!]%c8on",
        "E$i!d",
        "M`FLJ",
        "!J(zW",
        "iXs}wdzz",
        "INT_NEW_EX_DATA",
        "`=TJj<",
        "R]d]Y]k]r]",
        "wZW/gl$1e",
        "7AUqe",
        "8 9+9y9",
        "IG?E?",
        "H_ SN",
        "rYx2{kX",
        ";1;M;i;",
        ".?AVDNameStatusNode@@",
        "VMCALL",
        "dF036",
        "8CDa9",
        "Zoq0h",
        " ^3<?7",
        "I:|K9@~",
        "Could not remove the symlink (CH)",
        "ConvertStringSecurityDescriptorToSecurityDescriptorW",
        "=Wlw|",
        "=HqmD",
        "uHjAXf;",
        "en-BZ",
        "1%1>1W1",
        "0_=^z",
        ">K4{f",
        " 0x14",
        "4bb$'\\",
        "[+vX|",
        "6/6N6i6",
        "5p2&M>",
        "W1FhM",
        "AtNqFK",
        "Qh8(M",
        "ZlP#c",
        "j<Wea",
        ":%&B{OLQh$",
        "v 'W[",
        "n(n(nHTh",
        "Uav8\\",
        "{X;.)",
        "DS_DeleteFromSystem32 started.",
        "6|o6WF",
        "Z[U6J[",
        "u $ieB!",
        "6H75(AR",
        "jNU=,\"N",
        "8)n;)iw",
        "rY4?j",
        "J.%)D",
        "9~P~6",
        "q7M{w",
        "eosEw",
        "sel|&",
        " AdYZ6",
        "6w]Zq",
        "A\"i+p",
        "zE5x23",
        "QhyO$",
        "190502000000Z",
        "151C1u1",
        "%xp+7",
        "2&454S4d4",
        "The user is %sAdministrator",
        "a+vv#",
        "tY,YR",
        "&cLi7",
        "sZKjTnr",
        "n1V>OG+",
        "4Eg>o",
        "e,*O{",
        ",1%cm;",
        "GetSystemMetrics",
        "|Cs0<u",
        "QngA|",
        "3L$83L$,",
        "_O_[/",
        "PJAG+:",
        "SlWrN?",
        "~-?^@u+",
        "rX_5P",
        "t$(hH",
        "Pipe broke: handle %p, url = %s",
        ";~F r",
        "<W=W>W?W@WAWBWCW",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ocation, as }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11798905 it }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 appears in your ",
        "ocW-o",
        "8 808@8P8T8X8p8t8",
        "2 242@2H2`2h2p2x2",
        "M>:Hqv",
        "=6}('",
        "*2fC5",
        "+u{Qs",
        "'WQyY",
        ">M}%=",
        "\\WW9{7%k",
        "'#WL&",
        "d-buB",
        "removing value ",
        "<!=0=C=I=l=",
        "8=i17",
        "RA;8i",
        "X\\REf",
        "L{0P|",
        "1+#JB'",
        "eib>u",
        "%0n} tJ",
        "kkeJ>",
        "*w~f%",
        "QSI]\"",
        "M:'/Q",
        "jojxj%",
        "_`l<Dn",
        "3h2BG",
        "%s exists and will not be replaced.",
        "p3[)z",
        "y^R%H",
        "StopURLFService_rollback finished.",
        "s@(!^",
        "A/RkI",
        "4UH+uB",
        "2)3e3l3",
        "X2qI4",
        "RgZ:,",
        "+#pD*J",
        "aaj_55",
        "RH`C1",
        ">c?j?v?",
        "&qU7 ",
        "=.=J=f=",
        "G]j0u",
        "Mo5kD",
        "\\xMWoSlr4",
        "vzJW7",
        "2B'y-",
        "&K+(SM",
        ".?AVtype_info@@",
        "OD/{D",
        "9Mc)j",
        "Y`L'|",
        "]Z?#q",
        "\"tk%?`",
        "PYd<v",
        "P2zcF",
        "is)j9",
        " 0:0X0v0z1",
        "x7EnG?^",
        "5DJN3t",
        "C11^%",
        "X-y=R:",
        "ogdu0Q",
        "TY#d@",
        "dMISX",
        "internal error",
        "3@</Z@",
        "h1r0xP)",
        "y/+2k4",
        "l@pu}",
        "ZEb5QC=",
        "Reboot required by deferred CustomAction.",
        "XtAt3w",
        "q5.Cr*",
        "O}lFo",
        "Manufacturer",
        "CF2\"Ze2",
        "HlztMD",
        "jurisdictionC",
        "&@T2&",
        "}ah<|S",
        "T=]la",
        "s%&ne]",
        "Th}%u",
        "*XFU0,aKH",
        "Unable to load %s",
        "363R3n3",
        ";'hQPc",
        "<i:+|",
        ">/>K>g>",
        "QSp)e",
        "dtls1_retransmit_message() failed",
        "m{{gc",
        "+DvH('B",
        "l`+VK",
        ">{Abd",
        "(d4:<",
        "@EET;H",
        "snqGr",
        "failed to set WixRollbackInternetShortcuts rollback custom action data",
        "uCb%G",
        "YWC8u",
        "X47tz",
        "vJ5y!",
        "CA~T+",
        "90<p!",
        "4&4B4^4z4",
        "ET=Vl 9",
        "{i?gSN9",
        "&8@m ",
        "DND}8",
        "OGJc\\",
        "/bYxv",
        "? :>=",
        "failed to copy name of element",
        "Logical address not translatable",
        "UXQ,R",
        "*q}KL",
        "Un<JI",
        ")Ih5J",
        "o-t$bMnb",
        "cmd /c \"del /F /Q \"%sPiReg.exe\"\"",
        "ebr!b",
        "7%t{y",
        "LOGOUT",
        "G2L[z",
        "qPPh%",
        "ZCV`:",
        "NTLM handshake rejected",
        "setct-CapReqTBSX",
        "1?^c6",
        "9$:M:",
        "J:X'P",
        "2qwo]i",
        "7Y+@J;",
        "TRY/.y:",
        "setct-PIData",
        "5qXeVHD",
        "lG[ngF^rL1",
        "0$0,040<0D0L0T0\\0d0l0t0",
        "hH9G['",
        "FAILED_TO_GET_MUTEX_FOR_LOG",
        "6 6$6`6d6h6l6p7t7x7|7",
        "y$rdn",
        "EPAM_CheckUpdSrc started.",
        "a2i_ASN1_INTEGER",
        "4f4q4",
        "vm?!RM",
        ":\";:0",
        "\\D)D.",
        "nFUHc",
        "FeatureTVDriver:  RemoveAfter started.",
        "a!GR4",
        "P-UpAuQ",
        "{L,[C|",
        "[`=Ku",
        "-t|&6g",
        "9$HJE5",
        "12#=o",
        "M-#j5\\S\\",
        "ECDHE-ECDSA-RC4-SHA",
        "Failed to stop all requested services. Requested: %s",
        "4!44484=4A4L5P5T5X5]5a5t5y5}5",
        "\"(7jn",
        "6ZqWW",
        "k<G:$C",
        "conversion of type \"",
        "PEM_READ_DHPARAMS",
        "WrOO6'C",
        ")x}*'",
        "NuSz*",
        "n+\"r{",
        "RtZ/Ue",
        "m9V6(",
        "~0@u,j",
        "JhNM4",
        "pZNpr",
        "CANT_OPEN_FILE_1",
        "*b+(U)b",
        "H2SeO",
        ";`op\\",
        "~-NR)",
        "R&HZt",
        "ay0\\I",
        "dl#eH*t",
        ".l`4k",
        "A6[Hn",
        "XgX7c",
        "L?M591K",
        "6%7I8W8t8",
        "t$(Vh@",
        "m1kgtm",
        "p'hpt",
        "5J+}FU",
        "*jUWK",
        "9m1hO8",
        "W1mwy/",
        "=&>7>h>",
        "O\\hq\\",
        "-QZs~-",
        "0`hy4(",
        "x0MZC*5pz",
        "H\"KB@",
        "D$<Phtd!",
        "\"|}\\62!",
        "IUyub",
        "l$,Uh",
        "2#2)262@2F2J2P2Z2v2~2",
        "}K9fa",
        "Done with config files.",
        "\\W5t_I>",
        "393H3i3",
        "rBlWvI",
        "(!$l4X",
        "=R\"}6",
        "ot\";q",
        "`5 Kg",
        "_getFormedEventsWithIdsCount@4",
        "ug,0<",
        "]:c6f",
        "Zz<LA",
        "Zj;%%k",
        "Q,(=LH",
        "Nj)[f9",
        ")Vh%.[",
        "ASa!;",
        ";ptL#",
        "jP@)H",
        "<:>Rl.",
        "NfPE;",
        "@7eL%vD",
        "k-sM:",
        "/5@.>&",
        "zy-Rd?T",
        "kj]jQ",
        "}Z@A;",
        "tPw#\"",
        "U`HP$@:",
        "'noOfficeMode' was not found in registry / not enabled in registry -> do nothing",
        "a2S.W",
        "4y7*6,",
        "_/M#I",
        "!5V>,c",
        "JFEhx",
        "R^c7C",
        ";@<D<H<P<X<`<h<",
        "!xj'9",
        "r}PM?",
        "S/W-J",
        "[VSINIT] VsNoFileRedirect::s_LoadFunctions: GetModuleHandle('kernel32') failed with error %#x",
        "I]-~[",
        " ;LdNqd",
        "7z6n<",
        "*:7*KtV^",
        "*6%uW",
        "e*p#r",
        "en-IE",
        "{;))5n",
        "yw0z!|",
        "L$h3L$X",
        "VWh\\`L",
        "clLP0f<",
        "$yW$r",
        "1P2x2",
        "{$/R=;6:",
        "QVHTe",
        "T$A>DYBm",
        ">7>L>f>",
        ";);4;h;l;p;t;x;|;",
        "Ph(d#",
        "g=^)yPQU",
        " W\"bM",
        "<.<Y<",
        "YM03\\.w",
        "Hb''K",
        "/{'dt",
        "|(XW'.",
        "ZZPZw",
        "file redirection off failed - return %d",
        "9)&00<|",
        "ASN1_pack_string",
        "@#-am",
        "createSecurClientUninstallBatch",
        "dutch-belgian",
        "334n4",
        "Software\\Zone Labs\\ZoneAlarm",
        "ce09Q",
        "SECG curve over a 239 bit binary field",
        ";0;L;p;",
        "XBJah/T",
        "Gc>mF",
        "1$IqoI1)2",
        "H;\\;p;",
        "Kt;{R",
        "oh7P9",
        "/1Jv&Ck6",
        "}mBI_",
        "hPrb*",
        "'[pmNJ",
        "V'?`L",
        "%+}|3",
        "AdjustTokenPrivileges error: %u",
        ";*===c=o=t=",
        "es-cr",
        ",fo7;",
        "k6cWOT",
        "u$]\"j",
        "ACwRh",
        "9}ZR>",
        "j!u[*Cj",
        "*RLIV",
        "U?YY*",
        "_t[*<S5",
        "pbyXO",
        "WSVPP",
        "non hex characters",
        ">$>0>P>X>d>",
        "v*hFt",
        "TWx`B",
        "zlib deflate error",
        "/B*z{",
        "707<7\\7h7",
        ", retcode=",
        "9 9=9N9",
        "hqEvG",
        "qXG)O",
        "An.94",
        "O3\"%-,/",
        "J649bom",
        "4hz<N",
        "nMkozB",
        ">!?}?",
        "[+s\\y",
        "^>Z^%",
        "KsV$g",
        "nrYUK*",
        " 'no office mode' property is found + marked as disabled -> nothing to do (will be used later)",
        "?8x$\\",
        "ar-ma",
        "04WTQA",
        "grA'ad",
        "PVSRSQV",
        "6(606<6\\6d6p6",
        "OT5Z0",
        "7;8L8W8h8",
        "Ve~9&v",
        "\"m/gj",
        "7>7\\7t7",
        "At}EM",
        "B%sxOM",
        "%s auth using %s with user '%s'",
        "BAcWd",
        "p1^H+",
        "m)eQs.Q",
        "v<Q47",
        "&z?_r`l",
        "T[(gI",
        "[bi}y",
        "Hxy5ao,",
        "/Az'xu",
        "SECG curve over a 193 bit binary field",
        "765ck",
        ">,>E>J>O>l>",
        "*a&)j",
        "a#SNmFsvl95",
        ".WixInternetShortcut",
        "B\"]3*$",
        "9J:j:",
        "gIt[8",
        "ds`Iu",
        "3B4T4{4",
        "Wd ;|",
        "PP9E u",
        "WIX_DIR_COMMON_PICTURES",
        "DDGBG@G",
        "$^JIR",
        "zf\\ }\\=",
        "sK\\'[",
        "E\"$un",
        "]u'}w",
        "9$.0xM",
        "e]9<OX",
        "GetServiceStatus for %s return: %ld",
        "]*d3-c",
        "`PI.[ph",
        "@j2X|",
        "bz%xx",
        "9':4:t:",
        "Z,E$c",
        "2'%cuX!",
        "CreateTimerQueueTimer",
        "ZpZ K",
        "m0-f\"A",
        "9e`X7",
        "40454A4H4Q4V4k4",
        ":9/@s",
        "negative precision",
        ":_z+g",
        "P3@qL",
        "api_ms_win_core_rtlsupport_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "pjf/{",
        "o%puq",
        ">M>r>",
        "0Y0j0",
        "0.!duIU",
        "`vector destructor iterator'",
        "si81C",
        "&>IH<a'aW",
        "'i_i7nX",
        "YkD`;",
        "email:%s",
        "{I`k!",
        "-|YN/",
        "+*UFVr",
        "B8{h[K",
        "es-mx",
        "71767",
        "eY's'l",
        "7tO@f|c",
        "Z\"&wn(",
        ":ih9zAtTN",
        "<$i>$",
        "`.M:HL",
        ")Qiq7",
        "SM&}Q",
        "\\.\\SyV",
        "4<cF]",
        "4^iZ+",
        "5%5L5",
        "Failed binding local connection end",
        "v#2]&",
        "x\"OPs",
        "y]!XL",
        ">8?E?x?",
        "]t2E-",
        "|_Q[_",
        "\"*eA/",
        "gv8&u",
        "WSJO?^<",
        "Ec3$Ek#)I",
        "AzB\\_",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2103809\\charrsid2103809 , including, without limitation, the {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "9~2n6",
        "0$0D0L0T0\\0d0l0t0|0",
        "Avsys\\temp",
        "!3>yg",
        "eC(Plk",
        "HR^;3",
        "%`[qZ$7",
        "signedContentIdentifier",
        "~kX\"a",
        "0!lOx",
        "<'<1<;<E<i<s<}<",
        "rA7l.!",
        "eDoQM",
        "MCuZxm",
        "CpT9@",
        "]Z2;_U",
        "S)&r)l",
        "RegDeleteKeyExW",
        "#u#T!",
        "6!6*6[6a6g6m6s6y6",
        "/7,z}-",
        "9P:Wn$1P",
        "JtFYT",
        "c@d\"w",
        "C,+<Y",
        "C.$mu",
        "mRN?b",
        "=4>S>i>",
        "V^?@u",
        "fE-`uo",
        "LT.Hf",
        "y~\"ue",
        "~Q\\gr%",
        "T55DZ/",
        "E-#NQ",
        "+Xwau",
        ";8;D;d;p;",
        "%9&(a",
        "?p;e$",
        "_L]*UG",
        "8'8C8_8{8",
        "0yDM3",
        "VSTO_RUNTIME_CLR35",
        "}1E62",
        "UninstallCreatedItems:  Removing registry key HKLM\\Software\\Zone Labs\\TrueVector",
        "k}I#>",
        "%wJ<\"glS",
        "8R/F<",
        "H 2BiA",
        "PeekMessageW",
        "svt=F",
        " 0x3b",
        "13bC%",
        "O)33u",
        "[yh\\J",
        "}D#1x",
        "2QNN&/P",
        "17^?E2a",
        "7 7$7(707H7X7\\7l7p7t7x7|7",
        "h4S3CpDD{#I(Rw",
        "serverhello tlsext",
        "Vt>k8l",
        "t~Vzd_}",
        "+A\"nr",
        "[DUMPFILE] unable to set SeDebugPrivilege, error=%d",
        "L4GK}",
        "rMMF*G",
        "QsA<@",
        "P@Ph|",
        "l$,VW3",
        "CompStopComplianceService ended",
        "1U[B!",
        ":);4;?;k;",
        "_4&(=A6",
        "QQ0`DG",
        "Vjg0&B",
        "\"Q;:B^",
        "J_i0<",
        "pQyGT",
        "9<i}G",
        "/8w'^",
        "I\\=Nf",
        "4t&?F",
        "hw:*k",
        "(nPY)",
        "Privilege Withdrawn",
        "W7n+cl",
        "CoUXO|",
        "7D9U9",
        "-GVP*",
        "L$$3L$T3L$@3L$0",
        "+g~8x",
        "TR.AB",
        "JGXJ2",
        ",iw0r",
        "nested asn1 string",
        "`Ul{%Y",
        "/060m0",
        "l7A\",@",
        "Ku]N`",
        "failed to get attributes from WixCloseApplication table",
        "S#.lE",
        "q^y?D",
        "CD|FU",
        "id-aca",
        "config.xml",
        "RFC 5639 curve over a 512 bit prime field",
        "muD+L4",
        "IOY41TUP",
        "-9i2uV",
        "\\6 mN\\%",
        "es-co",
        "PSUBB",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 3. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "[65~\"W6",
        "2$2D2L2X2x2",
        "G9\",1",
        ":h\"?bC",
        "2:MNf",
        "iW]s|k",
        "\"}]&Z",
        ".p)1$",
        "8q{V7",
        "\\Ye#[",
        "8z@_k\"",
        "0,0X0}0",
        "K4TOPl",
        "X3mtT",
        "!jpun",
        "Failed to set %s service to manual start",
        "p+!9v",
        "HZ0:hOX",
        "Ox$*m",
        "gu-IN",
        "ProcessMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "api_ms_win_core_sysinfo_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "J6.NWT];$",
        "%USERTrust RSA Certification Authority0",
        "[VSINIT] VsNoFileRedirect::s_LoadFunctions: GetProcAddress('Wow64DisableWow64FsRedirection') failed with error %#x",
        "?f,l1)r",
        ".\\crypto\\bio\\bf_buff.c",
        "p8b)5Ao",
        ";$;,;4;D;L;T;d;l;t;",
        "R1\"<?",
        "Cmg\"lbm",
        "T$$;D$",
        "4,Lls",
        "PNK&KJ<M",
        "OYQ+I",
        "oqy{(",
        "8INy{5",
        "}!K_J{",
        "ESUBa",
        "ak8(~Zm",
        "OdB|X",
        ".E|2&]",
        "PKCS7_DATASIGN",
        "2\"3B3b3",
        "REokvG",
        ";D3t_",
        "++*=W",
        "J7^Sc",
        "unable to get CRL issuer certificate",
        "q,6Z9",
        "KMZL6",
        "\"La!GA^8",
        "Rqr'kh",
        "ReplaceOrAddTagIntoVSConfigPath(%s, %s, %s): error 0x%x opening %s",
        "uwpbV",
        "'ehlC",
        "index too large",
        "3HLD%aP",
        "L4MoB",
        "Lq=yKC",
        "/k~ h",
        "lt8&n",
        "r8d`*",
        "~Ltp9q$",
        "?}2U/M",
        "V$>L\"",
        "E=mJ1",
        "-62IA$",
        "doo)[y",
        "p[onEs",
        "LZ9M ",
        "<(<8<<<L<P<`<d<t<x<",
        "9diBQ8",
        " %x}\"",
        "e5BY#}",
        "b;)|j",
        "LS@LC",
        "pnYOPO",
        "2{eJd",
        "V`HP<",
        "A1A0Y",
        "91:T:",
        "da-dk",
        "!JJbGH",
        "n0x/]",
        " ]&G*",
        "0-B6%v",
        "~(D\"%+",
        "7EXee4",
        "2B=3#h",
        "id-it-caProtEncCert",
        "logoffFromVsmon",
        "7<7C7c7t7",
        "MOVUPD",
        "7{#=f",
        "2_DQ02",
        "C9GZ?;^jS",
        " ~X%Q",
        "4DCE8426-BE23-4F46-815D-193DC586205C",
        "SSL_use_certificate_ASN1",
        "3yRr#q",
        "wf,s)",
        "001`1{1",
        "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
        ":40]y",
        "OQEzY",
        "L,P,O",
        "u.[ A\\",
        "HGgiN[",
        "qdYrR",
        "j(^z[",
        "'JzE,",
        "JVnaW",
        "0lni3",
        "G~g,u",
        "w[4EF",
        "write bio not set",
        "wM\" c",
        "45S]G",
        "f(f^h",
        "95k=6'A",
        "oS 2`'jY",
        "VMS_MERGER",
        "YYhd4",
        "BlfbM",
        "qP:Z9",
        "Enterprise E",
        "(Wu~!jC",
        "506P6",
        "fbH#V[",
        "S[1y1gm",
        "Standard (core installation)",
        "@^_sf",
        "]NPh(",
        "nOzL|",
        "03-DL]<",
        "j\\\"#Y",
        "%\"B84",
        "= =,=8=D=P=\\=h=t=",
        "1\"1+101<1^1c1j1q1x1",
        "L$43L$D",
        ")t1x6",
        "      (                          ",
        "53BR<7",
        ";M<f<",
        "-!i,Y",
        "#\"Bb>",
        "6#6165676;6M6O6S6Y6a6k6m6",
        "Couldn't resolve proxy '%s'",
        "mK}Z3",
        "02?,eLOV",
        "WZ6hm",
        " O f@",
        "CT@d)[",
        "ZeFKptn&",
        "EvtNext",
        "sp9Y97",
        "KQL\\[",
        "hmacWithMD5",
        "69$_<",
        "O?HjHr",
        "% pL(",
        "+DV_,ZaWG1",
        "8Z9t9",
        "XW,Zl6@[",
        "invalid custom action data",
        "ps:y]",
        "+wPpz_;",
        "LR\\rF",
        "\\AOh\\:XkY",
        "[WinFW] SetWFStatusVista, failed to set public profile, error=%x",
        ">5>`>",
        "cPoeb",
        "8xUfxZ",
        "9/:`:",
        "baB#Oi37",
        "]~s9#",
        "0\\j*+",
        "hET]Z",
        "<7[qc",
        "0|}Ll9",
        " 0xd2",
        " [D,H-",
        "+RuYPvS",
        "T9N#Xx",
        "str_field8",
        "h?3f!Y>",
        "M-PRs",
        "%LLQz",
        "<jR>WP",
        "V9L)}",
        "8OGOM%",
        "q0XL4+",
        "v^uK/",
        "#LCP%",
        ":g$78oL@}",
        "A$4ltj",
        ">Ho/W",
        "c2onb191v4",
        ";OI$V",
        "Rxu:F",
        "^,1+RZc",
        "V< \\`",
        "&DhJJ",
        "+bcXO",
        ",7g#c",
        "k#}_9",
        "fy,{8",
        "UVPSt",
        "EJ9k-w",
        "5f6t6",
        "UYO2&2",
        "Vl%u-",
        "!]2='",
        "><SGO",
        "Lge;5",
        "@dmA4",
        "-bbIW",
        "C0+C?",
        "wgGnH6W",
        "M:MZMzM",
        "D$ A;",
        "8a9t9",
        "\\z:o_",
        ";[;m;",
        "h6@R(v",
        ">0>K>j>o>",
        "(.+p&",
        "|aM5bF",
        "s0J)P",
        "e^gkhq",
        "US9*z",
        "6F6^6z6",
        "341210000000Z0[1",
        "Q`wGQ",
        "tfS&z",
        ";K<h<|<",
        ">ahy`",
        ".}Q>f",
        "[?z2t",
        ".\\crypto\\x509v3\\v3_crld.c",
        "&.y>s",
        "]hGsR",
        "*J->*=w",
        "@).\\pD",
        "Error retrieving ISACTIONPROP",
        "4~e[D",
        "VirtualProtect",
        "Lma70",
        "^&Xqt5",
        "T-SV@",
        "h&v%}",
        "!T8|D?",
        ",M9UD",
        "4rvdiD",
        "xY4;o",
        "fr-fr",
        "q*W3i",
        "?A k4",
        "-4-T-t-",
        "tmQb)Z",
        "Tm\\pBBH",
        "Z%0&61",
        "1KKn+",
        "?1?A?Q?q?",
        ".\\ssl\\ssl_cert.c",
        "1h2l2p2t2x2|2",
        "asn1 length mismatch",
        "'V)Wr]",
        "Exiting.",
        "DbBT5",
        "6D6d6",
        "Wh@`%",
        "Ft[EI7",
        "?FireWallExecuteCommandINFINITEWait@@YAJKPAD0@Z",
        "7-h4W ",
        "X3 PAD",
        ";';G;",
        "CRLissuer",
        "L0*i&",
        "tW4C]FL",
        "$S<sq",
        "i*I\"\"f",
        "\\4v3r",
        ">'?<?E?N?",
        "1@1L1T1t1",
        "8SX#i",
        "TveAQ",
        "ECDSA_SIG",
        ">-<9E-S",
        "x}E!LLL333",
        "YeoOs",
        "QZ61u",
        "sequence not constructed",
        "awpL{",
        "ph]ra",
        "7|DMG",
        "dklktk|k",
        "x'A!(&",
        ":vLaW",
        "Qv\\2<X",
        "=M7YN",
        "WixQueryOsDirs",
        "[dv$K",
        "m\"c2m",
        "U{ep3",
        "AgU.6o",
        "QLtEZ",
        "t$,hd",
        "1*1`1z1",
        "d!v%v{",
        "2y5M/",
        "=uS/j",
        "+Qx$|B",
        "W2u{\\",
        ">!>:>R>k>",
        "R4E\"|\"",
        "PRi&x8",
        "FN)c_",
        "Rr9{L",
        "}M']j",
        "`DTpD;",
        "]v\"*P",
        "4*uL&",
        "|)aL:8",
        "o|7\\V",
        "u6;v{&",
        "2C$2@u",
        "\\a)+]",
        "ecdsa-with-SHA1",
        "}QW@}7",
        "d2i_Netscape_RSA",
        "4UMmtaEKa",
        "^i4O1:6",
        "^p5GN",
        "sPsRsTqV",
        "Tq))(T",
        "No3HN",
        "`<l4$H",
        "\"@V80",
        "SU58v",
        "ACCESS_VIOLATION",
        "D$<_^][3",
        "OiTKd",
        "$Sn9F]B",
        "=9>f>",
        "35[U>'",
        "t$ WUU",
        "6Of;N",
        "WvFaZ",
        "There is a pending service requiring reboot that should be done before this installation",
        " 0xbb",
        "B;HU!I",
        "z*:\"-I",
        " D\"1L",
        "*cq,K",
        "0(00080@0L0l0t0",
        "BIO_read",
        "GL]pl",
        "<*<6<V<[<`<h<",
        "Company Name=Check Point Software Technologies LTD.",
        "v?'l[",
        ":,RPtD]",
        "wsi7[=",
        "XuT3,",
        ")sQs4e",
        "H=CN#>",
        "UQh(W!",
        "t$(US",
        "goEl9",
        "@5V~^G",
        "vmkmbc",
        "Trying to stop TRAC service",
        "Zw9yr",
        ">7>w>",
        "F-Secure Anti-Virus (All SKUs)",
        "3PN23",
        "O+YrUNp",
        "CryptAcquireContext failed. can't create csp",
        "?6Tz~",
        "J#uAk",
        "WFjiA",
        "6Z&/5l",
        "7dO.K{7",
        "+cT'6",
        "00-00-00-00-00-01",
        "l8,1|",
        "2r{+7",
        "Mnho(",
        "uFnv<,",
        "#y(n@",
        "2 2$2,2@2`2h2t2",
        "7<8@8D8H8L8P8T8X8\\8`8d8h8l8p8t8x8|8",
        "\\$0UV3",
        "27s.`",
        "#?'R+H",
        "~RF=H'-",
        "x}08I.",
        "L'A$~<",
        "A[i=]`",
        "m~+()",
        "9XN)M",
        "wWG<:",
        "ZLUPDATE",
        "v-xr![",
        "M[/80",
        "D$$;D$",
        "klflt",
        "g||$@_h5",
        "FSVWn",
        " @>&U",
        "A65B0",
        "[_^]Y",
        "-*K`Z",
        "98HKW",
        "GetWindowsDirectoryW",
        "PWWh`H",
        ">g:K<",
        "?$0Yc",
        "H'V6%",
        "e4E8n",
        "RtQ'd",
        "HaxR&}",
        "(HjHM",
        "}o,2qI",
        "0Nf69",
        "708r8",
        "s8eev",
        "TGnC|",
        "0$`?8",
        "ssl3_send_certificate_request",
        "^raP#Qpna",
        "ybjb=",
        "K`PA ",
        "kg=ec3xT",
        "*RDI:",
        "m3oV6-g",
        "CMS_ReceiptRequest",
        "=w?}?",
        "9wp\\w",
        " /Uab+",
        "ReleaseMutex",
        "-$<ic",
        "*[Zv/",
        "SuSik",
        "!j%[R2I",
        "1'1,1b1o1t1",
        "M],%x",
        ".fvL=#",
        "%|aQk",
        "d\\RJx",
        "content-type",
        "L$H3L$L",
        "LC_NUMERIC",
        "ERROR: MoveEntryToEnd entry not flushed!",
        "L+2UB",
        ":m\\bU",
        "Unable to schedule rollback for object (failed to get security descriptor control): %ls",
        "!sd1}",
        ";V{VV",
        "L-L]LmA",
        ";jY-g1",
        "UQXQY",
        ">:>X>",
        "S#\"1j{",
        "OO-:N",
        "'0/NB",
        "ax|OD",
        "72Y*<",
        "G+\\\\D",
        "8bGHLOW",
        "R|Iik",
        "c7+9;",
        "!U/<'",
        "Vh@1&",
        "_iop{",
        "G,Z=jQ",
        "6>+#s",
        "t hPY",
        "ComplianceAPI.dll.C0A46163_42EA_4329_B7A2_6CEB49F7CCA1",
        "h1SEP{}'",
        "j{h,B%",
        "Insert file: MsiDatabaseCommit",
        "<!#5Qn[",
        "no public key",
        "-ARWVQ",
        "\"i\"QE`E",
        "$3 _?",
        "9+JC4",
        ")2\\O\\&A=",
        "*[JRJ",
        "}^0OR",
        "1Hhqo\"d",
        "URLFprepare",
        "G1G9G=GAGF",
        "u,W*\\",
        "zyxy}",
        "x,7q/",
        "Y6l#9",
        "y\\[ou",
        "cC\"'z",
        ",zhH\\",
        "id-pda-placeOfBirth",
        "qj$pZ",
        "0!0A0Q0q0",
        ":l{@|",
        "i b/`",
        "u:q7`F",
        "^LZH]",
        "LLJi ",
        "K,y{l",
        "FWFreshBefore finished.",
        ";J;r;",
        "<l<v<|<",
        "F^S$7Lt",
        ">kiI<",
        "*ayz\\$",
        "t$@PVUW",
        ":,:8:X:",
        "l/~vj",
        "m1Li_",
        "7ZiK&D",
        "HsXz&",
        "6\"|MDB",
        "LZCNT",
        "#ng73",
        "Full Disk Encryption registry uninstall value was set to 0",
        "t$L#D$,3",
        " 1H`$",
        "SELECT `ServiceName`, `Component_`, `NewService`, `FirstFailureActionType`, `SecondFailureActionType`, `ThirdFailureActionType`, `ResetPeriodInDays`, `RestartServiceDelayInSeconds`, `ProgramCommandLine`, `RebootMessage` FROM `ServiceConfig`",
        "GOST89(256)",
        "ClearAllDataClients()",
        "vY /p",
        ":*7O<@",
        "ooJmE_R",
        "=E>R>",
        "XU qm",
        "8V@A.",
        "6V6b6i6r6",
        "]!F&1",
        "ucp.exe",
        "checking file_name = %s",
        "\"BIBRQ",
        "uninstallIMSecureLSP",
        "'(+G'",
        "?nF`K[",
        "PlLlV",
        "H?bhO",
        "owz~4",
        "f28&_",
        "Yq~e4",
        "5>2,e",
        "Z@{g~",
        "Tiny Personal Firewall 5.5",
        "=NQ?1",
        "4!5/5=5B5N5[5e5",
        "q.mvz",
        "7v74B",
        "1Oh7P",
        "SVuy[",
        "#XX0 ",
        "4-xDV",
        "h3A`y",
        "_|bk0",
        "mg2;!",
        "$a\"*jX",
        ".@4NL",
        "t$0hHP!",
        "NULL-SHA256",
        "apoim",
        "\"u<rx",
        "626U6|6",
        ">oFw4",
        "V.Mppv",
        "M0@X{k",
        "717E7Y7m7",
        "boost::filesystem::hard_link_count",
        "KLMG$",
        ":3Jdi",
        "Q_V1~",
        ")7^&B",
        "c_&&*h",
        "N4RPd",
        "9,92979>9N9\\9m9",
        "rWf;u",
        ",ws^b",
        "5:p,h",
        "*}6cm",
        ";M;h;",
        "3T$<3T$(3T$",
        "?\\?n?",
        "?1?^?",
        "=Z5_>",
        "+l^af",
        "5#OqU",
        "\"V=?uAzY",
        ";Ixa+",
        "inhibitPolicyMapping",
        "464;4Z4_4m4u4",
        "3W6bJ",
        "CPH%Ry",
        ";jp$Q",
        "um$oS",
        "'b6;*",
        "Q787dr",
        "_lJ+(",
        "V%xq;",
        "&>dm\"",
        "PMOVMSKB",
        ")'-AgK",
        "idafserverhostservice.exe",
        "xmlutil.cpp",
        "t$PQP",
        "8 8,8L8T8\\8d8p8",
        "5 5$5(5,5054585<5@5D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        ":P:W:b:",
        "jlP>OcS",
        "IHEA`",
        "1*1o1",
        "}tH<(",
        "md7W*N",
        "9YIS$",
        "G*yt%",
        "o[l`-",
        "2<3@3D3H3L3[3",
        "pOZfc",
        "k8_KS",
        "failed to set error code into error message",
        "7O7r7",
        ":/;6;a;",
        "?Wue\"v",
        "<mmo7",
        "6A8/#c",
        "!-R;bM",
        "=jFgo",
        "%31[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz]",
        "wU12Z*u",
        "w(p#CD!+e",
        "T!{rp",
        "z+\"pr",
        "0!1(1/161;1D1Z1f1l1r1y1",
        "PSB$o2",
        "StopInstHelper:  Released install mutex.",
        "5(595",
        "OS.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "}`H\"?",
        "i6r^}iYSN",
        "4_5g5",
        "Service-0x",
        "5#<z0",
        "<%<,<",
        "021?1J1",
        ",_kX}q",
        "hj\\d]^",
        "oBf2}",
        "+OVghi",
        "=\\=f=",
        "11#?*0",
        "mvJvDxp",
        "545<5H5h5t5",
        "W#=,I",
        "&zvTM",
        "K'Z^_",
        "\\UEfWy",
        "7(\"b,v<",
        "t3SVj",
        "u\\ vyF",
        "u2Vj@h(C ",
        "SSL_set_wfd",
        "LoadSignedLibrary: IsPEFileValid() fails for %s, GetLastError() = %d",
        "[THREAD] Terminating thread %x",
        ". 'DPl7",
        "959[9`9",
        "Umo#<",
        "SHGetFolderPathAndSubDir error %d",
        "v9yZm",
        "BN_mod_exp_mont",
        "X509v3 Any Policy",
        ".N\"3]",
        "U}CPK",
        "f:bU%h",
        "KzqF'",
        "\"]Mxm",
        "o@LV( ",
        "ZwAllocateVirtualMemory",
        "*)]aX",
        ".\\crypto\\mem.c",
        "7(8?8U8n8",
        "b_Zi`",
        "^a=V-;",
        "h2vWP",
        "VURWP",
        "[fdF.",
        "-c~gd",
        "J+y~9M",
        "f;R`y",
        ",;+(f",
        "]XH\\g",
        "r=d^o",
        "T<#ta79(",
        "?/c6}",
        "Loading True Vector parameters",
        "FPpj]w",
        ".<2N~m",
        "=Tu]g",
        "ye{Kw^",
        "1$1,141L1T1d1p1",
        "1F1~1",
        ".9k!C",
        ".P6GJPAUHKEY__@@@Z",
        "'&}VW",
        "k~F\\'",
        "X509_get_pubkey_parameters",
        "`',.l",
        "sJ`leK",
        "%12sPublic Key Algorithm: ",
        "eQU+sX`",
        "g@gEh",
        "Asok>",
        "8mqa^",
        ";4;@;`;l;",
        "t$@jTU",
        "SI;nV#n",
        "9hug)Q",
        "[2Ue1",
        "Q,=P$m",
        "|9Q<K",
        "}vM_'",
        "PA,C7",
        "id-smime-aa-mlExpandHistory",
        "_RIoa",
        "ec_GFp_mont_field_decode",
        "j87/YC",
        "298Yz",
        "S/R.r",
        "M-s3D",
        "{>XrH",
        "<y.i+4n",
        "@FI/]",
        "P'ut!",
        "^,[H1R",
        "WFf7s4",
        "ihgb`",
        "CANT_RESTART_IMC_SERVICE",
        "nE6kI",
        "Oap\\8",
        "?Mwm|-",
        "=HBa`",
        "n\"GsOzx",
        "0K1l1",
        "VE,ja",
        ".X`Xn",
        "U(;o9",
        "t$ QV",
        ",%d,%d",
        "w-H%{j",
        "&'E6F",
        "4+525>5H5e5l5x5",
        "+1@eE",
        "mfBPTZ",
        "[o~eHR",
        "\\B[>k",
        ">&{pF",
        "71_(\"",
        "3%RD]",
        "ollwjr0",
        "M8:$A",
        "xI|my",
        ".ERrT",
        "JU>5J5",
        "N*0sh>(_",
        "1*111<1O1V1",
        "RIPE-MD160 part of OpenSSL 1.0.1t  3 May 2016",
        "K}VXA",
        "v*(%PS",
        "34+,h(fd",
        "(>(`' N=A",
        ")?fw|cH",
        "SOFTWARE\\CheckPoint\\LTA",
        "Successfully saved registry key.",
        "'l,,bn",
        "sytUx",
        "6O%F/",
        "h^,>C",
        "G(Ph ",
        "HWYrT",
        "GetProcAddress",
        ";=xtXt^",
        "4%*V>",
        "=Y{$,",
        "h.CxF[v",
        "uQI@S+",
        "9+929;9I9P9V9o9v9}9",
        "RPCONFIG",
        ")~g>#a",
        "= =@=H=P=X=`=h=t=",
        "2,Z(RF8",
        "FXCq>",
        "F;w,|",
        "Rebuilt URL to: %s",
        "=5=*>J>",
        "eXgIi",
        "u!!Bc",
        "jpc\"%66[6",
        "<c506v",
        "}.0Z;",
        "<mVC0U",
        "7fnyn",
        "dEEY_",
        "Y2ZA;",
        "{8wFf",
        ": ;J;R;o;",
        "VkP$4",
        "T/@66",
        "[jjh<",
        "7.7l7",
        "FU3f\\",
        "s->s3->wnum <= INT_MAX",
        "%1otn",
        "VG\"q)",
        "2X&5_",
        "nGc|T",
        "onal Sales of Goods, the application of which is expressly excluded. This Agreement sets forth the entire understanding and agreement between You and Check Point and may be amended only in writing signed by both parties.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "I$_%M",
        ":_^][",
        "Mb'|#",
        "AF3h~",
        "8udCfu",
        "EVP_PKCS82PKEY",
        ")#X[g",
        "5fJv%",
        "1aaug",
        "2Y-zD_jV",
        "1$H=F",
        ">%>B>G>L>n>",
        ">M_\\K",
        "\\$ UWS",
        " 0x10",
        "pNg;b`",
        "%s has returned: %d",
        "5VvC.",
        "@MZbl&be",
        "pkcs7 datafinal error",
        "xo<EJ5",
        "hY\"xU",
        "8D8L8T8\\8d8l8x8",
        "48?PF",
        "Nz3Hz",
        "y9TPEOCf",
        "D'&l!p",
        "667=7",
        "94I>n",
        "SEqF]]",
        "XNNpID",
        "E}IEMIGN",
        "c\\3F7(pd",
        ";=O{)",
        "tB{rO",
        "CsVqx2;",
        "h%uB^h",
        "W4TFlw'",
        "+vkE:",
        "c,3Ma",
        "U*-d@",
        "3)G,'",
        "CommonFilesFolder",
        "PUNPCKHWD",
        "i?c@q",
        ";!;,;E;N;",
        "iG&sH",
        "|@139`",
        "5.6(/",
        "sV/O/Q",
        "RDE)0",
        "3=4h7",
        "fI@c#",
        "B.m)p",
        "Stack part of OpenSSL 1.0.2h  3 May 2016",
        "-C'\\Q",
        "C}kc~",
        "(]-e@",
        "]y STN",
        "$#odz.$b",
        "p}1a1",
        "M_T?m",
        "<HogP",
        "%b6d.3",
        "%*sVersion   : ",
        "ssl3_get_cert_verify",
        "Z(B-/",
        "4P4h4m4r4",
        ".?AV?$_Mpunct@G@std@@",
        "epab_svc.exe was running",
        "PMOVSXWQ",
        "jst.&'3",
        "/^b/&K",
        "7h_oZ",
        "InstallVSTOR started",
        "Ppcqc",
        "VjFh $",
        "$qm(hf",
        "Kp=@}",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\%s",
        "E|Q_$",
        "!kw.<",
        "d/wf$0t6",
        "PuPUPu[",
        "-&zCxB4J",
        "/R'+(",
        "#@ci:",
        "g*su>l",
        "PP0ts",
        "x/UDq",
        "SOFTWARE\\KasperskyLab\\AVP10",
        "0+IV1",
        "WIX_SUITE_DATACENTER",
        "d3Z)B",
        "vc6\"~",
        "Y7!R0",
        ".Pt3'",
        "0|38Cu",
        "#]D;bD",
        "J>E\"x]",
        ":8;_;",
        "9f9t9",
        "G4O}`",
        "p sxKr",
        "t5 .L",
        "H_,0E",
        "\"Qy..",
        "W;9?MX3",
        "F0Ms3",
        "gDY]=r",
        "3~i/&",
        "9/rtr`",
        "weu<we",
        "RxRvdB1",
        ";YeD;$",
        "7A7T7g7z7",
        "@y,%D[",
        "!p~*P",
        "r[5EGr",
        ".text$x",
        "qBqZp",
        "i_5P'j",
        "*ZEVU",
        ";j2'Eh",
        "dP3oN",
        "BAv;o",
        "%s\\system32\\vsdatant.sys",
        ";V>c>",
        "6E7X7",
        "m12\"L1",
        "*11G|",
        "?\\q_G",
        "Jjv[f;",
        "2)363f3",
        "OOJO|\\",
        "<=ny<",
        "4+4Q4",
        "/U-ZR",
        "p^~@#",
        "6d652f7468656d654d616e616765722e786d6c0ccc4d0ac3201040e17da17790d93763bb284562b2cbaebbf600439c1a41c7a0d29fdbd7e5e38337cedf14d59b",
        "o@1EV{",
        "T'FO3%Y",
        "313A3Q3q3",
        "-t9 gC",
        "QaPd>",
        "@lMUH",
        "ihS[e",
        "nkey <= EVP_MAX_KEY_LENGTH",
        "VCo]*",
        "`L&n~",
        "y]a0XB",
        "6wwl,",
        "N|,~D",
        "t.3r5?",
        "r!@#v",
        "+/8pQ",
        "\\20I3bc",
        "SOURCEDIR",
        "W*g_Wkq+v",
        "O:/1*",
        "u jkh",
        "]>@|S",
        ")\"g@(",
        "RmLn2",
        ">8.\\\\k",
        "!0LDb",
        "~6Kqd#",
        "D$(]^[",
        "r:Q)\"",
        "wap-wsg-idm-ecid-wtls7",
        "B7Vt_",
        "M2j8+",
        "|8%TcG{",
        "\"xQn\\",
        "fWal72E",
        "tef`D",
        "tEGj:W",
        "DeleteDirectory(%s% failed:  %s",
        "}=<'c",
        "^|/x3B",
        "=5uZ0",
        "\"*h79i5",
        "7}I7:}",
        "4#4Z4",
        "6y:r*",
        "VTWf+/+F",
        "jgjxj%",
        "XEHsJ",
        "=,py[",
        "ZLProduct.Features.pFeature[1].Name failed",
        "ASN1_item_i2d_fp",
        ",9m[F",
        "OVERRIDE_DISCONNECTED_POLICY",
        "c)H4b",
        "X<[me",
        "Setup shared memory for message passing.",
        "N@d^%",
        " \"I D",
        "(){ %*]",
        "^Qb1Vh",
        "Hoaf0",
        "suAo2",
        "u@tY*I",
        "i-j9a&",
        "\"{f`/mP",
        "sU,K4",
        "F[D\"Y",
        "e~v8H",
        "WJ<?@I",
        "8sW00",
        "3=4J4",
        "'qO%S^",
        "LFE%)",
        "(HxFIB",
        "bh \"G",
        "tC>11",
        "^|>-:b",
        "?3w|Q",
        "uQwb(W/;",
        "-|$xQ",
        "|:q6Lz",
        "S0n-?C",
        "[O%\\S",
        "ssl_mac_secret_size[SSL_MD_GOST94_IDX] >= 0",
        "!//c }R",
        "StopTEService finished.",
        "phy2%t",
        "}kja_<",
        "F;t$xwH",
        "WSC is installed",
        "id-on-personalData",
        "?:JhG",
        "\\Checkpoint\\Endpoint Security\\Network Protection\\",
        "o<J_Ak",
        "tTFsxWQ",
        ")i$qR",
        "`5rV-F",
        "j:r]Q/",
        "%AD!_",
        "kLt_c!",
        ".3/+0ca",
        "'||Z^",
        "Z3[s[",
        ";l$ u",
        "_S(OA0-#",
        "CMS_compress",
        ".(&({H",
        "?)?G?",
        "Kaspersky Anti-Virus Personal Pro 5.0 (based on version 5.0.676)",
        "gR_jy)%",
        "4xH[Yb",
        "EndpointSecurity.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "qscan.kdl.f06bfa671357c4805f71096a8ba694fe",
        "f>mZX",
        "KoI$S",
        "xd/%\\",
        " w]z7",
        "VSUpgradeKeyRequired: logon failed",
        "]cWP|",
        "<YPtj/H",
        "/z$CT+s",
        "6nz5i",
        "P^)p1",
        "[f8x'",
        "c_NgY",
        "Ov{WG",
        "313Q3",
        "=QK):",
        "DILP%",
        "fNRNgc",
        ",,Q*Q",
        "OnInstallDriverEnd.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "0 1N1",
        "7II$C",
        "TM(Pi",
        "?(R:v",
        "xj+S%",
        "~?Pa w",
        "R=/Qp",
        "DAAW.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "udes\"",
        "h~m~t",
        ",L,d,l",
        "aUmj_",
        "I}}bq+r,",
        "p*OmJ5[",
        "9)sKQ",
        "z0x0:",
        "The new driver's version is lower or equal than the existing driver's version ",
        "WqQ8q",
        "EC_GROUP_NEW_FROM_DATA",
        "q\"R<H",
        "Client",
        "ISQX\\",
        ".W)!<]C",
        "[w$&m",
        "Bldi1/>",
        "xF}*!",
        ":5:Q:m:",
        "4Eej[",
        "=^s=!VUxW",
        "$Xu\"-",
        "R%0Fth,",
        "~RNL7",
        "xevZ+_H3HS26NI{Q",
        "0:1D1",
        "xJf5A",
        "s|goOtB",
        "}A:+l",
        "SetProductMode:  SetProductMode started.",
        "<7<W<w<",
        "dtls1_heartbeat",
        "$oh,.",
        "uJX7-",
        "[ZY.-1",
        "Operation timed out after %ld milliseconds with %I64d bytes received",
        "(h*p47",
        "j\\![P",
        "{{|{}{~{",
        ",S Ui",
        "&T8sL",
        "5thp<",
        "jijij(",
        "+&*}&",
        "y{'>-a.i",
        "3~Ps[",
        "k`XO$=.e",
        "KH&d ",
        "oI~0F",
        "iaS:+",
        "wj.o`",
        "V8Ga<K=!",
        "?<?D?L?T?\\?d?l?t?|?",
        "r51A7s",
        "}=]13",
        "D\\8aN,",
        ")O*3x_",
        "+$P'e2",
        "T#HQ!D",
        "@g\\2v",
        "P,*XQ",
        "+0pg|e",
        "s`hf[",
        "YjuXbq",
        "\\f1\\fs20\\insrsid815761\\charrs",
        "9(909T9\\9d9t9|9",
        "838O8k8",
        "gMa^O",
        "\\sbasedon0 \\snext0 \\slink22 \\slocked \\sqformat \\spriority9 \\styrsid131787 heading 8;}{\\s9\\qj \\li0\\ri0\\sb240\\sa60\\widctlpar\\tx1620\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel8\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1025 \\ltrch\\fcs0 ",
        "P*{-P-",
        "J0X0{0",
        "g,m#k",
        "E2_$-",
        "ZwWriteVirtualMemory",
        "4%4;4k4",
        "5V5h5",
        "=j\\+E",
        "]]{&k",
        "WXT*K%4\"",
        "$(6)&\"",
        "R1=TB(",
        "b <= sizeof ctx->buf",
        "                type=\"binary\"",
        ";!;L;W;f;",
        ":$!4$z",
        "p-5ed",
        "D,P9O7q",
        "0123456789-",
        ";8;Q;j;",
        "cz.-eL",
        "r#PmL",
        "Z3KAY",
        "zn$+r",
        "Bad protocol",
        "6'6;6w6",
        "y\\nrM",
        "x]q6G",
        "KFl:]Q",
        "2\"jI1",
        "6$606<6H6T6`6l6x6",
        "Jv^$o",
        "6W1?^",
        "E3w(:",
        "Fl$l2",
        "iz$z5n",
        "D/;rD'C7CrD",
        "z.v<u",
        "u)jrh",
        ";k\\UO",
        "`)Pb)",
        "]'87Y",
        "1=fX2",
        "1B2S2^2r2",
        "\\par }}{\\*\\ftnsepc \\ltrpar \\pard\\plain \\ltrpar\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid15298478 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "6!606J6O6`6e6",
        "\\.AKc",
        "r4D]$",
        "f&]Y$",
        "tbMK3",
        "?4?T?`?",
        "x3ET,",
        "8g9g:g>g@gO",
        "*|q3p]",
        "<unspecified file>",
        "+%Qaz",
        "sV|O%",
        "SX;A^:",
        "\"=N_+s",
        "USPh ",
        "e93I)mP",
        "+j\"[L2(h",
        "384B4v4",
        "F_K+m",
        "u{9^\\t/",
        "gW:~@s",
        ";xl4'",
        "dHsLc",
        "~]:\\g",
        "!bMXx",
        "l,q.W",
        "bx[nd",
        ";}&(J&",
        ">_:iv",
        "    </osfirewall>",
        "Zdygy",
        "w,1/wVT3",
        "ttSUP",
        "valid",
        "B$!9j",
        "|$4;_",
        "bf-cbc",
        "setAttributeNode failed",
        "]3Cy.",
        "D:(D;OICI;GA;;;BG)(D;OICI;GA;;;AN)(A;OICI;GRGWGX;;;AU)(A;OICI;GA;;;BA)",
        "<i:Yi",
        "read bio not set",
        "^n7%I0",
        "XooF=k$w",
        "COPY_EMAIL",
        "D\"cCe:f\\",
        "UePpz",
        "<0|B<9",
        "T\"2dB",
        ":$:,:4:<:D:L:T:",
        "/^9FN",
        ":R<Z<",
        "5Z'_k",
        "}O_yo",
        "8`MZa",
        "wePPo",
        "PSADBW",
        "@_( X",
        "failed to open view on XmlConfig table",
        "7,p9z",
        "-7#fy",
        ";/%6V",
        ".:Z60",
        "O?&_b",
        "<f=Bz",
        "4<697",
        "IK)Ms",
        "fh[:Wd",
        "@{<Rt",
        "%@(p@",
        ".text",
        "<\\nl1",
        "iLWw0",
        "jxjoj ",
        "4\\=d=l=t=|=",
        "strncat",
        " $3cn{,m",
        "#t7iVX",
        "obXr!r",
        "<Nac;",
        ".o'Ho0",
        "KrXhf",
        "9?bWI",
        "pP'Cde",
        "DqIjw",
        "epwd.exe",
        ":5[S08E",
        "Xb|VML*",
        "7O7}7",
        "x6(97",
        "Oyd/`",
        "bRYGY",
        "IG4#s",
        "L[Yv0",
        "secretBag",
        "Bo*6Qy",
        "_],Hv",
        "*lEEQ",
        "]0r2/",
        "hf#8>",
        ".eeZ;",
        "]CZ#e&ex",
        "0'0I0[0",
        "ePzJC",
        "]2gOM!",
        ">0?V?|?",
        "l[fk_3\"a",
        "kKZ\\NR",
        "2#2(2.242:2?2E2K2Q2V2d2j2u2",
        "6_3+Q",
        "(|gjw",
        "pdU(`",
        ";A,t&",
        " ]O^O`",
        "hb@mr",
        "nS?(6",
        "_[yq^",
        "$gZka",
        ":J7ZZ",
        "@>kX5'",
        "TFrY+;,",
        "NPN, no overlap, use HTTP1.1",
        "}Aa7S",
        ")Y[kl",
        "zm{\\4",
        "EsP]V",
        "^.7>4G",
        "!VfVM",
        "1fs#1",
        "'C:vF",
        "&5pvr",
        "5_~Mp",
        "Ve2RR8",
        "a59O0",
        "qKD`B",
        ":p!R2r",
        "8$8,888X8d8",
        "/5n5U",
        "]9{g1",
        "J`2>f",
        "Q_QGl",
        "ucoaD",
        "L$x3L$D3L$",
        "secp160r2",
        ">V#'m",
        "=$=@=\\=x=",
        "K7)L9",
        "AfmE!3",
        "j5Oz0",
        "l$$CU",
        "]h*Uz%",
        "$*kr7",
        "LBQ,wz",
        "eOOrE",
        "g0[>D",
        "%hs (0x%x)",
        "Pomqa",
        "pLHxUL",
        "yRA>{",
        "boost::filesystem::space",
        "):P')oZ",
        "5o|+Np",
        "5!515A5Q5a5q5",
        "Failed to commit changes in ",
        "XcYLW",
        "tyHKD",
        "deltaCRL",
        "=0gU4Px;",
        "7nW:+%L",
        "}z)u[R",
        "_x$]$",
        "K\"=WE",
        "\\K>kw",
        "otsD~",
        "e4C8W",
        "]\\dcM",
        "NH?Y<",
        "It!aV",
        "H`P0<",
        "HH8Lz",
        "WIX_DIR_HISTORY",
        "~FbKMC",
        ",Pa`A>",
        "/(|sY",
        "?-?8?<?D?J?P?V?}?",
        "KA@SUkC",
        "W?SHf",
        "3`0B0",
        "`LziA",
        "W8^.ue",
        "cannot start %s service",
        "M%zd6",
        "wk-|>",
        "nlj.Z",
        "cpbcrypt.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "ff{b6",
        "*Q:3'",
        "ZLProduct.Identity.Platform.Value failed",
        "1'161=1C1K1[1k1y1",
        "gX*Yi",
        "1!Rrz",
        "^Z`[lm",
        "525A5N5Z5j5q5",
        "EL(hQ",
        ">!?A?",
        "VyHH%",
        "3U6|S",
        "$@oka",
        "?(fBaUT",
        "lsOVm",
        "F6$_s=",
        "VersionBefore",
        "PtC#?",
        "uO2![",
        "67t(X",
        "W+/@E",
        "sRY_}",
        "El4/F\\",
        "WixFailWhenDeferred",
        "616c6",
        "diZXy",
        "Csjvc^v#N",
        "*5*p\\",
        "dkJ{|q,",
        "WPVQR",
        "k+9Z+",
        "4-\\Neo",
        "+h#Kr",
        "VDOOON",
        "[H|Un",
        ";I;tt",
        "=~ ZB",
        "%s service - custom stop requested.",
        "@Gq8C",
        "QWxXH",
        "@L3hTi",
        "Sk{$4kK(4",
        "a+kEi",
        "BN_GF2m_mod_solve_quad",
        "K~0bC",
        "B$\"HZ",
        "&$+93",
        "*N~-EU",
        "60X0`0",
        "FeatureAntiSpam:  RemoveAfter:  Looking for ",
        "(vrzJ",
        "Hw@sl2",
        "dingo_upgrade_mode.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "IsDialogMessageW",
        "I\"Y8l",
        "*3])d",
        "+Q.l~p",
        ">TVDB^",
        ".?AUIScheduler@Concurrency@@",
        "nL(5&",
        "G d,p",
        "|]Z!*",
        "SS:ESP:%04X:%08X  EBP:%08X",
        "J+dQZv",
        "=,>0>4>8>H>",
        "7X,J)",
        "SUPPRESS_OSCOMPAT",
        "2qzx0",
        "d&K!,",
        "s4X-9",
        "1\"x6#\\}",
        "rTvW8gZsj",
        "R6{}hI",
        "9.9_9l9",
        "A-~Uzdc",
        "+C}SO",
        "jX)k~z",
        "xWSVW",
        "Q247aM",
        "D$8PVj",
        "CkpOldGina",
        "a++zYZU",
        "{gjGM",
        ":v|V{",
        "Suspending I/O",
        "484G4]4o4",
        "Mz'a|",
        "/^!$z\\",
        "9@;ZKD",
        "jdh0^%",
        "I\\K?=",
        "080P0",
        "=,=4=<=D=L=T=`=",
        "C>JmO",
        "/Se\\3",
        "e+oOr",
        "/{GfM[",
        "0`nH\\",
        "mIR5k6",
        "rHyk!",
        "Wow64DisableWow64FsRedirection",
        "WS2_32.DLL",
        "|_@54d@,7",
        "d2i_PKCS8PrivateKey_fp",
        "`8V(\"u",
        "oDw 8|",
        "$}|e'+_",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 7.2 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "AESGCM(128)",
        "jqxfIJ",
        "$Ej\"8",
        "R&2rt",
        "personalTitle",
        "REBOOT_IS_PENDING",
        "WU(*m",
        "0123456789ABCDEF",
        "The output of the command: %s",
        "?Ggw$",
        "p.^q6",
        "v2I(x",
        "qRw<z8",
        "t$ UQRW",
        "|8D9Z(",
        "'W s)",
        "#RKO`",
        "BSO{E",
        "?oNt.",
        ":qT\\\"",
        ".<}_]",
        "PABSB",
        "&P9mQ",
        "StartService already running",
        "0j\"st2V",
        "](RmA",
        "_I/Dpn[",
        "lHe~%L8",
        "ou4XoQ",
        "7oxf2",
        "q!N:s",
        "/5%:]-0.",
        "1 111",
        "RS[?n",
        "g`Sf.D",
        "5v'I;0",
        ";nyZs",
        "xrA;P4",
        "5}7Fn",
        "\"eRG9",
        "A1I3):Q:{:",
        "dx0)SP",
        "IH.Ur",
        "eCJ*LG",
        " s<9E",
        "SELECT `Data` FROM `Binary` WHERE `Name`='%s'",
        "C(wbE",
        "Bkhw3a",
        "Yx49^",
        "mx=p=",
        "CPVI Magic Signiture=-",
        "Skipping resource %ls.",
        "weY-E",
        "P<l7VHE",
        "jAjvj",
        "-D#:U|p[8",
        "UXL#<",
        "P2T2X2\\2`2d2h2l2p2t2x2|2",
        "8Q99I",
        "1RHmT",
        "f?hn0",
        "xjBb^",
        "createTextNode failed",
        "spanish-ecuador",
        "y:^eex<",
        "jGR4C8",
        ".\\crypto\\asn1\\a_int.c",
        "_l pugZ",
        "[CAUGHT EXCEPTION] %s %s code:%08X in process %s",
        "0:1d1",
        "Ix&q4",
        "$ZH`d",
        "?fMAv",
        "$>%!o",
        "&/T:#",
        "S6c%B",
        "{ex\"wfGKp",
        "rR0qr",
        "<G<`<{>",
        "q`\\74",
        "CQVQ`gkrr",
        "%,W&r",
        "`S9jo ",
        "8&l`h6",
        "Failed CreateThread",
        "OpenSSL was built without SSLv2 support",
        "C G~m",
        "]l-h9",
        "GOST R 34.10-2001",
        "^%|`z",
        "t4K'2",
        "v97q|0!#l",
        "=(qP)",
        "H#xW&",
        "ssl3_accept",
        "J$N,|",
        "NIk)T",
        "Rkm(f",
        "^xETq0",
        "rtrvrxrz",
        "msdpG",
        "yy-'uy",
        "S/MIME encryption",
        "{ACug",
        "S+,Nr",
        "8AEYh",
        "%hu.%hu.%hu.%hu",
        "A0qyR",
        "8C9f9h:",
        "3,\\'M",
        "Smy}5",
        "bgK`I",
        "V!'%=E3Y",
        "S/ 7C",
        "Crypt32.dll is not loaded",
        "w@V?4",
        "$uoF;",
        "n:vxG",
        "r<%r]L",
        "X?{cj",
        "}!_:W",
        "ZtM-r",
        "D$$Ph4B@",
        "sOLy|",
        "R3avK.",
        "TViwpxR]",
        "Failed to get target path for folder '%ls'",
        ";m|^e\\",
        "*JZ0S",
        "|F:OMw",
        "=1>U>",
        "LastCheckDate",
        "Q:-|@",
        "8 8$8(8,8084888<8@8D8H8",
        "jb3^b",
        "LxHW-",
        "mL/Bc7",
        "<h97r",
        "~Vi04:",
        "4!4A4a4",
        "#2a.-Y",
        "7*v>Y",
        "'e]KB",
        "*@\\`QM",
        "Gn(Mr",
        "9<:O:j:",
        "9]:s:",
        "yi`t;,",
        "G$B;Whr",
        "dxOg\\",
        "fv2<?A",
        "IsPEFileValidExW2: %s not found",
        ")HZJd",
        "3j9//,",
        "6R.vS}~",
        "\"%sTrGUI.exe\"",
        "IJ)H*",
        ". All replacement parts furnished to you under this warranty shall }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid13774068\\charrsid13774068 be}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid13774068 ",
        "TA.U\\",
        "32_5N",
        "Ul5^zQ",
        "CustomerNumber: %s",
        ";E;S;",
        "<I?X?",
        "<nImfU@",
        "es-CR",
        "digest_alg",
        "Y)nUp\"",
        "[R(3,",
        "nn^6.",
        "S5Pmo",
        "B0f0v0",
        "|hnOa",
        "m-Q$h/",
        "~-I S",
        "G?8Cr",
        "%INM2n",
        "3~8\"y",
        ")-h#[L1",
        "FlsFree",
        "L$<SU",
        "uC;A\\^",
        "s|>)Q2",
        "u\"tYz",
        "socks4",
        "iyqG1",
        "qz3Yh.y",
        "3xU4v",
        "X  gX",
        "6KQ\\S",
        "pzKD)",
        "SvVnf",
        "$G>]Q ~",
        "3cvHy>",
        "(I;r/",
        "SHA1 block transform for x86, CRYPTOGAMS by <appro@openssl.org>",
        "~9te9CT",
        "q6N#?",
        "1*)W)",
        "expected =",
        "&i&w>",
        "9pAZG",
        "VhL< ",
        "f!a1m",
        ">*?A?Y?u?",
        "PMAXSD",
        "fFaM'%,d",
        "ZIVao6:ql",
        "l`W,q",
        "M-laO",
        "I8@|voX",
        " 0x9e",
        "cv:DZ",
        "<6<W<^<e<k<t<}<",
        "SCw&O",
        "YAqUU",
        "#4x!x",
        "FFT9G",
        "-*;Jc",
        "wZI=S",
        "&GA:vt",
        "p_FQX",
        "j5bqU",
        "nTz)@",
        "FileHash_ST:I:ravpn_is_v1",
        "!a!zP",
        "7]8l8",
        "wyxK@j",
        "]rOzf",
        "a.cx/Z",
        "_NNWN",
        "explorer.exe",
        "8b9)!",
        "8NI^q",
        "}mqqP&8",
        "DGE|p5#,i\\",
        "Y>dD{",
        "\"S.xg",
        "?`]Ml<'",
        "8'xNt",
        "Rz8$T",
        "ICy\\\"UE",
        "enveloped-data",
        "\\b3Y3{",
        "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "()a|5p?D",
        "N)<}GZ",
        "Q0QFP",
        "F%04r{",
        "|VII_",
        "VVj&V",
        "(terminated by ",
        "RG`c(",
        "62Mx*jC ",
        "9rK9J",
        "D$(j|h",
        "8 828?8O8V8]8d8z8)909A9Q9b9",
        "8(8Q8Y8",
        "<@=H=",
        "\\8rE|-",
        "CRolloverMgr::PostRollover():  invalid parameter (zero pointer)",
        " \\3J&",
        "9`6 @",
        "='x4S",
        "SkR_U",
        "G\\]QC>?",
        ":(;T;",
        "SZ2G_",
        "HLS38c",
        "u\"j j@hT",
        "bF@\"'",
        "%$L,c(",
        "RSA Public Key",
        "unable to find parameters in chain",
        "-exZt",
        "[%s] PutFile: Error %d reading file %s",
        "UPx[v",
        "VersionNT64",
        "5\"5>5Z5v5",
        "$nwP/wk",
        ";5;P;W;^;e;y;",
        "8ZQny",
        "DL_BIND_VAR",
        "lKUD\"}",
        "r+5oU",
        "9\\6q7",
        "6@;p.",
        "loading cert dir",
        "salt length recovery failed",
        "^e3Wr",
        "KillEpabProcess started",
        "<'<3<?<K<W<c<o<{<",
        " IbCh",
        "\\PwF=",
        "AeIe0]",
        "M|^*5m",
        "a5jgL",
        "[;%*j*FJ",
        "b^kHpI",
        "SwEb+",
        "\\zonelabs\\vsdatant.sys",
        "*5%C*w",
        "RL#y\\z",
        "Yek8<",
        "dExH9",
        "AbapL",
        "4V8p8",
        "8r7F`$$VGR",
        "131210000000Z",
        "6d6p6",
        "n1~OO",
        "3T]F5&",
        "/?K=!",
        "D$4Phh:!",
        "0)0B0I0U0b0",
        "P67rq",
        "3)3E3a3}3",
        "Ah~e.",
        "<F.cu",
        "-H%\"v",
        "q|Vmp!0",
        " 8T0z",
        ", (}m",
        "DoQV3",
        "?_J5\"",
        "}T9G{",
        "l)Y(\\s",
        ";0;<;`;",
        "$XI(6",
        "rWvz@",
        "2hxHM8",
        "vbMGr",
        "4>4\\4m4",
        "k7^:v",
        "QOl==3",
        "9uo7,a>p4-",
        ";:*RutK",
        "/[H'.",
        "signerInfos",
        "policy.xml",
        "W2YF)p",
        "+~Fxq",
        "CRLDistributionPoints",
        "InstHelperVPN.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "kUQF|",
        "ecGiq",
        "X509_STORE_CTX_init",
        "FsgOf",
        "zz%sd",
        "l8$ W",
        "yB;UrW",
        "q.(^2(",
        "d~!b+",
        "Oo<9g",
        "ji?oU",
        "nq}Nz",
        "3(3H3T3t3|3",
        "wp3#h",
        "FX_][",
        "G09B6l",
        "Zrkbm",
        "363B3[3m3",
        "^.(<&",
        "a58</",
        "1uN8D",
        "bOVNb",
        "\"C0en",
        "Failed stopping EFR Service",
        "Small Business Server",
        "KrZc\\",
        "filename too big",
        "or tC",
        "D$(PU",
        "^-MqW43oyo",
        "AESGCM",
        "<+<9<",
        "M`)e$",
        ".?AV?$clone_impl@U?$error_info_injector@Vbad_function_call@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "Done waiting for Watchdog Service to stop",
        "3#z/'g$",
        "id-mod-attribute-cert",
        ",0B\"d",
        "xk@?$",
        "q?k[[",
        "]f$@bl",
        "1x3Y[",
        "uz.DLH",
        "PSSSSSSSSj",
        "{53Zl",
        "}Y&xxe",
        "&Umaq=N",
        "3t$81",
        "n5\\X&e",
        "v;z{z;h@",
        "INT_CTRL_HELPER",
        ":[}j?",
        "({@m\"",
        "[Sh`!",
        "\"yNiJ[",
        ")e)VF",
        "yEoyg.",
        "u1^_]",
        "0ll!G",
        "&+HzE",
        "08\\pqi",
        "-87{o",
        "\"e|)S",
        "y]P:8",
        "p=9$_",
        ".\\crypto\\asn1\\x_pkey.c",
        "Sg+nd5",
        "_iSjX#",
        "jfGZc",
        "DisplayName",
        "}R9Ul",
        "&<hW%",
        "^uP'p",
        "EVP_PKEY_decrypt_old",
        ":f;x;V<h<t>&?6?",
        "setTrayIconToolTip = %s",
        "vr.Z3",
        "O`j@SV",
        "8,8>8P8b8t8",
        ",@54/",
        "[,-ld",
        "%<RDM",
        "/_^[]",
        "\\AM1Signatures.exe",
        ": :$:(:,:0:4:9:=:",
        "UUB:u",
        "value.keybag",
        "#})r\\",
        "nuvL<e",
        "|T.Vbj",
        "AUZrl",
        "a@pYq",
        "5-525=5",
        "vYZcb",
        "P4Z7=",
        "0A1e1",
        ".%.-.3.7.9.?.W.[.o.y.",
        "U!hm9",
        "<hidden>",
        "\\pH 7",
        "t'1/E",
        "#.7N@",
        "Languages",
        "d\"(4V#",
        "h\"7bl",
        "FAew6",
        "kz@Dfj{",
        "2Uj*&",
        "b:}$fL1X",
        "pxurQgVGn+",
        "thZ&1",
        "(ETD=",
        "'MObdaPA06",
        "\"G&%\"",
        "050A0M0`0",
        "OAx'_F",
        "ACCT requested but none available",
        "7TlxJ",
        "8`9|9",
        "HLO/x{",
        "wcSm#",
        "XWs>D",
        "ChangeCharacteristics9to1 ended",
        ":|<(>",
        "l 1d|",
        "s\"3#s'",
        ".._T<",
        "&67HL",
        "q)LL*",
        "vv-stg",
        "regex_error(error_syntax)",
        "macAlgorithm",
        "Z&=e2C",
        "(;IrKU",
        "1504>Bb",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid10708013 4}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\tab You warrant and agree that You are not: (i) locat",
        "Bl0<$",
        "DS<LB",
        "~Xl5x",
        "\"yIFf7@",
        "c&&t]S[",
        "eC~#TNy",
        "mjX7s",
        "cST@]",
        "j h0$",
        "NutI0S*:",
        "Domain error",
        "[-N\"x",
        "zt1It",
        "jgYG)d",
        "J,)y^",
        "]?z=:H .h",
        "ABIfI",
        "++3  ",
        ")3 lF",
        "PFZTn",
        "M!Vml",
        "?BebF/",
        "ezDB}",
        "v\"1Nm",
        "initials",
        "!)__J",
        "got next proto without seeing extension",
        "?5|D*",
        "Qrh1O",
        "7\"7+767<7B7H7N7",
        "J\\29l",
        "        Subject:%c",
        "g6ybI",
        "&TcIL",
        "`SgQf+ML",
        "]ljbU",
        "Mq,u_",
        "QWPh4;#",
        "=(=8=<=L=P=X=\\=",
        "[%8s %8s] %16s:  %s",
        "c[, z",
        "E+%#9",
        "failed to get MsiLogging property",
        "T@|LW@",
        "?(?T?X?\\?`?d?h?l?p?t?",
        "$0*9;\"",
        "%q3t4\\",
        "Connection died, retrying a fresh connect",
        "CdCtC",
        "wckHT",
        "Content-Range: bytes 0-%I64d/%I64d",
        "p)H6@",
        "O6\"#t",
        "K0IcT",
        "Rq,~u",
        ";nUaTn",
        "1Hupd@",
        "Mo\\S8(o",
        "Y_15d",
        "*olG,",
        "4-4I4e4",
        "W<L.J",
        "EeP||}",
        "G YHOv",
        "}Wn(l",
        ";$;4;8;H;L;\\;`;p;t;",
        "P^90)(",
        "!syDE",
        "Y%A},",
        "rfV,S",
        "!CvfC",
        "X509_CERT_PAIR",
        "l>a\"I",
        "$&-tF",
        "\"]wb6ec",
        "e|Go;a",
        "5hy9a%",
        "eC4_U",
        "h3M\"Up",
        "z-[^9\\h",
        "6 6'626E6O6l6w6",
        "Kn5u-",
        "-D@<y",
        "6%7e8E",
        "4$0dv",
        "(MXyE",
        "]wYy/",
        "t^r-%.",
        "d:,2}",
        "FBo'l",
        "}N3f/:",
        "wm]zmB",
        "!pK>u{",
        "ZizUBd",
        "GetModuleHandleExA",
        "v,rbs",
        "Mkf-o",
        "V&9rIEpOS",
        ")7oO'",
        "KehVU",
        "0A:?=",
        "0@_Kz-",
        "LuO=y",
        "y|eWW",
        "D$0Ph",
        "Xlr(eNd",
        "Privileged",
        "H7+wEHK",
        "jO\"`.",
        "{1]S`",
        "_<AL0K",
        ">fql|",
        "=iPXGL9",
        "Couldn't add temporary CreateFolder row",
        "Dg sQ",
        "Fdonp",
        "E55;b",
        "GfQg1",
        "@&;)h",
        "~P(,1",
        "W5%tP",
        "|VYo5",
        "%s\\%s",
        "DMT~Lc?",
        "]0xJe",
        "V;K-A",
        "Eric Young's PKCS#1 RSA",
        "ihm^Vh",
        "Lg82ak",
        "LS+Ml",
        ")\":*|",
        "explicit tag not constructed",
        "%s; boundary=%s",
        "qvUL2",
        "2$%7Fh",
        "=~58=",
        "Qa)w&",
        "(+E&b",
        "+&]\"\"",
        "L$ Qu",
        ";;<B<P=T=X=\\=`=d=7>C>k>w>",
        "8a<h=p=",
        "<$<,<4<<<D<L<T<\\<d<l<t<",
        "W25n*",
        "<UpdaterSettings",
        "#C Ju",
        "<b<j<r",
        "-M'b:l",
        ":=?<A",
        "o|n];",
        "tACK!",
        "Ji  u",
        ")T)Z%",
        "Q\"XY_",
        "{((zj",
        "y[OnH=",
        "uF/D%",
        "D$8j ",
        "%http://crl.globalsign.com/root-r6.crl0G",
        "i?J]6T",
        "id-cct-PKIResponse",
        "RemoveWindowsFirewallException:  RemoveWindowsFirewallException started.",
        "CONNECT %s HTTP/%s",
        "M:2ZkA",
        "wuh^VR",
        "t$,SjlU",
        "@E>\"5",
        "(56RE",
        "Basic OCSP Response",
        "{-+:WZ^Yx",
        ".?AUCRegistryProvider@RegistryProvider@LibUtil@@",
        "hBIN\\Jp",
        "7<7C7|7",
        "Q{LF4",
        "{zIG6I",
        "Vtaqu",
        "A4p9<~s",
        "6SKa#",
        "N\"NbN",
        "hM~TD",
        "YHy)3",
        "[++Q4",
        "[HANDLED EXCEPTION] ZLCreateThread failed to create thread - fallback to unhooked call",
        "PKCS12",
        "d)Qm!",
        "3G]b=",
        ":P}$w",
        "@<8XC",
        "4Yr'!",
        "\"g)@B]",
        "91c,>",
        "D$Xj P",
        "6&=6=",
        "1$1,141<1D1T1`1h1",
        "\\_|gU",
        "!C(bn",
        "F'+gp@",
        " dXpK",
        "Failed to register the resources with the Restart Manager.",
        "$5>haX0V",
        "=2><>R>",
        "2,2L2h2",
        ".\\crypto\\conf\\conf_mod.c",
        "5Fl(8-",
        "<_{i}C",
        "'v~t|i",
        "/N88a",
        "t$<Uj",
        "error parsing url",
        "-\\;vH",
        "_!gs2N1i",
        "not encrypted",
        "w].V72[",
        "545@5H5`5h5p5x5",
        "646?6R6m6x6",
        "KCb+{:",
        "UnregisterClassA",
        "Y.1_(x}p",
        "k/wm_ B",
        "De!.CR",
        ">!>'>5>E>_>",
        "0.9M.",
        ";|$$t)",
        "kWKQKqK",
        "reIk)",
        "jfjuj",
        "ii|bVP",
        "(\\,l\\O",
        "AK6kDE",
        "2$2,242<2D2P2t2",
        "WwhRDW.",
        "0[P\\ ",
        "F$nVf",
        "bN*TP/",
        "yQRWN",
        ",j4=j^",
        ":)UoI\".",
        "ssl_session",
        "0\\1a1[2",
        "D$L9t$",
        "vrjhB*",
        "+6R95j\"\"wxlD",
        "4z(\"p$",
        "+3d*s",
        "QKQlQ{Q",
        "Mom~^",
        "9?!B|h",
        "U?)od",
        "cGETT",
        "a,$yi",
        "r,HD&",
        ";,;0;H;X;h;x;",
        "L44Bs",
        "W6a3W",
        "4dr\\0",
        "S|JOT",
        "AntiViral Toolkit Pro",
        "SFM&FB",
        "9R(.\"",
        "ix.>Zq",
        "-)Jm4",
        ">^BV8UU;e",
        "Failed to save key to ",
        "j'bbc(",
        "8+909M9Y9^9y9",
        "PN~b$",
        "CVTDQ2PD",
        "\"2_U:J",
        "ccT]v",
        "RYA+i",
        "\"pCDu",
        "|& ]]",
        "<8<H<P<U<`<",
        "J3/t{",
        "DW,~\\l",
        ";V;g;",
        "_lemW2",
        "U3.!a",
        "%s\\CheckPoint\\ZoneAlarm\\vsmon.exe",
        "zo~?j*",
        "?&?Y?`?",
        ">X>x>",
        "\"rg/%",
        "!5`6@",
        "The entire document is already downloaded",
        "[VSSHUTDN] LoadVSData(%s)",
        "QVhR^",
        "%.\\O/",
        "Vl<TW",
        "949d9",
        "hF,te",
        "`local vftable'",
        "::u-y",
        "343d3",
        "?!?8?M?d?y?",
        "3Kpe*]P",
        "sXpUu*_9",
        "CleanLegacyFrameworks.E4CDA224_53CA_4F07_890F_38C80EA13002",
        "mmpqtV",
        "~!/M!",
        "wrtV=",
        "9ZXuy/j",
        "tSSd]b",
        "t3WhD",
        "(L#18",
        "aGXQ+",
        "E~.}M",
        "@P[CD",
        "HsKXS",
        "~~zG==",
        "2ALo<~X",
        "EnableDisableSDL",
        "888O8V8u8",
        "4\\5b5k5q5}5",
        "k#i;.",
        "$4|e-+",
        "/9n2Z\\",
        "spanish-puerto rico",
        ":(a@~",
        "W]MVL",
        ".\\crypto\\cms\\cms_io.c",
        ">$>J>v>",
        "`h_<<`g",
        "L$(S\"",
        "ssl_cert_new",
        "0'=>d",
        "zA%}&",
        "5'555D5U5c5n5",
        "T )S'J",
        ")=@ZM",
        "u9<)S",
        "jwj(T",
        "|c`BA",
        "2r2~2",
        "u|Re:",
        "spanish-peru",
        "1L.a;",
        ".2UUW",
        "m/S:g",
        "4Z4[4\\4]4^4_4`4a",
        "c]?#8",
        "mK^T-~S",
        ",*3ph",
        "Pjpj%",
        "9+:Z:",
        "fb1UZ",
        "_o3g\"au",
        "I5IUIuI",
        " e.&(",
        "Q8xpd",
        "LLLLLLLLLLCR~@",
        "G3\"5?2X",
        "Rw,X]",
        "0vN_6",
        "`Yl;5",
        "Kv$pTP",
        "RSA_generate_key",
        "`?myWH1_",
        "=[~O~",
        "AEBd0",
        "F#c$z",
        "32`d%",
        "um4,l",
        "/N6pYLdH,",
        "k`Uxj",
        "<A|2<P",
        "o: K`",
        "k 8k*0",
        "6\"6O6z6",
        "\"ModulesInStack\": \"",
        "DH-DSS-SEED-SHA",
        "\\lsdunhideused1 \\lsdlocked0 Table Simple 3;\\lsdunhideused1 \\lsdlocked0 Table Classic 1;\\lsdunhideused1 \\lsdlocked0 Table Classic 2;\\lsdunhideused1 \\lsdlocked0 Table Classic 3;\\lsdunhideused1 \\lsdlocked0 Table Classic 4;",
        "sG[%fr;",
        "/4G#V`zR",
        "G[SvQ(",
        "]tEZz",
        "U:H{x37'",
        "<C<J<R<`<h<",
        "OOf$Yz",
        "a.dXK",
        "o DQj",
        ",`vuV",
        "PKCS7_FIND_DIGEST",
        "Ok./0",
        "\"fTkl",
        "`OSt13",
        "(m,ON",
        "?$nl9",
        "w.A/)",
        "/d}G\"}",
        "g>jg'@i",
        ">Zu j",
        "Gl8.4",
        "_thyP",
        "kKRB5",
        "0p8<MZG",
        "^dd%B_",
        "607D7H7X7\\7l7p7",
        "DRqTv=KFeSP",
        "PRODUCTNAME_NOT_SET",
        "i)=&Pav~y",
        "CMS_RECIPIENTINFO_KTRI_ENCRYPT",
        "[VSDATA] AddDataClient: DeviceIoControl(DIOC_PRODUCT_VERSION) version=%s.",
        "d~7iV",
        ".?AVFeatureTVDriver@@",
        "MM'Z;",
        "\\sbasedon10 \\slink9 \\slocked \\ssemihidden \\spriority9 Heading 9 Char;}{\\*\\cs24 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\ul\\cf2 \\sbasedon10 \\styrsid13193413 Hyperlink;}{\\*\\cs25 \\additive \\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\b ",
        "U$|}i",
        "System\\CurrentControlSet\\Services\\vsmon",
        "Y>!cK",
        "C=e?:",
        "lp<~6'!",
        ";';6;>;Z;",
        "inoTDC",
        "libcurl/7.49.0",
        "bz.>a",
        "v:_+Ya.dh",
        "~|q:D",
        "<ASN1 13>",
        "+U.Ce",
        "?<?H?h?t?",
        "\\f1\\fs20\\insrsid11798905 You when}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11798905\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 opening the Support Service Request}{\\rtlch\\fcs1 \\af1\\afs20 ",
        ">\"0>Rx",
        "qut@\"",
        "=O=':",
        "<ASN1 11>",
        "AnGxw",
        "NJ  4",
        "?1?D?L?S?",
        ",#f@x,",
        "[VSSHUTDN] DriverSetProtectionCtrl: call failed - no hDataModule",
        "Sufx ",
        "=]`n3",
        "Be.+Y",
        "t;;t$0u5",
        "1\\a{.",
        "Failed to set AllowProcessStopService registry value, Error: %d",
        "Z>46iI",
        "Qh(Z#",
        "f6tu!8l",
        ",J*Nj",
        "*b9>6",
        "CLEAN",
        "R6030",
        "BX/I{",
        "Ignoring duplicate digest auth header.",
        "Sv>%X",
        "VtDv8",
        "<cYq;+",
        "UxY%U{",
        ":+MqP",
        ")W^]K%",
        "`W<uB",
        "<P@4.",
        "&/gDP",
        "CleanLegacyFrameworks started",
        "\"}LK$",
        "=4{L3",
        ">PTp},",
        "Jb9JX|h",
        ".+%ZHQMa",
        "cts with the export and reexport restrictions applicable to the Product and will otherwise comply with the EAR or other {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States{\\*\\xmlclose}{\\*\\xmlclose}",
        "OPENSSLDIR: \"C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/ssl\"",
        "3&3B3^3z3",
        "`VN+2",
        "c$Zdwa",
        "gZE )",
        "M`^SO",
        "=I'JR",
        "h7>MJ7\"",
        "I`ETR",
        "6n<TQP",
        ">$>0>P>X>`>h>p>x>",
        "4:4O4\\4e4j4}4",
        "zJ}P5",
        "QPeA~S",
        "~4QSVa",
        "374i4x4",
        "YJBoh",
        "(;SeZ\"",
        "Removing cppol archive...",
        "B,xLl",
        "u)j~h|",
        "s>HeD",
        "$F^d6",
        "jv\\i<ouO",
        "F88B01B9-24CF-4242-AAB4-59C0723BC03C",
        "{b;+G%",
        "+AQ6>",
        ":z ](",
        " 0xe5",
        "3WZ6Z",
        "CS9 ~}j",
        "Wn6X[",
        "9KqCa",
        "SYSTEM\\ControlSet001\\Control\\Session Manager\\Environment",
        "'UO4h",
        "uIc.t",
        "/4[tx",
        "rW!dg~xc",
        "P:z0<^O",
        "c[%rKY![x",
        "F.Dm'2E",
        "3KEod",
        "//a~q",
        "w:im$x",
        "7$7?7b7",
        "KR[%j",
        "generic-type-",
        ",K,vN",
        "H|<^JaQDr",
        "EnablePolicyView",
        "Ov(A|",
        "@^i[z%",
        "<\\<q<",
        "O%D,72W",
        "H =@$@",
        "Failed to get SID; skipping account %ls",
        "h^xnO",
        "^*Oyf",
        ".?AV_Node_base@std@@",
        "bbbbbbbbbbbbbbbbbbbbbbbb",
        "string=",
        "EPClientUIService",
        "404@4",
        "*>HD@",
        "WideCharToMultiByte failed. Last error: {}",
        "7F;U;6<E<&=8=c?",
        "4,ES#Kn",
        "xJ:Z`",
        "B0h[@",
        "u&_^]",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 4}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5010868 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        "t$8VS",
        "WJWLWN",
        ">E>L>T>b>j>",
        "KillEpabProcess",
        "r,v~?-",
        "Archived %d bytes in %s to %s",
        "<!<+<><C<h<n<t<z<",
        "tW+c7",
        "hoEHj",
        "SQs!3",
        "WR/<.",
        ".vGZq",
        "5:<&56",
        "4F4L4V4a4j4o4u4",
        "FH#~4",
        "y7@e bE",
        "huif*",
        "WKKdS",
        "aw/5!jZ",
        "> >$>(>,>0>4>8>D>L>T>X>\\>`>d>",
        "1-v6t",
        "\"kv/I",
        "'GY@2",
        "ad#6+",
        "IZ)ThE(,.",
        "-x[+:",
        "W#8&&",
        "k_h\\z",
        ":eBu'",
        "9Sod9",
        "GetDIBits",
        "8p\"@J",
        "TDiT*",
        "uu;UPn",
        "\\f1\\fs20\\insrsid5000668\\charrsid15169477 B}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 efore Check Point or its partner exchanges a}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11303137  }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "w?gq'",
        ";rR>l",
        "-y[}:",
        "[}By[5e]-{{",
        "l$(%@",
        "'0'tO\\N",
        "PerfUnregisterStateChangeCallback",
        "regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.",
        "212?2",
        "@P 6p",
        "3 3(3<3D3L3\\3h3p3",
        "8!9;9C9S9~9",
        "do}NP",
        "d PpWS",
        "$NIK8",
        "K](Na:M",
        "161(c|b`",
        "LSM}'",
        "tA$zD",
        ".4P5x6",
        "l]?[n",
        "aW-X8g",
        "4Oplq",
        "uOT](r",
        "$_^]3",
        "N$8jn",
        "*YX{d",
        "#7jwG",
        "Zy3{$W",
        "2m3x3!4)414E4^4i4",
        ";!;:;q;",
        "GET_CLIENT_FINISHED",
        "_0?,H.q[K",
        " NNZ:6",
        "b{ewV~",
        ">yC%&",
        "%Ye6Kj`]",
        "Iwwqkq",
        "SNxw|",
        "Configuring SmartDefense settings (4 of 6 tasks done)",
        "O=7Ch",
        ",<xRM",
        ">!>(>5><>",
        "p&B =",
        "p9F`Zq=L",
        "PWhHj#",
        "tZhVG",
        "nN6\".:)",
        "]rHiK#S",
        "vNJz ",
        "Yxu5`",
        "&s;}N",
        "#9\"l'",
        "}=}E4O",
        "<,L 9",
        "ex7kq\"M",
        "1kz8R8",
        "@jI+BGp",
        "QPcoV",
        "u5_]^[",
        "PRQVSW",
        "y.v{@",
        "KZ}\\kFP",
        "U;,%<*",
        "es-j\"",
        "Error in the HTTP2 framing layer",
        ":^/WTVEI",
        "KwI{]",
        "id-GostR3411-94-with-GostR3410-94-cc",
        "I~t\"h",
        "b{.Oq",
        "lOyl^",
        "o$,*nZ9GIQ@",
        "||e%k",
        "1VjP\"",
        "PKCS7_add_crl",
        "=NZ3e",
        "fx&wi",
        "gp/a(",
        "\\@xvb",
        "e *bd",
        "K-571",
        "HW%<<5",
        "GetConsoleCP",
        "W$%T(H9:",
        "&gNT.",
        "+X!X;",
        "k]4[r4E",
        "f'#__",
        "'b<Z;8",
        "7zaHw",
        "?+q 6",
        "Q5F\"6",
        ",>Ps/",
        "hH@t$",
        "\\par }}{\\*\\aftnsepc \\ltrpar \\pard\\plain \\ltrpar\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid15298478 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "^Ui*n",
        ")3~8Z",
        "2h,Hg",
        "d########'#",
        "EV}T?",
        "Hf91u",
        "/ATX7",
        "TS_TST_INFO_set_msg_imprint",
        ";P<!=4=",
        "7 7$74787H7L7\\7`7l7t7|7",
        "?:?V?r?",
        "WsxE%*",
        "8XtG`",
        "R*<lJ",
        "$?%XY$",
        "o^,Rs",
        "Vj4Jq|",
        ")k14Ha4bV",
        "*02CKR",
        "8\"82878<8L8Q8V8f8k8p8",
        "5q5w5",
        "B=>B~",
        "Exception caught in SetProperty()",
        "?&N3=-",
        "!m&EQL",
        "YuoxJ",
        "dvUR?",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\event.cpp",
        "d*_d_",
        "/Yc!s5Y",
        "B^1}Yt",
        "finish.png",
        "]79tN",
        "failed to set application exception edgetraversal property",
        "1:1b1",
        "m/\\$a",
        "qn1QG",
        "222I2=?",
        "vu' I",
        "sDC4>{r",
        "61oE f",
        "sect283k1",
        "4+gWp",
        "7\"MVHN",
        "$/OYl",
        "<z<Op",
        "aWolK_",
        "d>FRd(|J{",
        "\"{df\\",
        "SYSTEM\\CurrentControlSet\\Services\\DNS\\Parameters",
        "%cU3r",
        "+OR60 e",
        "HxPou",
        "F*gEv",
        "t%(+u",
        "Mu`H(",
        "SOFTWARE\\Classes\\Installer\\Products\\3CEF7BE31A8A3AE4F8E4A8D671289E7F",
        "dingo_SC_type.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "$Mj0Q",
        "3ZZ?`\"",
        ".?AVptree_error@property_tree@boost@@",
        "8K4tF8",
        "ofsM9",
        "qP5QB",
        "f1<`~@",
        "HHTP^u",
        "u]8b>@rG",
        "<d]?##",
        "Rv/.|",
        "CHPVUU",
        "QM5xs",
        "^kW*-/s",
        "dhSinglePass-cofactorDH-sha256kdf-scheme",
        "5b2-Z",
        "POLICYINFO",
        "Z,[.K",
        "U8HN$",
        "}^\\Ye",
        "WN_%w",
        "EBw]Q ",
        ";#;7;F;",
        "WSVRQP",
        ":Xq)W3",
        "?!?(?/?8?J?Q?X?l?s?z?",
        "server requested blksize larger than allocated",
        "Bitdefender is installed at ",
        ">m+y6t@",
        "<5<H<W<^<*=T=",
        "N(y!e\\",
        "5l@ge",
        "f`0ioE",
        "4h}Ru",
        "@:QSvAzh",
        ";8~z]0",
        "D9g*:U:",
        "$vv&y",
        "\"\",nx",
        "qm!\"X",
        "UQEUTE",
        "CRW=W",
        "?<4Je",
        "a\\o ]",
        "reboot_file.log",
        "9 9$9,9D9T9X9h9l9p9t9x9",
        "i\\]I#",
        "9w:P;z;",
        "jn%Of",
        "X]\"&Gt$",
        "\"q8X-",
        "=3?V?b?",
        "m3/}l",
        "7S\\6M",
        "vWb=M",
        "W)[=*",
        "m\"NeD",
        "wMWP)y)",
        "?+xt\"",
        "4?4a4",
        "RIPEMD160",
        "\"|xQ,",
        "g<jHM",
        "a6vBVMY",
        "2-2:2^2e2t2~2",
        "{8!F;1./V",
        "[tP*C\\",
        "4D6CL",
        "MaxNumFilters should be increased",
        "~3b,pV::",
        "i2H]~",
        "4Ny-B_7",
        "N!Fk)q",
        "iu@D!",
        "<r\\5?z",
        ". Check Point has no obligation to provide support, maintenance, upgrades, modifications, or new releases for a Beta Product. Owing to the experimental ",
        "8ec D&",
        ">&>->W>]>h>",
        "3#4q4",
        "B5b',mYXJ",
        "}AaXBL",
        "14@mAP",
        "E|[Ksd",
        "[X1sO",
        "|}? /aw0",
        "*#qX8",
        "wN%$l}",
        "Certificate:",
        "}<Nhb",
        "8M:J9L9",
        "di?}bZ?",
        "9%9H9b9",
        "um9.u",
        ">Z1bC",
        "060O0h0",
        "guUA_",
        "}-UU,&/",
        "FO0K{",
        "(<>`5",
        "nML*q(",
        "Vn\\NU",
        "NYT\"6",
        "0Lq:c",
        "rNhMr",
        "nY+ 9",
        ",|S,a",
        "uV`+h",
        "E\")Ia",
        "GKNKSKkK",
        "W^&^M",
        "b{}{48\"j",
        "5@*wk",
        "e|!ey",
        "arg2 lt arg3",
        "ImZ,@",
        "[H(u/u",
        "oom'y{",
        "(@\"+S",
        "Call would block",
        "vRU&O",
        "DES part of OpenSSL 1.0.2h  3 May 2016",
        "o%%Jr..\\$",
        "293I3",
        "Lrgjt",
        ":}Gvb",
        "vector<T> too long",
        "WTSQueryUserToken",
        "7GKUin",
        "%Qro<",
        "7 70747D7H7L7T7l7|7",
        "898K8S8q8|8",
        "/8 sq",
        "D$7QP",
        "`5:^K",
        "LPg&Rd",
        "&s/c-+",
        "rM9_ vH",
        "9_;n;",
        "~?`>d",
        "j\\Xf9FHu",
        "MXLd[",
        ":1:^:",
        "1 1$1(1,1014181<1@1D1H1L1P1T1X1\\1`1x1|1D<L<P<T<X<",
        "tr-tr",
        "oojno",
        "s^#*50",
        "dM0M5",
        "`C:/'",
        "B8;5c",
        "+RtXM",
        "failed trying to find existing port rule",
        "replaceOrAddTagIntoVSConfig;",
        "SEC_E_UNFINISHED_CONTEXT_DELETED",
        "*d.8CQ",
        "vMmw*",
        "e7t1~J%}",
        "z%bRq",
        "1G6./",
        "ixiv~~",
        "i2d_ECPrivateKey",
        "ZM<hJ",
        "RcHq<",
        "[,w^F",
        "YljmA",
        "AEku{",
        ";><R<",
        "[R{wO",
        "]\"mXZEf",
        "; ;g<",
        "SOCKS5: no connection here",
        "i%g\\I",
        "G|;^',33",
        ".?AUIAtlStringMgr@ATL@@",
        "RegisterWaitForSingleObject",
        "OBJECT",
        "kimFP",
        "PSPECIFIED",
        "call to empty boost::function",
        "EAdhh",
        "#KOZG",
        "53rhM1#",
        "type not compressed data",
        "$ID#U",
        "M1Pw#k,",
        "AE7%\"",
        "'y\\7I",
        "$n3Gz;",
        "778B8K8T8Z8",
        "T*$99E",
        "vDuvR",
        "D3TD5",
        "sR@C5>C",
        "x,69Sj",
        "Failed to get active DB",
        "SEC_E_REVOCATION_OFFLINE_C",
        "~${em",
        "@Mz!s[",
        "~DD4jv?K_",
        "D$Xj SP",
        "?Ui\\D",
        "TNC_GROUP",
        "X9-57",
        "0#YfH",
        ":mbro4",
        "l2'{u",
        "M:b:!",
        "keygen failure",
        "NdMS$",
        "d?G(=",
        "O<8m%",
        ".\\crypto\\bn\\bn_mont.c",
        "VAjXs",
        "u,XYj<N",
        "Ni-8Z",
        "3D$03L$,",
        "?%?6?=?e?m?z?",
        "obE+,",
        "Bh,vQ",
        "*F_l\"",
        "Can't remove directory with RemoveDirectorySilently function. Error %d.",
        "QV(r-h",
        "656F6[6`6",
        "H>bC^w",
        "\"Hgtl/OJ",
        "b9\"AK",
        "cpda.exe",
        "VD`_5",
        "1@2J2",
        "\"n)!J",
        "Descriptor is not a socket",
        "Z.sr@",
        "7LbzC",
        ";A;`;k;",
        "Ibka:O&",
        "IAh.DE",
        "F$_^[",
        "?]OPS",
        "dFu>U",
        "#bu21",
        "(D$;{",
        "`p9;S",
        "CAMELLIA_INIT_KEY",
        "^6Mr2",
        "=xKl%",
        "05`eT",
        "_gk;)f",
        "B.#La",
        "t|=Op",
        "CF~R@",
        "(x_\\}",
        ".?AVFeatureAntiVirus@@",
        "lI&QN\"x.",
        "HKWm%~m",
        "++x{3m",
        "#$Co0",
        " E.^/",
        "37f|}",
        "qd`w:",
        "fOuH[",
        "SOFTWARE\\KasperskyLab\\protected\\AVP8",
        "+kqojk",
        "ux~<n",
        ".J{)m",
        "T[i vS",
        "awc>/",
        "sect113r2",
        "I=']q",
        "dml@\\",
        "5N'yvu",
        "}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Sudan}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid9048298 {\\*\\xmlclose}{\\*\\xmlclose},}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "oPN s",
        "Q],B;eP",
        ".?AV?$basic_altstringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@io@boost@@",
        "t$HPUV",
        "T_jhW",
        "I>'B;",
        "X!9 ct",
        "FS_+P",
        "~}MN5J",
        "IxeBc",
        "2'*, s",
        "3?3I3S3b3l3",
        ":TrJVR",
        "unwise.exe /S INSTMLF.LOG",
        "/n?!<O",
        "W$'vP",
        "ZoT11",
        "4!.AC5q)",
        "Couldn't set desired mode",
        ">T>_>j>o>t>",
        "R,R-R.",
        "FUCOMPP",
        "kz+~on",
        "me0K,",
        "sl-si",
        ".1'>|",
        "9r848",
        ")+BD#",
        "Wya+j",
        "E}0%g",
        "[]r7p",
        "BQSr=",
        "<7%X8",
        "PMOVSXBQ",
        "S<aUA",
        "%Kg+i",
        "V$-Knh=",
        "F$_K-1u",
        "?9?g?",
        "{nGdUM2/",
        "g;P<:vp\"",
        "pU%6g",
        "M3U&6P",
        "KWSn/2",
        "7H8a8n8",
        "w jZZf;",
        "3$3,343@3H3l3t3",
        "aS_dP",
        "O?[4y",
        "x *P)",
        "@cWLm",
        "CertCompareCertificate",
        "V@W=J",
        "9M!\"n",
        "[;<8d",
        "Y?0=HZ",
        "LangPack1.xml.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "zr!]UoE+",
        "=><N?",
        ":~+9`>",
        "8A.0CY",
        "7z2#p",
        "Z=,6(u",
        "#bLIW",
        "T/p%(",
        "@6]:Y&",
        "Pw%\"]",
        "!pjBS<",
        "qpL*v",
        ";@Uw|",
        "ppLt05",
        "K6 y 5d",
        "7'_@SC",
        "6\"7[[",
        "$}Wgo>",
        "VvjzYIZV&",
        ">d`D$",
        "client_sub_type is not as it should be '%c', will be rewritten",
        "6?/!O",
        "B?}fB\\",
        "Wsd!X",
        "Tf%.|",
        "pDw<l&(gR",
        "@N}i&I",
        "IR?r%)-",
        "\"v: .,",
        "495f&\\",
        "j$SV3",
        "pQ5nFO",
        " EX$C",
        "A]BLR",
        "'i_O~v",
        "r}nirD",
        "CS:EIP:%04X:%08X",
        "UNUSED_5",
        "GetLocaleInfoA",
        "+L+8*<V",
        "x:`k6^",
        "WlhM\\",
        ";,<[<",
        "ASz>l",
        ">RRD0",
        ";E1{8",
        "2*$51",
        "-\"0K^",
        "3BO 9",
        "ECDHE-ECDSA-AES256-SHA384",
        "7+717>7M7S7^7m7s7",
        "2r^NU",
        "z5W:|f",
        "535N5v5",
        "_yvyc",
        "x\\-:P",
        "733CC7E9883605E448B30F4523FC043E",
        ",$7Rp",
        "/<FoU",
        "{W>2T",
        "GetTokenInformation failed, err=%lu",
        "<F=U=6>",
        "DJqUH",
        "id-it",
        ":8<u<",
        "M5xL(j",
        ";pjTY",
        "wI@BI",
        "A%u$d",
        "iPMq<",
        "H0hQ4",
        "ft\" cB",
        "Y^Pg&a",
        "GNoFy",
        "8+8G8c8",
        "A,x`=>",
        "txp#&",
        "~8nmA",
        "=='=%=b",
        "T(Ea{",
        "\\p'CEW",
        "pH>\"}",
        "]ujxQ69",
        "DSZ\"_",
        "B1x`L",
        "WV{*[6",
        "z%A*\\",
        "LTcTZ<",
        "dhSinglePass-cofactorDH-sha384kdf-scheme",
        "ECDHE-RSA-AES128-SHA256",
        "9)9d9}9",
        "xSw9)R",
        "\\bin\\SR_WatchDog.exe.delete",
        "|{A0)",
        "L`Sc:?",
        "y1h0|",
        "A+X$[",
        "w3R!\"i",
        "El5E}4",
        "|F7YJ",
        "VZ,=U6",
        "Qkr2q7;",
        ":+:b:",
        "IsRebootSuppressed:  ReplacedInUseFiles=",
        "D(LGSbd-5+w",
        "cYlg,",
        "747>7M7T7f7",
        "mf:E)",
        "aMs{E",
        "VN2q1Ju",
        "07X!8",
        "BzaHO-&p[",
        "f\"\\@ nm",
        "^G3,Q",
        "n:V5l",
        "{YR3t",
        "%bR!9j",
        "FeatureIMSecurity:  RemoveAfter finished.",
        "9N9\\9k9x9",
        "x`}P<~+\"",
        "&i}WI",
        "l+qe|v_",
        "nk0tr",
        "#F`]{",
        "&cat1o/y",
        "I~Y~6",
        "nywWPVi",
        "*[a.:",
        "+}Np* ",
        "Lt3M}K ",
        "2?l~l5",
        "h\\ N<3t",
        "<-=m3",
        "}VhT?",
        "9~NNO",
        "DSA_generate_key",
        "[g/fFF",
        "U~N(X",
        "uAZHi",
        "GBQvo",
        "?D%M$",
        "b;0x%V",
        "738}8",
        "J9aDq",
        "|c)9i",
        ",>3Rk",
        "ikD1m",
        "Ha&8M{",
        "=$=H=h=p=x=",
        "I%;Mj",
        "bfff0000001c0200001300000000000000000000000000000000005b436f6e74656e745f54797065735d2e786d6c504b01022d0014000600080000002100a5d6",
        "EK9!~",
        "*O$R ",
        "f6:\"b",
        "n%2Vq",
        "\"\\.zD",
        "* CpZ",
        "FFb0La",
        "[V9An",
        "5.5?5Q5l5",
        "2*3G3O3a3~3",
        "y-,ww",
        "#~x/[F",
        "Exponent:",
        "6].A-",
        ",D?gU:",
        "ovUwC-",
        "zT[d'",
        "?>3~l",
        "->'lm",
        "m/kUye.R",
        "NT7`Sc",
        "D$<1D9",
        "2V7yr",
        "1f1z1",
        "{83w}V",
        "UVsonj{e#",
        "pv`PEa",
        "v1EQ_b6,",
        "RSA_NULL_PRIVATE_ENCRYPT",
        "d'G?L",
        "OpenThreadToken",
        "0F0l0{0",
        "FP=G!8",
        "~0sOF",
        "$J|oa[",
        "tsSme",
        "1Sn<W",
        "[$;_J",
        "\"=3OO",
        "Remove cptray auto startup registry value",
        "<E=O=l=}=",
        "[sF%W",
        "\\a1[b",
        "}?To?",
        "8y\\Rl",
        "mI`T4!j0",
        "q~sDn",
        "4c0:tO%",
        "x@SVW",
        "bad ecdsa signature",
        "\\M}/qx",
        "RI-5b",
        "{{{{{{{{{{{{x",
        "!5HMNS!_Y",
        "?+?H?V?o?w?~?",
        "UpNm5?",
        "6%6U6^6g6u6~6",
        "3&353U3s3",
        "I=xv@",
        " 0x5f",
        "!nNI\\+",
        "3?r2_",
        "$}?GB",
        ":BIaX",
        "@UWU&",
        "v/jpi;f_",
        "`[mlaB\\r|'",
        "k2c\"9",
        "ERROR - CLIENT_SUB_TYPE property not retrieved",
        "krb5 server rd_req (keytab perms?)",
        " S>[X",
        "qA\"H,5",
        "I]PGMfS",
        "o3^{W",
        "\"RP?@",
        "?T9gk",
        "?)?J?",
        "?!?(?-?C?H?",
        "\\6g9C",
        "(G/0TD",
        ":cxLE",
        "~,;Oy+",
        "+k]>K",
        "VT^ij",
        "00000021000dd1909fb60000001b0100002700000000000000000000000000b20900007468656d652f7468656d652f5f72656c732f7468656d654d616e616765722e786d6c2e72656c73504b050600000000050005005d010000ad0a00000000}",
        "%C=u)",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5995582  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 and Bureau of Export Administration. You warrant that You will comply in all respe",
        "\"ST;6",
        "x-R2nx",
        "4Bh~p",
        "[/u*sEI",
        "#u[c]",
        "3XRS+,",
        "t\\aMZ",
        "J[Q_QL",
        "CpPolArch",
        "'U#hx0",
        "j(/%{-\\;",
        "&2twG",
        "JI*`&",
        "UDWE^fO",
        "f9Rl&",
        "<m)iXa",
        "yhFN$",
        "^iCdz",
        "w #wB",
        "<$=(=X=\\=",
        "XSC]1",
        "ogf\"Z",
        "@d%sP",
        "WPh`5#",
        "B22bq",
        "t_w=$N",
        "bb\"c;*",
        "NIST/SECG curve over a 224 bit prime field",
        "(kdw?",
        "*p[[[[[[[[[[[[[[[[",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 9.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "8ub)\"\"",
        "101@1D1T1X1\\1`1d1h1p1",
        "f@7dr",
        "k:\\(2~",
        "CMS_SIGNERINFO_CONTENT_SIGN",
        "B>.xe",
        "4&484k4",
        "5,5H5d5",
        "/n7c%",
        ";F<U<",
        "hcOW{",
        "Q)bTh",
        "#9|\\D",
        "iN,Bf",
        "o}TK(",
        "t$(hX]!",
        "CryptMsgOpenToDecode",
        "t`WVS",
        "Kaspersky Anti-Virus Personal (based on version 5.0.676)",
        "The max connection limit is reached",
        "f4xs{r,",
        "4@ eon",
        "5=@?P",
        "s3V*t",
        "a;2}s",
        "Xp&?D ",
        "zhpV!",
        "Yippg",
        "[+=sH",
        "(o]Uo",
        "~S]wi",
        "3kz|p_",
        "^>Y:v;D",
        "\"!2c.",
        "xYOd8p+",
        "5YB-]",
        "SJx4)",
        "v!UHJV",
        "bG>a{",
        "J;l$_S",
        "uW{%yU<",
        "pA_a4'aB^8",
        "B`QAm",
        "^huzg",
        "@0h0o0v0}0",
        "='=1=K=R=a=o=",
        "263Y3g3v3",
        "zt45@",
        ".eD(@H",
        "lNyY@",
        "475C5Q5d5",
        "1H1S1b1",
        "*~66V:9",
        "C#\"}7",
        "364G4T4|4",
        "s?6Z)",
        "oV~]}",
        "i~<w^",
        "tBHt;",
        "7+757",
        "NfDU%",
        "n>?jZ=1",
        "TX|O^",
        "9?:l:",
        "failed to get XmlConfig record Id",
        "7jE $",
        "?jlkhlh",
        "R4?}y",
        "bq\\,J*",
        "id-aes256-wrap",
        "q?hS6W",
        "VY|}/*5",
        "<#JYQY",
        "4BjO:",
        "functionality not supported",
        " micalg=\"",
        ";6<G<h<o<",
        "V(d:Fo",
        "b(\"Nc",
        ",`,xz",
        "saT4?",
        ",&Z*Z",
        "Yi^!4m",
        "4l]2d",
        "+0=&X<)d",
        "Bud3/P",
        "7!8I8q8",
        "H68yu",
        "T6OmN",
        "rra+x",
        "FzdlO",
        "58Lr&",
        "|*A*sY}",
        "eZ>Y|",
        "A&$&Q",
        "*4LWxzA?",
        "(}OJG",
        "B?d?+",
        "`qE%W",
        "yk>]S",
        "#Y,l[>",
        "Yj=.nW",
        "dzW/_",
        ":$:0:P:X:`:l:t:",
        "2{+3k",
        ")j\"Yf;",
        "pCiyI",
        "&bFBx'",
        "zQU1+eR",
        "4,4<4H4P4",
        "$\\#}F",
        ".\\crypto\\asn1\\a_set.c",
        "FDA~i",
        "lS7/b",
        "O[:EG",
        "D] [V",
        "[wm<Z",
        "B*Bk/",
        "JYvOn",
        "G<Kv9",
        "L;> (",
        ",;k9a",
        "FIPhg!",
        "<m}p'",
        "&,.Fan",
        "L$H[3",
        "c2tnb239v1",
        "\\database\\userc.c",
        " -Dh^84\"u}",
        "&amp;",
        "setPropertyInCachedMsi",
        "]]t9z",
        "3L$P3L$43L$,",
        "pS.Xo",
        "D>ZU]",
        "iVRhR~",
        "INSTALL_START",
        "QF&Hi",
        "u!SM[",
        "CfgMain",
        "VDDQ%",
        "g(FBD",
        ";_tQB4",
        ").._p",
        "MV<8&",
        "+4h.\\R",
        "Bv2jC,",
        "FDwH]V",
        ":@4MI",
        "*?SOl",
        "\\t<Zh",
        "7 7@7`7p7",
        "|z'TL",
        "de:6Y",
        "4(TU g",
        "|zu&1",
        "?'?7?e?u?}?",
        "\\installUtil.exe\"  -d -r",
        "!*=NG7",
        "_kooup",
        "p-s3.",
        "8eE;f",
        ">M>Y<",
        "kN[Lz",
        "py5kj*J",
        "ui level is 'Silent' -> do not launch message box 'restart' message",
        "[aOni*{",
        "7i!n*",
        "5X,=W#",
        "!/P8j",
        "5ipza? ",
        "%s. hDatabase: %d. Result: %d",
        "error in thisupdate field",
        "2`2v2",
        "E#Pz0W",
        "TKTWTgTnToTyT",
        "-f$oW",
        "1@2t2",
        ".\\crypto\\dh\\dh_gen.c",
        "RFR;S[y,",
        "8r[(B|",
        "bsYt!s",
        "sEp<niVv",
        "qtq-jTu",
        "r}8%D",
        "LqM&XW[Mp",
        "F*W.sW\"KQE",
        "aUrpc\"",
        "e}ehO",
        "m%tOB",
        "HandleDriverInstallHang: vsdrInst.exe is not running.",
        " H#o[",
        "> >$>(>,>0>4>",
        "6%6@6Q6y6",
        "?'?m?t?",
        "`Ln8&",
        "2%2/292Q2g2%333i3u3X4",
        "failed to add table name to rollback CustomActionData",
        "\\)F|E",
        "Ev681",
        "RxG6y",
        "$;`og",
        "SPEc}",
        "X30tQu",
        "1#1p1",
        ">(>/>:>A>f>m>",
        "khvASkI",
        "u0jph",
        "_set_app_type",
        "t{}F/",
        "Ie \\@",
        "<B<Z*",
        "o/p\"4",
        "v)pEP",
        "*F}j~",
        "OCSP lib",
        "u eAL",
        "<ATHy",
        "4\\4`4d4h4l4p4t4x4|4",
        "0h2WO",
        "?[Hd7",
        "Bt/:5",
        "9TI+;",
        "0Hrhr",
        "C,'B8",
        "hdch+I;",
        "<&=K=]=",
        "!+&-5",
        ".7}\\e5",
        "W<sjnB|",
        "&x4K_",
        "cZ}Bm",
        "mac absent",
        ":3;c>",
        "HSUBPD",
        "SOCKS5 nothing to read",
        "^rE,`",
        "SJj|0",
        "yVvT][",
        "zVS>#",
        "]1]&r2",
        "iN9lc",
        "V0J+,e",
        "blksize parsed from OACK",
        "CNgN.",
        "fwKtAa",
        "OT^TR",
        " qSVc",
        "7 7$7(7,7074787<7X7\\7`7d7h7l7p7t7x7|7",
        "C (d6",
        "pka8l*p&",
        "?G&{V>",
        "13;kzi",
        "Chunk callback failed",
        ".Oe<5",
        "h#ll*|v",
        "mQa_m",
        "qJc2F<",
        "Si[q3",
        "9#9(959:9F9X9^9e9",
        "3(4L4",
        "5R6_6j6",
        "T<HyQ",
        "2 2$2(2,2024282<2@2D2H2L2P2T2X2\\2`2d2h2",
        "|wxyK}",
        "3H,3T$`3L$d",
        ".H5:[G",
        "setAttr-TokenType",
        "%*sOnly CA Certificates",
        "?QOl}",
        "B^=pO",
        "zt+VKT",
        ";+<6<?<I<[<a<h<q<",
        "O^ByS",
        "C:S=R",
        "ansi-X9-62",
        "?:?k?",
        "s:,Tm\",0",
        "Z|;7V",
        "2 3(343T3\\3",
        "e&DIR",
        "w\"$gm",
        "<%<X<g<",
        "f^Ur9",
        "nKHItg\\",
        "4$R@I",
        "$[MF5?",
        "UtL5\\",
        "_YeL)",
        "?'u`C",
        "`qOAF",
        "</assembly>",
        "K2raa",
        "PKEY_DSA_CTRL",
        "<[>c>",
        "Z4!C&",
        "q,F!1",
        "UOg]#Z",
        "jchTY#",
        "`hSjJ",
        "G@YZv",
        "n'Bn/",
        "[VSDATA] WaitForSingleObject failed. res=%d, error=%d",
        ";,;8;X;`;l;",
        ":V[bH",
        "J ~/V",
        "6=7M7X7a7h7",
        "7_G^b",
        "4<5_5v5",
        "?>^=Ybe",
        "wQn!*'",
        "x|>fJ",
        "Z!&J*",
        "$V9fD/",
        "?uaZ/",
        "t9@DJ*",
        "kW+PkP",
        "WaitForMessage",
        "3t$<3",
        "1l1q1",
        "PRNG not seeded",
        "$7sl3:",
        "V~KcT",
        "2h|hWu",
        "2v%7d{u",
        "qaJxc",
        "><>H>l>t>|>",
        "74787P7`7p7t7",
        "aY\\\\O",
        "36q.b",
        "/LTO0D",
        "SxRgW",
        "<<=F=",
        ";\"S6Uog",
        "13H}D",
        "4/464B4P4i4p4|4",
        ">QJwEV",
        "!)f0'",
        "V2I_IDP",
        "oH+u*",
        "SSnk:w",
        "?O?T?^?",
        "1!1|1",
        "D$HPUS",
        "Fp1bC",
        "Uz%et",
        "y-x%r",
        "{[bV<",
        "YYb05Fj0",
        "H('y5iL",
        "VKl5!",
        "=[[ic",
        "7}7,K",
        "9C`u99C\\t4",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\truevectorif.cpp",
        "$+?+Mat",
        "#T$H#",
        ">tIHZ",
        "?5N5p",
        "I>,RF",
        "RSA_sign",
        "<&<8<U<",
        "jN%Kp",
        "<K]fh",
        "7(7L7T7\\7d7l7t7|7",
        "?+\"q@",
        "\\B9c~",
        ",F7Bz",
        "~fQa3J",
        "N-Z4a",
        "l95gI",
        "`X@mdK",
        "(67dG(",
        "ga7'!o",
        "8T9#:W:",
        "zD&~=",
        "'vT:v",
        "6.6`6q6",
        "GDGQH",
        "/sD;tQ",
        "#`<k~7",
        "#AUNwY",
        "|9o%)#",
        "Xl6_F",
        "helper.GetCustomerNo() returned: %s",
        "vQxTAJ!",
        "N#+O}",
        "7\"zbL",
        "t$,SPh",
        ":0?4?8?<?@?D?",
        "`j{vxdl*K",
        "5=9Itd",
        "QJNvV",
        "Yt#\\&",
        "*!-:(",
        "ECDH_CMS_DECRYPT",
        "DefaultPolicies.exe",
        "/O # ,",
        ":+:5:X:u:",
        "BqN:D",
        "1pD8*",
        ".kNWq.",
        "GDI32.dll",
        "pxYzu",
        "n#I\\Am",
        "om77tu c\\b",
        "6C{62",
        "+xfO/@",
        "AM_INSTALL",
        "Y6^zW",
        "6*|+o",
        "m87HO",
        ",]E~E",
        "1B2L2i2s2",
        "CompPrepare started",
        "InstHelper run task:  %s",
        "=#>G>Q>_>",
        "LC_TIME",
        "Q;UnZK6",
        "N!L$1Y",
        "@gpL/E",
        "%c?F|",
        "=Ep!u)",
        "_ByKvy",
        "D(jI:",
        "%5nOx",
        "2YZHQ",
        "}v@hB",
        "BIO_sock_init",
        "^E%_NU",
        "HVB;X",
        "X(F\\-",
        "5!\\U$",
        "5#7)7k7",
        ":$:N:{:",
        "5$6B6_6",
        "?G0\\%",
        "gANQf/Z",
        "c.xXe",
        " 0xe6",
        ":w^@\\Wn",
        "w[~IO",
        "QAeBIu",
        "_~K|4<G",
        "pqQ-%ZB",
        "+j,Gr",
        "7MZ:zh",
        "Q:?~\\~",
        "jzhX=%",
        "E?FKP",
        "IJbjC;",
        "EfsF%",
        "w?Gh^",
        "#VT_]|",
        "(7PHB",
        " }7bD",
        "1HAK\"",
        "#QJTn",
        ".|!V)2",
        "5(5DY~9",
        "Keshv",
        "wP!fR",
        "x>@vS",
        "10eU.XJ]",
        "3?@W,",
        "6S9an",
        "&X`\"IUu?:",
        "\"iFLC",
        "Tk3zb",
        "%c%s%c%s",
        "CreateInstallMutex:  Unable to create install mutex.",
        "'b+3#",
        ".S;ys",
        "LaU&RC",
        "'Kv~Q ",
        "ssl2_connect",
        "!mWAr",
        "e\"U/O!;qx_!",
        "gTF%Y\"",
        "o%X<l=",
        "LwI\"g",
        "`coZ//",
        "r-pr\"`",
        "o@9NJFlw",
        "%tGW1",
        "EIEK0W",
        "]0Q1hK5",
        "\"Yuu=",
        "EEfW6F",
        ">&eGx1",
        "(jU~M",
        "&6mHE",
        "Y7Y/K",
        "1!1A1a1",
        "^~m'7",
        "-zb2]",
        "R6018",
        "hH g#Z",
        "))#U)",
        "Six)Rr",
        "G!ABw",
        "'l1\"Y8",
        "333333333333",
        "CreateThread",
        "ecc cert not for signing",
        "sDVte",
        "h1|Xu",
        ".?NdA",
        "KhUUQ",
        "]_go,C",
        "pY3yQU5",
        "S4V:g",
        "aMZ:?9",
        "*GvRy",
        "ssl3_setup_key_block",
        "UDZ8Q",
        "j\"$|*",
        "B]`:9oE",
        "3t$ 1",
        ":'3pcF",
        "D#,ksHy",
        "4'21#Y",
        "]t24Z",
        "WE-l;",
        "c;A<!",
        "P\">N[8",
        "_'DIu_&_,M",
        "jF[L8@",
        "K>Lw_1",
        "rm(cU",
        "R~#V6",
        "a<K|MK",
        "f[T5H7",
        ")*P%U",
        "A\\]eP",
        "bad psk identity hint length",
        "Yt>9}",
        "0B0r0",
        "CSCNP",
        "0Vu]lFU(",
        "SVo%:",
        "2Td(d",
        "0mejBK)",
        "PRQ-'z",
        "qLAZ'",
        "Ph+)G",
        "5ARd&q",
        "mo-jn",
        "~2jjO",
        "030L0e0~0",
        "x\"}@D",
        "9YU\\@",
        "NW)TR",
        "i 4tL",
        "E{koJe",
        "b`[-I",
        "dv8R+",
        "expecting an integer",
        "@.o'5",
        "fagEjE",
        "b@,fa&",
        "FeatureAntiVirus:  InstallShellExtension started.",
        "7 7$7,7D7T7X7h7l7p7t7x7",
        "F/&Sc",
        "{~)er",
        "pDrl>Bwr",
        "FSMS-",
        "44494",
        "|>)?I",
        "| E=i/",
        "jCjoj",
        ";;;E;T;Y;",
        "jM[Q2",
        ">([ }",
        "%~_Zf7",
        "Z&>Jg",
        "X+pQ&Vm",
        "gMKV(",
        "1TA6YWk",
        "selV)",
        "?2?G?P?",
        "TK7-b",
        "LDAP local: ldap_simple_bind_s %s",
        "`[hQ,",
        "/IB'O",
        "yEwI)HI",
        "1.151<1C1J1`1g1v1",
        "b[&^W",
        "*NE&+R",
        "=4JBr",
        "{xEe&",
        "cG1Z_\\",
        "'y,Ab",
        "f,u7|",
        "8P)WZw",
        "KC3-Rlf",
        "Pf|H-7\"",
        "+a(^X\\|W",
        "quR(A",
        "policy when proxy language requires no policy",
        "#DWPc-",
        "zeAHpt",
        ")W4}Ohv8,Zpq",
        "%iB+5",
        "id-it-subscriptionResponse",
        "x~S]Xh",
        "BN_BLINDING_create_param",
        "; ;@;`;",
        "0)0F0`0",
        "?tJrrq",
        "PinPad.png",
        "HFnd-",
        "#AnQc",
        "pT6wU",
        "{09^)",
        "0\"0;0T0m0",
        "zu'g#",
        ";(4j9@Y",
        "TvE0I",
        "RH}baz(",
        "syr-SY",
        "B_7a3RW0",
        "nwOw^n",
        "P0We0",
        "SVj/W",
        "+wgnx",
        "ka_-d",
        "+>jE~",
        "_:\\PY",
        "V<tON",
        "KPGQVt",
        "ZoneLabs\\av.dll",
        "$);|pK",
        ":8%^%t",
        "848<8H8h8t8",
        "__&mn",
        "D4$A!cB",
        "rtAy!",
        "{2(v)P",
        "N{C:}",
        "AQ63%",
        "BD_PATH",
        "naCRj{O",
        "Nwbbh",
        "k]`1.",
        "n-OpZ",
        "@e:XV",
        "Av]J ",
        "5'5S5x5",
        "=!2sfi",
        "~P8Z%",
        "EP7Q2",
        "of~iH",
        "w_1'k",
        "U$VEGUDEpD",
        ">I(eP",
        "QtQyQ",
        "2Qn!I",
        "}zTAuy7[",
        "jCj{j&",
        "ivSQQ",
        "@COWW",
        "DigiCert Assured ID Root CA0",
        "`CEwj",
        "\\5Lfr",
        "D$`+L$@",
        ":!VP8",
        "G)B-5",
        "0$0?0f0r0",
        "RulesSetPropDWord",
        "??bwZ",
        ">1q%'Y5",
        "M^)V?",
        "5#b9j",
        "wiCx[",
        "<5~<tb_",
        "Ir${J1u",
        "ZBxMc",
        ".;tJ?{*g",
        "{*2%Z",
        "g0UKg[",
        "%~epI",
        "9V:.;",
        "fxE8gX",
        "?,?E?^?w?",
        "*'3BC",
        "XDvn{ob",
        "e&p/ll",
        "UI_new_method",
        "A-,*(UA/",
        "SDK_VERSION.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "1 1$1(1,101418182@2H2P2X2d2",
        "Fi/pm",
        "YA{\\={e\"a",
        "0Rq) ",
        "~J?=G",
        "UsJx)",
        "o==`O0",
        "eOnXg",
        "O-]_P",
        "b LzB-j",
        "14`3u",
        "q6$Vz3$",
        "kZQBy",
        "imregexp.dll",
        "7Xh+?w3",
        "$p(rt",
        "j[fXj",
        "d*B4i",
        ":i{{X",
        "(BZK*",
        "6EGUC",
        "a*blVs",
        "^%ka4",
        "FSQVA",
        "%Okk5|",
        "F|hBj",
        "ADH-AES256-GCM-SHA384",
        "fSR6y/",
        "*,7ok_",
        "dgxEZ",
        "EPO,47",
        "Cfz.Z'5_",
        "j*'&R",
        "M_f$G",
        "404<4\\4h4",
        "=S:)P9",
        "j`0?]",
        "fD+UP",
        ":3W[}",
        "D$(jpP",
        ")\\A+%;\"k",
        "oq)H1",
        "\"`)vA",
        "HM#9'U-y",
        "l0\"zG",
        "(}t>z",
        "@g!0g",
        "iP\\Pq",
        "jejqj",
        "D$DQP",
        "r\\:}w%L",
        "@][1&dc^vu}j+Q",
        "e2e&E",
        "505<5D5\\5d5t5|5",
        "failed to skip shortcut target from custom action data for rollback",
        "URPQQh@P",
        "210429000000Z",
        "([/:b",
        "/1OT\\",
        "\\5t@OS",
        "Z {t-$",
        "k%k%l",
        "]^EQV",
        ")CXi@T",
        "03.9}x",
        "7$aGZ",
        "=0=S=Y=a=",
        "V<0f]",
        "-:ky:",
        "@lk90",
        "9A9l9v9",
        "/8Pdau",
        "p$5M6^",
        "Y[|Av",
        "*,<Xx",
        ")q$\"n",
        "N/4qfd",
        "D$$PQ",
        "p(+2#",
        "t1wR5",
        "\\SecuRemote\\bin\\vna_utils.exe\" -d product uninstall SecureRemote",
        "-#&nr",
        "bn lib",
        "?g)([|X>=",
        "ASRMP",
        "PhRR+j",
        "I5Bj(",
        "DE_9f",
        "xA'2SN",
        "v/u$y",
        "EIYKS",
        "XsR4qf",
        "NNNP/l",
        "wbX#F`",
        "uO.eac",
        "+@Dk[",
        "\"DKA79",
        "EBJ6E",
        "UZ8yE",
        "3MaM/l",
        "W24yy<i@",
        "_0R@]",
        "$@FlsAlloc",
        "lh^A9",
        "6#6)6/656:6@6F6L6Q6W6]6c6h6n6t6z6",
        "606T6_6m6y6",
        "[VSDATA] %s could not acquire DataClientLock.Continuing anyway...",
        ">[`Hv",
        "F0PVj",
        "cQYjh",
        "+zZ y",
        "a@e7pv",
        "tvloglimit",
        "#]3]8]=]R\\h",
        "$ Svu",
        "y.!^u",
        "BC[ua",
        "|xl<[y4^",
        "6i,(2|n",
        "BVje&",
        "#6y(+",
        "|37OU",
        "3L$$1",
        "l$(;l$",
        "j\\t7HP",
        "3\"4v4",
        "4x$Nb",
        " bY{FL0",
        "2.?led~",
        "VQ ](",
        "mV}&'(",
        "V\\#nhJ.b",
        ";&112",
        "M9VVE",
        "ue]W'",
        "\\UINotify.exe\" finish",
        "*/m5q@",
        "ts(#$",
        "HMAC routines",
        "E+E1EAEIESEUEaEwE}E",
        "jqjyj",
        "Jg_c.ug{",
        "nF{;i",
        "4.Ta\\",
        "X+Lcg",
        "|g,zu",
        "X0GT1",
        "ZgldK3",
        "0i1s1}1",
        "4X5y5",
        "VSCheckPasswords: logon failed",
        "AGt7xs.\"v",
        "G1IE1",
        "XdQY:",
        "OnInstallDriverReboot",
        "Wait for InstHelper.exe failed",
        ":aIUJ",
        ".q)sR",
        "929b-",
        "\"Je:k",
        "mbF0_",
        "Agnitum Personal Firewall 2.1 (AV SKUs Only)",
        "\" j#z@[",
        "$RO,L;",
        "\\\"/$&",
        "5gSeX",
        "T\"{ C2",
        "cH`W<",
        "]-V.W",
        "        Subject Public Key Info:",
        "2\"2(2",
        "v' 9@",
        "7g8p8u8",
        "z2CH? ",
        "f1$Mj",
        "UW[}ogB",
        "KYfh?P'",
        "}2Dk/",
        "iDTgn",
        "`Zwcw",
        " v @]",
        "<O<W<h<",
        "B 5u#",
        " wX<6",
        "DnQT{",
        "Vt_af",
        "tf-XXF",
        "9WX+.",
        "h@g0a",
        "8Px!|",
        "YKdO]",
        "?@?Y|",
        "_15j:",
        "0;<k<",
        "YK#bF",
        "\\R\\tK(",
        "ac!/:",
        "CxQUi",
        "BN_lshift",
        "RtlUnwind",
        "091h1",
        "7FvCZ",
        "\"j7O4/j",
        "7a*]m",
        "090Z0u0",
        "put_preserveWhiteSpace failed",
        "_5ECQ-",
        "t?)uP",
        "    Cert Status: %s",
        "lW48.I",
        "UT3;E1Ak",
        "i#D=S",
        "fnG&{D",
        "<9=x=",
        "oH&Ao",
        "M>8y`y",
        "1\"~C`\"\"<& =",
        "A/A0A7CrD>C",
        ";2KXn:",
        ";B<\\<j<",
        "-*OGO",
        "]Y]]_a",
        "M#M3M&Km",
        "b8>DX0",
        ",|vts5",
        "|q>Xs",
        "W^h)HEM",
        "F1<gt",
        "\\Z{s6",
        "id-pkix1-implicit-88",
        "Failed to MsiDatabaseOpenView",
        "WM1{x#z",
        "En(B'",
        "M_UK[",
        "+Sqvx",
        "Elevation:Administrator!new:%s",
        "xn)0^",
        "~I=Ik",
        "1D|E?Z",
        " 0x3e",
        "aWTdgH",
        "identity",
        "|aDJ2",
        "reverse",
        "}'2`{",
        "ClientVersionString.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "I!y{A]",
        "m Pwx",
        "Helper::stop() -- set exec",
        "VSTO redistributables were installed. Rechecking installed VSTOR features",
        "ssl_sess_cert",
        "@2;mSa",
        "mPxUgX",
        "6B;*$",
        "yN~HDG@",
        "#cTGG",
        "vMFJ4",
        "\"ggtxb",
        ",qxy%q1",
        "r\"SVr",
        "9>9k9",
        "2'1v9A",
        "4h0y[H",
        "fepy!",
        ":H:t:;<g<",
        "2f4~4",
        "6T6k6",
        "h)8SQ",
        "\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\snext11 \\ssemihidden \\sunhideused Normal Table;}{\\*\\cs15 \\additive ",
        "kY9tw6",
        "4/5l5",
        "5E3&W",
        "5doj-",
        "STREAM_ERROR_WRITE_FILE",
        "YB@?y",
        "Z,x:sy;",
        "YJSTN",
        "w#IF\"",
        ">1?a?",
        "x{<SS<`",
        "5;?1H",
        "4;Gzt[ 0L|d",
        "aE%h-@",
        "w+;N8w&",
        "2{Y.@*x",
        "bnZbN",
        "(.3Y)",
        "$Q5MN",
        "bWnn:",
        "f(|&]#T",
        "D$,Pj",
        "5$5,545<5D5L5T5d5l5t5|5",
        "525N5j5",
        "Xas8j",
        "``EYW",
        "DisableVistaSDL",
        "vLRQh",
        "CE8Ph$8M",
        "[*SUE",
        "[^^U8",
        "\"40/'9D",
        " 0x31",
        "L(d{KS",
        "|di5=",
        "+O~;/",
        "4`p[]",
        "mL*LM",
        "\\$DVWf",
        "2'8A?",
        "AWk*[",
        "; ;x;",
        "PMULHRSW",
        "m]9*s",
        "Password",
        "VCIe!h",
        "OJ6LOV",
        "hWv;b",
        "gr+m5",
        "5\"eCaS",
        "ALL_PROXY",
        "2siu0",
        "U|_k$",
        "m\"!Fj",
        "w65/6f",
        "J0Wl>",
        "DISONNECTEDPOLICY",
        "IKIob&",
        "american-english",
        "\"/@e`",
        "7<Hn[wMb'",
        "-/$4}",
        "_+\\*k",
        "1CxkCY",
        "#GM#D",
        "X!$W*T",
        "#RTBA",
        "@a|9J",
        "G( u0",
        "'vI1d",
        "j-Xf;",
        "9=:L:",
        "8P8|8",
        "3u`|xu1",
        "KxUMK",
        "/bQ]4",
        "\\SecuRemote\\bin\\vna_utils.exe\" -d om drv unhook",
        "LMtM[",
        "/qQf:i",
        "H6-1A",
        "J_0(u^",
        "k}~Va",
        "9*:p:",
        "Zdx}`u",
        "YQ.?3el",
        "){7Acv",
        "ResumeThread",
        ":&DJa",
        "********",
        "G^D,HEp",
        "SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters\\FsctlAllowlist",
        "i*!\"<",
        "ru#J1n",
        "setext-track2",
        "|^=`g",
        ">i%u[/",
        "7<7H7h7t7",
        ";5;Q;m;",
        "7J&s3",
        "P9=/8",
        "mwpe>",
        "r_3'+vp",
        "F[dbOd8VYmR]",
        "<(<j<",
        "D$ USPSP",
        "failed to get firewall exception port",
        ";);=;G;Y;d;};",
        "-;-C-I-M-a-e-q-",
        "zP630;",
        "v70:Z",
        "Q=%Yc",
        "/#:t\\p",
        ":Po\"yc3",
        "^`&]/",
        "}\\kiZ;Qp",
        "jjkkR",
        "C*/)3",
        "0 0(00080@0H0P0X0`0h0p0x0",
        ":E:h:",
        ",oPpa",
        "Kc)'n",
        "[[np\\",
        "sh0]Z",
        "-ufj{",
        "vJ~j>",
        "<0Dco",
        "u[=H5:Y",
        "a[RHu",
        "jR[(|C2D",
        "bkE\"4",
        "ObY4Q?",
        "jBjrj",
        "=3?F?",
        "iH(rDK",
        "CM?m@X",
        "-Cut2",
        "T$X^]",
        "g)n_:",
        "~XNQI>",
        "%{lb<J{",
        "AFr%zV",
        "24Uqi8s",
        ".Z^%^",
        "UciaC",
        "L$hQh",
        "k4F 4",
        "\\wU&]F",
        "88'5~t",
        "E?S&L0",
        "PIPEk",
        "S9'j&",
        "@byszY",
        "A] 7&",
        "l4P@B",
        "18>Wg*o",
        "DQqK}",
        "hu2(\"|f",
        "A+W s",
        "W}yj)",
        "9iYJ#",
        "gYExR",
        "9&6sf",
        "ce@CX",
        " 3eVD",
        "h5hUhuh*`k",
        "DSA_PRIV_ENCODE",
        "N))lT",
        "\\)9!K",
        "_+fPH",
        ";&<?<",
        "\\6GyE",
        "SD0d:G",
        "tnQ9e",
        "C'\\SM",
        "{-=d4",
        "0]-;Y6s",
        "Y.S\\&",
        "always",
        "l<rmzp",
        "C@t ]lR",
        "1^R b",
        "3,&]\\",
        "jYs@y",
        "Call stack from last DbgPrintf (ignore first 3 frames):",
        "dcSgp",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\clienthotfix.cpp",
        "8y65D",
        "D69\\&fC[z",
        "jAj~j\"",
        "Lt~-t",
        "54585D5H5h5l5x5|5",
        "w| 8X",
        ":K:S=[",
        "d*~e ",
        "M :\\#",
        "caHm7",
        "isModuleRunning;",
        "L6PX(",
        "(?:tb",
        "7 )0@O",
        "M&ovs",
        "SEC_E_CRYPTO_SYSTEM_INVALID",
        "F0M<K",
        "t$9k@u",
        "w)`Xt",
        "hLvpq]",
        "(sbF9",
        "@Yop?",
        "5%5B5S5h5m5",
        ",IE`3",
        "J~P#v)",
        "kok-in",
        "y)-!J",
        "E\"k~q",
        ":5:Q:4<m>",
        "Kh:9;D",
        "<QUqV",
        "'-%\"C",
        "[m5^ ",
        "Ht2~U=",
        "jF=7~",
        "9] SS",
        ")yHIi",
        "3,303@3D3H3L3P3X3p3",
        "3Tj1squ",
        "!w?j ",
        "s^f}g",
        "keyEncryptionAlgorithm",
        "UgUWF\"",
        "MIC-ONLY",
        "D2I_OCSP_NONCE",
        "cs-CZ",
        "Ttwp]-",
        "f[beq",
        "%\"^v#",
        "`7Evbn",
        "2TC|W_4",
        "GX{Hq",
        "Y\\Ydr",
        "y&^Gu",
        "t$<WS",
        "VSh(,",
        "*v.f&",
        "_@q]q_R",
        "VP&oO",
        "yn;|bZx",
        "X509v3 Inhibit Any Policy",
        "j>pB.3",
        "Y\\$;k",
        "&Njb<)",
        "]%z-q",
        "*0oA4",
        "|rZsfw2",
        "\\jl\"#",
        "X'q5S",
        "X,,tX,,t4",
        "iQYaEQ",
        "))e-F",
        "&%&E&",
        "\\r9[g",
        "Utb[|,4",
        "BwDmS",
        " 5Q`I",
        "IS_UninstallIMSecureLSP",
        "ph@yad(",
        "tsk\"r9|UW",
        "9>9I9O9e9m9",
        "Ld62!",
        "%(])G(S",
        "EYFv$t*p|n",
        "SQ$vZ",
        "_vectored_",
        "4$404P4X4d4",
        "q7Ai6b",
        "l\\>UH",
        "`E9#?",
        "[VSDATA] DriverSetProtectionCtrl: OpenDriverHandle() failed",
        "K4t;^",
        "CheckNetworkFilters started",
        "~cZ0$1",
        "!fHsB#",
        " 0xac",
        "!SPYLV",
        "MI5'#",
        "^gCe:a",
        "/Q)\"0",
        "%1I.gT",
        "\\L*-1",
        "JzjJ1",
        "XF*1G",
        "^^v5C",
        "K\\2$J",
        "~}b]Q",
        "Failed to read data",
        "?#%X.y",
        "cSCRM",
        "2j2N9",
        ":F1,(",
        "_'~g1",
        "AAEEQUUP@TPU",
        "@bMjR",
        "sovdD",
        "vZ4fc",
        "1$1,141<1D1L1T1\\1d1l1x1",
        "\\InProcServer32",
        "8F,1k",
        "RS51?",
        "bnIjhi",
        "N||)W",
        ", value ",
        "ecumi",
        "u_1D!",
        ",7+||E",
        "1W\"Ke",
        "L)BA-",
        "_$_)^;{",
        "%^#hZ",
        "Kaspersky Antiviral Toolkit Pro (All SKUs)",
        "111?1M1R1^1k1u1",
        "XdTxM",
        "C:\\Windows\\System32\\FDE_srv.exe",
        "CANT_STOP_CISCO_SERVICE",
        "{P7pG",
        "%t<~[",
        "\\b&]86",
        "1p1v1",
        "ShellExecuteW",
        "8K8d8",
        "y&Vhe",
        "&QmGte",
        "RG4TfY",
        "@p-%/",
        "TF+rC",
        "PendingFileRenameOperations",
        "socks5",
        "~.w`/~lb",
        ">9>|>",
        "Ca\";bp>&:G",
        "AE3q<",
        "You must uninstall Checkpoint Endpoint Security Secure Access component before you can install Check Point Endpoint Security VPN.",
        "_?d?G",
        "\"d(=;",
        "]}4/$/2",
        "#P 7Z^",
        "mWE0_q",
        "a>_]~",
        "hXfVjE}",
        "G:^ 2",
        "4!555d5i5o5v5",
        "?Y1Bt",
        "In Remove case, continue...",
        "2%2q2",
        "!<.Kj",
        "kxfBrVo",
        "s;W:0",
        ",}q}Y;q",
        "5N6^6g6v6",
        "t1tBizg",
        "6<w*b",
        "TrueVectorIF constructor -- refCount = %d",
        "H m=U",
        "yLE{*",
        "p1_{w%",
        "2>M0,",
        "4rDIB",
        "B%#t0",
        "L^r/2",
        "&`h0H#",
        "Yyt>-<a",
        "7XgF8",
        "UZ!tD",
        ":3:X:i:",
        "XmlConfig.cpp",
        ".!>9.",
        "eEv|{8",
        "'mTqbe",
        "Uninstall individual drivers.",
        "G|1;$ ",
        "+d+qpXPc",
        "zr'M*",
        "T+Aaqy",
        ".6Pq4",
        "{;kCU>",
        "f1WZd3^",
        "omwS7F",
        "fs4=.",
        "6,686X6`6h6t6",
        "L2%izT",
        " o6j}",
        "InitClientSubType",
        "l*,05^",
        "zL1(j",
        "}M0\\:",
        ".Fd0Q;",
        "wzmu3",
        "nt'joY;",
        "W`>Pc",
        "8[9s9[;",
        "V4-'P",
        "glV>1",
        ",=!|U",
        "EPDRIVERSGUID",
        "Vo_TD",
        "0\"guB",
        "$ThFeZ",
        "GetProcessCmdLine",
        "1:2y2",
        "y,*)Uz",
        "eI?mM",
        "_9qL+",
        "tx;:u ",
        "Wxfxgg",
        "{Rb?7",
        "d2i_ECParameters",
        "MAIL FROM:%s AUTH=%s",
        "N2\"Gw",
        "|=-DDG",
        "OXG!r",
        ")b~MI ",
        "n_j:*b",
        "1:NDH5",
        "A6_[7",
        "jtEh&",
        "SdB#>gp!y$",
        "7Yc?)6`",
        "7`8r9",
        "3\"313j3",
        "^yK09",
        "GetLocaleInfoW",
        "(Ftx\"'Bp",
        "3.AQ4",
        "=d}GM",
        "VSInstallerCancel: succeeded. ",
        " nSrav",
        "4kC]C!^s",
        "6x6{7",
        "!0CZ{",
        "whh8;!",
        "mCl8+",
        " filename=\"smime.p7s\"%s%s",
        "8P{2uk",
        "\\-<*/",
        "An>@l",
        "Q@wE#",
        "ctM';",
        ";0'#|",
        "=+Uhj",
        ",@Y#^",
        "150LR",
        "a=!Z ",
        "I1oZ7",
        "Ec^+d+",
        "lZp1X",
        "_4aX4r.a",
        "W+9hX?",
        "[Dxo{~rZ",
        "rty to) remove any copyright or other proprietary notices from the Product. Your use of the Product may require the purchase of separate licenses to use particular features, functionalities, operations, or capabilities. ",
        "wgtR=",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  Third }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "9W:q:",
        "SbEwd",
        "@KSwg",
        "Y o!F",
        "zE&8,",
        "m$QFZp",
        "g=lj ",
        "132V2d2s2",
        "UEm}E",
        "(}\"Z3kh",
        "g}%F2",
        "X509_NAME_oneline",
        "0SrPT",
        ";Pc7?z",
        "T$T#L$ ",
        "1T$(3\\$(",
        "o=vhT",
        "Failed to pWseUnregisterPlugin",
        ",PzD\"!",
        "{m*Sp<",
        "mV}LA",
        "C+4r(b",
        "h&91n",
        "UJIR9[",
        "ZO\"LTztAD",
        "x$I}ypGM\"k",
        "eKwVSv-^Y",
        "=YFm7",
        "e/jU5g",
        "5+Poc",
        "AnE6$-c",
        "4(4,4044484<4@4D4H4L4T4l4p4",
        "4&sZ_",
        "5oN4H",
        "6X6p6",
        "ihG-]",
        "cSu/w",
        ":(T|Kp",
        ",.~D\\R",
        "TC?=K_",
        "o#`C(",
        "-0r--{",
        "camellia-256-cfb",
        "c\\&DC",
        "#~p\\P",
        "WNQ=jk",
        "@Oaf r/",
        "7Y8d8p8",
        "R0:`I",
        "2M2r3",
        "o~_Mp",
        ";\"A9Uu",
        "i*|H'zU",
        "8A8r8",
        "ozNfT&m",
        "\\p65~",
        ":usjf?",
        "7n'[D",
        "CAMELLIA-128-OFB",
        "D%]Bb",
        "sLGIS",
        "-,ET9M",
        "647;7B7I7",
        "vP/'%%",
        "sU)kj",
        "fTXm$4",
        "ADDFW",
        "s#p6 =ev",
        "cZ:ka",
        "T$@3L$P3L$8",
        "1f2x2",
        "7\\py[",
        "j))bR",
        "7A)~L",
        "E3^VZS",
        " 0x21",
        ">OSdl",
        "Zi)lY",
        "HbM#v",
        "s9q]%",
        "oz<HM",
        "\"n`pd",
        "edJSF9",
        "X509 V3 routines",
        "626N6j6",
        ";e;};",
        "Succesfully opened registry key ",
        ".}KxJ`",
        "pkcs7",
        "ExpandEnvironmentStringsW",
        "UMYIGQ4D.",
        "5/595J5b5",
        "Qrz:D",
        "L$,QV",
        "`%Bp~",
        "=I.)c&",
        "L>#Rn",
        "unsupported algorithm",
        "bjJ(3",
        "3T$@3T$,3T$0",
        "K6\\4I",
        "gz6l9",
        "oTQ6F",
        "IP Address",
        "3S4X4]4b4r4",
        "AIP%n",
        "f%_\"|",
        "2Xa=Fq",
        "rn[6E",
        "Glg^K",
        "s]]GH",
        "Unloading GUI",
        "{~\"MQ.",
        "pl_+:",
        "b3ve<",
        "xd/gDX<",
        "?\"?j?|?",
        "74898",
        ".sgFN",
        ")^Yb7",
        "hKW\\my-,_",
        "+6k)hA\\",
        "C{M(k",
        "`CrR(",
        "#tU?4",
        "1k2w2",
        "e{WFUaI-",
        "$v4#i?}",
        "Qow\\[",
        "R6025",
        "ar-AE",
        "SetBladeProtectionStatusInVSConfig: modifying tags %s/%s, setting protection to %s",
        "L.7#|e",
        "2fR/Q",
        "bad rsa e length",
        "CI) k|",
        "S8gRz",
        "M3O+r*[qN",
        "OnUninstallDriverRollback",
        ".?AV?$encodedString@$0A@@@",
        "; ;0;@;D;H;L;T;\\;`;d;h;l;",
        "q).D3*",
        "\\{GQH",
        "jXxgt",
        "KillTimer",
        "k.%?l",
        "K_z^5",
        "?u@h'",
        "sgqInX",
        "U)Hne+,",
        "sect131r2",
        "#K[D#",
        "kRp*v",
        ";3H A",
        " aah<",
        "[@9uz",
        "jqjfj!",
        ");i~p=",
        "dVT~Cs",
        "L=92$",
        "LoES?",
        ")4Phh",
        "\"c:\\Program Files\\CheckPoint\\Endpoint Security\\NEM\\NEM_svc.exe\" --service",
        "ND[B8",
        "=)=8=G=U=",
        "library has no ciphers",
        "\\zonelabs\\Updating.dll",
        "calling...",
        "0>3R3e3",
        ">i?s?",
        "YfnZU",
        "pF;%A",
        "%D@\"{",
        "'VNF!",
        "KnD6Q9",
        "Lq~SG",
        "hash<",
        "Y1_P4y",
        "6DLp^",
        "@@`\"p",
        "C>}wQ",
        "]2DEW",
        "setct-PI",
        "Key Compromise",
        "l^?$%X",
        "%.h<k",
        "O=S\\E",
        "d%ts]",
        "PKCS7_set_cipher",
        "?%?1?b?s?x?~?",
        "I6&zu=",
        "k@G.,",
        "=%=V=e=",
        "yX%<Z(",
        "o<xSZ",
        "\"lJx}",
        "QjpNqU",
        "-=NY^",
        "RAXOv(#",
        "grzpe",
        "dE%r@U.v",
        "L'p4 +",
        "/iZ0e?cO",
        "g4 19G",
        "kVrmE",
        "sZ_(^",
        "4a40.",
        "b/SvC",
        ":.:T:s:",
        "222N2j2",
        ",IQV&#&X]",
        "L$h3L$@3L$83L$0",
        "(UE@T",
        "SSL Client",
        "~F[v@",
        "2P[__GwDD",
        "e&oVgL",
        "/DPh>|",
        "{5b\\OF|z",
        ">0ocJ",
        "l=&l<",
        "y`|\"j",
        "__crt_strtox::floating_point_value::as_double",
        "CANT_GET_TEMP_DIR",
        "UpgradeCode",
        "htQ.$",
        "Z7'ay",
        "Ou2x0",
        "M\"xX;Uy",
        "iNC6y' ",
        "k+:w#s",
        "mZ3(8",
        "V{kr8",
        "lb^uv",
        ";!<I<`<j<v<",
        "kn#mUR",
        "999\\9",
        "=l';m}",
        "BXb~e+",
        "Failed with error %d to CopyFile from %s to %s",
        "%!S*V",
        "6to>\"",
        "=&KSm",
        "ZRU;S8",
        "7e7r7",
        "'<Rj5",
        "qtzoKIi",
        "point is not on curve",
        "eG7EE$j",
        "yA`:3",
        "3 3$3(3,3034383<3@3D3H3d3h3l3p3t3x3|3",
        "p+pkp",
        ":70_(",
        "5R1\"N>piS",
        "1.1X1",
        "n/nd'Xl",
        "2B2V2",
        "jMfRk",
        "Q.[@<",
        "^&BHE",
        "1/1A1",
        "]Y>SA ",
        "|$Rvz",
        "<uq<%",
        "Connection to proxy confirmed",
        "9\":p:",
        "k#3y9",
        "L-I-@",
        "TST0k",
        "dpNFB",
        "I0C9G",
        ".||Z\"",
        "<!=n=",
        "WixShellExecTarget",
        "\\lsdunhideused1 \\lsdlocked0 HTML Address;\\lsdunhideused1 \\lsdlocked0 HTML Cite;\\lsdunhideused1 \\lsdlocked0 HTML Code;\\lsdunhideused1 \\lsdlocked0 HTML Definition;\\lsdunhideused1 \\lsdlocked0 HTML Keyboard;\\lsdunhideused1 \\lsdlocked0 HTML Preformatted;",
        "R4;bP",
        "QW=;Qv",
        ">//^q",
        "6W7c7",
        "@*Ux_",
        "E[w(lY",
        "s~GI2",
        "GetVersionExA",
        "8'8-8=8L8R8]8l8r8}8",
        "acceptableResponses",
        "jS!wKM:E3",
        "hr!1V",
        "SX8^i",
        "xI!oxj",
        "8D8H8L8P8T8X8",
        "YK'1&",
        "DetachDataClients",
        ",o{eB",
        "-.R/@",
        "3L$X3L$",
        "230202155701Z0+",
        "GxVPR",
        "Z/LZr",
        "35N_@/",
        "Ek|#h ",
        "9rqt!",
        ":$:):9:>:C:S:X:]:m:r:w:",
        "D$$_^][",
        "2r=h;",
        "TMInstallationCancelled",
        "j]N$*Lh",
        "/sF*tZ3",
        "x*xjx",
        "=r>}>I",
        "WXWbWdWhWmWwW",
        ")|c@o",
        "XmrbL",
        "<(@A@",
        "+6qw`iN\\(&",
        "Gk<SV",
        "5G<4a",
        "#]!C4",
        "8nfB'",
        "{3gd%R",
        "x%E\"v\\",
        "X509V3_get_value_bool",
        "O8W?fJ",
        "~(Qb.",
        "jm sJ",
        "tZhx'",
        "Cp-j;n",
        "\\1M^TG$D",
        ".CRT$XIAA",
        "_$A+t",
        "ixOy_",
        "ecp_nistz256_set_words",
        "FALSE - Map Doesn't Exist",
        "<[U^k",
        "'*Neyy",
        "_1Rv/",
        "C\"<\\6",
        "q}\\pp",
        "\\$,Wj/S",
        "%$bALb",
        "id-aca-chargingIdentity",
        ";7;P;Z;g;v;",
        "PZiy/",
        "K<<H!",
        "c[,s =MW",
        "/A f9",
        "zCrQ=",
        "WJ/T@",
        ".C2MK\"",
        "ys(lP",
        "mc[?_",
        "tE6Aj{V",
        "^:$Bx",
        "@%bK1",
        "5$585k5y5",
        "c?&JV&",
        "0is>DHS",
        "4%$J}s)",
        "SELECT Condition FROM InstallExecuteSequence WHERE Action = ?",
        ">(>4>T>\\>h>",
        "Sd9U/",
        "MxM <",
        "fH|*t",
        "An exception occured during unregistration request generation. The computer will remain registered after client uninstall",
        ">A>~>",
        ": o,XA",
        "!|o/;)",
        "282J2`2e2j2",
        "2@2d2",
        "t$ SVW",
        "_[}Rl\\",
        "6g]gegjI~",
        "s/~r.I/",
        "TZB:k",
        "6!686V6h6",
        "r%S8j",
        "DS_RollbackCopyToSystem32 ended.",
        "C>rKr",
        "q@?8 m",
        "3|$<1",
        "\\Th3e",
        "oYsO1i",
        "H#%!`n",
        "VWh y",
        "lH+0,",
        "=}Q.J",
        "q]{,ms",
        "4bOK,",
        "=}<:*",
        "Nol,?",
        "SERVER_FINISH",
        "l$LPVS",
        "<$=:=",
        "9Xi(p$",
        "invalid form",
        "\\x+cP",
        "K7S' R",
        "t]VWj>",
        "UXXk._",
        ",^2.W",
        "b3^g4AU",
        "Content-Type: multipart/signed;",
        "OCSP_REQUEST",
        "}'2p%",
        "tO9x7v",
        "x]OX;",
        "2 2,2p2|2",
        "jv!l/?^",
        "3!4M4",
        ",{N3q",
        "q@2r'",
        "SSL_ctrl",
        "5!5'5-53595?5E5K5Q5W5]5c5i5o5u5{5",
        "\\Hash.exe",
        "static ",
        "_{@_Y",
        "}CW'z",
        "X8C.1_P",
        "CbbT/Kc",
        "Tbl_7",
        "@)`V/",
        "?&_Qe",
        "546y6",
        "$?6?{",
        "ou9`@",
        "uv~suu",
        "/}r|6",
        "u(#jJ",
        "{k3)A",
        "PSUBSB",
        ".*{?Ui",
        "Musvsv",
        "?StHd",
        "-V4S7*",
        "/9_60",
        "#i7#>)r",
        "yf<Yz",
        "1=3W5",
        "M9@mc'",
        "CheckIfRebootRequired ended.",
        "?<ZFk",
        "C'&Wm",
        "d49t^",
        ".?AV_Node_end_group@std@@",
        "okq|3",
        "`,E&i",
        "Rqp*H",
        ">%?R?",
        "1{l74",
        "Xt6i.C)",
        "CPPSM",
        "{?3ni",
        "[VSDATA] SetEvent failed: %d",
        ">~I~VN",
        "P*;-G.",
        "=i>)?",
        "oYfqs",
        ",yp;-",
        "]O(?k[",
        "RdC@A6#",
        "242@2`2h2p2",
        "${T9V",
        "fo.jjE\"",
        "<G[fu",
        "9E%%hRE",
        ";7_'Z;",
        ")nx:;",
        "%s\\Start Menu\\Programs\\%s\\%s",
        "xE&NYf",
        "Z~4HY",
        "e$3Nxo",
        "@5+o7",
        "VPNAtInstall is set to false",
        "not vista - no need to change.",
        "NETAPI32.DLL",
        "9\"9>9Z9v9",
        "QW_h&",
        "S1_{{",
        "7,878<8e8m8u8",
        "_N#kv",
        "E|eaP",
        "gm6'A",
        "= =0=4=D=H=X=\\=h=x=",
        "2PND/R%",
        "Oa|O<",
        "1LOcN",
        "D$4PW",
        "g*1k'",
        "3/3H3a3z3",
        "2/h% 8",
        "Be(O+>",
        "spanish-dominican republic",
        "~i(:oi,",
        "wr^n#",
        "helper::tvDbgPrint",
        "&|%e^rg",
        "z_lYOb",
        ">&?8?}?",
        "U^,RW\\",
        "id-alg-noSignature",
        "656e74323d22616363656e74322220616363656e74333d22616363656e74332220616363656e74343d22616363656e74342220616363656e74353d22616363656e74352220616363656e74363d22616363656e74362220686c696e6b3d22686c696e6b2220666f6c486c696e6b3d22666f6c486c696e6b222f3e}",
        "bcyh#",
        "4$404<4H4T4`4l4x4",
        "'zT&^YpqY",
        ";);a;w;",
        "0;1t1",
        "Fis1(",
        "DES-CBC",
        "PBE-MD2-RC2-64",
        "K K'K",
        "s'wC}",
        "M`iwzD",
        ">}AGK",
        "gK$#H",
        "\\lsdunhideused1 \\lsdlocked0 E-mail Signature;\\lsdunhideused1 \\lsdlocked0 HTML Top of Form;\\lsdunhideused1 \\lsdlocked0 HTML Bottom of Form;\\lsdunhideused1 \\lsdlocked0 Normal (Web);\\lsdunhideused1 \\lsdlocked0 HTML Acronym;",
        ";KYRp",
        "| Mzc",
        "@A`e/",
        "`ZTLj",
        "Gs{~[H",
        "wZx5M",
        "y44t<b",
        "5C\\G7",
        "<$<,<4<<<L<X<`<|<",
        ")!)Q)",
        "dTc~HjU",
        "JetZF!",
        "+#jOE&",
        "Oh_^][",
        "=!=1=A=Q=a=q=",
        "]4^t^",
        "pr7>J",
        "8;8W8s8",
        "!wsw_\\",
        "n=6A67%",
        "g\"E?a",
        "%s HTTP/%s",
        "p'$N&",
        "#-r>X>",
        "o8PfV",
        "5%nPYl",
        "mk>s3",
        "6E)*6Tg0",
        ">C?H?M?m?v?{?",
        "7U7k7|7",
        "E#K(+6",
        "b>0E]",
        "$EzAG ",
        "$miZ*",
        "4%:(Z",
        "m:IIbyS\"",
        "icyN[",
        "6_jfS",
        "\" @x ",
        "^$_P/F/;",
        "jej{j",
        "Tm4ru",
        "NY]Ey",
        "@'d4G",
        "l8-i,*",
        "thhXd",
        "SzSWg,",
        "sT*9x",
        "P>?yH",
        "w#VB*",
        "i cn(3",
        "H4/v-",
        "qr_0]",
        "t=*|E",
        "Q+pPNEV",
        "@bEcM",
        ";qi!rH",
        "bwK`b",
        "*hcYj",
        "0K1t1",
        "B20xD",
        "*?|#2",
        "JZI\"9dW",
        "n}#Pf",
        "Ru/qh",
        "7=e0Y",
        "$6;`6eL",
        "$hI\"H",
        "ih{$8_~",
        "=$===B=G=d=}=",
        "yYgd-",
        ".OdjU",
        "\" x -o\"",
        "@a'^y0",
        "&,O6|h+",
        "WD_CheckFolder CP folder is safe.",
        "uW(LD",
        "ms-my",
        "R^m/j",
        "!D19~",
        "WnOh9)g",
        "uz|lK",
        "len == (unsigned int)ret",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  Certain ",
        "051m1",
        "F@a(L",
        "^L->y",
        "H1#@N",
        "failed to launch target: %ls",
        "uHoc0",
        "3&3.3A3t3|3",
        " \"J|GS",
        "zp~{gz!",
        "[#tC0",
        ". *bF",
        "InBinaryTable",
        "7H>((h",
        "Unable to backup (error %d)",
        "b0U7]",
        "89p=5",
        "~XL-+",
        "yC7(}",
        "2wad]",
        "Z{K;)l",
        "_,,$U",
        "kKsG/Y3",
        "ua\\(N=",
        "EXTRQ",
        "9E>]\\",
        "}&IJ l",
        "mCU%+",
        "owKtl",
        "7p/~$",
        "o5Zch3ig",
        "1$212`2l2",
        "7_^][3",
        "=F~/\"",
        "b0R0f",
        "DDSuh",
        "VuWXkX",
        "l%<r!",
        "3J*3_",
        "/2);3",
        "Dn.[&hy",
        "3sMW|",
        "1%2X2",
        "4$4,444<4D4L4T4\\4d4l4t4|4",
        "!,Z(f",
        "u(t?xap",
        "I):W&",
        "5bJ\"/:{",
        "DTLSv1",
        "\"xHep",
        "[LICENSING] License file is ReadOnly",
        "?G5Z3",
        "StopServices started.",
        ">$y'#6bPx",
        "9x'U?",
        "l}C.we",
        "Common",
        "JLjJ?",
        "RtlInitUnicodeString",
        "Got a blank Session ID",
        "b0-+V",
        "%:{C3",
        "m^^uI",
        "[r/jTXu",
        "2(3D3",
        "{/R!%7",
        "p_<\\2$",
        "i+mko",
        "z[b&,",
        ":);n;",
        "b}Oe(amtH",
        "mHJrjQ8",
        "MSIUtils",
        "dTSMf",
        "PKCS12_add_friendlyname_asc",
        "State_InProgress.png",
        "L yA9.",
        "DH-DSS-AES128-SHA",
        "NORTELINSTALLED",
        "E=),<",
        "exYYy",
        "[**FAILED SESSION**]",
        "_+,b#",
        ":T:^:c:r:x:",
        "6NoToZo^odorl",
        "Z(Q_U",
        "F@2w-",
        "9'9D9U9j9o9",
        "CiHf2E",
        "L^08&*{_",
        "V2I_POLICY_MAPPINGS",
        "SmqND",
        "7'9X:",
        "LZRq.DTM",
        "3F4O4r4",
        "qE6^f._",
        "\\cJ?X",
        "B*q/@.Y1",
        "/V9]H",
        "invalid format specifier for char",
        "28*7d",
        "#?DIKP",
        "D+VZ>",
        "v{2'/w5",
        "``AEru",
        "EWyxH",
        "\\2jx|",
        "NMVNW",
        "ym\"wk",
        "z%z-z5z=zEzMzUz]zezmzu~}",
        "dDJ-OM",
        "H;g(>{",
        "-T*~j",
        "6T7k7q9",
        "TbF7Jv=",
        "FreeLibrary(wsock2) failed (%d)",
        "uP_r1OAW",
        "5+6q8",
        "02BM}lV",
        "h{er&",
        "okTw'pk",
        "Wo2FCU",
        "V!;Xp",
        "mzNf)kS;Z",
        "@7:mI",
        "8{kz|s",
        "|$D;|$ w0",
        "OVA0&",
        "B<$t>",
        "Z?'N;",
        "AA7:r",
        "t5|}|",
        "b([G1",
        "\\zonelabs\\zlsre.dll",
        "jAjsj\"",
        "P?%S?78",
        "&=GN2",
        "626B6\\6m6",
        "r1;(F",
        "_r8nL",
        "u%&cS",
        "fJcKU",
        "@/ W,",
        "6?BfD",
        "2>~q&$",
        "B5I6N3j",
        "D(VQl",
        "{MHJW",
        "OO\\FN",
        "; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\\;`;h<l<p<t<x<|<",
        "<~^rI{",
        ",o5O/js",
        "{GTLwg",
        "OCSP_SINGLERESP",
        "=$=,=4=<=L=T=\\=d=l=t=",
        "&6R9:",
        "Tuz\"G~",
        "[RjLA",
        "n`{%?0",
        "ZT=UO",
        "Wo=x~",
        "u=G}`.",
        "ar-ye",
        "QB'Im",
        ":7:<:C:J:Q:X:_:f:m:t:{:",
        "Vicgp",
        "D$(hP<!",
        "4,5=5|5",
        "'vhvDO",
        "4`j=N",
        "A9^E3(As",
        "+O*1Le",
        "setCext-hashedRoot",
        "r~+3T",
        "Failed to MKD dir: %03d",
        "ASN1 OID: %s",
        "$FJED",
        "=yOB#]D",
        "\"$WbC",
        "O x? .",
        "9vvIn",
        "D$0u43",
        "UxU<UE9V",
        "7=$)4-c3",
        "dmq1 not congruent to d",
        "ErL!`",
        "_1st_",
        ".?AVbad_cast@std@@",
        "If a Hardware Product or one of its component parts does not function as warranted during the warranty period}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5649851 , }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9202780 ",
        "L$4QSP",
        "<G<t<",
        "Failed to create record for prompt.",
        "SlF$x",
        "4\"4&404:4>4H4R4V4`4j4n4x4",
        "c/=$U",
        "!@D \"",
        "BA![^",
        "be5pq",
        "mmD]y",
        "Z}Hc_cLd",
        "=i=v=",
        "-q{z+",
        "g'cV*",
        "?ubR5",
        "/x.V\\",
        "747?7Z7y7",
        "?Bjo_m",
        "qAE,xU{",
        "~oJhs-",
        "9f/W#",
        "{_?xy",
        "RU#@ ",
        "n]A?]X)",
        "GtDB0&",
        "Nk(uU",
        "t?h;k",
        "&UT<4",
        "vaFKor",
        "<I0I ^B",
        "F\\%k0Y",
        "mOI2&",
        "3Mr*{",
        "]iGor",
        "VTQUkEG",
        "J4&U-",
        "Connect data stream passively",
        "m~YQf",
        "Vg\\+2",
        "M,&{2r",
        ";);=;p;",
        "'+VYg",
        "0:1L1",
        "75'Oln",
        "<iMVBN",
        "failed to allocate string for query",
        "ZKO(QF",
        "_z^zZ",
        "d/j->",
        "5:Rlr",
        "ZLProduct.Features.pFeature[0].Name failed",
        "hRES,",
        "7sQ9(",
        "g0$#W&",
        "|tQw{*",
        "%N:NFs",
        "pGroupAffinity",
        "L_)#9",
        "zA8!)",
        "jfjqj",
        "Fsjy_",
        "leXA,Z~",
        "<firewall>",
        "=,=8=X=d=",
        "C1A5G~E(DrF",
        "CMS_decrypt_set1_password",
        "QYA[s4x",
        "JVpQ8y}",
        "9RO4>",
        "j=/QE",
        "zB5je",
        "InstallDotNet4",
        ":M;v<|<",
        "1m1y1",
        "6)ez)",
        "3T$@3T$83T$0",
        "E?I}/",
        "Cx?wFE",
        "c.OAb",
        "W8;dQg",
        "_$5)S",
        "9%=!BJ",
        "?0?P?",
        ",@:n{",
        "D{<Oh`",
        "5\"5U5\\5v5~5",
        "x{bnY",
        "3\"Gp^",
        "?tEq~{E",
        "setAttr-PGWYcap",
        "=V=K%X",
        "JJ[?P",
        "G-27j",
        "Q-H$xyti",
        "Hash.exe verify <password> ",
        "|MwW[c+>5S{",
        "rP$B9']",
        "2dr`$",
        "x>n~quu",
        "~^F7O",
        "De+{zQq+J",
        "!Mv2'",
        "m(mHmhm",
        "C1A5G~<",
        "y\\YA~A",
        "K@HD?T",
        "R},ye",
        "blP`Q",
        "k~%Tg",
        "f:\\local_ckp\\xl\\boost\\1_68_0_za_vs15_7_5_2018_08_15\\boost\\property_tree\\json_parser\\detail\\parser.hpp",
        "failed to write Name to custom action data: %ls",
        "\\Do)i.",
        "?@b56",
        "020_0",
        "1Y3<8V",
        "1VQ1-",
        "#@xWy",
        "kP}W6E",
        "BI4\\c",
        "User was rejected by the SOCKS5 server (%d %d).",
        "-N1;4",
        "g;-YH",
        "2vyP@",
        ".b10E",
        "xo+Zi",
        "GetTempPath return %s",
        "=1>8>J>",
        "[SYS_EVENT_LOG] type=%04hx id=%08lx text=%s",
        "<4a1q",
        "s7'}}",
        "wtujj",
        "cptmdemo.exe",
        "Ha$v^",
        "D`-Mr",
        "'>2v@",
        "d!Cg#",
        "E{B!!",
        "^\"'\"2DmK",
        "9X9]|",
        "BAD-TYPE",
        ":<9\\fm",
        "3wrQzoJ",
        "9.[Yq",
        "=&=1=6=<=F=P=c=h=",
        "Z3MUmA",
        "3 k0F",
        "Mioi2",
        "D-1I(J/",
        "g_6F=1}4",
        "j5Jx\"h",
        "t'jv_f;",
        ")_w&O",
        "=%`;u",
        "(R\\939",
        "C7A4)",
        "4!JqorRPu",
        "X}1D&",
        "[}xzr",
        "DjJW+{",
        "SSL_RSA_PUBLIC_ENCRYPT",
        "8#8*818k8",
        "9W':Ix",
        "3\\{(*8",
        "l+{TNor",
        "]Eww,",
        "[<pDU>",
        ";~lJ4-",
        "Jx)+s",
        ".Z|Aw",
        "Fa9y1d",
        "QeBe4!",
        "KAEONUninstall_X64",
        "6'O$a",
        "SetSecurityDescriptorDacl Error %u",
        "Wm{qT",
        "aJ&<i(b",
        "}igg;",
        "cB;]yb",
        "Jh|^\\",
        "WV~y6",
        "+x5<*",
        ";4;h;",
        "$0(_c",
        "9{`u/",
        "pbeWithSHA1AndRC2-CBC",
        "g*RC|",
        "?Z&2>",
        "8qaC[",
        "5NvRv",
        "t7]aS+",
        "fk6QC",
        "$F$@M",
        "P5=g>",
        "=4z\\z",
        "S7ya{",
        "Io&rkV",
        "929Z9_9f9m9t9",
        "=H=l=",
        "HSgt,",
        "x+sk'",
        ".?AV?$_Node_str@_W@std@@",
        "BitDefender uninstall...",
        "r4D_p",
        "_&zC$",
        "00:00:00:000",
        "YqFer",
        "Oz&[N",
        "QQj%R",
        "PnO-d",
        "Q|M)<",
        "hw+<=*N=",
        "U.x;e0jtO",
        "HMAC-SHA1",
        "R(l#9j",
        "+u&6]Jg'iB",
        "i)^RMe1",
        "87mie",
        "4$4l4",
        "f6__0",
        "526f7",
        "9J:aY",
        ",!h?Au",
        "Bpe},",
        "|C!fP",
        "=;0S&",
        "M-GCkA",
        "zuiQI>W",
        "~3+~P;",
        "\"'>D &Uj8",
        "wuS\\e",
        "N-w~c",
        "AD_DVCS",
        "b-iAa",
        " dQE:",
        "cgW1Y6",
        "7LNO v7",
        "\\trufos.inf\" /S /F /C",
        "message imprint mismatch",
        "Y=UU(b{",
        ":Bc>;+",
        "E)FqF",
        "\"-uyN",
        "smime_sign",
        "go-5v",
        "-a[pQ",
        "2xyXX+",
        "Dz i+",
        "Global\\tvperf_start_coll",
        "F9)<.f",
        " (jKf",
        "/dq!a*",
        "|$$t6",
        "/!/a/",
        "]7JOL'",
        "mFsUc",
        "UmX8n",
        "StopInstHelperSuccess",
        "RV[ghP",
        "YwJ(:F",
        "z*DH)",
        "*/(/'w1",
        "DHE-DSS-CAMELLIA256-SHA",
        "XC|C|",
        "jGLEh",
        "sC.2K",
        "o8g}|",
        "WD OD",
        "_unlock_locales",
        "^Rb|YZ",
        ">c)A~*a<c",
        "9Nb8-b",
        "vvxCD{Cp",
        "PUrY(",
        "krl`1",
        "cFZY4Q",
        "S:1V2",
        "JJ>JA",
        "%9bNX",
        "y!_DJ",
        "H`s.WU",
        "MvIfx",
        "i&&6DkG_&e",
        "7$7(707D7L7T7\\7`7h7|7",
        "1[e\\iq",
        "=FACi",
        "2;2m2",
        "V\"/^D",
        "dd.\\J",
        "|&Rl]",
        "_:nk<",
        "55#bfu#",
        "$/N=K,\\",
        "idea-cfb",
        "e!g(cJ",
        "%t,-q",
        "SSL routines",
        "*iS<4>(",
        "n?0Hkr",
        "NRCOo",
        "0=1a1",
        "=P]Vt",
        "+0fs<",
        "AkD[_7i",
        "t$$VW",
        "I\\+Y+",
        "Zcw&Y",
        "3V's:",
        "d!3Bh8",
        "S,WcJz",
        "~D_T/^/j",
        "D$(PP",
        "Z=4f4",
        "3&v3v",
        "jbZRX",
        "=XZ?j/",
        "sa9l$,w",
        "W6@'00s",
        "&EB1[,W",
        "StopAllServices started.",
        "ghDW1",
        "bad key length",
        "*+hNp",
        "pilotDSA",
        "failed to get length of custom action data",
        "x1V3}",
        "89@J#",
        "|y<+@",
        "l y%?",
        "SYSTEM\\CurrentControlSet\\Services\\TracSrvWrapper",
        "{\\XhK",
        "Cr7,0",
        "_u 5=\\|",
        "YYhpO",
        ". With respect to any pre-release version of a Check Point product, including a Beta or an Early Availability product (all collectively referred to herein as a \\'93Beta Product\\'94) that may be provided to You by Check Point fr",
        "_4Kb[",
        "U=rQc~",
        "Exiting installation.",
        "4!4A4t4",
        "ASN1 lib",
        "*:*@1",
        "SOCKS4 reply has wrong version, version should be 4.",
        "*6 #S",
        ">M>y>I?\\?",
        "Vjuh$",
        "96i!}I",
        ")T_i^",
        "\\FMl#",
        "oQ((s",
        "#5q;y",
        "5:5?5[5g5l5",
        "151P1k1|1",
        "ps$.P",
        "6P7f7",
        "?8?S?",
        "xr@A*X",
        "?W7es",
        "%;v3/",
        ">;>U>m>",
        ",?@JC",
        ">Y;Y*2J",
        ";4X)f",
        "]qx|(",
        "s%#>!",
        "b\\gx'",
        "4d8nA",
        ";#;a;i;",
        "_Cj#?",
        "G@,)(",
        "\"/ynT",
        "BF'v$",
        ";9;[;",
        "Xf#&b",
        "}em=P",
        "|$$SWS",
        "4jbRL;",
        "ERROR : Unable to initialize critical section in CAtlBaseModule",
        "08O| ",
        "~ 0AA",
        ",zG(U/aww",
        "DTLSv1 part of OpenSSL 1.0.2h  3 May 2016",
        "HhHxA",
        "O80MY",
        "{%q^_",
        "server",
        "3$3(3,3034383@3X3h3l3|3",
        "abcdefghijklmnopqrstuvwxyz",
        "3R4c4n4",
        "hCEWs",
        "}!mboM",
        "DestroyRolloverMgr():  manager pointer is zero.",
        "l)w2o",
        "6\\(VK",
        "';@xi",
        "L$T3L$",
        "old session compression algorithm not returned",
        "22Bfd",
        "ko79 j",
        "RXU~V",
        "jrjgj",
        "5&5?5X5q5",
        "i~@0gI",
        "zab~z`",
        "PreInstallCheck:  PreInstallCheck started.",
        "u^hh*",
        "&&`fP4",
        ".?AV?$messages@G@std@@",
        "0F/#m",
        "f\\EjA",
        "aVVfA",
        "``!4p)[",
        "]_u&=$",
        "Upgrade, stroring current EPCBuild",
        "X(\"y %",
        "^gHQN",
        "Is{[o\\jf",
        "v&gIXtd",
        "0123456789abcdefghijklmnopqrstuvwxyz",
        "i!JF9",
        "expecting a ec key",
        "U`{3*",
        ";!;&;C;t;};",
        "PUNPCKLDQ",
        "LohBr",
        "89&iq",
        "^T7r:*",
        "v[ssm[;",
        "dJxn<",
        "JAIR[",
        "ldL)\\f8",
        "GetProcessPathW",
        "N7`hc",
        " 5hg_J>",
        "Y=X14",
        "3]?\"I",
        "7%7/7:7D7O7Y7d7n7",
        "setct-MeAqCInitResTBS",
        "\\fi-180\\li2160\\lin2160 }{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703\\'02\\'03.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "\\lsdunhideused1 \\lsdlocked0 Outline List 1;\\lsdunhideused1 \\lsdlocked0 Outline List 2;\\lsdunhideused1 \\lsdlocked0 Outline List 3;\\lsdunhideused1 \\lsdlocked0 Table Simple 1;\\lsdunhideused1 \\lsdlocked0 Table Simple 2;",
        "p.zVn",
        "TrueVector driver: Data thread killed.",
        "ddb9p",
        "es-HN",
        "}261+",
        "a<%r)",
        "}WO)&",
        "oG1K/",
        ":+\\}M!7",
        "4gFL1KN",
        "{r#F%",
        " j/xb",
        "`^].M",
        "|W'LU",
        "IPv6 numerical address used in URL without brackets",
        "%8sSubject Unique ID: ",
        "Modification is not required",
        "PKCS7_SIGNER_INFO",
        "Vm0g@M=",
        "5f)cv1",
        "`5&wh",
        "LLL333",
        "=\"=/=B=H=W=|=",
        "B$,+'W",
        "DIMUU",
        "0.1H1",
        "QXzl(D%",
        "YVHTJ",
        "^,K*4",
        "sa3&k",
        "put_async failed.",
        "message extensions",
        "Enterprise",
        "4~/U_",
        "9!;g;",
        "Check Point Full Disk Encryption",
        "#ncv)",
        "PNy8}",
        "4fDq ! ",
        "Z_GI7mf",
        "-S-;l?",
        "fJ4S1XV",
        "jfjpj",
        "O>.>cb7",
        "`xxxF",
        "PKCS7_add_signer",
        "rOq^Xj",
        "k3kcQ",
        "&fn5'j*",
        "jD9`G",
        "C$:/c",
        "S2I_ASN1_IA5STRING",
        ";!;';7;C;I;S;e;k;",
        "555p5",
        "U@JVgO",
        "$d`D-laM",
        "LR2Brdg",
        "h*Yz!",
        "F<_@^",
        "_X_X^",
        "d2i_ECPKParameters",
        "808<8D8\\8d8l8t8",
        "K|Thg",
        "? ?(?4?T?\\?h?",
        "11A:}5",
        "MTQcM",
        "Kaspersky Anti-Virus 2009",
        "0Cd`Mj",
        "-(vswz",
        ".K`#/",
        "=.>:>f>S?d?",
        "whvS\"[",
        "@5F[x",
        "#\"_vdq",
        "H52KYD",
        "#vJ[Q2",
        "b+o-gc",
        "format error in CRL's nextUpdate field",
        ":,;8;B;G;X;t;",
        "1F3U3",
        "^o|('",
        "5!5=5Y5u5",
        "~*uyt",
        "otherName",
        "/}c4t",
        "The token does not have the specified privilege.",
        "#n&43",
        "4o5v5",
        ")\\I_b",
        "3iSW-",
        "0Rs+u",
        "?}y\\$B",
        "big\\?",
        "<.[j%",
        "}~V7'",
        " government, including the U.S. Department of Commerce, which prohibit export or diversion of certain products and technology to certain countries. Any and all of Your obligations with respect to the Product shall be sub",
        "n~QT6%Qt",
        "&2C~O",
        "i0i^ibih4",
        "_qW W4Q8",
        "k<9]D\\",
        "+|@:!",
        "odCnJ",
        "s;G<4K",
        ":shb4f",
        "ZwQueryInformationProcess",
        "pV.7A",
        "> >(>4>T>\\>d>l>x>",
        "E>5ah",
        "U3K4Qr",
        "tVORc",
        "bad protocol version number",
        "?]$c(",
        "/S\"4r",
        "l|#fX",
        "i1@Ij~R",
        "Mc$mT",
        " _^][",
        "D,e9YSSi",
        "5%5P5",
        "_____2",
        "cH+if6p",
        ">64Beq",
        "\\Counters",
        "`?6+GV",
        "?D?I?",
        ",b)K@Y>",
        "%f*.a",
        "o\\hgm",
        "!V0qZ",
        "DL_UNLOAD",
        "3 \\}w",
        "yOY}~",
        "B'M*z4",
        "\\`&SY",
        "\\proptype3{\\staticval 1}{\\propname lqmsess}\\proptype30{\\staticval 624256eb-0524-4977-8836-a6759041d44a}}{\\*\\xmlnstbl {\\xmlns1 http://schemas.microsoft.com/office/word/2003/wordml}{\\xmlns2 urn:schemas-microsoft-com:office:smarttags}}",
        "j0dpu",
        "6'6C6_6{6",
        "968;IhH",
        "/t#S0(",
        "h':BZ",
        "tNN<r",
        "r_t6_6",
        "`W?e o",
        "!qi!*_",
        "5\"5.5B5M5S5Y5f5k5}5",
        "%_6)WS:",
        "wqTW!",
        "EXTEND ASCII",
        "jAjxj",
        "7@PVW",
        "~&PSW",
        "/6,]D",
        "loadVswmi;",
        "(UD>7",
        "#+5!e",
        "WE](]2]=]G]U.",
        "loag4",
        "U(USd",
        "W+da?",
        "<!<)<0<<<C<P<W<j<y<",
        "m\\0T>",
        "host=%s",
        "YjMW{",
        "oInstHelper.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "G,;w0|",
        "#EC-/o",
        "'*=F/\"",
        "DriverCtrl",
        "oa)sO",
        "(H9D*",
        "]>b;9a",
        " D`8d!",
        "/3E}|",
        "united-states",
        "(|;Pn",
        "O7yIj",
        "hruLp)",
        "M!?;l",
        "Tdk27",
        "92999V9e9",
        "RjqB,",
        "2d395{5",
        "x|SG~P",
        "U15*0'",
        "$/cX'",
        ";-nRe",
        "'}o~Q",
        "Dnn6C",
        ";.w[{L",
        ";ZuB&",
        ".7ctX",
        "$[L[r[|",
        "#\"tXou",
        "r>HA=",
        "@HX/K",
        " YZd}",
        "?Ki&t",
        "WTMW~",
        "e?lOI",
        "space",
        "4'4u4",
        "R:-Rk",
        "=3o9)",
        "f{Rp(nO",
        "m7D*LL,",
        "1\"1B1z1",
        "eE/{^",
        "{7i'>",
        "BbYI6p",
        "X]a I",
        "5n^G|",
        "Pe^|QqAR",
        "fSexB",
        "fsJ;}",
        ">4>@>`>l>",
        "N9[f%U",
        "`AVQQ",
        "Jy5}5",
        "PEM_do_header",
        "`E1VU",
        "*X\\Hj",
        "#'#)#/#3#5#E#Q#S#Y#c#k#",
        "3\\3b3",
        "*lm*a",
        "<<T$e",
        "4-IrI",
        "language",
        " r18+I",
        "FX-F(",
        "MHSWQ",
        ";5<e=",
        "2keP?65",
        "-i6pO",
        "mq[tc",
        "ZBys6\\",
        "q/d$Xu",
        ")\\N}So-5$o)*",
        "6=.o=6",
        "2G,8#K",
        "\"BN8(",
        "PfK>]n8",
        "$3$3%",
        "kECDH",
        "t$ WU",
        "OII^c",
        "<`=g=",
        ".\\crypto\\x509v3\\v3_ncons.c",
        "Y,o$,",
        "QBDEl",
        "`?\\7e",
        "6.JRr",
        "Corrupt MpClient.dll",
        " you return to Check Point for any reason all programs and data not provided by Check Point with the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2260672\\charrsid15169477 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "V9PBW>!",
        "Wow64RedirectRestore",
        "desx-cbc",
        "Jersey City1",
        "u)h||#",
        "c5028",
        "`z<=uo",
        "VW@&v",
        "yvs!F",
        "(u'K6",
        "wpr`q;",
        "3 3$3(3<3@3D3X3\\3`3t3x3|3",
        "D&_S\\.J}f",
        "9<9F9O9",
        "5.5|6",
        "Ph(bG",
        "T$$jZ",
        "SchedSecureObjects",
        "6jce3V",
        "BVj(j",
        ">jaK<A",
        "0123456789abcdef",
        "U%q>\"0",
        "!TqgV",
        ".^4WQt",
        "DHE-RSA-DES-CBC-SHA",
        "8!838Q8V8i8x8",
        "=<Ur@",
        "nJojx",
        "EnterpriseChecks_Warning.bmp",
        "7G7N7V7",
        "`%vCc+",
        "t(Ph8",
        "j+jKj}j",
        "OQnOO[i",
        "0(0,080H0,2H2L2h2l2|2",
        "!~InwmP&",
        "8ETNO",
        ":7Q~Ka",
        "t ,59ZB1",
        "6t1\\/",
        "707I7b7{7",
        " o2b{",
        "YB^?H",
        "969R9n9",
        "[1wJi9",
        ",]EbAq",
        "dQfbf",
        "operator \"\" ",
        "^*l.%",
        "KL]5$",
        "tje5RL",
        "7i;b?",
        ".\\crypto\\asn1\\d2i_pr.c",
        "? ?$?(?",
        "333330",
        "aoMx)",
        "bhQ~v",
        "'&B??",
        "[%s] compressed file %s to %s",
        "zS~q$",
        "$*Z4]^",
        ":[F~s",
        "jzQMr",
        "Q.QjQnQrQvv{",
        "g3'_k",
        "L~U;Xl*",
        "5t5|5",
        "Error updating property: %s",
        "]B`Bbapa3",
        ")KK1Kbz",
        "Qh(@%",
        "z]=X~j",
        "3=\\VO",
        "SOFTWARE\\CheckPoint\\SmartDefense\\1.0",
        ")V4s/",
        "#\\TE|",
        ", SD:",
        "WD_ExtractFiles",
        "V_:X1:",
        "._Xz*MBh",
        "K\"7@6",
        "8}5xL",
        "<y;1(e",
        "oWH>+",
        "gj0}~~",
        "QD>Jk",
        "<Aq(n",
        "@M{DV",
        ",?zy8",
        "yu1D8/",
        "sb~\"m",
        " #;|:2A",
        "T`00P`00P",
        ">cFye",
        "pilotAttributeType27",
        "|EN\\-",
        "7k4Vp",
        "5qSC&",
        "xA=-%2",
        "Zr^M!o",
        "Qu 2e",
        "3h~New",
        "kKs[+U",
        "| ^S@gw1",
        "\";R!W",
        "g_NU!",
        ">o_OL#",
        "Content-Transfer-Encoding: base64%s%s",
        "SHA1 part of OpenSSL 1.0.2h  3 May 2016",
        "Rzwfu",
        "`vU0p+3",
        "Y&G/5f",
        "d/O\"&",
        "(7W1T",
        "FP<wq",
        "c2i_ASN1_OBJECT",
        ")EYM*",
        "!yx}v",
        " 0xda",
        ",)kf'",
        ">)?o?",
        "H1 }I",
        "AW6x.",
        "9@p;9",
        "eN059",
        ".PUe0",
        "xxu%K",
        "&R:T`",
        "{5Uek",
        ">#>2>@>Y>`>p>{>",
        "jLhp`%",
        "G&7Pcf",
        "||403",
        "secp128r1",
        "1F1f1",
        "Fn/&7j",
        "d.subjectKeyIdentifier",
        "3L$D3L$<3L$4",
        "JP*.D",
        "|I77:",
        "t-UVW",
        "1q1|1",
        "%sAuthorization: Negotiate %s",
        "k30n`",
        "(\\<[p",
        "0\\2`2d2h2l2p2t2x2",
        "EqualSid",
        "hSSs3\\",
        "24282@2H2P2T2\\2p2x2",
        "t5MuFbr,",
        "9X:T!T&",
        "Xgw@s",
        "c_$tU",
        "(Dr(QNZk",
        "FLA\"0",
        "N&.r\\5",
        "x!j$Xf9",
        "\\fs20\\insrsid3428060\\charrsid3233976 our }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid3233976 property.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid4410457\\charrsid3233976 ",
        "v.Wh2",
        "1q.rw",
        " bDJ\"",
        ":(:H:P:X:`:l:",
        "^ `r2",
        "rEh2kP",
        "F.(xt",
        "66wf5+",
        "Z3Rdh",
        "GrRU9",
        " ST;$uF",
        "SGsu,",
        "%&&_;",
        "load unsuccessful",
        "$Qy\"6",
        "Ws;rmJ",
        "V-.PV",
        "D$(tbS",
        "ptA&t",
        ">2Y>k",
        "Hmo`M?",
        "/_:55",
        "z-2fj",
        "]C@1%",
        "4]zy&",
        "\\/Yb.",
        "c*kJMo",
        "s8=F!Gl",
        "L'ORT",
        "?Q;W%L",
        "SHA2 signature is supported",
        "i/rH-&t",
        "#~dMesX/",
        "<s={=",
        "F(c44`",
        "OnCancel",
        "+y|^Q*} M",
        "OZw3(?",
        "Ak20#",
        "|AHI#",
        "d.pwri",
        "KG>XE",
        "LbR4pBj",
        "M.5i2>",
        "X,uVQK",
        "m/sSp",
        "$74.8/z",
        "evw;)",
        "b$*nhr",
        "T,(3t",
        "##wMK",
        "}IujL",
        "Bc1eT",
        "6;6`6",
        "?&k,C",
        "Wu0WSh",
        "~2Pj0",
        "J!Wf-",
        " verify {AC30BFB5-834B-46d2-B912-6CE71684EB2D}",
        "c9O;jz",
        "TDlqQ",
        "jzkhh",
        "F$&!6",
        "EK4h~",
        "Could only read %I64d bytes from the input",
        "P*S d",
        ")aM3y",
        "rI/qn",
        "-[kQ?",
        "Lm3d[A",
        ",a.Il",
        "]3SGN",
        "}9p(Y5",
        "CA|JJ",
        "CLFLUSH",
        "#8rn7 ",
        "g'z?sg",
        "shutdown.exe /t ",
        "QH.$B",
        "o<wzii&",
        "75h2C",
        "0$0,040@0H0p0x0",
        "64686P6`6d6t6x6|6",
        "jch0c\"",
        "H%x^r ",
        "vstor_redist.exe",
        "n`yKxuIX",
        "?$?6?@?`?",
        "X~MBW",
        "6:7{7",
        "/7;cK",
        "4@5Mq",
        "={q@+w",
        "Vi,3dl>V",
        "InstallationStarted",
        "Y7`mh",
        "n@eb5",
        "?9'fg",
        "3KJt?",
        "DY/z2",
        "0Z?JsA",
        "-JW)=",
        "_n/2^",
        "45@B;",
        "_&G<S",
        "(?=SV",
        "~X=,}",
        "GdB`X",
        "7mblE\"s",
        "Zd]\\Af",
        "xp/lR",
        "G3^9)",
        "|Ja_8(j|z/",
        "1?Z^UT\\",
        "\"W^I!",
        "\"_&e%m",
        "-Bq3#}D",
        "r w%;",
        "^}.aP ",
        "D[8]I",
        "SEC_E_NO_AUTHENTICATING_AUTHORITY",
        "l}ev@5",
        "Q:Ke+",
        "?Ml*}",
        "geZjG",
        "no verify callback",
        "An unknown option was passed in to libcurl",
        "Kaspersky Anti-Hacker",
        "^*)YA",
        "i |V~z",
        "].:Jgr",
        "2D={k",
        "t{&%Q",
        ".{:i9",
        "hUpi0",
        "ex:j_",
        "F0!`LEX",
        "4 SqBd{d",
        "Found cached FDE installer",
        "'hOx[Q/",
        "] [,;",
        "4igZH",
        "Jg1J^",
        "w8A.| ",
        "not a square",
        "}r5zw",
        "8T;U&=WS",
        "y8Hf'Z",
        "738S8",
        "SubmitThreadpoolWork",
        "x51pb",
        "dJqMT",
        "uR9GPuK",
        "})f0)@",
        "M5MUMuQ",
        "_xt.B)",
        "2Amj)",
        "RemoveSC",
        "rlpF;",
        "<Z'FDp",
        "!NXF`m'",
        ";D$ u'",
        ";qn][%F",
        "IE-`E",
        "'Symantec Class 3 SHA256 Code Signing CA",
        "4!4,4?4F4t4",
        "q&Q&EO",
        ".?AVCLicenseFileMonitor@@",
        "GetRolloverMgr():  manager already created.",
        "L$T3L$X3L$",
        "N@u3B",
        "X509_STORE_CTX_new",
        "4.=_9",
        "8 8@8L8l8x8",
        "kk-KZ",
        ",Q@nZ",
        "SELECT `Name` FROM `Binary` WHERE `Name`= ?",
        "6D6h6t6",
        "[u9(1",
        "Q)R!\"C ",
        "0:64-\\",
        "Fm% d",
        "8?t$x",
        "+@RN2",
        "i,0Ix%",
        "IsBinaryExist failed to GetActiveDatabase. Error: %x",
        "b}tteZ",
        "37U#F",
        "MNi@p",
        "5evD+3",
        ";NMAxn",
        "uX?qFve",
        "T6Bx ",
        "nF$x7{",
        "AC@,wLf",
        "khDB'",
        "pFsC*",
        "LtK.RQv",
        "]]300",
        "^]1sE",
        "0@1c1",
        "D)/\"e",
        "_3.#?",
        "InstallPrerequisites started",
        "FPq)^W",
        "Yp4W-O\"",
        "!hlY17",
        "!P~%xX",
        "$:h4n^]",
        "Fu&D4e;Z",
        "qZHw&",
        "n rU8",
        ")xZ<]",
        "KHakG",
        "J0kzM/3",
        "212C2}2",
        "rF;Ka",
        "SwK>e",
        "A0H0O0V0",
        "<<=l=",
        "AQ!~g[",
        "`'Li+j",
        "|^cd.",
        "2hc2}",
        "9(949D9T9X9h9l9|9",
        "B=t;Q",
        "9g/gw;c",
        "[f9^,u\"",
        "L1<I9(",
        "^p8C^",
        "TSDrp",
        "WIX_ACCOUNT_NETWORKSERVICE",
        "nF_qw",
        "j0?l1",
        "J$O&&",
        "FgJW@",
        "#5FJ>7",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 as Check Point specified in }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "6M6Z6",
        ".uoP!",
        "DcuzN",
        "<iIlo6G",
        "W=HXY",
        "^sQPL5",
        "*0.+W",
        "<,<0<4<8<@<X<h<l<|<",
        "'zPZ9",
        "Exu)DM",
        "i\"C:K",
        "_xp]f",
        "929K9d9}9",
        "ZC~!Am",
        "%JsZ!`",
        "w%Nl3",
        "`,TeV4",
        "vG<O3",
        "mMw\\;-",
        "%Y!Mo",
        ")T;yni",
        "BJq{I<",
        "z'ynkC3",
        "7kzUgV",
        "jh?M,",
        "IH&nn2l4V",
        "6o]&r$l",
        "i2IS)",
        "&HH^h\"",
        "ML]]]5A]]]_M#",
        "oMZp_",
        "9%9_9|9",
        "~aIy3",
        "DG=b@",
        "{W:<I",
        ").F}J\\<",
        "<(<4<X<x<",
        "[VSDATA LOAD] InitializeSecurityDescriptor failed: %d",
        "BXrUr",
        "bB5rn",
        "@'j|Ft",
        " u#&3",
        "CJ:bc",
        "\\`B`3",
        "bRQL&",
        ">Z?p?",
        "lr9vM",
        "F7c]t",
        "Rm{Tx",
        "NO_=;",
        "7$7n7",
        "?WmK_Vr",
        "G3f%-",
        "`KQE2",
        "3t$P3t$(",
        "T9\\AB",
        "ESCehE",
        "_<K9+",
        "6(6L6l6t6|6",
        "oQN}[",
        "J)[V=",
        "<Hh/#V",
        "c*|+D",
        " H&=e",
        "L4qio",
        "A%#P%",
        "8\\R^x",
        "4/xNs@",
        "k~%Hb",
        "DE4(`",
        "7\"7*707>7r7",
        "26n#l",
        "GF5x%-&^",
        "compliance.exe",
        "#iV7$",
        "M7]8a9a",
        "wcawow64.cpp",
        "};hSw9",
        "!s9OHg",
        "Ume&x_",
        "0!0A0a0",
        "Y`qy6<",
        "PPPPPPWP",
        "3C>;T@XYSxg",
        "> !?Y",
        "{@s<-",
        "$bM:wA",
        "@&_d>",
        "Np'y`&",
        ".)WPGt{",
        "J`1tX",
        "\\$\\VW",
        "$9l$$",
        ":I~VEsn",
        "\\FTSJ",
        ",<gH!",
        "n.N;^:",
        "kCush",
        "Y><Tg",
        " pXr{",
        "]u:xa",
        "hB I2",
        "V]Sl!",
        "v5I[3",
        "8Y$kG ",
        "PGZu7",
        "*h3Cv",
        "u!MHT",
        "t$4WW",
        "k]6XW",
        "FeatureAntiSpam:  RemoveAfter:  mantispam.exe is stopped.",
        ":C;H;",
        "cannot obtain CurrentMinorVersionNumber value %d",
        "1fPmpt",
        "@*z)M z",
        "FNWw ",
        "Km:>L",
        ",Ejf@",
        "0)0.04090a0f0w0",
        ">[&3IN",
        "T9>e)",
        "6$6@6\\6x6",
        "m39-<",
        "universalstring is wrong length",
        "Zr9q'",
        "5&&$\\L8A",
        "50?C9mMk",
        "^|P\"(",
        "Vlf7R",
        ">*]?|T",
        "?#8r],Y",
        "kl*wo",
        "keyEncipherment",
        "dhSinglePass-stdDH-sha384kdf-scheme",
        "k)Q~P[! ",
        "failed to extend progress bar for InternetShortcuts",
        "SSL_ERROR_WANT_READ",
        "TELETEXSTRING",
        "failed to create output pipe",
        "}_|mPG@j^h",
        "Yo+#&",
        "e??.1a",
        "<:t2<,t.</u2",
        "@@I;jb1",
        ":';U;",
        "^Dg>=",
        ":*:1:M:h:n:",
        "Reboot flag is TRUE",
        "`B+u+",
        "I07:x",
        "Y[J|~QSB",
        "@pQ+'{(",
        ",QmN/",
        "e-F9QL",
        "Ojc$R",
        "^TlJW",
        "5tw>[{",
        "Failed to start service %s. error %d.",
        "[VSDATA] Clearing client with pid = %x",
        "tfwLk",
        "%-M{z",
        "0]8.,",
        "lN'Fb/C_7",
        "]Y]}_",
        "z^fEd",
        "XAc,g",
        "j/yP_",
        "F@kdo",
        "InstPrep.exe",
        "1\"2S2p2",
        "Y~1|TFH",
        "uGZ}cym",
        "l*&5{",
        "[,KH6",
        "8#T0B",
        "l}6.,",
        "TA~jz",
        "VerifyInstallDirLength",
        "wtfzmt",
        "PKCS12_item_pack_safebag",
        "2$2T2{2",
        "[/f,U",
        "9(969D9R9_9m9x9",
        "yJ}/M[",
        "Pj9|e3",
        "-9K$e7.8",
        "*b'zB",
        "iMci7JG}_",
        "969V9",
        "'[3a{p",
        "DW{k6",
        "9$919H9N9U9w9}9",
        "L=BQ1",
        "8ZoM\\",
        "\\INSTALL.LOG",
        "?+tHahc",
        "KERNEL32.DLL",
        "t*jBh",
        "<V1#O5fZ",
        "*%H@!",
        "X1!mW[Ucc",
        "*R,%<",
        ";$<V<",
        "2>2X2",
        "X&`sV",
        "CM-S(N",
        "EKj\"aW",
        "&M^#^0",
        "_PSE2:",
        "00*l^%2",
        "Cl*1\\S",
        "8%8*8E8a8",
        "9F9S9p9",
        "rpT~(_d",
        "IswMultiReadSpinLock::ValidateLocker - tid=0x%x le=%u",
        "<gf.o?",
        "Lh}hU><",
        "b?))|",
        "5 WiR",
        "VMPTRST",
        "Y>!QR5c",
        "TH(0Q*",
        "bm&Tm",
        "nq#hE",
        "R[6BX",
        "Y]dsS",
        "7$7D7L7X7x7",
        "]L~TkA<h",
        "{rGC'",
        "PWShx8M",
        "Onx9T",
        "7(7H7T7t7|7",
        "{wE6,",
        ".gQ#U",
        "R\\?f+",
        "???K?d?",
        "?#S\"MB",
        "-!-a-",
        "KzlE%",
        "`X9Hp",
        "xs}Rj",
        "VAP;'",
        "c;Qv%",
        "F4FDC53",
        "D8TH3!",
        "id-smime-spq",
        "|A\"m5DE",
        ":$:7:>:Y:b:r:",
        " -.T%",
        "Jd\\%n",
        "atlTraceNotImpl",
        "E23/:.",
        "$N.#2",
        "Corrupted sugnature",
        "YrZ/xS",
        "mOY>A",
        "hn[bsd",
        "BrSJF",
        "D$ 9D$4t",
        "%Ww8(",
        "z.<lL",
        "}u`O'",
        "m o}\"",
        "Bf%g_",
        "camellia192",
        "%tPY8",
        "Q>/Z[",
        "ecdsa-with-SHA384",
        "hvgPM",
        "D$4I@",
        "<c=h=",
        "?OSM|",
        "Ssn(@",
        "F1'F`+",
        "Y^M|>",
        "EVP_PKEY_encrypt_old",
        "]3^s^",
        "kLx1b",
        "wXSr^",
        "1_w8M",
        "|Sr;`t)",
        "YLYVYWYX,",
        "Ty9lc.",
        "?S{tB",
        "epcgina64.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "}q7`[",
        "8*9/9Y9^9",
        "yr`h\\",
        "tD&&U",
        "y;{y-",
        "a9NA9",
        "Ut|/?I",
        "guCLn",
        "pi2y85",
        "dt\".v",
        "9Iawd4",
        "L7OpR",
        "2}D2s",
        "G,R^c",
        "1t1'w",
        ")_4aHaTa:",
        "qpO$<8",
        "vjnJR",
        "RW`jn",
        "{S}po",
        "w8CkV",
        "'7=2y",
        "i_? :",
        "^6O\\/n7h!.,j",
        ">#E&g",
        "hX9&H",
        "2B 2y",
        "vn+qg",
        "__wbR",
        "1(161E1[1l1y1",
        "ODF_RULESX",
        "L'gzp",
        ":>)r.X|",
        "dB*LGk",
        "548s._+*j",
        "AIk d",
        "Lp-U%",
        "%w0nv",
        "Y1c]i",
        "G1qe1",
        "4$4(484<4@4D4H4P4h4x4|4",
        "Wd$vt",
        "memory buffer routines",
        "bad generator",
        "J1WEF",
        "+\"*(v2",
        "|ZW*YE",
        "ml8Su",
        "SOFTWARE\\KasperskyLab\\AVP7",
        "Sl|T<",
        "w%I'5",
        "3$4/4?4H4X4w4",
        "dzxZR_",
        "?cK`1",
        "D$pSUV",
        "Tt.jh^;",
        "4}uJ=",
        "EWV]zs:",
        "[c7po",
        "$=t4H",
        "uQPVj",
        "\"d>jx0",
        ":3:?:T:d:r:",
        "jejxj#",
        "f}CmHc",
        " K6&D",
        "EY^e+^",
        "Dy4%;O",
        "z{6F.t",
        "c=C<~",
        "Q3SeI",
        "mi-nz",
        "{{G!3",
        "I\"#'y",
        "{]d!u1Sv",
        "P)5s(=0",
        "2hO^9",
        "R @FV",
        ".ifhB0",
        "42-D7",
        "%,KCt",
        "9+9o9",
        "attributes[0].value",
        "<-3W%h",
        "&$c$F;",
        "id-GostR3410-94-CryptoPro-D-ParamSet",
        "vIX*\"W\"",
        "$wL4|l",
        "ztr/X",
        "RO/;z",
        "}}B#y",
        "#gdWR",
        ">@?]?",
        "9Eh_+",
        "#VMZN",
        "Mr0=lo",
        "]4FLU",
        "30oO^",
        "=)]mb",
        ".tO}h",
        "},oj) [g",
        "-$te_",
        "'F.[Tc",
        "2gRtI`",
        "OTJ8L",
        "h'(@=",
        "bad dsa signature",
        "Helper::stopABService",
        "Failed to create driver uninstall process or this process hung or returned error code.",
        "eYlYn",
        ";\"?g)Uf",
        "SZU3C",
        "m2y{f",
        "jq4nw",
        "B[x?%",
        "WSACreateEvent failed (%d)",
        "&@'kd",
        "&bQ7m",
        "{\\!:C",
        "u.$vFo",
        "v0kE%",
        ":x<U:",
        "2'2C2_2{2",
        "english-can",
        "ENGINE_add",
        "EC_ASN1_GROUP2PARAMETERS",
        "R3aF1",
        "i E4im",
        "H=>I>r",
        "M7uo7h ",
        "no section",
        "lTte!",
        ".eAzqv",
        ":\":=:T:_:g:m:s:{:",
        "0\"1E1",
        "/3TTD2",
        "Soz$-FdC",
        "Y-3V3",
        "c`s2i",
        "4y5$6",
        "urhpZ[kl",
        "t$<WRP",
        "policyConstraints",
        ";\";:;@;J;a;",
        "a?W^n",
        "McAfee Personal Firewall Plus",
        "R=}.6",
        "44]O-",
        "i#shC",
        "Ze(#j",
        "B\\wnv",
        "J[MqU",
        "<Xg:U ",
        "/l5=D",
        "p#W?Nc&4",
        "V.RW.",
        " \"$bKC",
        "j>EY[ny",
        "GV*JR",
        "({nm<|",
        "imZF'",
        ";@BL-",
        "Q+QKQkQ",
        "2K3L4",
        "2 3(3L3U3z3",
        "YYh01",
        ":3:g:",
        "}F0tmw",
        "m;mbH",
        "BRG*Cf",
        "Insert file: MsiDatabaseOpenView",
        "C*PjTW",
        "<d6^#",
        "~W^Vh",
        "$8MxM4KH",
        "yw'0&",
        "],)~f",
        "R#$)M",
        "2SRXP",
        "W/OB&(",
        "(c!V!",
        "<3&r-",
        "_b;CX",
        "zg>'!",
        "]Lht\\",
        "*}OOYZ",
        "stream error",
        "r*@WE",
        "l$Ht]",
        "h8,4$",
        "dTZV-Q",
        "Y=Q#9",
        "pop3s",
        "SecureFile:I:ravpn_is_v1",
        "sZDs|",
        "7_jSO9",
        "\\{[A-F0-9]{8}-[A-F0-9]{4}-[A-F0-9]{4}-[A-F0-9]{4}-[A-F0-9]{12}\\}",
        "=,>aYJ",
        "(\\_!E",
        "pYXo{",
        "^)\"d(",
        "C{->:",
        "080D0h0",
        "r/er8=",
        "<:m;X",
        "H)!SB",
        "PasswordVerified RC=%d",
        "9[;v;v<",
        "5$5,50585L5T5\\5d5x5",
        "{qBaXaFa",
        "Configuration=WIN32/release.dynamic.msvc141",
        "}5$aa",
        "GetInstalledVersion: AvSDK value does not exist",
        "^ '[BG",
        "A'k)qb1",
        "SEC_E_CROSSREALM_DELEGATION_FAILURE",
        "OFqs7",
        "AES-192-CBC-HMAC-SHA256",
        "iS=g9 ",
        "\\$tWS",
        "{!PR!",
        ";1;B;W;\\;",
        "a <xxa",
        "e}6q{",
        "Utv@b",
        "|$<WU",
        "=K=Y=u=",
        "aes-192-ccm",
        "Xgh%Wc",
        "lmx_MD_vs2017x86.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "AHPQVR",
        "c,`f0z",
        "P.WYu",
        "TG|Lx",
        ";=;^;]<}<",
        ":DCGA",
        ">\">->5>E>L>`>n>t>z>",
        "1<d%`",
        "fsEH'",
        "$Y-Y<YAYIYWYm",
        "An1(4",
        "z#Ty~",
        "sect131r1",
        "DL^U]7",
        "^]9[7",
        "N#Q|6",
        "6]S^h",
        "_%%HW",
        "1D q}",
        "WBsl4",
        "]XA1#AR",
        "/!;b=",
        "L14E4m4",
        "K32GetModuleBaseNameW",
        "P?HFC",
        "|VGMfc",
        "_m\\SKW",
        "7]o,1p",
        "ubOZn",
        "\\i*pU",
        "oRYUb",
        "M/MOMoM",
        "Wph:~#",
        "\\($a[l",
        "HqI9x",
        "Failed to allocate path to clean up CAScript file: %ls, hr: 0x%x",
        "_%gSPQ",
        " vPp ",
        "\\<aM6",
        "GSIhG",
        "RMnJUx",
        "Suppress reboot because user chose to reboot now.",
        "R`#je~^",
        "[DUMPFILE EXCEPTION] exception %x at %x",
        "8*8~9",
        "bOR;&ks.",
        "V;jcZ[tc\\C",
        ": :<:@:\\:`:",
        "9+y:`",
        "R >9_",
        "SOFTWARE\\KasperskyLab\\sdk\\AVP8\\environment",
        "ADH-SEED-SHA",
        "ivlfF",
        "!G4n8",
        "T*$@b",
        "y5Y@=}",
        "\"I<\\=",
        ">5?P?u?",
        "qX-KV=",
        "][X?e",
        ";<Msz",
        "Z80kI",
        "*NAb#",
        "8WSUU",
        "unable to extract public key",
        "xr=.z",
        "mp}0Z?3",
        "jr|8E",
        "/^Vra",
        "DVlTn",
        "c7~?5<r;",
        "0s0z0",
        "zEao|v",
        "jej|j",
        "'cWhy",
        "0123456789abcdefghijkmnpqrstuvwxyz",
        "])E%#",
        "EC_GROUP_set_generator",
        "R2\"/ ",
        ";3;A;U;a;p;",
        "Xq-7;",
        "K0&Hi",
        "L63a>ayRT",
        "B=cO9~",
        "rQ8AS",
        "8l.e;",
        "failed to write exception port to custom action data",
        "(<]}S-=qt",
        "@9b Y-",
        "s5/~;",
        "6l8{@eO",
        "@d@+d|",
        "Y\\j`+_",
        "?(?0?T?h?|?",
        ":N^@6",
        ";/;^;f;",
        ":~aaK ",
        "+Ae`t",
        "~VPSU",
        "=&=+=f=k=",
        "U@iAk",
        "{_w8B'A",
        "VvQ$S][",
        "t*h\\X",
        ".?AV?$sp_counted_impl_pd@PAXV?$bind_t@_NV?$mf0@_NVCRolloverMgr@@@_mfi@boost@@V?$list1@V?$value@PAVCRolloverMgr@@@_bi@boost@@@_bi@3@@_bi@boost@@@detail@boost@@",
        "5TDrY",
        "9 9<9L9X9x9",
        "y]jgN",
        "VUgSS%Q",
        "+VaSYv3",
        "P`zHp",
        "^)+=JIR7{",
        "4:4^4",
        "'<z2$",
        "E5Um ",
        "8>x@z",
        "<(=U=",
        "8F9q9|9",
        "z\"]7Ns",
        "DuplicateTokenEx",
        "~ 'h=",
        ",[2K_",
        "CXiHbc@",
        "TaNlw",
        "xi x ",
        "j_$\\*i",
        "jojyj",
        "/,-KQK",
        "?$?d?l?t?|?",
        "1.1?1g1v1",
        "L$,SUV",
        "[WinFW] SetWFStatusVista, failed to set domain profile, error=%x",
        "Failed to read value InstallDirectory",
        "Arg list too long",
        ".\\crypto\\rsa\\rsa_crpt.c",
        "NU(4Qd",
        "\\{xaH",
        "KcGRF",
        "F76~{M",
        ";e;j;r;V<",
        "Vh1.#<",
        ",x mu",
        "sNjM{v",
        "u?pI2",
        "|$Xj4",
        "nC/D9",
        "r7jfqQ",
        "=1=I=5?",
        "XP$UJ",
        "w<)pA",
        "!<pzw\"-",
        "[PERFMON] LoadProvider - already loaded",
        ".\"7'B",
        "CDab7",
        "^hxhs",
        "DW+Uc",
        ".%/%/%0",
        "g2kjU",
        "f,Tx.",
        "j#%/v",
        "555q5",
        "z@wbd>",
        "[PERFMON] provider %s failed IsPEFileValid",
        "W|W3]",
        "g=pAH$-",
        "SVj(h",
        "ug9u4",
        "1$Sw]",
        "zKL*'",
        "U}aSC",
        "no content",
        "=&bdH",
        "<R&i6;$L",
        "c=;h1pM>",
        "5 Gh%",
        "8<8G8]8",
        "Ty987v",
        "3t=x=|=",
        "HKLM\\SYSTEM\\CurrentControlSet\\Services\\vsdatant was not found",
        "SuppressReboot",
        "j~juj ",
        "\\ipgp3\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp29\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp29\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp19\\itap1\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp19\\itap1",
        "Ek!mZ",
        "&SMU\"",
        "d1kV'",
        "PJJCB",
        "no such file or directory",
        "CrL$!Bw",
        ";C;I;R;s;x;",
        "PSLLQ",
        "%/QOX",
        "MAILSAFE",
        " ui level != 2 -> NOT silent -> Other",
        "PostMessageA",
        ".CRT$XIZ",
        "4F0:W",
        "n&#LH",
        "ir^4_^`_",
        "Configuring product, this will take few minutes.",
        "8%8V9e9",
        "gr{^S",
        "D$xSUVW",
        ")o~1Jd",
        "V>Q*y",
        "setpass ",
        "Registering EAP zlxeap.dll",
        "LFnsSb",
        "<$<O<{<",
        "3 3T3d3p3",
        "P\"gII",
        "id-GostR3411-94-TestParamSet",
        "t;;<\\",
        ":Geyt",
        "1Td9Wt",
        ".?AV?$clone_impl@U?$error_info_injector@Vbad_format_string@io@boost@@@exception_detail@boost@@@exception_detail@boost@@",
        "-jd4r",
        "jgjxj&",
        "()%Z1 ",
        "p[aO{",
        "yhm_w",
        "Wait for a request timed out after %d seconds:  ",
        "j@j%V",
        "Elj+@)",
        "|.?,?",
        "3dk4k",
        ";0;;;C;S;d;",
        "9X)}z",
        "8vx~/",
        "a,!6T",
        "4f}~I",
        "nixC;",
        "hUU/H",
        "a&MVsu",
        "]RxzLf",
        "W _rJ}F",
        "5)5=5U5",
        ">m?q?u?y?}?",
        "setAttr-TokICCsig",
        "http://www.digicert.com/CPS0",
        ".pVFX$H",
        "8#8w8",
        "JxyN9",
        "XfdTE",
        "Vt?1Y",
        "yG:l@",
        "JU}Lm",
        "Failed to load CRL file (path? access rights?, format?)",
        "Ttdk\\4",
        "?N<1b",
        "DTLS1_GET_MESSAGE_FRAGMENT",
        "m-Y=DWc",
        "}yc0k8",
        "in use",
        ".E9y3",
        "OW3nN",
        "****************************** SetVnaInstallProperty ended **********************************",
        "los[u",
        "Wz.VG*",
        "dFj|5j",
        "o.GE?",
        "@V`U`]`]`} ",
        "Avoided giant realloc for header (max is %d)!",
        "E,^*D",
        "6b&^5<*",
        "e;[<a?M",
        "SELECT * FROM File WHERE File='%s'",
        "TFTP finished",
        "SUITEB128ONLY",
        "u$QrS",
        "ig]gCD'",
        "V 4us_",
        ":@:n:H<T<`<n<",
        "gAef,",
        "tvVW3",
        "]No]]",
        "Sg,!Cyi_",
        "szEventGroup",
        "B^*V@",
        "A|qVr89",
        "zB{Z|",
        "dW^$c",
        "\"-`Z)",
        "9 9$9(9,9094989<9@9D9H9L9",
        "3+4L4d4w4",
        "O%SAUAWA[A]A_A",
        "%N5$N",
        "Unable to load Direct3DCreateEx function, so the driver is not a WDDM driver.",
        "VSInstallerCancelEx(%08x)",
        "g7`l-",
        "#QfDHI",
        "|QDVs",
        "8\"8_8",
        "A(V9qU",
        "A4?^\"p",
        "783\"p",
        ".N5Ht",
        "72787>7D7J7P7W7^7e7l7s7z7",
        "Phe5g",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11555386\\charrsid477636 ",
        "EGe1C",
        "7zppn",
        "=5=N=j=s=y=",
        "?4?R?s?",
        "0{BH4",
        "idea(int)",
        "^.(N}W",
        "c.Y5X",
        "(4IfC",
        "X#IPag",
        " S35/,",
        ";^D 7",
        "5%5X5",
        "failed to get firewall exception component",
        "hzR,F",
        "mR9@N",
        "Failed to initialise SSL crypto engine",
        "n%,A1",
        "*RAkE",
        "v[1+N",
        ";(<H<h<",
        "zC{V+",
        "7zwy!U",
        "D3F3f",
        ".?AV?$basic_ios@DU?$char_traits@D@std@@@std@@",
        "Q];S!`",
        "bW)wa",
        "jwjtj.",
        "Dh@<U",
        "~q%yq",
        "32zP\\>",
        "k>U[uK",
        "biyX~sT",
        "VIT]0",
        "=)n<K",
        "p?l=D",
        "ojZPP'#",
        "Tmw1_",
        "<$<,<8<X<`<h<p<|<",
        "<#<?<[<w<",
        "S<[3F",
        "raq?C",
        "f65sz",
        "d@h6O",
        "!:AP]`",
        "3U4Z4_4d4",
        "::<D<I<i<",
        "6\\_8b",
        "pp'-)L",
        "rQ`(@",
        "4dl~\"d",
        "S8lfl",
        "OUTPUT MARKING",
        "w]/zq",
        "3-383",
        "EpamService",
        "NHnK\\",
        ")4s$6",
        "46@qn",
        ".\\ssl\\s3_lib.c",
        "U|U45",
        "X?r8[",
        "?y/Sa",
        "=b6Kn",
        "#:)qd",
        "_f&:S;{",
        "-(L~?",
        "EC_GFP_SIMPLE_SET_COMPRESSED_COORDINATES_GFP",
        "`vf#0cB",
        "i[`,(?",
        "jijlj'",
        "mcGS&",
        "CQQ%:!",
        "Error in the SSH layer",
        "4?4k4",
        "/3B>_",
        "unngn",
        "bmR^J",
        "uGj/W",
        "nssslserver",
        "7<t8F",
        "'Gf\"41",
        "13R{c$#",
        ".\\crypto\\ec\\eck_prn.c",
        "8)8A8",
        "<&>8>",
        "tqyxB",
        "=Zk+*",
        "X509v3 Basic Constraints",
        "&&/&N",
        "/3W]Yh",
        ",;)yh",
        "SDL enabled going to disable it",
        "d[o@^>G",
        "Q/@ai5",
        "^2QDe",
        "Ktbzq",
        ";]{z~",
        "S\"9C1?",
        "(a&GCN",
        "}/\"W9jn",
        "5>5E5",
        "\"N~33",
        "-aY|p",
        "SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\ScvMonitor\\1.0",
        "90&NN",
        "?U|jfp?",
        "({\":N",
        "/y:5N~",
        "< <&<,<2<8<><D<J<P<V<\\<b<h<n<t<z<",
        "qpS47",
        "}ZW$Em",
        "\\$$UV3",
        "h=?Of",
        "29];|?",
        "Od.^'$m",
        "acG:x=d",
        ";&~7/l",
        "i]f3jO.",
        "toj?V",
        "FNIRo*o",
        "7@[<c",
        "Permanent Identifier",
        "F`grRZ",
        "a\"S5x",
        "atlTraceSecurity",
        "*BN,v",
        "HF3~j",
        ";v0[}",
        "l3eWu",
        "#bOc@l",
        "0Z^2S@",
        "u WPS",
        "v2o-k3",
        "MHAoK",
        "|vdX\\",
        "B'wStX",
        "+\"jP{/",
        "dNCYZ",
        "]H\\j$85",
        "9X]54",
        "ve=1vtzB",
        "$6K &",
        "<:<V<r<",
        ")#&`j!",
        "'_=v*",
        "7)L@~x",
        "X-/;I",
        "vsmon_Live",
        "|ua$=W?p",
        "U]s4h",
        "FcV}W",
        "9\":;:T:x:",
        "y<%'#",
        "]:Ky)",
        "receiptsTo",
        "]PtqK",
        "Dy7/7^L",
        "SaveVpnRegistry",
        ">D?R?`?i?",
        "8We4!",
        "\\`iWv`",
        "RI\"H!x",
        "WcaNotVerboseLogging",
        "vsdatant_win7.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "MtH95",
        "tu9H!",
        "v#4B ",
        "S*`!]",
        "uM8* ",
        "y^'^!u",
        "yvTHY=W ",
        "preferredDeliveryMethod",
        "#m,(pZ",
        "Saving DisabledAdapters...",
        "GlPx2mT",
        "Fb5t<",
        "'i#c9)0",
        "3G~&&",
        "t(f90t#",
        "ihmW,F",
        "v9QhH",
        "peer did not return a certificate",
        "error parsing set element",
        "CreateSemaphoreW",
        "ZrKM-.",
        ":5:[:",
        "W>@G/",
        "+=i8jT",
        "uVbM~O",
        "l4o  ",
        "<c<j<y<",
        "2Ay/@",
        "ETfND",
        "^z'JA",
        "2iiSY",
        "ddDN,Z",
        "Z)&xw",
        "oT>6sW%",
        "=RE8 ",
        "3MNyEk",
        "zJ3SYyp",
        "Ua&3)",
        "7t=~!",
        "\"5JAj ",
        ">[w)#",
        "9cS4w",
        "8=xEj",
        "affiliationChanged",
        "JR']\\kJ",
        "@%m0(,o",
        "/lFm(/j",
        "uh4[tw",
        "^$9T ",
        "9ik89",
        "Jf.^E'",
        " 0x79",
        "BSRem",
        "7kk}%",
        "3j0l~Bik",
        "u/jch",
        "6PzegN",
        "5ZVg4*",
        "*6K-q",
        "]rU`v",
        "cy,]~",
        "EVP_CIPHER_CTX_iv_length(ctx) <= (int)sizeof(ctx->iv)",
        "WUYU!",
        "A-AiAqAuA}C",
        "  \\Le!vi",
        "MPFe\"C",
        "joj~j%",
        "api-ms-win-core-winrt-l1-1-0",
        "wap-wsg-idm-ecid-wtls5",
        "5 5$50585<5P5T5`5h5l5x5",
        "C`'A25k.70",
        "Qe_eae",
        "aaj{s",
        "fFH/l",
        "%UUUU3",
        "3+383>3Z3",
        "b*$4JB",
        "_ZeXr",
        "gi9_&",
        "LEN&K",
        "k]1T~",
        "T>F8=F",
        "Cannot set value with illegal type",
        "3;nfH",
        "~Z\"tT#;",
        "R.udA",
        "t$<WV",
        "SetTdiEnable: vsdatant registry key found, tdiEnable value will be updated in parameters key",
        "- 2p/",
        "@{bE4",
        "OI`[D",
        "|i3z/\"",
        "|wQ+=",
        "lR%,$HU",
        "c2pnb163v2",
        "'#^QTy",
        "PcV\\H<",
        "2Kkgr",
        "ePQRA",
        "VswCw",
        "L+<cc",
        "}~8bz~-$?",
        "GbwVv",
        "CPVI version=5",
        "dwAffinityMask",
        "5vD]Q",
        "dN-@VHu",
        "5 5(50585@5H5P5X5`5h5p5x5",
        "AyILh",
        "glDUsT",
        "@0I0a1j1p2x2",
        "=G>c>",
        "m{8$~",
        ":&;-;U;a;",
        "O5:*-",
        "!S9ds:",
        "RSAES-OAEP",
        "S?TJcS",
        "@TFWN",
        " AwM0M",
        "#$[wq",
        "=@>/}",
        "GF@{q",
        "C<j<k",
        " ^z&D",
        "9$9@9\\9x9",
        "._o!7",
        "2!2%2)2-2125292=2A2E2I2M2Q2U2Y2]2a2e2i2m2q2u2y2}2",
        "'*#OPg",
        ":.}_`",
        ".D7mf\"=v",
        ":}XT@l",
        " ,mr'-",
        "j,4\\^",
        "/H$q0E",
        ")V=VpW",
        "pMKiaS",
        "D;_M=",
        "z6\\`J",
        "FQ%rU",
        ">G+61I5w",
        "m>[r4",
        "9b9p9",
        "5$5,5<5D5L5T5\\5d5l5t5|5",
        "7oTjl",
        "Cluster Server",
        "Kn,?:",
        "D%\\#\";\\",
        ">1D<:",
        "671/9;",
        "J[yoI",
        "< <(<4<T<\\<h<",
        "/e`J([",
        "boost::filesystem::directory_iterator::construct",
        "{>g9V",
        "\\lsdsemihidden0 \\lsdpriority64 \\lsdlocked0 Medium Shading 2 Accent 3;\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 3;\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 3;",
        "<INVALID>",
        "}VK63",
        "invalid purpose",
        "x9jg`",
        "S*w9}W",
        "\"OHMd!b",
        "iwC\"t]Jr",
        "+P=1D",
        "725e/",
        "`/7#/s",
        ")p!0TpT`C`",
        "eF$HM",
        "[){\"?'a",
        "bad class",
        "{P)L(",
        "'ut3\"",
        "dy~{|",
        "Yd+q3",
        "\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2708596 ",
        "TW+_H",
        "ZZBEBe",
        "Exec format error",
        "E%DJT",
        "(CTND",
        "=zTUFv",
        "JZ\"eo",
        "(n]_<",
        ",&bX[",
        "*#FD[",
        "done turning protection on",
        "6D6juy",
        " ;}Sh\"R",
        "odWUy|",
        "~^H`yq",
        "v%Z%z(",
        "PRCPnb",
        "{E*0p",
        "q\"Z b",
        "!BQcB",
        "Jj=v_1",
        "SETAE",
        "KN'wzQ",
        ")6)~S",
        "4$4G4j4",
        "=9Vle",
        "F&L89",
        "_$.R_",
        ")73xO",
        "Rr:=ZO-",
        "5F6^C",
        "<5WnE",
        "(q?t\\",
        ";sha256//",
        "xpV6>",
        "jptQ'q&w;",
        "2$3H3l3",
        "yAtrJ",
        "McMb$4",
        "@HSrGp]",
        "g=pf,",
        "mB)%0",
        "$lISni",
        "T?J4V#",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 MAINTENANCE AND SUPPORT}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "Unexpected failure.",
        "l/{j1",
        "4=5Qx",
        "=-S][6",
        "As$xo",
        "nj{u5",
        "VnaInstallStatus",
        "zyJ1P",
        "@\"cLmPs",
        "VSPWInstPasswordRequired: logon failed",
        "rFC822localPart",
        "sb*$H",
        "_2vZ/Cfp",
        "{\\f418\\fbidi \\froman\\fcharset186\\fprq2 Cambria Baltic;}{\\f419\\fbidi \\froman\\fcharset163\\fprq2 Cambria (Vietnamese);}{\\f421\\fbidi \\fswiss\\fcharset238\\fprq2 Calibri CE;}{\\f422\\fbidi \\fswiss\\fcharset204\\fprq2 Calibri Cyr;}",
        "b'%!v",
        "Ph@U!",
        "1g)^d",
        "~}a4M",
        "\\lsdsemihidden0 \\lsdpriority65 \\lsdlocked0 Medium List 1 Accent 4;\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 4;\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 4;",
        "no privatekey",
        "5E5Q5k5t5",
        "(qz#MO!",
        "FLMMGLNN",
        "m}w*-",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\sa80\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid3736522 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 You agree:",
        "GetDC",
        "^01A*",
        "ssl3_get_next_proto",
        "u!jfh",
        "1YGt2",
        "Edk|+22",
        "X_pvFi",
        "N~k3i",
        "@Be+'",
        "%TcD[",
        "!`>fA",
        "c\\p$z",
        "Rn!S`5",
        "^4L-OY",
        "i:>\">%",
        "PMULDQ",
        "/!2GZ",
        ".\\ssl\\d1_srvr.c",
        "D9@R;q",
        "aes-256-ecb",
        "1 1<1X1t1",
        "aRW2_",
        "]ZMm6",
        "Esc((~",
        "Success",
        "t\"f;U",
        "<=<k<",
        "hvW_@",
        "vy3K3",
        "l{_Lo",
        "2h3l3p3t3x3|3",
        "jijyj&",
        "=V`5{Q",
        "9B9j9",
        "!f&fG",
        "m&:`gM",
        "3T$83T$43T$(",
        "-=bSy",
        "4)uz*e?E",
        "z<)%?",
        "}o!*|<H",
        "s2i_ASN1_OCTET_STRING",
        "Tvg7v3",
        "8^8y8",
        "Turning on protection",
        "2) software or interfacing supplied by anyone other than Check Point, (3) modifications, alterations or additions to the Hardware Products by personnel not certified by Check Point or Check Point\\rquote ",
        "9ri<{U",
        "AF-d@",
        "eDZ_s",
        ")=+j8n",
        "D$gR,",
        "A03D$",
        "b1\"{r",
        "5#RaT)",
        "Qu<O{",
        "\"gsA/",
        "N!yjFa<d",
        "GKVii",
        "1^rcIR",
        "^~y?}a",
        ".:F6],",
        "^B@oZ",
        "?D?L?T?`?h?",
        "&v?uk",
        "7[z\"R",
        "|k7Qr",
        "=:=I=S=`=j=z=",
        "A&BVQ",
        ".+9O0",
        "#c<%dm",
        "dN\"{P",
        "hj>\"o",
        "W:|K,",
        "file %s extracted successfully to temp directory",
        "DL_NAME_CONVERTER",
        "5&<8<X<]<v<}<",
        "B=8Ld",
        "a-QR$",
        "Tp8o%",
        ".q11 ",
        "4%5+6",
        "6 6$6(6,60646R6d6h6l6p6t6x6",
        "\"c<zO",
        "7dmywT",
        "1.yv-",
        "/0<,!",
        "EftTVO",
        "%;o;L/",
        "-@[`|",
        "KDv-WN",
        "pMt_z",
        "5;9sr",
        "wr5'F",
        "Succeeded to take ownership",
        " \"j+m",
        ">1gAM",
        "'SB~=hm",
        "x'/?i9",
        "`L)I/d",
        "IJJN:>~",
        "!J'=>(",
        "+ZO]!L",
        "FiBd8",
        "w9NvE",
        "{i/b~",
        "sl?T%",
        "BrFJm",
        "8?So*?",
        "7{8b9",
        "[]p\"1",
        "%s - does not exist",
        "t-VPUW",
        "%~ WchD{$",
        "cIF1[",
        ".r8j%}",
        "cqv#m< 8",
        "iVwVq",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529  shall be free",
        "X7U.k",
        "str_field5",
        "d:>jC",
        ";TE^~",
        "T#6Op",
        "$=o$+5b6",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid15945664 \\rquote s shipment of }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid16017612 the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid13775897 Hardware Product}{\\rtlch\\fcs1 ",
        "=f=}=",
        "4(4H4x4",
        "* M8'u ",
        "H8{xd",
        "B/yq:",
        "eGd|K",
        "q^dOq",
        "3+Bnz",
        "s.$9l|",
        "<NULL>",
        "t5-zV4",
        "1zX_6",
        "$JT0J",
        "SpecialBuild",
        "= =3=",
        "igv63r",
        ";d?h?l?p?t?x?|?",
        "l(14p3",
        "SELECT %s",
        "7$7,747@7`7h7",
        "SOFTWARE\\Classes\\.",
        "libdes part of OpenSSL 1.0.1t  3 May 2016",
        ")DL7<",
        ",sL^Q",
        "[{TjX",
        "|p]$0",
        "X509_NAME_ENTRIES",
        "2$2D2D4I4N4m4",
        "PEM_ASN1_read",
        "F_OAD9",
        "/([B@",
        ".?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "&vvK5",
        ";f[4~",
        "i?kKWB:",
        "+_BQX",
        "PPWVj",
        "aXul;",
        "#@Z|0<",
        "CMS_OtherKeyAttribute",
        ">1>B>Y>_>e>j>z>",
        "ny3Q!5M,",
        "]<\\Fg",
        ":%:G:R:",
        "9TWls",
        "failed to get record field: %u",
        "[_Xgh",
        "545A5^5z5",
        "<\"NqN",
        "0<XE:",
        "EXPORT40",
        "8P8`8",
        "Failed to get temp path.",
        "Service already stopped",
        "en-za",
        ";@;R;{;",
        "2)3[5",
        "HX$P(.w",
        "3K3q3~3",
        "y`4 L",
        "Found EPS installer",
        "jAjvj\"",
        "-mXWt",
        "SSL_load_client_CA_file",
        "$U?CX",
        ",K//b",
        "_dh].]",
        "0>1I1T1Z1r1}1",
        "X%|RZ7",
        ";$!\\sHT ",
        "WriteSuccessReg:  WriteSuccessReg finished.",
        "kzwt^S>",
        "\\V>MIi",
        "&hop1{",
        "..'/GI",
        "Preparing installation",
        "8D0\"1",
        "~TY#!",
        "APPEND_EXP",
        "5)505;5J5Q5\\5n5u5|5",
        "m)m=o",
        "z&^4,&j",
        "Ad[+\"",
        "{X`}3%/",
        "k\"Hdf",
        ".'w\\&",
        "9<Dap",
        " p3Iw",
        "{=j0CA",
        "2J3[3s3",
        "IPSec/IKE/Oakley curve #4 over a 185 bit binary field.",
        "|9A!!B",
        ":$;>;",
        " Ss''",
        "/Xudk",
        "5\"5B5b5",
        "37THQ",
        "jnjnj",
        "c{N\\'5K",
        "c:O*7",
        "X.$NuS",
        "6!Ifl'",
        "WWWWW",
        "md_gost94",
        "A[87#",
        ".?AVexception@std@@",
        "MT^Ie1",
        "J]{&}4",
        "(nil)",
        "777)8",
        "2W*UU",
        "0Ph8W\"",
        "Us<I7l",
        "yEY#i",
        ",VBO ",
        "{bu}]",
        "p=YLDCq",
        "&#ea!",
        "7#;WYq",
        " GSS-API confidentiality",
        "int_thread_get (err.c)",
        "operation would block",
        "1wEfd$",
        "fQhE)%j",
        "b>&qt",
        "jyiuY|\\",
        "kq?]2p-b\"",
        "}T9wIB",
        "p9l}(R",
        "24g,g",
        "6-o%T",
        " issuer: %s",
        "\\{WE]g",
        "3++O:64V",
        "}V+7hC",
        "Ho9%]",
        "wJc.lYu",
        "gNHm~",
        "1N1_1",
        ">7>c>",
        ".#N0A\"",
        ":/:A:",
        ",mM*/",
        "?\"?~?",
        "\"fEgEoExE",
        "8$8N8v8~8",
        "4*4r4",
        "071~1m2",
        "F*D*qT<",
        "(@;1@}",
        "|;3NR",
        "R6026",
        "g^^Dv",
        "9,9@9T9h9|9",
        "VTcwc",
        "L$(9H",
        "w:LMrEG",
        "G+G~T",
        "*P85uM",
        "bad ssl filetype",
        "@s!7[*75'",
        "bdE~(",
        "quarantine\\temp",
        "_h=2|",
        "RegLoadKeyW",
        "l6|=!_",
        "e)*5-",
        "NoKeep = true",
        "5*5x;",
        "H<4DP",
        "j#&T2aA|",
        "/-1Vg",
        "]Oncaq'.",
        "~M$Po",
        ".\\crypto\\pkcs7\\pk7_attr.c",
        "LEQ^|",
        "o#tsy",
        "jq=p>",
        "*Oq)}OW",
        "J8{t.{",
        "j!Qa1n",
        "Jaj.;?",
        "z\\}0G",
        "9Y5r>",
        "g-`H ",
        "* a)i.",
        "_|e?&3F",
        ":vE8m0",
        "e,k//xPm",
        "ih2KZ",
        "Bkuj+:~",
        "737:7A7@8",
        "fips2",
        "ff8\"iWT",
        "_lp<p",
        "wIa9x",
        "MgW\\6",
        "MonitorGetCharValue",
        "O+?hD",
        "=Eg\"j",
        "}%Y!#[",
        "3 3<3X3t3",
        "english-usa",
        "4@p2W ",
        "F-Secure Security Suite (All SKUs)",
        "6!6/6z6",
        "jQweK}",
        "DL9e\\",
        "[}/'d",
        "NIST/SECG curve over a 384 bit prime field",
        "}ds(q",
        "*Y{#}\\=",
        "Zr4J\\",
        "pkcs7 to ts tst info failed",
        "4mm-&i",
        "DMu9\\",
        "BpP!<Xt>",
        "< <$<(<,<0<4<8<<<@<D<H<",
        "t-QPV",
        "jgjfj*",
        "WARNING: failed to configure server name indication (SNI) TLS extension",
        "F7iNo",
        "K^Jsn",
        "|h1!:",
        "Immediate custom action CopyPoliciesFromOldDir",
        "3;3P3[3",
        "=.>6>6?>?",
        "+C}'[+_+",
        "T,@|pX",
        "NFOBOIOS",
        "aDP0;",
        "4wZl5Px",
        "K}\\`s",
        ")nj^h",
        "=N=S=",
        "&sw,Y~",
        "S#`pMrg",
        "R<'[RX",
        "=[b%g",
        "D$81D9",
        "373_3",
        "yFD,/-",
        "]@QT\\",
        "?AgWt",
        "%9/vy",
        "<xmlcomment>",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        "(FQyO",
        ">[Gkp",
        "    </security>",
        "atlTraceException",
        "RegQueryValueA",
        "]`X_aBi",
        ".+b~.L",
        "V*s;b",
        "PSHUFB",
        "jAjij'",
        "!-Hc188",
        "3;/?<Mwf",
        "\\F-1^",
        "e\"5{*!",
        "^!#ak",
        "okj'G",
        "0g;$R",
        "z`#e8",
        "config.xml.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "We are in Secure Remote mode",
        "ssl3 ext invalid servername type",
        ")'Y%o",
        "xK;M7Bn7",
        "`6]\"]",
        "RWVQPS",
        "t$@QR",
        "9-)J#x",
        "R +tp|",
        "\\drivers\\vsparam.reg",
        "!ZC :z",
        "L3X]m",
        "nmApj",
        "`@5!y,#",
        "Kp5o:",
        "]Exli",
        "1c1D4",
        "}8X$X",
        "^meH9",
        "-OxjD",
        "EY::x&S/",
        "4U].H",
        ">:>L>W>8?",
        "&'&)&5&;&?&K&S&Y&e&i&o&{&",
        "5sV0y",
        "failed to schedule ExecServiceConfig action",
        "cointerface ",
        "\"zp%z",
        "f`y[6",
        "|$\\SWS",
        "EWd\\r",
        "%f>MvG",
        "4bn$:",
        "!N^v|B",
        "nCK))]",
        "hUhVhWhXhY",
        "(VI'r",
        "9MMv&C",
        "&mKx!",
        "K`8\\b",
        "Session:",
        "@&4>y",
        "d1txptL",
        "5.6E6v6",
        "5/5D5Y5i5y5",
        "Yu?2q",
        "Yby3a",
        "U\\Qd&",
        "tkQ{A}",
        "9%909C9",
        "yc%Ga",
        "g#sQ8",
        "[WvB=",
        "PPSWP",
        "3%4;4",
        "Unable to save backup data",
        "jhMz6",
        "Unable to find mirror.exe",
        "%TPxH",
        "\\\\VEXb",
        "`m2:h",
        "zD1b>=",
        "E@e`>",
        "N4QmE",
        "ct of 1979, as amended, any successor legislation, and the Export Administration Regulations (\\'93EAR\\'94) issued by the Department of Commerce, International Trade Administration,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "AES-192-CBC",
        "@dQCIc",
        "Jmw5:Sn",
        "HkGlX>",
        ")SZ[_z",
        ")23Ad",
        "jTh<8#",
        "j@|G)",
        "K!DA9m+_q",
        "_L.AM",
        "RO_}:",
        "s`W,5l\\",
        "lKE)C%TJ",
        "<o4%}F",
        " 0xb5",
        "9=,@'7",
        "3fwd7g",
        "%daE<<0",
        "OnRemoveBefore",
        "ng{ng",
        "W.i6oH[",
        ":q=2\\",
        "w =eD",
        "WARNING: Using weak random seed",
        "zZZNd",
        "\\$$SUV",
        "0Xr_.q2\\",
        "* KT(",
        "%U70c",
        "u=1Mk",
        "^mHOZG`",
        "2)\"an",
        "&nSFk",
        "74_>e@",
        "[H\"z1",
        "3Xa#C",
        "+S=5G",
        "]CD0^Cs",
        "^\\.d,*",
        "k@F'.2",
        "Pry6<",
        "J3V/H$",
        "\".7)G",
        " D+\"_",
        "1l\\1?",
        "$f7eq",
        "V5eff",
        "z4\"\"D",
        "L|n83",
        "~IxLfT",
        "Hpwet&)",
        "rc4-hmac-md5",
        "?[8/{",
        "Hgx,?",
        "'f\\{e",
        "!+4\\p",
        "*X7B`w",
        "L3A9:6",
        "OnUpgradeAfter:  Register plugins",
        "g*9@{",
        "$a$.M'4",
        ":#:B:]:|:",
        "7O8b8",
        "G.kvK7$b%JN",
        "~iesX",
        "CMOVP",
        "@G`ic",
        "g,`aE",
        "HHtXHHt",
        "ZC-yA",
        "e}?hm",
        "H%@J`N",
        "s[BS!",
        "}sF1f",
        "L'ONd",
        "wI)Ny",
        "}].T3;X",
        "\\par }}{\\footerl \\ltrpar \\pard\\plain \\ltrpar\\s47\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "jAjuj#",
        "/<fel>",
        "^{x%z!",
        "px6,:",
        "14d[-:",
        "RT3 ]",
        "-{@x&",
        "qchT,",
        "rvxx\"p",
        "u(RPW",
        "ku~-CFb",
        "@\\CMG",
        ":`.E\\",
        "%u %i",
        "<K<R<[<d<",
        ",b7g?;t",
        "<9>L>",
        "iM\\B^",
        "C\"P_u",
        "bFj<.+",
        "ANP0s",
        "P'RsW",
        ",t.8=",
        "j1;uJJ",
        "%4I64dk",
        ".]@cL",
        ";)<3<P<a<v<{<",
        "/){\\44ztw",
        "k29Yn",
        "VZqjg;",
        "4*484F4T4b4p4}4",
        "nkq=!",
        "cadM}",
        "RunVsmonInstall:  Cannot access \"",
        "OCP[]U",
        "C^#Y6",
        "?|~sQ",
        "failed to set string to format record",
        "nL}Z?",
        "D8Sm5",
        "+O8$q",
        "4je#B",
        "^F\"KK",
        "jijgj",
        "707`7",
        "&&bX@<",
        "^=G q",
        "Hx];b",
        "F&q,)",
        "(My#p",
        "Va8Di",
        "f(+!R",
        "PMULHUW",
        "sn=FL",
        "@h<=L",
        "s)joh",
        "bad dh p value",
        ")?@$1",
        "ject in all respects to such United States laws and regulations as shall from time to time govern the license and delivery of technology and products abroad by persons subject to the jurisdiction of the United States, including the Export Administration A",
        "PatchOldMECA",
        "eps_ConnLogo.png",
        "!?`5,",
        "3#}-&uE",
        "c6sj^g",
        "!HfLJ",
        "(-X(k",
        "helper::stop()",
        "neTT]",
        "0f88d94fbc52ae4264d1c910d24a45db3462247fa791715fd71f989e19e0364cd3f51652d73760ae8fa8c9ffb3c330cc9e4fc17faf2ce545046e37944c69e462",
        "\\SecuRemote\\bin\\conn_config.exe\"  rem VPN",
        "Pzrx$",
        "-]EtC",
        "+$7\\Z",
        "I\\yRf^(1q",
        "646X6",
        "6R[yag",
        "8V|jc",
        "Failed to modify record in ",
        "6!6+616?6V6d6",
        "1%1*181",
        "rZf;E",
        "eP/Bq",
        "vNF:d",
        "4Rhq,",
        "=!FGv",
        "[\\Zce",
        "gI(k5F",
        "smtps",
        "}x8>G",
        "=,FuG",
        "CRolloverMgr::ClearLog():  unable to set the new log file size",
        "`9m:Kb",
        "ProductName",
        "lILe=x",
        "004080<0@0v0}04181<1@1D1H1L1P1T1X1\\1`1d1",
        "N??^nA",
        "d5a6\\",
        "0B]|b",
        "{gxAv",
        "$xMl\"",
        "unacceptable policy",
        "}2X/.",
        "\"`}Yyqcz",
        "MF*_m-",
        "8Ni&p",
        "cZ,lT",
        "b!7E[",
        "kF]La",
        "boost::filesystem::rename",
        "SSWVj",
        "`ZdnD",
        "0o7=5",
        "rn4h>",
        "\"*DJ>",
        "Ru=kR Z",
        ">nMzy-",
        "GENTIME",
        "hH}eO",
        "Lk#8i",
        "#5I=D",
        "N~ 9,<",
        "#Q?&4",
        "%P%S`19",
        "N\\iJ#",
        "4 4(404<4\\4h4",
        "?)/mZ",
        "Rb]<iP!(",
        "6A415",
        "343<3D3L3X3x3",
        "!pmm0H",
        "F&vt4",
        "$@IsWow64Process",
        "W<%,MKS",
        "JHm-qe/>",
        "|c33Kr$",
        "f=-Iu",
        "QUE)MGL",
        "=B?g?",
        "/H/ING8",
        "YL.JX",
        "xg0Ll",
        "PE\\(p+",
        "8$1_H4",
        "LBI;9",
        ":$,W:",
        "Au?qc",
        "4O\"`,",
        "BN_GF2m_mod",
        "160kb",
        "p['Aa",
        "+-Ftja",
        "^$ZG(",
        ":9yZZ",
        ")yeciC",
        "B388{",
        "K&mptu",
        "4,4N4Y4y4",
        "{*ZqV",
        "3&3,323d3",
        "[?E g~",
        "GYxv=",
        "`]mp3",
        "{\\*\\xmlclose}, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566\\charrsid12218863 {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Canada}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566 {\\*\\xmlclose}, }{\\rtlch\\fcs1 \\af1\\afs20 ",
        ";,;0;@;D;H;L;T;l;|;",
        ",O4oL",
        "zXE0A",
        "$6Aas",
        "$(mwG",
        "P}{Px",
        "jrJ_jm",
        "6@6H6p6x6",
        "i[().3",
        "J1{va",
        "e>6=4",
        "W$_^]Y",
        "+ P#w",
        "bYbP\\",
        ".)l$H",
        "(~\"VH/",
        "r2FbU",
        "SetMemDump:  SetMemDump started.",
        "(l2sW",
        "anyPolicy",
        "|5$Ar",
        "$d#`S2r",
        "Y.H2j+R",
        "V:sGC",
        "3*i%!",
        "UX$_>4",
        "4 4(40484D4d4p4",
        "AddDataClient()",
        "KjNhe",
        "#|Rf&",
        "h:?34",
        "u1A(4",
        "_D\\2U",
        ",848<",
        "UpdateVsconfigXML: SetEventGroupInVSConfig failed.",
        "MY9`$",
        "x3d3q",
        "3\"3V3b3",
        "uW\"KB",
        "apIM:",
        "J3|qR",
        "`5@]o",
        "7t-m0",
        "M>Q4Y",
        "*e3:Y",
        "id-alg-dh-pop",
        "zj<TQR;>'d",
        "fA)R-S^AB",
        "=.SD9",
        "9E_&2Z_",
        "w=8d}Qw",
        "W+W;WKW[WkW{W",
        "QSVW3",
        "ZW}i6",
        ")tW/X",
        "|!H/{!:",
        "W@/9J_",
        "7*8^8",
        "snmM H",
        "Could not get the token. Error: %d",
        "v{sc9vi",
        "2G|o&",
        "U$O$:",
        "m}h&$",
        "*P^IV",
        "jOo6e",
        ";lT(.",
        "o8}OE",
        "u|K;@",
        "[ZwV`|",
        "ot$0J",
        "Education N",
        "StopCipollaServices_rollback",
        "Xy_Zw",
        "?Q FaA",
        ";*:b[",
        "i<c}O",
        "V>{!9",
        "8m|xT`",
        "yVzm(c",
        "hrpW_",
        "Zonelabs\\updating.dll",
        "q[u\\:",
        "`local static thread guard'",
        ":(;L;x;",
        "Z6)j$'",
        "hPd.e",
        "V0Y4&",
        "wd0V%",
        "r!|3~",
        "Q1f{F",
        "RWT8.",
        "yBP-JZ[",
        "\"DauaT",
        "$my1^B",
        "[VSDATA LOAD] CreateFileMapping failed: %d",
        "#&|:ij",
        "`1irp3",
        ".M'|gI",
        "!~4X-",
        "=K>h>p>",
        "e)s5zO",
        "ejC9R",
        "Mn9}ay",
        "k\\Gk3",
        "fbl#7",
        "RVMx?",
        "S9/x-",
        "+WrE<hr,",
        "%xl7N'",
        "OeG8#",
        "DSA_sign",
        "\\'02\\'02.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li2160\\lin2160 }{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703",
        "o/2 nd",
        "Aq&1au",
        "L$<A;",
        "tVpEJ-;",
        "1g9~|",
        "DPL@I",
        "e=D9f Q",
        "8}3NG",
        "E*ny-",
        "C\"Rk$*,v",
        "PKCS7_set_type",
        "|5+Z('",
        "\\avckf.inf\" /S /F /C",
        "j@j _W",
        "NetStatisticsGet",
        "|a,'(I",
        "****************************** ChangeWSCSVCStartupType ended **********************************",
        "S&Ubu",
        "no sign function configured",
        "eQcM?s",
        "U'Vi:f",
        "686X6",
        "d1TDE5",
        "r-%:j",
        "s$Q\"Y",
        "4%444B4X4_4n4{4",
        "5,545<5H5h5p5x5",
        "DD_yQ",
        "vsutilDir",
        "{7s4\\",
        "h#3bL",
        "ss;ib,",
        "@2\"M0A",
        "[!7QU",
        "Not upgrade",
        "W&2Pj",
        "Bk,LkU ",
        "\\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid1729076\\charrsid15169477 HARDWARE REPLACEMENT PROCEDURES}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076 ",
        ")~2$,",
        "b8$/:",
        "@6Kf.",
        "U9k]^",
        "2[\\T+Q",
        "Ph,)!",
        "LYF5>",
        " CZjz",
        "lX3`?",
        "j8C?c",
        "zj..7",
        "z7OMs",
        "*rCj{",
        "Vh\\$G",
        "k[}>Z",
        "\"N+=`u3",
        "l5mxe`>T",
        "8&959i9f:u:V;e;",
        "FCMOVNB",
        "crMEk",
        "6;+TXD",
        "]f]E.@",
        "</G|#w",
        "Netscape Certificate Extension",
        "v,|v]<",
        "f(vF;",
        "#0Z0a0h0o0v0}0",
        "`zZU`",
        "tDKUV",
        "prime192v2",
        "LOA9P",
        "missing second number",
        "2%1W*It",
        "b\"_PU",
        "Bq/.8",
        "y9)~&",
        ".5%C+",
        "tsRr0",
        "&,4$Ew",
        "gP/ur7",
        "successfully created secured folder",
        "gu-in",
        "ZLd;K",
        "4=4L4k4",
        "=;U5 4",
        "i#l5k",
        "dpogYL",
        "NoKeep = false",
        "dKnh(n{)",
        "+d1|f",
        "RUMt*a",
        "kp}dnr",
        "id-alg-PWRI-KEK",
        "<,<8<l<p<",
        "8&8?8X8q8",
        "E%xW>",
        "[dbY;U",
        "ep2! ",
        "E9MnT",
        "@Z [ \\ b b c",
        "3+Ey\"",
        "v21yT",
        "cXgg}",
        ";\\DZ-",
        "vvQ\\;",
        "Y}s7r",
        "2K2x2L3k3u3",
        ",KW)=n7",
        "blK{b",
        "B`r0*",
        "t`xy#",
        "B6bYb",
        "'f8^B",
        "Wnrp2",
        "G72s=|",
        "~Eh@$",
        "zs$i<",
        "Rh<Gh",
        "<+t(<.u",
        "`\\kU\\=",
        "8S%M]",
        "e*4-#\"",
        "EC_GROUP_copy",
        "466G6",
        " X4Y~",
        "(*4Kg",
        ">LGO8",
        "t16+x;",
        "bResult",
        "757N7g7",
        "`tPJ]b",
        "wAB#Jxx",
        "v`9lO",
        "7QF^R",
        "3*sW%",
        ":Blowfish part of OpenSSL 1.0.2h  3 May 2016",
        "dMq7*",
        "id-smime-aa-macValue",
        "N_3haO",
        "5%APGm",
        "CMS_SIGNERINFO_VERIFY_CERT",
        "LAI)haL<|p",
        "%S7^7",
        "nn-NO",
        ".\\ssl\\tls_srp.c",
        ":\";c;",
        "b>C-~",
        "Socket is not connected",
        "L-6E2pQ\"",
        ":':+:1:K:Q:[:c:g:m:y:",
        "emV/o",
        "SEC_E_WRONG_PRINCIPAL",
        "<$xX;",
        "OLD_POLICY_PATH is empty!",
        "VD^ZL",
        "u4mKf",
        "2<T|fY",
        "444L4q4",
        "\\$4#|$",
        "Eq/t;?",
        "PLAIN",
        "__stdio_common_vfprintf",
        "mNOOK9",
        "ZLInstallKey",
        "'Lr:W",
        "rJST4",
        "RRahc",
        "4C)4c6",
        "N7&6G",
        "unable to set private key file: '%s' type %s",
        "rRc>0r",
        "j.!BI",
        "46: 7`?Mx",
        "E427<",
        "T$ #D$(#",
        "Lwx\\I",
        "\\s38\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\b\\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "q@8K/",
        "fDuB)",
        "q0rc'",
        "d$ULa",
        "pgotm[",
        "d>W{x",
        ".~97P",
        "%=8o.",
        ";$;,;4;<;D;L;T;\\;d;",
        " /:08",
        "%+aMwL<",
        "VISIBLE",
        "Z9M`W",
        "}x0y(",
        "c\\:Hz|",
        "E|(s ",
        "D$(USj",
        ".(Em8h",
        "n~oiw;",
        "ohV8U",
        "QN%b^",
        "D$$j@P",
        "SbTbT",
        "oyF@\"",
        "hU:H,CHP",
        "_D}U;",
        "DGa.]",
        "mCX:Q|",
        "bH3/=C#",
        "INT_CTX_NEW",
        "708a8",
        "r2e3m3",
        "jL^Xn ",
        "[=(y BC",
        "BSPSJS",
        "$@N-gQ{s",
        "cHo/&",
        "p`3v{v",
        "-Pzs|",
        "&:JVd9j0",
        "w+OQvr",
        "strcspn",
        "\\Oc{X",
        ":0;];",
        ".t&5r",
        "r&3CI",
        "R=)Oq",
        "*n')P",
        "SetNamedSecurityInfoW",
        "=EXW^",
        "Zw~%/",
        "'V5F m",
        "}_\\%:",
        "R[45w",
        "M_Ui{",
        ":9:U:q:",
        ".r_h=<",
        "iY$QC@",
        "161R1n1",
        "D\\F?S",
        "%3<4[z",
        "2.282D2I2N2i2s2",
        "OVPM,",
        "value.x509cert",
        "5*fp4ij",
        "<p4Ko(:",
        "Failed stopping EPAM Service",
        "7?zh*)",
        "6(646@6J6N6X6d6n6r6|6",
        "a~[3Y",
        "A^)H3",
        "<4<]<",
        "ko^GO",
        "!FVHo",
        "9]DCB0",
        "/>%LX",
        "a^8mB",
        "rSa*>",
        "8+z\"_",
        "N%`%8&",
        "u$BA;",
        ".?AVIConsumer@TelemetryISShared@@",
        "yd,Z`",
        "~E]L7",
        "9/A\"J",
        ";[Px[{",
        "j-AUDK",
        "\\1',#:R",
        "%sBr\"",
        "tW,AG",
        "CCJz!",
        "dt5oFo",
        "oIz2M",
        "S=={[+",
        "RDS1B",
        "ZdQ!O",
        "ymLys",
        "j<X||",
        "'6H(n",
        ":Wc\"6",
        "7je.+,M5",
        "&]6]d8R",
        "9LBJQr",
        "8C{Tc#C'`}",
        "Yirw8M",
        "ImpersonateLoggedOnUser",
        "PVVVh",
        "W]'^z\\mj",
        "!TU3c",
        "u,Wsg",
        "m8=,O",
        "setct-CredRevResTBE",
        "Service %s does not exist. error %d",
        "-:Rzl",
        "=,>3>Y>_>j>",
        "CRolloverMgr::CopyRolloverBlock():  unable to position read pointer",
        "-AC;_",
        "%sXPZ",
        "/xIm=",
        "R437g1",
        "`p]1{",
        "Found %d network filters",
        "no digest set",
        "E}G}I}K}M}O}Q}S}U}W}Y}[}]}_}a}e}g}i}k}m}o}q}s}u}w}y}{}",
        "102b2",
        "`]'{R",
        "282T2p2",
        ";)Ku<=b",
        "{2dBbJ",
        "?F?a?",
        "&4$ZIdh\"",
        ";!;*;",
        "CloseThreadpoolTimer",
        "Configuring VPN settings (2 of 6 tasks done)",
        "[VSDATA] Data thread cannot suspend itself.  Possible trouble ahead.",
        "(~o}Q",
        " 0x81",
        "9|$,v%U",
        "Failed to logon to vsmon as Installer.",
        "$</z^",
        "_strdup",
        "BI\\&8",
        "(r_Ae",
        "~6x}j4",
        ";Pi[c",
        "I5@;K",
        "\\rsid13896749\\rsid13922132\\rsid13961794\\rsid14122115\\rsid14159930\\rsid14161991\\rsid14171957\\rsid14173174\\rsid14234393\\rsid14253759\\rsid14296673\\rsid14361226\\rsid14362965\\rsid14380787\\rsid14438322\\rsid14487764\\rsid14558434\\rsid14614630\\rsid14639131",
        "G>3N?",
        "I6lRcP",
        "6DLhlk",
        ";+2$b",
        ".OkKA",
        "G PWV",
        "v<Q(u",
        "`a8Ax",
        ":&:+:0:@:E:J:Z:_:d:t:y:~:",
        "ADDPS",
        "Kai%O32X",
        "2'rSg",
        "_`;TV",
        "\\asianbrkrule\\rsidroot13193413\\newtblstyruls\\nogrowautofit \\fet0{\\*\\wgrffmtfilter 013f}\\ilfomacatclnup0{\\*\\ftnsep \\ltrpar \\pard\\plain \\ltrpar\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid15298478 ",
        "7Nb~)",
        "YI+o\\",
        "kmZ%S",
        "[d%&j{&tG",
        ":(;U;d;v;",
        "[3bD>",
        "-pm<;",
        "c!cO`",
        "t$4h\\",
        "U\">/fv\"",
        ";R;!<",
        "!D8f`R",
        "?9e%;",
        "ZOMkG",
        "2-2<2H2R2\\2",
        "jRvyZ",
        "Xh4#!",
        "&EkeI",
        ")z##p/",
        "SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Parameters",
        "tfjgvmfv",
        "p6PoD]x",
        ":(:8:D:T:d:h:x:|:",
        "<m!U(",
        "3'343o3|3",
        "(#$EMkE",
        "F5Dsj8X",
        "2 3]3t3",
        "StopEFRService",
        "Error openning registry %s",
        "> >2>=>l>v>",
        "$n7JT",
        "Bn4;@O",
        "'MS-Q",
        ".]_5Fq-",
        "h[=:O",
        "AntivirusMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        ">$>/>9>V>[>m>",
        "Minor Release Number=0",
        "#HttpOnly_",
        "ssl3_do_change_cipher_spec",
        ";$;);\"<9<D<z<",
        ";$;7;^;",
        "Z;AKp",
        "?j}Yv",
        "?5j;jQ",
        "(lr[<e]a",
        "PVVj7V",
        "}tGwcFT",
        "jR]GS",
        "{jdkP",
        "?CleanAll@@YAXXZ",
        "1@1u1",
        "WDigest",
        "7,cAy",
        "(Y=|^",
        "CLIENTTYPE",
        "0Ph`U\"",
        "rnX|x",
        "kY(QZ",
        "LFZQH",
        "rJBnF",
        "3;3W3s3",
        "\\Check Point\\CPInfo",
        "ENGINE_init",
        "J3^Aa",
        "5\\I^*g",
        "permitted",
        "Dsr<<5",
        ":#:6:]:c:l:",
        ".\\crypto\\bn\\bn_print.c",
        "; ;<;G;L;Q;~;",
        "vND\"E",
        "jgA4H",
        "NIST/SECG curve over a 283 bit binary field",
        "jc\"mf1K",
        "jg\\2/i",
        "MHcN*P",
        "85tl;",
        "d&@\\L6",
        "u? tn",
        "ktgWI/{",
        "Dh!+V ",
        "&VyU`",
        "\"FDs{",
        "1l2z2",
        "9(9,9@9\\9`9t9",
        "ALERTMODE",
        "#[KxZ",
        "Ze+-y",
        "2KzA@",
        "9gTZ+w",
        ";D< D#",
        "EHZ.p",
        "&Sh04-",
        "3(Q#q",
        "netascii",
        "#87lG",
        "YcE<tx",
        "58sb<",
        "/-Om-",
        "\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 6;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 7;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 8;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 9;\\lsdunhideused1 \\lsdlocked0 index 1;",
        "^F!PH",
        "E#?}mp",
        "%%zZm",
        "H.LbsT",
        "E&+N9",
        "?]x*9",
        "2 2$2(2,2024282<2@2\\3",
        "p6],I",
        "cp_InstPrep.exe",
        "Object Signing CA",
        " a&T/Gu'F",
        ";0;4;P;T;d;h;t;",
        "i+Y_96",
        "}1#h2M",
        "4p7h%",
        "p~LET",
        "@K+2i",
        "\\\\.\\%s",
        "V%*lD",
        "x`~{K",
        "K#:&S",
        "[)UJV&",
        "Vj<hD(",
        "CMS_KeyTransRecipientInfo",
        "90:j:",
        "RulesQuery",
        "q}qsz",
        "X$D91",
        "122W2}2,3",
        "Qdh}J",
        "xKkfy",
        "n9;s\\",
        "%`Zi/M",
        "RyDT\"",
        " 0xd5",
        ">@ia#",
        "YR93q",
        "5U;*l",
        "}H$a$",
        "3DUDE",
        "generationQualifier",
        "e!OS8s",
        "}oc)!p",
        "6SLs,",
        "pQ_SC",
        "sslv3 alert certificate revoked",
        "pHhXpHhX",
        "STMXCSR",
        "NXd`|",
        "es-sv",
        "borMd#",
        "StopNetFltDrv finished.",
        ":$:(:",
        ",df~@.",
        ".TRf1",
        "]EuA7=_&Z1b.",
        "N)Y^o$^b",
        "Q5L$0",
        "%c&8l",
        "eKdhbS",
        "j:EEA",
        "LE73}M",
        "C08q:",
        "|$<u0W",
        "3T$<3",
        "7t1aY",
        "EC_KEY_new",
        "=#>(>6>K>b>u>",
        ":`3 /",
        "7qEh-",
        "GetShortPathNameA",
        "~*Fa<",
        "__restrict",
        "MfJX5",
        "KFaf4",
        "[fFd)",
        "'QTRD",
        "2(242@2L2X2d2p2|2",
        "L`Fu1a",
        "CMS_RecipientInfo_kari_get0_alg",
        "IOaOHa",
        "E%qDeD",
        "sF`]5",
        " CkX,",
        "@*L1S",
        "fuE#V",
        "65&^%k",
        "2&6>(",
        "GCfp@6",
        "wCg^?",
        "not a signed receipt",
        "(vIpw",
        "_6+wP51&",
        "r+CG/",
        "cuYk&",
        "zaF0l",
        "DbgPrintfEx/DbgOutput -1 is illegal, use ODF_xxx flags",
        "(Z2Y]AW&",
        "MBw3Rp^Z",
        "b(cP\\",
        "%\"%2%{%",
        "_i_J_K",
        "[l[(Ni",
        "PKtS(/",
        "4n74X'Tp",
        "=fR?O",
        ")cd1f",
        "DQ|M3",
        ">P>T>X>d>h>",
        "3>4j4",
        "Ydd215",
        "WZ;&o",
        "z[Z1hK",
        ".\\crypto\\asn1\\a_dup.c",
        "%MG7w",
        "g/JQ7",
        "'Cc)%/",
        "9[~,=",
        "t&A3\\6Q",
        "***** OnError started *****",
        "Command not found: %s",
        ";.;J;f;",
        "!7X4C.",
        "#\\`YJNG",
        "luj/@J",
        "^Gk%S",
        "~xt@e",
        ".%t9 w3",
        "&w={U",
        ")\\SHwM",
        " [Q|8",
        "[ifg ",
        "NBX-g",
        "_L(oq",
        "!Mj]i",
        "MsiDirectory: ERROR_DIRECTORY %s=%s",
        ":$:8:L:`:t:",
        "pGAi+",
        "260|B",
        "dOQ?q",
        "|mL7a",
        ".Gp.i7",
        "v2jAI",
        "LMyWM",
        "Rz}R'>r",
        "^O]#!\"",
        "f>)H<",
        "SHLWAPI.dll",
        "=+<B&G",
        "{.'p~",
        "ZZN'J",
        "}X-8Nr",
        "5!6Y6",
        "tiLr=",
        "E&QJ4",
        "+ P x ",
        "'tl#&",
        ": W'fA",
        "%1023[^;",
        ">6\"n#DBT",
        ".\\crypto\\x509v3\\v3_pci.c",
        "758:8P8",
        "86.20.0118",
        "o9^wh",
        "\\KiWg",
        "u|9w8+6",
        "failed to open registry key winlogon",
        "PKCS12_init",
        "@\\owI",
        "6~[}k",
        ">%ugj",
        "PC w]",
        "a#2MS\"8",
        "L`ja5",
        "^NAjM",
        "vsinit.dll.1F357923_E5ED_4F4F_9B28_B146153C7446",
        "(`V8EC",
        "number is too big",
        "Lc<|r[",
        "H$('#(",
        "061z1",
        "ssl_check_srvr_ecc_cert_and_alg",
        "v<^wO",
        "Kxtk2nyg",
        "LocalFree",
        "MU7s\"",
        "K9C9.m",
        ".PB_W",
        "u2yo*{",
        "`0Vr@",
        "delayed-auto",
        "Bad message size",
        "#Hh-}",
        "yq`[~",
        "7;7P7]7f7k7~7",
        "v>6_K",
        "mdc2WithRSA",
        "9V:v:",
        "!,9yAmo",
        "Local port: %hu",
        "pmu}G",
        "RegEnumKeyW",
        "`3okTT]",
        "j(R\\s",
        "_'sVQ",
        "(5<{\"",
        "?}>6G",
        "~6Kc!",
        "Pj}j#",
        "puG:~",
        "3)505w6",
        "<.<4<",
        "h*yF|",
        "epWq<q",
        "k\\E.&",
        "}4clnER",
        ":':,:4:?:G:",
        "HQ:Bu",
        "%9xie",
        "L%}_Ym;",
        ":WL+d",
        " means a computing device with a specific function and limited configuration ability. The }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "Ehg**/",
        "mN\\M$X",
        "zkE8t",
        "{=\\[>PE",
        "7Htg ",
        "@S|wsf",
        "f(+{p",
        "M?HMb",
        "\\$ PV",
        "msS=Mn]wY",
        "Failed stopping AB Service",
        "DS_CopyToSystem32 FAILED.",
        "FjFZ*",
        "daLt_",
        "Xx^JJ",
        "505:5m5",
        "Remove old ZIC key from UIFramework 1.0 adapter list",
        "}|Bsu'w",
        "g`@C[",
        "=m3q%",
        " dKwS",
        "v)G\\8",
        "8b9p9v9",
        "^3b'I",
        "kKuwq,",
        "!R\\/m",
        "2G2z2",
        ".zse77",
        "TqjI8W&",
        "i`!Cv",
        "]fE|[",
        "?q\"6)t",
        "}Zi$Q",
        "=_7V2",
        "1`R`!",
        "F|(R9",
        "AES_T4_INIT_KEY",
        "NpSUxh",
        "lzL01",
        "1M1b1r1w1|1",
        "[VSMON_SERVICE] Service open error = %d",
        ";H=\\{<",
        ";$;@;",
        "NHTco",
        "^>4Y8 r",
        "SECURE_MOBILE",
        "S#9J\\",
        "L$43\\$<3\\$ ",
        "nEdsr",
        "IntegrityMode exists in registry",
        "5+5E5",
        "o5oBoJoU7",
        "@oo{b",
        "8G8M8X8",
        " 0x7f",
        "9,9`9",
        "|spv$O",
        "FaTFeT",
        "$|J;e?YO",
        "X!ke-",
        "1+\"y,",
        "missing tmp dh key",
        "8WnBm",
        "odd number of digits",
        "9\"$Wj",
        "2QN1kma^Kd",
        "x72<K",
        "N~By;3Fo",
        "XMM12",
        ",\"j@,",
        "?_?e?j?",
        ".uS)}f",
        "rvAe$",
        "`HZ/-",
        "0jrGb",
        "1R1[1",
        "2(282H2`2l2p2t2",
        "_o^~K",
        "TC05Z",
        "..4m>",
        "a:73K&",
        ".?AV?$_Func_base@XABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@K@std@@",
        "E0TBg",
        ".?AVTimedSingleWaitBlock@details@Concurrency@@",
        "3H4a4o4}4",
        "GZ!H]",
        "%~Wf~",
        "WaitForMultipleObjects",
        "]=#E!",
        "..?<J!9",
        "$%js4",
        "d.ori",
        ".WduR",
        "5S>h'-",
        ":$:8:C:V:",
        "#-+h&s(_p",
        "^1`Sc",
        "*j1Oi",
        ">MI9=",
        "Vr3iA",
        "Q58BP",
        "6_3, ",
        "E^[HG6I",
        "404Z4h4m4",
        "z>3?QDi+",
        "zyMPF~",
        "6+777",
        "D$HUWP",
        "xhSb)",
        "FeatureVpn::LoadSettings: begin",
        "=0>j>",
        ".jo-k?",
        "bad alert record",
        "tYVSP",
        "AQCu6z49",
        "There is a registered product.",
        "6UYFx",
        "id-smime-ct-DVCSRequestData",
        "tjA9B`",
        "4HEp,",
        "PZq1e",
        "PKCS5_v2_PBE_keyivgen",
        "J{ nR",
        "L$$^3",
        "o,d6<v",
        "memory buffer",
        "3(3H3h3",
        "jkjrj",
        "= =(=0=8=<=@=D=L=`=h=|=",
        ">E?P?",
        "UH3TaU",
        "Nm$g}",
        "+Z\\Rw~e",
        "Z:G(i]AtQ",
        "c'a[;i.&\"",
        "sdL3x`",
        "u_*;h",
        "ea\"mP6$",
        "J0WD8",
        "...///001166::",
        "cxp*A",
        "_0x?O",
        "-|W\\[",
        "REFl;",
        "9OO92",
        ")}(j1h",
        "t$hSR",
        "`\")HjN",
        "#;V'x",
        "t(<t.",
        "isdigit",
        "9E6+xt\".:gn!-",
        "Q4p+[A",
        ";kKzn",
        "c@6\\E",
        "[VSMON_SERVICE] Service delete error = 0x%x",
        "SCVMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "e\\4<V6k",
        "Z 5On",
        "cwj3!",
        "=0=8=@=H=P=X=`=h=p=x=",
        "X2jd\\",
        "hz)i)",
        "No data was received!",
        "8)858A8M8Y8e8q8}8",
        "\"$>mo@",
        "-D2uq[",
        "PSUBUSW",
        "Dg/0l",
        "%8!Z4",
        "-\"fO4b",
        "/vUm=Z",
        "cME1%m",
        "\\@+T}#}",
        "BwQz)@",
        "Y?'b]",
        "}bGW4yx",
        "V22dN::t",
        "\\{{6A<X",
        "<8All",
        "t!X,t<",
        "0rvRE",
        "'mKcB",
        "GIpqTt",
        "hxhKp",
        "89]4w",
        " C-Nw",
        "8<8S8}8",
        "A0h N",
        "mz(rA",
        "F4;D$",
        "p#}\\l",
        "ClientVersionString",
        "5Naj(U",
        "?$?,?4?<?D?L?T?\\?d?l?t?|?",
        ";)<X<",
        "iI7>%z}",
        "(K8K3",
        "D$$hP<!",
        "ALG_MODULE_INIT",
        "vJib72",
        "kt*J7]",
        "Windows Installer XML Toolset (3.8.1128.0)",
        "`+s1s",
        "setct-CapRevResTBE",
        "424N4j4",
        "sid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 2. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "6Yo4f",
        "*lp@l",
        "h%#n?",
        "BV]av",
        "9H:r:",
        "PVMjP2mV",
        "8S(IB2",
        "kGOST",
        "}sdQ*",
        "~Z\\tQ",
        "{\\fdbminor\\f31559\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}{\\fdbminor\\f31561\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}{\\fdbminor\\f31562\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}",
        "5RxB5",
        "Zn]i:I",
        "\\rsid2633647\\rsid2646135\\rsid2650399\\rsid2689536\\rsid2703887\\rsid2708596\\rsid2764809\\rsid2849700\\rsid2912818\\rsid3017503\\rsid3083316\\rsid3165572\\rsid3169179\\rsid3226310\\rsid3233976\\rsid3297348\\rsid3374529\\rsid3412682\\rsid3422540\\rsid3428060\\rsid3481596",
        "zmRgr",
        "R1Jov",
        "short ",
        "no start line",
        "~Gz~\"",
        "S\\;w+l",
        "Qkf+l",
        "vs}KH6",
        "u!NKN7",
        "vb\\~hV'",
        "%s%s%s%s%s%s%s%s",
        "=E &U-!",
        "bignum out of range",
        "close",
        ":/:V:b:",
        "vsdatant_win7_64.cat.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "id-mod-cmc",
        "r$[Gf",
        "= =$=@=D=P=T=X=t=x=",
        "V3\"/\"6",
        "kzLy_",
        "0Jxlk",
        "N=<N&N",
        "FCOMP",
        "A}XdL/",
        "495?5i5",
        "pExecutionResource",
        "aG/&.",
        "J,-i0",
        "i3;LW",
        "|-M24",
        "m(*ph",
        "nKo>>",
        "XF2g}L",
        "Received 101",
        "3]3~3O4u4",
        "Z!Cnm",
        "q^BgX",
        "&O[BI",
        "5ulPi",
        "4L4r4",
        "u*)Ws",
        "9d;/<",
        "(]V$P",
        "LD?g5r",
        "|/_P/",
        "CryptImportKey",
        "RegEnumKeyExW",
        "Second SetNamedSecurityInfo call failed: %u",
        "\\AntiMalwareAPI.dll",
        "p/xNrM",
        ";3vrs",
        "3)4^4",
        "!O(nH~",
        "<k}VOu~o",
        ":*2xw!h!",
        "+>qAM",
        "F &yA",
        "2 383<3L3P3\\3l3",
        "R>PTe",
        "!HkD6$",
        "z\\o>9",
        "jT!6+",
        "discarded",
        "eGg$li",
        "-k'BX",
        "rc5-ecb",
        "I);]2B",
        "`string'",
        "7PmND[S'",
        "N-{A]h",
        "xuRg5d",
        "$5JUz",
        ";M;k;",
        "Woy;8",
        "folder_0",
        "Can't delete current directory.",
        "uTt\\l",
        "_9LN-",
        "7F9U9",
        "667B7\\7",
        "So[4#u",
        "=(=5=U=_=q=",
        "yZ.~\\",
        "xEF9}^",
        "e9r?e",
        "LOwIz",
        "`Y/sM",
        "$R`aiQ",
        "~SSWU",
        "]l`V\\9",
        "4/4s4",
        "setct-CredReqTBS",
        "?7;<d",
        "&ZSb?G",
        " `EYa",
        "Gh,uZ",
        "0L0l0t0|0",
        ">i*5f",
        "LX)yZ",
        "Tq3v0",
        "dYE&9",
        "2)252Y2]2c2k2o2u2w2{2",
        "D Nt4Ehe",
        "=k&wq",
        "5<6R687",
        "1Q>4TC>",
        "wu,:3`4",
        ":\":<:o:~:",
        "french-belgian",
        "WOW64",
        "d%-qqhcJ\\",
        "3y7'C",
        ",qUql",
        "o0qY1j",
        "1\"2)242q2",
        "~^`2Qa",
        "7sme=mh",
        "a5G=vg^",
        "j0h02",
        "IATjQ",
        "Uan#=]<T",
        "&sBes.",
        "FOH1K",
        "HW|$_",
        "X9.57",
        "CreateProcessAsUserA",
        "OO^$P",
        "ZwProtectVirtualMemory",
        "CJkJP",
        "th}ZSI",
        "9FD1j_",
        "RQf>m",
        "Z\\:UM",
        "8I9\":q:",
        "M`nD#*",
        "5ELD'&",
        "FTP: couldn't set file type",
        "6-7L7P7T7X7\\7`7",
        "U?mutH",
        "YGu!A",
        "~pjCXf",
        "FF7bZZ1OT",
        "%f{wX",
        "~%1C9",
        "\":dg?",
        "u0jAXf;",
        "N'/Ks>i",
        "eJ/Az",
        ".bzEL",
        "Issuer",
        "iQ^0/_|",
        "UQ6<G",
        "f.l$rI",
        "files name is: %s",
        "tSVSW",
        "?3?c?i?m?",
        "X o%r",
        "48|pB_",
        ":%6#75",
        "kSy+D",
        "0>0|091H1f1",
        "sWj=M",
        ";!<O<|<",
        "^g9GY*Mw",
        "n2w]%D\"",
        "*&lX)",
        "GetPrivateProfileSectionNamesA",
        "gZ8)E",
        "D$8SU",
        "Lz~o4",
        "t$H1t",
        "=+a*cU",
        "]vKVH,D",
        "aj$!&",
        "kYGQq",
        "-6zHbl",
        "CertIsStrongHashToSign",
        "Jglr!z7",
        "lProductMode",
        "5xNZ[*",
        "ueId{8",
        "90dFCR",
        "out GSS-API data",
        "3=gd%",
        "ssl3_write_pending",
        "2l@TZ",
        "v$]%!",
        "&]M;|mU",
        "@RA$>-",
        "qX'M,",
        "N-'kb",
        "n(cp5",
        "0$0)0.0H0T0Y0f0k0p0",
        "vvc1G",
        "=D/P)",
        "h#RC>",
        "J!bK&3g",
        "/yFji",
        "8iH4Zk",
        "}VHv?",
        "0&0-040",
        "9V:(;T;",
        "b fi7",
        "<(<8<<<H<X<",
        "}.@F^",
        "aJKbr",
        "dSeSg",
        "XA{}0",
        "-fI>j;1",
        "[VSSHUTDN] CallDriverCtrl: dwCtrl: 0x%x dwFlags: 0x%x",
        "^|L|S",
        "2BGhb",
        "<yuN\\ ",
        "m52/'",
        "!bAgBH",
        "}ubys",
        "H[uw)",
        "P.>U@Mzs",
        "uQ'y@",
        "\\zonelabs\\avsys\\ssleay32.dll",
        "ZoRd-",
        "EH5Nn",
        ">C?H?M?]?b?g?w?|?",
        "/$6#$t",
        "fG{65v_",
        ":d`&|",
        "PrivateBuild",
        "\\E>#M",
        "guwdf",
        "f)mJlboM",
        "ZSN`i5",
        "UF4aY!",
        "Endpoint Security Clients",
        "Td%eN",
        "z\"kipsw",
        ",2B2G2*",
        "1lR$B",
        "YmX7-",
        "K'\"_E",
        "#RjYu",
        "@x6.V",
        "#+#Af:b",
        "V2^){",
        ",KNvA",
        "bGtVG",
        "3'HoXn",
        "/UFSVwh",
        "cBLgM1",
        "`L14B",
        "&u]+)",
        "--:--:--",
        "ym!K;",
        "-e5'|Mk",
        "u,h\\n%",
        "urYh0mK",
        "GA8_.",
        "{oc(n",
        "> >(>0>8>@>H>P>\\>|>",
        "r^[.mY",
        "pl,a_*",
        "%{6}8",
        "d.registeredID",
        "ssl3 ext invalid servername",
        "ADH-AES128-SHA",
        ": ;l=",
        "|In-q",
        "jKTU)",
        "mbg>h",
        ">`---",
        "P25\\p",
        "C05qA",
        "}6x)R-",
        "fI;yQ",
        "*`[[+",
        "m$?>Zb",
        "crP>?FR ",
        "Xnz[[3",
        "7oCGsC~",
        "EdiPartyName",
        "nV@C_",
        "_Gw;<n[",
        "pmw8wy",
        ".CRT$XLF",
        "PW,Wg}s",
        ")}V![",
        " ffqS",
        "#( S>",
        "\";|reo",
        "36ehv7",
        "7gU6Gqt]",
        "zo;bl",
        "sq(0Quc",
        "5r`:@Lq",
        "|:k`Q",
        "Ias9`",
        "TVDIR.37D41C91_E86B_4EF0_84D3_97F98AB77A0C",
        "889Y9}9",
        ";;F u'3",
        "+QPRV",
        "EVQSP~Z",
        "%:lUR",
        "ABBV3N",
        "&F@6E",
        "n09&dx7",
        "\\^c$j",
        "Waiting %d%% done for cmd:  %s",
        "=*=k=",
        "nD~@gxg",
        "%F^_N=,",
        "DH-DSS-AES256-GCM-SHA384",
        "405_5",
        "vsdatant.sys matches vsdata.dll version.",
        "^h<|%",
        "\"}#oq",
        "dt&RSr",
        "To$&?",
        "SSL connection using %s / %s",
        "]zmh3",
        "5^6k6",
        "BdmG4",
        "p<p@pApB",
        "{{{{{{{{{{{{{p0",
        "$-f@-",
        "p9XR>",
        "bYAj1H",
        "1yO?.rE",
        "bl!=\\",
        "a5%-3J\\",
        "Edu*9",
        "V_wKKKKK",
        "DCcf7[m",
        "= V^^",
        "lVMN{K3",
        "9[PHD<",
        "kyj{I",
        "O%b*<|",
        "EXCEPT FOR BODILY INJURY OF A PERSON, IN NO EVENT WILL CHECK POINT BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DAMAGES ARISI",
        "Yd#Es",
        "RegSetValueExW",
        "VD]TB",
        "nxQ/(",
        " /l*v+ \"",
        "WWWPWS",
        "RP%fl",
        "eU3cx)",
        "UaHgr",
        "dinfo",
        "p),N|",
        "VIIooV",
        "Cw8#\"",
        "^waOH",
        ";3t\\W",
        ";e{\"{g",
        "%pLKi`",
        "XrSCI",
        "?WCpV",
        "*Wa~J9F)",
        ":X:|:",
        "Yf9bIa",
        "0@#|>",
        "ZI^w3",
        "c)mA8X",
        "EN bX",
        "p' OA",
        "Jw-|s",
        "lv`HXzA",
        "_#tM/",
        ":RfxFolder",
        "k#{Qt{",
        "CrlID",
        "[*\\*]",
        "Z7P7N",
        "Nw_\"u",
        "mMvE8b",
        "Vt/A9",
        "t&\">e",
        ")bP%)",
        "x<O*U",
        "{M5JN",
        "Service is not active (already stopped)",
        "disconnected.png",
        "gqT$ /",
        "L$ SW",
        ")mHz0",
        " -3N3",
        "0;r!;",
        "$_r6Y",
        "T+^g/",
        "SEC_E_SHUTDOWN_IN_PROGRESS",
        "c;za<",
        "n many countries you may be required to advise users that their data}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7224833 , action}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid3422540 s}{",
        ".OzF[7",
        ";(;A;M;c;v;",
        "r(r@r>r:r6p4",
        "d Iv}Q",
        "eX*iD",
        "0)090",
        "EjAs32~",
        "\\f1\\fs20\\insrsid8989067 echnical support by web request at}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1786542 :}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8989067  URL:https://usercenter.checkpoint.com.}{\\rtlch\\fcs1 \\ab\\af1\\afs20 ",
        "D)bjP",
        "CreatePerfCounterObj",
        "7E8K8",
        "R1y~s",
        "?<L|\"",
        ")9UFF**S*",
        "e`Yi7",
        " ee)ke",
        ":)GrWD",
        "K7KG.",
        "FirewallCtrl",
        "ap[4g",
        "|Egvv",
        "W;X>Kn",
        "TS_VERIFY_CTX_new",
        "@0PT&*",
        "25n0;",
        "D$$j|hd2#",
        "t-~S ",
        "00-05-9a-3c-78",
        "h6O'r4",
        "O,-~Z",
        "b[=i$",
        "a)W=,",
        ";7u`9}",
        "CreateSymbolicLinkW",
        "l$8UU",
        "r'ewS",
        "0(0,0@0P0T0X0\\0`0d0h0p0",
        ">?^JK",
        "_[F:,",
        ",Lq%h",
        "UgH]c%",
        "n?E!3",
        "e}c7p",
        "_9ca^",
        "F'F\\L",
        "Forcing reboot because user chose to reboot",
        "yVL!6",
        "_Tr\\B;+",
        "Failed to write client_sub_type with value of 'SecuRemote' to registry",
        "wfF2rE ",
        "'rGQ[]",
        "|sY B",
        "33333333333333",
        "@` 10b`",
        "&u%,`T",
        "\"5ptS",
        "b0|i5!g",
        ">e_/*",
        "]-GPu@",
        "]f0z<",
        "=_>x>",
        "\\uhGo",
        "*'=BZt",
        "YC1JE",
        "SONDK",
        "t3f9]",
        "DHE-DSS-AES128-SHA256",
        "Reconfiguring Service: %ls",
        "nJ{\"t",
        ".\\crypto\\pem\\pem_info.c",
        "l/9Pi",
        "v@*,{",
        "&2ZcL",
        "HeNNi",
        "zZ4jUp",
        "\"#&\"FFPD",
        "]V`hR",
        "){#sA",
        "`rtk2X",
        "<3<8<^<x<",
        "9I|Z5t3",
        "{aZD]",
        "A password has been set for this computer.",
        "Sau_(",
        "&E4yS",
        "boA;%",
        "=`y Y",
        "<+p3gs[",
        "C*3+k,",
        "3D$41",
        "SG)op",
        "=a=q=z=",
        "7 7$7(7,707",
        " ~;t/",
        "1@1k1",
        "< <,<<<L<P<`<d<p<",
        "bn]f8",
        "ibxD[('wcC",
        ";B,6W",
        "CAMELLIA-256-CFB8",
        "\\H\",d",
        "og\"ZN?",
        "5q~jR",
        "^U^Y^]^a_e",
        "+o\\7FC",
        ".Zli/",
        "X,_(m$",
        "u8b_U",
        "3?is1",
        "G~2<O",
        "j$YLN",
        "O\"F\"P",
        "CX&,`8",
        "+=\\fFQ}",
        "Ff=S-c",
        "T+yr&;",
        "failed to set application name",
        "Gk%[=",
        "$S?73",
        "jB]F?]",
        "i{ca5",
        "o:;_g\"D",
        "<4:ra",
        "j::zn;",
        "Tt)jhZf;",
        "^!,xF",
        "6/719e9r9",
        "$;Np ",
        "error:%08lX:%s:%s:%s",
        ";$;,;4;<;D;L;T;\\;d;l;t;",
        ":F;g;q;",
        "bg\\TZ",
        "(!)a)",
        "%bR<`",
        ";\"][Yam",
        "J$ad7",
        "6@g=l/i",
        "eNt{W",
        ")L\\el",
        "A[M)}z",
        "<}53c",
        "`n?>A",
        "d!rG39",
        "Fjz#ZiUA",
        "TOta$",
        "n~y8l7y8x",
        "2D'K6",
        "@u!J,4z.",
        "[5j5n",
        "00-60-a1-00-00-00",
        "ZspUDN",
        "StartServices ended.",
        "]Ae'j",
        "2+2@2E2",
        "E^.&teF",
        "QA*T}",
        "seek callback returned error %d",
        "EnterUmsSchedulingMode",
        "W8B\\P",
        "UpdateVsconfigXML:  Delete unwanted iamdb.rdb prior to vsmon logon.",
        "SNjNa",
        "3'4;4K4U4x4",
        "6KfSK",
        "X#0W|",
        "vd- a",
        "\\CheckPoint\\Endpoint Security\\Common",
        "nuHo8G",
        "pi`A!J",
        "X:tOe&",
        "$l>2\"",
        ")=0`B",
        "GetFileVersionInfoSizeA",
        ":(:8:H:X:\\:l:|:",
        "5-XDO",
        "7e;TE",
        "hoIdL8",
        "MonitorLogoff",
        ">5>D>O>T>Y>w>",
        "R3\\<]",
        "\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 6;\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 6;\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 6;",
        "mcWeG",
        "6 6$6,6D6T6X6\\6`6d6l6p6t6x6|6",
        "PKCS7 routines",
        "<=<B<c<h<",
        "3_D+P",
        "4.5.0.0",
        "8n>qc",
        ">X\"lZ",
        "!}FJ:8",
        "Ar#yz",
        "operaton not initialized",
        "}tkiW",
        "IcC3Ph",
        "r[6<J",
        "*Chg1I",
        "2&2;2O2\\2d2w2",
        "L(3lJ",
        "u/n`p",
        "F*-Dx",
        "+)~g'",
        "FD[W]",
        "APPE %s",
        "4$5c5",
        "Jbx@=",
        "_8FuRn",
        "j]O'q*",
        "=5>f>",
        "9P[rM",
        "_FO7e",
        "qaxb8",
        " o>o{3q3r",
        "PathIsDirectoryA",
        "C7Jv5l",
        "+vx{}",
        "mlK6Z",
        "jurisdictionST",
        "oriValue",
        "3 3$3(3,3034383<3@3D3H3L3P3T3X3\\3`3d3h3$4(4,4044484<4@4D4H4L4P4T4X4\\4`4d4l4l5p5t5x5|5",
        " 0xcf",
        "UpdateVsconfigXML:  Using file ",
        "0*030",
        "aw\\k5",
        "FCMOVBE",
        "|oLiy/",
        "i[6-#",
        "Q2|o%",
        "-y>B[",
        "kr@K!(i",
        "5o;F2D",
        "lR+uT",
        "> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>",
        "`IZJ=",
        "VsDe_",
        "wP!ml",
        "q*w&O*",
        "DZ>ysJ",
        "p73weVC",
        ", Type=",
        "EslHj",
        "SEC_E_ISSUING_CA_UNTRUSTED_KDC",
        "tRCXJ+",
        "n98PllZt",
        "*AQCg",
        "7D8V8",
        "VZ.owd",
        "N/!}}W",
        "\\zonelabs\\icslta.dll",
        "not encrypted data",
        "hidden",
        "H{WJz",
        "w8T>|//",
        ",Z L`",
        ")KR`X",
        "//iBqQcjpn",
        "jQ%CT",
        "K$N}R^",
        "re}lT6&L",
        "FJ`\\A",
        "4n$ur",
        "7$@c<)a",
        "<X=h=",
        "7$|i]",
        ".?AUIResourceManager@Concurrency@@",
        "*87F:",
        "4$444<4D4T4\\4d4l4t4",
        "Registering service name %ls with the Restart Manager.",
        "Convert2MSI.exe",
        "D0<z/",
        "35|eN",
        "+m~iTl(",
        "zaZ~y`",
        "eZmdL",
        "jKzb4",
        "MIMIMIMINIm[",
        "NKqtY]",
        "\"P3gm",
        "W@j0P",
        "void ",
        "n_/Er",
        "\"8U eHu8!",
        "T^L*H",
        "2 2(242<2\\2d2l2t2",
        "03h3o",
        "YXIDg~",
        "w2ITL",
        "0\"0>0Z0v0",
        "tviz\"",
        "mxj-?",
        "8+8c8",
        "5F6W6|6",
        "6\"nLl",
        "G/pb|",
        "6?eZF\"",
        "uxK|4",
        "D2I_X509_CINF",
        "0=0N0",
        "Plain text password |%s|",
        "7h`U!",
        "kqqhz",
        " `a\\b",
        "$>OMu",
        "a0<7G",
        "(ChTW",
        "T$,SUV",
        "9M2l*",
        "Instructs server to resume from offset %I64d",
        "pub: ",
        "Ga7G~`",
        "VMmr~t",
        "U@b3d",
        "`h````",
        "071L1",
        "tX<KtT",
        "Uv?1sX?$?/O",
        ">u*!I3iY",
        "]cxDH",
        "0?ASzl",
        "GOST94-NULL-GOST94",
        "TEFXj",
        "SleepEx",
        ": :$:8:<:H:P:T:`:h:l:x:",
        "QSVWj",
        "Et$8F",
        "D3 K7",
        "'O0xb",
        "JyHS6",
        "$#(sU",
        ".\\crypto\\asn1\\p5_pbe.c",
        "bIsUninstall",
        "jm]+g",
        "fn7y0\\",
        "E)EeE",
        "OOt~$",
        "QueryServiceConfig2W",
        "h[f=A'U",
        "g`Bgzl.",
        "9!9=9Y9u9",
        "_0M=-d",
        "9*-yv",
        "K5N4i[",
        "\\s:N{",
        "Loading due to change",
        "api_ms_win_core_util_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "KN)v2",
        "V}%_|",
        "D$ VWP",
        "'xT2cg#_",
        "\\;tcO",
        "Qo69o",
        "]^#sUU",
        "l`V_w",
        "0M1e1",
        ":&:7:E:P:r:",
        "zrq\\\"M?",
        ")+\\|n",
        "VPVW)",
        "u.:[Q",
        "MdE_iG;",
        "X*7oG{b",
        "!0ho-",
        "z%\\$;",
        "AIctG",
        "4,0:y3",
        "8*8k8",
        "n7>{o!",
        "<qQ:G",
        "bBbVHT",
        "p MWj",
        ",{{Utj",
        "9D$(U",
        "KHC--K",
        "*RFY&7",
        "j&jgj",
        "hr/LL",
        "> >3>",
        "\"Wrsg",
        ".?AV_Node_end_rep@std@@",
        "H\"uQ8",
        "p$2N ",
        "cm=%Sk",
        "WdA;@",
        "biometricInfo",
        "mqCM8C",
        "X-P19V",
        ":|Omp}",
        ":0:B:^:d:i:s:",
        "a3cjbr",
        "OtE:.",
        "WhtV\"",
        "&Z.g0",
        "gw@'6",
        "Eg?sq",
        "}>Pcq",
        "0 0$0(0,000",
        "VggjeK uO5n",
        "DvoXr",
        "eV}3[",
        "hxDK,",
        "\\ltrch\\fcs0 \\fs20\\ul\\insrsid2388238 DLP}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid883884 \\'94}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid2388238 ) Blade}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\ul\\insrsid7224833 , }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "=4>S>u>",
        "5P2Fb",
        "failed to write XPath selectionlanguage indicator to custom action data",
        "InitializeSecurityDescriptor",
        "6Lpd:",
        "9F3T/",
        "3<3\\3h3",
        "-}/.K",
        "1:NfD",
        "i!JCd",
        "vg1'3",
        "J}@{/",
        "2Co\\P",
        "^S6TM>c:/P",
        "cipher table src error",
        ":8:q:",
        "f?v_.",
        "?!?9?A?b?",
        "1NvVJ?",
        "#h!,j6Z",
        "v%.pm",
        "uVWVU",
        "tbQPS",
        "2@w`})3",
        "$Z{mJ",
        "Om/g ",
        "/?]%[^",
        "ZJYL1%5%",
        "DSA_PARAM_DECODE",
        "474S4o4",
        "{N/^8",
        "4%-F(",
        "O.u9PM",
        "\\O%@>\"2",
        "6tb]<u",
        "`-%X$",
        "1_54>",
        "3^\\mg",
        "H9DQW",
        "7)O#F1",
        "\\9sLU4",
        "OlXD)kT",
        "4I;1F+j",
        "lbk!R",
        "AC{m?G",
        "BUFFER_CTRL",
        "|RL=;b",
        "g~-g^",
        "9L:j:",
        "d&-x~k_",
        "D$0SRP",
        "|PC6p",
        "#m|6l",
        "HF^.:x",
        "<+=5=R=c=x=}=",
        "k^4j>",
        "c3\"zrt",
        "X6+wT",
        "_+Q]V",
        "basicOCSPResponse",
        "Lx*F+",
        "+ qcj",
        "Fbm|$G&DH",
        "J3d'm",
        "*:(mk'",
        "FWFreshAfter:  InstallProduct",
        "dNh\\k",
        ":(:H:T:t:|:",
        "6dM4;",
        "J< e}`29&",
        "B\\^?v",
        ";'z\\r",
        "l0f]l>",
        "4#4(4.454E4M4T4[4s4",
        "tiffV",
        "$a@WH",
        "Failed to find SC GUID in registry, get last error %d",
        "1e[)g2!M",
        "3H6rA",
        "i#l99",
        "2!292j2",
        "4=L(KT",
        ".tls$",
        "U{URO",
        "{%Cjrl",
        "}ec@\\7",
        "(Mu5R",
        "z+DJ{^",
        "202006301200",
        "[;_ C>_y",
        "Q8Iww/{W",
        "m+OUO|6",
        "qG%Z/",
        "+LRFk",
        "pfsOY",
        "^R||+",
        "][$iD",
        "TzrU5",
        "2jJ;b",
        "(1;c<",
        "02Q T=B\"",
        "tlL4u",
        "Plugins::UnregisterAM:  Unregistration successful.",
        "-/fGx",
        "85!@Ls&",
        "p)V4)",
        "P/}{\"",
        "{ex<Y",
        "\\evWG",
        "ukV(b",
        "sequence length mismatch",
        "vN1z/",
        "5#535G5[5",
        "%q#OW9",
        "createElement failed",
        "Cg2Vf",
        "$aFeg",
        "hu-HU",
        ".?AVjson_parser_error@json_parser@property_tree@boost@@",
        "c1HGHnI",
        "WixExecFirewallExceptionsUninstall",
        "<J@|=",
        "<Mp:s",
        "DBRYsG",
        "3<3F3y3",
        "909X9",
        "naV+]",
        "vz-@j",
        "NAOFFD",
        "X3Q8\"",
        "dGvt(g*",
        "]J)3P",
        ".3Ibz",
        "Kz;v(",
        ":'RIzs",
        "jAjlj ",
        "2>?W-",
        "DFa~o.{",
        "9U%+a",
        ")P&CMjU.",
        "PBE2PARAM",
        "1$1D1L1X1x1",
        ">#?N?",
        "J28$jb",
        "EXg52h",
        "%4U$~5",
        ";]##u",
        "r<q$`",
        "&*&.&2&6&:&>&B$FLlL",
        "YZ2M+",
        "C;Wz/",
        "Yf2q8",
        "q6){3`i",
        "%\\P0-/",
        "#@gY>",
        "q!@=((",
        "`3TG`",
        "656F6i6",
        "gZ~@\"",
        "%5P/cZ",
        "4p-N'X",
        "rL`g.",
        "? ?$?(?,?4?L?\\?`?d?|?",
        "=p9o\\",
        ": KyK*",
        "xiEL ",
        "/y _|P",
        "9F5O[",
        ".DuDv",
        "szOldFirewallPath",
        "y\\]Kt",
        "OZmfv",
        "5-Yby>",
        ",#*#)#",
        "~]iX7H",
        "gW&wH",
        "D$HWP",
        "failed to allocate string for unique column: %d",
        "QueryDepthSList",
        "hR@t@",
        "4!515O5",
        "*9P]K)L",
        "JNN~~",
        "T.{V>",
        "unsupported salt type",
        "x$BTT/",
        "s;r+i",
        "H/rx9Y7",
        "JId4dAI",
        "Zyax%M",
        "ba0)KS/",
        "K]2Mi",
        "ODM F",
        "pZf.'",
        "FindFirstFileExA",
        "- unable to initialize heap",
        ".3zVLl",
        "disable",
        ",l}VU",
        "[p8J!",
        "9&929v9",
        "DY&`\"8`",
        "4)505<5F5]5d5p5z5",
        ")\\ZEo^m/",
        ">7?q?",
        "68q{/",
        "Connect data stream actively",
        "/]4L4",
        "n1lo}",
        "Cl@?%",
        "N:sT ",
        "length is greater than %ld",
        "ECDH-ECDSA-AES256-GCM-SHA384",
        "8TS\\v",
        "C,PjVW",
        "d=Zj#",
        "~,?;EO",
        "!I7M:jD",
        "Ku=.u",
        "'{$eb]",
        "pC?UIg",
        "~nWUVV",
        "Upgrading driver files.",
        "\\%|JI",
        "wI=d-",
        ",q2wAG7l4,",
        ",)alA+",
        "@0>0<",
        "Vm]{d",
        "t$ VW",
        "I'rx|",
        "5R!Obz",
        "QaI0m",
        "`YKd/&",
        "Me>}M",
        "31373e3{3",
        "R6034",
        "Ie:McG",
        "f!Awc",
        "}4^K3",
        "mX=-@`1",
        "nz]6)",
        "2MjyizQ",
        "\"B <1=",
        ".&osn",
        "(uTXH",
        "=zS\"'e",
        "gGTJ\\4",
        "bv!e1+*#",
        "]E]4f",
        "+121:1B1J1",
        "@n*?5",
        "JN0jm\\",
        "s,e0Z",
        "'h]'*",
        "ds9j2",
        "2B3M3X3_3j4",
        "&|3SJ",
        "v=,`b.",
        ".\\crypto\\cms\\cms_sd.c",
        "OuyLZ",
        "s'|`<F",
        ":pP=m",
        "INTERACTIVE",
        "919:9G9R9",
        "yugoZ}",
        "vQ(as",
        "fx12Uzq",
        "isv,V",
        "KO=2X",
        "}<Im2",
        "=`!>3",
        ".OM>&b4",
        ">{l6T",
        "m_QK+",
        "8ewuI",
        "*1$!s",
        "P^7_n",
        "MU!n?",
        "!JII)",
        "=0H'8F",
        "Z}\"e/",
        "BQn5_)",
        "XseVt9|c",
        "?qJm;f",
        "jq[Da",
        "SHFileOperationW",
        "ConfigureClient:  ConfigureClient finished.",
        "mK+g1",
        "646G6",
        "nd:\"T",
        "8/9R9",
        "<vrXF",
        "D$h;|$\\",
        "7A7u7",
        "314N4",
        "4#C9,p",
        "+\"RGpZ",
        ">1>=>I>i>",
        "esponse dialog, and the insertion of text in the authentication success and authentication failure dialog boxes}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid8607116 ;}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "H&$R,",
        "c:DlJ",
        "B(CX ",
        "B`aOja",
        "PatchSBAInstallerCA",
        "<*<=<d<j<s<",
        "7{O^Y;",
        "686O6q6",
        "`){.@",
        "HU100",
        "9$fg~$C",
        "I !S2",
        ">K, M",
        "#0ew!T",
        "7{ng$",
        "8(8L8l8t8|8",
        "k,?3Y",
        "ko<<n",
        "cG^$NSI;",
        "iQ9Qm",
        "z)k/~",
        "Q5@L+",
        "_s!ImQ",
        "adding object",
        "3c,:{#",
        "IL//VG",
        "uBjAYjZ+",
        "N&x\"b",
        "2hkCd",
        "E|iiQ",
        "l>!eX",
        "_=ckn",
        "~r$t$",
        "EcS0f",
        ")O`|Sa",
        "S&]@h",
        "V?&|]_",
        "$QbD@",
        "u*8zE",
        "|$@;h",
        "=&=e>",
        "kOs/v",
        "cms_set1_SignerIdentifier",
        "K<2QJO",
        "O+zN+",
        "kD>gr",
        "6']c ",
        "Wu9f5",
        "6@7S7e7",
        "4Hl(h",
        "sgtu9",
        "zgGbwV",
        "vFYS[",
        "K/C9g",
        "WUSSS",
        "BN2222v2",
        "p@yZn",
        " copy failed.",
        "2S3w3",
        "<ASN1 29>",
        "hJsljv8}",
        "ExA;K",
        "AU@ZG",
        "BWOs'",
        "o+\\HiE",
        "zl+J|",
        "5(515`5s",
        ");h*'",
        "=\\uI=",
        "\\?4 i",
        "wmB8a",
        "imaps",
        "jejgj",
        ":2IZ0",
        "!tX)i",
        ">|&i|",
        "+w@9VX",
        "3'O s",
        ";1D4p",
        ".\\crypto\\bn\\bn_gf2m.c",
        ",http://crl4.digicert.com/sha2-assured-ts.crl0",
        "DO_PVK_BODY",
        "ghY\\5-",
        "3L$03L$(",
        ")m0c(",
        "6=wHY",
        "3-P{F",
        "6e6p6",
        "2;2o2",
        "X0e2j2o2",
        "0/x!8",
        "xw%TT",
        "6*656G6V6",
        "E-+j?Q",
        "^[l(:",
        "mW> <",
        "%w#W%",
        "hMQZ\" \"",
        "RjY:YW",
        "y'c52OrO",
        "1,1F1",
        "WIN32/release.dynamic.msvc141",
        "D$ WPV",
        "DHMim",
        "))BPKI",
        "Kq&e]",
        "5{AkZ",
        "XN$+vDy",
        "<!<B<",
        "0PZ,3S",
        "z,QoH@=x",
        "DgN,Bc",
        "f~n($",
        "Cd?LK",
        ")cK0q$#\\",
        "Sh j#",
        "{%+Tq%o[",
        "C-QVl",
        "{E1V\"",
        "h,GR:/",
        "ED$TPU",
        "9 HCM",
        "6e7U8",
        "FV:1d",
        "P_qQ5",
        "05g<P",
        "]y+up",
        "4W_9X",
        "U[:?k",
        "^xF&z^:",
        "0]Da*",
        "&hni/",
        "R!{uN",
        "T^dfW",
        "0 0)0.0F0T0`0f0l0",
        "486l6",
        "l$tUh@!#",
        "3IB(27M",
        "\"?Bd-",
        "PQWSV",
        ",~]N4;",
        "agh'<(",
        "compressionAlgorithm",
        "/:PQ.",
        "^PPU-V",
        "{dS~`",
        "2&wMV'",
        "\\k183br",
        "cz4+J",
        "!(RjQP",
        "FbUMi",
        ";/;V;",
        "DgZ\\]",
        "sL;K*r",
        "~48\"pk",
        "H\\h:4",
        "b.Kim",
        "&,d/2",
        "= =5=j=q=",
        "\\ /.i",
        "mYyb5",
        "8C!za",
        "KAfyH",
        "I:agY",
        "7P7t7",
        "0yS;o",
        "RSA_ALGOR_TO_MD",
        "LK,67",
        "5A6Z6s6",
        "XMJ CH",
        "7k!q}Suh",
        "Vh\\0&",
        "(nT9e",
        "(ENWG",
        "v:^MY",
        "NeedToUpgrade",
        "Last Windows error = #%u, %s",
        ":<_X~<1",
        "j%l7i",
        "COMISD",
        ",qN_Xe",
        "lstrcpynA",
        "(ME_{",
        "6.Efd",
        "#IbVI",
        "9ax'NS",
        "L$L_^3",
        "B@z-N",
        "Can't find Secure Client proddir",
        ">7><>A>",
        "J?mIq.",
        "bu:#`]/",
        "2&303G3s3",
        "sxoKGi",
        "z-ByyME+",
        "Rf_4R0)",
        "Q'%Av>",
        "Entry path is '%s'",
        "<MERegProtectionON>",
        "?$?,?4?D?L?T?d?l?t?",
        "L4G=^",
        "4_!9W",
        "ByM~'",
        "+diP]c",
        "\"b&Ak",
        ">=gM8eB",
        "\"GGmf",
        "Oo]|[",
        "szNewPWInstall",
        "4 4(40484<4D4X4`4h4p4t4x4",
        "Z w}c",
        "[NE,v4",
        "z$nVu",
        "}^zNKW",
        "Remote access denied: %d",
        "7\"8e8",
        "b]CN[",
        "bgAGCw;",
        ";={._QmM)",
        "{Q,9WE:OkC",
        "mJ`pJ",
        "D$<j0P",
        "j'*Oj",
        "ITFMAt",
        "6tkTX",
        "D$0Ph,",
        "``#.nR",
        "g2|2z8",
        "<,<0<H<X<\\<`<d<h<l<p<",
        "u'GO.l`~<",
        "?Hx2N# ",
        "e03@Q",
        "X9.62 curve over a 239 bit prime field",
        "USER32.DLL",
        "LFQxNAe`!&",
        ">%>B>m>",
        "GkR[4",
        "y^uzW",
        "TE5/b",
        "(gv3>",
        "b!'@6",
        "E<m\\sV",
        "L.eS+H",
        "0'1>1g1",
        "RemoveSD",
        ":(:0:4:H:L:`:d:p:x:|:",
        "1^/['M",
        "Suite B: cannot sign P-384 with P-256",
        "= =0=<=D=\\=d=t=|=",
        "({|Rq",
        ";PgO.",
        "!2|0>@]4Y~",
        "Server verify",
        "!R!E\"W",
        "\\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        ">2}GvL",
        "7)7G7i7{7",
        "?.|qG",
        "_{.JR",
        "`LE0sC",
        "F,1FL",
        "r6#6mp",
        "@_o5J^",
        "qgradient",
        "InstallPrerequisitesNoWait",
        "\\W?jX",
        ")W@Ig8Cp",
        "L m5=43",
        "*aPK*",
        "4Fh, 3",
        "]O.\\(U",
        "5(5H5h5",
        "\\unregConf.txt",
        "s)jdh0",
        "FreeLibraryWhenCallbackReturns",
        "'~YBO",
        "7,SqE",
        "E: 36",
        ",X7V-B",
        ".?AVformat_error@v8@fmt@@",
        "-Es>T",
        "n2,Au@",
        "5$5+52595A5E5I5M5Q5U5Y5]5a5e5i5m5q5u5y5",
        "%s |%d|%s|%hu|",
        "H\"9ER",
        "h&o-ei",
        "RfAQfJ",
        "failed to set WixCreateInternetShortcuts custom action data",
        "t>'1A",
        "R-!4E$1^",
        "f_qn>",
        "Ld\\ '",
        "<oCxy",
        "HPQVR",
        "boost::filesystem::file_size",
        ":P#p?",
        "RESETVPNCONFIG.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "?#?)?L?",
        "M0^fx",
        "uNSVW",
        "GetCurrentThreadId",
        "1o2v2",
        "jzj{j.",
        "#W=D-",
        "q8=VS|",
        "m@mTm",
        "/z=rC*",
        "0qT*Uv",
        "O+Xd4@$0%`|",
        "+cYs9",
        "!?<-kG",
        "u2tM1",
        "m%W[0",
        "g:{4W",
        "3%4U4",
        "94f8N",
        "@ZaA(",
        "Connection cache is full, closing the oldest one.",
        "y!2V|C\"",
        "=\\&>.",
        "f9F.t",
        "AtA~y",
        "\\$4UV",
        "bU a\"",
        "p.\\M[Os^",
        "exponent1:",
        "mS^!t",
        "jzjuj!",
        "w)*5~",
        "i h2jEj",
        "ggKAk",
        "J _m+",
        ":-IMv",
        "~@Iv2",
        "^h'cU",
        "<\"=B=b=",
        "=yyXh",
        "5 5J5z5",
        "E$+m]o",
        ";sFfv",
        "!cwS1\"D_?",
        "q.q<q>q@qBqDqFqHqJqLqNq\\M",
        "4 4T4d4p4",
        "r:0BK",
        "BIBSBUB^BbBiBjBmBpBxB",
        "n^UZ'",
        "~F^jHe",
        "O4OtO",
        "LDAP.",
        "!R7\"yqE",
        "7qTN$r",
        "+\\gC1M",
        "J<Zv\\",
        "474k4",
        "4;4q4K5",
        "24$ #Ro",
        "RESETVPNCONFIG",
        " -disconnectedPolicy ",
        "9LF,\"",
        "VWho\"",
        "CJb~s}",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\Framework",
        "J{sp&y",
        "lc %r",
        "ctrl operation not implemented",
        "dNSDomain",
        "2HFE!",
        "_ps:U",
        "Yzk2k",
        "ffffffffffffffffffffffffffffffff52006f006f007400200045006e00740072007900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000016000500ffffffffffffffffffffffff0c6ad98892f1d411a65f0040963251e50000000000000000000000005019",
        "Afxu^'k",
        ",?bRmw6",
        "m8GVK%",
        "5lWh{",
        "D6\"]E",
        "/D&6P",
        "q]A<T",
        ";4w-q",
        "^pS*qC",
        ".^2CT",
        "v,1LL",
        "y?784",
        "(R-?%",
        "-VWxZ",
        "1z7)<",
        "#]3Yc",
        "Q89Q4u",
        "%%|=%",
        "U 3P0",
        "CVTPD2PS",
        "gB,F5",
        "\"GO2M",
        "+ec98",
        "G,-bI",
        "d+iCI",
        ".-WQ=",
        "-g1^r",
        "1^1j1x1",
        "_+F.7%Va7",
        "K$'Ow",
        "ti:\\=",
        "{]-&Q$",
        "l:1<u",
        "P\\\\G+",
        ";9J9#",
        "a)ig`?",
        "MpNOf",
        "M;Wm^",
        "!Ve\"pt#!",
        "ebPeYeO",
        "8Kgi+",
        ":~t-o,",
        "Set OVERRIDE_DISCONNECTED_POLICY to true",
        "#(`)y]",
        "ZT9]Li,",
        "select/poll returned error",
        "wfVos",
        "ggM/r.",
        "=1OR3{!",
        "ikXRr",
        "w3Dl`",
        "Xi(so",
        "b;'Qr",
        "kk%Ou",
        "Failed to delete WcaNotVerboseLogging global atom.",
        "ECP_NIST_MOD_521",
        "AC2y@",
        "?,?p?u?",
        "b'!y1@",
        ",:KLk",
        "(Rm$'N",
        "*VUbI",
        "e?AsC",
        "SOFTWARE\\CheckPoint\\Endpoint Security",
        "5h@kJ",
        ">3>G>",
        "SetTdiEnable: vsdatant registry key was not found, tdiEnable value will not be updated",
        "&$D~:",
        "e\\_d$",
        "jmjej",
        "acexG",
        "%%TXb",
        "-64Pm",
        "BCryptGenRandom",
        "FNCLEX",
        "o9ba&w",
        "=u~`8",
        "DESCRIBE",
        "L$<_^][3",
        "ZLCLIENT",
        "P`c68",
        "dp?]?",
        "tHE@z",
        "bad cast",
        "@&LSj",
        "y@[%bDplt",
        ">(?b?",
        "5j@@1",
        "G;~P}",
        "5f5u5V6",
        ":i%-[6",
        "7Tg)b%b",
        "Z|ORX",
        "*.dll",
        "(l^07",
        "O|{k~",
        "QEdYOVnL",
        "Nu-]&",
        "~bW;U",
        "[)RD|,",
        "Unable to negotiate SOCKS5 GSS-API context.",
        "7uct. Check Point does not guarantee that use o",
        "9+9R9s9",
        "Xy`X ",
        "QD:GG{<92c",
        "a*IUS",
        "Wr`KX",
        "SEC_E_NO_CREDENTIALS",
        "FAILED_TO_DELETE_VALUE",
        "d1j1p1v1|1",
        "Vaq(C3aw",
        "called with even modulus",
        " CCq2+",
        "u9$< ",
        "RegKey::GetSubKeys()",
        "N'O'9*",
        "j 2Bl",
        "&3jQ!",
        "E kn$",
        ">)8=-",
        "NAOVTD",
        "I{<${2'",
        "b2\"rTm",
        "NU6sK",
        "Bi{$Y",
        "CL@s\"",
        "ay#U=P",
        ">zzoV",
        "e0W%M",
        "~nP6~W",
        "P,04q",
        "j0Xf;",
        "Set reboot flag TRUE",
        "YLE64",
        "!rlQs;",
        "%s service - failed to request stop.",
        "WD_RemoveWatchdogService",
        "$_@0p",
        "SG;Hr",
        "',^e_",
        "OELnz",
        "*hE~M",
        ")%,!3",
        "peer error no cipher",
        "jIel(",
        ";$25H`",
        "ENGINE_get_pkey_asn1_meth",
        "D$TPS",
        "m%[T`0xY",
        "~mvVF",
        "VT;2;",
        "9YwjQ",
        "user32",
        "8 8-878A8G8Q8[8i8o8",
        "W\"v\"4",
        "D$8WP",
        ">[Y-I",
        "qLM0o",
        "cannot obtain CurrentBuildNumber value %d",
        " RBVBZB\\A",
        "MergeCommonBackup skipped",
        "h:%H2",
        ".ZSZg^",
        "\\5@O7",
        " 0xef",
        "n),y{+~",
        "KK+.TK",
        ":oY|Q",
        "npRNQ",
        "[CVW\"2",
        "1%1A1]1y1",
        "3`y0hPc`(",
        "oR@fH;!",
        "kV_B&",
        "3L$T3L$41L$ ",
        "'+crg)",
        "< <<<@<D<H<L<P<T<X<\\<`<d<h<l<p<t<",
        "glNB_",
        "eLv)F",
        "$]`t!T",
        "&#KcY",
        "4 4$4(4,4044484`4d4h4l4p4",
        ")N^GX",
        "<?SBM(z",
        "BAD ENUMERATED",
        "P9X9`9d9h9l9p9t9x9|9",
        "|[D1h",
        ",!9W%",
        "=K(3\"",
        ".kK>80\"",
        "AES256",
        "IZzZuBhD8",
        ":1;\\;y;",
        "m2W-}",
        "9.|m,",
        "z;dV_N{",
        "0U?`q9",
        "wIT.N",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\featurefde.cpp",
        "gF!>Or",
        "!T^{/",
        "5hm\\o",
        "_}kU>",
        "?8.LQ",
        "#h9C7",
        "j7!.Qc",
        "8<$QDI",
        "t#htU!",
        "api-ms-win-core-processthreads-l1-1-2",
        "EZTEK",
        "kJ.bn",
        "AWL&:",
        "YLiMY",
        "O\"}C;",
        "3LZCu",
        "u+9D$",
        "(f+Dk",
        "Telemetry was not sent and not stored.",
        "?!?1?Q?a?",
        "no issuer details",
        " c*h[F?Sb",
        ">YcJh",
        "_KKK_",
        "5EpJ)J",
        "jZ;15jY",
        "LrO}p5",
        ".r~m$5D",
        "160107120000Z",
        "UnhandledExceptionFilter",
        "1g1l1q1w1",
        "invalid mgf1 md",
        "6/7~7",
        "OCSP_SERVICELOC",
        ".qk2^",
        "> >2>;>@>R>[>`>q>",
        "des-ede-cbc",
        "nH@#V;Cr",
        "3:wlB",
        "dtplat.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "<(<<<@<P<T<d<h<t<|<",
        "[z /6G",
        "t#p\\i",
        "0.d!>_o +",
        "%J(Tg.",
        "}<9=U",
        "`&Z|@F",
        "\"@`3ux",
        "setext-cv",
        "?1cK0",
        "dyXPK.",
        "2!2&2G2L2t2",
        "aAaaaaaaaaaaaaaa=",
        "v](09i",
        "D$PSUV",
        ";REMOVEPRODUCTS_C;REMOVEPRODUCTS;REMOVESYMANTEC;RPCONFIG",
        "7V9'~%}N",
        "x\\I[O",
        "=ch$^B",
        "V%>RXd",
        "bh0]g",
        "363@3J3T3^3h3",
        "-ARb>",
        "[DUMPFILE] dbghelp.dll too old (missing MiniDumpWriteDump), unable to write dump",
        "CA1]_^",
        "zG_O89\\",
        "Z4p/Gqq",
        "L$,USj",
        "][^_3",
        "restoreSecureClientUnInstall",
        "oYA&<=}",
        "-V&+Z",
        "C)]tj",
        "YI %sx",
        "MV8.b",
        "q'; g",
        "@/R|@",
        "IuY@+",
        "%r`>W",
        "IEL+^W",
        "YU)Xq",
        "Y9DJgV",
        "PKCS7_simple_smimecap",
        "xo$8$",
        "181<1D1X1`1d1h1l1p1x1",
        "_8hTxq\\nSeO",
        "FW_SHA1",
        "rCA[yr+",
        "28I^x",
        ",]Xn,y",
        "SetFilePointer",
        "3JhRRK",
        "&]jN4",
        " #8Fc",
        "_A-z?M",
        "KE3o?J",
        "N[~h'",
        "last octet invalid",
        "1<1@1D1H1L1",
        "K6*Q-",
        "]=x'>}",
        "%/>as",
        ";t$,v-",
        "%*sTrusted Uses:",
        "' vMt",
        "D$ ;G",
        "Failed to retrieve request from Binary table",
        "Ly[S\"",
        "2y(V%",
        "`a4``aT",
        "(EI#Y",
        "-=b[b",
        "3M1EM5o",
        "JbZ|Exaa",
        "2*282I2N2f2x2",
        ";+;>;j;",
        "t$@WVUV",
        "3TO& ",
        "\\p6m^",
        "0(!%ze4",
        "53Eg&j*ok",
        "%niN{P",
        "null parameter",
        "5&6U8`8",
        "6 7M7z7",
        "\\CALibrary.dll",
        "a^*X,",
        "D!clM",
        "Component '%ls' action state (%d) doesn't match request (%d)",
        "Jj7xt",
        "%'%1%=%C%K%O%s%",
        "*X&@?J",
        "2}O922",
        "CMS_CertificateChoices",
        " //!\"#$%&'()/*///+,-/.",
        "9$9D9L9T9\\9h9",
        "2u`c$",
        "\"k6n&",
        "STARu",
        "bZ4-0",
        "failed to open view on SecureObjects table",
        "O>zrb78",
        "^;?#)",
        "Bh*it",
        "qePtQ",
        "_getUnformedEventsWithIdsCount@4",
        "a=bqNA4",
        "v@3Aa@",
        "*[9=O4I",
        "_T&|RS@(",
        "6Q6a6w6",
        "SOFTWARE\\Zone Labs\\TrueVector",
        "failed to schedule ExecSecureObjects action",
        "f9D$4w",
        "8cSwK",
        "s}H\\|",
        "Q<6-V",
        "}$~ ?",
        "[FUTj",
        "$8{b`",
        "NGZ=S",
        ":cu84y",
        "2nR5.",
        "7G N?",
        "VerQueryValue for file error %d",
        "43<-`\\R",
        "S|'b.",
        "CMS_sign",
        "IPSec Tunnel",
        "do*NS ",
        "&zwc|y",
        "mRb R",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Anti-Malware",
        "1B1Q1",
        "-^Q(Y",
        "o?Dno/",
        "oGp'F",
        "CIaB4",
        "1G6Yu",
        "jyjsj!",
        "00191?1",
        "D$$UP",
        "dji_,",
        "?$?2?8?I?\\?b?g?",
        "+JFRU",
        "xg,nS",
        "X'T;sO",
        "0$0D0P0X0",
        "kQt@h8h>",
        "oKA&'",
        "curl_easy_cleanup",
        "eOtIx",
        "SetLmhostLookupParam",
        "D2I_ASN1_UTCTIME",
        "'cQ\\4",
        "q.I5TiS",
        "2J?S1",
        "`?u9e 'GL",
        ",l))=",
        "2VF*W",
        "rXq+x",
        "D$X;t$Lr",
        "%KdIo;G",
        "x#zm2<Lw",
        "0&787",
        "<=W6N",
        "9@=Q>",
        "4Tj{)",
        "C.P<P",
        "0$8q>vm]",
        "w?Gx$",
        "obLgf",
        "aemS7",
        "\"wyU(",
        ":/;k;",
        "1<v+7*",
        "=%>->=>k>{>",
        "b=}Re=",
        "pGp^q",
        "tlsv1 alert access denied",
        ".c$n +",
        ".cUC$t",
        "Z0]#x]\\",
        "Q,r,2",
        "%EY4QAV\"",
        "f:v-M5",
        "\\[gfI",
        "OnFreshPrepare",
        "979H9P9^9",
        "]~/mpo7",
        "C&hQ1j",
        "LLQ-p",
        "<j|lx",
        ">,'1D=",
        "H'K:{+",
        "%yLB.o",
        "9d*U,",
        "n\\w*V",
        "3`Z}%",
        "6M Ih",
        "221219114005Z0+",
        "e&Rh!",
        "n%&_^Y",
        "SC-EYq",
        "L{9<[",
        "\\Internet Logs\\vsdata.dll",
        "7;8;9;:;;;<;=;>;?;@;A;B;C;",
        "jAjvj!",
        "SMIME_read_PKCS7",
        "j3Zy-",
        "O|\\Ns",
        "w5xex",
        "~|}=RU",
        "3)vY5n",
        "0c;F8",
        "oY.r`;",
        "cNk_.B",
        "VSSSSS",
        "id-smime-aa-timeStampToken",
        "]\\r*)",
        "lep8C",
        "PKCS12 lib",
        "2-3D3",
        ",7=y{",
        "F<9Fl}",
        "5y!NyV",
        "w~z=k",
        "\"xz1M&",
        "P5a-Jzh",
        "PBEPARAM",
        ";D;t;",
        "5!5&5,52585=5C5I5O5T5Z5`5f5k5q5w5}5",
        "!at$|",
        "eE-ey",
        "4sq5w1",
        "&ytM:",
        "9D$,W",
        " PjPW",
        "DMHX+",
        "OhNX</",
        "lh2~aV",
        ">&/o;",
        "McAfee Firewall",
        "102e2",
        "+^eNJP",
        "7k/;z@",
        "FMW(Ks",
        "t$0WU",
        "T3qcj",
        "W;RJc",
        "A,;vM",
        "1s^~}%/t[:",
        "]+oUs",
        "!{mGx",
        "~@UZHa/",
        "D$ WS",
        "o\"~?B~",
        "R.j&3",
        "StartServices",
        "b#>@zK",
        "@^:tCx",
        "8-p1 ",
        "a2Ro>Y",
        "<e%k5",
        "-MhwWz*2'",
        "RSA lib",
        ";`73b",
        ">=t&>",
        "U2d%a",
        "%fO'=",
        "=s.(B",
        "q?]ng",
        "1I]VU\"nNl",
        "W!&qU'",
        "9\"9.9;9E9{9",
        "WIX_SUITE_BACKOFFICE",
        "cu9NG ",
        "PREV_BUILD",
        "u&h`s",
        "I]=^4",
        "i0@1b132:2",
        "^LF'^",
        "Action",
        "777>7I7",
        "uW8\"}-^",
        "p@Qvsi",
        "y6R9pr",
        "?d+dF",
        "c<6\\Q",
        "<$<(<8<<<H<X<h<l<|<",
        "l``^7q+",
        "YO[eaO\"",
        "r *-V",
        "t3{/g'",
        "D-~b0S",
        "AgJg\\g",
        "=fpw+",
        "F{\\L{te",
        "oaep decoding error",
        "9$9<9L9P9`9d9h9l9p9x9",
        "[8mW:",
        "eh|&w",
        "\"!4LJ-",
        "sc#0aZ",
        "1YMeE",
        "GQ)W@;",
        "EncodePointer",
        "Q\"z>[",
        "2U2/zM",
        "CRolloverMgr::CopyRolloverBlock():  unable to write the file header",
        "Vljts",
        "?(?L?T?\\?d?l?t?|?",
        "3T$L3T$$",
        "t$ UU",
        "vU\\d% ",
        "&KLWd1",
        "&l9K=HO",
        "onlyCA",
        "d}~kw",
        "_xRnx#(",
        " The License Key You obtain from Check Point enables the Licensed-server which enables You to use the Licensed Configuration of the Produ",
        "lr(6[VDg",
        "str_field7",
        "q/4G]q",
        ")Hbc5",
        "M|]|m|}|",
        ";C;p;",
        "aa~!6",
        "f+Al#u",
        ":g:v:",
        "blowfish",
        "G+~$uE",
        "6>7L7\\7i7y7",
        "VSReadKeyUninstallInfo",
        "KAg>D",
        "=>p} ",
        "%GaXy=N",
        "RVL6p",
        "p-+CT",
        "-]'9l",
        "st|*x",
        "DefPolPrepare failed to backup common policies folder.",
        "Bh}2.",
        "A$G4J",
        "Wj XP",
        " V5.&",
        "'qS1=",
        "{X{&R|?*@",
        "letter shipped with the RMA, to }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 the Check Point designated}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "? ???",
        "DeleteProcThreadAttributeList",
        "uGI$BS",
        "5#ffp",
        "^HfC:",
        "vzgTJ",
        "M*JgP",
        ">%>0>&?8?M?",
        "JCY]1o",
        "jqjqj\"",
        "unknown result from WaitForMultipleObjects()",
        "9C&0ys",
        "D$4_^][",
        "smEg4",
        ":SU)7!",
        "G@kX1",
        "illegal hex",
        "sZY\"n@",
        "_z%SG",
        "2*3D3`3",
        "!LplX\\",
        "ub2t\\K",
        "jkrp:@",
        ";uwBv",
        "O1`Kb",
        "V[VmF2Z",
        "lJ@OG",
        "3x0(|",
        "EPkhpT",
        "Found conflicting software directory",
        "81+g)",
        "tzP!yt`A5",
        "?|I7Z#",
        "+J;$J",
        "t:K8M*{'",
        "gs/8s",
        "yD_um",
        "9$i0A",
        "1T2n2z2",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 2.4\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 General Restrictions.}{\\rtlch\\fcs1 \\af1 ",
        "}=S2ds",
        "dQGm>",
        ":M?8?",
        "&@^tu",
        ")x\"N{@]",
        "=(=H=h=",
        "\" @_sQ",
        "N0_{)",
        "\"!T^`",
        "D=1G,",
        "95`{N",
        "*32s:(",
        "wa.z3b",
        "6KU't>s",
        "7hjP`",
        "D\"u`k",
        ".TX;A",
        "fr-mc",
        "^2=.\"",
        "j*&-o",
        "W5%gt{",
        "Y8,QF",
        "iEUIiu",
        "uqhlS",
        "i32,*",
        "^lJ3Gv",
        "6]8:T",
        "T0\"GC*C",
        "9|r*s+",
        "D$pPj",
        "-?=F^u4",
        ">e>y>",
        ">K?o?t?}?",
        "mUaxW",
        "3B\"qj",
        "] /6O",
        "CBT\"iH",
        "7Ct~U",
        "<1=R=j=",
        "\"`pa_",
        "D8(Ht'",
        "#-u9>",
        "'6l)&",
        "x509Certificate",
        "uyoHk",
        "B$WvlW)",
        "5Y=Eg",
        "Error in streaming file from Binary table",
        "\"T!}G",
        ": :$:,:D:T:X:h:l:p:t:x:",
        "p~)s#",
        "]7naq",
        "}J\\TCg",
        "ssl_create_cipher_list",
        "DX kI",
        " -pwinst ",
        "5_(av?",
        "HashDB:I:ravpn_is_v1",
        "qP_+f",
        ",ex}y",
        "SzfR%(",
        "p!!dk'",
        "curve",
        "=.===Y=h={=",
        "unsupported or invalid name syntax",
        "D$$Pj",
        "Fe__A\\",
        "*UW<=4a",
        "]xcr&?",
        "7~V39>V",
        "Ko$%$",
        "^nC\\vf",
        ";M~b'",
        "i|TdD",
        "q,uTW",
        "`nF?:",
        "FG#}b",
        "FLDL2T",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 6.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "<^Gv!-",
        "PRZF]=M",
        "DY,i@`~",
        "dingo_SC_type",
        " 0xdf",
        "q jvJ",
        "Failed to clean up CAScript file: %ls, er: %d",
        "h[{<_",
        "G20jE",
        "Policy ",
        "Fc)MEDE4X",
        "2B3d3i3",
        "_w=84#",
        "4d6w6",
        "l s=.",
        "mT]/D]",
        "&c}{?",
        "PKCS7_ATTRIBUTES",
        "8%|hO",
        "S @<V_",
        "jSWG%",
        "U$Sv;7",
        "Found registry key for possible conflicting firewall",
        "Vu-]i",
        "Negotiate",
        "gz/F_",
        "RbH@)",
        "PmM02",
        "8{w3m",
        "Cx~[^~{",
        "a6IA`",
        ">/?z?",
        "F1$Q3",
        "V+ERLslfb",
        "@(<_b",
        "W:Gzu",
        "<BDAVRegProtectionOff>",
        "&X\\.G",
        ":0k1/2",
        "}\\6~+^",
        "\":D20",
        "1\"H.9",
        "{pAY>",
        "xJ@{P",
        "sR@?Z8v",
        ":dM^>!>'[H",
        "Ph<)M",
        "o4O%H",
        "[3[C[[[s[",
        "3(1 ?F",
        "='Lk;",
        "d8NM;",
        "hc.k]",
        "};4ml",
        "XTuNJd",
        "ReplacedInUseFiles",
        "?SYSTEM\\CurrentControlSet\\Services\\vsdatant",
        "N)mIK",
        "86,8,7200,02",
        "Proxy-authorization:",
        "mI)kp",
        "Offset (%I64d) was beyond file size (%I64d)",
        "WgmBuU",
        "SWj=V",
        "@-[&}0",
        "X@*3'",
        "M8`9L!",
        "xzNi=[",
        "wZcM#",
        "bJgvv_A",
        "h2hRh",
        "]Y|&c",
        "^.A]K",
        "nONq*",
        "Compliance.exe",
        "O\\f>g",
        "kL+)H",
        "x$^C(",
        "e$ eA9",
        "g Y(i",
        "9,9[9o9",
        "6L7p7u7",
        "w\"BU<f",
        "$)O^^",
        "5Hk]e",
        "Z\\okX",
        ",9(39",
        "}A^IW_\\",
        "j7~5h",
        "RGxqe",
        "<'>?>T>o>u>",
        "ovrWdE",
        "3C.0=",
        "eQ:@3",
        "&c#Q/",
        "bad ip address",
        "\"[ja\"",
        "74'd=",
        "{C\"L/<K",
        "A8l@/",
        "gB{]R",
        "gv!GU",
        "</h_n",
        "QE>BO",
        "|s5n'F",
        "jVJn-",
        ";$;(;H;h;",
        "'/(o(",
        ")i^Xc",
        "?VnaCleanWithDir@@YAXKPAD@Z",
        "!j% X=",
        "[DUMPFILE] zipping dmp file: creation time: %d %d, install time %d %d",
        ")Hvv/",
        "3NY~5",
        "__pascal",
        "jPY #",
        ";Q(u&",
        "1vtja",
        ">$>*>:>P>f>w>",
        ":_L1_",
        "@HBh\\",
        "snO`8y",
        "1 ! +",
        "IS'Z0nUT",
        "#pI!p",
        "g_%BI",
        "!y).<",
        "0(0,0D0H0`0p0",
        "IJQct",
        "WIX_DIR_ALTSTARTUP",
        "5 53585D5K5T5Y5n5",
        "V)PU_",
        "ByJU3",
        "<~cN/'",
        "20$zG",
        "@5?*5",
        "|!o,[",
        "i#=@u'",
        "/||:.",
        "<|m I.",
        "fh+^Q",
        "<z:=7w",
        "R%UTs",
        "fSCVwc",
        "G.L0Ej",
        "8S~:+",
        "3R{#y#5#5#5*3",
        "\"=-TV",
        ".WAw\\",
        "ZQbz*f",
        "JOINT-ISO-ITU-T",
        "qCkY]",
        "*z/q!t",
        "M_{aN2x",
        "zXQ+0",
        "<A%1j",
        "RZ48l",
        "v$o)_#A",
        "j>vPn",
        "ol;Vxi",
        "M'KU9$",
        "L0:)/q",
        "Z%m!jy",
        "^TI|DmMO9",
        "u\\.hw",
        "8+Lp@",
        "5p1RM{",
        "030P0j0",
        "9(9,90989P9`9d9t9x9|9",
        "l65Ku",
        "y;K$x",
        "M2ocp",
        "c=6u]%",
        "FVDKr;",
        "SoXAj",
        "jnjhj!",
        "$g%Rs",
        "|3O)4Do",
        "$\\+XY",
        "permitted subtree violation",
        "unknown message digest",
        "1+2y2",
        "Hf9>u",
        "kQ)3PK",
        "1r1}1",
        "ioctlsocket",
        "L$X;L$$tOh",
        "qC*c{",
        "N=8b9",
        "RU*'G",
        "@o>@$>i'",
        "?h..]r",
        "qQE~x",
        "&MEHzDz",
        "{;<3Cti",
        "%3I64dd %02I64dh",
        "aF{_$",
        "keX))",
        "]1`9#5_f]",
        "koVdh",
        "aP- D",
        ">Vy1S",
        "kQyu ",
        "va:El",
        "jjh0^%",
        ">Nu^:",
        "<(<4<T<\\<h<",
        "3=ufT",
        "7%7-777@7Q7c7",
        "# Fatal libcurl error",
        "s|h_K",
        "OnInstallDriverPrepare.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "g]D$V",
        "r'o~{$",
        "!xUs^",
        "L Sx&",
        "l%z~!lZm",
        "0,0K0v0",
        "g2wr7",
        "onlyuser",
        "strncpy",
        "MdC's",
        "434w4",
        "=9{^U<K",
        "T&'J!s",
        "(2Q$&S",
        "3&3.353P3^3k3q3w3",
        "rH;/|",
        "+M|fSf",
        ";$@$D",
        "3N.%b",
        "!F(#J*PA",
        "K*K<K",
        "h2|O!",
        "?PFB2",
        "S_;E[",
        "hash.exe",
        "!R<Sw",
        "1=1Q1",
        "_h}0f",
        "\\vswmi.dll",
        "4d<jl",
        "failed to open view on XmlFile table",
        "9\"9(9.949:9@9F9L9R9X9^9d9j9p9v9|9",
        "ag*o<c",
        "7G|Y)",
        "N{j0i",
        "-z}Kb",
        "9c<o3y",
        "9Mk\"y",
        "x5~Qw",
        ":'&]F",
        "\\sg]n_0",
        " 0xc1",
        "u#3By",
        "S}FeVXVA",
        "rT9TN",
        "vjIHz",
        "9eX<<[,",
        ">aJt(nuve",
        ":IyXT3#",
        "-cx!(",
        "L=,_I",
        "=\"=5=I=N=a=t=z=",
        "fx( tG`",
        "QUuNU",
        "D$HD$",
        "eVlPH",
        "p2d,P",
        "l*nlZ",
        "}B[@(",
        "pW{FPS-",
        "1<jKg",
        "3+|]'",
        "9MR<a",
        "7D7Y7o7",
        "IZ_.w",
        "L$$3L$ #",
        ";J;c;",
        "4 4G5",
        "<J\"r&",
        "BIO_nread0",
        "516s8y8",
        "blank",
        "#dE{6",
        "3 3$3(303H3X3\\3l3p3t3|3",
        "85wsf",
        "'eWY-CO+",
        "<Q'l8_",
        "S>ycr",
        "0sD$9",
        "'_&L#",
        "expected 'true'",
        "n]6M_Q",
        "? N[I",
        "6 6'636M6",
        "= =$=(=,=0=8=P=`=d=t=x=|=",
        "1'2O2w2",
        "W<D|n",
        "}!S)@",
        "h?pd_",
        "EzUn5",
        "L,@<J",
        "t51[Uu#A",
        ")6&C0M",
        "Jx#>s",
        ")#Bu@!1xk>",
        "SOCKS5 access with%s protection granted.",
        "%G*L7",
        "S[8e8",
        "}2+7X&bM",
        "'|B'M",
        "u6Fzw&\"v",
        "id-smime-ct-TSTInfo",
        ">+?p?",
        ":M:R:Z:_:d:s:x:",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 . }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2566336\\charrsid15169477 T}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 o securely erase from any }{\\rtlch\\fcs1 ",
        "Platform",
        "?Yz=5",
        "$#ftF",
        "s=E(X",
        "00080@0H0X0|0",
        "New insthelper.exe was successfully committed",
        "=X:F+",
        "WRU=n",
        "jZ])g1",
        "'8QJK",
        "<\"=g=",
        "QV4b ",
        "tHWSV",
        "PPQPW",
        "Un.}^",
        "/6D~FC",
        "4;4W4s4",
        "Jj^pb",
        ")g2yv-",
        "[DUMPFILE ERROR] error %d loading dbghelp.dll from %%PATH%%",
        "? ?$?0?@?P?T?d?h?t?",
        "OJqHb=",
        "cjZFh",
        ">2?>?`?",
        "*#(a)a",
        "2yIAf",
        "8$[|a",
        "B5wCq",
        "TR?~q",
        "kF-0)",
        "Whpf#",
        "wTYg2",
        "tSprD",
        "3L$P3L$4",
        "Z|h5{",
        "Vv$N,",
        "7;7m7",
        "?|SG0)K",
        "?`5G[0+",
        "zt%Z/",
        "5uB3}",
        "#xwM<Q",
        "Inside, hWnd=%x, pid=%d",
        ".#6M/R.O",
        "c(jo,W",
        "lY w\\",
        "Vh@XG",
        "XyWcN0",
        "`oV-Y",
        "050w0",
        "*_small.dmp.zip",
        "C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/ssl/private",
        ">\"(zn",
        "X509_print_ex_fp",
        "t$$VU",
        "CpSbaCipolla",
        "rsa routines",
        "\\^0j ",
        "$7BTg",
        "l$DUP",
        "qjjx)",
        "KLx)Y",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  77",
        "%HABP[g",
        "SB2Ek",
        "~.+rA",
        "3:ph/h8e",
        "1$ h7",
        "_b$sv$",
        "j]^js",
        "\\3564",
        "!46#(",
        "1-2J2_2y2",
        "1:2b2",
        "Z:ZPj",
        ";pg,f",
        "ssl_get_server_send_pkey",
        "WxE_o4",
        "7+7\\7~7",
        "<@<Q<",
        ">{oSU",
        "$I38F",
        "C1A5G~F6C1C",
        "&,.(<",
        "9s>Qg",
        "U\\Cmtc",
        "OmK8^",
        "Ax@+L",
        "d_{a/",
        ":D;_;s;|;",
        "b/axhx",
        "9Cdpq",
        "cWKjd",
        "+sC<A;]\\",
        "&pULE^{",
        "SRQVPt",
        "~=&Drj5",
        "696Y6y6",
        "failed to remove port exception for name '%ls' on port %ls, protocol %d",
        "1i2~3",
        "8M8U8e8",
        "gIb,Z",
        "QXWIt",
        "CANT_LAUNCH_CHECKPOINT_UNINST",
        "?(?D?`?|?",
        "9^H#]",
        "a|qKW",
        "/)A#n",
        "3n8,F",
        "4.5>5T5{5",
        "d5`uB",
        "1k1.!",
        "it-CH",
        "ssl_cert_dup",
        "Ax,xP",
        "qq=!@*",
        "invalid ticket keys length",
        "8rB=O",
        ":$:D:P:p:|:",
        "I6:]N_",
        "already loaded",
        "7\"8A8f>x>",
        "cEah5L)O",
        "\"#%4LA",
        "ReplaceOrAddTagIntoVSConfig succeeded.",
        "F^wZ.R",
        "dtls1_send_client_verify",
        "t$TS+",
        "AddWhiteSpaceToNode failed",
        "3,3<3@3D3H3L3P3X3p3t3x3",
        "CdGb.",
        "6-6g6n6",
        "^T?cb",
        "MZ]<0",
        "$_CGv",
        "]cxX%",
        "failed to get component attributes for XmlConfig: %ls",
        ";*O*t",
        "X!eV<",
        "b|bN56",
        "GetFileTime",
        "F)^Z<",
        "eKZK6",
        "<p6[.",
        "1 2;2c3}3",
        "2@2L2T2t2",
        "]^h))G#8X",
        "1/=I3",
        "3}r/6",
        "q{y p",
        "&n]}D4",
        "}31UZ4[",
        "9FC%:",
        ">h.;DjF",
        "{P<dC",
        ",%E;c0K",
        "id-mod-dvcs",
        "809e9",
        "i%{ZH",
        "%H8zv`&",
        "aQf'os",
        "****************************** VnaUpgrade ended **********************************",
        "DSA part of OpenSSL 1.0.2h  3 May 2016",
        "Sqn$^;",
        "tW$?~",
        "mber will be required for all RMA cases. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11543880\\charrsid15169477 ",
        "/.Z!k",
        "06\\wa",
        "OY8xt",
        "9<9g9",
        "fD>n&",
        "<5=Nk?",
        ">D?J?P?W?",
        ":sFT%",
        "x0<uXSQ",
        "fJCNE",
        "jyjtj",
        "<l:@Y(",
        ":+;5;R;c;x;};",
        "failed to initialize WixRemoveInternetShortcuts",
        "{HQ>1|",
        "=p$Tx",
        "s9?zP(",
        "\\y0`z",
        "hPk_0",
        "`Pv*T",
        ";Jh8W",
        "152Q2]2",
        ";_pya",
        "k2)Cv",
        "j=2{\\",
        "#\\Q^s%",
        "&Xqfy",
        "SECG curve over a 224 bit prime field",
        ")7@u\"",
        "LINEMODE",
        "seed-ofb",
        "not initialized",
        "7+727;7I7P7V7o7v7}7",
        "d##{Owr6",
        "%08X: ",
        "8$8,848@8`8h8t8",
        "u@0?2",
        "E@DA#K",
        "W[i#f&",
        "D$Pj@P",
        "Issuer:  %s",
        ".j;sK",
        "J^&B=",
        "xt.p735",
        "Remove CPES uninstall link from ARP",
        "[%s LOAD] %s %s, process count:%d, cmdline:%s",
        "2D3d3H)Hg",
        "T&vv3p]",
        "#^6sG",
        "L%XH?",
        "=8?>?F?",
        "zl4u%",
        "{/-5:@C6",
        "Xe,2^",
        "#~0)1",
        "3(_I?d",
        "YPSSSSSSS3",
        "ol:~$",
        "dG/$$",
        "%{N3)",
        "ROG2E",
        "XN'pZ",
        "= =$=<=@=X=h=l=p=t=",
        "\"/J !9<",
        "{D,:>",
        "/q^<\"",
        "gqQ@8",
        "x[v,[",
        "d.signedData",
        "i p(Dp",
        "pkO<v",
        "4E4{4",
        "@VNem",
        "CHPUV",
        "Failed to open rollback CustomAction script.",
        ".aHSa",
        "At4ZBo",
        "8>&kd",
        "DESTROYOBJECT",
        "G2Z% ",
        "B\"u}uS",
        "?zEgT",
        "C705]6",
        "~4$';",
        "ftp://%s:%s@%s",
        "a49\"\",",
        ";NLyB",
        "US++4$",
        "=$=,=8=X=d=",
        "%P%Q%W%X%Y",
        "$*{TO",
        "r_=Cln9",
        ";k7P+p",
        "[z!kM9",
        "ysRY.",
        "-q%sS",
        "%T hq`o",
        "u kE$<",
        "*gk}2",
        "TLS Unknown",
        ">PgJ;I",
        "W-eBYf",
        "<P S-Bx+3",
        "t.Xpx",
        "OMflNf",
        "F'x1v",
        "B98>\\C",
        "w.in\\",
        "%s was renamed to %s.",
        "critical,",
        "4)575",
        "q,8m#",
        " 0xfd",
        "np.blJ",
        ">B>w>",
        "hJv `",
        "`LVEP\\Z",
        "w$Y`CZ8oG;",
        "xNiGDB",
        "AddMitigationOptionsRegValue: registry key was created.",
        "api-ms-win-core-localization-obsolete-l1-2-0",
        "2,363?3",
        "RBSBVBZ",
        "}qLAG",
        "cy^IR",
        "Oao$>k",
        "Q\"ey1",
        "8$848<8D8L8T8\\8l8t8|8",
        ":aZJ!",
        "tls illegal exporter label",
        "'Lm\\/",
        "]k4k[G",
        "?*i>5",
        "({>UT",
        "rAf;E",
        "}dnfn",
        "SB|(K",
        "6%6T6t6",
        "MSchedExe.exe Stop",
        "c1kw_",
        "%u %S",
        "@rHJ\\",
        "UVG_L",
        "t$hWj\\",
        "c||#L",
        "s?-4h",
        "C`({T",
        "HRq>-",
        "tzfB;",
        "i(VS>",
        "alpha",
        "MuA[`#",
        "@=Y+R",
        "Vqg%R",
        "*,x%?`",
        "K-9A6",
        "%+jqQ-",
        ":utLI",
        "h9$+@",
        "BWvy*",
        "~? H^<",
        "8s.E+Y",
        "SOFTWARE\\KasperskyLab\\protected\\AVP9",
        "eT&W~r",
        "tkGJf",
        "9T9|9",
        "@>.s]",
        "1$1@1D1H1X1t1x1",
        "f[@Z}y",
        "@z>zL",
        "mub%OTG",
        "6_{[^",
        "EC_GFP_SIMPLE_GROUP_SET_CURVE_GFP",
        "KUJA<",
        "x~`gv",
        "6,646<6D6L6T6l6x6",
        "7 7-737@7J7W7]7m7w7",
        ".G0g3g",
        "A(uJP5",
        "j&0Q=",
        ">$?m?",
        "A=ze,",
        "SSL_SRP_CTX_init",
        "vo]$mJ",
        "Z'$xZ",
        "-pnky",
        "failed to write exception protocol to custom action data",
        "7R}[UV",
        "*Zm ?",
        "&qHjS",
        "nyWNS",
        "^!bW>",
        "O6+fX}",
        "hwn30",
        "u9sN1",
        "48O(7",
        "},\\*X",
        "running query %s",
        "^CR!1",
        "ZYhDx",
        "bM{hS4",
        "c;2fT",
        "Au]lfK",
        "Z{>rd~",
        "\\hh+Q]j",
        "%-[k1",
        "W2M+M",
        "657:7Y7w8",
        "S[PML",
        "dsa not implemented",
        "7SSLdZd[\\]^E_`a",
        "=VpwA2",
        "Fb|\\b\\",
        "IAY,T",
        "6[7~7",
        "GD~rX",
        "Dej65ZM(",
        "{J>ZI",
        ")0nu#",
        "$VMhC\\",
        "R5XU)$",
        "535F5v5",
        "imz ~",
        "BS\"gM",
        ";iaaow",
        "Name: '",
        "Byya\\T",
        ";xrL^cp",
        "Qy>J>",
        "rMo+#E",
        "y7\\;{X",
        "XKA*YD",
        "PKCS12_add_localkeyid",
        ")]8w}",
        "4S+'-T",
        "3\\$01",
        "CAST5-OFB",
        "'!J|Z",
        "3$4e4",
        "9o`v9h",
        "caught an error",
        "]p8o`[",
        "={fUK",
        "DiLfK6",
        "o=jAd",
        "8F&YY8",
        "'>L?O",
        "d7rIolv",
        "[hY!:",
        "'Hl@&'",
        "',d/8{3",
        "Helper::generateUnregRequest",
        "Av6`>",
        "00000000!=",
        "DRIVERMODE",
        "1A1Y1",
        "ng!7eU",
        "QHV.4",
        "Wuub#",
        "&p>I^^",
        "+{b-U",
        "{TGkx",
        "1+262A2I2R2",
        "/C{VH",
        "VQI1Cx",
        "<]K#o",
        "h?m=|",
        "5(&dV",
        "'MG9#O",
        "~s%7Y",
        "`Df\";Q",
        "jW5D5",
        "^I !.",
        "\"1nwj",
        ":Y}Itd'",
        "qP/oc\"*",
        "_invalid_parameter_noinfo_noreturn",
        "RSA_padding_check_PKCS1_OAEP",
        "(c^:;",
        "xY^`T/^",
        "9u2UF",
        "H(nK]",
        "J[[&l",
        "-!SOWG",
        "<H-gK",
        "}Xl9@",
        ".$H1ld~",
        "7{'D&",
        "ZU:+t/",
        "0\"'Vn",
        "xz,46",
        "2W2l2",
        "OpenTVDebugLogZip:  error opening zip file, ",
        "Wl1(`U",
        "3'393@3G3#4*4<4K4Z4l4s4z4",
        "k#}sy",
        "<&=5=k=~=",
        "kij.(",
        "VhPXG",
        "8u>fz{",
        "D$(VR",
        "7,747@7`7h7t7",
        "sSOFTWARE\\CheckPoint\\Endpoint Security\\TMStatuses",
        "Gax##1",
        "y1~?|\"",
        "#tE4o",
        "8#989J9s9",
        "Exit code: %d",
        "9;H.MO",
        "\"Zt\\c",
        "@G#-L",
        "[&[.[6[>[F[N[V[^[f[n[v[~[",
        "])w^ry",
        "76W66#",
        ";kKb>",
        "SETGE",
        "Gj\"f+",
        "kVaV?",
        "5(6=6P6",
        "8L8\\8h8p8",
        "H4IYp",
        "iI<#U",
        "kp(;g",
        "/:IT1",
        "@GL):",
        "~#[J$__",
        "\"T0#;",
        "-z5 l",
        "Failed to get current service config info.",
        "XCv>M",
        "T[#%J'A",
        "WX8PN",
        "WixInternetShortcut table doesn't exist, so there are no Internet shortcuts to process",
        "8A9[9d9",
        "c/K:.m]",
        "2n%Vwn",
        "sbgp-autonomousSysNum",
        ")050r0",
        "u~^{Y",
        "\"}91QO",
        "\\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9312430 cove}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1190034 ring y}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9312430 our region}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "handlekmsg.exe.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "y8(LZ?",
        ">Srof",
        "3).>5",
        "Dx^S ",
        "!\"lgM",
        "failed to send progress message",
        "> >8>H>X>`>h>|>",
        "F^6h\\",
        "CMtt+",
        "u/jYh",
        "out of memory",
        "# u*Z",
        "05?<3",
        "~\"rKxZ#sO",
        "leOJ ",
        "4>qN0=",
        "Cannot find Check Point VPN InstallProperties",
        "/F}g\"",
        "?oz+/bY",
        "f;t$ ",
        "{Ejhm",
        "e|8_2",
        "Sq=$i",
        "8t/'(",
        "<S^j]",
        "j\\G{aM",
        "e<4naT",
        "\\zonelabs\\avsys\\fssync.dll",
        "d.receiptList",
        "DefPolExtract_rollback common backup restoring failed, error:%i",
        "<!<(<",
        "`MLi|",
        "Kt5J[",
        "`#am=tx",
        "~Pc\"4",
        "2+R+r+",
        "KU`yZ",
        "InstHelper is not running, will not be able to stop services",
        "3 EWW",
        "Mti\\*",
        "4E4u4",
        "T\\ZL7",
        "Issue another request to this URL: '%s'",
        "OCSP_RESPDATA",
        "WBINVD",
        "vlxv7",
        "MessageBoxW",
        "Thread times",
        "$SSUg",
        "\\6\\V\\v\\",
        "^c#!c",
        "Z[tl{=.",
        "unauth_attr",
        "o] Mz",
        "^;>f+4",
        "DnlGi.",
        "|`1Gd",
        "U1~ a",
        "~v]MS|",
        "4w\\GTR.",
        "4HC?D",
        "F1FG+BHG",
        "U*3SK",
        "x]E!w~X}",
        "3(3H3`3",
        "^d!m$/",
        "]Z-#R",
        "id-Gost28147-89-CryptoPro-Oscar-1-0-ParamSet",
        "L+\"UO",
        "KI|6/",
        "\" W)l",
        "n/@uZ",
        "x^D\\']",
        ">+>G>c>",
        "Qtl-l",
        "IDEA(128)",
        "[&+o^",
        "i*!$C",
        "?{q\"R",
        "no srtp profiles",
        "XJ5hj",
        "-,2$I",
        "5&*QhF",
        "jgjgj",
        ":):3:F:j:",
        "\\[Sv$",
        "$*\"Jm}",
        "9kqo>6",
        "VNP%vR-",
        "-CT0#A",
        "VjEh(",
        "@(.gr",
        "y<}XX",
        "sig_alg",
        "qDh`_!",
        "i/T&I",
        "33PzvB",
        "tX?G1):N",
        "e(m#5",
        "->4(\"",
        "P]8.$",
        "^9By!T",
        "sdAREG[",
        ">F02$>",
        "Different CRL scope",
        ".|e*+",
        "jW'pQ",
        "_N>-$",
        "BIO_ctrl",
        "2Z01O",
        "InnerMSI = YES",
        "nL<^W&",
        "?ZZ?b",
        "6$6(6",
        "]UM<0p",
        "ePYDJ",
        "$'[#r",
        "9#9)9.949:9@9E9K9Q9W9\\9b9h9n9s9y9",
        ".\\crypto\\bio\\bss_mem.c",
        "82)5$",
        "~a2h6e",
        "031N1v1",
        "failed to enable SDL.",
        "]yoC.)",
        "Uo$: ",
        "Verify error:",
        "9x*S*^",
        "Found vsutil.dll",
        "GetSidIdentifierAuthority",
        "'$3}>",
        "#n~Z#",
        "pkcs9",
        "w 7WqsL!-S$",
        "+C5#^",
        "J}Is@//",
        "x: C\"",
        "o.o4V",
        "PBE-SHA1-RC2-40",
        ">$?0?A?f?",
        "mi-NZ",
        ".g8b ",
        "[\"!mnr",
        ":$:0:<:H:",
        "&GERI",
        "CAMELLIA128-SHA",
        ":GuP9",
        ";:<y<6=0?y?",
        "}rG)H?&",
        "CQCy-",
        "&NH~)|",
        "[xhVT",
        "#=JJI+i",
        "s?SmG?",
        "p9K;m",
        "T{$'~",
        ",DvI\\Q",
        "SXNET",
        "]$b&dZ",
        "`8\" =",
        "U%\\%I",
        "gn\\@ ",
        "Ga^fq",
        "r{U\"I",
        "fy5qa",
        "Pq]a4",
        "M~)M4",
        "http_proxy",
        "'_QQU",
        "o9~]O",
        "Nx:/s",
        "3#shj",
        "lO;B>",
        "Failed to set verbose logging global atom",
        "HT#U9m3",
        "#1/1J1",
        ">*>@>G>V>c>",
        ";Hp5;",
        "UPGDPW",
        "7\"7>7Y7",
        "/4^.(x",
        ")$6nB",
        "NpN*N>O,':'",
        "TmZP[m",
        "PKCS12_pack_p7data",
        "2/hn!",
        "bad iv chars",
        "e&@*\\",
        "At!ube",
        "~#7=L",
        "%s %s p:%06d %16s:  %s",
        "sdsTt",
        "'kh^(l",
        "'I3#u",
        "JKbN?L",
        "D$,PWVSU",
        "74BzRc",
        "MXR$.,",
        "5)5F5o5v5",
        "SetThreadToken",
        "?Jyyh",
        "CMS_Receipt",
        "L$(Q3",
        "CommonProgramFiles",
        "=LyI*",
        "pm8e#",
        "u'^W<",
        ".?AUIUMSCompletionList@Concurrency@@",
        "dwT[be",
        "\")em2",
        "+(Q,K",
        ";$<2<g<{<",
        "\"rSLG",
        "]2<Kx",
        "~N#5m",
        "7xh6mP4\\",
        "[7><A{",
        ")ag2J",
        "lVEo ",
        "othQ)%",
        "usRWP",
        "^XXg~",
        ">|<X2",
        "id-mod-timestamp-protocol",
        "UI{Y}",
        "292Q2b2",
        "/[]>v",
        "Zgc=w}",
        "'sQ`E",
        "j%B-s",
        "qiC,EyU",
        "hXx(gy",
        "1~Nq6",
        "40iTng",
        "=:[k9b",
        "44@*?",
        "\"3FnF&F*E.",
        "Rr/d`",
        "N)qwu",
        "{gc|OV",
        "VbSHrbA",
        "x/;X3 obQ",
        "/MCk(",
        "6DRZXH",
        "J2h3}#",
        "Hz{*V",
        "jAjsj!",
        "\"py.E",
        "H1~Gw",
        "P;4nm-",
        "presentationAddress",
        "hUqE&<q|",
        "h)=KJ ",
        "(iCY`8.v",
        "N}trYI",
        "+r(HY",
        "b(R\\3,+U",
        "(IjnC",
        "u-PWWS",
        "g-ONb",
        "lis'C)",
        "Tw4FE",
        "Set-Cookie:",
        "{mU9a",
        "3\\>$j",
        "|8]V0s=",
        "vO[2v",
        "%X(n<",
        "lM}lk",
        "Failed to Set Property (of temp file name)",
        "Y,Bf>L82I",
        "8-Beo",
        "XGlG4U{",
        "s.Lx<",
        "y\\kQl",
        "O ,hd",
        "(?m)3vj",
        "wzz]w{",
        "Unexpected installed engine type.",
        "jBjyj",
        "Check Point VPN-1 SecuRemote",
        "!8;57",
        "J85I\"",
        "T1h}|B",
        "%s does not exist in temp directory, continue",
        "(qO@r",
        ".,%uv",
        "ar-DZ",
        "788C8N8S8X8p8",
        "ct_precert_scts",
        "1Y%N8",
        "pzpHo",
        "</:Cbg",
        "MU5VD69",
        ")m6?u_",
        "KXRya]^O",
        "TranslateMessage",
        ")!)#)?)G)])e)i)o)u)",
        "\"'02Hq",
        "dW2a&",
        "J5E4U",
        "<1PL.^j]",
        "GetAdaptersInfo",
        "5SWpb",
        "1`2^hIa",
        "/\"vWA",
        "jN=Ew0",
        "SPjdVQ",
        "9)9}-T",
        "3 3,3L3T3`3",
        "<C32t",
        "8v'Kw",
        "132A3O3",
        "DeviceEventName",
        "tSl,}z",
        "cy#pQ",
        "\\+:TYy",
        "_,[,0n",
        "2D[xMlS6",
        "1mhdF",
        "g_nh!+OF",
        "7\\9f&",
        "%f>tC&",
        ">ck? /",
        "cptrayWUI.exe",
        "Mk:0y{<",
        "(]nEq",
        ">Y^,s8",
        "}Ag9E\\",
        "cRLSign",
        ":@;G;g;",
        "4OEs8",
        "~w1E(",
        "jP_>=M?",
        "q^aN[",
        "We91T",
        "Q%=wW",
        "u$@;F",
        "<1<@<c<o<",
        "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff090006000000000000000000000001000000010000000000000000100000feffffff00000000feffffff0000000000000000ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
        ".?AV?$string_path@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$id_translator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@property_tree@boost@@@property_tree@boost@@",
        "0utb>",
        "N)!v{",
        "+stH2",
        "F0P%&",
        "ge,ygL",
        "vQdp^jS",
        "1?2d2r2-7",
        ">&>?>X>q>",
        "ResetEvent",
        "rNleU%4",
        "%`6)(",
        "GK:2O",
        "%t k+",
        "NNATj=",
        "Y4_f_d",
        "LP.u$",
        "error converting private key",
        "J]V*9",
        "User-Agent: %s",
        "22p@J",
        " 0xaa",
        " 0xcd",
        ">uK/|6",
        "setct-CapReqTBS",
        "sTaEJB^",
        "q7]0D",
        "  ##%%&&))**,,//1122447788;;==>>@@CCEEFFIIJJLLOOQQRRTTWWXX[[]]^^aabbddgghhkkmmnnppssuuvvyyzz||",
        "=f$hZ}F",
        "nRSi_n",
        "ASN1_OCTET_STRING",
        "french-luxembourg",
        "dgw\"B",
        "CCZ[ N",
        "failed to set text to: %ls for element %ls.  Make sure that XPath points to an element.",
        "extension name error",
        "cD6L4As",
        "R.%9R",
        "GPup\"",
        "2,343D3L3T3`3",
        "3{&6P",
        "OnUpgradeAfter:  LoadVsocnfigXML",
        "iGF|3%GQ",
        "BQ<'=",
        "]vB:w",
        "W=KiD2",
        "id-aes128-wrap",
        "7\"\"DU",
        "S8),)",
        "cKJ{~",
        "d|lD$$",
        "[Gz]X",
        "b4<A~(k",
        "F0&4#",
        "2;2O2t2",
        "CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!",
        "m5L.:",
        "qy@\"|",
        "+(wWg",
        "AKocb",
        "m'M2W'",
        ">ak(@",
        "G<GdGbER",
        "$J\"<fF",
        "@\"pZX'c",
        "f\"LL~",
        "ConfigVsdataParams:  ConfigVsdataParams ended.",
        "P.lfF",
        "@PQVSP",
        ".?'={",
        "z42Jyl'",
        "ie!?;1",
        "F1<at",
        "gw[P1",
        "InstHelper is not running, will not be able to stop Watchdog service",
        ")-d;}",
        "\"~|T}u",
        "We are in 64 bit OS. Registering SCV Plugins under wow6432node key in registry",
        "kI)$]dT",
        "ar-YE",
        "*/0<G",
        "8O8g8",
        "InstallPrerequisites finished",
        "i&*s(",
        "323E3v3",
        " PVe?",
        "4*))I",
        ";,D=G",
        "TG4y%",
        "%l#IK",
        "f|7e6",
        "2J:eX ",
        "WDqSm",
        "P%6W&!O",
        "xoGk!",
        "I OT1",
        "Q!Pt7t(DeH",
        "p#ei@",
        ";stNC",
        "qR\\`H",
        "SE(v.",
        "i@:k9",
        "]FZ;TS",
        "7 70787@7H7`7h7t7x7",
        "9[kTrg",
        "Y/cVM",
        "58;ZC",
        "aReOh",
        "8x:q;",
        " QsoX_b",
        "K|=;8",
        "2-2r2",
        "4(444T4\\4h4",
        "v2z2~2",
        "JR[7yQx4",
        "simpleSecurityObject",
        "9+:o:",
        "0D!,?",
        "#l 'E",
        "f$bP+",
        "ARc1D]3;",
        "not initialised",
        "80<0@0D0H0L0P0T0|0",
        "s$p$h",
        "D@h3%",
        "3 313B3O3`3l3}3",
        "nlTjC",
        "5(50585@5D5H5P5d5l5t5|5",
        "U,s/IT_M",
        "/<]2#",
        "vG%FM",
        "RCe>j",
        "[Yf>8",
        "1FKMI",
        "PMAXUW",
        "1U1l1",
        "PU)~`",
        "SOFTWARE\\Sygate Technologies, Inc.\\Sygate Personal Firewall",
        "socket",
        "CANT_READ_COLUMN_NAME",
        "NZZ<r",
        "V^cONH",
        "p@hZ`d",
        "VirtualFree",
        "6!9?9V9?:!;",
        "3O3V3t3",
        " 0x90",
        "{&14E",
        "B.+\"v/",
        "8Ra%-",
        "qDu=m",
        "rLAv$",
        "oA7T#R",
        "zh-chs",
        "0UH[f",
        "h&j<X",
        "Tp<dV'",
        "ARPRQh",
        "?nRBIG",
        "&R697",
        "Xfzp%",
        "Removed value ",
        "4)4/4N4T4^4d4v4|4",
        "Hb2WQ",
        "3VH{\\",
        "'CJ;VF",
        "2(Iv*",
        "yBZ'YT",
        "He4bHsE",
        "api_ms_win_core_file_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "str^uB",
        "jfh3xfamxp19nr78q802hib4400",
        "'>X!Q",
        "Probable in upgrade - continue to check...",
        "pt-pt",
        " v?zly",
        "oc;4Yp",
        "}_kR5]6",
        "Y&.(]@)g",
        "001n1p2[3",
        "qk;\\G",
        "+M-YW",
        "637B3138-6D48-44A0-A415-D2BB31030B64",
        "=|+c<[E",
        "?/?c?v?",
        "\\c*!l",
        "~h]k?",
        "z(/)I",
        "u|Kpva",
        "e;<B+",
        "mF(>m",
        "YaXG2",
        "Ln.C|",
        "^(u.MOv",
        "O8 x ",
        "P]xX:Qd",
        ">z^o*",
        "8.u\";",
        "Dc&:1",
        " PndSvc",
        "ydb3)",
        "jAjdj+",
        "\\f1\\fs20\\insrsid13844772\\charrsid15169477 ",
        "}hQ;Z",
        "re Check Point process}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12926876 es}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607  the RMA.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "qB93f",
        "t-jgh$",
        "|$@Pj",
        "zs&D<",
        ",D1]A$N",
        "Hw^U35s",
        "TMInstallationError",
        "t6VVVVVVVj",
        "ij *M)|",
        ")6&I\\R",
        "F2jgYf;",
        "!>:3~",
        "`1_,`",
        "&Y4zo",
        "P~eL+.",
        ".._y^\\",
        "Beem]=M",
        "'~Vx(",
        "certificate already present",
        "$i_8D",
        "_otYr",
        ".?AVDAConsumer@TelemetryISShared@@",
        "<$<,<4<<<D<L<T<\\<d<t<|<",
        "CreateWindowExA",
        "k2Z<1J",
        "gppx1",
        "t$ UV",
        "ChFy8",
        "CMS_final",
        "1'7$I7",
        "8#828D8N8\\8h8r8",
        "<)<H<e<",
        ";FhtA",
        "]F]te",
        "*n//M",
        "EVP_CipherInit_ex",
        "7mF7Y",
        "wt*cwY",
        "kk=fY",
        "F_!'^",
        "*\"URL",
        "rcA-:f*s",
        "h=64l-#",
        "#<b@_",
        "-JXj.B",
        ";BS%8",
        "9^ u3hI",
        "=3?E?k?",
        "434r5",
        "7i8h9",
        "7%8'9W9",
        "7+7V7",
        "+eCV|P",
        "\"A<Ia",
        "SiIXd=",
        ">;>W>s>",
        "Od{5j>",
        "ynV^IA",
        "s_M@N",
        "~a._+",
        "!dphDa",
        "HJBYL",
        "statusBarOrange.png",
        "WHKG=",
        ">1?n?",
        "3\"3'34393T3",
        "j?w3_",
        "oIg~#",
        "n[qex",
        "XORPS",
        "Q,,$4K",
        "j\"B:YM`",
        ">)>B>[>t>",
        "4F4V4{4",
        "8SruI",
        "invalid asnumber",
        "P`d!ne",
        "0[9;Uh",
        "GTqkP",
        "y,y*E",
        "X400Name",
        "ms*<7",
        "S=MK5",
        "7$7,7<7P7X7`7l7",
        "ZMIf%S",
        "JY4\"?",
        "B%C4F",
        ")579@'",
        "<gik\\6",
        "JQ.xa",
        "@+Mg$",
        "R+*O>vc",
        "CONF part of OpenSSL 1.0.1t  3 May 2016",
        "l{GqU",
        "shaWithRSAEncryption",
        "SetDefaultDllDirectories",
        "EX;E$u7",
        "B7e`2)",
        "OnInstallFinish",
        "YTf|C",
        "hL%BoA",
        "/B(sD",
        ")^\"mE[",
        "cumfeB",
        "\\sbasedon0 \\snext0 \\slink17 \\slocked \\sqformat \\styrsid13065977 heading 3;}{\\s4\\ql \\li0\\ri0\\sb240\\sa60\\keepn\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel3\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\af0\\afs28\\alang1037 \\ltrch\\fcs0 ",
        "!`Ffu",
        ",7,*w",
        "@cD2G",
        "Y_g\"|",
        "_A&=jC",
        ")vh|6o",
        "X&MCR",
        "No VerifyPath specified for delete element of ID: %ls",
        "A`n3x",
        "</=?=F=Q=d=n=",
        "DW:I)",
        " xAb|",
        "tls1_setup_key_block",
        "Qex%&",
        ".8aVvcX7T",
        "'d6$V&F",
        "#+nj2",
        "xf^ftg",
        "setct-OIData",
        "PRIVATE KEY",
        "g&K?P",
        "9$9(989<9L9P9`9d9t9x9",
        "ggg]\\",
        "5 50545D5H5X5\\5t5",
        "sect113r1",
        "PADDSW",
        "gN\"5'o",
        "C<UVP",
        "4'5MI",
        " l@D`",
        "{h^[_]",
        ";,<0<4<8<<<@<D<V<j<",
        "Ymok[",
        "+3bxJ",
        "2Y2G3b4j4",
        "8>\\wi",
        "Wildcard - START of \"%s\"",
        "PREFETCHT0",
        "N+p`bL5Z",
        "PT,OX*x",
        "Failed to pCreateLocalCatalogXml",
        "N)cQL",
        "{B=a2",
        "57GxQ",
        "N^+g(",
        "/rZU>",
        "'QMa|k",
        "111`1f1",
        "2T3<5",
        "[iid(",
        "E~AV!",
        "StopAllServices.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "1!2&2[2}2",
        "jSrOM",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\AntiVirusMonitor\\1.0",
        "7!,!E`",
        "/[q5!",
        ";-<7<`<s<",
        "ntDlp",
        "1\"1>1Z1v1",
        "\":;  [",
        "6F8X8",
        "K(soS",
        "Y.`V}",
        "0$0@0Y0o0x0",
        "YU+p3",
        "ckXoA",
        "K&\\Hj\\",
        "pkcs12 cipherfinal error",
        "-#/z#",
        "@s}y]",
        "IGzGCh",
        "hfaT_",
        "r^8'_",
        "h_}C{",
        "V^@%vs",
        "G:Ai5",
        "=c<O#b",
        "@_%:r",
        "A_$Ta<\"e",
        "'j&EQ",
        "p_2!g",
        "NAOVTS",
        "EVgHh",
        "=N>m>y>",
        "R}zSb:*",
        "tzN16#f",
        "SKINIT",
        "FK1un",
        ".?AVCachedTransmogrifiedPrimary@details@Concurrency@@",
        "mb4$s",
        "]\\om)",
        "&UU*Uuh",
        "G]o|N",
        "`1XLn",
        "zt`ES",
        "hT5Qz",
        "Tr[XR",
        "mqkGP",
        "efAf`x",
        "(SVW3",
        "WSBrv",
        "/IOO^A/\"",
        "6J7k7",
        "ax&T2",
        "I9WCnQ",
        "wv'X=",
        "C4C,(W/",
        "_b_h_j_r_",
        "vX6G^",
        "181f1",
        "t$DUS",
        "{,#|jj~",
        "m^YQJ",
        "x:{g5",
        "hey^%",
        "5!~0 4",
        ")mYw4",
        "%255[^:]:%d",
        "}c(a2g",
        "!,Wpm",
        "o=P.{",
        "'yyx'",
        "_D4<NC",
        "r)as(9n",
        "W)Z&~",
        ",8KxdV",
        "Nf&70",
        "zeLl).9",
        "6%7S7",
        "(L(@'",
        "m89M+^CO",
        "+.r?[u",
        "`>mlw",
        "no explicit policy",
        "=3>q>w>",
        "%Sp,nUK",
        "Z#Rc5",
        "u]l2c",
        "Starter",
        "/\"q)I",
        "AK!:U5",
        "o]Ogq7",
        "OCSP_response_get1_basic",
        "Z0K;Z",
        "C9gp0J@#",
        "1N2a2p2w2",
        "'bAp7;",
        "8H7oU",
        "GnI+H",
        "$;X68T",
        "Q69!H",
        "\":mQ8",
        "DefaultPolicies.exe not found in Binary table.",
        "NOTICE repairing license %s from server merge. expiredate: %d, install date: %d, trial length: %d",
        "7m;'8",
        "zh3tNR",
        "7zQb=2",
        "vkD&}",
        "NS)4q<",
        "8N8S8c8w8",
        "<Source ",
        "t$TQP",
        ")flTH",
        "PKEY_EC_CTRL",
        " 'kSg",
        "n\\K4y",
        "_`G7y",
        "b1uI$q",
        "?i[X\"?RL",
        "$H32%r",
        "Bck.M",
        "hi-in",
        "2!2y3",
        "D`=rO:",
        "zh^zf2;",
        "!\"Gb4 ",
        "NIST/SECG curve over a 571 bit binary field",
        ";V:Jw",
        "Vf(xL-",
        "m3Qk^",
        "030f0",
        "Fp_$!",
        "'y583+",
        "s*w%Y",
        "vQW#S]-",
        "JRCXZ",
        "Q82@2",
        "wj/ky\\,K?",
        "1!;cR",
        ":9Y2|MC",
        "*n6aT",
        "*::QR.",
        "\"U<*R",
        " ,qX@x",
        "Q}n`aC!",
        "+w.hJ",
        "RSPQU",
        "U=+R!&[mv",
        "wFmD}[",
        "2,202@2P2T2X2p2",
        "rL1GC}",
        "uI>Ay",
        "ASN1_BMPSTRING",
        "fcP*gAT ",
        "H)HIHi@",
        "d|gWT",
        "cF'kT",
        ")YEGu/O",
        "id-smime-ct-DVCSResponseData",
        "3^3l3",
        "H8\\ 1",
        "=8=Bf",
        "e~L2w",
        "IGJGKGLGMG",
        "0123456789ABCDEFabcdef",
        "1=2r3Q4o7!:",
        "!(\\g=",
        "4drL`",
        "uVUR7",
        "z&0$(",
        "5t}a}",
        "R4k:K",
        " 9dt#",
        "GTi6K",
        "f3Q4c",
        "5<5H5h5t5|5",
        "1.151S1Z1e1",
        "rqf;M",
        "des-cfb1",
        "jT|v\"AKq",
        "TO]UU",
        "IUYfX!)",
        "5=*hG",
        "5,646G6",
        "Server denied you to change to the given directory",
        "CLIENT_MASTER_KEY",
        "U/lY~",
        "<'<j<",
        "LSa;Y",
        "vHNo}",
        "{y.'g<",
        ".\\crypto\\x509v3\\v3_extku.c",
        "G{WpU",
        "#ccM1",
        "NpT20",
        "3!%F,",
        "dbghelp.cat",
        "6F6M6Y6c6",
        "Tp'J6",
        "=8/ Ke*",
        "A=yFh",
        "@vNg\\S",
        "jAjrj#",
        "eueN2",
        "qHst^}",
        "TS_RESP_CTX_set_status_info",
        "MRhTp",
        "Remove cptray2.0 auto startup registry value",
        "=e~A?",
        "+D$<+",
        "?r!p_",
        "uhjz'",
        "CT Precertificate SCTs",
        "QPh8W\"",
        "UX+#FI",
        "bAA6$#]",
        "?IHz:",
        "MOVSS",
        "$<Ntx",
        "eG)#}",
        ">^BRo",
        "(*<]k",
        "H%`4bd",
        "B{@&&",
        "zkYddg",
        "6\"6,686B6F6P6\\6h6t6",
        "szPriorTag",
        ".n-\"7",
        "XH|4o",
        "9~,~k",
        "0Y1s122",
        "\"NdZQ",
        "*L.>&a",
        "x{w!U?7",
        "Ge1l;}#",
        "9$999K9a9}9",
        " failed to set SrLMHOSTSRevert value (%d)",
        "O.\\}'A",
        "GKCt{",
        "K{/0]",
        "Failed to recurse path: %S",
        "=V>h>",
        "\\c6]Of",
        "> be3",
        "DR[O[",
        "f}=5hVOX",
        "Z?,t;oS",
        "aN*M<F",
        "]85~.0",
        "h{+F^",
        "_q7ol ",
        "5-6U6}6",
        "C4c435S5",
        "*p* T",
        "XFfPg",
        "Can't get user sid",
        "Basic",
        "9 90949D9H9L9P9T9X9\\9d9|9",
        "7iOyc",
        "?]\\GuQ",
        "jijwj",
        "&9Vwv",
        "CMOVNZ",
        "7E8K8#:]:",
        "+PjUW",
        "- @w-",
        "p:K9!",
        " 8'!2",
        "7N7o7",
        "<ph=g8",
        "jsj~j ",
        "MLW<#~!Im",
        "5(6$7",
        "Gn&xi",
        "NQhk7",
        "lDRjH]",
        "+f`e(",
        "[VSDATA] releasing DataClientLock.",
        "a5!eZ",
        "%nLQ#j",
        "D$@PhTA%",
        "W%N$@s",
        "FWFreshAfter finished.",
        "=L9o<",
        "t,_^[",
        "Found EPS InstallProperties",
        "\\bin\\DeviceAgentAPI.dll",
        "PScLG",
        "Ph`q&",
        "Failed to get formatted string: '%ls'",
        "DL_LOAD",
        "/jVPZ",
        "protocol error",
        "Loading custom registry settings",
        "?(?Q?X?x?",
        "\\@RLq",
        "r,HXp",
        "+\\BB@",
        "$~\"-\"",
        "2<aaqq",
        "i_NqScr",
        "^xL{z>&",
        "vPmqT",
        "i2tQLQ",
        ":0:8:@:d:t:",
        "me!|[",
        ":TO2K",
        "[LOGMON_PROXY] LogMon stopped in process=%0x",
        "WM#id",
        "5lo\"U",
        "~[~6Nx",
        "jsw/%DN",
        "6727M",
        "8-']>?",
        "L$ SQP",
        "^}rG{",
        "G#z78",
        "%8^kb&",
        "a(!)Q",
        "EEuMe",
        ":lofU",
        "OBdwY",
        "xxk}n",
        "?,!%>&1",
        ";aU\"W",
        ":00a9",
        "}FD_eJ",
        "`(,@1;",
        "nY_o|{V",
        "(*No}W)^",
        "no matching signature",
        "<$<8<H<P<X<",
        "1RAcz",
        "+hA>w",
        "'1)*Z+",
        "`3.\"6",
        "K9HQ'b",
        "%;f@kQ",
        "J^O`y",
        "w,af~",
        "ssl_prepare_serverhello_tlsext",
        "$HkeM",
        "2#2v2",
        "QrkMnW.",
        "Yx8,)",
        "id-Gost28147-89-None-KeyMeshing",
        "SOFTWARE\\Classes\\Installer\\Products\\117CD7D3CB2C542438D083C010944001",
        "u$\\IJ",
        "  <UpdatePackage",
        "O[M(&*",
        "yQ;il",
        "6&O)N",
        "3.MI\"",
        "H0BB ",
        "LFEDW>",
        "X509_CRL_print_fp",
        "<nQ6|",
        "sG+y<",
        "/*% j1",
        "failed to get firewall profile",
        "9@9D9H9L9P9T9X9p9t9x9",
        "iw#}4Ay",
        "!Kdqwc",
        "N(@9^<",
        "TracConnected.wav",
        "+V\"%7pS",
        "fS+;w",
        "Ns@6l<",
        "t\"@@o",
        "If@B!",
        "NFGY[",
        "2Q=!E,'",
        "XJ9F2F2",
        "ssl_parse_clienthello_renegotiate_ext",
        "3}k@\\",
        "9 9(9,989@9D9P9X9\\9h9p9t9",
        "tZr/dm;",
        "%.'?6",
        "8277086f6fd3ba109126dd88d0add40384e4350d363f2451eced0dae2c082e8761be9969bb979dc9136332de3168aa1a083ae995719ac16db8ec8e4052164e89",
        "Q0D0T",
        "*/JIh",
        "RZ#h(:",
        "mrm$I",
        "<vH$^-w",
        "oF|2P",
        "&>NLn",
        "x.g6RU",
        ":&[S ",
        "\\'02\\'06.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-360\\li5040\\lin5040 }{\\listlevel\\levelnfc4\\levelnfcn4\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698713",
        "*<~lP",
        "/tK6_",
        "Z%pzx{",
        ")RH:ty",
        "8io*f",
        "MnMr$wr",
        "Bws&Y",
        "J21FE",
        "u82I-s",
        "t|0$V@",
        "KS^V8",
        "rM,t$/8^",
        "gGQ<y",
        ")G8yiw&",
        "old session cipher not returned",
        "^J'`+",
        "M1Tzb",
        "vR8.F",
        "V(VDVVV",
        "M0v!&#",
        "?76H8",
        "b:r;9",
        "8 8$8(8,8084888<8@8D8H8L8P8T8X8\\8",
        "ProductExe",
        "<</4v",
        "NNU(8",
        "eC:GR",
        "CMS_EnvelopedData_create",
        "ENGINE_UNLOCKED_FINISH",
        "CreateWellKnownSid failed, err=%lu",
        "<LCE4",
        "2'7_ud",
        "/HpKe",
        "PIWjT",
        "a/:rp#f5P",
        "pR[n|",
        "Lfxpx",
        "x~.-^",
        "P,d-*",
        "4&656",
        "O\"\"RH",
        "UpAl3",
        "Qbp@f",
        "Me\"(}",
        "<b8VJ",
        ",$D$T6",
        "@;kK1",
        "uN7B#$",
        "id-DHBasedMac",
        "[EXCEPTION SUPPORT] FindOldestFile: FindNextFile: Error %d",
        "Th*kNd",
        "bXJ'pT",
        "1zJ8.",
        "7(.9iy",
        "m_9b7LB_",
        "3;v]0",
        "Gz)}b",
        "NEW_ENV",
        "PatchOldFdeMsi",
        "=_FqZAD",
        "y)#-d",
        "hashAlgorithm",
        "St~i8k",
        "PreInstallCheck:  Will not check for Kaspersky Antivirus.",
        "`}^X0",
        "kRRtj!",
        "sk}G-",
        "\"lzzm",
        "WIN32_GLOBALLOOKUP_FUNC",
        "K2|.]",
        "%Jsp{",
        "X%nN{NrC",
        "lvC5m",
        "%>5}+@W3",
        "ECDH-ECDSA-AES128-SHA",
        " mP7h",
        "&H#Shz",
        "o]lTE",
        "DSjrv w",
        "hp-v;V",
        "wV)R,V,56",
        "signing ctrl failure",
        "G1SDA",
        "#yjFN",
        "SECG/WTLS curve over a 112 bit prime field",
        "n<Lc>",
        "S/MIME email",
        "Proc-Type: 4,",
        "%u2dj",
        "nl-BE",
        "TI3k-q)",
        "Trying to open ",
        "EnterCriticalSection",
        "t{gkzea",
        "R[)!Q",
        ")()I'",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477  service, it is required that you deliver }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14159930 the}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 ",
        "'Xo@Qv",
        "=5,p5",
        "s?ZRG$",
        "_DA7E",
        "6V<^|",
        "RegOpenKeyExA",
        ".?Kb,G]R",
        "*I~/i",
        "cJx\\ }",
        "O.Z8M",
        "=8>]>",
        "GdI]E",
        ".?AVSEException@libutil@@",
        "-\"4>b",
        "XMJ+u",
        "]E:%=R",
        "&7}j`+",
        "`]$E5",
        "K:ZrH",
        "hfj2^2}: ",
        "AES256-SHA",
        "StopTEService",
        "s.Ui:",
        "'xN t",
        ";:'zMu",
        "=#=*=<=L=[=k=~=",
        "Cisco VPN is installed on the system. Attempt to use the existing vsdata.dll",
        "^:3B[)",
        "IsJXL",
        "({RM{",
        "eLNtg",
        "cR;\\lV",
        "=6>^>",
        "f)g~e",
        "e@)Jp",
        "<Fs\\k",
        "=sX.n",
        ",][XM",
        "KB#Pm",
        "OqN_x",
        "~-SBW",
        "DTr~1",
        "PulseEvent",
        "hK,b#1",
        "05.x#",
        "<0<F<c<",
        "id-GostR3410-94-CryptoPro-XchA-ParamSet",
        "*9]tgN",
        "fT)ly^!",
        "Found FDE installer",
        "ATL$__a",
        ":HJ,r",
        "sQ)X%$u",
        " ^Qfo[",
        "bq5J\\VM",
        "N_\"l1h",
        "cmd /c \"del /F /Q \"%s\\System32\\CPEPC_PLAP_user64.dll\"\"",
        "6T7~7",
        "HuBhs",
        "d:a$waG",
        "U04tc,{",
        "? ?$?4?8?<?@?D?L?d?t?x?",
        "z/Y3a",
        "RfKL+",
        "{Rx!-",
        "wtx7!@",
        "Failed to open registry key ",
        "unhandled critical CRL extension",
        ".\\crypto\\evp\\bio_enc.c",
        "ASN1_TEMPLATE_NEW",
        "t)Ln&",
        "3!3/3E3L3\\3j3",
        "5 5n5",
        "\\0`0d0h0l0p0t0x0|0",
        "m,/7k",
        "BLZwP",
        "</plugins>",
        "]LZLt",
        "p15c&",
        "#g######)'",
        "Content-Type: application/x-www-form-urlencoded",
        "[MSIInstallProductShouldProtect] Bad Input:  %s is not a client type",
        "yKLQF",
        "c744|~",
        "e0}]r",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid923653\\charrsid15169477 {\\*\\datafield ",
        "6RRJT7",
        ">??R?",
        "i>ve}",
        "E\"r7?",
        "`,X~@L;",
        "={hC/",
        "j'IwIr",
        "{=.~-",
        "G>Z:3S",
        "-$Jv]",
        "+(=Pz",
        "?#?,?C?o?",
        "6gCp=",
        "\"![0x?b",
        "8_g.`",
        " 4\"Zh",
        "QvO(G",
        "{'#'r)",
        "9191:",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 If you are a customer who has purchased the support plan with Check Point covering}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        "-P$6+L",
        "QCFM%n8",
        "jaZf;",
        "Ey[g3",
        "66<kGW",
        "B[-s/",
        "t}.!g",
        "6lV6F",
        "0v ]h",
        "\"jB</",
        ",\"bGg<",
        "jCjvj%",
        "void __thiscall boost::property_tree::json_parser::detail::source<struct boost::property_tree::json_parser::detail::encoding<char>,class std::istreambuf_iterator<char,struct std::char_traits<char> >,class std::istreambuf_iterator<char,struct std::char_traits<char> > >::parse_error(const char *)",
        "z&o/pV",
        "2\"2(2.242:2@2",
        "- not enough space for stdio initialization",
        "ripemd160WithRSA",
        "1z4P5b5t5",
        "5&i{-,p",
        "]yyk~",
        "01^\\D",
        "+?PHR",
        ">-o|-",
        "93]]).m",
        "0\"0L0r0",
        "#J_F! ",
        "OLvT#",
        "Ou}zf",
        "setCext-certType",
        "|0uJ ",
        ";(;A;Z;s;",
        "c663e2abb2b34b23da76f6352ba57ca2881844c1111ab189d8c7e07e1daaa04f40255c77988aa05fe06e4e5bdb4cb9c5394bbaf28d98c1d971ccd20867e556a7",
        "S_#![48Deq",
        "\\RD9*",
        "K6T}S}T@",
        "ls_DtD",
        "|RLU)FM",
        "Qg:w$,",
        "fD[|$E.",
        "0Z#)5",
        "|}uzu",
        "^/3CLe",
        "Z[C3~Ha",
        "182U2f2",
        "v2-$.",
        "6?HmWZ3",
        "7]v*\\T",
        "Content-Type: text/parameters",
        "dh-std-kdf",
        ">!>H>r>v>z>",
        "2*jRR#",
        "`6t76Y",
        "=,OWN",
        "@y3{gDeF",
        "3!v->",
        "*hN#%",
        "5K{Iv7L",
        "<+<1<A<O<V<",
        "$<!'2S",
        "v8=K\"X",
        "G<8NG",
        "X*2Gg",
        "P=XW<6Zn",
        "qNBTB(",
        "ssl3_send_server_certificate",
        "6!6)6+767@7F7Z7f7",
        "j~:80",
        "OQ* c",
        "G^MY%lX",
        "\\f1\\fs20\\insrsid9651500 covered }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 under warranty fails to operate within }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid13256927 thirty (30) days}{",
        ";%;g;",
        ":T:^:x:",
        "ln&gxuo",
        "OdNWP\\",
        "{w`'hQk",
        "@Z9>3vw",
        "RmJoinSession",
        "3;me5",
        "8)9/9<9U9e9",
        "3D$83L$4",
        ":8;>;D;J;P;V;\\;b;h;n;t;z;",
        "HeapReAlloc",
        "0Pjx7'",
        "7Go(Qz+",
        "223e3",
        "Fe$+^f",
        "sgGnz",
        "? ?(?0?",
        "[Le50",
        "$5YdI",
        "Rgdg&",
        "failed to allocate string",
        "0 0N0y0",
        "eN(l7 ",
        "hNF3K2c",
        "5G5t5",
        "n?EB^]",
        "/}EO!",
        "MOVNTDQA",
        "hh9E{J",
        "Oe^Yz",
        "E~9Ea",
        "FhlN^{n",
        "1!121Z1",
        ")QZPe^`",
        "OLD-ENVIRON",
        "\"%svna_utils.exe\" -d -ap vna drv load",
        "o6Ac|",
        "Failed to read from handle.",
        "3,;|t",
        "k,uI'",
        "Ym0uiu",
        "P%?d\"7",
        "5-6T6",
        "oy.(u\"",
        "7o'KN",
        "Y/&LO",
        "Failed OpenProcessToken",
        "Be+.iQ",
        "9F'yN%",
        "A;!++",
        "{Sl\"v",
        "NyxAf+ae",
        "%*sIssuer: ",
        "0x0gc",
        "sGlJ~",
        ")`xNM[h",
        "^r0+fN",
        "sQ;v\"w0",
        "N'TKh",
        "_y*q-",
        "value",
        "2F3X3u3",
        "u~-\"HMq",
        ">4SJUr[",
        "{E5K7",
        "bsVsa",
        ".\\crypto\\evp\\digest.c",
        ":);|;D<",
        "3\"4.444U4",
        "VGnja",
        "{3\\*,",
        "RESETCHOICE",
        "Mn0Cb",
        "2fm?'I.-",
        "^joNjll?",
        "G,z 5",
        "6b}zcg",
        "606L6h6",
        "hkbswm7s17g1st9gv8cn2x1f040",
        "@vBYH",
        "r#'7nD",
        "RCPPS",
        "2R3f3u3",
        "cASUy:[",
        "#+A~)",
        "Cannot create CheckPoint folder",
        "[UNHANDLED EXCEPTION] Before Last chance callback %x",
        ";*1C_",
        ",F8yc.],n",
        "VjVChX=%",
        "L4}kE",
        "7'7W8n8",
        "^2k_x{",
        "8zm1}q",
        " 'sqE",
        "_1GA;",
        "235XI",
        "ZwQueryVirtualMemory",
        "0-050a0h0p0",
        "656S6^6r6",
        "^S(W#",
        "qpw/g'",
        "cB  V",
        "0\\avc3_sig\\avcuf32.dll",
        "s8|j&",
        "t z]h",
        "n{v^*",
        "DIST_POINT",
        "CLX%B",
        "x1^Xl",
        "n)lAh",
        "S]LfHu",
        "\\VvJ+ZCJ",
        "SWPWU",
        "{8}H=",
        "Z+\"FI",
        "?]d\\M{%",
        ":)[89",
        "63{,v",
        "eyA-3y",
        ": :$:4:8:@:X:h:l:|:",
        "6y~6sL",
        "fF#b8S?",
        "boost::filesystem::create_directories",
        "RSA_BUILTIN_KEYGEN",
        "InstHelper exited with code %lu",
        "+0[F43z",
        "+jaQOM5",
        "%s has been successfully streamed out to %s.",
        "MonitorLogoffvsmon",
        "~E\\iw#F",
        "%iIYv%",
        "\\J=R30p",
        ">]K4Qb",
        "w|(6_",
        "Y]mU6",
        "$mx<Yz",
        "W{PVU",
        "&26_1",
        "&.h*ygB",
        "@rvI#",
        "pQp(/$",
        "ProcessPemFile this is not a repair",
        "t({VR",
        "aT;ns",
        "vnHkt",
        "scBEb",
        "[]+U8",
        "1&1C1K1t1{1",
        "Om~h#n",
        "uxdGF",
        "gh$o\"/",
        "wait for InstHelper.exe failed",
        "hb^o\\",
        ".!mgb",
        "z]UHYT",
        "Wd/$+",
        "&}q\"x",
        "\\8X/B",
        "a5iVP",
        "O3DH1",
        "zx~yy",
        "[kI6&",
        "*:B%-",
        "pskDt",
        "?Y5`6",
        "zKH,oB",
        "~cL)t^Y1",
        "8[.L4",
        "!a\"u=",
        "$$@mr",
        "8R0<MM`",
        "^Fmj,",
        "[U`S>a",
        "8D8g8",
        "%,_yI'",
        ".2E\"z#",
        "A(}}0",
        "{n7PM",
        "eqAE`R",
        "UI.0R",
        "0000000000000000000000000000000000000000000000000105000000000000}}SetupProgress{&WixUI_Font_Normal_Bold}Installing [ProductName]The program features you selected are being installed.DlgTextPlease wait while [ProductName] is being installed. This may take several minutes.SetupIconLbStatusStatus:ActionProgressProgressBarProgress doneMaintenanceDlgRadioGroup_IsMaintenance{&WixUI_Font_Normal_Bold}Program MaintenanceRepair or remove the program.Repair installation errors in the program. This option fixes missing or corrupt files, shortcuts, and registry entries.Ico1Ico2ReadyToRemoveRemoveNowYou have chosen to remove the program from your system.{&WixUI_Font_Normal_Bold}Remove the ProgramClick Remove to remove [ProductName] from your computer. After removal, this program will no longer be available for use.DlgText2DlgText1If you want to review or change any settings, click Back.RemoveDlg{&WixUI_Font_Normal_Bold}Uninstalling [ProductName]The program features you selected are being uninstalled.Please wait while [ProductName] is being uninstalled. This may take several minutes.Finish{&WixUI_Font_Bigger_Bold}Installation Wizard Completed[ProductName] is successfully installed on your computer. Click Finish to exit the wizard.TextLine3[ProductName] is successfully uninstalled from your computer. Click Finish to exit the wizard.CancelSetupNoYesAre you sure you want to cancel [ProductName] installation?To install/uninstall this program at a later time, please run the installation again.TextLine4The wizard was interrupted before [ProductName] could be completely installed.TextLine5The wizard was interrupted before [ProductName] could be completely uninstalled.Click Finish to exit the wizard.SetupErrorErrorText<error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here><error text goes here>AAbortCIIgnoreOOKRRetryWarningIconErrorIconYour system has not been modified. To install/uninstall this program at a later time, please run the installation again.FilesInUseExitListFileInUseProcessSome files that need to be updated are currently in use.{&WixUI_Font_Bigger_Bold}Files in UseThe following applications are using files that need to be updated by this setup. Close these applications and click Retry to continue.DisableAgreeToLicense <> \"Yes\"EnableAgreeToLicense = \"Yes\"ShowNOT REMOVEREMOVEDefaultNOT UpdateStartedNOT REMOVE=\"ALL\"REMOVE=\"ALL\"[SHOW_CLIENT_SUBTYPE_DLG]1(CLIENT_SUB_TYPE  <> \"ENDPOINT_SECURITY\" And  CLIENT_SUB_TYPE  <> \"SECURE_REMOTE\" And CLIENT_SUB_TYPE <> \"SECURE_MOBILE\" And ISACTIONPROP1=\"\") Or SHOW_CLIENT_SUBTYPE_DLG = 10(CLIENT_SUB_TYPE  = \"ENDPOINT_SECURITY\" Or  CLIENT_SUB_TYPE  = \"SECURE_REMOTE\" Or CLIENT_SUB_TYPE = \"SECURE_MOBILE\" Or ISACTIONPROP1<>\"\") And SHOW_CLIENT_SUBTYPE_DLG = 0NewDialog[LicenseAgreement]SpawnDialog[IsUninstaller]_IsMaintenance = \"Remove\"_IsMaintenance <> \"Remove\"_ClientSubType = \"Check Point Endpoint Security VPN\" Or  _ClientSubType = \"Check Point SecuRemote\" Or _ClientSubType = \"Check Point Mobile\"[CLIENT_SUB_TYPE]ENDPOINT_SECURITY_ClientSubType = \"Check Point Endpoint Security VPN\"SECURE_MOBILE_ClientSubType = \"Check Point Mobile\"SECURE_REMOTE_ClientSubType = \"Check Point SecuRemote\"[ProductName][_ClientSubType]SHOW_CLIENT_SUBTYPE_DLG = 1SHOW_CLIENT_SUBTYPE_DLG = 0ReinstallModeamus_IsMaintenance = \"Reinstall\"ReinstallALL[REMOVE][FW_INSTALL]YES_IsMaintenance = \"Reinstall\" AND CLIENT_SUB_TYPE = \"Check Point Endpoint Security VPN\"[REPAIR]EndDialogReturnErrorYesErrorNoErrorAbortErrorCancelErrorIgnoreErrorOkErrorRetryInitClientSubTypeInitializeClientSubTypeInstallationStartedSetDefaultClientTypeCLIENT_SUB_TYPESetFWInstallFW_INSTALLUnloadGUILoadGUISuppressRebootREBOOTSuppressVerifyInstallDirLengthOnSuccessOnErrorOnCancelBlockDowngrade27001BlockATMUpgrade27002SchedFirewallExceptionsInstallSchedFirewallExceptionsUninstallExecFirewallExceptions[ProductName] Installation Wizard[ProductName] Uninstallation Wizard[ProductName] Installer InformationCompanyMenuFolderProgramMenuFolderndfwqpew|Check PointTARGETDIR.lf-brxoy|EndpointSecurity0vkzdd9g|SecuRemoteCompanyFolderuxkfcmlv|Endpoint ConnectProgramFilesFoldernshllvar|CheckPointWindowsFolderTelemetryDirCompanyDirusjd06do|Endpoint SecurityCommonAppDataFoldereko5hy2g|CheckPointSourceDirNewer version of this software is already installed, installation will exitInstallation of non ATM package over an ATM client is not supported, installation will exitCannot connect to Windows Firewall.  ([2]   [3]   [4]   [5])ProgressMoveFilesRemoveFilesRemoveRegistryValuesWriteIniValuesWriteRegistryValuesUnmoveFilesAdminInstallFinalizeSetProgressEP_DriversEndpoint DriversVPNWatchdogVPN Client WatchdogRedistributablesProductFeatureCheckPointVPNabout.pngConnLogo.pngCP_Left.pngywr_klii.png|endpointBanner.pngzxqohwqf.png|endpointBannerBig.png-2nw-7ci.chm|VPNClient.chmva7eosra.png|endpointBanner.pngdkie_8rd.png|endpointBannerBig.png9h6xii0p.chm|VPNClient.chmxvubgc1_.png|endpointBanner.pngxymtkn51.png|endpointBannerBig.pngc_yqkbyf.chm|VPNClient.chmmjkijyhf.gif|update_site.gifjz2p3l8v.wav|TracSiteUpdateSuccess.wavqpm13yip.png|certificate.png8aysvlh9.png|connected.png9eti89z-.gif|connecting.gifg4elj6dx.png|cp_middle.pngkuwexoew.png|disconnected.pngcdzen1_i.gif|encryption.gifumechnop.png|endpointConnected.pngwnw1qlge.png|endpointDisconnected.png4ow33ham.bmp|EnterpriseChecks-Disabled.bmpirdujmox.bmp|EnterpriseChecks-Error.bmptfkp_kws.bmp|EnterpriseChecks-OK.bmpzvetself.bmp|EnterpriseChecks-Warning.bmptwetxezw.png|error_connection.pngkxewjjt1.png|error_connection_hc.png0lohjc-p.png|erroricon.png2qe_fapg.png|ModuleBar.pngli3oqgvq.png|ModuleBarHighlighted.pnge43yavwn.png|Modules-Compliance.png3oilixxp.png|Modules-FW.pngwt0c-jok.png|Modules-VPN.png75fguljh.gif|progress_hc.gifvzpezl68.png|reauthentication.png_lgfizrj.png|SCUIAPIConnLogo.pngau3ogxoa.png|SCUIAPIEndpointBanner.png6stu01zr.png|SCUIAPIEndpointBannerBig.pngtgak3ke9.png|securityAlertIcon.pngr3uiqkgn.png|securityInfoIcon.png0kzlpajn.png|sidebarBackground.png-cqiykae.png|sidebarButton.png4-b4rgix.png|sidebarButtonPressed.pngqcbwcynp.png|sidebarLinkBackground.png3wpkh-eg.png|State-Error.pngbjfbvkjm.png|State-InProgress.pngej1k7jiy.png|State-NotRunning.pngState-OK.pnghtkqqm7a.png|State-Warning.pngou2ymzuv.png|statusBarGreen.pngw5ceml8f.png|statusBarOrange.pngu9t9r0vn.png|statusBarRed.pngfcvknpbe.wav|TracConnected.wavfzinx6nk.wav|TracFailed.wavxqsmthcl.bat|AdminMode.batst-a9f5j.exe|cpmsi_tool.exe98.6.1046.4103382.3.0.1698.61.4.6028.60.6.1026t1cjerkg.dll|cptmsender.dllvb-81gch.dll|epcginashim.dll98.6.1046.1xva-i5kr.dll|epcginashim.dllopzbpuuf.dll|CPEPC_PLAP.dllwpwnf3fx.dll|CPEPC_PLAP.dllicon.icoNOT UPGRADINGPRODUCTCODE AND NOT TELEMETRY_DISABLED=\"1\"FindRelatedProductsValidateProductIDProcessComponentsUnpublishFeaturesRemoveShortcutsRemoveFoldersCreateFoldersRegisterUserRegisterProductISDOWNGRADE<>\"\" AND NOT UPGRADINGPRODUCTCODEIS_ATM<>\"\" AND IS_ATM<>PACKAGE_TYPE AND NOT UPGRADINGPRODUCTCODECLIENT_SUB_TYPE=\"ENDPOINT_SECURITY\" AND NOT UPGRADINGPRODUCTCODECLIENT_SUB_TYPE=\"UNDEFINED\" AND NOT UPGRADINGPRODUCTCODEResolveSourceNOT InstalledNOT UPGRADINGPRODUCTCODEVersionNT >= 600 OR (VersionNT >= 501 AND ((MsiNTProductType = 1 AND ServicePackLevel >= 2) OR (MsiNTProductType > 1 AND ServicePackLevel >= 1)))RemoveExistingProductsFW_INSTALL_REBOOT<>\"YES\" AND VNA_INSTALL<>\"UPGRADE\" AND NOT UPGRADINGPRODUCTCODEScheduleReboot(FW_INSTALL_REBOOT=\"YES\" OR VNA_INSTALL=\"UPGRADE\") AND NOT UPGRADINGPRODUCTCODENOT REMOVE=\"ALL\" AND FW_INSTALL_REBOOT=\"NO\" AND VNA_INSTALL<>\"UPGRADE\"NOT SkipFinalDialogMigrateFeatureStatesInstalled=\"\"REMOVE=\"ALL\" AND NOT UPGRADINGPRODUCTCODE(Installed<>\"\") AND (REMOVE<>\"ALL\")#EP_Trac_VPN.cabARPPRODUCTICONMsiLoggingvoicewarmupUNDEFINED#1Check Point Endpoint Security VPNSHOW_CLIENT_SUBTYPE_DLGNODISABLEADVTSHORTCUTSPACKAGE_TYPE#0TELEMETRY_DISABLEDErrorDialogDefaultUIFontWixUI_Font_NormalManufacturerCheck Point Software Technologies Ltd.ProductCode{938B6804-77BB-4B53-972A-2EE180F45250}ProductLanguageProductNameCheck Point VPNProductVersion98.61.4605{9DFE58C2-323A-4ABC-8D92-53A34F0B6575}SecureCustomPropertiesCLIENT_SUB_TYPE;EPS_INSTALLED;FW_INSTALL;ISACTIONPROP1;ISDOWNGRADE;PACKAGE_TYPE;REMOVE_SUB_TYPES;TELEMETRY_DISABLED{&WixUI_Font_Normal_Bold}&Keep all settings.{&WixUI_Font_Normal_Bold}&Delete settings for current user.#2{&WixUI_Font_Normal_Bold}&Delete settings for all users.{&WixUI_Font_Normal_Bold}&Endpoint Security VPNCheck Point Mobile{&WixUI_Font_Normal_Bold}&Check Point MobileCheck Point SecuRemote{&WixUI_Font_Normal_Bold}&SecuRemoteI do not accept the terms in the license agreementI accept the terms in the license agreement{&WixUI_Font_Normal_Bold}&Repair{&WixUI_Font_Normal_Bold}&RemoveSoftware\\Checkpoint\\TRACdisable_telemetry#[TELEMETRY_DISABLED]SystemInfoSoftware\\CheckPoint\\Endpoint SecurityTelemetrySoftware\\Microsoft\\Windows\\CurrentVersion\\Run\"[INSTALLDIR]TrGUI.exe\"Software\\CheckPoint\\TRACisATMcpvpnURL Protocolcpvpn\\shellopencpvpn\\shell\\open\\command\"[INSTALLDIR]TrGUI.exe\" CreateSiteFromLink %1Software\\CheckPoint\\TRAC\\5.0PRODDIRldanzleg.png|versionFrame.pngcp_menuFolderRemovalTrGui_shortcutqy9qbdos|Check Point Endpoint Security VPNArialWixUI_Font_Normal_BoldWixUI_Font_BiggerWixUI_Font_Bigger_BoldISACTIONPROP1ISDOWNGRADE{B78B87C8-E88F-4E89-86D9-F6C4ED0B6737}0.0.1EPS_INSTALLEDCheck Point Endpoint Security VPN GUI*[#TrGUI.exe]ModuleSignatureModuleID9.86.10.4605EndpointSecurityVPN.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5VPN_ProxyServer.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5edwdprua|VPN_ProxyServerProgramFilesFolder.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5CompanyFolder.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5[ProgramFilesFolder]CheckIfSha2KbIsInstalled.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5OnBegin.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5StopTracService.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5VersionNTStopServicesVNA_INSTALL=\"UPGRADE\" AND NOT UPGRADINGPRODUCTCODEVnaUpgrade.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5(REMOVE=\"ALL\" AND NOT UPGRADINGPRODUCTCODE) OR REINSTALLVnaUninstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5DeleteServicesSDLUninstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ComponentsBackup.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5SSOClean.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5clean.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5DeleteConfigs.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5NOT REMOVE=\"ALL\" AND VNA_INSTALL<>\"NO\" AND NOT UPGRADINGPRODUCTCODEVnaInstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ComponentsInstall.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5InstallServicesNOT REMOVE~=\"ALL\" AND VersionNT > 400SchedServiceConfigStartServicesStartTracService.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5CopyLastMSILogFile.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5pgcgrbjb.htm|index.htmlindex.html.2C0EAE67_7A1D_43BF_B3D9_476098DF60F598.6.1002.4evd4vzv_.exe|VPN_ProxyServer.exeVPN_ProxyServer.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F598.6.1045.2lm6kpqvs.dll|AntivirusMonitor.dllAntivirusMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5mun7ehdn.dll|BrowserMonitor.dllBrowserMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5oomuhb5l.ini|BrowserScv.iniBrowserScv.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F598.6.1045.1568blzzr.dll|CertEnrollProxy.dllCertEnrollProxy.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5CLI_help.txtCLI_help.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5collect.batcollect.bat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F592.8.370.4cpbcrypt.dllcpbcrypt.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5unsly0st.dll|cpopenssl.dllcpopenssl.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5cpprng.dllcpprng.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F592.8.370.3alznnasw.dll|DataStruct.dllDataStruct.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5dtplat.dlldtplat.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5EPC.iniEPC.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5epcgina.dllepcgina.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5epcgina64.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5itm2jtrn.dll|FileHash_DYN.dllFileHash_DYN.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5bepgo6qg.dll|groupmonitor.dllgroupmonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F51p1rivj-.dll|HotFixMonitor.dllHotFixMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ro5iqoe3.dll|HWMonitor.dllHWMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5jk8okbga.xml|LangPack1.xmlLangPack1.xml.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ccardj0o.dll|LogonISReg.dllLogonISReg.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5vnaap.catvnaap.cat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5vnaap64.cat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5vnaap.infvnaap.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5vnaap64.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F598.61.4.112vnaap.sysvnaap.sys.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5vnaap64.sys.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5jnzszpmh.bmp|new_extender.bmpnew_extender.bmp.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5openmail.exeopenmail.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5OS.dllOS.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5nroi3sd4.dll|OSMonitor.dllOSMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5OsScv.iniOsScv.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5qc3l8awh.dll|ProcessMonitor.dllProcessMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F58frui1iy.dll|proxystub.dllproxystub.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5gxuqgf0x.dll|RegMonitor.dllRegMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5RunAs.dllRunAs.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F54t56fgoz.dll|ScriptRun.dllScriptRun.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5qwrw4982.dll|SCVMonitor.dllSCVMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ce14x4pt.reg|ScvPlugins-32.regScvPlugins32bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ko_4kixx.reg|ScvPlugins-64.regScvPlugins64bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5o5mjfhkx.dll|scvprod_lang_pack.dllscvprod_lang_pack.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5nrbdfzfm.reg|ScvProxy-32.regScvProxy32bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5hazhixb3.reg|ScvProxy-64.regScvProxy64bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5q8n0osoc.con|qt.confqt.conf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5zfppmp-o.con|trac.configtrac.config.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5trac.ddftrac.ddf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F51.0.0.0akjz8hzp.def|trac.defaultstrac.defaults.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5trac.exetrac.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5TracCAPI.exeTracCAPI.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5wnblplrp.cmd|tracCPInfo.cmdtracCPInfo.cmd.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5utngtgtu.exe|TracSrvWrapper.exeTracSrvWrapper.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5u4wydb_z.con|EPS_ICA.configEPS_ICA.config.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5TrAPI.dllTrAPI.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5TrSAA.dllTrSAA.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5i74cz32p.dll|TrScvStub.dllTrScvStub.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5tr3aucm7.exe|UninstallSecureClient.exeUninstallSecureClient.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ruyo26jy.exe|update_config_tool.exeupdate_config_tool.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ver.iniver.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5fcvwos8f.exe|vna_install64.exevna_install64.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5ehgvsoz0.exe|vna_utils.exevna_utils.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5kca3a2qe.dll|WindowsSecurityMonitor.dllWindowsSecurityMonitor.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5DAAW.exeDAAW.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5tafbttzw.txt|DAAW_help.txtDAAW_help.txt.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5Component contained in the module.ModuleComponentsDefault language ID for module (may be changed by transform).Module containing the component.Version of the module.Default decimal language of module.Module identifier (String.GUID).Action to insertModuleInstallExecuteSequenceStandard Sequence numberBase action to determine insert location.BaseActionBefore (0) or After (1)AfterRemoveRegistryForeign key into the Component table referencing component that controls the deletion of the registry value.The predefined root key for the registry value, one of rrkEnumForeign key, Component used to determine install state ServiceConfigPrimary key, non-localized tokenServiceNameWhether the affected service is being installed or already exists.NewServiceFirst failure action type for configured service to take.FirstFailureActionTypeSecond failure action type for configured service to take.SecondFailureActionTypeThird failure action type for configured service to take.ThirdFailureActionTypePeriod after which to reset the failure count for the service.ResetPeriodInDaysPeriod after which to restart the service after a given failure.RestartServiceDelayInSecondsCommand line for program to run if failure action is RUN_COMMAND.ProgramCommandLineMessage to show to users when rebooting if failure action is REBOOT.RebootMessageName of a service. /, \\, comma and space are invalidServiceControlRequired foreign key into the Component Table that controls the startup of the serviceBit field:  Install:  0x1 = Start, 0x2 = Stop, 0x8 = Delete, Uninstall: 0x10 = Start, 0x20 = Stop, 0x80 = DeleteArguments for the service.  Separate by [~].Boolean for whether to wait for the service to fully startWaitInternal Name of the ServiceServiceInstallDescription of service.Arguments to include in every start of the service, passed to WinMainExternal Name of the ServiceDisplayNameType of the serviceServiceTypeStartTypeSeverity of error if service fails to startErrorControlLoadOrderGroupOther services this depends on to start.  Separate by [~], and end with [~][~]DependenciesUser or object name to run service asStartNamepassword to run service with.  (with StartName)PasswordEPC_Lib.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5CPINSTADDINT_Pireg.exeWixCA.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{9291A5B8-999F-4789-91FB-D113507C46F1}{71D6CC1C-8F97-4783-9509-50EB02DF523B}{743DD118-CE76-4617-9F6B-7EE0DC878C13}{27BAD3D5-4B3D-4A0F-977D-D40EF16FEFA0}{4A76D691-83D6-43C0-BE92-B4EF7041BC1B}{4869EFDA-9E3D-4691-A83B-2AD657317723}{D2B81C26-DB57-493C-BDC7-0531E3169726}{CA7DE025-396B-4E4F-AF6E-A9360799F715}{695F6AE9-CA47-4808-A2E7-0884C0BAF127}{04BD122D-7BFF-43B2-8663-7E51960955A8}{360EA6DB-0529-4FD0-8B38-4D300704FA54}{F576D8DD-754C-4BA9-9A7B-018548C31ADD}{7CB7D607-033D-4AC5-AB3D-F7423B6FC14B}{5F8091B7-9BDA-4BDA-87CA-951A5F31E430}{48103C69-D9B3-4DB2-9058-6B85EA7C6417}{D5262561-28EC-4537-A342-7038DB17B185}{62988631-31F5-410C-93D6-7EF9D161FD55}{B27750BA-AFFB-404E-B82D-A7D50390B192}{F476DC47-D5E2-46FF-A654-9F7378CBBC83}{49BBF153-7878-4A05-B209-4C25D21CFB22}{F1012F31-01ED-4265-B3A5-7FD30FB5EBE5}{8DFCF776-3031-481C-B999-81A55390BCEE}{4695A2D9-46B0-4BAD-A4C8-CA28501BAFB3}{15AC1F45-CADC-4322-877D-B0F6B8FBAE1D}{C3A7CD29-170E-4AC1-802E-80D08DB53C01}{976F8868-97D1-4ACC-A873-675BCAFF018F}{8301F95D-18AA-4435-B95B-FD1B7FDFE09F}{3B111FCC-0019-42C6-BCA9-019BCEB92B56}{9EB5CBA9-8364-4355-922F-42F40C33F1AD}{67965F17-E087-4538-9C13-92079F025B40}{7C396593-67AB-4DFB-9308-FC872C36DD48}{421DD629-A62C-4409-9924-4B1F4EC7B9FD}{3DE8ABCF-B131-4C80-B858-4B3F65F583F7}{4B98138D-1144-4372-922D-CAB9E742F0FA}{14E476EF-DE6B-462D-A711-8D005E41148C}{BEA23236-41F3-434E-9042-A2F10A10F13C}{F68CC5C6-35F6-4D54-8A2C-6547FC9444EE}{79978AE6-E4B5-49C1-99F6-D5C164043DD3}{466FAAD4-CD1B-46EA-BD8C-946F9BC81635}{E666998B-975F-4BE0-9133-D00963E045C1}{56D54D17-95A0-4C2E-82DA-92C8A52D6EE3}{11D0D41B-9CF4-426C-B354-2919B0B14B87}{B847CF4F-B207-4156-8E1F-1103A03DA915}{A7488D3E-7303-44E1-A58A-F3DF76EC2F06}{7736AC00-7BF6-4E4A-93FE-F5A8A6D2A4E2}{40992305-7189-492F-9959-7B85D6D1303D}{28308938-9B23-44BC-AC0F-FC36659D4539}{4B1B7800-BAC0-41FB-B316-59808DD0F6CC}{FAAA9BBD-E18F-492F-9631-022FA760AB98}{65E5EB9C-2215-4537-8EC8-7B9D41BD675B}{B9747D78-6A0A-4052-8BAF-F56DA704CABC}{EB5891C7-C022-4477-BDA3-9B0A876053D2}{7055A297-7BBE-4567-970C-CFD5879540DE}{EEBFC8B3-68B6-49F9-935D-779950DA0D3C}{277ED39A-79B5-4E06-B154-167BDA898825}{9C9B47B8-60C4-4F1B-8BA4-C7F031AB1C45}{A7FA7C39-E934-4AD0-A489-81536C32A6D3}{189F96FE-4809-468A-9DCC-CA663E4E1776}{BCA116A9-235B-4F68-8CC8-1E8CB5F5CB92}{BF0CC772-1B87-4FFC-AC3D-F65450FFB6F9}{5C53E0D0-BAB8-4F0D-9A03-4F7F29AE30A2}{93802988-B145-4E41-854B-986B9AA15D96}{0006216C-4560-44C2-9639-034854A81606}{81857FEB-77F6-4E96-9A80-DB107A51CDA2}reg450C90B597C11B830DEAE67E53CD842B.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{6E883670-0A97-4CDF-BB58-770CA59F2CC7}reg_DisableThreadedIpsec.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5regC33A0CEC066AF5307247E69896EB0F7E.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{9052684B-0543-4483-92F4-5F66AEF68829}reg_Version.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg7A9F65E094322E361AE3BA64881115D4.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{9BE7CA22-316C-4A9E-9996-9C2A586A99EC}reg_EPCBuild.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg8B37DBD2673E709C6C4FDB8F3F5AC361.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{4C667E77-13CC-45ED-8CA0-DF95ECF36EAD}reg_CurrentVersion.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg86C64025ABCBFEC5C600670D33D98995.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{D646F319-4A80-447B-AE7E-A35A07F3DB79}reg_Policy_Reload.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg2BF9BC09C9A2AC88085A88FA46A261BC.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{4E78D311-C964-4FAB-91F5-C06FFDEB4580}reg_CurrentLabel.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg3ABD6B3C76551E837991992C76F61225.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{36E10524-12A5-4251-85AE-6D730FDCD4DA}reg_CurrentSP.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg8AE357A28123E80B71F7895047E7325B.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{3CF7BA33-B393-4A28-AFF5-0E721641F88F}reg_PRODDIR.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5regFB559A5C1ECE3C9ABE34BA48695CE080.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{70B03E27-103E-4F2D-B062-A0FF8783DA51}reg_PKGPATH.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg3CCF29E3ED987DB9704FEBEBF0E37850.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{E9719E6F-A866-4AE2-B5D1-487420B01260}reg_PRODUCT_GUID.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg6DB462B84A1E7E5093B334562E41F508.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{B98279EB-83E0-47C9-9894-EB084F7666EA}reg_CurrentMSP.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg68585343B46E9FE85304A2B6EC8438A4.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{A628C400-0CA9-4488-AF0F-F63466C4F6FA}reg_MSP1_PRODUCT_GUID.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg3AD2089DF78407096D3C9AB557804855.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{78C6CB0C-6C6E-4709-A6DA-8F417AD09E71}reg_MSP1_Dependent.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5reg_EnblLegAutoProxy.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5{475A787D-600F-4F59-A437-7DD716BA6EE4}CheckIfSha2KbIsInstalledOnBeginStopTracServiceVnaInstallComponentsInstallVnaUnInstallVnaUpgradeUninstallSDLComponentsBackupVnaCleanSSOCleanStartTracServiceCopyLastMSILogFileDeleteConfigsExecServiceConfigRollbackServiceConfigFIXED_MACNO_OFFICE_MODESDL_ENABLEDFW_INSTALL_REBOOTVNA_INSTALLINNER_MSISC_UIFRAMEWORKECDEAFULT_VPNNoKeepNOPASSUNINSTALL_PASSWORDomusREINSTALLMODEdisable_threaded_ipsecE87.20986104605EPCBuild5.0CurrentVersionforce_policy_reloadR55CurrentLabel4CurrentSP[INSTALLDIR][DATABASE]PKGPATH[ProductCode]PRODUCT_GUIDCurrentMSPSoftware\\CheckPoint\\TRAC\\5.0\\SP4Software\\CheckPoint\\TRAC\\5.0\\SP4\\MSP1Check Point VPN-1 Pro NG with Application Intelligence (R55) Software\\CheckPoint\\TRAC\\5.0\\SP4\\MSP1\\DependentPkgsEnableLegacyAutoProxyFeaturesSOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet SettingsnonerestartTracSrvWrapperCheck Point Endpoint Security VPN serviceDhcp[~]vna_ap[~][~][#TracSrvWrapper.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5]Check Point Endpoint Security VPN Service8.0CPEPDriver.6B6E64A3_4478_4297_9CD9_3D71DBCD974ASystemFolder.6B6E64A3_4478_4297_9CD9_3D71DBCD974ASysFdl[SystemFolder]ZonelabsTVDIR.6B6E64A3_4478_4297_9CD9_3D71DBCD974AProgramFilesFolder.6B6E64A3_4478_4297_9CD9_3D71DBCD974ACheckPoint.6B6E64A3_4478_4297_9CD9_3D71DBCD974ACheckCurrentUser.6B6E64A3_4478_4297_9CD9_3D71DBCD974APatchDiscoveryVPNCA.6B6E64A3_4478_4297_9CD9_3D71DBCD974AWIX_UPGRADE_DETECTEDPatchSBAInstallerCA.6B6E64A3_4478_4297_9CD9_3D71DBCD974A( FW_INSTALL = \"YES\" AND VersionNT>=600 AND NOT ISACTIONPROP1 AND NOT Installed )CheckNetworkFilters.6B6E64A3_4478_4297_9CD9_3D71DBCD974A( FW_INSTALL = \"YES\" ) AND NOT UPGRADINGPRODUCTCODEOnInstallDriverPrepare.6B6E64A3_4478_4297_9CD9_3D71DBCD974AOnInstallDriverBegin.6B6E64A3_4478_4297_9CD9_3D71DBCD974A( FW_INSTALL = \"YES\" AND INCREASENETWORKFILTERS=\"YES\" )IncreaseFiltersMaxNum.6B6E64A3_4478_4297_9CD9_3D71DBCD974AOnInstallDriverFinish.6B6E64A3_4478_4297_9CD9_3D71DBCD974AOnInstallDriverReboot.6B6E64A3_4478_4297_9CD9_3D71DBCD974A9.26.0.7302vsdata.dllvsdata.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A86.8.7200.2vsinit.dllvsinit.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974Awyvgvzj6.exe|PacketMon.exePacketMon.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A97.9.0.5fwcpp.exefwcpp.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A8.68.62.2-9aqscof.dll|FirewallMonitor.dllFirewallMonitor.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A86.87.2.3qpcuc9z1.dll|Epilogue_spdlog.dllEpilogue_spdlog.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A8.68.72.5vsutil.dllvsutil.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsconfig.xmlvsconfig.xml.6B6E64A3_4478_4297_9CD9_3D71DBCD974Aconfig.xmlconfig.xml.6B6E64A3_4478_4297_9CD9_3D71DBCD974A9.26.0.5812vsdatant.sysDriverWin7.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant_win7.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974AVsDrInst.exeVsdrInstWin7.6B6E64A3_4478_4297_9CD9_3D71DBCD974AVsDrInst_win7.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974ADriverWin7_64.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974AVsdrInstWin7_64.6B6E64A3_4478_4297_9CD9_3D71DBCD974AVsDrInst_win7_64.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974A8.68.71.3epklib.sysepklib_x86.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974Aepklib_x64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A8.60.3.1130ccore32.sysccore32.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974Accore64.sysccore64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant.catvsdatant_win7.cat.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant.infvsdatant_win7.inf.6B6E64A3_4478_4297_9CD9_3D71DBCD974As7ol4n9e.sys|epklibproxy.sysVsdatant_epk_win7.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant_win7_64.cat.6B6E64A3_4478_4297_9CD9_3D71DBCD974Avsdatant_win7_64.inf.6B6E64A3_4478_4297_9CD9_3D71DBCD974Aqcnmlosi.sys|epklibproxy.sysVsdatant_epk_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974AModuleInstallUISequenceCustActionLib.6B6E64A3_4478_4297_9CD9_3D71DBCD974AInstHelper.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974AHash.exe.6B6E64A3_4478_4297_9CD9_3D71DBCD974ADisconnectedPolicy.6B6E64A3_4478_4297_9CD9_3D71DBCD974AOrgDisconPol.6B6E64A3_4478_4297_9CD9_3D71DBCD974AFW_INSTALL=\"YES\"{2A6864EF-AA82-4305-8001-6C41DDE49BA7}{7628BF7B-4A89-4A4A-91D9-29FAE875CF4B}{1D5626F0-85DF-4A89-9A39-74C8604B5352}{CCAA09B4-8B05-43E6-80F0-3E49F5D9E1BF}{F17E06DE-E1B2-449D-AC08-E619C346B9FB}{FADC6839-E0F1-5A02-A3F6-9ECBC699EDC0}{66E7742F-BA83-4481-8E14-EB0C7480753C}{25D8DC25-63A2-4723-B258-C70FE39C1255}{5CE9689B-3A02-4041-9439-1F2B491A8A6F}VersionNT>=601 AND NOT VersionNT64 AND FW_INSTALL=\"YES\"{411E6E63-D247-4C7D-AF66-4A4C4BC08B33}{37683CFC-1E09-4B9E-977E-C1DB6061B3E6}VersionNT>=601 AND VersionNT64 AND FW_INSTALL=\"YES\"{D43892C3-C747-4C54-8F49-78CB73141C6E}{98624430-A1FE-40FC-9604-1EF5D4C27B65}regA9F9FF4A90EDE4EA03D37DB78FE01184.6B6E64A3_4478_4297_9CD9_3D71DBCD974AFW_DRV_REPLACE=\"YES\" AND FW_INSTALL=\"YES\"{2C51D3B3-9705-4552-8FE3-50EAB4C037C2}DriverParameters.6B6E64A3_4478_4297_9CD9_3D71DBCD974ANOT VersionNT64 AND VersionNT >= 600{5CE9D00D-A54F-4CB3-BBC4-424A6DAB0216}VersionNT64 >= 600{FE929C82-A311-469E-9AF0-78F6268E3837}{50906B71-AC1B-45B8-9647-760F16956025}{728F0ED5-4C89-427B-86AA-267DDCAD8C2F}CheckCurrentUserCheckNetworkFiltersOnInstallDriverPrepareIncreaseFiltersMaxNumOnInstallDriverBeginOnInstallDriverFinishOnInstallDriverRebootPatchDiscoveryVPNCAPatchSBAInstallerCAFailed to set security descriptor on object [3], system error: [2]. Windows update for SHA-2 code signing support is not installed. See KB3033929.Failed to access cached MSI of previous version. [2]You must restart your computer before installing [2].  File operations from a previous installation must be completed by rebooting before a new installation can be started.The system has reached the maximum possible number of network filters. Installation will exit.EP_Drivers\\E87_20\\B868720006EP_Drivers.6B6E64A3_4478_4297_9CD9_3D71DBCD974AEPDRIVERSVERSION6B6E64A3_4478_4297_9CD9_3D71DBCD974AEPDRIVERSGUIDFW_DRV_REPLACE\\\\Program Files\\\\Checkpoint\\\\Endpoint Connect\\\\FW_DIRFW_INSTALL_ERRORINSTALL_POLICY[FW_DOS_DEVICE_C]InstallDirDeviceSYSTEM\\CurrentControlSet\\Services\\vsdatant\\Parameters[INSTALLDIR]PacketMon.exeSOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\PacketMon.exereg7B6552A4F0CB3AF4576D6309378E693C.6B6E64A3_4478_4297_9CD9_3D71DBCD974APathregF37229EB36D434F00D66FD83BA2F950A.6B6E64A3_4478_4297_9CD9_3D71DBCD974A-PacketMon.6B6E64A3_4478_4297_9CD9_3D71DBCD974A[FW_INSTDIR]InstallDirDriveregFC9F0E33A0A6D32C3B54ADA008B019F2.6B6E64A3_4478_4297_9CD9_3D71DBCD974ACPEPConnectDevicereg68A1C41570A2B077CE80F1842F1B097D.6B6E64A3_4478_4297_9CD9_3D71DBCD974ACPEPConnectDrivereg75ACBD620BA572D51313628127C72FBD.6B6E64A3_4478_4297_9CD9_3D71DBCD974A#3TdiEnablereg5EEFF295F9136338748240D96B24444C.6B6E64A3_4478_4297_9CD9_3D71DBCD974AInstalledProductregEDDF7BD892F413C7B388F7686F49C01D.6B6E64A3_4478_4297_9CD9_3D71DBCD974ASYSTEM\\CurrentControlSet\\Services\\vsdatantregD842C663F3C9F99073139CD8F52967C1.6B6E64A3_4478_4297_9CD9_3D71DBCD974A8.68.72.3EPS_Watchdog.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WatchdogDir.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WatchdogProgramFilesFolder.13280B40_9130_4E2F_97CC_FF2D9A5C57F4CompanyFolder.13280B40_9130_4E2F_97CC_FF2D9A5C57F4Log_cfgCKP.13280B40_9130_4E2F_97CC_FF2D9A5C57F4Log_cfg.13280B40_9130_4E2F_97CC_FF2D9A5C57F4LogsLogs.13280B40_9130_4E2F_97CC_FF2D9A5C57F4CommonAppDataFolder.13280B40_9130_4E2F_97CC_FF2D9A5C57F4[CommonAppDataFolder]WD_StopService.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WD_ChkFldrBefore.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WD_ChkFldrAfter.13280B40_9130_4E2F_97CC_FF2D9A5C57F486.8.7000.1EPWD.exeEPWD.exe.13280B40_9130_4E2F_97CC_FF2D9A5C57F44kl0p4_c.exe|EPWD_Tool.exeEPWD_Tool.exe.13280B40_9130_4E2F_97CC_FF2D9A5C57F4jg2elaiv.dll|WatchdogAPI.dllWatchdogAPI.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F4watchdog.xmlwatchdog_xml.13280B40_9130_4E2F_97CC_FF2D9A5C57F4Epilogue_spdlog.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F420572019.8.1.0hzrxrjyy.dll|lmx-MD-vs2017x86.dlllmx_MD_vs2017x86.dll.13280B40_9130_4E2F_97CC_FF2D9A5C57F4pio_7m2u.tom|EPWD.tomlEPWD.toml.13280B40_9130_4E2F_97CC_FF2D9A5C57F427vtjotc.tom|default.tomldefault.toml.13280B40_9130_4E2F_97CC_FF2D9A5C57F4Reference to another table nameDirectory;File;RegistryLockPermissionsForeign key into Registry or File tableLockObjectDomain name for user whose permissions are being set. (usually a property)DomainUser for permissions to be set.  (usually a property)UserPermission Access mask.  Full Control = 268435456 (GENERIC_ALL = 0x10000000)PermissionCustActionLib.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WixCA.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{2EF74CBE-F514-4650-8250-CE8CC010527F}{52F2BA44-3506-47C6-9A5F-F714BEEFC7A3}{E6F8096F-7E53-4785-8DDA-B777FF0C1FA7}{D919F73F-115C-45EE-BE1E-D9A81403C93C}{D548BF1A-1976-5C87-AE35-A72278A7760B}{A4268BB9-AA4A-5EDE-9F9D-F15577E19912}regB14C7B2D4A7B9102A8FCB015038E8F09.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{F6E2D9A2-B0CF-481C-B6A7-D918072F1292}reg_Stoppable.13280B40_9130_4E2F_97CC_FF2D9A5C57F4reg1A8DE655B8B6546647BD0AB11823A084.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{375ACE62-68B6-4619-B7FD-37475D0FBF2F}reg_LogLevel.13280B40_9130_4E2F_97CC_FF2D9A5C57F4reg82A4B2A93886D2EB5613C5A8BE33D724.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{C8E96C8F-29DE-41B5-91EA-A5C88994FFE1}reg_LogLimit.13280B40_9130_4E2F_97CC_FF2D9A5C57F4regED6F3EB7D4EF5AF51CF31279D2B1EFCA.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{A2A3A40D-C94D-4C78-BDD6-66BCE400FED6}reg_LogTrunc.13280B40_9130_4E2F_97CC_FF2D9A5C57F4reg8DB213C9250DEFF89C5709095DC7332E.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{F7A4AF61-8A14-422F-8DB6-58F694483F6F}reg_GracePeriod.13280B40_9130_4E2F_97CC_FF2D9A5C57F4regF75BBCDE870CBACCBA66233A562189C5.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{DB836B94-6259-47E0-BE1A-F266A1188785}reg_trGuiPath.13280B40_9130_4E2F_97CC_FF2D9A5C57F4reg93B98691985959B7D893925A8FE5EF49.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{D0ECE4CA-14E4-47EB-B050-785B75685E99}reg_tracSrvWrapper.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{462958C3-2FFA-457B-9667-7AD686A20DF6}Log_cfgComponent.13280B40_9130_4E2F_97CC_FF2D9A5C57F4{5D4E3494-8392-5299-956D-E2980D438618}{7EC0CF7A-001C-56EA-AA96-F43CCE855615}{E0830C52-3500-4AE0-9251-86805030C52E}LogsComponent.13280B40_9130_4E2F_97CC_FF2D9A5C57F4WD_StopServiceFromSCMWD_CheckFolderFailed to stop Check Point Watchdog service.%ProgramData%\\CheckPoint contains symbolic link that cannot be removedAdministratorsEveryoneEP_MSM_Watchdog\\E87_20\\B868720003EP_MSM_Watchdog.13280B40_9130_4E2F_97CC_FF2D9A5C57F4StoppableSoftware\\CheckPoint\\Trac\\WatchdogDLogLevel#10485760LogLimit#7864320LogTrunc#180GracePeriod[INSTALLDIR]TrGUI.exetrGuiPath[INSTALLDIR]TracSrvWrapper.exetracPathEPWDCheck Point Endpoint Client Watchdog serviceCheck Point Endpoint Client Watchdog14.0Microsoft_VC140_CRT_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3SystemFolder_x86_VC.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3SystemFolder.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3System10.0.10586.15flkgvdpp.dll|api-ms-win-core-console-l1-1-0.dllucrtbase.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3api_ms_win_core_console_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B314.15.26706.0e5c2w6m8.dll|vcruntime140.dllvcruntime140.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3vcruntime140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3msvcp140.dllmsvcp140.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3msvcp140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B360kzyxuf.dll|msvcp140_1.dllmsvcp140_1.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3msvcp140_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3okh-mk0p.dll|msvcp140_2.dllmsvcp140_2.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3msvcp140_2.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3-dkwnr3s.dll|concrt140.dllconcrt140.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3concrt140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3xjk6qap7.dll|vccorlib140.dllvccorlib140.dll_system_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3vccorlib140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3orz9nv8z.dll|api-ms-win-core-datetime-l1-1-0.dllapi_ms_win_core_datetime_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3wj-wflpu.dll|api-ms-win-core-debug-l1-1-0.dllapi_ms_win_core_debug_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3unlcfdq1.dll|api-ms-win-core-errorhandling-l1-1-0.dllapi_ms_win_core_errorhandling_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3_lrlfgft.dll|api-ms-win-core-file-l1-1-0.dllapi_ms_win_core_file_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ubomx1uj.dll|api-ms-win-core-file-l1-2-0.dllapi_ms_win_core_file_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3pwhngsml.dll|api-ms-win-core-file-l2-1-0.dllapi_ms_win_core_file_l2_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3p_1y8rgm.dll|api-ms-win-core-handle-l1-1-0.dllapi_ms_win_core_handle_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3amwaxaso.dll|api-ms-win-core-heap-l1-1-0.dllapi_ms_win_core_heap_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3gtg-trbr.dll|api-ms-win-core-interlocked-l1-1-0.dllapi_ms_win_core_interlocked_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3szen_yzs.dll|api-ms-win-core-libraryloader-l1-1-0.dllapi_ms_win_core_libraryloader_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3r9rxv9r8.dll|api-ms-win-core-localization-l1-2-0.dllapi_ms_win_core_localization_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3a543pm7m.dll|api-ms-win-core-memory-l1-1-0.dllapi_ms_win_core_memory_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B33ndvk0x2.dll|api-ms-win-core-namedpipe-l1-1-0.dllapi_ms_win_core_namedpipe_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3zqo1l1r3.dll|api-ms-win-core-processenvironment-l1-1-0.dllapi_ms_win_core_processenvironment_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ygotu7ix.dll|api-ms-win-core-processthreads-l1-1-0.dllapi_ms_win_core_processthreads_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3rpi0s4ow.dll|api-ms-win-core-processthreads-l1-1-1.dllapi_ms_win_core_processthreads_l1_1_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3knbimgrp.dll|api-ms-win-core-profile-l1-1-0.dllapi_ms_win_core_profile_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3a2iar0pk.dll|api-ms-win-core-rtlsupport-l1-1-0.dllapi_ms_win_core_rtlsupport_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3613ejxwa.dll|api-ms-win-core-string-l1-1-0.dllapi_ms_win_core_string_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3x_sr-csw.dll|api-ms-win-core-synch-l1-1-0.dllapi_ms_win_core_synch_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B39cd6r8w9.dll|api-ms-win-core-synch-l1-2-0.dllapi_ms_win_core_synch_l1_2_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B39f0l3frf.dll|api-ms-win-core-sysinfo-l1-1-0.dllapi_ms_win_core_sysinfo_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B35c0uqche.dll|api-ms-win-core-timezone-l1-1-0.dllapi_ms_win_core_timezone_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B31ixtxe2b.dll|api-ms-win-core-util-l1-1-0.dllapi_ms_win_core_util_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3abdcmc3v.dll|api-ms-win-crt-conio-l1-1-0.dllapi_ms_win_crt_conio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3aunl2qua.dll|api-ms-win-crt-convert-l1-1-0.dllapi_ms_win_crt_convert_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3glpulfxs.dll|api-ms-win-crt-environment-l1-1-0.dllapi_ms_win_crt_environment_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3iurqmcpy.dll|api-ms-win-crt-filesystem-l1-1-0.dllapi_ms_win_crt_filesystem_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3scnfeby5.dll|api-ms-win-crt-heap-l1-1-0.dllapi_ms_win_crt_heap_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3uuneguxg.dll|api-ms-win-crt-locale-l1-1-0.dllapi_ms_win_crt_locale_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3gtrmocu6.dll|api-ms-win-crt-math-l1-1-0.dllapi_ms_win_crt_math_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3-dhtxh0m.dll|api-ms-win-crt-multibyte-l1-1-0.dllapi_ms_win_crt_multibyte_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3q4wos0qq.dll|api-ms-win-crt-private-l1-1-0.dllapi_ms_win_crt_private_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3egmsyt8w.dll|api-ms-win-crt-process-l1-1-0.dllapi_ms_win_crt_process_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3s3w2ao34.dll|api-ms-win-crt-runtime-l1-1-0.dllapi_ms_win_crt_runtime_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B36lbqhfa7.dll|api-ms-win-crt-stdio-l1-1-0.dllapi_ms_win_crt_stdio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ixkjsdfd.dll|api-ms-win-crt-string-l1-1-0.dllapi_ms_win_crt_string_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B36all5l1t.dll|api-ms-win-crt-time-l1-1-0.dllapi_ms_win_crt_time_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3lxtlxxgx.dll|api-ms-win-crt-utility-l1-1-0.dllapi_ms_win_crt_utility_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3ucrtbase.dllucrtbase.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3{42F41217-AF8B-33D4-9CB3-FF5F696BECBB}{E8E39D3B-4F35-36D8-B892-4B28336FE041}{A2AA960C-FD3C-3A6D-BD6F-14933011AFB3}{A2E7203F-60C2-3D7E-8A46-DB3D381A2CE6}{BC0399EF-5E9D-3C7C-BFF5-5E9A95C96DAF}{9FC931F8-9ED1-3263-A0F1-8ADE330D0ECE}{0200CF79-B9A1-3BE4-955A-29FA9D4B1A5C}ALLUSERSDirectoryTableDirectoryTable100_x86.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3trch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid8868444 to }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13200219\\charrsid8868444 ",
        "73&ma",
        "sslv3 alert certificate expired",
        "AN6B2",
        "BHf\"T",
        "%0K][",
        "Oy6ae",
        ">*>0>C>i>",
        "h1J9p",
        "ET7q;",
        "f4%pa35",
        "B>}3(+",
        "Cbv`g",
        "n%@R$",
        "bn~N{",
        "0$0,040<0D0L0\\0d0l0t0|0",
        "!GV=R",
        "0G1s1y1",
        "R9|CI",
        ">!>H>O>[>e>",
        "avf_<",
        "1m`Ac",
        "dIqfz",
        "8#%G|",
        "vH)G9<",
        "'BH;~",
        "mpydv&",
        "J;C9t",
        "XVyfn",
        "\\ZoneLabs\\oper.pbv",
        "j&jej+",
        "CANT_WRITE_ALTDIR",
        "1kK?+B",
        "\\MUp}",
        "\" yl_L",
        "Smav:",
        "^[kx\\y",
        "[MQ~4",
        "-inZ=",
        "&\"&X$LMh",
        ".\\crypto\\x509v3\\v3_pcons.c",
        "1\\zMS\\",
        "Hi=(*",
        "+(-t:",
        "/|U8k",
        "|nOH5",
        "[**SESSION STOP**] [PERFORMANCE]",
        "^Ansf",
        "]kcYv",
        "gbNaK",
        "D71O-*",
        "PEd2*",
        "~bPPOW",
        "MM)MRd",
        "%BaT{",
        "Found pending file operation",
        " 0x19",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid3374529 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 Check Point warrants that the }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "848M8f8",
        "u)s<=",
        "j\\QZeu",
        "5fKz'",
        "/;D$0",
        "`STFdW",
        "4rxT[eeT",
        ":0Py=",
        "g@:$$?",
        "QI;kr",
        "9Ef2hh",
        "xxe{QSZ",
        "'96o<",
        "R-$AK",
        "M,{pI&]",
        "oA9&|I",
        " 5bRY",
        "%*sNo Trusted Uses.",
        "/zE71",
        "2oil>h~",
        "$>^M$",
        "kzg'0*<",
        "Version: %d",
        "5$6/686I6R6[6f6k6t6",
        "m>pGx8OX3",
        "f3vw>",
        "{ [Qv\"",
        "$eWaC",
        "HA#fQ",
        "/Sw:C=",
        "i<YK(@f",
        "W72Uyp",
        "Xs6~]",
        "V$y$|/",
        "unrsYC",
        "0F|*EF",
        "ZSr-[",
        "|py35^",
        "l-{tF\\",
        "Checking for App: %ls Attributes: %d",
        "SsKUGa)",
        "QiUq1",
        ":d:n:",
        "18W$L.",
        ":8;h;r;",
        ";;H?6A",
        "Ysa^L ",
        "mo:z %",
        "Z+;(@",
        "im5,b}n",
        "RSQRTSS",
        "[Sh hL",
        "E3`cfkSq",
        "+_#~.",
        "N@Dw4",
        "GetHelperProcessHandle() returns:  %d",
        "z$W>s",
        "XKY8S",
        "SZ7P=",
        "h'HOG",
        "50)|'",
        "|<e9n",
        "kh:96",
        "X0>PL",
        "bdqA4",
        "9it72",
        "818F8X8q8",
        "'snh^ ",
        "P@cDC1",
        "3Zi^p",
        "qOq<<",
        "s H!.",
        "%Nn*DydIz",
        "a~Lm-",
        ">`1|^",
        "AeJal",
        "(undef)",
        "OC%a~",
        "isiDj<",
        "7Z8a8,969x9",
        "v\\7O}",
        "3(3H3P3X3`3l3",
        "autoexec.tv",
        "T$P3T$",
        "JZ Qa",
        "6g9}E",
        "NdXYd",
        "-b\"ocnQ",
        "152P2a2m2",
        " 6:/p",
        "sO5nj)",
        "?n~e[",
        "9&:5:U:s:",
        "b*AKK5",
        "DS\\Ov>r",
        "B&ALQ",
        "tvdumplimit",
        "^E+8[",
        "nwmk\\LF",
        ":]:y:",
        "oBHyy",
        "XY~#T",
        "*2&tK",
        "X; zs",
        "|X\"L#EG",
        "Pr$T&",
        "b`7Z6",
        "L)0!%zeS1",
        "+ERVF",
        ".?AV?$_Func_impl_no_alloc@V<lambda_0181ba6b4c688320166279c58f783d31>@@XABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV23@G@std@@",
        "Failed to open ",
        "`fSxG",
        "Yh`|%",
        "failed to create record when sending error message",
        "IwMaWY",
        "Sysnative",
        ")Xo`0",
        "DFLT_ROOT_NOT_SET",
        "3FkI%",
        "I]N_<",
        "Y+zN^",
        "G[t)+V",
        "^l3WMDWW#",
        "OO<S\"9",
        "vV>9|#a\"",
        "%'SXC",
        "T,6YT",
        "[/)5U)_",
        "zi&WH",
        "3=6k9",
        ":K:`:s:",
        "a%$Jb",
        "X>@,P",
        "$tqa`'",
        "t$ PQ",
        "\\vsdata.dll",
        ":9:m:",
        "[WinFW] GetWFStatus, failed to read status, error=%x",
        "KP$cX",
        "jL(mA~\"",
        "d?2Zo",
        "[x+A?",
        "jvh<v%",
        "X509v3 Delta CRL Indicator",
        "RestartDriver",
        ",.I/,1",
        ",!{gN",
        "dd!f=",
        "sha-512",
        "QbT9z",
        "3H4{4",
        "URI:%s",
        "FG*Pt'",
        "?@.Y;",
        "EC_GROUP_SET_EXTRA_DATA",
        "TracFailed.wav",
        "](Sxc/",
        "v&]Z*",
        "f#N4L,",
        "<\"=u=|=",
        "D0$(3",
        "1KzRl",
        "<6<J<f<q<",
        "ec_GFp_mont_group_set_curve",
        "MOVDQ2Q",
        ";p;IPP",
        ",)Xhq",
        "tR^) Nc",
        "L@ea=",
        "vsdatant",
        "%]{3=5",
        "&apos;",
        "****************************** ComponentsInstall ended **********************************",
        "0r9b^R+/",
        "WxKQm",
        "3YR.B",
        "_6?S2",
        "Manchester1",
        "?0123456789ABCDEF",
        "ECPKParameters_print_fp",
        "4iRH^",
        "?Q+eKW",
        "1%1_2",
        "%R'0 q",
        "<]`ki",
        "(;{LT",
        "8,848<8D8L8X8`8",
        "JdRk)",
        "Q~}.V",
        "b;tvE",
        "nMM x",
        "NqcPxc@",
        "+w;8|",
        "/QXW}",
        "\\G,(U",
        "Lg 4d",
        "8i)0S",
        "Wj4XPV",
        "|c7.&",
        "]85OH",
        "5`3B8",
        "UQ]L'",
        "\"3MfrY",
        "T:ejM",
        "PrqO`",
        "D$DPW",
        "X509_REQ_print_fp",
        "KnvO:",
        "\"f!jX",
        "6]e(b)Ym",
        "~;.dHm",
        "K]:pim",
        "999U9q9",
        "Kaspersky Anti-Virus for Windows Workstations (based on version 5.0.528)",
        "7cJ!V",
        "T6kawm",
        "H0(k+",
        "Cookie: ",
        "isModuleRunning",
        "..trQ",
        "|\\4N!",
        ">y>oI(W1",
        "?H3*A",
        "7+84888>8B8H8L8V8i8w8",
        "eLUme",
        "'P5?#7",
        "<m*At",
        "d.enveloped",
        "QVWSj",
        "fU:sG",
        ";53P9",
        "/(%<Vg",
        "KERNEL32.dll",
        "XbQus",
        "MinBootTime",
        "tZVWj",
        "B)>~&",
        "4 4V4h4t4f5x5",
        "mG>Nm",
        "(8WfoX",
        "ESJ|0X",
        "|sfw>C#",
        "1 1(1,181@1D1P1X1\\1h1p1t1",
        "operation not defined",
        "X!t/G",
        "H<{ZFa",
        "p>LFE",
        "^FMQ$",
        ".\\crypto\\x509\\x509_vfy.c",
        ";1ub;",
        ",*&Fh",
        "@E@H@L@M",
        "PreInstallCheck:  Check for conflicting Kaspersky Antivirus.",
        "WVQux[j",
        "4C4H4R4x4",
        "S}iJs=",
        "H~Jc#",
        "t!jGh",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid344604\\charrsid15169477 ",
        "sNnr{",
        "SetEventGroupInVSConfigFlat(\"%s\", \"%s\", %s, %d)",
        "<=F<e",
        "j_f`9",
        "8=#0W",
        "p@i]8",
        "`}%-i",
        "6r7C8M9",
        "{(?'4a>",
        " 5pF@Z",
        "FPP5Y",
        "484a4",
        ".\\crypto\\evp\\evp_pkey.c",
        "cmd /c \"del /F /Q \"%s\\Temp\\vna_install64.exe\"\"",
        "&BV72",
        "z={51^",
        "id-hex-multipart-message",
        "<!<1<A<a<q<",
        "[|/d4=",
        ":6:_:",
        ",nh-/|6",
        "b;#:%",
        "`%e27",
        "&GHD]",
        ",L)\"6",
        "jdjdj$",
        "2;2C2S2",
        "Initial current directory = %s",
        "{~r|b",
        "(1ECV",
        ".?AV?$numpunct@D@std@@",
        "%s_%s.log",
        "9xE6k",
        "Diffie-Hellman part of OpenSSL 1.0.2h  3 May 2016",
        "l+<l9",
        "[VSSHUTDN] CallDriverCtrl dwCtrl: 0x%x dwFlags: 0x%x FAILED.",
        "VQghF",
        ":)=0~",
        "a!\\'T8",
        "(@/j!",
        "?Oin1 Jbjd",
        "t$$Ph",
        "#If^K",
        ">'?f?u?",
        "0at0h0",
        "Q@*Uv",
        "Kviq)",
        ";BWv9",
        "h>0i,>0",
        "&6PhO",
        "[LICENSING] NOTICE corrupt beta key %s attempting repair. modedate: %d",
        ">g,(wx",
        "/2WLd",
        "9l?p?",
        "oGWHe",
        ".7M7L7K7",
        "MsiCleanAll",
        "(-8cX&",
        "1<1C1i1m1q1",
        ":&:7:V:]:",
        "=9=D=R=n=s=",
        "|c*#F",
        "K(Xi-lC\"P",
        "I@8)LwZ",
        "P s#^",
        ";<;D;L;T;`;",
        "(%7bN",
        "-N~n>Ih6i",
        "?KGs-",
        " 0x50",
        "O>8l [.",
        "&MHW%4:Q",
        "6[)Dp",
        "=H=W=d=j=p=",
        "6>a$~",
        "Tfd5`|",
        "uS2tm",
        "2\\3i3",
        ": -f5",
        "G4 evA",
        "d9`k|",
        "au2aO",
        "?3F1o4",
        "7 7(7L7T7\\7d7l7t7|7",
        "4\"5B5|5",
        "W]/4!",
        "CA'.q",
        "7^[_3",
        "/s^//",
        "9J%4S",
        "N];pH{",
        "id-smime-aa-ets-certValues",
        "To upgrade, modify, or remove Secure Access you ",
        "5[)b\\",
        "uy(Hk",
        "G`A(D",
        "CtL(L@",
        ":\";a;l;",
        "]I=j5",
        "'>-mD",
        "RemoveSD()",
        "sc stop avckf",
        "z@{nr",
        "[B^.eDEz~",
        "HH4i1<Xq",
        "\"gp?HX",
        "eY~:zW",
        "93s2]e",
        "{?Anz",
        "u\"!S$S8Fn",
        "D$(Ph\\",
        "1$1^1c1h1m1u1",
        "af'BS",
        "G~l5@",
        ")-PHL",
        "<Peps",
        "<UV\\#",
        "94`tEd",
        "ROUNDSS",
        "^Vt\\c",
        "3w,{,h",
        "7U!JXb",
        "6Giuu2z",
        "SQytO",
        "Gm3gG?,QA",
        "PSGControl.exe",
        "L$$3J",
        "XJ}_ ",
        "C}c/1n'",
        "t626I",
        "chunked",
        "IDEA part of OpenSSL 1.0.1t  3 May 2016",
        "tyPVj@W",
        "!2+L#",
        "wO`aMLKbcZ_QD",
        "l#CNl",
        "jsjwj#",
        "ZUNV4",
        "?4?T?t?",
        "C7WlB",
        ">Qe4Ba",
        "failed to copy component id",
        "nPFWQ",
        "=?0Gn",
        "WzZff",
        "/`Gfc",
        "bJpIb",
        "A)+:7",
        "fqrDyIa",
        "f<`i}",
        "$%^24Q8",
        "Ku:,\\oG",
        " ?f-9t|",
        "[LICENSING] not revived, beta license past date by %ld days",
        "?)?6?B?",
        "CycKw",
        "NDQr\\",
        "y8`|!,\"R",
        "242D2L2X2",
        "0 0@0H0X0`0h0|0",
        "*S! 4",
        "zUMrz",
        "'S>=^",
        "<mr:0",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078 ",
        ":$:2:B:L:o:",
        "}R}BDW9",
        "WIN32_PATHBYADDR",
        "wKERNEL32.dll",
        "+*|cHI",
        "Plugins::UnregisterFW:  Unregistering ",
        "Ej=.'",
        "}\\BW@",
        "j?@GZ|=^",
        "@R7aZ",
        "edWw>",
        "O)V],[",
        "AddWindowsFirewallExpcetion:  AddWindowsFirewallExpcetion started.",
        "BN_GF2m_mod_mul",
        "gsh,0YmF\"",
        "ebEw$",
        "{/+#^",
        "{aT?^",
        "__,nI",
        "DPP@B",
        "242a2",
        "VSCheckPasswords()",
        "named_curve",
        "P3|a\"",
        "y]H?y",
        "ArchiveLogFile: Error %d writing zip %s - zipOpenNewFileInZip %s",
        "7F?I}F!'",
        "o0opo",
        "-d-p.",
        "7(3&0A",
        "D$41F",
        "RSA_NULL_PRIVATE_DECRYPT",
        "M`\"+\\u",
        "^RU+#s9\"",
        "=\"=&=*=.=2=6=:?>",
        "869Y9",
        "P}?q4",
        "DWFm0",
        "wVM\\^",
        "->.PX<[",
        "b|U,\"C",
        "u<VGg",
        "373V3",
        "!QZ^XZ",
        "]VtP\"",
        "jfj|j",
        "t^j*Yf",
        "Lr5nG",
        "u'h@U!",
        "{\\fhiminor\\f31576\\fbidi \\fswiss\\fcharset163\\fprq2 Calibri (Vietnamese);}{\\fbiminor\\f31578\\fbidi \\fswiss\\fcharset238\\fprq2 Arial CE;}{\\fbiminor\\f31579\\fbidi \\fswiss\\fcharset204\\fprq2 Arial Cyr;}",
        "yN-&+",
        "`?5BQ)#",
        "1)141",
        "l6<-6",
        "S p?/",
        "qROKbS",
        "Q%JG5&",
        ":3;sY",
        "3!3A3a3",
        "gD7F>G",
        "8<8s8",
        "it+R1",
        "5'.Xk",
        "tEffY",
        "*W {\\",
        "E&a[8[",
        "@9rOKP",
        "R))WY",
        "M'Vfl",
        "998&>",
        "FI@r!",
        "Eb`&Y",
        "$PhP_",
        "FTP: can't figure out the host in the PASV response",
        "_]xxc",
        "0S1Y1",
        "32U$x",
        "UsMf\\",
        "*fk}K",
        "#.9SP",
        "Y~rT]",
        "rzn6i",
        "H0k{Xc",
        "iBLTEn",
        "?,cb&_",
        "Sq*0Ef",
        "5*6B6",
        "SSSSj",
        "<$=6=",
        "boolean",
        "#;CK#;",
        "7+797",
        "q@LTpP",
        "=)%-Q",
        "=!>K>",
        "YoE,mK",
        "Ex?'4",
        "Ifbn,",
        "&BFYv.",
        ".?AVstl_condition_variable_concrt@details@Concurrency@@",
        "W/r'b",
        "gZ&th",
        "process",
        "x9D*Gt",
        "AECDH-AES128-SHA",
        "lN7p1",
        "o<8f]y8|",
        ":LvFg",
        "%mj#!",
        "BRpt#",
        ":@h8L",
        "7#7l7u7~7",
        "^ul74",
        "value too large",
        "[7QJsr",
        "--*%b",
        "de-AT",
        "LmR.?",
        "void __cdecl boost::property_tree::xml_parser::read_xml_internal<class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > >>(class std::basic_istream<char,struct std::char_traits<char> > &,class boost::property_tree::basic_ptree<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> >,struct std::less<class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > > > &,int,const class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > &)",
        "HA}Av",
        "q4[#3y",
        "177cS",
        "l2 Us",
        "a<-0t",
        "4Muk<",
        "3'3Q3",
        "7).p<",
        "Wx?ym",
        "WseUnregisterPlugin",
        "atn(V\"p~j",
        "40T_d",
        "<\\t!</t",
        "?AkZ2",
        "C[3Vs",
        "PRINTABLESTRING",
        "crl already delta",
        "g!M?&",
        ",%\\%&",
        "}N x<",
        ";mw1V",
        "|_^tN",
        "2XB&Z%",
        "bWK3Qk",
        "z8KET",
        "G?:+8fP",
        "2b/Vr",
        "FCy]1H",
        "Y/)5u",
        "9&9I9l9",
        "yip\\R",
        "90&IO",
        "xeGAA",
        "OnBegin.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "L$X_^][3",
        "5i]fVkU",
        "rUHJ*",
        ")mexhE",
        "(!pR R R`R",
        "l==i_k",
        "e$e,e0e2e6eTeVefele",
        "GetBladeRequiredDiskSpace: cant MsiViewExecute on Feature: %s ERROR: %d",
        "Software\\CheckPoint\\SecuRemote",
        "Zone Labs self-generated shutdown dump.",
        "LBj^~wE",
        "DUKn&",
        "5S3+dC",
        "Oh`0`",
        "l$1d6",
        "4,4<4@4P4T4d4h4x4",
        "<VVFp",
        "8Z%~JVwu",
        "*JEH.",
        "97,]L",
        "*0'y?d",
        "@@_0St",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 GOVERNMEN}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386 T REGULATION AND EXPORT CONTROL}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "POX6TU1",
        "EQ?-&",
        "-Wfqj",
        "DH-DSS-AES256-SHA",
        "jN,/T}!",
        "T/K1q",
        "jCjsj&",
        "cy-GB",
        "Y{2MQ:",
        "^`-<<7g",
        "zWu;'\\",
        "^zja=",
        "I`5eD",
        "0p=x:0",
        "9^^J!",
        "tY%)?",
        "BN_GF2m_mod_exp",
        "rA/Lf7F",
        "I|:N^",
        "Jo\"`&",
        ":vfA+;",
        " 8U(5.",
        ":.Nr<",
        "set-attr",
        "j#+'0",
        "3Dbl\"",
        " disposition is:  ",
        "4MwS\"$x",
        "_WJ+j",
        ":#:<:U:n:",
        "E'TbZ",
        "9DJt*",
        "?X_}Pb",
        "D44`@",
        "i2s_ASN1_ENUMERATED",
        "'BWF6",
        "cC&]Q",
        "Z8_1s3",
        "p_0dOf",
        "m;-bN",
        "GGttDDGGttDBG",
        "TS_RESP_CTX_add_policy",
        "=$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        ">X!1:l",
        "n]Fg=",
        "B##44BB#S",
        "ruT]yv",
        "QsM17\"$",
        ":I:}:",
        "failed to tell Darwin to use explicit progress messages",
        "RKQu]",
        "-Sp,3",
        "`92fZ",
        "ckvZ,",
        "2S&AZ",
        "{DhJn",
        "Changing blades only, without removing FW. Skip vsmon stopping",
        "3H3u3",
        "M[2|c",
        "iu6+.d",
        "C5_A:c",
        "-(Tqq%",
        "HEgs ",
        "A3ba8",
        "SOFTWARE\\Zone Labs\\TrueVector\\Store",
        "l$,UV",
        ":><)Y",
        "= =+=?=M=U=r=x=",
        "5ntel",
        "1b%F\"\"b",
        "5R729W:*=5=H=R=p={=",
        "k(QMR",
        "sN$kj?",
        "\"dLs,",
        "5-#HI[!",
        " 0x47",
        "header too long",
        "WoN,-",
        "C~&s\"P",
        "i+`]Y`MhMlMnMpM",
        "5(515I5O5i5",
        ">73+G",
        "s!:bD",
        ".}$o/X",
        "Dgdc`",
        "TEx9s",
        "LO*H_Ui",
        "zAq&7",
        "}K-1o",
        "&E{^3",
        "DS_CheckIfRebootRequired started.",
        "q_)nRm",
        "T%`a5",
        "_23J.",
        "fp__'",
        "1#1?1E1J1{1",
        " I!-'",
        "LLA$j",
        "0~^Dz",
        "id-cmc-identification",
        "DAx2VV5M",
        "!XTZ\"\"",
        "directory services (X.500)",
        ".\\crypto\\x509v3\\v3_conf.c",
        "q oh5",
        "yUX }`(o{KK6",
        "s),gx",
        "CompareStringEx",
        "N/ZKDr",
        "R\"XQ#",
        ";CmpNw",
        "fvP#?",
        "8 8?8G8j8r8",
        "Network has been reset",
        "FOS`^",
        "NAMM2",
        "Lx%?w",
        "7%abD",
        "T4?*'",
        "DIRECTORYSTRING",
        "BSo._",
        "-F.?M",
        "DEADBEAT",
        "ZE5pb",
        "A|>-pX",
        "OnUpgradePrepare",
        "c=Y*uVW",
        ";!;';-;3;9;?;E;K;Q;W;];c;i;o;",
        "|[Rc'",
        "6a7f7k7",
        "O;4IQO",
        "2^KUJ",
        "b/yE__)]",
        "90949<9T9d9h9",
        "4A4V4^4q4",
        ".?AVstl_critical_section_win7@details@Concurrency@@",
        "dbfSi7.",
        "[w7FN7",
        "i h+u",
        "D$wQRP",
        "5U5_5|5",
        "5%6+666&757f7",
        "1!1H1t1",
        "@YA. 4",
        "SPxxR",
        ":Ea {p",
        "9y&otz",
        "X=->Au",
        "!m_)/",
        "8\"r5n",
        "%@|ek",
        "1*242Q2b2w2|2",
        "@PQF1KO~",
        "&Aem}Io",
        ")Jco'EIa",
        "`P~68",
        "streamed out ComplianceAPI.dll to tempfile.",
        "AES-128-CFB",
        "$oQ@Y",
        "D<[+h",
        "8C9W9j9",
        "4&4-444;4B4X4",
        "4$^)&",
        ":oSku",
        "BRq($",
        "__^`)A",
        "VN0(j",
        "_!|D?z",
        "UY9LU",
        "/gwstats/services/antimalware/1_0_0/log",
        "dsaWithSHA",
        "w.{>:-",
        "Q#}VT",
        "AddDirToPath",
        "jSX{T",
        "V7&*;",
        "2QA2f",
        "]DPxNAQX2",
        "&{mCC",
        "2>3X3",
        "IPxz{",
        "pJ.H7]",
        "MIR[u",
        "*T%MV",
        "t;8]>",
        "6n%qi",
        "zlscv.dll could not be registered with the CheckPoint client",
        "`IYR?",
        "^+z+v",
        "+}HD-",
        "g7UBa",
        "-].@[\\",
        "2 nA'y",
        "3!3%3)3-3135393=3A3E3I3M3Q3U3Y3]3a3e3i3m3q3u3y3}3",
        "ur-PK",
        "]`=KU",
        "hq}y(E3jy",
        "6566vJ",
        " [{m'",
        "*Nq7&",
        "?\"?X?",
        "]Gk.~",
        "i,1\\m",
        "x1a\"em",
        "vbems",
        "%s %s HTTP/1.0",
        "2s3U=^",
        "Cuhj~",
        "On=m_",
        "9!929G9L9",
        "bXD1\\",
        "{KC\\Z",
        ")9S9E979-",
        "(i\\Ej",
        ",5Nl#fn",
        "Q)XQ~",
        "XYob%@",
        "SEC_E_NO_PA_DATA",
        ";7;^;",
        ";i995-Q",
        "Phd<!",
        "security.dll",
        "m5=yZ",
        "rkf;u",
        "$oXcE$h",
        "D$,3|$ 3",
        "e4 mX",
        "NMK-U",
        "\"yJh)",
        "*:r!a",
        "V4_^[",
        "CRolloverMgr::ClearLog():  unable to flush log file",
        "8,9MI2",
        "5,5H5W5",
        "wOn^}",
        "^JR:Q9",
        "Old file: MajorVersion %d MinorVersion %d BuildNumber %d RevisionNumber %d",
        "s->version <= TLS_MAX_VERSION",
        "$x>.T-)",
        "S}TL4",
        "*?\\ID",
        "DO*/*",
        "@SZm2",
        "EC_KEY_generate_key",
        "KQxM}",
        "GeneralString",
        "UninstallIMSecureLSP",
        "mY9&3",
        "w 4&G",
        "D$(PWV",
        "242P2l2",
        "9%9-949[9",
        "Rbg.E",
        "%+,A1",
        "F('V0",
        " sVb8",
        "the traffic at the gateway in order to inspect it, after which it is re-encrypted before it is sent to the server.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1140480\\charrsid15169477 ",
        "failed to set shortcut '%ls' target '%ls'",
        "Custom action: %s",
        ")g!-M",
        "%g#Q,",
        "rB\"#t",
        "a7^sz",
        "TVRl`",
        "T$ 0\\$3",
        "jgjkj(",
        "rKV2wRJ",
        "v>;\\$",
        "?}O\\m]",
        "S1b?>k",
        "RemovePRHelperReg finished",
        "!\\Bsa",
        "!77Fs",
        "L1#{s",
        "XAI<w&",
        "i&':@",
        "aSbV`",
        "?\"?<?C?R?`?v?}?",
        "40M1_1D2",
        "Adj>y",
        "9 <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\\<`<d<h<l<p<t<x<|<",
        "=(=,=0=4=8=<=P=T=d=h=l=p=t=x=|=",
        "v;;Mv;;M",
        "k*#Y)",
        "AI%qK",
        "m2a7a^",
        "^BX5W",
        "A)wS8",
        "8SwQxQ!)",
        "DSh)4)",
        "O|u}b",
        "R Ih/",
        "=$=,=8=X=`=l=",
        "O2 y~",
        "g$nEV",
        "2I6{Wz",
        ">)izJk",
        "PhXWM",
        "I^_*X)\"",
        "7gCa'd",
        "Y3c_xFj",
        "Ewo1'T",
        "G:F\"E",
        "egHH##-",
        "%:dh,",
        "C84GX",
        "Fp``4",
        "4 5*5J5b5t5y5",
        "@N0`-",
        "RKQJSO",
        "FkQ\"l'C\"",
        "IO|Nm",
        "?NXZL",
        "[json.exception.",
        "be2x2/",
        "{xA9e",
        "g6Z*F",
        "Gue,Tf",
        "(H59s",
        "`e[!V",
        "Wq<%HV",
        "r8l%{",
        "It`z%",
        "KY~Lz",
        "qE_]}",
        "l$ WU",
        "Z0\\mL",
        "C10P`",
        "}CKb>",
        "1x$Y#",
        "D$,UPQ",
        "a\"6C}",
        ")/'}$3",
        "en-jm",
        ";Lf1K",
        "+q~lat",
        "gCO%2",
        "^]La0",
        "/iKb3i",
        "g1 gV",
        "&Z$*E_Q",
        " l(e*",
        "E}_`\\",
        "$'h$7\\",
        "tWVWj>",
        ";{6%'",
        "rq+3D",
        "q67KZ,",
        "1*2W2",
        "5-6:7",
        "lstrlenW",
        "@y#Dy_",
        "TDj;5",
        "dJ{Fw",
        "i2&DI",
        "W}YR&",
        "JSA1`",
        "ZC@om",
        "d`xB+",
        "CANT_COPY_REGISTRYFILE",
        "D$lSV",
        "ouAxZ-",
        "B~Bp,7",
        "3/K/O/W/_/c/o/s/{/",
        "VSTORFeature_CLR35",
        "2,2@2S2]2p2",
        "&kA$0|",
        "?VMbg",
        "2''tNR",
        "LX,VX",
        "+(jn\"y#%WKh",
        ",$5n#X{7",
        "error in extension",
        "KG|$|",
        "RDMSR",
        ".n|ic",
        "y}B/q-G,6S",
        "dsOKja",
        "@EWM@GK==W+",
        "rOmzG",
        "T@`1Y`sJ",
        "dy?/O",
        "_X\\W-",
        "PlP?P",
        "=K|x&",
        "-ut[j?",
        "l>3LFk",
        "m]{JB",
        "oc(H[",
        "X[%CUp",
        "tht)Q",
        "j'=U!",
        "IMSECURITY",
        "cslNMaOM",
        "Tz7Z:",
        " 7uB ",
        "#hJ,vN",
        "=MB{zm",
        " 5F}MOUO]O",
        "$3wg3",
        "WKu{5",
        "i\")R/",
        "E5;Tu",
        "p&;rd",
        "?_p\\\"",
        "2.3}3",
        "`1~He",
        ";*<8,",
        "PRIV_INSTRUCTION",
        "[Self Validation] Detected",
        "iqJ4nO",
        "F@Ww%",
        "J}IugrD",
        "8Q8_8m8r8~8",
        "HADDPD",
        "Ql`bY",
        "?\"(G7u",
        "set-rootKeyThumb",
        "~uGY5",
        "cJbKH",
        "ec_GFp_nistp224_point_get_affine_coordinates",
        "R9tB5",
        "^=v6x3",
        "Found Check Point SBA upgrade product code",
        "9P\"tHFp",
        "A!'}w;",
        "D$<j\\P",
        "u%j0Zf;",
        "nS`KV1",
        "-]tTr",
        "<securitypolicy version=\"1\" >",
        "wqyT_",
        "cmd /c \"del /F /Q \"%s\\System32\\CPEPC_PLAP.dll\"\"",
        ">*>F>b>~>",
        "*M!-e",
        "#caE#",
        "Hx_06",
        "_\\!~u",
        "8P#$W",
        "J@JTJd%",
        "\"Y.3}6:",
        "VF5|A",
        "\"=&IV",
        "*E,AN",
        "PEr0u",
        "x#2:1",
        "> ?@?H?P?X?`?h?p?x?",
        "ffj-w[5",
        "U=pC}",
        "m(}6R",
        "-\\sts>",
        "~OQE.",
        "`klmk",
        "vX;|W",
        "nD?Hsu",
        "_+2@k",
        "|[0Tw",
        "unable to create an SSL structure",
        "P/b_3",
        "09Tb:",
        "<4<<<D<L<T<`<",
        "*BTiD",
        "5/5?5K5Z5@6G7U7",
        "T-!{lRgJA",
        "dx9u9",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 s prior written approval. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "\\$#<D",
        "+n'A;1",
        "t6|^)I",
        "8'9<9E9b9",
        "|v3?+",
        "+%?'y\"",
        "_#'4-",
        "gk{h>Kg",
        "RT@|Z",
        "'p~es.?",
        "zMSG.",
        "Miy F",
        "<<tYW",
        "hM0eW",
        "S}Y:n",
        "dxjd$+",
        "D'`_\"",
        "3T$,3T$",
        "}:;2|6",
        "=NM7d",
        "+xHz\"",
        "CY>yJ",
        "4uWj$3",
        "VTr9K",
        "ASN1_sign",
        "Lv)h!",
        "$r'q<",
        "A1@P:",
        "Nq=Jo6",
        ",YNN]",
        "($6#_c",
        "&{)2{",
        "bQ6@I",
        "V^fmX",
        "1|$0#",
        "OrFL;",
        "~f5Ml9\\3I",
        "ANu]g",
        "rMf3P",
        "YimPY'",
        ".-ah$$*",
        "os]%z'",
        "]mA_`=",
        ":?;R;l;s;|;",
        "wwwwwx@",
        "08^7(\\l",
        " noOfficeMode is enabled -> about to write it to registry",
        "Q]xTPg",
        "Excess found in a non pipelined read: excess = %zu, size = %I64d, maxdownload = %I64d, bytecount = %I64d",
        "]^M<4",
        "wkC=3",
        "\"P#[&",
        ";H;b;",
        "~C#_m",
        "\\mirror",
        "VOYjk",
        "wuauserv",
        "GU?$9",
        "lwo4N",
        "2 2$24282H2L2\\2`2l2|2",
        "wm:-V",
        "5O6k6",
        "))Dki",
        "g~69S",
        "+N[4=",
        "d2i_ASN1_type_bytes",
        "#Ny!d",
        "K3I0w{",
        "n}KO\\",
        "lu.&a",
        "94h(=",
        "VvVtRz",
        "9V(~>j",
        "j-Zf;",
        "{!)}p",
        "*%v\"5b",
        "YFDAt",
        "<;<K<S<",
        "3e3x3",
        "#A:Ic",
        "SEED-CFB",
        "]'*R{",
        "<M*\\!}",
        "9 9,9L9T9h9",
        "laj=U",
        "'dSEh@#.0",
        "FtPWW",
        "*.log",
        ">*FGu!",
        "RunClientHotfix InstPrep patched the client. Installation will finish now.",
        "B|jp8",
        ".ri7~",
        "p:pHqTm!",
        "%L B)jc",
        "Ht=0~!",
        "5o689<9@9D9H9L9P94:",
        "auvuL",
        "{ivc''",
        "=@>S>",
        "`j&tm",
        "Qs2v`!",
        "0A0v0",
        "C`1{LPQ",
        "PKCS12_gen_mac",
        "`n1YH",
        "j<D)/",
        "Yb2P0",
        "Failed to create Record",
        "\\b\\fs28\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext0 \\slink18 \\slocked \\sqformat \\styrsid13065977 heading 4;}{\\s5\\ql \\li0\\ri0\\sb240\\sa60\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel4\\adjustright\\rin0\\lin0\\itap0 ",
        "sy~qW",
        "0+,r'",
        "2O O/,",
        "trustRoot",
        "3L$D3L$01L$",
        "Error removing registry value:  ",
        "8K9~9{:",
        "]X(T1",
        "CMS_set_detached",
        "$UhX|&",
        "Ks h)2",
        "c6+0@+.`",
        "bHs&`",
        ",=GgJ*}",
        "*i=1z)",
        "Y`Ya,",
        "6qbMa",
        "/b4wWlN",
        "cfR!F",
        "R@1:d",
        "GetDriveTypeW",
        "|3G3P",
        "zh-SG",
        "H1P1\\1`1d1p1t1x1",
        "=FK{P",
        "TJ21P",
        "NPN, negotiated HTTP1.1",
        "yI yMZ",
        "3Lv?r",
        "jvL/{",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid10102966 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6752132 ",
        "MO$m(e",
        " 0xa5",
        "xK;5 ",
        "mcP1J",
        "hKaY+",
        "=Jclv",
        "ero.3",
        "N;gyz",
        "CurrentMinorVersionNumber",
        "232L2e2~2",
        "#&D7 ",
        "<tSC<",
        "8OPNw",
        ")j&,\"6",
        "jCjyj%",
        "NpNrNtNuNwN{",
        "5Fx;<",
        "JLw9h",
        "Program Files",
        "`M ol",
        "NH\"},",
        ";%<Z<",
        ")j)(9",
        "{\\flominor\\f31548\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}{\\flominor\\f31549\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}{\\flominor\\f31551\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}",
        "</UpdaterSettings>",
        "`3Z[y",
        "camellia-256-ecb",
        "'{.|^",
        "zcvUr",
        "***** OnCancel started *****",
        "OfIf'",
        "DPpcp",
        "Xgejm",
        "NqR.=?{",
        ">k=.QC",
        "<4<<<H<t<",
        "yz{z}z",
        "GlobalFree",
        ":g+pjk",
        "%L,ja",
        "auML-",
        "\\D6X4",
        "w)t!=",
        ";uWU ",
        "kC>.#D",
        "k<m15+",
        "_h&0.",
        "]Uy^M",
        "0wWM9",
        ",yZaL",
        "$#x{A\"",
        "ZrmbS^",
        "+Sx(D",
        "R(Z0Qi",
        "id-GostR3410-94-TestParamSet",
        "8#9'9+9?9]9",
        "0?4.o",
        "sx:YC",
        "n\\)t<",
        "Fn\"}5a",
        "9EQX]b",
        "E<\\}N",
        ":y|xY",
        "usqE{`",
        ":Y).n",
        "FlushFileBuffers",
        "__std_exception_destroy",
        "sha-256",
        "fr-BE",
        "zr(*Cw",
        "}zV3w",
        ";';B;];",
        "RulesInsertObject",
        "hLDgL",
        "Accept:",
        "failed to execute view on Registry table",
        "Unable to add dump callback handler",
        "B`>OC",
        "S\"C3r",
        "Cu[ar",
        "SOFTWARE\\Zone Labs\\ZoneAlarm",
        "@vBUn,",
        "6`$S\"@n",
        ". 7{9{",
        "reqCert",
        "pD2.t",
        "StopCipollaServices",
        "<9<E<K<t<~<",
        "w%A1~",
        "p0u]{",
        "base64 encoding",
        "sU\\/l",
        "(V[moT",
        "bkL3~4",
        "^o[qp",
        ">1?Q?",
        ";G@92",
        "1-[C^",
        "system lib",
        "|o@tc",
        "=xi.N5Q",
        ".95aA",
        "rW;:)",
        "<;>G '",
        "f]wK/",
        "\"tIJtF",
        "}jV2u",
        "x1hN[i-`",
        "3zOU*~",
        ":K0dR",
        "767O7h7",
        ": :l:",
        "!4UxzJ\"(",
        "4'6WJ",
        "\\Check Point\\UIFramework 2.0",
        "n,gNK",
        "||gEu",
        "4$4,484X4`4l4",
        "-`!^~&`",
        "error adding recipient",
        "}8(`r",
        "jVh`B%",
        "zffLC",
        "2u;-iW",
        "l[3Qu-",
        "j|B#!-",
        "2'232W2",
        "/Bj/3j",
        "z+-^@#+",
        "\"KGOiq",
        "Not a directory",
        "https://d.symcb.com/rpa0",
        ".`<PX",
        "ED0BU_",
        "G+0<n",
        "keyid",
        "/1Noh",
        "IiG{x",
        "<pqA1",
        "4'414;4H4Q4Z4j4",
        "<$<,<4<<<D<L<",
        "4yu(}",
        "1;2l2",
        ">Of<!$",
        "EXPLICIT",
        "%O0HG",
        "pdUKbG",
        "pqq44",
        "K7rdh",
        "\\lsdunhideused1 \\lsdlocked0 Salutation;\\lsdunhideused1 \\lsdlocked0 Date;\\lsdunhideused1 \\lsdlocked0 Body Text First Indent;\\lsdunhideused1 \\lsdlocked0 Body Text First Indent 2;\\lsdunhideused1 \\lsdlocked0 Note Heading;",
        "o>[,nW",
        ".Dg{Bsv",
        "dI\\O80",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\F-Secure Anti-Virus",
        "Z` {\"",
        "l|+FZ",
        "ct_cert_scts",
        "}\"}.}0}>}D}J}P}^}f}r}|}",
        "6Z7Z>Z",
        "jJYf;",
        "]7=H ",
        "839_9",
        "Q6$Og",
        "ILh(2",
        "?La~&0aJI",
        "E\"piI",
        "OO;L=",
        "]tCIx",
        "XbL5n^",
        "#2tT$`WgyUU7",
        "_EVn*sr",
        "qYYVHE-",
        "T$8jc",
        " -policy ",
        "uK,47",
        "<B9~*",
        "Bm3oM",
        "auvB&",
        "G<PVU",
        "%s IAC %d",
        "\"]t:O",
        "?q3m!",
        "D[~.D",
        "UZdz@i",
        ";~_tc",
        "bad write retry",
        "hLFvf",
        "=>=R=",
        "?$?0?<?H?T?`?l?x?",
        "5Urw%",
        "5yGj_",
        "mT{\\b",
        "about to InitializeNoOfficeMode...",
        "<mPKzD3HUm(",
        "<z#44",
        "0/S]k",
        "tvVWPS",
        "53vRb",
        "&Of.Z",
        "                                 H",
        "expected ':'",
        "SE42r",
        "[])?;v<@",
        "b^Vn,",
        "F5a @`ym",
        "KIE;)",
        "CANT_LOGON_TO_VSMON",
        ".mm^UkH",
        "UlKv2",
        "e,+8^",
        "GC;\\$$",
        "\\f1\\fs20\\insrsid3017503\\charrsid15169477 NONCONFORMITY IN THE }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11954918 HARDWARE }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3017503\\charrsid15169477 PRODUCTS, ANY AMOUNTS",
        "121N1a1",
        "iR|@9",
        "^[_]Y",
        "K#SXru",
        "0=a\\o",
        ".KnN`",
        "FV#=h7",
        "}mC*A",
        "=/F` ",
        "&L5AX!",
        "=E|G3",
        "K`(,('657%%%&SA0a/",
        "z?dmv",
        "&`n>I",
        "fZM0m&'",
        "])jNX",
        "~C|csH",
        "3RFEujKMj",
        "V -gP",
        "MWj_}",
        "FfyprLP",
        "~g3,S&Q",
        "A*Y(iwy",
        "<N8qA",
        "do21a",
        "i6f:?",
        "59nV]3",
        "3\"3B3",
        "COS+]",
        "zc#k~",
        "zM\\{}",
        "0#1h1u2|2",
        "K5I#)",
        "M1,-/Wgk",
        "5G6h6",
        "3tT9O",
        "vU>1M",
        "ks-Nm",
        "\"]/g+u",
        "t$(hd",
        "FDE_Remove starting.",
        "lx=QB",
        "2Jc+_8O",
        "sA-8'",
        "Diffie-Hellman part of OpenSSL 1.0.1t  3 May 2016",
        "IY+4&1L",
        "m(mR%3",
        "&*dV >",
        "x500UniqueIdentifier",
        " 0x37",
        " `<Ey.",
        "XRls`N",
        "\\R&oZ",
        "CMS_SignerInfo_verify",
        ">)>\\>",
        "(GG]%",
        "N360=+",
        "]M[HS",
        "OoHG\\e",
        "b\"(k<",
        "|;]zq",
        "ZOiK8",
        " a;z`",
        "****************************** VnaCleanWithDir ended **********************************",
        "5$5C5",
        "k)l1V\"8",
        "263H3e3",
        "{']OhOlOtOzO",
        "experimental",
        ";Sk%W",
        "02.n.0",
        "\\lsdunhideused1 \\lsdlocked0 List Number 4;\\lsdunhideused1 \\lsdlocked0 List Number 5;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 Title;\\lsdunhideused1 \\lsdlocked0 Closing;\\lsdunhideused1 \\lsdlocked0 Signature;",
        "PEX J",
        "1i2Y'",
        "registeredAddress",
        ">0>4>D>H>X>\\>`>h>",
        "GmHSaW",
        "qZHyf",
        "x9x~h",
        "&_<0@Np|",
        "i!?=QK",
        "HM7!d",
        ",yl>B\"=",
        "xEJFh",
        "20282@2T2d2p2x2",
        "{hgZ/",
        ", value=",
        "b$Q0/>o",
        "+C%$O",
        "Ez,[6?",
        "\\j\\5rR0_F",
        "0kP#Sp3@l",
        "Unable to parse FTP file list",
        "6-656E6V6",
        "X+#PG",
        "ChM?>U",
        "s&^| h",
        "zx~xx",
        "(p1>D",
        "0NMyo",
        "rt-Q)",
        "'5JX4*T",
        "cms_encode_Receipt",
        "`managed vector destructor iterator'",
        "W=6TW",
        "kjSb\"",
        "$E|zbGF",
        "LEAVE",
        "%rZN<T",
        ".?AVinvalid_link_target@Concurrency@@",
        " P>uR",
        "R@^.x",
        "*)$%Gf+,&",
        "8:8f8",
        "M{M%J",
        "slovak",
        "n%yQ;",
        "2$Y~$",
        "( Cth",
        "C9VOG",
        "2$2(282<2@2D2L2d2t2x2",
        "!Zt;iPe",
        "=UFlcS",
        "D$HUPP",
        "0gt3i3M",
        "m\\;'Y@",
        "G*6U2",
        "6D6O6",
        "=F[hK",
        "cH~Y:(",
        "nbHfw",
        "****************************** ComponentsInstall started **********************************",
        "yD7Gh",
        "m95#-",
        "[\"O5)",
        "Se~&TY",
        "isspace",
        "nx*'<mZ)",
        "Q-Wa4jB",
        "b{+NH",
        "'pJ.0.`",
        "i*UfF",
        ",A%E ",
        "oP$vY",
        "sha384WithRSAEncryption",
        "2F3Y3!4",
        "FeatureSmartDefense SD=NO shall not run sd_uninstall.bat",
        "aMy8l",
        "[2e!j",
        "[~r4`",
        "DlBBg",
        "}re3!g",
        "X&+IX",
        "S [cRhZ3",
        "Iww2VH",
        "(B9Jf",
        "cant check dh key",
        "^,,tb",
        "hC+Ew",
        "BA=X[",
        "h_o$H",
        "Ij1VA",
        "eup6d",
        "tC97u?j4",
        "2\"2,2",
        ".4LI7",
        "2#2?2[2w2",
        ".?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@",
        "nJb!C,",
        "Q>&+]",
        "O\"GX`",
        "unwrap error",
        "tsize",
        "X`o}|",
        "~&~eH",
        "-42zR<",
        "w4s@NB",
        "7gw3f_",
        "uD:Sp.",
        "M(Ua1",
        "j:Yf;",
        "*sI2/",
        "/J^82k",
        "3~{c}",
        "VO1h:",
        "\"]\\bl",
        "QHu$'",
        "%c%`meu",
        "qmn*Sc",
        ",}o-;{",
        "8 `B)",
        "RegOpenKeyW",
        "Nh|N|/",
        "\\uFTF%>",
        "[)T=[",
        "DOF8?",
        "UNUSED_1",
        "&$&,&2#8G",
        "bY|r 4",
        "1w/4:",
        "j]TE5TQ",
        "eW}dG",
        "~*Fs1B",
        "K'na{",
        "3L$41L$,",
        "1X* %",
        "eio[&(",
        "X1a5P3",
        "[<mOCB|",
        "W/jb!",
        "7yAS2U5~",
        "dz(ZdY",
        "Property %s for UpgradeCode %s temporary inserted to the Upgrade table. Err: %u",
        ":(:4:T:`:",
        "1(M_:",
        "Stopping epnetflt returned %d",
        "+Ox`=",
        "l4_=d@c",
        "8@vc ",
        "<\"<;<T<m<",
        "x{ = ?",
        "B2iRI",
        "_udpn",
        "?ffffff",
        "UvY_a",
        "bad address",
        "RClR+",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7224833  taken on the data,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238\\charrsid12465679 ",
        "1<1c1",
        "&fO/h",
        "6!nm9",
        "Field Type: %s",
        "+>Z3K",
        "_%p$yS",
        "UWs_f",
        "/Ryv55",
        "!~3I.",
        ":.;{;",
        "34Z|PXJ",
        "L$d_^][3",
        "2[ZU5",
        "4{z.i",
        "GOST2001-GOST89-GOST89",
        "failed to open view on database",
        "Bz{()",
        "XFZ =d",
        "Failed to create DA\\VsDrInst registry key.",
        "ASN1_seq_unpack",
        "*:l)P",
        "oMhjzR",
        "r;l&AI",
        "%hM(Y",
        "ou0C$Y",
        "[\\3Qh",
        "vl\"ho",
        "sdl.png",
        "|;Z~7",
        "*QAev",
        "KK;E?",
        "0_MGH",
        "=#=/=4=9=W=a=m=r=w=",
        "uz-UZ-Latn",
        "5Oy{e",
        "tBjf@h",
        "l?l[pXl",
        "tV k!(",
        "\"0]Qh",
        "gethostbyname",
        "@iw'&1 ",
        "`vcall'",
        "O:+Eq",
        "2C2c2",
        "7,787@7d7l7|7",
        "R]hi(",
        "w)'dA",
        "k2>+N`sc",
        "Ji]#Io",
        "7y*Cb",
        " 0xe0",
        "TLS change cipher",
        "M|)HT",
        "323R3~3",
        "_q zs",
        "4E1Yc",
        ">,>0>4>8><>@>H>`>p>t>",
        "k\"`}f",
        "mrcr<",
        "]G&&G",
        "epklibproxy.sys",
        "qINsyh",
        "8 9n9v9",
        "!m6QK",
        "DqqHpb",
        "M QNy<X",
        "*;89n",
        "h4O,Pxj(U",
        "]=G+.",
        "dar<[",
        "TzF[H",
        "wAY\\om",
        ":?9B:",
        "E,PVVS",
        "The service stopped",
        "7\"8c8",
        "(^O8Q_",
        ":?t-/BY",
        "TJ\\%<",
        "m*E4'",
        ")zJI 5",
        "IjLJF",
        "^x,L&",
        ">Px'S",
        "ONcFE",
        " $G{W@+",
        "C1A5G>;",
        "Dwdnp",
        "jqfSPV",
        "5-WzW",
        "+yB4r",
        "Friday",
        "?''|'",
        "G( u.",
        "bV']O(S",
        "n:AP.",
        "xTQ^N/",
        "Uw0h^",
        "Y]F}7",
        " ^u,m%",
        "1i1r1y1",
        "graph",
        "5#5F5i5",
        "\"\"97v",
        "WKcW=",
        "t,wV4",
        "2%2P2f2u2",
        "rlME/Ot6",
        "zg\"M7",
        "F'YN,!",
        "`aG/:L",
        "4$4P4",
        "/,6FZ\"",
        "dtls1_client_hello",
        "7 vT$",
        "|5$BJ",
        ".yse^",
        "M(mpj",
        "Yh6CnF|",
        "&z 4d#",
        "Cx2.>",
        "7(7j7",
        "RozZ\"`",
        "bYg,+L#M",
        "2cLlT",
        "08A{dPS",
        "a[Mlb",
        "'}$3b!",
        ">,><>@>P>T>X>`>x>",
        "dRgx5",
        "mZ~3G",
        "Unknown registry key root specified for secure object: '%ls' root: %d",
        "@7)t*",
        "mz?\\j/",
        "L@:pn4h",
        ".)brzvN+r;",
        "iGu\\:",
        "-9lP<a1ncB",
        "9P0Mp",
        "{B)D?",
        "i*lAa",
        "[F8P*",
        "PatchOldInstHelper",
        "6*6/6C6Q6p6x6",
        ">twvX1",
        ")MLY5W",
        ">p[7;",
        "RWv14",
        "securityAlertIcon.png",
        "VMS_UNLOAD",
        "2&2K2",
        "8(8h8^9",
        "Y\"fUz",
        "vi|Au",
        "9$909P9X9d9",
        "m{,qYb",
        "Gs-]R",
        "Duwijj50",
        "*Eyy>",
        "t1hLz&",
        "crZf,",
        "bad fopen mode",
        "bUDEH",
        "failed to get QtExecCmdTimeout",
        "t$hSP",
        "cms_RecipientInfo_pwri_crypt",
        "Sq[)L>njR",
        "9t$,t'^_]3",
        "9,_gK",
        "=8~3~to",
        "C6kY=X",
        "=ZZ l",
        "8 8$8(8,8",
        "RQ85]",
        "-',$0",
        "BlU9G",
        "GetStringTypeW",
        "id-it-currentCRL",
        "B-409",
        "FSINCOS",
        "IsBadReadPtr",
        "1x4@VQ#",
        ";f<]=",
        "T$$3L$8",
        "1>1l1",
        "9Gn|~Ll",
        "L?Tw0",
        "4J,&$& &f&",
        "T+7&!3",
        "*h'`?$",
        "OnSuccess",
        "4l<\\T_TE",
        "tk3ml|:",
        "}_,?g",
        "</rule>",
        "record length mismatch",
        "cere1",
        "4&444B4U4\\4y4",
        "pNQEA6",
        "w2o/_z\\",
        ";:`1l",
        "DNS:%s",
        "EFRCommit",
        "Q{ec<",
        "FmA#%)",
        "//^u5T x",
        "&\"FSDHFR",
        "qi&Uc",
        ",6l=\\",
        "LeM]N]O]P]",
        "listen",
        ";E<U<",
        "SecureCustomProperties",
        "d2i_PublicKey",
        " 512c>",
        "8 8$8(8,8084888<8@8D8H8L8P8T8X8\\8`8d8h8l8p8",
        "jk!7aY",
        "O SUw",
        "zYR=|",
        "u3vJYuI",
        "cs:4\\",
        "_cBY`:N",
        "Y[rXS",
        "~P+/w",
        "> ?g?",
        "Q'Hnjpk",
        "Ov)YK",
        "Wp9.)",
        "rq\\c^",
        "D$,9Y",
        "} Q1}",
        ";qp\\5F",
        "?h*f&h-",
        "&!n1[=(",
        "LLCH~@",
        "XS]U ",
        "failed to to enable application exception",
        "int_field3",
        "{z<<W",
        "pKl#dK",
        ";*<Q<\\<l<",
        "=MQ*]",
        "=]~msG",
        "?!mCD",
        "'U;yp",
        "xV%Pup",
        "|1w[8",
        "|tyur:n",
        "W<jI=",
        "[oxZ]",
        "7VewS",
        "^^_^(;",
        "=*=9=C=M=\\=i=y=",
        "9,fR_",
        "c'|1\"",
        "@/|D$",
        "i-bs$?@",
        "ZZ8%j",
        "1)&{{",
        "=po(?a",
        "Fh0_aF",
        "<D*Dp",
        "BAD_RETURN_WAiTING",
        "eEvTi",
        "IU^kF",
        "6_lAk+,",
        "VWj j",
        "1)101f1",
        "unknown error",
        "101]1s1{1",
        "e_Im!g",
        "RDf)2.",
        "<)<5<C<O<S<[<e<k<q<",
        "cA+FC",
        "9 9H9O9l9y9",
        "!@.')}",
        "<\"=C=m=",
        "5y`x%cf",
        "rY#>5",
        ":2;L;r;w;",
        "sf7'g",
        "l7B~W",
        ".?AVSchedulerProxy@details@Concurrency@@",
        "j-swM",
        "4 4,484D4P4\\4h4t4",
        ":0;M;",
        "O:rR{",
        "C}ab9",
        "bLb+`",
        "'[ek6",
        "$8< t",
        "HIz(0#",
        "hJ:'%",
        "z7)!v/",
        "=,=4=;=H=O=Z=a=s>}>",
        "U6t7N",
        "d;]7(",
        "invalid time format",
        "&BYQ4KBe\\",
        "A8\\,r",
        "oC'Gc6",
        "Gdd]D",
        "?z<p0]}s",
        "go&<J",
        "&5]'E",
        "setct-AcqCardCodeMsgTBE",
        "A(;rD)C*H",
        "6$606P6",
        "K]gy']",
        "7N]>.",
        "DeleteFileA",
        "NRfOu",
        "$`Z(+",
        "7$7,747@7`7h7x7",
        "CLIENTVERSION",
        ".3u3J5",
        "7zww{",
        "c`K4w",
        "T0B7a",
        ",W4Y!",
        "failed to get firewall exception name",
        "T1X1\\1`1d1h1l1p1t1x1|1",
        "}#-xe",
        "C} &-",
        "j(P7)",
        "iQ` l",
        "'aERj",
        "jV_f;",
        "illegal Suite B digest",
        "me#RA",
        "Couldn't resume download",
        "ComplianceAPI.dll",
        "rgC\\e",
        "issuerNameHash",
        "Failed sending HTTP POST request",
        "6<9K9",
        " d%&al",
        "/qFe<3",
        "[hKuq",
        "8u9y:",
        "u\\(&Ov",
        "j-0DJ",
        ",2mV9R",
        "<2<S<{<",
        "\\system32\\zllictbl.dat",
        ";9;S;",
        "?K>&12",
        "a{2zS",
        "*{ORTx",
        "CERT verify",
        "kw;L\"",
        "n%1X1*",
        ",F?lX0lX",
        "QVndJ|,",
        "|I;?.",
        "&=nck",
        "5,5P5\\5d5|5",
        "j|!6rc<",
        "SAVI_CUR_DIR",
        "11161;1P1g1",
        "C1A5G~;",
        "9|c)-",
        "Lo7g68h",
        "DF.o11",
        "haI)|pL<",
        "\\PatchOldFdeMsiFiles.txt",
        "(R/~GX2",
        "4h8l8p8t8x8|8",
        "(u[WbI",
        "L=z k",
        "PQh|S!",
        ";UU(]VKh",
        "!0b\"bJD",
        " 0x54",
        ".html",
        "3$3D3P3p3|3",
        "a#vA?Y",
        "l&.>g",
        "^~3i0h",
        "fppW/",
        "+8H*}Y",
        "SlQ<o",
        "JYO,XH",
        "V>_q'",
        "U\\W{W",
        "H+-Ix",
        "sI.fo",
        "dMq>:",
        "1);y9",
        "[.-C-",
        "uFVWhd",
        "9kZ'_",
        "|A(I@\"",
        "M+$~.",
        "jm]$`",
        "[yt40",
        "AllocateAndInitializeSid",
        "2Tk;K",
        "nZbFm",
        ">&?2?",
        "[QX-\"n",
        "`*&/QK",
        ";9se*$",
        "r:t=]",
        "%2xky",
        "q}s}t",
        "8FKtS",
        "KdymD",
        "m&SDT",
        "z9oDHe",
        "~)Ot ",
        "yE2\\Z",
        "7$?(?X?l?p?",
        "Connection #%ld is still name resolving, can't reuse",
        " C\"C-*p",
        "'7U5c",
        "5,505D5H5\\5`5p5x5",
        "k|vm4",
        "*|}-z",
        "Dg.||Td;",
        ")MM*X",
        "oK!u`",
        "5+585P5Y5i5p5",
        "I[9o^p",
        "100-continue",
        "{<pf~",
        "no cipher set",
        "vv == NULL",
        "- floating point support not loaded",
        "nq|y<",
        "LWPh{L",
        "Sb*(7-",
        "pwinst ",
        "QqGbC",
        "3+3W3",
        "|?!CL",
        "uzyR|R",
        "\\Xm>$-C0",
        "Pib/d",
        "_=<h.",
        "F9{#h",
        "-Y-1'7",
        "ia5org",
        "JhK>&",
        ".edata",
        "|yM9'",
        "XGghc",
        "gM2\"|t",
        ".<&is",
        "Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)",
        "CorExitProcess",
        "0<0!_",
        "&Q umkL",
        "er of the provisions of this Agreement shall remain in full force and effect. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid14380787  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "OQGOL,8",
        "[LICENSING] new license",
        "ccs received early",
        "i@\"xN",
        "[R13D",
        "failed to get xml file for XmlFile: %ls",
        "1rMsU)",
        "Received last DATA packet block %d again.",
        "7l4\"(",
        "<*<Z<",
        "ER+$_N",
        "w?*J ",
        "11ErzQ",
        "Fe0a\\\\K",
        ":5/^{",
        "V-a=e=o=",
        "tTa>S",
        "[Zz`K",
        "jAj~j",
        "?#?5?B?a?",
        "[5[uw",
        "Hc>7)",
        "AYqtYN?:",
        "=)>3>>>",
        "^!^Y^i^",
        "zDdJ}",
        "^SAF(",
        "y\\=J-",
        "R/;AB",
        "{3289703B-61D3-428B-A496-24FF37BCE3C6}",
        "We<:Y",
        "bW)V7",
        "2T2q2",
        "c/\\VAX",
        "mD#hp",
        "<szmF",
        "7k{xg^",
        "2tL~!",
        "uva>3Uk",
        "_h[! JWT",
        "3Oy:a",
        "a_LeW",
        "mV)+)K)k6",
        "6)ZK'",
        "y>[BM=)",
        "HhFxGuX",
        "(X^R8",
        "' G7U~",
        "8&.<U",
        "Sz 1}",
        "ZoneLabs\\vsssopro.dll",
        "FUCOMI",
        "Lh7E0",
        "@F,`\\",
        "\"ToUR",
        "STORAGE1",
        "<sXh/",
        "yjhc#",
        "P#>tg",
        "-=[ (",
        "D?D.,",
        ";+y-;",
        "w\" `Ga",
        "9R9u9",
        "gMt9w",
        "5\"6B6[6",
        ">JuDAH",
        "\\$(VWQh@",
        "!vh=:",
        "j]s(?",
        "0K*bY",
        ">n0O\"9",
        "_cGR`",
        "9&9?9Z9_9{9",
        "$r*tEtD",
        "$Q+grGw",
        "PBAjI",
        "57,9N",
        "<*kOt",
        "F(WWV",
        "CNh5V",
        "JBw1.%/S",
        "vh.zJ\"",
        "U~Dh<;",
        "WweL\\",
        "{X^-/",
        "FC`$B",
        "{,u6z",
        "CHECK_PADDING_MD",
        "9 9J:",
        "V]TyN@",
        "858@8T8_8n8y8",
        "0Vf3d",
        ") does not exist",
        "jfjhj",
        "d*\"m!",
        ",o!_-",
        "success",
        "\\vsdatant.sys",
        "4$j6a",
        "1)111",
        "zW})J",
        "/f/{=a",
        "5 5@5L5l5t5",
        "XW>$;P",
        "3/tt%Pj~",
        "V[W[X[",
        "rYZ%4",
        "wixca.dll",
        ">,.X|",
        "F'H'J'",
        "4Kiqf",
        ":%:/:::N:m:y:",
        "jvjom(",
        "7Vsd=",
        "5hTZn",
        "PEM_read_bio_Parameters",
        "Going to delete folder ",
        "IvRW)",
        "y6O7x4",
        "P={')4",
        "Ayakr",
        "I2B_PVK",
        "unknown pkey type",
        "sknXz",
        "\\hUNH",
        "!qB\"(z",
        "X*R,g",
        ".x5G?.",
        "e'G*r",
        ">7I*l",
        "jkhFoo",
        "vGUGuG",
        "9p8Oe",
        "=mL)K",
        "Home Premium",
        "v<+JI",
        " 0@:z",
        "P=Dy7",
        "M',')",
        "DM2X0<F]",
        "N(09^,",
        "h^~lj",
        "StopInstHelper custom action end.",
        "userPassword",
        "CLASSES_ROOT\\",
        "_&v>S",
        "%H : %M",
        "RW*Iy",
        "u~F0%T",
        "rd0g+",
        "Sy&ym,",
        "jgjyj",
        "#qIF:<O",
        "n$=4n6@",
        "MD5bE",
        ",,Au]Z",
        "=vtRl",
        "S2f#K[2",
        "4QzP|@3",
        "1,1F1y1",
        "1,232",
        "hTgZpQ",
        "PRv=L",
        "(Ai4%",
        "WW-<(",
        "contents",
        "eck Point, You may request a License Key from Check Point which if provided to You will allow You to use the Product after such evaluation period, but only subject to all of the terms and conditions of this Agreement. In the event that You determine not t",
        "767D9",
        "_mtZRU",
        "n?x{T",
        "_lock_locales",
        "^ElY#",
        "Z-'$H",
        "4<g_~'",
        ".[O*do'v",
        "Y(m:|",
        "eD:<+",
        ")\\`+]n",
        "JzWJW",
        "\"ez.ffe",
        "u9:77K",
        "1e_YZ}",
        "jq7v`",
        "PZ<?x3\"}",
        "XoD1Z",
        "2&\\)j",
        "=L1#.",
        ";PhpG(",
        "msSmartcardLogin",
        "hXz+Q",
        "&AwCA",
        "9Vw]g",
        "u^gi ",
        "WD_CheckFolder failed on ownership.",
        "Apzpe",
        "C4?K3",
        "Z5Wqd",
        "t3VQUW",
        "userc.c",
        "/(.,?g",
        "6e22206267313d226c743122207478313d22646b3122206267323d226c743222207478323d22646b322220616363656e74313d22616363656e74312220616363",
        "A3!/'.",
        "+=TsS",
        "v_X~7",
        "D3=NQ3!",
        "AE9a]L",
        "jLvYU",
        "(0'yX",
        "Success to validate password",
        ">4=04",
        "E&0&D%",
        "9,9A9L9R9\\9w9",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\sa80\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid3736522 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607 6.6. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12151078 You shall }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "TakeOwnershipOnFiles: ",
        "FSS{t",
        "6.6I6",
        ".8|ZK",
        "6xTp/aB=",
        "<$<<<L<P<`<d<h<p<",
        "<$<0<8<\\<d<l<|<",
        "6!zoa",
        "Hl1vs",
        "3%4f4",
        "$L4]8",
        "sUZAX",
        "4bzds:R",
        "D$@SU",
        "I+n<X",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        "sig_algor",
        "j_dnJjQ",
        "4D<zG",
        "NoGracePeriod",
        "b1r=^",
        "=4&jp",
        "#T$L#",
        "<0EIl,",
        "'vPfA",
        ",L.,RX",
        "\\d2Pl",
        "6m4@{",
        "j?f'=",
        "aKv.Z",
        "1:79$",
        "CAMELLIA-192-CFB1",
        "BD:}f",
        "> >J>o>z>0?X?",
        "bOg+C5K",
        "+vZ(T",
        "n=Nw+",
        "1R'!a",
        "7>7x6",
        "PVVVh$",
        "AA.lA",
        "\\sp;Y",
        "GXFX/",
        "uqA%C",
        "i_{i`",
        "no_proxy",
        "tlsv1 alert record overflow",
        "OaaJd",
        "&9[v|",
        "ZlL4D)",
        "KKq/H3",
        "=$=L=Q=^=",
        "p>ojt",
        "~i!.5O",
        "1T2\\2d2l2t2|2",
        "tV%.#",
        "!M#=w",
        "tb\\_iT",
        "D2I_ASN1_HEADER",
        "b_'h_",
        "xTI'c",
        "h,LGH",
        ")qa)f",
        "Failed to run MsiGetProperty to retrieve NoKeep. Setting to 'No' as default.",
        "aCfqC",
        "e@SOi",
        "TxNak",
        "`5y?,kM",
        "!lAmD",
        "F-BF5",
        "wqYIq",
        "V?jrc",
        "vx8J@",
        "BD&}Z",
        "FH#Hr",
        "i8Mj<",
        "-H/a3A^jZ",
        "':TVsO",
        "RME9I",
        "l$ )_",
        "GetCurrentProcess",
        "e&e.e6d>%cK",
        "2n''Lc@",
        "#lDNQ",
        "/_^][",
        "dGQO7&",
        "FlB'qD",
        "9frzx",
        "[n<R:c",
        "N=8B$",
        "wN=e=",
        "f(t+:",
        "D$ _^]",
        "vo:=L",
        "DSO support routines",
        "<1<M<i<",
        ".YNYeY'",
        "-R8Tj",
        "*@I)!",
        "tS$rU",
        "@1F8Y",
        "A|(*_n",
        "39qKb",
        "gi#e3-",
        "9FHtV",
        "certificate verify error",
        "P 5h4",
        "2 hM)",
        "~n_]\"",
        "28lCU",
        "Uh-$$9 5",
        "=(v%$",
        "/$YOt?y",
        "%F|K|",
        "Y0YPO",
        ",n\\[a",
        "'G38F",
        "PKCS7_SIGN_ENVELOPE",
        "@k@CF4v",
        "Cl8|Y",
        "#aD_D",
        "k%qU(=",
        "|cL{7",
        "2#303X3r3",
        "YBGfb'",
        "1q 2W",
        "y_$ZR",
        ":~uVG%",
        "$fq0y",
        "}70=`",
        "JoSjfz",
        ">Y!tg",
        "\\,Tq/",
        "- [qcH",
        "[PERFMON] Performance provider unload",
        ";F^PF",
        "122}2",
        "\\Qewo",
        "lbV1i9",
        ")RURI",
        "91:A:6?H?",
        "_Wl\\~",
        "y;[~vp",
        "^Rvl{",
        "K@ 2P",
        "`dJ&eJ",
        "S~Z2F",
        "cWz<v",
        "y=V/e",
        "p6P:q",
        "MpM9]",
        "O,)}q",
        "Qj%}1",
        "..n;]",
        "Cq3C4e",
        "eX&3N",
        "XlGXtZr",
        "j)ERD",
        "1Z1i1w1",
        "63738B8X8t8|8",
        "klupd_klif_klark",
        "456S6",
        "1t2x2|2",
        "(\"a}Om",
        "PUR<]",
        "SN&7&",
        "kEECDH",
        "\\\"V6H",
        "a6\" E",
        "%c0Ol",
        "-4126HIPz",
        "subtree",
        "Failed to create message window.",
        "T$T3t$$",
        "pLuD-",
        "vsutil.sys",
        "K_B2V",
        "no conf or environment variable",
        "x)?z}Bd",
        "5P6k6",
        "<,v^h",
        "OCSP Nonce",
        "I(JBP",
        "`@AA*",
        "h0\\yXp7",
        "z:3ctb",
        "~vj]u",
        ",>SU?=",
        "4/}Qun",
        "~3A<Q",
        "BrowserScv.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "~5pVel",
        "8PNH20",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\urlfiltering.cpp",
        "pT2c&S",
        "gq:2k",
        "SVWtW",
        "WSEUpgradeKeyInstalled()",
        "H/(O(o(",
        "kkTmI",
        "CRolloverMgr::TruncateLog():  unable to position read pointer",
        "5?6V6",
        "Z4a^V",
        "\\/<:{)",
        "5ZX<=",
        "[LICENSING] Reviving beta license with %ld days left",
        "Nqr#f",
        "-K60v1i",
        "3`4s4",
        "&Y\\[c0",
        "a7qtOh",
        "~8866v>>>>>>>>>>>>>>7>F",
        "|Pd{p",
        ")5n7;",
        ")')w,",
        ">^8v|",
        "PCMPEQB",
        "u3jPj",
        "UFh'N_x",
        "|<:.]\"",
        "=A8c~t",
        "?SetEnvVar@@YAJPAD0@Z",
        "f*3_!",
        "1H1b1p1",
        "Mc5F7",
        "dQ9-!",
        "record too large",
        "k>728D",
        "Z\"Eyeu",
        "3Dpe\\",
        "F;7es",
        "Ci~_>",
        "vJ-b+",
        "wWw.%",
        "u(lobu",
        "1GYv#",
        "Uninstall",
        "'\"7~oX",
        "(5@Ctc",
        "A*zb?",
        "2$2(282<284T4X4p4",
        "YXzs2",
        "=d%OUN1?vOM",
        "VS_fu",
        ";*_'k_0",
        "t[<Z2",
        "#rH*:>",
        "V@j0P",
        "4X{[g",
        "Load key:  ",
        "=y0&=",
        "PN/}W",
        "+N6BxP",
        "L4Vx!Y0",
        "'~{`g",
        ",\"YdZ",
        "2T4q4",
        "#!n:M",
        "\"u3|w-",
        ".`OTF",
        "zF2j6sA",
        "cJ]nO",
        "rtD|C",
        "....................",
        "/q.0Kd,",
        "FqMzq",
        "TyJd,",
        "ekn,7MO",
        "illegal time value",
        ")&5jV",
        " dm8*c",
        "4VgQK",
        "qw27f",
        "^V/DE",
        "9%9+91979=9C9I9O9U9[9a9g9m9s9y9",
        "(.\"id",
        "`vector deleting destructor'",
        "(f8}8rx",
        "U%A7>",
        "CurrentMajorVersionNumber",
        ";^?mYb",
        "ZNS \\",
        "+t`^l",
        "N3-$?",
        "StopABService started",
        "WJKd~i=V[",
        "R9dZFv",
        "[Q6#?",
        "{{uVq",
        "''-xc",
        "9 9$9(9,9094989<9@9D9H9L9P9T9X9\\9",
        "|/O]8",
        ":%:O:[:s;",
        "h]YK+",
        "__CxxFrameHandler3",
        "~~Jckq",
        "gYYFY",
        "GetLastError",
        "'JBNQ",
        "v'4}=",
        "RoF0_",
        "WcQK]",
        "ASN1_seq_pack",
        "Qg(|?M",
        "n-2c6",
        "U!ZlgE",
        "?Eh'J",
        "=n2alN%",
        "`vtordispex{",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<unsigned int,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,unsigned int>>(const unsigned int &,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,unsigned int>)",
        "<2}:}B}J}Dx",
        "3.K2f",
        "P5qeeZk",
        "/N=/'+",
        "QjUkf;",
        "<)=O=",
        "organizational_identifier",
        "1}#i^VH",
        "=I-~=",
        "p7#h<",
        "U>p,5",
        "txRvn",
        "=$=,=8=|=",
        "8&8L8Z8o8",
        "Q*JG&",
        "jAjlj",
        "HKLM\\SYSTEM\\CurrentControlSet\\Services\\vsdatant has been removed",
        "c2vF ",
        "GJ#F!",
        "$h\\1G",
        "7=c.:@Q",
        "\\f1\\fs20\\insrsid2566336\\charrsid15169477 a}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477  Hardware Product that you do not own}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3736522 .}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "<4<[<i<",
        "GOST94",
        "ecp_nistz256_points_mul",
        " ?M:w",
        ".\\crypto\\asn1\\a_time.c",
        "xC_r:",
        "(_/+,",
        "YY_^[",
        "FaultAddress",
        ":YT&4",
        "j.vszz",
        "d {_;",
        "3#4R4",
        "q^nMt",
        "3!3,353:3@3]3",
        "FWFreshAfter:  SetProductMode",
        "K:*q5",
        "GSSAPI handshake failure (empty challenge message)",
        "6#$3f",
        "CIETL",
        "q_60D",
        "jf2nq",
        "CPvt|",
        "P5s?-4",
        ".cCELu",
        "Z=BfNlV",
        "\" /qn",
        "tawQt",
        "#`N(w",
        "I2S_ASN1_IA5STRING",
        "(NYKDY1",
        "Pn*FN]H\"o",
        "^`^v|",
        ";giCv2?",
        ".jk`F\"",
        "pHook->dwReady is not zero. dwClientCount=%d",
        "jRufz4SH'",
        "c8`bg",
        "O^ObSi`O",
        "Q\"Kd\"",
        "D$0_[",
        "6,`f&T",
        "decrypted key is wrong length",
        "*R$YQ",
        "l%D;m",
        "SxM!6\\z",
        "\\t(}Ku",
        "Wv4uU",
        "+;j406",
        "L2QI5",
        "3Sr8Md",
        "UP*r?",
        "\\zonelabs\\avsys\\libeay32.dll",
        "f5r3!`",
        ")XG@A",
        "XWH! b",
        "cppsm_tool",
        "-K#qP",
        "EOej~",
        "&rVHI%W",
        "PX43/0",
        "3$34383H3L3P3X3p3",
        "}g2o1",
        "]lid8",
        "camellia-192-ecb",
        "=np;}",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regkey.cpp\" line:  383",
        "jPkPo",
        "[w?^%E",
        "kZ=)q8",
        "vZXdV",
        "el`Ka",
        "b!!&J",
        "7Ej2Vg",
        "u_e)`",
        "0qL][",
        "j5unl6",
        "?+?8?l?s?",
        "JOT0w",
        "14f G",
        "P%pLF=+",
        "cR_{O",
        "181I1b1",
        "3k{P3]",
        "p(cuh",
        "D{R={",
        "xWUhN{",
        "q%WlM8",
        "JYd7Z",
        "|-BN(x",
        "D$$3L$D3L$",
        ")0>7S5",
        "V5+3C",
        "j^4VF",
        "r(f;E",
        "\\$@SP",
        "erO4,",
        "]%s7[",
        "Ok7--c",
        "<F)(X",
        " I; 6$",
        "4T`N(",
        "W\"Qiy",
        "N|vs&l",
        "6#lp9",
        "'J Y+",
        "L.yr(",
        "=RDpY",
        "\"JHHkG",
        "bAylJD",
        "6G7R7_7q7~7",
        "not key agreement",
        "$SVW3",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Services\\Pending",
        "4DZKQ",
        "D$ _^[",
        "WaLLa",
        "w~|\"7",
        "SetFileSecurityA",
        "Wd.Mp9d",
        "M M0M",
        "2bC{SH",
        "_}i}s",
        "Vm1&/",
        "t\"_^]3",
        "I+y++.",
        "znQ:q",
        "8l;*WI",
        "V:f[C",
        "949<9\\9l9x9",
        "T-Mz-Ro",
        "{>4B:",
        "j`DzGvV7n",
        "!J>zC'",
        "VhQ1Q",
        "B6LWK",
        "%s%02X",
        ";D$ s5",
        "w22!7f",
        "10141@1H1L1`1d1x1|1",
        "GqQXV<Yy",
        "69HNnG",
        "Z~id,",
        "6CPL#j",
        "ca-ES",
        "nEaDi",
        "?,?0?D?H?\\?`?p?x?",
        "~7S\"7dF",
        "DCm9Vwv",
        "g]Z1y",
        "7g5qw",
        "~ +~4+",
        "H):zf",
        "9 9$9(909H9L9d9t9x9|9",
        ">2>]>",
        "N2222Yt",
        "mJ$Rt",
        "e\\hndX~",
        "(cq6I",
        "rEO}$ \"",
        "n4}d1J",
        "L$(UQV",
        "C,PUW",
        "<96:S",
        "7*818<8",
        "ym<R[",
        "xWxXh",
        "r:a-L",
        "sslserver",
        ">[?{?",
        "k!=/(In",
        "%s\\MSI*.LOG",
        "=Jc()",
        "ZxRBd",
        "G.zHv/c^G",
        "SEC_I_SIGNATURE_NEEDED",
        "Tx\\cSu",
        "-PJN!",
        ".?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        "X`l3#-",
        "g2lb~T",
        "3W&%wp",
        "tpwv,",
        "qQQiJ",
        "dfAd#",
        "oVSZC",
        "FAILED_EPAM_SHUTDOWN",
        ",\\[8;",
        "m}63.Q",
        "\\?F|b",
        "2Kpl1",
        "khP6C",
        "cS\\;P",
        ".;.}J",
        "0FL$E ",
        "};l,53",
        "T$@3t$",
        "Y&e6bq`",
        "4Xz{F=",
        "LINEBUFFER_CTRL",
        " -j/+",
        "!5!A!I!O!Y![!_!s!}!",
        ",@>/*",
        "FISUB",
        "X509V3_EXT_add_alias",
        "4LPK!",
        "j:Zf;V",
        "WpJYc",
        "QtExecCmdTimeout",
        "r=U3z",
        "gDD-SA",
        "+\"N$J",
        ";'w]r",
        ")n6P[",
        "Loaded zlcomm.dll",
        "Wz{G^",
        "o'y&e",
        "5NH>g",
        "BXnNw?i4",
        "364;4",
        "4-JJD",
        "6:T\"\"",
        "en-JM",
        "Y6jnG",
        "$)SsXY",
        "y^/gV+",
        "8]U\\3",
        "jMR%r^H~V",
        "n^#]&",
        "q1#%D",
        "Ia,DxeZ{",
        "9S&49S",
        "4tm#s",
        "7C`RX",
        "`w'dEA",
        "PAQM\\",
        "n&v[>",
        "{o!v;.16;})",
        "n)W+WY",
        "N=lM%5",
        "Filename too long",
        "U39{e",
        "=[e7YA",
        "Sv*Vrq",
        "Failed to send SSPI encryption type.",
        "72\"W ",
        "2xX!|",
        "xppwpp",
        "6`/T5",
        "D$,[_^",
        "=)%NVT",
        "q|5-p",
        "z%4ig",
        "1`HUg?",
        "cmd /c \"rmdir /S /Q \"%s\\Temp\\ics4x\"\"",
        "$Z;LT",
        "\"S1X@",
        "jFWkx",
        "tw8^lu",
        "1I\\@Hw",
        "vouVQY",
        "Finishing install",
        "D@G!V",
        "'=p#|a",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\featureantivirus.cpp",
        "VX{jT",
        ">@+,eSA",
        " _\"Uu",
        "xljDu",
        "o@?aw",
        "3vsS@(",
        "PreInstallCheck: Reserved space for AM signatures: %I64d MB",
        "9 92979<9Y9u9",
        "{MkT;&",
        "t~}D*\"",
        "*PjTW",
        "AJ|eN",
        "int_field2",
        "YSZdG}w",
        "]_}}W*K",
        "@Y <(",
        "EgTjL",
        "g&>0q\\",
        "8{]~cX",
        "parse tlsext",
        "PQVSW",
        "fNn88D",
        "ASN1_verify",
        "I2Y+9o",
        "x9!Cun",
        "929_9",
        "#m=_>",
        "ZwYieldExecution",
        "w:y~J",
        "/OFArz",
        "{`ek<",
        "%s service changed to manual start",
        "A:M@+",
        "expected a section name",
        "3\\$ 3",
        "UCI4}wV",
        "o/Q;x",
        "nuBS^",
        "+F*d9p3",
        "([U7K",
        "BN_mod_sqrt",
        "YT3Sgl",
        "navPs",
        "3*3F3b3~3",
        ";kWed",
        "Z=^Jb",
        "F#s]@(",
        "XSp4K",
        "87$6Y|",
        "r1B*Q",
        "O,>d7",
        "343@3`3l3",
        "XB{!i",
        "J[h#-",
        "Oz>PS",
        "l+lkl",
        "\"[=BSZ",
        "\\:MvdRlr",
        "O+krp",
        "0&0/080A0J0S0\\0e0h1l1p1t1x1|1",
        "q-te`)J",
        "pOY(X&",
        "BM.>s",
        ")?0!XZ",
        "r{BZ}J",
        "lA*vi",
        "~1u;I*8",
        "CVTPS2PD",
        "3k5r5i6p6",
        "rv2]F",
        "g(Q.A.Ut",
        "~|wz\"cx",
        "r7$v(-",
        "wv6!6",
        "}N1\\a",
        "0BI :",
        "` fs,sv",
        "flUI[F",
        "Call interrupted",
        "3)3w3M6",
        "oRCl*",
        "N@Rshw",
        ";{$XM",
        "];wc`",
        "PKEY_DH_KEYGEN",
        "K-Dr0",
        "55Z<z W7",
        "u 9D$",
        "sig invalid mime type",
        "?]\"A!",
        "rZkCbt",
        "('fJ.th",
        "Nn[qC9",
        "7;8F8[8t8",
        "T$4_^]",
        "jOhPS",
        "'p{C}",
        "Failed to send SOCKS5 sub-negotiation request.",
        "H-EPD",
        "]G.%6",
        "~<$NV",
        ";(;,;<;@;D;\\;l;p;",
        "plzHe",
        "E[3xl",
        "failed to read target from custom action data",
        "X!o3Y",
        "<Wv%h",
        "\"2m_){",
        "7ozvK",
        "E-[#)1",
        "(+*@l",
        "#*jBk-",
        "gK99r",
        "9$]w.",
        "eEhWO",
        "Firewall blade is going to be added",
        "U6&]O",
        "T}nZh",
        "&5ND8YM",
        "Z6dQ:3",
        "'A,?d",
        "kjQjr",
        "cgU_OM=",
        "h}^]\\",
        "A<S,o ",
        "J6[vy",
        "4%~P\"~",
        "7V'S8",
        "4JuKb",
        "FWUpgradeAfter:  SetProductMode (again?)",
        "-]Dao",
        "CFS~bo",
        "KgKU!",
        "O1o:/3t<",
        "AlR,}#n",
        ",PO3#",
        "V_Zk%",
        "z*5%6",
        "b^'~[",
        "sidebarButton.png",
        "@xQVc",
        "7,7074787<7@7H7`7d7|7",
        "setct-ErrorTBS",
        "5$7,s1",
        "i9\"eC",
        "D$8hP<!",
        "strchr",
        "Helper::isInstHelperRunning: Trying to open process w/ PID = %d",
        "`gp.i",
        "CANT_READ_TABLE",
        "`K84U3[",
        "z%{50e",
        "%Q7'SU",
        "cGvDe7",
        "6X*~i",
        ".?AVThreadVirtualProcessor@details@Concurrency@@",
        "V++}V++}",
        "VerifyVersionInfoW",
        "C(1CH",
        "L)n{zS*",
        "=Ml'(",
        "B5>!/bw",
        "{MX+\\L",
        ",YPwq",
        "B\"@b3",
        "6[7n7",
        "%s(%d): OpenSSL internal error, assertion failed: %s",
        "widWB",
        "Timeout on debug mutex",
        "$Da6p",
        "2/3S3X3",
        "+m_&e",
        "C^[1fX",
        "/;Bqg",
        "wl9b&2",
        "h6J>o",
        "y:-$l",
        "SQRPW",
        "Loj}H",
        "G^#&&b",
        ";|;}:~",
        "],uh-F",
        "<RH0[>",
        "P^^~R",
        "/fhj$",
        "{ND=O~",
        "`(P((",
        "=W06U,",
        "@K@.$",
        "fJ5%Ku",
        "jqjuj!",
        "pPhj`",
        "internal list error",
        "|VpPr",
        "cPLNaTs",
        "&c fvr",
        "_is_double",
        "&.@4'R",
        "m[s\\)",
        "BP/y)b\\",
        "3G3z3",
        "0(1@1[1f1",
        "=8^E=q",
        "COd52",
        "<SN1foO",
        "2AcUk",
        ":9Vdk",
        "t$<VUU",
        "dlhNv_",
        ";7.L2L7p:",
        "AspOe",
        "SUVWh`:!",
        "SymantecPKI-1-5670",
        "{:e[e",
        "ySzcz",
        "t$ hh",
        "|$ CW",
        "0 0]0x0",
        "~Gg`/",
        "iB(hx",
        "-DEAi",
        ".]a=1",
        "rJhsv",
        "~qK>z",
        "iIRN|EK",
        "#G&d9",
        "&\";L)OS",
        "eprb~",
        ".idata$3",
        "Enterprise N Evaluation",
        "?O~\\M",
        "vDZe,",
        "j-y5<",
        "fts o",
        "7^:3{",
        "b=rF'",
        "qM[8\\A",
        "cJc)eGw",
        "rYB4v<",
        "EC_GROUP_set_curve_GF2m",
        ":C:h:",
        "8(8H8P8X8d8",
        "{5091E222-902F-4000-A97F-ECEDE5211191}",
        "[VSDATA] Rules_XML::get_next_tag t8",
        "\\zonelabs\\zlupdate.dll",
        "o!f+tM",
        "9F*\"_",
        "Yw!g`K",
        "Tt5gC",
        ":7:r:",
        "KNLc$",
        "p|W$1",
        ">o2#c",
        " 0xd0",
        "3`4d4h4l4p4t4x4|4",
        "7(7@7I7Y7f7~7",
        "tv}d_x",
        "J}CU[",
        "kwM;a",
        "dF%%W",
        "2/.Nx",
        "win.nt.vista",
        "6P.?x",
        "gn)E&",
        "cT}s/\"",
        "l4i(}L",
        "Session: %s",
        "`88zaeA",
        ".?AVentropy_error@uuids@boost@@",
        "&_ofS",
        "71n<V",
        "J=1U4",
        "ll\"&R",
        "5_X$5",
        "y#zr%",
        "Ld_h3{,",
        ":0:D:h:",
        "tF38K",
        "t3VPW",
        ";PcV|K",
        "lIS'\"",
        "G{AUVM",
        "8Z879",
        "Failed to save value \"VersionBefore\" into registry. Error code: %ul",
        "6[x%F",
        "+{z#}",
        "JAwq8",
        "LoC|<",
        "mp@MW",
        "_KJ=T",
        "9B9t9",
        ". -Uo",
        "kgtvtW",
        "KuJ;k",
        "expecting an rsa key",
        "d[<48",
        "Phh-$",
        "p-_8i4",
        "222F2U2v2",
        ";g:4W^W",
        "Tp7Hz",
        "t$ SV",
        "`\"D&:",
        "{uo6H_",
        "5dS!EHqq7",
        "(Ni8g>g&&",
        "5i6$7.7e7o7",
        "unimplemented digest",
        "%Q%d%",
        "+45Ma",
        "L4`T;",
        "g/CbHc",
        "o-\"WU#4",
        "J]YR6%",
        "2u5'E%",
        "GENERALSTRING",
        "wttC+",
        "jn^#.T",
        "@~6pn",
        ">N#,9!",
        "failed to set string value at position %d",
        "9:9T9",
        "cert already in hash table",
        "MeyP|",
        "&vFx&m",
        "IZHrK",
        "r6<tz",
        "`/!t{3xx",
        "w80Frg",
        "W{asjsy",
        "K$*;+",
        "W8^(u:",
        "5^N92",
        "Y sk|",
        "o.ykh",
        "B9\\%W",
        "=\"=5=",
        "*+<{l#D",
        "no matching recipient",
        "|}PR)l",
        "k^{_A",
        "(p;$e",
        "dz>TI",
        "+HeI}",
        "b)c*0",
        "cACompromise",
        "}M>{~A5",
        "@&<nq",
        "w\"ejp",
        "o #xp",
        "IO?e}_l",
        "5+5G5c5",
        "Unexpected return value from prompt to continue.",
        "00-50-56",
        "%2$GB",
        "8(979@9",
        "DR6h$",
        "3 3(30383@3H3P3X3`3h3p3x3",
        ">@>k>",
        "C!wl\"3",
        "=#>y>",
        "KMB-m1N~I",
        "2/3v3",
        "1f}E.",
        "m5dU]",
        "helper::loadVsutil()",
        "<+>E>",
        "?!?8?[?p?",
        "id-smime-spq-ets-sqt-unotice",
        "szGameExeFullPath",
        "CU,OLr",
        ">5 ~V",
        "K;C)is",
        "id-GostR3410-2001-CryptoPro-C-ParamSet",
        "y{yTx",
        "uH58X",
        "Rw%#{",
        "KFm|<",
        "HpW/e",
        "        Issuer:%c",
        "B]eVX",
        "f33Uf33U",
        "~)p$w",
        "_initterm_e",
        "trac.exe",
        "Js/Jv",
        "!D-l\"",
        "<VeriSign Class 3 Public Primary Certification Authority - G50",
        "sapi_",
        "D2rBi",
        "G6y9a",
        "stLDp",
        "KNx^hc8i",
        "1xA^@lCA",
        "4{FlM",
        "$5~]]7;",
        "P+di>p",
        "@@0qT8",
        "GQi;=",
        "M 1.b",
        "tst info setup error",
        "%]890",
        "Netscape Base Url",
        "mJP*1",
        "c\\'>8UW",
        "mD@fS7;",
        "p,`aE",
        "#<(e\\",
        "SA7OoKS4,",
        "bmN:R",
        "\\zonelabs\\updtrsdk.dll",
        "5tf<k",
        "Z5?Bk",
        "r~T\\h",
        "InstHelper.exe.",
        "um\\K;",
        "*<{@<^=[G",
        "^eH1p",
        "b<go>",
        "F9gb4",
        "=m-ac",
        "050G0]0b0g0",
        " 3-_\\",
        "|>45T",
        "T$T3t$$#",
        "cB\\VlT",
        "1(Yzh",
        "8 8,888D8P8\\8h8t8",
        "JZCZY",
        "WfW3rI",
        "Hostname mismatch",
        "b:S9(",
        ":gjs|",
        "aZUxQn",
        "Yk\"_;",
        "+Dp3^",
        "F[.?[",
        "cmd /c \"del /F /Q \"%s\\Temp\\ics*\"\"",
        "1>1\\1k1~1",
        "j\"Xf9",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Product\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  means t",
        "PADDUSB",
        "f4.DK",
        "<(<0<4<@<H<L<X<`<d<p<x<|<",
        "se5ox",
        "4^}fM@J",
        "yNQ+1M",
        "p'tnNN*",
        "j<f+mV",
        "rKuN.>#",
        "do+u(",
        ",$l-h",
        "0Xs1,",
        "=R=b=",
        "5lkxWu",
        ">l>p>t>x>|>",
        "uy)hC",
        "%W]>#5",
        "1FrJR",
        "[{Yi2*",
        "]]%7.",
        "eu@N+",
        "Ull0d",
        " '.V9G",
        "attributes[0].name",
        "fgOke",
        "t$<WW",
        "jxTJwc",
        "othername",
        "Yb6|E",
        "B <K ",
        ".o*3bzPe6",
        ";H+#Q",
        "5rPH`",
        "y)JLSf",
        "%s:%d",
        ";fq@v",
        "2><I7",
        "Service %s is active. Wait 1 second.",
        "tkg.x",
        "xh3|.",
        "<Hh|dIMz",
        "dITRedirect",
        "<;[[[\\",
        "BNH(3",
        ":h;r;",
        "ThVVEIa|j4",
        "+Z-e[Y",
        "No data record of requested type",
        "1)DmO",
        "%2H/r",
        "O%.yl",
        "*WHW!",
        "!z@nnpw",
        "/Vcw|",
        "L$,Rj",
        "FindNextFileA",
        "1H4L4P4\\4`4P9T9X9\\9`9d9h9l9p9t9x9",
        "@3J@f",
        "ENGINE lib",
        "h4UUuX3e",
        "Y4XF@",
        "OSm]<",
        "Shutdown finished",
        "m@${>3",
        "]qjFM'",
        "D!UJS",
        "protected: ",
        "[r=vV",
        "fUvX?E,I",
        "?HZ}C",
        ",oydn",
        "GetClientType",
        "=&?2?",
        "`hz_i[",
        "1~-d8",
        "J]6mU",
        "$qzvO",
        "w6#CM",
        "`local vftable constructor closure'",
        "X>G}g",
        ":F:`:",
        "l9H9{\\",
        "6&Ss(",
        "\\Zo\"E",
        "479C8E74D27ABDA4F89B9D4FFE5C6A5B",
        "public key encrypt error",
        "y%7Y\"",
        "Y>5m=",
        "rcL;1",
        "Sg62?",
        "8&959e9",
        "949L9P9T9X9l9",
        "j[BI{",
        "o1Q5fs",
        "BSj-O5",
        "-4esl",
        "=$=,=4=<=H=l=t=|=",
        "jAjdj.",
        "need at least one digit after '.'",
        "\\3eL%",
        "CR%d&",
        "|vm(;",
        "3mvZMiZ",
        "l,1N*S",
        "aadedb3d1441a89b6a929501833b197fee7b9641a3503739e57c732a59b1f7da1cf8a73b1f9bcca0945b874d4393dbbf10b1680f66bbaa5d6f96e77b6f59113d",
        "rF$}4",
        "GetFileAttributesExA",
        "h4T,-t",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "9(9?9c9k9u9{9",
        "{<)H/",
        "`)UZx,",
        "H[:1N",
        "error initialising drbg",
        "00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899",
        "3|p9*'",
        "{G3gf",
        "w3g~h",
        "%04x - ",
        "74#7Q`",
        "> >(>,>8>@>D>P>X>\\>h>p>t>",
        ";)<6<><Q=",
        "OK3|(!",
        "kZCvH",
        "SY~At",
        "QU3XmYUY",
        ">c6km@",
        "@o!f\\",
        "]yu=k",
        "D::)[",
        "Not After: ",
        "3Q4d4h4l4p4t4x4|4",
        "e}=2I",
        "-m1*xc",
        "ecdsa",
        "xy)o7$P",
        "cmd not executable",
        "set-policy",
        "\"jf:5",
        "252M2b2j2z2",
        "#qXuQ",
        "N@_^][",
        "~\\V\"v>5U",
        ">gN ~O,",
        "\\3l[<|t",
        "QW+[M",
        "E.g0.",
        "BDe=S",
        "\\%02X",
        "WRITE_PENDING",
        "ZKZSZ[]c",
        "c5Yz.",
        ",19 Z",
        ":iOaq1h",
        "I$p31",
        "EVP_VerifyFinal",
        "R[L0O",
        "/(.Y+;EiH",
        ":mDX<",
        "uuYYQ",
        ",6L;;",
        "U(dZO",
        "|}]c\\",
        "TLknN",
        "F4h P'y",
        "3'VCo",
        ".)AX.",
        "XHd2J",
        "D@gqo",
        "-8(\\\\VH",
        ";H@yr",
        "OnFreshAfter:  RunVsmonInstall",
        "9[[Z?",
        "*WWA2",
        "y|9~tS;",
        "2kW0{",
        "P&p06",
        "Ca*#Y",
        ">R?\\?y?",
        "NOT UPGRADINGPRODUCTCODE",
        "gost89",
        "Unknown error %d (%#x)",
        ".?AVSchedulerBase@details@Concurrency@@",
        "zkqi'",
        "Bk9W[+",
        "WQqGL~l",
        "6r\"/Y",
        "GKzEH",
        "5'555J5\\5o5u5",
        "NHarF]N",
        "%8BB)|",
        "qI_j'X",
        "2!3.3L3\\3",
        "h\"@[ZY",
        "F/W7K",
        "CsiX$",
        "*~eBU",
        "|\\;V*p",
        "ConfigVsdataParams:  ConfigVsdataParams started.",
        "[s~`;U",
        "<KAVFileProtectionOff>",
        "?*?T?",
        "!(QD`6",
        "sL{#w",
        "g5LR5",
        "[(_jH^",
        "SQRTSD",
        "rP)M;",
        "nukVu",
        "Y^<T!",
        "Hl=)?m",
        "+u+dP",
        "H.{z'",
        ">/7QWg",
        "o&y1&e",
        " and web traffic may be inspected. Please consult the }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238 Check Point }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238\\charrsid12465679 ",
        "A%|5l",
        " to perform its responsibilities under this Limited Hardware Warranty, Check Point may ship all or part of the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2260672\\charrsid15169477 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "J~@2,U'v",
        "libutil::CalculateHash",
        "Did not find EPS InstallProperties",
        "H:u1V",
        "R])03",
        "0$0,040@0d0l0",
        "I@9zL",
        "ni16$",
        "RFi5(",
        "bad digest length",
        "ERROR ",
        "\\7_()e",
        ":ss*'",
        "7P8ab",
        "rA83[",
        "Hf(`e@9,`",
        "W.j;0&?",
        "invalid signed data type",
        "*ClB3",
        " WinUpd",
        "rA*Tf",
        "OBJ lib",
        "z8AMc",
        "%BwXNe",
        "S%UQq|J",
        ">&>N>",
        "E|CN`y?",
        "?8?J?U?h?",
        "t!bP^",
        "0K1o1t1}1",
        "&D6w4",
        "S Jc[",
        "yZK?oU",
        "DqI##",
        "'o&2Q",
        "9c+ w",
        "3n\\lR",
        "8;9E9",
        "notBefore",
        "H<rSJ",
        "lJh%V",
        "~pT9.",
        "46vuC",
        "s}$7[",
        "-,<VT",
        "N^Lj8",
        "RCOu<",
        "q ]r1",
        ")1;t8",
        "<!<-<6<;<A<K<U<e<u<",
        "8.O'@",
        "6(6D6`6|6",
        "`b*$yu",
        "ua6_d",
        "$V4S'",
        "-=\"hFS",
        "3 3(3,383@3D3P3X3\\3h3p3t3",
        "%_\"/H@XU",
        "meTeTit2",
        "vFmo^",
        "tS6yE",
        "&ez4c",
        "<EMPTY>",
        "RFC 5639 curve over a 256 bit prime field",
        "(4\\K5",
        "~D?:9",
        "DQNt-",
        "SECG curve over a 160 bit prime field",
        "=\">?>",
        "<Up7 ",
        "dx`ZQ",
        "S|zF(",
        "p0uZU1p",
        "(K(>p",
        ">\\@y.",
        "P?x}:#",
        "]OdnTQ",
        ".?AVIHashDB@@",
        ">[,pX6",
        "kEvg.",
        "\\drivers\\klin.sys",
        "^)unV?g",
        "Unspecified",
        "`JeN>",
        "iG.Y2]/",
        "#U5ww$@",
        "$?%?&",
        "P*@4[u",
        "SSL_use_PrivateKey_ASN1",
        "\\WE}W",
        "R^W#/",
        "t$WUV",
        ".\\crypto\\ec\\ec_curve.c",
        "w7-5_",
        "H?;Px4",
        "iRijj",
        "connect error",
        "pz%k'",
        "<xt\"<Xu!",
        "tgFa~",
        "S|4wRK",
        "$FvP#",
        ":<zk?",
        "5$sz.",
        "IE\"V]1",
        "'h\"L)~;6",
        ":t/$QD^DBW",
        "BN_mpi2bn",
        "port=%ld",
        ".}4_R",
        "U77[G",
        "j~r=\\5m",
        "EJOmS",
        "Unprocessed type %d",
        "4$4+42494@4G4",
        "x38}D",
        "LYu.Bj",
        "Zl?'u",
        "*3r@]",
        "\\)#:S",
        "}^`0t7>",
        "tLM*rk",
        "A83 A{",
        "D$$SVh",
        "4wG+e",
        "Yq307",
        "y{KCK",
        "=;=W=s=",
        "<i*s>",
        ";0;>;H;e;k;s;",
        "l|Eq ",
        "<}`uDJ",
        "status expired",
        " 6*&`",
        "767^7",
        "<E;-9",
        "t^Wu6",
        "=QT=%t",
        "op{01",
        "$-c_`1t",
        ")/b\"A_O#",
        "void __thiscall boost::uuids::detail::random_provider_base::get_random_bytes(void *,unsigned int)",
        ":';9;S;k;",
        "ZAN*zH",
        "z\"+ :mB",
        "uZ!#8B",
        "/Y:@}",
        "\"gTV=",
        "8^l12",
        "v~R@VG",
        "'tzL\"",
        "v\">m-",
        "9hysZ(",
        "8=9O9",
        "nbFwh-F",
        "(-GH}",
        "sr_y%",
        "R7a(-",
        "?5KGE",
        "?&W-x",
        "aEL!H.%!\"",
        "604qP",
        "[\"9k:2",
        "G4GDB",
        "N%|.2",
        "*0}yt",
        "D$LPQ",
        "DH/RSA",
        "hZ,+(Nw{",
        "Kj\"~$",
        ".?AVptree_bad_data@property_tree@boost@@",
        "YSHbY+",
        "[lMp9",
        ">@?J?",
        "i=q=}=",
        "Ev[|P&V",
        "boundary",
        "`:F4\\",
        "|[htw",
        ";A$vH",
        "PlYi`A",
        "F}cP3",
        "_OtN{",
        "9%$Ckh",
        "h~}pb",
        "uZ?]O",
        "`PXC{",
        "DVJU1`4?",
        "x5rAG :",
        "JC>; M",
        ":q5@\"a",
        ")]bCOA",
        "hySKJ!",
        "SVhD=L",
        "6/656F6L6_6e6v6|6",
        "Mikk4",
        "J+Z(\\M+",
        "330810235959Z0j1",
        "!+y8.1",
        "{JSW.t",
        "*lK8r",
        "Ho8XN",
        "'Symantec Class 3 SHA256 Code Signing CA0",
        "AKL)q",
        "SOCKS5 GSS-API protection not yet implemented.",
        "TB^FX",
        "cms_set1_keyid",
        "uDF1%_",
        "Replaced",
        "394?4",
        "m.opa",
        "mCTU5\"",
        "Kne|~",
        "ssl_add_clienthello_tlsext",
        "f-$E+Y ",
        "FeatureVPN _RemoveBefore",
        "CO+T]",
        "a)7pZ",
        "#ct1>",
        "D$ ^_]",
        "$2^rb#7",
        "KS,WRj*\\",
        "N\"?Ms",
        "~d06p#*8",
        "%?/?!",
        "kB&[C",
        "V!^VK",
        "nIr=v=z=",
        ",E6'Z",
        "A}T)I",
        "|g.h1k",
        ")xn$v!72/(",
        "3'5Y5W6",
        "jzjpj!",
        "Failed to alloc memory for big header!",
        "]=9MIu",
        "Ue~e1",
        "[WIy/",
        "WxDas",
        "`sO*WtK@",
        "{BfT0",
        ";W;J=w=",
        "}'n\\&,g<9",
        "{1nd7",
        "jAjgj\"",
        "R}K2/",
        "0^bI:p",
        "404<4",
        "aib)+",
        "4V4\\4",
        "{J0)S'",
        "PFCMPGE",
        "IYWO)?",
        "|H\\ADKG",
        "ru-ru",
        "727N7j7",
        "5jVcv",
        "0t$O'",
        "(KV4Z",
        "S,A!\\/^N",
        "G!%vN",
        "MOv8U9[[",
        "5!6}6",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\",
        "<qca8",
        "[KgW:",
        "8bzR?",
        "5-e%`",
        "FH9X0t",
        "y@]vS",
        "0 0$0(0,0004080<0@0D0H0L0",
        "3>SL.",
        "*l7e0l",
        "]66S%is-",
        "'bQvE",
        "<N=j=",
        "R5j<;",
        " wBjC",
        "MVi,SVX!v",
        ":F;U;",
        "4qbZ#",
        "1iQiqi",
        "V1kOE",
        "2*2F2b2~2",
        "P@1IN",
        "i*urO",
        "I=R P",
        "ec_GFp_mont_field_sqr",
        "  :[C|D",
        ",DoO6",
        "]PoU@",
        "=qVC{",
        "Wa_FN",
        "=FLgX",
        "{5PU8S",
        "=?t]H",
        "7b(rkQJ",
        "BT1j(",
        "v~QRB",
        "4UzRwD",
        "a_(tYb\"",
        "n(/EA",
        ":a:e:",
        "VNe.>k",
        "~aEU%*",
        "(BSmt",
        "lU:s60+",
        "x?mIG",
        "jAjpj\"",
        "K.rN[{",
        "TELEMETRY_DISABLED",
        "xuyd,",
        "\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 3;\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading Accent 4;\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 4;",
        "*z?VB",
        "TNEc\\V",
        "CloseHandle",
        "c`<Y,lw",
        "u29K\\t-",
        "n#w~F",
        "mJm0I",
        "_iXfl",
        "OnError",
        "rHQ s",
        "mM1$3k",
        "BAh<\\6",
        "9!9A9",
        "rO4=[GG",
        "}cN'?",
        "qvH;H",
        "t$$3E",
        "u7(6%",
        "?'?5?U?u?",
        ">KFf+",
        "g)Ec[",
        ",c0]~%",
        "68gv[",
        ">DG'_ywG",
        "e+.vx",
        "2YZ5E[",
        "*EDHW.",
        "q<s<W<X9",
        "z4~f*",
        ")F8`(",
        "id-Gost28147-89-CryptoPro-B-ParamSet",
        "Cannot delete %s",
        ".E*zc0",
        "565H5x5",
        "2 2@2H2P2\\2|2",
        ">nb-]z",
        "r}9B=",
        "%s (%ld)",
        "~C34s",
        "SOCKS5 server supports GSS-API %s data protection.",
        "A!A%A.",
        "X1O5[",
        "5,`($",
        ";{={6y",
        "id-mod-kea-profile-93",
        "Mbp?333333",
        "aiKwZ",
        "|J}xO",
        "(M!J}",
        "JLV6I",
        "HH:mm:ss",
        "q0mv$/Q*C",
        "j=zuCjL",
        "\\lsdsemihidden0 \\lsdpriority60 \\lsdlocked0 Light Shading;\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List;\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid;\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1;",
        "]23FV7F<",
        "s{yBa",
        "Ow=s8",
        "xlc49",
        "8#W?>88f",
        "Could pipeline, but not asked to!",
        ".RgOK0",
        "101M1j1",
        "MmLfX",
        "'nAc&",
        "d@BK4 ",
        "q,l63",
        ".?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "Connection timed out after %ld milliseconds",
        "S\"nsSO",
        "G%)Z.",
        "5NT> ",
        "1Qrbn",
        "D$0h5",
        "0d:@D+",
        "rvat#",
        ">MU`[",
        "bC|_n",
        "=$>T>",
        "3!hAW!b",
        "yFCcC",
        "UxX}Q",
        "T|n1^",
        "pAhf'",
        "A9[*,",
        "6-vTRk3",
        "Slc}H4",
        "HLoenh",
        "lI>Q'",
        ":e#3d",
        "vIrJt*",
        ":W:s:",
        ";@;`;",
        ".  No name for value was supplied",
        "FeatureSC _FirstBefore",
        ")E\\\\*=",
        "ufj6hT",
        "818A8Q8a8t8",
        ",(.H2",
        "w%ld ",
        "[NESTED UNHANDLED EXCEPTION] Use .cxr %x in WinDbg to see the context of nested exception pExceptionInfo=0x%x.",
        "id-cmc-queryPending",
        "hCh3N",
        "3T$D3T$L3T$",
        "0c0q0{0",
        "RLFd|f",
        "SRP-RSA-3DES-EDE-CBC-SHA",
        "7E|]&q",
        "ee&M6= .u,",
        "oY(M#:-Wl<",
        "3o8tQuwP",
        "4ANZ&NC7A",
        "QUuHS",
        "cYuy]6",
        "kdf parameter error",
        "263@3]3n3",
        "=q1Xy|",
        "mA  H",
        "92:_:e:k:q:w:}:",
        "}Fn]I",
        "}Xb$Ax",
        "1I^6D",
        "7.7J7f7",
        "c2o<@",
        ">>B]j",
        "-?oy!",
        "Xq3_E",
        "ZO<u?",
        "-ZFDYO",
        "*pe D",
        "5DD0F2395AF67624F9FCE676A2A4176A",
        "=`ye4",
        "\\CS8=",
        " 0x57",
        "7vPLL9m",
        "M[?&i",
        "9j,cW",
        "u@CW^U",
        "CleanLegacyFrameworks",
        "?q9tu2",
        "userClass",
        "C1mD\\",
        "VY$wr",
        ".~PdF",
        "RCaDCD",
        "\\fi-360\\li5760\\lin5760 }{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'08.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "6~\"Rfl",
        "W<91[m",
        "L$P]_",
        "'WoOr5 ",
        "quhOSm",
        "ec%iP",
        "4I^9tt8~",
        "<>.u&F;",
        "%hu%*[xX]%hu",
        ")!I^S",
        "failed to read todo from custom action data",
        "ModifyUpgradeTable started.",
        "9+P/0",
        ")WL'1",
        "O5}0Q",
        "rpfjG",
        "768;8O8T8",
        "\\c&I_oA",
        "OguQ>",
        "$,aSw#",
        "W<D3B",
        "q?0=ZO",
        "4<4`4l4t4",
        "Djp8\\",
        "-bbv!",
        "$S~S`jp",
        "Uki/&",
        "xcjQG",
        "N%9C`",
        "323F3X3q3",
        "7_8e8n8t8",
        "\"Z@z.",
        "Oq[t\\",
        "{)>Gdv",
        "@`/nM",
        "?ORGW",
        "-1SvP",
        "Rt9Ef",
        "-ZBh_%",
        "S8KHl~",
        "?uV7:",
        ":+:C:S:v:~:",
        " 0x59",
        "kJ<X6",
        "object",
        "V2S3PR[",
        "6(C.O",
        "!pk!sFwV1b",
        "D#^c6/",
        ": :/:<:p:w:",
        "bzHZg",
        "1*0Zw$",
        "Ix,5`$9",
        ">Q]WD",
        "S-1G5",
        "P{[:$",
        "-5Vk!",
        "\\A0Ryz",
        "r(t\"X",
        "Kcms?",
        "+6)rm",
        "909<9\\9d9l9t9",
        "=9O;)",
        "{E,pv",
        "IE+r}",
        "''r3+",
        "S}STl",
        "=c7F7h",
        "\\XTsS",
        "b$5$k",
        "j.7xH.\"",
        "a7{`*",
        "d%3Hq~StB",
        "^HLqz'",
        "bn to asn1 integer error",
        "5(a*Bf>",
        "SetWindowsFirewallStatus",
        "h\\+Pn",
        "Wsf'N",
        "{S7b5",
        "dy=ocL",
        "l?uXnAo",
        "0bnK4",
        "?'?D?U?j?o?",
        "%I64i",
        "9p*[&7U",
        "|U`x]",
        "}#F IjB",
        "_except_handler4_common",
        "FY([^",
        "NrZ^'9",
        "*Fcbh",
        "aS8M[SQ",
        "9p t ",
        "F1Kj ",
        "+E)j\"@2",
        "Lh[dM",
        "yZh_1)",
        "4pHK^h\"",
        "w5R\"iH",
        "k0W`/",
        "=7+Fo\\",
        "VB8b]6",
        "gu:Sg",
        "B{qK6",
        "*\"W*1",
        ")\\w`x6",
        "nXA3`!",
        "reboot_file.log is still pending for deletion",
        "g?.X|/Yo",
        "6@+}>",
        "2,2H2b2",
        "0(0K0",
        "L*\\Vouf",
        "9%9.979@9I9R9[9d9m9v9",
        "Q5i&]6",
        "Aq.$f",
        "7A8F8q8v8",
        "]8#|S",
        "5([JT",
        "9K(G[zz",
        "=uGbh",
        "V\\\\|=zyh",
        "<C=R=",
        "XDQD2",
        "[zz,-j",
        "E5]_^[Y",
        ":):H:T:",
        "request",
        "(DS'&",
        "< t4<",
        "HxBd*",
        "'vFK#A4.",
        "5b2Ug[",
        "8Ki6<t]H",
        "boost::filesystem::create_symlink",
        "api-ms-win-crt-locale-l1-1-0.dll",
        "zB30$Y-",
        "7fG`x<",
        "&X4tJ",
        "[x@kw",
        "l^>+2",
        "u)(q+",
        "^I\"e/",
        "jejuj",
        ">LFmH%",
        "failed to process attributes from CustomActionData",
        "/F(Be",
        "yM36!,y",
        "0~:To",
        "f-40H",
        "[DUMPFILE] wrote %s dump file %s",
        "M&&N/",
        "jijqj!",
        "k)ca9",
        "@7&JS",
        "K/~/1]`",
        "P %D]",
        "DvT*s",
        "eS$/E",
        "Y6hiH",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 and/or may be subject to additional export control laws applicable to You or in Your jurisdiction}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "%}[?o",
        "N,J/'6",
        "QeyM\"E",
        "yo1 i",
        "xe\"46",
        "#yg[._",
        "N+Kek",
        "I1`jn",
        "{Pk%|",
        "R6df:",
        "U!\\X5,(",
        "[Cbb;",
        ">I?m?z?",
        ",VxPb",
        "=PC)78",
        "Failed to save changes to XML file: %ls",
        "=OlZ*",
        "X36Y^CJ",
        "jhjhj!",
        "J`LLG-",
        "]w>XN",
        "-.m19",
        "|5/;?/l",
        " laws and regulations in effect from time to time.",
        "4T5v:",
        "&UbgHWG",
        "t3lD,",
        "gkV>t",
        "6j7-8e8x8",
        "^-{!U",
        "reOoS",
        "u9WVU",
        "id-GostR3410-94-b",
        "6&757",
        "APV_@",
        "3\"?e^",
        "WD;WDw",
        "M7;3o/\\*z<",
        "0<0@0D0H0v0",
        "oz;YCL)",
        "\\ uRT",
        "L)4`$",
        "x!!v|*",
        "PreInstallCheck:  Check for conflicting software.",
        "c/|F:",
        "[T+eNR",
        ".Megc",
        "attributes",
        "p^?fb11",
        "?a@a8",
        "cpMQ;",
        "B F G",
        "0EigHY",
        "0${Ek",
        "+D),U",
        "c7+`%wA",
        "8#9K9s9",
        "RLZIR",
        "_dq-^",
        "._t_sc",
        "e;B-d2",
        "'$Qvv",
        "bhmUC0",
        "dSAQuality",
        "WmWjU",
        "6 6,646T6\\6d6l6t6|6",
        ")9ss3",
        "`hvicL",
        "[C*Fu",
        "Q##{1*C",
        " o9Rc",
        "116A6Q6a6q6",
        "4+4\\4f4o4",
        "jzTE3j",
        "A9}#J",
        "q1rIrur",
        "[sXZ44",
        "U&#![",
        "stZk'u",
        "t$ PP",
        ".?AUTopologyObject@GlobalCore@details@Concurrency@@",
        " name=",
        "/%s5(",
        "IsValidLocaleName",
        "t$tPSV",
        "%s%04x - <SPACES/NULS>",
        "?@R3D8$76SqGG",
        ",jRjz",
        ">U#w/",
        "@P @l",
        "^TO'`",
        "pb-r0",
        "fOKJ_",
        "303E3U3b3",
        ".\\crypto\\asn1\\a_sign.c",
        "PFRCP",
        "h,9F3",
        "+xXpH",
        "v+0A2",
        "g.&!+9",
        "-`w%X",
        "(!:h8",
        ":kn(v#",
        ": :$:(:,:0:4:8:<:@:D:H:L:P:",
        "Vj*Kf",
        "Y45sc",
        "no?M)8",
        "r+p~2z",
        "f)3UvBj",
        ")g-1)%",
        "`N[6j",
        "c XBCx",
        "E'q?e",
        "i`Agc8",
        "sHhiv",
        "O\\<iU",
        "gc'-na",
        "F9vu5=",
        "]-^>l",
        "e<KYp",
        "(]h@\\2N",
        "9v^?m",
        "wKWq:",
        "szyX$",
        "]3=oq",
        "hAx^H1",
        "W.=gMw",
        "WindowsServiceIPC.dll",
        "_initialize_onexit_table",
        "{5F'~",
        "'ysH5",
        ":M;c;",
        "XNgCN",
        "ZLsvw",
        "p4A7^",
        "g\"X,A",
        "&4XZR",
        "ECrI7I=",
        "!Lhwf",
        "lt_v#",
        " Z:wF",
        "XiK0zj",
        "Modules_FW.png",
        ">N(a,",
        "oS.fE",
        "QL?Kg",
        "|Qx*c*",
        "VSSetUpgradeKey: invalid key %s",
        ")x>;$",
        "?y=WV= {",
        "=P=`=l=t=",
        "UNZQ@M",
        "apx\"w",
        "<%<.<8<Q<[<",
        ")R_\\/y",
        "~%9=:4J",
        "Hold Instruction Code",
        "4)4.4J4e4",
        "R9Hc=",
        "5e?;=",
        "RRMS>",
        "|5'?qS",
        "ksIv%",
        "/6VDf",
        "^i>1z",
        "+$BH ",
        "\"Kl\\~G",
        ",o:K^i",
        "QDlktJO",
        "r\"rrrRp",
        "L<sTg",
        "m7Bbh",
        "nicR]P",
        "PFADD",
        "7!7>7O7d7i7",
        "UninstallSecureClient.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid5259060 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid15092562 6.7}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 . }{\\rtlch\\fcs1 ",
        "ka3^l",
        "9$~:(68",
        "40a;y",
        "(K_'?*T",
        "grU/pP",
        "V~/1V~",
        "LDw+L",
        "$>NdT",
        "{x]<1",
        "{[>%K3-}",
        "QKIuf(4d",
        "uV&FG",
        "f<#\\U",
        "WB,4U",
        "\"u5Y,LJk",
        "k2)z]",
        ",%x9G",
        ")<T(T",
        "o?tb:%Ts",
        "?++1j&",
        "9'9.9@9K9R9Y9}9",
        "+D$HP",
        ";<?4.",
        "sh,t;",
        "@1k8*K",
        ".k$U,x+",
        "c ZdN",
        "z&;k_>",
        "% %(%0%y%",
        "CompStartComplianceService ended",
        "yL_{9",
        "5/5G5i5",
        "tZQQj",
        "|lpqF",
        "8#8)8/848:8@8F8K8Q8W8]8b8h8n8t8y8",
        "VC90_MISSING",
        "l$$PW",
        "t@Ge(",
        "bLC\"D",
        "C@&uk",
        "\".\"BB",
        "<6<b<",
        "z*\"h<",
        "No connections available.",
        "Fk-!!",
        "J6fdVe%",
        "s^<oo",
        "LDDQU",
        "-q $)",
        "s+iqi1",
        "3/4i4",
        "B@W]f",
        "V2I_NAME_CONSTRAINTS",
        "CAMELLIA-128-CBC",
        "ipsecTunnel",
        "K7*|a",
        "dkSUR;\\K",
        "f@Z>A",
        "t$ EV",
        "sRqV,",
        "<5<r<",
        "en-GB",
        "b'nzD",
        "9$:J:\\;d;",
        "K$o!J",
        "?L~y]",
        "Al)SaY",
        "hYSM]u",
        "%87\"%w",
        "v{1YWy",
        "+<F^@",
        "W[-dI",
        ":?qls",
        "n]nRk",
        ":#:-:4:A:Q:X:^:h:w:",
        "C$PjQW",
        "2;}ol",
        "C j&h",
        "jUu5i",
        "5A5y5",
        "=m!Sg5",
        "c@G6fM",
        "h:QkG",
        "D$4j P",
        "`?SrwU",
        "mI2 W",
        "(B^>+",
        "N1P%D",
        "b@dhL",
        "y|vwH",
        "HB(\"7M",
        "CB.lX",
        "=!=-=9=G=",
        "OnUpgradeAfter:  SetProductMode (again?)",
        "QupB,",
        "?XXx.$",
        "<D<o<",
        "rQ.#6",
        "__stdio_common_vsprintf_s",
        "Lj?>k",
        "SDDIR",
        "8 8?8",
        "J1m_eT",
        "OPENSSL_ENGINES",
        ").$ff",
        "illegal padding",
        "x+0,y",
        "RebootFlag.pending",
        "&7<N\\",
        "N$/8{",
        "Zp7*-",
        "?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v",
        "TL~<\\",
        "jhh$<#",
        "2!2-2=2M2e2",
        "uaCS,",
        "[LICENSING] beta license expired - non-matching publication",
        "yXTGxl",
        "5X^J.",
        "dv ]=",
        "?,?H?T?c?",
        "11_8$",
        "<gM6qJ",
        "1%1[1k1v1",
        "skn&Zy",
        "otHaV",
        "5Ucjl",
        " XAeL",
        " FZl\\A",
        "K2Hh|&",
        "+3E9Gr",
        "m)e|t*",
        "|aQk4",
        "`+U@81",
        "Y%\"|C",
        "sha256WithRSAEncryption",
        "DQCd1P",
        "OZ*5H",
        "D0?Ld",
        "WGvu<",
        "BuZ,s",
        "<f<x<",
        "fafegi",
        "`!`CC)",
        "tYw&&",
        "Cannot execute view %s. Error: %d",
        "|8R!Lix",
        "CMS_ReceiptRequest_create0",
        "8Z8t8Y9",
        "0\"020H0]0m0x0",
        "2]3KV",
        ",#7muq",
        "Ldy>}#",
        "ct_precert_poison",
        "\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp2\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp24\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp29\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp0\\itap0\\li0\\ri0\\sb0\\sa0}{\\pgp\\ipgp19\\itap1\\li0\\ri0\\sb0\\sa0}{\\pgp",
        "819L9T9c9",
        "6RMT-a-",
        "+#WYU",
        "#lpxAG",
        "msgsigdigest wrong length",
        "ssl3_enc",
        "<u_HP",
        "j?nZ&",
        "9\".]q",
        "faqr[S",
        "B*I4H}",
        "DwK+1",
        "6nIi]",
        "S{o{v{8M",
        " CO91v",
        "Ck$rl",
        ":2:\\:z:",
        "mLUxp",
        "CPNnS",
        "Q:>$qX",
        "-:H61F",
        "Qe\\iW",
        "ssl_mac_secret_size[SSL_MD_SHA1_IDX] >= 0",
        "7T7t8",
        "`$>Ng",
        "*<@Ih-",
        "{ZDzP",
        "IR-iZ]X",
        "tiuivi",
        "7]41c",
        "t$ h\\",
        " ~+x'e>",
        "X,fOv",
        "4C\\{V$k",
        "<+z)7",
        "wds2sH",
        "DS_PrepareCopyToSystem32",
        "9cA.Z",
        "FGM[vX",
        "aes-256-ccm",
        ",!zvm",
        " }z6T",
        "=2=Y=",
        "-[v5|",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13844772\\charrsid15169477 ",
        ";B<L<V<",
        "NCHU)I",
        "=*\\x~=9",
        ".4\"!Q",
        ",\"Fco",
        "BFH[C",
        "_ _>6H",
        "$0)0@0T0h0|0",
        "`,Dfb(",
        "W?-{d",
        "<{GX$'j",
        "different parameters",
        ";\\;6=C=^=V>c>",
        "StopWindowsUpdateService",
        "\\w_Wh",
        "< <)<4<F<O<]<l<r<}<",
        "2M&JpD",
        "]h7S^",
        "uJr2V",
        "+[lLlp",
        "HX-A\"9",
        "]{9#l",
        "V\"L!dD",
        "X509_STORE_add_cert",
        "DLXi1",
        "zrDQp",
        "2$2/282",
        "FileDescription",
        "T0{UB8",
        "Proxy CONNECT followed by %zd bytes of opaque data. Data ignored (known bug #39)",
        "IJ_H^[",
        "t(XCyt",
        "t jzh",
        "P:V}Qf:o",
        "AVInstalled",
        "!PHtT",
        "QueryServiceLockStatusA",
        "1(1D1H1L1P1T1X1h1l1p1t1x1|1",
        ";ek5\"c4",
        "t<CH?",
        "B$$FR",
        "ALLCADPROPS",
        "[RN9o!",
        "z+47Mq",
        "updatekeyfiles.xml",
        "c>yxS",
        "E(E8EHEXEhMx&",
        "S dL4B",
        "hM(pXo",
        "<g5Et",
        "w$u8Su",
        "oc{qI",
        "T)HqH",
        "7<7F7",
        "C.:\"mc+",
        "setct-CertReqTBEX",
        "$*<`K",
        "; ;&;,;P;l;|;",
        "const ",
        "T\\1B{",
        "z0C![",
        "fX=&m0",
        "no accept port specified",
        "t&>@bm",
        "=Yp9'F",
        "3T$@3T$,3T$$",
        "*0Ro@",
        "SOCKS5 reply has wrong version, version should be 5.",
        "545R5^5k5",
        "Y%33*",
        "2}mjw",
        "&@\"A1",
        "7/8I8~8",
        "jT^i.Q",
        "0.0G0`0y0",
        "@[g#u",
        "PXT]9@=",
        "2$2(2,2024282<2@2D2H2L2P2T2X2\\2`2d2h2l2p2|2",
        "VA\\zmZ",
        "Z#OCQ9*?L0",
        "!\\^^,",
        "Qy4\"\\a",
        "Ch&Mf",
        "UBOsY",
        "(GlobalSign Timestamping CA - SHA384 - G40",
        ",4<j7fc",
        "H7p-t",
        "- Attempt to use MSIL code from this assembly during native code initialization",
        "h-R[P:",
        "0+NIL",
        "7ImCP",
        "*{oUy",
        "cert cb error",
        "`<F9;",
        "-!~.R",
        "W>WFW",
        "!fjw,",
        "6;P\\I",
        "`]|`5",
        "Xn#h=",
        "P(1@0]",
        "CAMELLIA part of OpenSSL 1.0.1t  3 May 2016",
        "RegSetKeyValueA",
        "=`)>2",
        "!cRAP",
        "gopher",
        "SOFTWARE\\Agnitum\\Outpost Firewall\\Paths",
        "1F2X2p2{2",
        "5%5+585G5M5Z5i5o5z5",
        "0u0w0y",
        "t$L3t$P",
        "t=DT@t",
        " ctXf",
        "CompareVersions",
        "iagKE",
        "jn<bXM",
        ".1gcj",
        "QQ<YU",
        "vYn5F",
        "KD?arv",
        "/=Mci",
        "Failed to read EPCBuild",
        "2\":'M",
        "P#lV\"",
        "7!%*kgZ80",
        "P;MB.p",
        ":S:s:",
        "`'P@~",
        "Q|?Q@",
        "SecuRemote\\",
        "L-rp&",
        "oMz@n",
        "SEC_I_LOCAL_LOGON",
        "[WinFW] GetWFStatus, failed to get the domain profile, error=%x",
        "T\\i:hnBNhw",
        " w}1T",
        "\\7*%$\"",
        "*'e9;",
        ";wsGw",
        "yY^ez",
        "failed to schedule WixCloseApplicationsDeferred action",
        ">,?D?O?",
        "2(232",
        "!A1Xm",
        "jdjej",
        "?B?Ut",
        "XdLZ(",
        "(;d8e~3D)",
        "%d Error opening the symlink le:%d",
        "0(090M0",
        "4XIe:",
        "/iMqj",
        "`<0V1`",
        "PrintOpenSSLErr: %s - err=%d.%d.%d @ '%s' line %d",
        "pbeWithSHA1And128BitRC2-CBC",
        "C9}uC",
        ",{iE.",
        "s{kj/b?S",
        "k;bT?",
        "E+m)*",
        "jQ9yd",
        "#!40]",
        "NTNPP9",
        "YqI|N",
        ".`On-",
        "PDDfU",
        "898>8",
        "Ovf|L",
        "1W2x2",
        "setct-BatchAdminReqData",
        "=u\"LDT",
        "Xy<t8",
        ";_[^]",
        "{[b>b",
        "{\\fdbminor\\f31505\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}{\\fhiminor\\f31506\\fbidi \\fswiss\\fcharset0\\fprq2{\\*\\panose 020f0502020204030204}Calibri;}",
        "@gYZq",
        "0+mg7",
        "EW,$X",
        "B!M7DQ1",
        "cDF1;G",
        "O;$mh",
        "=y|gH",
        "O\"qOFg",
        ">uF& w",
        "en-US",
        ":1;T;w;",
        "$&E &T",
        "F]$g9",
        ">[cN_&uuo",
        "{!{A{a~",
        "5,6>6P6b6t6",
        "4PMAqC",
        "3L$03L$$",
        "<Wl7\"dTd",
        "[;ZPh",
        "CCIXLI",
        "Content-Length: %d",
        "6Yvy5d",
        "camellia key setup failed",
        "@!@%@+@1@?@C@E@]@a@g@m@",
        ">0>D>X>l>",
        "http://sv.symcb.com/sv.crl0a",
        "L$ QV",
        "CAMELLIA-256-CFB1",
        "Q6F-F",
        "\\dNvN27;7",
        "|+veR",
        "'nVDjk",
        "{VV$;",
        "uoLKP",
        "3[V^E",
        ".CRT$XCL",
        "1+1R1h1t1",
        "cXp<lH",
        "?ONL1",
        "0$0,040<0D0\\0d0l0",
        "XZFy q",
        "mEV#yC|",
        "ut$Y'",
        "SEC_E_CERT_UNKNOWN",
        "BpMK6",
        "oiu^b>4S",
        "cfX]jR|",
        "Sx>wv",
        "l)$> ",
        "Multiplexed connection found!",
        "x|oqW1>",
        "-tP[o2",
        ")O|Q!",
        "kESL3ct=",
        "?0h}n",
        "W'uG!K",
        ".?AUIExecutionResource@Concurrency@@",
        "Cyl,;",
        "0U<w^6$ ",
        "2uv`&",
        "(~kl~",
        "L!+e8",
        ">k|]v",
        "failed to initialize",
        "gk5Qbk",
        "-rj1cd",
        "ALL:!EXPORT:!LOW:!aNULL:!eNULL:!SSLv2",
        "Bp:x[",
        "516A6{6",
        "M:g M6C",
        "aXhD0l",
        "?>*!ZZ",
        "&+N9q3",
        "4&/+nkf",
        "-RNcw",
        "z8oyN",
        "7Lovl$",
        "/,7*q",
        "Yw0~>L",
        "2@Gt$xp",
        "<6=C=`=z=",
        "\\</BR",
        "u8u9u:",
        "((m3QA",
        "SZ3br",
        "313M3i3",
        "TNI\\;",
        "X'|*,",
        ";$;6;H;Z;",
        "1,kg*",
        "Rekc#5]",
        "\"'%5B",
        "002x2",
        "&^P?t/c}",
        "^)^e^",
        "#ETHw",
        "J4p{2",
        "Enabling SDL.",
        "4-VdK",
        "thA;j)1",
        "ZLComm.dll",
        "39-~m9",
        "]^ui}b",
        "jgjpj%",
        "t;gK*",
        "U2kF|3",
        "hR1|:",
        "FOMGH",
        " &N~F",
        "d_\"*>;",
        "3*404",
        "Found VPN InstallProperties",
        "7B7b7",
        "=1=Q=e=",
        "cw)N&8CM+",
        "Xts.M*",
        "De3eLf",
        "rZgR,,H",
        "V\"zJ:",
        "FTP response aborted due to select/poll error: %d",
        "EXOPL",
        "1c'HMD",
        "e)O)X",
        "D$\\Pj",
        "T8Q2m",
        "EHw_^\"\"",
        "QWPSU",
        "%vbo}y",
        "Oj7}s",
        "h35GH",
        "{\\listlevel\\levelnfc2\\levelnfcn2\\leveljc2\\leveljcn2\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698715\\'02\\'05.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li4320\\jclisttab\\tx4320\\lin4320 }",
        ".?AV?$basic_istringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@",
        "VrA'D",
        "(}cW8!i]",
        "k(({2",
        "Failed to get size of ca script file.",
        " H'KeW",
        ";X<p<",
        ">_?z?",
        "j)SwA",
        "w\"r6I",
        "EVP_PKEY_derive_init",
        "-q[fm",
        "F||<##",
        "J7y\"B",
        "/+LF8jb",
        "M2sE2",
        "Q1\\NY1",
        "Op/tzB",
        "z ++'",
        "202<2\\2h2",
        "kjj,h",
        "9A9f9x9",
        "=%l6>",
        "WY_8j",
        "Kqme(}",
        "6KE*O%",
        "c/(DY",
        "p{r`=6",
        ";D$ t",
        "unknown operation",
        "CopyFileW",
        "8#9a9",
        "I,.zF",
        "iZPY~",
        "e0#Tf';",
        "Uf:e}w",
        "*;0=`",
        "SZ1hI",
        "p;NO.",
        "multipart/signed",
        "o*FG[",
        "MG}0x'",
        "4`8d8h8l8p8t8x8|8",
        "Om*K\\7B",
        ",6Jm)K",
        "I85>E3",
        "%#?c\"",
        "dZ!2.",
        "1A2X2i2o2t2",
        "T &9[",
        ".\\crypto\\x509v3\\v3_scts.c",
        "?%?A?]?y?",
        "iO>2(",
        "Failed to stream out %s to %s.",
        "VjVChP",
        "UG``V",
        "7c8y8",
        "AaB>`",
        "NaWl=",
        "pAsci",
        "$>Ha[",
        "xeZx'",
        "DH_CMS_SET_SHARED_INFO",
        "D$4SU",
        "nfA<jW",
        "IND)ind)INF",
        ".\\crypto\\ec\\ec2_smpl.c",
        "t1H+M'",
        ":IzIbHU",
        "As?Aq",
        "V;h8X8]",
        "9Ta%M",
        "-r+m5",
        "3.\\crypto\\asn1\\a_mbstr.c",
        "4 4(404<4\\4d4l4x4",
        "q$\",j",
        "(E8fJ",
        "z.9X<b",
        "Sn|;9",
        "!lB.@",
        "UninstallCreatedItems:  Removing registry key HKCR\\Software\\Zone Labs",
        "Y3em+TI",
        "x#6q56",
        "JK>s[",
        "Helper.stop() succeeded",
        "MjGmb?",
        "Muh7n",
        "pA6# <",
        "7(e/Y",
        "aW4Yp",
        "a+;4{",
        "b[pB-",
        "}k~n3",
        "4$4(4,4044484<4@4D4H4L4P4\\4`4d4h4l4p4t4x4|4",
        "3 3$3",
        "Yv8]B3q",
        "Mu&Ro",
        "!<c+:",
        "UgioZ",
        "OpenSSL DSA method",
        "ilul'",
        "2{Zw^",
        "cm%J.",
        "ZNiP;g",
        "Y<6a7",
        "8qOgb",
        "SWWRSE>W",
        "T#1i1N",
        "*;C*w$",
        "tFMey",
        "d]xYR",
        "r\"FC9",
        "eK4}?",
        "<S`p<",
        "vHqL+K",
        "@)a>?",
        "l-\\1`q",
        "mjzAij",
        "(Lt6*V",
        "$T/(@",
        ".?AVIswProfileHolder@IswLog@@",
        "&HH`1(",
        "sslv3 alert bad certificate",
        "K(W[7",
        " msu;",
        "Kaspersky Anti-Virus",
        "8'dy&",
        "\\b\\f1\\fs20\\insrsid3737333\\charrsid477636 IMITATION}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid3737333\\charrsid15169477  OF LIABILITY}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid3737333 ",
        "prV9pi",
        "2xPnWC",
        "ZCCARSYM",
        "]t{25)",
        "=A>^>&?",
        "CWD %s",
        ")\"g6[",
        "\\2\\ q",
        ">,>a>Z?",
        "jjhDx#",
        "7RzK8}",
        "E(?(E8B",
        "C<Uw9",
        "-BA-]9",
        "Unknown share option",
        "L|`\\B |a",
        "-?\"t*!$",
        "Vn*JR",
        "\\bFh|",
        "*laM-\\SO",
        "FAILED_EFR_SHUTDOWN",
        "w%'deF",
        "wOUVWCNXYLKZD",
        ".=qG5",
        "eM UC",
        "Netscape Renewal Url",
        "pd3/dA*",
        "5wiIi",
        "YJM-}",
        "|$8HPW",
        "0vg\"k",
        ">@_\\i",
        "m77GG",
        "/Y}1DM",
        "\"bp|=",
        ")NZ4VI82rB",
        "[1t?5",
        "^4J$ D",
        "w3q&'",
        "<$<,<8<X<`<h<p<x<",
        "+a$EO",
        "SpsFO",
        "jqjvj",
        "/.K'v",
        "d.allOrFirstTier",
        "gXXtc",
        "KRvI9C'",
        "%7I64dd",
        "11+ibL",
        "?P4k&e",
        "%E}N~",
        " 3+Kl",
        "p>8Az",
        "w|e:#",
        "[3\\s\\",
        "90989@9L9l9t9",
        "ov** ",
        "#8l;_",
        "Check Point Endpoint Security Installer",
        "Hzbc?",
        "x\"xZt",
        "nuD2 ",
        "Ntifq",
        "\"[^D!",
        "(Pb v",
        "@L<k:",
        "x)LOG",
        ":&:0:::D:N:X:b:l:v:",
        ":_V%D",
        "5U-a1>{",
        ";l$ t",
        "/zpT?",
        " --install ",
        "lv'Aaif",
        "^3z=f",
        "not win7 proceed installation",
        "Failed to fetch record from ",
        "PO8yEb",
        ";Fv8Q",
        "\\s3\\ql \\li0\\ri0\\sb240\\sa60\\keepn\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel2\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\af1\\afs26\\alang1037 \\ltrch\\fcs0 \\b\\f1\\fs26\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "~@jeh<",
        "r9j)h",
        "NMQz3",
        "?J?R?k?v?",
        "{Ynfn",
        "&FkF5",
        "Y;(u+",
        "mP=j%",
        "(y> w [M",
        "I=Kp%",
        "<^B\"s",
        "S2U>A",
        "M6vgTk",
        "iu^cE",
        "Wa%X>",
        ">iNT$",
        "|j`e!",
        "6$7/797>7U8z8",
        "\\qzYb",
        "Gmscoree.dll",
        "5Y8Y%",
        "J!r%z",
        "FV,L'",
        "rI9bx",
        "!FqqP",
        "2@]0S",
        "\\>1Lj",
        "Loading error information from msi database -- Failed to fetch record:  ",
        "},l(a",
        "2M?wO",
        ".Q;|m",
        "c{?&?",
        "cLK7c",
        "(4Jg)",
        "9(9v9",
        "[v'@;",
        "Oa6C3",
        "R'*?,(Q",
        "2$2@2\\2x2",
        "ENGINE_get_next",
        "=}(9E",
        "3`s)iR",
        "{\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname PlaceName}}User{\\*\\xmlclose} {\\*\\xmlopen\\xmlns2{\\factoidname PlaceType}}Center{\\*\\xmlclose}{\\*\\xmlclose} and as verified with }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "ioLsY",
        "z-ov1",
        "splY,",
        "8th})",
        ". 3i<",
        "\"w4m4",
        "BEqbdXg",
        "FKbsv^",
        "24292V2t2{2",
        "\\}\\=7",
        "d/YXp",
        "7^7qi",
        "i)17x6",
        "Wa4#e",
        "393b3",
        "]gL@$",
        "WuZ9X",
        "RV^I6",
        "\\9h=`bIV",
        "2JIK{_",
        "jQ,W)",
        "+ZM^y",
        "\"[8JP8",
        "D$hVP",
        "}^S\">",
        "H\"]lW",
        "x$TgF9",
        "DV\\58",
        "QoqKS",
        "GIKn3",
        "Sif*vN",
        "~/Z/%",
        "d/(6k",
        "?(cJzHF",
        "_ny;wT9",
        "<!<'<-<4<I<O<U<\\<q<w<}<",
        "OpbNuz",
        "O,(W5",
        "%]CZW",
        "T6^yiZ",
        "T\\zaaKJ'E",
        "\\5 Nl^",
        "HS`bIf,",
        "timestampsign",
        " S2}(",
        ".N7sIw",
        "bRAN.",
        "@^Mv2 ",
        "n4K=QP",
        "qQ#cQ",
        "\"^vU*",
        "z1S#X!",
        "MISSING_SHA2_SUPPORT",
        "6]5Ox",
        "p Bdr",
        "SSL_GET_SERVER_CERT_INDEX",
        "Ph ML",
        "(P-)&",
        " @>)u",
        "3g<y,",
        ";$;5;",
        "i5xH,3$lm",
        "L}lSI",
        " JyOuh\\",
        "O7t<`",
        "'gPMQ'",
        "o3Y$1",
        "[T~P(@(",
        "|A5YNeX",
        "e+000",
        "failed to get XmlFile flags for XmlFile: %ls",
        "ixdoi",
        "R3b!J(",
        "t2AeFt/\"",
        "2Q-[w|",
        "[VSinstallProduct-Silent]Install Password",
        "+^b?JE",
        "8lidh",
        "weAsl",
        "YxvOQ",
        "E>uHs",
        "en-ca",
        "`dynamic initializer for '",
        "ttC8OH",
        "Y9&gk",
        "ucp_eps.exe\" -y -o\"",
        "0+0J0^0",
        "N%e|d=",
        "62HCQ",
        "L$<]_",
        "^)5/u1DL",
        "z6Sqtt",
        "FAILED_WATCHDOG_SHUTDOWN",
        "_z3y,",
        "r1jDp",
        "90u);w",
        "`t'_^]3",
        "<&<W<",
        "@\\=7s",
        "`O]kg",
        "L(H_S",
        "cDcYcdcn1",
        "ec.\"s",
        "\"X1A?",
        "cc4!~",
        "E.f)Z",
        "O2No\\s",
        "##3UU",
        "NQ'sq|<3",
        "LYI\"4f6",
        "BWUM[",
        "&(1tL",
        "6I\\\\Q",
        "1#2E2",
        "wTXpnh{",
        "Y#`h0",
        "|PT/x!",
        "`I(_. ",
        "[VSSHUTDN] SetProtectionByChallengeResponse",
        "/ZmTF",
        "CMOVLE",
        "+x(1!",
        "`default constructor closure'",
        "`w'Ow.",
        "\"v#2`",
        "do_jI",
        ".eH|O{m",
        "W2?,2",
        "naq]f",
        "{\"} $)O",
        "2&333J3Q3\\3o3v3",
        "MOVSHDUP",
        "uB$?K$",
        "za+.=",
        "&Mnp-c",
        "islower",
        "H^(m=",
        "HELPER_FAILED_TO_STOP",
        "nv]hp",
        "GetVsinitFuncs",
        "Yev_C",
        "wm7M8",
        "gn{^S",
        ";!;(;<;O;T;`;g;p;u;",
        "9:9k9",
        "UISeL)",
        "5MrH+",
        "K:n%2",
        "nv'[I\\",
        "w[o#Y",
        "1*2R2r2",
        "Got an RTP Receive with a CSeq of %ld",
        "failed to add temporary record into ServiceControl table",
        "fy8b(",
        "fVWK-",
        "==>P>",
        "(ZUvRbv",
        "BXCU;",
        "spiUq",
        "vQvt3",
        "3l$ P",
        "C+>*&",
        "|$ ~3",
        "sk-SK",
        "atm+W",
        "7|6n#yd&",
        "j$mdk",
        ";_PHig!",
        "GSfyp9V^",
        "E5,|3",
        "0$00080\\0d0t0|0",
        "T$H3L$ ",
        "da%I+J\\X",
        "ox?$]",
        "NC[wQ",
        "[|p<I6",
        "z`h&\\",
        "TERt\"",
        "MsV_bmo",
        "'C?+!O",
        "Y@'OO",
        "Failed to create initialization event.",
        "%d6ilR",
        "4)4?4s4",
        "uX}Wd",
        "QM^^(}",
        "2\"2T2\\2",
        "e`Jg'",
        "DS_PrepareFACDriver",
        "vsdatant registry value exist",
        "(y~zH",
        "l' ee[",
        "_0f0o0x0",
        "EPAM_OnBegin ended.",
        "2pW}eY",
        "#J-<$",
        ",PjVW",
        "A@pMs{",
        ";b]Z]ry",
        "F@WO5A1T8",
        "Ho:]gl",
        "vx<tEg",
        "<@En[vP",
        ")53h6D",
        "KIKIKIKIKIL",
        "z;M=iV",
        "_/?7m",
        ":7:O:q:",
        "tP,BED",
        "EVP_PBE_alg_add_type",
        "[6qUf",
        "rsassaPss",
        "{,&/~",
        "Qo[DI",
        "NCB*UZwn",
        "MD;1 ",
        ";!7{A",
        "Nd\"^^",
        "h$fNjI",
        "sjT{E=-",
        "lh0}8",
        "4*4F4b4~4",
        "445>5[5l5",
        "7:|7I",
        "[IY*IFHt",
        "AQbw}",
        "Pm0ka",
        "eO:box",
        "6n=aG",
        "I8UtwAy",
        "`D<{^",
        "!8j<D$",
        "/Ou.iJ",
        "A@*yB",
        "ivYC?",
        "~2@bs",
        "Wx-@V",
        "t/)dE1",
        "4Omd!",
        "Rz3RP",
        "Q&ifg",
        "\\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Questions}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "T$L#L$L#",
        "~`wc!",
        ".?AVVirtualProcessor@details@Concurrency@@",
        "SOCKS5: error occurred during connection",
        "='@4}%)",
        "SXNET_get_id_ulong",
        "v<~Ym",
        "Uj'\\6",
        "11161A1T1",
        "zlJzV:",
        "K!'uR",
        "~n$MK",
        "%)YP]",
        " oQI.",
        "InnerMSI = NO",
        "Failed to create the security descriptor for the events.",
        "e%8mE)&",
        "wap-wsg-idm-ecid-wtls11",
        "<'f9y",
        "WD_InstallWatchdogService",
        "Failed sending data to the peer",
        "failed to get reset period in days between service restart attempts.",
        "i4,]`l",
        "lWzfHi",
        "VwW(%",
        " ) Tq",
        "REsqDp",
        "Bf>Nl",
        "1!Eh!",
        "['|$bD",
        "OJI4\\uU",
        "&ecUZT",
        "-5Au@",
        "ke?P^",
        "{\"A.&J",
        "tIjvh",
        "GENERAL_SUBTREE",
        "5@(@kC.",
        "Qj-NG",
        "Di,<1",
        "_a.i<l",
        "nek3h",
        "mE*RU",
        "cli::pin_ptr<",
        "u]%nMe",
        "\\31`2A",
        "B$'ZXA",
        "h(<#^W",
        "hm7/K",
        ",L]pS809",
        "{9~SK",
        "D$`WP",
        "?\\yM}Y",
        ";6<]<",
        "H/Jzg",
        "=)u[MJs",
        "F4q]LW&",
        "\\w#Az",
        "nMbf-",
        "9!9%9|9",
        "        Subject OCSP hash: ",
        "yk:8?g",
        ":.:3:K:X:c:",
        "eMdtq",
        "Mw(D@",
        "_Gt<(",
        "rc2-ecb",
        "Na/mO",
        "C!,^'",
        "gvLta-",
        "\\sbasedon0 \\snext0 \\slink15 \\slocked \\sqformat \\styrsid13065977 heading 1;}{\\s2\\ql \\li0\\ri0\\sb240\\sa60\\keepn\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel1\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\ab\\ai\\af1\\afs28\\alang1037 \\ltrch\\fcs0 ",
        "?]?u?v=wwc",
        "3-;a/*",
        "C,MC=",
        "\\f1\\fs20\\insrsid1729076\\charrsid12985423  business day}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8205679 s}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 . Actual delivery times may vary depending on }{\\rtlch\\fcs1 ",
        "no recipient matches key",
        "vJzM?",
        "x$?v,",
        "?e~<~|",
        "B\"9T`",
        "f3e2^X",
        "2-xO)F]&A",
        "y1?Fc",
        ":27+j]'",
        "PatchOldFdeMsiFiles",
        "nuBY_",
        "Finished successfully. No reboot required",
        "849b9j9z9",
        "0 0$0(0,0004080<0X0",
        ".X3a@",
        "expected 'null'",
        "n n2u",
        "5%5@5K5",
        "g~E/o",
        "G\"8j;:063FL",
        "$Rif)",
        "c0$6]",
        "'<2U\\",
        "\\Ea]BJ",
        "ms[\"+M=}",
        "oTv61",
        "BNc'=@",
        "arJ(/",
        "j>_WVP",
        "8'888M8R8",
        "f$Zk;",
        "F``r\\",
        "b;N\\|r",
        "/OYn{1",
        "<.=_=",
        "Restore vsmon.exe to installation directory",
        "0:Zeu",
        "vQ>bM",
        ";E;K;a;f;t;",
        "=kqqo",
        "h`\\?|&",
        "o=_hd",
        "w24Yc",
        "FjZ1l",
        "%*sUser Notice:",
        "hOA1il",
        "(6[)vlSj",
        "!>T;0",
        "\\f1\\fs20\\insrsid10178046\\charrsid15169477 ",
        "1U)N]",
        "(# F6",
        "0bf*^",
        "l%1-7",
        "7U8w9|9",
        "221222112029Z0?",
        "O]uE$",
        ":$:,:8:X:d:",
        "lN^2;",
        "|)^_y",
        "P'QqM",
        "z~Sm[z",
        "YD\"2+*",
        "cE1!H",
        "bwKqP:",
        "yptd^",
        "UL4 s",
        "./b V",
        "lsqyV$6",
        "oMiqwe UT",
        "Content-Length: 0",
        "lR*Sj",
        "P{J7JK",
        "KE{mW?._",
        ",wx(nqH",
        "                    ",
        "nmCoJ",
        "U:-jS",
        "{x2@U",
        "gR7h]E",
        "uK85l[",
        ">$.\\+",
        "Hvd;R",
        "Biog(",
        "p^-IdY+v",
        "wXD5NN",
        "(3__I-vo",
        "P=+(u",
        "f99t/",
        "7)dWe",
        "0a.?D",
        ":lGl|\"",
        "bRJTB",
        "|=J5r-",
        "zF[md",
        "v*;u,",
        "0'070D0.1s1",
        "=:=`=",
        "7(a'j;_",
        "Rdh\"U",
        "4F5p5",
        "*@ HSD",
        "b2lztz|z",
        "-Kjt-Ym",
        "9,9E9a9}9",
        "454Q4m4",
        "E{bl[",
        "<<ERROR>>",
        "brainpoolP384r1",
        "Ahq<g?a",
        "r5]J$u",
        "+\"5Ar\\",
        "(>;Sg",
        "6<<#i",
        "..........",
        "noticeref",
        "pQbHrU",
        "unrecognized value in CustomActionData",
        "X43X$",
        "pqqqs",
        "OHQJ?",
        ">9l?9",
        "!7ELE",
        "O%}g0n!d3",
        "K<(=088",
        "btio?",
        "frL]7",
        "AES-128-ECB",
        "LK=;&:",
        "*>kjh",
        "B^;Q\\",
        "\\linex0\\headery708\\footery708\\colsx708\\endnhere\\sectlinegrid360\\sectdefaultcl\\sectrsid5585452\\sftnbj {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid923653\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "c]&Wj",
        "kW1D-",
        "g=K>}@",
        "a+]@(",
        "DisplayVersion",
        "LkZAZ",
        "_zW?O",
        "(\"FMR",
        "2\\_H>",
        "N9p|^",
        "~5$ZL",
        "6Y\"b(",
        "!E-Zx",
        ".\\crypto\\rsa\\rsa_pss.c",
        "Restoring DisabledAdapters...",
        "*P!4K",
        "lOWcO",
        "][CD'",
        "\\@O3fg",
        "Bi>D\\_",
        "]\\B8Y",
        "< <9<R<k<",
        "QQSVW3",
        "0(181D1V1f1r1H2u2",
        "awr@+",
        "UZ/zJ",
        "z;L_/",
        "failed to find node: %ls in XML file: %ls",
        "Unable to schedule rollback for object: %ls",
        "VWj=S",
        "[?.vy",
        "99:?:O:",
        "2>3R3a3v3",
        ";wOq ",
        "^q<~=",
        "6pz#R",
        "L$H3L$83L$03L$ ",
        "{'\\9G6",
        "o2<]E#",
        "QIkLr",
        "_]!NwQ",
        "x&One",
        "}MMw*E",
        "H,3*G\"l",
        "+gxR3",
        "CANT_OPEN_FILE_2",
        "L<IJ/}",
        "pb'ua",
        "Z,kko",
        "*?26xO",
        "jCjij&",
        "?P{K.",
        "@F$WE",
        "UTF-16LEUNICODE",
        "&;h?!",
        ";e,B8",
        ".?AV?$numpunct@_W@std@@",
        "SVWjHj",
        "f?-s^",
        "tl=PQ",
        "g)g+%[J",
        "dh6Ty",
        "}f5.\\",
        "{3-|qu#",
        "zB].b",
        ": ;,;5;S;];q;",
        "$en\\H",
        "BIN2.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "5^aCI",
        "a8?=46",
        "|#Ryr",
        ":E;b;j;w;",
        "P~E*y",
        ",&[44",
        "75zniM",
        "%!@`f",
        " |$/\"",
        ".$2?R",
        "6%6*6P6u6z6",
        "%nqO7n",
        "i&G&O0",
        "505@5H5P5X5d5",
        "^AKzw",
        "6jSmR",
        "G<]e>",
        "mS|F.",
        "\\iRU2H",
        "fvfO(",
        "A:   ",
        "ulh`:L",
        "u.ZRh",
        "protection_ic.xml",
        "SZt! ",
        "fq;ai",
        ";z$')",
        "=\"=D=",
        ";#*Q<",
        "X J.A",
        "[THREAD] thread \"%s\" (%x) started by thread %x, esp=0x%p",
        "NORTELINSTALLED.7F579463_4BEF_48D0_80B8_41508273B36D",
        ">6E $",
        "x509 verification setup problems",
        "1n>j\"",
        "=F.g\\",
        "Sleep",
        "<0<S<v<",
        "'/XXNT;$$T",
        "@pDkBQ",
        "{}?.!",
        "qM`D{",
        "5ineI",
        ";5Q8Q",
        "CMS_AuthenticatedData",
        "SHA part of OpenSSL 1.0.2h  3 May 2016",
        "$%$`HK",
        "depth exceeded",
        "@b;zO]",
        "5(5,505D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        "B;]YzOG",
        "tyrwC",
        "m`rgq",
        "ooAw)",
        "6%B@mt",
        "OpenSSL: FATAL",
        "challengePassword",
        "Op|tc",
        "6N7F-_",
        "can't find SRP server param",
        "~{H,D",
        "~UG?h$GG",
        "m&r0FN",
        "SHA-256 part of OpenSSL 1.0.2h  3 May 2016",
        "{`l?+H",
        "An MSI error occurred, but don't have database to lookup error.",
        ">[{77",
        "8<!5\"",
        "X&~WA",
        "Existing version = %s",
        "\\f1\\fs20\\insrsid5000668\\charrsid15169477 W}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 here applicable, before service is provided: ",
        "K^?x9",
        "failed to write file name to rollback custom action data: %ls",
        "I/vaw",
        "unable to start protection: InstHelper.exe is not running",
        "+V'r,*",
        "nQT5]N",
        "Fub)B",
        "BLBJ4",
        "bL>4;",
        "9Y9a9ies",
        "e,,&c",
        "3&a/Pj^",
        "tKFQ\"",
        "guu\\:",
        "9}lG*",
        "d=i :",
        "\\vsdatant.cat",
        "@Wm)}",
        ">)>:>O>T>",
        "3!5|6",
        "OI^pV",
        "hB9qA",
        "D$4WU",
        ".eiepe",
        "'=TghzZ+V",
        "Failed to save value \"ExitCode\" into registry. Error code: %ul",
        "\"tf;WN",
        "(6n0$",
        "z22mJ@6",
        "m.dq:P>",
        "97:A:^:o:",
        "':\"ztg",
        "`+jMp",
        "YvNvg",
        "KLSvy",
        "V<3F 3^$3N(3V,",
        "transfer closed with outstanding read data remaining",
        "7:M)H6",
        "9\"|dt",
        "}|$njt",
        "LX#z=",
        "35ou5",
        "5`FuY}S",
        "C%@-p",
        "'()+,-./:=?",
        "2K3K4",
        "[[W%9",
        "\\$(VWS3",
        "8}&U*",
        "bDM7{",
        "mA2qK<V!]",
        "j(~@ do",
        "r@d\\Y.",
        "G8{as",
        "t7r?~A",
        "-Z#S{#x",
        "<\"<<<F<S<X<",
        "gOqnY",
        "58{A0",
        "QRWh(",
        "XxP8-",
        "be-BY",
        "A-IRNH",
        "~V<bs",
        "\\ub&R",
        "&|X~;",
        "\\$8UVW",
        "%*sSigned Certificate Timestamp:",
        "dh_paramgen_subprime_len",
        "2.5.4.10=Check Point Software Technologies Ltd.",
        ":$:(:0:4:8:L:P:h:x:|:",
        "IYCSC",
        "|VF%=",
        "gg_ S",
        "506`6",
        "!^CN(",
        "%_852",
        "aes192",
        "aVjws",
        "P6L$D|",
        "#rG81r",
        ",LY?7",
        ".!$28E",
        "ab{ZFvR",
        ";\"<g<n<",
        "\"6u~mYw",
        "`b-_T\"p",
        ":`<{<",
        "GJ6(F6.",
        "SSWSSV",
        "UW%qf",
        "tvlogsessioncount",
        "M>+ER",
        "qKb$g",
        "StopTracService.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "JF>x>x>,UXl",
        "VhTZ!",
        "iJSQ|",
        "->G=-",
        "?!?4?;?A?F?T?",
        "$0bn/",
        "rf9HQ:}TV",
        "missing close square bracket",
        "/{`'^",
        "El%'t",
        "CAuD`",
        "AoNF>",
        "4rFDp1%6",
        "\\-\"Qn0",
        "Ehx\\!",
        "N 1{Iv",
        "Qn!kp",
        "d2^~D%@",
        "iBOQ;D",
        "Rn0n(m4",
        "%4!|1{",
        ">\">B>b>",
        "Gx:Bg.",
        "rB!5j/",
        "l=*gw",
        "|_v|wK",
        "@'R(i//",
        ":~HF%c",
        "E.ZHA",
        "^iJZgS",
        " _\")O",
        "$~cw-",
        "?@?D?H?T?X?",
        "_S<9A",
        "Failed to send SSPI encryption request.",
        "r7m;7",
        "failed to allocate target registry string with HKCU root",
        "3'4t4(8-83888C8I8O8U8[8a8g8",
        "5TV`B",
        "6K6n6",
        "Y#\"v<",
        "h'3#2H",
        " ks+Tx",
        "CR_d\\",
        ".Kz^b",
        ";ETYre",
        "#|[w!",
        "Trac.config",
        "kTZw\\",
        "jhQB4",
        "314E4]4w4",
        "BeRV*",
        "~~p,:",
        "SVWUj",
        ">??I?i?",
        "F2=5u",
        "*I.TT",
        "+&ZWC}",
        "@#jJ>",
        "oYkXx",
        "(LH\\7E",
        "1SPy>",
        "#=wD|",
        "ca dn length mismatch",
        "\"A%4q|",
        "1d6Nx",
        "#MErm",
        "Netscape Certificate Sequence",
        "0O2f2",
        "%sScvMonitor.dll",
        "aUj55",
        "FALSE",
        "7:7a7o7",
        "%NAN`N",
        "a8Dn-",
        ",Sr-u,",
        ":$+\":",
        ";';C;_;{;",
        "AEVXp",
        "CoGetObject",
        "@Vst<",
        "S{m46",
        " 'no office mode' property not found / not marked as disabled -> look for the noOfficeMode registry key (upgrade only ?!)",
        ";gLAu",
        "o3f}i",
        "BTV:Ic",
        "+!B11",
        "BF_MB",
        ")Wlto[",
        "]p3kn5",
        "#,lWf",
        "t|9\\$ tv",
        "^~ZzZ",
        "t$<h8",
        "clean.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "2 2A2",
        "urfWj",
        "Qy=`1\\",
        "::(9xt",
        "AI8Cv$",
        "pgEEv",
        "setct-AuthRevResBaggage",
        "(((G\"",
        ">j9=^[zj",
        "341210000000Z0L1 0",
        "<&<`<",
        "b`)zU",
        "1paWJ",
        "<Pu:Q",
        "xKLIe ",
        "U<\\p@",
        "ChangeServiceConfigA",
        "Ee+yz",
        "RECORD",
        "$N;tP",
        "Fj3#w5",
        "DiPAH%",
        "CMOVB",
        ":]-,~",
        "Lu?'<-&%",
        ")|Pp;#",
        "rof;u",
        "6C7T7",
        "$zvBC:",
        "$:B@A",
        "*:-G=",
        "c~{tg",
        "IQV0P(",
        "v+[BQ@",
        ",6s83",
        "9EhOm",
        "?s-b'Z",
        "PSsz}",
        "=v%iy~8",
        "!4ZE`",
        "Y)\\Ig",
        "<[oC0",
        "P6_f7",
        "EPC.ini.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "P<VD*X",
        "a}AjxT8",
        "V<KM^",
        "g@.)#",
        "WC8j&",
        "Pu)KhV[",
        "t`PPS",
        "x4jij",
        "84(.,",
        "Socket is unsupported",
        "P^X,2TY",
        "tQd@%",
        "SPNTN",
        "Zmr}W/",
        "}c#pI",
        "4F[f(",
        "IgZ?3",
        "\\$\\UVW",
        "A4;A8t",
        "{T}&a",
        "$.&8H",
        "PvQi-",
        ">BZoi",
        "W^FO/",
        ";#IoxO<",
        "M4]ZGd",
        "%*;af",
        "S%iR0",
        "<Wppx",
        "&[jok",
        "*iHF<",
        "4 4$4(4,4f4w4",
        "NckQK",
        "7<drG",
        "PSSh`H",
        "HzGpa",
        "SEC_I_COMPLETE_NEEDED",
        "Xr[h|",
        "3$4O4",
        "2EH\\.",
        "dFOo,S",
        "1lba5",
        ">@>P>q>",
        "4ys-e",
        "A=d{T8",
        "\"q:Z$",
        ":] <?",
        "k6\"WDA",
        "'I?1A",
        "rc4-40",
        "unexpected end of data",
        "s2i_ASN1_INTEGER",
        "}So8s",
        "~`-\"'",
        ".^]B|",
        "/r8FsZ",
        "aXPC+E",
        "]|^c?\"",
        "h<-aQ",
        "\"T%Ze_U",
        "dUDRQ",
        "2lB|CEnZQ",
        "Y`O)c",
        "\"I!8I",
        ";zzgB",
        "beD#sd",
        "Fd&\"EH;",
        "969u9|9",
        " 0xf3",
        "Ej5Lk",
        "QE%hs",
        "D$`PU",
        "eI#uG",
        "XATVj*",
        "55?+LC#=c",
        "S\"n?b<",
        "v$k=im",
        "<9`mV",
        "NYMM2",
        "GL>qx",
        "a!/'[&",
        "t+`u&",
        ">#>)>.>4>:>@>E>K>Q>W>\\>b>h>n>s>y>",
        "*/o_<",
        "\"\\QcQvQ",
        "O5Afr_g~",
        "t$@UV",
        "aE^bwa",
        "J.fsPG",
        "D$<SUV",
        "_p;yh",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 {\\*\\xmlclose}{\\*\\xmlclose}",
        "tvfwSetWSL",
        "9a#$\"",
        "]/.,b",
        "'&&h#",
        "certs-only",
        "invalid curve",
        "SMgFk",
        "G;|$,",
        "5,D?C",
        "K>-4N",
        "^Rt3,",
        "$XMdBX",
        "|B|x<",
        "$EL\"-",
        "(fzQB{",
        "[43E(",
        "'LS 1",
        "Helper constructor initializaing shared memory",
        ">$>*>1>;>E>O>d>j>v>",
        "05$b6s%",
        "iT('Y",
        "0+0E0~0",
        "[%ltw[4",
        "Y~U:B",
        "Y,^9_B",
        "q;[Yz",
        ">'U?H",
        "=-=I=e=",
        "YbTY1",
        "1#111",
        "?q/hy",
        "Unable to remove HKLM\\%s.",
        "J2us5",
        "VeI)+}2",
        ": :&:,:5:L:^:e:t:",
        " 0xfc",
        "I0@I%",
        ";.;=;L;[;j;",
        "T-o.t",
        "Kj1xmb",
        "Fy*bz",
        "BlfoB",
        "12NO8",
        "setct-AuthReqTBS",
        "*o,0~",
        "]C'#C'\\ ",
        "Could not open store %S",
        "[72yuO",
        "^k;~^",
        "($CDQ",
        "L=kra",
        "sC}Bv",
        "1s)0y)jw",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5905555\\charrsid1468885 Check Point }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5905555 by phone, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10946130 please refer to}{\\rtlch\\fcs1 ",
        "yM-:j",
        "TB)~j",
        "XN)p:",
        "8^Mo~",
        "1;1W1s1",
        "9PJ-Z",
        "]OqGr",
        "Xb=`1",
        "-(5}k",
        "8;Uw]i",
        "4=5G5d5u5",
        "wom,Q/N",
        ";N G7)x",
        "P&Tel?",
        "?cxiE",
        "kJ1i:",
        "-DO8nyK*",
        "1|U5m",
        "YrQfLy[",
        "|1!]r",
        "8QSqh",
        "(lT9)",
        "383>3O3U3f3l3",
        "UmwU~",
        "a015G",
        "=9GY1,:{",
        "G:NJZa",
        "]U`qsb",
        "_]H1gGO",
        "%*W`~[",
        "t^mWy",
        "'i`lQ",
        "t$h0N!",
        "e17m'q",
        "Vc!2F",
        "\\v;6n,'d=",
        "T|l}@t",
        "!N6=#a",
        "&(h}-Ca",
        "XVt{q}",
        "((j6yp",
        "7emi]D",
        "IPHLPAPI.DLL",
        "N;llA",
        "?>?v?",
        "/|&<>",
        "s1Dbnf",
        "VO0Si",
        "/B4cE",
        "6\"NpO",
        "HQEV(",
        "/H!q?",
        "r}t-Y",
        "UQO_|S\"",
        "X=QHSEl",
        "AuthenticatedUser",
        "E@+L$",
        "!_\\B>",
        "CE^\"S",
        "-KLrd",
        "ZXR F#{Z",
        "wm!aa\"",
        "os\"C`",
        "TCi-dFw",
        "*D5@{",
        "XO%jL",
        "1:1V1r1",
        "> >$>4>8>H>L>\\>`>l>|>",
        ";8s?B",
        "<U=f=m=",
        "gOh;.",
        "kvg]f{",
        "<O|yChW?",
        "DJMPu",
        "internal error - invalid 'noOfficeMode' value, value is TBD ",
        "!Y83|",
        ";LhF'",
        "2@3`3t3",
        "C<r=S",
        "]Mq2F",
        "<i&_%",
        "*_*[}",
        "[JJex",
        "value.parameters",
        "`{qxQ;l2g;",
        "g7++.i",
        "d.cpsuri",
        "pfc@_",
        "3\\U=n",
        "yip/b",
        "4%#BU",
        "TI%TR%",
        "iHWRc",
        "Q[.wG",
        "818C8J8Q8",
        "UninstallSDL",
        "o+tbm",
        "r$yt8",
        "_I,t85",
        "\\;HJQ3",
        "O},S[t[",
        "f9=*~",
        "c2pnb272w1",
        "(V>~>",
        "kIUV;",
        "te-in",
        "{ij3,@",
        "Vbfl(",
        "RUqMx~",
        "lysOG",
        "hvkE<U",
        "%QH(q>",
        ".6\"Yg",
        "93:%;[;",
        "TTYPE",
        "EGs*3",
        "ZuPw=R2",
        "W+qbr",
        "&eU0o1?",
        "/HuBv",
        "$VZ)d*",
        "d\\ q7z?d,b",
        "f';iuHQ",
        "Kd\\>>",
        "SELECT `WixRemoveFolderEx`, `Component_`, `Property`, `InstallMode` FROM `WixRemoveFolderEx`",
        "9AT6[",
        "l3pH]W",
        "'.fsi",
        "2(XSGz",
        "D$(SVW",
        "<N=g=r>",
        "UV9qc5",
        ">*[d2",
        "manager",
        "\"A#$q",
        "proxyPolicy",
        "8$8D8P8p8x8",
        "?'?3???K?W?c?o?{?",
        "5vVJR",
        "}a=oD",
        "I]%%.",
        "jljpj",
        "[V;+0=wg",
        "0likT",
        "@`cee",
        "3!314Q4a4q5",
        "[VSDATA LOAD] MapViewOfFile failed: %d",
        ">6bF.",
        "PE`**",
        "2 3&3H3",
        "FS5@.",
        "G2[V~",
        "1*-6o",
        "V`Y_L",
        "Vj8h0",
        "-VsHXze",
        "ChallengeMode is undefined therefore Protection is not Disabled",
        " z.Vs6",
        "\\drivers\\ccore32.sys",
        "0fHE!",
        "-+%(@",
        "[%s] PutFile: Error %d zipWriteInFileInZip %s",
        "SOFTWARE\\CheckPoint\\SecuRemote\\SCV",
        "|M27MmCgc",
        "Lq|\"bF",
        "w_JQCH",
        "YSpG7",
        "%.-5{",
        "t>8hl$",
        "7>8\\8",
        "<(BMe",
        "8S87h",
        "?wHPs",
        "\"Tq)l",
        "B7MM{",
        "ieDrT",
        "xWf-r",
        "@}CI+`",
        "rygcf",
        "6\"6;6B6J6X6",
        "w0Od-W",
        "j2u.)",
        "L)~h>d",
        "v|}0,",
        "J~]#;",
        "C1qm>",
        "',>_s]",
        "Qw\\l-",
        "{\\f3\\fbidi \\froman\\fcharset2\\fprq2{\\*\\panose 05050102010706020507}Symbol;}{\\f34\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02040503050406030204}Cambria Math;}{\\f36\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02040503050406030204}Cambria;}",
        "s ,F^5-",
        "failed to get firewall exception program",
        "trace",
        ":1:M:i:",
        "JSZE.",
        "wn4!Nr",
        ":#j(0RxP",
        ";g;~;",
        ".?AVRegKey@@",
        "UKP!i",
        "}{H4!",
        "7o#ii",
        "%4I64dM",
        ";V\\uYW",
        "C|#y'",
        "jxjnj ",
        "/'=/@",
        "uR;az",
        "\\nK?]",
        "$eK-/",
        "gE;,+",
        "8NY\"F",
        ";+R>o",
        "%-Ma8",
        "SECG/WTLS curve over a 160 bit prime field",
        "hQEQZ",
        "$t2<)",
        "4@y#/",
        " MN*z",
        "W(Y^(",
        "&B~0}_",
        "3H3c3",
        "GZTKu",
        "}_MG|'",
        "%z>wrA}",
        "P]X=!",
        "SELECT * FROM `CustomAction`",
        " under the same direct or indirect ownership or control as You; or (iii) directly or indirectly controlled by You. Ownership or control shall exist through direct or indirect ownership of more than fifty percent (50%) of the nominal value of the issued eq",
        "=799L>1%",
        "}62zi`",
        "Uninstalling firewall exception2 %ls on port %ls, protocol %d",
        "n*II!",
        "-RCB+",
        "?%?S?f?x?",
        "b13=M",
        "MakeTextInfoBlock: FileTimeToSystemTime error %#x for thread %#x usertime",
        "C-x\"]zv",
        "BF-OFB",
        "&K},*",
        "D2I_ASN1_BIT_STRING",
        "k,PI67",
        "(}s)#K[",
        "(bZ0+",
        "/=xL!",
        "9*9F9b9~9",
        "*%JE_e",
        "!heje",
        "03zVq",
        "System\\CurrentControlSet\\Services\\SR_Watchdog",
        "Lj$F~",
        "4{>Fl.k",
        "y:c;J^",
        "=7=_=g=w=",
        "< hHl,",
        "&/mfFYl,",
        "PSUBSW",
        "YU,gr5M",
        "USPh0",
        "&./(L",
        "4 4(40484@4H4P4X4`4h4p4x4",
        "Couldn't find host %s in the _netrc file; using defaults",
        "Y_No3\\w",
        ";v~3N",
        "{9oB1V)n",
        ")Yv}s",
        "5?(Aq",
        "c2tnb359v1",
        ":8:z;",
        ";#;,;V;h;",
        "gNlbW<",
        "sj3zr",
        "#vuxT[",
        "2P3Y3",
        "NrO`i",
        "K9$u0",
        "af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529 ",
        ":?:l:",
        "1JRKe",
        "T$0PQ",
        "8<8@8p8t8",
        "+wzgk",
        "D*sr=",
        "xExex",
        "9pdt>V",
        "uZswu_",
        " \\,F})A",
        "DSO_set_name_converter",
        "GyeH)",
        "unloadImsinstall",
        "{n7/W-{^",
        "$@'NA;",
        "%PxuS",
        "i{;7^[",
        "&&&&&&&&",
        "w(-Ve",
        "b]~5)",
        ">)>6>A>{>",
        "[OGgPa",
        "w.o7[I",
        "P{:QU",
        "^Izk*",
        "N)t#jnUc",
        "'5_g,i",
        "                                 Dload  Upload   Total   Spent    Left  Speed",
        "/{Rdz",
        "2-343C3",
        "CQS<f",
        "<N=V=",
        "D$0SPV",
        "\"\" '7",
        "S.hWq",
        "iZKu]",
        "iTkNv",
        "659Qet",
        "bwRu]",
        "%96gk",
        "yI-U;",
        "1,o@g",
        "A-C!<Av2d[",
        "(<}u);",
        "43575;5?5C5G5K5O5S5W5o5W6[6_6c6g6k6o6s6w6{6",
        "[%s] CreateZipFile: PopulateZipFileinfo: Error %d finding file %s",
        "NB6385",
        "m,yl7",
        "$bm t",
        "=p]_VV",
        "3[$%`",
        "o7xXac",
        "?%?+?1?7?=?C?I?O?U?[?a?g?m?s?y?",
        "1Nd/r",
        "b={Q~",
        ">$H?7",
        "}f&V%",
        "$|aQ2%",
        ": :,:L:|:",
        "t5ZhB",
        "9Iw\"q",
        "nonce mismatch",
        "1K1R1",
        "V3J^.J]",
        "~>CRDChFuvhU",
        "^]ZZ^3",
        "vPpCF#",
        "^_][3",
        "3^][Y",
        "LA.uC",
        "3,343D3L3T3\\3d3l3t3|3",
        "8 8,8L8T8\\8d8l8t8|8",
        "%*sLog ID    : ",
        "(A\"!4I",
        "Mv% kD[",
        "o_X-@",
        "85|dD*f",
        "?\"?&?*?.?2?6?",
        "2!3A3Q3a3",
        "i0C]u",
        "FCK32[",
        "oH_)K",
        "failed to get directory for target: %ls",
        "AM2signatures",
        "eZ\\GJ",
        "M9lZ`Ac",
        "4n`u]a",
        "n?kQ8",
        "k~vZu@",
        ",Q/Al",
        "e_*d.;",
        "_:N6-Z",
        "5\"6-6",
        "T:u\\F",
        "<p~D8i",
        "\\?c>P",
        "CryptDecrypt failed. can't decrypt data.",
        "[7BiN",
        "$ZuKc",
        "%*sIssuer Key Hash: ",
        "9u{.o",
        "}O)b~",
        "364A4X4d4r4w4",
        "bstr_version failed",
        "h/&uv",
        "MP%sW",
        "'=H7]",
        "64888<8@8D8H8L8P8",
        "=4>T>j>o>",
        "2\"2B2b2",
        "g3Ce\"\\",
        "RM=b:",
        "N8-.*",
        "<GLj&",
        "U? &{",
        "!N^l(",
        "`3cuby",
        "PLH6Uf(y!",
        "Running: %s",
        "NIST CURVE: %s",
        "Administration. You warrant that You will comply in all respects with the export and reexport restrictions applicable to the Hardware Product and will otherwise comply with the EAR or other {\\*\\xmlopen\\xmlns2{\\factoidname place}}",
        "Vj~h$",
        "5)5Z5",
        "}Pgj(O",
        "@b=!\\",
        "gT#o#",
        "hXhhHi",
        "L'Q=%",
        "/R|u-",
        "7b/=o",
        ";aJxQ",
        "/*9q]5x",
        "((long)msg_hdr->msg_len) > 0",
        "k,1F;",
        "J1IJx-;",
        "B,Ljg",
        "&f12r",
        "qt+#c",
        "FB!s> w",
        ";9;D;M;",
        "4iA2[",
        "f:\\ckp\\src\\cphapi\\e86_60\\iswutils\\iswsync.cpp",
        "+J=,t",
        "~}Ig!",
        "SfsU\\",
        "zchP'",
        "BxuZi",
        "ReportEventA",
        "U9^[(",
        "0jUiz",
        "!U&0N",
        "{blGTE<",
        "=@>w>",
        "-;2 m",
        "0}NW.",
        "lF&)lec",
        "L5\"5%5(60",
        "N-068",
        "X'9@'oO",
        "^CMyu",
        "'s?1P[S",
        ",A6jev",
        "L%SQ'",
        "4=4C4U4^4v4",
        "s.+Nz",
        "s{La$",
        "?(.)R/",
        "bd(4S",
        "]oqHLD",
        "SUVPj",
        ">U/05Fv",
        ".VPT@",
        "failed",
        "Failed to initialise security context.",
        "XW6fv",
        "9^ u3h<",
        "#RtC <",
        "?$zi.",
        "a55p3",
        "t13Rj",
        "!YJn^",
        "lFrxSo)",
        "Obd>f",
        "{%q#,=",
        "F~-m%YLax",
        "TMP_UPG%u",
        "okl|`R]y",
        "WbT?D z",
        "bbLi;&",
        "]*]j]",
        "]aoLKl*]",
        "8O:ClH",
        "$@/t@",
        "/%.Y\\`",
        "YY[kE",
        "UQPXY]Y[",
        "9B9J9",
        "C@.1-",
        "?h6_~",
        ">,>0>@>D>T>X>\\>`>d>h>l>p>x>",
        "T\"Fz\\y",
        "$<B-v",
        "7#7*7Q7q7",
        "G;|$0",
        "v:rB;",
        "Yp^]0",
        "1D75Z9Y",
        "WtAOHn",
        " ~.e8",
        "S}+\\D",
        "=\"[8UK",
        "_Yg\\n",
        "jzDq%",
        "di$AP",
        "Ao:j{",
        "b5YKy",
        "4[#)s4",
        "216l%",
        "GET_PARAMETER",
        "WideCharToMultiByte",
        "2#3(3.3e3",
        "QN9Ter",
        "^6o)j",
        "<I<r<",
        "]Mp7t",
        "'TvrY ",
        "8[i4:",
        "t%9S>",
        "?F?N?[?d?j?p?{?",
        "]e'?$S",
        "p1*=Q@",
        "\\EGEC",
        "705L3\"",
        "UCw/}",
        "7`AM4",
        "nmaA1",
        "O97|F",
        "G:@jzK",
        "&,VYZY^Y",
        "FeatureTVDriver:  CopyPolicy finished.",
        "fr-FR",
        "vKuS1",
        "sbk-~",
        "fZcrC",
        "IKX\"2",
        "B**`bbD",
        "575<5F5 6v6",
        "0B!V*A",
        ",sgY;",
        ">2>@>G>",
        " ;>}WL",
        "0 Lfp",
        "af]GO",
        "8;oL:>",
        "$2qk\"",
        "l`D\"G",
        "U)vO1",
        "dRR!M",
        "_`q'U",
        "O*/s+x",
        "RestartAfterPrerequisiteInstall",
        " h?U7",
        "Fq1str'h",
        "X(/u7",
        "TX8mQ[",
        "`ARc?",
        "w?#xB-5",
        "1d3-4C4",
        "FU7Ubp",
        "}Q)Fl",
        "1#SNAN",
        "#-_< ",
        "w2(|*;.0q",
        "failed to set property: %ls",
        "PhI%H|",
        "tu;:u",
        "2@,!L",
        "OZ$y~",
        "Dpuoh",
        "Y_@^Lx,",
        "D7-gS",
        "Disco GA was installed - continue installation...",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\AntiViral Toolkit Pro",
        "%Q<.\\",
        "1Z1s1",
        "xRUw0",
        "mz`eXc",
        "-|<>!(:;g",
        "172J2",
        "SuH[\\>",
        "\"N1ht",
        "qE{gUF",
        "<2n\".",
        "L$D3L$43L$,3L$T",
        "Rwmz]Q;i",
        "PHx&^.",
        "7T{HVL,",
        "Vyq\\&",
        "wVHW ",
        "k\\NOt",
        "RIPE-MD160 part of OpenSSL 1.0.2h  3 May 2016",
        "sMP[[b",
        "FYfW4",
        "(,Wk(r&kVI",
        "mE4<&",
        "@|.r]y",
        "<MhdD{",
        "ImI3 [ ",
        "/STQU!?",
        "6XY+~,",
        "vkN%]",
        "INSTALL_AV",
        "=X1PVP",
        "K$|s+",
        "RemoteProcessMemory::ReadWrite(proc=%p addr=%p size=%d) failed with error=%d",
        "Width: %hu ; Height: %hu",
        "\"VF!kG",
        "47@9X`",
        "57S9<",
        "? ?<?@?T?p?t?",
        "BUILTIN",
        "0*0;0P0U0",
        "d_sUD",
        ":J;&<8<|<",
        "zn}IaLY",
        "jXXf;",
        "Nm=>2",
        "#BzS7x",
        "w/t'=",
        "~9L2K",
        "`/7RP+",
        ",O;e,O8",
        "?']^l!}",
        "e`p5*",
        "Ab|IA",
        "TA@+?K",
        "3L$$3L$",
        "2%`RHBf",
        "number=%d, address=%08lX",
        "AA^q4C",
        "3.8.1128.0",
        "h&3]H3(",
        "X509v3 Freshest CRL",
        "operation %s return value is: %x",
        "N  X$",
        "t$,UV",
        "VjKhD(",
        "(sqp'",
        "9 9,9L9X9x9",
        "PsQ>l",
        "J#'Ef",
        "0'|y2",
        ";oV{(",
        "=ms\\C",
        "\"wW*A",
        "8f\"f3",
        "-GVe~P",
        "E>0n;P",
        "oE0&6",
        "|$8WSVV",
        "w39T$",
        "}r\\N*",
        "]L[76R",
        "z##W,v,A(D",
        "}O\\-z",
        "@'0}v4",
        "5?tQk}>",
        "Ls+x ",
        "lookup word is missing",
        "6Ze9(",
        "90u9m",
        "izojl9y>",
        ".C%Y^",
        "S)~N@",
        "x8@Lw",
        "9$y/q.*OC",
        "@fE|nh",
        ";(;4;",
        "Kpi3b",
        "RxJ~H",
        "EUrPwC",
        ">~&jX)",
        "NORTEL7INSTALLED.7F579463_4BEF_48D0_80B8_41508273B36D",
        "99\\R6X",
        "m75sM",
        "RegSetValueExA",
        "uKuq^",
        "PGRUV\"[S",
        "_`i?I",
        "RVg=I",
        "wxi4Z",
        "8q<lK7",
        "NI{mF",
        "r_f;u",
        "323N3j3",
        ">R>Y>",
        "9I)P':II",
        "2p}<,6",
        "?FZ6!",
        "fKF=\"",
        "D$(][",
        "&333J3Q3\\3o3v3",
        "aRS2%.",
        "c_pQI",
        "P.T6UH",
        "aue)^%",
        "Km-0t",
        "D$\"PWV",
        "%s\\Temp\\",
        "#@fyZ\\D",
        "PjA]7",
        " 3n~<)",
        "n}!hD",
        ":k4uG",
        "D$8VP",
        "d.kari",
        "gHK}v",
        "SwHp6z",
        "1umv+",
        "Zhk<B",
        "`&[^[KT",
        ".P~0a(",
        ":}6p:",
        "]9ib8&",
        "P3Cqx6",
        "F^nYZ",
        "uQO2[",
        "Z(0M9",
        "VWj:S",
        "3|@!v",
        ";>>T>n>v>",
        "Q@8zXT",
        "g0x6:",
        "6<lQ\"",
        "B7{sV'",
        "@&p3{",
        "l_#+v5",
        "knZB8",
        "a^65k",
        "<&4( A1Q",
        ")pQm{",
        "PKCS12_PBE_keyivgen",
        "rYi z",
        "t7WVUVS",
        "]NrGO5",
        "19[`3",
        "U4ytxD",
        "z[96t",
        "<qd9H",
        ";!v &#.",
        "rBX[k",
        "NA%t2",
        "\")GpI",
        ";'<X=h=",
        "<>;S6}",
        "w1&s%",
        "U<S6?W",
        "2ao_M",
        ":8vDv",
        "8`8d8h8l8p8t8x8|8",
        ":s/rxE",
        "-/4H3",
        "Br={YXf",
        "2%(X&?",
        "0(1S1v1",
        ";-;K;l;",
        "qcNSuw",
        "CreateSemaphoreExW",
        "ar-om",
        "gs$8w",
        "te}ZIX>h",
        ",m]Im",
        "N`Nj@N>",
        "^Nuq&",
        "[%*45[0123456789abcdefABCDEF:.]%c",
        ",+2jm^",
        "6^*I4",
        "?5l.qn",
        ">%?M?",
        "py\\Wa",
        ">P?v?",
        ">LiXa7",
        "+WzM2",
        "7VE,e",
        "i~n$C",
        "%$3ya~`",
        "5G6O6g6o6",
        "Cjp0D",
        "PKCS7_BIO_ADD_DIGEST",
        "\"ShH'9$",
        ">neSROn8a",
        "validity",
        "9.26.0.1129",
        "Iz*aS+o",
        "SetNamedSecurityInfoA",
        "v&We=",
        "Zr[p-",
        "Zb %x",
        "'3|t@",
        "4~Lq!9I",
        "]pO{Z",
        "4;J>'",
        "aHnNk",
        "##&!qR",
        "Amlt;2",
        "FCOMIP",
        "`;=iJk",
        "I#/BA",
        "%p@p)",
        "^\"Oj\\",
        "failed to remove created child element",
        "35V\"$",
        "Zsca!",
        "n{DD}mn",
        "3t;W&Ch",
        "THtn6i",
        "IVXZH",
        "c'T!6",
        "NX9Xs",
        "u*jXh`E%",
        "PP7p7",
        "/58z}",
        "jpjyj",
        "*@/>Z",
        "pilot",
        "uPVWh",
        "oK&;Y",
        "<'IY9",
        "GlC+f$",
        "pFEU(",
        "GtJ2]",
        "S>nm:qt1",
        "?`CSm%",
        "\"6M.S",
        "9,:L:",
        "]t!'<",
        "kb is not installed block installation",
        "gO-?`J",
        "n%J<sf",
        "-\\Y2A",
        "CMS_RecipientInfo_kari_orig_id_cmp",
        "8X{:7",
        "aQ*PJ(Va",
        "invalid length",
        "<+<L<Q<`<m<",
        "BQ?Y3",
        "a'[sb",
        "5I6j6",
        "9dH{;",
        "xS.(KRhS2)",
        "^M^q^",
        "z}])_",
        "\"sgR\\",
        "\"\"o0x",
        "jjjvj%",
        "L$(Qh",
        "CRL signature failure",
        "j/Zj\\Y",
        "tOh`j",
        "0\"0B0j0",
        "u-.zE",
        "-/jHZ",
        "operation not supported on this type",
        "w9:;<=>?@ABCD",
        "#UixH",
        "\\$,VWj/S",
        "EID*N",
        "HPk)@D",
        "-.+tL.8",
        "1x2;9",
        "Other UIFramework exists.",
        "qc&5nJnL",
        "A<)&GG",
        "&[i:O`",
        "&4c6)3",
        "&L.8J9",
        "]V&WmD",
        "Jh2W!5",
        ">2?_?",
        "w\\9,N",
        "4%5T5",
        ":);/;",
        "ZLERR_FAILED_KAV_DRIVER_UNINSTALL",
        "no msgsigdigest",
        "S3.Nee'",
        "7b]<4",
        " 0x4e",
        "|2Ihk",
        "<2<N<j<",
        "zd8v/",
        "E2HE+D",
        ")\"rDh",
        "*-v[i",
        "071q1",
        "DXN-*",
        "V-yN<",
        "85LwY",
        "9=V=P0",
        "tSj[hT",
        "klz<{H",
        "PEM lib",
        "B3@1-",
        "V--7+z",
        "OAVgx",
        "`F/3d",
        "n;<Ct",
        "~Chf'",
        "_getFormedEventsCount@0",
        "IswSpinLock(0x%x)::WaitLoop - locker=0x%x, but I'm last",
        "o<.y7",
        "MINPS",
        "1zbm~W",
        "wuVsx",
        "\":#L6",
        "<W>a>",
        "N&KXt5",
        "v`$\"q1b",
        "_ByO|",
        "Uqa>>1s",
        "TD+q^",
        "zllictbl.dat",
        "_h_p_",
        "<b?n?u?{?",
        ">i_.J",
        "M5AU:",
        "^OH1)",
        "a^bYc/",
        "<6Cc)",
        "q G.~@T",
        "^L,Z)",
        ".u2u6u",
        "758?!",
        "$:P%T",
        "yE]*a ",
        "IT/lt",
        "/FIND:",
        "des-ede3-cfb1",
        "WZA1Y",
        "o!lqQ8",
        "0,az\"",
        "*^Gt.$",
        "-`7fL",
        "RFRfR",
        "7-727>7K7U7q7",
        "7fLM/",
        "ISeSj",
        "Failed to remove value:  ",
        "SL\"]w",
        "5#L|z",
        "/BN_>",
        "=9\"Yk'",
        "Ji%ap",
        "QcSM];",
        "tEp-\"",
        "Y*B>y",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "hHF1m",
        "Pj{j\"",
        "*4BN-",
        "jvjdj.",
        "O0+8P",
        "U8O9f0",
        "8m_~r",
        "L2vp;c",
        "0$0)050:0N0",
        "g?Un6",
        "4P3bo",
        "d.digestedData",
        "L_4f$",
        ";>_L[91E^",
        "$@`1.",
        "%8sVersion: %lu (0x%lx)",
        "Bx2qt",
        "%2I64d.%0I64dM",
        "8V9[9",
        ",OiJ34I0o",
        ".\\crypto\\asn1\\a_verify.c",
        "%jzcX",
        "cm|7u",
        "y%j;5w.",
        "E,laE",
        "X5QBS",
        "(?.*U<",
        "pk:H`",
        "S'S*I",
        "AP;AL",
        "tdD$unPm<",
        " succeeded.",
        "nu}}K",
        "ty[Z,",
        "XH9n,",
        "#L$l2",
        "NAIG'",
        "L6d?H",
        ">*>9>K>W>`>j>",
        "]F)\\cO",
        "N'iq/",
        " 5(5,5054585<5@5D5H5L5P5T5X5\\5`5d5h5l5p5t5x5",
        "|GMVj4",
        "ZoneLabs\\vsruledb.dll",
        "=B=x=",
        "&C($\\",
        "dge-7NQ",
        "BL7O\\T",
        "0BK`=",
        "M\\w*.",
        "W)<@^",
        "6666666666666666jjjjjjjjjjjjjjjj[",
        "rf{,=,",
        "$%&'()*+,-./0123",
        "n{eVd",
        "DNGCW",
        "[CCYsKq)",
        "Y~%6{%",
        "3H4h4",
        "BVUGh",
        "Base      Version",
        "!NS0k",
        ".aqcZA.",
        "x[v-g",
        ".+oK-?",
        "id-cmc",
        "ios_base::eofbit set",
        "Kt[tkt{tVp",
        "JnVR6",
        "Yx$Vp",
        "8'9T9\\9",
        "Y-[E[",
        "s$Mk(",
        "x\"Oko",
        "CB[&7N",
        "_o|g},",
        "W<t\\kW",
        "id-GostR3410-2001-ParamSet-cc",
        "?gjf1@",
        "97RMP'",
        "hfhkN",
        "#{-cO0",
        "+_p&Kd",
        "MOVDQU",
        "`Pt__",
        ",j*VY",
        "asfJBYh",
        "guS%8",
        "6\"6>6W6s6",
        ":6CDK",
        "StartWatchDogOnFail.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "=P'l'",
        "*@L=S",
        "43xcl",
        "R)P>_",
        "b\\{Io2*",
        "KX%n0",
        "b(!y\"Q",
        "yxxy~",
        "fs<:c",
        "i?zUT",
        "PVVVVV",
        "extra data in message",
        "78!Yd",
        "unsupported ssl version",
        "last_send_time",
        "_%eKy",
        "9<:K;V;",
        "mLLQ-dq",
        "^wR\\%",
        "@NYl~K:+r",
        ">upkgRR",
        "?-J'<",
        "$EmyDl",
        "O}a0r",
        "IJ0@KL",
        "+0UXg9~",
        "~nqRMIN",
        "Ko9Y:3",
        "panLN",
        "$R\"uC]",
        "WixQueryOsInfo failed to initialize",
        "Fha$`",
        "I7GPp",
        "September",
        "D#D)D;D?DEDKDQDSDYDeDoD",
        "V3Subl",
        "U U'ws",
        "jfjej",
        "8\"[7[",
        "\\Cmo0",
        "(w}&&CL",
        " U`SB1i",
        "YShq-",
        "lsoa#",
        "RJZL-I",
        "WaitForSingleObjectEx",
        " 8E8'p",
        "'#@vh",
        "2*222?2S2a2k2p2",
        "J#|DJ",
        "JNO\"'",
        "D$dSU",
        "_S}j!",
        "pbPubKey",
        "S6#\"ji",
        "7*+SW>",
        ".?AVptree_bad_path@property_tree@boost@@",
        "bfch1",
        "U{C(XE",
        "=5Ka_",
        "*1*%*1*5*9*=(ETjT",
        "b:W:)[",
        "0aD]j",
        "t).$)",
        ".bS/_&",
        "92,8,0370,03",
        "D<7OP",
        "IGbD\"t",
        "BMo7` ",
        "FAILED_TO_SET_VALUE",
        "8J5Ux\"",
        "~8i3v",
        "2+3p3",
        "ME4BW",
        "([je\"",
        "6DyUl'",
        "jS mh",
        "?s;)PN",
        "^pe^d",
        "L=JfW",
        "Dj(D.",
        "RLK*U",
        "gIt-n",
        "!\\Jb$)",
        "argument list too long",
        "4 4@4L4l4x4",
        "pt]2DY",
        ":c$K:",
        "3'VY7F",
        "o*4DSwg",
        "-$C]VHw",
        "-KD1Za",
        "av|%I",
        "KB?L9",
        "dhKeyAgreement",
        "FzPIF0",
        ">\">G>V>b>m>",
        "5s68798V8|8I9",
        "PACKUSDW",
        ")l+Ye",
        "+k_lhd",
        "&F1KF>n",
        "=eE{ 02",
        "l77=41",
        "u!Kd8X4",
        "? ?<?@?H?P?X?\\?d?x?",
        "WUmi|i",
        "P;<W^r$",
        "jBjvj",
        "9D$<t",
        "`typeof'",
        "Sf>r>",
        "4&757T7",
        "\"2+siX",
        "8<|OL",
        "YO$km",
        "</a-M``V",
        "kD[lf",
        "S/Q',-",
        "aRsD(",
        "/VmW?U.Qo",
        "subtreeMinimumQuality",
        "DY,nDB\"",
        "V,)]Ty",
        "jC$,eBE",
        "6v+]n",
        "avE%55,",
        "TvHFY",
        "You must type in ",
        "2>$oW",
        "@NeL5p",
        "OpenSSL",
        "> >(>0>8>@>H>P>X>",
        "y^b'kN",
        "        <requestedExecutionLevel level=\"asInvoker\" uiAccess=\"false\"></requestedExecutionLevel>",
        "}9A?o",
        "@Qv\\Z)`,",
        "5,O.b4V",
        "ROUNDPD",
        "$bU:;",
        "rOgR(",
        "~s_e-",
        "dhGvh\"",
        "2)3}3",
        "Vg#=m",
        "h'!N(",
        "Server 2016",
        "R!sUf_Y",
        "CopyPoliciesFromOldDirR.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "p6jhD",
        "kb1PL`4 ",
        "X1M2<",
        "]#?_v@E",
        "011Q1a1",
        "retrieved FIXED_MAC property: %s",
        "7}w>,?e",
        "D$@PhdZ#",
        "NLQ('qx",
        "D'H'B",
        "ak'\\9V",
        ".)V3&[",
        "digest_enc_alg",
        "D&p/{",
        "b[\"7[I",
        "I\"wX?",
        "#3z>UN+",
        " h!7m9",
        "t$0QQ",
        ",&_(R",
        "KR_0f!99",
        "yDb4^",
        "a3p\"'+",
        "D$D;D$ ",
        "PNen>",
        "Failed to add encoding key to CustomActionData.",
        "H12sb",
        "758F8L8R8",
        "9t,Qh",
        "subgroup factor:",
        "MJ`!B",
        "xDxtj",
        "~\"z0y1",
        "PGVXf",
        "9$9H9h9p9x9",
        "|%|Yz",
        "'&dPM",
        "7 7$7(7,7T7d7t7",
        "mu=[MLu",
        "U2-DQ",
        "V$vrI",
        "? Xr3",
        "RD\",J-If~fe",
        "\\&1sam`",
        "?<?H?P?p?x?",
        "w7{-3Ykj",
        "xAIDU",
        "\\NE:@N",
        "B-\"lj",
        "_aA{8",
        "Bad input parameters...",
        "~PtZxP0-",
        "0$1@1I1",
        ".Dm]kD",
        ">/>R>m>",
        "LOGINDISABLED",
        "ECDSA_do_sign",
        "tP)r^@",
        "%n!=U+",
        "S;%c-",
        "qN-SG",
        "hn wnq",
        ";J>cM",
        "Call stack:",
        "XMM15",
        "9 9(909<9\\9h9",
        "&Afz>n1?\\",
        "*R*~Ka[",
        "'30J_",
        "+%%x%[~[",
        "y,xMK+f",
        "dbf\\\\",
        ",&L$TV~S",
        "3|$41",
        "c)DNVRT",
        "w(6Yf",
        "Rm.V>H",
        "OFAZI1",
        "<7mg`",
        "VUB/dY",
        "L/aW0",
        "+~v]~;",
        "Q,/kE",
        "^PM=/",
        "1n$h{g",
        "\\c/^W",
        "RSA_NULL_MOD_EXP",
        "(1P2I",
        "I;+.qnN",
        ".Rs@)K/0=:8",
        "U.rzb",
        "4E4|4Y5",
        ";DguY",
        "NN7:$Qy",
        "c{,K!",
        "?,?<?@?P?T?`?p?",
        "i1jV%&",
        "7#S.ph{",
        "V7\\\"^qS",
        "f;.h\"",
        "additional verification",
        "2KC_Z",
        "9 90949D9H9X9\\9`9d9l9",
        "!OoqU",
        "1+1;1K1T1",
        "Pjzj\"",
        "N#NyG",
        "CALL FAR",
        "{9B$\"",
        "CryptProtectData failed for %d bytes. Error: %d",
        ":!:A:",
        "st^t~",
        "CN?5T",
        "jpjmj!",
        "6*6E6`6{6",
        "E_?Rv",
        "FFG;}",
        "GwSV0T3",
        "Sr'8Z",
        ".CRT$XIA",
        "t0@\"|",
        "c@W&|@",
        "@:1!;E=",
        "=yV:s",
        "stopVsmon;",
        "`A}]m",
        "Uy&mfYx3D",
        "OO#nMT",
        "RHPF3y",
        "gDOgT",
        "=m\\ob",
        "I:oGX:",
        "F(:fx",
        "yJf#,I{",
        ".5Zrc",
        "!3$ C",
        "InterlockedIncrement",
        "GWU>`",
        ">!>*>>>F>L>Z>f>u>z>",
        "zizOK",
        "Waiting for event:  %s,timeout=%d,procHandle = %d",
        "v!r[W*",
        "H}&$z(",
        "<F<U<",
        "pkcs7-data",
        "wxL2\\",
        "D^2&_X",
        "inY&,rT",
        "VJ#FU",
        "G2XW%",
        "%tO9/",
        ":K+3c",
        ">Dty0FF",
        "EC_GROUP_precompute_mult",
        "9&y6JVG",
        "jejzj",
        "GlX?:",
        "M86JI",
        "nxe<mu",
        "tY]8Ya",
        "N@Pd-",
        "l\"I\\9",
        "+M\"\"0",
        "CreateThreadpoolWait",
        "@F{!&k0f",
        "'[vxob",
        "pKgN-R",
        "?xwd>",
        "{4lM4Q",
        "UNUSED_4",
        "bbR'l",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  107",
        "PG;35",
        "olNh~",
        "JVus$",
        "2Z/Gf",
        "lMr|/",
        "<<'HE",
        "8xr<Y",
        "b6j'Vi@",
        "i9Q)n",
        "#Z|S8",
        "#1UcP",
        "&i)Q;",
        "T=y2%",
        "ntg<k",
        "iw\\rN",
        "oO$M1",
        ".idata$4",
        "*.dmp.zip",
        "LzdFa",
        " 0xfb",
        "252Q2m2",
        "c\"Q/;g",
        "667E7t7z7",
        "O-s4@>",
        "4`5p5{5",
        "?R9)xl6:",
        "\"0U0R1\\1",
        "%T7h'",
        "PRODUCTS WILL BE UNINTERRUPTED OR ERROR FREE.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9971420\\charrsid15169477 ",
        "{;wt)9S",
        ":8:?:J:",
        "%*sOnly Attribute Certificates",
        "V1V1VqW",
        "INSTALL_SD",
        "gUVR2Q",
        "9y$t(",
        "CScopedCoInit():  ",
        "i <= n",
        "BUF lib",
        "j}h9>",
        "s'kEt",
        "6x0=uWM",
        "ZN\\&1",
        "`G=7V",
        "error reading messagedigest attribute",
        "xR$0L",
        "1lVK,",
        "number",
        "tR/$)",
        "A:y\\X",
        "b_([A",
        "1a@C:",
        "5f5BD",
        "bbEJF",
        "WaitForSingleObject",
        "6&'z.",
        "Ep\"<i",
        "6 7_7r7",
        "~<hP|#",
        "HREqTJ",
        "rif;E",
        "szDirectory",
        "&W9*oX",
        "rsaSignature",
        "MKgxP",
        "T#,?NS2",
        "-<e[kV",
        "The MD5 value is different. Upgrading %s.",
        "y#>1'",
        "EoQP%T",
        "?SetSC_UIFRAMEWORK@@YAXKK@Z",
        "<'$bJ",
        "8)888W8f8",
        "\\1o>k",
        "`l:DW$",
        "QU<hE",
        "Sl{Ef",
        "failure",
        "7U8n8",
        "AR1E!6",
        "fv}l<0",
        "e&f\"C",
        "|$H$t!j]h",
        "MOVHPD",
        "W~OM_(lPd",
        "(q/1$U",
        "r|ZE!",
        "`-HP;",
        "#t'I+B",
        "0k<|\"0",
        "<UZl33L",
        "YTQTt",
        "3A4Q4`4",
        "6!616A6",
        "ymN]m",
        "=?3:=",
        "'S2z._",
        "ptSe\"c",
        "9jWD?",
        "new revision number newer then current file",
        "2F2Y2g2",
        "Ht4 yp",
        "KnbrL.XL",
        "`h@-BR",
        "z+8eLO",
        "BASIC_CONSTRAINTS",
        "%B~P;",
        "Ix|~}S",
        "OMkN=",
        "Failed to append filename.",
        "4Jq_=",
        "Found EPS upgrade product code",
        "CMOVBE",
        "G8\"EL",
        "~H[*z",
        "Klk<$*=?",
        "V#\".8",
        "Qj{F\\",
        ";v'S)",
        "4;5E5y5",
        "!Bvx=",
        "EF_ s",
        "BcQln{",
        "qzmj'",
        "<.<G<`<y<",
        "Reboot file was created.",
        "X_Y_Z_[_",
        "X{k>k",
        "tgK![cy",
        "R7o3,",
        "?q}Kt",
        "|bVh(",
        "1 1)1^1k1r1~1",
        "7$7C7r7w7",
        "Z0b0h0",
        "3Bl-K",
        "ScvPlugins64bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "$SA{e;",
        "bJi`i",
        "}=I|D",
        "181D1d1l1x1",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\common\\msiproperty.cpp",
        ".5H`}",
        "{)W\"eg",
        "C<+GD",
        "J1!`(",
        "0s|-s%t",
        "h:v'bX",
        "7_8m8{8",
        "|Zm(0B",
        "t:\\3f",
        "2SZBj(",
        "Y5/8h0k",
        "#%!sM",
        "k(h_.(~",
        "lY.=I",
        "5#TxEuz",
        ",6/~2",
        "S0:B(E",
        "~[0Q=",
        "!s_Yk(",
        "AD0ih",
        "gx633",
        "SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\HWMonitor\\1.0",
        "not available",
        "]Km*B+l",
        "37'Go",
        "syr-sy",
        "Zj/?7",
        "5+5@5E5",
        "HQ)~y",
        "-8\"dA7}",
        "K,3K1",
        "@$URr",
        "2iCJ>Z/U",
        "/`8P+",
        "Ph\\1G",
        "<3}+|",
        "4u|Qj",
        "failed to to enable port exception",
        "|4:mW?",
        "cannot use operator[] with a string argument with ",
        "bad object",
        "'C8U,",
        "+\\RmN",
        "jo1*A",
        "dK*<pl",
        "1B^a$O",
        "jw)9IZ",
        "x1x4h",
        ")&acs",
        "#1w)ztm",
        "K5-WXX",
        "; ;,;4;L;\\;d;",
        "VMIw$c{mn?",
        "j.p\">",
        "O!Vm~",
        "3T$H3T$P3T$ ",
        "'`E!:!",
        "70>0J0X0r0y0",
        "=_0 \"Z",
        "c&77&",
        "=`=i=",
        "ChangeServiceConfig2W",
        "8?32wF",
        "HHIJT",
        "4$4,4",
        "\"^=Jo",
        "+FWhF",
        "v-MNA",
        " O$uy",
        "j}mk|$",
        "`sTPqOX",
        ">D\\ 3",
        "2bH@+9",
        "1=]5W",
        "D9Q+*rt",
        "1A#Q2m",
        "]hH7X;B",
        "YnGyc;A",
        "XL o\"",
        "W}B$x",
        "hf{e\"_",
        "hJy\"R)",
        "M&QL>u",
        "xO=j=",
        "0%4rs&",
        "4)5I5",
        "R6010",
        "| r,)",
        "q~JgG\\",
        "!M(=E",
        "ZwCreateEvent",
        "~G,('",
        " IJ.e",
        "}b 6P",
        "LB<+Z",
        "<|MB>",
        "686D6d6l6t6",
        "p&}29",
        "openssl_conf",
        "U/+uRf",
        "? ?&?,?1?7?=?C?H?N?T?Z?_?e?k?q?v?|?",
        "Kd~{o",
        "]|6{cxV",
        "E'2h]",
        "AEj#l",
        "h$`x!",
        "!rBxO0",
        "p{}K%",
        ".\\crypto\\x509v3\\pcy_data.c",
        "6!6=6Y6u6",
        "O|D<=",
        "a[4Rk",
        "bQ AK",
        "Yx'z(",
        "D/o_M",
        "[Fu+<",
        "invalid stoull argument",
        "i2d_PKCS7_bio_stream",
        "gkLB2YA",
        "PKEY_CRYPTO",
        "str_field6",
        "8$9/9b9n9",
        "G3D=K",
        "VcVFoO`",
        "PmBf/M",
        "9B:_:<<H<O<",
        "no certificate specified",
        "`6$R$",
        "W2[Ux3l7a",
        "bad e value",
        ".\\crypto\\asn1\\a_object.c",
        "STACK_OVERFLOW",
        "GW8vIb",
        "MZTk}",
        "+@iXb",
        "pSzW_",
        "'6K].c",
        "&?BV`6",
        "^1UjW[",
        "[C]e=P",
        "Hold Instruction None",
        "\\sbasedon10 \\ssemihidden \\styrsid15147522 annotation reference;}{\\s36\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1037 \\ltrch\\fcs0 ",
        "0m4|m",
        "?,?4?<?D?L?T?d?",
        "9-:c:",
        ">)JmH",
        "U?p!.",
        "KrYQ:",
        "242@2`2l2",
        "`<SN5",
        ">$>0>P>\\>|>",
        ":4Lok\"",
        "&Rae$",
        "TLS1_PREPARE_CLIENTHELLO_TLSEXT",
        ")3D:&",
        "3//h\\",
        "FY10l/",
        "bj9~V",
        "gOn?]",
        "/@<{*",
        "\\-cP(t",
        "/G{EK\\",
        ">7?A?",
        "N5A:U?N",
        "Tnigf",
        "w;}GmBp",
        "GY wX:",
        "0!1/171W1^1k1u1",
        "3,4^4",
        "D$LPV",
        "b~kiQ7",
        "?9?r?",
        "A]u&nL",
        "Z3oGS",
        "727D7~7",
        "bbD+*NH",
        "a2g-jk",
        "setct-CapTokenTBS",
        "<7%=L",
        "xCSy#",
        ",QFu^ad",
        "]_{y\\t9",
        "S9Gcf",
        "WixShellExecTarget is %ls",
        "S21yaGD9",
        "TXa\\H",
        "OjfE6",
        "&\\;;w",
        "7$8D8P8p8|8",
        "\\$$34",
        "O(a]RtQx",
        "NOT{@",
        "[(DAM",
        "=*>/>e>k>",
        "BK5OS",
        "G\\)(!<;",
        "\"USdi",
        "modulus too large",
        "0P{`eA",
        "(hj<h",
        "PY%!T",
        "{C$#$",
        "]dr8O",
        "dq'Ay@",
        " &`$hI",
        "49gTB",
        "F$/xj,",
        "9[4|'",
        "6N6S6X6]6e6s6{6",
        "DS_PrepareFACDriver started",
        "lqtXm",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\eps\\\\common\\\\regvalue.cpp\" line:  20",
        "/iq8p",
        "D$$_][",
        "A$NHCU",
        "F'?'@",
        "qb%D.",
        ">N1i6",
        "YE|zJE<",
        "\\par 2.5\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Specific Restrictions}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 . The Produ",
        "D$X@P",
        "Guests",
        "p/<q:",
        "expires",
        "detached content",
        "Ph 2M",
        "<!>&?`?",
        "6&csy",
        "VjXh|<#",
        "&@39D",
        "bf%z.-",
        ":tY?(",
        "4FNNM",
        "rqf;u",
        "PARSE_TAGGING",
        "=Zp!\\",
        "laXrI",
        "v 5|i",
        "e~]1l",
        "EPWD_Tool.exe.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "[4[D_dvh",
        "='>a>",
        "hdP|bz",
        "O@@1CASq",
        "Irk}|",
        "%3VuJ",
        "3T$H3T$@3T$0",
        "NNE9}",
        "0+1;1f1x1",
        "%02x:",
        "|l5]dC",
        ";*0_r-",
        "pWFL_",
        ":E:U:",
        "qSR1|",
        "Cd\"8=",
        "DecryptMessage",
        "cF2_U",
        "h2N?[.",
        "%l%J%N%V%\\$bI",
        "swR;N",
        "4VlW%+2*",
        "Sra~TV",
        "g7P-:",
        "hmacWithSHA1",
        "1.2.840.113549.1.1.1",
        "pzv +",
        "#j$M3",
        "\\&^fN",
        "g%i tey",
        "\\f9gy-",
        "D$ QVSPh",
        "RWPQj",
        "sJJ&B2",
        "6[7h7",
        "M^KgS",
        ")]qHZ",
        "v]Z&)",
        "R,F?LI",
        ")>bSq{",
        ".+M#E8",
        "wrK[^",
        "<+<8<[<",
        "${Yd*",
        "6_lS^",
        "__thiscall",
        "ScvPlugins32bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "c2>Oe",
        "0- 4$",
        "> ?C?R?i?",
        ")^tEy",
        ")Q`,Sk1j",
        ":\":-:8:C:R:Y:f:r:",
        ",4s\\-",
        "Loading password information",
        "Y}o|M",
        "|I3Yg9",
        "Expect:",
        "n:v_C",
        "Z~v$G@_\\",
        "P;u2zX",
        "5\"5r5",
        "if}BvF",
        "PhP<!",
        "ZwWow64QueryInformationProcess64",
        "MinghuaQuS",
        "w.ysU",
        "I/#$v",
        "2[-Q_",
        "8o% K",
        "a<BhiqG",
        ")8*yQ",
        "I$,UZ",
        "`G,[\\",
        "cB|L/9",
        "hK0tS",
        "'?nkN",
        "SNsv;",
        "=+=9=P=]=",
        ":4F^o",
        ",Z5/ ",
        "?WF?\"",
        "|X'qoc",
        "distpoint already set",
        "VsDataInstHelperSetProtection - DeviceIoControl(DIOC_DRIVERCTRL/DRVIO_SET_PROTECTION/FALSE) failed. Err=%x.",
        "Ky.>)",
        "EZARV",
        "systemroot",
        "F^^Bl",
        "Failed to revert WOW64.",
        "%*sIndirect CRL",
        "m+lO.m",
        "ob!7=\\",
        "A.\\)*+",
        "Remove registry key for stop SBA service.",
        "oBR+n",
        "1)bdinx",
        "QMPqzM_",
        "14eC%",
        "\\red128\\green128\\blue0;\\red128\\green128\\blue128;\\red192\\green192\\blue192;}{\\*\\defchp }{\\*\\defpap \\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 }\\noqfpromote {\\stylesheet{",
        "9E:V:",
        "+6bvZe",
        "T>[]5",
        "q\"tHr^",
        "ZoneLabs\\smartdefense.dll",
        "AiAlAqU",
        "f*_>c/U",
        "-Z\"fT",
        "Zh~P-",
        "odE15B",
        "ts>((a",
        "+BBPW",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\sa80\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7500015 6}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "1!U<{bZ",
        "CRYPTO_set_ex_data",
        "t~._$z",
        "a`}dH",
        "Q\"|.JE",
        "1X80a%",
        "$3[a@b",
        "BK.0D.\\C",
        "RvqmF",
        "ASN1_OBJECT",
        ":3:;:E:K:",
        "noticenos",
        "M\\3g1i`",
        "y\"y&y*y.y2y6y:{><k<",
        ":Z<m<",
        "t8<>9",
        "^+e /",
        "M=vQY",
        "%I)_+)%",
        "D$dUWQPjr",
        "tBf90t=j",
        ",4$8_@",
        "SFN2~",
        "zZ@_K",
        "P4Cx@U",
        "\\$0UVS",
        "c2onb239v4",
        "(ztON",
        "U&;eW",
        ".+]!e",
        "PzuFyw&U",
        "%Sv_#>lC",
        "D8!%=P&D",
        "7V4Zf",
        ".weFj",
        "Failed to convert CustomRestartCountdown DWORD value to string",
        "Z7grv",
        "q/XhA",
        "\"|2 ,",
        "=d*Sk",
        "sg&E:",
        "[LICENSING] RemoveReadOnlyAttribute(). Can't set attributes. Invalid file name",
        "Hjg[}",
        "Q6O!S",
        "RxeOk",
        "_x&V_",
        "xI~OC",
        ">*r}P",
        "b5d'b",
        "fX6@V",
        "5M\\>Q",
        "ENGINE_load_private_key",
        "K*cOc/}",
        "5R+jPZA",
        "tfN'Z",
        "quz-bo",
        "7.=rP[rr",
        "{Znk:&;DH",
        "iu/0%",
        "HW87A",
        "[g*^6",
        "TL=fe",
        "UnloadGUI",
        "(aI`\"R",
        "F??t#n",
        "peer does not accept heartbeats",
        "2f]xO",
        "failed loading private key",
        "s%-@K",
        "VjbhL",
        "LfkG-",
        "$E#sL",
        "t$(WSV",
        "L$4H;",
        "#!ONOgaj",
        "t$4VV",
        "MFvt6",
        "L&vE.",
        "QbjI@b",
        ".?AVstl_critical_section_concrt@details@Concurrency@@",
        "%*sPolicy Text: %s",
        "[|1Uak_",
        "n:2C[",
        "cp_middle.png",
        "3u&($f",
        "w>q!3y",
        "'n=ApO",
        "yqp+,\"",
        "\\smartdefense\\",
        "lv6DR",
        "Failed to allocate memory for CustomActionData string",
        "tIi B",
        "sYOTZI",
        "7$777r7~7",
        "Xx^<N",
        "QHUW@[",
        "lYJW3",
        "D$ Qj",
        "EnRE^]",
        "447G7e7s7!9X9_9d9h9l9p9",
        "=FRFXF]F_FmFoFvF",
        "=/=K=g=z=",
        "v7{UX",
        "62|h@B)",
        ":$:v:",
        "--.M3",
        "03mn'4=",
        "-v,Wy",
        "jpjij!",
        "dn80{",
        "eDqKg>VN",
        "RYt&sz",
        "3 3$3,3D3T3X3h3l3p3x3",
        "G;nhv<r",
        "T$ VUS",
        "9*9O9j9",
        "1,2`2h2z2",
        "G[$pM?",
        "OnInstallDriverBegin",
        "zjUc`B/",
        "ZLProduct.Identity.OS.Value failed",
        "l5[~q",
        "U$!'T",
        "Can't complete SOCKS5 connection to %02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%02x%02x:%d. (%d)",
        "G|.W7",
        "6MoM#",
        "gyltR",
        "I(@Pt.",
        "x$ ul",
        "-|;85",
        "DRI!>",
        "~4vfA@",
        "25k3_",
        "R-e7`w",
        "C354s",
        "&Cga?",
        "2<\"m0",
        "9!9;9",
        "y{3sHi",
        "wUtLH",
        "t6AVw:",
        "utf-8",
        "LV{9R",
        "I9YO:",
        "<&|aO",
        ":k46{",
        "<YdSVc",
        "1tbwd",
        "VuwI{*_",
        "Qbe%Fk",
        "GENERALIZEDTIME",
        "stupA",
        "B\"YwJ7D=*_3",
        "api_ms_win_crt_conio_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "+*ipI",
        "&_0Puy[5'p",
        " v4mml",
        "~hUWVV",
        "des-ede-cfb",
        ">'>C>_>{>",
        ";Fa[j",
        "=RYRJ",
        "\"i@/I",
        " %)Ur",
        "WsKB_",
        "JzA,u(]",
        "jFj28s",
        "3%WJ|-",
        "XGZ%X",
        "M*K9a",
        "Cannot open view %s. Error: %d",
        "unsupported key size",
        "#HpqT",
        "4EESS44EES",
        "GIg`$",
        "cyptu\"",
        "M!rl%",
        "le|q(",
        "sK;xPL",
        "go]2]_",
        "EWq{B",
        "9xdiZ",
        "8K8}9",
        "*aI,U",
        "S$9HY",
        "=]B0KU#",
        ",<Kv$",
        "0f>K{",
        "0`#,Bl",
        "app data in handshake",
        ";S;u;",
        "S2@o[}",
        "Gp@Nr",
        "j(j8jBjXjhjr",
        "2)6>6X6",
        "NUfmz",
        "5qW\"e",
        "U`fP\"",
        " Ia*@",
        "j#JnJ",
        "`|?IN",
        "BeR~.",
        "wMAvI'",
        " \"|;]",
        "\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority31 \\lsdlocked0 Subtle Reference;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority32 \\lsdlocked0 Intense Reference;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority33 \\lsdlocked0 Book Title;",
        "xiUs<",
        "F0R0j0r0",
        "<J<a<E=e=",
        "=Kv5v",
        "not a NIST prime",
        "expecting a dsa key",
        "VPNAtInstall",
        "Mvp`a",
        "\\Wv3R",
        "Bad dynamic_cast!",
        "failed to initialize xml utilities",
        "4090>0Y0",
        "445,7F8Q8",
        ">$>4>D>H>T>d>",
        "2!3U3",
        ";{2B=w",
        "2<xo%",
        "1|4U+YFIc<",
        "]9O;]NaN",
        "+~B@;",
        "P(M0k",
        "'~ngs",
        "q3(:xL",
        "giQ/ ",
        "m^ oS",
        "eZe[e\\e]e^",
        "EiJPjk",
        " ;#Ii",
        "ModuleBarHighlighted.png",
        "Lvi)QsNQ",
        "CPEPConnectDrive value does not exist",
        "t$HPUW",
        "%Bc|f",
        "c{,mt-?9^~",
        ")D?VL2l",
        "H=uW ",
        "jqjrj",
        "]@5C1#",
        "M(af5o",
        "Oj+=oI",
        "XMLFILE.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "*196fe",
        "pyR}#",
        "+o*9+B",
        "p!|BU",
        "u>SRQ",
        ".ocKo`",
        "\\5N&+",
        "YRo-A",
        "=!>u>",
        "XCWf'",
        "2o}6E?",
        "yx\\Qo",
        "3:3U3p3",
        "6t6}6",
        "nM lql",
        "OgWbs",
        "}KVg2i",
        "<[<e<",
        "'WNTn",
        "!X84F",
        "T*S0,0",
        "t#RSP",
        "y@,Q@",
        "th279e",
        "%s: %p:%p,",
        "#^~id",
        "&=Xw2z",
        "Qjh/T",
        "+D$$E",
        "lPsn!`",
        "9B9J9Y9",
        "122B2T2",
        "1t2x2",
        "x5Y,4",
        "point arithmetic failure",
        "rCAA`x",
        "sQc?{",
        "0<.Wc",
        "zQJ%:Lb",
        "o%xlw",
        "Pfailed to get list of authorized apps",
        "'nci8)",
        "\"J`VU",
        "UqL?`",
        "NNEQ5",
        "DTLS1_PREPROCESS_FRAGMENT",
        "lhRAQ18e",
        "OpenDevice(%s) failed with error 0x%x",
        "rTM-W",
        "SecureObjects",
        "-[453",
        "9Y:d:m:",
        "e<nLWF",
        "^h:=b",
        "INITY",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  however}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid9391338 ,}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "Py))\"7[",
        "YDLX?(",
        "<W1K+@Q",
        "OVy.Q`",
        "fd^p.",
        "ra1[(",
        "+ib3I",
        "i*X6!<",
        ")y4iA",
        "$sZ!rf",
        "b'p`f",
        "1R1]1",
        "%9%U%m&",
        "inconsistent compression",
        "\\ uN.",
        "7Ir|wS!",
        "<|9uw",
        "38a-8",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13240566 ",
        "3^%b3",
        "4O\"zY",
        "tuIZ:",
        "X_Xj%",
        "fjeclPb",
        "compression disabled",
        ".\\crypto\\modes\\gcm128.c",
        "\\lsdunhideused1 \\lsdlocked0 FollowedHyperlink;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 Strong;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 Emphasis;\\lsdunhideused1 \\lsdlocked0 Document Map;\\lsdunhideused1 \\lsdlocked0 Plain Text;",
        "Checking ",
        ";[c^p|^\"",
        "m%RPo",
        "rAG[t",
        "4lY5+",
        "%[iuAk",
        "invalid private key",
        "6V@OL",
        "^:LVJC",
        "Vm{$!M",
        "failed to add data to Rollback CustomActionData",
        "tR( b",
        "o tXBP34",
        "Ujt<6SHZ",
        "68J- 0-)gs",
        "2Y[d!",
        "x9I+#",
        "x@MT[",
        ",OoTP$",
        "\\k'9I:",
        "keyInfo",
        "s[+>r",
        "tKSWU",
        "_{}BPI",
        "Failed to store ACL rollback information with error 0x%x - continuing",
        "`=GB&",
        "en-ZW",
        "firewall",
        ",MObI",
        "_TUi\\",
        ".WpQ&I",
        "VV\\O\"k",
        "fE6pG",
        "q[ND^UT",
        " 0x64",
        "MbR\"E2",
        "U_}/B",
        ":OV?G}",
        "{}&22",
        "2D3`3",
        "F(SSV",
        "dzbqP",
        "y8o3=@",
        "$i^0y",
        "PGV?9",
        "_001$2!3",
        ";uEPdP\"Q",
        ";C\\ul3",
        "L O=vv;",
        ")?\"r?",
        ":F;X;x;",
        "8`|KT",
        "api_ms_win_core_string_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "1 1@1`1",
        "L\"S&=",
        "e# 99",
        "[VSSHUTDN] LoadVsdataEx('%s').",
        "q9]&[;@",
        "\\6-@K",
        "`]asa",
        "AES128-SHA256",
        "Failed to open view on ServiceConfig table.",
        "cJd2'X",
        "WS8Gb",
        "a(Y6\\",
        "MDsbc",
        "p`2c/",
        "q?,e8",
        "IP$Rk",
        "'BJ%`xy",
        "40444@4D4d4h4t4x4",
        "failed to schedule ExecSecureObjectsRollback for item: %ls of type: %ls",
        "=3>|>",
        "!]'L#'",
        "ms{|E",
        "f'YKqE",
        "a0R.J!a|\\",
        "#-FwNO",
        "IB8S,",
        "U:*^H$",
        "'bB1<5",
        "sA |H",
        "^r%\"&",
        "q\"XAO",
        "BWcDW",
        "8;wxf:",
        "=I?JE",
        "~y.O&",
        "^l\\U,_",
        "expected PI target",
        "[VSDATA LOAD] MakeSelfRelativeSD failed: %d",
        "30<0j0",
        "F8H;Y+",
        "1:g2&",
        "Heap32First",
        "Ya<;DH",
        "D6__e",
        "P;Dv5",
        "?lQ!-",
        "\\'02\\'08.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fi-180\\li6480\\lin6480 }{\\listname ;}\\listid1263226230}}{\\*\\listoverridetable{\\listoverride\\listid-119\\listoverridecount0\\ls1}{\\listoverride\\listid-119\\listoverridecount0\\ls2}",
        "5-.>z+",
        "2hE.3<",
        "<VpQ.",
        "nQXa\"F",
        "KP~*Y",
        "ccXoj4",
        "0!GDY",
        "@Vm/5wB",
        "H|5xDf",
        "?A?F?u?z?",
        "r- A9+",
        "setct-CredReqTBEX",
        "J57X*I",
        "M,wrO",
        "CheckSubjectBlock",
        "`yjH,",
        "!)~]Tu",
        "8j<lU8",
        ">b}q|'P",
        "\\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7224833 any of these}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid2388238  product}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "[Wg*{",
        "l\"-E/E",
        "^1;,M",
        "lhash part of OpenSSL 1.0.1t  3 May 2016",
        "'n?V(n",
        "C1A5G~E",
        "=>\\tP",
        "-!-.-1,6",
        "!6u|\\b",
        "YY[I,",
        "XpMEiM",
        "W`ZTp",
        "V<sNL",
        "a#9jys",
        "XxCzQ",
        "CLIENT_HELLO",
        "0)0q0",
        "GRF,jC",
        "Y$P::yV",
        "t6p<!",
        "JJW\"TR",
        "NeX{{",
        "A$4i4",
        "QZ/a7ob",
        "LDAP local: LDAP Vendor = %s ; LDAP Version = %d",
        "LS@:y",
        "cR]*-",
        "ADF/|",
        "TQd*yr",
        "CAST5-ECB",
        "-ewK6",
        "4`R(c",
        "ckkOG",
        "n;4mO",
        "^85Q3D",
        "wpc#Zd($g",
        "&yLmt&",
        "4/5E5M5k5t5z5",
        "kbrPs8",
        "o~(PO",
        "W$3p/Af",
        "BC}zi",
        "=<=W=",
        "<Q7yn",
        "dYbJ,",
        "wHiKy",
        "#tSzc;,",
        "\">/az",
        "768C8W8^8",
        "cannot open file",
        "=^C_P) z",
        "<KAVRegProtectionON>",
        "y*-85",
        "6dP]]|}",
        "HdlO_",
        "v@ZP7",
        "]pl [n",
        "SSL_CTX_use_RSAPrivateKey_file",
        "%h0k,",
        "~[6NL",
        "Ql)!9&H",
        "\"/To%",
        "missing precision specifier",
        "193T3X3\\3`3d3h3",
        "uF}|z<",
        "5)5B5^5z5",
        "$[*FM",
        "^C@(wq8",
        "6gtY7 ",
        "$b O`",
        "j\\D\\3",
        "kev2Nt",
        "75N?6",
        " ClientType=%d",
        "Failed to configure service: %ls",
        "U$T^&",
        "D$TVP",
        "VMRUN",
        "uL\"k{",
        ":(:7:@:",
        "OT*~h",
        "nsWG[",
        "lM9r>",
        "~QcVn",
        "%zrJr<",
        "WCWlWvW",
        "9i0z7",
        "WMy1>",
        "%T@.`@zd",
        "FIK8_",
        "\"WJ4)",
        "A PPL service cannot be started and %s exist. Trying to remove it.",
        "Ilshh<",
        "SLRVj",
        "[-NG/?B",
        "0)050q0",
        "a90AI",
        "\\ltrch\\fcs0 \\fs20\\insrsid8673032\\charrsid3875139 purchased }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032 and }{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032\\charrsid3875139 active}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid8673032 ",
        "%CT,z",
        "|PJ+*",
        "thElR",
        "-\\e6m",
        ":$:,:4:<:D:L:T:\\:d:l:t:|:",
        ";(;,;@;D;X;\\;p;t;",
        "}*C@P",
        "=o_Rd",
        "6QA l6",
        "DUEG6",
        "setct-AuthRevReqBaggage",
        "Y!?o$",
        "TAEED",
        "Y'9T~",
        "7Z*W;)",
        "\\;\\~a",
        "NoKeep",
        "2@|up",
        "%s algorithm \"%s\" unsupported",
        "/MDO_",
        "teD.Z$",
        "Z<[9+",
        "7!727I7R7",
        "_3DNow! II",
        "sslv3 alert bad record mac",
        "No-'T",
        "cpprng.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "FSB<l",
        "1:2o2",
        "c9F(n",
        "7W\"*V",
        "\\$(QhP",
        "yq)Yx",
        "XEbQFq",
        "',s(V",
        "\":32-",
        "42&9$g",
        "3\"q@6.",
        "yfCEk",
        "Plugins::Register:  Registering ",
        "Unregister EAP dll.",
        "tS\\|Y",
        "%sBrowserMonitor.dll",
        "PBbb[",
        "\\c..[~B",
        "SRP-AES-128-CBC-SHA",
        "subgroup order:",
        "WNLDGY",
        "ktB*o",
        "TTYLOC",
        " 9Rx*",
        "44idK",
        "|L}U}\"aP",
        "[JFFf",
        "1InQ0",
        "DJM Jx^",
        "!V^AW",
        "@{tcE",
        "<wu6O",
        "j67]i",
        "D$,]_^",
        "Vs6(z'",
        "~#O-.",
        "?[OfE",
        "N9WUclQ",
        "Jc`@uI\\R^",
        "!o|P\"",
        "t$$Vh",
        "2W2r2",
        "=H=f=x=",
        "7nhI~",
        "p&8!z",
        "&v[Gw'kw",
        "D'Qqv",
        "e|uOX\\",
        "0D1K1",
        "WP(x/",
        ">$>,>4>D>L>T>d>l>t>",
        "ozqzszuzK{w",
        "Failed to execute %s",
        "~k;MA",
        " }h#0",
        "CtPUUS",
        "8&8S8",
        "=*tO%",
        "[V}noOu",
        "CR;J0",
        "S@IOP",
        "setct-PI-TBS",
        "_set_new_mode",
        "%&3Gj",
        "zafK~`;",
        "w!w<~",
        "C2;>J",
        "hbC;m",
        "5$5,545D5L5T5\\5d5l5t5|5",
        "@8y!~",
        "`uE{Ae{\\",
        "|6aZoq",
        "$@#f\"",
        "sgF]dP",
        "hx@L@g",
        "PV:'g",
        "4n;.N1.",
        "SYSTEM\\CurrentControlSet\\Services\\VPN-1",
        "InstHelper.exe is running.",
        "7j7q7x7",
        "D$$][",
        "GG%Y!u",
        "989D9h9",
        "Check Point SBA upgrade product code is not found in the registry",
        "S,~%))Hy",
        "(NkrE",
        "8T#wl",
        "2\\-gz#",
        "<!uc105n",
        "GetStoredHash failed",
        "v~mp=r",
        "OzO>m",
        "SetPassword:  SetPassword started.",
        "_P\",1>",
        "SBQ'(k",
        "BpZO7K",
        "`eh vector copy constructor iterator'",
        "Keep sending data to get tossed away!",
        "H4%=4",
        "gRoA!1",
        "yZ]\\;",
        "setct-PANToken",
        "u%l#J",
        "L^Y;:Q",
        "U<XQ'",
        "0N0wx",
        "n?[]uV:B",
        "A>*GcMdg",
        "U+e8!",
        "G3x;ZYM",
        "content verify error",
        "^E\\{-",
        "t-@se1=",
        "D$@h$",
        "camellia-192-cfb8",
        "sFK`\"~",
        "1LULe|",
        ".\\crypto\\asn1\\a_bytes.c",
        "D$(hP",
        "Failed to fetch a record from MSI database view",
        "\\bin\\cp_InstPrep.exe",
        "nq~jm+",
        "h_cW+#",
        "@sZuU<",
        "*pSit",
        "W8^0ue",
        "888T8p8",
        "E!M~R",
        "i)a:H7",
        "=oG{^1nK[",
        "737;7T7_7",
        "LKMkM",
        "PqODiC(]r\\",
        ";#;2;A;K;e;l;{;",
        "](]8]",
        "HTTPS",
        "EPWD.exe.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        "1M1_1",
        "<T7T'Hy",
        "JD)yZ",
        "failed to execute view",
        "Could not remove symlink le=%d",
        "9#:)L",
        "MonitorEnableAsyncCallback",
        "[BFcZ",
        "^hMe\"",
        "vz<:b",
        "@/7qh",
        "1$1/1O1[1{1",
        "X+-2M",
        "9d+ ]",
        "}?:1A",
        "5\"6U6d6m6",
        "<KE+F",
        "Ik.v&",
        "!yZw:",
        "Z;=j6D",
        "M$M:a@tN",
        "? ?/?N?]?",
        " =DE|",
        "X5;&\"",
        "9|WD=]",
        "DO_PKCS7_SIGNED_ATTRIB",
        "p\\^lLfe",
        "LdB&t",
        "^zb3/",
        " 0xe9",
        ";}YD2",
        "]XAe:-FL|E",
        ";&;B;^;z;",
        "s8A*X",
        "YxT\"R",
        "{nu#\\",
        "uqtw{zm",
        "|J-m8&Z",
        "v6@-k",
        "wm'jJ=",
        "Mu$NR$",
        "([v!ZQ",
        "Z<.mA",
        "MR{M`",
        "F{E0;N",
        "0 0,080D0P0\\0h0t0",
        "waiting for vsmon to stop.",
        "E\\%Tb.",
        "5$5J5{5",
        "9Gf1}",
        "pW]%5",
        "B|>\"B<?$ $?p #<r",
        "ju6%p",
        "4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P",
        "e|x\"M",
        "fE=-Kcu",
        "R;vM;",
        "<DIR>",
        ": :,:H;T;t;",
        "f[\"4>",
        "^{.^ ",
        "H2{|2\"",
        "\\n@Q{",
        ".H7l*:",
        "\"g7|S",
        "Z4V2jZ",
        "0=2E2|2",
        "111A1[1W2",
        ".\\crypto\\ec\\ec_pmeth.c",
        "^J_spY",
        "CxH(x",
        "vU`k=",
        "Z ZM<",
        "}T.e,",
        "j Y;E",
        "k;Sv`&e",
        "@&K1n",
        "cC_f\\B7[WVS4",
        "sy9f~",
        "8 -~M",
        ";b;v;",
        "Installing bundled VPN client, skip CP integration.",
        "WAtr2",
        "J(J8JHJXJhJxJ",
        "e!e*Y",
        "globe.png",
        "\\Zonelabs\\ccore64.sys",
        "Ap_kT",
        "<(<3<W<b<l<",
        "s1Ns@~",
        "TRUE - Map Exists",
        "HacZML:",
        "070}0",
        "*Dmma",
        "Previous installation was not completed. Before a new installation, you must restart your system to complete uninstallation of Check Point Endpoint Security VPN.",
        "::V.^",
        "u^]om",
        "j|zV9R",
        "sQr9/",
        "ARiDx",
        "GQT@j-",
        " %-FQ",
        "EY_@ I",
        ":0;:;D;[;c;",
        "expected value",
        "7A7Q7v:",
        "W8*^@",
        "jo0lv",
        "xvLq{",
        "j5V^{P",
        ".\\crypto\\asn1\\a_digest.c",
        "Ji>4)",
        "VX'sI",
        "{Y*hH",
        "`-g5vaz",
        "j<kf{",
        "dhi9S",
        "{o=v=",
        "Mhjp{",
        "8S&uYp;2N)gi9",
        "\\fi-180\\li4320\\lin4320 }{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\lvltentative\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703\\'02\\'06.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 ",
        "z5ACH]",
        "C:\\Users\\vlozano\\Desktop\\openSSLWork\\take2\\openssl-1.0.2h/ssl",
        "}~=~8",
        "d^:3W\"",
        "[bG^7",
        ";-;2;C;I;S;l;r;",
        "; ;(;0;8;D;d;l;t;|;",
        "pQHfm",
        "ge!Hc'",
        "}/sq2",
        "jIh`B%",
        ";F)B3",
        "Cannot SELECT without a mailbox.",
        "M^K~z2",
        "&[Le@",
        "w>y| ",
        "3T$<3T$(3T$ ",
        "v[^,Y",
        "JxECR",
        "eYtm[M+j",
        "5 5-5W5",
        "mz&|@",
        "3T$T3T$83T$$",
        "4(4A4Q4m4",
        "0\\0|0",
        "?P?|?",
        "GJ'-/",
        "\\par 2.8 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\ul\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 Customization for Product with VPN Functionality.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "Uk.1Y",
        "DY=&3",
        "]17[L",
        "4kppz+@",
        "setAttr-T2Enc",
        ";o<v<",
        "8\"8B8",
        "pox[,",
        "GW.Au\"B'(B",
        "YNdjM",
        "lwemj",
        "D$,PR",
        "3;3Q3_3",
        "Y*;fr\"",
        "aC@ A",
        "!,p?gd",
        "%s service has been stopped.",
        "w<f}|",
        "kQ>Kg",
        "File:  \"f:\\\\ckp\\\\src\\\\ep_calib\\\\e87_20\\\\vpn\\\\common\\\\regkey.cpp\" line:  380",
        "Vh,9#",
        "XE[?Mi",
        "TWHlW",
        "HyHJ)",
        "QR#l#",
        ")K,Xg",
        "-Nx.\"",
        "< <,<8<D<P<\\<h<t<",
        "xQK%o",
        "-\"$ KI",
        "WDi_OK&hX",
        "Ym=@HD}",
        "]C]P]W]v]",
        "MMv$.",
        "&Check Point Software Technologies Ltd.1/0-",
        "?'?3?8?P?\\?",
        ">-K+}=M",
        "rIOW!{_",
        "jjF{(@",
        "@x-@um",
        " ekFI`",
        "u'9iP",
        "\\|-KK",
        "iLv#-",
        "~ER^Aeon",
        "tqLr0];h",
        "Unexpected continuation response",
        "5 5$5(5,505<5@5D5H5L5T5X5d5h5l5p5t5|5",
        "H}W](v",
        "?%?5?<?P?^?d?j?z?",
        "_j`P!y",
        "\\/}-3B*",
        "g_=rg2N",
        "`eh vector vbase constructor iterator'",
        "*vjcM\"}9",
        "mirror.exe",
        "77r.9",
        "#W|5s{",
        "qi$hXC",
        "jm%BS",
        "6XM8B",
        "8Y8e8v8",
        "rIy'8",
        "f|tdm%",
        "da?=H",
        "Q54~:'",
        "ola3V",
        "&85Z<",
        "PreInstallCheck:  Check for disk space.",
        "?Zy|Fe",
        " 0x8d",
        "zMYT-0e{",
        "u<3dGe",
        ":/d[lo",
        "~&$0.C",
        "#_iHwQ:: ",
        "0I('9",
        "ihi|<",
        "u4>TV",
        "fixed_om_mac_address",
        "u3*@3b",
        "Pk)Dj",
        "U6{/X",
        "owU$]",
        "\"TUD+)+",
        "-zgHF",
        "id-smime-cti-ets-proofOfDelivery",
        "DH_CMS_SET_PEERKEY",
        "@1v[hc",
        "C';Vf",
        "Jl02y",
        "atlTraceISAPI",
        "k Q!e+",
        " )!)\"",
        ">xgnZ",
        "R/E:QN",
        "t(h\\4L",
        "0!1-1A1M1Y1y1",
        "8!}-fX",
        "l%U}<",
        "jQ;'*",
        ";:$}:l",
        "CXsDz",
        "shn-|",
        "DD5E2272BEBED6343ADF346241362FD7",
        "dwEKeyLen",
        ">GPa]v",
        "jp;0Bw",
        "T{4Et",
        "*~Baa",
        "252N2i2",
        "-D=vW",
        "8itQ^",
        "g,f$ ",
        "F;B@N",
        "='=@=Y=r=",
        "I4,(M",
        "NR)K}#K",
        "}'p+II",
        "-X0$z)",
        "NORTEL7LOCATION",
        "%0$121=1E1l1",
        "bq0>&`0",
        "Re.B\"",
        "n\\;{K@",
        " cHRM",
        "Xv xXL",
        "|$<u3W",
        "ar-jo",
        "? ?0?4?@?P?`?d?t?x?",
        "ibnb-",
        "'C]gKw~",
        "dt0x@",
        "~Uz&*",
        "P_)Z-",
        "@-\\22 -k",
        "i)rVs/F",
        "z?k+#\"",
        "nG7'DK",
        ":w3Aa+",
        "w.t&=",
        "BEOS_BIND_FUNC",
        "$`FWb",
        "PKCS7_COPY_EXISTING_DIGEST",
        "HMv[Z",
        "NaGbg",
        "oO:Mc",
        "&z@_qH",
        "E8re\"",
        "\"!1lmzd",
        "yumA6",
        "authorityRevocationList",
        "#\\CQU",
        "H1UJ)ai5",
        "8&^*n",
        "Failed to get ServiceConfig.NewService.",
        ",.sd\"B",
        "X*(#m",
        "GetCurrentProcessorNumber",
        "l$(hD",
        "2K2Q2V2",
        "X+8:,",
        "<G) ^=",
        "J) F|P",
        "DPXw;",
        "Tgf#Or",
        "kz<b3",
        "Ng.\\%",
        "q7MlU",
        "}bV#a",
        ".\\ssl\\s23_clnt.c",
        "_DmEa9",
        "_f9;u",
        "tZ2|a",
        "7;A.r",
        "securityInfoIcon.png",
        "brainpoolP192t1",
        "|;O72",
        "emailCA",
        "PKCS8_add_keyusage",
        "g82:*",
        "bKYNg",
        "\\n]DW5",
        "6n(\\M}o",
        "4t^N{",
        "Enterprise N",
        "Buh=_a",
        "V7MPu",
        "7D7L7[7|7",
        ".?AV?$_Mpunct@_W@std@@",
        "j5y\\_",
        "@40F/*",
        "E?98\"v",
        "DES-EDE-OFB",
        "z&-mN",
        "s4_A$",
        "****************************** SetVnaInstallProperty started **********************************",
        " set produceName to %s",
        "xxJo%%\\r..8$",
        "{eRxy,U0}[IS",
        "j7eR(",
        ":$:D:L:X:x:",
        "I3E`j",
        "G+@&s:E&",
        "a6d7p",
        "jREv6",
        "ET^^u",
        "@d.2z",
        "fW\\KQV",
        "j8c^+",
        "2[(M*",
        "fx{~r",
        "=;=y=",
        "Configure vsconfig.xml to remove AM protection",
        "}Rq)Q",
        ">r4/:m",
        "L|3\\_V",
        "uRC.b",
        "Trying to open process w/ PID = %d",
        "434:4E4v4",
        "_F2#b",
        "9 9$909@9d9h9x9|9",
        "56789:;",
        "P0BFI6'",
        "(C~P8",
        "t%C +",
        "JUfH;",
        "p\\lHtW",
        "Invalid handle to registry key.",
        "L+Pp8",
        ";/;K;^;",
        "dsfa.inf",
        "License key is ",
        "english-south africa",
        "FSAVE",
        "Ec/v(f",
        "K{<+e|",
        "}8+=I",
        "[k|<~D",
        "6F!tbd@/K",
        "http;",
        "no cert set for us to verify",
        "L$@QP",
        "VWG^~",
        "*$S;*rk",
        "K>AQ;!@",
        "?TUWL",
        "677B7M7R7W7o7",
        "9\"979M9S9l9x9~9",
        "&LNVr",
        "A+z4]",
        "rpdTG",
        "zT&=y",
        "&i-.Q%",
        "L*'r1E",
        "PRIVACY",
        "P_K7}",
        "Stdout SetHandleInformation",
        ">P,.853",
        "Failed to find GetCustomerNumberEx() in vsutil",
        "Q6c6h6r6",
        "ghcVI",
        "<)7rd",
        ":AK0ji",
        "d2)z/n",
        "\\0 9|0$|",
        "ZfNj/",
        "B9`p(PH",
        "CPEPS_DeferredActionRequiresReboot",
        "0Z7/1F@",
        "B+'n;",
        "\\~U@a",
        "5Z}G74",
        "q$Ba)",
        "i\"s(b",
        "5:7M7\\7",
        "kGUMj7$",
        "7E7v7",
        "7O7h7t7",
        "T(0*Q(",
        ";ynY*v",
        "7B7v7",
        "BT,IO",
        "4%\\9)",
        "Move %s to %s",
        "j>kkH",
        "o.S.nkX/",
        "TY;?5",
        "SITE NAMEFMT 1",
        "\\rtlch\\fcs1 \\ab\\ai\\af0\\afs26\\alang1037 \\ltrch\\fcs0 \\b\\i\\fs26\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext0 \\slink19 \\slocked \\sqformat \\styrsid13065977 heading 5;}{",
        "/ATs}",
        "failed to open ServiceInstall table to secure object",
        "3+3s3{3",
        "Y1S`-",
        "dmpiu",
        "newer crl not newer",
        "A![e:",
        "K`@qm",
        "UPEHI ",
        "DVZ>~",
        "?'?5?\\?",
        "Y;() |g",
        "0JsD/",
        "J_N_P_",
        "(;{Z$ } g",
        "<\";AN",
        "unprotectedAttrs",
        "mk-mk",
        "V58hovwQ",
        "jye0axA}",
        "f.XL:",
        "~%s3x",
        "Gj8F(",
        "Ui37#",
        "Zo! =1jhz)vx",
        " _7? ",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid1132737\\charrsid15169477 ",
        "C9jLJ",
        "=X=u=",
        "t$<Ph(",
        "+7!bs",
        "protectionOff;",
        "fuQJ$;",
        "qBs/n`",
        "SetSecurityDescriptorDacl",
        "7uWC7",
        ")C3(Y",
        "*;,)(",
        "RegisterSecureAccessDSM:  Create SecureAccessDSM registration.",
        " 0xc4",
        "OLDVERSION",
        "BV78Qw",
        "Odf}^",
        "IsPEFileValidEx2: %S not found",
        "(tXTd",
        "S!xr)",
        "?3?O?k?",
        "Bw>6SS",
        "$_|-O",
        ".!cWJ3:",
        "9*999\\9",
        "C-|`@",
        "=1>8>>>H>k>u>",
        "9MIjD",
        "reC8H",
        "H,1E&5",
        "!@n<O",
        "\\bZiP",
        "x.ey4",
        "<5=g=",
        "atlTraceHosting",
        "wYy,a",
        "cAN;G",
        "=J>y>",
        "jtru?hao",
        "y]>4]7",
        "h=!k0",
        "cJPwj",
        "[%3_K",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10",
        "{\"iq[/",
        "NhT]M)",
        "#tT\\(",
        "z*a,X",
        "S{I^`",
        "%0>Q3",
        "gn`o|",
        "bInc$",
        "1W2,3034383a3",
        "FFSs.",
        "CryptCreateHash failed {}",
        "jewxk28Q",
        "y2W6Q",
        "%=<XP",
        "213h3",
        "R6032",
        "B(mSS},V1vdY",
        "5*5o5",
        "vG)2Tc",
        "ExE(H",
        "7zt1}>",
        "/rf6\\",
        ".?AVUMSFreeThreadProxyFactory@details@Concurrency@@",
        "=$=(=,=0=4=8=@=X=h=l=|=",
        "X509_get_pubkey failed",
        "Eg{,]\\d",
        "^vyvzv{ ",
        "ge#`n",
        "r*wLJ",
        "\\$@9U",
        "^M2Cl",
        "[:J w",
        "6_=xK&4}",
        "!nw!r",
        "]5>U,~",
        "jdjhj",
        "<\"<M<s<",
        "{bvlmx",
        "zMW+?K",
        "YQ{J,",
        "7$8R8",
        "Q)8$}",
        "ja q,d",
        "T&?&V",
        "j)l*=I",
        "aP=_]",
        "/;y<\\",
        "y\\a/-",
        "i,glF",
        "+daE%",
        "]HS56<",
        "U5>1D1",
        "7$7@7P7\\7|7",
        "3!414O4",
        "O;1I)f",
        "RdTar",
        "CMS_EnvelopedData",
        "lc8#D$Lf|",
        "%*scrlTime: ",
        "@k,\"/",
        "Failed to execute MSI database view",
        "SetStdHandle",
        "?!?,?;?A?L?[?a?q?",
        "CHPVU",
        "GetBladeRequiredDiskSpace: cant MsiRecordGetString on Feature: %s ERROR: %d",
        "!+'~t",
        "u2BYgZ&5K",
        "!v.1dN9O",
        "TJc0c",
        " 0x70",
        "xd;R.",
        "id-cmc-recipientNonce",
        ",+]FX",
        "Ws;v=",
        "URLFextractUCP started",
        "$| 32",
        ">a'O-",
        "Z4OZ#",
        "FJDZ ",
        "cd%]BkC",
        "IP Address:<invalid>",
        "\\,4,q",
        "pivyK",
        "zoGI\"",
        "<5<d<",
        "$w\\_k8E",
        "}!0_ ",
        "5qbhI",
        "~>nyu",
        "q$7jo6",
        "<s&8S",
        "z[LU9A",
        "rjx<#",
        "jAjej\"",
        "t\"h@$",
        "g_lPuY)",
        "!O{I&",
        ";0{ir",
        "_4ydR5",
        "ENGINE_GET_DEFAULT_TYPE",
        "\\$8;l$ ",
        "}s9K6l",
        "@ ER4",
        "7;1d\"$",
        "o\"mw*",
        "j;y5yA",
        "SM`@o",
        "Hq1dZ~",
        "DZtkh",
        "2z='A",
        "=ae\"C<",
        "I2ka+",
        "#~>sIK",
        "pNZ_\"G;",
        "C]+t&",
        "t$,VS",
        "&Hg#t",
        "%{|(?",
        "fI0%\"C&",
        "QVjOS",
        "70878",
        "o4v+):~$t",
        "*Zz0?n",
        "03MX`#",
        "I~LtY>",
        "9;'q9",
        "p#hx=",
        "5%8\\,;=~CWErj",
        "FWREGKEY",
        ";D;T;`;",
        "[Sh|\" ",
        "use srtp not negotiated",
        "xO<b}U+",
        "4.<;e",
        "Failed to verify Secure Client configuration",
        "Z4$:`",
        "FeatureAntiSpam:  RemoveAfter:  need to remove MailFrontier folder.",
        "[LOGMON_PROXY] LogMon started in process=%0x",
        "J|$EY]&",
        "ECDH_compute_key",
        "3t&6P",
        "Vj`hl",
        "]}- P",
        "FE77&",
        "byT*:",
        "UvM/{",
        "9 9(90989D9d9l9x9",
        "0b2Q!",
        "(_T0V",
        "=4I (",
        "O?9E548O]",
        ".*lYmm",
        "OCSP_cert_id_new",
        "}T_Yl",
        " dP#:",
        "414Q4q4",
        "KAEONUninstall",
        "QayYv",
        "GQl5*",
        "freeaddrinfo",
        "j9[Ja",
        "<;u/V",
        "R5=I>u",
        "hI#Vj",
        "BWtc}",
        "U/ jc",
        "h#t\\dm",
        "^^I| QV",
        ",oK:[r",
        "7p<1>",
        "2X3l3w3",
        "t#E-hgI",
        "/8sC ",
        "u/Iw:|=",
        "InstPath is null",
        "-;)~\\p[",
        ",TqUl",
        "o'pN\\",
        "s%LF7",
        "WixRemoveInternetShortcuts",
        "7'717;7",
        "M,}\\_#",
        "n)irUce",
        "p?fAc",
        "pJ\"2'ya",
        "ZY_VV",
        "t8J\"@",
        "[EXCEPTION] Terminating the process.",
        "0*gpt",
        "~1\"<L",
        "MF%}O",
        ";2=%G",
        "sLI\"!/",
        "}k]A*",
        "xnlAW",
        "FeatureSC _Begin",
        "F+^-\\",
        "1 1$1(1,1014181<1@1D1H1L1P1T1X1\\1`1d1h1l1p1t1x1X;\\;`;d;h;l;p;t;x;|;",
        "Fg^M.",
        "LEGC0",
        "SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\ScvMonitor",
        "zh-cn",
        "?(?4?T?\\?d?p?",
        ">1?|?",
        "\\vGYl5",
        "STOP_HELPER_ERROR",
        "MOVHPS",
        "CertVerifyCertificateChainPolicy",
        "7X7(8",
        "Ngx*`",
        "0)060A0",
        "Folder does not exist",
        "l#-h$dB",
        "B%X,E",
        "*MgWo",
        "'Ro4K",
        "6husvd",
        ":f%L-5)",
        "P*)Y&C",
        "2bN6a#",
        "N)U-B",
        "j!~`P7^",
        "j9o%s6\\]",
        "::;G;R;^;",
        "s tPk",
        "(kT3L",
        "1VdZr",
        "cahgog",
        "t$$WS",
        "SvVJk",
        "DSA_generate_parameters_ex",
        "=[n.i",
        "X#(ix0",
        "ShM|K",
        "W=MS0",
        "WHE`B3",
        "@m nh|k",
        "WE['H`",
        "SSL_use_RSAPrivateKey_ASN1",
        "4!5G5",
        "\"o}8H{4Y",
        ":nTpxp",
        "nD`OQ",
        "-dvc/",
        "FeatureTVDriver:  UpgradeAfter started.",
        "Failed to write fixed_om_mac_address to registry",
        "v5vUvuv",
        "D:%TR",
        "'~:ua",
        ":$;B;b;",
        "[^Rm[",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid7943135 \\'93}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 EAR\\'94)",
        "9bZ3Z",
        "1E4Aup",
        "FindResourceA",
        "toZ5H",
        "ZXE\\p",
        "(0xJ-K.",
        "jtjtj\"",
        "VC0n;",
        ">085j",
        "=2>Y>w>",
        "h=_*'",
        "atlTraceUtil",
        "lFi~gb",
        "{%08x-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}",
        "\\FK%~@",
        ")?<yC",
        "<(=P=X=`=h=t=",
        "Failed to get condition from ",
        "qrnzZ",
        "unable to bind socket",
        "<xmlattr>.enable",
        "bx#)YS'",
        "p1L<1H",
        "VeyhD",
        ".d$D-",
        "\\:Na9",
        "t4QvEGx",
        "camellia-256-cbc",
        ".?AVpairNode@@",
        "HH'O:",
        "K4Tw.",
        "U'xHB",
        "CM~: E",
        "z%y;V",
        ":!! MXm#",
        "Un(6\"u",
        "AQA9vY%=",
        "NqNnM",
        "_@:YG",
        "atr7D",
        "3D$$3",
        "]Na#p(",
        "6HU8$",
        "Tp/RqT",
        "7\"7j7",
        "49>!U",
        "SEQWRAP",
        "=:>E>S>n>y>",
        "nature of the Beta Product, You are advised not to rely exclusively on the Beta Product for any reason.  NOTWITHSTANDING THE AFOREMENTIONED IN THIS AGREEMENT, YOU AGREE THAT THE BETA PRODUCT AND RELATED DOCUMENTATION ARE BEING DELIVERED \\'93AS IS\\'94",
        "trust",
        "QRw46",
        "Created a process, PID=%d,pHandle=%d",
        "{2vVj",
        "6#A]+",
        "C ]EA ",
        "\\J[0i",
        "Iw-Vg\"",
        "bA~h70U",
        "ssl_undefined_function",
        ":A:i:",
        ">!?8?^?",
        "!3GVP",
        "CXkT%",
        "uukk{",
        "Ctrl conn has data while waiting for data conn",
        "m#,T4",
        ";C[7n",
        "pA&W6",
        "setCext-IssuerCapabilities",
        "boost::filesystem::last_write_time",
        "T^`|PZ",
        "D$(+D$$",
        "Z%7zi4j",
        "I'aj*_1",
        "k=p*+",
        "wcawrap.cpp",
        "D*_mk",
        "nF h~PE",
        "Dependent Libraries Info:",
        "sh{-u",
        "Policy Qualifier User Notice",
        "RWQRP",
        "+xv/4>,3",
        "1IcPhI",
        "Z#-P-P",
        "n+.ve",
        "eCA&F",
        "TBTBN",
        "D-aILT",
        "2pI!O",
        "/Z`$,m",
        "Z?5mae",
        "4vG!8<w",
        "DJ YdH",
        "o1oQoqH",
        "a!~^}",
        "buffer",
        "4V_`g",
        "iu|:t9Cc",
        "HJeu!",
        "s b#_",
        "Shutting down the client and vsmon service to install/uninstall.",
        "a3!OF;",
        "6A6`6v6",
        "[ms~$",
        "8%9K9|9",
        "Q;FD~R",
        "2F3S3V4g4v5",
        "_,JfS",
        "717P7n7",
        "Y96~b",
        "ixDvT<",
        "}B!+q",
        "5E|_l",
        "N8IN?&;",
        "P:m8=",
        ">j'8Uj",
        "ADVAPI32.dll",
        "5tG}/",
        "api-ms-win-crt-time-l1-1-0.dll",
        "HaB>a",
        "rv'%u",
        "Eo1H}",
        "\"'Q/J",
        "FWUpgradeBefore started.",
        "AN3Tb",
        ">-><>[>j>",
        "INSERTQ",
        "rxfPF",
        "xYp5F",
        "rR(3[W",
        "I+'+|}",
        "Iw$?D",
        "[\"P#%{",
        "<\">n>",
        "6-6Z6",
        ":6kg4",
        "x!l@A",
        "An2O/",
        "9 9$9(9,9094989<9@9D9H9L9P9T9X9\\9`9d9h9l9p9t9",
        "d[@x[w",
        ")<)L$l",
        "V#5Z%w",
        "+yiZUV",
        "oV9)vV",
        "/V 1oRA",
        "%^{+h",
        "$a@-y!",
        "U(]81",
        "+>&ti",
        "F#LE6%",
        ",5x{Pc",
        "secp384r1",
        ":/:V:e:j:",
        "m#IBc,",
        "KuG-x3",
        "error writing to vsconfig: getlasterror = %d",
        "gS9:y",
        "xEINq",
        "5BU95",
        ".ZhcrA",
        "lX-HB.",
        "32ly*K",
        "de-li",
        "UQd9*I,",
        "x<@o[",
        "(V;34",
        "`c2?f",
        "usJ\"]",
        "s}\"(o",
        "D,\"7x",
        "!010E0a0",
        "34'g/1",
        "s->init_off == 0",
        "/WxWr",
        "fh`d1",
        "zWl40",
        "l9mnt",
        "7#7*757H7R7o7z7",
        "`-yg)/",
        "cp_right.png",
        "OnBeginExec",
        "5@5K5",
        "0)N}eR",
        "t@\"jO",
        "0K1W1l1q1~1",
        "Configuring Antivirus settings (4 of 6 tasks done)",
        "t&n6Z",
        "HxtT+4",
        "Qh8?5",
        "D$ S<ZtJ<-tF<+tB",
        "> _CK#rx",
        "7;8}8",
        "]O,'V",
        "DD&b<",
        "=r]qbr",
        "8>2h%",
        "n\\p\\r\\t\\v\\x\\z\\|\\~\\",
        "?J=[v",
        "JMP FAR",
        "BZ9K^n",
        "LTBiLP9",
        "L$H3L$L3L$",
        "Server certificate:",
        "F-*$i",
        "5A607f7",
        "F(gW)",
        "F1`$m",
        "<'<U<Z<a<h<o<",
        "(xSzS",
        "x{AMG",
        "#B9!#]",
        "sN>I(",
        "Fq)&u",
        "xA.xF",
        "w:@Zh",
        "eOsv|",
        "Qjj=(",
        "/zL$(",
        "4q4}4",
        "6x]Tm",
        "$&-Yg",
        "uw&%7",
        "VP&Q6",
        "\\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid2260672\\charrsid15169477 GOVERNMENT REGULATION AND EXPORT CONTROL}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid10707243 ",
        ";-;Q;w;",
        "A=Ps_R",
        "pIuY)WN",
        "O!{?dG",
        "<2L_&",
        "p\"M#-",
        "%BQk4",
        "x>y:[",
        "%DMQQ",
        "2B= 3",
        "v;p;L0",
        "r]f\"Z",
        "aMg'r",
        ".\\crypto\\rsa\\rsa_pk1.c",
        "Plugins::Unregister:  Unregistering ",
        "j:Vg^53",
        "F[~!v",
        ";uKJ&",
        "OnUpgradeAfter:  RunVsmonInstall",
        "B.i,w",
        ";gZ>rs",
        "kM}eM",
        "sW++;",
        "'@IE6",
        "`VSyd",
        ",egF\"",
        "g^l?Y",
        ":L&aA",
        "Bwh_^Z",
        "aXRv8",
        "|#<,?",
        "UU*&_At",
        "$?OY8",
        "Bh!#<mI",
        "DBIiq",
        "1 1@1L1l1x1",
        ": :8:<:T:X:",
        "U|`D,",
        ";LE-|BS-",
        "`hiCL",
        "H<B8yh",
        "q?Tz{",
        "YH@G]",
        "i+x.a=",
        "DG\"-Q",
        ")D8kK",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy\\AppMgmt",
        "b;s&DO",
        "necessary data rewind wasn't possible",
        "ssl_server",
        "IY}.HB",
        "Update MsiProperty: %s=%d  (old value=%s)",
        "de-LU",
        "[%n-^",
        "6k6t6z6",
        "70888g8q8",
        "3\\$0!",
        "'y[I.9qI",
        "~&4k*X",
        "t[m4{`X",
        "no compression specified",
        "Failed to delete ",
        "jjjjjjjj",
        "@HNFhD",
        "O@QVS",
        "G#bg|",
        "]<ZcLi",
        "TAC[^2",
        "I0G0E",
        " bskb",
        "1!111Q1a1",
        "'5@`x",
        "DX_Mgr",
        "X\\gZ>9",
        ";II9Irp",
        "2zM_9",
        "kc*S-9",
        ":L:X:x:",
        "b(_9e",
        "No6hNr",
        "ProfileImagePath",
        "lpwlQ",
        ")+J*,*",
        "cB'@kB",
        " 0x35",
        "4adND$",
        "=&=2=",
        "0\"1L1c1",
        "\")&tN",
        "d^);6'l&",
        ":PT-H",
        "58-Re",
        ")<,u%S",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13701052 2. }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid9905346\\charrsid15169477 E}{\\rtlch\\fcs1 ",
        "POP3S",
        "-gXU49",
        "1(1A1M1c1v1",
        "r_\\RKdn",
        "AKO'M",
        "9B:^:",
        "oU,Nv",
        "no such device",
        "SR0\\k",
        "*gs\\A",
        "EVP_PKEY_get1_RSA",
        "qa TP\"",
        "NV'#6']}",
        "The de-registration of the zlscv.dll was not successful...reason unknown, possibly failed to create process zlscvins.exe",
        "TSf`\"",
        "hr84C",
        "*B+)0}",
        ";piiQ",
        "0qF8'",
        "|Hy;oLc",
        ";&;X;",
        "9S1WW",
        "\\I3,Pmb;3>]I",
        "ml^ZT",
        "Failed to initialize 'RollbackServiceConfig'.",
        "rySUKK-",
        "tu\"K-",
        "pem name too short",
        "~h';|-:eQ2m",
        "Sdi/w",
        "Hic4}p-4<",
        "WJiF\\",
        "o)_Q0",
        "~0}gE",
        ")HnL%7H",
        "A #D$<",
        "849<9L9T9\\9h9",
        "/#`A<I",
        "ISIsI",
        "D0k.%",
        "})8Jj",
        "Received unexpected DATA packet block %d, expecting block %d",
        "WixExitEarlyWithSuccess",
        "-*+$o",
        "{tU0d",
        "T3Ui%5",
        ">B>Q>`>o>~>",
        "W\"M!b",
        "3hWyPr",
        "Il p(",
        "order",
        "h=@{A",
        "!9,i&",
        "amJ?+(",
        " s|p7",
        ".text$di",
        "_(`=*",
        "5$5(5H5\\5`5",
        "/5fjg2",
        "4?4E4j4u4;6Z6,7S7c7n7~7",
        "v+R5k",
        "W8^&ul",
        "\\!]isqjIGmF",
        ",bbd<}L",
        "r56/?",
        "21#g ",
        "+fBsV",
        "1a,8 ",
        ".\\crypto\\x509v3\\v3_pmaps.c",
        "g0Ii*3",
        "UACk|0b~",
        "19x'V",
        "xST.S",
        "N?2#\\",
        "8w|y6",
        "O[+O%|#",
        "lQAd`#E4",
        "gV!~d` ",
        "No such device or address",
        "> >(>0><>\\>h>",
        "(YZxa",
        "1o9i<",
        "^*%6t",
        "WtCSV",
        "2-2I2e2",
        "-lUbU",
        "M|4B8",
        "0\\7qd",
        "xknhvj~j",
        "QA>K[",
        "jCj~j%",
        "SELECT `FileSize` FROM `File` WHERE `Component_`= ?",
        "Z=y.f",
        ";a;h;",
        "no dynlock create callback",
        "t2T;=",
        "GEN*X",
        "+tbB0",
        "response reading failed",
        "BE[Mn",
        ":JZ$8",
        "9 9%959:9?9O9T9Y9i9n9s9",
        "grh&}a",
        "EUB'E",
        "`2GiP1",
        "g>Ge&",
        "S):1B.",
        "=1e_:oQ",
        "e,&Q&",
        "CRLReason",
        "sV[`m",
        "wt#c^yR~i",
        "(00z/",
        ",uAIo",
        " .LX\\",
        "d8X{.6",
        "Y(xB4",
        "p0t0x0|0",
        "Z[\\33@2",
        "ESK3K",
        "7}8g~.",
        "u97$9)7",
        "A@z{4n",
        "~5lev",
        "GJHN<6",
        "Y|lI?",
        "cnneTLo",
        "\\rsid7039639\\rsid7089828\\rsid7160239\\rsid7224833\\rsid7233772\\rsid7301054\\rsid7438025\\rsid7479812\\rsid7480943\\rsid7483310\\rsid7500015\\rsid7502794\\rsid7565078\\rsid7685162\\rsid7743908\\rsid7802178\\rsid7940874\\rsid7943135\\rsid8074794\\rsid8128984\\rsid8142133",
        "03-rH",
        "+V/h/",
        ")G_!K",
        "?r/};",
        "jjjkj!",
        "F8PVj",
        ")!&aS",
        "l~z33",
        "J|m}m",
        "G?T%9",
        "Ayl'mH",
        "5-686>6G6",
        "CGudc",
        "\"\\s7U",
        "K8Af|",
        "&6~a-",
        "Q9=a%{",
        "`]_o ",
        "-h8BM",
        "RF##eF##e",
        "EJyl^",
        "475J5",
        "'+/^74)",
        "|<~K4",
        "ASN1_item_i2d_bio",
        "<wh:8",
        ",xY&e",
        "565k5",
        "z{ eg",
        "[`[kn",
        "MNC&4H",
        "ImE%7",
        "a#vSK",
        "1' o\\",
        ":3SsRO",
        "`tM<D*",
        "Using %s from Binary table",
        "q{=DV",
        "j/_f;",
        ";s40u",
        "\"4Ak,\"Q",
        "qYg|.",
        "9%959=9P9U9f9x9",
        "lWNki",
        "ZoneLabs\\vsavpro.dll",
        "H@`}fR",
        "s2ZtY",
        "S6Vg'",
        "DH$CD",
        "q]ius",
        "xgS`)",
        ".00MX9",
        "0!RiZY",
        ".H:#V",
        "~t=uJ",
        "9FTt!h",
        "B\\@I>",
        "S~'a!",
        "jS@HX",
        "3+Qp9",
        ";\\$ ~;",
        "ySOe+",
        "G9}de\\E",
        "];GR9{",
        "failed to write exception action to custom action data",
        "fdH@J",
        "SE6)}4u",
        "NmS:Q",
        "n[*vQ",
        "L$L_^][3",
        "~)~=~a~y~",
        "g42shDt",
        "J?SvE",
        "=>=C=s=",
        "eocxt",
        "AvSDK",
        "EmgES",
        ">1l0+6",
        "L(]ts",
        "xf2^X",
        "FeatureTVDriver:  CopyPolicy started.",
        "SUVW3",
        "Xvr6D7",
        "{`:^2B",
        "rOYA!=q",
        "EF~L6",
        "VSGetInstalled: cannot log in",
        "algor",
        "jNh,'#",
        "nR4i:^",
        "Internal Error - Failed to read NO_OFFICE_MODE property, return false",
        "Can't delete the root directory.",
        "sr_about.png",
        ">x4':(",
        "XE~rq",
        "7M&\"!H",
        "-Y$G_",
        "%bzfQ",
        "TA l[",
        "P0_6rR4b",
        "{`L!c",
        " 0xab",
        "m/x;V",
        "'A;\\D",
        "A}K}OIT1h1o1s1y1|1",
        "3\"3>3Z3v3",
        "6*SL%J",
        "\"1;ht-",
        "[ =vj=",
        "id-GostR3410-94-bBis",
        "gcSk_",
        "FDbr!cC",
        "~_&qh",
        "DIVSD",
        ":a3u$",
        "@lFh2",
        "Spv&~",
        "flushing table",
        "==bLL",
        "ssl23_connect",
        "~>'\".",
        "November",
        "@v`~l'",
        "Ym{5i",
        "IEQO|ol",
        ":hqc`",
        "|tQj ",
        "^Un;D8$",
        "7/7R7_7|7",
        " Check Point support agreement}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid3875139 .}{\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\fs20\\insrsid10102966\\charrsid3875139 ",
        "/TgsDzl",
        "=>@@h",
        "FR#m.#mB",
        "060N0T0i0",
        "N*J$/_",
        "^Ob3}",
        "2e'>%=$JSuV",
        "Mhi+!",
        "R\\tEt",
        "<zvA<Ar",
        "B,~} m",
        "{#NlH",
        "<`7;xu",
        "Y%i Mt",
        "Vh cL",
        "oP\"&-tj",
        "m3FfDpXv",
        "&U*!j3",
        "\".&pf",
        "({9/x",
        "x.kr-",
        "t'jN9",
        "(sdb-",
        "9=~CR$",
        "+& BfLq",
        "XFyMx746p",
        "The driver isn't installed",
        "9YnF8",
        ",i\"\\&2",
        "\\par The warranties provided by Check Point in this Limited Hardware Warranty apply only to Hardware Products you purchase for your use, and not for resale. The term \\'93Hardware Product\\'94",
        "GGcGgGiFj",
        "T^TyP_",
        "p.char_two",
        "Software\\Zone Labs\\ZoneAlarm\\Registration",
        "User-Agent:",
        "74`\\]3",
        "#f{R>",
        "8q8\\V",
        "YKX^AGw",
        "2%323s3",
        ".?AVUMSThreadScheduler@details@Concurrency@@",
        "%s\\System32\\epcginashim.dll",
        "pJ;* Ck",
        "*kzMg",
        "/4jd/",
        ":!:A:W:`:y:",
        "\\$43D$03\\$8",
        "wf#HH",
        ">@=0)@O",
        "PWWWVS",
        "ziPL~",
        "|craG",
        "g64)Q",
        "nwLrw",
        "P|wdZ",
        "no verify function configured",
        "]b:%+",
        "SOFTWARE\\McAfee\\VirusScan\\CurrentVersion\\Setup",
        "86,8,6200,03",
        "!3;:iB",
        "cSjUW",
        "@7e)]i",
        " months from the date }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid15945664 of }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 Ch}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid16017612 eck Point}{",
        "oh(K|",
        "InstallVC",
        "8#9S9",
        "E;Ti)L",
        "z#|j_>",
        "RNOnS",
        "Error in encoding",
        "g'qSFV",
        "[jAtC",
        "!'fPc",
        "h`612",
        "~c9Iw@u",
        "E3yKu",
        "HIG9p",
        "D$09\\$",
        "U;3\\,",
        "9D$$UW",
        "IbFFS*",
        "SVKN*",
        "4*4[4a4q4|4",
        "l4y(a3my'",
        "!\"|(!!",
        "j*hl&",
        "FBlP8",
        "kzPb4 ",
        "'e'i?",
        "0 04080P0T0X0l0|0",
        "3F4W4",
        "=(?,?0?4?8?<?@?",
        ",eW1eJ",
        "ts9D$",
        "SqTUVG",
        ":1:^:h:",
        "JZ*tS",
        "IGhmL",
        "bx6%,",
        "+<pOG",
        "PMAXUD",
        "5c6h6{6",
        "7DF:Nx",
        "rr/V1'<",
        "7Z\\:i",
        "4e$sH",
        "KwXD&_",
        "Object Signer",
        "2{+zGS",
        "\\)o4pN",
        ")p0-/C",
        ">*rNo",
        "U{X4L",
        "$M{pb",
        "RaBF(",
        "pZe${",
        "6)}z@",
        "%Hpim$Ze)=",
        "lYV`&<7",
        "E}*O3",
        "q}cf1",
        ".$=2*",
        "P@D:C",
        "dsa_paramgen_q_bits",
        "zlunwise.exe",
        "c0 aK&",
        "'AxI8i3)",
        "*@{>H",
        "2:2O2",
        "tPZ|<",
        "3(4.4B4H4M4T4d4r4",
        "9S9o9u9z9",
        "Software\\CheckPoint\\Endpoint Security",
        "s^G80B2",
        "Suite B: invalid public key algorithm",
        "'H>DM",
        "K\"-c4",
        ":}t^ygT",
        "^B0_b",
        "ty;;u\"",
        ":):5:A:O:_:t:",
        "!v<?h",
        "220106235959Z0",
        "+}Ts/9Ucs",
        "<E=r=",
        "CSeAX",
        "-Vv2#L",
        "$ckb[=",
        "OhWeH",
        ";[_^]Y",
        "Q-8 fhw",
        "CMOVNP",
        "R)b5dk",
        "9tqS{F6",
        "7ZE!H",
        "|}k^4 ",
        "k`RoV",
        "FVLEQ",
        "|Tik=[[2",
        "Bpve[",
        "^Xb+e",
        "c yl8",
        "%*s%s",
        "PMULHRW",
        "=\">R?",
        "5fD##&",
        "XjxKD",
        "@Rf}zuhw",
        "f8R{|",
        "Ok>iYc",
        "[j|h;",
        "M%\"?C",
        "yaz>t",
        "v3f~]",
        "N[?\"+",
        "xAtDw",
        "qoj D",
        ">)]J(",
        "7EIwY",
        "TS_MSG_IMPRINT_set_algo",
        "NtQuerySystemInformation",
        "Y{#;{",
        "[j=YT",
        "U|U<QL",
        "EBEFEJENEREVEZG^#m6",
        "m3Vm7",
        "&1xxO",
        "h1!+2",
        "5TJqW",
        "d-+]uq",
        ":%:E:O:a:",
        "Qn!rhu",
        "r_J8y",
        "!{u]8",
        "DQCc~g",
        "*Z=| ",
        ";3.!!h",
        "yiw`|",
        "\\}nM6",
        "N<rY}",
        "1_Fzf",
        "PVVj8V",
        "&NrKh",
        "RSA_generate_key_ex",
        "4<5Y5",
        "w&q9E",
        "}x<(=j",
        "setUpgradeMode",
        "excessive message size",
        "5P6U6",
        "V4_^[]",
        "94f4R",
        "DGO)2",
        "7&7U7k7s7z7",
        "pr china",
        "Write error",
        "tb+e(",
        "WE4MK",
        "6xj-8",
        "6wykI",
        "<r0Vc",
        "yt>^XHv",
        "R}[S3",
        "Vb?M<",
        "ESS_ADD_SIGNING_CERT",
        "\\par }\\pard \\ltrpar\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid9651500 {\\rtlch\\fcs1 \\af1\\afs20\\alang1025 \\ltrch\\fcs0 \\f1\\fs20\\cf2\\insrsid13922132\\charrsid9651500 ",
        ");{0t3",
        "MM=ui",
        "[pt&B",
        ":+:0:5:?:E:K:Q:W:\\:f:",
        "050=0L0Y0",
        "3o4k3I",
        "\"~<^J",
        "<}0<x",
        "F'~*C",
        "UaqMC",
        "t6suB",
        "3shYv",
        "sslv3 alert unexpected message",
        ">#>z>",
        "2D4H4L4P4T4X4\\4`4d4",
        "2H+O!t",
        "Kaspersky Anti-Virus 6.0 for Windows Workstations",
        "hA;xZg",
        ",c]R'",
        "u/;V ]",
        "8 8&8/8i8x8",
        ">(>,><>@>P>T>d>h>x>|>",
        "9=ZwP",
        "2gd0Wy*",
        "0$'7d",
        "POLICYQUALINFO",
        "%mVxs[yhy",
        "no such file",
        ">$>/>5>:>H>M>j>o>",
        "dd8pG\\",
        "t/O-d",
        "4=4E4R4[4a4g4r4z4",
        "|9hJ4",
        "IQwte ",
        "Failed to receive SSPI encryption type.",
        "vKyHk@",
        "prc:#",
        "0u;n~",
        "S[|]nj",
        "eMNz[",
        "9t$\\t",
        "q|0^y",
        "H.,$x",
        "EC_POINT_add",
        "AXN`xL",
        "KYg~K:",
        "#ovkk",
        "6.mp{Bw09",
        "HQ)(t\"",
        ":[6<J[EE",
        "SSL connection timeout",
        "R{8:J",
        "\\)vXY",
        "#?]D]",
        "x}=^$",
        "aXz]l|",
        "me1k}",
        "X509_STORE_add_crl",
        "[@Z?4",
        "=$=,=4=<=D=P=p=x=",
        "y3#>Y",
        "-8.|#-",
        "re='E",
        "ct((G8",
        "$dQd2!_1+",
        "I%KB/",
        "_eq?We",
        "pA524",
        "479z/~(",
        "IO)$l",
        "040E0Z0_0",
        "UoD7\\",
        "\\rsid10967232\\rsid11012035\\rsid11029351\\rsid11213664\\rsid11216596\\rsid11222717\\rsid11226728\\rsid11303137\\rsid11349575\\rsid11409937\\rsid11414296\\rsid11429705\\rsid11543207\\rsid11543880\\rsid11549003\\rsid11555386\\rsid11743460\\rsid11798905\\rsid11819894",
        "P+Blo",
        "kClCmCoC",
        "%%q#Y",
        "|)@7t",
        ".*+nT",
        "b\"-e0<",
        "TDVNC",
        ";<;D;L;X;x;",
        "1C ,9SC",
        "\".s2E",
        "t|Snl",
        "!{IDR",
        "O!nVV",
        "<Md[4b",
        "U!M%t",
        "R;_Jn",
        "OT6X,",
        "@_t*l",
        ")lJ=E",
        "S,=^S",
        "Hh|xK",
        "|R]g? ",
        ".{,Yj8",
        "L$X)E",
        "9CPSMt",
        "56UFCR",
        "y/=XQ",
        "TULD4",
        "hS_|g",
        "YwWL!",
        "PC=t?",
        "VI)X5",
        "CLIENTWILLSTART",
        "AQT.o",
        "R.m)jn ",
        "Ss7'}",
        "x4D'cn",
        "n1l`B",
        "\\]`?c",
        "F|WQP",
        "debug",
        "jT5ae(",
        "r`')n",
        "MRI#A~",
        "byE|CE",
        "LV4.d",
        "_g/B:>",
        "x4SF;7",
        "l$<,B{",
        "!)v LW",
        "58PQ\\^",
        "(%WhU",
        "][_@^",
        "vista - uninstalling NP and PLAP",
        "load failed",
        "o^I2Z",
        "*_full.dmp",
        "H1ZiF",
        "HK_5d%",
        "_IOk@@4",
        "G&0Nh",
        "ETC?``",
        "Y}UET=",
        "&GHH>,",
        "u1WPV",
        "0J0T0}0",
        "ns-za",
        "7Yn.Guj:",
        ";$<t<",
        "t$4hp",
        "#&'af",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\install.cpp",
        "]mB%i",
        "xi7ec:!",
        "=,=<=@=P=T=X=\\=`=d=l=",
        "^\"]mja[",
        ";:# 9",
        "Jdm(4ev",
        "setAttr-IssCap",
        " SSL certificate verify result: %s (%ld), continuing anyway.",
        "lDN+m ",
        "5[nuz",
        "jCjej*",
        "PE\"#hJ",
        "N&&>'",
        "A&%0l",
        ",?d#06",
        "j&?a@?",
        "EF^j@",
        "es-SV",
        "!OB$A",
        "&<y42o",
        "=X|#jCd",
        "SOFTWARE\\CheckPoint\\TRAC\\InstallError",
        "t$jch$<#",
        "=Ng1Q",
        "za19`U",
        "</source>",
        ";h2`\\#5,",
        "0x-H,f",
        "_FV|C\"",
        "H]jYH",
        "Co\\?@\\",
        "434=4F4",
        "w4,WC",
        ",VK8mK",
        ")~ j#",
        "T_3B-",
        "I H_p",
        " $HP-s",
        "om}9a@",
        "FV.S ",
        "d{,S\"F",
        "D$ PVS",
        "Udl$r",
        "lIi3@",
        "61E162C2k2",
        "1V2e2",
        ":w`um",
        "vX-1<",
        "iKSz+",
        ",@'vDJ",
        "$OrMMB",
        "Y20\"z",
        "V1vu&",
        "6VC:l",
        "J}IT@mPW",
        "+\"suV",
        "Y nB;7Y",
        "EKV?c=F9{>",
        "2$202P2X2d2",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  means any legal entity (i) directly or indirectly owning or controlling You; (ii)",
        ">B?X?b?l?v?",
        "&{E{Y",
        "mWdF^-",
        "2B3X3",
        "c\"EcJ",
        "unProtectEPAM",
        "0:0a0",
        "P.`C\\5B",
        "N/t0E(",
        "h9Ihy;yqF!#>",
        "2$2.2H2O2^2l2",
        "SUVWh0a!",
        "g5U|[8",
        "/'';F$",
        "_>cPe",
        "j``Mm",
        "LY8Jw.O",
        "sB=j/",
        "()1ah",
        "2V{I|",
        "e*\"-D",
        "ASN1_STRING_set",
        "]oslc",
        "p`@W|M",
        "(bG8\"",
        "~14}'?R",
        ".AQ98,",
        " for ",
        "728X8",
        "5,5<5@5P5T5X5`5x5|5",
        "a@SQB",
        "Nu2Bi)",
        "+dGX%",
        "kut};",
        "#mS@4",
        "e7{IM",
        "signature",
        "rlgfI5",
        "203>3L3",
        "@^d$r",
        "xL~X'",
        "ExB!N{s",
        "Dman[",
        "gII}/",
        "\\$<UV",
        "D$<Pj",
        "inconsistent header",
        "6!7W8u8",
        "\",<BFr",
        "5{z14",
        "=A(|*",
        "mime no content type",
        "T13#fZ",
        "]~4HF",
        " 0xb8",
        "aNHb6",
        "FMR\"M",
        ":A$Z88",
        "ZTTo=Z",
        ".?AVUMSSchedulerProxy@details@Concurrency@@",
        "NdQ%s",
        "E(IWgi",
        ".FIB;",
        "m;$;q[",
        "t$$UWVP",
        "9!949Q9a9q9",
        "**XwH",
        "0&0B0^0z0",
        "nSN^H",
        ":|lu%",
        "YYhDn",
        "[ ]q_W<hf",
        "\\6SK ",
        "v(a9d",
        "B}E;S",
        "\\~^pv",
        "hJO\\x",
        "ae;}G",
        "DIR_ADD",
        "304A4K4s4}4",
        "ctrl failure",
        "@D)~\\",
        "-(2gckQu",
        "B|g+d",
        "qj|Y~J",
        "a5pD.y",
        "OpenDevice returns %d.",
        "F<FHER",
        "`Y&E(",
        "9rs/)~1i",
        "s&\"yw",
        "qzyh?",
        "C2Z\\5",
        "PIr`L",
        "-|Y!_",
        "//F/v",
        "ACCT rejected by server: %03d",
        "EoPb'v",
        "AaBn?",
        "ssl3-sha1",
        "md bio init error",
        "Rq-3b=",
        "m|?(0",
        "n{:E%",
        "[q_qbqfqiqmqpqtqwq",
        "Gz`d9+",
        "Z-h,F",
        "++z\\E2",
        "4S5f5n5v5",
        "PJ+o;a",
        "*;dj&nW",
        "%bxGN",
        "&7va,",
        "P\"QbW",
        "8]nzK",
        "\"lbN.",
        "zpzP{",
        "trinidad & tobago",
        "JNN}?",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid11303137 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5259060 8}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "3l4t4",
        "3(-BP%",
        "7^B`Z",
        "Stack Dump:",
        "5 5&5I5Q5",
        "8$8S8^8g8",
        "$I>{tx",
        "QPh #",
        "!%g b7",
        "i`Yk=",
        "[?!'p",
        "Y\"~R{",
        "6:<:B:H:N:T:Z:`:f:l:r:x:",
        "6/646>6}6",
        "L$X_^]3",
        "sdsiCertificate",
        "ALrGmf`",
        "_Ki~1h",
        "VI|Wg",
        "=] =%4999[^;",
        "F+|9n",
        ":u=VQf",
        "TrueVectorIF::SetProtectionByPassword(password)",
        "gAuXtBT",
        "zPtT*1",
        "EyuAm",
        "TJ~zP",
        "2d2|2",
        "_U_]/",
        "3pAwJ",
        "61d5J5",
        "Sbo>w",
        "~UkGj",
        "hM4{5,G",
        "<WV+=R=",
        "7}]Gz",
        "8Vvb?.",
        "bR~GD",
        "KH[c[",
        "_|lmh",
        "# https://curl.haxx.se/docs/http-cookies.html",
        "=K=R=",
        "+hI<E",
        "!gg3j*G",
        "D$lW3",
        "Q3PhvI",
        "? ?$?(?,?0?4?~?",
        "o=XV9O",
        "fVtWG",
        "S_^U;9",
        "n)f=nHf",
        "fH\\{=B",
        "? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?",
        " N V ^ d i",
        "-_sZs",
        "&N:PpKe*UL",
        "GKBmS",
        "Malformed ACK packet, rejecting",
        "!;81r&",
        ".\\crypto\\rsa\\rsa_sign.c",
        "H:L:P:T:X:\\:`:",
        "2 282H2L2\\2`2d2h2l2t2",
        "HRuntime Error!",
        "\\\\U9H",
        "Z3.mu:",
        "MhMvMw^?^hOfO9Om",
        "*&Y=<H",
        "L$X3L$L3L$",
        "=O&43/",
        "wC7^?",
        "cgCWp",
        "www.digicert.com1!0",
        " OT8>N",
        "OM}];",
        "h!a{~",
        "@[U5,",
        "JEK-lV",
        "s5?G[[",
        "9~4to",
        "?b45*",
        "QLEgp/L",
        "v`WbF",
        "AES for Intel AES-NI, CRYPTOGAMS by <appro@openssl.org>",
        "'Gl)N",
        "?%u*X1.I,",
        "5, j5",
        "TEq:w",
        "d%t_I`Td",
        "W&U~W",
        "XnNN\"",
        "UYEUVe",
        "mzs{Id",
        "[X3CO=",
        "}*UtcY",
        "^DsO]/",
        "l1\\E*",
        "lj,4),",
        "`!:<>",
        ";)+:%",
        "_BTec5",
        "a0'2u",
        "B-163",
        "000@0D0T0X0\\0`0d0l0",
        "wo}z*",
        "</UpdatePackages>",
        "pAy%/",
        "W^Sv!",
        "U/jq4o",
        "ZS;:.",
        "e?zdV",
        "PRET %s",
        "9\"9'9,9<9A9F9V9[9`9p9u9z9",
        "4&x5Q)",
        "162`2",
        "NVw|4",
        "_increaseArrStatus@16",
        "$4B|c`",
        "camellia128",
        "[VSWriteUnisntallInfo] Failed to write the Memory Map.",
        "b5+>P",
        "aAU@s",
        "LEMU@u",
        "_fn8\"",
        "9\":N:",
        ",K*_}z",
        "}{J{q",
        "JlE_%",
        "ar-OM",
        "c$khg",
        "4 {q'",
        "gdgH@",
        "~b0{Q0",
        "~>i-!",
        "XZr#x",
        "+-u\\Z",
        "8qpy\\eS",
        "TjBcc",
        "`managed vector copy constructor iterator'",
        "l_GzL_",
        "lI8uP2q",
        "'QI@A",
        "I=?FLp",
        "%Gely",
        "Om{,PM<",
        "Q-KsK",
        "G[0+Ff",
        "(z\\0xO",
        "CEIk9",
        "I}Z>e",
        "G{HWh",
        ":=;h;",
        "L_H7n",
        "r8N|=R",
        "-o91t",
        "|Rpqf",
        "YG\\g`",
        "P0A(5",
        "DdV)mn",
        "'iu:)c!",
        "######",
        "n3Nr\\",
        "9$9,949<9D9L9T9\\9t9x9|9",
        "WSESetUpgradeKey()",
        "&;:\\s",
        "50tlC",
        "2%2*2v2}2",
        "`,X>`b",
        "[%p'l",
        "N2jbb",
        "KkrM#",
        ">*I',",
        "j\\gIY",
        "m=kJX[ug^\"",
        "failed to get proc address error is %d.",
        "B8/,{",
        "d2i_X509_PKEY",
        "expected low surrogate after high surrogate",
        "h\"-;d",
        "failed to schedule ExecXmlConfig action",
        "3-3h3v3",
        "=$=4=8=H=L=\\=`=l=|=",
        "Zbdaj",
        "o;fKf",
        "[F[&w;nb",
        ">V?}?",
        "Ygtq@",
        "YpFv]ge",
        "FB{Cl#;",
        "#:h4-",
        "]{N}3",
        "FJv\\&",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\msiproperty.cpp",
        ",>A<DF",
        "H'laE",
        ")7rw\"",
        "D$$WV",
        "sg;~S",
        "#zg Yor61",
        "J:\\R'",
        " 0x29",
        "trac.config",
        "4 4@4H4P4X4`4h4t4",
        "rdiDv",
        "707q7%8B8",
        "f;\"b`",
        ":EXTERNAL TYPE %s",
        "=Sr\"*",
        "tP&\"_",
        "I=sN.dJ7",
        "\\m5\\2",
        "&27+G",
        "sW/4|",
        "=,=E=^=w=",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477 within two (2) business days from Check Point fulfillment hub, following confirmation of any such failure. Customer}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid14171957 s}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "dP~7+",
        "z/Z,L",
        ";nq:V",
        "2^b\"k",
        "subjectDomainPolicy",
        ";owt=m",
        "s4KZ~e",
        "55j_WW",
        "en-NZ",
        "66Z[)",
        "`\"Y;f",
        "ec'N'",
        "mr\">h",
        "W2uRlVj",
        ".}jP!",
        "Y`e&a|",
        "IgO#a",
        "jejtj'",
        "\\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid1729076\\charrsid15169477  ON ARRIVAL (DOA)}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076 ",
        "LoadStringA",
        "RdEE)",
        "-~]WR|",
        "X.@Hh",
        "4(`m#",
        "%s (0x%08X)",
        "1 2y233|3",
        "Ke's2",
        "L}t6f",
        "9Zh&Ks\\",
        "/~}Gq$BcF}(A",
        "2w2}2",
        "=fF^j",
        "Ejl_f;",
        "<La>e",
        ":8[d ",
        "]P~s\"",
        "<LGV ",
        "{g2RyS",
        "L7L>03",
        "e,RUk",
        "x[E\\/L",
        "lHPS)",
        "2f<U,",
        "N.?Bp",
        "fw27]",
        "ISTATES",
        "Ogg>e",
        " 5uHt",
        "'y`p(",
        "'L4dO84",
        "\\ZoneLabs\\updlog.dll",
        "`M0-&",
        "=P@:M",
        "uQ6V6",
        "h{9o6b",
        "&_hIv",
        "?:?j?",
        "969H9G;f;x;w>",
        "3n~ze",
        "}g43|",
        "gC2[aaHG",
        "i^VkBr4",
        "1B3F3J3N3R3V3Z3^3",
        ":3:L:",
        "l{z/BR",
        "9,909<9@9`9d9p9t9",
        "?\"?+?2?O?p?v?",
        "QAA@s6",
        "KEoKf",
        "6@7M7u7",
        "?XOPR",
        "NLwFl",
        "5VSgm",
        "??_g\\",
        "q#fu7",
        "_0R6P",
        "t/$vRr",
        "36n\\~N",
        "&U&m&",
        "czbg5",
        ")\\ V3",
        ">#>)>/>3>A>W>c>e>w>",
        "0#h ]",
        "F?a)0\\",
        "4<9h9/:p=|=",
        "5uA4e_",
        "?C~ajau2LF",
        "8$8D8L8T8\\8h8",
        "2\\!Mn",
        "@V4]&",
        "~Y`q5",
        "yplEG",
        "To!h{",
        "SHA-256 part of OpenSSL 1.0.1t  3 May 2016",
        "P@z7d",
        "SVWU3",
        "gJ2~|h",
        "Gdt*s",
        "J0J@JXJ`Jl%",
        "h&+%v",
        "s|\"q@",
        "91tV@",
        "juh0^%",
        "P @Kyw",
        "NRF\\7",
        "?X$C: ",
        "zz;SQ",
        "g3{2g",
        "T{YPP",
        "[_H,0Q!",
        "i+T5Qk",
        "LRY-W",
        "setct-CredReqTBE",
        "B9boF",
        ";/<T<l<",
        "W:X|5C",
        "3\"3,323<3J3P3`3l3r3|3",
        "Failed stopping CPDA Service",
        "H^;y#",
        "79C!$.",
        "}[V7do",
        "ipsecUser",
        "CE*@Q=[",
        "[%s UNLOAD] process count:%d, cmdline:%s",
        " 0xbd",
        "~<JlJUHI1",
        "1G`lt>",
        "u>j?Yf;N",
        "wI`R=",
        "4F sL",
        "SetDriverMode:  SetDriverMode finished.",
        "@{/!b",
        ")1Fyt]",
        "k&]N0",
        "\"J^YM3T",
        "W/~)r",
        "<lt)F",
        "7y<^?",
        "54787<7P7T7X7\\7`7d7h7l7p7t7x7|7",
        "paITg",
        "{T_IZO",
        "@k.KI",
        "z<(@t]",
        "P(<~H",
        "g P\"#",
        "%{7[c",
        "Nqy$-",
        "z,j*)'I",
        "/j.=;",
        ")$mKU",
        "RZrlLy-",
        "mQ,'.7",
        "eeuW:v",
        "H0M0u0",
        "N@>W=,",
        "!G8W[",
        "3Hz<8w",
        "/X_zbhv|",
        "/w`y=W",
        "_*xX;B2",
        "4GA-:",
        "6,616",
        "lk[_f",
        "ZoneLabs TrueVector service",
        "str_field2",
        "kp_[B",
        "$_4._",
        "i0#Q\\mZ",
        "D$8PW",
        "v)9FX",
        "]M`*F0",
        "OpenSSL DH Method",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{C90F3E44-3BF6-11D4-A110-00500405613A}",
        "4<5;6[6",
        "KuJ7}",
        "I6(J@",
        "2'2A2",
        "@!@T;6",
        "$v!2e",
        "1Y3^S,",
        "Si!iF?",
        "B3\\CW",
        "PathAppendA",
        "BHY=]",
        ">~Y2~",
        "C|V#}",
        "F!n?4",
        "Kaspersky Anti-Hacker (All SKUs)",
        "bVpnUpgrade",
        "zY%z8",
        "9=l9j",
        "`w*+@`",
        ">$>,>4><>D>P>t>|>",
        "Zx1+D",
        "};Lnpj{",
        "nkvh$",
        "6B6b6",
        "aom?@",
        "u^Mhq",
        "Q%e$?",
        "y|$2x",
        "4-e;'n",
        "$7=O'y",
        "d=bl*",
        "=9>|>",
        ".\\crypto\\bn\\bn_div.c",
        "Vk@.;",
        "!bW44",
        "TION OF DATA, OR FOR COST OF PROCUREMENT OF SUBSTITUTE GOODS OR TECHNOLOGY, IRRESPECTIVE OF WHETHER CHECK POINT HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. CHECK POINT'S MAXIMUM LIABILITY FOR DAMAGES SHALL BE LIMITED TO THE LICENSE FEES RECEIVED ",
        "R2I_CERTPOL",
        "K}1AL,",
        "> >@>H>P>\\>|>",
        "Q0 nl",
        ".[ij{$",
        "GC\\/27",
        "Vz:C[",
        "disabling EPRT usage",
        ".Y}D$",
        "/MP_8",
        "DuplicateToken failed, err=%lu",
        "1{0#/|",
        "3#Z}R",
        "cC#`#",
        "at*)J",
        "=zghI4T",
        "uZ #^#",
        "[<{{I",
        "?5~p&",
        "iyqUx",
        "TCN11",
        "y~Z<nb*",
        "Y$ycT-",
        ",#i$2",
        "nCeTg{&",
        "N&g!=b",
        "jI5\\z<",
        "y.|\\)",
        "Bad boolean",
        "AK<[To}",
        "!T^6I",
        "QA^,e",
        "XDUj6",
        "#4kfx%",
        "dZ8~#",
        "bW/lkg",
        "E_QG/Ey",
        ";/;H;d;",
        "Di5]V",
        "9xw,T",
        "XV#~s",
        "?v)^\\",
        "\\u;cO",
        "_<X>b",
        "\"eyO<",
        "t:(**j",
        "certificate has expired",
        "c2tnb431r1",
        "Helper::SetRebootFlag",
        "=c+xs~Ik",
        "-BH<Fh^)8",
        "](dXb8",
        "*zy8H&@",
        "R~rV^",
        "=!=^=",
        ">*>0>6><>B>H>N>u>",
        "D7CrD",
        "#hN|N",
        "ip=b6",
        "$6T8-",
        "`<)qGQ",
        "A6<F)P",
        ";+;U;",
        "4FDJXJlJtJ",
        "Kcq!e",
        "=.>D>d>|>",
        "p[BTT",
        "u)PSVW",
        "0~\">?",
        "D$pPh",
        "5%6<6m6",
        "~e50\\^",
        "ecdsa-with-Recommended",
        "PVhHJ!",
        "g[e3}",
        ">$>,>4><>H>h>p>x>",
        "yyxxz",
        "&02_F",
        "L|L:|m",
        "?zctk",
        "6<6M6\\6m6r6|6",
        "4M4Y4",
        "`^dIi",
        "]Dq?v",
        ";P)bG",
        "t&8%^",
        "0`Xqo",
        "! A6fK",
        "boost::filesystem::weakly_canonical",
        "C]DEU",
        "8+ Jv",
        "\\fQ4%bq",
        "?]6SvL",
        "*bZ`2",
        "8h!a{",
        "_,/=Q",
        "bs<Al",
        "id-smime-alg",
        "808L8P8p8",
        "zonelabs\\zlcommdb.xml",
        "fH0wb",
        "{D2^.",
        "0k*)S",
        "zj9$G",
        "aiPxT",
        "m+ws|",
        "wap-wsg-idm-ecid-wtls3",
        ".?AV?$moneypunct@G$00@std@@",
        "[^PY)!",
        "HU{DzfHxF",
        ">H<4p",
        "W&Jg^t",
        ";~%#NU",
        "p>hUZ",
        " error=",
        "GT%=z",
        "W*15<(",
        "iv{pE4rc",
        "?%8F;",
        "]B)^7",
        "; ;@;H;T;t;",
        "TiP`i",
        "7Wjg[ ",
        "i84A4M",
        "j:bf3s",
        "k&g+aR)",
        "1$1,181X1`1h1p1x1",
        "758P8k8",
        "0:0M0h0",
        "{&{,{4{>{J{",
        "3nZA>",
        "xnu#h",
        "a{:x{",
        "wOb;7vV",
        "KO9o/",
        "ySrb1lE[",
        "#CzG}dcsU",
        "\\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext45 \\slink46 \\sunhideused \\styrsid15298478 header;}{\\*\\cs46 \\additive \\rtlch\\fcs1 \\af0\\afs24 \\ltrch\\fcs0 \\fs24 \\sbasedon10 \\slink45 \\slocked \\styrsid15298478 Header Char;}",
        ":4:Z:",
        "uKh4L",
        "^wRfVW0",
        "TEi99",
        "cptmis.dll",
        "AjZLT",
        "iD>K$",
        "iEgIZ",
        "ZoneLabs\\avsys\\Bases",
        "[pu=>ct",
        "\\drivers\\fidbox*.*",
        "Y@EP,",
        "v.(X-Fw",
        "5s7N2",
        "\\V@XG",
        "Uo}xI",
        "`^@t8",
        "$Lz15y",
        "\\y|w\\",
        "e5$1n:",
        "Qh]?B",
        "OalS4t",
        "D#3F=~",
        "SM&\\P",
        "DSA_PKEY2PKCS8",
        "7*7Q7V7",
        "SecureClient could not be restarted following the registration of zlscv.dll",
        "&{g4 q",
        "Q\"|\\l",
        ":tQBp",
        "kwp\"o[_",
        "879?9J9",
        "[zaHh",
        "failed to read XmlFile table",
        "bcllX",
        "ek#{/q",
        ";Ms-~",
        ",J..[e",
        "YUXAX",
        "f}hJ-'",
        "$LjDlm",
        "G<)B`P",
        "A>}~x@i",
        "RdItB",
        "?lQIB]",
        "6 6(6,686@6D6X6\\6p6t6",
        "K'5oZe",
        "'$%ik",
        "unable to listen socket",
        "L%^h3",
        "SCFikN",
        "t2hDDM",
        "s>@L,m",
        "5C4:r",
        ">q?)l",
        "&#%w6",
        "JKXHO",
        "+\"+b2",
        "3t$(!",
        "Uninstall.bat",
        "&iy:O",
        "po#|Jz",
        "}DVqs",
        "zLg(t3",
        "P#OTc",
        "TFHNMN",
        "Jyr?x",
        "*<&+`",
        "DhuQc",
        "94:i:",
        "D$<;D$",
        "whWUSj",
        "Uel@/>",
        "y#SFvvw",
        "<_:5!%GrIE-",
        "D$HWPj",
        "wWzwX/",
        ";rTRq:",
        "jpjqj\"",
        "1-M(j",
        "unsupported status type",
        "^09^8t",
        "revocationTime",
        "dpqk|(",
        "msgbox_abort_",
        "<[Xi#?2",
        "{2{ho*T",
        "<)j)F",
        "SEC_E_SECPKG_NOT_FOUND",
        "QtML+",
        "password is NOPASS",
        "SSL_write() return error %d",
        "P2[PW",
        "ILXA=XS",
        " --verbose",
        "l=.=P",
        " ,oa}%",
        "{uhyZ",
        "createAttribute failed",
        "vPP%v",
        "v<~\"_b ",
        "g&P%q",
        "[BWAi",
        "0gBzo:",
        "\\b\\i\\f1\\fs28\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext0 \\slink16 \\slocked \\sqformat \\styrsid13065977 heading 2;}{",
        "3V3h3W4",
        "tqhp=",
        "failed to get WixShellExecTarget",
        "jSsJu\"",
        "S m`S",
        "ZA\\`{&",
        "7F^p*=3s",
        "$|'.)q",
        "%>Np6",
        "setct-CapRevReqTBSX",
        "=(0Kex",
        "C7E}z",
        "bm,'\"#Vc",
        "@zzjhr",
        "Xch2OB",
        "OU$aA",
        "WMs(1a",
        "X|)IU",
        "cz*m[s>",
        "Range: bytes=%s",
        "8&,ug",
        ".L9tJ",
        "_ FEiNc",
        "(L(|H",
        "BjC't[",
        "N?z/V",
        "ruOK(",
        "5h4i*>",
        " noOfficeMode is disabled -> do not write it to registry",
        ".\\crypto\\evp\\p_verify.c",
        "M,rB,5D",
        "656A6^7e7",
        ">$>,>@>H>P>X>\\>x>",
        "vTvR<Su",
        "O*y97tS",
        "HCeP+",
        "cmd /c \"del /F /Q \"%s\\Temp\\trac.config.upgrade\"\"",
        "i[bdM.",
        "L7cO?",
        "JlE]v",
        " set ProductName Failed!!",
        "y>F0\\",
        "TZ@K[",
        "#vmLd",
        "yCP6HW",
        "d#~*1",
        "XrV0L@",
        "=)nr{q",
        "Q?HJv",
        "Knnd!",
        ".\\crypto\\bn\\bn_exp2.c",
        "d2i ts resp int failed",
        "#7.h3",
        "1T$ 3\\$ ",
        "<z|_w",
        "F|vV]",
        "BihO/e~w",
        "={w'<",
        "`?wvJk",
        "+6uEBd",
        "\"cs73KI",
        "=KYH!x5a.X",
        "<&=s=",
        "%N?T3M]W",
        ";.`$j",
        "EM>C>",
        "?;$>H",
        "QvkVR",
        "lGPm4`",
        "37T'V)R",
        "Syntax error in telnet option: %s",
        "x:(qV",
        "Bv!UlO",
        ":*:Z:",
        "9$:<:d:",
        "|22or",
        "M/~(V",
        "djMA!",
        "$D[sx6",
        "_get_timezone failed with result = ",
        "@v6T@",
        "U#g41&J",
        "h({$1W",
        ",\\$'-T",
        "unable to find ssl method",
        "aQ;av",
        "r:9g5",
        "izL{w",
        "\"y:w&",
        "5!515Q5a5q5",
        ";A<}<",
        "%xh,n",
        ";5<]<}<",
        "707T7`7h7",
        "%4}\\6",
        "1f2l2u2",
        "wrzHf",
        "EGa#H",
        "bf-cfb",
        "4!5*5J5x5",
        "-2}*n",
        "Ouh/s",
        "?,c:yE",
        "P/K&7",
        "Code=",
        "hsgW3Do",
        "8{w2^",
        "ssl23_write",
        "U+P+&Q",
        "no subject details",
        "SETNP",
        "api-ms-win-rtcore-ntuser-window-l1-1-0",
        "Gw;W,",
        "9Jjr|",
        "U@?<A ",
        ";<;C;",
        "Z-Fy[",
        "=V=h=",
        "I=AQh",
        "?VvoKr",
        "MG[Zwh",
        "&'R\\#",
        "!*d-7",
        "$BiS~\\",
        "\"22O/",
        "{\\^[_]",
        "U$_BX",
        "Yo_M[",
        ",z'ev",
        "Ww1>8",
        "SecureClient could not be restarted following the de-registration of zlscv.dll",
        "(RhM+",
        "'J:^xW",
        "kaZC;",
        ";+;68",
        "\\?[`B",
        "2)2E2a2}2",
        ":T:\\:d:l:x:",
        "pQ5-a",
        "yy338ly",
        "dLLr}R",
        "g\\n^<",
        "U*\\As",
        "nf']&7",
        "kVY +",
        "J,.zo",
        "yAEEJ",
        "8'8,8]8",
        "B`drcl",
        "$6F%]8U+;",
        "v8VmK4a]",
        "UpdateZoneAlarmXml:  Upd_MergeConfigurationFiles failed.",
        "8F8~8",
        "3<4G4L4d4t4",
        "&v8fFo",
        "Dp-TP",
        "Y.O*vM{",
        "hXJ=>YWC",
        "0\"0(0,02060F0O0X0j0z0",
        "ISi{g",
        "ZFi}Qs",
        "$kPgK",
        "@e&Yj",
        "VSSetUpgradeKey: cannot log in",
        "kK04k",
        "7L#QBT",
        "`~K|4",
        ";/;Y;",
        "X509_load_cert_file",
        "k_3X^",
        "Ri]H4\"g",
        "9):o:",
        "t-EIKa",
        "failed to write to file: %ls",
        "ReadFile failed: %d",
        "$po88",
        "rtf;U",
        "H2/ra",
        "kPKBx",
        "r)k&B>",
        "0l_D\\",
        ".6N^G y",
        "AM1signatures",
        "%SKTK",
        "%s\\SysWOW64\\epcginashim.dll",
        "4-E@Kp",
        "#JejQ",
        "DBDRD",
        "ENGINE_set_name",
        "\\yuC_NM",
        "cx#Tq",
        "1N!#5",
        "TQz=.w\\_",
        "]JxV$",
        "<O#Jn",
        "rnxY_",
        "D$ SPQ",
        "=W7g5",
        "j{>:n",
        "qxgC-",
        "YU=}U",
        "=lvRI",
        "]s7,g",
        "0;1V1l1",
        "00C.,",
        "StorePropForDeferredCA",
        ":xXjC",
        "]38/V",
        ":\":E:",
        "MT_}S",
        "GFAC.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "Y@WV<",
        "aes-128-cfb1",
        "[fQbx",
        "=F>W>v>}>",
        "1K$|2W",
        "oH/*''",
        "7S7g7z7\"8",
        ":F/.P",
        "3(383D3T3$404@5D5H5L5d5h5x5|5",
        "Px$)eC",
        "5>MVv.",
        "%8+uc",
        "g2\"ma",
        "eQku\\GOQ8",
        "SetHandleInformation",
        "zFYDTw",
        "A9qOC",
        "LAb4'",
        "ude|m",
        "]mG\\^{jl",
        "Rm6`SBz",
        "G)%yW-",
        "common ok and cancel characters",
        "TrueVector driver loaded OK.",
        "ISM7?",
        "STREAM_ERROR_READSTREAM",
        "D$ 3,",
        "F|ht3",
        "mceG\"",
        "xVy}P",
        ".^/B/?=",
        "+S4T=el",
        "4:=?#",
        "organizationalUnitName",
        "t1Q[V",
        "<$<,<4<@<`<",
        "g0.c`|",
        "L$P_^][3",
        "TBn.].",
        "~ &e)",
        "@T*cm",
        "Illegal byte sequence",
        "~n(~`@",
        "M;ZFU%\"W",
        "Fe9&>",
        "NSTnx",
        "e[6%-k]Wq",
        ">t8bF",
        "!:$h/e",
        "jvjqj",
        "ft5T*Q",
        "7|ONU",
        "C&(f7&(",
        "V:{2:x",
        "t[)iv",
        "%#}yM",
        "SCRemoveBefore started.",
        "'=/?{0_V",
        "] p$D",
        "\\y14T",
        "z5}f>",
        "z0`uhc",
        "W,YF[",
        "objsign",
        "2+2t2}2",
        "RC4-HMAC-MD5",
        "ERsL)'/",
        "protectEPAME1",
        "X$C]I",
        "X-PPr3",
        "; ;$;(;,;0;4;8;O;p;",
        "000P0p0",
        ".-Y0j",
        "inappropriate fallback",
        "0<0D0L0T0`0",
        "`uHLC",
        "HFFe$q",
        "g55\"_",
        "e0@xZ",
        "Un,fb>",
        "%l4Su",
        "858B8w8",
        "`|y#7",
        " -A)$@",
        "!LZbq3o",
        "9/SF'w.",
        ")]+bn",
        "d&YvO",
        "VG+Qi",
        "t3hx\\!",
        " [-*;",
        "0 0$0(0,0004080<0@0D0",
        "cannot find global atom. Error: %d",
        "CMOVL",
        "mxzOC",
        "*ll+,",
        "pathutil.cpp",
        ":QR U",
        "+Y?ut",
        "OpenSSL ECDH method",
        "dL2t{S",
        "?xLoX%",
        ">i-AO",
        "Bvr'O3@",
        "0&.5;55",
        "{[8zu",
        "F%au3",
        "c45VZ",
        "1_M7>",
        "connection already in progress",
        "operator",
        "Z.@h4I6,y",
        "{\\listname ;}\\listid474762581}{\\list\\listtemplateid145639948\\listhybrid{\\listlevel\\levelnfc0\\levelnfcn0\\leveljc0\\leveljcn0\\levelfollow0\\levelstartat1\\levelspace0\\levelindent0{\\leveltext\\leveltemplateid67698703\\'02\\'00.;}{\\levelnumbers\\'01;}\\rtlch\\fcs1 ",
        "yTk+7",
        "`UuY[",
        "V?u*F",
        "?8d)IT",
        "\\ZoneLabs\\vsdrInst.exe -u {AC30BFB5-834B-46d2-B912-6CE71684EB2D}",
        "?eUamhp",
        "2ZEA8$",
        ":\\:{:",
        "CANT_SET_PROPERTY",
        "*&w{z^",
        "b`!Vq",
        "u jnh",
        "S\\m3y",
        "jJ5)S ",
        "f3}ME.",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{75193929-9A52-4CA4-98DE-8C7296940920}",
        "rs '#f>",
        "1MQG=",
        "> >,>L>T>p>",
        ")s7*3",
        "1/($-",
        "A7diRC",
        "9t9{9",
        "U^`q)@>r",
        "~MtnQ3",
        ":^ji}",
        "VWhtt",
        "$6E5T",
        "Mr%2D",
        "NNS`>g#R",
        ")bxPA",
        "3_>CWZ",
        "-Ih\\[",
        "MinghuaQu)",
        "spanish-bolivia",
        "P:+pK",
        "unknown certificate type",
        ":8w')",
        "q15 d=",
        "Public-Key: (%d bit)",
        " !\"#$%&'()*+,-./0123U456U789:;<=>?@ABCDEFGHIJKLMNOPQRSTUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU",
        "Tzo`>",
        "vj*Xf;",
        "5#5?5b5}5",
        "0jEKx",
        "9cb2400825e982c78ec7a27cc0c8992416c9d8b2a755fbf74cd25442a820166c2cd933f79e3be372bd1f07b5c3989ca74aaff2422b24eb1b475da5df374fd9ad",
        "333E3Q3",
        "Jkn|:`",
        "%.)1a=H",
        ">5^4Mt",
        "CleanTrayComponent started.",
        "?^BW7",
        "s%&\\V",
        "UCPm\"U",
        "e{3O:",
        "3L$<3L$,",
        " !J0(",
        "j{jrj",
        ">q-FA",
        ":,:?:R:a:l:z:",
        "u%%\\F",
        "*_R$a",
        "+XXX9H]",
        "lTH\\[",
        "HWe{9",
        "2/3i3",
        "6a7m7z7",
        "G=aF~",
        "3ux|w",
        ":@~9)",
        "L3w<O",
        "jPh<8#",
        "R]w4C",
        "=0=K=f=",
        "]>]H$%#",
        "Ov#)6G",
        "D$(Ph\\Z#",
        "|SUeS'",
        "rfor&JI`",
        "Dag4r",
        "ly=qP",
        "(\"Ey.",
        "setct-CapResData",
        ":NtfM",
        "X509V3_get_section",
        ")}L='",
        "8b`+A",
        "Gpc_7",
        "iS2C6",
        "+ms+^",
        "2rKj2",
        "[I}k{",
        "I&h[Y",
        "yQy):",
        "$0Ir3",
        "zTJGcY",
        "<<BTE",
        "%2DaB",
        "9n53~",
        ":%;;;C;Q;q;",
        ";\"jwo",
        "Pn8'e",
        "nan(snan)",
        "aX<8>",
        "(VL=p9",
        ";I<_<<=E=U=\\=a=r=y=",
        "N/|1;",
        "5E8_[",
        "?X1TNX",
        "(0!C6BB",
        ",O%RgS",
        "[.|/en",
        "V[l4{",
        "Xn[C@",
        "W,+IW",
        "Vx(q0",
        "\"~g0#",
        ":,zJ,",
        "mg8Zp#",
        "W*Z7)",
        "Tw=R#",
        "pilotObject",
        "(%?tJ",
        "wrong signature length",
        "<$<0<P<\\<|<",
        "#tO:t",
        "Tqqp|F",
        "8r<9:",
        ",MNLFSsS",
        "/EfEd8",
        "RY:a;",
        "[w[)M2S",
        "3(3<3L3T3\\3l3p3",
        "y=Y!QVx",
        "k5g;H",
        "l%K(;",
        "=J'ci",
        "ZK<gYZ",
        "B_l w",
        "> >$>(>0>H>X>\\>l>p>",
        "CSckl",
        "a|Qnz",
        "id-smime-aa-ets-otherSigCert",
        "8eH&d",
        ".\\crypto\\rsa\\rsa_lib.c",
        "A;LB/",
        "gX]QQ1",
        ".?AVlength_error@std@@",
        "Z [O|",
        "9,\\6!",
        "'$V&a",
        "\\uH<%U",
        "Pu4bX",
        "M@fMUq",
        "S?X71",
        ">\"N_0",
        "enin|o6",
        "82kY5",
        "p `Di~^F",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 certain programs and/or provide to You the customized ability to delete }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid16665164 and/or restrict access to }{",
        "; ;8;H;L;\\;`;p;t;x;|;",
        "K&L.LRO",
        "zK>r/",
        "X}yu~*",
        ":U`jv",
        "HEAD ",
        "<BDAVFileProtectionON>",
        ">u*}g",
        "%u}y\"4",
        "failed to getenv of 'ProgramFiles'",
        "fA<)Ej",
        "c4 pS",
        "B_\"5T",
        "D1%@(",
        "KfJfYq",
        "l#Pa?",
        "CYEcw",
        "G8kIn",
        ")^'IX",
        "1*1<1X1p1",
        "msg_hung_",
        "xLrnI,",
        "1?2?\\#",
        "iItp4K",
        "IX+/u",
        "\\*QBv",
        "Y:4VI",
        "4^L?Y",
        "CMS_EncryptedContentInfo",
        "D$$PSW",
        "dF&Ke",
        "Z8M{l",
        ",%|y:",
        "O$z'ja",
        "jgjej",
        "is#+M<C",
        "YyiS5",
        "?.?W?q?}?",
        "7)7E7a7z7",
        "__stdcall",
        "8N455",
        "M)Sp`g",
        "0{5+N",
        "??beD",
        "RSA_check_key",
        ",LSPZ",
        "Send failure: %s",
        "%HH/z",
        "1+1B1G1",
        ".?AU?$token_finderF@U?$is_any_ofF@D@detail@algorithm@boost@@@detail@algorithm@boost@@",
        "cNsLly",
        "6@6E6K6P6V6[6a6f6l6q6w6|6",
        "<1=w=",
        "<4i%x!:J",
        "E[:DGK+",
        "bl2q*#",
        "zOJDv",
        "D$`Pj",
        "y=f:>",
        "Failed to set Property: %S with path: %S",
        "OnChangeDriverRollback.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "pL`) h-",
        ":9:T:n:u:",
        "']*ga",
        ".-k2p",
        "{ro)w",
        "g'E^r",
        "[Y]9Ua=",
        "c?bGqu",
        "OnUpgradeAfter",
        "I\"`O(W4",
        "^Q\\Q[",
        "sv`=e",
        "(s$_h",
        "gpFmi[",
        "]YD |Hv",
        "h~;O~f9",
        "8Jg'KA",
        "8loy[2",
        "zab~s`",
        "757`7",
        "'7M}@",
        "id-smime-alg-ESDHwithRC2",
        "a^>jz",
        "vOj0<|;6",
        "2 2024282<2D2\\2l2p2",
        "-K6i&T/",
        "rvtd_+D",
        "8D$,t",
        "!3v0Q%",
        "]&hu~{?",
        ":hgWhBf",
        "CIR $",
        "_startSending@8",
        "1A2*<",
        "#v%S*",
        "w={7e+J",
        ">-OUs",
        "''Wa-}",
        ",xvWEX",
        "5'5.5v5",
        "'h~{H",
        "L$ u)",
        "3)X|bx",
        "c5>8X",
        "J\\d3N^",
        "F^k;XyCi",
        "qlPaZ",
        "f_GhV",
        "<_-zc",
        "<\\0zsl",
        "$B?>{Z",
        "7A7c7",
        "\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 5;\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 5;\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 5;",
        "cjf+d<",
        ".sJ/Fi",
        "2/aYF;N?",
        ".U~?6",
        "L|pIP",
        "#c92S",
        "_MU{}p",
        "a}LRj+",
        "l$$;t$4sS",
        "(q!2I",
        "-qgcD",
        "`]g}g",
        "+$~~p",
        "e2em\\:",
        "setct-CapTokenTBE",
        "Bh.xI-",
        "TTXTYju",
        "C%6A#",
        "&avU1",
        "2;2T2p2",
        "pr-china",
        "VSMON_WONT_STOP",
        "-xIDATx^",
        "aQJiR",
        "CoCreateInstance",
        "595D5",
        "SetTimer",
        "rQ|+a",
        "?C?y?",
        "8#9S9}9",
        "SXNET_add_id_ulong",
        "MSIPATCHREMOVE",
        ";#;-;2;?;I;S;_;",
        "B_b!Zq",
        "2,!>C",
        "CRolloverFileInZip::Open:  zipOpen failed",
        "8V9h9",
        "y:G#=",
        "+/ic2h{",
        ". G\\ ",
        "n#>MV1",
        "\"2GB~T$@",
        "UWSSS",
        ",LT: wD",
        ":@;j;y;",
        "K24y|",
        "z)JjO",
        "eCdC(",
        "^Tl+Q",
        "^XtOwa",
        "3Z\":0]",
        "bf-ofb",
        "Copying new files and updating system (0 of 6 tasks done)",
        ";$;,;<;D;L;T;\\;d;t;",
        "2$2,2D2L2d2l2",
        "Kaspersky Anti-Virus 2009 8.0.0.454",
        "zFer2",
        "p1t1x1|1",
        "DosDeviceC=%s",
        "'aUX#Q",
        "35#iw",
        "]Gfi$",
        "PjkhX",
        ",v4RD",
        "mSjA[jZ^+",
        "?+?N?g?",
        "Couldn't open file %s",
        "G(;_P",
        "D$8;L$L",
        ">]cZf",
        ".egoP",
        "\"o.Z(",
        "F((#c",
        "0'0=0T0",
        "P1Ilb",
        "+X\\uf[1",
        "u jPh ",
        "9t$lu",
        "R1_DJ+",
        "x<hA#",
        ")%.tj",
        "ep3*9",
        "9f:x:",
        ".PA_W",
        "Finished successfully. Reboot required",
        "lDd92",
        "UXFbl",
        "z#;)7",
        "#'9I20#;p",
        "JF%N%",
        "u(rBj+,",
        "J/hTc",
        "=PYAs",
        "D3e|;",
        "cP= ~",
        "9b%d&}N",
        "UE>]o:",
        "65UW@",
        "L6j5&",
        "CLIENTSTARTUP",
        "l'n/Cg",
        "9I:V:",
        ">)>I>i>",
        "0;hva",
        "UJcLXA",
        "my^kt",
        "b>c=6",
        "VW'Qo>gw",
        "]:G76",
        "v!n>Q",
        "6!Y*R-",
        "U&u Ts8",
        "V=*)?",
        "j\".:o",
        "1:2z2",
        "1[w4<V",
        ",Z\"![9",
        ":)wjc",
        "9VikH",
        ")68=A",
        "UVO5rT",
        "RbO[/=t",
        "UserLanguageID",
        "Pb@tN",
        "20Fyu|",
        "$X635",
        "i~wKVA\\",
        "jnd0 ",
        ";E;Q;V;z;",
        "!:9H3Q%.",
        "mf%Lf",
        "?_&]j",
        "D|EH7",
        "uazLT",
        "^l>ob",
        "S/Zds",
        "O04x0",
        "@}(v8t",
        "sR.6r",
        "`\"\\Dr",
        "6GTnWr",
        "rc4(8x,mmx)",
        "\\Check Point\\Help",
        "6-6<6O6[6k6|6",
        "k@w#!",
        "BhT46",
        "ucrtbase.dll",
        "f*o7eM<",
        ".6$:g",
        ";$;,;4;<;D;H;L;P;T;\\;p;x;",
        "FdbsO`",
        "dKijE",
        "o}nD?",
        "\\$$VPS",
        "_oy&9\"",
        "5rrKY0",
        "$Qa`@r?",
        "jrtfe",
        "_>OQB",
        "d4JNv",
        ">6?H?p?",
        ">*|LB4T",
        " 0xa2",
        "AEsct",
        "'?r5)",
        "eZhB>\"",
        "fu3DHB",
        "jQql,",
        "|-5R~",
        "ECKEY_PRIV_ENCODE",
        "L$\\3L$H",
        "n2e$hpV",
        "string",
        "4Jn.G",
        "&~nt/l",
        "2(.(0",
        "HOrRdP_=",
        "@t(dy",
        "XXXXXX!~",
        "-UW8}",
        ";0}S9",
        "NG.G@",
        "service was signaled to stop successfully",
        " Rj1Uh",
        "id-GostR3410-94DH",
        "tfb*i",
        "252N2g2",
        "C%eS}",
        "pt-BR",
        ")HMR%",
        "+dF`2",
        "u9f9X",
        "vS.$y",
        "c&&IX",
        "|9h(>",
        "m2@gVL",
        "5<5T5",
        "+8Nx6",
        "ASN1_ENUMERATED_to_BN",
        "wcalog.cpp",
        "?CiBO",
        "5,505D5L5P5T5X5\\5`5d5h5l5",
        "[q*'m",
        "id-cct-crs",
        "$6o:@",
        "/^RIX",
        "[VSMON_SERVICE] Service manager access error = %d",
        "#MvP;m",
        ":8;L;",
        "Wp*`a",
        "BNRAND",
        "a46j<",
        "-F:l_",
        "qYV.n",
        "gE/xjH",
        "?dC_^'",
        "Gi:,1",
        "3,343@3d3l3t3|3",
        "~Q`Li&h{(i",
        ">&zIB@",
        "Questionable extension field!",
        " 0x27",
        "\\6~Kg",
        "AECDH-RC4-SHA",
        "\"ojAg",
        "I^79k",
        "380118235959Z0}1",
        "Oio&j4",
        "U8I3k",
        "~@-@[",
        "!>h7u@",
        "<*=T=r=",
        "5RTjO",
        ">(?-?u?",
        "*5.52565:5>5,4",
        "X509_NAME_ENTRY_create_by_txt",
        "Ls*Tb<",
        "-}<7z",
        "v#p;w",
        ".|t)f\\",
        "'speCcF`D3",
        "IS~r1N",
        "BCt_XR",
        "'mVf+p",
        "=MpPj",
        "(#GFx\"H",
        ">9D$,",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx540\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid11555386 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 10.4\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "W6*.X",
        "l2E\"!",
        "K\"=!%v",
        "zkn-V",
        "~tbB\"",
        "G@Rvi(",
        "~c9}m",
        "T|-=2",
        ",:cYD(",
        "zS )\"",
        "ixA_CKS",
        "2 2$2(2,242H2L2`2",
        "R%WT{+)",
        "SO0bA",
        "AA)'/",
        "tls peer did not respond with certificate list",
        "+b.RRg",
        " z(PS#9!?",
        "`\"6Zy",
        "%@z_p",
        "-9xU\\",
        "K|^sD",
        "#xl's",
        "*C-R>7",
        "rc2-ofb",
        "oy)a]EC",
        "b&L+:y",
        "0$000P0X0d0",
        "DES-CFB",
        "!fo0Pzh",
        "S<Lb^P?",
        "Can't resolve proxy host %s:%hu",
        "MHriw",
        "I2$CG",
        "evp_pkey",
        "Wbs$h",
        "jAXt(",
        "/JFk.",
        "E&8t<",
        "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF@F",
        "SHORT ",
        "(N{jQ",
        "bp]H)",
        "s}X@?",
        "mstring not universal",
        "jdnb!",
        "8,8@8",
        "6-656E6s6",
        "FWFreshBefore",
        "8YdxZ",
        "\\KUz8",
        "(QN(lz",
        "Hr;<=",
        "t;\\!<",
        "SWAPGS",
        "|MwZU",
        "u\"ruZ",
        "|oZVZ",
        ">!>.>Z>d>",
        "bstr_wst failed",
        "_fq0F",
        "1`2k2",
        "-2-R-",
        "h%W^<w",
        "d!t\\I",
        "Repository",
        "w*VxI",
        ",w)VR",
        "]3(y`t",
        "<.BV\"",
        "&ilr5e",
        "q=itG[;",
        "\\par }}{\\footerf \\ltrpar \\pard\\plain \\ltrpar\\s47\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "$^&M9",
        "R9=tg",
        "FAK6d",
        "h^vWS",
        "|.5r}``",
        "4Yg#{J",
        "aL~Vf",
        "6g^g7",
        "extension exists",
        "aj##v)",
        "},,XsR",
        "yeFt6`",
        ".l9?Z",
        "aycPcHS",
        "K,WBISwF\\",
        "8@M<2\\",
        "BntLQR",
        "mbt<.",
        "pJ~?Z'",
        "-IOev",
        "t$ WRS",
        "<1<?<K<",
        "D$dPU",
        "rw,6-",
        "=%=,=",
        "d/|Yo",
        "_*]c/;",
        "9D$X~",
        "9:9]9",
        "z1c29",
        "Zuq`J",
        "V(S-cO",
        "5\"5&5*5.525/8",
        "@|'PN",
        "c]nqsY",
        "\"d4z2QV",
        "/>G9C|I",
        "979F9Y9h9{9",
        "FevCOH",
        "aes-128-cfb",
        "CMS_EncapsulatedContentInfo",
        "oqcF_",
        "UL'f1e",
        "x[=g_",
        "=/=H=a=z=",
        "Z44=Gi",
        "Du&NK",
        ";/;<;o;s;w;{;",
        "serviceLocator",
        "na+vH",
        "Hb#zH",
        "bRQ.[I",
        "DS_InstallFACDriver started.",
        "< t3<",
        "2::Kn",
        ">0?\\?",
        "ohfF~",
        "G=9hr",
        "GYu;O",
        ")|W>~",
        "W8^.uc",
        "v8l9l",
        "uUncd",
        "r\"#'hbt",
        "xpxxxx",
        "^FngJ",
        "c}^\\a",
        "s/gH:",
        "24#Il",
        "(:pne",
        "mZO_'",
        "yNyRzVK",
        "$,xIH",
        "8cv1RH",
        "d=f!Q'#Kf!|",
        "E$2v7",
        "WV<Kt",
        "YP2R)J",
        "<5<]<e<u<",
        "%e,Jt",
        "GU$%a",
        "oSWoO",
        "content not found",
        "@T~?y",
        "<ulNm",
        "`h`hhh",
        "PQ;28",
        "D$ SW",
        "ElgUk",
        "|^2v:",
        "1)252C2V2}2",
        "OSFWCtrl",
        "jU{Y+",
        "&:*U~",
        "q43$ ",
        "2U)(Q_H'",
        "ec group new by name failure",
        "TI!{i",
        "R1`j[",
        "RBM0F",
        "YY^_]",
        "JNN=z",
        "0Wd?u",
        "=G'ix",
        "#4KC<",
        "_I'Zc$h",
        "*tsnN",
        "ProcessPemFile Found pem file in TVDIR",
        ":!:2:=:l:v:",
        "Search for and remove and consumer products to be replaced.",
        "yUCW\"S",
        "-s=Za",
        "K# Hz",
        "7*7a7",
        "mt}&#",
        "9\\xg]?",
        "camellia-192-cfb1",
        "PUNPCKHBW",
        "#'$%h",
        "bbbbbbbbbbbb",
        ";$;6;I;",
        "Z*(3z",
        "(z_g-Q$",
        "3Tp/Xf",
        "Z|+'Y",
        "2r2222s2",
        "Dgji1\"",
        "r9D37",
        "zOu2G",
        "ECDSA_METHOD_new",
        "f{:D3",
        ">F>h>_?",
        "<Hri>C\\",
        "Some exception caught",
        "6M7Z7",
        "]{$:LG",
        "L$ 3L$X",
        "50\\0p0",
        "E9?Q^A",
        "wp.l\"",
        " z(3K",
        "LJhJxJ",
        "8-;}p",
        ",xy\\!",
        "5!5A5a5",
        "wCBM^",
        "9u[[z",
        "5[9[;[=[?[A[C[",
        "cs$#<",
        "0XurL",
        ";]0`IL",
        "!t B%",
        "_logb",
        ">`fkS",
        "x'yk}/",
        "4&434:4@4J4T4^4h4r4",
        "0S^rMqQ",
        "hEP0<^Ac",
        "2'S,a",
        "A}i&h",
        "X[3dH)^i^CKW",
        "fj0Pc",
        "SEC_E_UNSUPPORTED_PREAUTH",
        "#,fcX+Hq",
        "&&)/-",
        "}=X%.ai",
        ".`?BL",
        ") and all accompanying manuals and other documentation, if available, and together with all enhancements, upgrades, and extensions thereto that may be provided by Check Point to You from time to time.",
        "\"%s\" /e \"%sCommon\"",
        "3@4\\4x4",
        "wTwdx",
        "=%=+=",
        "server write key",
        "d2i_PrivateKey",
        "bg54v",
        "n4cOuL",
        "xg%\\x",
        "7Z3|j",
        ".\\crypto\\x509\\x509_vpm.c",
        "899)9P9=8$8",
        "kzokG{\\",
        "SnqK@",
        "fRTq[",
        "L07dC",
        ":c ~[3",
        "43CAC",
        "FcaciLm",
        "bqlF@",
        "I]g3F",
        "\\C)8R",
        "C=K=R=s?",
        "ssl23_read",
        "\"*>xj",
        ".\\crypto\\ui\\ui_openssl.c",
        "|DjB*O",
        "subjectKeyIdentifier",
        "n|-wG",
        "bbxs/",
        "wRjo(",
        "?A?c?l?",
        "e?IM\"",
        "7Q8e8",
        "?27ZJ",
        "2K5^5",
        ";C;\\;",
        "<98=~",
        ".F@\\e",
        " H;zw{",
        "+0QXf",
        "7,gm;",
        "L$H3L$,3L$43L$",
        "zCh&j",
        "D9D\",C^",
        "GetEnvironmentVariableA",
        "j9L[cY",
        "[9'^j",
        "B<wk!",
        ")4s3z",
        "StartServiceA",
        ">!>&>",
        "u?RPU",
        "XmlFile.cpp",
        "s|w&fC",
        "Fpy-':7",
        "|E-N_",
        ">\"}lA",
        "U=%=X",
        ".92+Q",
        "I[?[g",
        "I_@X0",
        "SchedulerKind",
        "xI+V5UW",
        "39>SI",
        "r$C6?mEmw",
        "sha512",
        "keyIdentifier",
        "#.< #",
        "7eC@s3",
        "VhXXG",
        "1.191B1M1U1x1",
        "!H3I5MU",
        "WIX_DWM_COMPOSITION_ENABLED",
        "vIj^6",
        "NA]#-",
        "&8+x8",
        "6mINB",
        "CHWoV",
        "F{\"'X",
        "4>5G5|5",
        "%s;%s",
        "0y2K3",
        "|?zDD",
        ";7<F<",
        ".z6BrK",
        "{ ! kDw",
        "(Z1i~:S",
        "-e^SW",
        "~(XhUG",
        "{OUAH%",
        "UIDVALIDITY",
        "cJ\"&X",
        "*MsSs",
        "Patching is mandatory. Terminating installation.",
        "WM\"u\"U\"m&}",
        "{@\").",
        "{O]Qd",
        "1 1,1L1X1x1",
        "W)}J6",
        "x&P/W`mi",
        "Q%L;9",
        "group=",
        "d~.8V_",
        "0+1T1j1v1",
        "file %s extracted to temp directory",
        "N ['R;",
        "7?=nM",
        "Fa]=7p<f",
        "uVRQh",
        "6R/%]",
        ")ZgjPv",
        "iD)]e",
        "PreInstallCheck:  Check for support OS versions.",
        ">oX\\s",
        "{{RFXk",
        " fYHV[CE",
        "XH[VTO",
        "$$WgH",
        "!TUxl",
        "z+%Ek+",
        "{={j~",
        "VD!V{h",
        "bad asn1 object header",
        "oOvMi",
        "failed to save shortcut '%ls'",
        "z%5mdd",
        "kw:5%",
        "l$ Uj",
        "\\par \\tab aMZ",
        "2g3v3'464",
        "Microsoft.VC90.CRT.manifest",
        "idea-ofb",
        "xb5mn",
        "failed to write to {} - {}",
        "EC_GROUP_get_cofactor",
        "FRRhj",
        "8 ;&8",
        "#cR^_>",
        "rGf;u",
        "Q*mR\"",
        "Failed in ControlService. Error: %d",
        "REMOVESYMANTEC",
        "CZI[:",
        "w%pU?",
        "Q1L$(",
        ".~'#c",
        "Y+XAp",
        "+a+tsbL",
        "x/+v^",
        "^FO10X",
        "|HnH'",
        " ^jAr",
        "PAg.X",
        "SYSENTER",
        "[UfM^d",
        "Tb>(?",
        "<ipaddress address=\"local\" operation=\"eq\"/>",
        ";!<E<X<",
        "9xHfV",
        ";lT@Qb@?",
        "W5aKl6",
        "op+xC",
        "\">q-}>?",
        "Public-Key",
        "*ZVk;",
        "Digital Signature",
        "d\"O;W",
        "chunk >= 0",
        "dcobject",
        "rDHIr",
        "Y\"&~+",
        "ko-kr",
        "9vq!b",
        "recommended-private-length: %d bits",
        "< =P=",
        "j7s4z",
        "SDL should not be installed",
        "yFj4t",
        "q)dx!",
        "Y=bP]",
        ",Reason=",
        "'jB,?HzQ",
        "@4,V0",
        "@6!y.",
        "l9Wzr",
        "r?}bV",
        "1;2I2Y2",
        "Gfab<h",
        "X6|6qE@",
        "i*y8j",
        "F\"rH_",
        "5Y5`5",
        "jJ\\A~",
        "y6RNq",
        "m\\lrW",
        "_f(#K",
        "failed to allocate target registry string with HKLM root",
        "TG27#",
        "MTB<a",
        "qr9s3n",
        "!:4/=",
        "cI5EO",
        "Failed to get the Attributes field value.",
        "Legal Copyright=(c) 2003-2022 Copyright Check Point Software Technologies Ltd",
        "n3 {5`",
        "C?,}h",
        "K0Z#t",
        "UpdateZoneAlarmXml:  Failed to obtain Upd_MergeConfigurationFiles.",
        "b#<oH",
        "Vjw(Z",
        "Copy_BladeFoundation.dll_2EPAM",
        "P:PXV)",
        "L$$Z%&",
        "fUN(#",
        "lT,mY",
        "<$<4<8<",
        "reuse cipher list not zero",
        "Nz,\".",
        "`832h",
        "Share currently in use",
        "Qpp{&(",
        "1+1q2",
        "+h!xA",
        "Vb6#ny",
        ">*?^?",
        "R $iM",
        "a\\y}y",
        "|(IA=Z",
        "T!E1rEb",
        "=(=4=@=L=X=d=p=|=",
        "ZHt\"D5QE",
        "qA`-7",
        "-tQXrtd",
        "?:?|?",
        "HxE=l",
        "VDg>B",
        "Q*4vQ",
        ":qV2P",
        "_Event",
        "\\U%04lX",
        "673#fV33",
        ";!>&@<}",
        "_b#s;",
        "zys%e",
        "Xo3gl`",
        "`M`MTK",
        "'r9asj9",
        "5UlmQ",
        "4#4*4W4",
        "Zdx44",
        "OBJ_dup",
        "<buhj",
        "ak/OlG",
        "r[(-*(P",
        "4&565w5",
        "<7C;t'",
        "OY:\\l",
        "Z5.4K",
        "Registry error:  Failed to create value.",
        ",|qPz",
        "@p8)T",
        "mq,>2!.",
        "Data Encipherment",
        "x?6i&",
        "Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>",
        "/r]B>",
        "H}xX]",
        "[97xw2",
        "R$qIoq'Z",
        "jCjyj&",
        "missing tmp ecdh key",
        "5\"5(5.5D5K5",
        "t]SUU",
        "-~IS7Z",
        "1Yyw@",
        "G|SyXR",
        ">\">&>*>.>2>6>",
        "hr5{6",
        "3xEyw;i",
        "]@bLS",
        "uC%|X",
        "x^7dGkJ",
        "Uninstalling virtual network adapter",
        "xbiD#",
        "ao\"VE",
        "lIj3@",
        "AES-256-XTS",
        "@xBwd",
        "UpdateVsconfigXML:  UpdateVsconfigXML finished.",
        "*{bCE",
        ".v;!(2q",
        ";1U_4sR?4",
        ":-h}IL",
        "J9*`+",
        "::,Gub;",
        "OlyFw",
        "Jqi}u",
        "t|pzp",
        "uut R",
        ")ff1*",
        "libcurl is now using a weak random seed!",
        "3H4`4",
        "C^T>D",
        "^4_t_tw",
        "o}>C>",
        "rf^%W<",
        "k b`Av",
        "`D]V^8",
        "s:   ",
        "9{dCH1#",
        ";5,$&",
        "Monv1d",
        ")z-R7",
        "\\zonelabs\\ntname32.dll",
        "] \"H@H0",
        "8Kr>r",
        " (Negative)",
        "Server updater ver not detected",
        "7%~5l",
        "2##\"*",
        "Hk(MB",
        "dDiaTWat",
        "V;pdG",
        "GA{x3",
        "Failure sending ABOR command: %s",
        "MOVSX",
        "@7E*X",
        "7&V:G|",
        "Z~J_9",
        "N=ufIy",
        "a!{I_M",
        "GRk5b",
        "Rew=6",
        "7#7)7/747:7@7F7K7P7W7]7b7h7n7t7y7",
        "V4emH",
        "^c-3)7",
        "Gf?b&",
        "4fh1&",
        "B?B=E",
        "bin\\sr_watchdog.exe\"",
        "{\\{Gm",
        "l$$hx",
        "fuqFm-",
        "nB5+&",
        "failed to read from stream",
        "6:6z6",
        "T/c(E9",
        "upeF,b",
        "Aurm#",
        "WD_CheckFolder CP folder protected.",
        "/Tl`JO",
        "(Dmu5",
        "sH5F']",
        "- `lm4",
        "2HtPY",
        "<$<,<4<<<D<L<T<\\<d<l<t<|<",
        "[*>WN",
        "2|fD}|Y3",
        "eJP7o",
        ")#na`",
        "E9rJ-",
        "\"Nk)%Y[",
        "v-?[t",
        ".?AV?$sp_counted_impl_p@Udir_itr_imp@detail@filesystem@boost@@@detail@boost@@",
        ".JDFP",
        "!?c^Y)?",
        "x&<Ah",
        "ON>}=",
        "8%9/9",
        "CrashDumpEnabled",
        "Y\"z_'",
        ",r<Dyh=\"",
        "/_Y`{",
        "Wa(pM",
        "n(iPaC42",
        ")VLZ(",
        "p&8N0",
        ".JQr`",
        "er;s3U",
        "Uf_'\">",
        "d\\Ny1=",
        "_|]{\\z%q",
        "7!8L8",
        "Resource deadlock avoided",
        "TOvVf",
        "sCj\\V",
        "V$D$E",
        "A\"U1Z/",
        "\"cdW]",
        "&9EUq",
        "The Root store has been opened.",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{56D45213-8AD9-46C5-A393-EB21A760DD43}",
        "invalid command",
        "DEF_TIME_CB",
        "|)T+2",
        "pjE2vB3u",
        "jxzKC'",
        "dEP^]W",
        "t{Z5J4",
        "=%=6=T=e=",
        "CURRED BY YOU IN CONNECTION WITH THE BETA TESTING.  YOUR SOLE AND EXCLUSIVE REMEDY SHALL BE TO TERMINATE THE BETA TEST AND THIS LICENSE BY WRITTEN NOTICE TO CHECK POINT.",
        "RSA_EAY_PRIVATE_DECRYPT",
        "5A/\"&$",
        "Nzw{2",
        "R6002",
        "X) ZEi\\",
        "$jaw2J9s",
        "h4u*N",
        "Netscape Cert Type",
        "ASN1_T61STRING",
        "Failed to open view on WixRemoveFolderEx table",
        "0123456789",
        "WIX_ACCOUNT_GUESTS",
        "*bmd6",
        "$#y&K",
        ".?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "#D$ 3",
        "5B6G6Q6V6\\6e6n6u6",
        "87t+2",
        "]#>6J*",
        "\\$tUf",
        "1:1j1",
        "GOST R 3410-2001 Parameter Set Cryptocom",
        "+ +M9",
        "3-3D3c3i3x3",
        "9.-@P",
        "l$l9l$",
        "xcJo=",
        "k|zcC",
        ",dH6X,y",
        "/}N8\\",
        ">uM~@A",
        "4Q5g5",
        "AddDataClientClass",
        "-WQb7",
        "k0i0$",
        "p\\h4ou",
        "3NpD!",
        "dtNd[",
        "3 4&4,42484>4D4J4",
        "p&B>e",
        ";-=/>",
        "w3w}$",
        "EI)'j",
        "6>7x7",
        "RV^'\"7",
        "/6?Zs",
        "n does not equal p q",
        "~R.Wdb2",
        "Xvr3[Z",
        "6#636E6Q6b6",
        "gi&&o\\.^",
        "/eKcpH",
        "^Uj(ff",
        "CMS_ADD1_SIGNINGTIME",
        "re all programs and data }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 in the Hardware Product; ",
        "FtDp#K'J",
        "|K \\G",
        " _(;+",
        "pwC7;",
        "&quot;",
        "0BwHG'",
        "[_<X^",
        "5-'!/",
        "zJ(SS",
        "508v:",
        "Gkfv%b-",
        ")m'wz",
        "6Qo|}`",
        "HPjPW",
        "9 9@9\\9`9",
        "20272I2c2",
        "Tt::-",
        "zT4#v-?",
        "\\drivers\\vsconfig.xml",
        "1|wh*",
        "Cannot APPEND without a mailbox.",
        "ykI\\*Lic",
        "yrk~H",
        "`2`XQ",
        "Can't undo switching to parent directory",
        "5:$^0",
        "<-<;<g<|<",
        "aa:q:",
        "bX[pK",
        "gCe'*Cm-",
        "Jo'Wh",
        "G?#Ak/",
        "SSL23_CLIENT_HELLO",
        "DL_MERGER",
        "invalid pentanomial basis",
        "tBh|E!",
        "Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S",
        "n=FIl",
        "t$,US",
        "F|LP{",
        "+bEns\\U",
        "Z.\\/s",
        "xL/XF3",
        "rsa_pss_saltlen",
        "Y{Uaf",
        "failed to initialize WixCreateInternetShortcuts",
        "1A1n1",
        "(0QA9",
        "o{V&q",
        "SECG/WTLS curve over a 131 bit binary field",
        "~tKN+",
        "?CPSystem@@YAJKPAD0J@Z",
        "Q}[KX",
        "bZaE{",
        "6VUlI",
        "text/html",
        "tf&_f",
        ".+\"VB",
        "FXRSTOR",
        " 0xcc",
        " C5vJ",
        "Ai)6K ",
        "1o0!E",
        "153rE",
        "jOxaH",
        "[s6Pn",
        "x`YsDQ",
        "Can't set %s and current directory.",
        "PKCS#3 DH Private-Key",
        "Bv7Cve#",
        "`%cCSo",
        " 0x73",
        "oQod3",
        "1!1A1Q1a1",
        "\"jA<q2",
        "`nD3x",
        "um|-f",
        "253f3x3",
        "x94h:(",
        "Failed to delete:  %s",
        "_w~<H",
        "+nUsA",
        "NG OUT OF THE SUBJECT MATTER OF THIS AGREEMENT, THE PRODUCT OR ANY SERVICES UNDER ANY CONTRACT, NEGLIGENCE, STRICT LIABILITY OR OTHER THEORY, FOR ANY INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQUENTIAL DAMAGES (INCLUDING LOST PROFITS), OR FOR LOSS OF OR CORRU",
        "UBW:L",
        "2WF3f",
        "%)%AQT7",
        "1>1b1",
        "failed to read name from custom action data",
        "!9Wzh",
        "55XMF",
        "}pVioo",
        "292>2Y2^2y2~2",
        "ec_GF2m_simple_point_set_affine_coordinates",
        "6E6s6",
        "4MXA?",
        "hY@?]L",
        "http://www.symauth.com/cps0(",
        "P_uQ<^g",
        "[)TcfD",
        "<YAMg",
        "]\\*}i",
        "InstHelper is stopping ...",
        "My2q#8(",
        "5xC'{c",
        ".39is",
        "bmK^!",
        "8 8'828>8T8b8",
        "Pk(uh;",
        " \\|tk",
        "c=LV*",
        "5)8TC",
        "O7E5S",
        "6$6,646<6D6L6T6\\6d6l6t6",
        "344S4",
        "e~$s>",
        "\\!ENJ",
        "va+X.hk",
        ",ic6 ",
        "DRuo2",
        "z;+n+",
        "$'{,Q",
        ");!LE",
        "!#+!-",
        "vG4A%",
        "L?:3\\",
        "Authentication failed: %d",
        "=MAE=ZqG",
        "+O=Oq",
        "{!DZ#/b)",
        "0F1z1",
        "su^Q {b",
        "5B5Z5",
        "[)dT!*",
        "<9RF8)",
        "0o2o4o",
        "On?D5YV$",
        "asn1 sig parse error",
        "l1oP`v\"i",
        "q[} G@Q3",
        "?-s~w-",
        ">7?=?N?",
        "AS^J;",
        "8+9:9K9P9W9\\9x9",
        "]9Q gr",
        "8$u)9",
        "RT[|?",
        "VhS]3Z",
        "kPl#I7",
        "R'SgS",
        "IC1oo",
        "{G=XX",
        "-[Np9",
        "949<9D9P9p9x9",
        "5KJly:",
        ":;gH<",
        "`'RGK",
        "%s\\system32\\DisconnectedPolicy.xml",
        "xAa00",
        "5{IvP",
        "ya#O#}e",
        "Uju\"\\",
        "5{/<:",
        "6k4h.\\",
        "nXtSH",
        ". [h.",
        "_ZWB(s@",
        "%lyTUd",
        "c]uEu",
        "c07@%",
        "UnZx\"Wh",
        "p]NHi",
        "3L$X#L$h3H",
        "v5`o4f$",
        "Winsock version not supported",
        "f0x061E1~1",
        "7zm3Y",
        "t#cz&c",
        "{x@GS",
        "wXu1tb",
        "lJ(avJed",
        "C~A6.",
        "&lc\\Tt",
        "failed to get Value for XmlConfig: %ls",
        "<(<L<\\<",
        "fpVc+",
        "|/T]*lI",
        "D/ODl",
        "8uhCf",
        "iV<iO4d",
        "+1nl^",
        "SetEventGroupInVSConfig succeeded.",
        "Y[KY>",
        ",5^1YH",
        "JaKKY+t",
        " a particular event.A standard conditional statement that specifies under which conditions an event should be triggered.OrderingAn integer used to order several events tied to the same control. Can be left blank.CreateFolderPrimary key, could be foreign key into the Directory table.Component_Foreign key into the Component table.CustomActionPrimary key, name of action, normally appears in sequence table unless private use.The numeric custom action type, consisting of source location, code type, entry, option flags.SourceCustomSourceThe table reference of the source of the code.TargetExcecution parameter, depends on the type of custom actionExtendedTypeA numeric custom action type that extends code type or option flags of the Type column.Name of the dialog.HCenteringHorizontal position of the dialog on a 0-100 scale. 0 means left end, 100 means right end of the screen, 50 center.VCenteringVertical position of the dialog on a 0-100 scale. 0 means top end, 100 means bottom end of the screen, 50 center.Width of the bounding rectangle of the dialog.Height of the bounding rectangle of the dialog.A 32-bit word that specifies the attribute flags to be applied to this dialog.TitleA text string specifying the title to be displayed in the title bar of the dialog's window.Control_FirstDefines the control that has the focus when the dialog is created.Control_DefaultDefines the default control. Hitting return is equivalent to pushing this button.Control_CancelDefines the cancel control. Hitting escape or clicking on the close icon on the dialog is equivalent to pushing this button.Unique identifier for directory entry, primary key. If a property by this name is defined, it contains the full path to the directory.Directory_ParentReference to the entry in this table specifying the default parent directory. A record parented to itself or with a Null parent represents a root of the install tree.DefaultDirThe default sub-path under parent's path.ErrorInteger error number, obtained from header file IError(...) macros.MessageError formatting template, obtained from user ed. or localizers.EventMappingA foreign key to the Dialog table, name of the Dialog.An identifier that specifies the type of the event that the control subscribes to.AttributeThe name of the control attribute, that is set when this event is received.FeaturePrimary key used to identify a particular feature record.Feature_ParentOptional key of a parent record in the same table. If the parent is not selected, then the record will not be installed. Null indicates a root item.Short text identifying a visible feature item.Longer descriptive text describing a visible feature item.DisplayNumeric sort order, used to force a specific display ordering.LevelThe install level at which record will be initially selected. An install level of 0 will disable an item and prevent its display.UpperCaseThe name of the Directory that can be configured by the UI. A non-null value will enable the browse button.0;1;2;4;5;6;8;9;10;16;17;18;20;21;22;24;25;26;32;33;34;36;37;38;48;49;50;52;53;54Feature attributesFeatureComponentsFeature_Foreign key into Feature table.Foreign key into Component table.FilePrimary key, non-localized token, must match identifier in cabinet.  For uncompressed files, this field is ignored.Foreign key referencing Component that controls the file.FileNameFilenameFile name used for installation, may be localized.  This may contain a \"short name|long name\" pair.FileSizeSize of file in bytes (long integer).VersionVersion string for versioned files;  Blank for unversioned files.LanguageList of decimal language Ids, comma-separated if more than one.Integer containing bit flags representing file attributes (with the decimal value of each bit position in parentheses)Sequence with respect to the media images; order must track cabinet order.IconPrimary key. Name of the icon file.Binary stream. The binary icon data in PE (.DLL or .EXE) or icon (.ICO) format.InstallExecuteSequenceInstallUISequenceListBoxA named property to be tied to this item. All the items tied to the same property become part of the same listbox.OrderA positive integer used to determine the ordering of the items within one list..The integers do not have to be consecutive.The value string associated with this item. Selecting the line will set the associated property to this value.The visible text to be assigned to the item. Optional. If this entry or the entire column is missing, the text is the same as the value.MediaDiskIdPrimary key, integer to determine sort order for table.LastSequenceFile sequence number for the last file for this media.DiskPromptDisk name: the visible text actually printed on the disk.  This will be used to prompt the user when this disk needs to be inserted.CabinetIf some or all of the files stored on the media are compressed in a cabinet, the name of that cabinet.VolumeLabelThe label attributed to the volume.The property defining the location of the cabinet file.MsiFileHashFile_Primary key, foreign key into File table referencing file with this hashOptionsVarious options and attributes for this hash.HashPart1HashPart2HashPart3HashPart4Name of property, uppercase if settable by launcher or loader.String value for property.  Never null or empty.RadioButtonA named property to be tied to this radio button. All the buttons tied to the same property become part of the same group.The value string associated with this button. Selecting the button will set the associated property to this value.The horizontal coordinate of the upper left corner of the bounding rectangle of the radio button.The vertical coordinate of the upper left corner of the bounding rectangle of the radio button.The width of the button.The height of the button.The visible title to be assigned to the radio button.The help strings used with the button. The text is optional.RegistryPrimary key, non-localized token.RootThe predefined root key for the registry value, one of rrkEnum.KeyRegPathThe key for the registry value.The registry value name.The registry value.Foreign key into the Component table referencing component that controls the installing of the registry value.RegLocatorThe table key. The Signature_ represents a unique file signature and is also the foreign key in the Signature table. If the type is 0, the registry values refers a directory, and _Signature is not a foreign key.An integer value that determines if the registry value is a filename or a directory location or to be used as is w/o interpretation.RemoveFileFileKeyPrimary key used to identify a particular file entryForeign key referencing Component that controls the file to be removed.WildCardFilenameName of the file to be removed.DirPropertyName of a property whose value is assumed to resolve to the full pathname to the folder of the file to be removed.InstallMode1;2;3Installation option, one of iimEnum.ShortcutForeign key into the Directory table denoting the directory where the shortcut file is created.The name of the shortcut to be created.Foreign key into the Component table denoting the component whose selection gates the the shortcut creation/deletion.The shortcut target. This is usually a property that is expanded to a file or a folder that the shortcut points to.ArgumentsThe command-line arguments for the shortcut.The description for the shortcut.HotkeyThe hotkey for the shortcut. It has the virtual-key code for the key in the low-order byte, and the modifier flags in the high-order byte. Icon_Foreign key into the File table denoting the external icon file for the shortcut.IconIndexThe icon index for the shortcut.ShowCmd1;3;7The show command for the application window.The following values may be used.WkDirName of property defining location of working directory.DisplayResourceDLLThe Formatted string providing the full path to the language neutral file containing the MUI Manifest.DisplayResourceIdThe display name index for the shortcut. This must be a non-negative number.DescriptionResourceDLLDescriptionResourceIdThe description name index for the shortcut. This must be a non-negative number.SignatureThe table key. The Signature represents a unique file signature.The name of the file. This may contain a \"short name|long name\" pair.MinVersionThe minimum version of the file.MaxVersionThe maximum version of the file.MinSizeThe minimum size of the file.MaxSizeThe maximum size of the file. MinDateThe minimum creation date of the file.MaxDateThe maximum creation date of the file.LanguagesThe languages supported by the file.TextStyleName of the style. The primary key of this table. This name is embedded in the texts to indicate a style change.FaceNameA string indicating the name of the font used. Required. The string must be at most 31 characters long.SizeThe size of the font used. This size is given in our units (1/12 of the system font height). Assuming that the system font is set to 12 point size, this is equivalent to the point size.ColorA long integer indicating the color of the string in the RGB format (Red, Green, Blue each 0-255, RGB = R + 256*G + 256^2*B).StyleBitsA combination of style bits.UpgradeUpgradeCodeThe UpgradeCode GUID belonging to the products in this set.VersionMinThe minimum ProductVersion of the products in this set.  The set may or may not include products with this particular version.VersionMaxThe maximum ProductVersion of the products in this set.  The set may or may not include products with this particular version.A comma-separated list of languages for either products in this set or products not in this set.The attributes of this product set.RemoveThe list of features to remove when uninstalling a product from this set.  The default is \"ALL\".ActionPropertyThe property to set when a product in this set is found.WixFirewallExceptionThe primary key, a non-localized token.Localizable display name.RemoteAddressesRemote address to accept incoming connections from.PortPort number.ProtocolIntegerProtocol (6=TCP; 17=UDP).ProgramException for a program (formatted path name).Vital=1ProfileProfile (1=domain; 2=private; 4=public; 2147483647=all).Foreign key into the Component table referencing component that controls the firewall configuration.Description displayed in Windows Firewall manager for this firewall rule.WixSchedFirewallExceptionsInstallConfiguring Windows FirewallWixSchedFirewallExceptionsUninstallWixRollbackFirewallExceptionsInstallRolling back Windows Firewall configurationWixExecFirewallExceptionsInstallInstalling Windows Firewall configurationWixRollbackFirewallExceptionsUninstallWixExecFirewallExceptionsUninstallUninstalling Windows Firewall configurationCostInitializeFileCostCostFinalizeInstallValidateInstallInitializeInstallAdminPackageInstallFilesInstallFinalizeSetupCompleteErrorSetupInterruptedSetupCompleteSuccessExecuteActionCreateShortcutsPublishFeaturesPublishProductIS_ATMis_atm_regsearchINSTALLDIRCurrentDirSearchinstaller_left.bmpinstaller_top.bmpexclamation.icosetup.icodestFolder.icoup.pngnewFolder.pngrepair.icoremove.icoCPINSTADDINT_Trac.configEPC_Lib.dllWixFirewallCAeps_about.png{456C60F2-F695-49FB-A03D-8FCE17382A15}EndpointSecurityeps_ConnLogo.png{67CF59BB-1AA0-4C63-8CD9-D52E6C4BDDEF}eps_CP_Left.png{286CBE13-F122-4056-B80B-13AA385DDB3D}eps_endpointBanner.png{1C77C012-DE0E-4E32-A4F3-E8CDE3AC06AD}eps_endpointBannerBig.png{918EDB4D-86B5-4B2F-ADF1-CE29CB733DDE}eps_VPNClient.chm{D5E20F67-9C80-48F5-8A39-10C1647621F1}mob_about.png{D6EC0B50-3198-4EDF-A49C-7B8067D1AFC4}Mobilemob_ConnLogo.png{5F7B7210-0F45-43BF-A053-BC36F61DFFEE}mob_CP_Left.png{5DF0A205-A3F6-4CEB-8EBB-BC6E5C1180EB}mob_endpointBanner.png{BCB6744A-4DE7-4804-A23D-37B8E6A189B5}mob_endpointBannerBig.png{8F3C465B-E7A1-43C3-B373-7EFA1F5C6C23}mob_VPNClient.chm{B241CEFE-C9CB-4DA3-BF02-9EDE6E368611}sr_about.png{15F15D5C-4AB0-4D72-A527-2F5698208332}SecuRemotesr_ConnLogo.png{BDE0870C-9F58-44DD-A994-BE6CC3DC0ED9}sr_CP_Left.png{0D487436-F76B-4185-B34E-41C5F7BACDEB}sr_endpointBanner.png{EEF21CA8-CDB0-4C5C-B2F6-ADC3A538B1D1}sr_endpointBannerBig.png{D2C91F56-EC95-4E1D-95C6-7CB2D4529555}sr_VPNClient.chm{31A214B7-CF99-4DF5-99DC-4F8BB3258725}update_site.gif{DF8AEC25-56AC-46CF-8F4B-B81C796C9AD2}resTracSiteUpdateSuccess.wav{7A3D669A-5217-41B6-A2D4-4E05499BC981}Apollo.png{475790D1-B2E1-402C-9222-EF185267917C}certificate.png{04DD06A9-1C45-4220-AF9B-D7EDD08A19E8}connected.png{C7DE4B1D-04D7-4585-810A-53F6B8C67D4D}connecting.gif{F8DAC0F7-E583-4CA9-B7FC-D04AD348CD05}cp_middle.png{1F05992E-5170-4465-8767-CF63044E292A}cp_right.png{E20AEED6-2DD6-480A-8D35-E7D18A9BBD39}disconnected.png{3C3B6DCF-4231-4FA7-8143-B600238D07FE}encryption.gif{12DC2AB6-802F-43A7-99C9-45D84F068AF9}endpointConnected.png{F11D5599-6E61-41BA-9746-21C179B5CDC8}endpointDisconnected.png{43775B88-E76F-4AAA-BEC5-A239F6BD84C5}EnterpriseChecks_Disabled.bmp{3A2ED154-28E2-4F4D-B09A-02B9268385A5}EnterpriseChecks_Error.bmp{919DEF41-7A3B-4949-9DDD-5BCBC3ED87A9}EnterpriseChecks_OK.bmp{0E3ABA29-0581-4648-85D3-03B4B2C45449}EnterpriseChecks_Warning.bmp{70AA9FDA-8A67-4F4C-8EB1-11F5D25FB948}error.png{1E940F47-8643-4BB3-8573-0D40EDB5C9CA}error_connection.png{B5D52D3D-E776-4E8E-A287-5E70E06E898E}error_connection_hc.png{1C5E7B70-475D-483C-8EDB-388BF56FCF4C}erroricon.png{9B87FFE0-25A9-4412-A9DD-722B2402A954}finish.png{452D017A-42EF-4B2A-9E2A-5EEB0E44D432}globe.png{EDB5C4FD-3119-4C0C-BA0F-E803A2082E42}happy.png{B7594EBE-47E9-4C6C-BC9C-6672A7475D7B}header.png{1D3C5E6E-B522-4991-827F-7C65E2D76092}help.bmp{486172A2-402F-4E4D-B8B7-4F14E361AF98}info.png{08F45B39-4850-4E30-8B8E-775B72A5939C}KeyFob.png{39CFF4AB-AB5B-4C5B-9FAA-029799DA2589}logs.png{96C711A2-613F-401A-BCCA-E9448A4C1630}ModuleBar.png{F6059DBF-568C-40F7-B401-7BB307FFB7ED}ModuleBarHighlighted.png{BEF51965-9869-476D-9598-8DD09A53B874}Modules_Compliance.png{549727A7-276C-4C4B-9219-4A1EA264F9DA}Modules_FW.png{9CA354FE-5597-4F70-8A69-5801CBDC7C2C}Modules_VPN.png{D56BBC43-AF85-4701-B251-4DCD0AA98944}newlogo.png{B9356AFC-3AA3-4FBD-9490-65E35604D20C}PinPad.png{BC66E074-A46D-4D65-9534-8B9B57C93C28}progress.gif{5989C267-C7E4-4DC0-A338-E7215D32CE68}progress_hc.gif{B7EB9BAC-98C4-410A-817F-48CA6A73846D}proxy.png{145604A9-505F-4337-B593-0540E4B6AE65}reauthentication.png{E9E3EF39-5441-4FC0-823A-A6E2F655884A}saa.png{188693B2-BD2F-4A32-9EE6-6CB5CCCC81AD}sad.png{4D67EF47-3BE1-47CC-8C6B-7D3147B44589}SCUIAPI.png{CB47284F-3754-499B-9E50-CC388FFE70EB}SCUIAPIConnLogo.png{BDA7D99F-D118-4A6C-8BFE-2A63087DDF91}SCUIAPIEndpointBanner.png{7B1E574E-9147-4AE7-AF08-6744DF24BBF5}SCUIAPIEndpointBannerBig.png{93568D70-513D-46DA-9D03-5FAC4DB34C83}sdl.png{1389CED1-832C-4FAC-95E8-D0B700C7439C}securityAlertIcon.png{745734EC-45AA-4A4D-97A7-C3E3CEDA61B5}securityInfoIcon.png{468A1058-B46B-4566-95A3-328E477D7DC5}sidebarBackground.png{44C16E55-E540-44A8-923C-A2B638FD7920}sidebarButton.png{EF5E8C1D-325A-4AC4-8294-29F6AB7EE78B}sidebarButtonPressed.png{B1676926-8A14-4B8F-AF95-172E3B2966C3}sidebarLinkBackground.png{8EC77353-1CB9-4D88-80B3-2618ABA327B7}site.png{36B167A1-934F-46A5-9BB5-A22349B212FA}soft.png{72A3BAD9-9637-4022-B760-12D8B89691B9}State_Error.png{F4E6AC9D-79AE-4B21-9D92-34F33C24946C}State_InProgress.png{FE0CF863-C6B5-401A-807F-765B39130BC8}State_NotRunning.png{FB5B1A31-7986-4F78-A00F-E7A36CAA261C}State_OK.png{FA59D381-40C1-463F-95DD-C37508D21CBB}State_Warning.png{5047AFE0-E0DB-4B16-9E70-2D0856D6D226}statusBarGreen.png{A35791F9-97AD-4668-B250-736AC9ED4C51}statusBarOrange.png{3F359D9A-F2EE-4525-A2ED-678F76BDDCC3}statusBarRed.png{72F392DC-DF49-4A48-B082-D8436142AFC8}TracConnected.wav{AAAAABBF-E6A3-4BDC-A3AB-8DBAC8C1FF81}TracFailed.wav{09F340AC-DD56-4869-AF5B-AC8B46CD31FF}triangle.png{2DD5A983-B170-4513-AD38-789199B39F8C}legacy_versionFrame.png{B9805A20-9404-4A55-91FF-A1F015C10B06}welcome.png{544357F2-9530-48B2-BF65-A171CFB41D88}AdminMode.bat{BEE8CEB2-D8B0-46E7-996E-D7EF1C82E846}cpmsi_tool.exe{651190A2-CD79-48B3-831D-26213CBD70A2}SCUIAPI.dll{F7509DAB-80F2-4A3E-9071-E862BB5554B0}TrGUI.exe{CA6BDB3D-A061-4749-BAAD-74268AEA7641}cptmis.dll{DBAEAE7F-9BC7-49A0-AE6A-DE63A29DA693}cptmsender.dll{04FB94ED-AADC-4FB0-B4D2-F0A3E4D67B85}reg_DisableTelemetry{C272C3B6-1635-49CD-96FE-C6F14107E387}regF18E8C69B2A6B3F16072868A4337B345reg_SystemInforeg9DD907EE637589BEBBEECA56EB4DDDF7reg_telemetryEnabledregEEACEC902D5D83890D56B4E18E8BCF81reg_runkey{52B80BAF-6B5E-403F-A94B-E360D4B9D841}regE9F4E4721FCD5ABB7B793A9AB8E80655reg_isATM{E4F35F88-A74D-43FB-9305-A3BAB4DF8934}regEB8277BCD3545486BE789B4E8303ADA0CpvpnURLProtocol{FFAC918A-3C39-4540-B794-0E976EB5D520}ShellOpen{2C39B14E-9207-47E5-8BB6-EC635053CE1F}ShellOpenCommand{63BCAA62-C677-415C-A584-C857272557CF}epcginashim.dll{651C9195-9257-4EFF-9E4B-7533A16B0AE5}System32NOT VersionNT64epcginashim64.dll{5421FDBA-5175-4B0F-87F2-78B3B14FCECA}VersionNT64CPEPC_PLAP.dll{6776203D-3B2B-4C1E-B51E-3CEF8359CE43}cpepc_plap64.dll{FE322C9C-43FE-4430-B95B-F19EA14F84A4}CreateEventsFolderCommonInstallWelcomeDlgNextPushButtonCancelBackTextLine1{&WixUI_Font_Bigger_Bold}Welcome to Check Point VPN Installation WizardTextLine2{&WixUI_Font_Bigger}Installation Wizard will install [ProductName] on your computer. To continue, click Next.DlgLineLineImageBitmapUninstallWelcomeDlg{&WixUI_Font_Bigger_Bold}Welcome to Check Point VPN Uninstallation Wizard{&WixUI_Font_Bigger}Uninstallation Wizard will uninstall [ProductName] from your computer. To continue, click Next.RemoveSubTypeDlgRadioButtonGroup2RadioButtonGroupREMOVE_SUB_TYPESDlgTitle{&WixUI_Font_Normal_Bold}Program UninstallerDlgDescRemove [ProductName] from your computer.BannerBannerLineClientSubTypeDlgRadioButtonGroup1_ClientSubTypeChoose a product to install{&WixUI_Font_Normal_Bold}Client ProductsText1NewProperty1Enterprise Grade Remote Access Client, including basic Endpoint Security Features (Recommended for SecureClient replacement).Text2NewProperty2Enterprise Grade Remote Access Client.Text3NewProperty3Basic Remote Access Client.LicenseAgreementAgreeAgreeToLicenseInstallMemoPlease read the following license agreement carefully.{&WixUI_Font_Normal_Bold}License AgreementScrollableText{\\rtf1\\adeflang1037\\ansi\\ansicpg1252\\uc1\\adeff0\\deff0\\stshfdbch0\\stshfloch0\\stshfhich0\\stshfbi0\\deflang1033\\deflangfe1033\\themelang1033\\themelangfe0\\themelangcs1037{\\fonttbl{\\f0\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}{\\f1\\fbidi \\fswiss\\fcharset0\\fprq2{\\*\\panose 020b0604020202020204}Arial;}",
        "L$(UWQh",
        ":3?,[",
        "uFlg|",
        "YEI%`pb",
        "3r)D[",
        "\\par }}{\\headerr \\ltrpar \\pard\\plain \\ltrpar\\s45\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "VHf.*",
        "kKj5%",
        "EXAMINE",
        "`,\\Ws",
        "z83nD",
        "39KZ;",
        "7Ghud&",
        "q&=`/",
        "@;iVtA",
        "4C8xj",
        "I,Gsb,",
        "!ql^8",
        "Kg}%4",
        "B@O=W",
        "subtreeMaximumQuality",
        "ssl2_accept",
        "L8'KZ",
        "7\"8P8k8",
        "\"`XD>",
        "ApkFT",
        "{XFQC)<",
        "?e|bc",
        "CAQuietExec Failed",
        "sF9siW",
        "}N=T-s",
        "MKBN3I",
        "WIX_DIR_MYPICTURES",
        "%2S#H",
        "i5iEiUiei",
        "jA_f;",
        "zp@KK",
        "P>F1<G",
        "jOa2#",
        "`FgXqD",
        "/USOU",
        "$8<0s",
        "W\"WZW`T",
        "3F4f4F5f6",
        "<1<H<\\<",
        "9S-#*`=7^",
        "6?iGwN<z",
        "BN_mod_exp_mont_word",
        "MaxConcurrency",
        "8 888H8L8\\8`8p8t8x8|8",
        "#pdGd<",
        "aybSr",
        "Zg6^&=",
        "KS`/.",
        "S3`#!",
        "D&Zh=",
        "t$,WP",
        "'O-.b",
        "l]jUl\"y",
        ".?AVsp_counted_base@detail@boost@@",
        "I*ICD",
        "{ja\\=.d",
        "<6?E?",
        "a>-3y",
        "05sZA",
        "smFq\\",
        "6\"dd(",
        "'e94b",
        "1%Pf#",
        "{!{A{y|",
        "|RLIn",
        "]Rc6:",
        "mz1-/%",
        "9N:(;Y<",
        "W(kA]",
        "Wi(rv",
        "fn>av<M",
        "-2?.L,\"",
        "<?^Mn5",
        "l3/zR",
        "d69G6R8",
        "8u8h0",
        "~9bQ^",
        "'_f@?W",
        "\"1X?hL-",
        "`V:Ot",
        "Hf'65j[r",
        "\\PSGControl.exe\" /cpd",
        "d####G'",
        "$p&@7V*",
        "T~xb@",
        ".-BQhk",
        "iostream stream error",
        "GcPOa2",
        "Qh }#",
        "3F3S3",
        "lmsvcr90.cpp",
        "kQVFD",
        "J &j0",
        "}6/i'bx`",
        "EC_POINT_invert",
        "-j+kd",
        "d;<<7M",
        "+',g-g.'/'1'9g",
        "\\i.iNinv",
        "RkL&Q",
        "l=zU!k",
        "snsou",
        "cl7s_'",
        "GetClassInfoA",
        "4 e0?",
        "1Tl^P7n",
        "6m#o|",
        "g6J{hr1w",
        "r-G k",
        ".sdata",
        "5jQIOI",
        "jJ'e<",
        "7`*T@Bg",
        "}k`CS",
        "jfjlj#",
        "3L$H3L$",
        "Gs=1N~?",
        "#m^. [",
        "GR~Gv ",
        "setAttr-IssCap-CVM",
        "Hzy}A\\]",
        "e@oBd3e&zP.",
        "230102152402Z0+",
        "G\"a/l\\",
        "_g-F\"",
        "W8^&u:",
        "C04DDCP",
        "EP_Core_Inst.exe\"",
        "=&=J=~=",
        "3'3r3",
        "? ?,?L?X?x?",
        "CANTGET_NORTEL_KEY",
        "ZkR{k",
        "f+'Yk",
        ".\\crypto\\cms\\cms_enc.c",
        "~N|K;",
        "jT=,i",
        "j^y82",
        "\\f1\\fs20\\insrsid11543880\\charrsid15169477 CCSP/CSP}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9516106 /ACSP}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8463807 \\'94}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "$03UjY",
        "U.; R",
        "P+t0t0/",
        "jejhj",
        "<{=M>",
        "767w7",
        ")5)e)p)|*",
        "n!Law",
        "wrong curve",
        ";%rJ+",
        " IN EXCESS IN THE AGGREGATE OF THE AMOUNT PAID TO CHECK POINT HEREUNDER DURING THE THREE (3) MONTHS PRECEDING THE DATE THE CAUSE OF ACTION AROSE.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10707243 \\tab }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
        ":5<F<[<e<",
        "%3D.a!Lr",
        "]2(ra",
        "Y!)F5",
        "~FxFlF",
        "0&1k1p1t1x1|1",
        "Hf60d8LY",
        "4=z<xP",
        "C4@^9i",
        "owqvwrt",
        "TerminateProcess",
        "f&#p7",
        "8EGX*",
        "2#Xs$v",
        ";$<,<^<f<",
        "#8e#S",
        ".K `^",
        "0q{tE",
        "3T$<3T$L3T$,",
        "WD_StopServiceFromSCM started.",
        "l$TVW",
        "!R\\5J;>7A_X",
        "c1Qb\"",
        "P!yO8",
        "Ln'>n&",
        "ADRQH ",
        "GG:02",
        "lds|h",
        "/F?o0",
        "^z\"~~h",
        "REMOVE_SUB_TYPES",
        "(ge~R",
        "mj>zjZ",
        "LG;2F)X",
        "8=8c8i8",
        "a,NOx",
        "Y@miK",
        "[Rv6.9kE",
        "p]Q<2",
        "Qhh}&",
        "uRpYS",
        "PPc2\\",
        "tYIPM>",
        "?4?@?`?l?t?",
        "REBOOTDELAY",
        "Im7Az",
        "4B4|4",
        "6\"636H6M6",
        "h$<)h",
        "pkZ~S",
        ";DwEwFwGw",
        "Y9ZHO",
        "S:;kD",
        "xB -XH",
        "!6U$d",
        "363J3}3",
        "t2a2R",
        "F+KwJxp",
        "EFRREGDATAPATH",
        "[e!iV",
        "}>o%T?",
        "6[iDI\"",
        "1N\\qE",
        "rMf;M",
        "=A=\\=",
        "RrY|g",
        "/H|k3",
        "SDL_ENABLED",
        ")76?V84",
        "50!I#",
        "0f?f?p,s",
        "Failed to write 'no office mode' to registry",
        "txiVn",
        "=&>J>p>",
        "&$&t&",
        "`%bmR",
        "\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid6823349 \\chftnsep ",
        "kI`T-",
        "q(%<-;",
        "failed to get permission to configure object",
        "tYhjsy=",
        "r[/[\\",
        "lW,+y",
        "jflV;\\",
        "%~\\og^",
        "VSCheckPasswords",
        "<KAVRegProtectionOff>",
        "+\\x5Y",
        "1.161B1a1u1",
        "><?e?z?",
        "EPBRf",
        "2,2O2",
        "%u %s %s %u",
        "~6eqE",
        ";-8Q!",
        "*N>j)",
        "4*qqu3$I",
        "Read %zd bytes of chunk, continue",
        " 0xe7",
        "+/Q4b",
        "SchedulingProtocol",
        "^5<bE1>",
        "lM&9z",
        "rlV3M",
        "lV/gs(R",
        "D$4PSU",
        "F(UWV",
        "Ja0T8",
        "AVA_.",
        "[nF75X^",
        "xO_TP",
        "2/3y4",
        "zE0kD",
        "INT 3",
        "Connection closure while negotiating auth (HTTP 1.0?)",
        "yOT}_",
        "_LbLb",
        "em4h]",
        ")^79n*",
        "G(L\\u",
        "1/1K1g1",
        ";2;e;l;",
        "_proxy",
        "rH<RDH",
        "*)xh!",
        "T-\\&7M",
        "P#!'vPHw",
        "3%4E5",
        "V35IE",
        "SDINSTALLED",
        "t$4SUW",
        "~S2pJ",
        "k<s<y<",
        "u<]VK",
        "zF1w ",
        "MOVMSKPD",
        "i2d_ASN1_SET",
        "MOVNTPD",
        "V\\9;6",
        "a2i_ASN1_ENUMERATED",
        "E$K 9",
        "I**nT{",
        "O{e}Jg",
        "rrh:!",
        "&|Sum",
        "95:\\:",
        "s5Hkw",
        "`|yN ",
        "6#6)6/656:6?6F6L6Q6W6]6c6h6n6t6z6",
        "6a_(K",
        "`OHy&",
        "no content type",
        "u-G^_",
        ">pW4n",
        "<Ev[h",
        "V{UCN",
        "t?bh6",
        "6?tZjv",
        "KSnSuS",
        "gphdR2MN",
        "IXj,PB",
        ";dqA8_",
        "]TN#+A",
        "dpl:h",
        "%80(.a",
        " !\"##%&'",
        ":^4xU",
        "vJ%nr1",
        "484C4P4b4",
        "[VSWriteUnisntallInfo] GetLastError: %d",
        "}b|rM",
        "{>Wp*",
        "ReplaceOrAddAttOrTagIntoVSConfig():3 returned %d",
        "q1y1U",
        "tj[4~K?#$",
        "DDzD#",
        "n&Q.hwb&",
        "!'i9`",
        "FAILED_TV_SHUTDOWN",
        "L~l{y5~",
        "'|9&\")",
        "wrong signature type",
        "!p2?_z",
        "H/HOHoH",
        "distinguishedName",
        "bU0h#",
        "*i`,r",
        " u[j2j",
        "JBrpP",
        "++96f",
        ",%o$<",
        "pDSdpH",
        "'Aoc<U",
        "tOVWj>",
        "hBJNz",
        "sGI?3",
        "+`oJZ",
        "L$<1L$",
        "]9$(%",
        "D$,;D$$",
        "9a6*(MS",
        "rx3?y&",
        "8M3DC",
        "foK|8|s",
        "$7FIW",
        ">1>A>Q>a>",
        "KJNZ{",
        "!}F`-",
        "s.T.>",
        "xjt03",
        "m|]y$d",
        "=~o=!",
        "DH_new_method",
        "l\\Aa_",
        "@06#5",
        "2#3F3z3",
        "E< ]N?",
        "w[^c ",
        ">=imO",
        "4Kh,=i",
        "dy X@",
        "d-PsJ^D",
        "D^n^N^P^",
        "ffVeW",
        "$Z&V^",
        "setct-CapRevReqTBS",
        "ze/d^",
        "L}cct~",
        "N4^][",
        ".Y1@2",
        "<&oxJ",
        "State_Warning.png",
        "JaLyR",
        "n-%,wL",
        "\"uV8@",
        "\\%u8Y`",
        "x0}J4",
        "reason(%lu)",
        "0-0C0i0",
        "&;$h&",
        "3(474{4",
        "IsStandaloneMode: RegQueryValueEx failed: %d - assume this is NOT Standalone mode",
        "R=,8C",
        "G /H4At",
        "-~ZK8",
        "ta&/`=K",
        "VWhhE",
        "|$x3L$ ",
        "]2BED",
        ">AV}iH",
        "\\par }}{\\headerf \\ltrpar \\pard\\plain \\ltrpar\\s45\\ql \\li0\\ri0\\widctlpar\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "sBLTqX",
        "ghM7BO",
        "<$<,<8<X<d<",
        "G=z~1n",
        "UGyGRt~^0y",
        "d+4|x9",
        "D$8UP",
        "BootCount",
        "uNP2(n",
        "ztY,~X",
        "2\\3d3x3",
        "3L$P3L$D3L$4",
        "GL@B#",
        "5+595A5",
        "t?VSP",
        "~\"Bvjl",
        "jZ^XE",
        "/Phw\\",
        "ZoneLabs\\",
        "d]df;",
        "L$DQP",
        "J\\$\\iW",
        "<z({B@Y`",
        "win.nt.xp",
        "enV3u",
        "2e4G5",
        "]Q7I3Z",
        "#I~g&",
        "x7<7/",
        "37TN,",
        "u3!A}Q",
        "CN<hI lN",
        "noconv",
        "leHU!",
        "y>qRu",
        "target.file",
        "3 3&3*303:3V3^3e3k3s3y3",
        "l&0T?S",
        "8gRh]",
        "r@vqY",
        "DH-DSS-AES128-GCM-SHA256",
        "UX*bF",
        "i/^s^",
        "\\Internet Logs\\*.RDB",
        "OBXc^}-",
        " This warranty gives You specific legal rights. You may have other rights that vary from state to state.}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid4410457\\charrsid15169477 ",
        "U#d\"a_",
        "vexw1",
        "b!d7t",
        "u.F/{",
        "N?Jgn",
        "9*eEX",
        "brainpoolP512r1",
        "id-mod-cmp",
        ",-}/0",
        "? ?0?4?8?<?@?D?L?d?t?x?",
        "6VH1n",
        "{8^{B",
        " expressly provided herein, the terms of this Agreement shall survive termination.",
        "<,W}?",
        "<AE2s3",
        "c^<%>8i",
        "6]y;q",
        ")l+9Y",
        "+\"E1z",
        "s7/6=V",
        "xB~lQ",
        "E!A0I",
        "Ta, \"",
        "ero_L",
        "jxjtj",
        "?(?3?M?U?h?",
        "x {8V",
        "<(}Tb",
        "9Yy%dr",
        "2S&X@",
        "#KZKP_",
        "nPDd.",
        "Windows",
        "tO39>",
        " Pt<%J",
        "${_\"oE",
        "zJ--=s",
        "tsAo{rL",
        "AESNI_XTS_CIPHER",
        "N$BP}",
        "bU(tyW",
        "iUjT+",
        "'=3hN",
        "OA.}Y",
        " ,',b",
        "xo#W#j",
        "Y*{`b",
        ">Ku3[pr",
        "{od,Qn",
        "&g+'e",
        "p+*I.",
        "5!{%~W",
        "tI210",
        "lI:Vjycs",
        "FHc\\/",
        "$]v~dH",
        "\"x4gF",
        "R$XW\\",
        "*qFvs",
        "L;3sg",
        "iYV$pIc",
        " 0x24",
        "6\"6.6;6I6P6W6n6t6",
        "q*oLK",
        "CompPrepare",
        "%%Jo..\\r",
        "RC2-64-CBC",
        "@Zzu\"",
        "0 0/0:0?0D0_0n0y0~0",
        "c/t_,^Z",
        "v:p,dS",
        "4vO?%",
        "yV0wmJ",
        "Configuring Antivirus settings (3 of 5 tasks done)",
        "t4<A|)<P",
        "Accept: application/sdp",
        "kqqoKS",
        "iyrMfUi",
        ":V;0=:=i=z=",
        "VL&tK",
        "6+7z8",
        "ma:LA",
        "wU$K!^",
        "Oc YQ`",
        "##gP0=",
        "8Ij4Ly",
        "ZK!\\Sz",
        "Umj+V",
        "\\v(pwqX",
        "[THREAD] Revive spew for AV service threads",
        "Wvx[$",
        ";BZFS)Kx",
        "^?{I`",
        "6f9VX@",
        "%tDiG",
        "@?D?H?L?P?T?X?\\?`?d?h?l?p?t?x?|?",
        "y\\3+|",
        "FD_^[",
        "xx}:4",
        "566D6",
        "$T,bX$%",
        "4o4v4",
        "y6)fU",
        "#h\\i:",
        "=&avod",
        "xb#cv",
        "K-1q1!",
        "9'_}'o",
        "&ZH<U\\",
        "lzW>_",
        "YD^Gp8",
        "D$,t6",
        "1$101X1|1",
        "<C;M}g",
        ".?AUIThreadProxyFactory@details@Concurrency@@",
        "Q8k5^",
        "Yv5Mm",
        "SSL_CONF_cmd",
        "6$7w7",
        "6.u`h]",
        "sqj}:",
        ":1;j<",
        "D$DSUV",
        "1(141@1L1X1d1p1|1",
        "Dq<-r",
        "[VSDATA LOAD] LocalAlloc2 failed: %d",
        "R6017",
        "g Ig1",
        "`y#fC",
        "D$4Ph",
        "DES-OFB",
        "h,Mcc",
        "@r8Be?3",
        "@4eYh",
        "asn1 error",
        " noexcept",
        "I#$3K",
        "X(4ycHJ\\",
        "%.UCk-",
        "8*9[9",
        "_H3V_",
        "4 5,545L5T5`5",
        "6(6H6h6",
        "W;y[6",
        "_jRH[",
        "W|4d,",
        "?6!1C",
        "p@E-D\"k]myY/,",
        "U m -",
        "^ 8bt",
        " %.2x",
        "fCv$+",
        "}9Z:Z",
        "?hgS$",
        "If-Modified-Since: %s",
        "gK'x?",
        "['mX+",
        "4;FLM",
        "( 8PX",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{3943C4CF-AC42-4E00-8824-25159B8478F1}",
        "<]UT O",
        ":`_ww:<",
        "$3OyB@",
        "enc_digest",
        "WD_CheckFolder",
        "3[4g4u4",
        "hy0y'l@",
        ">\\|>Q",
        "^)75T",
        "MqnfN",
        ";?cQh",
        "wh\\S!=",
        "j.7EY",
        "-3Hr!",
        "m[%12",
        ": :D:z;",
        ".&z(Hf",
        "&CZ@w",
        "JuCfVS",
        "ta@@&Q",
        "4e3Yl",
        "tvDebug.log",
        "I?(OL",
        "Q^9y*",
        "i@_>t",
        "-dCDa",
        "PQSVW",
        "V\"f^s",
        "n(Bc4@",
        "(E5='",
        ")V^)H",
        "ffnv\\;S",
        "9=:b:",
        "sw-KE",
        "originatorSignatureValue",
        "6W^u{",
        "63oS*",
        ":C:U:p:",
        "131O1k1",
        "8~:o;",
        "-s.n5ud",
        "KblV\\",
        "6ctp)I|",
        "0~qUz6#",
        "{\\fdbmajor\\f31519\\fbidi \\froman\\fcharset204\\fprq2 Times New Roman Cyr;}{\\fdbmajor\\f31521\\fbidi \\froman\\fcharset161\\fprq2 Times New Roman Greek;}{\\fdbmajor\\f31522\\fbidi \\froman\\fcharset162\\fprq2 Times New Roman Tur;}",
        "E)HT4",
        "b$qJU",
        "#ThSJ",
        "Failed to send SSPI authentication request.",
        "RemoveDeleteFlag for %s service",
        "x(j$Xf9",
        "r|aJk",
        "+rMlc",
        "6~W }",
        " ;k@>",
        "\"fkx.'",
        "IN\\n#K",
        "__#\\G+)\\",
        "NvMvT&vU=t}>z",
        "+%_S\"",
        ")|MfC4",
        "PRODCODE_TEMP",
        ";$;4;:;E;P;a;s;y;",
        "y>-O@I",
        ",n^/u9",
        "gf2Iy|Q",
        "^5V$e",
        "y3Une",
        "KHeHDjH",
        "mi|brf",
        "-{]7Q",
        "!j&<|",
        "F-\\/a",
        "Only Some Reasons",
        "2-a|SLG",
        "swiss",
        "9Fx^p2[",
        "U%MR|",
        "zSq+u",
        "r9)Y-",
        "t$PQPU",
        "X509v3_add_ext",
        "2%1q&",
        "5%.UQ",
        "M=\\n}",
        "J#*{-",
        "A7dnF",
        "    Requestor Name: ",
        "i?md1Y",
        "Wc?fo",
        "DLFCN_BIND_VAR",
        "Software\\CheckPoint\\SecuRemote\\5.0",
        "R$*|`pb",
        "J9Q:t",
        "!#(]\\",
        "Tw=$I",
        ":(:K:^:e:",
        ",d-Vm",
        "~dvg8",
        "giVda",
        "A! }s<",
        "K7;ew",
        "jvhDx#",
        "}4Iu3",
        "0O?n&",
        "ky]#3Q",
        "^;M+=8i",
        "BIO_get_host_ip",
        "bW(r|",
        "D$LWVPP",
        "1'2.2;2A2~2",
        "3#393^3o3",
        "bm*;\"zv",
        "~Qzk*",
        "i0g02",
        "?jt~=",
        "KQ~B&/",
        "?\"I9[",
        "%H#n0",
        "v1Aa,9",
        "Affiliation Changed",
        "UPGRADE_NOT_SUPPORTED",
        "ci#0j",
        "ReplaceOrAddAttOrTagIntoVSConfig():2 returned %d",
        "\"rJ/7",
        "wo6r4,",
        "'0f@^O",
        "MOG|ZR",
        "\"\"\"\"#\"",
        "jLQp3",
        "</m-N",
        "xCe.%",
        "D$8Ph\\o%",
        "discriminant is zero",
        "Verifying - %s",
        "Property %s for UpgradeCode %s temporarily inserted to the Upgrade table. Err: %u",
        "2-2;2Q2{4K9H:",
        "%&8jM",
        "I(X>+{",
        "0'1R1",
        "Z+w*_",
        ":=:\\:l:",
        "QVWjt",
        "8TPlJ^",
        "6$DN@",
        ";9&qVe",
        "QVA3n#",
        "owwjna",
        "-)*+WGlp,jfN",
        "ERROR: Failed to create SC unisntall batch error %d",
        "_4QacI8'",
        "p/5[c",
        "lc=`~",
        "u6k-^",
        "SGxL6",
        "L\\69D",
        "c~qSc",
        "]y4)4",
        "|.1UlJ+",
        "[g!nZ",
        "3^f;brg){",
        "RmGh`7",
        "A<K[K_",
        "*/'k[",
        "C%eJ7",
        "ASN1_FBOOLEAN",
        ":xV9K",
        "8d36/u;",
        "^iHhJ",
        ")3B0.U:",
        "unknown nid",
        "ar-kw",
        "Qjbhjg",
        ".?AV?$_Node_class@DV?$regex_traits@D@std@@@std@@",
        "uHJv(",
        "9YqzF",
        "-(5O,",
        "7~m]a",
        "w&Dnv",
        "dsa_paramgen_bits",
        "le terms and conditions set forth in this Agreement by your Service Customers. No Product, nor any portion thereof, may be used by or on behalf of, accessed by, re-sold to, rented to, or distributed to multiple customers, or to any other party, except for",
        "D$$SVW",
        "_#Z.L",
        "d^LZJ",
        "Px`@l",
        "pScheduler",
        ",r\\yc}",
        "maxsize=",
        "$R<_o",
        "3+4D4",
        "n{PB(",
        "p60M6EbE",
        "{)j]~",
        "lg^2Z",
        "^z4g.",
        "5$mpgb}t",
        "Ph0X!",
        "Loading driver configuration",
        "MKjIq",
        "a>i@d",
        "m;b~,",
        "MOVSLDUP",
        "MULPS",
        ";\\<\"=|>",
        "Program: ",
        "C{eaP",
        "l1|P~",
        "l10g/",
        "kQ3:|v\".",
        "< <%<0<8<",
        "se-no",
        "PKCS12_key_gen_uni",
        "AAS=4",
        "bsld`",
        "8-8F8_8x8",
        "EKq:6z",
        "Jerk1m0[",
        "b?5i1",
        "F0$?3=1",
        "1+@>h>c",
        "'v!F){H%",
        "a-5=o",
        "vuTK/",
        "~(~rw",
        "GYIk[",
        "97u!V",
        "T9J*Ig}",
        "X4e`hD",
        "DH_PRIV_ENCODE",
        "]K#QZ",
        "Z.dEX",
        "(/{#*[}",
        "w;Jmg",
        "setct-PCertReqData",
        "M^QtB",
        "zq^2W",
        "d=/4&",
        "R_8Ii",
        "^+#T[Y",
        "0wTMpB",
        "]8`x\"",
        "? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\\?`?d?h?",
        "Ms#:o",
        ",7p~w<",
        "#WnSU*P\\",
        "W}Wy+",
        "8\\f|,",
        "U)K3N^",
        "@~xTQ",
        "Co;5C",
        "jjYf;",
        "?Lgc4",
        "\\%enoUO",
        "]+W0Ow",
        "j1T!C",
        "h0;>B",
        "q0rHs",
        "D$Lj WP",
        "A*LB>",
        "sKgyxb",
        "666;6H6O6_6z6",
        "NCONF_get_string",
        "aIsND",
        "*Cl#k",
        " V|.9",
        "+p2\"/",
        "j~h(/$",
        "w{U|[1",
        "ssl session id context too long",
        "444<4D4L4T4`4",
        "=@\\uuk",
        "Gapi-ms-win-core-datetime-l1-1-1",
        "}2X=#",
        "l$8HG",
        "OhNC{",
        "wdnW9u",
        "9=.bW\"$}",
        "tls1_enc",
        "5x<`9",
        "4Ny,U",
        "230202160621Z0+",
        "2fg:LM\\",
        "\\[fCG",
        "7d1cn",
        "+\"DLK",
        "E-\"y6",
        ",X(XCE",
        ",/=^h",
        "AhzYlg",
        "CD9C@",
        "ZZuu3",
        "9!^]d",
        "w7_N)",
        "!B4CZ",
        "/F7(^",
        "03&0t^f",
        "/\\>\\h5",
        "}3SF>",
        "1b'ym",
        " >0o)Y",
        "3O4t4",
        "Kf)~X_",
        "9:9j9",
        "xEws5",
        "}N)Wy",
        "zF)rd",
        "HVsO[",
        "t.fW*",
        ">7~Nj",
        "BBH>abq",
        "5 5*5@5G5T5h5m5s5",
        "X6^>**",
        "8 8(8D8L8T8d8l8t8|8",
        "ENGINE_ctrl_cmd",
        "14_]P",
        "vR`]=y$",
        "6J.0W",
        "Failed to open SC uninstall registry key",
        "1<1b1w1",
        "3-3H3M3V3s3",
        " 0x30",
        "Cj-.n&",
        "CJe,=&",
        "Ff%>G",
        "LAcWT7",
        "vJDSB",
        "Stth5",
        "no public exponent",
        "\"I~Kw",
        "fE\"+5bV]/",
        "<b+\\8",
        "2EHDE",
        "zj!~^",
        "`^mBf#",
        "Maximum (%ld) redirects followed",
        "qud;{}",
        "T?T@TATBTC%D",
        "3)4a4",
        "5a}8W",
        " qii<8",
        "9p9 r",
        "){4FU\"",
        "<*=3=m=u=",
        "N6\\v~",
        "*e\"sS",
        "RzI6`i8hrjP",
        "EP7'X",
        "@3*8a",
        "3(3,30;4;8;<;",
        "U5K?JN;Nf6",
        "ugw!y!Y",
        "authorityKeyIdentifier",
        "P,_^][",
        "4`5o5",
        ">wnY\"",
        "Et?fI",
        "e}B3;",
        "t *cA6",
        "u8$%xrc]",
        "X=hbj",
        "Gd3op3",
        "JSz[d",
        "8M:?9",
        "8R`&,,L",
        "7@D9 ",
        "uzl;G,",
        ";B<Q<2=`?",
        ">#>0>B>",
        "RHG_\\",
        "2-2_2j2",
        "UPDATER_VER.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "O-&Qv",
        "9\"9;9T9m9",
        "d1lRn",
        "Services stopped successfully",
        "3wFu5",
        "jth`1$",
        "8:8V8r8",
        "ETWLx",
        "%.%:%F%",
        "4(4L4X4`4x4",
        "x{_rx:",
        "GT-};u.",
        "t#X:Iy0",
        "|Gh{:",
        "eK%+X",
        "v-?>E|",
        "Install Dir",
        "899f9t9~9",
        "UE;o/l",
        "<c$u4",
        "aKMV03",
        "InstallPath",
        "@\"4n.",
        "ACql=",
        "zol8H",
        "S}*0p",
        "&W1c{",
        "i8]y>",
        "8G<m=~=5>",
        "=R.:WTV",
        "uOe`v",
        "xeg33\\(Y`33<",
        "eH8<3",
        "7fk~ c)G",
        ">?GOXEn",
        "Ph|O!",
        "xMe9{",
        "=:=~=",
        ",NMF$&}z",
        ".uK(A",
        "FVWPP",
        "q'wBH",
        "jnle0^CF",
        "<fKLZ",
        ",_I~W3",
        "x;]5D",
        "}(Pi(?91",
        "TF1|8",
        "VWgqZ",
        "j9Kt^[",
        "[VSWriteUnisntallInfo] Couldn't open filemapping, so created it.",
        "+=S~p(A",
        "Eo`=(aa",
        "+~_)|<]",
        "oKD{5",
        "UqFx)",
        "Y2h7,8b8i8p8",
        "2wdo\"C",
        "!|^}m",
        "7!SkL",
        "R[[6-=",
        "x.*^M ",
        "Vm\\(8t",
        "O_LY2",
        "3t$<3t$,",
        "\\v) 0 ",
        "5$505P5\\5d5",
        "8&8+808K8U8a8f8k8",
        "p(b<E",
        "d`~YvyJ",
        "HZf#&*h",
        "Accept timeout occurred while waiting server connect",
        "5KM0O",
        "FKr/=",
        "Y,ZXv",
        "Zki#Z",
        "D$,#^",
        "J4KBxG=",
        "[VSReadUninstallInfo] Failed to open shared memory buffer",
        "<$</<<<H<S<",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13260676 ",
        "UeqUHJ",
        "3>dfc ",
        "KEGpH2t",
        "RAq$R",
        "nULFUb",
        "t}|/i",
        "nQ/8W%",
        "P&NW9",
        "d/e|,",
        "_8K8MZ",
        "2dlDi",
        "212^2",
        "tHSVj",
        "Gl#s5",
        "3VcyC",
        "D$T_[^]",
        "cJ-W=~wHrO",
        "N5G~9F",
        "/XD|DS",
        "PO,<0ii",
        "nfCEt",
        "dX/#W",
        "1)1.1I1N1i1n1",
        "-~PG2L _",
        "Kzc=K",
        "0KFcY",
        "qiW D2",
        "MNC\"'^",
        "iw)nG",
        "DN3%%mV",
        "df?V$Vj",
        "`op/YK",
        "&2?^u",
        "T9S@S",
        "JZ.e'Tp",
        "^=(g*",
        "\\p=Kwr",
        "5&{E^",
        ":\":':,:<:A:F:V:[:`:p:u:z:",
        "8h?}k",
        "c_LbH",
        "=_>.R",
        "QpSjjR",
        "QbJ!o",
        "unable to load ssl3 sha1 routines",
        "}\\Nqn\\",
        " 0xee",
        "ip`aK(",
        "j/CmN,6",
        "399483c90bd560b0b0263435085a21b0f22a9cf9356b38ec6046026d77eba3dc2dc60b17e92219e180643ed27acffba86e9c94c7ca9c225a0f1b0cfae0788ad5",
        "!Z,?d",
        "2@2W2n2",
        "lg5~H",
        "g)gih",
        "GetNumberOfConsoleInputEvents",
        "$F6}_",
        "APN0O",
        ",3034383<3@3D3H3L3X3\\3`3d3p3t3x3",
        "XmlFile",
        "&\"&2&j&",
        "zrGg#",
        "*[}eX",
        "L/Tkz",
        "V[5(1",
        "B@}L.8",
        "dnQualifier",
        "617<7W7q7",
        ">J(h:",
        "5;O>n_",
        "zt6MU",
        "Y_u)>",
        "EVP_PKEY_CTX_ctrl",
        "`i\\C{",
        "&=DDD",
        "q+Pw^et0",
        "a)\":y",
        "d.vr5",
        "?U+y\\",
        "#1\"DE",
        "060G0|0",
        "/E2Kv",
        "181205000000Z",
        "FN|1 O_",
        "wtZqo",
        "Q|TmX",
        "2fhJi0X\\a",
        ".0931",
        "File already completely downloaded",
        "SzZf@",
        "&\\$U,",
        "P~3H(",
        "75{ZQ",
        "@xCFy",
        "CANT_GET_CUR_DIR",
        "%gB`+`|",
        "EO_|]",
        "D`N!}",
        ")8Lf1",
        "v~MZ4@",
        "8-9m:}:",
        "=fY*%",
        "|I=>f",
        "fF#Ui",
        "EU|Z1a=",
        "^H^][",
        "080@0H0P0\\0|0",
        "(y}rhv",
        "e_%$AHx",
        "8[d,gD$",
        " Bg[$",
        "8V[UHE",
        "%dHUr",
        "EU~?\"g",
        "PKCS7_decrypt",
        "4g]W}",
        "[k+VyM",
        "wrong message type",
        "Mg9.17=*n",
        "n,)j3t",
        "XkJr@",
        "Brg/+\"%",
        "McAfee Internet Security 6.0",
        "&ZILq",
        "unsuported number of rounds",
        "\"^?g_",
        "8Kz9Y",
        "Agnitum Outpost Firewall 1.0",
        "'gziv",
        ">j.~-",
        "CryptUnprotectData failed for %*.*s",
        "<6=]=",
        "d/$`F",
        "W-o+0v",
        "klupd_klif_kimul",
        "pathlen",
        "6m/LT-",
        "0=U}m",
        "un|A #",
        "T?s.@",
        ".([Zx$",
        "gZ'>Vl",
        ")%fVy*",
        "<,<4<D<L<T<d<l<t<|<",
        "|hB{6K",
        "\";H]g",
        "8_^[]",
        "5.5A5T5",
        "{IDEJ]",
        "=&v\\lVO|",
        ";<p?\\",
        "n&@bF",
        "5hgN9G=",
        "*/JS]",
        "*+sX0uL",
        "0=1E1R1p1",
        "sE,(}z",
        "XPizO(u",
        "zezIzqzuzyy",
        "/d[tC:",
        "lfLbH",
        "+Q{PU",
        "w2`TkB",
        "ZF^jG",
        "zm*XE",
        "5\"627",
        "brg*r",
        "2Z0-!*",
        "g*]Mx5",
        "1B8hd",
        "SSL_CTX_use_serverinfo",
        "87[LA",
        "YN;$P",
        "1C1m1",
        "+yPen",
        "XIXK6",
        "$ck4,",
        "D$XjPP",
        "' '8'",
        "AmWUz$",
        "x$SVW",
        "VZdLF",
        "Hold Instruction Reject",
        "j <= (int)sizeof(ctx->key)",
        "q(7(y",
        "q K|1[",
        "could not load PEM client certificate, OpenSSL error %s, (no key found, wrong pass phrase, or wrong file format?)",
        "0 0(0@0H0P0X0`0h0t0",
        "doQpk",
        "SR3z5",
        "FTrV!",
        "&rz+I_E",
        "5F6`6d6h6l6p6t6x6|6",
        "@gH\"9",
        "q+f:um",
        "cX.lQ",
        "tH6}k",
        "\"@Q3P",
        "Stream error in the HTTP/2 framing layer",
        "2818ovC",
        ",z<V3",
        "I*pLr",
        "2 vgp",
        "^Gc`)",
        "A1Ome",
        "owU2v",
        "c'5y~",
        "strncmp",
        "6*626?6S6a6i6s6J7j7",
        "!R'0f",
        "sE%!Y",
        "9\"Yx6E%",
        "F%*\"Xi",
        "VWZ,R",
        "AQP4n3",
        "u~1uK",
        "1J?${",
        "3PfSZ:(S+0",
        ".rdata$sxdata",
        ";)AU_",
        "D$4PWW",
        "p??!)",
        "n*qVMV",
        "Q`A[L",
        " Z4ZC\\",
        "5U6]6",
        "_zTcG",
        "[zCbr5",
        "PKCS5_V2_PBKDF2_KEYIVGEN",
        "=$>a>+?|?",
        "}B=oW",
        " }Vd#",
        "OOeWL",
        "\\%28S6Bp",
        " 0x43",
        "1BlnV",
        "x1e\"TZ",
        "=st,U",
        "Rxyn ",
        "WVy{}",
        "KzB[>r",
        "@W}JD",
        "S@EeD",
        "lQk15",
        "SH6tc",
        "fS9y7b",
        "*(O9d",
        "D$dPh",
        "KO,v9",
        "{XoF,x",
        "ETb]r",
        "/Uh,e!",
        "Obr\"K",
        "63##S",
        "~BR5f",
        "646<6D6L6T6\\6d6l6x6",
        "D$8_^][3",
        "8,.eJ",
        "\\oNcA[h",
        "f|9j(",
        "[)r(}",
        "9*?$_",
        "%R\\g'",
        "/!_x1",
        ")G.G4G",
        "%y+Iq'",
        "+jkf?",
        "CM0:LP",
        "ntdll",
        ",_;7ymI",
        "Y='26",
        "7z@lA86,T]",
        "OBXp~",
        "e6f#6b",
        ":Q:W;^<",
        "7X8\\8`8d8h8l8p8t8x8|8",
        "EOMY#",
        "C(/,C`",
        "O1qZC",
        "t~I2T",
        "k,#(4Vw",
        "9~R\"Y",
        "SetProductNameProp",
        "UO>}#",
        "Dr76LUo2",
        "[rH'3$",
        "S^a)wm+",
        "8fW$*",
        "D$ @P",
        "SMDqd33-",
        "%,2\"}V",
        ";7(-K",
        ".\\#k\"X",
        "gI}LAv>=8",
        "#64Rb",
        "OmP1h",
        "^IG3oyf",
        "<8+/c",
        "?1m>+b",
        "\\#87D",
        "DEF_SERIAL_CB",
        "D6@4b",
        "2tdAu",
        "RoUninitialize",
        "FC-Ls",
        "u$jOh",
        "VW#1 ",
        "_l[` /",
        "a4@i+",
        ":0:@:D:L:d:t:x:",
        "&zcWH",
        "6}OC-",
        "(%`g&",
        "c9ZOP",
        "~\\tk~",
        "8 8$888<8H8P8T8`8h8l8",
        ">b?}?",
        "7i ,a",
        "no path supplied.",
        "~nfL??|",
        ">.?<?V?z?",
        "vDC8G",
        "',z^IY!",
        "mO+iB]",
        " IpjR",
        "*\\qqlA",
        "7:7K7d7",
        ";V(u*",
        "2N}\\`&",
        "727;7d7",
        "G,<`6GH",
        "5(gPU",
        "<2IJ%5",
        "WtwzG&",
        "[b.Xs",
        "Bg;ci",
        "lltts~",
        "6/676G6",
        "B\"no\"",
        "f-j%>",
        "r~S%>",
        "                   ",
        "SOFTWARE\\CheckPoint\\EFR",
        "\"bm1J",
        "eb31y",
        "nlSF6\\'u",
        "UninstallCreatedItems:  Removing registry key HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\CheckPointEndpointSecurity",
        "E]Fke ",
        "fp:5H",
        "lF&<;^",
        "CloseHandle failed: %d",
        "A4Gy:,",
        "545N5",
        "kJ^`o",
        "TjFD6",
        "Sg;r=H",
        "sHjLk",
        "A`2Cp",
        "WSVhd",
        "L$(1|$X1t$\\",
        "9x}vx",
        "fa-ir",
        "$We]bz",
        "0^4:R",
        "V;27X",
        "///////",
        "Set registry values",
        "]<(U%x",
        "`cE6(",
        "A)[MS",
        "4[?y+s",
        "SsI(P",
        "a2O92",
        "Dij.m",
        "ddY+/",
        "(W8x\\",
        "647^7",
        "mzt?|%",
        "ubjR)8,R",
        "U~E;/",
        ",ICzBI",
        "&FR&[[R",
        "sZ{UR",
        "CreateDirectoryW",
        "989@9H9T9t9|9",
        " yB1n",
        "2Q3}3",
        "########",
        "3088:",
        "Sa$_7",
        ":!:4:<:o:",
        "iCuo5b",
        "%T`'nN//",
        "c`U1Z\"",
        "{:3jg",
        "9A<u(_",
        "n)4grT",
        "Q`H0}}",
        "O>D)i",
        "]{;&+p",
        "C(Ahs",
        "encrypted",
        "u)Wf#'",
        "@i;'mD%",
        "L6`9k",
        "?2z?M$|D",
        "3RGz7",
        "wJ*xG",
        "a^Npx",
        "5JyAp",
        "@5_i-",
        "w_LYb",
        "|2[X'",
        "? ]>uM",
        "#u/%d",
        "DS_UninstallFACDriver ended.",
        "J3d6l",
        "D_CpZ",
        "}YEy|",
        "^\\tI36",
        "0#030=0r0|0",
        "BDNGB3fP",
        ")C&=w",
        "5)616",
        "PINSRB",
        "W*6WBted",
        "dOyI ",
        "z\\:A*",
        " QmXP",
        "\"mx~c",
        "<B=j=",
        "DataStruct:I:ravpn_is_v1",
        "KAiX+",
        "4wq6s",
        ")]-]1]",
        "u^ZJ)ob2p6",
        "'5K0$",
        "/@YA I-",
        "%*o$^y",
        "7:8}8",
        "p@dzn",
        ";K;4<[<",
        "hM\\,_",
        "k:J?\"A?",
        "vnaap.inf",
        "yn1*zc+",
        "StopABService_rollback",
        "TT/OxOf",
        "div-MV",
        "$=Xna",
        "Z5`<I~",
        "5Fe&=-",
        "F~&E\"{",
        "n9x(l",
        ";!;1;A;Q;a;",
        "sk139752",
        "b/|+Z",
        "2nc^s",
        "u71hE",
        "eeUwV",
        "FU 4g",
        "C0&'y",
        "dM{]&H",
        "Au}v%",
        "/NGD*",
        "|$@!up",
        "X{,39w",
        "R^[b]",
        "I@&Au",
        "&kAf#",
        "PreInstallCheck: Reserved space for Compliance data: %I64d MB",
        ";CZj i",
        "s[K?/e",
        "eY}pNo",
        "VdCq3y",
        "B64_WRITE_PKCS7",
        ";El6'6W",
        "3f^rJ",
        "D$ ~Kj",
        "/qi4!",
        "N83zv4/h",
        "}mm1I",
        "U`ac-X",
        "999w9",
        "OnFreshBefore",
        "7#7w7B;",
        "E</yd1",
        "Apollo.png",
        "usg+y",
        "2v<=xz",
        "4$5L5t5",
        "V=[ig",
        "\"L~L3",
        "d}[#_3",
        "#3:O4j",
        "CANT_FIND_VSUTIL",
        "c-9\"[",
        "w1N,\"]",
        "2:1I*",
        "cDbip-",
        "om/h}",
        "&RRUw",
        "Cc=>t",
        ".ss]>",
        ";*<N<Z<e<u<",
        "6'Y<i",
        "+K4%B",
        "D$ UP",
        "3L$X3L$ ",
        "Referer:",
        "FP@}A",
        "mb`eo",
        "P@N:C",
        "H8v(>:",
        "D~9)K/",
        "2 2,282D2P2\\2h2t2",
        "7'8A8[8u8",
        "\\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5995582 {\\*\\xmlclose},}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477  it becomes subject to regulation by agencies of the ",
        "2/DHW",
        "/gVkB",
        "K5KFbZ[",
        "67%da<Ohu",
        "kTL?H",
        "U%@wt%]Ktu",
        "ql,Qs",
        "X509V3_parse_list",
        "^N_MQ\"|",
        "=$>4>;>f>",
        "0Q0u0",
        "w5qw5",
        "n%S.\"",
        "WE_cc",
        "g,#0O,",
        "failed to get firewall description",
        "jqQj;",
        "S<&{W8q",
        "J[pW?F",
        "VYfYyY",
        ".?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@",
        "A:+q_",
        "$TxP`S",
        "RegKey::GetValue",
        "0#0N0]0f0s0",
        "Hc_{kK",
        "CRYPTO lib",
        "counter:",
        "?K?U?p?",
        "i{tHs",
        "(<<3=cB",
        ";mxxn",
        "@y[,U",
        "5;N;C",
        "PQCui",
        "=g>v>",
        "rm<6K",
        "`iKpY{",
        "=;=N=",
        "JF,>7",
        "qCM=s",
        "e+V74l",
        "gt5i.{9=",
        ":$<o>",
        "()4LY",
        "failed to write builkwrite value action indicator to custom action data",
        "u]eOp",
        "$\"%b%",
        "[VSDATA] AddDataClient: DIOC_HOOKALLOCATE failed",
        "-TmTZCZ",
        "UqKs3",
        "Z([P[Av",
        "Module32Next",
        "]#+qCP:",
        "%Ew{2",
        ",aPfn&",
        "OnUpgradeAfter:  SetPassword",
        "#dpM9",
        "wOZZJ3",
        "ar-EG",
        "5smp=",
        ".?AVxml_parser_error@xml_parser@property_tree@boost@@",
        "`bG+c",
        "B^ekI(",
        "@=a/=J",
        "<$<(<8<<<@<D<H<L<T<l<|<",
        "}0+w2B",
        ":S*RK&",
        "6,6]6j6",
        "dk6n7",
        ",238&",
        "5(5,5@5D5X5\\5p5t5",
        "uf[vXDP",
        "Cz3B;B",
        "?}1S:L",
        "XU?*,",
        "v?>&P~",
        "J;@t67T",
        "KM?Bs",
        "i?a7Z[",
        "g0f1|1",
        ";er4u",
        "x}P30u",
        "=9=O=Y=x=",
        "t#jv[f;",
        "$H,%!2",
        "\"ue?8",
        "Transfer-Encoding:",
        "aU$1Y",
        "6&6T6`6h6~6",
        "<(<,<<<@<P<T<X<\\<`<h<",
        ",&X$X",
        "[R5`G",
        "is-)EU+",
        "ebYZ|",
        ")bi5]",
        "3/$;`",
        "!UpDr",
        "lastModifiedTime",
        "}.\"YT$",
        "&=jNE",
        ">8?Ub",
        "sms-fi",
        "'~xR~",
        "Q_4pN",
        "\\@'HkW",
        "yGzO>",
        "jAjkj",
        "D=ew';",
        "7:8o8",
        "u'[Y^",
        "_=~a(8q1",
        "#'_0X",
        "G<AHQi`",
        "t D>@Q",
        "Ak~8m",
        "[e;'S+L",
        "FDRxh",
        "jZRvd",
        "cX&_b",
        "i;$\"m",
        "CAMELLIA256-SHA",
        ">bU7t",
        "C3U/X/",
        ".?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@",
        "\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 icense is designed to provide You with early operational experience with the Beta Produc",
        "BP;BL",
        "_.^g1F",
        "x/%# ",
        "7i>J3O",
        "nonconforming hardware component}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid84110  or return of the price paid for the Hardware Product}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid13774068 ",
        "TzB?1{S",
        "Y<rH>",
        "\\`md*[",
        "YD%\\!\\\"pjm+m",
        "(ntQhy/",
        "%BwYo",
        "%02d%02d%02d%02d%02d%02dZ",
        "PGr*4",
        "8?9E9J9e9",
        "\\X\"^;@",
        "dh6`v",
        "pbN?OI",
        "_Rk%4",
        "330508074158Z0c1",
        "3p{fX",
        "~,ck.C",
        " \\2H5",
        "\\8[eNT*",
        "N6+qI0",
        "BHX)L",
        "vsdatant.inf",
        "1(1L1T1\\1d1l1t1|1",
        "'M/_7",
        "Vb4}d",
        "thread_",
        ">KO I",
        "p0mN*",
        "'cS5i",
        "{{-Nv",
        "Pause pending",
        "9D$(|",
        "nXstc",
        "FlSQ1A",
        ":*:<:E:P:b:k:y:",
        "&YK]1",
        "d}F ?",
        "BN_GF2m_mod_sqrt",
        "3!4R4",
        "0#0:0D0g0s0",
        "azGf3f^",
        "C%C'C3C7C9COCWCiC",
        "\\bIUJ",
        "CXNMk",
        "WIX_DIR_MYMUSIC",
        "{b$p16",
        ", AWI",
        "/>v`{:",
        ":W-0m",
        "tls1_heartbeat",
        "X509_NAME_EX_NEW",
        "DU$*P;",
        "s4O H",
        "unknown purpose id",
        "U4C*p",
        "7@g,mh",
        "r] $J{",
        "w}!`f",
        "t+cJc",
        "L$TQj",
        "=&,&/",
        "srtp unknown protection profile",
        ".r9vqwZMN",
        "v#Dt:",
        "at9D/w",
        "4(H~Xk",
        "%h%:%B%H$PI",
        "hn?tc",
        "sL3?Hx;r",
        "LU.wf",
        "EF^g4",
        ";qL\"8:",
        "#GU|&",
        "YT0d[",
        "D$PPV",
        "UtdZS",
        "\\$H3\\$T",
        "8N8@9v9",
        "american english",
        "+ +)+m*",
        "6>7M7`7f7",
        "[N*.2",
        "fZBpm(",
        "\"4dV%",
        "1#1U1",
        ";&=2=v=",
        ":Q:l:",
        "u?_^]",
        "2V3J5",
        "es-EC",
        "S|(?^e=",
        "9_RirWKK?y",
        "t$4PP",
        "73@p!",
        "=#=x=",
        "qyrjGQ2",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477  or (ii) on the U.S Treasury Department list of Specially Designated Nationals or the U.S. Commerce Department\\rquote s Table of Deny Orders.",
        "n4XxO",
        "ky7.d@",
        "expected attribute name",
        "9M9s9",
        "1L2Z2m2",
        "5H6P6z6",
        "bad public key algorithm",
        "y5x| c U",
        "*\\h~|",
        "uZTV}",
        "!LwlBv",
        "i?`n?",
        "#UCx*]",
        "8%808;8F8Q8_8k8",
        "UNORD",
        ">!>:>S>l>",
        "[VSDATA LOAD] MakeSelfRelativeSD2 failed: %d",
        "HT1nE",
        "j k`l",
        ":</c:@",
        "d_N~X",
        "Q>QBQEQHQKQM",
        "spgCBa",
        "D>Obj",
        "C oP&",
        "U!zvF`",
        "uv4e{B(",
        ":hpgSQ.m",
        "}WStV+K",
        "Unrecoverable error in call to nameserver",
        "6B7K7",
        ":9;C;`;q;",
        "aYvF$",
        "T$AV1Yy8",
        ":6CsU",
        "MF5|w",
        "K|1=f",
        ">tgc$",
        "1*!00",
        ">2^w+",
        "f)=SZ",
        "9s$t\"Uh",
        "<i\\Q'",
        "Ua&i\"",
        "':WZx",
        "rNrN!",
        "bad signature",
        "*;YTE^e",
        ":3;=;G;",
        "^vv_T",
        "VL6qO#;",
        "7#7?7b7}7",
        "]CVMs",
        "9:w+M^",
        "#<N=tN",
        "l=hW,9",
        ";aSal",
        "8%\"~J(qR",
        "x}L}p",
        "g&gFgfg",
        "0 Umv",
        "vg_1r",
        "S1(IH",
        "d9sP'Z",
        "%^7:<",
        ",{#<E",
        "sF(zd",
        "Ry##~",
        "ZT3@f",
        " C Tc-",
        "M_25)",
        "1+b<T",
        "#E 6aw",
        "uNjNh4",
        "W\"DBq",
        "2qB#Qs",
        "6 6'636A6Z6a6m6z6",
        "F,;G,t",
        "9H5nJt",
        "BWf!DR",
        "RYR@t",
        "setAttr-Token-EMV",
        "SSL3_GET_RECORD",
        "[WinFW] GetWFStatus, got the domain profile instead",
        "RK(9!",
        "If,G\\",
        "R)z>w",
        "Lm]-:V",
        "{\\flomajor\\f31515\\fbidi \\froman\\fcharset186\\fprq2 Times New Roman Baltic;}{\\flomajor\\f31516\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}{\\fdbmajor\\f31518\\fbidi \\froman\\fcharset238\\fprq2 Times New Roman CE;}",
        "Weirdly formatted EPSV reply",
        "D9:8;",
        ".UQ'\\S",
        "]Al\\>",
        "q<j\"dq$",
        "5~@S}",
        "%_&MC4",
        ",\\#8s",
        "5i5s5V6y6",
        "JqwO0",
        "`S6B0",
        "f\\g@Z",
        "GQ`Di",
        "Val#[a{",
        "h.A0o",
        "ar-ly",
        "e()bP",
        "(Z 1Ce",
        "h2F]z$A",
        "bInstPWWasSet",
        "cv8\\c",
        "VSWriteUninstallInfo",
        "BBcS)",
        "P}UBL",
        "Re7\\.18",
        "f%vp;",
        "2W5k(",
        "lZYH#",
        "0)0I0",
        "GsORnh",
        "Q[H3%9",
        "JrN'`}",
        "COqbU",
        "NXHkP",
        "Iky'{",
        "#S5Mvv{",
        "33333330",
        "?T$|u",
        "6c7o7{7",
        "<C<H<s<x<",
        ";#*bDv",
        "Ig<7l>",
        "&*gN1U",
        "jCjlj&",
        "4%4,4;4l4s4z4",
        "gr0g\\",
        "N&fau",
        "RNRh|]",
        "mdLM4~",
        "W ?,V'G",
        "]!T(x",
        "2`811",
        "&,0#x",
        "otherMailbox",
        "OiCL{s",
        "y,_t?[{y",
        "XD7_a",
        "]1\"rk",
        "t$pW3",
        "Q92d'/",
        "V)Cdw",
        "=H=c=|=",
        "2)3,414",
        "lfB{V",
        "mB\"^p",
        "{SwaTt*",
        "=)=Q=h=r=~=",
        "5.5J5f5",
        "BQL{l",
        "fqAc|G\\!",
        "H1rM\\7D{w",
        "OG%^+",
        "opfNOB",
        "EVFze",
        "78M4H",
        "\"CN-^i#s",
        " name=\"%s\"%s",
        "56\\vcc8:",
        "6LB_?G",
        "|pg7\\",
        "6064686<6@6D6H6L6P6",
        "hZ^08.;",
        "4K5e5",
        "yocsf",
        "|=Ev<",
        "RSA-MD4",
        "Z$N@i",
        "int_field6",
        "G&L%(",
        "vhN`}6l",
        ".m.;]<]",
        ".xG6vw<",
        "&*Q35",
        "10maE",
        ":/ZTh",
        "Bvhko",
        "Sv-)-0",
        "6Br4t?",
        "\"f]dz",
        "Sr$$r|",
        "CANT_OPEN_VIEW",
        "H.~#S",
        "g@%t'",
        "i;=K5",
        "H)=tD",
        "CrpQ#x",
        "^BQDx",
        "#]6U'8",
        "j&l:5T",
        "N_j`/T",
        "The two certificates are identical.",
        "FSCALE",
        ">\\DL6T",
        "iwG[L",
        "l\\]Re'",
        "9 :$:(:8:T:X:|:",
        "^<V7w",
        "^aGy3,",
        "87@7E7O7T7\\7b7s7y7",
        "8AqsVA$",
        "7*717=7J7Q7c7j7q7x7",
        "3%3D3c3",
        "Y~:lGOe",
        "ez1Y'",
        "[<;RU",
        "E PQVSW",
        "<$=Y=",
        "\\[||Z",
        "o}@u}ey",
        "T3m$2",
        "CoDAk",
        "]:*n4",
        "<K<]<",
        "M/b<u",
        "2250x",
        "1 VuYvg",
        "J#s+v",
        "dA7f&",
        "h2 sm",
        "N<rP[H1",
        ",k-0{>",
        "GetCustomerNumberEx(%s,%d,%d,%d)",
        "K#BqAU6W",
        "4\"5,5I5a5g5",
        "CMS_ENVELOPED_DATA_INIT",
        "NS(\\Vg",
        "CN?DYy0",
        "%sOsMonitor.dll",
        "vtvtx",
        "J0JDJXIp",
        "8(8A8]8v8",
        "\\#7FI",
        "Qz2#i",
        "Jw*3S",
        "wrong content type",
        "j;tPN",
        "format error in certificate's notAfter field",
        "E$7F/",
        "1+$<FKS",
        "o@Wp^",
        ",{X!@",
        "*D/Ye",
        "!nh}f",
        "YCAFJ",
        "OEuP~",
        "D$D1F",
        "[2=\"l",
        "6XD?x+A6",
        "ufu..",
        "prime239v2",
        "Root Entry",
        "m&|@C",
        "StopTracService",
        "&7Ta_",
        "Command line returned an error.",
        "DOWNGRADE_NOT_SUPPORTED",
        "QF$H5\"-",
        "Ru;dnexaS",
        ":MBoo",
        "L,H.H!8",
        "P21}E",
        "Rh`cG",
        "\\unreg.bin",
        "api_ms_win_core_console_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "BB*%v",
        "<9=O=",
        "&>SZP",
        "; ;$;(;",
        "}Elp[",
        "r#91N",
        "?qVr~s",
        "fHa\"vH",
        "dJdKdLdMdNdO",
        "j\\.s|",
        "<rdC\"9",
        ".T`'L",
        "gGQ~V",
        "[~K-S",
        "H=`]i",
        ":,:0:@:D:H:L:P:T:\\:t:",
        "m&NU8",
        "NMRoQ",
        "^.rJz",
        "j4e'a",
        "Dj;3x",
        "'&y4/",
        "a@.;S",
        "C7.~u",
        "9%j.il`~",
        "DispatchMessageW",
        "imfZd",
        "80848L8P8h8l8",
        "\\lR%^",
        "4J5b5",
        "id-regInfo",
        "hy^3v",
        "AK@Ou",
        "{[)^F",
        "1Zg.n4",
        "ScheduleFileForRemoval:  MoveFileEx(",
        "vypb6",
        "q|r|#|",
        "szModulePath",
        "080U0|0",
        "n$Itw",
        "5$54595G5R5g5y5",
        "!kj5d",
        "32C_+",
        "*K3] ",
        "8F^7$7",
        ")*0CDE(",
        "pd]z5",
        "`Ghu[",
        "[{XVpl",
        "@,@Nf",
        "eJAWi",
        "'=PCv",
        "-\"^VN7",
        "Z{(ck",
        "616H6",
        "MhQ-+",
        ">eCl8X",
        "*fOn=",
        "#sg kse",
        "1t#31",
        "BFx.E",
        "}N\\`FC",
        "3uM?]",
        "jrJ+W",
        "kcm&`z1",
        "\"doF5",
        "atlTraceRegistrar",
        "c{nFK",
        "6^7u7p8",
        "Major Release=NGX",
        "9k&,e",
        ".FMVF",
        "Getting handle to SCM reported success, but no handle was returned.",
        "2i;%c",
        "R3nB<",
        "^^vTx",
        "2a3ga",
        "6(6=6]6",
        "wq-fQ",
        "U R968~",
        "KV5s4",
        "udrxDW",
        "I'IWI[I_IcHg",
        ":p%}|",
        "'BmRBp",
        "<]wn|",
        "|#Qbn",
        "GsD*H",
        "XKY6<t\\Xs",
        "zkjl5",
        "wuea#/",
        "O:Qur",
        "cRz{\"",
        "AX=b@",
        "#Fw1amZ",
        "<$<,<4<<<D<L<\\<h<p<",
        "bQO~p_",
        "Hh}1*",
        ":(:h:",
        "jdAFQ",
        "OW tw",
        ":6;C;_;",
        "<B<,]4U",
        "c-V$I",
        "State_OK.png",
        "BipULSOj",
        "FiM*+",
        "HL[F_w5L(O",
        ".:GQX",
        "\\vsdatant.inf",
        "tjtzt",
        "3Z3s3",
        "\\fg<]",
        "_>wY/~",
        "{B @g",
        "6]}#G",
        "fi_Wd",
        "r\\r</",
        "I.NBV",
        "?J,+ ",
        "CreateProductXMLFile failed",
        "+Te9}",
        "EV<[>",
        "SY71@u2",
        ";^hR)",
        "oy\\[C",
        "EPWD.exe\" remove",
        "?_Xlength_error@std@@YAXPBD@Z",
        "?Iy$tDy",
        "=sXJ:(N",
        "4$4/484?4\\4}4",
        "1Q;|;/<",
        ">&bl/J`Q",
        "id-aes256-CCM",
        ":.ouFO",
        "u.j_h",
        "*NV7|",
        "9=~`H",
        "]u+[P",
        "^DkHs",
        "ASN1_GENERALIZEDTIME_set",
        "{U_Up",
        ";.;L;b;h;",
        "5-c-c.",
        "F$x[{",
        "`unknown ecsu'",
        "Kerio Firewall 4.11 and 4.14 (All SKUs)",
        "dsgF{X",
        "X4A0Y",
        "O<Xbi",
        "Nq=YP",
        "CX\\*A",
        "?3?L?e?~?",
        "|lhdQ",
        "m8~\"a",
        "vmVez",
        "h&}G$",
        "}f.O;",
        "P7Lf<s",
        "~N9p~uix",
        "' { go",
        "oS@/|",
        "azQtZd",
        "!1^JP",
        ",d,y2",
        "(le3v",
        ";o_kQ",
        "0 080<0@0D0H0P0T0\\0t0",
        "u}R'v",
        "Yq;7DO",
        "$_!zq",
        "iuPfi",
        "GetComputerNameA",
        "fLIAg",
        "%>%Sc",
        "THa2b|",
        "$zEwd",
        "D$`SU",
        "pFeEw",
        "*\\q-l",
        "u*aUW",
        "\"/Q7%;",
        "*B_z@",
        "X509_EXTENSIONS",
        "h.cvl",
        "7}U[c",
        "ZQ9l\\_",
        "U.^FP",
        "AR$>q",
        "t$,VVS",
        "k4rMtc",
        "Xg#lCP",
        "<},%'5",
        "}iJ#b",
        "1fE^%v",
        "\\vsmon.exe",
        "By*yr",
        ">h~0t",
        "^0w)>",
        " 0x98",
        "f0iib",
        "< tK<",
        "[VSUninstallProduct] unable to shut down vsmon (3)",
        "Aa)HX",
        "Zz\\ULbj.",
        "656I6O6h6|6",
        "KGHAs\\",
        "nH?7I",
        "n9/#1",
        "LsN?k",
        "K[\\}[%",
        "?~C(}",
        "]d+}!",
        "t1x1|1",
        "jAjuj",
        "<(<H<P<\\<|<",
        "=\") k",
        "mdKW|",
        "OUT_OF_MEMORY_READING_BIN_VALUE",
        "<program name unknown>",
        ">:B`}",
        "6`5af",
        "kuCt(w",
        "Insert new file",
        "?g?q?",
        "V#wN9",
        "Symantec Trust Network100.",
        "g>ZHs>x",
        "M_L}_",
        "4X566",
        "&M+pQ",
        "jLo~f",
        "JYD Fb",
        "Last-Modified: %s, %02d %s %4d %02d:%02d:%02d GMT",
        "%^*6)",
        "<$<,<4<<<X<x<",
        "2 3S3s3x3",
        "d2i_PKCS8PrivateKey_bio",
        "JoKqj",
        "!zRBR",
        "no unload function",
        "Remove invalid products registrations:",
        "vJ9sz",
        ">2J0k",
        "DHCq\\O",
        "bKu/Pg",
        "i*Qk8V",
        "ciu9k",
        "4`Yal",
        ";%<T<",
        ";\\$ps",
        "8 898I8",
        "z;>:$V",
        "q`?I(/",
        "CATnH",
        "c:\\windows\\temp\\fdeRollbackData.card",
        "\"zQ#e",
        "_INSTALLED",
        "NX\"y&5",
        "\"h2']",
        "SaveData() suspended.",
        "%/<36",
        "a('o\\",
        "}_j`A)",
        "JUh~1",
        "'\"B8>",
        "=L>P>T>X>\\>`>d>h>l>p>t>x>|>",
        ",EP&To",
        "'{{+}",
        "W17`3",
        "flAQ0",
        "=RM#-",
        "Got RTSP Session ID Line [%s], but wanted ID [%s]",
        "nC6R>",
        ".%EP2",
        "kECDHe",
        "I_/'U",
        "9#B2N",
        "\\fs20\\cf0\\insrsid131787\\charrsid15169477 (ii) with regards to any Hardware Product, the license shall be valid only\\~as part of and for the life of the\\~originally designated Hardware Product}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "Z?\\nP",
        "5Ot=]",
        "=S?_[N",
        "aB{My",
        "ly5|f",
        "SSL23_GET_CLIENT_HELLO",
        "qQI\"7dn",
        "ut0'y",
        "5MbR~",
        "00080D0d0p0",
        "z$m#@",
        "0@e:87",
        "7ngsa",
        "CMS_RECIPIENTINFO_KTRI_DECRYPT",
        "KDw?7]",
        "'(c) 2021 Copyright Check Point Software Technologies Ltd.'",
        "y-p~bC",
        "MsiViewModify() returns %d",
        "v\\%0)",
        "0VeKy",
        "rIY$Kv",
        "jwo?2",
        "C<;y?",
        "I-sq&w",
        "8yTF5",
        "|9G?av-",
        "8jr&i",
        "Tn+z#",
        "Wp}, k",
        "reboot",
        "]HVH5",
        "^#+7PX",
        "8nVq`",
        "ECDHE-RSA-AES128-SHA",
        "n{J=-",
        ";r+4h'",
        "~t)]7",
        "P4qJN",
        "'-:4%q-",
        "2 202@2D2T2X2d2t2",
        "2O9)6",
        "t$4h`@%",
        "IXh]8",
        "|T~PO",
        " V>f:",
        "1*JYE",
        "YQ~\"J",
        ".*)U?",
        "Telemetry",
        "2>2\\2t2",
        "DHN%\"b2",
        "UQ)2t",
        ";D$$~",
        "383<3@3D3L3P3X3\\3",
        ": :$:(:<:@:P:T:X:p:",
        "8'8A8c8}8",
        "directory services - algorithms",
        ";&=5=u==>",
        ">&//\\",
        "qKMSM",
        "Failed to open a thread handle for logmon.",
        "%$09\\",
        "failed to get WixShellExecBinaryId",
        "2@dg3",
        "?DvOF",
        "XE?p7",
        "N8vMAE",
        "bY(w7Yn",
        "$_v=@8",
        "122a2",
        "rh8fl",
        "1B?s}",
        "D#W<&",
        "dd$h&p",
        "Range:",
        "1A2c2h2",
        "****************************** UninstallSDL started **********************************",
        ")<\"}|",
        "UA;gI",
        ":IHB@",
        "n<VOJ",
        "itEd1",
        "?Aw+2",
        "AjHX0",
        "peer error",
        "Invalid modification specified in custom action data",
        "XJ+g]",
        "B-233",
        "^{v[c",
        "2`3+4o4",
        "')*Y*((X",
        "0Z4Ot",
        "woTUj",
        "illegal integer",
        "<WhDT",
        "vsinit.dll.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "sjmj1-6",
        "*K}P'",
        "LDJ'^l",
        "{GUc0",
        "n9 ;fE",
        "lG97:",
        ",4vCR",
        "^V!1]",
        "ComplianceData",
        "(t$<o",
        "yY3;f",
        ";gMoZ",
        "E;>a!",
        "S8W{R=P",
        "%s\\Temp\\trac_install.log",
        "=G>Z>",
        "r~f;U",
        "ga#K-5@",
        ">*s\\rv",
        "FXQRW",
        "^mAWS",
        "Bsots",
        "PatchingOldMSI",
        "=gj>z",
        "P,5280",
        "}&.2.",
        "pt-br",
        "PC,Nv]",
        "QVzw9)-'",
        "6Yg[X",
        "<8=F=",
        "U1_A/",
        "oisK6",
        "Y#ihu2",
        "pKMzc",
        "bNHhw",
        "<;}$!q",
        " ^E-M",
        ">.?N?",
        "iB{yBLT",
        "o6wnk+h",
        "$M0B?",
        "0!@h.",
        ">2a6, q",
        "?%?0?;?G?|?",
        "!d-;d",
        "g`0Ik",
        "E+!-Q",
        "C*7F)",
        "dfdyD'`",
        "_ 5h~",
        "7c]v ",
        "SEC_E_KDC_CERT_EXPIRED",
        "9f@C~r",
        "DYnBFT",
        "#Jqn-",
        "u89F(u3",
        ".\\crypto\\asn1\\asn_moid.c",
        "r**&Y",
        "$PFDT.r",
        "9,9<9@9P9T9l9p9",
        "))uf)",
        "_aq^7",
        "s3X@,",
        "'m;]S",
        "PathFileExistsA",
        "&*eRBE",
        "$d= Ar",
        "w=dn7SN",
        "+v-Ad~",
        "[WinFW] SetWFStatusXP, failed to set standard profile, error=%x",
        "7T8u84:?:I:q;|;",
        "0+aQBZ",
        "6]aw<TU",
        "5(505P5X5`5p5x5",
        "&C8{$",
        "Unable to extract %s: %s",
        "1\\1`1d1h1l1|1",
        "jAjpj#",
        "Connection refused",
        "1Z1r1",
        "=]SUU!52",
        "~DM3Qv",
        ":$:,:",
        "7)7A7F7K7c7",
        "sx6oF;r",
        ">K>_>",
        "%_2D|Z",
        "_register_thread_local_exe_atexit_callback",
        "0%4-757l7s7",
        "2V3k3|3",
        "8V8d8~8",
        "IqF)lU",
        "ReadConsoleW",
        "T1l6T",
        "fMDMH",
        "Q<NgQG",
        "v4\\]E_",
        "w^.[b",
        "5#Uy|",
        "jxDcl",
        "S_OtK",
        "\\lsdunhideused1 \\lsdlocked0 Table Grid 4;\\lsdunhideused1 \\lsdlocked0 Table Grid 5;\\lsdunhideused1 \\lsdlocked0 Table Grid 6;\\lsdunhideused1 \\lsdlocked0 Table Grid 7;\\lsdunhideused1 \\lsdlocked0 Table Grid 8;\\lsdunhideused1 \\lsdlocked0 Table List 1;",
        "U$yK!k",
        ")!^kJ`",
        "_*7w&2",
        "%S#[k",
        "30383L3T3\\3d3h3l3p3t3x3|3",
        "}04N_",
        ":bc/G",
        "@e:@&",
        "h/j~d",
        "r5AeLS",
        "FETTD",
        "Lzf>\\",
        "v#y1q",
        " 3)<Ah_",
        "]-7=O~",
        "^b|s3",
        "64686<6@6D6H6L6P6",
        "ZR~jD",
        "U|.cVF",
        ".\\crypto\\asn1\\asn1_lib.c",
        "4$444D4H4X4\\4l4p4",
        "NEWINSTALLPASSWORD",
        "A m}^",
        "d>8?A",
        "    Requestor List:",
        "Server 2012",
        "Copyright (c) Outercurve Foundation.",
        "0&5K5",
        "w|;A;M",
        "$Sco}",
        "|8B,u",
        "Ja)vT",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477   For a Product with VPN functionality, customization is permitted to allow the inclusion of a bitmap on the left side of the authentication challenge/r",
        ",4cU-N",
        "aR.TK",
        "9BOfV",
        "#pjQ[",
        "v&,A<",
        "qr~r#^b",
        "6df+yJ>",
        "_nwaA",
        "EcA|a",
        "ZJ7y4g",
        "\"xi3j",
        "L2@e-",
        "Iw5v&",
        "zm;}G",
        "IgobQ",
        "Z@<Hl",
        "%s cookie %s=\"%s\" for domain %s, path %s, expire %I64d",
        "?Q8C*J",
        "&%-w:v[",
        "`uFZ8",
        "J5w{,?",
        "[LICENSING] timezone adjusted for date from server",
        "XVnb6",
        "+w\\F)0",
        ":%antv",
        "https://d.symcb.com/cps0%",
        "B33*|{mI",
        ",JYq<",
        "ho.1X@",
        "sar0.",
        "huCZ_",
        "mF24bQC",
        "1\"1_1q1",
        "95:l:",
        "Vqb2x",
        "-dIa+C",
        "i\\BG]",
        "Rdr7oT",
        "gr\"?c",
        "3?$Y3",
        "Stop CPDA service",
        "N6>.-",
        ")i\"xC?",
        "- l\\f",
        "<ZY+Wq8fe,Y",
        "w5% {",
        "~v6`h",
        "7'BYv",
        "'e=^ O",
        "\\f1\\fs20\\insrsid9843574 Check Point\\rquote s shipment of the }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11222717 Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid13256927 , Check}{\\rtlch\\fcs1 \\af1\\afs20 ",
        "=!=q=",
        "3d~3I",
        ")TU1v",
        "Os=w<",
        "GkS>S",
        "H<Pxd",
        "AE8:LN\"",
        "Failed to run MsiGetProperty to retrieve UI Level. assume default",
        "-?qmv",
        "l3:ms",
        "3*3T3_3m3",
        "%ce*U",
        "no publickey",
        "WRa` ",
        "\\HaPZ",
        ":<Oy0",
        "bxR;5;",
        "j,,_<,",
        "FeatureIMSecurity:  Uninstallation of the IMsecurity LSP failed with error code: szUNinstallErrorCode",
        "\\stat_time",
        "j#[(*T",
        "file error",
        "t6j/W",
        "xLYNu",
        "^ IDyw",
        "3&u<\\",
        "Suite B: invalid signature algorithm",
        "707W7g7q7",
        "ik<8xr",
        "[[2yQ",
        "!>|jy.",
        "q~*l]e",
        "*'*'*g+",
        ":s$(g",
        ">??c?",
        "\\3[#[",
        "~v[JiX",
        "|hWY$/",
        "tD_jP",
        "F3alC",
        "AL\\Un",
        "p~KVj",
        "\\zonelabs\\ZLUpdate.dll",
        "v=ItA",
        "*^a,b",
        "l7aBM",
        "9?:\\:b:l:",
        "rxRBW_",
        "7CW/k",
        "fHh$;",
        "FPq{D",
        "QTJ/\\#",
        "+0hAO",
        "&5ffb",
        "2M[>8",
        "9J:q:",
        "y%kV2A",
        "b7}&@",
        "KEgoe",
        "L$ Q3",
        "0,0G0R0k0",
        "D$$9D$",
        "^>Ik\"",
        "Plugins::UnregisterFW:  Unregistration successful.",
        "type=\"FromEndpoint\"",
        "_2uKd",
        "es-pe",
        "DefPolExtract_rollback started",
        "k#;%\"*",
        "Rh,[ey-",
        ">(?5???_?",
        "^/|EdD",
        "q~( 'J",
        "Oo:])",
        "xM}T ",
        "/mD^Bxy",
        "#63Y'",
        "<3=>=b=n=",
        "fVUpL{&",
        "7[E?Z",
        " ~$n|M5",
        "ctQ:8",
        "]@lpS",
        "7jy/?",
        "vk#2N",
        "7'7P7g7p7",
        "\\par }}{\\*\\aftnsep \\ltrpar \\pard\\plain \\ltrpar\\ql \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid15298478 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {",
        "7,7x7%8",
        ":N;S;",
        "FLUSH",
        "H#^D74@",
        "{HPD ",
        "Bi/\"*",
        "W-yX{",
        "v2Cw_r7",
        "xm8NG",
        "ieK$w",
        "dkn1w8",
        "<A?m%",
        "c\":at",
        " 1Rd|1\\\"",
        "-lK,7",
        "OAUTHBEARER",
        "bWcu|",
        " (QX&",
        "F-r_)",
        "R@i$l",
        "KM9bK",
        ")jn]K",
        "Failed to convert number into string.",
        "pLYW2",
        "\\\\VPM",
        "QMWihD=",
        "NX6u<",
        "1#2A2`2",
        "h_}7v",
        ">^//q^//q",
        "bS11*?",
        "jkfHF",
        "p5boD",
        "sk5a^",
        "~nL:2",
        "pi&A6",
        "IJ8zb?",
        ";C}C~C",
        "Xd+{'",
        "~EU\\hR^gT!",
        "U/)<e",
        "H(/o3",
        "[{>?~",
        "QL\\!m",
        "@Y<M,FV",
        "V8_[^",
        "Ph`U\"",
        "JTL&08",
        "jnpT+",
        "9\":R:",
        "Q%$&,N",
        "R9x\"!",
        "WIX_DIR_COMMON_VIDEO",
        "Z9d$.",
        "j_ATs",
        "ASN1_item_unpack",
        " a m6",
        ":Q]`'",
        " IL2c",
        "c|'Y=i",
        "`F*SV",
        ";,|VJ",
        "T\"XYu ",
        "nu`}d",
        "Content-Type: multipart/mixed; boundary=%s",
        "=N?;3",
        "3hvs,",
        "sas;.*",
        "*]qNY_",
        "NpXEB'",
        "jyjhj ",
        ">'>E>L>l>",
        "3]|b?s_",
        "\\{u+e:",
        ">0t<Nj0X",
        "sA{xC?",
        "Df:wv",
        "GetNamedSecurityInfoW",
        "/h+;\\",
        "X%>V(",
        "7Um?M6",
        "eVJ\"T",
        "[XI0+`",
        "?lg^|",
        "5Zr[%o",
        "/GvJ,",
        "\\}`v]r",
        "I&@M.,",
        "o<m%?",
        "Turning off protection",
        "a*sN^",
        "S'=>k",
        "+etxh",
        "849;9p<)>1>\\>c>",
        "2R2m2",
        "&{C8*",
        "`{Pv3",
        "-S)*4",
        "<kZiH9",
        "D$@PWU",
        "2yU8_",
        "= =$=4=8=",
        "/\"w,~",
        "}^,C]",
        "]I_^~k",
        "X9]S~",
        "msEFS",
        "pB-?A",
        "cH#GNN",
        "]R9~m",
        "8sZf2\\/",
        "HDGXX",
        "G9.s.",
        "8\"`DS/2",
        "jbS'l",
        ";]P7w",
        "'\\n>I",
        "Ns_3&",
        ",fli1y-",
        "HdRa{",
        "$;lqu0",
        "m&$LL",
        "[R11D",
        "262z2",
        "VO(gT!`6",
        "o8Q@)",
        "m|~@\"",
        "O5eiRcH",
        "~\\>/$",
        "32a423279a668bb6690c7e9956e90cfe766cb37b077538abd27a8b1cba48c80acc2a841f12e698f13a9e281c57911ce298950d7e03aba84ac8c154f8655c4f2a",
        ">XXt_Q",
        "n[2 c",
        "documentTitle",
        "op{Bg",
        "tiY\\}V",
        "set-brand-Diners",
        "YCqzS",
        "8i-d ",
        "mzjNV6>",
        "61z$o",
        "chinese",
        "<wT,6",
        "RSA-NP-MD5",
        "~FC OT",
        "Pt7dT",
        "798O8",
        "?.?6?=?V?o?w?~?",
        "z|)Bb",
        "Bby2r",
        "pF(qYZ",
        "e+#X(",
        "BYTE MACRO",
        "%VdGW",
        "Q1\"q'&{",
        "=b>.?",
        "t]m\"a",
        "AQ(jE-",
        "!U\\i(p",
        "QX2& n",
        "AdminMode.bat",
        "c8KhP",
        "N+!4[*",
        "o;WW$^",
        "Tq.aD",
        "q'O>E",
        "STATUS",
        "3-3G3",
        "DTBW\"'",
        "G`{PH7",
        "g&NQ7",
        "PWWWWWWWWj",
        "+0J0O0",
        "#%DhB\"",
        "8!8-8p8w8",
        "F0Y*u",
        "fFT1wV5p",
        "p8t8x8|8",
        "FeatureAntiVirus:  RemoveAfter finished.",
        "%'Ddl",
        "> >$>0>8><>H>P>T>`>h>l>x>",
        "W%kDh",
        "u81_3",
        "PVVj\"V",
        "d)Pet ",
        "!n`:`",
        "dbv5[",
        "20AN?",
        "cdcecfcg",
        "Pxvg@",
        "7(7H7P7X7`7h7p7|7",
        "091i1u1",
        "set timeouts for state %d; Total %ld, retry %d maxtry %d",
        "g)94tz",
        "Pq\\_JM",
        "0V1x3",
        "I)R48",
        "5WjF|",
        "qo\\Lm",
        "|qzU*",
        ".?AVtoo_many_args@io@boost@@",
        "Rwl.)",
        "failed to open registry key",
        "+At #~X",
        "4*O`a)",
        "4e(>5",
        "@8+KD",
        "62d;~$",
        "$;WsX",
        "tt%%-",
        ">Tq!N",
        ".?AVILogReleaseCallback@IswLog@@",
        "&g0Qa",
        "&6l&N",
        "^uA}t",
        "GetBladeRequiredDiskSpace: MsiViewFetch faile on Component: %s ERROR: %d",
        "GetSystemTimeAsFileTime",
        "&T^C&@qq",
        "929N9j9",
        "zdl=Z",
        "=g^giT",
        "yJeFj4m",
        "=d=j=w=",
        "^,v9u",
        "8xy~N",
        "\\zonelabs\\avsys\\kave.dll",
        "Ib~30",
        "?!?2?C?N?",
        "< <(<<<D<X<`<t<|<",
        "*^XtI",
        "tVD)g",
        "RKKwY",
        "\"`+oQ",
        "|')K<Y",
        "(wLK`",
        "revocationDate",
        ";K<Z<",
        "r?_!h",
        "*vo4?G[",
        "Failed to allocate memory for previous privileges.",
        "vsdatant driver is installed",
        "T00`P",
        "NJ_g@*",
        "&^\":@",
        "SOFTWARE\\KasperskyLab\\InstalledProducts\\Kaspersky Anti-Virus Personal",
        "IJ;Ml",
        "3)-<7BE",
        "@5Qx=oQ",
        "#1}0&2",
        "F:t,LX),Cf",
        "enc_key",
        "?jhid",
        "h-z4?ji(",
        "TL-sX*K",
        "Q8fi{Z",
        "H,1E&O",
        "Ly_#R",
        "LanmanWorkstation",
        "? ?0?4?8?<?@?H?`?p?t?",
        "VyuCi-",
        ">F>s>",
        "0#D`|",
        "/!P~Vq}",
        "c':t9",
        "Private-Key: (%d bit)",
        "hnB[U",
        "<8 S5^Yn6IbP",
        "%$&D&T&",
        "`{EGx",
        "d\\j:9",
        "PX2lLz",
        "6P7V7",
        "ICX3u2",
        "Too many links",
        "_L=q-",
        "p+b?s",
        "Version %d.%d found. Proceed with patching.",
        ",qw0+",
        "H`r<3",
        "cfX0,}U",
        "LX\"HXX~",
        "g\\>*x",
        "vFmE5",
        "S(x/n",
        "+|(1=",
        "}T9<'",
        "?3?@?R?j?t?",
        "9p1/G",
        "y!z\\~y.",
        "#mxA>/",
        "1*1c1",
        "JIZ*ZWr",
        "G>]d=",
        "{g_so",
        "4c=m%P",
        "H'MYeCt",
        "hResult",
        "Uw#@R",
        "i`^r_",
        "fVAOc",
        "EY:l/",
        "r99Kr99K",
        "StopEFRService ended.",
        "s7SIJX",
        "|xUaH~",
        "gR4Dcn",
        "g[Z%-`l",
        "30$XY>",
        "FXV+z!",
        "Basis Type: %s",
        "o-%|w",
        "Wqj%8",
        "Jlwb<$",
        "3g4z475J5",
        "/92&~",
        "}=Y?F",
        "y.*w(",
        "<19})<",
        "gV.6w",
        "3\\$T3",
        "d 7QB5",
        "Pp81*",
        "B&Cg;e",
        "E8zup4{i",
        "3(394K4v4",
        "#4*Qj",
        "*g|`uz",
        "+x6$u",
        "DN(j4n",
        "POLICY_CONSTRAINTS",
        "i!5$<",
        "Ko&@jm",
        "N8(P!",
        " {0=!cE",
        "i(>V}I",
        "jijkj",
        "2%2v2{2",
        "klupd_klif_mark",
        "d0H|}",
        "K=/YaZ",
        "3&E+_",
        "8lQoj",
        ";x=8Jr#r@",
        "/_^:t",
        "y=T~r'T",
        "d)&lc",
        "9hNdo",
        "VvCF`e",
        "R5>P[\"J",
        "ZASd'N+",
        "An installer error occured.",
        "y.ji6l",
        "[@Zfov",
        "c\"c3YI ",
        "x`M:8",
        "d0[bA",
        "'0,<'",
        "EE5}vw0",
        "5\"grd",
        "rSD42",
        "pOdhp",
        "K7*G?",
        "EUr3BR",
        "LLgo2G",
        "@vsP(",
        "0}0i1",
        "G5J`-r",
        "        Public key OCSP hash: ",
        "%i.%i.%i.%i",
        "%hz|Y",
        "g^{Md",
        "+e#/$W",
        "8K8a8",
        "wBCH?",
        "!qmv(",
        "!]?mr:",
        "3&4I41595J5",
        "3@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "\"HkET",
        "0GcIa",
        "\"[zyF",
        "q.\\D;",
        "triangle.png",
        "0g1u1",
        "7bfrj",
        "Em.zd",
        "OnUpgradeAfter:  logon to vsmon.",
        "a2/b*b",
        "oCpy5\\",
        "2+353?3I3d3",
        "CRtH2",
        ";P3$,",
        "]:s`R",
        "2*2C2\\2u2",
        "'{:2w,mP",
        "[.c/w",
        "Z9@en",
        "6$6,646<6D6L6T6\\6d6l6t6|6",
        "n=[Q>2",
        ":9;<>",
        "J|:,w",
        "yUv/{",
        "d[:FJ06-",
        "A7^S{",
        ";>[[z",
        "unsupported cipher",
        "FD/VH",
        "T=y3gh?5",
        "ADVAPI32.DLL",
        "WIIQ u",
        "'vGUiI",
        "n*z16",
        "r7Yr7=",
        "NoKeepFlag = %c; InnerMSI = %c; UI_Framework = %c; EPC_Default_VPN = %c; SDLEnabled = %c; FixedMAC = %c; ClientSubType = %c; UI_Level = %c; noOfficeMode = %c",
        "kw{oY",
        "yc&(d",
        "no operation set",
        ",g,oS",
        "regsvr32.exe /s \"",
        "StopCipollaService_rollback failed",
        "afI6&:",
        "+w]bv",
        "fw_instdir after the strrchr: %s",
        "r3'm2-",
        ".mY\\6[",
        "A+$Mi",
        "9@*Ok",
        ":F_iz",
        "wWWBTZLI",
        "h#L,8Xc",
        "Xm(37",
        "vs9{U2",
        "SYSTEM\\CurrentControlSet\\services\\vsmon",
        "uq#,u",
        "7I[^@",
        "Bx2dC",
        "6p`XZ",
        "l$$PU",
        "]-'h%",
        "5Jr@{`",
        "SEC_I_NO_LSA_CONTEXT",
        "3$3,343<3D3P3p3x3",
        "$jya8\"",
        "id-cmc-decryptedPOP",
        "SCf?+w",
        "5$sSQ",
        "`$C+gf",
        "2|]0p%M",
        ":YSLJ4",
        "Configure vsconfig.xml to protect both AM E1 and E2",
        "$7QFOh6",
        "\\ufffd",
        "y%k]o",
        "jvjtj'",
        "nH/G&y",
        "y!#V5G)",
        "\\LnC=i",
        "rs]w.\\",
        "EP,F5",
        "173\"A~e",
        "BBF;u",
        "=~*>ez",
        "czZ6~k",
        ";$;@;\\;x;",
        "WIX_DIR_COMMON_DOCUMENTS",
        "I_yXF%",
        "M,V*Z",
        "F7%U1",
        "_b -swm%f",
        "1o:Sc",
        "NS9MJ",
        "w}H3\\",
        "camellia-192-cfb",
        "no index",
        "<!<1<A<G<",
        "wJKtw+",
        "nZ7tC",
        "Failed to get service: %ls",
        "F{2mk",
        "<rnCnw",
        "pbyds",
        ";qlV5eS",
        "gyGyP",
        "p}@%s",
        "xB82{",
        "eHp/g",
        "REQUEST_CERTIFICATE",
        "=O=Z=q=}=",
        "(A7Ml^rAZ",
        ";SYMANTEC",
        "?aDEk",
        "=(=2=<=F=P=Z=d=n=x=",
        "Failed to initialize WixRemoveFoldersEx.",
        "Eki4f",
        "CAST5-CBC",
        "\\dsm @",
        "-~adU}",
        "Rv\\EFw\"",
        "CF3&n+;e!&",
        "2>A< ",
        "5&6>6",
        "b.[08",
        "Y%`_s",
        "AM1Signatures.exe",
        "B|m^v",
        "9J9a9",
        "n-]{tfx",
        "\"z;B*n",
        "zOI`35?.Q",
        "q]+9*i\\HBG=<",
        "nkb\\W",
        "ZLProduct.Identity.Language.Value failed",
        "c'C<h",
        "ihpa~",
        "SEC_E_CERT_EXPIRED",
        "~%L\\ZG",
        "69?|r",
        "8`99:",
        ">1>A>Q>q>",
        "Z>sC,=}=",
        "gJ>h[",
        "4.4G4`4y4",
        "no message",
        "2A3F3Y3h3",
        "Protocol family not supported",
        " wZiK",
        "Z%R%hEgDh",
        "8dNmO(",
        "x+ [jv",
        "4F5\\5",
        "(;a6m",
        "R7$UD",
        "GetFileAttributesExW",
        "iMcb'",
        "R2I_PCI",
        "1M1l1",
        ">+>M>",
        "@[2n|4",
        "ZLl&b",
        "_ur6{P",
        "/x*P2",
        "f!:`g1",
        "GS'7h",
        "khAdE",
        "zMW/zv",
        "n9DO'-",
        "'}\"$w",
        ":kGe+",
        "^8*C:",
        "B[%8x",
        "4+474A4Y4^4",
        "Referer: %s",
        ";\"<4<",
        "*pV{8",
        "%m:nQ",
        "!?/?nB8",
        "5Ix{:",
        ": /H#",
        "TS_RESP_create_response",
        "SYnU1",
        "p6sN7jww",
        "H+:eB>{",
        "Jq.1v",
        "k'5xx0",
        "bwRuJ",
        "j/Yf;",
        "?&?1?<?D?K?R?Y?c?n?y?",
        ";\"cW35",
        "HE0@C",
        "/TmZ.",
        "AGE'N",
        "yV]&W",
        "SRP-RSA-AES-256-CBC-SHA",
        "{T|\"B",
        "]8LPVzc",
        ".?AVsystem_error@std@@",
        "Km2rv",
        "ALLUSERS",
        "-sl8o",
        ".?AVinvalid_operation@Concurrency@@",
        "lw+0#,",
        "\\uBB39",
        "r$.8|#",
        "=&>T>",
        "5.Ih/W",
        "sG5&K",
        "6fSBd",
        "cGcR1",
        ";eH#s",
        "w^VZ8",
        "PPPPPPPP",
        ">-cYd",
        "de-ch",
        ";5;Q;j;",
        "GlobalSign0",
        "F5uZ1",
        "j7X]R",
        "S)h^t",
        "$b`wF",
        "w>O(>W",
        "5<Cu/",
        "S.w+V}",
        "O(}J[",
        "o/X)8",
        "y[p1A",
        "iyf(.?",
        "A5$mf",
        "9\"9G9V9`9m9",
        "MKD %s",
        "(fS{ggRcjh",
        "rT#pH:",
        "A|6ID",
        "WpnGG",
        "v\\amy/",
        " n^0Ga",
        "uniqueMember",
        ">;'v/,",
        "0)0Z0_0i0s0}0",
        "|I;:B",
        "RjS\"HiWQtx:f`",
        "fdP 2%",
        "*iHij",
        "#gMv\\Z/",
        "?oi*q",
        "0_^[]",
        "PJV^&",
        "L$T3L$<",
        ";=\\NN",
        ">=?C?",
        "DNpZR'",
        "bn+?l",
        "-<zTX",
        "AA#i~",
        "VhD< ",
        "Zad#'X",
        "+  nd",
        "!=UUU",
        "\\-c|V",
        "L&&jL&&jl66Zl66Z~??A~??A",
        "VOu_at",
        "Hc:MF",
        "CurrentProcessMemory::Protect(addr=%p size=%d prot=%d) failed with error=%d",
        "pCq\"f&",
        "Vl, aJ",
        "jbqr2\"N",
        "Access denied to remote resource",
        "(U_JT%",
        "8?9?j8",
        ">D?W?a?",
        "Unable to remove dump callback handler",
        "UHnA*",
        "1sDl8",
        " c=ep",
        "HandleSDLSupport",
        "!yhSN",
        "JZFV-",
        ">,Xi.",
        "&v#vQ",
        "\\$HVS",
        "]nepy $p,",
        "I}uiE",
        "xQ6ofI",
        "crcsct",
        "0I+><",
        "k\"x8T",
        "jnjxj&",
        "3D$D3D$@3",
        "FDE_Install end.",
        "j3X8M",
        "eZlX6",
        "yHW/&",
        "!3`NH",
        "O,u_]>",
        "3`W7w&",
        "Jve(5",
        "Uninstall in progress",
        "<)^]/{oM",
        "SchedFirewallExceptionsInstall",
        "7H7X7d7l7",
        "Product ID",
        "Ph<Z\"",
        "TD`uYC",
        ">7>J>",
        "<{xyY",
        "OzFSU",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\DeviceAuxiliaryFramework",
        "oO0>F",
        "jAjej*",
        "u]ht)",
        "CryptCATAdminAcquireContext",
        "a'PT3l",
        ",+N9\\",
        "$WUsP",
        "DH_generate_key",
        "i%v!jb",
        "~sA'^",
        "OCSP_basic_add1_status",
        "c;Sky",
        "apM'p",
        ".\\crypto\\engine\\tb_pkmeth.c",
        "{x#/'",
        "cVc|A",
        "%SystemRoot%\\MEMORY.DMP",
        ":3:W:",
        "a|;v'",
        "6'6,6",
        "B 6$&",
        "2U2r2",
        "y2_.G",
        ";e=#EL",
        "sX+Ui",
        "G,L)l",
        "OnInstallDriverReboot.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "jAjfj(",
        "KJ+Hj",
        "|\"ED=",
        "EPAM_Uninstall temp.",
        ".0&L*",
        "v)d3;7",
        ">+>A>W>m>",
        "%<@(M$",
        "_Yd>M",
        "?45nr",
        "4[MBo",
        "AUTHENTICATION",
        "C4YBkSa",
        "Mh0aF",
        "built on: reproducible build, date unspecified",
        "5GRR*",
        "Z.x]l}u",
        "Te !'",
        "O*'X)q",
        " .s-3s",
        "r+w[H",
        "T5TuT",
        "6K>'bL",
        "zfAmz",
        "V:|`0?",
        "T$P#L$h",
        "1!10181D1U1\\1",
        "endpointConnected.png",
        ">]>g>",
        ".K=\"=",
        "48?*^",
        "Z+xa;",
        "england",
        "lOtoV",
        "w9c:E",
        "yM#Z$",
        ")Z~;7",
        "QV!Au",
        "')`6Y&",
        "ZQD?C",
        "l,\\y[",
        "3+4a4",
        "FP!*x",
        "Yb6N4",
        "_)x|f*",
        ">wGd5",
        "fgO;D#",
        "7.8y<H=",
        "Installation Database",
        ")1*q*?'",
        "R&~T>K",
        "i5E10",
        "Failed to get process token.",
        "j]xLPm`*",
        "QhdQPq",
        "Vj)n,",
        "CleanUIFramework",
        "cd dKx",
        "T7'9N",
        "vcq}|!",
        "5H5R5z5",
        "#L$(#",
        "+_^OC",
        "w;dXMP",
        "?m0m40",
        "Out of file descriptors",
        "error with the srp params",
        "\\rsid14681161\\rsid14765360\\rsid14811648\\rsid14833988\\rsid14842029\\rsid14887030\\rsid14888499\\rsid14896606\\rsid14943329\\rsid15025907\\rsid15092562\\rsid15147522\\rsid15158512\\rsid15169477\\rsid15231522\\rsid15291811\\rsid15298478\\rsid15343697\\rsid15365936",
        "|GWlL(po",
        "-\\0C?",
        "hrc9?",
        "8$808P8\\8|8",
        "=CF#v",
        "9fI79",
        "^Brd{6",
        "E>=u~,)",
        "BwV*U",
        "=<(hJ",
        "YuRnV",
        ">KBIy",
        "ZP%BJ",
        "7C8O8`8i8",
        "\\$(UVW",
        "Remove",
        "qAUM0",
        "D$PUVW",
        "-0J>f",
        "kHy?S",
        "SetVnaInstallProperty",
        "M[3 mH",
        "Sx=\"9",
        "!CWnc",
        "8R}/9{",
        "y;['Yv",
        "e0lUb",
        "'/]O&2",
        "f]&(7",
        "f'8gLW6[oQ",
        "dP/Yrs",
        "W`;4or",
        "2Y6)ix",
        "_V!3,{",
        "DWP{s",
        "-14Su7",
        "]yDXY",
        "p\"#%XxP",
        "TIfG!",
        "!a8Yw",
        "_<M|\\(",
        "`K0t\"",
        "DnF>y",
        "!ibu{6",
        "a0A2g2",
        "F+&{$",
        "RC2_MAGIC_TO_METH",
        "'3J%'",
        "XL|p&",
        "34W:jr",
        "g\"8P8",
        "/=hIN",
        "|H8m-e",
        "r}S6{",
        "4qKv-R",
        "1cLmY*z",
        ":}Hu2qO>i",
        "js2JT",
        "keys not set",
        "~L)t{8[!Q",
        "Z~#rP9h",
        "\\BE\"4",
        "ur}ss",
        "t0Q<D",
        "sb':?",
        "Ms.pDp]_",
        "M/Im8",
        "s(07t",
        "!p.32J",
        " 0xea",
        "7d\\v!",
        "D$(Ph",
        "SCRemoveBefore.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "m_h@$",
        "vU?Gqaq",
        "9|*&I",
        "REOyA$&v",
        "_O!u:",
        "%Uz\"0",
        "VSInstallerLogonEx(%08x)",
        "0_0_0_0",
        "w10@oj",
        ";*<j<",
        "SSL_set_trust",
        "CreateCompatibleBitmap",
        "E;D%i",
        "ID_FINISH_ERROR_STRING",
        "w,D[6;",
        "x,N^x",
        "}\\i!dJ^.",
        "@Sy^1>",
        "s5gA&(",
        "W^m1Z",
        "Asa\"B",
        "J&ygs\\#J",
        "$/Zp'",
        "JjTX;",
        "CMS_RECIPIENTINFO_KEKRI_DECRYPT",
        "=23Y[q",
        "zFapw!",
        "D2%ub",
        "W cdt",
        "content type not compressed data",
        "+gX\"a",
        "RQI61:",
        "pJhUx",
        "c}YQ>5C",
        "{jK\\<b",
        "}cyF/7",
        ".$$dS7",
        "UPr$oM",
        "337#b3",
        "XR?+o",
        "cQm<s",
        "O'xz.",
        "jcP!K",
        "Comments=",
        "QK2oN",
        ".[>R)",
        "anQ5Z",
        "0=m^G6",
        "bad srp g length",
        "PEM_read_bio",
        "cxcBZ",
        "sO<G_@",
        "%tY=/",
        "WJ:3C",
        "tvencryptlog",
        "S707:",
        "Ne{CL1",
        "9F sd;^",
        " 0xf6",
        "bKh=k",
        "ya<<4u",
        "pIb==",
        "v;3-'",
        "Kk4dP",
        "FYFWe-](",
        "%M VjN",
        "Kaspersky publisher exists",
        "_1Va#",
        "0^1w1",
        "}\"oMh:a",
        "^NGdk",
        "|6'au",
        "Whr=\"",
        "91979K9S9",
        "=K=S=b=",
        "8%888",
        "<A<]<",
        "p\\f_J",
        "a!Y>6",
        "GetTempPathA",
        "oKXIOu",
        ";8;X;x;",
        "!^}G1j",
        "ZLProduct.Features.pFeature[2].Version failed",
        "wixca",
        "3'3B3b3",
        "T$83L$0",
        "EVGgi",
        "RE1!=",
        ">(>8><>L>P>\\>l>",
        "404E4J4e4r4w4",
        "^Q\\uI*",
        "CnJ@E",
        "Q=i])=",
        "r++kmZN~v",
        "sRzIg",
        "S0+oHI",
        "9*9h9}9",
        "wGvx%",
        "CIV]5",
        "'FA`%7|'I",
        ":=h S/>k",
        ")T4IH8",
        "odF!)",
        "R7xzF",
        ">\"?T?",
        "%@Xam",
        "t>~!f",
        "+G`Z{G",
        "FWUpgradeAfter",
        "0v1XE",
        "dBd=5r",
        ";2u};",
        "eFeG7H",
        "=>>H>a>f>",
        ";%;1;S;",
        "8o<2a",
        "5L/aX",
        "PM*NJ",
        "oB(\"2)C",
        ">X?x?",
        "5L{?*D[",
        "ScvProxy64bit.reg.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "cvN=l",
        "3in>CrQKt",
        "Ilp@]",
        "n\"OTb",
        "PFR2Hj",
        "ts!s)s1s9sAsIsQs",
        "8H9L9P9T9X9\\9",
        "g\\4Sz",
        "=<=P=X=`=h=p=|=",
        ">$>O?",
        "*V\\N('",
        "%`7#>",
        "NT)D$",
        "_Pk0[",
        "3/}fZ",
        "nsDataType",
        ">LcDm",
        "no inverse",
        "526v6",
        ";?;G;{;",
        "?YZt3M^4",
        "E@AP,#LD",
        "]y>MGNy",
        "session id context uninitialized",
        "cIFj,'",
        "Ar|:J",
        "<(<4<@<L<X<d<p<|<",
        "i.?po",
        "6`1MO7",
        "Jm*UlsO",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\msidirectory.cpp",
        "IHkM)&kj",
        "^|p!Ju",
        "E4`A]",
        "F*BE<",
        "\\zonelabs\\srescan.dll",
        "fVOX6",
        "6(686D6P6\\6h6t6",
        "{6X(q",
        "X(} D",
        "\\!^*5MF",
        "x|\\dF(",
        "q19n2",
        "D$,QP",
        "GaXGR",
        "jlsr+'",
        ",^XIa",
        "Y#'ET+",
        "0#rh>N",
        "Qhh@%",
        "x*_1xEq",
        ":G;q;",
        "(mzd7",
        "6 6$6(6,60646",
        ")bP3L",
        "3N;t$,",
        "ou}lN",
        "DyK(n\\6w",
        "`generic-class-parameter-",
        "sY~x/9",
        "liW8n",
        ">\\lu+",
        "@R^<<",
        "NX95#t",
        "H*3?'",
        "K5wPx",
        "F&Tx@Z",
        "oq0~!",
        "Ah}U9",
        "-;P}9}",
        "HC')~Go",
        "344B4|4/5=5f5+696a6",
        "t:84`",
        "pH?B}p",
        "H0*A[",
        "6GP0Tr",
        "no link",
        "hZDrHI",
        ">*>C>K>T>]>n>",
        "6oQxI",
        "^n@({",
        "1.2E2e2",
        "TracSrvWrapper.exe",
        ":PAR!",
        "cvnU*k",
        "m/IYIl",
        "?$?0?8?P?X?d?",
        "](z8A",
        "20' R",
        ".S*+br}",
        "-C'kW",
        "1ora:Z",
        "Hostname '%s' was found in DNS cache",
        "Wy?0:",
        " 0x61",
        "5*5v5",
        "4VNz~'(",
        "4/4L4",
        "o>Q`T",
        "D$4[_^",
        "3|$,1",
        "L:T$X",
        "R/f!lNv",
        "{pExy",
        "hHa]oe",
        "6iZJB",
        "4 5^5d5",
        ">5FVD",
        "W`&N2",
        "D$@PU",
        "1Mv_9",
        "aDS;7",
        "\\B.8>",
        "6> 1q",
        "Nn1W(",
        "jvjoj",
        "6%&2`",
        "|w):0",
        "tZhP8",
        "? ?9?R?k?",
        "h+1t93",
        "D7QLd",
        "DzI~{n",
        "|^)47-&n",
        "h`-!]9K",
        "^P5DZ",
        "|NaVEa",
        "h!D_e",
        "g[:,+c~Z13D",
        "T(2Rdi",
        "D&e7r",
        ":uq~z.",
        "kQ')w",
        "0Y85[",
        "JUc=I0U",
        "D$$Wj",
        "/k0s5",
        " %qLN^",
        "\"oN!f",
        "%I/9U:^M",
        "A:dtK",
        "Z]{35{p",
        "*l`zOL^",
        "O|!-_",
        "?ijcJ",
        "9E{H:",
        "CANT_GET_MUTEX_FOR_LOG",
        ":\":8:U:`:g:",
        "3+&%:",
        "5);BgVa5*s",
        "hrwX-",
        "1rQ$i",
        "P 2:>",
        "cIQ3 ",
        "7C7f7h8",
        "<NACx",
        "7ELaA",
        "DkMq^",
        ",bjsD",
        "iH,t/",
        "7X7h7s7",
        ",$52d",
        "bmPNz\\",
        "~\\h^t9.-",
        "W<a;%D",
        "o&]u!Q",
        "^WU>&",
        "N&m=\"",
        "*}QG`",
        "UBO]T(",
        "SecureClient",
        "`C=JBZ",
        "|5>\"B",
        "RSA-SHA512",
        "e85q{",
        "lq*54O",
        "l%4/S",
        "3|$$1",
        "@KP:D",
        "|'me4P",
        "2l<x:;",
        "[]y#@.-",
        "}nGe%",
        "j Ief",
        "<xl)u*h 08",
        "bits too small",
        "4.4:4H4Q4^4o4",
        "T}u=b",
        "BqI_g0",
        "mEop6",
        "<6=f=",
        "-_ 3K",
        "wKy,gr",
        "Q^E0]",
        "I#iUj",
        "!TglI?",
        "GQ_h+",
        "xz4$:",
        "MO+{'",
        "cm,Bv",
        "0,1`1h1z1",
        "=A>g>x>",
        "K9efb",
        ";0;<;\\;h;p;",
        "`y0]L",
        "LJs2%L",
        "P ext",
        "<Oy3Z",
        "GlobalFindAtomW",
        "p\\]AI?",
        "776&M",
        ".}6dI",
        "X\\V(Cp5",
        "FinVT)eL",
        "yoW[vL'mI",
        "g7&D(K",
        "s/$(o",
        "647D7",
        ";[>k>",
        "Afqgt",
        "MG*G*#",
        "h!nDL",
        "6#I*9",
        "WR?Ns",
        ".?AV_Iostream_error_category@std@@",
        "o+$#t",
        "G`?;.{!",
        "0<eSuH",
        "6&&9M",
        "Microsoft Local Key set",
        "D}JBy",
        ":!:<:",
        "cksGz",
        "OLE32.dll",
        "ne?&Y",
        "jkjoj%",
        "dt(:Z",
        "GR)>7|",
        "kkc&\\",
        "='=g=n=z=",
        "]RhHjX",
        "a5j_5W",
        "GD%q/",
        "T1!~({",
        "^%h%n%",
        "InstPrep.exe doesn't exist.",
        ":0806",
        "dNg24/",
        "KR8wD",
        "I5/c8we?",
        "c45SD",
        "x_N#~",
        "jjjpj",
        "q9l=4",
        "%Tg{u",
        ">:>V>{>",
        "F8F[6",
        "<s+hY'",
        "ec_GFp_simple_points_make_affine",
        "<#=_>",
        "Removing policies from: %s. Result: %x",
        "tvdebugcategories",
        "c%?\"~",
        "g1<ymJ",
        "'0A&i",
        "K1UGu%D",
        "u=Oq!iP",
        ",G3~5",
        "erF|PSW",
        "G%eRAa",
        "M'ka;7A",
        "F<7% [9",
        "<hU3sC",
        "z*saQ",
        "\"?wtyo",
        "IH:4z",
        "LjuAL",
        "/~O^vJw",
        "1X>2-",
        "J,ss6",
        "W>+Gl",
        "!?0TlZ!",
        "R9}2%",
        "ZQ\"H+",
        "m{,ql",
        "!WCmB",
        "X?BLf",
        "]+fZt",
        "C*Jn||",
        "!-dhD",
        "VPh@3M",
        "ssl2-md5",
        "jhjxj",
        "E4a}o",
        "ext-ms-win-kernel32-package-current-l1-1-0",
        "2 eC_0",
        "wlzu+",
        "J0\\)!<'",
        "FcU@i",
        "Cannot SEARCH without a query string.",
        "Z2Ad(",
        "l$ VW",
        "(ND,D",
        "yug8r3)",
        "I9cCO",
        "m#W}b",
        "&v[az",
        "|jw.'",
        "2wf0#v",
        "P5X/g",
        "9$9D9L9T9\\9d9l9t9|9",
        "L$,hPn",
        "6!737",
        "0\\3n?",
        "j*gr5m-",
        " !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~",
        "N_^\\j",
        "pP <\"",
        "D=YwV",
        "}%e_3C",
        ".\\crypto\\asn1\\x_long.c",
        "nU0RS",
        "(>qi%R#",
        "$dx)P",
        "ki 3\\&",
        "HaC-T",
        "k2Jw+",
        "%VOL\\1",
        "(-wj2R?X",
        "ve<Z(YmBl/",
        "bad hostname lookup",
        "=$=,=<=H=P=t=|=",
        "api_ms_win_crt_convert_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "*r3Ke",
        "gmc5r",
        "$OB(<",
        "x[L11",
        "6}yni&k",
        "kNGY|(",
        "A`II\\",
        "tO9q~%h,",
        "@/0rePu",
        "(3n&\\",
        ".?AVinvalid_multiple_scheduling@Concurrency@@",
        "Q8vN-M",
        "#j/4b",
        "1e2s2",
        "tmO&S",
        "JZu[!",
        "LFLOW",
        "Failed to get component name",
        "twjiYf;",
        "P%PBd",
        "64;8;<;@;D;H;L;P;T;X;\\;x;|;",
        "U[SxV",
        "xCxSWc",
        "9D?jT",
        "l%;lR",
        "9$9D9P9t9",
        "ud8F@u_",
        "Dj&/K",
        "t$8QR",
        "9|M.1}r",
        "]>*!%",
        "scewtX",
        "<0|o<9",
        "SvQ.Z",
        "q`8FQ",
        "^+I4+=",
        "&ufr?",
        " uER.",
        "0UpkU[]",
        ">/>;>",
        "!hr;r",
        ":f{4@",
        "tTEj{J",
        "3$3,343<3D3L3T3\\3d3z5~5",
        "9(9,9<9@9P9T9d9h9x9|9",
        "****************************** SSOClean ended **********************************",
        "tqWVPUS",
        ";pOkt",
        "uBe2qs",
        "d/}Fr",
        "&>1;y",
        "H]I>J.",
        "A[3t&6P",
        "xE'l26",
        ".YvGP",
        ")#DKj",
        "cms_set1_ias",
        "9D:U:",
        "5JP<j",
        "x=Xeb",
        "|$ SW",
        ";|[dC/",
        "Rl{'`7",
        "Dmt\\bu",
        "eIqdD",
        "#H;&b",
        "+dIK\\:",
        "HD4(%-M",
        "#/UmJ",
        "Eau`I1",
        "D*LQ- ",
        "){O$[",
        ":\"eg |",
        "Q;V9^9d9m9r9{9",
        "pen market at market prices. Any use modification, reproduction, release, performance, display, or disclosure of the Product by any Government shall be governed solely by the terms of this Agreement and shall be prohibited except to the extent expressly p",
        "(];)a5",
        "ABiXs7",
        ")1vd\\;",
        "eo* MK",
        "U>U6*",
        "VgXD3!",
        "QhP7#",
        "lRZw(T",
        "h638Zu",
        "I{~,\"d0kc",
        "5+6y6",
        "2#rL|",
        "ec_wNAF_mul",
        "{X'G*",
        "#P7u6",
        "garbage after data",
        "\\- RT",
        "*2<jp",
        "Setting %s = %s in property table",
        "8Z%frV",
        "3'3E3S3",
        "G\\+G`PWS",
        "iAt\"8",
        "tFB63",
        "syyG0",
        "f^\"qz~}>G",
        "jzjkj",
        "A qki",
        ";sDhdQ",
        "temp\\sdk8\\Cache",
        "=^s;b",
        "`p!)]1X",
        "8&]Nw",
        "EH+Z-",
        "unsupported content type",
        "tM(10=",
        "a~\\&o",
        ")bq,k^;|",
        "3%3-351=f;f",
        "4IsS~",
        ":aIyk",
        ">V!^{J#@^",
        "{i.uK",
        "OO_7,5",
        "D$,PS",
        "Umb4n ]",
        "*yd>^",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 LIMITED WARRANTY, WARRANTY DISCLAIMERS AND LIMITATION OF LIABILITY}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        ".?AVProdRemove@@",
        "[rc*+",
        "?M9]t",
        "{&\"]=",
        " 0xfe",
        "D$,EC;",
        "b&XO3",
        "/oE6;",
        "ewLR#",
        "5 5,5054585<5@5D5H5L5P5T5X5\\5`5d5h5l5p5t5x5|5",
        "_L}A;",
        "'8g$E",
        "%-\\E)F*",
        "868<8G8",
        "uO8x,6w",
        "1b0B7tGKk",
        "s\"nr1",
        "$vOwR7\\",
        "SSL_CHECK_SERVERHELLO_TLSEXT",
        "-EK9\\",
        "~C@pc",
        "O8b4rM",
        "STORE",
        "S~m2C",
        "|(v(i",
        "D$ PW",
        "O*@9.",
        ";f*!\\",
        "C?)n~ q",
        "?K:+p*1",
        "HW]Z-",
        "=3in]C",
        "kCrpJ`",
        "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ",
        "C9d)V",
        "n\"bLV2",
        "8xl~W",
        "[-1S,",
        "SCUIAPI.png",
        "`\"t~z&H",
        ",q{q;",
        "k&G_3",
        "Failed to get previous size of property data string",
        "Q*5@F",
        "$^NB%",
        "boost::filesystem::create_hard_link",
        "SYSTEM\\CurrentControlSet\\Services\\",
        "45<j0H",
        "vw*nqqk",
        "]l+:._N",
        "~\\lV\\",
        "sz:}9",
        "`?d+g",
        "RunClientHotfix Package is not a Client Hotfix.",
        "/5ZN\"&",
        "-mn;h^n",
        "F.P%g",
        "ll7Jk",
        "SV\\}+dx",
        "4(q[oo",
        "ZjPbo",
        ":?:W:",
        "o$wFh",
        "'^XW-",
        "c 3CD4pxUv",
        "49wae",
        "K+n<I",
        "c2hME",
        "BdFWT",
        "IsOpJc",
        ".fh|/",
        "Logical address:  %p %p:%p %s  (%s)",
        "1t$d1|$`",
        "fzVg9`tq",
        "%02X:",
        "strstr",
        "QmRZW",
        "jm<&!",
        ",S,TX",
        "N'WiS",
        "I'i[*",
        "PBE-MD5-DES",
        "@HOzMnw",
        "Otyh ",
        "VACj}",
        "34VkO",
        "(e/Z,b",
        "3k2@U",
        ">CH?F",
        "rMJHM",
        "^yc2F",
        "Camellia for x86 by <appro@openssl.org>",
        "nC5!0E",
        "tR`hO,",
        "ZuU7$",
        "qqJx!",
        "aMjY)l",
        "ECDHE-RSA-RC4-SHA",
        "!5b_>3=",
        "yFYG=",
        "UcoA*",
        "RDTSCP",
        "api_ms_win_crt_locale_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "{vQwG",
        " start date: %.*s",
        "5-52595@5G5M5q5v5",
        "AwEFtZ-",
        "\"w.<7",
        "GetFileSecurityW",
        "#,s,u,w,y,{,}-",
        "Pn6-D",
        "x]'1'",
        "YkeS6",
        "#9Npt",
        "e]:*\"",
        "C(v<0",
        "P4ke|oDZ7",
        "Advapi32.dll",
        "NTGetCanonicalUserID: error 0x%x in LookupAccountSid",
        "|M;`[pR(",
        "K)LUK",
        "LoadLibraryW",
        "5cLJA",
        "public key not rsa",
        "P83QC",
        "Sx6`j",
        "second QueryServiceStatusEx failed: %d",
        "[7kNCi",
        "3T$<3T$43T$ ",
        "\\.[M;",
        "iQ>0!",
        "vjRR!\\",
        "0(snn",
        "*$^zi@1",
        "gzcn_",
        ":8=<=@=D=H=L=P=T=X=\\=h=l=p=t=x=|=",
        "rUl{0",
        "777=7O7f7",
        "Xr}m5",
        "Z!\\O&",
        "5Gzm^FT-",
        "O8n.W",
        "&S?M/",
        "l\\%%en]",
        "8^8tb9^4~]",
        "\\tx1620\\wrapdefault\\aspalpha\\aspnum\\faauto\\outlinelevel7\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs20\\alang1025 \\ltrch\\fcs0 \\i\\f1\\fs20\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 ",
        "V#dk/",
        "=;`^e",
        "1#1Q1n1",
        "7d^.]",
        "cdJ_C",
        "\\OFi*!",
        "3~B'w",
        "sUNQxw2D*I",
        "C+~Od",
        "N^dV/{",
        "g)qGm",
        ">f\"$;",
        "5B!Ll",
        " A'M&>8",
        " UWI;]",
        "connection id is different",
        "F-F5G=",
        "7!7i7",
        "C,H_^u",
        "J/M#%%",
        "Done registering plugins.",
        " 0x28",
        "p{?N;w",
        "gEIkO",
        "britain",
        ")~Qq0",
        "5>$ZL",
        "KI&v6",
        "pW Du",
        "TTLSut",
        "5Q5[5",
        "Usage:",
        ";#;(;C;P;Y;^;c;~;",
        "\"<>|:*?\\/",
        "0AyF+",
        "Zc_6l",
        "7$7,747<7D7L7T7\\7l7t7|7",
        "Y{+xJ",
        "#0gTq",
        "=B1xX",
        "!0q:\"",
        "RwFL7",
        "-r]Q|",
        "a$`5,0",
        "FileTimeToSystemTime",
        "I&g\"=W",
        "RY ,9zo",
        "pmU3M",
        "%*=P ",
        "VrVobO",
        "su8on",
        "<>?<*",
        "RNpB.",
        "eXkdU",
        "'V$WOf",
        "+Dg|l",
        "SQRTPS",
        "]FicP",
        "=<pzzN",
        "OeDjQSG-",
        "gz0p!",
        "'QB=4`",
        "]mINWJ",
        "\\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 . }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid8728152  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 If the}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "Qhu\\``",
        "0$0d0k0w0",
        "id-it-keyPairParamRep",
        "dtls1_send_server_key_exchange",
        "b?+'o",
        "hK&HH",
        "_yV>K",
        "3.3Q3l3",
        "ADH-AES256-SHA256",
        "3dFC`",
        "Host unreachable",
        "|_j\\x",
        "/=&/B",
        "22Lgc",
        "6$7D8o8",
        ">H>s>",
        "(_??^'",
        "\\$ UW",
        "%u %s %X + %X  %2.2X %2.2X %2.2X %2.2X %2.2X",
        "B:$w{^",
        "&{O+Y",
        "iSMbY",
        " !\"#$%&'()*+",
        "u**$A",
        "?.?I?l?v?",
        "mJy]k)u",
        " Asj2d",
        "'Dzc/x",
        "1L1y1",
        "O[ZCR",
        ";9.Q5",
        "G`Oi58",
        "SHA256",
        "kd[Sw-}",
        "9F:^:v:",
        ">$>,>`>p>|>",
        "{KK fc",
        "<=<J<d<q<",
        "LbpES",
        "]KM0Y",
        "KU`|z",
        "_:u2;6",
        "XvS]q",
        "'RN22",
        "} ;p5",
        "1Z\\SOx",
        "NU$``",
        "RHo 1",
        "f]W'/:",
        "Pqk_]",
        "89^sD",
        "Xk7hss",
        "X07R3Q",
        "4p!9|",
        "StopServices ended.",
        "PUggd",
        "@U3!R'",
        "V1wC,`6,",
        "^|ws2",
        "',_Zi=a",
        "#g/=\"",
        ".'If[",
        "?~?\\6",
        "@Yxxf",
        "U]W}%",
        "jljnj",
        "N?X;u}",
        "FWU[~",
        "0lp6-",
        "D$,PP",
        "_p,]l{",
        "j!e. ",
        ")/Y]-",
        "f2X8+{D\\R",
        "&7q ^",
        "[> PT",
        "pbhI7",
        "thahh",
        "Sh I!",
        "veO2y",
        ";MHS1^",
        "Y=Rt/^",
        "heT.h",
        "~+.,W",
        "3'363",
        "T:MyY|",
        "OESEFD",
        "Vn`5NBQZrO",
        "il.O(;",
        "%Y%x<",
        "MS{5;!3_",
        "V\\\"QK",
        "P6Nvy",
        "9|9?AO",
        "33=WA(5",
        "C~[=\\",
        "2H3m3",
        "w3V,wR7p",
        "['MM{",
        "D$$1t$$3",
        "wH'Qv",
        "4-454E4s4",
        "AG`p`",
        "\"C#.F;I",
        "QqIMR",
        "5|p8}",
        "@Z]s@V",
        "UNKNOWN",
        "b1l1}1",
        "V+% B<#",
        "4(4D4T4X4d4t4",
        "Fe&5cL!",
        "r*'sw",
        "ENn1x",
        ";y/nn",
        "jnjlj",
        "RegOpenKey failed: %d",
        "ArchiveLogFile: zipOpen error creating zip %s",
        "3+4;4z4",
        "u2u<M",
        " ]%gw",
        "%o*o.~r",
        "[UNHANDLED EXCEPTION] Recursive call to MSJUnhandledExceptionFilter",
        "brZHHy;",
        "8&8-8W8]8h8",
        ">$>Y>o>}>-?v?",
        "failed to write file to custom action data: %ls",
        "+CG@P",
        "YW4.^",
        "MX5Et3qB]",
        "jCjmj%",
        "^C9\"-",
        "str.ia5",
        "jL8JW",
        ">,zqx",
        ">D3)r",
        "8!AA}",
        "regex_error(error_parse)",
        "EC_ASN1_PARAMETERS2GROUP",
        "PVVj5V",
        ".?AVFairScheduleGroupSegment@details@Concurrency@@",
        "Xk\\bG",
        ">0?d?",
        "3.IBe",
        "id-mod-kea-profile-88",
        "c\"sB0",
        "^:/?o",
        "bvOO}g",
        "signer_info",
        "'#PgE",
        "PP9E u:PPVWP",
        "Bd$_Bg",
        "7#767G7M7",
        "A7@v-o;jB",
        "=??w/w",
        "3`5b?T3u",
        "sO<ee",
        "3\\=bJ",
        "nv3_?",
        "t$03t$ ",
        "'!g!F",
        "$a5ZT",
        "Odlu?",
        "@`:*E",
        "A:g7(l",
        "LOV4k\\\"^",
        "bB?|z",
        "gc)uUwu",
        "UrU%t",
        "5vlcF",
        "-@>v]",
        "0Kd9X:",
        "?I=PU",
        "SO_PATH",
        "7XGuPK",
        "ZJV\\Ma",
        "xRGj}",
        "^0Hy7",
        "v(cQC",
        ")d6z!",
        "VsNoFileRedirect::s_EnableRedirect",
        "<%-oJ-U",
        "??nV:K",
        "$y;GA",
        "?LF,#",
        "N/gSy",
        "7&*WJ",
        "^z]<U|",
        "[f~((",
        "m&.Wm",
        "B ~HfHG",
        "`k.dz",
        ".?AVWaitAnyBlock@details@Concurrency@@",
        "Hv[f(uW",
        "/s5@Dqw",
        "!uB$[)",
        "failed to get third failure action type",
        ".\\QxJ",
        "pd[R$,",
        "4,)7@$",
        "+lY\"9e",
        "id-pda-gender",
        "N'xU$",
        "LB5-s",
        "6#h/R-",
        "l7F.S",
        "LoadResource",
        "C1A5G>C",
        "-w}ru8",
        "5B7c7}7",
        "jAj}j",
        "<j{&Q",
        "&JRH\\+",
        "@`-h1",
        "p`qvG:",
        "no signers",
        "DHE-DSS-DES-CBC3-SHA",
        "q3XLH",
        "sv-FI",
        ";%;@;x;",
        "8)8.848:8@8K8P8U8e8j8o8",
        "@I-\\9",
        "pWseUnregisterPlugin doesn't exist.",
        "pAy5b\\",
        "&`ht;YT",
        "1,141<1D1L1T1\\1d1l1t1|1",
        "{?!^/",
        ".?AV?$sp_counted_impl_pd@PAV?$basic_altstringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@io@boost@@VNo_Op@?$basic_oaltstringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@23@@detail@boost@@",
        "kJM*p",
        "EPAM_InstallRollback started.",
        "rOz@.",
        "%Lp{FqX",
        "}24^G",
        "3jUm)`OM",
        "Q=]%r",
        "BE/cNb",
        "zb4Vf",
        "Eyn,$D",
        "z(&p-",
        "\\4D9}",
        "C$CET",
        "xc/0fAn",
        "7+v!%",
        "};49~*o2",
        "0f2u2V3e3",
        "xzxyx",
        "+Q$?O",
        "7b8R9",
        "MAXIMUM_FILTERS_REACHED",
        "<I<e<",
        "pbwfa",
        "RSA_print",
        "GENERAL_ALLOCATE_PROMPT",
        "q'S|+",
        "S+GVSR>",
        "3 4D4",
        "`nD:;",
        "2(222=2t2~2",
        "|gxdv",
        "@zh]Z",
        "<&Ks~",
        "05wen",
        "yOTR1",
        "}O0PHu",
        "0=P$B",
        "oB}67",
        "ineIuV",
        "9wte|",
        ")R,e,",
        "5C<s;v",
        "4,4:4I4",
        "KOlA.",
        "(#4/rv",
        "es-pr",
        "u7x\\c?lS",
        "lD d8!",
        "&C'BDD5'",
        "7)8R8r8",
        "[PERFMON] error %d loading provider %s",
        "=!>0>9>",
        "LWElq",
        "c4)AT",
        "tvkfNC",
        "mime sig parse error",
        "WSC service status: (%d)",
        "!*.kk",
        ".?AV?$_MallocaArrayHolder@PAVevent@Concurrency@@@details@Concurrency@@",
        "/:+kl",
        "6}d;|",
        "e$cx_",
        "JDnl7|",
        "WIX_SUITE_STORAGE_SERVER",
        "0,0R0|0",
        "~d C{",
        "262`2",
        "Clew~n",
        "o_NnT",
        "0!010l0{0",
        "wP`L!",
        "G]ery9",
        "PBKDF2",
        ";IgYVU",
        "i#ARf",
        "_$z*O",
        "jejjj",
        "PKEY_EC_DERIVE",
        "Er1S<",
        "W2xE<",
        "(ln'b",
        "1;qPu",
        "jAjrj",
        "jA[jZZ+",
        "4l`}?",
        "%$LPS",
        "File too large",
        "2'.F|~H",
        "=.PnM",
        "l4'V6W",
        " rzX&",
        "Pf&pt+Cj",
        "0[n3R)\"",
        "sho\\E",
        "3L$T3L$43L$(",
        "~R2fo",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477 5. }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5000668\\charrsid15169477 T}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 o ship back the faulty }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "a-,;k",
        "<==N=",
        "6A^oS",
        "7~\"[H",
        "%'50\\",
        " Etmod)5",
        "D/A/g1",
        "s prior written approval. Any such approval shall reference a}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1926352 n}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "sha224",
        ":5FtOm>b",
        "2#oe/",
        "{FVtu",
        "8xl*<",
        "<?xml version=\"1.0\"?>",
        "D$(h!",
        "l$tVW",
        "5ob?8",
        "SendMessageTimeoutW",
        "5Aoh/xo",
        "|okOr*nD",
        "D$\\VW",
        "<\"<y=",
        "Lr%,f",
        "Xb?(h=",
        "Y{v[fB",
        "y==S]",
        "V:r,[",
        "Ph4JM",
        "`:UO\"m",
        ":a&N|\"",
        "|M`Kz",
        "7V8[8t8",
        "!Pjcs",
        "bG\"Ayc",
        " 5z[L",
        "4vIQ:",
        "<[Y8)T",
        "v^qvD",
        "D$HQP",
        "E<KuV",
        " HTTP %3d",
        "]`86Z",
        "cjbLS",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\tx2520\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid8205679 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\insrsid7565078\\charrsid5013025 ",
        "F:W1W",
        "db$I9",
        "+S4Cq",
        "-cUSCUU",
        "B9B$T",
        "Ydo$\"",
        "Ip,,Q",
        "jAjoj",
        " zip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll",
        ") b_9",
        "#^6*I2",
        "|\\Ps_",
        "FaJMS",
        "resource deadlock would occur",
        "V'4P@",
        "1&t4}",
        "1W1j1v1",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\calibrary.cpp",
        "_^][3",
        "wO3|t",
        "Backup from ",
        "}Gr^'",
        "JH_np",
        " {juJw",
        "2:YKn",
        " E@s;",
        "s^+9e",
        "h\"4WQ",
        "5bjH^",
        "0;0W0s0",
        ":& @_",
        "444<4D4L4T4\\4d4l4t4|4",
        " %/[;",
        "0@1A2",
        "W`g`*g",
        "b+oNw",
        "H&{!b!",
        "l$8US",
        "{5~l4k",
        ";w-|&",
        "A--P(",
        "my@HN[0",
        "alj<%\"",
        "u,f9F",
        "w3jNv",
        "HW]LI",
        "pl.(b",
        "j?m'm/",
        "deejefb",
        "I!p\\ZI",
        "TYPE=",
        "HJwe(",
        "BxMNt",
        "3B3I3",
        "\\system32\\drivers\\vsdatant.sys",
        "5&565E5T5",
        "vT=dy",
        "oZ.t,y",
        ";$;D;P;p;x;",
        "y+Q5cu",
        "@1{em",
        "Pg*'~",
        "Nh]Y~{",
        "I:!giKIz!",
        "GyZHh",
        "C240Y.b",
        "2'232j2",
        "WLqeB",
        "p4jHh",
        "ASN1_TEMPLATE_EX_D2I",
        "2m-ct5?",
        "7s$\",S5",
        "?q34I7",
        "rp[-Q",
        "Update from local server with old updater detected",
        "_=hVq:o",
        "AUTO_LOAD",
        "~l$,V",
        "8!8=8Y8u8",
        ";n<y<",
        "t$(Wj",
        "D$ SU3",
        "%`GGXe",
        "{@A+L",
        "?&<J*",
        "<GtT}",
        "j'mS]",
        "\\X-U;",
        "OKv-v",
        "`j?3r",
        "l2j:%?",
        "#@HZ(",
        ")BQb9",
        "*Os|Zg",
        "l//n=6",
        "+C.:}",
        "?z[&b@",
        "WTSAPI32.dll",
        "Microsoft Trust List Signing",
        "8H9O9T9^9h9r9|9",
        "x&r?_M",
        "AQ^lf",
        "Y)il-X",
        "_(oPv",
        "AcquireCredentialsHandle",
        "ZJjA-IC&",
        "4Pf)]P",
        "$Y|=~X",
        "`]|b_Dad",
        "(w~s%",
        "^l}9>",
        "=Igti",
        "02Q0M(",
        "d.R=^p",
        "4|mKk",
        "Nbxg6",
        "4{B{k\"mV",
        "s{]:H",
        "sa_addr inet_ntop() failed with errno %d: %s",
        "server write error",
        "#$*uE5",
        "jK4X:vEvww}Q",
        "iyOGkS",
        ";:;D;N;X;b;",
        "=(=0=4=@=H=L=X=`=d=p=x=|=",
        "rb;f'P",
        ":/4!rH",
        "bBa^Y",
        "+~h-n",
        "~n(:d",
        "SEC_E_DOWNGRADE_DETECTED",
        "s=dw#",
        ">K>}>",
        "7]9{k",
        "\\rsid15415134\\rsid15480523\\rsid15533839\\rsid15560429\\rsid15562515\\rsid15742087\\rsid15796939\\rsid15806449\\rsid15807945\\rsid15945664\\rsid16017612\\rsid16059775\\rsid16076773\\rsid16088589\\rsid16139452\\rsid16273898\\rsid16413999\\rsid16457937\\rsid16462323",
        ">N/A`",
        "llcx`",
        "}*#c$",
        "DES(56)",
        "r.Ber",
        "Vy?Va",
        "signature for non signing certificate",
        "SKIP USER: Can't get user's profile path",
        "8w>E-",
        "213[3r3",
        "r8stB)",
        "Q]7~2",
        "%}',I",
        "8;nCU",
        "\\oj{/",
        "S#(\"Oj",
        "<|,aV",
        "5X5\\5`5d5h5l5p5t5x5|5",
        "r4G==",
        "4u6z6",
        "rEwWO6",
        "NcX~Di]",
        "c<//R",
        "5+c>I",
        "QVWhH",
        "D5eMu",
        "1sG'\\leb",
        "%lu:%s:%s:%d:%s",
        "1-1I1e1",
        "uU|KZ",
        "c]k]s]{]]_",
        "N;:|K",
        "pWG)FX",
        "td\"Ahf\"",
        "{h{\\tH",
        "J}\"Lc3",
        "zFopx",
        "kV)kct",
        "Illegal characters found in URL",
        "UO:QW",
        " .uE#>",
        "%g!@7",
        "TQ](wh",
        "hVi'3p4",
        "[%F|Q",
        "%@%H$~",
        "Invalid arguments",
        "2c5<{\"`",
        "Zuw06",
        "pnU7Fk",
        "898W8",
        "\\=2K7]",
        "\\$ U3",
        "0lY3ux",
        "1*1/1:1R1",
        "8X9r9",
        "FB~N^",
        "iPlP~",
        ">XS,7",
        "lm@X4",
        "9J:e:",
        "DH-RSA-SEED-SHA",
        "0!060A0R0[0a0m0w0",
        "QY!fy",
        "gE^P,B",
        "qf+N@b",
        "|f+O>h:64~C",
        "SlpR2C(",
        "&PA..lG",
        "Entering certCryptoAPIVerifyChain",
        ":';W;",
        "@},8U",
        "^Efo(",
        "#1PEW",
        "Ks{<A",
        "8B9b9",
        "=\"=R=",
        "RKu~2",
        "3]jO2",
        "9t<:/",
        "wU.c@",
        "Microsoft Universal Principal Name",
        "VSPWInstPasswordRequired returns:  %d",
        "8&8B8^8z8",
        "5<S9)",
        "?BlB*B",
        "<+p.M",
        "des-ede3-ofb",
        " dHAi$",
        "aGXInm",
        "2fsE,C",
        "QkQW4",
        "*)b7VKAV",
        "kave8.dll.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        ">52,L",
        "JzLj(n",
        "1&1]1",
        "(_2y(",
        ".'^,'",
        "E_HpgA",
        "=x\"Zl!",
        "IgJ\\/",
        "?b?n?",
        "bYDk.?",
        "g-;p1",
        ":4;@;",
        "ecc cert should have rsa signature",
        "E.\\crypto\\cms\\cms_lib.c",
        "@PzZU",
        "D0L0T0\\0d0l0t0|0",
        ".1C_z",
        "(pWHV%",
        "*ue+aV",
        "8d]h`",
        "@G;SU",
        "@b$Sec",
        "CANT_RESTART_ATT_SERVICE",
        "QmVE_)F",
        "<$99*",
        "}`S\\j",
        "%s is not running.",
        "S,oX=<",
        "GoCBJr",
        "gKe@S",
        ":f;x;",
        "gDa$z",
        "id-Gost28147-89-CryptoPro-RIC-1-ParamSet",
        "8#929B9W9u9",
        "H.3M9",
        "2i7QqR",
        "SECUREMOTE",
        ".\\crypto\\rsa\\rsa_x931.c",
        "SC uninstall file will be located in start menu link under: %s",
        "I{&9=",
        "ugyUM",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477  etc.) or a full Unit Replacement.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7039639  ",
        "H?e@S",
        "8,kY'[",
        "d'El-",
        "&sEs; ",
        "rn6 n",
        "=)Xd}s",
        "^FC^t",
        "ol$Dp",
        "byx(r",
        ":'7Kp65",
        "5P5W5f5t5",
        "bgqZN",
        "97*/u",
        "Dd}qm",
        "ZSa`)`",
        "<C=g=",
        "|YI-r",
        "35qnK",
        "zW,1=I",
        "setext-pinSecure",
        ".?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@",
        "upgradekeyset ",
        "c9K{O",
        "VhL; ",
        "&y\\Db",
        "a0wX'\\u",
        "-R\\\"NM",
        "<DtF<[",
        "4y7(Ff",
        "o!xZ:cs",
        "P=J\"^V",
        "%*s<Not Supported>",
        "\\$ UV",
        "hb<S ",
        "Qh9Eo",
        "/K6Iv",
        "o$fD`",
        "0,010D0",
        "hG4^z+",
        "&<5]-",
        "-&$_p9+uh_",
        "mA-A?",
        "V8'Ve]",
        " means (a) You are in the regular business of managing the functionality of the Product for a fee, to entities that are not Your Affiliates (each a \\'93Service Customer\\'94",
        "474P4i4",
        "UpdateZoneAlarmXml:  UpdateZoneAlarmXml started.",
        "oE*V<",
        "#s8mS",
        "V4V+P",
        "wNJU6",
        "\\GceA",
        "jAjqj\"",
        "LE6rg6",
        "vW1-4B",
        "JqQM-:'",
        "Lbq$XW",
        "PKCS7_verify failed",
        "M`F8KQeH",
        "-G,!!",
        "r/?Ob",
        "LookupPrivilegeValueA",
        "VTtmDj",
        "oxOda",
        "\"Tnj5",
        "Qh`|&",
        "jhjoj'",
        "BN_TO_FELEM",
        "141@1`1h1p1x1",
        "qD_R%^8",
        "YH*`h",
        "EPS_INSTALLED",
        "+DmP|>",
        "vfxLZ",
        ".?AV?$_Mpunct@D@std@@",
        "l*7,5",
        "; ;$;(;,;0;4;<;T;d;h;x;|;",
        "%Xw;%",
        "fj;QiN_",
        " AND ",
        "Q&sS<",
        "RiqjB;fzdA",
        "R!qIe",
        "cTJer",
        "Re-allocated memory for a big registry value from ",
        "A2VPD",
        "yz74T,",
        "%HUi~",
        "|$$3x",
        "?\"?>?Z?v?",
        "failed to allocate memory for new xml file change list element",
        "[|D,D",
        "s3Rfy",
        "DlNDo",
        "7D7e7",
        "n]4|[",
        "4$4,4<4L4T4\\4d4l4t4|4",
        "T[[eP",
        "#RV[bN",
        "PG'{(",
        "= =(=,=8=@=D=P=X=\\=h=p=t=",
        "CompStopComplianceService",
        "jN0:}",
        "kx~s@",
        "This Agreement is effective until terminated. Check Point may terminate this Agreement upon Your breach of any of the provisions hereof that is not cured within thirty (30) days. This A",
        "?%PoT",
        "I$I0Iv",
        "XbA]-",
        "+Hl;~",
        "wH&j>",
        "VMSAVE",
        "l%B(J",
        ";?;o;",
        " MvOY",
        ".qN[2",
        "CurrentBuildNumber",
        "4#yH|$",
        "2h(o&",
        ".Bd,>J",
        "8qjh*",
        "5$Tw)",
        "f:/?=",
        "0jFNi",
        "l$,;l$",
        "Vsdatant_epk_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        ":QhMh",
        "Qh0|&",
        "080=0",
        "NISTP224_PRE_COMP_NEW",
        "M>9if",
        "TAs_7",
        "JygBK",
        "3B3I3c3",
        "8A}TO",
        "'quQXWenI",
        " F*]~",
        "N8/JGbQ",
        "b2Ddr",
        "708P8u8",
        "mb[&[",
        ">;DzVtW<",
        "r.qNL",
        "3tl`lHl`",
        "vIt\"4",
        "xbzp|p",
        "xBj?U",
        ">~o#*",
        "Yy<\"F",
        "aHWYD",
        " didn't stop in 10 seconds.",
        "`<(u\\",
        "jg)R;t",
        "=6=O=V=",
        "9#:_:",
        ".?AVIBase@@",
        "OXA3R",
        "a%2?:",
        "M\\Ao-",
        "M5_G+",
        "L~!QH",
        "pQx~/",
        "}Yl=p",
        "lO6H4",
        "Dgo|D",
        "j6]zP",
        ".?AVpcharNode@@",
        ":+;2;L;y;",
        "D6FrAA",
        ",B.l0",
        "JL<J)",
        "b6QgJO",
        "error_connection.png",
        "nk0HI",
        "sv-SE",
        "*.0t#",
        "g|Y=@",
        "test.cpp",
        "L$8SU",
        "<vaZf",
        "9[$7M",
        "ec_GFp_nistp521_group_set_curve",
        "private key encode error",
        "c,Z*a",
        "6$7q7",
        "b&LQQ",
        "y%<S9",
        "3Dzhg",
        "System\\CurrentControlSet\\Services\\vsdatant",
        "5+5i5o5x5",
        "t.SSSS",
        "[l!lp",
        "rwx-tTsS",
        "5,545<5h5p5",
        "7#mVn9",
        "%O$RI",
        "faqnUt)",
        "SHOWTUTORIAL",
        "}q?l}",
        "deVJu",
        "2%wLy",
        "fK08Y%",
        "+1i^V",
        " Subject to the terms and conditions of this Agreement, and payment of the applicable Product fees, Check Point hereby grants only to You, a non-exclusive, non-sublicensable, non-transferable perpetual license (with th",
        " 0x9a",
        "l=krv",
        "jAj|j!",
        "oU-Yhi",
        "7dddd",
        "BIO_MAKE_PAIR",
        "Ohl5 nU",
        "?<?K?",
        "|Ggsy",
        "|sV|8k",
        "ec_GF2m_simple_oct2point",
        "!&C0L1",
        "gj4H$.",
        "K 1DGqj",
        "c'rbK",
        "x`E~V",
        "~GH8)",
        "`I6` ",
        "SDK will be clean installed or upgraded",
        "=$>6>>>X>",
        "AddMitigationOptionsRegValue: exception caught.",
        "ObAB6",
        "[3mR;",
        "+ua{a:c",
        "|'iYi,",
        "dR.y#E",
        "EC lib",
        "+lD5f",
        ">yh[`'b0f",
        "wzk7*",
        "3 3,3L3X3x3",
        "i?O*z",
        "e=\\vb;",
        "3333;",
        "[q+V$5",
        "w&wFw",
        "Q)NNpY=0",
        "lq~-\\<",
        "|[9Xj",
        "5t`W]i",
        "&.1fg",
        "r:5&[",
        "OeQvU",
        "8?u'@",
        "jisW{",
        "^CF1r",
        "A#CFDM",
        "6,j#*@",
        "om time to time, at its sole discretion, Check Point grants You a non-transferable and non-exclusive license to use the Beta Product for evaluation purposes only. The }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13173947 l}{",
        "6%7+7v7",
        "o9DO6",
        "y5;1|",
        "DES-EDE3-CFB1",
        "?.?@?I?N?W?i?",
        "727G7L7X7h7r7",
        "2HK4-",
        "N9TiXZhrEu",
        "R4,Bm9i",
        "RzrDc\"fw",
        ".1?C$",
        "U{c.#",
        "95l=vz",
        "N]6<\"P#",
        "r#<D&",
        "TWlS\\",
        "x,_a&",
        "8#838C8S8c8s1",
        "w^$kV",
        "|F7}\"",
        "YX]+:",
        "english-belize",
        "CMS_SD_ASN1_CTRL",
        "Fl|;~",
        "%)T >",
        "~vzxu1",
        "uE4bmhKzc",
        ".?AVSS_Wnd@@",
        "ETEN=",
        "+Ub;:hL",
        ")j`FGoc",
        "Py2Z{",
        "GSV\"?",
        "jljgj",
        "t(,ma",
        "{\\f440\\fbidi \\fswiss\\fcharset222\\fprq2 Tahoma (Thai);}{\\f451\\fbidi \\froman\\fcharset238\\fprq2 Times CE;}{\\f452\\fbidi \\froman\\fcharset204\\fprq2 Times Cyr;}{\\f454\\fbidi \\froman\\fcharset161\\fprq2 Times Greek;}{\\f455\\fbidi \\froman\\fcharset162\\fprq2 Times Tur;}",
        "t+h<;L",
        "@x$s3",
        ".?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        "Y\"Vcw",
        "1_*>2",
        "MkG-,",
        "111B1W1o1",
        "5*5X5b5",
        "[\"C_}",
        "(e#@9",
        "]4G)l",
        ".\\crypto\\objects\\obj_lib.c",
        "8F;X;",
        "pU>\\AL",
        "NOxg:jc",
        "inhibitAnyPolicy",
        "GTx 55",
        "4eP&Y",
        "`FfQUn",
        "5]\"3,",
        "R(EYg",
        ",*s5fjd",
        "C.PjRW",
        "5HnA\"z",
        "3W3X|xC",
        "master secret",
        "t\\WVj",
        "28+Um",
        "Helper::stop() -- wait for done event.",
        "whh,]!",
        "1h[t?bxK",
        "T$T3T$83T$43T$",
        "Bp'e\"",
        "Helper::StopEndpointConnect",
        "ctH>3",
        "Undocumented SOCKS5 mode attempted to be used by server.",
        "n;r(;",
        "Gmq+\"V",
        ")%Bsba",
        "iH]&}",
        "H3hs-bmJ",
        "RemoveFromWinFwExceptionList:  Failed to load RemoveFromWinFwExceptionListA function.  Error %d",
        "$uEj)",
        "$\\<kt",
        "*q#Y2@",
        "7J7z7",
        "314v4",
        "Plugins::Unregister:  PluginsUnregister started.",
        "Nr?;A+r",
        "(]ft}@V",
        "<=A?}&",
        "DriverSetProtectionCtrlEx - DeviceIoControl(DIOC_SP_CTRL) failed. Err=%x.",
        "&+aIA",
        "C4!j!?!Q ZB",
        "N4|4$E",
        "eYAkX",
        "%ucuiu",
        "!pc_4",
        "<<=E=",
        "Newsession Ticket",
        "?$\\o|$",
        "sV+lD,",
        "zfv6L",
        "% %&%,%6",
        "oKfjJx",
        "nsCaPolicyUrl",
        "CACNCet{^",
        "yk,=H]W",
        "%\"&<V",
        "D$$_^][3",
        "Failed stopping URLF Service",
        "x5l \"",
        "(E&GW|",
        "Z## b",
        "stMT>",
        "jHh M",
        "n|=<a",
        "MMMMC",
        "mrrQ.",
        "<(GT+",
        "a6@iimH",
        ".btx`",
        ":xiL5U*",
        "LGmVy&",
        ",cmHx",
        "L1T y}",
        " %)0YO",
        "&4'YMJ",
        "H;Y^0",
        "0;0d0h0l0p0t0x0|0",
        "=*=F=b=~=",
        "=r5m8Y",
        "RSA_PRIV_DECODE",
        "pHr:k",
        "*/kL8",
        ">*D},",
        "CsVp$X",
        "(!(1(=(?(I(Q([(](a(g(u(",
        ">L:-`5@",
        "f~I{WV",
        "3'4Q4{4]5h5",
        "=6=;=@=",
        "hA:r1UX",
        "NNqt;9I",
        "u8#*Z",
        "CreateThreadpoolTimer",
        "Fy~S^",
        "qh=,$gG",
        "8+p1n\\]0",
        "5S>+dn",
        "`_X1w",
        "o\"Kv[",
        "5h5l5p5t5",
        "NIST/SECG curve over a 409 bit binary field",
        "Bgw&-",
        "AY={`",
        "wD)3SU",
        "S!;V?",
        "1Jt$*@",
        "3+3F3",
        "8 8$8",
        "x2@\"-OX",
        "`/C4E",
        "?1?5?9?=?A?",
        "[][]`1_xRD",
        "7g`Nv",
        "FK5l@",
        "/>r_^",
        ",-JeB",
        "6zG`G(",
        "Y7lbdJ",
        "UYeUVe",
        "baZaS",
        "jijxj%",
        "N[?5q0q",
        "V&z:r",
        "jZ)l65",
        "1:1]1m1",
        "9(949T9`9",
        "@wBJ2W",
        "<0<?<u<",
        ".?AVxmlstring@@",
        "\\lsdunhideused1 \\lsdlocked0 List Continue 3;\\lsdunhideused1 \\lsdlocked0 List Continue 4;\\lsdunhideused1 \\lsdlocked0 List Continue 5;\\lsdunhideused1 \\lsdlocked0 Message Header;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 Subtitle;",
        "'EEp~",
        "O#KSWI",
        "h5:#f",
        "]iAiM",
        "D$( u",
        "]Hs2s%}?",
        "bEk/'",
        "MW s;",
        ")W^~u",
        "5[IH)",
        "|$,US",
        "t j_h,B%",
        "Driver mode (TDI Mode) is %d",
        "Q.!d`w%\"",
        "6b~:?7",
        "'cr@@",
        "G11LUa",
        "?Vr{2!",
        "<H:u?",
        "R5#Wd$",
        "pQ@Q (",
        "yq:^X|^",
        "tHh9j",
        "*gJU\"",
        " doesn't exist",
        "j}LPb",
        "}C*[q~",
        "XW$$W",
        "HJ]#]",
        "U6s-D",
        "error setting nbio on accept socket",
        "\\;Fm\\",
        "%\\231",
        "0(040T0`0",
        "0v+QeOSb",
        "AES128-GCM-SHA256",
        "v(jC$sh",
        "dqUTQ",
        "jIhx\\",
        "r={6z",
        "=6>Y>",
        "W&|:=",
        "Plugins::Register:  pWseRegisterPlugin  Error code is ",
        "q<,Gy",
        ")/5W#",
        "DA9Wo3",
        "<0<9<O<q<",
        "2E#jX",
        "S/WDX",
        "$& QeT",
        "(YYBH",
        "{hZ1^;",
        "O`n<J",
        "digest does not match",
        "{$H&I",
        "6l7E8w9",
        "CPBDFWc",
        "!CVh2",
        "G]C)R",
        "G{\\(F",
        "6,6O6r6",
        "SystemFunction036",
        "Jnxv4c",
        "pPUSm",
        "{S2'?",
        "b'p7(",
        "+!YN$",
        "Z71W[\\3",
        "[b[R1",
        "# 4(i",
        "\\Y DO",
        "Q0#f$Iz",
        "}$tJ\\yf",
        "2zw &*",
        "}O\\lV",
        ")GqjYh",
        "CurrentVersion",
        "JE\"s:",
        "all,-database,-alerts,-sc_debug,-module_load",
        "US,I\\-",
        "]LVms",
        " #}LF",
        "[.b7< ",
        "\\drivers\\scap.sys",
        "2!262=2M2",
        "B@O@Ou",
        "4k^]+B",
        "Be(*&",
        "hX-6x&O",
        "<NPry",
        "2 2,282D2P2\\2`2d2",
        "Q})~xmK4>",
        "D@D/lcO+hcK",
        "<bq:7B8",
        " fulfillment hub region should allow for additional transit time due to international customs clearance.}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11798905  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076 ",
        "3@$:kF[ ",
        "tlF R",
        "T)Hcc4",
        "O'>Fsn ",
        "4@9XN/",
        "O?SjR\\",
        "(gIOW",
        "wU*no",
        "mmiP2t",
        "no private key",
        "080[0~0",
        "4(4E4V4k4p4",
        "crRl#",
        "rBjL2",
        "Wn+3[",
        "s5N3p",
        "S7/ u",
        ">2>K>d>}>",
        "TVdebug message:  %s",
        "ekB;P",
        "6%IlQ",
        "Killing process:  %s",
        "v5n5b|Qm",
        "su[R}",
        " FV 6&",
        "8G8}8",
        "L7qzA^s",
        "7Q!r;x>",
        "~z@'8",
        "j|\"=H2",
        "J~KY`:;",
        "{XHL!",
        "R@H}WN",
        "0<0X0h0t0|0",
        "t[LXj1",
        "4A9H9",
        "5 5@5L5T5",
        "\\`0>T",
        "ISO-US",
        "\\PassDialog.exe\"",
        "$?'_?",
        "I5hWnJ",
        "R},$L",
        "x[4!J{",
        "[VSDATA] DataThread: CreateEvent failed - terminating DataThread",
        "|,8Z8KG",
        "*72?F",
        "YUxcDd,?g",
        "(5#7D",
        "!xX d",
        "trac_msi.log",
        "SOFTWARE\\ZLTMP",
        "7-p%)",
        "CDv]v",
        "setct-CardCInitResTBS",
        "bT$,Xg",
        "(m] %",
        "\"yDWJ",
        "8(8H8h8",
        "u|`:^",
        "thread.cpp",
        "Dn,V#7",
        "O4T.!{",
        "L43[Q",
        "UnregisterClient.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "-jzGO@",
        "InstPWRequired() found ProcAddress for \"VSPWInstPasswordRequired\"",
        "dpe^5",
        "$Zr-q",
        "|?pAh",
        "ik  J W",
        "G9O8*",
        "9jnND",
        "*%XDlF^",
        ">(>4>@>L>X>d>p>|>",
        "6/7m7",
        "u5>xC",
        "?tKbU",
        ">>>f>x>",
        "~bQED",
        "{pXSC",
        "P}N_x",
        "=H5S&i3%",
        "?mNZ$",
        "g'GGk{VToX)",
        "7`)#F",
        "https",
        "L`0!=e",
        "U5 K_4h",
        ",pQ4S",
        "9k}k3",
        "by74TK",
        ".'`\" ",
        "a[sW|",
        "C*%KQHwC",
        "Nn4nL",
        ";-9c{",
        "Vh{w.&",
        "Jd=E(",
        "64686P6T6l6|6",
        "te#bZ)",
        "<e\"cfQz;o",
        "8!91969l9|9",
        "]N0{:%",
        "/Itvk",
        "WIN32_UNLOAD",
        "zonelabs\\config.xml",
        "'rO\"9u",
        "Thp,P",
        "C.Y|e",
        "ip!`Y",
        ">2?E?^?g?",
        "%'+Gq`<a",
        "/='nf7I",
        "54wYutx",
        "n.4LrS",
        "=8=D=l=",
        "$5OA[4",
        "nj^adu",
        "VQ.?H",
        "rqE,]",
        "7bMa'",
        "OsEdition",
        "9<'N #",
        "1%1+1A1a1",
        "-UUv7",
        "[>G>v",
        "|)1'36u",
        "^\"\\% ",
        "7W3\\v`c",
        "_6Nv=",
        "t$ ;w",
        "SSL_CTX_use_certificate_chain_file",
        "Wloo@",
        "am@K!",
        "u)j\\h",
        "ENFORCEPATCH",
        "(\\f7`j",
        "tF2vz",
        "383@3L3p3",
        "RC4 for x86, CRYPTOGAMS by <appro@openssl.org>",
        "s #`o",
        "[DUMPFILE ERROR] error %d loading %s",
        "lLrlf]U",
        "\\%,$u",
        "\\tqc\\tx4680\\tqr\\tx9360\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0 \\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\af0 \\ltrch\\fcs0 \\insrsid15298478 ",
        "XLbE+n",
        "Q4iTe",
        "4#5l5",
        "V]:!ODv",
        "9n9mH",
        "rA-N}",
        "dd d!\"dd#$dddd%&'ddd(d)*d+ddd,-.dd/0123dddd4d5ddddddd6dddddd789:;<dddddddd=ddd>?@ABCDEddddFddddGHdddddIdJKLdddddMNdddOOddPdddddddddQddRdSTUVWdXddddddYZ[d\\dd]^_dd`daddbdcf",
        "7$!I0",
        "2`w6`",
        "U*W@j",
        "`#ak%A",
        "c=B^-",
        "<NMMFfD",
        "#E/%$",
        "Xxs,]",
        "BeginSession started.",
        "p6'sm",
        "r50T.",
        "CANT_OPEN_PRODUCT_KEY",
        ".U8GS",
        "y\\[%<",
        "bd~#]",
        "><>i>",
        "?=d|H",
        "*GsfI",
        "C/-vg+]",
        "z6kl*",
        "RQWPV",
        "_get_initial_narrow_environment",
        "Y^7Lx{",
        "2^T+v",
        "J5xw#",
        "/\"/H^",
        "Tb?:L<O",
        " AK,/m'0w",
        "ZHDu6",
        "{SbhQ",
        "dZ#eC",
        "?!?A?",
        "VUVYV]VaWe",
        "YS:'#H",
        "c>b'\"",
        "0$0o0z0",
        "CVTTPS2DQ",
        "Can't Load a user's hive %s ",
        "9*9I9X9w9",
        "BTh`'",
        "Lv<v3]",
        "609Tm",
        "l`:yH",
        "/+^d(",
        "instHelperProcHandle = %d,PID=%d",
        "!0F0{0",
        "<;r(1",
        "X&e*j",
        "'uzP.",
        "Deferred custom action CopyPoliciesFromOldDirD",
        "The certificate has been deleted. Continue.",
        "Certificate Status",
        "YM~BR",
        "}NYhem",
        "xixrt`:",
        "g0=E&",
        "=R]!l",
        "?SetVPNAtInstall@@YAXKK@Z",
        "'DnA{.",
        "TCbIv'",
        "](=c2",
        "qZW5]@",
        "=W{ejv",
        ">GU&&",
        "2/NaC`",
        "m=,%@",
        "^ncU6",
        "@<Bqd3)",
        "{5Yd8",
        "SUED1",
        "X7iyc]C",
        "A+RI8",
        "VJ(\\^s",
        "JZXpQ",
        "d.signed_and_enveloped",
        "yJ(g.",
        "pl981",
        ")Y-r4,",
        "49l{MPb",
        "a&v7wbfs/",
        "`o#z@",
        "a(*vs",
        ".0|r<",
        "c+,Wa",
        "^o\"_^",
        "0wd#%",
        ">i!%A",
        "#%P=`",
        "Mw980A",
        "fc3\"t",
        "m0e&h",
        "Y<wd\\",
        "v.UFX",
        "8>9k9",
        "regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.",
        "2&)1gy",
        "=die~k",
        "=JmrO:",
        "@@ t7",
        ":(JgB",
        "=3=O=k=",
        "`<Gf4",
        "=zQ{/",
        "RE^RI",
        "G(;xZ",
        "m:3;+(",
        "B9B4$a",
        "MfV^fZ",
        "H|C,.nN",
        "Lj8/O",
        "LOGIN",
        "P!KoJY",
        "dL\\Ot",
        "R=XWF(",
        "4VDXC",
        "AQx)8[$M< a",
        "k_qO&w",
        "UninstPwdHashDA",
        "g}sKL",
        ">;ixW",
        ",]g}ex",
        "dxo=Y",
        "JA@H1",
        "1&343",
        "e~V@Xg",
        "cY@je",
        "JOyce",
        "HSP->",
        "~>H6<Sr",
        "4TVZT.|",
        "wqd@t",
        "ucnfk",
        "F.u0=",
        "\\,t6o",
        "? ?@?",
        "[q]wG",
        "R^}*I",
        "fhZ>:",
        "yRav<",
        "6#5cL",
        "J+,4B)",
        "j5XJS",
        "Ia9[j",
        "YqdIN",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 TERM}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11555386  AND TERMINATION}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "A%tm#|",
        "BplfD",
        "dH$>sY",
        "Yl-0)",
        "617020786d6c6e733a613d22687474703a2f2f736368656d61732e6f70656e786d6c666f726d6174732e6f72672f64726177696e676d6c2f323030362f6d6169",
        "*Z(^L{",
        "oc:!)$Y5",
        "%lO6?o",
        "0P1^1q1",
        "u'aC3'",
        "^T3uQ",
        "UK2%1",
        "JybaT",
        "PEh>ZA",
        "1Z(^\\P|",
        "LJ1Lq",
        "~vL'6T",
        "V(&H2",
        "\\v\\*%",
        "]`icN",
        "2QZPp",
        "R1Xnq",
        "6dWR:",
        "U0(KM.@",
        ">:?G?",
        "N.[9l",
        "8M\"SuDZ",
        "h4Re9h71S",
        "Attempted a typeid of nullptr pointer!",
        "LQHK+J",
        "6%7R7Z7g7k8}8",
        "6c7|7",
        "south africa",
        "Bld_Y",
        "Failed to get shutdown privilege LUID.",
        "/-2K]",
        "CreateUmsCompletionList",
        "^5$2f4",
        "$r?_8D",
        "we;l~",
        "DYH4)",
        "fbk*L5G",
        ".R[ZB",
        "X60]!",
        "SU Tc",
        "Kf+a)",
        "OBJ_nid2obj",
        "; ;6;p;y;",
        "3u(kO",
        "Na73G",
        "ejHz<<",
        "3>`QF",
        "kr5][",
        "D$$SP",
        "CANT_CD_TEMP",
        "'()*+,-",
        "d+5Ur",
        "gl}7s4(",
        "00<@1",
        "jAjhj",
        "101B1O1V1",
        ".n4v:",
        "Q&&&h6",
        "Hy\"ik",
        " (\\/^",
        "F*ub}",
        "{@g_M-",
        "}6Es'",
        "3V,~$",
        "nt#igG",
        "D4$F;",
        "a~(&K",
        ";,BSy=X",
        "yr8F=",
        "7[_^]",
        "+|E?@6",
        "]G[Gu@",
        "3(3,383H3X3\\3l3p3|3",
        "1X9vy",
        "Q~lM~",
        "MrOcV",
        "Hd?~R",
        "} A:]<",
        "@ImNq*",
        "/^/Va",
        "u7Y5^",
        "0&0V0c0",
        "SpcIndirectDataContent",
        "w+kA^",
        "|}='.",
        "=`)B[",
        "3$3,343<3D3L3h3l3p3t3x3|3",
        "?DfN@E&",
        "~hIE4G",
        ">.N.^.`,",
        "eysCb",
        "Z4rt;",
        "7 797",
        "EM P0Eq",
        "E5YQG",
        "tH .5t",
        " kEA:",
        "7ocDW",
        "AsN(jY",
        "3b2sh",
        "T45,hR",
        "H-H_X",
        "0.181@1R1W1d1w1",
        "Dhj%Cs",
        "'PzBI",
        "eO?cD",
        "YPX#W",
        "&??{)7a\\a",
        "W<GOi",
        "Fd->J",
        "e<g;*",
        ";|$,r",
        ")\\a~k",
        "Read key ",
        "d,DFb",
        "E3F$dgS",
        "l$D8D$Lt[",
        "4%4`4",
        ">.>5>B>N>\\>h>w>",
        "]nD~G",
        "V\"Hp ",
        "2 2(242T2\\2d2l2x2",
        "#j#:#B&J",
        "'*@T65",
        "SSL3_NEW_SESSION_TICKET",
        "=>=[=s={=",
        "PL(kT",
        "EcOi%",
        "|||33",
        "C}YU;",
        "Q*0by",
        "file type ENG for private key not supported",
        "V/G, l",
        "[gDLM",
        ";1;;;j;t;~;",
        "/Piq*)",
        "G_Vym",
        "VaKJx",
        "}d[=AX",
        "f{sGB",
        "-v>uN",
        "KpPHI",
        "5,585@5X5d5",
        "P\\3CD",
        "@\"2,W",
        "Bb#qE",
        "k{/|<",
        "QQSWj0j@",
        "$|dd#",
        "aclutil.cpp",
        "signedAttrs",
        "2mT;>x",
        "&0m:+?",
        "4W6#8",
        "J8[}H",
        "hxjfb",
        "Server %s is blacklisted",
        "e5eQeqe",
        "%&\"L:q",
        "|5YW1s",
        "xm\"/f",
        "?A,~<",
        "9,9H9d9",
        "+fJR~",
        "2sSY{",
        "<<=i=6>^>",
        "@PSVV",
        "+M]\",",
        "&o?k+6",
        "_)OJPZ",
        "5[Om*Z",
        "Nrc*1",
        "ct_precert_signer",
        ".?AVVPNConsumer@TelemetryISShared@@",
        "Xt,mt5`",
        "Qt/3f",
        "BW;Edhd",
        "PTw_ [F",
        "<[)`pl",
        "wap-wsg-idm-ecid-wtls6",
        ",cUbz&",
        "9D9u9",
        "F*OJgf",
        "[!qD(z",
        "u)j\\h<",
        "]tVD .)",
        ",+E_,",
        "r}'}>]",
        "ruZq2",
        ">H#sZ",
        "[J@|%U",
        "=Gh9.?",
        "#Hpk}",
        "]AmgX",
        "^HeAE",
        "PI*6EK",
        "0C0Y0o0",
        "8!9:9S9k9",
        "PJ4D>",
        "L$dQj",
        "****************************** OnBegin started **********************************",
        "131?1n1",
        "xclK(",
        "}g>\\1a",
        "OPENSSL_init",
        "W#$`~",
        "[w5kK",
        "j,vae",
        "5vm[T",
        "noOfficeMode",
        "Tno->H",
        "|sm/~",
        ":1;M;",
        "2 3/3",
        "id-smime-cti-ets-proofOfOrigin",
        "A|!sS",
        ";lsZh",
        "Entering SendServiceControl",
        "Nb!hX",
        "%u %s %s %s %u",
        ";dcn}$0",
        "bX`tag",
        "\\;3wI",
        "GQ5O/",
        "|5~uO7",
        "BYJu].gDcOJ2~!L",
        "; ;@;",
        "9r9|9",
        "J%\"I**%",
        "|+Pg[2",
        "MrE'LtJ1",
        "jCztty",
        "~'zCm8",
        "/209MQ",
        "2e;KH[p",
        "4(414:4C4d4h4l4p4",
        "S)Wi e",
        "&H)utu",
        "3+3D3`3|3",
        "App: %ls found running, requiring a reboot.",
        "GetXMLDOMString failed",
        "keMa/c",
        "%s attributes: %x",
        "e+cJW",
        "?(?0?4?@?H?L?X?`?d?p?x?|?",
        "HjWdfd_%e",
        "[E?H*",
        "api_ms_win_crt_heap_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "FIADD",
        ";Lgtn",
        "|3R3[",
        "R:.8,8J",
        "ar-SA",
        "I.e}$T*[",
        "22dl#",
        "ModifyUpgradeTable",
        "n$)`(",
        "4*5b5",
        "P5nKz",
        "n*6pZ",
        "IJZ['",
        "099?0",
        "[\"[*[4[6[B[L[R[d[n[~[",
        "1':Xn",
        "l$(G;|$",
        "S\"jPZ",
        "0CT[XPN",
        "6by`w",
        "V;Hu:",
        "Ew*JD",
        "*4/z#T",
        "J)%7.6",
        "y[ZpU",
        "api_ms_win_core_processenvironment_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "_|^c5-",
        "GOST 28147-89",
        "Q:pS0",
        "&Zz/Z",
        "mu2h!",
        "As@Nd",
        "e_}UG",
        "RK=Se",
        "!u6)-",
        "mt-MT",
        "QApV ",
        "StopRemediationService_rollback started",
        ";<n8O",
        "?SunMonTueWedThuFriSat",
        "3M#$DR.",
        "or9qc",
        "RE:/D",
        "6NhE9",
        "As_F~",
        "475W6",
        "]FepP",
        "n`\\'=H6D",
        "$NJ,M",
        "Il@} ",
        "1:1c1v1",
        "/:PZt",
        "-|B3-",
        "@+ /)&ZA",
        "Z}kSJ5T",
        "1Z1w1\\2",
        "sK@v{1,;",
        "C%k%q",
        "@(|AR",
        "Lf%f..",
        ")hg,t",
        "SetEntriesInAcl Error %u",
        "JNES[e",
        "Y\"BIQ(y;2",
        "RSA-MD5",
        "BFJ@)7 ",
        "}pO!h",
        "<!=Q=^=",
        "9i|ct",
        "y9,h/",
        "Ha{~N}SD",
        "9\"y$o",
        "*[\"WV",
        "Y;=P)",
        "T(P|Bn",
        "-3Iyv",
        "FP) lw",
        "vc5-(Y",
        "<*^[A",
        "jCjpj",
        "tV{D;-",
        "<assembly xmlns=\"urn:schemas-microsoft-com:asm.v1\" manifestVersion=\"1.0\"><trustInfo xmlns=\"urn:schemas-microsoft-com:asm.v3\"><security><requestedPrivileges><requestedExecutionLevel level=\"requireAdministrator\" uiAccess=\"false\"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns=\"urn:schemas-microsoft-com:compatibility.v1\"><application><supportedOS Id=\"{35138b9a-5d96-4fbd-8e2d-a2440225f93a}\"></supportedOS></application></compatibility></assembly>",
        "pSpopT8",
        "@HLE(A7B",
        ";/LekG",
        "$tl<o\"_",
        "rP\\7No",
        "Failed to create the Global\\WixWaitForEventSucceed event.",
        "en-zw",
        "8`U?M",
        "OnUpgradeAfter:  Failed to unregister SecureAccessDSM.dll.",
        "K\"{)HHRT",
        "+VqOW'",
        "r<;)mq",
        "ddOKq",
        "hM\" d",
        "T18i~.\"",
        "4ZtwwJ",
        "NIST/SECG/WTLS curve over a 233 bit binary field",
        "FAILED_TO_LAUNCH_REGFILE_TEMPFILE",
        "Wt935iMgIG",
        "q_$d$",
        " -ti5",
        "JuLUi",
        "SystemTimeToFileTime failed to process start time of the driver upgrade. Error code: %ul",
        "'FL*6",
        "$:)jx",
        "wLKX'N",
        "x;O*y",
        "ExYAYRr",
        "uQUe/",
        "T6>f$e",
        "_}KSz",
        "piA.|",
        "9M8Zg",
        "j.KZR ",
        "&8P'I",
        "/wb)-",
        "9/989A9a9",
        "the install.",
        "'LA\\%",
        ".?.&0",
        "e_4wH",
        "u 'JX@",
        ")nC[*,",
        "6;D2+",
        "Ntf#%",
        "(rz9iX",
        "bc0.EK ",
        "-q~18",
        "MYKC|x",
        "&Nff>",
        "f2LDm",
        "api_ms_win_core_file_l2_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "T{CK'C|",
        "4F4`4i4",
        "5)60676>6E6|6",
        ",>-#)P",
        "pJ1Hhe",
        "-!OH~a.A",
        "1 1&1+11171=1B1H1N1T1Y1_1e1k1p1v1|1",
        "c?fvR",
        "l=b4*",
        "034f(",
        "#7fuF",
        "foF@n",
        "7fQ?0",
        "brc4a",
        "xbB^r\"\"z",
        ".,H\\y& ",
        "V2I_AUTHORITY_KEYID",
        "SERVERINFO FOR ",
        "7E-'xK",
        "L$8UWR",
        "HAI8xpH",
        "d9@l24<",
        ";`fW.",
        "N&/RJ",
        "%-18s",
        "k_$P4",
        "oUzwf",
        "*s}BL(/",
        "6'Z=;?",
        "rI/tz",
        "bsgav{",
        "fL;B;",
        "azhsk[",
        ",^)uq",
        "l_>)!\\",
        "8@8d9h9l9p9t9",
        "pUqUs",
        "CreateZoneAlarmXml:  CreateZoneAlarmXml started.",
        "Lock already taken",
        "+*>vf",
        "&.pta6",
        "qb3ec",
        "-* MH",
        "8_^][",
        "i1K`S",
        "CA Repository",
        "=uM&F",
        "\"~{AG=",
        "['f'?",
        "5$5D5",
        "XDpiU`",
        "ntej+*",
        "EP5D9",
        "s0W2r",
        "Qr6r<",
        "&:+GZE",
        "F?(Av",
        "eGvM)",
        "1^('tA,",
        "id-smime-cti-ets-proofOfReceipt",
        "n.2JU",
        "&1S??",
        "]jO\\9",
        "u$Qt!",
        "generic",
        "_;=?5",
        "pY:$hC",
        ";&;0;@;P;`;i;",
        "V,_^[",
        "e9eef",
        "'>ejHd",
        "Biu%oz",
        "F^y;1[",
        "7J-^a",
        "Closing event handle %d for %s",
        "ogut,",
        ">@?O?",
        "FXsiUEY",
        ",0L0X0x0",
        "R$W6p",
        "v$Q54?",
        "4'$j)",
        "`Cq*^Z",
        "z<z>z@yB",
        "RgvGl",
        ".V7Qo",
        "7 828L8X8n8",
        "WIN32_JOINER",
        "StrDupA",
        "5fS};",
        ")kjdk",
        ".7E~e",
        "Pd6n`",
        ")x|ve",
        "Richn0[",
        "\\0DJW",
        "zgmBkcr",
        "?'90i",
        "K^M>-",
        "@Jj7;",
        "/!sL=Y",
        "0>\"3q",
        "]t)m&",
        "On5M]^s`",
        "A,98~",
        "*!5Vu",
        "VFffM_",
        "unable to find message digest",
        "O2yIz",
        "-YV>Cz<",
        "fX\\fRy",
        "id-it-preferredSymmAlg",
        "co_ZQN",
        "@L,2\"",
        "eR:%:",
        "Vb|u~y",
        "D1NgWg|g",
        "DQnHeP",
        ".7l.yc#",
        "KLDDi",
        "#Z7k/",
        "j%ko@",
        "`DwKVn",
        "i?~GZ",
        "tJ<_t<<$t8<<t4<>t0<-t,<a|",
        "A0a0q0",
        "D$0WPV",
        "UpN-e",
        "z Bp&",
        "]vQ<)8",
        "-pP^_",
        "S%^ djMb",
        "Z6 _SB",
        "v-lWO",
        "w9C0?",
        ".a&.(",
        "P3T8t&",
        "EPClientUIService;",
        "~KD,-",
        "7 757:7T7\\7v7",
        "QfEv)",
        "q-35Y",
        "CP&bj",
        "d2i_ECPrivateKey",
        "&J\"yo",
        ">(nr2",
        "y)IH&fR<",
        "J!S*|",
        "w/3Al",
        "XPj Q",
        "DSO_new_method",
        "T%@`J",
        " 0xbc",
        "Set value %s to %d",
        "D7ckCL",
        "MFENCE",
        "Sc~`!",
        "mt(8y",
        "{KhcS",
        "f\"ds#",
        "iH/Ci",
        ":)baQ",
        "Fg \\0N",
        "6j~ARX",
        "G0_^]",
        "6mOi:",
        ".?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@",
        "]l9mJ",
        "&=<%[Q",
        "failed to get command line data",
        "[INSTALLER] WSECreateLocalCatalogXmlForUpdatingComponent(\"%s, %s, %s\") - end",
        "$hg{0",
        "?(?v?",
        "wMSPG",
        "7C|i9>",
        "9&vq#<",
        "TC7NK#",
        "WF!1L",
        "r +k=g",
        "'/t!2",
        "Subject Information Access",
        "\\+p*j",
        "+&?FS G",
        "kin!OjM",
        "0|d+x;",
        "MP~af@",
        "7(GU%L",
        ":0cNs",
        "Address in '%s' found illegal!",
        "B?WiiV",
        "[VSSHUTDN] CallAddDataClient: Failed to load vsdata.",
        "L!OAn>*",
        "U.\\/J",
        "2()3t",
        "szIut5O",
        "hsisk",
        "QZ{}8",
        "8M~c1",
        ":,:3:B:O:",
        "t!]#wEl",
        ",)oYM@",
        ";4<<<T<\\<t<|<",
        "roX:E",
        "pl0Kl6",
        "failed while looping through all objects to schedule rollback for",
        "f0y' ",
        "8w10\"",
        "P|W}S",
        "656Q6m6",
        "o4bL>",
        "mP=[Q",
        "TryEnterCriticalSection",
        "sFE(v",
        ",hB`q%",
        "sc<ONF;p",
        "2}yX.",
        "828N8",
        ">:>V>r>",
        "$)}t3",
        "Ne@5/",
        "[idSv",
        "hDatabase is NULL",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{749F7127-A1E2-421E-99D8-09B895DD892D}",
        "8W9[;",
        "SHOWWIZARDS",
        "[NESTED UNHANDLED EXCEPTION] %s %s in process %s",
        " 0uRdq",
        "shutdown while in init",
        "';U\"+",
        "9[Ht]",
        ":D:{:",
        "6&707M7^7s7x7",
        "Authentication cancelled",
        "] 9xn",
        "ed[w<",
        "Rw) U",
        "&ekWA4",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\TID",
        "^.z?s",
        ":2:N:j:",
        "cons: ",
        ";7;l;",
        "value.bag",
        "IE`RvJ#",
        "PSRLD",
        "YjgFt",
        "[1Nu\"",
        "<!<A<Q<q<",
        "1NQS[",
        "setPWInstall;",
        "___mb_cur_max_func",
        "'HMU ",
        "7SR'+",
        "Ja?%N",
        "7,7<7@7P7T7`7p7",
        ":PcMJv",
        "j\\Zf;",
        "')1v5",
        "#4#F#",
        "c[8z8",
        "/8qG.",
        "vzKOF",
        ">0>P>X>d>",
        "AKn}b",
        "_B#Lh|",
        "@5ClAO",
        "Pqyq!.",
        "RuK56",
        "EPAM_CleanLeftovers started.",
        "vsxml.dll",
        "9'7$3",
        "-6yb4",
        "Zg)+$",
        "Y6`@9q",
        "%s%s\\",
        "{'?'s",
        "D[FR&",
        "wSl}D",
        "pg}0tX",
        "_o$ ;",
        "Z&RDX",
        "|7.3f",
        "Y9$io%",
        "6$6,646@6d6",
        ",-&D!",
        "\"sU\"u",
        "rz|m>",
        "EO/{6CM",
        "GBT\\\\",
        "19(;$'",
        "MD*(Q",
        "GT\"'Y",
        "4wx;b;`",
        "9N|.J",
        "0M1W1t1",
        "0=V]F",
        "scr=\"u",
        ">,VR)",
        "l1la{",
        ".0]1t1",
        "G?\"kD",
        " from key:  ",
        "<'a~=",
        "<2<R<r<",
        "Pw <*",
        "vDn/:*",
        "vY5F9",
        "9jeG#y",
        ".\\crypto\\x509\\x509_obj.c",
        "FeatureSmartDefense ADDSC=NO",
        "\"i24C",
        "fixed_mac already exist in registry",
        "au@1D\"",
        "PKCS7_RECIP_INFO_set",
        "oEo%\\E",
        "host!",
        "yv?Srw",
        "^b^V^",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5259060 8}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid11303137\\charrsid15169477 .3\\tab You understand and acknowledge that upon entry of the }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "xe-+!",
        "2o?8d",
        "]N_(Q",
        ")_}Ej",
        "}OXQ~?2$",
        "VV\\V_",
        "_&F_A",
        "p-Dz(0A",
        "gkj$i",
        "P3L$T",
        "5%5*5E5a5",
        ")?1?A?",
        "626R6",
        "?(?H?T?t?",
        "SaH9U",
        "c~n^~",
        "^_\\0;$d",
        "#R[=k",
        "\\]~]7y",
        "n!z0R",
        "W\\Fnx",
        "Installing SDL",
        "nP&>,W",
        "4^sY\\",
        "k{Y,-",
        "ch!=)",
        "C\"**x",
        "1&GFN",
        "FGou ",
        "k*kHk",
        "STORAGE.DA5C0B1B_759E_4256_9F02_1D6C54339DBB",
        "P\"-rI",
        "UWQMU<9",
        "88 Q>",
        "GetWorkingDirectory failed to get the current directory",
        "w-D~j|",
        "P*jkC",
        "Bwhz]q;",
        "-hyRS",
        "~&RJ,",
        "Pez'&",
        "u@ShD@",
        "a]W=}",
        ";G=e% ",
        "6nn4L",
        "SSL_CTX_use_certificate_file",
        "Base Policy Chain Status Failure: %d",
        "K{{&r",
        "=j&&LZ66lA??~",
        ":PU .z",
        "=9=O=",
        "=+>P>\\>p>",
        "nrM6.>a",
        "6MdOB",
        "nextUpdate",
        "4F6U6s6y6",
        "I=%&N-",
        "]ZoYe",
        "06<6H6T6`6l6x6",
        "KiHUJ",
        "tdNIH",
        "2Rzk-",
        "y+.-/p[",
        "Fx!<m",
        "C@$_g",
        "id-smime-aa-ets-archiveTimeStamp",
        "]'?WC(h#",
        "8iT:p",
        "1w[:6",
        ".?AVNo_Op@?$basic_oaltstringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@io@boost@@",
        "3 373B3O3e3p3u3z3",
        "8BM30",
        "lR@/`",
        "1VS11aJ",
        "invalid boolean string",
        "3|\"ZOv",
        "_X/$k",
        "i@S)s",
        "gOt2)xL",
        "4'434n4",
        "Y.<:mtg",
        "nc[?BZ",
        "0;Eq`",
        "teu!3",
        ":/;h;",
        "!Ake!",
        "L`Ea%Z)",
        ";<<]<",
        "D$DjPP",
        "7B(_Q",
        ":(:x:",
        " y8[?",
        "i[IX&",
        "a!.?6h",
        "`u5![QX",
        "tVWh<",
        "0.0[0",
        "@Tb*<",
        "\"Y 2*",
        "2.2J2k2p2",
        "Vcy%)",
        "!gN<r",
        "~fl!-",
        "mBxI<8",
        "YYQhx",
        "WOW64 detected.",
        "> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\\>`>d>h>l>p>t>x>|>",
        "z y6,",
        "D$,h:",
        "n5DD1",
        "<'<:<[<h<}<",
        ";=i*&",
        ")Q\\M\"",
        "D$$_]^",
        "7sqUq",
        "o7\\qq",
        "(7(8}M",
        ";`$xU",
        "x@kf eB,",
        "BAD_RETURN_WAITING",
        "[n5| ",
        "\\'iaa",
        "C*QW-",
        "_*tpE",
        "s?=vC",
        "2$2L2f2k2",
        "9%9/9;9W9g9|9",
        "W&NvNJ",
        ";Q1Sx",
        "#</t2",
        "jrjsj\"",
        "Op 3@",
        ">->J>g>",
        "010M0i0",
        "Service %s stopped",
        "PSSSSSSSj",
        "2&2<2D2J6p7",
        "shutdownVsmon timed out, trying again.",
        "6XMZv",
        "p:k$]",
        "L$<3t$8",
        "3%3s3|3",
        "n@GQ8%",
        "D7C\"Q",
        "o;M?|\\",
        ">{KKm",
        "oL$p1",
        "^D^X_",
        "CANT_CREATE_MUTEX_FOR_LOGFILE",
        "-T.H/",
        "jWd0Yk",
        "$O.c1",
        "sf*uL8",
        "w{t&3.KB",
        "@Va*o",
        "mx}y7@",
        "9nZa>`",
        "1&VU5=",
        ",Ra-16B",
        "Bind to local port %hu failed, trying next",
        "ALPN, server accepted to use %.*s",
        "IuMAM",
        "Xh$hJh",
        "#GLP\"y",
        "UnregisterWait",
        "$q]f-",
        "Clz017",
        "vI?|l",
        "GetMappedFileNameA",
        "0!F2a",
        "o:$o<bk",
        "_TbF~",
        "9)KUZ",
        "X9.62 curve over a 191 bit binary field",
        "K`LkD",
        "lz3+kH",
        "O$LR[<",
        "7>HVVA",
        "?MVs3",
        "%V),Z",
        "cOc4@",
        "o$r_pS",
        "2!3-3>3_3",
        "FlnX4",
        "\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 2;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 3;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 4;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 5;",
        ";$;4;@;`;h;p;x;",
        "6?7I7O7U7c7",
        "@GE#b3",
        "faXw[",
        "Operation was aborted by an application callback",
        "8>8S8a8o8y8",
        "0-o@!+",
        "71SJIRPG",
        "\"n@[onh",
        "UGUIe",
        "j-!6Hl",
        "CustomActionError",
        "\\C0.@",
        "api_ms_win_crt_math_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "Jx{e\"R",
        "8nU* ",
        ",n_|vK|",
        "wx}qV}",
        "\"^'+]",
        ")FfsU",
        "b-xX(a9",
        "7Jhys",
        "Y1j`'",
        "r]Ji]f",
        "D!) {",
        ",7?o9",
        "Aoy+v",
        "D[yfD+S",
        "gost-mac",
        "?ppqG",
        ")kH!G5",
        "y%E7z9",
        "a~\\@Q",
        "g/EM^",
        "uUUyX",
        "|~vg<g[w",
        "Failed to resolve \"%s\" for SOCKS4 connect.",
        ")@VdV",
        "afZ#E?(",
        "031Z1",
        "\\f+MD",
        "@,mjI",
        "2?GaH",
        "3~{[x",
        "failed to create an instance of IUniformResourceLocatorW, skipping shortcut creation",
        ";fm19",
        "zkY>i",
        "Failed to look up account for SID; skipping account %ls.",
        "NEGV6OT",
        "9!:U:t:",
        "`\"w2m",
        "? ?/?6?E?Q?[?y?",
        "$.YFk",
        "\\b*r4",
        "Ac0I<",
        "485<5@5",
        "t>/!M",
        "m0HNYnfcE",
        "N:NZNzN",
        "FAILED_TO_LOGOFF_FROM_VSMON",
        "Oz&\\6Bi ",
        "F*X27",
        "K@.P\\",
        "xU\\>;x",
        "9*cQc",
        "$8olWI",
        "<*</<<<M<k<|<",
        "Failed to register the process name with the Restart Manager session.",
        "1+181@1S1z1",
        "}F[c@",
        "8)8U8h8l8R9",
        "\\lsdsemihidden0 \\lsdpriority66 \\lsdlocked0 Medium List 2 Accent 2;\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 2;\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 2;",
        "no issuer certificate",
        "5l<>#",
        "Tj5Px",
        "uSekh",
        "DLFCN_NAME_CONVERTER",
        "A++/H9",
        "id-ppl-anyLanguage",
        "1)2.2I2N2i2n2",
        "FDE_Remove end.",
        "2R>C3I",
        "<m=8>",
        "1 3mK",
        "7aWc\\",
        "U'j()",
        "WSh$u",
        "bBncX",
        "uantAt",
        "NCONF_dump_fp",
        "italian-swiss",
        "2.dWr",
        "H-vsvF",
        "1q]*7",
        "FfuFe",
        "v-j/b",
        ">!^$f",
        "vFMD||",
        "kfFOe8<b",
        "3W0Uv",
        "1*e})a",
        "*`[pTB",
        "\\vsdrInst.exe -u {AC30BFB5-834B-46d2-B912-6CE71684EB2D}",
        "555I5Z5d5n5x5",
        "V$bwH",
        "MT(Pi",
        "avu1sj<",
        "G+-/J",
        "invalid key length",
        "kF-jy",
        "9@9t9",
        "60>u>",
        "<(6g'",
        "D9RNo",
        "U<q%E?",
        "RegDeleteValueA",
        "qlR*$",
        "N.jad]A",
        "},!nBL~",
        "7P*?z",
        "D$ hP<!",
        "PWVWVh,",
        "J,J@JXJhJ",
        "af\"j:",
        "{(NhF",
        "w`Rg8",
        "Can't get the size of file.",
        ">#>)>j>p>",
        "'J{{<",
        "DaB}!B",
        "q&+!u",
        "1 1(10181D1d1l1t1|1",
        "HwKuy",
        "020A0L0R0a0j0o0u0",
        "F2h?)",
        "iJHS<",
        "82=2C2H2S2Y2_2e2k2q2w2",
        "int_field10",
        "^0+0'",
        "b+`*4",
        "FC[dJ",
        "(*VY%",
        "DRIBycR",
        ";cT89",
        "Ep_Core_Inst.exe",
        "BBQ,4",
        ".'MCt.",
        "\"_;~6",
        "/(s.:U",
        "?,?>?~?",
        "Ek_^\\",
        "BawXG",
        "p::,{",
        "-.H$v",
        "5%5A5]5y5",
        "dK\"[V",
        "w@-igI0",
        "\\.Qk*hWY",
        "P0T0X0\\0`0d0h0l0p0t0x0|0",
        "g@101$3,",
        "0]2cI`>q",
        "WB5=>g",
        "@y3=R!",
        "=@Y_,",
        ",/UKgR",
        "tlIS[",
        "Z3S6HG",
        "nx/I.",
        "=!=K=Y=g=l=x=",
        "L$t_][3",
        "0,000@0D0H0P0h0l0",
        "8i9~9Z=r=",
        "-Ht=Q&",
        "aGozuiRN",
        "=By~#",
        "+XY$5A",
        "EPAM_Data.8792D4CE_35B7_41EC_AEEC_B7D5617B0989",
        "9\\$ us",
        "]CZoZ3",
        "*G|ie",
        "?|f>g",
        "GlobalFlag",
        "T;-8k",
        ">&yh(",
        "Killing process [PID %d]",
        "/K<%[ ",
        "s609p",
        "E$KfgR",
        "lVh89`%=:",
        "=!='=-=3=8=>=D=J=O=U=[=a=f=l=r=x=}=",
        "|$,VW",
        "jgYjG",
        "7I'%5",
        "Yp4N|sO",
        "!C^e=<",
        "ihd{^",
        "~M?q:",
        "PKCS5_pbkdf2_set",
        "+mp=K|d",
        "pkparameters2group failure",
        "X]Dc,",
        "iZUwU",
        "SOFTWARE\\McAfee.com\\Personal Firewall",
        "5O5b5m5x5",
        "[aTJ+",
        "MtP|3",
        "]i%y*",
        "{U=.fhrk",
        "dQo)Y",
        "bq*:Mua",
        "C8rz~",
        "GBHUYO",
        "*f#wAT",
        "486Sx",
        "RSA_verify",
        ";?;E;",
        "p`SWV",
        "\\f1\\fs20\\insrsid1729076\\charrsid15169477  TAC will either issue a replacement of the faulty part (like Power Supply, Fan, Hard Disk}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8463807 ,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "0qIq@",
        "J?KZ]",
        "NO_OFFICE_MODE",
        "-\\m\\1",
        "U1[{<['M",
        "8E9S9v9",
        "1bvtK\"",
        "(9pr ",
        "`qi|#6",
        "0#1<1D1K1a1",
        "hMIg6",
        "1'2U2]2o2w2",
        "3L$@3",
        ";5<p<",
        "b7cyx",
        " uPGYQZk",
        ",BAn9",
        "z9>,E",
        "8G8L8",
        "7Y|*.",
        "JhQd#",
        "M3-Rk",
        "Dn(?G",
        "*d1^}s",
        "/Spn3",
        ",k]}\\",
        "%&VX#",
        ".?AV?$buffer@D@detail@v8@fmt@@",
        "3/Pc(a@",
        "w+/2o",
        "\\D4UEe",
        "3|$(3|$",
        "3mAVb",
        "Netscape SSL server",
        "nFuBqe",
        "4UT9}",
        "S-<N;Y",
        "L>'v!K",
        "ufbQ2",
        "95c8q",
        "-:s%'3",
        "<V=a=l=t=",
        "(1,uc",
        "jaj\\B%'",
        "r`i 0",
        ",0:0c0q0",
        "^8tX ",
        "N+F`ll",
        "sect193r1",
        "SCRemoveAfter started.",
        "GetDiskFreeSpaceExA",
        "L<Lz)",
        "7,787X7d7",
        "bH:B~@k",
        "6,%XR",
        "~L,/;}",
        "Hb1BS",
        "!]=J_9t",
        "If90u",
        "`#i\"U",
        "X\",iFoy",
        "_1i\\H",
        "3*353`3",
        "r#ZTb",
        "<9}*M$",
        "^`=ta",
        ",,mP(b",
        "1{1$}AR",
        "h|K4A;",
        "J?ULX",
        "$ ~*%ud",
        "ywx%c",
        "R7#;B",
        "api-ms-win-crt-string-l1-1-0.dll",
        ";7%v&",
        "qD*>\"?k",
        "*1^<#R",
        "<\"j{|",
        "eJJGo",
        "484@4H4T4t4",
        "wV+)i",
        "T:I&R",
        "Ja..J",
        "Bvi_;r",
        "vyJg|",
        "; ;,;L;T;\\;h;",
        "AQ9%7",
        "@G#V5",
        "1P1U1Z1d1n1",
        "w(_^[]",
        "'J_'n",
        "fEGy:17",
        "RC`@J",
        "Hq#Df",
        "invalid argument",
        "D*24cm",
        "PV<MZ3",
        "<'E]Qq",
        "4>.p$x",
        "@^qJ:",
        "9m.[k",
        ":6:H:m:|:",
        "UChYZ",
        "J;0>?",
        "CANT_CREATE_LOGFILE",
        ">*kL;k",
        "eNST=?",
        "O/\\tan",
        "&(h2p%",
        "X[]_^",
        "Z^cp\"o[>",
        "qA^cr",
        "\\$4GS",
        "5#5A5N5q5~5",
        "Dv%z ",
        " FromEndpoint is first choice - going to block install",
        "\"29Cj",
        "E9jHe",
        "{%L{p#W",
        " :R1a",
        "'+?/h",
        "]2}{5",
        "GIw<*",
        "M\"5V&",
        "jEhp*#",
        "id-mod-qualified-cert-88",
        "uw{|z",
        "failed to process condition for WixCloseApplication '%ls'",
        ";RTqE",
        "!Gn=z",
        ">M?\\?",
        "p9w+k,",
        "ZGe#TV",
        "JE{Xye%2Ai",
        ">1>T>o>",
        "3F6wP",
        "force_policy_reload",
        "6|[)6=",
        "Z[iv`",
        "'U!S'",
        "5< oUV!",
        "jKeMdxJm",
        "GPFZh",
        "BN_BLINDING_new",
        "hGV~&",
        "gU=fx~w",
        "`m l`RH",
        "EC_POINT_set_affine_coordinates_GFp",
        "Gam/gf",
        "uzc-KT3=",
        "\"BL-R",
        "wT9u)",
        " \"m$$%",
        "mfk%JU",
        "3+PDX",
        ":/2gc^#",
        ".4\"s*",
        "LJa`8",
        "v\"g\"b",
        "O~aS<7",
        "O*9y]",
        "CK_W,",
        "7&787",
        "CCCCCCCCC",
        "-\\, 9",
        "EO`a|",
        "|r&O;",
        "zQ>X[\\J|i",
        "E9Ru,",
        "E43N@",
        "x'{CY",
        "{aU68$hDzNzd",
        "l1iGUQQ",
        "h]>oi",
        "q4\\=ht ",
        "A1hY@",
        "n6/`p",
        "!6\"{s",
        "^7x6z{",
        "ajwb8x)",
        "cms_get0_enveloped",
        "smime.p7m",
        ")o|\"F\\",
        "2wk}HZ",
        "yL$FL",
        "A0B;W",
        ".O8q`",
        "!=>$2",
        "ReleaseSRWLockShared",
        "5#J8E",
        "=<=g=",
        "MPV.0uQ]",
        "R!so[",
        "VZsO_",
        "9t vs",
        "qy.@u",
        "0J{Rm",
        "8aFJ;6",
        "Tg#i[l",
        "U^eV(G",
        "<P=i=",
        "6!6.676=6C6N6V6`6h6s6y6",
        "++?(@",
        "0Gc_\" N",
        "<G*E_w2",
        "StopRemediationService_rollback",
        "3:3I3h3}3",
        "Public Key Algorithm",
        "#cwFigV",
        "8&8F8&9F9f9",
        ">;>V>",
        "iz3o$",
        "Id=a%d^k",
        "[8;2b",
        "O-sD&3_v",
        "IqI\"S",
        "*f Q4",
        "h7^+x",
        "[LICENSING] Using subscription key instead of server key",
        "GetUserDefaultLCID",
        "vy<>C",
        ";!j[?^v",
        "t&$DV:M",
        "Kx7hU:",
        "_sendEvent@8",
        "=pf3[",
        "4F58A865-6963-48D9-83C4-92FEA8657CB1",
        "]Jr/}",
        "DjR3ai",
        "-_SS{",
        "0$000P0\\0",
        "8iv:X ]",
        "D(]]P",
        "]4_bY",
        "failed to add exception to global list",
        ".YA:l",
        "< <$<(<,<",
        "C#,;;\"",
        "67R%I",
        ">q_E'",
        "fr<qg",
        "uz/e{",
        ";,;0;<;L;\\;`;l;|;",
        "oO;HN}",
        "6F7X7",
        "3FlUX",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Third Party Software Provider\\'94}{",
        "%Nj!:",
        "e_OY1;30",
        "I}~k&",
        "lGr.3[",
        "H>6~&",
        "i.A>Fru",
        "DHE-RSA-CAMELLIA128-SHA",
        "WIN32_GLOBALLOOKUP",
        "ai#W`",
        "sXogL",
        "7iK;#",
        "SYJ8p",
        "hjeFm",
        "A;F(K",
        "< <@<H<X<l<t<|<",
        "oX:cjo",
        "^8E5\";",
        "zOt,R",
        "sr-ba-cyrl",
        "k#-1a",
        ">3`#u[",
        "bd*A5e",
        "A>`0^*",
        "S'5]<",
        "^Cboc",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\faauto\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\caps\\f39\\fs20\\insrsid5854202\\charrsid2703887 Part I - Software License Agreement}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        "2'2H2O2v2|2",
        "O)s#[",
        "Aaq!v",
        "<.2\\n",
        "@0@4\\",
        "D4c>2",
        "D$0WP",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 7.3\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "ZA8Bk",
        "!w5^C",
        "%n+J-",
        "':l.~}",
        "?xL |",
        "WakeAllConditionVariable",
        " $p}=B",
        "[Jo*,",
        "l1#pH",
        "8!8T8j8",
        "Failed to modify regValue PendingFileRenameOperations for %s",
        "8$8,848<8D8T8\\8d8l8|8",
        "T6ulR",
        "?RM4i",
        "OPENSSL_malloc Error",
        "%aRwr",
        "Sy6Bs",
        "X:~*B",
        " 0xb6",
        "{Na'E",
        "~m1;-|+",
        "=>~GWE",
        "G$W$Z-g",
        "ZFD{ZuB",
        "ssl3_get_message",
        "R8BGc",
        "\\\"({f",
        "2yidK",
        "1EBs3",
        "ku0%8V",
        "4hIbb",
        "tC#;r",
        ".XUr&^{b#",
        "&P#|,?",
        "}M4`f",
        ":&Rlr",
        "e*JlgI#",
        "979P9i9",
        "the asn1 object identifier is not known for this md",
        "<\"_9M",
        "AXAvL",
        "=&nBZl",
        "e@Z.T",
        "]PyB.3K",
        "lxMj`X",
        "bd\"Ji",
        "& &z$",
        "Ub).+",
        "EZ:S~",
        "spWZ_.",
        " #49l5",
        "z+G;C1",
        "wHHBNoQ,w",
        "U2RGn",
        "failed to open view on Registry table",
        "spanish-nicaragua",
        "tuOUVW",
        "i1NvVY",
        "J1.1u",
        "SEC_E_ENCRYPT_FAILURE",
        "L$$1L$",
        "tTThZ",
        "aC4g|",
        "P:   ",
        "tfD[qy",
        "\\ ud6",
        "$&QX,",
        "SetCurrentDirectoryA",
        "tHYl\\",
        "^@i=\\",
        "U|>Q_",
        "\\%Cf\\",
        "737Z7",
        "#p6.[.",
        "U$qk.",
        "Nyu_F",
        "w$leW",
        " 0x6e",
        "mi~x=Asa",
        "5b5q5",
        "7(848",
        "~\\]w}",
        "/w_:`=",
        "0(040@0L0X0d0p0|0",
        "@){qkj",
        "expand on static bignum data",
        ": :V:",
        "(`PjJ",
        "M?UVG'N",
        "<6<B<^<y<",
        "`r4I ",
        "%VIM]/",
        "9K~tM",
        "Hm\\aL?",
        "+;!\"8",
        "E0/3~",
        "D0TP3",
        "setCext-setExt",
        "SOFTWARE\\CheckPoint\\Endpoint Security\\Network Protection",
        "L$(Ib",
        "MsgWaitForMultipleObjects",
        "*}Xay",
        "?(?0?L?h?l?t?x?|?",
        "XHf)u",
        "4r*uF",
        " mf5b",
        "/ON{o",
        "dG5=v0",
        "3L$h#",
        "6B6K6S6[6",
        "1`fwf",
        "<<u?1~",
        "T%#MP",
        "0S@\\kB",
        "Failed to format property value",
        "7za.exe e -y \"",
        "t1SVj",
        "u}Ue_u3",
        "%4IHB",
        "Try,3",
        "t:!6F?[N",
        "MA&|;Lq",
        "V5@pvK",
        "TFTP response timeout",
        "TU,z2k",
        ")(YXpXB",
        "V?ku6o[F}",
        "y%a4VO",
        "{)Iml",
        "=>Y%R",
        "W~^nK)z",
        "W;D]\\",
        "SSL2_READ_INTERNAL",
        "GetThreadContext",
        "6 N=-",
        "mwY^h;",
        "ASN1_PRINTABLESTRING",
        ".S[VPP",
        "&R3f+",
        "4&454E4",
        "Y%=%wd",
        "2!3;3V3q3",
        "7(707F7[7a7",
        "mP,z]=f",
        "cT(!%",
        "m8YwE{",
        "4p}ve8\"&",
        "949T9x9",
        "-sBf\\>@",
        "R0wl\\QxP[h",
        "Z06&v",
        "X,#li",
        "Ta\"[@",
        "ssl_mac_secret_size[SSL_MD_MD5_IDX] >= 0",
        "Wzq3X",
        "hY13>w",
        "g'`a'U",
        "4[n(+",
        "A&H1x~",
        "cp191",
        "c0OKU",
        "Df(kS",
        "Error accept()ing server connect",
        "countryName",
        "2o3u3{3",
        "f %WJx",
        "=1>>>]>j>",
        "Q,Se~",
        "=dim;",
        "GZ?H:",
        "H{1WGB",
        "H(kgv",
        "+2^=A",
        "OuTWi",
        "=r_i\"",
        "missing eoc",
        "2%3P3{3",
        "q.b~9",
        "\\$8Pj",
        "NO_OFFICE_MODE property is 1 -> return true",
        ".yH>A",
        "5 lF\\_h",
        "IokDUS=",
        "yK 0A",
        "6GL^'",
        "Z|'jl+",
        ">F$TI+",
        "xh#9w",
        "getGinaName",
        "<0<T<\\<i<o<",
        "<RXoe",
        "APOP %s %s",
        "9r:}:",
        "$k:S{o",
        "EaP8(",
        "?`hahK",
        "bs-BA-Latn",
        "3,3034383<3@3D3H3P3X3`3h3p3x3",
        "yRs.0",
        "9$}+ ",
        "l$$Vj",
        "]K^l#",
        "M3MSMsM",
        "Cached msi of Check Point SBA (",
        "7W8q8",
        "9$9)9}9",
        "6p&tM",
        "8|*[-n",
        "unable to find ecdh parameters",
        "MergeCommonBackup iterating via common folder failed, error: %i",
        "G^5$@",
        "T\"(_.",
        "failed to stream out ComplianceAPI.dll to tempfile.",
        "2vj\\l",
        "}KMv#VW",
        "TfC5m",
        "~8VUg1",
        "iCMEH",
        "2'282E2",
        "B*w}:>",
        "tn-ZA",
        "fjR.zCZ",
        "xar4sut",
        ".\\ssl\\d1_srtp.c",
        "[{cSUC",
        "o^%&{",
        "nm&VZ",
        "xY)j=",
        "J.L71",
        "unsafe legacy renegotiation disabled",
        ">]r6^",
        "NvE*sP",
        "t39od|*",
        "HO()A",
        "Failed to copy %s to %s",
        "DGPZN",
        "SSL_CTX_use_certificate_ASN1",
        "f-xh/",
        "}dvYs",
        "i?S~OQ",
        "|mDkp]L",
        "2(3s3x3",
        "cHs-}4O",
        "n[[nFb",
        "ow=hs",
        "=(>f>",
        "!Q&WS_Q",
        "v+38?R",
        ".tls$ZZZ",
        "/!_]x",
        "1kS$#",
        "k%rj!",
        "8I8g8w8",
        "SetPassword:  SetPassword finished.",
        "0.]H]G",
        "x]@=h <`\"",
        "CfA+J",
        "/X^'z",
        "gf8F^",
        "@w%w H",
        "8yB>Ni}",
        ">q3l*",
        "`|>h(h",
        "Jj]X?CN9",
        "1qnvg3",
        "/UlO:",
        "no sig content type",
        "'3e!^",
        "Z[6]2",
        "Rpq;4 ",
        "ETHg|r",
        "\"u&:CSn",
        "MoveFileA",
        "%oXtW^,",
        "&C[wb",
        "%)IZy^J",
        "imsinstall.dll",
        "*dYL*[|f",
        "Nf 8wD",
        ";OLu&;OPu",
        "Ve0[{",
        "PnHhuM",
        "mX|$_",
        "~{+Pe4",
        "Converting error(5) to success",
        "R weN",
        "=H>O>[>i>",
        "E(-Ce",
        "L/X/0",
        "p is not prime",
        "SWhHl#",
        "jhBC&",
        "NgUW8R",
        "failed to allocate memory for string",
        "sz7v2",
        "extension value error",
        "w}'IA",
        "2xNxb7",
        "^&jCn",
        "@Oq!c*",
        "1)*W ",
        "#>g\\4",
        "gY@q*[&",
        "Install Helper process failed",
        "G4V:C",
        ")m!!i",
        "`gN&|",
        "#B:0.",
        "french-swiss",
        "WcK*&",
        "eN-V7",
        "We are in 32 bit OS. Registering SCV Plugins under regular TRAC key in registry",
        "0%171G1t1x1|1",
        "6Wf:s ",
        "eD# $",
        "?awuS",
        "7Z8q8",
        "7f4#t-",
        "%F}x}",
        "@^Ydgjg",
        "hAv969",
        "pq?1=~",
        "~\\K'31$",
        "VjuhT`%",
        "UN'f^",
        "U#ro-8a ",
        "@@}rr",
        "7rhAI",
        "5*m *",
        "-y?2/Bn",
        "authsafes",
        "2*2O2`2u2",
        ";'<N<",
        "(-.JC!h",
        "&jm4U",
        ".AaVS",
        "u|%z~+.",
        "w$VKG`9",
        "Syskd4",
        "YfVL8",
        "nl1o\\.",
        "N9vR;",
        "OKtvu",
        "19}3(",
        "xK}!n",
        "8*949\\9o9",
        "@XsW$",
        "[LICENSING] ERROR: (appending) wrong number of licenses after appending (expected %d)",
        "4 3 e",
        "^(9^0t",
        "retrieved temp file name: %s",
        "W(}\"HI.",
        "9oylZ",
        ".t-,?",
        "t$ Wj",
        "YZfZz9",
        "J>@G_",
        "6$848a8#9",
        "; ;8;H;L;P;X;p;",
        "E,PVS",
        ": ;V;r;",
        "Mk,^G",
        "(Fdj%\"",
        "7$7=7F7P7i7s7",
        "_81V5",
        "%9*SV2",
        "]qT1up}",
        "&K#Y0",
        "6<V-N",
        "basy*3",
        "ps*3t",
        "H1PS+Z",
        "V3!Sd",
        "Installed",
        "yM'A#",
        "fC2<V%",
        "\\$ UV3",
        "SK8j]h",
        "klifsdk",
        "]BebG!",
        ":A<v<",
        "- [9L",
        "0#0.0>0V0h0",
        "_~;Z_",
        "t11R2$j",
        "j+-:^:",
        "SA%:FR",
        "ktj]}",
        "0M0}0",
        "+dU|A\\",
        "A7Bg>",
        "AreFileApisANSI",
        "Z|(G=",
        "OKU-\\",
        "(lQi?",
        "Tel Aviv-Yafo1/0-",
        "Xs2o#",
        "3!3:3Z3d3",
        "qDY8v<",
        "=>>V>",
        "5d.T4",
        "/f:(L",
        "=x4|0",
        "p:bh ",
        "FindClose",
        "L!A!F",
        "3:AIAYA^AeArdw",
        "UZcJ=",
        "R79a\\.",
        "$qeq@Aby",
        "\\LPa#",
        "9_XH@",
        "Y<y,/",
        ">w(a3nG",
        "D$ 3L$HP",
        "5w0n( q",
        "wIQ1TQ",
        "cY<|'",
        "GetPriorityClass",
        ";}|n2",
        "Y/5E;>",
        "bt>i;",
        "4T5`5",
        "Q?d{Mb",
        "SEC_E_ILLEGAL_MESSAGE (0x%08X) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.",
        "<%`;B+",
        "|0J&Lj",
        "<?<b<",
        "jjpt_",
        "VyiF^",
        "++v9(C",
        "Key Encipherment",
        "eJep^",
        "L3*F'1",
        "1]smu",
        "Timeout waiting for service",
        "sii(iq",
        "XB=La",
        "0'0F0\\0f0l0w0",
        "Failed to change recovery action to ACTION_NONE for service %s. error %d.",
        "4 424?4G4N4W4",
        "unsupported encryption algorithm",
        "^K\\\\c",
        "*>K+*",
        "{KV_-\"",
        "7+8i8",
        "\\:39[",
        "DFiWmH_",
        "V~=oU",
        "2NBt5",
        "C;uU{G~",
        "xtPoc",
        "/fN|[",
        "C '{|",
        "B iv;",
        "DO_BLOB_HEADER",
        "H_Gr/",
        "h|T,':",
        "<$<.<9<C<P<Z<g<m<x<",
        "Fault address:  %08X",
        "_!I[f!",
        "oN*NV",
        "&Fl}K",
        "|`q`2@",
        "I2lwt",
        "/up4<J",
        "8G=Re",
        "Z?&P])'",
        "3rrJo",
        "9(989<9@9X9\\9`9d9h9l9",
        "VSSetInstalled: cannot log in",
        "KhJ1A",
        "recursive_directory_iterator::operator++",
        "D`GQ6",
        "<(<D<`<|<",
        "/Z^&(",
        "3/454;4A4G4M4S4Y4_4k4(5",
        "4)4E4T4",
        "+LfGT",
        "vhTEr",
        ",A-A.",
        ";^;w;",
        "e~[]|",
        "(RCTVb",
        "{DqfG",
        ";f[)/",
        " s>TA",
        "URLFUninstall started",
        "vKg!O",
        "LS{>)",
        "l7;sv",
        "z4+ei",
        "k7.z9a",
        "8 8H8l8x8",
        "O7,D^1",
        "3}e73#",
        "<r+xP",
        "2(3H3h3",
        "383e3",
        "m$ Ob",
        "w.w(]",
        "262E2",
        "oGq$U",
        "IiGM>nw",
        "M3fU3",
        "D$<VP",
        ",zqs03",
        "D(uH4k",
        "d$~e5MA",
        "(B}l6",
        "{Rn{<",
        "\\9oPZ",
        ":Gihw",
        "c{TMM",
        "XS<Md5",
        "=TNx\"",
        "Host: %s",
        "n(IyY",
        "Mn<;t",
        "RYu;9",
        ",cjHG",
        "e29=w",
        "$a(Yn",
        "yc<mp=c",
        "fr-CH",
        "r&P[k",
        "#L08B5",
        "8m&\"qO",
        "S[> u",
        "Gq@.7-",
        ".?AV_RefCounter@details@Concurrency@@",
        "]ta8*",
        "\\V,Pm/",
        "'tst ",
        "PN'4}",
        "!|(jk",
        "%s exists",
        "=C~CjCkCl",
        ")*)J)j)",
        "r1NjD",
        ".+Zv9",
        "pn;t4",
        "7>7P7s7",
        "VC'#/w'",
        "(}^zx",
        "9:9U9p9",
        "CW^yi[",
        "35xeN",
        "h:$7N,",
        "p;qYb",
        "Path syntax error",
        "SOFTWARE\\CheckPoint\\EndPoint Security\\Framework\\Adapters",
        "3\\*s(",
        "mac setup error",
        "VUdF%",
        "zJ$Ja",
        "ITEegm",
        "</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX",
        "G4e2x",
        "[\\(*BS~",
        "`m(WY}J",
        "$]o7N3",
        "O)-Pl",
        "\\lsdunhideused1 \\lsdlocked0 Table List 2;\\lsdunhideused1 \\lsdlocked0 Table List 3;\\lsdunhideused1 \\lsdlocked0 Table List 4;\\lsdunhideused1 \\lsdlocked0 Table List 5;\\lsdunhideused1 \\lsdlocked0 Table List 6;\\lsdunhideused1 \\lsdlocked0 Table List 7;",
        "v/B061~I",
        "8)848S8",
        "Jzwr2",
        "<>LVMO",
        "Z-v{l",
        "?-?I?e?",
        "7ryDr",
        "YYjgXf9",
        "j~D`5?",
        "mY`tz",
        "75l<T_,",
        "?s~]WR",
        "2&L+9[",
        "BY65>3",
        "aSh@2&",
        "RjX14",
        "'tm^.^:t",
        "`Q'-`{",
        "compression library error",
        "Kc)t-",
        ".?AV_Root_node@std@@",
        "9$9v9\":-:d:",
        "j2'/Y",
        "PRODUCTCODE",
        "<B>v?",
        "z{!JRxF",
        "PMOVZXBD",
        "uV+Yqu5YLp",
        "3,303<3D3d3",
        "undefined",
        "ByY_c",
        "ocsphelper",
        "failed to create thread for stopping service with error: %d",
        "\\lsdsemihidden0 \\lsdpriority0 Default Paragraph Font;\\lsdunhideused1 \\lsdlocked0 Body Text;\\lsdunhideused1 \\lsdlocked0 Body Text Indent;\\lsdunhideused1 \\lsdlocked0 List Continue;\\lsdunhideused1 \\lsdlocked0 List Continue 2;",
        "YR>{';o<",
        "@@Z0x",
        "9*9<9N9`9r9",
        "4fqP2",
        "Success. We added the property.",
        "I('55%-0",
        "Sj31 ",
        "krb5 server tkt expired",
        ",d:|7w",
        "[CPQ#",
        "bWo3\\",
        "Yp^r>",
        "@[1~+pg",
        "TM&Id",
        "cCCB^aN",
        "D$83D$",
        "d;Gv+",
        "0EQ_9",
        ":_HI{",
        "n%*#Do",
        "*':UBX",
        "SSSSQPSh",
        "secp128r2",
        "w26Tb",
        "KxSjb",
        "WatchDog service stop DLL path %s",
        "9}X{2G",
        "2D2t2",
        "ad dvcs",
        "D[8J?7",
        "Oi2TQCb",
        "zc%yw",
        "UVllY",
        ",nan=nEnMlU",
        "gItL\"g5,+_8",
        "yYDM+",
        "Cw)L9",
        "aV6_XciR",
        "h!PnM",
        "o2-NfMy",
        "riUJ#",
        "gAQkqd",
        "SRuB9\\",
        "|\\hle",
        "0+0B0P0",
        "\\{QG.z",
        "T7$Yrh",
        "[04](",
        ":yFQ2",
        "RN9xF",
        "uIG$F",
        "[9] >",
        "s[^A\\",
        "8j;TG9",
        "JVXXjh",
        "z-kJd",
        "OAH?3",
        "@ia8A",
        "pvRFh",
        "+8$<PN",
        "TS_TST_INFO_set_serial",
        "T$X#L$T",
        "l$$t5",
        "X W$V",
        "A=ud'",
        "GLv6!",
        "D7C!Q",
        "private",
        "SsjUl",
        "vsconfig.xml.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "Streamed out %s to %s.",
        "&iw]KBn",
        "-5#!>",
        "mw@bp",
        ">\">m>",
        "1p!hn",
        "9t:x:|:",
        "L`<+bG",
        "TQ_2(",
        "66Gn$",
        "] <wz",
        "c$JAp",
        "E[SE9",
        "`vucf",
        "~m,9O",
        "VnaUnInstall",
        "uvj7=",
        "yv\\uh",
        "Y;lS^",
        "certificate has no keyid",
        "\\rtlch\\fcs1 \\af0\\afs24\\alang1037 \\ltrch\\fcs0 \\fs24\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 {\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid5854202\\charrsid15169477 Software License Agreement & Limited Hardware Warranty",
        "h&B~m",
        "iyVo:",
        "HH!7n",
        "&.={{",
        ">P>X>",
        "Failed to completely read ca script.",
        "e|bajNgN",
        "XzX_X\"",
        "Yh0kJ",
        "8O8m8",
        "Uv:8s",
        "oOE~3",
        "%I64d",
        "EPAM_Install finished.",
        "5 5<5X5t5",
        "Lu}(1~B",
        " a\\y3",
        "\\\"\\2\\B\\R\\",
        "|}}ZP",
        "PKCS12_item_decrypt_d2i",
        "#]bu\\",
        "3cBXoVRX",
        "161G1\\1a1",
        "CUwXq",
        "-2*i'",
        "Zl\"Zh",
        "U{U@<",
        "2$2,2`2p2|2",
        "-Ld'3TX",
        "(HQXl",
        "tbsRequest",
        "F}i>W",
        "d,'WJ",
        "{[^c^o^",
        "VWjmh",
        "\\f1\\fs20\\cf1\\insrsid13775897  Hardware Product}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529  has not been activated, the warranty will be valid for }{\\rtlch\\fcs1 \\",
        "w6bqmc",
        ">:@:B:D:",
        "\\@)W8",
        "of-ymD",
        "CL_OspK",
        "bad hello request",
        "595|5",
        "LCxzp",
        "C4S &",
        "NZ6n}f",
        ";#U=Q}qc",
        ">\"?s?",
        "789>9c:i:q:",
        "l,RLw",
        "SQ|J5",
        ")c{Kj)",
        "E3X&f",
        ":4ht\\",
        "#gjp?y",
        "SSL_set_session",
        "policyMappings",
        "GetCurrentDirectoryW",
        "o$|Qi",
        "#7b<E",
        "VT\\2A",
        "9(949@9L9X9d9p9|9",
        "ez~LdH",
        "iSD8i",
        "JBMsL#",
        ".qs/)",
        "}2j8=J",
        "NM;.V",
        ")a,3b",
        "hRVaW",
        "gpiz*",
        "PVE,I,9",
        "34w9+$",
        "%s %2d %02d:%02d:%02d%.*s %d%s",
        "TXsz9%*",
        "]6'T.",
        "sma-se",
        "b,k69",
        "h,fu.",
        " \\<'-yp",
        "YUafe_",
        "FE}?A@",
        "zoQtWC+d",
        ":rvvm",
        "bGb4LI",
        "v#M/S=",
        "9^4u0R",
        "6)'k8",
        "%sScriptRun.dll",
        "CommitCAScriptCleanup",
        "]J!NW1",
        "oM2^:",
        "OG;TL",
        ";B~J}`",
        "B)?mI",
        "7 7&7,72787>7D7J7P7V7\\7b7h7n7t7z7",
        "lL=ml",
        "L$H_^][3",
        "!;Ru{",
        "TOYNO",
        "UP<47",
        ",6  xc",
        "d& 48",
        "D.2./,",
        "set-brand-IATA-ATA",
        "+F=&@",
        "<p3_D",
        "TspBW",
        "u*O>[g*1",
        "5Z5b5",
        "]ofs)l",
        " KAaz",
        "l$0t\"j?U",
        "m]SVk",
        "%m_Y/Q",
        "(_|:I",
        "R)*\")",
        "3d|>*",
        "i7}K2D{",
        "eyLSI",
        "-R`)S",
        "pe'a2",
        "W9HM#s5<",
        "xrM%(2",
        "/|?m$",
        "{TzE(",
        "Z8a|b",
        "qy:4%",
        "lff,A",
        "&kPH|",
        "IDE_CUR_DIR",
        "}qBN2",
        "?X33JV",
        "^SJ(3f",
        "2S/_$oLSW",
        "hr-HR",
        "nsCertExt",
        "&d%1 ",
        "L.u{ S",
        "Z;;mX",
        "Xh4kj,\\",
        "OSYIa\\",
        "#*c_|",
        "&+pyf",
        "jejxj",
        "sWixRestartResource",
        "=%=6=G=M=R=W=k=",
        "<6D6L6T6\\6d6l6t6|6",
        "10<Ea",
        "1tk=D",
        "-H} Y",
        ";al}9",
        "!f{N\"",
        "$TUv,",
        "Gbc)x",
        "]jb6P",
        "*~mY9",
        "StopABService_rollback started",
        "5L5]5n5",
        "GetProcessTimes",
        "4$4)4I4N4",
        "'/|-Z",
        "EO/TBbk",
        "ey^o/<",
        "0X=G~",
        "quarantine\\temp\\sdk8\\Cache",
        ".k!%~@",
        "*M\\<Jy?A",
        "&tX-yjo",
        "W`0Th",
        "=0=B=u=",
        "y,eW8C",
        "\"x$O7KY\"",
        "x{)_0",
        "PINSRD",
        "L$D3L$43L$,3L$",
        "iuP<$1$",
        "(h`H1pqA",
        "FDgnW",
        "h@=Y(c)",
        "dn#f*",
        "t%(q5^",
        "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
        "wcbn#",
        "PKCS12_ADD_FRIENDLYNAME",
        "6I9O9",
        "ls+U'",
        "5cUVOA",
        " entering...",
        "3(7X^Hn",
        "7*717",
        "vI_&\"",
        "\\ESF\\",
        "serialNumber",
        "<8wtAw[",
        "16dQ3",
        "@}g7Xl",
        "5 505@5D5T5X5d5t5",
        "}ru]p",
        "AI+^n",
        "iBU{c",
        "3s$<CDE4",
        "h/V W",
        "<0|]<8",
        "failed to resume file:// transfer",
        "S'02j",
        "g7,+O",
        "set filename failed",
        "6h6zk",
        "NIgEni_",
        "p{z,w",
        ">F>X>e>|>",
        "$8:+B ",
        "q;+V\\",
        "R<23W4;",
        "N\\!ws*",
        "6||ao",
        "C0[=[s",
        "LY\"J,",
        "0W{\\\\k-",
        "bY:s2",
        "E\"25'U",
        "4?jYs",
        "Failed to concat key: %ls for secure object: %ls",
        "tGm?F",
        "pYF.~*ep!",
        "; ;$;8;<;P;T;h;l;",
        ",0X0\\0`0d0h0l0T5X5\\5`5p7|7",
        "x3uT}",
        "%Ifa8",
        "4g[m.",
        "Jn&X4Q",
        "0ZodB",
        "%p?&I",
        "sslv3 rollback attack",
        "uGO`d",
        "$NI#I1D",
        "Spe]_",
        "2A2l2",
        "2L[xL",
        "2<7KAQ",
        "hD;Wx",
        "2!FOBe)4n2>",
        "_OGVu>",
        "/6J&H",
        "****************************** CheckUninstallPassword ended **********************************",
        "=*c{f",
        "jojqjsjukwU",
        "t$bSl",
        "2@'kV",
        "\\bin\\dingo.dll",
        "QI{#6",
        "uA3kpC0O",
        "h=c^/=",
        "2+4/43474;4?4C4G4W4]4c4i4o4u4|4",
        ":A:W:",
        "`PD?|V4m",
        "DTLS1_PROCESS_RECORD",
        "@NI[rq",
        "(7]4;v",
        "3UxeA",
        "C`QWB",
        "1-!A(",
        "qe-Tm",
        "7%7A7]7y7",
        "5#636;6K6v6",
        "iAZH{",
        "$\\,OY/",
        "0w>Ik#",
        "iBp\"P",
        "PjV+Yr",
        "V.`#j",
        "CM Sj",
        "4]['W",
        "dh_paramgen_generator",
        "jDTc?",
        "connecting.gif",
        "be( 0",
        "1%)JW@",
        "8f9^,u#",
        "=A>X>",
        "}q:Q7",
        " 5B2W",
        "090C0d0k0u0",
        "PO7bQ",
        "\"+<$C]",
        "U\"m.g",
        "w8i_q",
        "18-g03",
        "~XP'.",
        "uy<,uuS",
        "__w\\w0",
        ":BZ!Iy",
        "6$6[6a6w6",
        "4mc>gPKD2",
        "Nunpc62",
        "FgeH5s",
        "Gd;`N:",
        "z=hhU",
        "Pjlj\"",
        "uHCLR",
        "krb5 server tkt not yet valid",
        "could not obtain hardware handle",
        "bk/;1",
        "TT!-=",
        "D:\\EndpointSecurity\\Modules\\osrc_wix3\\build\\ship\\x86\\firewall.pdb",
        ">*VW:",
        "?1TP+",
        "DeviceIoControl",
        "kNJ'lyS",
        "9L9P9T9X9\\9`9d9h9l9p9",
        ":/3di",
        "ZT_6/",
        "?./>S",
        "8i=|DWy",
        "/lLC`s@",
        "Y'KF'",
        "wzG7,",
        "VSPasswordRequired",
        "xvNo'R9",
        "Error: cannot create dir '%s' (errno=%d).",
        "malloc failure",
        "PKCS7_SIGNER_INFO_sign",
        ":!;#<><Y<",
        "aS KBZ",
        "&YIQ8",
        "?+?D?R?]?h?s?",
        "WQPu?",
        "Z=g&TVm",
        "@\"DcO",
        "6HO@'",
        "fh{?ECz",
        "D$<SU",
        "!+Ciy",
        "NFYDC",
        ".?AVfilesystem_error@filesystem@std@@",
        "Pj}j!",
        "SmIO3",
        "XO8k'W",
        "0jr3D",
        "f}!tq33/",
        "); or if You are a company that provides such managed services to Standard Users that are a part of your corporation or",
        "+#4.;.C.",
        "QoEsd#",
        "could not create temp record for table: %ls",
        "Jd4mKum",
        ";(2( ",
        "yPypy",
        "' Nsy%",
        ")~*sO",
        "<?@3\"u",
        "GYK3B",
        "x#s'O",
        "nkYzYS",
        ";D$<~(h",
        "9I{;`",
        "k&5$9U_'",
        "vDn#q",
        ", AVq",
        "UCc=.[",
        "Y50R$:",
        "[IsServicePPL] dwLaunchProtected = %d",
        "aUS3c",
        ">*Gn'*",
        "\\_m-Hq",
        "oaNbva",
        "ELs?T",
        "_N~QM#",
        "=QB}V$",
        "Content-Encoding:",
        "0*&.g",
        "Ir*>7",
        "certificate is not yet valid",
        "Failed to get reg key root for secure object: %ls",
        "=ApSE?",
        "#9LA.",
        "iIg0[",
        "ntNo?h/",
        "j\\8XH|m",
        "Hv[q[",
        "-N@hm",
        "Tj~*l)",
        "2Q2x2",
        "nhLxV",
        "/WYc|",
        "W&4i0-",
        "I}]!|",
        "c\"hH\\$",
        "[;6*/+X",
        "couldn't open file \"%s\"",
        "3[xm@$",
        "}Z&ra",
        "i+4ID",
        ".e_gK",
        "949a9|9",
        "9/:D:N:",
        "3V4i4v4",
        "$fwfPK",
        "q.{QWhE=",
        "Enterprise (core installation)",
        "twdq0",
        "d0 $#",
        "=:>n>",
        "[VSDATA]    %d.%d.%d.%d",
        "559ol9",
        "]b+y3q",
        "g&F.~",
        "*t$}M",
        "@|x'#!",
        "\"NXP9",
        "Address family not supported",
        "L?)_D=",
        "4C4L4V4Z4`4d4j4n4t4x4~4",
        "$XZD%",
        "1g43z",
        "b{4x8",
        "qV#qq",
        "Yf2)n",
        "Can't get user localappdata",
        "yL&a';",
        "Q@/5uq",
        "h'-o?FY",
        "] ,<e.@",
        "#?t'\\",
        "vx;Wq",
        "Zi)XD",
        "_2nd_",
        "i$+=a",
        "98r1)/r",
        "HGlPR",
        "xNuf@",
        " e&;W",
        "CD-^<,m",
        "/>Li'",
        "Nx;N|}",
        "e.O+q*",
        "0*iq`_x",
        "installProduct;",
        ":z'H>",
        "zn.7<?",
        "]5S}M",
        "upgrade, no need to delete disconnectedPolicy",
        "8dy2lc",
        "b/1hI",
        "At%X?",
        "s()z%",
        "f(M!@M-xo{I",
        "5{)K69",
        "9\"969D9",
        "KqX|\\",
        "2|rV_",
        "\"ybt0",
        ":i:s:~:",
        "F~}8xG*lK",
        "lh]Z-",
        "qb]Hb",
        "%*L->i",
        "OJ>VY",
        "/e_6!F",
        "{teX3j",
        "[J>z\"",
        "YO5:U'O",
        "\"^UeT>S",
        "`Jwb\\'",
        ";+<7<y<",
        "G'Jp1]",
        "FILE_READ",
        "4P-bS",
        ".4GO4E#",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{3D7DC711-C2BC-4245-830D-380C01490410}",
        "0~o\"V",
        "$V#|\"){",
        "KD^16(I",
        "!=@jU",
        "3\\$83\\$0",
        "868R8n8",
        "u|MB+",
        "CnMmH",
        "CX[_^",
        "(*tC!",
        "0&121v1",
        "4.4V4j4",
        "YY;7u",
        ",~J:~",
        "4V|J=",
        ":)-)C",
        "Y\"~O/",
        "<Q]a%",
        "E&0L,",
        "-){+z",
        "q^+0Qs",
        "JEWv)?J&",
        "0RfdU",
        "\"$ SA",
        "U/_q{",
        "<4<T<x<",
        "O,zJFI",
        "'hS:v",
        "0aZg0",
        "ony$!",
        "UUTIz",
        "1dr_^",
        "pa),h=]$",
        "SdkyBRi",
        "\"Q^R`|",
        "StopInstHelper custom action start.",
        "sr_endpointBanner.png",
        "LHfUI",
        "l#T4V-J",
        "hx0?(5",
        "\"Io?]:",
        "M~^|n",
        "_q(AMY",
        "jkjxj#",
        "(8ph(",
        ",e`t$",
        "0UR,b",
        "$M_CJ5",
        "< <K<P<x<}<",
        "2|y_v",
        ".CRT$XTZ",
        "%d.%d.%d.%d",
        "f9%'bY",
        "unterminated string",
        "1}T~q",
        "J\\NlW",
        ":IM=y",
        "X(-5V|",
        "DES-CFB8",
        "Ub^o9f",
        "1|9dY\"",
        "0}}{]",
        "l8e~w'",
        "d1NZ\"",
        "6w7R8\\8",
        "2gh7-r",
        "3Ldj,y",
        "1(L#]",
        "Timeout was reached",
        "<<<@<L<P<p<t<",
        "2@2E2M2",
        ":.NtX",
        "Jq#]5",
        "V%A+=",
        "8*8O8j8",
        "2QW~'6",
        "9{t3 ",
        "H--^zR",
        ";:<#=",
        "M f/)",
        "X( &BNWxW",
        "s6X};",
        "A|y S;",
        "tN4(.",
        "]Y\\jns",
        ">/>Z>",
        "X\"yNG$",
        "KGGc}:",
        "i6;2,",
        "wsw6=",
        "\"L*TW",
        "+9b_7c",
        "Lw|!-D",
        "p2CX`",
        "No0sj",
        "tJediN%",
        "a<K9G",
        "mpuKj",
        "AaOxt",
        "xVTL;1",
        "D$,PUW",
        "multiple sgc restarts",
        "WqyoY>X",
        "WP<xv",
        "n]`v0",
        "5/7P7",
        "GkI4F",
        "p4+]4XF",
        "t~b$B",
        "()`^O",
        "'7RcQ5I",
        "(9uNo",
        "Jf*;U",
        ")$fhC\\",
        "2(0;!",
        "yEbvN",
        "C(o+V>?",
        "bC6i4k",
        ",wB_w/+",
        "A3WvDj",
        "brPQuj",
        "PAVGB",
        "-~M7[",
        "xh@es%",
        "q+eQK",
        "-----BEGIN ",
        "+h+PN",
        "Wov.0",
        "``De6",
        "unsupported signature type",
        "9 F[An",
        "-\\+UerH",
        "O3,s~H",
        "Requested SSL level failed",
        "7#7/7h7r7",
        ".KX;`{",
        "MWF/]",
        "^$hpL",
        "sda_=",
        "P#hj ]",
        "\\*\\jb",
        "KGYQ~>",
        "p8V]bo",
        "ADH-AES128-SHA256",
        ">1>E>~>",
        "CMS_decrypt_set1_key",
        "x!j^&",
        "SSL: SSL_set_session failed: %s",
        ":n\"P6Xf",
        "4&5T5n5",
        "B?Cc@",
        "0,0F0S0m0",
        "*uC8N",
        ",|,'L^",
        "*Hpa3S",
        "RC5-CBC",
        "_sendJson@4",
        "NR2,X",
        "client_version",
        "MK t0Y#S",
        "<\"<-<:<i<",
        "n-{_;E",
        "COSH'",
        "a[OZG",
        "nk2@i4>",
        "$;@I,",
        "{{{{{{{{{{{{{0",
        "I67b ",
        "RegQueryInfoKeyW",
        "VWjch|",
        "V&N}:",
        "0^wF\"'",
        "W{+|&",
        "1&$KG",
        "]g:;P ",
        "jp^1Y",
        "98:C:R:}:",
        "DeleteService",
        "< <(<0<8<@<H<P<X<`<",
        "status too old",
        "16=u3",
        "@>G ,",
        "7E7i7",
        "/1P+.J",
        ")X[]W",
        "1\"1)151?1",
        "z(Rp0]",
        "##]'S",
        "D$ F@",
        "fE3RQ",
        "curl_easy_perform",
        "CD2|>]l",
        "mPd/6",
        ";smO<d-",
        "W8^0uc",
        "V'Rl0",
        "Fu{f>]zV",
        ",WdflfbM",
        ";_^][",
        "!AJp}",
        "uC}O)",
        ";/;b;",
        "2>2n2",
        "*fCqp",
        ",bm[bcf.",
        "u_j V",
        "D$$^][",
        "EvtCreateRenderContext",
        "y,v6X",
        "O}?}4",
        "px[ZCM",
        "K/h6pB<",
        "dfp+8",
        "5-525A5",
        "2p~Q.",
        "[8+tGo",
        "Ie}[^",
        "(Hzo=",
        "iOjlT",
        "L~+H}",
        "{\\fbimajor\\f31503\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}{\\flominor\\f31504\\fbidi \\froman\\fcharset0\\fprq2{\\*\\panose 02020603050405020304}Times New Roman;}",
        "Ql$J%D",
        "LockResource",
        "URPQQh",
        "?H'd;",
        "X#4o$N",
        "byNt2 ",
        "1\"1;1T1m1",
        "31Vo^",
        "jT(VH~>",
        "9P]0P",
        "ssrem inet_ntop() failed with errno %d: %s",
        "wuo`t@",
        "~1} {",
        "iye[syY",
        "YvP^@'",
        "p%'Et",
        "3+728",
        "CountDataClientClass",
        "GetMessageW",
        "}0?{q]<_",
        "\\u)PV",
        "8ek]*",
        "4)}K%",
        "}Gn_I<",
        "8Q%'&t",
        "JO\"[e",
        "-|#?D",
        "%.L&]Y)4Q",
        "eKt[4",
        "|$ PW",
        "exists",
        "UCw>+",
        "Resource temporarily unavailable",
        "}@+0K",
        "e4Z lF9",
        "-Qq4xW",
        "*:UPJ",
        "w\"9!;",
        "1R5w1 bk",
        "CT!_Q",
        "[2G1L,",
        "`|r:n9",
        "8<8|8",
        "z/erSk",
        "9\\[I)->",
        "\\#_0K/",
        "7MeH)",
        "{}Gw @",
        "s:(En",
        "azC:=",
        ":$;U;",
        "<ru3>",
        "q|e q",
        "Found bundle for host %s: %p [%s]",
        "1ry9sO ",
        ">:}wP",
        "id-aes192-wrap",
        "LCA)E",
        "POLICY_MAPPINGS",
        "fM+cV",
        "BN_mod_inverse_no_branch",
        "~I@dMy",
        "$[}V%",
        "*AV{.",
        ".?AVcontext_unblock_unbalanced@Concurrency@@",
        "D~Ym(",
        "D*`C@S",
        "CreateToolhelp32Snapshot",
        "*Tn=eI",
        "9OV'u",
        "Eyt(c",
        "2|,}C",
        "B:KNH",
        "P;4} MC",
        "VizJh",
        "o. s[o^",
        "ZxnA4",
        "[THREAD] Terminating thread %x, no dump needed",
        "\"'ccu",
        "7l8s8",
        "n3L$<",
        "LQ_&5",
        "TS_RESP_SET_GENTIME_WITH_PRECISION",
        "ar-QA",
        "G0CnV\\",
        "3E@7]z",
        "0x;p?",
        "t+j0j",
        "d?1(PK",
        "jsj~j",
        "twyr6",
        "AES-256-CBC",
        "FgYn,",
        "2C3q3",
        " #;AR",
        "*F1%K?",
        "TUol|T",
        "rules",
        "AcquireSRWLockShared",
        "i[@ Q/",
        "IyMF1",
        "\\9DgAJR",
        "L)BI;l",
        "FWRemoveAfter finished.",
        "db.>OW",
        "c#T?L",
        "&t&D$",
        "_n@&'",
        "8aMbF$",
        "pa>Gk(YAe",
        "{A~!:l",
        "g5Dy:",
        "*I)3U",
        "p&g\"\"l[",
        "S\"6cz",
        "sslv3 alert unsupported certificate",
        "%,mYc<",
        "sxQAMt",
        "u5jZWV",
        "wwAxd5",
        "-D})J0",
        "PBMAC1",
        "G=paB",
        "OhSQJ",
        "Z%t~~",
        "EpVB2wIf)P",
        "Installer is done ... this is the last message.",
        "g\\/!S",
        "D3t _0",
        "y:)}b",
        ",i}dAb!",
        "`D2vA\"",
        "kVMx^",
        "I{YJo-",
        "{Ng#~M",
        ")[/{b",
        "V%NT`)",
        "te;L$",
        "3$3=3V3o3",
        "FZ[(Un",
        "9XcNyC",
        "HF~#KV",
        "J*&'I",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{E4DC62CE-5F95-11D6-B254-00C04FF4B435}",
        "B4\"H]",
        ">F?X?",
        "=2?W`;",
        "I$'tFH",
        "=1=^=",
        "|j@hH",
        "y*b8[",
        "lB]uN",
        "u&P%IeY",
        "s*')\\r",
        "[Mock] Loaded %S",
        "nk/{:z",
        "+b\"fn",
        "tFAOufwB",
        "G)!/a3a;a",
        "ld6]O",
        "common libcrypto routines",
        "-0a q",
        "^l2o-w",
        "ssl2_set_certificate",
        "    <osfirewall>",
        "unique_client",
        "-W{'C",
        "+=m37",
        "2UXUkH{t",
        "xTGK/",
        "(mEp%",
        "t$$UV",
        "=4=9=M=j=",
        "r}:@U",
        ":1:6:H:^:c:u:",
        "+,-.///1",
        "connection aborted",
        "KHNXJ",
        "id-GostR3410-94-CryptoPro-XchB-ParamSet",
        ";*vH;",
        "m<fA7l",
        "j\\hDB%",
        "/9M*~",
        "$k=s~",
        "k.e[U",
        "O.z5P",
        "4J4z4",
        "cO+6C",
        "tJhnsV#",
        "2$2,242<2D2L2T2`2h2",
        "K~i:=",
        "3l`n'",
        "kHpeX",
        "d16\".",
        "]Xdw0m",
        "|$$Wj",
        "gU?~V",
        "yQz!>h",
        "dKP83KgX",
        "InfPath is too short",
        "SET_PARAMETER",
        "{p7PkD",
        "A53:i",
        "\\/Aco",
        "boolean is wrong length",
        "8 8&8,82888>8D8J8P8V8\\8b8h8n8t8z8",
        "A5B|Ae,",
        "lbt5th",
        "uninstallFW",
        "rXK6M",
        "BIN2 is blank",
        "_7OoG",
        "6/Fmu",
        "Ph87#",
        "@8!M4",
        "Krgq`",
        "unknown proxytype option given",
        "6(646T6`6",
        "B~`NA",
        "&$@C{iVC",
        " 0x3c",
        "'mjI?",
        "ShellExec failed with return code %d",
        "9J|I'",
        "[LICENSING] SetKeyInRegistry %s = '%s'",
        "77wCV",
        "oD$\"s",
        "Bo.wG",
        "TV<r_^",
        "EVP_PKEY_get1_DH",
        "7;1u\"3",
        "')B4:",
        "Ri-cl",
        "T~!0x",
        "%Ge`O",
        "\"Ih2zgt",
        "@#R\\Sq",
        "kY,aE",
        ".I%dp",
        "fCFq0]",
        "1`Mh@",
        "-;bCU",
        "FRTCu/",
        "6jgy&^",
        "G\"ZR5",
        "9wO=X=[C",
        "888Q8j8",
        "473QD^",
        "SE0~b",
        "N_Y$lq5",
        "`='<?",
        "WCL&C",
        "/@x`f4",
        "W?~40",
        "AdnfW",
        "s arising under or relating to this Agreement shall be resolved exclusively in the appropriate Israeli court sitting in Tel Aviv, {\\*\\xmlopen\\xmlns2{\\factoidname place}}{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Israel{\\*\\xmlclose}{\\*\\xmlclose}.}{",
        "COMISS",
        "r7#'\\]T",
        "5`~H*",
        ";|g+@",
        "I)#Z>",
        "DefPolPrepare",
        "CN=Check Point Software Technologies Ltd.",
        "@WWUR+",
        "Go/VUM",
        "iy$qt",
        "jaRqk",
        "tZ^I)",
        "P!4D?",
        "E\\ xu;",
        "=p8o,]q7Y",
        "(3VDX",
        "EsDp~",
        "j:3C/<",
        ";)<k<",
        " 0x20",
        "5Fe2T",
        "K@M9\"",
        "fd`#x",
        "$8FxR",
        "P`,dv",
        "808E8U8d8",
        "VyET.",
        "jwW(j",
        "?>'R(",
        ">m.dq",
        " / d ",
        "{29Mx",
        "#8|s(",
        "You need to read the OpenSSL FAQ, http://www.openssl.org/support/faq.html",
        "<FB\\1,T",
        "VERBOSE",
        "h8K~x",
        "p3Vk>",
        "Ya[?:",
        "7d)y[",
        "7zI&b",
        "!# G]",
        "cz,?s7o_6",
        "HUzw%",
        "7&7l7",
        "scPI1",
        "HESrg",
        "7y79e",
        "y[h\\j",
        "ntK-e",
        "xC0r#",
        "InstHelper is not running, will not be able to stop EPAM service",
        " 0xf1",
        "4g w_",
        "%2hh{hJ",
        "invalid digit",
        " >K=J]",
        "C%by{",
        "\"YJl-",
        "\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid6904607  }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid1729076\\charrsid15169477 Advanced Replacement}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid8868444\\charrsid3545685 ,}{",
        "Vu6S\\&g",
        "X{loV",
        "chinese-simplified",
        "o^<AGmV[",
        "<KM@e",
        "id-smime-ct-compressedData",
        "2#212:2@2W2`2w2",
        "-+jML",
        "`WsxQK",
        "'N^ S+",
        "GPB0y",
        "S[0>-",
        " 3+6G",
        "3F5U5",
        "A~yP'`",
        "Ihz6:",
        "DKpSt",
        "telexNumber",
        "\\zonelabs\\avsys\\ckahum.dll",
        "xIZ2#",
        "copy %s to target",
        "D0P=g",
        "HIQ>(xG",
        "&<qrn",
        "D$@WPSU",
        "j]BF}",
        "|4h1w",
        "0F0f0x0",
        "8*}j(",
        "^zr!z",
        "?,?<?@?D?\\?`?d?h?|?",
        "uZi?z/",
        "0ralY",
        ";3Ua5",
        "7B'VJ",
        "9.929<9",
        "4*4A4",
        "AX<lc-",
        "<[=c=x=",
        "e9z% ",
        "z8:\"{",
        "9w;C^",
        "PROPERTY_CLASS_NOT_INITIALIZED",
        "H?)#v",
        "961c151d2e87f2686a955a9be24d316f1362bf21 3.5.0",
        "|f}  H",
        "585D5d5p5",
        "{jtq:",
        "x|/)%",
        "!}(?~",
        "6 6$6(6,606<6@6D6H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        ".la\\;",
        "@0Bt.",
        "4;P8G^",
        "V5N.j",
        "}[cY[",
        "n0RgN",
        "+Y(PZ",
        "2&Ktd2C,",
        "GT+0:i",
        "tF~#zUf",
        "XX?7[I",
        "z&aRf",
        "exptext",
        "(bQ6zY73",
        "n@tZy7}",
        "0cVH+4^Ov",
        "3#4Y4",
        "1*2y2",
        "?\"j/n",
        "6$6/6>6i6z6",
        "Q[D:*",
        "(Ni<*",
        "ciJ66",
        "unsupported recipient type",
        "QO)8p",
        "qmmKJ",
        ">V?h?|?",
        "\"rexe\"\"z",
        "u79D$",
        "Connection was reset",
        "}_'tQ",
        "X!3`D",
        "I]TfYK",
        "8r:{:",
        "8J:e:",
        "3-`D*U",
        "8mW<o",
        "'-R3I",
        "U-=V*^",
        "l4\"(R<",
        "__stdio_common_vsprintf",
        "|oAM~",
        "HYaD\\",
        "Y6Zho",
        "\\q>{S",
        ";~}d(",
        "9=9C9E9G9I9K9M9O9U9]9_9a9e9g9k9m9o9s9u9w9{9}9",
        "UGb[R",
        "6-7<7M7^7o7",
        " *+s>Y4",
        "&JUQo!",
        "U1t@p",
        "]_^[Y",
        "h#l.k",
        "505@5D5T5X5\\5`5d5l5",
        "signfinal error",
        "W,9-xR)",
        "l'LfH",
        "4d`@ggh5!,",
        "XMJa(",
        "-~8[Q",
        "S|U{V",
        "Rh9dv",
        "rt@,K$4",
        "}Od<M",
        "EVP_CIPHER_iv_length(cipher) <= 16",
        "SOFTWARE\\CheckPointRW\\Endpoint Security\\Telemetry",
        "be#r/5",
        ":(:A:Z:s:",
        "yLwNKI1",
        "AS@xT",
        ",-./01234567",
        "(%['d",
        "dc-~-",
        "Y0qJL",
        "_RRpp",
        "P:Tb$",
        "PzN)K",
        "$DD$P",
        "}H[aPQ20",
        "(@+^gQN~v:q",
        "'VMF ",
        "^mX5V",
        "2~YfB0{",
        "Xun7ec",
        "7$7(70747D7H7L7X7\\788L8 :4:",
        "8<8Y8k8s8",
        "jj^f;",
        "[{6*>M",
        "babeci",
        "XL$+/",
        "EP_&gG",
        "n*\"GA5M",
        "LoadData() suspended.",
        "Y'_yVF0T!eF",
        "j0Zt4f;",
        "5J3!T",
        "OP:}(",
        "!314A4Q4h4}4",
        "T;6m]d+",
        "(ko#a",
        "0\\:z]",
        ">/vPZ",
        "Id3GJ7",
        "ctx->buflen <= ctx->bufsize",
        "\"{ !:",
        "616q6",
        "api_ms_win_core_profile_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "l}73T",
        "Stop CPDA Service",
        "DFqea",
        "\" \\ky2$",
        "RhkiA",
        "32gTF",
        "~tq' ^",
        "V{9 $B",
        "-GCJR0",
        "m95Q\\[",
        "{A^Z9",
        "YPiWY>",
        "tt@*b[",
        "CT-ee",
        "~gL~N;=",
        "*6}=(X",
        "failed to copy XmlConfig record Id",
        "KI]&j",
        "[WinFW] GetWFStatus, input validation failed",
        "=@9)W",
        "|A#U0I",
        "j &96",
        "3mn[+[[J",
        "The process was shutdown using WM_QUIT",
        "00000000000000007777777777777777.\\crypto\\pkcs12\\p12_add.c",
        "iy[,1Ok=",
        "cms_msgSigDigest_add1",
        "t*i'(",
        "H[@*Qp",
        "J\\ FJ",
        "xkQ.>x",
        "(udV\"",
        "Helper::stopEPAMService",
        "JR+PpE",
        "C5yO{",
        "Mc$kF~P%",
        "r1EP)",
        "\\rsid5995582\\rsid6035146\\rsid6047445\\rsid6161681\\rsid6166062\\rsid6240750\\rsid6297815\\rsid6304988\\rsid6378379\\rsid6449162\\rsid6564918\\rsid6751690\\rsid6752132\\rsid6780890\\rsid6823349\\rsid6884130\\rsid6889473\\rsid6904607\\rsid6911489\\rsid6964635\\rsid7018887",
        "%HNj3",
        "cpdevmon",
        "0$0,040<0D0T0\\0l0t0|0",
        "w\"r7J",
        "6aXC5",
        "F7.uJ",
        "``YLx",
        "8 v't",
        "'n=#i",
        "T$ SQP",
        "\\#u):~",
        "6+KxpP",
        "[VSMON_LOAD] StopProtection %08x",
        "!oB)A",
        "edJ@H",
        "c%|s@",
        "6 6@6L6p6",
        "5Q5]5",
        "BN_GF2m_mod_solve_quad_arr",
        "!6r7PY-",
        ":W4KS",
        "CcJ3?",
        "^Qxw6",
        "B0Vb4",
        "@`ei\\",
        "mzR6S",
        "camellia-128-cfb1",
        "f9<H_}",
        "e*qnK%",
        "W,g7</",
        "P.gUo",
        "EC_ASN1_GROUP2CURVE",
        "|;6Cc",
        "40555?5p5u5",
        "$LIMIR",
        "NXUq'",
        "CI_tlT",
        "l&9@-e",
        "u8!=5u",
        "]NHeD",
        "~2H`]",
        "d+bn:{",
        "%s{FY",
        ">5>I>f>",
        "cptray.exe",
        "Vl71T",
        "F|>Bb",
        "506K6x6",
        "0=0b0",
        "#OWQ^8",
        "465;5M5n5",
        "%]bn*",
        "sslv3 alert decompression failure",
        "<8?&l",
        "404A4V4[4",
        "~qUWVV",
        "R5\"mF",
        "Q`.:;",
        "QyG&O",
        "~,9\\$",
        "P%KuD",
        "tWyH)",
        ".?AVinvalid_argument@std@@",
        "?0?L?h?",
        "3(4,4044484<4@4D4H4L4P4T4X4\\4`4d4h4l4p4t4x4|4",
        "postOfficeBox",
        "<,<0<4<<<T<d<h<x<|<",
        "q;R\"k",
        "vx\\6+",
        "invalid utf8string",
        ",A}mM",
        "eLc/+",
        "Hf\\.=",
        ",{BCf",
        "?8DBb-",
        "K]|{?",
        "Y$,z(",
        "=Oz:z",
        "Z8]/^`R",
        "=QfD4",
        "6 s,C",
        "a|*6L",
        "0U1r1",
        "i%fyQ",
        "eM$Bg",
        "+<&3dx",
        "ASN1_digest",
        "`LXB*",
        "3D\"zn",
        ">+?A?_?v?",
        "{oUQ!]",
        "c<J-'|",
        "o3Klq0",
        "INNER_MSI",
        "Gxs%U",
        "Cannot find Check Point SBA InstallProperties",
        "+*O9^",
        " &B0!",
        "1X4AP",
        "b\"QF}",
        "I<y0R#",
        "f0I+S",
        "*fy*8",
        ">2>?>r>",
        "e:tD7e2",
        "spanish-guatemala",
        "#y{T'",
        "MEMDUMP",
        "3,303<3@3`3d3p3t3",
        "\\N$^]9",
        "]!\"KP",
        "z6d8Z",
        "Yy\\}Xu",
        "&A<$m",
        "1 2$2(2,2024282<2@2Z2F3L3X3^3",
        "5(5,585@5D5P5X5\\5h5p5t5",
        ".oUOG",
        "aA\"c{X>p",
        "6f,4Ik",
        "smartdefense\\sd_info.bat",
        "tkBdV",
        "&*`)A",
        "cNVXN",
        "(3FRw",
        ";w;RO",
        "=S?SCSESGSKSMSOSQS",
        "WZjD(;vV",
        ":HOHi",
        "7+7_7x7",
        "kfQL2",
        "Swa{Dgy",
        "yym#:",
        "B#B)B/BCBSBUB[BaBsB}B",
        "5,5<5@5P5T5X5\\5p5",
        "D(qRH",
        "a7^=#n",
        "=#%z@.",
        "h^Kb~",
        "u0jrh",
        "<4<8<x<",
        "1N4FTG",
        "ecc cert should have sha1 signature",
        "!CqrG",
        "73<-J",
        "4k-$w%",
        "R,C47",
        "jpjpj!",
        "9R9[9o9|9",
        "&W'QR",
        ",{_nT",
        "G7An,",
        "qe 4\"",
        "?_+wT",
        "t@jbh",
        "unknown key type",
        "=fitn",
        "!&^_!",
        ".HZjCZ",
        "P2Y*8%vM",
        "sO%dp",
        "OnChangeDriverRollback",
        "%.2^!",
        "qN'Jq",
        "s5~e\\B",
        ":T9.>",
        "/E3_-",
        "E+0U ",
        "Y06\\|",
        "U(|{d",
        "- unexpected multithread lock error",
        "*<pe@]",
        "tRPBWJ",
        "B.nCVS",
        "@H#?43",
        "[(-|[/",
        "9;z'={Af",
        "g{TLi",
        "?xnb|",
        "thSVW3",
        "D'F/B",
        "b)= {;",
        "0yU7M",
        "\\3JlzB",
        "_^9m$",
        "A\\hPE",
        "g,BVL",
        "CALibraryDll: %s",
        "~nkr-",
        "F]G]HJL",
        "%Ubcw",
        ":E[N3D",
        "#|bU?",
        "Q65-N",
        "<C<V<`<",
        "eTSMZ",
        "[-<S;",
        "kW$4k_(4",
        "=.GER",
        "T4Vd!",
        "setct-CertReqTBS",
        "OGTy#@",
        "|mv7:{",
        "/qvPu",
        "Bs^7I",
        "8&939O9r9",
        "JRu1x",
        "3(383\\3d3l3t3|3",
        "FX{R=X>",
        "3 3@3`3",
        "hj~6'",
        "TS_RESP_CTX_set_accuracy",
        "?l~EU",
        "K5\\E9",
        "M~0ok ",
        "H0c$X",
        "p5k/#",
        "SetEnvironmentVariableW",
        "5tw10",
        "IB5mAV",
        "}EGbw",
        "(s*GV)N",
        "X6H$U",
        "FTP: command REST failed",
        "cmEI$",
        "3:3n3",
        "5~>js",
        "kAAam",
        "~|7#r",
        "dx}><",
        "vtV_A",
        "c*.Nm2X=",
        "getaddrinfo() failed for %s:%d; %s",
        "z<zS3",
        ".E&zN",
        "d&0Kt",
        "(w=zW",
        "Mwmh(",
        "re-enter the password, or Cancel ",
        "eZYVj",
        "'-5Fd",
        "5HM<[",
        "Q4X=8",
        "e`[/Br",
        "Y)T:[",
        "*~.2/",
        "N4NtN",
        "zKbTd",
        "4 4(40484D4d4l4x4",
        "InstallDotNET started",
        "P_y`D",
        "l\\=A4",
        "9Na0~",
        "jsv2uk",
        "f@Hev\\",
        "xya7*",
        "5*!U7cT3m",
        "*ch8X",
        "Mmutz",
        "3f< 6gf",
        "-L+P9",
        ":#;|;",
        "+cBGat",
        "e>U.5",
        "crossCertificatePair",
        "aNULL",
        "VersionMajor",
        "{SF=9",
        "eW]52",
        "eps_CP_Left.png",
        "y`B}yO",
        "NTGetCanonicalUserID: exception in LookupAccountSid",
        "}^u{g(!xyt8)",
        "[SSxK",
        "^,-Ih",
        "\"*Tjd",
        ";T:\"Wm",
        "KhhkB%l",
        "ec_GFp_simple_point_set_affine_coordinates",
        "?IsUserProcess@@YAHKK@Z",
        "fSykF",
        "d0XOd*",
        "hTHu-R",
        "JN<AH",
        "ql1QdW'",
        "~f9h}",
        "VXY:7",
        "I$47f1",
        "AES-192-ECB",
        "d^n/e",
        "Lly`:",
        "\\Aw6G",
        "J eEX",
        "&<#nJu",
        "failed to query verify path: %ls",
        "l4p-'",
        "-/-O4oM82",
        "#.#3#6#= A'",
        "M'T+mn>z",
        "|nm]<",
        "T*tDA",
        "u)^]N'",
        "]q0i$",
        "D;)z\"",
        ";~w n",
        "P;pvl",
        "={_hU",
        "y@J>`",
        "9A:?_",
        "xu_^]@[",
        "1!1,171K1V1]1h1o1",
        " 0xdc",
        "y7i~c",
        ":$:=<",
        "}#^nOf",
        " @\"M\\",
        "ys$eo",
        "debug_malloc2",
        "FCn3h",
        ",tXc/",
        "Yo%GS",
        "vSEfEu*-IX",
        "N{pH^k",
        "1*121G1Z1x1",
        "j!UWI",
        "`v5b-s",
        "X\\Y>AF",
        "cMRI@>",
        "3L$<1",
        "5F!lw",
        "G,QqX$)",
        "5}5i|",
        "Bj@nNEdz",
        "hg2ad",
        "_WL.u",
        "CV0uh!",
        "}6[la",
        "n6tw[",
        "F0Mdw",
        "e>O%E",
        "&qTD*$",
        "aBJo>",
        "6LDORx>",
        "ZY4 ~",
        "x,>$U",
        "DirName",
        "3@4R4\\4",
        "x,;*m",
        "CLPjQW",
        "rc4(idx,int)",
        "I_hx g'0",
        "zGQz|",
        "D$(WUPj",
        "AW^{2o",
        "+])`ZV",
        "Wk.ye",
        "~LQ~B",
        "UGBg7",
        "t;'}m1;",
        ";{EFG",
        "Me,KxU",
        ";FqYU$",
        "v$ym~-",
        "85LRF",
        "pm:IX",
        "0.3Y_;",
        "n,gpM",
        "4e=)L",
        "6gYY4[",
        "HXWfm",
        "Can't open file %s for writing",
        "&|U/13=]",
        "p)piaw",
        ">'>2>F>Q>_>q>",
        ".?AVEVPHasher@@",
        "&x,2fu",
        "<#<w<",
        "tWF+G",
        "Lq&9=e",
        "2N7fQ",
        "G\\e78",
        "'T:% ",
        ";-<9<A<Q<",
        "J7_3)",
        ")o[]&r",
        "3e{ir",
        "<\\=y=",
        "%s does not exist!",
        "OcJC)",
        "4;F\"<",
        "$>$N$V$R",
        "PR=Xh",
        "p[656uujw",
        ".hWr ",
        "<=6YUHP#",
        "yqZj{oe",
        "3{H=?",
        "nrp;qiri",
        "4*,XT",
        "sWWG^",
        "%,A E",
        "no message available",
        "+VK2i",
        "7\"8*878E8_8",
        ".a5L=",
        "e9emf",
        "ZoneLabs\\zlff.dll",
        "DO#f\\",
        "1x2*g",
        ",$v&_",
        "fKrM0",
        "dSDX=",
        "j:<lV6m",
        "rxMkNM(",
        "63787=7B7Y7i7",
        " xKLUr",
        "QliWDl",
        "V&1?'d",
        "yx4Um",
        "AGGwN",
        "!p9.%",
        "lgjn8*",
        ">9I16$",
        "WUX*2",
        "+gkZx",
        ";2<R<i<q<v<",
        "4qQ${",
        "MHq>8",
        "r;f;u",
        "-jh;n",
        "'i&EN",
        "?0?\\?",
        "$=u3h",
        "RegGetValueA",
        "3V4f4Z8",
        "#_|OJ",
        "./saYF",
        "/^!3@",
        "6SB{u0",
        "<(<f<q<",
        "S|]/J",
        "+WVHP",
        "818Q8m8",
        "IswSpinLock(0x%x)::WaitLoop - locker=0x%x rv=0x%x",
        "EVP_PKEY_get1_EC_KEY",
        "clzmd",
        "YMHZQE",
        "\\smartdefense.dll",
        "es_/H",
        "$<;{d",
        "Uuu56",
        "t hPEM",
        ",'HtI",
        ":,:P:\\:d:|:",
        "vJrd[H",
        "25LGVg",
        "d0Z[.2",
        "dxe=*8yG",
        "BSU,+",
        "regex_error",
        "file_digest: Unknowen cryp_type %s",
        "OV;Yo",
        "SSSSS",
        "9Njm|",
        "@BNv-0",
        "u|}Y'",
        "J\\$lsS",
        "5_6o6",
        "UninstPwdSaltDA",
        "2=F[[",
        "Check Point Endpoint Security VPN Installer",
        "Gyy![",
        ">rf@/",
        "Jn:lN",
        "4?u1#",
        "O7prE",
        "[^;Z{",
        "}yS?H@",
        "REMOVEPRODUCTS",
        "heartbeat request already pending",
        ":H:f:n:|:",
        "G\"BvR",
        "B^R83Lw",
        "VWj\\^j:",
        "s.yY{KM",
        "A<A]g",
        "Socket is already connected",
        ")rh=ql",
        "5HtryYb",
        "Wjw6|",
        "3[*9x",
        "30T0v0",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477  ",
        "K~BF,",
        "U\\omU",
        "WnWknQ",
        "(pm!|w",
        " 9 Ne",
        "o@&fdIX*",
        "= =0=4=8=@=X=\\=t=",
        ",3W#J",
        "\"T5Z]",
        "[VSWriteUninstallInfo] Can't create shared memory mapped file",
        "7!9@<g<",
        "~2&JZKX",
        "nJJlW2",
        "7'7M7y7",
        "up,Vh",
        "D+ z^g",
        "s]V_08",
        "MODULE_INIT",
        "62777B7",
        "X9_62_PENTANOMIAL",
        "pbjmW",
        "t3x(=",
        "G)G9G\\GhG",
        "}F&MU",
        "%SystemRoot%\\Internet Logs\\MEMORY.DMP",
        "D~5Le",
        "s@H2>(",
        "H[sG]13!6!n",
        "]C_kE38=",
        "U8Ay\"",
        "6&-d?",
        "MD(%C",
        "fB]l\\",
        "R%Vt\"w",
        "8$8(84888<8X8\\8h8l8p8",
        "Invalid multi handle",
        "FeatureAntiVirus:  CleanLegacyComponents started.",
        "2Iu5J",
        "JPR0W",
        "|$4!u^",
        "JL*2-",
        "]c6(b+",
        "W8K.#x&",
        "+ZAhB\\aC",
        "Za02+2GH",
        "z'0)8X",
        "].,FY7",
        "Host down",
        "t)h$z&",
        "3#4(4S4X4",
        "=(}g~",
        "Ci=SF",
        "\\BVnt",
        "=D<p4",
        "9 9?9N9m9|9",
        ":\"a!(",
        "f5=H[X",
        "y@X,{06",
        "P?w2D",
        "Ux>^n",
        ">:(aG",
        "6 6$6(6,6064686<6@6D6H6L6P6T6",
        "q{6SA",
        "hP4@4",
        "1}C+b",
        "8$9(9",
        "To verify:",
        "3%3i3",
        " E\":|",
        ";W&xc",
        ">!:VN",
        "##1.)",
        "j_|Q\\",
        "Need destination address",
        "failed to set %ls",
        "c,r+~",
        "4(l2I",
        "LhUaj8d",
        "343D3H3X3\\3`3d3h3p3",
        ":D;S;",
        "t0nda",
        "[hykH[q",
        "ZUr6P",
        "jpjnj!",
        "b[_X{6",
        "RSA-SHA1",
        "!)i0B",
        ":ns.v<",
        ";+ipP",
        "=qQVK",
        "~WR.^@ ",
        "zR4k4",
        "'7& ;6",
        "2/s,y:I",
        "*6Jc!",
        "]PI=r",
        "Jh@M!",
        "id-GostR3410-94-CryptoPro-B-ParamSet",
        "O!'> ",
        ";7;k;",
        "Cyc7/*~",
        "hI{L[",
        "REMOVEFW",
        "[VECTORED EXCEPTION] C++ exception",
        "8!828^8",
        "Shha\"",
        "qJCE`",
        "13p&4w",
        "api-ms-win-core-fibers-l1-1-1",
        " 0x34",
        "tP#p*",
        "_ww&;",
        ":':1:=:S:o:~:",
        "void __cdecl boost::property_tree::xml_parser::write_xml_internal<class boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >>(class std::basic_ostream<wchar_t,struct std::char_traits<wchar_t> > &,const class boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > > &,const class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > &,const class boost::property_tree::xml_parser::xml_writer_settings<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > &)",
        "0S5~o",
        "wWK};3]",
        "lh}vm",
        "dbpk4",
        "<.u>FV",
        "wB>]0",
        "2D73{",
        "%gn\\L8",
        "0t$@;",
        "AmuuF=B",
        "G]X'X",
        "h#fLk",
        "N$QDL[l",
        "|7LO\\aZs^",
        "PVSWj",
        "&}1^=",
        "szNgdt",
        "It1\"q",
        "`u4\"n",
        "K~jyg",
        "npx2g",
        "&5+o%D",
        "'6,FK",
        "LCCXh",
        "RL>uUD",
        "^qbn+",
        "m;M=%",
        "3`3j3",
        "T)Hc{e",
        "*WmDW",
        "V*2[H",
        "<X0j>",
        "MINSS",
        "=J`Z@",
        "k'rS#",
        "IBI9CI",
        "{Ii>)",
        " from material defects in design, materials, and workmanship and will function, under normal use and circumstances, in accordance with the documentation provided, for a period of one }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529 (1) }{",
        "PltYO?",
        ", :ij",
        "JCfeG@",
        ">nE):",
        "=!=u=",
        "EqTCf3",
        "TZGz8",
        "ENGINE_LIST_REMOVE",
        "]EVFY]",
        "rqcv>",
        "securitypolicy/osfirewall/rulegroup[@name=\"protbdavfiles\"]",
        "1|$01t$T",
        "erminate and You shall promptly return to Check Point or destroy all copies of the Product.",
        ":(6zE#E?",
        "ssl3_peek",
        "e7zzj}",
        "pr!vk",
        "@.{oH2",
        "CheckPoint Secure Client is not installed.",
        "ON6O^",
        "NbQp#",
        "fL\\0w)",
        "8V8[8",
        "ZrY4u",
        "^Oxn_2z",
        "DP[ry",
        "'h54z~",
        "`|$1q",
        "~\\ToU",
        "ah($R",
        "AOT=E",
        ",y,tc_dT\\M",
        "Dv;[g",
        "d|S.3",
        "mLmlm",
        "=(-b\\",
        "aMaWa`Pi",
        "3t$X3",
        "W.V&Vr${u\\",
        "g2QpjC",
        "EnableLMHOSTS",
        "?D[B\\-L@d",
        "2 2(202H2X2\\2t2x2",
        "t3jgh$",
        "|$8`&",
        "QOA9n",
        "Uj[dyr",
        "CA: [%8s %8s] %16s:  %s",
        "d|00R",
        "~g:l\"@t",
        "wap-wsg-idm-ecid-wtls4",
        "C?vNJ",
        "kts5L",
        "gP\"6w!De",
        "Y |CS",
        "cA]n,eBa",
        "CVTSD2SS",
        "0I~U{K",
        "FN;%2",
        "sthH/~O",
        "R}sL)z",
        "jojpj!",
        "\\Zonelabs\\ZLCommDB.xml",
        "&|?AK",
        "H*0\"ZOW",
        "e>8(n",
        "co6j8`[*.",
        "Vjx.f",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 , Check Point will use commercially reasonable efforts to ship the replacement hardware }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid12985423 within }{\\rtlch\\fcs1 ",
        "s*88.",
        "0sII'",
        "Y,a]F",
        "?dwkk(",
        "@LQluY",
        "%12s%s",
        "585[5",
        "T_l_I/",
        "xmmy\\,",
        "Ivh;}",
        "nw_ @",
        "==c.xp|",
        "DM91x",
        "l>ReF",
        "<oOz/",
        "roe3^Bs%",
        "Z&};?",
        "4(4,4@4D4T4X4h4l4x4",
        "i6+%q!",
        "vector<bool> too long",
        ";z&=|1",
        "OQ`Yo`",
        "qgo@wYP",
        "_pQ%bW",
        "z;i5N",
        "kC&GW",
        "vGT0E",
        "fr.fr",
        "]%`1hP",
        "rvf;M",
        "t(,G_",
        "*T(c[r",
        "83s{97g",
        "tx+Y]",
        "b({Jf",
        "C%PWu",
        "*4F5d",
        "d=xu9",
        "RDJ~l",
        "}`w,f",
        "!`s~]",
        "mtJ8CY",
        "-^0<baU",
        "0$0,040@0`0p0",
        "6S798",
        "Success.  We set the property.",
        "d<R:0",
        "xjkwp",
        "~N83<h",
        "Fr-nN9",
        "7a8f8q8",
        "8H8h8",
        "6#6/6<6|6",
        "9 9%9=9[9n9",
        "j3/*z^uz\"",
        "OCSP_ONEREQ",
        ":G?l.",
        "Cc%b2",
        "vsdatant_win7.inf.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "\"M]%p",
        "Could not process message.",
        "5yvnpPN",
        "New Jersey1",
        "4<5c5|5",
        "6.6b6",
        ":(:,:@:D:X:\\:p:t:",
        "Cdl#6",
        "H(4ta",
        "u9tf\"`",
        "!7RG[s",
        ">nY` ",
        "/E^Az",
        ",#,/,5,9,A,W,Y,i,w,",
        "9`<l<s<",
        "change file shortcut according to client type",
        "M1OeLt",
        ">RsJGl-",
        "BW=6a",
        "L$8Qh`",
        "L$SU#",
        "UgHTem",
        "8/8K8g8",
        "p`hg.",
        "[z&Un*c",
        "Thread32First",
        ".\\crypto\\ecdh\\ech_ossl.c",
        "GY+Y)Y0Y6",
        "Ud_~_",
        "%j_ih7",
        "mF$Gfi",
        "FfT.?",
        "BHr(n",
        "=U=[=",
        "BMY$?\"",
        "vVlfY",
        "^L8pq",
        "808K8",
        "<Oz2I\"&",
        "B0`6'",
        "QI`ij",
        "DES-EDE-CBC",
        "loadZlcomm",
        "ax\\}s",
        "oM%MS",
        "}5} SYKy",
        "]{U7D",
        "t$ Sj",
        "xAu h",
        "g!+$>",
        "V};`M1%",
        "0~NWv6bq",
        "d,,%>",
        ":\":8:A:L:[:a:n:{:",
        "aiFCZ",
        "mf6; K(\"",
        "\\par }}{\\*\\pnseclvl1\\pnucrm\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxta .}}{\\*\\pnseclvl2\\pnucltr\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxta .}}{\\*\\pnseclvl3\\pndec\\pnqc\\pnstart1\\pnindent720\\pnhang {\\pntxta .}}{\\*\\pnseclvl4\\pnlcltr\\pnqc\\pnstart1\\pnindent720\\pnhang ",
        "SEC_E_NO_S4U_PROT_SUPPORT",
        "nPe1 ",
        "u:jZh",
        "@'Wk':",
        "RKF/6&",
        "8;9|9",
        "Registry error:  Can't read value.",
        "RV)V{",
        ":);;;x;",
        "x`i59\"",
        "&y.?Og",
        "#\\tP>`",
        "< <$<(<,<0<4<",
        "q4E(%",
        "?eWob",
        ":,:9:l:p:t:x:|:",
        "MHulo, ",
        "O=-=D",
        "snaY8",
        "+_Y3*-",
        "tlsv1 bad certificate hash value",
        "\"U$)K",
        "2c3r3",
        "h}='/",
        "|W|+T",
        "]S2.BU",
        ";k3rY",
        "s$dwv",
        "\\(Kr?",
        ":c7ET",
        "klF>PL5",
        "Jll$n",
        "3z*N2I",
        "T[Z_V!jQ",
        "wV!vm",
        "MIME-Version: 1.0%s",
        "9&9<9B9G9M9X9^9m9t9y9",
        "U|Gz8YWB;",
        "N-q9>",
        "+y;_bI",
        "1 1,1<1",
        "o^*`j)_",
        "?d\"xa/}",
        "9_jNf",
        "P7bnkh",
        "AIp2M",
        ";H!h.8",
        "M6r51x",
        "registerPlugin:  %s",
        "2AhD2",
        "3tLD;",
        "1nO:M",
        "5$ry,",
        "Vjrh(",
        "1CI\\;",
        "3H4k4",
        "Cjk.i",
        "9+*d|",
        "!oD;/4",
        "WMgL/",
        "e?M-#+",
        "c<Kc<",
        "not REMOVE=ALL, no need to restore SC uninstall",
        "|\"SM|",
        "7'708T8",
        ">*?g?q?",
        "h*8#B",
        "9mC~4~",
        "\\YT=-",
        "$'^Ot",
        "8&:5:S:s:",
        "Ck!-V",
        "\"9&eW",
        "G~D Kj",
        "nVi8tV",
        "value.other",
        "id process",
        "8Yg9w",
        ".\\crypto\\evp\\evp_cnf.c",
        "8>?RJ",
        "cLxj_4N",
        ";;wp]M",
        "+rSN+[",
        "+n}OD",
        "}8[,=",
        "EnZlz",
        "QCPS&\"o_",
        "CMS_EncryptedData_encrypt",
        "accept",
        "`lI`k",
        "?2{9*{",
        "^42(0",
        "R;>4!?",
        "skF6vpP",
        "$ ;re",
        "1O2x2",
        "&{8!KQ",
        "?q-xH",
        "`.i|DI",
        "`z!BZ",
        "{\\f411\\fbidi \\froman\\fcharset238\\fprq2 Cambria CE;}{\\f412\\fbidi \\froman\\fcharset204\\fprq2 Cambria Cyr;}{\\f414\\fbidi \\froman\\fcharset161\\fprq2 Cambria Greek;}{\\f415\\fbidi \\froman\\fcharset162\\fprq2 Cambria Tur;}",
        "mi(-]",
        "383?3H3X3d3x3",
        "LoadTestGUI.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "JY$aL",
        "A^a<!",
        "pXTY(",
        ":V.t*",
        "EAK%J",
        "6_f%S",
        "ULV $8",
        "/T=YXX",
        "KVx|T_",
        "\\{97pM",
        "nB_IS",
        "$0aa L",
        "Ug7o1",
        ";*;G;|;",
        ">?>e>",
        "bad decompression",
        "#0v;6",
        "SSL_CTX_check_private_key",
        "#*N33",
        "  CRLfile: %s",
        "ut='D",
        "T.tt;0~*",
        "{HcdW",
        "xR'0a",
        "3$3?3Z3u3",
        "Cyc8yI",
        "b;_wf/",
        "Qe-B$",
        "=h$Z)",
        "Y-V\\(5q",
        "^P-<r",
        "{ZLWB",
        "r$v5&",
        "ENGINE_set_id",
        ":3:O:k:",
        "Failed validate password ",
        ">xK)g",
        "X509_ATTRIBUTE_create_by_OBJ",
        "XLM65",
        "-d-d-v",
        "0123456789ABCDEFabcdef-+XxPp",
        "U1'EM",
        "jUPYZ",
        "openmail.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "+%+5+E+U+e+u+",
        "!PZ1t",
        "RU?aF",
        "ba$'':;<P",
        "J!>x}",
        "no policy identifier",
        "\\f1\\fs20\\insrsid11543880\\charrsid15169477 ) must }{\\field\\fldedit{\\*\\fldinst {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid923653\\charrsid15169477  HYPERLINK \"http://www.checkpoint.com/services/contact/index.html\" }{\\rtlch\\fcs1 \\af1\\afs20 ",
        "Reboot required by at least one custom action.",
        "Oo\"D!S",
        "vICx~~",
        "\\{s=Tg",
        "SYSTEM\\CurrentControlSet\\Control\\Class\\{4D36E972-E325-11CE-BFC1-08002BE10318}",
        "u^vYu8",
        "2G*$|",
        "DlgO_",
        "i~m==",
        "{\\fdbmajor\\f31526\\fbidi \\froman\\fcharset163\\fprq2 Times New Roman (Vietnamese);}{\\fhimajor\\f31528\\fbidi \\froman\\fcharset238\\fprq2 Cambria CE;}{\\fhimajor\\f31529\\fbidi \\froman\\fcharset204\\fprq2 Cambria Cyr;}",
        "438}Li",
        "KSB;KP",
        "SetProtectionByPassword returns %d.",
        " 5wbh",
        "?%`qod",
        "#-cg>",
        "_cNf~",
        "vrKdg",
        " KE!gmA",
        "S,K.P",
        "0l&d#",
        "c5JDCi:",
        ",I2*9r",
        ":LW'`",
        "9(y@gC_uk",
        "invalid operation",
        "UninstallString",
        "m%Dxb",
        ">+>D>T>v>",
        "U(@\"U",
        ")YH*`h:",
        "]B\\9\\",
        "\\2BI8`M",
        "WoY3~",
        ",=F-n",
        "!*(jN",
        "yp9>=h",
        "_AKf~",
        "NXS`so",
        "wsq[Y~q",
        "B/I\"t0qrk&~",
        "G,jrhx",
        "blowfish(idx)",
        "<4<><O<a<r<",
        "xmkR>X",
        "C~-J'",
        "~e !E",
        "FD2\\4",
        "Q@v]B",
        "i'K;$",
        "^8S.}",
        "BNH5H",
        "@p)P)",
        ":Av\"Y",
        "pubk-f",
        "1K(b8",
        "d3hha",
        "detect64Bit()",
        "4qx9y",
        "R!={^",
        "UninstallAS:  UninstallAS() in vswmi.dll failed.",
        "<+<s<~<",
        "8.p\\D",
        "d:zRr-",
        "%Vf_8",
        "a?I,{",
        "Failed to find all files in path: %S",
        "#hXC}",
        ":Z/|w./",
        "l.}~_",
        "{K8r`",
        "Restoring ipwval...",
        "\"7P),",
        "KC!DIU",
        "; b ]",
        "_\\aQ+",
        "J8g-=g",
        "agUfk",
        "<4=G=",
        "JU]<:<",
        "_qoa*q8d",
        "nF2Lr",
        "fLG|`",
        "Z}24`",
        "AND*Q",
        "N2ajQ6$",
        "i2f}4",
        "<#=X={=",
        "TFTP: No such user",
        "*#T[\"",
        "*:}Sv^",
        "H {3?",
        "9!9)9.9N9S9{9",
        "dSB>P",
        "7,7:7",
        "?K#x`P",
        "Z$z$Z",
        "sw}@\\&",
        "\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid5727096  (\\'93Warranty Period\\'94)}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3481596 .}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\cf1\\insrsid3374529\\charrsid3374529 ",
        "FSTCW",
        "MN\\Rp",
        "7%oeFK?",
        "setct-AuthResTBEX",
        "~zj3#",
        "=/=6===D=}=",
        "}%J4$",
        "_dWHo",
        "Cc= u",
        "@rET ",
        "4&i||",
        "X9_62_CHARACTERISTIC_TWO",
        "X9_62_FIELDID",
        "\"73)Q",
        "WoVwt",
        "#d+%!",
        "uNhh;#",
        "FH<au",
        "Ca~,Xp",
        "xBr)&",
        ")wfi!",
        "j%I$#",
        "-BWH,j)*s",
        ";V<d<~<",
        "_X8gp",
        "c\\>O.",
        ";)[(d!@G",
        "pqNn2|",
        "#u\"Su",
        "6%6*6E6a6",
        " record in ",
        ",KWSZ",
        "7j]eIv;Ub",
        "Ph\\]7 ",
        "i[2V,",
        "*<Y=qc:",
        "}un\"`",
        "9>9r9",
        "Eu9!D\"",
        "kok-IN",
        " _L%#kR",
        "X!mv=",
        "qBw|&",
        "X-4QB",
        "$u*8H",
        "[VSUTIL] : MakeVsmonPath:  GetModuleHandle('kernel32') failed with error 0x%x",
        "2[a0IVp",
        "rr+cHj=",
        "false",
        "i>Qf&",
        "b3lt+",
        "n9\"cJ",
        "&0X0]0",
        "`\\0\",i",
        "void __cdecl boost::property_tree::json_parser::write_json_internal<class boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >>(class std::basic_ostream<wchar_t,struct std::char_traits<wchar_t> > &,const class boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > > &,const class std::basic_string<char,struct std::char_traits<char>,class std::allocator<char> > &,bool)",
        "GWY_c",
        "Pj0R#jsg",
        "PPWhZ",
        "< <$<(<0<H<X<\\<l<p<x<",
        "#\"Z#ju+",
        "[p^Ff",
        "e&<'\\",
        "2m2s2",
        "UIFRAMEWORKGUID",
        "[Self Validation] Stack trace",
        "Q f`F",
        "#d5tE~",
        "u,8D$",
        "57YfV",
        "DS_RollbackCopyToSystem32.D0C5EC8C_E5AE_4D71_A5C8_AEE96E7E9230",
        "5Z5i5x5",
        "mTol6",
        "ByJJNT",
        ":\\^RTu_",
        "p)<A_.",
        "ctdS**",
        "-4';T?c",
        "EPC_Default_VPN = YES",
        "@Ax~K",
        "C\\9YG",
        "T_+HO",
        "Q,T[c",
        "9 9(9",
        "_LTv,",
        "vJf;K",
        "zt$<N",
        "UU%%(",
        ";5jEh",
        "rxxAu0",
        ">wn5&",
        "6by{##",
        "<\"=)=x=",
        "d;&lGJ",
        "|a23q",
        "t!hD-#",
        "address not available",
        "7E7]7x7",
        "^d3(R",
        ":?~6|0T[O",
        "@g*Cc",
        "X_XPQ",
        "D$PPh",
        "VhdT!",
        "unknown digest",
        "0#0)070;0U0Y0[0g0q0y0}0",
        "5wg4yoT",
        "r,Ze<",
        ":\":>:Z:v:",
        ";-;<;",
        "Rewinding stream by : %zu bytes on url %s (size = %I64d, maxdownload = %I64d, bytecount = %I64d, nread = %zd)",
        "Lf'nU",
        "P{8{({",
        "yR{\"^",
        "\"NLk6",
        "N%=|r(",
        "E|QW}",
        "@rG~O?",
        "$h7Dp ",
        "dxWUR",
        "_W:\"6",
        ",KCIc",
        "FW_INSTALL_ERROR",
        "9E\"~m",
        "2y8P-",
        "nWG#L",
        "\"(8[G#",
        "UKMi=",
        "2WXzu",
        "NUj::",
        "x{KS6",
        "Yl6fi",
        "@f s0/",
        ":B:M:",
        "VVAq ",
        "yH&\"p6H*",
        "#Jn_ ml",
        "Failed to extract %s to %s with error: %d",
        "QDxh^bCa5",
        "ZF#JA\\",
        "Y[jT?",
        "yA;!g",
        "DHE-DSS-AES256-SHA",
        "KZz6c",
        "Dy9PJ",
        "#wi[6",
        "pats.",
        "a]Yiw",
        "SW(1L~",
        "wNF.Y",
        "4)4>4C4",
        "qZecA",
        "2?^.}H?",
        "3T|Cp",
        ",|u/1",
        "Q0V0[0y063F3",
        "A,YAD",
        "2W2`2k2s2y2",
        "6:'(z5&}6%",
        "sb&VZ'(i",
        "ERROR: MoveEntryToEnd failure to delete old entry...",
        "T[o3\\/,7",
        "failed to set authorized app path",
        "RSA_private_encrypt",
        ">4><>D>L>X>x>",
        "Gu@-rS",
        "?5,3!;",
        "3ZLn^",
        ")1&QSbS\"SBT",
        "kDU_mm~i@t9",
        "Y?Z ]",
        "C_kRQ",
        "qRwso",
        "g719n",
        "cH&8Fl63:",
        "'wn?U",
        "OpenSCManager failed: %d",
        "jnjkj",
        "-5 JE",
        "HZ>5\"",
        ".\\crypto\\bn\\bn_lib.c",
        "a39GZ^EK",
        "|<x7|N5",
        "ucVVW",
        "8#n@d$",
        "4HyOk8Fz",
        "Raz=w",
        "\\Zonelabs\\ccore32.sys",
        "6Z7f7n7v7",
        "bad get asn1 object call",
        "-$[lO\"",
        "time stamp routines",
        "TSOYL",
        "ld\"}kR",
        ".?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@",
        "8X!4D",
        "kmn[<",
        "|DB-2",
        "}TwiB2",
        "5~8Eg-k[",
        "N+SOQH|",
        "_!{R{k",
        "N[.{L",
        "lW1e|UQ",
        "bW$-/:",
        "4:5>5B5F5064686<6@6D6H6L6P6T6X6\\6`6d6h6l6p6t6x6|6",
        "okDHzv*#",
        "1wy9EP",
        "!2Y{14O`",
        "5 6T6",
        "VGd84",
        ">jl?0",
        "'NrI6",
        ".5 S8",
        "vO 'dC",
        "? ?8?D?d?p?",
        ";H[q3",
        "`;`{x{",
        "^ss;]",
        "b U1ls",
        "Qp9[e",
        "8*8B8j8r8|8",
        "$|z{o",
        "V$Gw:",
        "PBE-SHA1-2DES",
        "-%L(,/",
        "hKt+7",
        "YDFQ|",
        "A%ZvbZU",
        "=NB6&",
        "asn1 lib",
        "{\\fbiminor\\f31581\\fbidi \\fswiss\\fcharset161\\fprq2 Arial Greek;}{\\fbiminor\\f31582\\fbidi \\fswiss\\fcharset162\\fprq2 Arial Tur;}{\\fbiminor\\f31583\\fbidi \\fswiss\\fcharset177\\fprq2 Arial (Hebrew);}",
        "e|Ej\"",
        "d|$#1/",
        "-LMQwo",
        "]g9 N\\#",
        "3*G]d",
        "8Urv^",
        "\\zonelabs\\html.tdr",
        "OSh=?h",
        "vE$ z",
        "2!3i3",
        "=.=@=",
        "dEj4Yk",
        "r5}GC",
        "0IIf,",
        "=00F4",
        "&#0^>",
        "\\?R_t",
        "V~'a^",
        "jQMAn",
        "X8?+Ku@",
        "LvMM\\",
        "rUA@8y",
        "4J/74",
        "||A[o",
        ".4o$G",
        "_vMY.E",
        "1A26b",
        "yvIj}?`",
        "zpjUi6",
        "\\lsdsemihidden0 \\lsdpriority71 \\lsdlocked0 Colorful Shading Accent 1;\\lsdsemihidden0 \\lsdpriority72 \\lsdlocked0 Colorful List Accent 1;\\lsdsemihidden0 \\lsdpriority73 \\lsdlocked0 Colorful Grid Accent 1;",
        "#adV5",
        "fYs&:",
        "|;,.v",
        "sx=7F:",
        "%pAxF",
        ":$;,;L;d;p;",
        "JyU_KJ",
        "F\\l](T",
        "{GyD@",
        "j*l0;|",
        "&&\\Vl",
        "%;9Pl",
        "Nc)Nn",
        "P9w(d",
        "n r!_",
        "tF9Ou",
        "ANNOUNCE",
        "ECPKPARAMETERS",
        "{D7(V",
        "=*=d=n=",
        "D$8PWh",
        "[_U-L?",
        "GET_CLIENT_HELLO",
        "[VSDATA] DriverXMLCtrl: OpenDriverHandle() failed",
        "}c'74",
        "<#<A<M<T<^<e<o<v<",
        "cyv)5",
        "nmC/?",
        "D$0CV",
        "DSA PARAMETERS",
        "\\par }\\pard \\ltrpar\\qj \\li0\\ri0\\widctlpar\\wrapdefault\\aspalpha\\aspnum\\faauto\\adjustright\\rin0\\lin0\\itap0\\pararsid13701052 {\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid10821911\\charrsid15169477 ",
        "l=40y",
        "FH[a!",
        "7(2$gp",
        "MP02'",
        "T#UcU",
        ".80wZ",
        "&}/RqIb$",
        "90I[|",
        "2/9Z/",
        "x(#{2",
        "r{t t",
        "RWnpx",
        "`sN3n^",
        "6\"6)626;6",
        "#pn/*",
        ";{\\tA",
        "E:IT$",
        "&x3lR",
        "U[mR@",
        "sA64lm",
        "GX_^[",
        "Old server detected",
        "nYcw{",
        "libeay32_0.9.6l.dll",
        "020M0x0",
        ";,;W;",
        "7$7@7\\7x7",
        "yC}%EP6",
        "6d$Pg",
        "6qF\\0",
        "C[w^_S,~",
        "N1&=5,",
        "4(4[4j4",
        "4(444T4d4l4x4",
        "T%t}`z",
        "ssl3_get_finished",
        "EE?8Q/",
        "kRjt_",
        "9,64j+O",
        "xB3-CD",
        "Failed to format string",
        "L143`",
        "[V{|O",
        "-\"ed6",
        "nvRJl",
        "&HmI2",
        "DH(1024)",
        "WixShellExecBinary",
        "{/j5|",
        "73>\"D",
        "2U3u3",
        "whTz,",
        "9h^'n",
        "nOGL@p.",
        ":$;6;<;O;];p;",
        "##b[F",
        "4&444C4T4b4m4",
        ";Q<U<Y<]<a<e<i<m<",
        "5M5U5",
        "RrS~9",
        "win.nt.2000",
        "%E1t5",
        "376Er&%,",
        "77.7\\",
        "%>~zU",
        "yO_YI",
        "jAjyj\"",
        "@9J;Q",
        "ServicePackLevel",
        "1R1_1",
        "5Qc)@",
        "4%4t4",
        "%7!ft",
        "\\etl^",
        "_Ny{,",
        "<;10a",
        "zRrOP",
        "X509v3 AC Targeting",
        "JFMLQ",
        "ydCy%",
        "9%:B:Q:",
        "cKQ]7",
        ".%#[ex-",
        "api-ms-win-core-string-l1-1-0",
        "F+H?h",
        "qjx^c",
        ":zxwI",
        ">U?r?",
        "(GTw_K4",
        "GCd9*}",
        "D4SPm",
        "stI,I",
        "p'\\RA",
        "?D?H?L?P?T?X?\\?`?d?h?w?",
        ")24\"\\",
        "jj]jhj[",
        "SecureObjects table doesn't exist, so there are no objects to secure.",
        "mi]^Np[",
        "!g=ZP",
        "H_2A![9",
        "H[P[)",
        "&'X|!R_",
        "2:2]2",
        "*l=Om",
        "YjP,X",
        "]AJUw",
        "wP@=g",
        "N=<lYX",
        ";{3!H=",
        "kU:TH",
        "0x)d?sr",
        "=H=}=o?",
        "~StYm",
        "bs(]]_=",
        "}M,Cw",
        "FCMOVNBE",
        "6<Yy!",
        "xi+l[",
        "#{O.A1V",
        "(./t~(r",
        "Improper termination for %s",
        "8]I'u",
        "E@u/4",
        "c2tnb191v2",
        "missing tmp rsa pkey",
        "UfIrLi",
        "]He2'=",
        "D;O3X",
        "[LICENSING] beta license expired - already",
        "`pmWY",
        "partial download completed, closing connection",
        "SCUIAPIMode is set to true",
        "Hk.so",
        "\"{2GI",
        "H9N#\\",
        "1{dP,S",
        "?0F0v0{0",
        "w2pP\\",
        "bSkJx",
        "e'50z",
        "bY`q7",
        "7 7,747\\7d7l7",
        "(gR!>",
        "r\\s2]",
        "L @po",
        "camellia-256-cfb8",
        "!32zF",
        "KMH3$",
        "failed to set exception profile",
        " ?W$g",
        "D$`SP",
        ";Zof[",
        "decryption failed or bad record mac",
        "(a*Og?",
        "failed to build domain user name",
        "spanish-modern",
        "mk(=7yG",
        "C$k1n",
        "x:SUVV",
        "R7x Case - exit installation",
        "hgKoF",
        "failed to free xml file verify path in change list item",
        "E5cRK",
        "D$0;\\$(s",
        "? ?(?",
        "9[rVa",
        "5e+C('\\",
        "9{@t59}@t0",
        "\\$q[2",
        "AppPolicyGetThreadInitializationType",
        "=GM+K",
        "a-,Z)",
        "UTqp%",
        "!+rbx",
        "X >ZP",
        "ClientVersion",
        "j?)*W",
        "K|K4j",
        "Aod4,",
        "9yqr}",
        "failed to duplicate write handle",
        "\"(BiVM",
        "< <(<0<<<\\<h<",
        "xl1aa\"\"",
        "-$}|'S",
        "jCjmj(",
        "/)4Jw",
        "1d9:\\",
        ")H:_sX",
        "RebootRequired",
        "}U@++t",
        "]fz.j",
        "9~BFv-",
        "j4cBs",
        "jqhxE%",
        "australian",
        "pmefu",
        "^4e2Xt",
        "deltaRevocationList",
        "A>w)2",
        "&hugZ>",
        "ec_GFp_mont_field_set_to_one",
        "IuFUo",
        "Fy6;_",
        "7\"797q7",
        "unsupported MDTM reply format",
        "}r{t<N",
        "FO9J|9",
        "Switch from POST to GET",
        "}KCkE",
        "CertOpenStore",
        "vU,KP",
        "!/o,c|",
        "KToyp",
        "kjz7)p",
        "le;Gw",
        "KsuAl",
        "dtls1_send_client_certificate",
        "l<?6~",
        "*|x xHX8",
        "U}^?k",
        "set directory back to %s",
        "9:9V9r9",
        "aQbPd",
        "{2@68",
        "Q$0!;",
        "^-Ahl",
        "9B9m9",
        "tlsv1 alert decrypt error",
        "bZ*v)",
        "<[U#wll",
        "KMp$^q",
        ":6:R:n:",
        "TNx%)!",
        "Z2nYE",
        "33RO<",
        ".e#+KU",
        "42P_V",
        "2!2A2i2p2w2~2",
        "k>O|Z",
        "<E{J.B",
        "f9<H}",
        "[ q^Lr",
        "6nBplp",
        "[3pT8}",
        "=gFeNK|*=",
        "f\\U3R",
        "jT-Yn",
        "ag&Pj6",
        "ar-TN",
        "%p  %s",
        "iYMX|",
        "jzjdj",
        "Configuration failed",
        "sr-sp-latn",
        "~^%D]",
        "4j\\k>",
        "bad state",
        "RulesGetPropString",
        "yVK[r",
        "6jDb4",
        ",RHMG",
        "YTEVD",
        "2S66 e",
        "<>o~t",
        "qS@oo&",
        "|$D;|$$w0",
        "G>w'A~",
        "oE;Y)",
        "S~.NVW",
        ";Gbr+1",
        "wmUo0",
        "wA/E}",
        "+7Yb;4;",
        "~a_bv",
        "CountDataClientClass()",
        "%2%:$DJ",
        "[S[(X",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid1729076\\charrsid15169477 ",
        "0$1J1",
        "NRuZt",
        ")G&}j",
        "2=hd-",
        "=&>3>H>P>V>d>l>",
        "g5/gN",
        "8!8'8-83898?8E8K8Q8W8]8c8i8o8u8{8",
        "EYHnCx4",
        "':?pu",
        "^i+dJ",
        "}{))R>",
        "eps_about.png",
        "6+9$[",
        "S)(e%",
        "L>^p%z",
        "-v2x~",
        "90YJ -6",
        "a\"4h9",
        "nOb4_p",
        "R2H7%i(",
        "tO0[v",
        "Zgu%_/l",
        "ee}ZW\\",
        ".g&C=#",
        "SetThreadAffinityMask",
        ";4;;;J;W;",
        "h+5;I*h",
        "61[bA2",
        ")FT~AZ>2i,X",
        "=&>8>\\>m>",
        "aT7tH%",
        "FJ:V=",
        "NA%$z",
        "g`na\\",
        "]z#x!",
        "k8;f45a85f7",
        "QU%}f",
        "-6?c<Z",
        "VQKkKC",
        "0F_/#",
        "SECTION",
        "failed to write exception target (port) to custom action data",
        "Jv5Z8",
        "Ku?Qx",
        "QmBP}7",
        "LPjQW",
        ".?AU?$error_info_injector@Ventropy_error@uuids@boost@@@exception_detail@boost@@",
        "<0|*<9",
        "_set_fmode",
        "nL!E.",
        "EDX:%08X",
        "lTnlz",
        "(M~6R",
        "&A:Xe",
        "F0H@BM",
        "t$ SS",
        "c6&zV",
        "\\lsdsemihidden0 \\lsdpriority61 \\lsdlocked0 Light List Accent 3;\\lsdsemihidden0 \\lsdpriority62 \\lsdlocked0 Light Grid Accent 3;\\lsdsemihidden0 \\lsdpriority63 \\lsdlocked0 Medium Shading 1 Accent 3;",
        "$zW=qew",
        "/JH1#",
        "evp pbe cipherinit error",
        "GetCommandLineA",
        "Z@G6}",
        "D,*0>",
        ":^IW.",
        "1$2)2",
        ":M;S;^;z;",
        "D?mhcB",
        "<-<M:M",
        "n6jA!",
        "%*1<H",
        ")I%~u",
        "%\"{Ce",
        "KxA3X",
        "I~%[c",
        "f9uI/",
        "CO\\0i",
        "LUR))",
        "&6EkA",
        "WYFO`8",
        "yJ;M?*$",
        "{8:s2L",
        "rL%pm`",
        "2 2'2s2z2",
        "!@7vC",
        "&<tp?",
        "EU}<p",
        "$X~_s<",
        "<`rf(",
        ".\\crypto\\asn1\\bio_asn1.c",
        "2Y@t3",
        "l%doL",
        "#:!v<",
        "@7DMYV",
        "WShDM!",
        "?4p7B)(",
        "JCmx#%",
        "X&]t*",
        "B,VX$d5H",
        "K5Bq}",
        "api_ms_win_core_interlocked_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "4'.x-",
        "8w~?M",
        "a!BKPj",
        "ljXCRn~l",
        "Xx]Y[8V",
        ";1=A=",
        "4A4i4",
        "4kzZ+",
        "\\|MTx",
        "= =@=L=l=x=",
        "failed to write mode to registry",
        "_{xH\"",
        "english-jamaica",
        "x~pA[",
        "CreateMutexA",
        "kHp4c",
        "{X+`1",
        "^9P7T1x",
        "|?5R @U8",
        "EC part of OpenSSL 1.0.2h  3 May 2016",
        "2N3U3",
        "CompStartComplianceService",
        "3<3@3L3P3p3t3",
        "j;-w(<|",
        "Cl[h<&~L>",
        "E929889F202883548BC74E6CCDEA3BBE",
        "LookupAccountSidW",
        "$|91_h",
        "D<i~6",
        "=y=N?",
        "091v)+",
        "CRYPT_E_REVOKED",
        "id-regCtrl-pkiArchiveOptions",
        "nnNBU|# ",
        "7U9U:U=U?U",
        "j^& i",
        "5Y5^5~5",
        "`{=r.",
        "IDy.i",
        "a*)mV",
        "End Point Security R80",
        "Ck,DXig,",
        ")tXnm",
        "cg1<>",
        "4J5Q5c5r5",
        "5HX*&^",
        ".\\crypto\\asn1\\tasn_dec.c",
        ",K'Z+",
        "EV~TF?",
        "e`?(m7",
        "PJ;@D",
        "ML&P\"",
        "D+l?]@",
        "bS?Qv",
        "C&[dTmR",
        "A5h|P",
        "a+S_g",
        "5$6(6H6l6p6t6x6",
        ".5i[F",
        "kUPh4@",
        "XZtO:%",
        "rx<jX ",
        "3b9pa",
        "bH]#E",
        "s#\\hK",
        "cmd /c \"del /F /Q \"%s\\System32\\drivers\\vnaap.sys\"\"",
        "|\\+WI",
        "=&=.=7=@=`=i=o=u=",
        "+ZZFV",
        "IM_SECURE_NETWORK_DUMP",
        "W\"y6#",
        "CHECK_CONTENT",
        "%sProcessMonitor.dll",
        "ZBWUP",
        "\\7)7w",
        "$$sn//m",
        "rzVO--k",
        "ij(0Y",
        "=-=vNw",
        ")ElH5",
        "my$#$",
        "}*=^g",
        "TS_TST_INFO_set_tsa",
        "zonelabs\\plugins\\version.xml",
        "4#5A5",
        "llXS9O",
        "Z,LVV&",
        "iUdbZ",
        ":(:\\;><S<",
        "uSAMT]epc",
        ">#LK|",
        "-\">!-*>1-2>A-:>Q-B>a-J>q-R>",
        "t@*_Fq",
        ".?AU?$error_info_injector@Vtoo_many_args@io@boost@@@exception_detail@boost@@",
        "}G(4yo*N~",
        "NFNHa",
        "Xw%Ef",
        "666R6n6",
        "V0lQRp",
        "y;q;R5",
        "St;i$",
        "openssl.cnf",
        "`'V+~=",
        "&GhG6c",
        "/G3Ae",
        "`N4BcX",
        "%V4T1",
        "Dg?nh",
        "tMO|L",
        "979V9",
        "9]4wj",
        "{X3di",
        "WxxK5 ",
        " 050I0",
        "f\\:x0*",
        "l=7UA",
        "= =0=8=P=T=h=l=",
        "AAAAAAAAAAAA]A",
        "h/=T~",
        "Li(6v",
        "5;6@6k6p6",
        "V.o{Eo",
        "REBOOTDELAY.7F579463_4BEF_48D0_80B8_41508273B36D",
        "CGf$K9",
        "$0WR)",
        "Hu%nM",
        "xICZm6,",
        "\"M6s>",
        "[<O:'",
        "}QXE}",
        ".PQEa",
        "Cm)CI",
        "unsupported protocol",
        "8 8<8X8",
        "`$SjL",
        "lS_Ho",
        "X%DpA0",
        "yaX=B*",
        "setDafStoppable failed.",
        "Y/)@;X",
        "u #)r",
        "&[\\MV",
        "malloc",
        "U,51d",
        "?NV}n",
        "y?%R*",
        "2ej{^",
        "j]|,P=",
        "r@r6B8X",
        "C PjPW",
        "uy/h6",
        "\\PKHu.",
        "tt+?3",
        "G8_^[",
        "GetCurrentProcessorNumberEx",
        "WSACloseEvent",
        ">U{eLP",
        "Dd`bf",
        "|]@h(Z",
        "6-gs{",
        "&=U +",
        " (K|\\[g_",
        "zp)dN",
        "7Kh8(z",
        "EVP_PKEY_verify_init",
        ")]<I>",
        "\"&&ceBb&",
        "29y//\\",
        "#0}6K1",
        "\\)ES_`lF",
        "loB?f",
        "}\".)E?",
        "2k~ow",
        ";C>[z",
        "*%*/*O*U*_*e*k*m*s*",
        "<+<B<V<j<~<",
        "B\",dM",
        "h&@Nt[",
        "!(OSy",
        "7enrw&,&",
        "lK+wq",
        "1$2)2.2M2f2v2",
        "5*6j6",
        "Yn|E^",
        ".A:L{",
        "rCLU&Vj>",
        "[tAxZ",
        "O}J U",
        "Dahi[",
        "jfjdj+",
        "y1cIxE",
        ".?AV_System_error_category@std@@",
        "u}9^4~x",
        "missing ecdh cert",
        "setct-CapTokenData",
        "33t0&n",
        "Delete",
        "-0*1[",
        "{x0`7",
        "~|kgf",
        ".?AV?$holder@V?$string_path@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$id_translator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@property_tree@boost@@@property_tree@boost@@@any@boost@@",
        "E<TS{",
        "E28HF",
        "RL1!(",
        "z$zDzdz",
        "\\>~a1",
        "`ZXg[4",
        "\\zonelabs\\zlquarantine.dll",
        "3s.)F",
        "W,M~j=R/q9<",
        "HM/az",
        "\"AEVw",
        "MA@,#",
        "'o/On",
        "nl&`a*",
        "B&H(7",
        "08r==7",
        "k:[E#",
        "]`fa~[N",
        "F(jgYjGZ",
        "_FHgs",
        ",d1#j",
        ";j<p<v<|<-=<=C=Q=W=e=k=u=",
        "_E%xG",
        "\\J3C&@",
        "tL.`Y",
        "0!0.0;0H0S0j0",
        "removeSD",
        "SUBPS",
        "2*2N3",
        "\\af0\\afs20\\alang1037 \\ltrch\\fcs0 \\f1\\fs22\\cf1\\lang1033\\langfe1033\\cgrid\\langnp1033\\langfenp1033 \\sbasedon0 \\snext42 \\spriority0 \\styrsid3737333 Body;}{\\*\\ts43\\tsrowd\\trbrdrt\\brdrs\\brdrw10 \\trbrdrl\\brdrs\\brdrw10 \\trbrdrb\\brdrs\\brdrw10 \\trbrdrr",
        "z_~:\\o",
        "Oq)p2",
        "XscUa",
        "9v`&ua",
        "UzZA-",
        "StopTEService_rollback failed",
        "lhR[!",
        "wo.R,R",
        "Ofr*z",
        "*Z=b6f4gUXpBV",
        " 0B0[0j0}0",
        "LQS89",
        "(^=5z",
        "spanish-honduras",
        "2HrK{\\",
        "unloadVswmi",
        "='b@]",
        "585?5D5H5L5P5",
        "]z=zn7",
        "% %,%4%>$Hx",
        "OgML3Db}",
        "=Tl_u",
        "q.9@W",
        "BoN$#",
        "gT9=#h",
        "U}vl.K",
        "H9L9P9T9X9\\9`9d9h9l9p9t9x9|9",
        "Check vsdata.dll and vsdatant.sys version",
        "Pjr;X",
        "CRL signing",
        "@UV75",
        "9!:V:h:",
        "ar-tn",
        ",k{W/I",
        "dacUbT",
        "/%I<:K",
        ",=:g}",
        "5e9x9",
        "s@Ai6",
        "UWQPj",
        " 0xbf",
        "'7_-'.'R",
        "P!R_}",
        "2N|]>u",
        "v$D%`",
        "|$PVW",
        "jL%F]QG",
        "H'T*Z",
        "{2-r&",
        "uSXK2",
        ":2:@:G:M:Y:e:s:",
        "bU+#^>",
        "H2(C,.n",
        "Site %s:%d is pipeline blacklisted",
        "2@f$A",
        "z`wjY",
        "2.jPt",
        " AO1k",
        "ajaaO",
        ",W60*",
        "Sh  !",
        " and use of such features with future versions of the Product may require purchase of the applicable future version of the Product. \\line ",
        "_VTc|",
        "VMS_BIND_SYM",
        "Dyb(VSi(",
        "gh^\"6%",
        "tbn|(",
        "@UH%1",
        "d.ux]",
        "6%737",
        "t\\u&KN",
        "667C7I7e7p7",
        "Y_h`X",
        "`97)%",
        "1x<`w",
        "Process id is: %d",
        "failed to get target from WixCloseApplication table",
        "k\"IRl",
        ">/Y>qbX7q",
        "IVr>Z",
        "v{00g",
        "P d#co-",
        "@I-7q",
        "9y7iq%",
        "privateExponent:",
        "MitigationOptions",
        "X509_ATTRIBUTE_create_by_txt",
        "Publisher",
        "8k|Mf",
        "TE4B!",
        "1%`NJ",
        "qx2~a6",
        "/A`g48f,",
        "8pFO^1",
        "ldFR3W9",
        ",)-)y",
        "ASN.1 part of OpenSSL 1.0.1t  3 May 2016",
        "a}yNT",
        "E0PpW\"",
        "a,;@ra",
        "extReq",
        "16(7L]",
        "P^K0@R",
        "c\\0~1",
        "%,%:%F%",
        "unable to get issuer keyid",
        "D?=O~",
        "I,j!-",
        "unable to get issuer certificate",
        "4=4N4k4",
        "O6([4",
        "\"*OfM\\",
        "5(545<5p5",
        "f-H)l$'",
        "id-aes128-GCM",
        "\"j\"k\"l\"m\"n\"o",
        "W0f0y0",
        "Check Point Software Technologies",
        "=!=6=A=G=M=R=Y=_=h=u=",
        "U}>_c",
        "<}3hNU7R",
        "W7We_",
        "a:-Df",
        "\"<.*y",
        "s.%u$",
        "1ir43q;Xb",
        "el-GR",
        "^}s'z",
        "j8Z4T2",
        "69@+0",
        "lGo2J",
        "<E|9w",
        "n>7\"/",
        "(!7]A",
        "&bv%n",
        "lN2aG{",
        "37@My",
        "2\\<N%",
        "86.40",
        "646?6M6",
        "Failed to register the file name with the Restart Manager session.",
        "RV;*|",
        "CGDH5_",
        "+R$W*",
        "g$CL7",
        "?P$4|",
        "id-GostR3410-94-CryptoPro-XchC-ParamSet",
        "\\GUhnt",
        "wQaDE",
        "D{Ir[",
        ":aH#6",
        "MD5-SHA1",
        ">03sQ",
        "7Z>|k",
        "_7*_S",
        "Xd.{X",
        "=R>[>p>v>}>",
        "?!?1?A?Q?a?q?",
        "eJZJ^K`%V",
        " $H+\\",
        "Logging off from vsmon",
        "n]Js.",
        "p5IwN$7",
        ">Eu\\a",
        "5K5O)",
        "z>p3vM",
        "-o=Dw",
        "nI68`",
        "<(<A<Q<i<",
        "WixRemoveFolderEx",
        "t$VWQ",
        "S3_8v",
        "ar-JO",
        "{EzYd",
        "`Q2(Y/",
        "#<]IU%",
        "FYY;w(|",
        " ]v#H",
        ">3?V?y?",
        "j,U07",
        "nOO#.",
        "~~HO4",
        "NORTv",
        "SCFu$FX",
        "DY86+",
        "7A7b7",
        "cmd9=",
        "x@PP4",
        "SIur^",
        "cTY;3^",
        "h%'R^",
        "[i^MW8w",
        "P?%]q",
        "_^AIv",
        "F}j%Q",
        "&.7ZY",
        "2'Hc]",
        "Rx>HosH",
        "314|4",
        "dVF](_O",
        "d{![i[x@",
        "[VECTORED EXCEPTION] The RPC server threw an exception.",
        "7i)!@[T",
        "EMXPi",
        "V9mag",
        "?Uz7x",
        "{jkfwb",
        "*{j/O}",
        "Z-ugN",
        "DeleteConfigs",
        "Z)2JVW",
        "GetFileVersionInfoA",
        "D Q:h",
        "ggv)HH",
        "0l0x0",
        ". You may not assign your rights or obligations under this Agreement without the prior written consent of Check Point. }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid14380787  }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "nxdnp4",
        "MultipleInstaller",
        "c!1-:/vN2\\",
        "invalid compression bit",
        "*2R8G(",
        "\"?&H;",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\f1\\cf1\\insrsid3374529 \\~",
        "l>JGW",
        "V9k6yJQ",
        "DmM4G",
        "$[x&p",
        "GetSubMenu",
        "a)1fKT",
        "O=r\\X",
        "0Q0t021",
        "KeyFob.png",
        "x$wo-",
        "aPT.j",
        "Z%yGO",
        "W)^WAu",
        "GIyNR=",
        "E#Rm9$O4",
        "AK.L2",
        "Er2n!",
        "uGE^a",
        "I-.ek",
        "0d:H4",
        "F't@{@",
        "lPmmp>2",
        "#&%x^To",
        "+j6on",
        "1$1?1f1k1",
        "i\"nE0",
        "{<~2W",
        "u(hH;L",
        "^okdAO",
        "QhQiQjQkQl",
        "<9-<v",
        "q~>~l",
        "Too many references",
        "E ~y9",
        "jkjnj",
        ">6vCJ",
        "GVcB5",
        "l ?y>",
        "`~Pd)",
        "< ;'B",
        "#E\"xlf",
        ",K5Tc,",
        "|RT}7",
        ":O;};",
        "Pc1'(",
        "Y&Vu$}",
        "='=u=",
        "yNCN65",
        "a\"JQ(",
        "727v7",
        "~38Ln",
        "KcYgn",
        "9F.a;",
        "VA<t3",
        "SvM|\\VEZ",
        "939\\9t9|9",
        "u?'&o",
        "D$(P3",
        "CryptCreateHash",
        "WIX_SUITE_SINGLEUSERTS",
        "LanguagesExclusive",
        "AAACg{",
        "kQ't8",
        "p:w3q;",
        "hdS$uc\\",
        "+Y7qk/",
        "Zr/p:",
        "=6>)?<?h?o?",
        "0%6%@%",
        "U{:7CP",
        "/b, _",
        "=f>w>;?Y?",
        "?PIdW",
        ";#;%;':)A",
        "P\\4Y`D>4f",
        "Done waiting for TE Service to stop",
        "F(1FH",
        "8B*+<",
        "d@vbmt",
        "ca dn too long",
        "(Ey85M",
        "HO[k`",
        "serially",
        "Char=",
        "czech",
        "\"i6]>$",
        "i ?\"e",
        "$&Xty",
        "_Z9Xn",
        "id-smime-alg-ESDH",
        "4,565@5G5Q5[5e5o5",
        "AddToWinFwExceptionList:  AddToWinFwExceptionList() failed.",
        "242<2D2P2p2x2",
        "^aN#j",
        "5xz[o",
        "aDWl\\I",
        ">zO(8",
        "9Jk.z",
        "5>/e|",
        "7m|h9",
        "B}![vH",
        "Successfully changed DACL",
        "_M/r/Q/t/U/",
        "|$$UV",
        "]eXu@i",
        "<<<t<",
        "8$8/8J8",
        "'Qu(W",
        "j<6oC",
        "_;wIl",
        "^;7eg",
        "H;D$,",
        "uW 323",
        "R(Ry_",
        "=>$ |TB",
        "7/757<7A7b7g7v7}7",
        "^~lYI",
        ".mnIw",
        "!h<m^",
        "%Iye<",
        "FMSBM",
        "$PJO`I",
        "+hq[,um",
        "FSQRT",
        "H}om3",
        "28qN#",
        "=-E3h2",
        "yjLsdP",
        "G^0/_,",
        "wJ-A),F",
        "ExecXmlFileRollback",
        "O~2M{",
        "Id,PA",
        "OID_MODULE_INIT",
        "y#N)}",
        "Radlyl<",
        "Ol>ur",
        "zzdzu",
        ".e]OD",
        "USVW1",
        "Q.,|5.z:",
        "u_A;L$lr",
        "<!<1<=<B<R<",
        "7r|7*",
        "sidebarLinkBackground.png",
        "e}X1Y",
        "PKCS7_signatureVerify",
        "9(:`:",
        "<-nW#",
        "EgS~5u]~k",
        "N6xsi",
        ">(>3>Q>a>n>{>",
        "6&Z>|",
        "hKM3\"",
        "m0Z<I",
        "<gpB1]gO)$",
        " 5V$}",
        "m+Jr4",
        ":*`OR",
        "rbRJZ%OR",
        "cKA%vxnW",
        "l$#0L",
        "xP} 6",
        "{z+VF",
        "lbz>,",
        "1<1H1h1p1|1",
        "{IAj(",
        "#BqxV",
        "42Yqg",
        "EG3I2?lj",
        "E[*C-",
        "f=>fZC",
        "3Jj{0",
        "d/ats",
        " {tee%",
        "DY>F/p",
        "2!2:2S2l2",
        "\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid13701052 ",
        "eo\\]\\]F",
        "[E<pw'",
        "G_/R ",
        "=%=j=s=",
        "f[YJkO",
        "?&?0?:?D?N?X?b?l?v?",
        "X509_PUBKEY_get",
        "T70fe\\",
        "^lfVMdN1)",
        "RegisterWindowMessageA",
        "jtj}j.",
        "$F+QN",
        ">'>,i",
        "qBJx7K",
        ",X~UfG",
        "zg-tT",
        "5}+f}",
        "Y4In&",
        "<*=4=;=b=",
        "\"s)BK?",
        "y=w{9",
        "k'mLRy",
        "=N>,z",
        "'d0ka}~Fj",
        "yKIKu",
        "2'2Z2",
        "ii6#A/",
        "z;>ny",
        "XZI<L",
        "]_*#U",
        "u~$+T",
        "$wE/Z",
        "i8i! ",
        "owIRd{",
        "vsmon.exe",
        "<JU{)o3H",
        "Y2EP]",
        "-$ZP5",
        "2*252q2",
        "p0Y/i>/",
        "H*bGU",
        " j hX",
        "D9%=%`",
        ";4;n;s;x;};",
        "hu+rt^",
        "WP=uhU",
        "):ba1",
        "Suite B: invalid ECC curve",
        "Z!Z)Z",
        ".E_\"/D.W",
        "xD?7Q",
        "z!dTG-",
        "Th`L!O'",
        "t$$VV",
        "encapContentInfo",
        "Ef;VO/",
        "D$<QP",
        "GB<\\\\:zc",
        "N1B\\\"",
        "g}kJ$",
        "no port defined",
        "x%^ZQ",
        ".iWS'K",
        ".(V`$T",
        "4$U\")",
        "A(.dp1",
        "2ePW1u",
        "E/$0/4",
        "pnGUv",
        "333O3k3",
        ",lv3C",
        ";OU.K<",
        "WatchdogAPI.dll",
        "q0Wzo",
        "-A($8P@",
        "ASN1_TIME_set",
        ".?AVerror_category@system@boost@@",
        "60F0v0",
        "`^\"eC",
        "Successfully stopped TRAC service",
        "TAK*L",
        "t7jHh ",
        "_t:sx",
        ".!s_iX",
        "js,c,",
        "Q4AOp=",
        "M:0dy3",
        "CZ.5b",
        "J|cV[",
        "'ExL%",
        "C`<C0",
        "Disconnected",
        "targetInformation",
        "^}+^+j",
        "LrA&^",
        "rbp<3",
        "B},!=",
        "setct-CredRevReqTBSX",
        ",F^+w",
        "7 818J8",
        ")~kPC5_",
        "sealRDB()",
        "/ys'O?",
        "9F:P:m:~:",
        "Rs8<K",
        "2#?4U",
        "#\"|zB%",
        "SE?j$",
        "Msw%Y",
        "]x$.G",
        "f:\\ckp\\src\\ep_calib\\e87_20\\vpn\\calibrary\\readpropfile.cpp",
        "uPybd",
        "b9NLEhS",
        "6#Rj\"ik@`",
        "(j,#9b/G",
        "UWee,",
        "dSIFNW",
        "F!iB%",
        "9$949<9D9L9T9\\9d9l9t9|9",
        "|j!q{",
        "]XjRu",
        "deQrJ",
        "FkFo#",
        "~C<31'",
        "0(=rp]",
        "q^$.znfIC",
        "Ep{)6",
        ".?AVwindows_file_codecvt@@",
        "NzCp<!x",
        ">pY:L~d",
        "m93Fr",
        "iXUypK",
        "{xj^&",
        "3$4.444J4f4t4",
        "+QQ 3K%",
        "sgq5^/",
        "Af;:u",
        "0s~96y",
        "sD+-+",
        "`S)$Y5",
        "1GX9y",
        "r0Y(N",
        "H.f16S",
        "r&Kma|",
        "BN_CTX_get",
        "1,e~_",
        "c=tksd%",
        "szProdCode",
        "5 5,585D5P5\\5h5t5",
        " *lFK",
        "808]8",
        "h}>0,G",
        "*(<h'",
        "dIu3C",
        "^zh4(",
        "[Q9RcI",
        "?H?s?",
        "T(z@4SD)",
        "5 o?t",
        "4o}tv",
        "Gk`u?",
        "!lJU/2",
        "<V=c=b>",
        "|d|Xl`",
        "Y/58U_",
        "3T$01",
        "api-ms-win-security-systemfunctions-l1-1-0",
        "P(p +",
        "]UJl=",
        "wVd#|",
        "}^U\\vv",
        "X3g/0",
        "{kW&V(?",
        "Failed in OpenProcess, error: %d",
        "HelperPID",
        "tqQRW",
        "MY]XK",
        "Lf!z0&",
        ".`ig4",
        "{|ZnT",
        "Y[Wtq",
        "3hMQ5,h",
        "*q+n\\R",
        "!4|>.",
        "-Z5$Q7",
        "`M]6{",
        "6\\7d7",
        "|HL5{",
        "H6q N",
        "Qca|I.8",
        "5$5D5L5X5x5",
        "V?,j>",
        "8(8,80888P8`8d8t8x8|8",
        "SVj0^V3",
        "8sSso",
        "Failed writing body (%zu != %zu)",
        "U`vEHfYa",
        "4I:y)",
        "jjjwj%",
        "zhwGk",
        "`dvfv",
        ";2<M<",
        "J7'v.b",
        "%ND0vI",
        "7!ruTQ7",
        "LbxYc",
        "tTJ7C\\",
        "\\ZWNe<5",
        "B&gw_|T",
        "P:4vQ/{",
        "^Ry(xd",
        "2Rw<K",
        "KZeTW",
        "3jIkCr@c",
        "c5f5j5t5e",
        "#RzvP%",
        "OIC@/b<\\L",
        "H,KMK",
        "r=)r'",
        "7@t(h",
        "xbEa'",
        "dc~NM",
        "<}<A1",
        "ALERTS",
        "bQ2./Hu",
        "B$]CHz+o",
        "7#zu@o",
        "XTt89t1Z",
        "-=[$b",
        "Menwo",
        ";[R6)!SL",
        "1#1J1j1",
        "BV.PH4D",
        "X+)n;",
        "<2p]>MK",
        "?&?1???",
        "PWWWS",
        "Failed to run MsiGetProperty to retrieve INSTALLDIR . Setting to NO as default.",
        "1AqE<",
        "bP%5$1",
        "uP<;?",
        "pyPlt",
        "+K1{9^",
        "l92=r",
        "\\U|'V",
        "*>Y_Q",
        "ttkbP",
        "no solution",
        "6L{r$",
        "COMPUTE_WNAF",
        "kfpJM",
        "V6Oac1",
        ";0c0V",
        "pjjW\\",
        "]1(xqw-",
        "&5G\"m",
        "ssl_undefined_const_function",
        "}[<1S",
        ";NDt1hX",
        "CPINSTADDEXT_",
        "Yl<CP",
        "FpWug]",
        "6\"6'626U6a6f6k6",
        "5T5[5b5l5{5",
        "+fjMl",
        "|IktV",
        "fd2`3r",
        "oGV9p",
        "\\InstallProperties",
        "hXo h",
        "}K.`}",
        ";(;H;P;\\;|;",
        "%\"^)NA",
        "5#5'5+5/53575;4?j.m",
        "lOF'f",
        "*^D<1<",
        "%s%s=%s",
        ">(>|>",
        "m_]8'",
        "Zz5uqc]",
        " }H8D",
        "DetachDataClients()",
        "dqSu[",
        "3B4J4Z4",
        "r*td7",
        "ul=_g",
        ";&<5<{<%=",
        "oR[Qk",
        "M\"UL7",
        "V1\"+W",
        "$b>{w",
        "'G*>^",
        "y>,jO",
        "^1oC)l`nP",
        "FJ9)#7\"",
        "Av.qd",
        "CC7.$",
        "3\"3v3",
        "JwI~C",
        "CLfu\"",
        "{0s.Zq",
        "Q\"FD[3(7",
        "?Yq7>",
        "5K#b?T",
        "Lnd< `",
        " cg*;",
        "7Zy9]",
        "XRmX-\"%2Z$",
        "!yw[l}\\o",
        "(.AG=",
        ",b1`A",
        "P&<N@N",
        "Iqw}wB",
        "@0D0H0L0",
        "C0@\\Y",
        "1~#&}fE",
        "uH:H.",
        "+cp]t",
        "h{_zu",
        "h~&?d",
        "6H9B]",
        "D$lSU",
        ".,OvM",
        "ouC|T|",
        "H%3]S",
        "LtsW>:",
        "~|F6Z",
        "LMM#z",
        "NP2Qmv",
        "tXA32M",
        "RP:YG",
        "hyJ:0",
        "}`>wh",
        "Hw,?/q",
        "lRD%h",
        "PKEY_EC_KEYGEN",
        "6#616D6o6",
        "sy77yC",
        "Z,oOG",
        "#rA,(",
        "HKyyA",
        "(t[fb",
        ".Cw=t",
        "@Kp072",
        "~+&,f",
        "C[ls#XS",
        "Ng;`_",
        "(||9ts",
        "4qe{X",
        "?b[WaXQ",
        "?f){}",
        "t#zh\"Y3T}p",
        "-U' '",
        "w3kKt[",
        "\\lsdsemihidden0 \\lsdpriority0 toc 7;\\lsdsemihidden0 \\lsdpriority0 toc 8;\\lsdsemihidden0 \\lsdpriority0 toc 9;\\lsdunhideused1 \\lsdlocked0 Normal Indent;\\lsdunhideused1 \\lsdlocked0 footnote text;\\lsdunhideused1 \\lsdlocked0 annotation text;",
        ">jn:M",
        "YySto&W",
        "/8wsf",
        "wsL?t",
        "OM/_.E",
        "W2c!y",
        "0123456789ABCDEFabcdef-+Xx",
        "e$k |n|",
        "n:&5f",
        "|qN/iM]",
        "SRP-DSS-AES-128-CBC-SHA",
        "Vh^!:*",
        "zc+FBgQS",
        "y3I/_",
        "ar-lb",
        "c!!B0",
        "fI(~L{",
        "Y+H>\"",
        "e`g5l|",
        "F_%dJ",
        "}<d&uLR",
        "vovn'^zg",
        ">8><>P>l>p>",
        "epklib_x86.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A",
        "challenge",
        "H7WJ$B",
        "%us)/",
        "d [\"v",
        "BUF_MEM_grow_clean",
        "R1lgV",
        ":@H]rT",
        "VfxC?`",
        "3\"k :o",
        "$9Ck(",
        "TlaO0Pm",
        "v:N=r",
        "n'R`u",
        "hin=8B",
        "=z_^y",
        "nSRecord",
        "NetCfgInstanceId",
        "7'72777=7G7Q7d7i7",
        "R[]pC",
        "JI@ 7",
        "*#7Gl",
        "&0<0G0L0",
        "n-#w o",
        "; <0<`<",
        "9_:|:",
        "Z#L$<",
        "UPGRADEREMOVE",
        "7B3]m",
        "*RQ}(",
        "|U|e^",
        "9%9B9g9",
        "I=wKh",
        "vj,?W8",
        "A=aa=",
        ":|c_a",
        "\"H{WgS",
        "v?@y0C",
        "Z|^tZUT",
        "vE`x?",
        ":':8:a:s:x:",
        "(J`\\u8iG\"&F",
        "EDH-RSA-DES-CBC3-SHA",
        "C Mp,",
        "Ia2zR",
        "jmjpj",
        "D$(^][",
        "VB?0%",
        "jTxV>",
        "Y=$.\\",
        "@I`ja",
        "k W<u]",
        "\\ZoneLabs\\avsys\\drv\\",
        "7+7o7",
        "!Qk27",
        "re$EzN",
        "qE[!n",
        " c4bO",
        "4tkMJ",
        "{c2s{d",
        "sXJ4:",
        "BnU'LB",
        "<!<-<C<L<U<",
        "nF96H",
        "yNJ..",
        "W76)d",
        " B0@CQ",
        "CleanTray20Component finished.",
        "H;F#%",
        "\\J>%f",
        "GetSidSubAuthorityCount",
        "19<6[",
        "mLw^1B",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\common\\logger.cpp",
        "~\\R&Ss4",
        ">8W'E-",
        "/yH%r;M",
        "6s t4",
        "D$$hT",
        "y7H|oK#",
        " _9%(",
        "ReportError",
        "45G++",
        "Ex+vq",
        "H/`JO",
        "5'5`5",
        "jHT|B",
        "SSL_CTX_use_RSAPrivateKey_ASN1",
        "94:Q:Y:~:",
        "[(&zi",
        "|W2QW",
        "%s is a symbolic link. Installation under symbolic link is impossible",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\upgrade.cpp",
        "HiwH@",
        "?&?8?Q?g?{?",
        "tm}5Ml3",
        "KSdlg",
        "3*MJvzen",
        "x7|}t",
        "3IxFY",
        "+sPe*",
        " KB>B",
        "r(,~_",
        "gtB>^S4",
        "m=4ar",
        "vN\"(^E",
        ")_0s|",
        "=:?cw",
        "yaK-?",
        "NecH*&",
        "+At+D$",
        "9m|\"U",
        "373<3G3K3Q3W3[3a3g3k3q3N4",
        "GY~]PvA",
        ",4DHr%",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\install.cpp",
        ":$81O",
        "OX=Fm",
        "<0<?<D<",
        "ubP}$O",
        "0 0/0p0t0x0|0",
        ">qAj`j",
        "'^<}g",
        " 2kDb",
        "CLIENTSTARTUP.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "{\\*\\latentstyles\\lsdstimax267\\lsdlockeddef0\\lsdsemihiddendef1\\lsdunhideuseddef0\\lsdqformatdef0\\lsdprioritydef99{\\lsdlockedexcept \\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 Normal;\\lsdsemihidden0 \\lsdqformat1 \\lsdpriority0 heading 1;",
        "{JQ\"*",
        "}gD]+j",
        "{o/c0",
        "h9Q!e)",
        "AnTuq",
        "ckqq>",
        "f\\?kmKG0",
        "^z4X]",
        "b76{N~",
        "lXiWs g",
        "Sd06N",
        "/0RzW",
        "%/v/z",
        "^+qn3W",
        "BIO_nwrite0",
        "FUCOMIP",
        " `qot2",
        "9*:v:",
        ";<;D;P;p;|;",
        "JJw@h",
        "L{Nh1a",
        "NW) <",
        "m]Yf0",
        "X\"f`^",
        "778H8Q8",
        "b[`U3OG",
        "TO\\Xs",
        "\\gHaCs",
        "zV6*i",
        " PT@vo",
        "B8`;t",
        "ZoneLabs\\zlsc.dll",
        "OUSVW",
        "TD=gD",
        "s+5Cj",
        "bX ,d",
        "d/1`'",
        "v|+W]",
        "KK|SD",
        "2V<#c",
        "^4Dy3u",
        "M_Z8X",
        "BJ4MCC",
        "r a{y",
        "\"lQE+]",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11555386\\charrsid15169477 ",
        "CRolloverMgr::CopyRolloverBlock():  unable to open log file",
        "*kbyn",
        "Wu0WSh\\",
        "]R2Wv8",
        "?x,v&",
        ",fhfq1",
        "(owJ'",
        "_zj>g",
        "q'~GJ&WN",
        "i({2ny",
        "gkKYD",
        "1/1A1N1h1m1",
        "2G3Q3n3",
        "vm`o*eE",
        "&as~4z",
        "bPiB,y",
        "jVYlJ",
        "j=^y1",
        "\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2764809\\charrsid13256927  from its activation}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid13256927\\charrsid13256927 ,}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2764809\\charrsid13256927 ",
        "7}g_&",
        "Some in use VPN files are not removed.",
        "3-6&Dc",
        "O+P\"u",
        "Found cached EPS installer",
        "DM,A ",
        "x^i\"z",
        "\"G=LP",
        "ssl3_send_client_verify",
        "3\"3/3B3H3W3|3",
        "K\"{7H",
        "D$XUP",
        "\\6I,;<AE.",
        "rQS{C",
        "5InkI",
        "{8<nj",
        "Client hello",
        "D*f-s",
        "ZP/:2d",
        "8$8,848<8D8L8T8\\8d8l8t8|8",
        "n#n0`1#",
        "{K`rHZ",
        "InstHelper.exe: StopEndpointConnect",
        "[|`^\"",
        "ENGINE_FREE_UTIL",
        "<r'^W",
        "l$(WV",
        "%kUaU",
        "@D/R3",
        "C^Tqx4",
        "xbc'm",
        ">Hc~(",
        "UI~;*EA",
        "klbackupdisk",
        ";Q:78D",
        "lg4|*",
        "oQu!$",
        "failed to write XSLPattern selectionlanguage indicator to custom action data",
        "gxx_$",
        ";_tr.",
        "streaming not supported",
        "2bcaK",
        "z1_el",
        "InstallVSTOR",
        "ChangeServiceConfig2A",
        "z1~6I",
        "j5SR`",
        "<)<5<C<|<",
        ",|:0;",
        "V9c+P",
        "vi~y>v",
        "[e:+'",
        "4,404<4L4\\4`4p4x4",
        "d%1ymQ",
        "pbeWithMD2AndDES-CBC",
        "A3LLK",
        "Idxvg",
        "A duplicate pointer was created. Continue.",
        "j&jnj",
        "jqjzj",
        "RECONF",
        "X)I6@a",
        "P=:R;",
        "trac.config.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "3-3H3c3",
        "t^HCr",
        " +z[>",
        "zzB\"J",
        "6t*N@",
        "firewall.cpp",
        "1#tFu",
        "tm2g4",
        "473<I",
        "F3/\\v",
        "6(6<6@6`6t6x6",
        "^4<jy",
        "CB9i$",
        "PG}WT0",
        "J34A\\",
        "0/0K0g0",
        "~lzPq",
        "9'5MP",
        ".kbjZ",
        "RI_HG)",
        "5BFp%",
        "'xfeO-",
        "\"VsB;",
        "Q-2zV",
        "PruR^<",
        "Error",
        ">1>8>D>j>x>}>",
        "Xux%v",
        "0( o~",
        ";y3xW",
        "InitializeCriticalSectionAndSpinCount",
        "&`p@lT",
        "y3Jmw6",
        "6+7<7u7",
        "unsupported digest type",
        "[VSDATA LOAD] SetSecurityDescriptorDacl failed: %d",
        "<o'+/",
        ".g+|~j",
        "m0%8+",
        "\\f1\\fs20\\insrsid11303137 ",
        "LinkName",
        "O]*dR",
        "q/xKa\\#",
        "QxSsQ",
        "=8=t=",
        "%_&xG",
        ":W;a;",
        "\\ax.)Z",
        ")MOu[",
        "0%]-5",
        ":>U2g~%",
        "l~PtM~T",
        "\\$$UW",
        "q+ME)",
        "LDAP: search failed",
        "739d9x:|:",
        "_tx/C",
        "=)8YX",
        "=g=o=z=",
        "atlTraceString",
        "3@3I3g3",
        "\\par }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9205239 8.1 }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid2703887\\charrsid9533499 In the course of receiving Limited Hardware Warranty services, }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 ",
        "gq:be",
        "Rw|27",
        ",a.U,",
        "A%Es|?W",
        "2WfUz",
        "EQ7[J",
        "8\"8B8p8",
        "J|{C%",
        "Z25j_",
        "&xAP{C",
        "ZwWow64ReadVirtualMemory64",
        "])S&v",
        "vq(>o3",
        "\"JXYJe892",
        "Could not resolve %s: %s",
        "1Vk92F",
        "U2E6Jf\"",
        "zr#5v",
        "o*+]Y8",
        "NKl(Ux",
        "<;=r=",
        "9?^T@t/",
        "aj]rC",
        "dTHYML",
        "#u0cc",
        "~^8#o",
        "=aR1?/}",
        "TVgLJ",
        "Q#34ao",
        "ka)\"T",
        "$+ZsZ",
        " ^[OQi'3/2",
        "pCS1?",
        "private key header missing",
        "w^S1F8I",
        "Jj]D7K",
        "kD|!3dV",
        "mL)Oj",
        "3T$@3T$",
        "^:\"|'",
        "Monday",
        "1(101<1\\1h1",
        ".EM_D",
        "v\\*[[fU>",
        "ec_GFp_nistp521_point_get_affine_coordinates",
        "6M\"GNy7",
        "removeSC",
        "xR[;G#u",
        "{sKtT)",
        "b*ih=",
        "2Y9=.",
        "NVEoD",
        "jl/,e54",
        "-EJx-N",
        "Xy.1Kz",
        ">a?o?",
        "8BnLY@M",
        ":!;9;U;",
        ">!>=>Y>",
        "bzh\\h",
        "{Dy^L",
        "REPAIR",
        ">sEwv",
        "()_-9^",
        "f8x+6",
        "Q2S=42,",
        "o}0+UoG",
        "16?go",
        "es-ec",
        "t$4QP",
        "DGh+D<oz0",
        "\"GL/Gn",
        "|LL w&",
        "uE0oG",
        "RL[B$%",
        "oepoG",
        "X'XGXWXwX",
        "+-W7pG",
        "t$(WS",
        ",c]IR",
        "Xt>W{",
        ">/>7>P>[>",
        "JB-]j",
        ".Bu6$",
        "}4#o;a",
        "q@c$]",
        "TnT9S#",
        "\"-L{+",
        "Yih)*",
        "'<wK7d",
        "SendInfoMsgToProgressDialog: Could not process message.",
        "7)>j$",
        "p:C]X",
        "<v;vN",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid5259060 7}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid477636 . }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\b\\f1\\fs20\\insrsid3017503\\charrsid477636 L}{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 ",
        "T5vyen%c",
        "g;eUM",
        "&aVX;Ks:|U",
        ";(;x;",
        "SETNS",
        "B!;f'",
        "bad srp a length",
        ").WI.&X",
        "`\\ci_",
        "R{KsJ",
        "-(oZJN",
        "b_,Rf",
        "[+O)=",
        "SELECT * FROM Binary",
        "_r'LRO",
        "5Zo=:",
        "w|9G ",
        ";v0]K;",
        "8R/4%",
        "!B3D@",
        "%,z|u",
        "R]WDC",
        ";:,Y\"",
        "content type not enveloped data",
        "RSJXK`i",
        "vnGQw",
        "?-?:?L?V?",
        "8O({g",
        "0Za[a\\a]a^a_a",
        "-KY#C--Z[c",
        "-|dUG",
        ">'>L>W>f>",
        "&mnxy",
        "0#03[b",
        "I6%&t`",
        "=2m;K",
        "7smwu;",
        "qU:+l",
        "Kd!o/",
        "8Q8q8",
        "\\.#r-",
        "A{mY;",
        "8Bx)E",
        "l&zD{",
        "AlK=s",
        "DH PARAMETERS",
        "310106000000Z0H1",
        "Q&V?.v%",
        "44'SL",
        "\"<~E ",
        "div by zero",
        "_3`s`",
        "ScriptRun.dll.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "RFf{bP",
        "uninstallAS;",
        "F6-sA ",
        "wItA=",
        "Ne:9>",
        "4U+ED'",
        "CANT_LOAD_VSINIT",
        "V\":GF",
        "c@xKYN@",
        "  %08X=%s!%X:%08X",
        "0#2#\"\"",
        "a32D!",
        "+tMt/",
        "CryptExportKey",
        "]G+or,",
        "G}cAf{",
        "IaI,s-6F",
        "BupsN",
        "OQ'`s",
        ".\\crypto\\evp\\p5_crpt2.c",
        "yyyy'-'MM'-'dd",
        "eUYYK",
        "7$8t8",
        "kyZN{I,",
        "yvJow",
        "0}#'Z7",
        "#bCi!",
        "pg'_|",
        ",]Pu.=g'",
        "TEARDOWN",
        "XxE^P",
        "ubAH]",
        "Oa0I'",
        "[N!2O&",
        " G07v5",
        "SOFTWARE\\Tiny Software\\Tiny Personal Firewall",
        "In install / upgrade case. Checking if FW component is installed on machine",
        "OLOrK",
        "whO'F",
        "NrN 4",
        "epam_svc.exe\" --uninstall",
        "zpbII",
        "t$XUh",
        "d^e/Q",
        "`Nq<=A",
        "7d8d9d:d;d<d=d>d?d",
        "5K6U6k6|6",
        "M9^)|",
        "7uysO",
        "d)+Yxl",
        "\"aLs$",
        "P((xP((x",
        "*bh+\\",
        "XyxLP",
        "djLUK(",
        "w!&$f$V",
        "2*U$R",
        "VSInstallerLogoffEx(%08x)",
        "PFCMPGT",
        "l85)Y",
        "$cB6/",
        "6KF&? 3",
        "[@*adG",
        "&NQ;R$",
        ">J?U?",
        "W\\o&g",
        "Jx$Hoq",
        "$zCp.",
        "40484P4\\4|4",
        "#;`;k",
        "<Dg\\Fk",
        "[f:w{?",
        "Y4j[S",
        "G&DSn",
        "5&3X+",
        "@z&A+",
        ";Ih^=",
        "failed to write file contents to rollback custom action data.",
        "CREATE_FAILURE",
        "y`POdGY",
        "aBt^q,",
        "+m:3T",
        "=4J6:s",
        "re)A)",
        "2:2U2t2",
        "z,u4~I",
        "4'a%]",
        "FT9~Xt0",
        "kU;hX",
        "3E=Xd2B",
        "{\\*\\xmlopen\\xmlns2{\\factoidname country-region}}North Korea{\\*\\xmlclose}, {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Iran{\\*\\xmlclose}, {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}Syria{\\*\\xmlclose}, }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "UfBBW",
        "0AS3Sc",
        "Ai8x7",
        ":C*&5",
        "+q1GJ",
        "`j'MA10",
        "q%-`[G",
        "EorRj",
        "\\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 GENERAL}{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787 ",
        "[>fgw",
        "7)Mau",
        "+1{NSt",
        "\"wNcmoD",
        "v`EkwZ",
        ".\\crypto\\evp\\e_camellia.c",
        "#dv1R5",
        "Bad file",
        "l;Xhmu",
        "Failed to connect to Windows Firewall",
        "xx*iX",
        "=8=Q=j=",
        "iRB%X",
        "tlsv1 alert decryption failed",
        "9V:c:",
        "eOpY}D",
        "{iLYc",
        "__p__commode",
        "{cRc\"",
        "G$sJsf",
        "g0CqbT",
        "izu4f",
        "@^-c.",
        "z=_Je",
        "#Urg*",
        "WRNB~",
        "X&=~zQ",
        "? ?'?9?=?D?S?n?t?",
        "Qn/kA",
        "X~]EY",
        "}COq5_",
        "?zX+s78",
        "CKr\\?",
        "L7TwB",
        "lpMr!",
        "/llV)",
        "@vzpip",
        "SxGbQ",
        "^^C8n8|",
        "Datacenter (core installation)",
        "\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 4;\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 4;\\lsdsemihidden0 \\lsdpriority70 \\lsdlocked0 Dark List Accent 4;",
        "41484D4N4",
        "5$5,545<5D5H5P5X5`5h5p5x5",
        "q5z;c",
        "CMOVA",
        "failed to add timeout data to CustomActionData",
        "cmFkv",
        "8\\8V7",
        "\"M%k}",
        "UETE(",
        "wl;niZ",
        "MD\"f+",
        ":;-;};",
        "#WK`j",
        "#%ru7:",
        "PSK-RC4-SHA",
        "8^(u-h",
        "AppDataFolder",
        ".IwT4",
        "[VSDATA] pHook->dwReady=%d, pHook->dwUseCnt=%d, g_AC_TerminationOnExecution=%d, pHook->dwMsgHead=%d, pHook->dwMsgTail=%d, pPendingMsgInfo=%p",
        "6Zsarmv",
        ")r=H{",
        "X509_NAME_ENTRY_set_object",
        "p#gx89",
        "~um{v",
        "\\A,KW",
        "a~&iM",
        "9\"9B9b9",
        "^vdvdv",
        "S(z-e",
        "JbQ=4",
        "BPm9=",
        "%Va6!\"%",
        "!#LdZ",
        "0'16165E5\\5",
        "ro'*|0-",
        "8 .a`",
        "MROBf3)G",
        "DEFINE %s %s",
        "RDPMC",
        "upw-_",
        "RoGG@",
        "f;F$t",
        "?+7MHt",
        "4=5H5T5",
        "kmdy-",
        "EJT~I",
        "3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t",
        "xz5@A",
        "*{w0x",
        "8'a:o",
        "+A(q$",
        "08`IF",
        ".a<Ecm",
        "BIO_get_port",
        "?1?E?S?",
        "j|.=W",
        "Y*>+_R",
        "Yhv3|",
        "{A[u-S",
        "<hp1V",
        "XZ'YE",
        "0-[&C;)",
        "l$PUVW",
        "M;zO_",
        "w4p0P",
        "m\\m}A",
        "I;GGH",
        "  CApath: %s",
        "\"u0v1",
        "?wM;~4",
        "invalid string position",
        "#83fbp",
        "5*6G0",
        "0.T/U&",
        "a  T\"s|lC]",
        "Ana!<S",
        "&Sv%i",
        "]%UqJ",
        "7/8;8",
        "=(=P=W=v=",
        "O.\\e5",
        "IoDMm",
        "9OV;.",
        "@).xl",
        "oNilt",
        "sX~%w",
        "boost::filesystem::is_empty",
        "?:?J?",
        "A2I\\A",
        "9a(AG'Pm",
        "g/maZ",
        "ZC<2R`)",
        "l]L cV^X",
        "3P#&65",
        "WJT.~",
        " of the warranty or that a warranty claim is made after the warranty period, the cost of the repair by Check Point, including all shipping e}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11029351\\charrsid15169477 xpenses, shall be reimbursed by }{",
        "7BJHw",
        "~5Z^Z\"",
        "6\"6W7",
        "2(20282@2H2P2\\2|2",
        "<&<O<V<",
        "JNWz+",
        "k+4%y",
        "O:4f>",
        "g'sYx",
        "7P4Nd",
        "9QAI}",
        " 0OssH",
        "5'?ku",
        "o*2MQ",
        "f9;t!",
        "TQ%:5",
        "x`Ctu",
        "$ qa>f",
        "7J9f:",
        "NXNYHyt",
        "~G'FcC",
        "tasIwf",
        "Configure vsconfig.xml to protect AM E1",
        "FYgFB",
        "#}&,M",
        "5mDW>",
        "_uGpA",
        "?|#>h",
        "&3KwD*",
        "oHO/C",
        "X%VhD",
        "ww$<(y",
        "6 6(6,686@6D6P6X6\\6h6p6t6",
        "createLocalCatalogXml",
        "C'2Fe",
        "(N;[Y",
        ",d0`}",
        "fX)J\"!",
        "0-*j9",
        "wKv'Ab",
        ">(>C>Q>]>i>}>",
        "imp3C",
        "Lrt]C",
        "WWa;4",
        ")! X)^",
        "o4>8-",
        " 0xb1",
        "t jnh",
        "c*1XF",
        ")qbcI",
        "invalid blocksize value in OACK packet",
        "s{rblo",
        "646<6T6\\6t6|6",
        "IIW5#",
        ".,r;6",
        "N))==",
        "fnoW1",
        "aes-192-cbc-hmac-sha1",
        ">XQKb",
        "t0jXXf",
        ";6;^;",
        "z_6*c",
        "$To(KQ",
        "FWUpgradeBefore.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "\\NvO\"2]",
        ".L~hn",
        "v9kC\\tE",
        "dO_\\T",
        "ydBn.[",
        "krb5 server bad ticket",
        ">,>4><>D>L>T>l>t>",
        "e=SVS",
        "CA7;^",
        "OCSP_request_sign",
        "@ZIpP",
        "TI))k4",
        "INFU?!}",
        "]I_,Z",
        "fJED2:u",
        "8,N.|",
        "0%0.0D0U1]4",
        "747T7\\7d7l7t7|7",
        ",EB#$",
        "DWpUd",
        "engine",
        "L$(UQVW",
        "j[hH:#",
        "`1r$F",
        "U:FY/",
        "UsB(nW",
        "LY{+s",
        "Gp`>a0",
        "-</r!",
        " /q /norestart\" ",
        "|ZWyaT",
        "CpSqt",
        "Transport:",
        "zl)OMf",
        "PHSUBW",
        "4`h`66",
        "VsDataInstHelperOpenDriver - DeviceIoControl(DIOC_PRODUCT_VERSION) version=%s.",
        "S]w9|u",
        "JqsCj",
        "flf1A",
        "cJVcS^",
        "4/4K4g4",
        "\\)jTV",
        "|!oPd",
        "c2pnb176v1",
        "[qXd;",
        "fGs,`",
        "3.cJd",
        "v[ c5",
        "pkcs7 sig parse error",
        "Dq@Xz",
        ")e'^oy2H",
        "T[$:.6",
        "\"*$2I",
        "cBL<|",
        "Dg!NQh",
        "*^0163",
        "7,7<7@7P7T7d7h7l7p7t7|7",
        "7S`qVH",
        ".?AVRules_XML@@",
        "oWgz,",
        "aD8enB",
        "l(qs8",
        "565g5",
        "GetUserNameA",
        "Found vsinit.dll",
        "FCLEX",
        "+*O/0J",
        "tJhxs&",
        "8?8N8v8}8",
        "r:[9)",
        ":):;:M:_:q:",
        "E`(bf",
        "BXLvpB",
        "|*&ov",
        "Hw4KO",
        "+B:+{",
        "tgh4s",
        "1\\MqN",
        "=QXiH",
        "NOTICE_SECTION",
        "D$\\Ph",
        "_TufJ",
        "vcrf r",
        "no)CueN{",
        "indirectCRL",
        "combase.dll",
        "<o6;1}",
        "jEYla",
        "G97T_cW",
        "Q5_J-]",
        "2:lzV",
        "ffffffffffff}g",
        ") Wu>",
        "organizationName",
        "T_A05",
        "&E<dA",
        "xT?Z?",
        "|?n7>+#o",
        "h*zex",
        "}File {} hash  {}",
        "3L$@3L$,1L$",
        "j\\}64",
        "Kn7=:",
        "v<c0n",
        "E>]X'",
        "?)O'|M",
        "fSAT=1='",
        "JDV,KE",
        "5S+\"=",
        "POyMH(",
        "SQj9zxY",
        "b9f%!",
        "w~r;!7",
        "~Yl/O",
        "eB6[R",
        "lfbM:",
        "nk0;P",
        "MOVAPS",
        ";wL~S",
        "mC%@*",
        "3i!O|k",
        "TC$UT",
        "e&GDY",
        "[0Jv<",
        "FtqAD",
        "UNUSED_6",
        "directory",
        "D2lf.",
        "6!616A6p617Q7",
        "1)]P>",
        "u0jhh<",
        "<z?dT",
        "_jK@c",
        "PyV'*",
        ")^>aH",
        "b@ThC",
        "K)lea",
        "Il_~8,",
        "FB=-m)_",
        "g8AP[<m",
        "wMPhx",
        "wrap error",
        "y; B;",
        "failed to write Don't Preserve Date indicator to custom action data",
        "3EZt*",
        "DCDSDc@s",
        "$0P'j",
        "TNR=s",
        "9%:,:3:::x:",
        "j'\"h%",
        ":E:T:f:u:",
        "l~Hoi",
        "IV block",
        "9D$$t",
        "^!?-?",
        "o@&=w",
        "KaG8:",
        "R0/ M",
        "Aus8B",
        "e!Hy8o.u",
        "E4MS;",
        "(iR!$",
        "^HI*(",
        "J0yL0K",
        "QWORD ",
        "j;0<:=",
        "7c=h)[",
        "PZYh,",
        "Wvwzc",
        "u=gi]",
        "kgz~o",
        "+5+vZ",
        "kS}cPn",
        "'7vWs",
        "organization",
        "4#}v3y?",
        "mv7Ok>",
        "P&T5d",
        "8~&xN5",
        "OBJ_create",
        "989B9T9v9",
        "|)J4&",
        "Dx9*`",
        "@-SiA`",
        "WixCloseApplications",
        "YG>-ZU",
        "5cLM)",
        "0\\YaWX",
        "oN _b",
        "S^Tpxww",
        "issuerAltName",
        "$ARQmo",
        "!GIpD?'",
        "QRPVh",
        "6s*Jf",
        "CLno/c",
        "|U$E9m",
        "[KFOuD;|r",
        "ASN1_INTEGER_to_BN",
        "}3[2z3_Uqf",
        "failed to register NP.",
        "xfH)bc=)",
        "VUTo=",
        "2{|T ",
        "D$`Ph",
        "c:sO}",
        "invalid code sequence",
        "0\\0n0",
        "r'nsd",
        "^lfVM",
        "YzIb|",
        "pbM1:t",
        "hgs1,",
        "ioUC'@",
        "trgui.exe",
        "qHj`[2",
        "u\"bmH",
        "J37$p",
        ";=*pV",
        "/S.F]",
        "^#v7I",
        "c:>Mtn",
        "&b~v3",
        "Jt<4b2",
        "Oh6xe",
        "/X.S^",
        "VWjDXj",
        "*xQ'(",
        "=;Kb9",
        "S`MSG",
        "1G1t1",
        "J'K#O",
        "yKI9PO",
        "zh-tw",
        "p[Rqh",
        "@hTv\\",
        "4$44484<4@4D4H4\\4`4d4|4",
        "282@2H2T2t2|2",
        "0&+q8",
        "dv9}2(",
        "{$pHt",
        "<{}vN",
        "g9.#B",
        "S\\GJU{",
        "failed trying to find existing app",
        "UI_dup_input_string",
        "boost::filesystem::status",
        "ZE[U]",
        "F`.V90",
        "F?.[I",
        "984X$",
        "+E%B1e",
        "Fh U|",
        "Q(7OQ",
        "\"ofPI",
        "\"/b&Z",
        "xa<3}Xvd",
        ",64%H",
        ")4-+8's",
        "CANT_SET_PRODUCT_MODE",
        ".?AV?$ThreadProxyFactory@VFreeThreadProxy@details@Concurrency@@@details@Concurrency@@",
        "json<",
        "eSoEL",
        "EVP_DecryptFinal_ex",
        "QHn:g",
        "@O__%F",
        "Up&RZ",
        "ho$g*",
        "r+X_`",
        "FSUBRP",
        "Hp7 &H",
        "9G9U9",
        "4]5b5n5{5",
        "9Y@YBYaY",
        "9sLBzY",
        ";V=c=",
        "ITQRBfnM",
        "r_f;M",
        "n\"[$&",
        "Generator (compressed):",
        "+HB]1",
        "9e;$S",
        "646c?~?",
        ",RfT67",
        ">$>,>4>@>`>h>p>x>",
        "4G4s4}4",
        " o+VYw",
        "MfzNe",
        ".>_Hu",
        "R$e:a",
        "I>Lq)",
        "RT'5(",
        ".3 20<",
        "Uq2B@F",
        "PASSWORD_NOT_CORRECT",
        "zE,x!",
        "I5Nsi^43",
        "\"eqprS9",
        ";~s/ @",
        "l<ow k",
        "xJ[Q~",
        "NtN}B",
        "I_#*I_fh*k?o#",
        "j+r%NMl",
        "yd>,.",
        " 0x95",
        "xHIR]^",
        "9J^ic",
        "HJ YI",
        "7'_C(",
        "y:%_S",
        "PS@mR:,",
        ".fjfRNH7",
        "151N1g1",
        "i!)?7?",
        "UI_dup_input_boolean",
        "H!=a<S",
        "Repair",
        "8%BO[4",
        "8094989<9T9X9h9l9p9x9",
        "^sFR^",
        "dl<@SW",
        "\\zonelabs\\vsmon.exe",
        "t,WW9}",
        "AKAPAYA_AcAeAjA",
        "Creating IUniformResourceLocatorW shortcut '%ls' target '%ls'",
        "vnnXx",
        "3z]K`",
        "mRS6f",
        "|;Vxd",
        "T-}8^?",
        "=x<fL",
        "A<6pj",
        "6#xw[",
        "tgk,uktN",
        "u9lQ\\/",
        "58AWh",
        "processes.xml",
        "CVTPI2PS",
        "d<lzQ6",
        "6XDej",
        "w\"f*5",
        "oUpU~",
        "7_^[]",
        "OxME%",
        "P'!<5",
        "H\\s.Q/",
        "'d+l?<",
        "=-24L",
        "_f\"C~",
        "\"S%S+",
        "]f4U}",
        "^yP+<U",
        "tk{l>",
        "system32\\drivers\\",
        "F:\\ckp\\src\\cpopenssl\\E86_20/preCMpub/lib/engines",
        "*XP!GADv",
        ";\\s@d/",
        "#0P`F",
        "657;7Y7",
        "1Zp>tC",
        "nka]1",
        "%PT R ",
        "C:AC&",
        "oOJDK",
        "3@byl\\",
        "yt]F@",
        "1:mR}v20",
        "RSA_CMS_DECRYPT",
        " y\"~Bo",
        "tqvNb#3",
        "2?<27jr,",
        "313:3b3",
        "0]0r0",
        ">&>B>^>z>",
        "#)Qkz",
        "nmKt@",
        "1D2N2[2",
        "$;i)1",
        "#nr0 ",
        "on#aLBqyd",
        "CJ'sQ",
        "*c-%!b",
        ")-1Ze",
        "|^rf']",
        "585D5L5",
        "`GK!F",
        "\\-\"|$b",
        "%<]lGh",
        "gVR&TJh",
        "shellexecca.cpp",
        "-.?8k",
        "RmEndSession",
        "|6I)J",
        "?9]-z^",
        "]~],bDMK",
        "*5RI#",
        "j9=s?",
        "pMj_)[",
        "$SJZq",
        "bnc)R",
        "=)=3>n>|>",
        "az-az-latn",
        "=U=u=",
        "?B6bS",
        "su@`N,",
        "r2+$I>",
        "Qi:PX",
        "!Ik^t",
        "oeL9q,",
        "DSA_PUB_ENCODE",
        "hmacWithSHA256",
        "s/j\\V",
        "485@5L5l5t5",
        "^w_MWa",
        "O=Z`q",
        "_50tZ",
        "m!0 @B`C",
        "-$n/Xe",
        "l$TPV",
        "SOCKS4%s request granted.",
        "[[CpPolArch=%s]]|[[STORAGE1=%s]]|[[cppsm_tool=%scppsm_tool.exe]]|[[SUPPORTDIR=%s]]|",
        "9&Bi_W",
        "[LS3??MP3",
        "J_:n4",
        "Got unexpected imap-server response",
        "i\\H`O",
        "CMS_GET0_CERTIFICATE_CHOICES",
        "ZzaCu",
        "6&757z9",
        "3_~%vh",
        "P5zFTr",
        "V%^%d%l%",
        "!{9&s",
        "<mRW[i",
        "6#7(7f7q7",
        "m7|6&sB3",
        "FeatureVPN _MaintAfter",
        "#-~awb",
        "OX)j$_",
        " u\"9~",
        "<8.u9@;",
        "CAMELLIA-192-ECB",
        "|~'}|",
        "c'6hS",
        "@?UAN",
        ")IW3q",
        "'32GK",
        "inRPw",
        "unsupported cipher type",
        ".$Ml1",
        "udc(q",
        "Y)P%r",
        "KPuX^",
        "@ObLXqq",
        "su6qL",
        "#:*s,",
        "h$|IiF",
        "I:yT)6",
        ":t{i`",
        " LhUl",
        "2LtLw{x",
        "C=VhL%&(",
        "jzfqq",
        "p2|/8",
        ")x^r*",
        "f5><>i",
        "@ ydr",
        "Lp#mN",
        "^C8~)",
        "3T$H3T$83T$$",
        "J>\"M`",
        "Load certs from files in a directory",
        "Ni297j6.",
        "3T$83T$03T$",
        "5 5$5(5,5054585<5@5D5H5L5P5T5X5\\5`5d5h5",
        "6%626>6F6N6Z6",
        "e?VH?",
        "g%`Ez",
        "2&353",
        "3%LIq3",
        "Yp+7%",
        "CxbUu",
        "0+x.V.",
        "D)>+x5",
        "TMd<pR",
        "k?nm>",
        "4Gk5P",
        "@vd3i",
        "323C3",
        "~ .EgEP&",
        "alu\"w)",
        "-@1AI(",
        "$v+94",
        "292P2_2m2s2",
        "0dfb5393d964f9cc9bad5c313709ea70f561ed3ea7b053075221d51696910d0d339585004b34272bff7213cc7a510a5454a3b349b1b206c1f0af490176745d4b",
        " gTv;r",
        "0giZh",
        "tQ?b;",
        "kG*{9w",
        "<\"wqOa",
        "}.S<V",
        ".TXYp",
        "IMsProvider.dll",
        "do7!9y",
        "oL-g<",
        "L7iq1",
        "3a^EX*",
        "8a9m9",
        "=L7?K",
        "KLR`K,",
        ";F]IIp",
        "epam_svc.exe",
        "$MPZ1",
        "O8Ew2",
        "Y'=?{",
        "DHE-RSA-AES256-SHA",
        "SetConsoleCtrlHandler",
        "\"H$pH",
        "I0e0~0",
        "nE5R'",
        "m)7 0 *0",
        "V7z=H\"!u",
        "|.Rj]z",
        "P'aZKG",
        "1f_+j",
        "s,*tF",
        "6,T?,",
        ".\\crypto\\dh\\dh_ameth.c",
        "KIc]C",
        "JLy&f",
        "5#G|d",
        "x)1!w",
        "DigitalSignature",
        "OnMaintBefore",
        "Global\\ZL_INSTALLER_RUNNING",
        "startTag != endTag",
        "D$,PSU",
        " yJ?n",
        "#}3,Z",
        "missing private key",
        "`8MOa",
        "urH~.",
        "@}!CJ",
        "RaGFJ_",
        "sMTi5",
        ":,~&u",
        "id-aca-group",
        ")D*V5X",
        "KrN P0",
        "c>&Biu`",
        "TODO-%x",
        "o*<b5",
        "=#q5qKN",
        "fg%kx]",
        "<w=t>",
        "|`[(d",
        "d.>c]",
        "1CZg0F",
        "MSVCRTD.dll",
        "\"Q=CL",
        "X*(YL%",
        "eQkih@",
        "8=5wq",
        "}VWj=S",
        "`fPw.",
        "2!21272A2Q2[2`2q2w2|2",
        "~cH{ ",
        "Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0",
        "1d[O~",
        "az-AZ-Latn",
        "n<:j*",
        "Lnuh)Z",
        "FTP response timeout",
        "%%%02X",
        "0#0C0",
        "n?D2?",
        "+\\uBNs",
        "<c=\">",
        "S@k|f",
        "Ad+p<+r",
        "ARz&,",
        "FeatureAntiVirus: Noting to do. AV is not getting installed",
        "Zjfm+",
        "4PiPb",
        "B%L1(l",
        "N3qC|5",
        "+8M.(#",
        "T^HS.",
        "fI@#Y' ",
        "-]Z~, ",
        "C8=i')",
        "DES(40)",
        "YyH|c",
        "K}yx?",
        "#!^L'U",
        "`2+IB)\"G",
        "I)ILa\\",
        ">T>t>",
        "939?9",
        "]1>Q=$",
        "7]:@#",
        "j{juj!",
        "Rcxi'",
        "eE_Et",
        ";OSsk",
        "ECDSA_do_verify",
        "6E6r6",
        "5q}S2",
        "#iv73Rh6",
        "CONS_IMSEC_INSTALLED",
        "])O|wHW",
        "\\yW3}B",
        "sb;3u",
        "EXPERTXML",
        "v+0&+8>z",
        "\\(E=f",
        ";ZW0YJ8",
        "id-ID",
        "B|Nk-q",
        "DPujU",
        "<#=S=l=q=w=",
        "727k7",
        "MmH&8",
        "/J/|B",
        "e2k7i$",
        "+VF;r",
        ";r#1O",
        "V!+Cz",
        "hzC!U",
        "aR)]v",
        "xg`k:",
        "Q~OLR",
        "set INSTALLDIR to %s",
        "%s://%s%s%s:%hu%s%s%s",
        "SOFTWARE\\KasperskyLab\\InstalledProducts\\Kaspersky Anti-Hacker",
        "bA&y7",
        "N<PV6l",
        "U&RPQ",
        "n1l)nI",
        "0u{nDb2;",
        ";!<2<",
        "{LI\\d%",
        "#DLmv",
        "pG*#X",
        "TruncateLog() failed.  Clearing log file, ",
        "uKyLP",
        "=\\0Lb",
        "NTLM handshake failure (internal error)",
        "ABCDEFGHIJKLMNOPQRSTUVWXYZ",
        "Wov<8",
        "0Q1g1",
        "UKM#SK7BW",
        "KXO@WjqP",
        "i-vTw",
        "qD;-6",
        "5=5c5",
        "Dk%_M",
        "WZ]m|",
        "Z6#be\"&",
        "GlobalFindAtomA",
        "l1@x6",
        "cm?Ag",
        "QQLI3",
        "3C.A;",
        "3Gl3W|",
        "create_directories",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<wchar_t[1],class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t [1]>>(const wchar_t (&)[1],class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t [1]>)",
        "j\\%@o",
        "d|`/k",
        ":QtN r",
        "P>TGY",
        "778D8",
        "rmS3R6",
        "1?}}N",
        "SWt@jU",
        "8A8n8",
        ";k;t;",
        "q3Cu'",
        "ZmTEUhK",
        "7xT:?<",
        ";A;X;x;",
        "t*SRV",
        "com.5",
        "m{e*-",
        "l$ 9M",
        "`,@a$",
        "l <= sizeof(iv)",
        "H:J~k!JV5",
        "Z5~Rd2",
        "{b1r ",
        "22E^;-po",
        "4\"4C4J4U4l4s4~4",
        "@{]3G",
        "J7s@;",
        "e-8MY",
        "CGQ%F",
        ".,Csx",
        "\">,7l",
        "u\"tHDI",
        "180620000000Z",
        "^SD51",
        "Ln!W7",
        "'j|,w)",
        "%s (%s), %s, %s (%d):",
        "&!n;:",
        "<*=j=",
        "33#@4M",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa40\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Affiliate\\'94}{\\rtlch\\fcs1 \\af1 ",
        "v#kM+",
        "Kc4/{",
        "j)qwiJ\\d",
        "00d9M",
        "KKH9+",
        "7#8/8=8R8d8y8",
        ";*<9<}<",
        "Z}\"6m",
        "Nd(|0",
        "X:Y[M",
        "wf93t",
        "FjRrqoL",
        ".4-<(",
        "7a1Ci",
        "ufiID-",
        "P-521",
        "S-%lu-",
        "3S4P5",
        "?\"?@?b?",
        "l*N1x",
        "MzhyM",
        "NFY|Qf",
        "?>#KD;",
        "azz!L",
        ">(>,>4>L>\\>`>p>t>x>",
        "0L0a1",
        "u*H-v",
        "C,sp]",
        "8#^n-",
        "r3+5bYJ",
        "<tCMW",
        "Xnvrnh ",
        "DNC,5",
        "W3hk'",
        "GOgmY+:",
        "W}F)^",
        "<,<4<@<`<h<t<",
        "*\"=|0u",
        "0pM*K",
        "(DG_uD",
        "A\\pr2",
        "\"ZF\\)HG",
        "#J}_!W",
        "qask0]",
        "7Y*O+",
        "1F.r<",
        "keyAttr",
        "D$ _^",
        "E]fEy",
        "C75Xx",
        "wT_UH",
        "5#687",
        "1A1_1",
        "||iW=tYk)*",
        "/d[,y",
        "uF<a<,m+I",
        "Sb33E4",
        ")$Nax",
        "w9Ug<",
        "&DrkL:",
        "LXbXZX",
        "KV=/;",
        "failed to get component name for XmlFile: %ls",
        "Jl%ZM",
        "[%Ulr",
        "? ?(?0?8?@?H?P?X?`?h?p?x?",
        "aFi=q",
        "HN4=v[",
        "Telemetry was sent successfully.",
        "AZF2t",
        "{\\fbiminor\\f31584\\fbidi \\fswiss\\fcharset178\\fprq2 Arial (Arabic);}{\\fbiminor\\f31585\\fbidi \\fswiss\\fcharset186\\fprq2 Arial Baltic;}{\\fbiminor\\f31586\\fbidi \\fswiss\\fcharset163\\fprq2 Arial (Vietnamese);}}{\\colortbl;\\red0\\green0\\blue0;\\red0\\green0\\blue255;",
        ">8<4ni1",
        "j9yiw",
        "j0tLYZ6",
        "?@?L?g?",
        ":}~k)?y|",
        "x\\y<^",
        "}PEw=O",
        "o3\\Ep",
        ":8(uQ;",
        "<q]q|*",
        "`(90c",
        "9jmN;iL",
        "4*4\\h",
        "6b6i6",
        "{^NUP",
        "Iqrt[",
        "%E D(",
        "}iY8v",
        "\\|kU_hg)",
        "buildingName",
        "T@avP",
        "F%P4P",
        "jjjoj",
        "new file and current file are from the same version",
        "R.&.M",
        "NEW_POLICY_PATH.DAFDA02E_B73A_474F_90D3_CDE1B018E52B",
        "BIO_write",
        ".a_6E",
        ")zq{d_",
        "L$d_[",
        "80888D8d8l8x8",
        "1qLgb",
        "/z*CtZ",
        "646M6f6",
        "3T$T3T$43T$,",
        "I:bIK",
        "True Vector",
        "}M5{=",
        "0zul^",
        "D$ SV",
        "_ZSp{",
        "Pu\\\\m\\",
        "nHA ll",
        "=F?W?",
        "868A8h8q8",
        "L$(3G",
        "0f1w2",
        ">RE8~v",
        "?.?5?A?K?",
        "5<PbV",
        ".?AV?$output_string_adapter@DV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@detail@nlohmann@@",
        "Successful install of %s (version %s) finished at %s. ",
        "(0-0u0",
        "K0oIq",
        "162H2",
        "lPX'$",
        "Failed to install catalog file %s",
        "k:syv",
        "KF7O*T[",
        "m+<LtI",
        "El|;wh?",
        "kL1.:",
        ";l/?(M",
        "KaJo>",
        "4p4t4x4|4",
        "0v$B:",
        "0E0T0f0y0",
        "ja{mn",
        "5&Ky6k[",
        "rR44iXv&",
        "n]$ah7g",
        ": k8C",
        "\\ltrch\\fcs0 \\f1\\fs20\\insrsid7743908 upon}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7743908\\charrsid15169477  }{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid9252096\\charrsid15169477 Check Point\\rquote ",
        ";9%ha",
        "{,*G(L+",
        "'S>)(",
        "]T:wmZ",
        "D.22Z%4",
        "CML+#V[-",
        "Ut]<E",
        "c,<?Q",
        "VmIv`",
        ".mjhl",
        "2.2:2Q2o2}2",
        "#E(Fj|wF",
        "G<:.'",
        "TS_CHECK_IMPRINTS",
        ">!?(?",
        "_87]>",
        "HKB.$",
        ";#I^v",
        "1\"1/1",
        "kCp||",
        "*O&H)",
        "UbjGu\\",
        "d{T2Th",
        "6$7<7",
        "- CRT not initialized",
        ":d#Fa",
        "w5C\\Z",
        "@g \\4^",
        "O:ot:,R",
        "~}#I/~l",
        "P@{>/X",
        ".?AV_Facet_base@std@@",
        "watchdog_xml.13280B40_9130_4E2F_97CC_FF2D9A5C57F4",
        ")C@u5k",
        "ms-BN",
        "*6NeB'_",
        "!WXY3/ ?",
        ";Q$`&a}",
        "missing tmp rsa key",
        "7H7p7",
        "^SSSSS",
        ")a*<'",
        "jljnj%",
        "o*+!(2+",
        "82K_\"",
        "2[R9f_",
        "\\ZoneLabs\\appinfo.kli",
        "enE#W",
        "wF&tz",
        "Mz[Sv4",
        "_DEKx",
        ",Ap^N",
        "WPQh|S!",
        "<pwZt",
        "lg,o#oA",
        "aTQ/'",
        "_+kp}<",
        "2p ]>",
        ":4:P:l:",
        "sXiD=y",
        "E*'Og",
        "q;2Cww",
        "df0B6",
        "GetTokenInformation",
        "\\<\\<n",
        "zmrCM",
        "tb;9i`",
        "s1HNwt",
        "zPLP9",
        "dT}PU",
        ")%v.!^",
        ".I3Q ",
        "V/&iG",
        "Ya#tB",
        "}H:h:V&",
        "YR[bR",
        "&OKi0",
        "a;:HK",
        ">1>I>",
        "1~~gn&",
        "uerfu",
        "Plugins::Unregister:  Unregistration successful.",
        "8'8I8V8v8",
        "Ex[Io05c[",
        "h(1#E",
        "FEN(#p",
        "@TkfFa_",
        "<?<k<r<x<Y>",
        "[K|eh",
        "<5Y1<",
        "?)?1?R?",
        "f -Hq",
        "|&I3`",
        ":xWB|",
        "unable to load ssl3 md5 routines",
        "h!(Se",
        "V2TN<",
        "Aw d^",
        "<7<R<",
        "d$HHJ",
        "sK \"da",
        "}<}M_PF",
        "L/c:O",
        "QEg[d",
        "'mKEb",
        "^sm2]l",
        "&B~~&",
        "k|+V?",
        "%y{j,",
        "failed to read shortcut path from custom action data",
        "VWh(u",
        "invalid trinomial basis",
        "2!3N3",
        "8V:h:",
        "%d, %d",
        "|h+mJ",
        ">A?y?",
        "-4-,|",
        "_y`C[+",
        "|:8)Fo",
        "^T.I%",
        "Z^Y\\'oX34O",
        "log10",
        "9\"9?9P9e9j9",
        "YQYRYq",
        "$oh|J",
        "WN;w+_`",
        "/<rl>",
        "+`WnW\\V",
        "BTxA/]",
        "'OO+%L",
        "343@3`3h3p3|3",
        "I5fA2",
        "Kr[V\"\\ K",
        ";2<V<a<z<",
        ";9;@;G;N;Y;g;n;u;",
        ">)fd.",
        "XqX`_dU",
        "z&`UL",
        "hijkTl",
        "MASKMOVQ",
        "&<g=i",
        "7t;x;|;",
        "\";sb`",
        "{zllp:V",
        "E!Wsgh`",
        "^d6.w",
        "KCZbj>",
        "mBh#P",
        "LVYq:",
        "%d/%d/%d %02d:%02d:%02d",
        "SetFileAttributesA",
        "c\"z ,",
        ";JkY!",
        "5/16sf",
        "<-CAY'tQ]",
        ":mA2nc",
        "[%s] MessageBox lpText=<%S> lpCaption=<%S>",
        "PINSRQ",
        "s\\P$/>",
        " 0xd4",
        "8MY$HL%",
        "PAn%;",
        "dhmAk;",
        "gJfcMc",
        "%a!KX",
        "|$8SWS",
        "e@eQN<",
        ",|5RU|",
        "3 3D3d3l3t3|3",
        "!J;Om",
        "CANT_UNINSTALL_OLD",
        "Ph g#",
        "@&Y[A",
        "75+|BP",
        "LJ'=v",
        "G+86j",
        "H'~8~",
        "i*@2c",
        "CryptMsgGetParam",
        "&UywR",
        "$RPkq",
        "?Uz>N",
        "MWeXC#q",
        "8&8T8`8h8~8",
        "szMsiPath",
        "SJecX",
        "{`.Wb",
        " fO{!",
        ";=Ze2",
        "fj82j5UDW#",
        "8M990",
        "FYL2XP1",
        "l2BTD",
        "1#INF",
        "8G{l1h",
        "su.1c",
        "no parameters set",
        "SEC_E_QOP_NOT_SUPPORTED",
        ".j(ao2",
        "898T8s8",
        "f>-F%",
        "+?:aV",
        ">7M<\\",
        "DSh#M",
        "/E3K5",
        "0$0,040<0D0L0X0|0",
        "G$e!~}",
        "TBf4TA",
        "u[7`-",
        "74%n)",
        "4;`HS",
        " KM%AW",
        "?I^Kx",
        "AM_INSTALLED_SERVICE.CAA4AB4B_AF5A_45B5_AB9C_E8526E8F11D5",
        "}y.&~",
        "nCi<Qx@",
        "INSTALLDIR",
        "T^H0<",
        "Or2v)8",
        "fAc4*<^",
        "2*3H3%4]4",
        "2[2f2r2|2",
        "DH Public-Key",
        "/o.,?",
        "cofactor",
        "OoZ1:",
        " ^,+$",
        "E-^%A^",
        ">=?e?",
        "[Ke[D",
        ".e7F3h",
        "?:?z?",
        "^:-}-A-Q.",
        "<&<;<U<j<",
        "b\"px}",
        "K>n\"%",
        "747K7b7v7",
        "3\"5C5]5",
        "\"|I?(/",
        "failed to get service name for secure object: %ls",
        "#y6Dl| ",
        "MULPD",
        "v!|,s",
        "SHOW_CLIENT_SUBTYPE_DLG",
        "RNu@DH",
        "K];TD",
        "Gx5l/i",
        "^S7AD",
        "G_&ql",
        "}.p7`",
        "2C3l3",
        "eu=kR .",
        "cOjB(",
        "Can't find procedure VSBanProtectionEx in vsutil.",
        "Shell",
        "G.!M R",
        "EVP_PKEY_new",
        "INT_ENGINE_CONFIGURE",
        "CMS_OriginatorInfo",
        "\\SQOB",
        "N9#HGz",
        "YB.87N^",
        ";$;);.;>;C;H;X;];b;r;w;|;",
        "3>3D3N3q3",
        "pPwnL",
        "SSL3_ADD_CERT_TO_BUF",
        ":*;W<",
        "I')&y",
        "PjIIsW",
        "3L$41",
        "4)4E4a4}4",
        "\".Jzd",
        "x}~y}",
        "[3>=&5",
        "UT.n)-",
        "7j`6/",
        "t/xV,",
        "thisUpdate",
        "unknown tag",
        "@I;Cey",
        "vvebz",
        "87RzPu",
        "<J)<F",
        "MD5 part of OpenSSL 1.0.2h  3 May 2016",
        "2#\"6R]",
        "1ct (q",
        "h8Cbwyz",
        "A<Olg",
        "@Dw1[E",
        "Wow64EnableWow64FsRedirection",
        "8f/PO",
        "CGpQO",
        "Binary ID cannot be null",
        "0_9L;P;T;X;\\;`;d;h;",
        "INSTALLDIR.F1785FCD_C1D1_49EF_9CCD_CBF3C9E22D1D",
        "5 5+5",
        "udY ]",
        "?1k{u]D;",
        "invalidityDate",
        "^[9un",
        "*{q4w",
        "T?mSU",
        "yGXW>",
        "+(]/%",
        "zu.D+",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\3CEF7BE31A8A3AE4F8E4A8D671289E7F",
        "[Uninstall]VSTerminateTVService/TerminateProcess failed (2)",
        " v\"w}",
        ".;XEZ",
        "eo>v<",
        "GF0I/",
        "NkdO!",
        "Y~$B)",
        "VoEkig",
        "v):?EV",
        ">.k5/",
        "|p#C_",
        ")Y|]\\",
        "$:I9R'",
        "B^^[[",
        "?8cPS",
        "rfHR$",
        "Z<Q\\0N",
        "7?7T7x7",
        "j Pj Ph",
        "SECG curve over a 112 bit prime field",
        "6m*p8i/lJ",
        "<$<4<8<H<L<X<h<x<|<",
        "wVmd5",
        "Y%7)!",
        "%hZ2V",
        "bjW A",
        ".\\ssl\\s3_pkt.c",
        "Failure sending EPRT command: %s",
        "Zf|Y1",
        "F):[U",
        "ts[\"[",
        "0!0,070B0M0U0\\0c0j0t0",
        "Key: %s",
        "p=OTp",
        "Wr'dB",
        "t:<.t",
        "7_7|7",
        "is[*RLEP",
        "~b:azZ",
        "]BaO}",
        "DSO_convert_filename",
        "657[7}7",
        "9d\\Xo",
        "W\\wk.",
        "{KI{m",
        "^:FO^S$",
        "{^m'A",
        "(e'mzf'",
        "t$(WW",
        "4Fq*l",
        "KlYX}",
        "kEJA^",
        "37Fz.",
        "8#*,#*,1",
        "nJbF[S",
        "=;=R=c=q=v=",
        "STREAM_ERROR_EXECUTE",
        "SC=Q`",
        "pb:+F",
        " >[agx~",
        "id-smime-ct-publishCert",
        "9:9E9N9U9q9",
        "run length compression",
        "illegal options on item template",
        "\"~Wv0",
        "@Q%gK",
        "6!;sd(",
        "8M9w9",
        "Module Name=dtis",
        "CheckPoint Secure Client is not installed",
        "|oeQ]",
        "0e;BRn",
        "e[i]r",
        "9AwQu",
        "T{D7:",
        "7c|uy",
        "%P;rj*^",
        "network reset",
        "The deletion of the certificate failed %d.",
        "MW4Q9",
        "N^V97",
        "LookupPrivilegeValue error: %u",
        "[4K& ",
        "jijnj",
        "?6?R?n?",
        "Y*4}b9uN)",
        "FIDIV",
        "{@n#0",
        "CuPtT",
        "0Pp{i",
        ";4<e<r<",
        "K$69zrH",
        "<Iev/",
        ";GiZ_",
        "j\\g[r",
        "*,k6:E",
        "b4'!1&2",
        "^4A._",
        "(`xMC.=",
        "_rxA!",
        "oM$2(",
        "T5{co`",
        "!dar!",
        "!*SC~",
        "QueryServiceStatusEx",
        "t$N'c",
        "8%9N9",
        "0P[QB_",
        "4/4N4b4",
        "4q/LYt",
        "mC;|C",
        "#0<0I0l0y0",
        "X~+T-",
        "bGz'u",
        ">W>-?",
        "o@%C<",
        "WPh@~&",
        "878e8",
        ":&rR{",
        "RemovePRHelperReg started",
        "hN`UM",
        "NZK($bn",
        "`mKoS",
        "Ys`/!",
        "failed to write additional changes value to custom action data",
        "V.Kmt",
        "j\"@acY5",
        "LpfJ#`%",
        "<56La]",
        "M~N\\E_",
        "K5xiR",
        "08:)3",
        "gJKy9)",
        "8 8(8h8l8p8",
        "tn-za",
        "zs26P",
        "SOCKS5 read error occurred",
        "<$hpR",
        "nTk+||l",
        "Ke$_x",
        "<&=S=|=",
        "\\zonelabs\\qrbase.dll",
        "tfg8Z",
        "2Pyu)",
        "id-smime-aa-ets-commitmentType",
        "w9P!2$",
        "VwzMh",
        "Pq<9bNg5",
        "}vXvZvjv",
        "dD4*~9",
        "fa2IH",
        "TryAcquireSRWLockExclusive",
        "= =_=",
        "L>4\"C1",
        "CEXEWv",
        "@cPQW",
        "Vj<zD",
        "r6Xkk",
        "`4vf`cU",
        "v6p5A",
        " %s%lu (%s0x%lx)",
        "1Fa'4",
        "9-9r9#:x:",
        "SRTP_AES128_CM_SHA1_80",
        "0!0&060;0@0P0U0Z0j0o0t0",
        "[QZ>p",
        "],uaX3",
        "?[)\\YO",
        "hCKq-5",
        "bL/.zj",
        "l$(V3",
        "3L$D3D$H",
        "7BGEj!",
        "l1k7b",
        "Peer haven't sent GOST certificate, required for selected ciphersuite",
        "9/:T:g:",
        "yy'Mv",
        "i%3ju yC",
        "V'/_:",
        "(cd,J&",
        "Qfw3\\",
        "5Tcq^",
        "]),:I",
        "|9oYy",
        "`4CRO",
        "vW)lp",
        "0qTij",
        "8&858W8\\8{8",
        "<cE~=",
        ">->H>T>^>",
        "#Y}Na",
        "fb-Z\"",
        "6JN_a",
        "4NXM_@",
        "7\">(>.>4>:>@>F>L>u>|>",
        "{ qHk",
        "Eud%g",
        "V,HT?TP",
        "V>ZJEn",
        "1K0(b",
        "****************************** OnBegin ended **********************************",
        "+&/MF`",
        "BL_nk",
        "]pOt1",
        "rvy^P{{q",
        "{V50]",
        "]U]d]o.",
        "d'5Xb",
        "$h%Cz",
        ":6<F<",
        "Sy|@c",
        "%>z%>",
        "f4N26~",
        "7k>42",
        "CA Compromise",
        "=\"I, z",
        "\\vsutil.dll",
        "1 2_2q2",
        "^g4>c",
        "T[;L'",
        "<G,|{",
        "spanish-el salvador",
        "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffffffffffffffffffff0000000000000000000000000000000000000000000000000000",
        ".?AUmessages_base@std@@",
        "~[m|r",
        ",l,,,,?,X",
        "Agnitum Outpost Firewall Pro 2.1",
        "K)PlM",
        "}LGmo8]",
        "zldwbK",
        "^a{TS!Dfr`",
        "\\JNxT",
        "X>cZT",
        "Stop pending",
        "dingo_upgrade_mode",
        "x8%mv",
        "6*707U7[7u7{7",
        "G7K`d",
        "?YWJC",
        "PEM_WRITE_PRIVATEKEY",
        "JH,mH",
        "Z_f6Hg*",
        "\\mEf12",
        "&#32;",
        "CANT_OPEN_FILE_MAP",
        "*|Fs!",
        "pKZ-M",
        "4_<xa",
        "Ke!(tr",
        "jijhj",
        "w<Amr",
        "xrJ:DCG",
        "=f?x?",
        "|$=ht",
        "F$|mW",
        ".gcyQ3",
        "\"<Zcr",
        "olFYH",
        "Z9G J",
        "4>L,L$yd",
        "nlt^rQ",
        "N?C-w",
        "Uo;5k",
        "KrAO6T",
        "oADE>/",
        "ych.CQ",
        "/F+k&N",
        "e9qZ?2$",
        "mCjhX5",
        "7~-r0",
        "sH^0Wzc",
        "-EY4\"P",
        "-s/>/8Y",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid344604 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 8.2 }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "@KKVQ",
        "Y$2!(",
        "#U)3;",
        "}=6Ql<",
        "Ou{BGGC!",
        "2}xx\"",
        "raYMs",
        "p@0pqE5tsO?|1",
        "Start",
        "93Byt3",
        "Bn(L/$",
        "9k[XE{",
        "]^)u4",
        "'0$\"ek]",
        "pBuU2",
        "F*/R9",
        "fdRy9",
        "q8a+l",
        ";zW1J",
        "2/2E2J2O2m2",
        "$Sw}o^7",
        "m*u*}*^(j",
        "^}`7U",
        "Oi/w=",
        "xzzu;",
        "r$aak",
        "%,A!1g",
        "ZjI_)m%",
        "`5VR+",
        "teletexTerminalIdentifier",
        "forward",
        "Ao#dC",
        " e_?e",
        "PMINSD",
        "~+Y]Z",
        "F+<E\"y",
        "qjl})t",
        "IM_SECURE_DEBUG",
        "failed to open Registry table to secure object",
        "QU*19",
        "%M;(W",
        "cgz\"\\",
        "ShellExecuteExA",
        "VMWRITE",
        "1F9zV",
        "onlyAA",
        "grp!V",
        "jkjkj",
        "d:\\BCZ",
        "Xeb9R",
        "KoWfG/",
        "a;@.{!",
        "      ",
        "qZ~{6A",
        "Y?]N&",
        "****************************** UnloadGUI ended **********************************",
        "\"!:5&",
        "MCXkX",
        "{hfCY",
        "5D46*s",
        "VapDL",
        "0/1c1",
        "Jf\\[5",
        "oW%~-",
        "Written %I64u bytes, %I64u bytes are left for transfer",
        "Extracted Secure Client GUID: %s",
        "+3x?I",
        "P0#RK",
        "F@Kp'",
        ">X;hrp",
        "u)9L$,u#J",
        "^$xpZA",
        ".\\crypto\\cms\\cms_kari.c",
        "z{SIwy,",
        ">0>O>h>",
        ";!;W;h;r;};",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 \\b\\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 \\'93Managed Service Provider\\'94}{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        ":C:V:m:",
        "HCQ$X;",
        "!+Z3P",
        "\"eyBa",
        "I0G08",
        "?vF\\R2",
        "_S7B3",
        "XkVxA",
        "invalid codepoint, stray low surrogate",
        "g:y|G",
        "~)@GL",
        "Ba }1",
        "XZQUS",
        "7&7B7^7z7",
        "Oj16<u",
        "SEC_E_ALGORITHM_MISMATCH",
        "PSLLW",
        "9~8~Q",
        "[%={A6",
        "e]rge",
        "22!\"S",
        "f/h]M",
        "Qle{y",
        "5wpY<",
        "8u?<O",
        "v*l{?",
        "gHb11",
        "X]Y9f2^1",
        "WB<2GO",
        "nPxCT",
        "4)4=4Q4e4y4",
        "NCONF_load_bio",
        "eH\"VM",
        "X\"\"6QX",
        "Extension",
        "S&|Y@",
        "[|ibk",
        "4VndY",
        "Couldn't parse CURLOPT_RESOLVE removal entry '%s'!",
        "cT2\\)9YN",
        "GJ{ `",
        "d{@`s",
        "UQx).qJ",
        "\\{?>_",
        "ReplaceFileA",
        "aTAi9",
        "^[}m{",
        "3e5fd",
        "5BGqo",
        "h6M/2",
        "4N4G8f8l8v8}8",
        "=c9F=",
        ":-5Tm",
        "B%qD^",
        "e.pC?",
        "x8SVW",
        "1?2L2Y2p2u2",
        "hc1$A",
        "w[~us",
        "i3;yC",
        "PKCS12_item_i2d_encrypt",
        "FQ8So",
        ";G QZI",
        "jejdj+",
        ";';V;h;",
        "'J{KJ",
        "#(3qR",
        "jc_'7UZ",
        "o\\H<:",
        "SC_DEBUG",
        "/'Sl)#*~",
        "YXdP+",
        "C4sYkH",
        "F:\\ckp\\src\\cpopenssl\\E86_20/preCMpub/ssl/certs",
        "04*AR",
        "~e7PO",
        "35=ad~",
        "PENDING_MSG",
        "WD_SignalStartServices ended.",
        "0G$\"G",
        "{cTzwE*",
        "< t1<",
        "3\"363F3V3f3v3",
        ";in^t5",
        "va?ye",
        "9D$8s%h",
        "Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.",
        "WSC\\Yb",
        "{J_tE",
        "&5bg%Q",
        "OS_FIREWALL",
        "nV*Y?",
        "Qg uJ",
        "document",
        "eD/]m1",
        "ucrtbase.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "Udm>XC",
        "#'0QD",
        "WxF^@",
        "]Yv%Kg",
        "av'mP",
        "mK9A!n",
        "$Q!)!\\",
        "fJwVE",
        "h7x%A`",
        "LdrLoadDll",
        "hmNN=<",
        "InstHelper is not running, will not be able to stop URLF service (gwcc)",
        "w!wQw",
        ",!\\b\\R\\r",
        "1@1Q1f1y1",
        "Jo_XV_",
        "aes-256-cbc-hmac-sha256",
        "Free: %I64d bytes",
        "u*jnh<",
        "lkHcf<9",
        "9rjJ^\\*^E",
        "0 00040H0\\0`0p0t0",
        "PBE-MD5-RC2-64",
        "030>0C0c0",
        "\\f1\\fs20\\insrsid7565078\\charrsid15169477 . You acknowledge that}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid12926876  in order}{\\rtlch\\fcs1 \\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid7565078\\charrsid15169477 ",
        ">{5%]",
        "application/pkcs7-signature",
        "Hy#EN",
        "7H4#\\",
        "\\$ Vh",
        "8w!qg",
        "+L_m$",
        "+yg+.",
        "( yHu?",
        "0Ae|:",
        "!jmdC",
        "path length constraint exceeded",
        "bLl$)pfA",
        "PCMPESTRM",
        "hzzPe",
        "5h:O6",
        "Location:",
        "PI2FW",
        "d%S/!",
        "[?f8>h",
        "bKk[C",
        "\\zonelabs\\av.dll",
        "!)F`A",
        "Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{D0DCD54F-C829-41A5-AF32-71E632BB0E2C}",
        "Failed to set the new PATH",
        "v)vpp",
        "w~D~'",
        "o47<7 7$7",
        "aUuG>",
        "\"%s\" -u",
        "~2s$~",
        ":.:D:R:a:u:",
        "WzGMK",
        "^O~Gqc",
        "KVf8n",
        "ipwval",
        "6f6x6",
        "|E$yA",
        "/A<jJ[zl",
        "vN-:7",
        "w?[x^m~;",
        "f6Fz*",
        "Ly2r}",
        ">+>@>J>",
        "=0=<=D=L=",
        "QueryContextAttributes",
        "2uG!J",
        "2;5PR",
        "eA4!&",
        "4!454z4",
        ">R$`~",
        "0h0*}BP",
        "8460oeQ",
        "w`E=W",
        "Negative content-length: %I64d, closing after transfer",
        "P)$AdfX",
        "e$_m/",
        "Modules found in stack:",
        "&2Snq",
        "16h?El8",
        "FeatureAntiVirus:  CleanOldCache started.",
        "VD0/=n",
        "ZpV{I",
        "L_jCe",
        "file:",
        "H6dHr",
        "7nz3(gq",
        "L]>/l",
        "2*313<3Q3a3",
        "b6$&D",
        "/Vq(qdf(",
        "'#g/;",
        "uUZxm]'",
        "SOFTWARE\\Classes\\CLSID\\",
        "7\\>Yy",
        "n'%\"6x",
        "zLhp;",
        "F/yE)",
        "RSA_EAY_PRIVATE_ENCRYPT",
        "@:_ p",
        "88ok\"x/",
        "303V3",
        "Afpntx",
        "2:jFA",
        "Hu\\y#",
        "F$B;Vhr",
        "4*4M4",
        "Failed to get document element.",
        "?3Wu]",
        "8!8/888E8O8g8}8",
        "555}5",
        "8^zw/%",
        "<+__Z",
        "Invalid data read from ca script.",
        "K~_g-#",
        "+|Ghw",
        "BAG|L",
        "|+H8j",
        "O7!8*",
        ".l!=j",
        "(RJJ8Z",
        "\\LKBp",
        "ki`?T",
        "!/>w*",
        "oo@/B",
        ")N/lX",
        "-{)0D",
        "%-j3uW",
        "Jm\"%|",
        "0C0H1",
        ";[;c;",
        "8_ZA)^%",
        ">Y?z?",
        "gKqRM",
        "7}p>|",
        "mw.s8",
        "Vmc?Wx",
        "97`c7",
        "Helper::setEventGroupInVSConfig(%s,%s,%s)",
        "Ix\";Hn",
        "deZ|&",
        "failed to create FwRule object",
        "Registry error:  root not set.",
        ".$_b;A",
        "Pjej*",
        "M^~+N",
        "AES(128)",
        "?cP$G",
        "\\vsdatant.inf.delete",
        "<miDz!",
        "Q}RO\"",
        "j}U\"%",
        "?[,:\"*",
        "1Q<<U*",
        "0H[bW[",
        "|(]x.",
        "v:DT;",
        ";T\"r;s`7;",
        "Request CERT",
        "bx3e[",
        "5?OT-&|p",
        "@%F1\\@v",
        "J9]rb",
        "'UVu0",
        "7&7_7t7",
        "jghp?%",
        "@,{tO",
        "S]X8O",
        "z)glo.?",
        "ojA:8",
        "nPunl",
        "5\"UUxhdvwG",
        "6=6j6",
        "##!+`I",
        "@Q!:`",
        "[THREAD] _beginthreadex  \"%s\" failed with %d",
        "kSywg?M~s&h",
        "*5&-n",
        "K*\"q1r",
        "1%2G2`2",
        "es-bo",
        "SCHEDULER",
        "kWw6l",
        "ClientSubType = 'S'",
        "3333w",
        "Zv(=r",
        "kc/$8",
        "wtf%s",
        "/'}f'-9",
        "gt?jdrh",
        "ec;*@R",
        "/\"&zs",
        "v0 d4z-",
        "RA&(c6",
        "We got a 421 - timeout!",
        ")]_^Y",
        "k$a{.",
        "ctx->length <= (int)sizeof(ctx->enc_data)",
        "?$3HlV",
        "http request",
        "6<7R7",
        "\"zmL/",
        "E.ts|}",
        "KxnY/",
        "9U9k9",
        "failed to write ElementPath to custom action data: %ls",
        "V\\$:B",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UpgradeCodes\\",
        "`+h,u",
        "##;n'",
        "t|G\"b",
        "_purecall",
        "WX`R^",
        "ZtU`;W_",
        "LN@=U",
        "CANT_GET_CISCO_STATUS",
        "RMwf0f_",
        "l,kg<i",
        "z;gu0",
        "=!=A=Q=a=q=",
        "\\I%>Jl",
        "i)?&9",
        "8f9}9",
        "i#Rn6K",
        "(|h1^",
        "AI2kfTjk",
        "-/\\|'",
        "Xwnj=}",
        "FWRemoveBefore.F87AF79D_F10E_4FC8_A4A1_7A12C7210F71",
        "O82b)",
        " <@ZP",
        "J=t N",
        "jxjyj",
        "Z0[p[",
        "m*zBS",
        "_=$;8U",
        "889<9@9D9H9L9P9",
        "CqTR;",
        "V78ZA",
        "xh-za",
        "read wrong packet type",
        "UAarT}aV",
        "uo02S5",
        "G*DfAd8",
        "c:Cm+j",
        "aZODU",
        "&Lj&6lZ6?~A?",
        "=xhy!!{I",
        "n(9@e",
        "StopCipollaService_rollback finished.",
        "k-5ULr",
        ")b.+w%",
        "error loading dso",
        "SX{?}",
        "GENERATE_KEY",
        "TQz}v",
        "_small",
        "$xw{.",
        ".?AVstl_critical_section_interface@details@Concurrency@@",
        "_}0-h",
        "failed to Query Service.",
        "Zf|4Hl",
        "Expect: 100-continue",
        "9I`b]",
        "r*&bK",
        "9!:b:",
        "{GNuD",
        "Failed to get module handle.",
        ".~bk!'>",
        "JM#e*PD",
        "fF1Pb",
        "T[G-`",
        "HIC@w;.",
        "(rdb(",
        "U^O%$",
        "zlBn,",
        "2!c,)",
        "PRRRRR",
        "\"dM.>",
        "?5z/Rc",
        "3shrpq",
        "3K4W5",
        "zn$l%",
        "$bdHpe",
        "mnmo\"",
        "UJ6{\\T59=",
        "lvn*2",
        "=`Zm.~\\",
        "KR}2ZR",
        "_?p!S$",
        "RSA_padding_check_X931",
        "1]RU^",
        "u*C49",
        "MonitorAddEventHandler",
        ">EnLCx",
        "'i1F8",
        "D)x)?",
        "1)191V1w1",
        "JZgI'",
        "s#$9\"",
        "zhw1J?",
        "0N[`d",
        "vN,pp",
        ">#Ot[",
        "HH':'mm':'ss",
        ")AdY'",
        "\\FXRf",
        "0 0.0@0P0k0w0",
        "Oz-YIMnTku",
        "PKCS7_ENC_CONTENT",
        "j5~ec K]J",
        "3(q<Kp",
        "5H7g7",
        "'7.?-",
        "4 494R4k4",
        "e1*5AwT",
        "t$DRV",
        "-r<~!7k>",
        "&{NBn",
        "S`I,q",
        "7=f|\\F",
        "pv?\\v",
        "0 0R0b0s0",
        "9'9C9_9{9",
        "L&#D-",
        "rR5%LjXj",
        ":5XvxUi",
        "0gy@g",
        "D$$Ph",
        "9)znc\"",
        "404v4",
        "2-2B2G2",
        "TLOSS error",
        "K)0E?~",
        ";>.;Xc",
        "<D<H<X<`<h<p<x<",
        "ou%K]",
        "authority and subject key identifier mismatch",
        "5&5T5i5q5",
        "m #L6>",
        "J9l:&\"",
        "D`K#()0",
        "p8CQy",
        "T~9KW",
        ",,\"uKt",
        "L&bDs",
        "]*}3?BW",
        "O0\\zJn",
        "e5E6W",
        "d.F]^",
        "shutdownVsmon succeeded.",
        "=5ME`",
        "L>a^-",
        "3L3P3",
        "FETCH %s BODY[%s]",
        "w/#BA",
        "4gg\\[",
        "]!&(wP",
        "JW^WxR",
        "wQP =",
        "KOc7t",
        "failed to write shortcut target to custom action data",
        ",'8,!y#",
        "G,[oN",
        "8(898?8e8",
        "/vP?gV",
        "577v8",
        "&PwOq7",
        "U1(\\Q",
        ";L7qo",
        "<4J$'YZ",
        ".gN#)~",
        "JIxdy",
        "H/5~:",
        "\\`g+>o",
        "p6innT",
        "bstr_wsn failed",
        "0(020<0F0P0",
        "42nEO",
        "j{hd^%",
        "w$FyI",
        "3-z1_Ex",
        ":K)nk",
        "4D<Q9J",
        "0L2%!;Vu~k",
        "Address already in use",
        "void __thiscall boost::property_tree::basic_ptree<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> >,struct std::less<class std::basic_string<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t> > > >::put_value<const wchar_t*,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t const *>>(const wchar_t *const &,class boost::property_tree::stream_translator<wchar_t,struct std::char_traits<wchar_t>,class std::allocator<wchar_t>,wchar_t const *>)",
        "]jF)5",
        "i?BL3SR",
        "{\"?L?",
        "DaZ'M",
        "AFm}UWjn",
        "69$Tu",
        "jXYf;",
        "GUm87",
        "#Ak@1",
        "didn't go into ChangeCharacteristics9to1",
        "Hp1!B",
        "Ms+|y",
        "5d6h6l6p6",
        "NxO2'>'",
        "Sj+PS",
        "`w8C#N",
        "%;/VO",
        "Compliance.exe was stopped",
        "8@WK#",
        "+LAvp",
        "sgkf\"iR",
        "O%`?p",
        "uLS}xc",
        "-Ml Kx",
        "5=:\\|",
        "CRYPTO_get_new_lockid",
        "@7zs$=",
        "0E0[0c0j0",
        "4?&>Q4",
        "2.3F3D4",
        "'|hMU",
        "Q0wu]P",
        "|Qbt\"",
        "usSSSW",
        ",)4SmJ4",
        "MOVAPD",
        "}]\"<%",
        "OSc]v+4",
        "z/.os",
        "`V+)=",
        "d^keW",
        "id-ct-asciiTextWithCRLF",
        ">7>>>R>",
        "664L~",
        "1\"2e2",
        "6$606P6\\6|6",
        "\\securemote.reg\"",
        "m&-p1",
        "aHR{'",
        "?q.LO",
        "M}bG&y",
        "w]bvy",
        "\\I3\\!",
        "Vko^y",
        "WoPV1f",
        "^3<?yX",
        "9(9.9A9K9Q9",
        "_GE%\\",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\widctlpar\\tx360\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 4.\\tab }{\\rtlch\\fcs1 \\ab\\af1 \\ltrch\\fcs0 ",
        "<\\CHf",
        "}#r%:Z",
        "|3391",
        "j\"_VSSSS",
        "U-=7V`V'",
        "A,^_3",
        "ktMjh.",
        ">Klo0",
        "31st [=",
        "$Q`@{",
        "IlGV)",
        ";M;l;p;t;x;|;",
        "0<0@0p0t0",
        "3CD&r",
        "9t$4t",
        "c{U7FQbCl'_",
        "sbgp-ipAddrBlock",
        "grF,Cf",
        "<!=q=",
        "W4$Bw",
        "NZD<K",
        "Custom acion:  OnBeginExec: started",
        "aP$}|",
        "j.7} ?",
        "-xQa7?",
        "<@=w=",
        "^B^l^x_W/l/",
        "Bm!^j;",
        "?rpa=I",
        "^`r]1=",
        ";eywB",
        "K;%mja[",
        ".z^:t",
        "H*X#;j",
        "fecc8",
        " G3*X",
        "q.?8`)!",
        "7 7(747T7\\7d7p7",
        "SSL_CTX_set_cipher_list",
        "|bW4Z",
        "?!J*@",
        "0<Hq@",
        "smartdefense.dll is installed",
        "VhT; ",
        "SetFWInstall",
        "\\$$UVW",
        "`_lRC",
        ";!Pg\"",
        "QBO^S",
        ";(4=z",
        "MUJ%(5",
        "`{7~@",
        "~?Wu3",
        "Oh?U6",
        "~Y&[q",
        "4#+ku",
        "=\"t5!",
        "`XV:u",
        "0Ay'C*",
        "K#dP)",
        "<MERegProtectionOff>",
        "failed to set exception protocol",
        "EVP_PKEY_verify",
        " -V81",
        " failed to open registry key (no OM)",
        "KXs c",
        "===Q=x=",
        "WE.bL",
        "r^WMg",
        "Received invalid version in initial SOCKS5 response.",
        "l{'$X",
        "555D5",
        "CryptCreateHash failed: %d",
        "Q!\\**",
        "9H:a:l:",
        "OOU:=",
        "yS-Oz",
        "|FM[I",
        "E{g3VB",
        "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UpgradeCodes\\A3122864DEC94E444992B26D2D1900E2",
        "1h/&0",
        "3D$43",
        "Lo^AD",
        "9\\C={",
        "3&3+3=3f3x3",
        "=(q34",
        "qIpT9",
        "!*0Cg",
        "expecting an asn1 sequence",
        "OnDQ\\",
        "WxrUq(",
        "9$>4z",
        "[[%s]]",
        "2(20242@2H2L2X2`2d2p2x2|2",
        "8*8F8b8~8",
        "|)vdwu",
        ";h+D]",
        ",LN[\"",
        "3D$43D$0",
        "3;3I3P3f3p3D4",
        " OH'.",
        "jurisdictionL",
        "_Pbvb",
        "\"|D;W",
        "Network unreachable",
        "9\\UVG",
        "<%<-<6<q<",
        "Uk\"U[",
        "PEM_SealFinal",
        "q|-Y[",
        "SG$ -",
        "UPDATEURL",
        "7H!&L",
        "|ST+~",
        "JXqoo3",
        "d+&n.0d",
        "B!\":S",
        "V(Fkf",
        ".[i7E",
        "8Q\\Ga",
        "5(5H5P5X5`5h5p5x5",
        "cannot switch from manual to automatic argument indexing",
        "bh&1kbQ",
        "O~>5z",
        "\"WooL",
        "viTP)",
        "bDE?X",
        "YO!Bc",
        "($Vh(Hy-",
        "{RUP_G",
        "88~#T",
        "z.dH+",
        "ad{!=",
        "L$H^][3",
        "5VgL%",
        "vsmon_unique",
        ">>4!\\",
        "`m!zM",
        "/f;Ah",
        "nSQRD",
        "e+xj0",
        "SOPHOS_BASES.50F05011_FC3E_4209_A92A_9D8DF4E71D10",
        "ccUE?",
        "_6>L\"|",
        "iJ7Y2",
        "PaNox4S",
        "3f4u4",
        "SpcSerializedObject",
        "bad end line",
        "t$(Vj",
        "0'050C0Q0_0m0{0",
        "7*767E7K7a7p7v7",
        "Got the account sid. snu:%d",
        "challenge is different",
        "|3~t6",
        "4+4j4.5q5{5",
        "POLICY_MAPPING",
        "<2<7<P<U<b<",
        "q>!8,",
        "f3e5;j",
        "cF:b'",
        "K=K7=x",
        "5xZ[i=`",
        "uC&>{C}",
        "en.US",
        "G(WZ#",
        "B(ibn",
        "4i5t5",
        "Z)B!zc#",
        "=[Yj@",
        "M*wk0?@",
        "a96kJr",
        "BMPSTRING",
        ">2>M>u>",
        "EF\"Mr^",
        "8Nx^lj",
        "W)zF'-z@",
        "i#BHd(",
        "Fa`j~ia",
        "wjS#J",
        "JIWiJ",
        "2|i.F",
        "grt0R",
        "%tr!}",
        "?96+8",
        "Ia\"{p",
        "fxWbW",
        "SchedServiceConfig",
        "Y:H %",
        "t$0VV",
        "oG.x=o",
        "7I6c/",
        ",d(d`",
        "?/?9?C?",
        "2OP0N",
        "wMk!!",
        "?j-J9",
        "'\"Uk6",
        "KG|@>m",
        "logStoreDir",
        "{(o9OtS",
        "LULuL",
        "T\"M$6~",
        "8+939C9q9",
        "[;T$S",
        "7/(Y3e(",
        "n[H0?",
        "{2%D\\c",
        "MINOR",
        "121J1U1Y1_1r1",
        "5(d:O",
        "+L''99a",
        "2 242B2J2P2T2Z2^2d2h2n2r2|2",
        "RSA part of OpenSSL 1.0.1t  3 May 2016",
        "&F~-vi",
        "TargetOversubscriptionFactor",
        "=v!0)",
        "jmhDx#",
        "d`oG5",
        "LWhf\"a",
        "IQ<lkf",
        "(x2{.",
        "171P1t1",
        "|<?PhP",
        "a9&@gh",
        "_;:Stj",
        "AvgBootTime",
        "t$(SV",
        "\\a0h(.",
        ">!>=>Y>u>",
        "CL:`H",
        "ej\\'e",
        "nb9vm",
        "j@hhJ",
        "D$@_^][",
        "GKVHj4",
        "bad response argument",
        "]v~E\\y",
        ")d#~Y",
        ")}dXa",
        "L}1DL3",
        "\\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid5186676 and/or restriction }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 ",
        "4%5?5M5",
        "api_ms_win_crt_string_l1_1_0.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3",
        "hW<Q,",
        "expected codepoint reference after high surrogate",
        "6)6Z6g6",
        "o}_Hs",
        "1\\1|1",
        "/)?:D",
        "z5DkA",
        "Y%6Zu!FM",
        "&YT[r",
        "SVhhNL",
        "<`JaG120",
        ")(D1{",
        "k-Xd=",
        "e7`5\"",
        "v7BC=",
        "S)D%4",
        "3%3A3]3y3",
        "~eh@M!",
        "&T^=k",
        "9E;R;",
        "1#292g2",
        "92BuR",
        "='=i=q=y=",
        "=[UqwQg",
        "ame}h[",
        "q:0obz",
        "\\$B/i']",
        "+y32+",
        "RC%jA",
        "-&<1;",
        "{tOq#",
        "\\ZoneLabs\\avsys\\",
        "j]Yf9",
        "=$=(=8=<=@=D=H=P=h=x=|=",
        "<tm,S",
        "c_nV?",
        "7:*zNo`",
        "%fO_;1`a",
        "S.^',+",
        "a!*T%",
        "A3HYJ",
        "\\X?,q",
        "#{X0`HP",
        "[1FU[",
        ".YOl[",
        "\"o(W%",
        "[lGIK",
        ",ex^jo",
        "@|:!M",
        "bm8x2",
        "acv!M",
        "lj:aD",
        "]R@8<",
        "O`,1fz",
        "0gCq=A",
        "2*H$<F'",
        "SRP-DSS-3DES-EDE-CBC-SHA",
        "^J|r]+",
        "HXqIme",
        "B!f+?",
        "SVWQj",
        "(*8_`",
        "o7U4u",
        "atQax",
        "_y)6kAw",
        "iMo Y",
        "\\InstHelperVPN.exe",
        "@yi@Ke5kj{",
        "1$2C2Q2f2r2",
        ".?AVtype_error@detail@nlohmann@@",
        "|#{[Q",
        "Security",
        "9Ta1a",
        ">e>Em",
        "&3fs*{",
        "8#8)8/858;8A8G8M8S8Y8_8e8k8q8w8}8",
        "Check Point Endpoint Security Tray 3.0",
        "'}Yd6",
        "q#G}#Z",
        "vN?m6F",
        "CmV4A",
        ":z\\p\\5",
        "Ieqj<",
        "p_tB2|",
        "JlgY\\",
        "[D=jt",
        ")u`F:",
        "\\temp\\sdk8",
        "i\"J@|",
        "T% @ ",
        "6d;,}",
        " 3W\"$",
        "-~$6T",
        "uc1O8",
        "1M2a4e4i4m4q4u4y4}4(5a7e7i7m7q7u7y7}7185:9:=:A:E:I:M:Q:",
        "UAlnv",
        "CMS_add1_recipient_cert",
        "&MDD,",
        "led%>",
        "Private",
        "-6@)Li)C",
        "WD_InstallWatchdogService started.",
        "$#|%)",
        "ZlAhH",
        "u+\\(d",
        "kOBg&",
        "&uh\\:",
        "jsM&_",
        "Ge9VU",
        "o\\$`f",
        "^|bIr",
        "7J\\6g",
        "gIjmY",
        "<O*@Q9H",
        "/_^[Y",
        "Gu4~t",
        "could not set engine",
        "<;<_<",
        ";%;+;B;b;",
        "M;H!;",
        "2&272L2Q2",
        " `T(VI(",
        "D$RPUS",
        "M4O$y:",
        "y6^XN`",
        "0 050T0$151<1D1Z1v1",
        "ei~il",
        "h#t9#:$",
        "#I3I:E",
        "1?Gb0O(",
        "|JK4`",
        "OUQgZ",
        "sQjr.q",
        "Plugins::UnregisterSC:  Unregistration successful.",
        "k0unC",
        "sK,t6:",
        "+4Y&x",
        ":B:O:a:r:x:}:",
        "[VSSHUTDN] UnBanProtection ",
        "YPX6mE7",
        "Wi,+UXg",
        "DTjRa",
        ";!;n;",
        ",H2<LK",
        "FileTimeToDosDateTime",
        "XLmQ\\",
        "*]|i\\",
        "hx=\\:T",
        "mC]Ya",
        "2&2-242E2_2n2u2",
        "\"=&GT\"",
        "u|||y",
        "%8?<yP",
        "UUUT`@D",
        "N.Wq#",
        "message digest",
        "<G|2!",
        "blksize",
        "6)6I6i6x6",
        "f:\\ckp\\src\\ep_calib\\e87_20\\eps\\calibrary\\calibrary.cpp",
        "M:=z:",
        "?I0EXi2",
        "invalid ip address",
        "Y5hSb",
        "\"**jnBb**pr",
        "Esm9_",
        "B8I'wto",
        "mbqE'",
        "Qjmj\"",
        "4:4j4",
        "8I!J4\\P",
        "'D{I(",
        "B35B~k",
        "cR$d8",
        "RT~T`<E",
        "-$5w ",
        "9 9,9L9T9`9",
        "IPn\"g ",
        "setAttr-Cert",
        "%u %s",
        "9oj)#p",
        "h'r&dI",
        "FreeLibrary",
        "C6'u{",
        ":1:=:J:j:t:",
        "]=na.&",
        "fpSg)",
        "n*]/i",
        "t$(GV",
        "u#jQh",
        "WGUww",
        "L<8@=",
        "1<1H1",
        "*@dJ2D",
        "a;U:<",
        "H]z#v",
        "V$G%v",
        "A_s\\)XA:G-",
        "oa8[W",
        "t$$WV3",
        "v8i/b",
        "jm\\>N",
        "\\$(V3",
        "9z@y,",
        "SYSTEM\\CurrentControlSet\\Services\\VNASC",
        "0@#l;e",
        "fFew[",
        "XlC\\M",
        "RegDeleteValue failed: %d",
        "\\fs20\\insrsid16581128\\charrsid15169477 at its sole option, }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid15169477 either repair or replace the }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\insrsid3017503\\charrsid5186676 ",
        "[3Kki",
        "I2bi=|d",
        "ZtmW'",
        "(eLRMfh5",
        "?#?<?U?n?",
        "@QGRs",
        "0= {t",
        "Ev2SY",
        "[%s] MessageBox lpText=<%s> lpCaption=<%s>",
        "default",
        ")8)tR",
        "\\vsinit.dll",
        "E7|(S[ 3",
        ",lX,7)",
        "lOB_]",
        "OCSP routines",
        "VhpV!",
        "Y]SbA",
        "o0$WV!(",
        " vSyr.",
        "invalid trust",
        "incompatible objects",
        "={\\qt",
        "e0kGE",
        "84bH2",
        "4c5}5",
        ";(ND~n9C",
        "4H5f5",
        "Gl15XF",
        "&2Iyt",
        "a:) %",
        "P=T@\"",
        "<;=]=",
        ",%1R4(",
        ";7uu9}",
        "poXF2",
        "+NOU#@u",
        "?X/_s",
        ":7dkC",
        "bN _$",
        "4:[$;",
        "5-&8{",
        "rs7h3",
        "vA?m\"",
        "a''F(",
        "%I8;}",
        "G/33c",
        "ILTSwO",
        "%e3kft",
        ">GBbk",
        "http://ocsp.digicert.com0A",
        "/f3 Q1",
        "Js%\"a",
        "jw393-",
        "\\par }{\\rtlch\\fcs1 \\ab\\af1\\afs20 \\ltrch\\fcs0 \\f1\\fs20\\insrsid11555386\\charrsid5010868 ",
        "/(B@|",
        "G_Cx2",
        "no load function",
        "Tb`O#\"",
        "^}>TP",
        "sG/T'",
        "e\"eBD",
        "1ww)!",
        "48Rcl",
        "|x N4",
        "KSV$=",
        "KG?#5",
        "l8.(R",
        "regex_error(error_backref): The expression contained an invalid back reference.",
        "zl.FrodoLives",
        "i2d_ASN1_bio_stream",
        "^d$xj&",
        "|M\\W\"v@",
        "qqX)C",
        "K@O;R[l",
        "eMeae",
        "Y[3ER",
        "8d'Tb",
        "Pue}1\"",
        "Wppl6",
        "(/#jD^XJ",
        "B<O,KA",
        "$(<=h",
        "}.Ic2",
        "\"''rr\"r/-",
        "J@#}+",
        "$lz3VYy",
        "616Q6",
        "5[X.I0",
        "ej)hx",
        "{TZFU:",
        "Dw$G:",
        "/#K>t",
        "=fKj]",
        "SEC_E_KDC_CERT_REVOKED",
        "#d]8=1",
        ";$J=yH",
        "TLS app data",
        "caQ|0~",
        "22>Na",
        "9^PuDh",
        "OCSP Archive Cutoff",
        "j:Lm#o",
        "2 282@2T2d2p2",
        "7EG(h",
        "464R4n4",
        "nV+*s4TuS",
        "0lhJ]",
        "_ud->",
        "@ZxWC",
        ".xXse",
        "G6eL<l",
        "9#f~VM",
        "pHj2Q[s",
        "_PSSSSS",
        "v35'6",
        "FAILED_TO_MAKE_REGFILE_TEMPFILE",
        "6(6<6@6",
        "1 1@1H1P1X1`1h1p1|1",
        " 0xb4",
        "5OL7z#",
        "B,B,C",
        "4>5[5",
        "?\"~T?",
        "\"`ke'",
        "AH6be",
        "lcnma",
        "(_:1<^hM",
        "7y[VQK",
        "mj.uBE_a",
        ".R B_",
        "ia=MI",
        "hs&?k",
        "u u.P",
        "_5K<d",
        "K/dZ]",
        "<KaS3",
        "Juh{}",
        "jurisdictionLocalityName",
        "/?6'o",
        "%BHI:B",
        "{\\/>r",
        "6 \"2r",
        "\"h\"vz",
        "=2===R=",
        "|>>4J",
        "dTu_t",
        "y5;Y|",
        "6@Ln`",
        "`dZF{",
        "PTdZ<",
        "J4TI!",
        "chQ4H",
        "aaL$o3",
        "mstring wrong tag",
        "issuer_and_serial",
        "'V:F@\\q",
        "0k@I<![",
        "2xF7&",
        "/tP+M5",
        ")0IXO=",
        "k%!ee",
        "Saving VPN files.",
        "h5?'5%",
        "x}Id^%f",
        "zHXv\\",
        "=9=?=J=",
        "HKLM\\SOFTWARE\\Microsoft\\VSTO Runtime Setup\\v4R\\VSTORFeature_CLR40 not found",
        "=$=,=4=<=D=L=T=d=l=|=",
        "4roT~",
        "Lj0-X3@q",
        "\\P=my",
        "z*zJ}j=e=E=e",
        "S_Dt}",
        "\"c3#mh1",
        "KX)]fo",
        "o}~Yz",
        "lg-ogx7",
        ":,:<:@:P:T:X:\\:p:t:x:|:",
        "? ?$?(?,?0?",
        "W)W.W6W;WRWWW_WeWnWsW|W",
        "G,PURQVSt",
        "0.0S0",
        "Z77gE",
        "2'3E3\\3w3",
        "%g$}@",
        "0ndZuq",
        "Did not find unreg request",
        "101F1U1v1",
        "&aN->",
        "$k'XI",
        "{P4`TT",
        "T2jqV",
        "eLV\"T[6",
        "cBf*U",
        "`&2M I",
        "=!Vx?M",
        "TracSrvWrapper.exe.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
        "N#CPA",
        "XFM>X",
        "f8ad/",
        "DeleteObject",
        "If any provision of this Agreement is held to be invalid or unenforceable by a court of competent jurisdiction, that provision of the Agreement will be enforced to the maximum extent permissible so as to affect the intent of the Agreement, and the remaind",
        "5,575[5o5",
        "r6[IR",
        "3'3V3",
        "808<8X8x8",
        "P0Wxc",
        "client_sub_type=%s was found in registry",
        ":9;y;",
        "win.9x.98",
        "_lclose",
        "vno'q",
        "./V8-",
        "Ae5hm",
        "U`c6a",
        "5 5$50585<5H5P5T5`5h5l5x5",
        "/)mU,_",
        "Pzf5 ",
        "expecting public key blob",
        "CAMELLIA-192-CBC",
        "5b!#Gg",
        "4!k-Tp",
        ",)|C{",
        "{={B^",
        "\\5/2y",
        ";7uG;",
        "n!0ti",
        "x[|fip",
        "ResponseVerified RC=%d",
        "xL9v\"",
        "socks4a",
        "iGcr9",
        "j4I^}",
        "F'i>w",
        "DB Error: %d: %s",
        "-Op+Z",
        "RNUjX@_",
        "GA&sE",
        "Can't find:  %s",
        "m[\\r\"",
        ";u))H",
        "D<Y>y",
        "6LM$[N",
        "QRhtQ!",
        "_;,?=<8",
        "Rs3C`",
        "4JKES",
        "W=`Gs]",
        ".@&39C,",
        ">aY,V",
        "UNINST_PASSWORD",
        "jR&ZyOb",
        "UN?@{",
        "2&343Q3",
        "ey{dS",
        "kqn3U",
        "/,{z]ua",
        "kUi1G",
        "nh8FA6",
        "<Llk4w",
        "W<XkT[G",
        "l$$VUW",
        "az!lCI",
        "Yi`g=/",
        "|zyUX",
        "dp,DA",
        "6P7X7]7g7",
        "ZLE[i",
        ".~{79",
        "se-fi",
        "Rewinding stream by : %zd bytes on url %s (zero-length body)",
        "M(Ij!",
        "Z^{R>",
        "Backup vsmon.exe from installation directory.",
        "-po,:Y",
        ")loQ)",
        "u<x=@",
        " HeiP\"]",
        "unknown cipher returned",
        "#;^\\Zz",
        "Content-Type:",
        ">4?Z?",
        "Vih%!t",
        ":=;&<5<|<",
        "7(M/u",
        "`u5?y",
        "data too large for modulus",
        "67NT1",
        "1u;-7i",
        "6,z5w",
        "18<Cl",
        "=!U]U3Q",
        "4,4W4",
        "'qUSm",
        "1 vk8",
        "Getting temp dir",
        "~XXPI",
        "34MCk+",
        "\\par }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 9.3\\tab You understand and acknowledge that upon entry of the Product into the {\\*\\xmlopen\\xmlns2{\\factoidname country-region}}United States}{\\rtlch\\fcs1 ",
        "KNw;O\"",
        "en+Hg",
        "i.3$tM",
        ";.(2q",
        ";F+e.",
        "Gk1Bf",
        "G;} s%V",
        "D]HY.^",
        "ifgXs",
        "=W*?p",
        "U|pvI",
        "X9.62 curve over a 431 bit binary field",
        "tDQoV",
        "172V3h3",
        "a. /zYM}",
        "1K{<\\(",
        "N_f,=U",
        "huf>]",
        "CMS_decrypt_set1_pkey",
        "}:8>o",
        "Wuj>'h",
        ",J4ly",
        "'htsH~",
        "Error: cannot open file '%s' for writing.",
        "Y\"x*6",
        "~rHIw/r",
        "<^F8M",
        "'1iV$",
        "Q+p6C",
        "5$b}t",
        "-@p9*",
        ".cxzK",
        "\"%s\" OS=%s USERINSTALLMODE=%s MSIPath=\"%s\" Standalone",
        "3$3x3",
        " 0x5a",
        "3g.\\p",
        "!O~wrw(?",
        ")b!R$",
        "lO@grbs",
        "9^t_>",
        ">#>*>4>?>J>U>`>k>v>",
        "121P1T1X1\\1`1d1",
        "WwOuc",
        "connection type not set",
        "/]E2\"",
        "bzBbuB",
        "),Z5p",
        "F*_k:",
        "Vjxh(",
        "@Y`cBI/",
        "PE_mu",
        "\\Wm+_",
        "-)-1-9-A-I-Q-Y-a-i-",
        "f6hs2",
        "msiexec /i \"",
        "|.$p;",
        "B$Vg:T",
        "DuplicateHandle",
        "7 8H8",
        ",J|H(<",
        ";#6ZF\\F",
        ".\\crypto\\dsa\\dsa_ameth.c",
        "<JXht",
        ",ax(W",
        "SEC_E_OUT_OF_SEQUENCE",
        "1s7&t",
        "y13TE",
        "040II0",
        "Check Point SecuRemote",
        "APPEND %s (\\Seen) {%I64d}",
        "r#?l2",
        ".UAk'",
        "NY&>9",
        "uU@Bh",
        "iX!pH",
        "1$1D1P1p1x1",
        "<`<l<y<",
        "VJ`e;",
        "P'>Dn",
        "`-7oJ",
        "2~\"%#",
        "/&&&&&&&&&&/&&",
        "3b11F",
        "J%~#s",
        "bh)`l",
        "+%lO.",
        ")Dk,Vq",
        "\\lsdsemihidden0 \\lsdpriority67 \\lsdlocked0 Medium Grid 1 Accent 6;\\lsdsemihidden0 \\lsdpriority68 \\lsdlocked0 Medium Grid 2 Accent 6;\\lsdsemihidden0 \\lsdpriority69 \\lsdlocked0 Medium Grid 3 Accent 6;",
        ";117;4",
        "y`8qr&",
        "9EJr;)To^I7",
        "h6 rt",
        "=G=M=S=",
        "y3eai",
        "85ls!",
        "d.kekri",
        "\\i-f5",
        ":P:W:f:t:",
        "O#\\#m",
        "7t-pp&",
        "}=&\"e",
        "`ENZ]([3O",
        "!#(xT",
        "dwCZ>F",
        "1Y\"L*",
        "Kv) &",
        "FWFreshAfter:  RunVsmonInstall",
        "]\\KZ4q:",
        "1Z-$:",
        "H,CmZ",
        "VVAVL",
        "FAILED_TO_COPY_POLICY_FILE",
        "CoCreateInstance failed",
        "Sectigo Limited1,0*",
        "sg<ba",
        "D%K$'",
        "jIotY^g",
        "b&NkyV",
        "ASN1_D2I_EX_PRIMITIVE",
        "<Uz3~",
        "\"t8|G",
        "EWB?9",
        "e\\-o?",
        "=~=!^",
        ">.>W>u>",
        "484H4T4t4|4",
        "5$5D5P5p5|5",
        "wJ{;{m7",
        "GetDeviceCaps",
        "hJLB.",
        "13Oa9",
        "xVSVW",
        "g/LQ\\",
        "XO1AC",
        "DeregisterEventSource",
        "O`Q,U",
        "1$3.3b3n4s4",
        "MVtY3-S",
        "fg (@",
        "@F8W?",
        "ANoyG",
        "Vq]L:",
        "2K3U3r3",
        "BITSTRING",
        "j}UB,t:",
        "M,j\"^QRRRRR",
        "\\ubHj",
        "infinite",
        "eI/!Y",
        "A7)qi",
        "#g]~d",
        ")+%T`p",
        "T7=?@a",
        "/\\C3#q",
        "7$8F8K8g8",
        "q(=\"wE",
        "bL3%I",
        "@H>Plk",
        "Y{Wxs2",
        "}_|6R",
        "zWn,e",
        "k4V#v",
        "\"7=-p*!R|",
        "A43D$",
        "$}u|N",
        "KWpFv2",
        "BBtFa",
        "Userenv.dll",
        "XcTmI7",
        "g$rX+",
        "O.9\\tv",
        "Z`.PE",
        "O~&M>",
        "&K-)V",
        ",oY<\"",
        "M) 1l",
        ".\\crypto\\asn1\\a_strex.c",
        "R##Fe",
        ".V.$#(",
        "TAKING ANY STEP TO SET-UP, USE OR INSTALL THE PRODUCT CONSTITUTES YOUR ASSENT TO AND ACCEPTANCE OF THIS AGREEMENT. WRITTEN APPROVAL IS NOT A PREREQUISITE TO THE VALIDITY OR ENFORCEABILITY OF THIS AGREEMENT AND NO SOLICITATION OF ANY SUCH WRITTEN APPROVAL ",
        "d|uY}",
        "u!*m[$|B",
        "D7Qdq",
        "P#06P",
        "J}oo*",
        "\\lsdunhideused1 \\lsdlocked0 header;\\lsdunhideused1 \\lsdlocked0 footer;\\lsdunhideused1 \\lsdlocked0 index heading;\\lsdunhideused1 \\lsdqformat1 \\lsdpriority0 caption;\\lsdunhideused1 \\lsdlocked0 table of figures;\\lsdunhideused1 \\lsdlocked0 envelope address;",
        "n>{r`",
        "nU#Kta",
        "XwRa^7l",
        ")AkHf",
        "8\"838H8s8",
        "7skv:",
        " 7WC&",
        "4N5y5",
        "ARJf(2",
        "5957DE",
        "NugmN",
        "4aJ8!3:f",
        "{\\f424\\fbidi \\fswiss\\fcharset161\\fprq2 Calibri Greek;}{\\f425\\fbidi \\fswiss\\fcharset162\\fprq2 Calibri Tur;}{\\f428\\fbidi \\fswiss\\fcharset186\\fprq2 Calibri Baltic;}{\\f429\\fbidi \\fswiss\\fcharset163\\fprq2 Calibri (Vietnamese);}",
        "M461O",
        "2eC(`",
        "3y&6P",
        "w=hTW!",
        "cmd /c \"del /F /Q \"%s\\System32\\vnaap_coinstall.dll\"\"",
        "crl verify failure",
        "fbRc0`",
        "i|v|j{?",
        "4DsX]Sx@w",
        "TIII@",
        ")UR I",
        "<$<><",
        "020U0b0",
        "GLx$K9",
        ":\\?SJ",
        "mh/PwD*",
        "P3Qk.",
        "pz1%D#@#>#J#",
        "`{nN!",
        "~Hiji",
        "?,?8?X?d?",
        "<,<0<<<@<`<d<p<t<",
        "revoked",
        "010F0V0[0`0{0",
        "0INGM`M``",
        ";/t#S",
        "topE\">0&",
        "p$J.>",
        "M24bos",
        "PmQ{8",
        "=$=,=4=@=`=l=",
        ":A:c:",
        "r(D&bL",
        ";0;Q;",
        "uw+t^>",
        "oFoG[",
        "sP{M-",
        "^c-gi",
        "SpcAttributeTypeValue",
        "/6/f_",
        "65x0)~X",
        "=0=;=@=E=o=",
        "V syF",
        "LLLLLL",
        "\"+V60",
        "4757e8d3f729e245eb2b260a0238fd010000ffff0300504b03041400060008000000210030dd4329a8060000a41b0000160000007468656d652f7468656d652f",
        "~EhxJ",
        "Kill EPLauncher.exe.",
        "2$262B2S2`2d2n2",
        "H-LhZu",
        ":HJrp",
        "m{5iW",
        "\"r#m8",
        "$h>pp",
        "'noOfficeMode' was found in registry -> set the property",
        ">f&_8",
        "+.'1\\",
        "failed to add data to CustomActionData",
        "8H8Hl",
        "aes-192-cfb",
        "ffjrb",
        "O]C#w",
        "rL|s2V",
        "RSA(1024)",
        "84U7%",
        "XmA*f9",
        "failure occured while processing WixFirewallException table",
        ";Io**",
        "4 KG`",
        "`G)~,S$",
        "hVV-E",
        "<M:Y4y",
        "x)Xoz",
        "NuuV]Bt",
        "^o6@s",
        ")kqsG",
        "P:9g#v",
        ")UXNq",
        "amMXI",
        "If>:+",
        "CopyPoliciesFromOldDir",
        "c!Uy6)",
        "de:'mLDL",
        ",|`YF",
        "2@3F.",
        "@tOhp",
        ".\"7yTF",
        "$09\\?",
        "4)4]4",
        "SetThreadpoolWait",
        "z~1N2",
        "U=snt",
        "J\\1$H",
        "s_p_J",
        ">9OHt",
        ",1bDd",
        "QY(/[",
        "344O4",
        ";ok=g",
        "TlV[3",
        "CheckPasswords() found ProcAddress for \"VSCheckPasswords\"",
        "Content-Disposition: attachment;",
        "9#:):O:g:",
        "no response data",
        "a0&nBl",
        "mNGh:d",
        "2X6,j",
        "y_ySA",
        "$QP=a",
        "J}7=1a",
        "B1P\\f|",
        "~\\+=h",
        "vgY#CW",
        "1B2M2",
        "Z >s-",
        "9)S*+!K:",
        "'cH,7",
        "`tDO?",
        "5+63x",
        "D$(_]^",
        "ASN1_BIT_STRING_set_bit",
        "K{w0.",
        "unknown format",
        "OLDINSTALLDIR",
        "I'++0q",
        "QQQPQ",
        "_=0|1",
        "YQwg8",
        "L}gML'",
        "<DI.Y",
        "@}_e{e",
        "/(AL\"I",
        "Vw}Ol",
        "N=DtVZ",
        "3l$43l$ ",
        "L1Am1",
        "3=3Z3|3",
        "The requested URL returned error: %d",
        "Yb.V0",
        "L$LPQ",
        "h ?{5",
        "mRWPj",
        "%x{cR",
        "Failed to load value as document.",
        "\\par }\\pard \\ltrpar\\s42\\qj \\li0\\ri0\\sa80\\widctlpar\\tx360\\tx540\\tx720\\wrapdefault\\faroman\\rin0\\lin0\\itap0\\pararsid1132737 {\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 \\fs20\\cf0\\lang1024\\langfe1024\\noproof\\insrsid131787\\charrsid15169477 10.1\\tab }{\\rtlch\\fcs1 \\af1 \\ltrch\\fcs0 ",
        "?YPx[",
        "bad srtp mki value",
        "5m[U[h",
        "oq\\xC",
        "?f?r?",
        "2B3_3k3",
        "Mwyhb",
        "STOREDPROPERTIES",
        "&0N+/",
        "C$y`o",
        "1(181<1@1D1H1L1P1T1X1`1x1|1",
        "DS_PrepareCopyToSystem32 started",
        ">IKc6}",
        "VL^@3",
        "9~0uK",
        "3*'=)\"2Iy",
        "7$7Y7s7"
      ],
      "virustotal": {
        "names": [
          "E87.20_CheckPointVPN.msi",
          "5b1e969.msi",
          "9ceb26.msi",
          "E87.20_CheckPointVPN(1).msi",
          "9dfe9841.msi",
          "CheckPointVPN.msi",
          "3cd86a.msi"
        ],
        "scan_id": "ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
        "md5": "66cf09849cd854c2e6717ad2db5e0248",
        "sha1": "0a329279777bfb9f501ac2694a7ad21df31c73ba",
        "sha256": "ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
        "tlsh": "T13E7701027E42C472DBAE16344039F7BE6ABDD820172489CB97D83D3E6D705C2673A667",
        "positives": 0,
        "total": 76,
        "permalink": "https://www.virustotal.com/api/v3/files/ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
        "scans": {},
        "resource": "ffda8051b2dc3c9da9d40549d811fd044ebac0dedd18e4131890277e9d341f8b",
        "results": [
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "Skyhigh",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          },
          {
            "vendor": "huorong",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "McAfeeD",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "CTX",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Kingsoft",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Xcitium",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Varist",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "TrellixENS",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "alibabacloud",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "DeepInstinct",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          }
        ],
        "detection": ""
      },
      "selfextract": {
        "MsiExtract": {
          "extracted_files": [
            {
              "name": "3b337643545e1c58b2fa8636f22332e4e801a202020413a1d0843daa9fa869a9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3b337643545e1c58b2fa8636f22332e4e801a202020413a1d0843daa9fa869a9",
              "guest_paths": [
                "AdminMode.bat"
              ],
              "size": 115,
              "crc32": "0E78FC8E",
              "md5": "f461201f31a37df40bfae4d164df2cec",
              "sha1": "371024253728e04095291bfb2095319bc2dc4666",
              "sha256": "3b337643545e1c58b2fa8636f22332e4e801a202020413a1d0843daa9fa869a9",
              "sha512": "b9eaabaced909c03726087fe231d47c8a70b0f5d435aed5eb570393daa163e0e224a999455c4e9b6ce0f82ba58a7b8aa84b01309259ae2c63fea2bd87ad1e12c",
              "rh_hash": null,
              "ssdeep": "3:mKDDaF3mXqLCFg1JlMjl3ZlKsonqAEhFkrX2z3jvGpIML:hUVL3vlM3Z24wD2fupIML",
              "type": "DOS batch file, ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T124B092116C4AA02DDA992255D4A242E0958AE042C2E0BA01C8C78CA464886CFAC6E7A4",
              "sha3_384": "27eb4d858a4e9123ab2b8d48d7021956ec3458b44d2204546f109a6e5631409a56c6f3d8933b33f23d7714f68833fc12",
              "data": "@echo off\n@echo Restarting Endpoint Security GUI\ntaskkill /F /IM \"TrGUI.exe\" > NUL 2>&1\ncall start TrGUI.exe /admin"
            },
            {
              "name": "b4186679df3aee4c9d54d96735f8ed36298ddad525fd130c99a901e5f145e3e4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b4186679df3aee4c9d54d96735f8ed36298ddad525fd130c99a901e5f145e3e4",
              "guest_paths": [
                "AntivirusMonitor.dll"
              ],
              "size": 68032,
              "crc32": "BDE3CE4A",
              "md5": "ca528bba366b2c249b82e95cfeaf479c",
              "sha1": "77cb731d4bc193f7763db08154724d855cec1f16",
              "sha256": "b4186679df3aee4c9d54d96735f8ed36298ddad525fd130c99a901e5f145e3e4",
              "sha512": "f24dda70a07e9e9a5c990a752d0cdd9b9d9860270142b1ab7a1a1ada94fa15b5082459f18d02d989c81e691cfd9230136b1e9b66fe71cba9f417bd1952b9a573",
              "rh_hash": null,
              "ssdeep": "1536:Y9+0igxwMlcS1nw7S+L1+RFKVbPDlt3sN57NSy:Q8gxcT7SrKVbPDj3svgy",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T159638D52F70440B2F7CE52B831A6AF3B44B9FE548FE255C3DF661A3A4911AD37A30609",
              "sha3_384": "9bc1dade347c26d80f76726d7e399db226a0c96f227bfda3db3355e87cc6b7e3ac3220781298f3d5e15b82c4ed9228ac",
              "data": null
            },
            {
              "name": "5cedcaf76bdfcdc79dd62969c3a995a19f0a9e965837595a188416f807c9ec21",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/5cedcaf76bdfcdc79dd62969c3a995a19f0a9e965837595a188416f807c9ec21",
              "guest_paths": [
                "api-ms-win-core-console-l1-1-0.dll"
              ],
              "size": 19848,
              "crc32": "E651780B",
              "md5": "0518ac3c9d9d872f5b9be29809fa3a7c",
              "sha1": "f54e4defb53ce9b4165acbb486d2330e3a7af5f2",
              "sha256": "5cedcaf76bdfcdc79dd62969c3a995a19f0a9e965837595a188416f807c9ec21",
              "sha512": "e36e2e61adbae2a53645e7bd79cd17639da66b5657d9f9fba83c9923ba4e5df3f91b7b340e06e0c8fbc59a379e099e743fd57c1af0a51180dc2d32ad5f8f3390",
              "rh_hash": null,
              "ssdeep": "384:8WEhWBYBm0GftpBjThaQHRN7jmlJ2wHOjuxY:apViRhLjyFO8Y",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T146924C978EFC9803EDD2ADB057A8D8877C3DEBC31D2095152069F5D91C837D2AB18A2D",
              "sha3_384": "8c911810ff3583e18a31499025de5df9f01f23653e8a5c0552e9cbedc250716a175ee24ebdf6b3d750a0d50f7db1c225",
              "data": null
            },
            {
              "name": "6e22840349b2609a441fe99a1452767b37ffb32d75b04aceac4d39009ff0a2c8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6e22840349b2609a441fe99a1452767b37ffb32d75b04aceac4d39009ff0a2c8",
              "guest_paths": [
                "api-ms-win-core-datetime-l1-1-0.dll"
              ],
              "size": 19344,
              "crc32": "AF189809",
              "md5": "453df73af929a042cc43d5b0f31cce54",
              "sha1": "e518ce69139615bb174feb6f9071a0691c8c5a5e",
              "sha256": "6e22840349b2609a441fe99a1452767b37ffb32d75b04aceac4d39009ff0a2c8",
              "sha512": "d0597f02f4cc4cc6f2c333e7035936bec1ab9f990eb5744726039627efe149c007c4a2e62a08aabde2cc22db9905892f8501e915a4aa3d7d3d8e41d3839c2e7f",
              "rh_hash": null,
              "ssdeep": "192:mPWEhWpjdsNtLxCjdks/nGfe4pBjS3rZzDeWAaAXcrMHnhWgN7acWiKJVaJqnajB:qWEhWvsngm0GftpBjuKaQHRN7GJcl9P",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T17E923A89CAFC9043EC979D7063B8ED877D3DE7C31D20952614A9F1991D833D5AB28A2C",
              "sha3_384": "36ab9fcc0fb2aa3d8ee22a350c53ac17895fda4761ceeb2332fb608e953ae7319d7abd9aea0430eb4e58fb7bf3e8fdfc",
              "data": null
            },
            {
              "name": "60c7cc1b5771f86c3b2af541489743fdce36c03664293079f1bebd66803f9583",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/60c7cc1b5771f86c3b2af541489743fdce36c03664293079f1bebd66803f9583",
              "guest_paths": [
                "api-ms-win-core-debug-l1-1-0.dll"
              ],
              "size": 19328,
              "crc32": "61027010",
              "md5": "eaa16d9339eeab504a80d9ba077d1750",
              "sha1": "5ff1ec797a3ce8d359e809564e92e360b8a18c79",
              "sha256": "60c7cc1b5771f86c3b2af541489743fdce36c03664293079f1bebd66803f9583",
              "sha512": "db2dd1a05376c3beaf438b6ffaf6d78e62ea88aaffbbdb60e6eb70a0af73941fff4a794ebba8a7637a7f16984c303e1d9f4ebe2930f4ccb3a52da20c2d736bb4",
              "rh_hash": null,
              "ssdeep": "192:yPWEhWIJ+49Cjdks/nGfe4pBjSLhgHfxCyWAaAXcrMHnhWgN7aAWZHPQqnaj/6gt:2WEhWd4wm0GftpBjx3aQHRN7mYltA6",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1AF921AD1CBBC9543ED97AC7063ACED87BD3DDBC31C2049261159E5A91C833D6AB24A2C",
              "sha3_384": "63dde0ebe46d7ea54501f7c3cb30240d7357b55e2aba1641120da243fafdde1f7cfe31d31b43158362c73a0611588374",
              "data": null
            },
            {
              "name": "152e68fec76cad6122df36ab848a948a0b05829f89509cdf96167515e254176f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/152e68fec76cad6122df36ab848a948a0b05829f89509cdf96167515e254176f",
              "guest_paths": [
                "api-ms-win-core-errorhandling-l1-1-0.dll"
              ],
              "size": 19360,
              "crc32": "E8E97B7C",
              "md5": "bcc6a04e498020ea55cd59003a621de4",
              "sha1": "3cb0032f5c58f11635a4e0075fe950a88eab6a3e",
              "sha256": "152e68fec76cad6122df36ab848a948a0b05829f89509cdf96167515e254176f",
              "sha512": "93c96b5668a1c557cc7f26634f242160c55e5bd2129b49575f2a231c7f7ffdb475b55fa8d5c922bed06fafb4738677c9dd7ea3a57499cc12a434635a8a02bb3d",
              "rh_hash": null,
              "ssdeep": "384:UpcWEhWkQim0GftpBj3jLaQHRN7sJlmTWFvu:Up6FfVi1LLMG",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1CD923B95CABC9443EDD2AD7063A4ED837D3DA7C31C30452A1199F6A91C837D5EB24A2C",
              "sha3_384": "d429a45e549f1c5a4d16f8538452b95df35d46cdb913a6baeb1694e0b5ed1dd6fe5bbd69a67ea76a5f1d425155916f68",
              "data": null
            },
            {
              "name": "a37b86176f50e1956cd1c8781c7ac12c3c210e7e28346905760e93792a875441",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a37b86176f50e1956cd1c8781c7ac12c3c210e7e28346905760e93792a875441",
              "guest_paths": [
                "api-ms-win-core-file-l1-1-0.dll"
              ],
              "size": 22912,
              "crc32": "C33CAED3",
              "md5": "13d361689aa36fb4c5c88fdef46cd13c",
              "sha1": "cf492ac78d6502cdeeaa91886a2b925ef9abfe4c",
              "sha256": "a37b86176f50e1956cd1c8781c7ac12c3c210e7e28346905760e93792a875441",
              "sha512": "ccc311c2056faa7d6fd704694dd59d255aed5f1fc903f55ad0e79a465240e58136b86f4d983a63e2b62285357746ea0d22d7c269b7ad58ec999562bd70d9ed63",
              "rh_hash": null,
              "ssdeep": "384:/PvVX3WEhWtYBm0GftpBjhnaQHRN78klD+8V:/PvVXXNVinL8aZ",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T154A21897C9B8E64BFCCB9D7022A5C8836C39C3C3082055961699E7AD3CD33D6E76895C",
              "sha3_384": "fe610e033f8cab4296651401c60dc916e05e68e5cef19e7bfcec640acba92491b3dd59e1b9247389dd807284626440c1",
              "data": null
            },
            {
              "name": "94c41ef05c4cd7fd0e7b0266b8be5e2aef4aedec704428ff8f82712b71747ade",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/94c41ef05c4cd7fd0e7b0266b8be5e2aef4aedec704428ff8f82712b71747ade",
              "guest_paths": [
                "api-ms-win-core-file-l1-2-0.dll"
              ],
              "size": 19328,
              "crc32": "FFBE8CAD",
              "md5": "4c544e7466420b46c91886c58ce90537",
              "sha1": "2efc27c43f0c2abbdb1a14ca61c19f093a706dc2",
              "sha256": "94c41ef05c4cd7fd0e7b0266b8be5e2aef4aedec704428ff8f82712b71747ade",
              "sha512": "6698943055e360166c669b33ec090ffd5811008c94b2dcd9ba90c1a16f0fb611cb3c1cba47345cda4cd995ec50054b5b6797a688c9fdf12e4237f70b25154747",
              "rh_hash": null,
              "ssdeep": "384:fWEhWHk4wm0GftpBjm0hJaQHRN7JdHlD16SWe:PpFViRJLD7",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B8922AD5CABC9583DCD3AD7063A8DD87BD3DE3C31C20991511AAF5D928833D5AB24A2C",
              "sha3_384": "f20c737658b611507b6430c252c2a7a246d58e37f9e17152becc814337e4b789de7e935f7f34ac02ad0a4eb588ad7454",
              "data": null
            },
            {
              "name": "738954850c4c70a6336ed856824504c3042767e13ab10cf9ca463a3f3120c2f4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/738954850c4c70a6336ed856824504c3042767e13ab10cf9ca463a3f3120c2f4",
              "guest_paths": [
                "api-ms-win-core-file-l2-1-0.dll"
              ],
              "size": 19328,
              "crc32": "ED24C679",
              "md5": "b87db0d6cac805263604d4733968f786",
              "sha1": "546ab87ad8999587062b8aafcda403b03459bcd8",
              "sha256": "738954850c4c70a6336ed856824504c3042767e13ab10cf9ca463a3f3120c2f4",
              "sha512": "044fde5f01dc496cca9ed03cbb972ea357f2b91544d4e702fba2e98178c27771e644d0dd0c775c1c359199bc2221764632377ca7d1533d1153a5a115199dfaf7",
              "rh_hash": null,
              "ssdeep": "384:w3WEhWKFm0GftpBjHIkaQHRN71IRjl9/A:6vVi6kLal",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1219219D5CABC9083ECD39D7053A4DD877D3DA7C30D20852A1599F6A92C833D5AB14A2D",
              "sha3_384": "0daee254acc488ec011654b20b37e0338eff889531091f6997d082a3262eed32d8e530a2af4fb3835768e619f8cbb037",
              "data": null
            },
            {
              "name": "91b572a3154013dbd80a4dedf12e25363d9ba39da4aed6deafad5d345d0fa927",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/91b572a3154013dbd80a4dedf12e25363d9ba39da4aed6deafad5d345d0fa927",
              "guest_paths": [
                "api-ms-win-core-handle-l1-1-0.dll"
              ],
              "size": 19328,
              "crc32": "504BE558",
              "md5": "6005c8a956b0d4fc10a00925ac61f778",
              "sha1": "e45901a43aaf06677d5b4494a5204fccc03106b8",
              "sha256": "91b572a3154013dbd80a4dedf12e25363d9ba39da4aed6deafad5d345d0fa927",
              "sha512": "11449c843143bc4f398c0b66f837cd4ec558a98d626852b3c6085d7fb231649ba64d52016b02b8681af4d6267c856777ff28a9945b7791841239bcfe5e34f756",
              "rh_hash": null,
              "ssdeep": "384:LWEhWM4wm0GftpBjjWysaQHRN7llDlDlH:z1FVi5ZsLlljH",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1BD922AD5CABC9443ECA7AD7063A8DD93BD3DA7C31C20852A04A9F5D918C37D5AB14A2C",
              "sha3_384": "21ce3f3d973090b9ef960b36cc3a11efab56f405b5c4e9d96b56609306833d0bb91b6489f6ca2893214943e3974401ef",
              "data": null
            },
            {
              "name": "d56715940211c98eb467ca903f12422a2674cfd621f089b388b830ea2875c310",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d56715940211c98eb467ca903f12422a2674cfd621f089b388b830ea2875c310",
              "guest_paths": [
                "api-ms-win-core-heap-l1-1-0.dll"
              ],
              "size": 19840,
              "crc32": "8684AFA4",
              "md5": "fc375ad99c56c43ee8e31eaef4776be9",
              "sha1": "b7290831331f9ae666a06088c8c9c3cbc0120d3d",
              "sha256": "d56715940211c98eb467ca903f12422a2674cfd621f089b388b830ea2875c310",
              "sha512": "ffcb49a86306f1b2e335473fc493264cacb387cbb9a12c562f93e34f5cf2489c79659148ed1002b4c7093759cdc97d363a3d2f212f7cc1605c051cabe3790bd1",
              "rh_hash": null,
              "ssdeep": "384:UlCWEhWcQim0GftpBjIPKaQHRN7iTlD16SL:31fVi+PKLS",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T138923BD9CABC9543ECD6AD706398DD877C3DD3C31D20851505AAF19928837E5EB38A2C",
              "sha3_384": "824772b747b50f07076a8b216c52e7ff349f094766f393f200954d53424325bdc92ad71c0a3c427568c1c03cc5667b49",
              "data": null
            },
            {
              "name": "d08c20328fd272f1dc800d07a8335d8c0e77a57f023c35d7f6383bef11a0ef94",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d08c20328fd272f1dc800d07a8335d8c0e77a57f023c35d7f6383bef11a0ef94",
              "guest_paths": [
                "api-ms-win-core-interlocked-l1-1-0.dll"
              ],
              "size": 19864,
              "crc32": "39C42A5B",
              "md5": "57b415b4bbf62963a5b7da7306d205e1",
              "sha1": "a348a1a5b0540d66aa746d08e5747b79f26fed3e",
              "sha256": "d08c20328fd272f1dc800d07a8335d8c0e77a57f023c35d7f6383bef11a0ef94",
              "sha512": "73a51325d0a4c7bb59ce77dd5975156a052a7dcb9c369fd72cae749add1063842074484165adf6c4df0f494ae67925c80499a2fcfc47b594e9dd29821612e5ed",
              "rh_hash": null,
              "ssdeep": "384:7lYsFGWEhWeJsngm0GftpBjd1u5aQHRN7ZolDlKp:EEngViNsLZII",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T185923985CAFCA043EDDA9DB013A8ED837D3D97C31C104526069AF69D18C77D5EB28A2C",
              "sha3_384": "212f6d1a2cf3a4bd7feb0f044c380ebd2e68b2cd1943d328792cdd90353fa2d4d54535766f48aa02868185b1c229c7c4",
              "data": null
            },
            {
              "name": "5dc62878d3a30d980bb1f33ca64955f2bafdcc888b90ff56d620feb0e0dfbf7e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/5dc62878d3a30d980bb1f33ca64955f2bafdcc888b90ff56d620feb0e0dfbf7e",
              "guest_paths": [
                "api-ms-win-core-libraryloader-l1-1-0.dll"
              ],
              "size": 19872,
              "crc32": "0A14F551",
              "md5": "801634734d526efa374ea58c7ba29725",
              "sha1": "7d80a667eea30fccaf4a7fb48054b61e8924cebe",
              "sha256": "5dc62878d3a30d980bb1f33ca64955f2bafdcc888b90ff56d620feb0e0dfbf7e",
              "sha512": "d1361bc56c992c81058aa881ed0377c01519133ef4d1b7bfe9df29b70b98928646c3b224b7a94d404fac12dd975728bf9790d77ea0aa411b2dc74f820b89a5dd",
              "rh_hash": null,
              "ssdeep": "384:bvuBL3BWWEhWTQim0GftpBj40FQ+SsAaQHRN7tglJ2wHOjJa:qBL3BMqfViakYLeFONa",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B8922AD6CABC9403E8D6AD7063A4D9877D3DD7C31D21982514EEF6A81C933D1AB14E2C",
              "sha3_384": "f6278c4275026748dc1f820e06d04c410205020d310c02c9ac22ab3783e49eb01578463baa08533d2d459a70fd364c93",
              "data": null
            },
            {
              "name": "bcfabb053d831a2b4c640144bf5064839477ff9f9e36864cb638ab7d43cf8c44",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/bcfabb053d831a2b4c640144bf5064839477ff9f9e36864cb638ab7d43cf8c44",
              "guest_paths": [
                "api-ms-win-core-localization-l1-2-0.dll"
              ],
              "size": 21920,
              "crc32": "A4E565A7",
              "md5": "18cdededc9e9ba62eb83498baffda43f",
              "sha1": "8be0f10bc91eb5cfa8ea9aa86894f8e1972c8264",
              "sha256": "bcfabb053d831a2b4c640144bf5064839477ff9f9e36864cb638ab7d43cf8c44",
              "sha512": "1a95cb7c7e9b0ae0b145442a3aa5d304bc1abead51392b482872276ee3cc5f85aac0aa70eea8945e4e728cca3339b3640669ba6c944aa600aceb58929db2206f",
              "rh_hash": null,
              "ssdeep": "384:fOMw3zdp3bwjGjue9/0jCRrndb9WEhWI4wm0GftpBj3taQHRN70TlPFz6:fOMwBprwjGjue9/0jCRrndbltFVihtLz",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T195A23A96C6BCD647EC8EDD707265D9437C3CA3C60C21992612E6FB6928D33C5E76062C",
              "sha3_384": "5a0c031d17dac157519393bcad92c0defdd5764c49c64e3f09d078e35e9d5b6826784061a034f20c27be43603ef7dc1c",
              "data": null
            },
            {
              "name": "ed9148179d3f58984bb46a6e28841d104e4023c62941dbcb12d6462c9405f671",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ed9148179d3f58984bb46a6e28841d104e4023c62941dbcb12d6462c9405f671",
              "guest_paths": [
                "api-ms-win-core-memory-l1-1-0.dll"
              ],
              "size": 19848,
              "crc32": "D229E7CA",
              "md5": "16b2a3490e36ef9d2b2899c9f13de738",
              "sha1": "a07dade597dd419aec1abe71cd3264188e50308a",
              "sha256": "ed9148179d3f58984bb46a6e28841d104e4023c62941dbcb12d6462c9405f671",
              "sha512": "09ff5c935a3be790c564c82dbcb3cfc7aef09ada8249d33c4d949c63b764085fff29cedd954c8eca44b797808b0ffc36c016508a513faa131e182a41cc93623a",
              "rh_hash": null,
              "ssdeep": "384:oj5WEhWSsngm0GftpBjftJaQHRN7h0lmTWpIN:od+ngViptJLhj",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T183923A88CABC9403EDD3AD7063A4DE977C3ED7C31C20542615A9F5991CC33D5AB2492D",
              "sha3_384": "7e6c3098e2f86019cff695ead53a15b164e05b804e0ca2e8230f85553dd3b3af53f0a3761685ae5e8bc2fe3090fffcfe",
              "data": null
            },
            {
              "name": "0d5c3ee2da18580d40bf25150bcb0ba1ef1cb81da6acc7ae2ec26064be29b3c8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0d5c3ee2da18580d40bf25150bcb0ba1ef1cb81da6acc7ae2ec26064be29b3c8",
              "guest_paths": [
                "api-ms-win-core-namedpipe-l1-1-0.dll"
              ],
              "size": 19344,
              "crc32": "C9CD0951",
              "md5": "a7c061c903ceb0588591358a96600975",
              "sha1": "7e0e62647b373d79be9cdc5701fe447bcd2a8af7",
              "sha256": "0d5c3ee2da18580d40bf25150bcb0ba1ef1cb81da6acc7ae2ec26064be29b3c8",
              "sha512": "68d27ccaed177ea8d32af9bf763428366398c77e15f5a46c0b2c7edd7e60e24af61bf0a1b5532c94847f95b44cac07d4d0874175051b68044ac8a78d50b8cd05",
              "rh_hash": null,
              "ssdeep": "384:9WEhWZ5OZkum0GftpBjJMx54aQHRN75KqlJ2wHOjG:lyoVi0kL5K2FOS",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T126923B958ABCD443ECD7ADB023E8D9837D3DE7C31D109525109AF9A81C833D5EB24A2D",
              "sha3_384": "1df349eefda2e67405dd7ac37cffef6c3f63335d946331ff4a29ee5ae9cfbeffeef345b4d593e448315c8d59da20f563",
              "data": null
            },
            {
              "name": "0cbd2b277689fd7f3738b51eba51496cae50f1984b07355543186c9ba2e30a33",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0cbd2b277689fd7f3738b51eba51496cae50f1984b07355543186c9ba2e30a33",
              "guest_paths": [
                "api-ms-win-core-processenvironment-l1-1-0.dll"
              ],
              "size": 20400,
              "crc32": "A618D3AE",
              "md5": "4d177965cb8b11b4cf3d8b6f17e31b0e",
              "sha1": "8106b381e792e2a541da4bf32ab3cdd569810c25",
              "sha256": "0cbd2b277689fd7f3738b51eba51496cae50f1984b07355543186c9ba2e30a33",
              "sha512": "b69db7e3a6ceddc2997406b05e50cd17b420bb27d9d722fefa9661895a04246939b5d7b827bc4205c69bc6ba06cfe10eb54a804eb7dc0a95a15276356b9aad19",
              "rh_hash": null,
              "ssdeep": "384:JLWEhWlXRm0GftpBj7Mx50UHaQHRN7YJzMlDl0nH:ZSVimHLH0nH",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T155924BD5CABC6103EDC6AD7052E8E9A73D3DD7D31C20442A01A9F6A92CD37D1EB14A2D",
              "sha3_384": "1cad21d086fe00e01c2578db33c79054bdb4c1e773657d40c6d4624287295da22ca29bf112991d91fcdc7a295d2a8115",
              "data": null
            },
            {
              "name": "f29961ffa822d4ed3455b2561b35c346ab5f52365a312bdc081b625763c9a9f2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f29961ffa822d4ed3455b2561b35c346ab5f52365a312bdc081b625763c9a9f2",
              "guest_paths": [
                "api-ms-win-core-processthreads-l1-1-0.dll"
              ],
              "size": 21408,
              "crc32": "3CCD4037",
              "md5": "ac2ca1f32a845b679389c2cd46a19abf",
              "sha1": "fbb5ff26cbdcd0733725576edcd0acdff5236303",
              "sha256": "f29961ffa822d4ed3455b2561b35c346ab5f52365a312bdc081b625763c9a9f2",
              "sha512": "9207565bc1d41c939b47ffe695f639c47eee539213d9c7dc405eccd7fc351e73aa43648cadb69a8947fe9af61df5ccf27c518602b32c587244a41f0a5199d5d9",
              "rh_hash": null,
              "ssdeep": "384:tTk1JzNcKSIpWEhWnvm0GftpBjPMr/7SaQHRN7jbltA6:QcKSwgVii3SL9",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T165A22BC5CABC9583ECCAAC702294E9937D3ED7C61D31452505A9F2E92DEB3C1DA2852C",
              "sha3_384": "356f3596a762cfb5be37961334ad399e73f042f01d2bb6dbd4ecf6776c6d72cb5740d6f700b9788dac6023b07e0bb615",
              "data": null
            },
            {
              "name": "cd78cd4201b599f79ea0523df309ef902a3312366b1991c4e4115cc6b86341aa",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/cd78cd4201b599f79ea0523df309ef902a3312366b1991c4e4115cc6b86341aa",
              "guest_paths": [
                "api-ms-win-core-processthreads-l1-1-1.dll"
              ],
              "size": 19872,
              "crc32": "33A9DE18",
              "md5": "33ee00d951da4901651e484537fce714",
              "sha1": "533a6aeab9ead127fd5c02fb4e94f21371750b1a",
              "sha256": "cd78cd4201b599f79ea0523df309ef902a3312366b1991c4e4115cc6b86341aa",
              "sha512": "6d98c03d04a1d13283fc730f56a8bb463a22e55ccda1f259bd07f5b7a3540ec0123ee414d05c6546284f7a9d72c28f04dc9063cefa8e3c5f7ecc04099cb79591",
              "rh_hash": null,
              "ssdeep": "384:ODfIexWEhWX5OZkum0GftpBj+BtaQHRN7PRltARzf:ZehooViKtLy",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T114921A85CABC9543EDD79DB063A8ED877C3EDBC31D304525006AE1A82DD73D1AB14A2D",
              "sha3_384": "acda1c61490f35f7e4ca9db7dcae36800eacb846cdff50b90dec5587db994e23777a24283b7de9dd85d51aaa09c96ac8",
              "data": null
            },
            {
              "name": "db3cbfe85048935037bff1943670039b6cf0e4f23989bada8a239a967b60eed0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/db3cbfe85048935037bff1943670039b6cf0e4f23989bada8a239a967b60eed0",
              "guest_paths": [
                "api-ms-win-core-profile-l1-1-0.dll"
              ],
              "size": 18824,
              "crc32": "EFA3C2CF",
              "md5": "b6d759e5bfc02ca24a1e6d465220d1bf",
              "sha1": "855dfa88f32d61016aa135a861b4dae51707dd22",
              "sha256": "db3cbfe85048935037bff1943670039b6cf0e4f23989bada8a239a967b60eed0",
              "sha512": "b44b6e9a6aed05e5aa6897a264813fdb35e129210202f0ca6d0e4b048349f60aeec0ce682a084231e0cc4a188a7cd2f8580aa606eb8c43f8a994d63093e6374a",
              "rh_hash": null,
              "ssdeep": "384:n+uWEhW1vm0GftpBjI++aQHRN7ElJ2wHOjc3:taVi/+L4FOe",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19F822996CABC9403ECD3AD7063E8E9937C3DE7C31D20552914A9F6D918837D1AB24A2D",
              "sha3_384": "ddf799dc9145daf728a21e4dc559710f59d297e7248a009a1381bb26237537fefabf0f4235a687da0c861ec8ec8006f1",
              "data": null
            },
            {
              "name": "168b83fff028a6155e005a75373ace9e123a1f9ddb79131519bf3f6197656502",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/168b83fff028a6155e005a75373ace9e123a1f9ddb79131519bf3f6197656502",
              "guest_paths": [
                "api-ms-win-core-rtlsupport-l1-1-0.dll"
              ],
              "size": 18840,
              "crc32": "22E401D6",
              "md5": "7fc3111ec531ef8f5697bac63e6dd4e5",
              "sha1": "f3564bf2b3c5e56445f2b7cca07cc8da9aeac89a",
              "sha256": "168b83fff028a6155e005a75373ace9e123a1f9ddb79131519bf3f6197656502",
              "sha512": "8617ca22c1043d6d07b7cfe634033d1371942aef7694b105d1b2e6c77e10b50d0422582b026ae4574789a9fd5b2d583093827199053f6203314234e9483225ad",
              "rh_hash": null,
              "ssdeep": "384:DGdWEhW0DzDm0GftpBjug5aQHRN72HltA:DGF/VizL",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1878229D5CBBC9543EDD2ADB013E8ED97BC3DDBC31C209526145AF1A918833D5AB24A2C",
              "sha3_384": "beb265812ed6bde3f28bb7b5b04c5999bcc30196baee79e98bb87b295ca0b13419314cc17a1969d806135bf5e1317c04",
              "data": null
            },
            {
              "name": "2f3dcfa63b4cd2837a4dcd7b2f9ff341a344e187b6669c52991391f4803ff9b9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2f3dcfa63b4cd2837a4dcd7b2f9ff341a344e187b6669c52991391f4803ff9b9",
              "guest_paths": [
                "api-ms-win-core-string-l1-1-0.dll"
              ],
              "size": 19336,
              "crc32": "A32ECF44",
              "md5": "c3c1c9e409eb61bd76e68955c1cbd1c8",
              "sha1": "63ff89d0ae0006ebeceabf971dc65588239f1fdf",
              "sha256": "2f3dcfa63b4cd2837a4dcd7b2f9ff341a344e187b6669c52991391f4803ff9b9",
              "sha512": "f3f45f5007b366589b6e64ef1a52035374bed8033a0dc98f45398392bc650880abf689382286c066694323a93e8534969d9ad8d56abe7b74d9411fd27af6f344",
              "rh_hash": null,
              "ssdeep": "384:pyMvxWEhWUzDzDm0GftpBjbmnaQHRN70lmTWB:pyMvhrViFmnLe",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T168923991DBBC9403EDD6ADB023A8ED977C3DD7C31C2085660099F1992D937D5BB24A2C",
              "sha3_384": "4ca4337e5ac13d7da87cbcfad33e3fa924049441c47a033293a2fe602455cb8dc60c1d9802f4fbd155b7d312ac5209b2",
              "data": null
            },
            {
              "name": "76478e2dc9f350fcc5aeb9f86b4c73e66f34199df964a7eaafff5d11d21837ae",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/76478e2dc9f350fcc5aeb9f86b4c73e66f34199df964a7eaafff5d11d21837ae",
              "guest_paths": [
                "api-ms-win-core-synch-l1-1-0.dll"
              ],
              "size": 21376,
              "crc32": "C5396C45",
              "md5": "231f059a3134912289eba810b9573484",
              "sha1": "e8c2b6cbada7eba4e13e77e854390782ffdc0589",
              "sha256": "76478e2dc9f350fcc5aeb9f86b4c73e66f34199df964a7eaafff5d11d21837ae",
              "sha512": "20c463d7c135f9f0c7ce8d77448176d8b1d127c6ce47a9d6a4a103bb99a034a319116151f01086a3f6b9ee54e0e7e974316214cf36b49efff4668d572fe02b2f",
              "rh_hash": null,
              "ssdeep": "384:sdv3V0dfpkXc0vVa3WEhW2YBm0GftpBjVIaQHRN7J0LltARo:sdv3VqpkXc0vVaXEVifILJg",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T148A22A86C6E8A543E88BDD7052E9D9837C3DD7C31D3089261099F6A93DE33E1DB2852C",
              "sha3_384": "ab88809751b3a14f3c0bb5b388bc6ba3a5ecdfd73c5eb4c96c4fb3ff3484a2b5703cb2f45ce683efd2d4888f8d5eb9f5",
              "data": null
            },
            {
              "name": "bbe2c936a6682ca1f653b9fb3956be78bd5ed37acf8395b877aac2059e605590",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/bbe2c936a6682ca1f653b9fb3956be78bd5ed37acf8395b877aac2059e605590",
              "guest_paths": [
                "api-ms-win-core-synch-l1-2-0.dll"
              ],
              "size": 19840,
              "crc32": "BF06FD14",
              "md5": "8eb2c078c048844d51b73578440ebdfe",
              "sha1": "9f6af830be62f2a159e8e8487eb437688413829b",
              "sha256": "bbe2c936a6682ca1f653b9fb3956be78bd5ed37acf8395b877aac2059e605590",
              "sha512": "b3d226a41aab0079e159bae99152f577cf272df7ed3083a6dab5f0a28be670cba0b78c58bdb4aa7f0893921cf324fbc290ba6e53f3fe71f16ddd9e7053ed7294",
              "rh_hash": null,
              "ssdeep": "384:2tZ3gWEhWs5OZkum0GftpBjKffmaQHRN7TdltADP:V3oViueLEP",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1AA922AD6CBBC9603ECD6ADB053E8D9837C3DDBC21D205925116AE1A92CD33D1DB14A2D",
              "sha3_384": "46ca0a21278951b4312ab91e66f12ea1dc0956cc54258bc1bd1198f429dfced0c21775ce79d06e4c238baf0328f1250d",
              "data": null
            },
            {
              "name": "668b38e604e03071352e10ec0ecec25a064e91a5e9925d765a8a67b86a382bf6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/668b38e604e03071352e10ec0ecec25a064e91a5e9925d765a8a67b86a382bf6",
              "guest_paths": [
                "api-ms-win-core-sysinfo-l1-1-0.dll"
              ],
              "size": 20360,
              "crc32": "27D45D89",
              "md5": "027c2c30f88520e466ece876ac28a05c",
              "sha1": "241457e72a2f92e82b42636ac6174cd5a4d106fa",
              "sha256": "668b38e604e03071352e10ec0ecec25a064e91a5e9925d765a8a67b86a382bf6",
              "sha512": "c7a0300fd6b39fa00f5501472788bc600927c6d48d81b5e326b5737b9ab6638b8294fec838f983945f225471dac2ca6d0522770b598ea97ca161cc98bced7950",
              "rh_hash": null,
              "ssdeep": "384:0gPUZWEhWQ3szm0GftpBjS/NEaQHRN7olDlG:0gPUZT8zViU/NELIG",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A0923B96DABCA103ECD65E7022E8D9837D3DD7C31C21852E01DAE6A92DD33C5EB2452D",
              "sha3_384": "63d91120e3552ecca4510e659b0d495f7dfc214d781679150a1d3de061a9b8cc7a2d53c2f35656a55a6a91b7e66dbfb6",
              "data": null
            },
            {
              "name": "0af8caa08ab824e06dadf0e6aaefbf383fe0d283c2c0eae0421cf3647d466cdc",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0af8caa08ab824e06dadf0e6aaefbf383fe0d283c2c0eae0421cf3647d466cdc",
              "guest_paths": [
                "api-ms-win-core-timezone-l1-1-0.dll"
              ],
              "size": 19344,
              "crc32": "26D50840",
              "md5": "d5d58ddaed6856ad7a33389a4024618c",
              "sha1": "75806570e99f3983b7bca6410b06ec2d59a4685d",
              "sha256": "0af8caa08ab824e06dadf0e6aaefbf383fe0d283c2c0eae0421cf3647d466cdc",
              "sha512": "a2f3332d16656cdc4659eae708164fe7e4c7e7e1c3385687d7cee3209fc92985834f88d43cb4fe84dc43715daecec6dc854629fbcf40a7d20ba05f5a23af1458",
              "rh_hash": null,
              "ssdeep": "384:7WEhWosngm0GftpBju5voBaQHRN7pIl9G:DUngViqvoBLpV",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16F921899CABC8043ECD79E7053E8ED877D3DA7D31D209526049AF5A92C833D5EB2492C",
              "sha3_384": "a97c40779017cbdcf89b4fe15a73661e90cf4530eff1ce415f976388feeebaf768d63e018e9b4ec2711fec72edf97cd6",
              "data": null
            },
            {
              "name": "1f7e83fd55e191d4ad152a07b6b763d30fb071d102c47f3c6ddfbed17e5ee398",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1f7e83fd55e191d4ad152a07b6b763d30fb071d102c47f3c6ddfbed17e5ee398",
              "guest_paths": [
                "api-ms-win-core-util-l1-1-0.dll"
              ],
              "size": 19320,
              "crc32": "57266B15",
              "md5": "4b804285d49cd882756b1ee73da6db31",
              "sha1": "b738e170fecc27eb222a5282d71b94ab6e1e49e7",
              "sha256": "1f7e83fd55e191d4ad152a07b6b763d30fb071d102c47f3c6ddfbed17e5ee398",
              "sha512": "f47426012cc1e51f73ed55b3c4ad6f4f7d5758b4e43e2dfa500309c1c774c8698192a2613563ca2d7b3daeec680f8cc6594432f0c679ae9d61080bb96a47fe5d",
              "rh_hash": null,
              "ssdeep": "384:vWEhW44wm0GftpBjAaQHRN7DlJ2wHOjwZ:/BFViyLPFOsZ",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B78229D68AFC9443ECD3AD7063A8DD837C3DE7C30D2055261499F9991D833D6AB24A2D",
              "sha3_384": "5d14fa35af58b1dd4c5aa1e92b436f7afa55f17d0cf1a902f13f6b1424d15639cbd235538e7e28a4705873dc9ca9028a",
              "data": null
            },
            {
              "name": "593dc1d408dd781f381fa7474c15f9e47e7d82bcf1edb161bbe7d9823b9760eb",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/593dc1d408dd781f381fa7474c15f9e47e7d82bcf1edb161bbe7d9823b9760eb",
              "guest_paths": [
                "api-ms-win-crt-conio-l1-1-0.dll"
              ],
              "size": 20344,
              "crc32": "60CCC41B",
              "md5": "7c943a05dd6081ed08be7c164f63c81a",
              "sha1": "850b13b0c218616ae141ac2b33d4604f2418f35f",
              "sha256": "593dc1d408dd781f381fa7474c15f9e47e7d82bcf1edb161bbe7d9823b9760eb",
              "sha512": "3e98784b51fc1db1a2fef478296daa9f095ff0b6b182b97009766504f7cf40784779fd09e65d16bd3ce31c62b8854fa36959548f0c9026027dc1512603a77caf",
              "rh_hash": null,
              "ssdeep": "384:aj0WEhWWXRm0GftpBjOaQHRN7rWlJ2wHOjjTb:Qi3ViELriFOv",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E3922B9686BC9843D8839E70A3F4DAD3BD3D97C32D206525149AF4A428C37D6BF2493D",
              "sha3_384": "53edb97af638890464ed3ad03b0cbf74f3c4607bb52562f6b9d8d3520815c0bb14a057824dde2a9c5413515ab9dcf893",
              "data": null
            },
            {
              "name": "0715e20ca1ba34f1ecb8766952bd10140ea806a0f8eb21e2bee2ca00f9bb5a3e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0715e20ca1ba34f1ecb8766952bd10140ea806a0f8eb21e2bee2ca00f9bb5a3e",
              "guest_paths": [
                "api-ms-win-crt-convert-l1-1-0.dll"
              ],
              "size": 23432,
              "crc32": "79759187",
              "md5": "80fd476003d4cb6dc96930da5791eaa2",
              "sha1": "5b0ff5a5c4806f34e5146723c7d06e8488209c4a",
              "sha256": "0715e20ca1ba34f1ecb8766952bd10140ea806a0f8eb21e2bee2ca00f9bb5a3e",
              "sha512": "12b8e8c37358cf7de15764ccbf87c868346afd0ecf7179108a1da9a1ca24478100edab04bd4848d72d68f177e8c1e15e5aac2745b825d017e2dd48b9bc89bd2e",
              "rh_hash": null,
              "ssdeep": "384:nuyFWEhWkQim0GftpBj9URaQHRN7ElmTWx:j1fVi/iLe",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1ADB2098796E86E12E9CB5B7122FDDBD7293D878219204275C107E19C38837D1BE67C1E",
              "sha3_384": "9ea142bae62a869463451d75bf728a48122687995fd620645b48cf17c1da91113954183e4a34e4f4149e4da30efcef44",
              "data": null
            },
            {
              "name": "54d5599db9f6405641080a96d59a23eed26fe5e13b4dd4e2076ae0dd8f0cbfc7",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/54d5599db9f6405641080a96d59a23eed26fe5e13b4dd4e2076ae0dd8f0cbfc7",
              "guest_paths": [
                "api-ms-win-crt-environment-l1-1-0.dll"
              ],
              "size": 19856,
              "crc32": "B75854FB",
              "md5": "9fc02eb85a8b93876f85c23a5ae21146",
              "sha1": "d3ad6a4b3d111631b4b616f6e67209e959b11f5e",
              "sha256": "54d5599db9f6405641080a96d59a23eed26fe5e13b4dd4e2076ae0dd8f0cbfc7",
              "sha512": "40d159bfe4569eda28ced031e98a5e36b0d05e221647130211b2d40ffa5812055e45afcf47eb09f6c5fff8c61ddec2c4174fc203f6571ed714a1a0ef9d753c6d",
              "rh_hash": null,
              "ssdeep": "192:XPWEhWPQTVCEmCjdks/nGfe4pBjSbO7n0nzWAaAXcrMHnhWgN7aQW3zqQqnaj/6s:/WEhWUvm0GftpBjV0laQHRN7qltAg",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1099229C68BBC9543EDC7AD7052B8EE877C3DDBC71C205526046AF1982C837D5AB24A2C",
              "sha3_384": "7cca3bc8a0b70f18036389a550ba4a4044bdce60d2609dd10138772f0379f6cfd09ff35245d4ea4408ae417c30eb73b3",
              "data": null
            },
            {
              "name": "223b1e4f1e835c6fa78a6354b56ae5c2b818be06053eaaf1d3fbcb6730f055d7",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/223b1e4f1e835c6fa78a6354b56ae5c2b818be06053eaaf1d3fbcb6730f055d7",
              "guest_paths": [
                "api-ms-win-crt-filesystem-l1-1-0.dll"
              ],
              "size": 21392,
              "crc32": "8D4AD450",
              "md5": "a72d53a5a06a63c011b202d946f2bb9c",
              "sha1": "6f2a35ffafb826f3c8d740eb1768da7c08e53b27",
              "sha256": "223b1e4f1e835c6fa78a6354b56ae5c2b818be06053eaaf1d3fbcb6730f055d7",
              "sha512": "c2787566db8e0b43547afbf66dcdbeb57e4832ef0be7c7b2ea7e34e5791e078d719511d1f71e151326524e07e9a47a3cdcc368e8d63816d58cddce481b07ce9c",
              "rh_hash": null,
              "ssdeep": "384:lq6nWm5CdWEhWUsngm0GftpBjheZaQHRN7enlD16Sw9:c6nWm5CFkngViaLem",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DEA206978AE86D43DDD75E7162F8DBCB7E3D9782185289228017E1983AC33C17F2582C",
              "sha3_384": "075e90c88d67202734d838f74a835160cd079f8b98eb4489dc0504c9c8b26a17908e85ae6abeecfeff97e0fa3fc1660f",
              "data": null
            },
            {
              "name": "0db3755cda83d6dd540a4762d83bb6596b5b8eb22fa984084cae101ace5b26f0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0db3755cda83d6dd540a4762d83bb6596b5b8eb22fa984084cae101ace5b26f0",
              "guest_paths": [
                "api-ms-win-crt-heap-l1-1-0.dll"
              ],
              "size": 20344,
              "crc32": "8F0D0667",
              "md5": "49958e718479f927ec69f46858c18a54",
              "sha1": "30ff4a5d53f63b0861f3dc3dd8130b4351d42396",
              "sha256": "0db3755cda83d6dd540a4762d83bb6596b5b8eb22fa984084cae101ace5b26f0",
              "sha512": "dd1082e507654c73104a663dac236e6cb9da07b010da53101a8f04d398aaa0cafa5b9b652d8cba8ebabc2d1cf90bb175b2480f2c9d33468bbff6483612c19ebd",
              "rh_hash": null,
              "ssdeep": "384:0lWEhWSYBm0GftpBjnZaQHRN7jltAD6jN:0dkVi7LzR",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F7921BD6CABC9543E9D3AE7062F8DACB7D3ED7C26D204516405BF1A91C833D1AB2452C",
              "sha3_384": "546f423b5550e257acb6425b3aca6a15f784c87ad04d61185c5dd5c407fd3e36fc16930f1b41a96d0d3fca1483554853",
              "data": null
            },
            {
              "name": "0c86915d6e30121d461513dd699898067209c3e0a9c6c75f9c03cf9ca13e54c2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0c86915d6e30121d461513dd699898067209c3e0a9c6c75f9c03cf9ca13e54c2",
              "guest_paths": [
                "api-ms-win-crt-locale-l1-1-0.dll"
              ],
              "size": 19840,
              "crc32": "54B998DD",
              "md5": "57d7f66321780dadc8b6d5cd7672a6e2",
              "sha1": "436d27273134ec68b0f96df8e8e1ad8eef1ae67f",
              "sha256": "0c86915d6e30121d461513dd699898067209c3e0a9c6c75f9c03cf9ca13e54c2",
              "sha512": "25be4f2cef97fbb455570bdaeb66d6c2314b43fb9207eb8455a558735026adbae5aa6c133f56460ecdd2e401b68d3f9865def040c1feef91e9db62ba6034f07f",
              "rh_hash": null,
              "ssdeep": "384:sWEhWKsngm0GftpBjNwmlh2aQHRN7rltA+z2:qengVi8Ih2LLz2",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1AE922AC6CABC9543D9C39EB016B8EE87BC3ED7C31D214526119BF5A82C833D5AB2452C",
              "sha3_384": "b618bf9e6379ff64115f8612cc51f076a0779d0de7b5803bdf674c6775f5d45dd5d66e75fb081f045bfbc44ddb4003fa",
              "data": null
            },
            {
              "name": "e6a216b1eea2e507b65753fdff2df6d0b94791b317dd554acebd68de3e2adeaa",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e6a216b1eea2e507b65753fdff2df6d0b94791b317dd554acebd68de3e2adeaa",
              "guest_paths": [
                "api-ms-win-crt-math-l1-1-0.dll"
              ],
              "size": 30072,
              "crc32": "784F6980",
              "md5": "49a67884d183c9c00f72966250a09299",
              "sha1": "212f0eea140359f9e0b87eae62cf147e046da46f",
              "sha256": "e6a216b1eea2e507b65753fdff2df6d0b94791b317dd554acebd68de3e2adeaa",
              "sha512": "b79c85ee3e104b50594d39af99862c14091ba147290b6549e7fef3eda2c8c4e570082d4165deffed46fcab8c2d9907c97ee42e523928799f7bd944e94d690195",
              "rh_hash": null,
              "ssdeep": "384:c47isbM4Oe5grykfIgTmLKWEhWFYBm0GftpBj6ubgaQHRN7zRlJ2wHOj3:V1Mq5grxfIno9ViH0LhFOj",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T154D2C68789ECBF53D8CB1BB311F4CBCA6A385B9214A175B4D887E1C834927D47E5B908",
              "sha3_384": "77bbd592c96f8337538d629ebc079da5664d42b14d97ea59e7ad28029a67994293dec9750f7ebe89b11f1bb54ab73792",
              "data": null
            },
            {
              "name": "fb927f6ab27578cae0ef2b434dc05cd5e314405ebeed50ba4226f3f4a38fb4c1",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/fb927f6ab27578cae0ef2b434dc05cd5e314405ebeed50ba4226f3f4a38fb4c1",
              "guest_paths": [
                "api-ms-win-crt-multibyte-l1-1-0.dll"
              ],
              "size": 27528,
              "crc32": "5C3FDB95",
              "md5": "81d6d80c97c4221ce8904d081c0e85b9",
              "sha1": "ed7c6045e202eba8e1cbd0317942eed115e891b1",
              "sha256": "fb927f6ab27578cae0ef2b434dc05cd5e314405ebeed50ba4226f3f4a38fb4c1",
              "sha512": "57ffc87ed3b21484f88a9f58108c7f674ca587bbdf29bcaab07c6233b716ce3d08ac3e0bf65cc30dc315e06393da08f3c9ebd31c54579f6f2cf525af8a12bb49",
              "rh_hash": null,
              "ssdeep": "384:hy+Kr6aLPmIHJI6/CpG3t2G3t4odXLZWEhWhXRm0GftpBje42vaQHRN7lGT6lJ20:hZKrZPmIHJI6raViGvLaGFO2",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T134C2946B8EA86E12D58BD7F3B5F1C7C73A354F8104C07775A16B95883842BD9BD02E18",
              "sha3_384": "40cb0b2e435a19f1f7f035b7f2978be4954be3f4f2ac52aaa7a8c406a7f10febe5e718fb577565fdf3c566092ff63c75",
              "data": null
            },
            {
              "name": "ed823afdfff0f64760e9a647bcfb1a15472bc85dbd30a40a6921aac53883c5c0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ed823afdfff0f64760e9a647bcfb1a15472bc85dbd30a40a6921aac53883c5c0",
              "guest_paths": [
                "api-ms-win-crt-private-l1-1-0.dll"
              ],
              "size": 74112,
              "crc32": "A9F3408B",
              "md5": "da4cabd7fc5b4cf9c940dce9090b1da9",
              "sha1": "58ac2e659a1ab1edfa024ac5372679cf1248d159",
              "sha256": "ed823afdfff0f64760e9a647bcfb1a15472bc85dbd30a40a6921aac53883c5c0",
              "sha512": "09041c543da6749aa81e1d2e347238d8a0ee9a19b1f9993c205c49c90f0e37e2f342b8bd53e68b3cbf23028da84cecf89e454740d549792b8289e79e312f9c3b",
              "rh_hash": null,
              "ssdeep": "1536:Bt2b2De5c4bFX2Jy2cvxXWpD9d3334BkZnkPCcVHv:Bw2De5c4bFX2Jy2cvxXWpD9d3334BkZs",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T17A7329DB89E93F22E58FF7B367FB57C90B253A4418806170E9C7956B34853A9BC53A00",
              "sha3_384": "58411f029d2e55ca05a03714dd1f12322310a4398f9ed41e324ad879cb5c2e1b71c360462177b402f9fa19fffdd72ed8",
              "data": null
            },
            {
              "name": "03b6e46d829395180ebb5fcd0590c29b87268b9adb4991bcf61223178b3050c4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/03b6e46d829395180ebb5fcd0590c29b87268b9adb4991bcf61223178b3050c4",
              "guest_paths": [
                "api-ms-win-crt-process-l1-1-0.dll"
              ],
              "size": 20352,
              "crc32": "94282622",
              "md5": "751d02532639f01a28a6532c4176aa99",
              "sha1": "ac01926c7a0a8a40239e2b3fb5b0c807267cf73c",
              "sha256": "03b6e46d829395180ebb5fcd0590c29b87268b9adb4991bcf61223178b3050c4",
              "sha512": "01653920c54f66be9b57dad24b4c26a31ec5aaacd1a341b2c0a5ef6f3f3f6a921d41d30832214de171c0484ed53e85a993a31c26c882efe61726c0d65c49b721",
              "rh_hash": null,
              "ssdeep": "384:GK0WEhWzvm0GftpBjr5bJTaQHRN7QGjlDl7t:uIVifRLQc7t",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B3921987CABC5943D9A39E7052F8DA837E3F97C35C10852A446AF19D28833D5AF2492D",
              "sha3_384": "b9a38f8bcef8bdfca4c6104d95dfb86fbf122466157dd2de8fd1dc28310da27bca7bb040dacc1058aff0bfb785e45a94",
              "data": null
            },
            {
              "name": "e1db85780ff1abc4670d330ecc4e0b74e36d6f73791c8c7165522ea6967d621b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e1db85780ff1abc4670d330ecc4e0b74e36d6f73791c8c7165522ea6967d621b",
              "guest_paths": [
                "api-ms-win-crt-runtime-l1-1-0.dll"
              ],
              "size": 23936,
              "crc32": "169ECE9C",
              "md5": "06d5830a4e01f240b87391bcfe56d386",
              "sha1": "e1e193e4b0fbad53ff09f079fb9152ee18600ff0",
              "sha256": "e1db85780ff1abc4670d330ecc4e0b74e36d6f73791c8c7165522ea6967d621b",
              "sha512": "570fc23e6560b9e6a42af2512eeb023a19da8dea9ccdfde501e71cf0e266952a5dc8a1e57162638072a03bd0a5ba199c0f7fc27c0e1a8cf469c87453a346b331",
              "rh_hash": null,
              "ssdeep": "384:Bb7hrKwWEhWG4wm0GftpBjbVaQHRN7+vlJ2wHOjrj:BbNrK2bFViRVL+rFOHj",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B4B22A838AFC7E03D9836F7222F8DBC76E3A9382192055358457F4D829837C5BE1661D",
              "sha3_384": "8309a77276cf331d86d75457ccf8f2d993fb8734193c46ea7aedf8d11d15338e1f61f45ff9a4667086e141766d66a5eb",
              "data": null
            },
            {
              "name": "3b9665f3a7cbbdd75c900721ff974216da276cd5512502bb30204eb5fa73d084",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3b9665f3a7cbbdd75c900721ff974216da276cd5512502bb30204eb5fa73d084",
              "guest_paths": [
                "api-ms-win-crt-stdio-l1-1-0.dll"
              ],
              "size": 25472,
              "crc32": "00B746D5",
              "md5": "bb1fd3c87c6e278b361e0507a618dfa6",
              "sha1": "a22ff05627479a0e2d0cf8236fee5995e033c16b",
              "sha256": "3b9665f3a7cbbdd75c900721ff974216da276cd5512502bb30204eb5fa73d084",
              "sha512": "7ab2dc8cc612bb8827dd8ec8dc5d029fdef379cbdf9b24e12d557666e3f90a7e0468d716d08e42afabe0bc5a4af6606bb52db23995340a606a704c4a697f89f1",
              "rh_hash": null,
              "ssdeep": "384:RUFVhLWEhWOsngm0GftpBjWaQHRN7k7YltA:Gl+ngVikLk7",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T164B2F78785EC6E42D6878B732AF9FFDB6A398783281075398007E49839C63D97E1751C",
              "sha3_384": "513c5e2ba226e4881265a30b08f84b2aad01302df1218f8bc7e21557121dbd7bcdbbee265a4216af26f6211525258fac",
              "data": null
            },
            {
              "name": "6ba2eb804139a1102011c7a0e0909f11787cede4d4ff0a31916cc8329ed16bc3",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6ba2eb804139a1102011c7a0e0909f11787cede4d4ff0a31916cc8329ed16bc3",
              "guest_paths": [
                "api-ms-win-crt-string-l1-1-0.dll"
              ],
              "size": 25472,
              "crc32": "C355D581",
              "md5": "839eefc12f8d3bc6159c2f214da88e24",
              "sha1": "0f7e3040059b43c1c78743fd923a86bd45712fd8",
              "sha256": "6ba2eb804139a1102011c7a0e0909f11787cede4d4ff0a31916cc8329ed16bc3",
              "sha512": "8e47d75ff31c5fc1c66e9279ea6463fc312aa0377d10d4b83f23f7483fa96eac09dc6d27cea350be36a2f56fbbc2d8b28d744df9bfcc3e5776dc62399778c512",
              "rh_hash": null,
              "ssdeep": "768:T6S5yguNvZ5VQgx3SbwA71IkFUgViAXoLRI:Tl5yguNvZ5VQgx3SbwA71ILgVTSRI",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D6B2E94386F83F42C9CB5BB256F9CBC76D398F4715101275D067E59838827E6BE2A90C",
              "sha3_384": "d2e04fc99137899bf7ac5917e14bb765bb9d9d81fddb6bfb1f2fd7c96953e68ced9fbf24915fd9a389ff7e08b9e150bb",
              "data": null
            },
            {
              "name": "7178909221b256769cf8153e24926560b2e5c5dfe0e09fada8f55936c68dc67e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7178909221b256769cf8153e24926560b2e5c5dfe0e09fada8f55936c68dc67e",
              "guest_paths": [
                "api-ms-win-crt-time-l1-1-0.dll"
              ],
              "size": 21880,
              "crc32": "17E3C390",
              "md5": "ddcfe4dca06486a7412bc65e84dd0a24",
              "sha1": "155f7c19a20e19651f49bd4321a8b89f1567dd84",
              "sha256": "7178909221b256769cf8153e24926560b2e5c5dfe0e09fada8f55936c68dc67e",
              "sha512": "76c86d2263fdb6c6f5a066350ffb2f93167632fc35b03be5abe0a385474d8c480255c56af8d9ea48ac0ea6cd1a75f6c51f8cc2114ed1c959dcd6d84251229170",
              "rh_hash": null,
              "ssdeep": "384:LbWEhWR3szm0GftpBjfmMxHaQHRN7DBlDlN:/y8zViFTlLDtN",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T110A219838AE8AA07EDD74F7052FDDBD77F3997C21D50652A4056E49839833C4BE1292C",
              "sha3_384": "fa6f6ee20cf215b6490b1d6ddb7964f016f1a7b5ee3df8fca49eebc8aadd6a1f7db96a3f6ad44f3c68a21e73ee32d99b",
              "data": null
            },
            {
              "name": "c6df460fbc31f3f0476e8efbff5bc5f7e6d293dd43ccbee03303b2a501334073",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c6df460fbc31f3f0476e8efbff5bc5f7e6d293dd43ccbee03303b2a501334073",
              "guest_paths": [
                "api-ms-win-crt-utility-l1-1-0.dll"
              ],
              "size": 19848,
              "crc32": "F94F1B9C",
              "md5": "f36e96525f2777c8c204ce575ed4a985",
              "sha1": "74bf396e8f7d28655bc11ac7b9d598a25d529db3",
              "sha256": "c6df460fbc31f3f0476e8efbff5bc5f7e6d293dd43ccbee03303b2a501334073",
              "sha512": "4bb9765fd59d58827e28d46c0041f3350401a77244845791a4786fdf6f16a3e31596bf8fc490d0e803d6a54d341c4413ac545e963f6c1a6a300047704b8151ed",
              "rh_hash": null,
              "ssdeep": "384:FfhWEhWZYBm0GftpBjx/4aQHRN7HlmTW2:Ffx1ViEL",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T182922A968ABC6403EEC76EB053F8DE877D3D97C31D208526409AF59928837D1FB2492C",
              "sha3_384": "3b236a89a4ee30287f693e395a7b8094ea0e122cf327b519bce65bab9539e5738d9d4b3b3bee45b9e0c7c7bf2cb569ee",
              "data": null
            },
            {
              "name": "bab3e5405eb8c06891ee3b436e0e69c0ef855042aa1871bd9189dfd2caa2b416",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/bab3e5405eb8c06891ee3b436e0e69c0ef855042aa1871bd9189dfd2caa2b416",
              "guest_paths": [
                "Apollo.png"
              ],
              "size": 2345,
              "crc32": "E1CACA96",
              "md5": "0bf2527c5a2fd87035c1341742f17523",
              "sha1": "6d917e0e8a459d218465ba262f0a86d9ef00c12f",
              "sha256": "bab3e5405eb8c06891ee3b436e0e69c0ef855042aa1871bd9189dfd2caa2b416",
              "sha512": "74d9b2ed3df2bc9ee6072910245c2d6fdf688075765615677a83a36846a0566a4665dc5b63f418e4cd719738970326af292f4c0fe5d5add459fffd65d20f8ef0",
              "rh_hash": null,
              "ssdeep": "48:rOivRyaM+63qLS2wPKzDhmwdmrjF3F8IJSagwRE9nOUWV1n3:KyMjqb2oFdmrjdjhEgUWvn3",
              "type": "PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16E411B7EEAB2671A7A50587B8CC1CA4AD8A7D8071D568B46960809F1C1FC6797073382",
              "sha3_384": "cab0181c4ef43b171d33019cbd38f1f056ebd0b7f5d9486d728500c8911341a58711cf431ca766b60f6e74629b418736",
              "data": null
            },
            {
              "name": "0da21ce907fa2a416f7b624808b94ad3385bda5a7e7b4044c146475f14bb3edd",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0da21ce907fa2a416f7b624808b94ad3385bda5a7e7b4044c146475f14bb3edd",
              "guest_paths": [
                "BrowserMonitor.dll"
              ],
              "size": 64312,
              "crc32": "9C144756",
              "md5": "17ffb7e16c4cc858f25d0a16d2965f19",
              "sha1": "2fa3ddb164f03427e2d9e98528a4059b0aa8783f",
              "sha256": "0da21ce907fa2a416f7b624808b94ad3385bda5a7e7b4044c146475f14bb3edd",
              "sha512": "cb97b90784d1563edaa0799093aeffb4a7bb7b583f9e57e370110e03426ed772d2fecfef33c83d5bd5e770b6ac49a7bcba2732bdd637362adbf8079fa69df197",
              "rh_hash": null,
              "ssdeep": "1536:BheSzN7TkGHNq/+CS14A78P+nnS15JrBxYDGL7fix5O:/eg7TkGHlCc78PBJrBxYDGL7V",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13E536C46FF0051B2F6CD0370399AAF3A043DF5386BF141C3AFAA093E59616F16A3560A",
              "sha3_384": "01ed5c15506121c819899946d5f65b42d2ce45d114e90217262493f216d883878d942806d58b86243739a25e3d5f50c7",
              "data": null
            },
            {
              "name": "97d5234a311996a6249c2c25468bd49454141525a06c7a8b648cc9e2ebfeb414",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/97d5234a311996a6249c2c25468bd49454141525a06c7a8b648cc9e2ebfeb414",
              "guest_paths": [
                "BrowserScv.ini"
              ],
              "size": 273,
              "crc32": "F1F88A27",
              "md5": "0d176c6404cc4431c00f084918010bef",
              "sha1": "414e338b9bcb5fb64419048e0a7391a8e5461a39",
              "sha256": "97d5234a311996a6249c2c25468bd49454141525a06c7a8b648cc9e2ebfeb414",
              "sha512": "185cf9c0b2022c0940a54116d69bb6361cd3bcf092de7ee984b21e352bec21f96cadbd0268f9d679d8a923604a8086ba4522c5e09a657351629b38f24f93b4f1",
              "rh_hash": null,
              "ssdeep": "6:Tgia4J2guH1jY6j5MXkArYUcHvpwy7mP3v:Tg1b5VjXOXk2am/v",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1C5D02B0A122C0A36F900F7D306582A119278F5C5FF0440642CC04300144F3D5F6C4A7B",
              "sha3_384": "9398ad8214bba3dc68b7986dc0ffd61eee4dcdbfc2e346cc416357e596aeb2896c6affc9ce1fd356f1486dc6eb7492c7",
              "data": "[ZONE_REG_KEYS]\nBROWSE_SCV_KEY=\"Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\\"\n[ZONE_VALUES_NAMES]\nBROWSE_SCV_DOWNLOAD_SIGNED_ACTIVEX=\"1001\"\nBROWSE_SCV_RUN_ACTIVEX_VALUE_NAME=\"1200\"\nBROWSE_SCV_DOWNLOAD_FILES=\"1803\"\nBROWSE_SCV_JAVA_PERMISSIONS=\"1C00\"\n\n\n"
            },
            {
              "name": "e8dc926ad2a55c8522fbf09765371322c3dcf5067ef46b7cbb9ea3188b52fdc6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e8dc926ad2a55c8522fbf09765371322c3dcf5067ef46b7cbb9ea3188b52fdc6",
              "guest_paths": [
                "ccore32.sys"
              ],
              "size": 223392,
              "crc32": "AEC3728A",
              "md5": "fcfa4e29cecf08afddc21e18975ff60b",
              "sha1": "bf4b15c46410a6bef145e4a8343c7dba42c6f734",
              "sha256": "e8dc926ad2a55c8522fbf09765371322c3dcf5067ef46b7cbb9ea3188b52fdc6",
              "sha512": "dd61cf07ef223d523fc1a23c605b62719ba9b22e769de738d6058cb5e33f801b2f9e27540709c8708d2e92120bcf110ed91634f10ca44534d7773b3895d5e044",
              "rh_hash": null,
              "ssdeep": "6144:F9/IxFyx+6/M8hvqc39PqqDL6E9vd6M0a:PIxFo+SM87Sqn62b5",
              "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T10E244A13E76101FAD0694B3506FF3765566B83F523A352D32B116AE86EE23E13E31AC4",
              "sha3_384": "3bbe94b11bc4b0a204de4793a3370b9ba154c9b333a277dc310ced872c42489590cd4956939cfe37cad36e4f645f6c7e",
              "data": null
            },
            {
              "name": "e119e0cc3d1ff1fcee4a4a3b72af387d3d058eb0c44e0157b5648b29b04f7c05",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e119e0cc3d1ff1fcee4a4a3b72af387d3d058eb0c44e0157b5648b29b04f7c05",
              "guest_paths": [
                "ccore64.sys"
              ],
              "size": 277664,
              "crc32": "532DC650",
              "md5": "a0b4597f341070795db6dc344604f003",
              "sha1": "ebf7c6934e285cb18566da7afe0b4eef6836e676",
              "sha256": "e119e0cc3d1ff1fcee4a4a3b72af387d3d058eb0c44e0157b5648b29b04f7c05",
              "sha512": "e03ae8569e7f6ac417bb3a5b832aee7f1768eb7d00fccde55d8bf3aadc1fab51f0c4958c76efb8ae629bc097cf2a9d9d0caedad201cb4f1d5d169e4162ab79d2",
              "rh_hash": null,
              "ssdeep": "3072:4xSdvcOPlZhxFx3HKLYQUpSCnsggSoV08RwZX9f3bJMqqDL2/+Ygn9f3bcvF/gdS:4IPDXSosggBwZX9WqqDL6i9wpgle",
              "type": "PE32+ executable (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18F444C03F77905E5D02A8B3449AB0752EA7778A5136393E71B205A6C5FE33E13E76B80",
              "sha3_384": "eca45ca607767ba46d7779ac520c0687cda151ff7b21cedc323c8d8c331f616f3a13de71792d15aa060a30f0270540d6",
              "data": null
            },
            {
              "name": "a0f42e1062575e6c47640dee2883319addf781e830a2e9fc0937d25a1d24e070",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a0f42e1062575e6c47640dee2883319addf781e830a2e9fc0937d25a1d24e070",
              "guest_paths": [
                "CertEnrollProxy.dll"
              ],
              "size": 26560,
              "crc32": "9E9EA02C",
              "md5": "45fad8dee777bf3a26c840c2bf1d1c36",
              "sha1": "7309a87c12d43475c89a0672b2c790b2d272b972",
              "sha256": "a0f42e1062575e6c47640dee2883319addf781e830a2e9fc0937d25a1d24e070",
              "sha512": "5050355bc4b15079ee860ff6a867dd326976d15ff2fb1c14935d4593e2a5653fcdf1b7d8c7eba5cf79ed78a40d79c33145e1bcb8a3e67e78b0489cc0646a9f2b",
              "rh_hash": null,
              "ssdeep": "384:LBLD0rJrGq4JPrUtH4ris+yoDiawGBkNl6bCI9IYiLQjv:lLqGLZrUams+yoD7kNlT5Yisv",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T108C26DD2FB340571FD490A70A8E2A513EC78B6C18FD0458B67079A6D666C3C53E3CA76",
              "sha3_384": "e6addbe6cb7918f84d25965433f15658f5a82fed7da0a86b20feb1cf41a6019e0f7fed24b3fe429e15f7c1e15d761315",
              "data": null
            },
            {
              "name": "05d89120d232c23ff51d75634f94818ec10d91ae14f74153a365ceab49c5f65f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/05d89120d232c23ff51d75634f94818ec10d91ae14f74153a365ceab49c5f65f",
              "guest_paths": [
                "certificate.png"
              ],
              "size": 820,
              "crc32": "5C02A2FE",
              "md5": "80a5fb839be1ab5803f4d7e002dc3e8a",
              "sha1": "92dde58a14269485bad80213b4730324ee750010",
              "sha256": "05d89120d232c23ff51d75634f94818ec10d91ae14f74153a365ceab49c5f65f",
              "sha512": "be8e7832ed1a3be33feafc20e84bd1d408c854a99bf3c928be3d268647dc3cd09631fea91bcc2888a8372333bc3bd7c0ab4fc4004c6fe1c511f5e153dbee6859",
              "rh_hash": null,
              "ssdeep": "12:6v/7u/UKqDqDkjY9ucuRRmoY4th76w4tPNFIM:sKqDqCyucuRpth76w4d9",
              "type": "PNG image data, 16 x 16, 8-bit colormap, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1500120818360E44CC809D234447064C5B4A33C56A5AFC846AE21FBFD71752802054B9D",
              "sha3_384": "b47938a82e2298dcbc33267c9887401247704c515b6b51c9d577b6bfdee66a4640faefa4df2cfc159bad6b5933910437",
              "data": null
            },
            {
              "name": "08c8501b32815ff7296ba51049a152d731b65f549e27a95c79233e1f9cb6e982",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/08c8501b32815ff7296ba51049a152d731b65f549e27a95c79233e1f9cb6e982",
              "guest_paths": [
                "CLI_help.txt"
              ],
              "size": 13448,
              "crc32": "646D7483",
              "md5": "6a693df7e5fa86cd88374099d1083afd",
              "sha1": "8438fa36734e1803ceea7b647a9cef98c428829a",
              "sha256": "08c8501b32815ff7296ba51049a152d731b65f549e27a95c79233e1f9cb6e982",
              "sha512": "a38f81e252debd09795cdeff752ad8cfa0aeaef89c44d71162f2e965eebf92543125610c95a9b6da367a794a90dffb707cb7c7a3ca390857a27002004c8d286c",
              "rh_hash": null,
              "ssdeep": "192:pebIbq3UCUIfYe2cTp7gXrJtNynEDp4tmNF3otRZzEIRmf1KmKiy//nhJONTZ:IUCUIfx7gvkEWy3otRGIRageX",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12052C711018CFBB318CB1336D75A528EDB3CD22D52B3511263F960B936A9DBAD12E5E3",
              "sha3_384": "a7eae622a030dc6c2bfe1296b954ec3914c1a049ac236eb1c9756bbb8757091acc041b37f79668a325c6a0cc31b02321",
              "data": "# format\n#\n#{\n#Command\n#\n#Command description (no comments allowed)\n#\n#}\n#\n#\n# Based on the admin guide - command_line section\n\n#Command Line Usage\n{\nusage\n\nCheck Point Endpoint Security command line usage:\n  trac <command> [<args>]\n\n  where <command> is one of:\n\n\tstart\n\t\t\tstarts Endpoint Security service\n\n\tstop\n\t\t\tstops Endpoint Security service\n\n\tcollect_logs\n\t\t\tcollect logs for the administrator\n\n\tenable_log [-m <mode>]\n\t\t\tenable logs\n\t\t\tMode is optional and can be either \"basic\" or \"extended\"\n\n\tdisable_log\n\t\t\tdisable logs\n\t\t\t\n\tinfo [-s <sitename>] [-tr true]\n\t\t\tlists all connections or prints sitename info\n\n\tconnect [-s <sitename>] [-g <gatewayname>] [-u <username> -p <password> | -d <dn> | -f <p12> | -pin <PIN> -sn <serial>] [-a true]\n\t\t\tconnects using the given connection.\n\t\t\tOptional credentials can be supplied\n\n\tupdate [-s <sitename>] [-g <gatewayname>] [-u <username> -p <password> | -d <dn> | -f <p12> | -pin <PIN> -sn <serial>]\n\t\t\tconnects using the given connection.\n\t\t\tOptional credentials can be supplied\n\t\t\t\n\tconnectgui [-s <sitename>]\n\t\t\tconnects using the GUI (GUI must be running)\n\n\tdisconnect [-g <gatewayname>]\n\t\t\tdisconnects the current connection\n\t\t\tOptionally disconnect a specific tunnel of the active connection\n\n\tcreate -s <sitename> [-di <display name>] [-lo <login option>] [-a <authentication method>] [-f <fingerprint>]\n\t\t\tcreates a new connection\n\n\tdelete -s <sitename>\n\t\t\tdeletes the given connection\n\n\thelp [-c <command>]\n\t\t\tprints usage information\n\n\tlist [-s <sitename>]\n\t\t\tlists the user's DNs stored in the CAPI\n\n\tver\n\t\t\tprints the version\n\n\tlog\n\t\t\tprints log messages\n\n\tenroll_p12 -s <sitename> -f <filename> -p <password> -r <registrationkey> [ -l <keylength> ]\n\t\t\tenroll of p12 certificate\n\n\tenroll_capi -s <sitename> -r <registrationkey> [ -i <providerindex> -l <keylength> -sp <strongkeyprotection> ]\n\t\t\tenroll of capi certificate\n\n\trenew_p12 -s <sitename> -f <filename> -p <password> [ -l <keylength> ]\n\t\t\trenew p12 certificate\n\n\trenew_capi -s <sitename> -d <dn> [ -l <keylength> -sp <strongkeyprotection> ]\n\t\t\trenew capi certificate\n\n\tchange_p12_pwd -f <filename> [ -o <oldpassword> -n <newpassword> ]\n\t\t\tchange p12 password\n\n\tset_proxy_settings [-m <mode>] [ -h <hostname> -po <port> ] [-u <username> -p <password>]\n\t\t\tchange proxy settings\n\t\n\thotspot_reg\n\t\t\tregister to hotspot\n\n\tfirewall -st <state>\n\t\t\tenable/disable firewall\n\t\t\t\n\tsdl -st <state>\n\t\t\tenable/disable sdl\n\n\tuserpass -s <sitename> -u <username> -p <password>\n\t\t\tsave username and password (for ATM only)\n\n\tcertpass -s <sitename> -f <certificate filename> -p <password>\n\t\t\tsave certificate and password (for ATM only)\n\n\tget_cross_site_intersections\n\t\t\tfind if there are gateways from different CMAs that has ip ranges intersections \n\t\t\t(used in case of multi-site mode only)\n\n\tget_cross_gws_intersections -s <sitename>\n\t\t\tfind if there are gateways that has ip ranges intersections\n\t\t\t(if no site provided, command uses active site)\n\n\tdisable_cert_filter -s <sitename>\n\t\t\tdisable certificate user filter\n}\n\n{\nstart\n\n\tCommand: start\n\n\tDescription: Starts the Remote Access Clients service.\n\n\tSyntax: trac start\n\n\tArguments: none\n\n}\n\n{\nstop\n\n\tCommand: stop\n\n\tDescription: Stops the Remote Access Clients service.\n\n\tSyntax: trac stop\n\n\tArguments: none\n\n}\n\n{\ncollect_logs\n\t\n\tCommand: collect_logs\n\n\tDescription: Collects logs for your administrator.\n\n\tSyntax: trac collect_logs\n\n\tArguments: none\n\n}\n\n{\nenable_log\n\n\tCommand: enable_log\n\n\tDescription: Enables logging.\n\n\tSyntax: trac enable_log\n\n\tArguments: none\n\n}\n\n{\ndisable_log\n\n\tCommand: disable_log\n\n\tDescription: Stops logging.\n\n\tSyntax: trac disable_log\n\n\tArguments: none\n\n}\n\n{\ninfo\n\n\tCommand: info\n\n\tDescription: Outputs all connections or site name information.\n\n\tSyntax: trac info [-s <site name>] [-tr true]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\t\t\t-tr\ttrue \tindicates whether the transport type of gateway tunnel will be shown.\n\n\tExample:\n\t\t\t>>trac info\n\t\t\t>>trac info -s mygateway.domain.com\n\t\t\t>>trac info -s mygateway.domain.com -tr true\n\n}\n\n{\nconnect\n\n\tCommand: connect\n\n\tDescription: Connects the local client to a site.\n\n\tSyntax: trac connect [-s <site>] [-g <gatewayname>] [-u <user> -p <password> | -d <dn> | -f <p12> | -pin <PIN> -sn <serial>] [-a true]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\t\t\t\t\tIf not given, the client connects to the active site. \n\t\t\t\t\tIf no active site is defined, an error message is given.\n\n\t\t\t-g\t\tname of the gateway.\n\t\t\t\t\tIf not given, the client connects to the preferred gateway. \n\n\t\t\t-u\t\n\t\t\t-p\t\tusername and password credentials.\t\t\t\n\t\t\t-d\t\tDN\n\t\t\t-f\t\tpathname of P12 certificate file.\n\t\t\t-pin\n\t\t\t-sn\t\tSecurID PIN and passcode.\n\t\t\t-a true\t\tautoselect a certificate from CAPI store if there is just the only one.\n\t\t\t\t\tOption is useful if there is no saved certificate_dn in the config and user hasn't passed a dn with -d option.\n\t\t\t\t\t\n\n\tExample:\n\t\t\t>>trac connect -s mygateway.domain.com\n\t\t\t>>trac connect -u myname -p mypass\n\t\t\t>>trac connect -s mygateway.domain.com -f c:\\p12file.p12 -p xxxx\n\t\t\t>>trac connect -s mygateway.domain.com -a true\n\n}\n\n{\nupdate\n\n\tCommand: update\n\n\tDescription: Update the given site topology.\n\n\tSyntax: trac update [-s <site>] [-g <gatewayname>] [-u <user> -p <password> | -d <dn> | -f <p12> | -pin <PIN> -sn <serial>]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\t\t\t\t\tIf not given, the client updates to the active site. \n\t\t\t\t\tIf no active site is defined, an error message is given.\n\n\t\t\t-g\t\tname of the gateway.\n\t\t\t\t\tIf not given, the client updates to the preferred gateway. \n\n\t\t\t-u\t\n\t\t\t-p\t\tusername and password credentials.\t\t\t\n\t\t\t-d\t\tDN\n\t\t\t-f\t\tpathname of P12 certificate file.\n\t\t\t-pin\n\t\t\t-sn\t\tSecurID PIN and passcode.\n\n\tExample:\n\t\t\t>>trac update -s mygateway.domain.com\n\t\t\t>>trac update -u myname -p mypass\n\t\t\t>>trac update -s mygateway.domain.com -f c:\\p12file.p12 -p xxxx\n\n}\n{\nconnectgui\n\n\tCommand: connectgui\n\n\tDescription: Connects to the gateway. If a user's authentication credentials are not cached, it opens the login page so the user can authenticate.\n\n\tSyntax: trac connectgui [-s <sitename>]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\t\t\t\t\tIf not given, the client connects to the active site. \n\t\t\t\t\tIf no active site is defined, an error message is given.\n\n\tExample:\n\t\t\t>>trac connectgui\n\t\t\t>>trac connectgui -s mygateway.domain.com\n}\n\n{\ndisconnect\n\n\tCommand: disconnect\n\n\tDescription: Disconnect the current connection. Optionally disconnecting a specific tunnel of the active connection.\n\n\tSyntax: trac disconnect [-g <gatewayname>]\n\n\tArguments:\n\t\t\t-g\t\tname of the specific gateway whose tunnel should be disconnected.\n\t\t\t\t\tIf not given, the client disconnects the active site entirely. \n\n}\n\n{\ncreate\n\n\tCommand: create\n\n\tDescription: Creates a new site and defines its authentication method.\n\n\tSyntax: trac create -s <sitename> [-di <display name>] [-lo <login option>] [-a <authentication method>] [-f <fingerprint>]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\t\t\t-di\t\tdisplay name.\n\t\t\t-lo\t\tname of the login option.\n\t\t\t-a\t\tValid values:\n\t\t\t\t\t\tusername-password\n\t\t\t\t\t\tcertificate\n\t\t\t\t\t\tp12-certificate\n\t\t\t\t\t\tchallenge-response\n\t\t\t\t\t\tsecurIDKeyFob\n\t\t\t\t\t\tsecurIDPinPad\n\t\t\t\t\t\tSoftID\n\t\t\t-f\t\texpected fingerprint\n\n\tExample:\n\t\t\t>>trac create -s mygateway.domain.com\n\t\t\t>>trac create -s mygateway.domain.com -di \"My Gateway\"\n\t\t\t>>trac create -s mygateway.domain.com -a certificate\n\t\t\t>>trac create -s mygateway.domain.com -f \"LEFT SAN MEND SLAT MUTE STAB GURU BOLT FRET SAT CORE LA\"\n\n}\n\n{\ndelete\n\n\tCommand: delete\n\n\tDescription: Deletes a site definition.\n\n\tSyntax: trac delete -s <site>\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\n\tExample:\n\t\t\t>>trac delete -s mygateway.domain.com\n\n}\n\n{\nhelp\n\n\tCommand: help\n\n\tDescription: Outputs help on the CLI or for a command.\n\n\tSyntax: trac help [-c <command>]\n\n\tArguments:\n\t\t\t-c\t CLI command name.\n\n\tExample:\n\t\t\t>>trac help -c start\n\t\t\t\n\t\t\t\tCommand: start\n\n\t\t\t\tDescription: Starts the Remote Access Clents service.\n\n\t\t\t\tSyntax: trac start\n\n\t\t\t\tArguments: none\n\n}\n\n{\nlist\n\n\tCommand: list\n\n\tDescription: Shows user domain names stored in the CAPI.\n\n\tSyntax: trac list [-s <sitename>]\n\n\tArguments:\n\t\t\t-s\t\tname of the site.\n\n}\n\n{\nver\n\n\tCommand: ver\n\n\tDescription: Shows the version of the client.\n\n\tSyntax: trac ver\n\n\tAr <truncated>"
            },
            {
              "name": "937c1edcedde0eeb9c64717959540c184282650cb94343bf6c62ed8123bd9a15",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/937c1edcedde0eeb9c64717959540c184282650cb94343bf6c62ed8123bd9a15",
              "guest_paths": [
                "collect.bat"
              ],
              "size": 9933,
              "crc32": "A9C0C5D2",
              "md5": "a8b28226fd7b5fe586b309a2045fbea7",
              "sha1": "bff1bddd5890c256d74d6b2b53a7528b36920df8",
              "sha256": "937c1edcedde0eeb9c64717959540c184282650cb94343bf6c62ed8123bd9a15",
              "sha512": "70f8c35ee0171789ae940cbf3b746ff2a2f9730e159296b1c9f1d1580558ae4e140bd1635a5737ddbdf797d9f6d2cc7ad584d7213d9c6519fac770be56e9dd3f",
              "rh_hash": null,
              "ssdeep": "192:I1YPy0TLLdAr/dqf65ugOngr0lS60885rfZUSMZMDMiMwQS/7mf2RT:80BngAhST",
              "type": "DOS batch file, ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14B22BA4E3FB83474A35BE7687F0AC291E316A98C82407C1657C392BB52D06EC291FDB1",
              "sha3_384": "a321acc7f1334aa47581d7575113d04e4e073a0ebb2262d6ee5cb3a447aca1bf8e1e8465973f2e02ca6bf69224903c4f",
              "data": "@echo off\nrem ======================\nrem DO NOT EDIT THIS FILE.\nrem ======================\n\nSET FNAME=%1\nSET DIRNAME=%2\nSET CALLMODE=%3\n\nIF '%FNAME%'=='' SET FNAME=trac.cab\nIF '%DIRNAME%'=='' SET DIRNAME=%TEMP%\\trac\n\nmkdir %DIRNAME%\n\nif EXIST %DIRNAME%\\collect.log del %DIRNAME%\\collect.log\n\nset PRODDIR_PATH=\nset PRODDIR_REG_KEY=HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\5.0\\\nFOR /F \"tokens=2,*\" %%A IN ('REG QUERY %PRODDIR_REG_KEY% /v PRODDIR ^| FIND \"PRODDIR\"') DO SET PRODDIR_PATH=%%B\n\nif not defined PRODDIR_PATH (\t\n\tset PRODDIR_REG_KEY_64=HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\5.0\\\n\tFOR /F \"tokens=2,*\" %%A IN ('REG QUERY  %PRODDIR_REG_KEY_64% /v PRODDIR ^| FIND \"PRODDIR\"') DO SET PRODDIR_PATH=%%B\n) \n\necho collect.bat started at %date% %time% >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\necho ver >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\nver >> %DIRNAME%\\collect.log\necho route print output >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\nroute print >> %DIRNAME%\\collect.log\necho -------------------- >> %DIRNAME%\\collect.log\necho ipconfig /all output >> %DIRNAME%\\collect.log\necho -------------------- >> %DIRNAME%\\collect.log\nipconfig /all >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\necho trac.exe printProxyConf >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\n\"%PRODDIR_PATH%trac.exe\" printProxyConf >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\necho tasklist output >> %DIRNAME%\\collect.log\necho --------------- >> %DIRNAME%\\collect.log\ntasklist >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\necho netstat -ano output >> %DIRNAME%\\collect.log\necho --------------- >> %DIRNAME%\\collect.log\nnetstat -ano >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\necho collect trac registry tree >> %DIRNAME%\\collect.log\nmkdir %TEMP%\\reg\nif exist \"%TEMP%\\reg\\trac_registry.log\" del \"%TEMP%\\reg\\trac_registry.log\"\nreg.exe export \"HKEY_LOCAL_MACHINE\\SOFTWARE\\CHECKPOINT\" \"%TEMP%\\reg\\trac_registry.log\" /y /reg:32 >> %DIRNAME%\\collect.log 2>&1\necho ------------------ >> %DIRNAME%\\collect.log\n\"%PRODDIR_PATH%trac.exe\" info -t 20 -tr true >> %DIRNAME%\\collect.log\necho ------------------ >> %DIRNAME%\\collect.log\n\nrem compress the logs into a single cab file:\n\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\helpdesk.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\helpdesk.log.0\ncopy helpdesk.log %DIRNAME%\ncopy helpdesk.log.0 %DIRNAME%\ncopy trac.ddf %DIRNAME%\n\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac.log\nfor /R %%G in (trac.log.*) do copy \"%%G\" %DIRNAME%\nfor /R %%G in (trac.log.*) do echo \"%%~nxG\" >> %DIRNAME%\\trac.ddf\n\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_startup.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\epwd.log\ncopy Watchdog\\Logs\\epwd.log %DIRNAME%\ncopy trac_startup.log %DIRNAME%\ncopy trac.config %DIRNAME%\ncopy trac.defaults %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI_SDL.log\ncopy TrGUI_SDL.log %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\WscScvDebug.txt\ncopy WscScvDebug.txt %DIRNAME%\n\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_fwpktlog.log\nfor /R %%G in (trac_fwpktlog.*) do copy \"%%G\" %DIRNAME%\nfor /R %%G in (trac_fwpktlog.*) do echo \"%%~nxG\" >> %DIRNAME%\\trac.ddf \n\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.log.0\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.log.1\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.log.2\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.log.3\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.log.0\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.log.1\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.log.2\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.log.3\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\DesktopApplicationApiWrapper.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\DesktopApplicationApiWrapper.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\DesktopApplicationApiWrapper.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\DesktopApplicationApiWrapper.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrSAA.log\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrSAA.log\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrSAA.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrSAA.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\scapi_vsmon.log\ncopy \"C:\\WINDOWS\\Internet Logs\\scapi_vsmon.log\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\scapi_vsmon.log.0\ncopy \"C:\\WINDOWS\\Internet Logs\\scapi_vsmon.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\scapi_iclient.log\ncopy \"C:\\WINDOWS\\Internet Logs\\scapi_iclient.log\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\scapi_iclient.log.0\ncopy \"C:\\WINDOWS\\Internet Logs\\scapi_iclient.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\tvDebug.log\ncopy \"C:\\WINDOWS\\Internet Logs\\tvDebug.log\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\fwpktlog.txt\ncopy \"C:\\WINDOWS\\Internet Logs\\fwpktlog.txt\" %DIRNAME%\nfor /R \"C:\\WINDOWS\\Internet Logs\\\" %%G in (TracSrvWrapper_*_full.dmp) do echo \"%%G\" >> %DIRNAME%\\trac.ddf \ncopy ver.ini %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TracSrvWrapper.dmp\ncopy TracSrvWrapper.dmp %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.dmp\ncopy TrGUI.dmp %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI_appdata.dmp\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.dmp\" %DIRNAME%\\TrGUI_appdata.dmp\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI_appdata.CRASH.elg\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\TrGUI.CRASH.elg\" %DIRNAME%\\TrGUI_appdata.CRASH.elg\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TrGUI.CRASH.elg\ncopy TrGUI.CRASH.elg %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\TracSrvWrapper.CRASH.elg\ncopy TracSrvWrapper.CRASH.elg %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_capi.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_capi.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\trac_capi.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\trac_capi.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_install.log\ncopy \"%WINDIR%\\Temp\\trac_install.log\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\trac_msi.log\ncopy trac_msi.log %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\dlog1.txt\ncopy \"%ALLUSERSPROFILE%\\Application Data\\Pointsec\\Pointsec for PC\\dlog1.txt\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\command_line.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\command_line.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\command_line.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\command_line.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\sys_command_line.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\sys_command_line.log.0\ncopy \"sys_command_line.log\" %DIRNAME%\ncopy \"sys_command_line.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\DesktopApplicationApiWrapper.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\DesktopApplicationApiWrapper.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\DesktopApplicationApiWrapper.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\DesktopApplicationApiWrapper.log.0\" %DIRNAME%\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_access.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_access.log.0\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_agent.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_agent.log.0\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_error.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_error.log.0\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_referer.log\necho \"FILE DOES NOT EXIST\" > %DIRNAME%\\ProxyServer_referer.log.0\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\ProxyServer_access.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\ProxyServer_access.log.0\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\ProxyServer_agent.log\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\ProxyServer_agent.log.0\" %DIRNAME%\ncopy \"%APPDATA%\\CheckPoint\\Endpoint Connect\\ProxyServer_error.log\" %DIRNAME%\n <truncated>"
            },
            {
              "name": "049e56f9c97edc7fcc07fe405b18c8bab9ba18f5bcbaf23b696d258c80e12c1c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/049e56f9c97edc7fcc07fe405b18c8bab9ba18f5bcbaf23b696d258c80e12c1c",
              "guest_paths": [
                "concrt140.dll"
              ],
              "size": 246576,
              "crc32": "73D14D14",
              "md5": "10d129e4358761eac7ab08d6b02b9202",
              "sha1": "0d9fb66a034d7a05b772f3ce3f45ec80f9a40dc9",
              "sha256": "049e56f9c97edc7fcc07fe405b18c8bab9ba18f5bcbaf23b696d258c80e12c1c",
              "sha512": "0abdf64da4a4b306f33444033f9b8f972e28ca6453cba6724e72c403e7437f038f55d10429d804706861686545d4457c4360b6631d1e27241af2ab2b35950118",
              "rh_hash": null,
              "ssdeep": "6144:yHPZLWTmuey21iBMTbiluLm2P7+wC+lUlT1Z1MP12z/7pKX:wPZNqlem2hCF1MEzc",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15A345D92384084F7F75F47368438D66B90BEF6402BE991D75BACDA4D1DA0AC1E9324E3",
              "sha3_384": "58add38a83fda558aa126c219daf4f651a6227e8b3c2358ab1a055ed94a1a2202bfc90f9571b64a3d399316c230b0ee2",
              "data": null
            },
            {
              "name": "a946f1194e193ebf48cdebab56c2928689db97a507d3566a2f419b896ee6439d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a946f1194e193ebf48cdebab56c2928689db97a507d3566a2f419b896ee6439d",
              "guest_paths": [
                "config.xml"
              ],
              "size": 23340,
              "crc32": "79926E57",
              "md5": "db07c22dd0c9eb15e53cf92cda5c02fa",
              "sha1": "5b9af60578d4007b7502eb6af2ffbebf63e5706e",
              "sha256": "a946f1194e193ebf48cdebab56c2928689db97a507d3566a2f419b896ee6439d",
              "sha512": "cecdb9b1cd709160991915d81932109685bbd66c277307831f9152ca900b889fd5116e2bd3c690d6d8dffc78402ac5cc3287d813d84528f6a89694d7c9d4fbc4",
              "rh_hash": null,
              "ssdeep": "384:H1uiN2n64vtn7k0elOHXMg3uvY1X+cMsY/0+7YM:3Itn4blOHXMg+aX+cn+",
              "type": "XML 1.0 document, ASCII text, with very long lines (614)",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1CAA29800E8B4A85A039D4302AA60DD2B3DE24ADFC7015665F8DD05FA7F43D59CB9B3E6",
              "sha3_384": "c96bf322d1d50e38b64994e99b811495a4d3df974b7094b0847aca6b151131da0ffb5536721467527dc1bba4ee7484d1",
              "data": "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n  <ZoneLabsSettings version=\"1.0\"\n  \t\t\txmlns=\"http://schema.zonelabs.com/policy/v1/\"\n  \t\t\txmlns:ml=\"http://schema.zonelabs.com/policy/masterlist/v1/\"\n  \t\t\txmlns:types=\"http://schema.zonelabs.com/policy/types/\"\n  \t\t\txmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\">\n    <policy_info author=\"Check Point, Inc\"\n    \t\t\t\tdescription=\"Default Personal Policy\"\n    \t\t\t\tpolicyName=\"Personal Policy\" version=\"\"\n    \t\t\t\twarnOnlyEnterprise=\"false\" entAppPermOverride=\"false\"/>\n    <ruleset name=\"startupruleset\" start=\"onstartup\" stop=\"afterstartup\"/>\n    <ruleset name=\"runningruleset\" start=\"afterstartup\" stop=\"onshutdown\">\n      <integrity programObservation=\"0\" observationInterval=\"0\">\n                <connection name=\"ZSP3\" host=\"zsp3://cp\" trigger=\"always\" connectionId=\"checkpoint.zsp3.daf\" orientation=\"Enterprise\"/>\n                <policyAskServer enabled=\"false\" URL=\"\"/>\n      </integrity>\n      <general>\n        <detectedNetworks status=\"yes\" disableWirelessOnLAN=\"false\"/>\n        <security trusted=\"low\" internet=\"low\" blockTrustedServers=\"false\" blockInternetServers=\"false\" gatewayEnforcement=\"false\" lockHostFile=\"false\"/>\n        <fwoptions cpSignedAppsPassThru=\"true\" blockFragments=\"false\" blockProtoVPN=\"false\" allowProtoMisc=\"true\" arpProtection=\"false\"\n\t\t\t\t\t\t\t        enableSpoofProtection=\"false\" debugMode=\"false\" noFWLock=\"false\"\n\t\t\t\t\t\t\t        debugFlags=\"0x0\" maxFileSize=\"0\" FWDebugRegistry=\"false\"/>\n        <autolock enabled=\"false\" engage=\"screensaver\" lockmode=\"normal\" alertOnViolation=\"ShowAndCancel\"/>\n        <autoVPN refreshTime=\"30\" throttleTime=\"30\" zoneRefresh=\"3600\" allowMsCfg=\"1\" allowCiscoCfg=\"2\" allowUDPCheck=\"0\"/>\n      </general>\n      <email>\n        <outboundMail ompEnabled=\"false\" mailEnabled=\"false\" maxMailSent=\"5\" recipientEnabled=\"true\" maxRecipients=\"50\" interval=\"2\" senderEnabled=\"false\"/>\n        <spamFilter enabled=\"false\"/>\n      </email>\n      <firewall>\n        <expert>\n\t\t<rules>\t\t</rules>\n        </expert>\n      </firewall>\n      <fwrestricted>\n\t\t<rules>\t\t</rules>\n      </fwrestricted>\n      <zones>\n        <trusted clearOldEntries=\"true\" defaultNetworkStatus=\"yes\" defaultAdapterMode=\"off\" autoExcludeNonWEPWlans=\"1\">\n             <iprange address=\"127.0.0.1\" toaddress=\"127.255.255.255\" status=\"on\" description=\"Local Loopback\"/>\n             <iprange description=\"All IP\" address=\"1.1.1.1\" toAddress=\"255.255.255.255\" status=\"true\" ml:refId=\"102\" ml:refDescription=\"\"/>\n        </trusted>\n        <restricted clearOldEntries=\"true\">\n        </restricted>\n      </zones>\n      <customSecurity>\n        <trusted>\n          <highSecurity>\n            <allow DNSOut=\"false\" DHCPOut=\"false\" cast=\"true\" pingIn=\"false\" otherICMPIn=\"false\" pingOut=\"false\" otherICMPOut=\"false\" IGMPIn=\"false\" IGMPOut=\"false\">\n              <incoming>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </incoming>\n              <outgoing>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </outgoing>\n            </allow>\n          </highSecurity>\n          <mediumSecurity>\n            <block netBIOSIn=\"false\" netBIOSOut=\"false\" pingIn=\"false\" otherICMPIn=\"false\" pingOut=\"false\" otherICMPOut=\"false\" IGMPIn=\"false\" IGMPOut=\"false\">\n              <incoming>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </incoming>\n              <outgoing>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </outgoing>\n            </block>\n          </mediumSecurity>\n        </trusted>\n        <internet>\n          <highSecurity>\n            <allow DNSOut=\"false\" DHCPOut=\"false\" cast=\"true\" pingIn=\"false\" otherICMPIn=\"false\" pingOut=\"false\" otherICMPOut=\"false\" IGMPIn=\"false\" IGMPOut=\"false\">\n              <incoming>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </incoming>\n              <outgoing>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </outgoing>\n            </allow>\n          </highSecurity>\n          <mediumSecurity>\n            <block netBIOSIn=\"true\" netBIOSOut=\"false\" pingIn=\"false\" otherICMPIn=\"false\" pingOut=\"false\" otherICMPOut=\"false\" IGMPIn=\"false\" IGMPOut=\"false\">\n              <incoming>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </incoming>\n              <outgoing>\n                <protocol type=\"IP_TCP\" enabled=\"false\" port=\"\"/>\n                <protocol type=\"IP_UDP\" enabled=\"false\" port=\"\"/>\n              </outgoing>\n            </block>\n          </mediumSecurity>\n        </internet>\n      </customSecurity>\n      <alerts show=\"medium\" moreInfoHideIP=\"obscure\" logEvents=\"on\" logProgramAlerts=\"high\" displaySystemTrayAlert=\"false\">\n\t\t\t\t<logging enabled=\"true\" archive=\"5\" delimiter=\"comma\" file=\"C:\\WINDOWS\\Internet Logs\\ZALog.txt\" archiveLogLimit=\"1\"\n        \t\t\t\t\tnetBIOSBroadcast=\"true\" netBIOSNameOut=\"true\" recentConnection=\"true\" nonSYNTCP=\"true\" routed=\"true\" loopback=\"true\" fragments=\"true\" nonIP=\"true\" otherIP=\"false\" blockedApp=\"false\" lockViolation=\"true\" mailSafeQuarantine=\"false\" clearCurrentValues=\"true\" newPrograms=\"true\" changedPrograms=\"true\" repeatPrograms=\"true\" serverPrograms=\"true\" newProgramComponents=\"true\" changedProgramComponents=\"true\" osfwSuppression=\"low\"/>\n        <suppression\n        \t\t\t\t\tnetBIOSBroadcast=\"true\" netBIOSNameOut=\"true\" recentConnection=\"true\" nonSYNTCP=\"true\" routed=\"true\" loopback=\"true\" fragments=\"true\" nonIP=\"true\" otherIP=\"false\" blockedApp=\"false\" lockViolation=\"true\" mailSafeQuarantine=\"false\" clearCurrentValues=\"true\" osfwSuppression=\"low\"/>\n      </alerts>\n      <imsecure>\n\n      </imsecure>\n      <applications securityLevel=\"off\" alertOnBlock=\"false\" denyAskIfNoUI=\"true\" tempAllowRequiresAuth=\"true\" moduleTracking=\"false\" clearoldEntries=\"true\" disableParentCheck=\"true\" disableProcProtect=\"false\" disableKeyboardMouseProtection=\"false\" askOnListen=\"true\" disableAdvProgProtect=\"true\" enableOpenProcess=\"false\" programDisplay=\"displayAfterUse\" enableCBP=\"false\" disableSendMessageProtect=\"false\" disableDNSProtect=\"false\" askUser=\"false\" programAdvisor=\"off\" PAGUID=\"\" askPA=\"false\" osfwSetting=\"false\" osfwEnable=\"false\" CurrentRunMode=\"high\" DefaultRunMode=\"high\" RunModeRevertDate=\" \" ask=\"server\" >\n        <default allowTrusted=\"allow\" allowTrustedServer=\"allow\" allowInternet=\"allow\" allowInternetServer=\"allow\" appsec=\"AskSD\"/>\n        <reference allowTrusted=\"allow\" allowTrustedServer=\"allow\" allowInternet=\"allow\" allowInternetServer=\"allow\"/>\n        <programGroup allowTrusted=\"allow\" allowInternet=\"allow\" allowTrustedServer=\"allow\" allowInternetServer=\"allow\" passLock=\"no\" programType=\"false\" overridePermission=\"false\" alertOnBlock=\"no\" moduleCheck=\"yes\" privacy=\"no\" sendMailPermission=\"allow\" omp=\"false\" hideBeforeUse=\"true\" action=\"add\" rank=\"1\" ml:refId=\"28\" name=\"fgm534:Critical Services\">\n            <programs>\n                <program path=\"svchost.exe\" description=\"Generic Host Process for Win32 Services\" checksum=\"8f078ae4-ed187aaa-bc0a3051-46de6716\" skimpChecksum=\"cb7da36f-d45d1f1a-168e0fa3-e6285a03\"/>\n                <program path=\"lsass.exe\" description=\"LSA Shell (Export Version)\" checksum=\"84885f9b-82f4d55c-6146ebf6-065d75d2\" skimpChecksum=\"493f6c81-83f8a5aa-6026d914-68455ec7\"/>\n                <program path=\"USERINIT.EXE\" description=\"Userinit Logon Application\" checksum=\"39b1ffb0-3c229632-3832acba-e50d2aff\" skimpChecksum=\"a8d8e662-c9f5f62c-d2e03c2e-ce72357a\"/>\n                <program path=\"winlogon.exe\" description=\"Windows NT Logon Application\" checksum=\"986ec72d-788e00e8-e397b7bb-7f5a9e45\" skimpChecksum=\"6a86a7f0-aad7594e-ee85897a-48a2f70a\"/>\n                <pro <truncated>"
            },
            {
              "name": "7c3f1262699e65ea1d45c28990de0295c02be256a88718c7cfdff06525dcb473",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7c3f1262699e65ea1d45c28990de0295c02be256a88718c7cfdff06525dcb473",
              "guest_paths": [
                "connected.png"
              ],
              "size": 544,
              "crc32": "097BA18D",
              "md5": "04756e764f7072b686d19dc66b0528ea",
              "sha1": "262ba8f4b924bea4cce35d0e7f7e66291883e210",
              "sha256": "7c3f1262699e65ea1d45c28990de0295c02be256a88718c7cfdff06525dcb473",
              "sha512": "c2785eb8bef94e2c058e945d266da14914d3cbc9a98c6227f39d89705e6a49c9ea6f3620fc208141e05fd6ec205db76df499d64809935ff91380ef2d74667a92",
              "rh_hash": null,
              "ssdeep": "12:6v/7t8D0/EcidbpgvS0tF3GvTdiQfHvrRgXGGGZqREBhiWxhsQSZ9:H0mtpgv/IdNfHaXGdZqREXimSv",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DAF075F05EC0FF3CD04C97A1D29A91B4CEF6948626BA01873E0888F493CC01824E1B00",
              "sha3_384": "c5d3700bba7bff1de2ee28c572107bec1a59026c8a70446c8b37451691bf68c7ca401c61314781c3e7491b6a80e74166",
              "data": null
            },
            {
              "name": "a8602103f1eb425be0173fcb9f3cfcc3381d2778023f5126b6125785ebbf4c4b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a8602103f1eb425be0173fcb9f3cfcc3381d2778023f5126b6125785ebbf4c4b",
              "guest_paths": [
                "connecting.gif"
              ],
              "size": 1304,
              "crc32": "F30BCFD9",
              "md5": "f67e8224246e59618fc706bc59ca3694",
              "sha1": "aa0d3010d09919db0d951fd6612938f976f51b69",
              "sha256": "a8602103f1eb425be0173fcb9f3cfcc3381d2778023f5126b6125785ebbf4c4b",
              "sha512": "f0916c04c470d9eed9526c38d4b446b281c05d3d787a93e4db4c11616006b0fbe07936ab30cb703ecdf42650ec0ae0f2840594f7fe51222a0325530e95abeb44",
              "rh_hash": null,
              "ssdeep": "24:WsMoMBcFGXXYweoiU2DGf3IPGbIeDDDI1mqOEee860zWtS:WsJEMGX5eoiU2SftIeXDu5Nee6cS",
              "type": "GIF image data, version 89a, 16 x 16",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1BD21FE0E1F8082B0C6574C2579012A3AB77AF8E9CC956315BF1E69AEBA9605D2405172",
              "sha3_384": "e04fed214633f00c7bf2419a01bb048584fe2ceb5e0e239c6404feb5434be33254afc48fd4afae7a2dcab97d7247f07b",
              "data": null
            },
            {
              "name": "2bbb3cd79eee023cef4e98ad02facd48495d3fec57e832f0224295afe2b05a1c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2bbb3cd79eee023cef4e98ad02facd48495d3fec57e832f0224295afe2b05a1c",
              "guest_paths": [
                "cp_middle.png"
              ],
              "size": 297,
              "crc32": "28E14EF1",
              "md5": "da635a877264cbf1c1965ea0ed89d21a",
              "sha1": "9013ce61d80b52bd93e27a413abdc1c5f064e0be",
              "sha256": "2bbb3cd79eee023cef4e98ad02facd48495d3fec57e832f0224295afe2b05a1c",
              "sha512": "9116a24448bfce738e281bcec2611f6f97738953125e35a45df6f114796f1b9c17515bf6d31fb0a984cb9ddaff9909a1175ca5ec443491a8d8621bc814c561b2",
              "rh_hash": null,
              "ssdeep": "6:6v/lhPUCzW3MR/UyKVDNuDvvNZvOix6yiUch8ixyZkup:6v/7ZW3M/U5G1ZGix+UcRxyn",
              "type": "PNG image data, 1 x 42, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T172E0E7E3BA451278C943013240D5754179354874333D0C197914C41D5F1830105CE341",
              "sha3_384": "ef0f06b880a1248b021842ea5d0892fd8d1e468f9b9084a92a6cba9b5a345cc52400457bb0a3b421d778de758c56c385",
              "data": null
            },
            {
              "name": "dcccf2528084116a3ab9000baee606a763bf76a6cccc4abd97192ad6f71ed0af",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/dcccf2528084116a3ab9000baee606a763bf76a6cccc4abd97192ad6f71ed0af",
              "guest_paths": [
                "cp_right.png"
              ],
              "size": 5220,
              "crc32": "9D98B4D2",
              "md5": "ac0a83204783d960a43279b5991403e5",
              "sha1": "e09f0eecdfc70f2cb3ec56966284ebb22d1883b1",
              "sha256": "dcccf2528084116a3ab9000baee606a763bf76a6cccc4abd97192ad6f71ed0af",
              "sha512": "12046b5890fbe9a4ffeead2580a89e6ff327f984cb4d12bc4eeed405aa79c0437ce51dca9e2dcd42d2689fc47eb8221300eccdeadb0a5d0c510825e616756142",
              "rh_hash": null,
              "ssdeep": "96:rcuQbHQjiVyZSnbbpkp8uSPlqiAJACPgJ16sHEaaFqOMcZ:4uQDQ+kZSnbbeviAJLPgqiEnqHcZ",
              "type": "PNG image data, 180 x 42, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15FB17FC8BC13AFF151C7C2C72296413256D1D859D258491BC509DE296D0379F74E49B7",
              "sha3_384": "7ed4a9d092b212c54bda2071d12da38c496c5c83c5a36f75af8b232ac5fdb56dd597c3f77fca03c00e3e05668e07e142",
              "data": null
            },
            {
              "name": "55a67dbb497ce9b161194c9def966f0d90f663eec41a8f5795d9e2fa9cd8aae3",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/55a67dbb497ce9b161194c9def966f0d90f663eec41a8f5795d9e2fa9cd8aae3",
              "guest_paths": [
                "cpbcrypt.dll"
              ],
              "size": 208832,
              "crc32": "445D1B94",
              "md5": "c440ecf9208977a0b9f369ec503d1c97",
              "sha1": "ae07ed3da33513c2672193daa4e14abdbda4729b",
              "sha256": "55a67dbb497ce9b161194c9def966f0d90f663eec41a8f5795d9e2fa9cd8aae3",
              "sha512": "d2b51b61af12a49e37de4e210a4c4c5dad648bedd939578b6f35a2ce0dd1b324ddaf44a6948e623ed25c73371ae96ba2240bc48e6b3e489ac915bc1108e0f8db",
              "rh_hash": null,
              "ssdeep": "3072:q6X81WxV06rUJVscgKhcfhYVQCe82IhT9f3bDMqqDLeA5MqqDL2/oHADzmvo:q69czKf6V482qT9EqqDLeASqqDL6oGb",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [
                {
                  "name": "embedded_macho",
                  "meta": {
                    "author": "nex",
                    "description": "Contains an embedded Mach-O file"
                  },
                  "strings": [
                    "{ FE ED FA CE }"
                  ],
                  "addresses": {
                    "magic3": 189144
                  }
                }
              ],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T154148EC067734BA5D41E0F39E6AB5F6A653A17FD2F44D197CB003E4A58162E353382AC",
              "sha3_384": "ab793b8ec2b5ca62f8c2440cf780cf7719cedf88dc998736644a652688b4a5735284a22a360d81d4cffb9206aa3a7248",
              "data": null
            },
            {
              "name": "599b4f2286a8cb61a790ce238cbd87360707996f7a030fa37a93c5e0fbcc90bd",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/599b4f2286a8cb61a790ce238cbd87360707996f7a030fa37a93c5e0fbcc90bd",
              "guest_paths": [
                "CPEPC_PLAP.dll"
              ],
              "size": 236344,
              "crc32": "C4FFD2C5",
              "md5": "dd7b4f652a19a5dc8b84931873c9441a",
              "sha1": "12a284c194e0b0d30860815ac4e880640195659b",
              "sha256": "599b4f2286a8cb61a790ce238cbd87360707996f7a030fa37a93c5e0fbcc90bd",
              "sha512": "269bc639f14bbabb454a3f3d4aff19f29c0f01db6d6f85a2da21609ae720764fdb2ece443d4b4a91510be22b9f76b2816e41bb1dba5ce2673549be8d7c875ed1",
              "rh_hash": null,
              "ssdeep": "3072:6x7PZmZsDvMGIcaCtzT86LEnqrXmOnQRK8S/raXs3JKDh7n:6x7ZmZs4Gvf+Ormsw",
              "type": "PE32+ executable (DLL) (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T103343A12BEB944ABE835523CC45A1663B3F1F4023314678F271C5E6A9E6B3C9792FB11",
              "sha3_384": "a4e0fb825078ef065dd305f82e266cd9e9c530a44a060f8db0b3b2492d6a517b900ce4715969d363cee704ad35da611b",
              "data": null
            },
            {
              "name": "9973b9506e58686bce29679de6396acb5e1ccb510ad6efce829e052ce882f9c9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9973b9506e58686bce29679de6396acb5e1ccb510ad6efce829e052ce882f9c9",
              "guest_paths": [
                "cpmsi_tool.exe"
              ],
              "size": 75712,
              "crc32": "60DBE259",
              "md5": "f7c83bdd0cbaf041fc91017c7a6acb67",
              "sha1": "d0327b804551a579f24a8d5bc8008fadf420fea5",
              "sha256": "9973b9506e58686bce29679de6396acb5e1ccb510ad6efce829e052ce882f9c9",
              "sha512": "1a1f4ad3607d20e9740eaa670d5bf3af735ab90516e9a84cead83ea5806c7cd214e2bf53d290e9e8ed1c4febc48d2349f99d27bb755847e790e576e0de9d5ea2",
              "rh_hash": null,
              "ssdeep": "1536:okHf/ILTlhvpaHNjZhdiefx4ver+KZxrDdcN57D:owmlvaHNjZhdiefker+ixrD2vn",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DF731A42B7FA8124F5F266B42D715BA1957EB9E4FF30C2CFA34049191961B90AC34B3B",
              "sha3_384": "04ce7aec7daf1145456789cb1262e8df432a2388fee0331ae5ea25eddf1df5d01ce8c51580137dcce295ce69d85675aa",
              "data": null
            },
            {
              "name": "f80126c2e93c5c4af41f5d9bcd092718be36f97b565898acc2f7f97c3b74b695",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f80126c2e93c5c4af41f5d9bcd092718be36f97b565898acc2f7f97c3b74b695",
              "guest_paths": [
                "cpopenssl.dll"
              ],
              "size": 2236864,
              "crc32": "5599BAED",
              "md5": "671921bb517de16ab99145c4391b4e8f",
              "sha1": "346dbc08ff4bd7df02bfa9d674db9bec6aff92b0",
              "sha256": "f80126c2e93c5c4af41f5d9bcd092718be36f97b565898acc2f7f97c3b74b695",
              "sha512": "a0f8c18a3fd7f99120456d63e90d6d77dc326af30b793051d12ae56d0d6de521c2f1bc64af934a1817c05c3ef324e5101e9dc765faf3acf5f4e2149ab52c8233",
              "rh_hash": null,
              "ssdeep": "49152:N954a/brI79qtPAo3jx8f1CPwDv3uFgm9Nex4/MJ0MR:N954anIYmcx8f1CPwDv3uFgm9NW",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T127A5AE03FB8695B2EADE457D61A7577F4D3756149338C9D38BA22C618C226D0623F3C8",
              "sha3_384": "7137a537b9ad18f57d2a07711eb6d2bbba41068dff7c48e37363406101811fb4de7e85fbc34a71577c9490941c05837e",
              "data": null
            },
            {
              "name": "b190acdfb16aef71f3c784c0671a7dc861d8aec2a9a6035d2b8afafea0127233",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b190acdfb16aef71f3c784c0671a7dc861d8aec2a9a6035d2b8afafea0127233",
              "guest_paths": [
                "cpprng.dll"
              ],
              "size": 1409472,
              "crc32": "3059CB67",
              "md5": "dc1726830b9205f14f7f84d7b86cf9cb",
              "sha1": "4211b3bc7a61deffe30bed8597814b919ce7e9b3",
              "sha256": "b190acdfb16aef71f3c784c0671a7dc861d8aec2a9a6035d2b8afafea0127233",
              "sha512": "9ae9d29eef9221aa0106cc3d58b989f91026787f82e7b84372e0c9a789fd83529988fc4cfd75be72e33edecb6c46675c8c6ada8e5b076bc1aaa9f74544ac73ce",
              "rh_hash": null,
              "ssdeep": "24576:q+idPN1UJIzkQtlgMwFxfa57TU1UzcmIYR8718HtPUIQm8kbZE+6:G1n3vQU5tVCatPUIQmtbZE+6",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19065C003FB8285A2E5CF527851A76B7F9D365A149324C9D3CB916CE28C322D1673F389",
              "sha3_384": "bc18628eb7e6501a499fd63f1eb4183b6b44037d39fa10695c521a1989eacd404c55a4191fa831a82a8e932da32c492b",
              "data": null
            },
            {
              "name": "ad0f1c3044f8dd2571f497b986e5f2bfd5a74ad29f2c1c1e125e9809d274c484",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ad0f1c3044f8dd2571f497b986e5f2bfd5a74ad29f2c1c1e125e9809d274c484",
              "guest_paths": [
                "cptmis.dll"
              ],
              "size": 1610344,
              "crc32": "DBC1C7DB",
              "md5": "1ce6fc2126680a60c65c4bd2cf924ef2",
              "sha1": "879ce4d8c57bcab7e85a7306215f8a3b1df3db1e",
              "sha256": "ad0f1c3044f8dd2571f497b986e5f2bfd5a74ad29f2c1c1e125e9809d274c484",
              "sha512": "ad5863edee55eb755c2ed784fc506d54889e58e1d823813293d39af5bec2cafe2ac2a183c57b94266b3c3e7b5efc16f6ac9a28bf8accac79e718b79053b10b40",
              "rh_hash": null,
              "ssdeep": "49152:I9qjvurnhW3T7p+YfOcx+daPU6kEhLPBJ+aM:I9wubhkp+YWcabEm",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16B75AE03FB4586B1E9CE427461B76B7E4D36AA145728C6D3D7D029A98C312E13B3F389",
              "sha3_384": "7dffd061dc23501d97f7cb175e48fe09f9cf7bc7d6a298686d9c8b11369b52311aa83b7208440fa8c5f4b3444917ec33",
              "data": null
            },
            {
              "name": "43d5118544e40ddf5c94eb6cc4c08117689563ec405b7e3ae09991b9e05eadd4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/43d5118544e40ddf5c94eb6cc4c08117689563ec405b7e3ae09991b9e05eadd4",
              "guest_paths": [
                "cptmsender.dll"
              ],
              "size": 1614952,
              "crc32": "6573F20D",
              "md5": "0e82523007b7090b024ffb9d56ad05b1",
              "sha1": "7b1865cc8a7082e8c0cb1c48fddfc803d6df0e8b",
              "sha256": "43d5118544e40ddf5c94eb6cc4c08117689563ec405b7e3ae09991b9e05eadd4",
              "sha512": "6e579cf68f4786aa40c410fd30e532144ff13461748db455b32a687e3326cf2104fc29e6e9ac4f90c1e600765f77bb31bcff03898742a64d28bff360a35342ab",
              "rh_hash": null,
              "ssdeep": "24576:2+KpPoG+/wNNjaywp59bZI46nL1hk4yu3xQ2LPbQNf/5OuVaaMaPcPGgBbX0fxZj:C7aBlbn6/k63xRvu8DaPcPHX0fxZuq7",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T11175AE03BB8586B2E9CE427462B76B7E4D36DA14932885D3D7D029688C312E1773F7C9",
              "sha3_384": "1ef669566587468c54273a648d5e6bb21fdb35fcee21a6eb1f97a194b64167fec8636a5b474231270d9ea7762fbb62e0",
              "data": null
            },
            {
              "name": "046561237427a78f43b5780dc9c7e312d20ae292f26a4637075fa8f1e34b60c0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/046561237427a78f43b5780dc9c7e312d20ae292f26a4637075fa8f1e34b60c0",
              "guest_paths": [
                "DAAW.exe"
              ],
              "size": 306624,
              "crc32": "5293B6DC",
              "md5": "3bfb71ff5cc5ab2f5d7426013ce9a83c",
              "sha1": "f29d71a91472a59b1c62fee83a9081fc45508234",
              "sha256": "046561237427a78f43b5780dc9c7e312d20ae292f26a4637075fa8f1e34b60c0",
              "sha512": "6f35330fedf683e24739383a2fd535753fb5329e045e464cf601b05b7ba78084201531b9b718396a0b99cf3867754c35f3f9ad7c26fedb79049e4939013277e2",
              "rh_hash": null,
              "ssdeep": "6144:Ubb/pSqzhRxlriBAeFo3L8DJPFP6K+YJ9q8EECdY2h/EZ2Mht8sYJW61pPr:Ob/pSqzhRxlriBdIL8DJPFP6K+YJ9q8y",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T186647D1277058472EA4602B62A99177BC03C9D345F21A2C3E3C57B69A9713E79E33F27",
              "sha3_384": "19c3868fd34f2e72c98488496e6e7fe92074cc36e399167263e7be0fb8cdaf5e0b69dc05737c8a3433bfecf329722cc7",
              "data": null
            },
            {
              "name": "7204ebdd8fb01f614b5685aa3f8ccd94be2fc09b81f546cf088989957f9ca033",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7204ebdd8fb01f614b5685aa3f8ccd94be2fc09b81f546cf088989957f9ca033",
              "guest_paths": [
                "DAAW_help.txt"
              ],
              "size": 2568,
              "crc32": "FBA1F58A",
              "md5": "52bf5f4ac667a956002a2961232989cd",
              "sha1": "63acbd79b9aa8932e6335e59f1bae96b7502e268",
              "sha256": "7204ebdd8fb01f614b5685aa3f8ccd94be2fc09b81f546cf088989957f9ca033",
              "sha512": "4f33f0190be0d905945b491c98fe63acaedf27002f777ac6b16294818fcdf35cba55abddc1a7e8a0eee0dca8c83921b82d750b37b614b7210ae653c433723197",
              "rh_hash": null,
              "ssdeep": "48:WPcxYx42+Qc6sP+Qg3GldN/y41UL5aw3iy3eFAnswx:WPcmFc6OF6GB6V3X3xnT",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14B516446BECCA4A3C26E0127183C9BC22A3DB17D55F7C444FD7EA584AE40CCAAA470E5",
              "sha3_384": "5129373d0618c824b2a5966b80ad14976e2b41ffc7d9b08cb66a131c0380f391df0ce32507ca4460467a3e204bdfce8d",
              "data": "# format\n#\n#{\n#Command\n#\n#Command description (no comments allowed)\n#\n#}\n#\n#\n# Based on the admin guide - command_line section\n\n#Command Line Usage\n{\nusage\n\nCheck Point Endpoint Security DAAW command line usage:\n  DAAW <command> [<args>]\n\n  where <command> is one of:\n\n\tgetProxyAtt [-d 1]\n\t\t\tget the proxy configuration for the logged on user (-d for extra debug info)\n\n\tsetProxyAtt  [-flags <proxy flags>] [-url <the url of the proxy auto configuration script>] \n\t\t\tset the user proxy configuration\n\n\tdownloadFile [-url <file url>] [-fileName <destination file full path>] \n\t\t\tdownload file from the internet.\n\n\tgetProxyForUrl [-pacFileUrl <proxy pac file url>] [-host <host ip>]\n\t\t\tget proxy server for specific url\n\t\t\t\n\thelp [-c <command>]\n\t\t\tprints usage information\t\t\t\n}\n\n\n{\ngetProxyAtt\n\n\tCommand: getProxyAtt \n\n\tDescription: get the proxy configuration for the logged on user.\n\n\tSyntax: DAAW getProxyAtt\n\n\tArguments: \n\t\t\t-d pass any value to enable debug mode (will print IE-alike proxy information)\n \t\n\tExample:\n\t\t\t>>DAAW getProxyAtt\n\t\t\t>>DAAW getProxyAtt -d 1\n}\n\n\n{\ndownloadFile\n\n\tCommand: downloadFile\n\n\tDescription: download file from the internet.\n\n\tSyntax: DAAW downloadFile [-url <file url>] [-fileName <destination file full path>]\n\n\tArguments:\n\t\t\t-url\t\tthe url of the required file.\n\t\t\t-fileName\tdestination file full path (on the local machine)\n\n\tExample:\n\t\t\t>>DAAW downloadFile -url http://pac.proxypac.checkpoint.com/wwproxy.pac -fileName C:\\temp\\my_local_copy_of_proxy.pac\n\t\t\t>>DAAW downloadFile -url 192.168.10.10/wwproxy.pac -fileName C:\\temp\\my_local_copy_of_proxy.pac\n\n}\n\n{\nsetProxyAtt\n\n\tCommand: setProxyAtt\n\n\tDescription: set the user proxy configuration.\n\n\tSyntax: DAAW setProxyAtt  [-flags <proxy flags>] [-url <the url of the proxy>]\n\n\tArguments:\n\t\t\t-flags\t\tproxy flags - see 'INTERNET_PER_CONN_OPTION' in msdn - .\n\t\t\t-url\t\tthe url of the proxy server\n\n\tExample:\n\t\t\t>>DAAW setProxyAtt -flags 5 -url http://pac.proxypac.bobo.com/wwproxy.pac\n\n\tThe flags argument:\n\t\t\tthis is a bit mask of the follow:\n\t\t\t0x00000001 - Direct - The connection does not use a proxy server. THIS SHOULD BE ALWAYS ADDED ????\n\t\t\t0x00000002 - manual defined proxy flag (#3 below)\n\t\t\t0x00000004 - 'use automatic configuration script' flag (#2 below)\n\t\t\t0x00000008 - 'use automatically detect settings' flag (#1 below)\n\n\t\t\t[#1] Auto Detect\n\t\t\t[#2] use auto configuration script\n\t\t\t          script address: http://pac.proxypac.bobo.com/wwproxy.pac\n\t\t\t[#3] Proxy Server (manual)\n\t\t\t          address(ip:port): proxy5.bobo.com:8080\n\t\t\t          bypass: *.local\t\t\t\n}\n\n\n\n\n"
            },
            {
              "name": "ba62a23092b70cdf626d27560e904e3b7a830fc45295d1a5a8894328a61be1a8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ba62a23092b70cdf626d27560e904e3b7a830fc45295d1a5a8894328a61be1a8",
              "guest_paths": [
                "DataStruct.dll"
              ],
              "size": 210368,
              "crc32": "BC3DDDCC",
              "md5": "ee71bb9c44ffa67e9991affaeee0e376",
              "sha1": "f5f66aa75e1d305b5b6995d0a1f13252867b5157",
              "sha256": "ba62a23092b70cdf626d27560e904e3b7a830fc45295d1a5a8894328a61be1a8",
              "sha512": "94c30f1a4c82739aeaaff4b31253eab37891fed6d342d146b0e372805523ab07c68e057a6ae16eefd4f85d1620a41f95def1654d3ebbd658f868e5d2c2f01338",
              "rh_hash": null,
              "ssdeep": "6144:dMQmKvEkTsUen7hPMICeOLv+ENdNv6yf5:dMnKvExUI1PMjeOLv+EdR",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EC249E51BF92863BDA5F92B959AF073B1925D34087258AC3E34E0D2D9C233D61F3B285",
              "sha3_384": "50aac107e08e0ee355522f7e4474f7cfbf91d67a9f398e54843875d16af8d7fba919b87854d9c97def942109c4e1bcda",
              "data": null
            },
            {
              "name": "4e7d264cfc6627286ced0c65b5c22ecc27cf1b0078b6823e68bbabc0cb86f370",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/4e7d264cfc6627286ced0c65b5c22ecc27cf1b0078b6823e68bbabc0cb86f370",
              "guest_paths": [
                "default.toml"
              ],
              "size": 1491,
              "crc32": "9EFAF669",
              "md5": "6bf6927c23509ce15028ca1cd7a7d532",
              "sha1": "c5053d705635e9fe43720505927df7eb280d556a",
              "sha256": "4e7d264cfc6627286ced0c65b5c22ecc27cf1b0078b6823e68bbabc0cb86f370",
              "sha512": "1293612c0d148f7a3c3e67d503839ed824aaa93b7e92c98d8fd69e9e34c145514b7e2c7b4ff4af253a0aec83fc7db289dcab0838f1e0fbf96d157c3e4d91ebb6",
              "rh_hash": null,
              "ssdeep": "24:wPJwUQ2YhemBmmBVBQ+qM+arTUcPSKf/lSfoFhCWKf/RsttAJoFcajY4hbaF4hbL:wxwQ9WIdg7f7hcf4hZhThe/IAahjhCs9",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E0317F6A488A1F1E2F7DF804A98D3548FD3591916576B1946BC4B68EC0C0C5BE7C3C59",
              "sha3_384": "d7c61b08eb40ce08beee4f1fe8ccbd47b51602ecae17a2c02514879bbb806f5d4ae489ce9e5e81091a865b3ad224f688",
              "data": "# level is optional for both sinks and loggers\n# level for error logging is 'err', not 'error'\n\n#supported variables\n#{folder}     - %programdata%/Checkpoint/Logs\n#{userfolder} - %LOCALAPPDATA%/Checkpoint/Logs (for user processes)\n#{filename}   - exe name without extention\n\n# max_size supports suffix\n# - T (terabyte)\n# - G (gigabyte)\n# - M (megabyte)\n# - K (kilobyte)\n# - or simply no suffix (byte)\n\n# check out https://github.com/gabime/spdlog/wiki/3.-Custom-formatting\nglobal_pattern = \"%Y-%m-%d %T.%e t:%-5t %-10!n [%-5!l] %v [%!]\"\n\n#could be used for UT projects\n[[sink]]\nname = \"color_console_mt\"\ntype = \"color_stdout_sink_mt\"\n\n[[sink]]\nname = \"rotating\"\ntype = \"rotating_file_sink_mt\"\nbase_filename = \"{folder}/{filename}.log\"\nmax_size = \"20M\"\nmax_files = 5\ncreate_parent_dir = true\n\n[[sink]]\nname = \"rotating_daf\"\ntype = \"rotating_file_sink_mt\"\nbase_filename = \"{folder}/DAF/{filename}-dafadaptor.log\"\nmax_size = \"10M\"\nmax_files = 2\ncreate_parent_dir = true\n\n[[logger]]\nname = \"root\"\nsinks = [\"rotating\"]\nlevel = \"debug\"\n\n[[logger]]\nname = \"foundation\"\nsinks = [\"rotating\"]\nlevel = \"debug\"\n\n[[logger]]\nname = \"bf_msg\"\nsinks = [\"rotating\"]\nlevel = \"info\"\n\n[[logger]]\nname = \"essentials\"\nsinks = [\"rotating\"]\nlevel = \"debug\"\n\n[[logger]]\nname = \"cppsm\"\nsinks = [\"rotating\"]\nlevel = \"debug\"\n\n[[logger]]\nname = \"daf_dsm\"\nsinks = [\"rotating\"]\nlevel = \"err\"\n\n[[logger]]\nname = \"daf\"\nsinks = [\"rotating_daf\"]\nlevel = \"debug\"\n\n[[logger]]\nname = \"bladeis\"\nsinks = [\"rotating\"]\nlevel = \"info\"\n"
            },
            {
              "name": "19e56b1d51fa8850d6e29244073af31d6cc69f667581476068c733a391ca3d2a",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/19e56b1d51fa8850d6e29244073af31d6cc69f667581476068c733a391ca3d2a",
              "guest_paths": [
                "disconnected.png"
              ],
              "size": 485,
              "crc32": "9D38F046",
              "md5": "e7c1fa299e0dc5fb4d2fef5e70ee5331",
              "sha1": "94108ae0181966eeb6fee68864e20af245bd824b",
              "sha256": "19e56b1d51fa8850d6e29244073af31d6cc69f667581476068c733a391ca3d2a",
              "sha512": "4f92eff8341b532c31b83989c9d474e3ba5b75f6b92d15630aee736bc48d4bc9ed81695b94c1223fcf5ef6b61c1126eeda961fd403e48d06d51752979dfdf647",
              "rh_hash": null,
              "ssdeep": "12:6v/7tY6S0/Ewjw7cSFyxAIOqzKgafU1CHP/p9:P70Jjw7tiXOqz7afU1eP/p9",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12CF054E37903F926601883D663023351D9EC2042CBD13022D200089DAFED0D517F4FA7",
              "sha3_384": "2461c5ecfd0f07c4f5a26a9420b913c11165fb355ffac95552a9cebd72625ddced6e93a9a5f178460e0b6a2b7f7fd65f",
              "data": null
            },
            {
              "name": "c3a365570c7cb2dbc59404bf3cf76bce6bb3747ddb74e9424979b9a11c27236c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c3a365570c7cb2dbc59404bf3cf76bce6bb3747ddb74e9424979b9a11c27236c",
              "guest_paths": [
                "dtplat.dll"
              ],
              "size": 49600,
              "crc32": "F129CD18",
              "md5": "451fa761b156ed97c9559bc538db3490",
              "sha1": "1be714802fd131df28447325bc8bc672b855e4b6",
              "sha256": "c3a365570c7cb2dbc59404bf3cf76bce6bb3747ddb74e9424979b9a11c27236c",
              "sha512": "a2ec7e407a42b940f15825f5703b971ec8bd241d0d80d9a5d76de4d5de1f66f879e4f24aaa914756c0e36458587bb6dbd63f4bad584b9004b45e560284ee8165",
              "rh_hash": null,
              "ssdeep": "768:j9JvDlG1BECoNm/WyXq5jr86yoMbKQdAgMr+gKDyQkkNlT5YiXX:jZC0m765jr86yrJdmr+gKDyoN57XX",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T11B238D02AA01C1F3DBCE427438A55B2F1CBEE9405BE182C3538346ADD9A13D5FE79297",
              "sha3_384": "e8449b23add1b21bc0c5e2392322ebeef771febc3bf4d7e73db440ecd4cbcc6f593d737c95cdb1c65a8f7925da84d9be",
              "data": null
            },
            {
              "name": "0e77808dad80f3d4b02b1f48f5674e78456321aec63550658cb7d0f09cc3eaf2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0e77808dad80f3d4b02b1f48f5674e78456321aec63550658cb7d0f09cc3eaf2",
              "guest_paths": [
                "encryption.gif"
              ],
              "size": 1158,
              "crc32": "65C2EF21",
              "md5": "f8bae6877b3438dc7910c1b90de966e7",
              "sha1": "fe1f88c8d86049550d2e6765f88c065751b5c4f6",
              "sha256": "0e77808dad80f3d4b02b1f48f5674e78456321aec63550658cb7d0f09cc3eaf2",
              "sha512": "3d323ae1cce5aa1f38cf5bc1618bb49cf0cc6a0d657be9fee38cf920f2ee35865bede4e1d96d913a8e52c8e52dd992523cfe266bc959cb42404447f34dbf2cde",
              "rh_hash": null,
              "ssdeep": "24:O0oSvH2yg4X81bfg7OE83QYPRNaX0BgCgcRC5Z2+PLe:IWWybyb47OxrRNakBgCFcD2iq",
              "type": "GIF image data, version 89a, 16 x 16",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19421A79E06908AA1850614BABC15CB3C5CBDE09BEC4D37563E0B2850DFB118CD89FA33",
              "sha3_384": "2217a4552aa3e5a93a1c6c9731c325d72fa717fd3498f2a47af3e67ba88900091ec181727a4f8950d18bc1035210c1d2",
              "data": null
            },
            {
              "name": "0901eb5bffd0e0e21f389fbe619cea63470443b4f4d216f63d9b2d6b19d152f6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0901eb5bffd0e0e21f389fbe619cea63470443b4f4d216f63d9b2d6b19d152f6",
              "guest_paths": [
                "endpointConnected.png"
              ],
              "size": 6075,
              "crc32": "68B46AE2",
              "md5": "bd0ddcabd65638469a47c9df4e361bd8",
              "sha1": "3c68dbb61073bf7a39601dd814efe34ab8f2fee7",
              "sha256": "0901eb5bffd0e0e21f389fbe619cea63470443b4f4d216f63d9b2d6b19d152f6",
              "sha512": "b5ef837fe9dd90531065909c1f4b99cbf1de8da10156052428e88f80b24501943b45061b5d4df4ab5ad946726510fafc38c166d7fa7e9e6386787445b7fe1566",
              "rh_hash": null,
              "ssdeep": "96:HGPMG5tMwPD1e9wBJf+pkOBkryth2irGPXpL9wclqp6s34PitwU9MBYZ:mFLLeLkOBYy/2m6J9Z76Z",
              "type": "PNG image data, 48 x 49, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1BFC19EA2B196E1FDC144682388F2D4FFCE3C9BAA531684056A36E59092564F4C3BE2D3",
              "sha3_384": "2dd415ae9774e6c62c351da22caefb22b9fc3ccdfeaa864de1c511f2b0e929b53a35fca44aa8dba144b7237cddf6dc88",
              "data": null
            },
            {
              "name": "902fad0f910aecab369a5d3618a259a98ca7cf472872d8bab56e6bf977fc6adb",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/902fad0f910aecab369a5d3618a259a98ca7cf472872d8bab56e6bf977fc6adb",
              "guest_paths": [
                "endpointDisconnected.png"
              ],
              "size": 2155,
              "crc32": "FFA2FD77",
              "md5": "09dc5d4762e55f52dab4c79ca6e58996",
              "sha1": "0b7f5e913371de1c1556d935c34e2380e9fd7138",
              "sha256": "902fad0f910aecab369a5d3618a259a98ca7cf472872d8bab56e6bf977fc6adb",
              "sha512": "7285e3729f47f935d70b35272cebf0efe6690653ba03a3eb2189307b5128f5e4597ebfc23517e4291de6292d314c225c2e628b3ff89bd2b77356633d9de6ea41",
              "rh_hash": null,
              "ssdeep": "48:KUp+LQ7uhtqBTbAmkqvo8bCKB1mR5XfZcZt6q6/:xALn6zy8bhWhceq6/",
              "type": "PNG image data, 49 x 51, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A5411A455953D93D9C1187D018DECA2034B766F8FC6F98E6495393AC64E874983A2F82",
              "sha3_384": "bc0a9446375642cf2bb0d27e2907862f56ac8e95974fe151b8d302c375361e53c20fc62aec6935ff3a746c6767f82369",
              "data": null
            },
            {
              "name": "f406b4a33620719800a7f13ca2ae8d4461e9886e913c38f5a085919fa6eb431c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f406b4a33620719800a7f13ca2ae8d4461e9886e913c38f5a085919fa6eb431c",
              "guest_paths": [
                "EnterpriseChecks-Disabled.bmp"
              ],
              "size": 2254,
              "crc32": "019DC0F9",
              "md5": "f9cf5e189af97ba218f8faffdb5394ad",
              "sha1": "a0aacafed12a0129422de3dddf69a5aeedd4e7b7",
              "sha256": "f406b4a33620719800a7f13ca2ae8d4461e9886e913c38f5a085919fa6eb431c",
              "sha512": "6273bced43d82b91ee303e6ee02807de85e13e9236250682c0da0d7562f967ae9fa8a522f3cfdff4fd17b1b2f4ca479fecdac2efe4c1bc7613bf448176c18b12",
              "rh_hash": null,
              "ssdeep": "48:lDtDMlhq+4oa+vrtl0yMtWzLNiQw2qaa+3Ia4aaa+wIaas6Y:lDtIPqIa+Ttliww2qaa+3Ia4aaa+wIal",
              "type": "PC bitmap, Windows 3.x format, 29 x 25 x 24, image size 2200, cbSize 2254, bits offset 54",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EC4182DE2B151362F55D223834249F263D30352CB3A0B2C86E34478076F538726BD6A8",
              "sha3_384": "679c8633fc26e50bb7eacc9df874f3f98b8adb9d99dfe0cb7e4aa1ea95b2626214fe31ddb6fd5755f38690b9777fe2fa",
              "data": null
            },
            {
              "name": "01be6cfcf5ad4c60e9a732c61859409d6df0ee62c587c83f7a8617572283021f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/01be6cfcf5ad4c60e9a732c61859409d6df0ee62c587c83f7a8617572283021f",
              "guest_paths": [
                "EnterpriseChecks-Error.bmp"
              ],
              "size": 2254,
              "crc32": "F2A84E29",
              "md5": "a4f60160dfd6a1c1f07654cbed6e2a2c",
              "sha1": "0688e2ab32db2f4bb65f9aec235f86af5d908827",
              "sha256": "01be6cfcf5ad4c60e9a732c61859409d6df0ee62c587c83f7a8617572283021f",
              "sha512": "e6e47d3c6468840a1fd70dbd5da52a230b6dc662ace13fe96d09959f2a38511d08b10a662807d2eb8709eb418dfb01d93a28b97877b8d242ba190b4347112a04",
              "rh_hash": null,
              "ssdeep": "48:I5s6NGZ4kFPM98gCfJ/fmEuV1priUBTTTTTTTTlN7lQslOmW3:IO6NcTO9tCxx+6U3N2Bh",
              "type": "PC bitmap, Windows 3.x format, 29 x 25 x 24, image size 2200, cbSize 2254, bits offset 54",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DF41D9870B3107B3ECC456F73295630E2D429D2636585C746D73B88CF1B02DF049E292",
              "sha3_384": "36b13c0794bcfcdffd02a1cddd0d0003c4aa4a2524e4bea5a5183449a524f70a3e703246c5677e8727db3a90195d8830",
              "data": null
            },
            {
              "name": "89dfd8ea2a38b9c19ca8c5fbeb0c9629e6beae8914b4b9ab5bac4676aad8dd7d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/89dfd8ea2a38b9c19ca8c5fbeb0c9629e6beae8914b4b9ab5bac4676aad8dd7d",
              "guest_paths": [
                "EnterpriseChecks-OK.bmp"
              ],
              "size": 2254,
              "crc32": "82B87A74",
              "md5": "7c17308d7ffd8ccb36fd291a0aaa3609",
              "sha1": "6b9430b3d8701b2bdbfef252fad301767b7ececf",
              "sha256": "89dfd8ea2a38b9c19ca8c5fbeb0c9629e6beae8914b4b9ab5bac4676aad8dd7d",
              "sha512": "7386961847c414030c56a718dcdefd6b0ac045773fc82812fcb80f273780c80a68076d6b1b2fd921bb60e1f7167da66224e1f138a0439d1d2ce8d47c76ad4f4d",
              "rh_hash": null,
              "ssdeep": "48:ZZQa0DpJLtzWpV6xLL+zilYYEiiCi0iiiGViuh4VR:ZZQbTxzuV6UWmrY0R",
              "type": "PC bitmap, Windows 3.x format, 29 x 25 x 24, image size 2200, cbSize 2254, bits offset 54",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1914142027E56A37CF5B6777A0280A9C336F49D0329ECFED5EE25B5036A3B44CAC15242",
              "sha3_384": "af96bb729aa295810832619f25731d97033d9bf05962cf6f9da442f7c97718bbdf05640ad9b97f85b4cf369d1c0be6c9",
              "data": null
            },
            {
              "name": "e984a835e4fc44338419407d4b0b9bbcb0cf6b19f6e4da25e35d8f73ebe6af2e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e984a835e4fc44338419407d4b0b9bbcb0cf6b19f6e4da25e35d8f73ebe6af2e",
              "guest_paths": [
                "EnterpriseChecks-Warning.bmp"
              ],
              "size": 2254,
              "crc32": "37C4050B",
              "md5": "210086f9f11c62028f3578f9b784a512",
              "sha1": "2009c3ebf538b1915dc429d2c1ed5bdc06e6b26e",
              "sha256": "e984a835e4fc44338419407d4b0b9bbcb0cf6b19f6e4da25e35d8f73ebe6af2e",
              "sha512": "011b1589d1fd75c19f9703549c667f1c93de0f69055f1a4a42dfcaeb2a71d31ce8b8f69b30294f845e6740348b3a807e7cf8559676efd5d159d7268d2ccb5005",
              "rh_hash": null,
              "ssdeep": "48:Jqc03DdQ/V2p7+ocktorrfDrrYhottthutttR7Y1Px:M7aV27+VOorr7rrYetttstttREf",
              "type": "PC bitmap, Windows 3.x format, 29 x 25 x 24, image size 2200, cbSize 2254, bits offset 54",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1714140B9680D2062DDF76073A1EA40EF63D97706A3BB42570C699D813B94C0FBC36A13",
              "sha3_384": "8dec7d64bde57add2dc12cd57d116844629a5f1d927c66d321e6b8527ff08f873c31865d0b701ca38f782a8a89012139",
              "data": null
            },
            {
              "name": "07a129fb428e5a139c7e33b18b4ed7f95cf558b377776145fcb34f3a8c82a221",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/07a129fb428e5a139c7e33b18b4ed7f95cf558b377776145fcb34f3a8c82a221",
              "guest_paths": [
                "EPC.ini"
              ],
              "size": 1939,
              "crc32": "DD8E2503",
              "md5": "28ed3e1e9904b7a92f47935a4baf8e77",
              "sha1": "eb96bd014f1f7fbcc4af54428ed9e449fa4efd65",
              "sha256": "07a129fb428e5a139c7e33b18b4ed7f95cf558b377776145fcb34f3a8c82a221",
              "sha512": "585ee470dba3bde6d3e77886d6ec2584634a864ad5fe87a41d6ffee6214abfb2656a43fcc8e7edf973d6115f02a11dc637ebf07034ca70fcfa3813dab9ed66a3",
              "rh_hash": null,
              "ssdeep": "48:FAO04evXBZ77af1wynJnHGv5neXRORSiDVzCfAdDtoD8ci:OvXzg7nJnmv5neXWSiDVzC4dxogci",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1FA41312394FA051C613C361A3EDB9081CD319C8D43A134353BC895EC822ABF1B9B6FDA",
              "sha3_384": "9e314e902899881ca280a6b185165ce3f826c7accdd40935dc251c373f5058bb3727fbbbf63a3e1dec13d4873ca026f8",
              "data": "[ExplicitVariables]\nPGRFILES =\t$ProgramFiles\nINETLOG = \t$windir\\Internet Logs\nTEMPDIR = \t$TEMP\nSYSTEM32 = \t$windir\\System32\n\n\n[RegistryVariables]\nINSTDIR = \tHKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\5.0\\PRODDIR\n\n\n[ProductName]\nName = \t\t\"EPC\"\n\n\n[CopyFilesAlwaysLow]\n;=====================\n;Configuration Files\n;=====================\nEPC_Trac_Config \t= \t$INSTDIR\\trac.config\nEPC_Trac_Default\t= \t$INSTDIR\\trac.defaults\nEPC_Trac_DDF \t\t= \t$INSTDIR\\trac.ddf\nEPC_Ver \t\t= \t$INSTDIR\\ver.ini\nEPC_DesktopSet \t\t= $INSTDIR\\desktop_policy.ini\nEPC_userGroups\t\t= $INSTDIR\\user_group.ini\nEPC_ConnectXml\t\t= $INSTDIR\\ConnectedPolicy.xml\nEPC_DisconnectXml\t= $SYSTEM32\\vsconfig.xml \n;=====================\n;Logs Files\n;=====================\nEPC_Trac_Install \t= \t$windir\\Temp\\trac_install.log\nEPC_Trac_Capi \t\t=\t$APPDATA\\CheckPoint\\Endpoint Connect\\trac_capi.log\n\n[CopyFilesLow]\nEPC_Logs \t\t=\t$INSTDIR\\*.log\nEPC_Extra_Logs\t\t= \t$INSTDIR\\*.log.*\nEPC_AppData_Logs \t= \t$APPDATA\\CheckPoint\\Endpoint Connect\\*.log.*\nEPC_AppData_Extra_Logs \t= \t$APPDATA\\CheckPoint\\Endpoint Connect\\*.log\nEPC_DMP_FILES \t\t=\t$INSTDIR\\*.dmp\nEPC_AppData_DMP_FILES  =  $APPDATA\\CheckPoint\\Endpoint Connect\\*.dmp\nEPC_TEMP_AutoLogs\t=\t$TEMP\\Check Point Endpoint Security\\*_auto.cab\n\n;=================\n; REGISTRY SECTION\n;=================\n[RegistryLow]\nCheckPointSoftwareKeys\t\t=\tHKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\n\n\n;===============\n;METHODS SECTION\n;===============\n\n[MethodsLow]\nSystemInfo\t=\tTRUE\nRoutePrint\t=\tTRUE \nIpConfig\t= \tTRUE\nNetStat\t\t=\tTRUE\n\n[MethodsHigh]\nMsInfo\t\t=\tTRUE\n\n;===============================\n;Endpoint Connect Custom Methods\n;===============================\n[CustomMethodsLow]\nEPC_TRAC_INFO_COLLECT1 = EPC_TRAC_INFO_COLLECT\nEPC_TRAC_INFO_COLLECT2 = EPC_TRAC_PROXY_COLLECT\n\n[EPC_TRAC_INFO_COLLECT] \nParam = \"info\" \"-t\" \"20\" \"-tr\" \"true\"\nCommandPath = \"$INSTDIR\\trac.exe\"\n\n\n[EPC_TRAC_PROXY_COLLECT] \nParam \t\t\t= \"printProxyConf\"\nCommandPath \t= \"$INSTDIR\\trac.exe\"\n"
            },
            {
              "name": "0e7ef82eb14da1ace577448cecb84f6451c141500206bee437e314ee775fd5d0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0e7ef82eb14da1ace577448cecb84f6451c141500206bee437e314ee775fd5d0",
              "guest_paths": [
                "epcgina.dll"
              ],
              "size": 600512,
              "crc32": "EE3F0CDF",
              "md5": "9dbf627859ff5d501bbea4865870988d",
              "sha1": "2d6ad8e77598ca7adc4db692d430001071c5e96a",
              "sha256": "0e7ef82eb14da1ace577448cecb84f6451c141500206bee437e314ee775fd5d0",
              "sha512": "75dd4b58135c42d9e61ae21c8f1865c4a86650a265f942524cadde14ff4dbc32ef378a42090bff2a04f397b35c821c26e5835d80a8afe20246a6399eb315b12e",
              "rh_hash": null,
              "ssdeep": "6144:eeEVkARP6e+XtqLXZfYUS7mv1xqk2CyJrgknrPYcUI7pxGtyOAJe9oFV/CUgonya:eeA/+XcLXZ8mwp",
              "type": "PE32+ executable (DLL) (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E3D4594DBA844673DC269172CCA12D2BD131BF815254C58EAA14B78DEAFB321F87EF50",
              "sha3_384": "4cb08b9bd8382b424035c72e87bfe92ee2ef7ff83b58b854e4e5f851d611873a7116266ba41caa26e86e5f6e106e51c2",
              "data": null
            },
            {
              "name": "b95bd9e0c796af8e5d094003e735732fd2ffcb98ba4ad5e28f61ae0f2f136157",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b95bd9e0c796af8e5d094003e735732fd2ffcb98ba4ad5e28f61ae0f2f136157",
              "guest_paths": [
                "epcginashim.dll"
              ],
              "size": 163128,
              "crc32": "C5C9F2E8",
              "md5": "f64de43ee9d8f30ca7c5bd0031f202ea",
              "sha1": "c5f78b46246b12595269327219955b6d4fb17168",
              "sha256": "b95bd9e0c796af8e5d094003e735732fd2ffcb98ba4ad5e28f61ae0f2f136157",
              "sha512": "01f040716f3c931664d17152cac60f11de953e5691653fc07bc39ef421eee7253b31a89af1b5d198befb8657ca846cd895441c8018c10409613d6282a47d8bb0",
              "rh_hash": null,
              "ssdeep": "3072:q8xMrR87ZVAdOHFCQ79zMMJKRPHPIkxEDa7K:PC+7ZBlZg2",
              "type": "PE32+ executable (DLL) (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16DF37C5777E100BBE47A9239C9A30A06F7B274151B60CBAF036443765F27391AE3EB61",
              "sha3_384": "828b16ca8ae89b506958e6119495c8d9beb67b824b9bf891b4f24b6ff14daf59383b4fe6d2ef1ccc07958c9b0cb354e5",
              "data": null
            },
            {
              "name": "11253c77d6f9569c9d03e4a96ef510fd72bc2e86ab4c4094d24104096782e875",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/11253c77d6f9569c9d03e4a96ef510fd72bc2e86ab4c4094d24104096782e875",
              "guest_paths": [
                "Epilogue_spdlog.dll"
              ],
              "size": 662976,
              "crc32": "F9794B18",
              "md5": "c61641a9138c88ad1268ef430ed21e96",
              "sha1": "bcc5edcf2722b1a7d107c18117cc012d230a2c2a",
              "sha256": "11253c77d6f9569c9d03e4a96ef510fd72bc2e86ab4c4094d24104096782e875",
              "sha512": "f7b785f9e862016199f9b9a6b2bd4a6e9a6217500f755e177046b82a31beed889b4baeb2bc158bbe2e0295519e402bd43462be3abfbe7aec49fe98bf7ce293c0",
              "rh_hash": null,
              "ssdeep": "12288:bhIQDJliiGU2p8GAshey3wK+GSHwbRzQUBGbU4OqX4Fy+R4zK:9IQDJliiGU2p8GAPy3wlDOqX8y+CK",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A3E47E22BB06C1F9F9EE02F3943C6B7F456D95240B6445C7A6C85B2E59206E32E37B13",
              "sha3_384": "dbf9fdac5f1a459d6ee6de6f18d410d7dfd5194bf073306889525305a1bbebc0e1e27a1731263f1e5dc332f06b4f419a",
              "data": null
            },
            {
              "name": "a77efc801887a45a3a946ba90eabfbaac893d30d74e4872c096cf3c49bdf7667",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a77efc801887a45a3a946ba90eabfbaac893d30d74e4872c096cf3c49bdf7667",
              "guest_paths": [
                "Epilogue_spdlog.dll"
              ],
              "size": 853952,
              "crc32": "BE1C139A",
              "md5": "f6d06cf5536b0655f83cce533456596d",
              "sha1": "e6b61ef50937049bd989d88bb38582c9a48a162c",
              "sha256": "a77efc801887a45a3a946ba90eabfbaac893d30d74e4872c096cf3c49bdf7667",
              "sha512": "038adb150a5073a185cbdcca90e63aebb692011304612737355718445552e4e89809c79ea858c1defad001fb738dee38264f353f6aec97205b6b24e6c869bcd1",
              "rh_hash": null,
              "ssdeep": "24576:Sqhoudyvm6MRK8spRWT2ZlbJNP7ZlAu+6qe4De:SMoBxlV+PDe",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1C80529707D0AC539FB8A01BA99FCBE2F455D8A840F7842C7976C5A196EA41E31F30D63",
              "sha3_384": "f612b007dda785d144816b5a23ec81de54a400ccd1aaf8e7adea309ed2d65674ccb58a044fac08b47b4c2fb8de5489c5",
              "data": null
            },
            {
              "name": "3d470ce4df59c70108d1253271a68633828b5e3a0c79f6c32ae661e7ac152c3d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3d470ce4df59c70108d1253271a68633828b5e3a0c79f6c32ae661e7ac152c3d",
              "guest_paths": [
                "epklib.sys"
              ],
              "size": 171112,
              "crc32": "423AA199",
              "md5": "02e85405a4f6f380562cf82c7c337432",
              "sha1": "cd33694a3b34b0bb472968aeee36c5ca5a1fb1ce",
              "sha256": "3d470ce4df59c70108d1253271a68633828b5e3a0c79f6c32ae661e7ac152c3d",
              "sha512": "03749fc0d424c890194a42f3862a6ab7dec0b6d327fc6ce36c3e82ea9daeb50b00fbbdce904f703932718f06e6b52f9595e1a2bddec5d78d8c1e2180f45c3c10",
              "rh_hash": null,
              "ssdeep": "3072:Ws2aeMPaAWUnz+QFwquYKmeIxPsoKT9gNDhDW4JGCFoRDrg28ub/M:uaxaXQFwquYnLKT9gNDhnDoRBHg",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T154F38D42B4D444F1E093667D8E66B352BA3F92704F3961D752338A6EBA34DF1893438B",
              "sha3_384": "54c8ddd1551d207a929d531aa9e5032972cb52af2367dd0a1b9b646250cab1be521acbe6ebdeb81042f7d4c224a77c88",
              "data": null
            },
            {
              "name": "ffdf61afda10616ec48a28237e4eff5020d28e0ef5b804e36fd4d22257d6ac36",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ffdf61afda10616ec48a28237e4eff5020d28e0ef5b804e36fd4d22257d6ac36",
              "guest_paths": [
                "about.png"
              ],
              "size": 15350,
              "crc32": "58FA0E26",
              "md5": "5fb23e7bb1480ee9385c452fa5113fbf",
              "sha1": "c5f0ccb32f1f487fb18a6014e5f63833300f1d19",
              "sha256": "ffdf61afda10616ec48a28237e4eff5020d28e0ef5b804e36fd4d22257d6ac36",
              "sha512": "bb07ac90963d07955d0109f01c48e03a4b08714c2796b51a9aceae330be32e4eadfc20f76e0a60258e97ac49df1e49aa0544d344c75365c2cfe90c7404f1b05c",
              "rh_hash": null,
              "ssdeep": "384:P97MZIjrmaasoka4iwmSLycSULp5/u37ZqHaDGvos:P97MZYmtsoSiTSLycDG37EmEos",
              "type": "PNG image data, 460 x 306, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14062BF14E651B89E07BD2BA39B1C164F9CF1F6BD4C12034BC645B5CF5B4B904ABB09B4",
              "sha3_384": "6fb4be27e9079efbdad7d205a414212a17a6fd9c729f017b63ce94ccd03ef064cb3ef2cc1fb35da08fb6d59910350855",
              "data": null
            },
            {
              "name": "e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "guest_paths": [
                "endpointBanner.png"
              ],
              "size": 16022,
              "crc32": "207EB6EC",
              "md5": "54a672a163e27e5d3668feaf138fb6ea",
              "sha1": "c9a5074d72dee5173badf4ae3f0d417395c4c0a0",
              "sha256": "e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "sha512": "dab02eb280d80acbaf057dcdd8963b1ba4c367aa482882d071718ba1b4cf9a51756ade37b73adbfb9d0ac5360bcc0d2385b66c0d6709ccf24698d1ebf0a1c990",
              "rh_hash": null,
              "ssdeep": "384:60Sinm2GOulyO/WAYpDUR/wBGuMIe8I5RQZaPJ1VJWYlP4:VjmnyrvpDUR/wBZMF8I5RQ4nO",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12C72D04105CE671FA2F7873A1D8EA76845EA6E254C10518E08C1776B6DBFDEE0D3174C",
              "sha3_384": "6c9004af4f3e2608a3a39cc53b244f79b1ad6d990a55f162b5e360ec75d7a33de0f752ede8a48606dc5b6791badd6ca0",
              "data": null
            },
            {
              "name": "e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "guest_paths": [
                "ConnLogo.png"
              ],
              "size": 16022,
              "crc32": "207EB6EC",
              "md5": "54a672a163e27e5d3668feaf138fb6ea",
              "sha1": "c9a5074d72dee5173badf4ae3f0d417395c4c0a0",
              "sha256": "e15967c7d5e42feed5c66dee1cedf5ba1635e13f4ab32ac7924b1ea5ee5910be",
              "sha512": "dab02eb280d80acbaf057dcdd8963b1ba4c367aa482882d071718ba1b4cf9a51756ade37b73adbfb9d0ac5360bcc0d2385b66c0d6709ccf24698d1ebf0a1c990",
              "rh_hash": null,
              "ssdeep": "384:60Sinm2GOulyO/WAYpDUR/wBGuMIe8I5RQZaPJ1VJWYlP4:VjmnyrvpDUR/wBZMF8I5RQ4nO",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12C72D04105CE671FA2F7873A1D8EA76845EA6E254C10518E08C1776B6DBFDEE0D3174C",
              "sha3_384": "6c9004af4f3e2608a3a39cc53b244f79b1ad6d990a55f162b5e360ec75d7a33de0f752ede8a48606dc5b6791badd6ca0",
              "data": null
            },
            {
              "name": "61d30db71f46858a6217e84d54f644dbd4fdd6fa48462904b2df59de14bd3611",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/61d30db71f46858a6217e84d54f644dbd4fdd6fa48462904b2df59de14bd3611",
              "guest_paths": [
                "CP_Left.png"
              ],
              "size": 11770,
              "crc32": "5C5EBADC",
              "md5": "1bd3221daf71b7d86df2bb5cb2b24805",
              "sha1": "63f160e0abaabbce2e98b1276774db06a4b29695",
              "sha256": "61d30db71f46858a6217e84d54f644dbd4fdd6fa48462904b2df59de14bd3611",
              "sha512": "5a9a81eef3bb19abe5b663152cc3a358580f2f77bb62692dab4c3be5d9ee95f27e6de46b0f115bc25a6b654bc4c6a9bab4811f470bcc3543828e8d4d3d603e66",
              "rh_hash": null,
              "ssdeep": "192:4QlL9+HkGbgbaWvXSZKd4PAR5ScqDGW8Ymde7K+l8uP:hl4dWKZTAREVGW8GW4P",
              "type": "PNG image data, 255 x 42, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12632BF0098166DDDBEC2E52C7A32D854EB03E9AA4EB2CF5255F6C064096FD53A0D3737",
              "sha3_384": "fd0ecc2b386dcb28c8dcec44ec66c07ea27c81627e615cedf621f4b770c7317d131bb57d7de39b87866ca2705ffdecd5",
              "data": null
            },
            {
              "name": "623c9f4d1a254f7401b0214959279af952ffe3fed8aa50a7d4066dac57e96de2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/623c9f4d1a254f7401b0214959279af952ffe3fed8aa50a7d4066dac57e96de2",
              "guest_paths": [
                "endpointBannerBig.png"
              ],
              "size": 17520,
              "crc32": "6017AE40",
              "md5": "3dcd821a4841160ac658b3f3e3fd4298",
              "sha1": "31e5e91bea800e65f42f9111736d7132daa53673",
              "sha256": "623c9f4d1a254f7401b0214959279af952ffe3fed8aa50a7d4066dac57e96de2",
              "sha512": "8fbdea3d118c389d8532297670124929abb765a5353ec0117a659eaf324ac1af8d292855c6121e8ce14f10c2ba8cad4ec72569e87a8ca828b92ddcfafdc2b57e",
              "rh_hash": null,
              "ssdeep": "384:r4PGWRmuf0Q3EZzvKjDxeL0ph8xN4eCxPNn41geA1z4/+:9qmufZ3ezvYvYN4VPNH91kW",
              "type": "PNG image data, 702 x 61, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16872E11B82BA5D2CBCC7A127E64EE2FC509FA01FF58740731B597E123B27A1B5B50540",
              "sha3_384": "e89e3c0f4b4ef21cad42b361e91174f7b4f04fe1eead01f532d3bbeb7ab5b8712d89856bd77d6f35e59dcdfec51a42db",
              "data": null
            },
            {
              "name": "d08022f5b7545fe7069fb2b52062d984f781708a8a056e7e7a9a4de0d6d87506",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d08022f5b7545fe7069fb2b52062d984f781708a8a056e7e7a9a4de0d6d87506",
              "guest_paths": [
                "EPS_ICA.config"
              ],
              "size": 19,
              "crc32": "1D8F7F58",
              "md5": "3299de72583a027be04a2353d9c7c21f",
              "sha1": "d0232dc569bcca8f4bccf847f03af89703e63714",
              "sha256": "d08022f5b7545fe7069fb2b52062d984f781708a8a056e7e7a9a4de0d6d87506",
              "sha512": "bbdf5278346098550ac599ca7defd8015960b0585bab291ca65865e7a3faed5fcee75aca578e948527d57de3219632f0a0ce2b41a61c8b731070f58d66f01735",
              "rh_hash": null,
              "ssdeep": "3:fgQxn:fgQx",
              "type": "ASCII text, with no line terminators",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": null,
              "sha3_384": "b1e24087b7b44214b1dd74fad160b2f1d59b8f1e671b6bbf176d159eaf4c63ba6579cebbe60862df955138a35b7ae31c",
              "data": "FILE_DOES_NOT_EXIST"
            },
            {
              "name": "2c0e74ebf307cdcbc3c9d838356a19682ecae85c3234765522eec123671b0a72",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2c0e74ebf307cdcbc3c9d838356a19682ecae85c3234765522eec123671b0a72",
              "guest_paths": [
                "VPNClient.chm"
              ],
              "size": 54594,
              "crc32": "2584F20B",
              "md5": "108c14019a71fcacdbc0fd8f717f1c3c",
              "sha1": "ca21d9a4c3c74c75af412ca25529b87f7ef26028",
              "sha256": "2c0e74ebf307cdcbc3c9d838356a19682ecae85c3234765522eec123671b0a72",
              "sha512": "29117124023b4996e6d99cdf943e289dc032e366d74c81bc76239cd5bd18d4d8969d65e4744aba841805888c1e8826fee482dc28495a8ca3601008aafa204444",
              "rh_hash": null,
              "ssdeep": "1536:SWy/6qPOt7Vc9jB/I7Up3akTuXgBcm+u9:KSqG0tAURaiuF4",
              "type": "MS Windows HtmlHelp Data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DB33F2885A6A0D0CED1D3B336ED7071DFA13EDAAD52D1F85B3814B2DDBA0415DE0680E",
              "sha3_384": "954760361a1851e1c47829023abf7254cf725900362e4187db9224646a3062138fec758d85a5e62d73b455c75f8d8052",
              "data": null
            },
            {
              "name": "e0252577dfffed61e8960009923893fcb0c4f829e89fcbb8200b382d0e118bca",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e0252577dfffed61e8960009923893fcb0c4f829e89fcbb8200b382d0e118bca",
              "guest_paths": [
                "EPWD.exe"
              ],
              "size": 547776,
              "crc32": "50024B8F",
              "md5": "e394c132c73f75231faf15465236b8cb",
              "sha1": "db02017b055b240976f59330829764cd6f2b5e77",
              "sha256": "e0252577dfffed61e8960009923893fcb0c4f829e89fcbb8200b382d0e118bca",
              "sha512": "64937cfca8ed1f3be39c97d0c34481fbb5575f00e4fed5187033836e193eafbf233acca934c13835b3b704900a8572cc9208ff49ad723d680bdffea2ce84ac50",
              "rh_hash": null,
              "ssdeep": "12288:yya8SDrRFAxXHXH8HjfJL0MOcUnkeUltkDO1:yyyFAxXHiJL0M1UnkeUld1",
              "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1C5C44B11B750C135E5A251B09CB8ABBD5439ED689F3446CBB3CCAE2E38719C26A31737",
              "sha3_384": "c9635441eb34c832c885af12711a74394dc6b7944279a7ead67b3f6d6b5c968564e54b3482b45d41b63970eb7b9da797",
              "data": null
            },
            {
              "name": "ea5357e6a74609c78e00de3cccf5e2c14a5a066c69a09b421e79d8a2abece1d8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ea5357e6a74609c78e00de3cccf5e2c14a5a066c69a09b421e79d8a2abece1d8",
              "guest_paths": [
                "EPWD.toml"
              ],
              "size": 95,
              "crc32": "6FB12DB6",
              "md5": "9c0137e1575a0272fd0f3c6cc3829941",
              "sha1": "7d63b05e71acff863a5e71cded450b21a52ce5f2",
              "sha256": "ea5357e6a74609c78e00de3cccf5e2c14a5a066c69a09b421e79d8a2abece1d8",
              "sha512": "5f5ab5f3cc2bc14d9f538e2b85bed4e2880c249ae664c1af8fdb9d13d542894a225045ebd86cfc00d75f6e48b8e47ae821b7bd48b1be5dd1b5c20009a7dae01a",
              "rh_hash": null,
              "ssdeep": "3:FOREIgYFHXS2NLY2lRHEkEnYFHXhAMsWQG:0REIHHi2+ARHEaHxnsXG",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T107B012F249434F0D2598B4448B286494E8334091094830843B10E49FC0C081BD5D350C",
              "sha3_384": "0f98948ad642a5848c869e10b7b38af4cc3eab9b04d8be55ed908a2d15471d13b68bc50eb04a9cbb6590bce6f9873fed",
              "data": "[[sink]]\nname = \"rotating_daf\"\ntype = \"null_sink_mt\"\n\n[[logger]]\nname = \"root\"\nlevel = \"debug\"\n"
            },
            {
              "name": "36811cc9ec4803fa1908d8241b2d2a650a6bc1f3a9887ae040f14d948eb788a5",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/36811cc9ec4803fa1908d8241b2d2a650a6bc1f3a9887ae040f14d948eb788a5",
              "guest_paths": [
                "EPWD_Tool.exe"
              ],
              "size": 71616,
              "crc32": "BDDAE92C",
              "md5": "21167215cf53861457c6e823c0b7de1b",
              "sha1": "31bf887e5e476bc192d820085d0275bb45b07c6a",
              "sha256": "36811cc9ec4803fa1908d8241b2d2a650a6bc1f3a9887ae040f14d948eb788a5",
              "sha512": "cb7d50eeb566e2e9ee56a23843c0c6129a9ca8e0c2a41d75bea6fbe271bcf9fd49a3d85837a0a92c4a0092040f5fc720c086e1db69813755a2ba327b2cf779e8",
              "rh_hash": null,
              "ssdeep": "1536:7oo7rMcsaO5FlLmEwWAAf4H1cnfbyo4p0kt0N57pF:7oopOFlLmEwn1cnGD0kt0vFF",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EE636CC362C1DE40E1713930C4AE99F53539EDD1DA689FA7569A7E0A3F30283A53931B",
              "sha3_384": "53aba4d22b872fd1be4127ad1c24c2ce487085ed16c951381b5fc60973f01e2130f3fb592e32ef51a567859fda1cbb89",
              "data": null
            },
            {
              "name": "b9e64c17f25de41e5ff2ec9958facab081f2a5584c3f82afaf79bf8bf6906ee2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b9e64c17f25de41e5ff2ec9958facab081f2a5584c3f82afaf79bf8bf6906ee2",
              "guest_paths": [
                "error.png"
              ],
              "size": 464,
              "crc32": "BD381A05",
              "md5": "ed87905d663a03c23407a7e239c6a24a",
              "sha1": "ad0faf735dc31f30db889ea961d3a19be7ec0c06",
              "sha256": "b9e64c17f25de41e5ff2ec9958facab081f2a5584c3f82afaf79bf8bf6906ee2",
              "sha512": "ca0c9c62b71590c70a663dba951252778ec8c2a03eb05540f78c5f5ecbdca0435efcf76ec42cd9ff13b6fd58c2cae8fcfe99bc395a75a34c215543e6658c92e8",
              "rh_hash": null,
              "ssdeep": "12:6v/7tw0/EHnZvunglSqaPwqdqz+0zNYxMI:H0pLIFnzNYxMI",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T111F054C13E489E30C24786F08057C2B1FD2A8340234003486382341F002416C5AB5A50",
              "sha3_384": "f7e081db632bcd5cd8ba7ecefcb33f79b3338cd53a1fb7d653cfc63de0cd394fcf1ac567aebbb6a9b2a9dbc3ce0431e8",
              "data": null
            },
            {
              "name": "9166f23c3b5d1934f15c66fbc165de66290a1011932aeffc0ef22ac15b14e9f2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9166f23c3b5d1934f15c66fbc165de66290a1011932aeffc0ef22ac15b14e9f2",
              "guest_paths": [
                "error_connection.png"
              ],
              "size": 3386,
              "crc32": "83B3A985",
              "md5": "10529193c82f2f14b62d446b66a2e317",
              "sha1": "e5bd99e76c07aa32dcc19a5819f1daae502ffb67",
              "sha256": "9166f23c3b5d1934f15c66fbc165de66290a1011932aeffc0ef22ac15b14e9f2",
              "sha512": "4c8d8a6a853451c990b260ecc31e2c39052210477502a09661b186934bbecdd54573602e453cedaf16bf3d91da090812bb018b30749f7bde3277011adabc726d",
              "rh_hash": null,
              "ssdeep": "96:CU7Ew4HDSG/n4bKm+N9qTMzv/iHkWUgHx8Xe:C24jSxIzv/iHagHH",
              "type": "PNG image data, 150 x 124, 8-bit colormap, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T199614D6642C6307DEDEF877B40892859FAE8B51F1134309380D78E6A59B28C853DD522",
              "sha3_384": "a5e142da2358ca48cc1388d0b84e944aac77954aef3b88356f4d58cae7832f8888c14dde195484bd5f1fd3279ac17b24",
              "data": null
            },
            {
              "name": "30ef459d054f99d00af2ed565e0f22527ace9a3459d26b008bb65ea4546b21b2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/30ef459d054f99d00af2ed565e0f22527ace9a3459d26b008bb65ea4546b21b2",
              "guest_paths": [
                "error_connection_hc.png"
              ],
              "size": 2453,
              "crc32": "AD26276C",
              "md5": "c0bd24302417129dc66c9e9fef71b653",
              "sha1": "7e45ff1397f27cd527d766c951ac6ee5880a6e23",
              "sha256": "30ef459d054f99d00af2ed565e0f22527ace9a3459d26b008bb65ea4546b21b2",
              "sha512": "aeb2e022bb46599228041b3befdc301ccb186273e34caa97b366ce3c6db8b8454cfed94d2b21e5334d4eced59a10d011b0e8ab208dc8f419d1a0739b544af142",
              "rh_hash": null,
              "ssdeep": "48:EqB/puOnKD5fLWaJJnbSxLc/FZXDePYKijgNk2b6tcliMr0U1nO:PJpu/5fLtJbB/FZ3jGDb6tWiFUnO",
              "type": "PNG image data, 150 x 124, 8-bit colormap, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T168513BE3E333551E9963E1581931F67C951DF528ADC8878467C938E08BD61C530A4F5F",
              "sha3_384": "e60322337b7a1c15a99fa123811f6a0ba1016fb24692b41f375e74e1290f3adbd7926668ae7b7fb91de2a18e72b32b55",
              "data": null
            },
            {
              "name": "97553ee34a244fcce583c8ddb774504ac280c866cc3fc654df31e2451bf2a5e9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/97553ee34a244fcce583c8ddb774504ac280c866cc3fc654df31e2451bf2a5e9",
              "guest_paths": [
                "erroricon.png"
              ],
              "size": 2799,
              "crc32": "07AB0A53",
              "md5": "1935f172096bf3a78e93f4d4873a24bb",
              "sha1": "56b2f8c85c76b9329b3142f1b55f12cd1e12c63a",
              "sha256": "97553ee34a244fcce583c8ddb774504ac280c866cc3fc654df31e2451bf2a5e9",
              "sha512": "23020e309681865187ac42072d5e02c1bb71a703e0c3cf4830c5e735b43eb63acdb44dc97d5548e1e48eab66e833dfea84582703a337f30190866994f90eda41",
              "rh_hash": null,
              "ssdeep": "48:KFbDq4ZkzU4SJYzDtd1buft/EQBJWP4GC2F1mz+xjxBNiJRs9DAlajX:qbDSBDTw18qJWtCiltx3illyX",
              "type": "PNG image data, 42 x 41, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D9514C579CDC1D7776E99461104C333E741BE029EA992103644A30DFC92C415CE7F360",
              "sha3_384": "5d433f1b8f7b0b12ba6dee0f0ab6129e264d7ffe600b74725232d41807e58306537cb68c2a2fbbeb30e49ba473b1d3dc",
              "data": null
            },
            {
              "name": "1a7805e8ca78cf8a847e681c193d2145d3c4c52001bb0e9182b9f4e175979823",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1a7805e8ca78cf8a847e681c193d2145d3c4c52001bb0e9182b9f4e175979823",
              "guest_paths": [
                "FileHash_DYN.dll"
              ],
              "size": 23864,
              "crc32": "0B9AF7B7",
              "md5": "1c856d0aabd654fe88b29e4b8ee33c78",
              "sha1": "22f660a4812c8271f19c88ee91824e880f71246d",
              "sha256": "1a7805e8ca78cf8a847e681c193d2145d3c4c52001bb0e9182b9f4e175979823",
              "sha512": "77dff7234d8c1b5c074c34037047d87cdf03d0f6e9c92bff09948449bbd639444de39540e0de85c3c622c44a7f327764423cdd47e07a90452885c25c104dce61",
              "rh_hash": null,
              "ssdeep": "384:7VKA8qZrKQe2JLOf5fgRvhgnDMXIYif8ZpHzGoveYHa:7uqZA2No50hgnDMYYifiRPc",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19AB27D86AE4454B1EAE71A7038F2DF336D70B6215F9088977B924109179A2D27F3C27B",
              "sha3_384": "70764a27f9c31450218057028187233d5f215328e097cfc92f529c647835a99a310428ea59393c9d8c25aad814c83d02",
              "data": null
            },
            {
              "name": "e693008a7933c952ee9baa565a3ab24fbfa3d8f620c81d36abf89ac8b9e1a3df",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e693008a7933c952ee9baa565a3ab24fbfa3d8f620c81d36abf89ac8b9e1a3df",
              "guest_paths": [
                "finish.png"
              ],
              "size": 26893,
              "crc32": "1F616F06",
              "md5": "f5e90a376f2632d17ffe220985264fcb",
              "sha1": "bbb9adbc9198773629b3aa9e0e27e76d56d46359",
              "sha256": "e693008a7933c952ee9baa565a3ab24fbfa3d8f620c81d36abf89ac8b9e1a3df",
              "sha512": "76fcf2c5fcf6529e9cdf3144ff9cb0405c0599bb766038d28232ab9e8e1d5ffd638758e6aa0ed16b428b6be65f54b0aa795868fab1907fd930f5d5438c9c833e",
              "rh_hash": null,
              "ssdeep": "768:OxyMeqACSv3HmrELTK3SReTCNWK+M2XJIxUzAVZrma:OTSFTK3SQTGWHJJzOv",
              "type": "PNG image data, 136 x 314, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12EC2E181F207EC10CAF10DE74A994162F557EDD249AAC98172B27C2DAFC7A14E10B592",
              "sha3_384": "ab0da1eed66f674974c979ac2ca8859cb3ec24950d5c1c463acb20eb907c5f1aa2c6686909a370fc89c59f93e2c784ab",
              "data": null
            },
            {
              "name": "e542cf42943790e4b497eb7c08513232dbb321030969cad58b53912a20b5116f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e542cf42943790e4b497eb7c08513232dbb321030969cad58b53912a20b5116f",
              "guest_paths": [
                "FirewallMonitor.dll"
              ],
              "size": 244712,
              "crc32": "54E5049E",
              "md5": "54207e9f7dfd7674cd6849001a3e5c13",
              "sha1": "48dec425ec1077955cb8f28cd7b26eee08248f27",
              "sha256": "e542cf42943790e4b497eb7c08513232dbb321030969cad58b53912a20b5116f",
              "sha512": "5e2cf75071b8ca7397808c01e2239b0d96221e38a7998584de6de3fc01b9429e0108e455072765fd2af44ecd37b11e70da900d94c1e084f4502bf4c8b69e60ed",
              "rh_hash": null,
              "ssdeep": "6144:lWok49jbwLq6DDjSUu8aWKNIo+Lcx1WSuyXwiPjgs2LVJ8CyfcR6yRNayeX9X6:RCnUcQyRP",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D83419703606C97FDB9E137698398B1F601966C11F70D0D3B29CDF6A69B84C31A329A7",
              "sha3_384": "53cb091af83be72ad156080eaa67d1d526002777dc8ec2b7fec00cd80e2d22b688a245a8bb70a1eeb48990794cdd4fce",
              "data": null
            },
            {
              "name": "21a0036384848248e75608b52c05bcf04fccd9e8002c070b006935893350c5da",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/21a0036384848248e75608b52c05bcf04fccd9e8002c070b006935893350c5da",
              "guest_paths": [
                "fwcpp.exe"
              ],
              "size": 34296,
              "crc32": "89320D0E",
              "md5": "f896a1194fe3974b4f60f79319bd2a78",
              "sha1": "eade2543cd23dd3762be4c8b63731ab3bfb81d5c",
              "sha256": "21a0036384848248e75608b52c05bcf04fccd9e8002c070b006935893350c5da",
              "sha512": "7960ddd49e05042c9e839c21d116a72fc4a9f5179944bb76c330c33a095261227cc920e6e7e5104e8ed54af967b4a6a6703068cc74d255791e2438d2d537e835",
              "rh_hash": null,
              "ssdeep": "384:BpPBw61nvRM+4gdEe8UjK8u2RxafGtCERTg5gkopDTXYJLu1QxbCrH:PzDHC8u4afGtCERjpDT2LWYbCb",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T113F27D9B5B5408B3ED884BB020B79356ED37F1F45F9080DBC7A41C442D6ABA32F36699",
              "sha3_384": "40a9d298045307a5300cb47f09f63cab90b3881d857538c15639561bcd6fd7b61a5b3fab2b8560b00fe1e61fc84b1547",
              "data": null
            },
            {
              "name": "e687831fc461c87760fff42b98d80af5ad6794ee2d837a59888452154f5f4e71",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e687831fc461c87760fff42b98d80af5ad6794ee2d837a59888452154f5f4e71",
              "guest_paths": [
                "globe.png"
              ],
              "size": 3137,
              "crc32": "382D664A",
              "md5": "e0449e70cc69532b99cb0499581f03e5",
              "sha1": "56081c9781a33ac253d40d4a6eeafac522150aa4",
              "sha256": "e687831fc461c87760fff42b98d80af5ad6794ee2d837a59888452154f5f4e71",
              "sha512": "15d3247e0cde8a8679adc51a59c798d0149a5fee3efa8e3c470900d6a604510de1de922cabb45670bf77982ca5245277e5c21c23e6032383534901ec97fd02af",
              "rh_hash": null,
              "ssdeep": "96:fDct3T3WJVQMrHvkJrs5GnPS4wdZKkdJUYqX/12kkVs6c7YQRp8:fwt3hMrHgr/n7YdJ412kkVspP6",
              "type": "PNG image data, 34 x 43, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D7516B4747C640AB9E26379C0209E411E7DE2BF89AFD26DD3305ECF14776A829E71013",
              "sha3_384": "7b7e30eef69e1aeb2c9cc7902a6285f85c5114055d7e786ef4fcf1564835a5c0501a3269e56f948c456a1d7fdeb49813",
              "data": null
            },
            {
              "name": "01c936c8f3c29e7fc0ce9d18851e9c065ac42a4378ee02b41529421c8afad629",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/01c936c8f3c29e7fc0ce9d18851e9c065ac42a4378ee02b41529421c8afad629",
              "guest_paths": [
                "groupmonitor.dll"
              ],
              "size": 59192,
              "crc32": "14D77335",
              "md5": "ff169072efecf702f16feaf3158f161c",
              "sha1": "22064d9a9eaab7f9aefe7bf0738fa2cd0f83343d",
              "sha256": "01c936c8f3c29e7fc0ce9d18851e9c065ac42a4378ee02b41529421c8afad629",
              "sha512": "d45038bdb9874a126224327cac4f9432b6bc992d9a75fae99d26beecfe82baab230217af6235111971e2f8093c519d6c0ee21ed4241d7421102daece5f4c177f",
              "rh_hash": null,
              "ssdeep": "768:vK9yFJdDF6cGpRSaCdS1Hux77olX45THkDpbzabff328dDi7LBeBEQYifiRPRR:08vcRSLdS1m7mXYTHH328dDmCH7fixRR",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1AC438C43FA0084B2EBCE017435EB5B7B4978F6144FE105C3AFB605AE9921AE2F63114E",
              "sha3_384": "9def7c80531317becac3d477b666f3c0c06500b54e8f0c5ba9fa451dcd09bdc43fd4f5b688dc6b3e50eb3d360c7703ed",
              "data": null
            },
            {
              "name": "d1a670afcd8d8122feb3d524c89bbea0d144a8433222ebf648b691aeb626fe78",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d1a670afcd8d8122feb3d524c89bbea0d144a8433222ebf648b691aeb626fe78",
              "guest_paths": [
                "happy.png"
              ],
              "size": 797,
              "crc32": "263A6AD0",
              "md5": "f2f79f65c0b17330b7804ea2655577d6",
              "sha1": "313c10dce71d2c518e0c2c5afa0ef5223e66f328",
              "sha256": "d1a670afcd8d8122feb3d524c89bbea0d144a8433222ebf648b691aeb626fe78",
              "sha512": "718457c6a9121459c523bc203357dd4a58525cbfcc96715a5b0e8c601ef779967bd0098327e8756d0857f9ae5d92d546c3ea1d9b31b9755f3cfe03a88134546f",
              "rh_hash": null,
              "ssdeep": "12:6v/72r6CtF6zDM2Ixm/F+axzR7Szl8xoKe7DjrgWvgDtenB38zK7IL9:3DzdjQF+YzdSzaW7gWvJnBMz1L9",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13B017A9535B2D5102E0196538F05113E74571F8C0F4EB259B9239407288AF0945BDC62",
              "sha3_384": "ffcb9f64bc38074712eccc0a924c32c46a1b90fe51dc823f1e43f292675250a6840c3d8cbbe4a3bee2b5bbd2f2ec8146",
              "data": null
            },
            {
              "name": "3d2faca48bd42a4103e9c81694ebcad3de4ad6db722e3c395940d376eb962081",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3d2faca48bd42a4103e9c81694ebcad3de4ad6db722e3c395940d376eb962081",
              "guest_paths": [
                "header.png"
              ],
              "size": 10387,
              "crc32": "1FCF7003",
              "md5": "c89a91c2032e4f37652b73e91e51ea38",
              "sha1": "637e8f858c9267424f60dfe0f3e05b46039fcfe0",
              "sha256": "3d2faca48bd42a4103e9c81694ebcad3de4ad6db722e3c395940d376eb962081",
              "sha512": "2615f9f8b265eabc80628bb3761278ba80c0f2d6d9513b29b07c85ade380bdc2335b5327ca6da99af896d3ffc9a0f0fa748a9760aad5ba17b521734da2ed32e0",
              "rh_hash": null,
              "ssdeep": "192:CSDS0tKg9E05TuMvGcEWskvjxREhku3mLj9PylAIzkhdu3I9yM:dJXE05z1vdREhZ239PHhQ3I9/",
              "type": "PNG image data, 480 x 62, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T10822AEBED150D6CEC52A349738091781FF24A3FD4B9A866CE2A5EA9ECD259433BB0044",
              "sha3_384": "1dc9627064c6c50dea39bbf2ad0e95601609184e87e19e658637471baaa046975213fec9faeec4c4d4a6838b2687b882",
              "data": null
            },
            {
              "name": "d366fd9847edef4352f9c7f99861d235afbd7acc90569b80cbb2a0886edfb3bb",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d366fd9847edef4352f9c7f99861d235afbd7acc90569b80cbb2a0886edfb3bb",
              "guest_paths": [
                "help.bmp"
              ],
              "size": 1196,
              "crc32": "C417E5B9",
              "md5": "ed2a33f6e17635d3d06dfa3d680fd0c3",
              "sha1": "2075f40357b9e98991789973da85c8c2b12881fc",
              "sha256": "d366fd9847edef4352f9c7f99861d235afbd7acc90569b80cbb2a0886edfb3bb",
              "sha512": "d9873af25bda52e4f19798b9234889c6dd489ac95a12dd21b32f1f3f4dc59d6fb0bf6f6639c9389d7f305254e411801909c1028eb87365b11a292482142d55b8",
              "rh_hash": null,
              "ssdeep": "24:mYlmlXveve0thfSdNNWDbamTWpXM15BNm3WRuQcgt9fBtihi:xlEowNW3a6WZ8FuQcgtjtihi",
              "type": "PC bitmap, Windows 3.x format, 19 x 19 x 24, image size 1142, resolution 2834 x 2834 px/m, cbSize 1196, bits offset 54",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15E21ED8D75420BE8EA6224B9DF1595FF20256CEAECC00E5732C27F0FE43585D7128510",
              "sha3_384": "949f5e1b26ddb5bb59b8311813ad795db07c34f403221d0e5735ef2776839616886bb7235b76e710e52b0eac398bf521",
              "data": null
            },
            {
              "name": "eff4f171dea2422a54cfa4e4435ced57f3379bbfc76ff9b25b85264aadfcdf5e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/eff4f171dea2422a54cfa4e4435ced57f3379bbfc76ff9b25b85264aadfcdf5e",
              "guest_paths": [
                "HotFixMonitor.dll"
              ],
              "size": 73016,
              "crc32": "DE8BA9A3",
              "md5": "e2448949c84a42c4660ec448f956a4bb",
              "sha1": "7709ba787063108d843ab65c82ffc7f0f1999f36",
              "sha256": "eff4f171dea2422a54cfa4e4435ced57f3379bbfc76ff9b25b85264aadfcdf5e",
              "sha512": "74e4d3ad6572c4b5ca91a9ca14e6757b8223e4c8d7b70518606dcede38eac904f594895df048f942faf2d81607813fa4d19930ff50f3db76e43b0ebc9d2ca082",
              "rh_hash": null,
              "ssdeep": "1536:1mkgeopmjHFOqS167kQHg2cAFQ+qaZsOY+LD07fixt4D:1mkhog0q57bA2cf+qaZsOY+LD07Uw",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EB637E41BF058472EADD417035A7AF3E597AB2598FE100C36BA65A6FB530ED13E3120E",
              "sha3_384": "d423a1fe2e59a7ced0116d865b04497a5a57bc6f1781f873cb5d920897d6895319e14a15f32905e5a501c0ba13ae330c",
              "data": null
            },
            {
              "name": "17a196714697409f2682c44e523b7d11e9f61130ca11a9ed3667a011e38c7cd4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/17a196714697409f2682c44e523b7d11e9f61130ca11a9ed3667a011e38c7cd4",
              "guest_paths": [
                "HWMonitor.dll"
              ],
              "size": 60352,
              "crc32": "AEBB3771",
              "md5": "e2d16185af4eb77e086056fea1bfd444",
              "sha1": "5a796ce9a32e0ca9df75ba2cf3a9f05abb1f8e2a",
              "sha256": "17a196714697409f2682c44e523b7d11e9f61130ca11a9ed3667a011e38c7cd4",
              "sha512": "89324b90f15a015b3d0c60e56996fe3ef74f859ce39286cde0be039aba5d5e126221d965e07ed948eec3068221936bdfa6826e618dd7adf539846050673a7531",
              "rh_hash": null,
              "ssdeep": "1536:+0iAv44N7S1e7mXJBfzH6IzyT/MUDwN57k:9iAv7Z7mfyTUUDwvY",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12A437D43BB0144B3EBCD057835A6EB670878E6A44FE115C3BF660A7E59207E1FB36249",
              "sha3_384": "51eba42f32c36428b714a52e03ac29aabdfe067cedd5b9ed166ca3832d7b29cd16079d4a5f761379e2f1817064d53d0b",
              "data": null
            },
            {
              "name": "1f91d0a205a69c6f3ddbacd9cab9f44e6c7d0b7575e1b6240d9744f279b5a779",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1f91d0a205a69c6f3ddbacd9cab9f44e6c7d0b7575e1b6240d9744f279b5a779",
              "guest_paths": [
                "index.html"
              ],
              "size": 86,
              "crc32": "14D4286D",
              "md5": "eb6650324c880fd51ef2a86b157c2eb7",
              "sha1": "594acdd1449d808fda3fa1cefb55bd86f360fd6a",
              "sha256": "1f91d0a205a69c6f3ddbacd9cab9f44e6c7d0b7575e1b6240d9744f279b5a779",
              "sha512": "cad96e2f6e2fd5a465b8da8771a3218789eb57b38dda4b3aa8e1394db8beabbf298eb6da71a1d932ac036a0ff3ee0374308df4a1e4d8ea9e134b61ea4d398d20",
              "rh_hash": null,
              "ssdeep": "3:qVv5XLFKAtUbjOrlMjPFZTQiFc4NGpn:qF5Xo3P6lmF3m4Qpn",
              "type": "HTML document, ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T125A01252300A132CA8E8041104800258D00641C4C1E02C4119C94055F000E4ACD3B68F",
              "sha3_384": "0d8a7d097b98a25f4195336a3445fc367cca19ee89aecd5493c9184b3d41577edb591eae0a1dedca24e4573887ed39c6",
              "data": "<html>\n<body>\nWelcome to Check Point Endpoint Security - VPN Portal\n</body>\n</html>\n \n"
            },
            {
              "name": "e13ec5d2463a9c47cd4d49f4b94d15fa640ecf10e8fe2952ca4c590beaa1e823",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e13ec5d2463a9c47cd4d49f4b94d15fa640ecf10e8fe2952ca4c590beaa1e823",
              "guest_paths": [
                "info.png"
              ],
              "size": 1575,
              "crc32": "4B8F3BA6",
              "md5": "aa9826a0aa074fed5368a9939b57cfa4",
              "sha1": "db69ba4f22c9b7f44e3459e9616ff2a9d49a083f",
              "sha256": "e13ec5d2463a9c47cd4d49f4b94d15fa640ecf10e8fe2952ca4c590beaa1e823",
              "sha512": "5f10e51311b79e1ac16cdd889f533b0b0244812abe04e593f0a6be085e65a3ed704051383eb613ac0b3d8134a68adb052d228baa77aa48391a88a325025a16df",
              "rh_hash": null,
              "ssdeep": "24:wdCtwTbqyjQqZ0Q4mtRlLI5ZYlwoQrs193lOli6dzEm//yR2TTI9TlVNxxQycse:wYOJjQqptR5I5Sl9usflOg6B/zTQxkse",
              "type": "PNG image data, 29 x 29, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13E310CD4FB81F57ED3D89C58DCE09337A9326240750516C4438659FD3777815241492D",
              "sha3_384": "92e6b28415cb167151db3c4fb3d88ccf0c1b12987c15250ba0bcb9f03ebe75ff74fc99d2a42d080c4100e34d49303f45",
              "data": null
            },
            {
              "name": "da7a6b6894dcedb2abf7ca851d3ca5c4895a832c2a67d5086f17f1184b6a25d4",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/da7a6b6894dcedb2abf7ca851d3ca5c4895a832c2a67d5086f17f1184b6a25d4",
              "guest_paths": [
                "KeyFob.png"
              ],
              "size": 3741,
              "crc32": "9C3C66C6",
              "md5": "52fbc64d11d3c5e464c0445a591249c6",
              "sha1": "19887acc03ee3f69d99779a991a08fc550620632",
              "sha256": "da7a6b6894dcedb2abf7ca851d3ca5c4895a832c2a67d5086f17f1184b6a25d4",
              "sha512": "eb09cca26a47a4eabbaff6966156a9915480ce8cfd1e93a0f739ee151f6105ba044d71371f88f6d157e929b496d665c931db6b5d910db2863cf773429ef542b7",
              "rh_hash": null,
              "ssdeep": "96:O7nFvumMqnX9QMZl4017qwbTPQL+OvK8R:eFvumbnX9FZu222Pez",
              "type": "PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T148718D3ADF923037CA4851B5F4CFA25BA1B22C7C5192DA194627FE0C093513F6271459",
              "sha3_384": "56fa7b9f18fca7e5750d898f21ce1b99de6378d4edba84eb23bd05f7c68af6801aa88df0f6d29c9f8e4424a660630cab",
              "data": null
            },
            {
              "name": "47cf2285186ebb9acb4b8f667e962c146cd1f09e7aa3de570d63f74119175f55",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/47cf2285186ebb9acb4b8f667e962c146cd1f09e7aa3de570d63f74119175f55",
              "guest_paths": [
                "LangPack1.xml"
              ],
              "size": 1411658,
              "crc32": "F555B2DE",
              "md5": "665e5f50420d7a0f11d44d9ec1929fd3",
              "sha1": "95f1278fde71c2937d6ed16c1889c6ceea05c16f",
              "sha256": "47cf2285186ebb9acb4b8f667e962c146cd1f09e7aa3de570d63f74119175f55",
              "sha512": "26ec5eac98a848bf0ab2ee4477ea717f5c613684194129119e11125efac815de946970776c51c87b79a9c0a47ac41fbc52bd1013d078d0ecbae7ec216f820f0c",
              "rh_hash": null,
              "ssdeep": "12288:X/tW/8b1uwYdtF0Bwu44ZWDS/HfZHcF9+fZmEoV/y47s3v869U1Ux1v/jnTfq+Z8:vqtwYMwu44ZWDI69+c/yzv/jU",
              "type": "XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18D6546D670A95F50242F2A19C621ED53DC4C0BBF5BF42561B84D6233EAB1C69E8C33E6",
              "sha3_384": "86e2f088a3678ddf15bb1c34d32af1a46dde22e45c486b030f11f0aea96c8eecad0411529121f5b6e772e7dd2bc55d09",
              "data": "<?xml version=\"1.0\"?>\r\n<?mso-application progid=\"Excel.Sheet\"?>\r\n<Workbook xmlns=\"urn:schemas-microsoft-com:office:spreadsheet\"\r\n xmlns:o=\"urn:schemas-microsoft-com:office:office\"\r\n xmlns:x=\"urn:schemas-microsoft-com:office:excel\"\r\n xmlns:dt=\"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882\"\r\n xmlns:ss=\"urn:schemas-microsoft-com:office:spreadsheet\"\r\n xmlns:html=\"http://www.w3.org/TR/REC-html40\">\r\n <DocumentProperties xmlns=\"urn:schemas-microsoft-com:office:office\">\r\n  <Author></Author>\r\n  <Description>Avner 21Oct2004</Description>\r\n  <LastAuthor></LastAuthor>\r\n  <LastPrinted>2008-10-02T16:52:18Z</LastPrinted>\r\n  <Created>2003-04-08T06:53:40Z</Created>\r\n  <LastSaved>2021-03-31T07:28:32Z</LastSaved>\r\n  <Company>Check Point</Company>\r\n  <Version>16.00</Version>\r\n </DocumentProperties>\r\n <CustomDocumentProperties xmlns=\"urn:schemas-microsoft-com:office:office\">\r\n  <PREDIFINED dt:dt=\"string\">%CR% %CRLF% %TAB% %PROD_SHORT_NAME% %PROD_LONG_NAME% %PROD_FULL_LONG_NAME% %PROD_VERSION_STRING%</PREDIFINED>\r\n  <Classification dt:dt=\"string\">NoClassification</Classification>\r\n  <ClassificationDisplay dt:dt=\"string\">[No Classification] </ClassificationDisplay>\r\n  <ClassificationEntries dt:dt=\"string\">1</ClassificationEntries>\r\n  <Classification_1 dt:dt=\"string\">XHlreHRmd3RXZVBje2p2a25tQXOLKnQ0JTU7nIKSISaSPCwqOlKXm56FXzI4PihYR0BCX10yRQ==</Classification_1>\r\n  <lqminfo dt:dt=\"float\">3</lqminfo>\r\n  <lqmsess dt:dt=\"string\">dc590010-e0b5-45ca-a6ce-a8e132abaae3</lqmsess>\r\n </CustomDocumentProperties>\r\n <OfficeDocumentSettings xmlns=\"urn:schemas-microsoft-com:office:office\">\r\n  <DownloadComponents/>\r\n  <LocationOfComponents HRef=\"file://planet/cdcopy/pc/Applications/limited%20software/Office2003/\"/>\r\n </OfficeDocumentSettings>\r\n <ExcelWorkbook xmlns=\"urn:schemas-microsoft-com:office:excel\">\r\n  <WindowHeight>8055</WindowHeight>\r\n  <WindowWidth>21570</WindowWidth>\r\n  <WindowTopX>0</WindowTopX>\r\n  <WindowTopY>0</WindowTopY>\r\n  <TabRatio>775</TabRatio>\r\n  <ProtectStructure>False</ProtectStructure>\r\n  <ProtectWindows>False</ProtectWindows>\r\n </ExcelWorkbook>\r\n <Styles>\r\n  <Style ss:ID=\"Default\" ss:Name=\"Normal\">\r\n   <Alignment ss:Vertical=\"Bottom\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n   <Protection/>\r\n  </Style>\r\n  <Style ss:ID=\"s62\" ss:Name=\"Hyperlink\">\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Color=\"#0000FF\"\r\n    ss:Underline=\"Single\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s63\" ss:Name=\"Normal 2\">\r\n   <Alignment ss:Vertical=\"Bottom\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Calibri\" x:Family=\"Swiss\" ss:Size=\"11\" ss:Color=\"#000000\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n   <Protection/>\r\n  </Style>\r\n  <Style ss:ID=\"s64\">\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s65\">\r\n   <Alignment ss:Vertical=\"Bottom\" ss:WrapText=\"1\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s66\">\r\n   <Borders/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s67\">\r\n   <Alignment ss:Vertical=\"Bottom\" ss:WrapText=\"1\"/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Bold=\"1\"/>\r\n   <Interior ss:Color=\"#99CCFF\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s68\">\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Bold=\"1\"/>\r\n   <Interior ss:Color=\"#99CCFF\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s70\">\r\n   <Alignment ss:Vertical=\"Top\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\" ss:Bold=\"1\"/>\r\n   <Interior ss:Color=\"#99CCFF\" ss:Pattern=\"Solid\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s71\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\" ss:Bold=\"1\"/>\r\n   <Interior ss:Color=\"#99CCFF\" ss:Pattern=\"Solid\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s73\">\r\n   <Alignment ss:Vertical=\"Top\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s74\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s75\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s76\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Courier New\" x:CharSet=\"204\" x:Family=\"Modern\" ss:Size=\"12\"\r\n    ss:Color=\"#808080\"/>\r\n   <NumberFormat ss:Format=\"000000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s77\">\r\n   <Alignment ss:Vertical=\"Top\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"MS UI Gothic\" x:CharSet=\"128\" x:Family=\"Modern\"\r\n    ss:Color=\"#808080\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s78\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n   <NumberFormat ss:Format=\"00000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s79\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <NumberFormat ss:Format=\"000000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s80\">\r\n   <Borders/>\r\n   <Font ss:FontName=\"ï¼­ï¼³ ï¼°ã´ã·ãã¯\" x:CharSet=\"128\" x:Family=\"Modern\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s81\">\r\n   <Font ss:FontName=\"SimSun\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s82\">\r\n   <Alignment ss:Vertical=\"Bottom\"/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Color=\"#000000\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s83\">\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s84\">\r\n   <Alignment ss:Vertical=\"Bottom\" ss:WrapText=\"1\"/>\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s85\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat ss:Format=\"00000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s86\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\" ss:Size=\"12\"/>\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s87\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat ss:Format=\"000000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s88\">\r\n   <Font ss:FontName=\"SimSun\"/>\r\n   <Interior ss:Color=\"#FFFF00\" ss:Pattern=\"Solid\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s89\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Times New Roman\" x:Family=\"Roman\"/>\r\n   <NumberFormat ss:Format=\"000000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s90\">\r\n   <Alignment ss:Vertical=\"Bottom\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s91\">\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Size=\"9\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s92\">\r\n   <Alignment ss:Vertical=\"Bottom\" ss:WrapText=\"1\"/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Size=\"9\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s94\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Size=\"9\"/>\r\n   <NumberFormat ss:Format=\"000000\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s95\">\r\n   <Font ss:FontName=\"SimSun\" ss:Size=\"9\"/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s96\">\r\n   <Alignment ss:Vertical=\"Bottom\"/>\r\n   <Font ss:FontName=\"Arial\" x:Family=\"Swiss\" ss:Size=\"9\" ss:Color=\"#000000\"/>\r\n   <Interior/>\r\n   <NumberFormat/>\r\n  </Style>\r\n  <Style ss:ID=\"s97\">\r\n   <Alignment ss:Vertical=\"Center\" ss:WrapText=\"1\"/>\r\n   <Borders>\r\n    <Border ss:Position=\"Bottom\" ss:LineStyle=\"Continuous\" ss:Weight=\"2\"\r\n     ss:Color=\"#A3A3A3\"/>\r\n    <Border ss:Position=\"Right\" ss:LineStyle=\"Continuous\" ss:Weight=\"2\"\r\n     ss:Color=\"#A3A3A3\"/>\r\n   </Borders>\r\n   <Font ss:FontName=\"Calibri\" x:Family=\"Swiss\" ss:Size=\"11\"/>\r\n  </Style>\r\n  <Style ss:ID=\"s98\">\r\n   <Alignment ss:Vertical=\"Top\" ss:WrapText=\"1\"/>\r\n   <Borders/>\r\n   <Font ss:FontName=\"Arial  <truncated>"
            },
            {
              "name": "3230bd330151583e5a94ee1d8c232447eb8066663c55302886921837ddaafa8c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3230bd330151583e5a94ee1d8c232447eb8066663c55302886921837ddaafa8c",
              "guest_paths": [
                "lmx-MD-vs2017x86.dll"
              ],
              "size": 402944,
              "crc32": "D37F3267",
              "md5": "6b4d594db003e16c2207099f229b04f4",
              "sha1": "4b148fcf7f6e08a6960abd4f9ba39f394cfc9c0c",
              "sha256": "3230bd330151583e5a94ee1d8c232447eb8066663c55302886921837ddaafa8c",
              "sha512": "454d39a3bd5d91f9c1b2951922c29747ad51201532203efb32c2138dab39b8ec55ab203d4d8b21d415fa1a86610ed38cdf0efdf41afe943a11231a9d6722d959",
              "rh_hash": null,
              "ssdeep": "6144:YiaF10+IrL3JNm3kMhX11dz9WCZbWLQIn:YiaF10+iL/IhXDdz9BZb8D",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T199845C21F7478939DACB927558D8773F9279A6048B3486C3C3C8592E9B322E32E335D5",
              "sha3_384": "2293bf30a8ad2406b2a7956cd0d6ed6bcd5c7284025d3c6402fffef394ac54c98d23c571e621fd2c5d4cd2cb5d20839f",
              "data": null
            },
            {
              "name": "511bf104a79fcb7d5dad8333f0e95f2cc8f553d8305512a268a3b5804aa45d7d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/511bf104a79fcb7d5dad8333f0e95f2cc8f553d8305512a268a3b5804aa45d7d",
              "guest_paths": [
                "LogonISReg.dll"
              ],
              "size": 57792,
              "crc32": "BCA1582F",
              "md5": "b552fa95450c45ac06fe0db921c44975",
              "sha1": "2e94419e189509b97310093f7af4a3970386266c",
              "sha256": "511bf104a79fcb7d5dad8333f0e95f2cc8f553d8305512a268a3b5804aa45d7d",
              "sha512": "ad27844f8ba40a8a8a819655c94bfc314848b2078bb65d29cbfa3f76c71c8d672395f442be3295cc303bd85c8e97cb18ee00296998cba46576608910cc6f3f91",
              "rh_hash": null,
              "ssdeep": "1536:ERbbJRl3tyfLJkS+rKEzkQay5LgT5w4eVn4Nx/VQUvo9Br2LXMKDk4MzjN57mp:EpDl3tyjJkS+rKEAQa8LgT5w+VQMo9l+",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T175435C236B1081B3D7CD527070AB9B2B5A3CB9884FE000D76776967C9D623D17A7DB0A",
              "sha3_384": "c8d4de4bff02c26d8f9b19ebd7d14accdca912a4debfa6e0dc033cb58c6c0a1ea369e52965458b59067df97faecc8256",
              "data": null
            },
            {
              "name": "16f9a40dc9ad9860f754fc9a47fb81832d8fefdedadfecbab2cc8e6548f3012b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/16f9a40dc9ad9860f754fc9a47fb81832d8fefdedadfecbab2cc8e6548f3012b",
              "guest_paths": [
                "logs.png"
              ],
              "size": 745,
              "crc32": "6114A306",
              "md5": "35387acc08638d2151b582030b4aa677",
              "sha1": "cded3b2e9f55e8d08d9d3dc0478423acaef9e8bd",
              "sha256": "16f9a40dc9ad9860f754fc9a47fb81832d8fefdedadfecbab2cc8e6548f3012b",
              "sha512": "4ae5965e06c0151553c9ec4fe33a9e6886eaed6fb8c7acdbbaacb082827e1d2dc3a11b948e7b5dd8d517c183f11475784a83dae4eaf91ddbc990bd1493985068",
              "rh_hash": null,
              "ssdeep": "12:6v/7WYLrN3CoBNP5rB98cSQrl4nA/S7XkCG7oPf2qkDsfKF5hUirzAAq6sjbskc:4N3CWozQ//SYsX2bgS9qdX+",
              "type": "PNG image data, 28 x 34, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19701BAEFE3D4BC0A125510F093C1487104378FDBD9D5C80245D0DD8DC6B427CC485601",
              "sha3_384": "28b073b394a11468d69d3a5a10329e2b87ca57d59e8fceed4e53fcdbc849c991f2f1af02f8766c3bf409f376b2af9917",
              "data": null
            },
            {
              "name": "d6c8580c138f3d537d524af596bfb0c5daa5031bee974f462911fdc03c40187f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d6c8580c138f3d537d524af596bfb0c5daa5031bee974f462911fdc03c40187f",
              "guest_paths": [
                "about.png"
              ],
              "size": 15375,
              "crc32": "DD42206D",
              "md5": "3e6626df08da675c52e96048a84052ee",
              "sha1": "f979000f01c3e16107ebb260e4503418abe49aeb",
              "sha256": "d6c8580c138f3d537d524af596bfb0c5daa5031bee974f462911fdc03c40187f",
              "sha512": "74e644ff4eaeb3de188a51f80ac401cc9faeb9182b041c3d9116720d146ceba32e5d9b96677db9ac110b34d341c1ef088409f8e71905d3691c97f77c6bb91b65",
              "rh_hash": null,
              "ssdeep": "384:SdmIbdYvfTrfpR1ok4AZXohiqBc4/tNf1U9a/K7BbP:Sdm+6fTLloFjhi4ckNf1ca/KB",
              "type": "PNG image data, 460 x 306, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15F62BFA1F6E994ED067273714D394B0B4A42DC3D1F06820EC8613C5EBB5EB1562F49AC",
              "sha3_384": "9d6fd34105e62cbe9248fe500b404ca1bd8c26949d457bbd0a5632ca7de589f31f2a177d4747eb7fa105cfd9e1999821",
              "data": null
            },
            {
              "name": "1956271c0f95f53d21fb5441ec8d17028b920c6c7b6c11ddb74528a7ffe1674b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1956271c0f95f53d21fb5441ec8d17028b920c6c7b6c11ddb74528a7ffe1674b",
              "guest_paths": [
                "ConnLogo.png"
              ],
              "size": 16151,
              "crc32": "6B2933ED",
              "md5": "3806aa11aa6cc19f8e78d3efed3b499d",
              "sha1": "e34902c7d99c4ea2b71186d7553ef7c12b952f67",
              "sha256": "1956271c0f95f53d21fb5441ec8d17028b920c6c7b6c11ddb74528a7ffe1674b",
              "sha512": "175c9e9e2b2cacfe4beaed03cd034a3a6819f583a5cc0c6bd655056749727d9b2aefa8b80d5e69538a7cfea82e5da0b613e210463ae4efb4f2e9b9b64adf0794",
              "rh_hash": null,
              "ssdeep": "384:YBCALX7V1+IukJnDZEV+Q4PjpDJfALDKjzPm2Ud:YcA77BuID6VKVDdO86h",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14872E07902346E93CAA16703B53E815D933AD0021F1E4A8BD4157A1AECE22D3BF7D2A4",
              "sha3_384": "cc7d302562f4e8666ef386de53e75a88c7fa42f48ef9ea41edaa2992404121595670e890544a61ba75df7972c4a291e3",
              "data": null
            },
            {
              "name": "bac69f4c3f90bd3a9d1a310239dfab279cd3da620e53500c931065c9a5b16564",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/bac69f4c3f90bd3a9d1a310239dfab279cd3da620e53500c931065c9a5b16564",
              "guest_paths": [
                "CP_Left.png"
              ],
              "size": 11340,
              "crc32": "7AA73203",
              "md5": "785bad796c6c5956ffc1d337905c2700",
              "sha1": "ce6730a57f4acb6d704790c03a1e8cad000b51d3",
              "sha256": "bac69f4c3f90bd3a9d1a310239dfab279cd3da620e53500c931065c9a5b16564",
              "sha512": "af24ab70e4cad9427eeec7c93ca9de4a8222dae02ec1d0d6ca599920415314f6aab887d5e28d454fe8f284bf1ce13fffd78e1ac3e31d48f2d8b627c2b70cbff4",
              "rh_hash": null,
              "ssdeep": "192:J2SDS0tKg9E05TaqEMD72VYht2hndUsRvRvZKVdC8LeoGmGEc3kRb:HJXE05gMi3k+1GL4+19",
              "type": "PNG image data, 255 x 42, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1FE32B05B818410EFE58DF7240D8D4A88AFA62214FDAB6B35AAE640FE42C6563FF5140C",
              "sha3_384": "43e9e508eef9a1645bafa51279b0eb3145e3d92fb3b0871283cd2a096ff5fede062d428f1c4045224057208de78e3c0c",
              "data": null
            },
            {
              "name": "3705715a33a5d7b546964accac47d1023cfa1089977fd92c9d81c31df49b77d8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/3705715a33a5d7b546964accac47d1023cfa1089977fd92c9d81c31df49b77d8",
              "guest_paths": [
                "endpointBanner.png"
              ],
              "size": 16018,
              "crc32": "F7E55A6F",
              "md5": "3782aababa7b51577de9519d978d25f2",
              "sha1": "079a2b1949a2dcc68f511883bac87c7d3d7c5d50",
              "sha256": "3705715a33a5d7b546964accac47d1023cfa1089977fd92c9d81c31df49b77d8",
              "sha512": "911f34393f4c20af6882583254679cdc5d097786a4e30f07b6d7c320b97755cee17eea588273f38d130b02a89425ae9f8f6c4205d66145e349150714e30c0247",
              "rh_hash": null,
              "ssdeep": "384:svhdx2nxQIGimgwvQGErzIEn4dBOpUBuJC:20ymRwTEnJn4D/BuI",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E872D16B30E57743D46B31651FAC4D483CDF1023EF33AD77282AEA99385B0494669C09",
              "sha3_384": "22101503d92ed34c011e13272012d7a783b6b4d62cf8e5b811c0bd79318c08fcc8461821a653c4b99e84875ece298163",
              "data": null
            },
            {
              "name": "ff98ce7d2e161ce2c4735669e6a1323a6e0da77120b43064f298d6c7e13bebd9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ff98ce7d2e161ce2c4735669e6a1323a6e0da77120b43064f298d6c7e13bebd9",
              "guest_paths": [
                "endpointBannerBig.png"
              ],
              "size": 17531,
              "crc32": "10403C0A",
              "md5": "fddb5f934a778dc85998ac4e69d65151",
              "sha1": "7ab24ee432478af385f5e6cf2a222d5be31d7e0f",
              "sha256": "ff98ce7d2e161ce2c4735669e6a1323a6e0da77120b43064f298d6c7e13bebd9",
              "sha512": "939e7e3b4bac2a09ad8f99bc801f83169717afa0ddd38d2c892ca96cabc77cd9138bf3289d7763705b18ee4cde1c5537c8d5322c8662f48e712c3bd1e15869f2",
              "rh_hash": null,
              "ssdeep": "384:aC3t55B67VUVlqt5NLULXsV/lK4IBCP4Qvkk6pB2Zz:aM67VkK5NLGsV/lK4SCQRkmB2Zz",
              "type": "PNG image data, 702 x 61, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EA72D0C6E330F2C72963D77866FA5C45E430DCAAE613ACD1EC6B226C1BC095196A63C5",
              "sha3_384": "51276966d5c50507a60113b13e5c04864a6a1df393ae4481752b8c1761724a4c7ff56437406ed221e7a14e40127c26ef",
              "data": null
            },
            {
              "name": "ad9e3eff848995349a1223c45dba57db42de9efd02dc22b09a4c50c3097f6bef",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ad9e3eff848995349a1223c45dba57db42de9efd02dc22b09a4c50c3097f6bef",
              "guest_paths": [
                "VPNClient.chm"
              ],
              "size": 51541,
              "crc32": "11E112B1",
              "md5": "707f09b056c6a90accb36388c1160431",
              "sha1": "88fdf43818068592f3ba31d8f164e2473bb4624c",
              "sha256": "ad9e3eff848995349a1223c45dba57db42de9efd02dc22b09a4c50c3097f6bef",
              "sha512": "90102f48d2963a5f8a06c2dc18132be4e64d4392e336e19ae4ce658913edb8efaf7f459a001d1d372268c45f441fb9fae996c8334ca50d36e3776bcbf0e29480",
              "rh_hash": null,
              "ssdeep": "768:Q+eIjc1UjmAg0bu3+2IkFgVLCJ10klLy1OCtgJAfhuFn097YO0FF/Yz:Q+eIjKUjR/u5PADvCghO097YLFF/y",
              "type": "MS Windows HtmlHelp Data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18F33E1E43A674186ED24B6B30BEBD3DD24623516DE8703422263D9071770F16A6BB2FC",
              "sha3_384": "b1d0fb6014f2eb1325a1fc04277dfccbfe39b747e64b1e022b9d17357cd2fbd4dbd613473c18787be4edbd595d75c549",
              "data": null
            },
            {
              "name": "68dd54ed684626859f6b4a13c0dc7f7cdb69c1748329cfb8998881ad783bf46c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/68dd54ed684626859f6b4a13c0dc7f7cdb69c1748329cfb8998881ad783bf46c",
              "guest_paths": [
                "ModuleBar.png"
              ],
              "size": 645,
              "crc32": "71ADBFC8",
              "md5": "76aac1b7fd75ac912b685431edd056a2",
              "sha1": "b4c4db43eadcc02d0d1a070b99252e5828460975",
              "sha256": "68dd54ed684626859f6b4a13c0dc7f7cdb69c1748329cfb8998881ad783bf46c",
              "sha512": "88e09c6b1600835f2ad79e8bee6e74e5cecc5f8bd5339198b9d0f72983e0a492bb3d1e126a0b933ae8485fd46e5943df6b7c341547424a6664bb997a82790c65",
              "rh_hash": null,
              "ssdeep": "12:6v/7rTCXVMRX7HC1ygBDrcZMaOG+nFekBT+BGnHQvz1KslBXCUuBlBMGSEcYBAB6:mCFMVrC1dD4ZMaSFp8qgboTgW+DQ97P7",
              "type": "PNG image data, 711 x 41, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1FCF0AF90DA14A47376A90560B9951997E0761E773810CF3491C7381F1B2BF793CBEE06",
              "sha3_384": "da4fffe35ebe2b82b5ebaadb31eaf814cfd7a39e3e8ae8002e6b4a0784a10b7711521dd331612589ea921c81d2f1f59d",
              "data": null
            },
            {
              "name": "c5e5163b73089baed2bc6c72257a4d6d87a64cf1e1dd29de95fec9da3ec14875",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c5e5163b73089baed2bc6c72257a4d6d87a64cf1e1dd29de95fec9da3ec14875",
              "guest_paths": [
                "ModuleBarHighlighted.png"
              ],
              "size": 595,
              "crc32": "14103615",
              "md5": "f0b0671fc9eeeb966900010c3c2f2607",
              "sha1": "6216c13adbb62cfbbce60626d1331b59089b4fbb",
              "sha256": "c5e5163b73089baed2bc6c72257a4d6d87a64cf1e1dd29de95fec9da3ec14875",
              "sha512": "a06b353dbb9701ae092839309b1f33d7f635a56082e4dfeb7ad0580a9865f47921466f1acc40b55ce2c3abeca30b0e6ae3dcfb816d4c0fe68fccccc5588d8eb8",
              "rh_hash": null,
              "ssdeep": "6:6v/lhPzlllhCX85zoD8d46kf/kBDIX3vE6nyjfjiFE6nyjfjiFE6nyjfjiFE6nyZ:6v/7rTCXqz7iAWfyuyuyuyuyuyuyuyuQ",
              "type": "PNG image data, 711 x 41, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T136F066A8D090A8F7362413039DB046811B354C627744DD87B5EF76DF82A1F359F35618",
              "sha3_384": "72e8cb9d44521208f66862d6818ebf19911f21f6a6f3c9f83ab71bd47d9a17af25ade942d5a36e975955232d7e755af3",
              "data": null
            },
            {
              "name": "43f0835a732c0aa0a3be75d51b8819401c7641026eb70837e2369281545b54c6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/43f0835a732c0aa0a3be75d51b8819401c7641026eb70837e2369281545b54c6",
              "guest_paths": [
                "Modules-Compliance.png"
              ],
              "size": 832,
              "crc32": "F2C3316E",
              "md5": "7e3902cb7b3915fc3b8d45d9877d0fb7",
              "sha1": "8353a817c431f6e51fc3e3c5d9d826567d4ad1d6",
              "sha256": "43f0835a732c0aa0a3be75d51b8819401c7641026eb70837e2369281545b54c6",
              "sha512": "c37035fd83a9c2e77cff3121dd5b439c35a3db1d1aba9a164a694752fd7c11a6015ea76668347c2178b0a1a5bf292c9197ae3764c83df673e7b9f902f0df40f7",
              "rh_hash": null,
              "ssdeep": "12:6v/7Tr1VapRsGjlzfIHH29iwq39tGwqaMt8c6+Ej1oc0Yd0U5czXXnFwNIGe6m2q:21GsGpAWXoaaW8cqocd0U5hN5ofvb",
              "type": "PNG image data, 22 x 22, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E00186C8FF26499F831DB47EAA39C0299A7A81D94C8C61981C2868DA155095681B4F13",
              "sha3_384": "6ecfd49095698538cce40f89e0e48333c39eb540140baa20d95b532bac111bf93eff241710c4841f16333571f1bac166",
              "data": null
            },
            {
              "name": "9c246f4912f3b000cc3a40f62dc018f5435e695085481b1e8334f125375ef3b2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9c246f4912f3b000cc3a40f62dc018f5435e695085481b1e8334f125375ef3b2",
              "guest_paths": [
                "Modules-FW.png"
              ],
              "size": 1238,
              "crc32": "E830AF12",
              "md5": "1a0413aa941248fa467624f47887da86",
              "sha1": "f4c19322498dcf1087b75e3f6a17317956165232",
              "sha256": "9c246f4912f3b000cc3a40f62dc018f5435e695085481b1e8334f125375ef3b2",
              "sha512": "f7f7f3a325170d044df582c2faa7e927951ee50ddde446754469ec7eb62ac1b2d82963ffa1e8e208e40e514aa715189d4fad0cec4c9afaf17bd02a8653d4fd8c",
              "rh_hash": null,
              "ssdeep": "24:q2LkRsT8HnoRf6hINKzRdgOEVN8h91Fk8tvZhWCrmMIUNJVc:NLkR3Qf6CNKvZEVN8rBhWQ9a",
              "type": "PNG image data, 22 x 22, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T11421E7C280B2A642B10ED873401CB0B2CA2180E7622DD45B0A948D9FE7F9C248E68D1B",
              "sha3_384": "00ae689c251dcd0881f4e70904e6ddba9b8a1d52466876556a585e0f67050119a02e8b4ba48757923464091880a48171",
              "data": null
            },
            {
              "name": "f7f5e35237ac251d802c75a803f49ba30fde74dff810490d29024b09b70ab0a6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f7f5e35237ac251d802c75a803f49ba30fde74dff810490d29024b09b70ab0a6",
              "guest_paths": [
                "Modules-VPN.png"
              ],
              "size": 1395,
              "crc32": "809FE5B7",
              "md5": "d5f6afdcfc9f04602a707ceee3b10cd9",
              "sha1": "56e01b67a69355b5fbc08e3f473885e364782bf5",
              "sha256": "f7f5e35237ac251d802c75a803f49ba30fde74dff810490d29024b09b70ab0a6",
              "sha512": "88026c2206e4b96d07a53650d62c942fb59f2d6b5a79f9ec939abee61f159ad5992356212529d1a664991fa8b8b9241cc81e326b1b4f921dbf043fdbdc6f0bf3",
              "rh_hash": null,
              "ssdeep": "24:2UhExlMA/a81oCMF2TKsrNLd2dYDCl6ApwZ5wo+db2gqfhtagR1D0RQ/R8H05Efs:1pUoCMF2+srNdLCHwHd4bmfhtacD0jHy",
              "type": "PNG image data, 22 x 22, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DF210EC57E955AF3D00646D8EC4C92B5401745501EF41B611E4716C992F1FCFCDF8067",
              "sha3_384": "8c52c272046f483b9615a2b3b5e3d7e650c11bc18ef3a7d9f1862b7827db3bc7a0ccc30282978d3826eeadb4ec483a3d",
              "data": null
            },
            {
              "name": "1ecd899f18b58a7915069e17582b8bf9f491a907c3fdf22b1ba1cbb2727b69b3",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1ecd899f18b58a7915069e17582b8bf9f491a907c3fdf22b1ba1cbb2727b69b3",
              "guest_paths": [
                "msvcp140.dll"
              ],
              "size": 453416,
              "crc32": "B7D17810",
              "md5": "9dda681b0406c3575e666f52cbde4f80",
              "sha1": "1951c5b2c689534cdc2fbfbc14abbf9600a66086",
              "sha256": "1ecd899f18b58a7915069e17582b8bf9f491a907c3fdf22b1ba1cbb2727b69b3",
              "sha512": "753d0af201d5c91b50e7d1ed54f44ee3c336f8124ba7a5e86b53836df520eb2733b725b877f83fda6a9a7768379b5f6fafa0bd3890766b4188ebd337272e9512",
              "rh_hash": null,
              "ssdeep": "12288:B6Z1JFeuKLOU7oiz28hUgiW6QR7t5s03Ooc8dHkC2eskHA1:sZDF3U7oiz2b03Ooc8dHkC2e5HA1",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1C2A43923BB420DF2F5AA13B671C9532593F5FC1147A0A3C393EAE4196F652C6A733690",
              "sha3_384": "1019dee8266934b35b03cb4763a6ea78c911077f0cc07d380b809b760668eb028ff080a299abc7314a646fea9d24f53f",
              "data": null
            },
            {
              "name": "93d42826a58ebda4dd558f003f0666658dd992dc921b5ca896db0751eb0b0f22",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/93d42826a58ebda4dd558f003f0666658dd992dc921b5ca896db0751eb0b0f22",
              "guest_paths": [
                "msvcp140_1.dll"
              ],
              "size": 28472,
              "crc32": "02967BDF",
              "md5": "c65c6524b05fb33b59fc307cac4fa9b3",
              "sha1": "c07dc8ee124cd75a7d2050becb40533b2a716849",
              "sha256": "93d42826a58ebda4dd558f003f0666658dd992dc921b5ca896db0751eb0b0f22",
              "sha512": "ecf27e62096fd12d00d7d5281e8046e1712476fdff1ac427c8358397d1354f0a5a696d78bebb1a8b0bcea31c791580639209ae6cb7eeeb8897dac057442a7afc",
              "rh_hash": null,
              "ssdeep": "384:+rVRmoC12U7Ju7iPFOf7Wci53WNj9Qim0GftpBjZraQHRN7tHOlmTW:MCoCUU7oiPFOCS9fVijrL5",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T157D26C86FB684452EA860C7066E8EB476D3EE7D21FA050D766C6E7490D937C2FB3091C",
              "sha3_384": "3a23ce9636eb0ba3796063d6a2b58c0753fe44f030adc2fdef93db9c8c447e1c401e7a450a7026ad8420bf060b44ec84",
              "data": null
            },
            {
              "name": "a39dd4202cecb0884e61dec8a76f9c970fa703252f7a0cd9770610959a990e29",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a39dd4202cecb0884e61dec8a76f9c970fa703252f7a0cd9770610959a990e29",
              "guest_paths": [
                "msvcp140_2.dll"
              ],
              "size": 154416,
              "crc32": "92FDAC88",
              "md5": "a081175f8a516ccba77242b3980b2e4b",
              "sha1": "7d148a056631ca6e89c14e409bb621215b4f9ffd",
              "sha256": "a39dd4202cecb0884e61dec8a76f9c970fa703252f7a0cd9770610959a990e29",
              "sha512": "1181749198227d6502d508e84b94e2319a8eb63c3fe4667313c7764660284d5183e7dc70a342d4357c9e36a46a02f2299bb6e96987a61d32c8e9acf5e69cce02",
              "rh_hash": null,
              "ssdeep": "1536:ouXPptoyhOJGZr3ignxQfFn7uPZHWgHJ6atx8Ijs9b5K8R9fVdF:ouLoyUGZr3uFnMH96mnsNK8R3/",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T196E37DC26D284292E05E097E6150A67F103DFD92ABBD45CBB782864FDC38EC18DB4D5E",
              "sha3_384": "fd4b06a52667f486f21d56d198666a4496d02f0e700e86986ebceade73cc815e582dd3aabb38c61643b8b26839b793a2",
              "data": null
            },
            {
              "name": "0e9fbeaa85461d6d3974e5eae41417b831e8ee8acf223eda6bc2a6307cf04ce5",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0e9fbeaa85461d6d3974e5eae41417b831e8ee8acf223eda6bc2a6307cf04ce5",
              "guest_paths": [
                "new_extender.bmp"
              ],
              "size": 20060,
              "crc32": "FDD62D2E",
              "md5": "37e296969c2824a7b383d54360e0e5d1",
              "sha1": "382ee0679c690b2c0926cb3b78558d18c030ac3e",
              "sha256": "0e9fbeaa85461d6d3974e5eae41417b831e8ee8acf223eda6bc2a6307cf04ce5",
              "sha512": "1a70a7fede24eb32b411611092fc20c324e5b72679b50aaa6b12e3d176f0733dbe6dc1ad4ee655cfc4ea24e70fbfa785064c6b1f52d2e3e2a530a759081c4aac",
              "rh_hash": null,
              "ssdeep": "192:I1cLIOpxvoSZrPIoTyiEEEEUMCJPYqKKBrgtjscylJl2daO16lNhM4C/hRdcr6ew:IYCSK0CLEgNl2/kNht6R2gNj",
              "type": "PC bitmap, Windows 3.x format, 291 x 65 x 8, resolution 2834 x 2834 px/m, cbSize 20060, bits offset 1078",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1329214C4B257AE24F33AD83AE328BED054CE4161AD13599CD42E7B35E24D38B1B9744B",
              "sha3_384": "f3aec90ff174b0c361cd1254587b6da323471c20d5ffdadba69dad29e46634d3349ead1438ca04e328a3867de6901684",
              "data": null
            },
            {
              "name": "f00691d775a4004e76c57f3bb0a9bbab702c3ca85aabd48e44dd186540e81334",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f00691d775a4004e76c57f3bb0a9bbab702c3ca85aabd48e44dd186540e81334",
              "guest_paths": [
                "newlogo.png"
              ],
              "size": 28085,
              "crc32": "3145903E",
              "md5": "a3f2b8e1d44f6f237f5644ac287bc00e",
              "sha1": "f9d3acddef6401576a2360d783f53895c3a38184",
              "sha256": "f00691d775a4004e76c57f3bb0a9bbab702c3ca85aabd48e44dd186540e81334",
              "sha512": "6ffd80e9fb58e64d759ddb44e585a036c49b25eeb00896d091a3cc286469f49ac4d2090ca3f3e97b2f97d5aac4f0d54eccda9e9308cf9c62f573566be526a3d1",
              "rh_hash": null,
              "ssdeep": "768:wft4puxyCIamfCjMCnGlAGKnNgDxPGxAhdIu2vQs02SRMJH4QkI:wfmKmf6TlnoxiAhdxFR25r",
              "type": "PNG image data, 147 x 161, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T117C2F1DD06A961F8277BEF754DF244A9C8FF9243A1264CDA49981AD24B3B34C9B04B13",
              "sha3_384": "0fa28330099f9cba8de277f8cd08892d3763f8bddd14e3e31c98209111b7d30bdb10a32253cca1d371baaf2a6f9a0e9b",
              "data": null
            },
            {
              "name": "a60a008920d130e990d42db434b6395eca6bb027e92d0db3a54caf730642645f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a60a008920d130e990d42db434b6395eca6bb027e92d0db3a54caf730642645f",
              "guest_paths": [
                "openmail.exe"
              ],
              "size": 39736,
              "crc32": "ED917BBF",
              "md5": "149af46eb5ec439ae2572bd3a8705a1b",
              "sha1": "9ad785dc5a618d9ed118e2ffc0c2ebd6a6df6c25",
              "sha256": "a60a008920d130e990d42db434b6395eca6bb027e92d0db3a54caf730642645f",
              "sha512": "c665a76c58438396cc8e935cd01dc18e4bab7f270a46bf751438d290f7f20051813ff687ab80d0ad866dfcef10dfadaa146b1291e79599fca28e4259bf023917",
              "rh_hash": null,
              "ssdeep": "768:Kny8+Xxec6uGZF0andPaaUPMSEa1ru43J2bjBmDicOYifiRPQGG:KQ9APtdPatF9unBmDi37fixQGG",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14E038C537E868830E99302B824F79F739C77B1B15F2096D36B50485A16396E1AFBC02F",
              "sha3_384": "0912ee3a93c3a38813196d1c512380b595acdf75474461988d307f882bf050eb78dce173f2e36c4ddc7e84aa20d4e2d2",
              "data": null
            },
            {
              "name": "08d31d7a26a843bd6b7a9e678e32db6c135510abba6bfd6009cefa26cd23717b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/08d31d7a26a843bd6b7a9e678e32db6c135510abba6bfd6009cefa26cd23717b",
              "guest_paths": [
                "OS.dll"
              ],
              "size": 636864,
              "crc32": "C4E76337",
              "md5": "ea1f15b4b09c6a19a2e7935644fc0178",
              "sha1": "4c36671d32925e99621e8d04320319f86cf9bc03",
              "sha256": "08d31d7a26a843bd6b7a9e678e32db6c135510abba6bfd6009cefa26cd23717b",
              "sha512": "05e3c5a3ef548201a5abe767d6eb3b00b1ae2ac7b064876bda89aa7d4394cede2f6474aca0bd8cc1fb563a3510578e25bd2cecc5d73277128fefeba6cfaa3fae",
              "rh_hash": null,
              "ssdeep": "6144:adgr6N0it4uYNvJAaJA++jXVCAHDWGtnrXBGkCIxK:MgGN0ithYByo7+RBlnkP",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T102D4D977EE81E837C91D00FA8C7752663DEA60DF46138A9F300CF55874D61B83AA52B9",
              "sha3_384": "c8f1ce8af1bc1456ddcf220453392481323e6a13ef53bf27cef5547cf9691dc906517bc4a3a915b98a160e777ecfbb39",
              "data": null
            },
            {
              "name": "09f5d4928368144417b60e328345f826eb8c87d67026083902461fe55c5a7baa",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/09f5d4928368144417b60e328345f826eb8c87d67026083902461fe55c5a7baa",
              "guest_paths": [
                "OSMonitor.dll"
              ],
              "size": 70592,
              "crc32": "62FF34D4",
              "md5": "f5b9323d27f335a440af5e6642f76178",
              "sha1": "55e43b0cca793661903e268ef9e37e4763d1e06b",
              "sha256": "09f5d4928368144417b60e328345f826eb8c87d67026083902461fe55c5a7baa",
              "sha512": "811d8bb5ff2e6dbb1489b8c9c32442c2eab9af2ba50baa5eb3194f585299c64481672a7a4cc82ba984f9966a0c5f61f74f9c3f50d747958372babb27e00fabbf",
              "rh_hash": null,
              "ssdeep": "1536:21LcO9pceRXLS19w7xMQdXvpPCmRkxTl5kwiNgNPBdgzsdmdbZ1WQzylSvDmN57h:239ZLp7xMyzylSvDmvQS",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T127634C52EB0480B3E2C943707DA96F390A7CB6949FF156C7AFB75A3D96606E32634304",
              "sha3_384": "0dfa65ce2b797b3be122c3de1c733acd4414329deb1ba52384d615ad584c168a11e7cc06d473fc15049c15dea01dc25a",
              "data": null
            },
            {
              "name": "dd8677390e85da6449728b5c507f691f3fc7ceb13244ab6fb680f0a63f1a6f5c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/dd8677390e85da6449728b5c507f691f3fc7ceb13244ab6fb680f0a63f1a6f5c",
              "guest_paths": [
                "OsScv.ini"
              ],
              "size": 241,
              "crc32": "208DAEFB",
              "md5": "d351a3b1f61450638cbb993fbf23d99f",
              "sha1": "075e5e6f1babb78cc3e2f6afc8bd0804a0998559",
              "sha256": "dd8677390e85da6449728b5c507f691f3fc7ceb13244ab6fb680f0a63f1a6f5c",
              "sha512": "40f483bf6b436871539945156fae6bb8536ac14e922bb6788b3b016a4cf2fe27e965bdbe823cb50250ff584eb3df12f25525b135cb428ebe178d99bbdb620a25",
              "rh_hash": null,
              "ssdeep": "6:gfhok38GLlvy26k38+YTEMprgFk38XgxW5EME1Ek38+8TEMXMn:Yr38GLdy2z38DTEjq38XcW5EL1N38/Tg",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T168D017A145DC1527DBCAB60B7377DCC490090DC91D84B246BAFB986604BFA41B2C898A",
              "sha3_384": "eb1d7d1f8172fefe73e898b4f8e719333870e916d993457709bc0ea0b018bf65c52c48048270c0edbb4a709b87eabf1f",
              "data": "[REG_KEYS_AND_VALUES_NAMES]\nOS_SCV_SCREEN_SAVER_KEY=\"Control Panel\\Desktop\"\nOS_SCV_SCREEN_SAVER_ACTIVE_VALUE_NAME=\"ScreenSaveActive\"\nOS_SCV_SCREEN_SAVER_TIME_OUT=\"ScreenSaveTimeOut\"\nOS_SCV_SCREEN_SAVER_ACTIVE_PASSWORD= \"ScreenSaverIsSecure\"\n"
            },
            {
              "name": "dc5dbd753efafe28e5ed3f682fd867ae1a8cc9cf8f3bd0983499973f72b27a19",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/dc5dbd753efafe28e5ed3f682fd867ae1a8cc9cf8f3bd0983499973f72b27a19",
              "guest_paths": [
                "PacketMon.exe"
              ],
              "size": 183232,
              "crc32": "E78DE7D2",
              "md5": "1d94510a45fe6d716b19b91f207b4f3f",
              "sha1": "a0e38c82edd8e7abb3cea12744f998512143f1fd",
              "sha256": "dc5dbd753efafe28e5ed3f682fd867ae1a8cc9cf8f3bd0983499973f72b27a19",
              "sha512": "33b8b00648b33c0a08c8659c10e3ceb9871fc796835294cdc5bf925c03d16ea159ca36e3ea7d66c6794d00100d97d3253dc79959c1eb636b6c9e66a48efa43d8",
              "rh_hash": null,
              "ssdeep": "3072:O/sjjNgzt59qOkwpNA65D4+u87757T9OaArYSSYYHarP0L0dqPiopQJvJzLMGQTk:QQRgzt59qOkwpNA62j8J7T9OPrYSSYYe",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16F044A31B982C032D49A02751AB54BB66D3C7D30171963EB32B072A84D356E37BBD9E6",
              "sha3_384": "db26a6a65fb0941eeba2a77d77aba8726423613df7c9588d75057d31a5dec6a1367a4133c20ea72be7fcf757b930d6ed",
              "data": null
            },
            {
              "name": "31c64cfd2fdea89f4c9a89e9c933892ae94f7701e3d3747633a554786a4fe02f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/31c64cfd2fdea89f4c9a89e9c933892ae94f7701e3d3747633a554786a4fe02f",
              "guest_paths": [
                "PinPad.png"
              ],
              "size": 5162,
              "crc32": "F0123C49",
              "md5": "27404715f11869f55fe652925f4aa0d9",
              "sha1": "5162433eb4ced4a59831ed2dadff7942f15faf7d",
              "sha256": "31c64cfd2fdea89f4c9a89e9c933892ae94f7701e3d3747633a554786a4fe02f",
              "sha512": "6daaae31b5bc65f21f1f0ce6a1302ba4b00ca87e40d42de76d8153d163ad79a06c1549651bb99f7f863d1629f68cdf719e1a487d20cddb6f5602e6ac97565a0b",
              "rh_hash": null,
              "ssdeep": "96:nPC5GEvGIe5HIuWZUuvEVGDwtlU5EuenYDfY1bD4dtlmazKfe6GovOpSqVX69Xea:nq04AHIB25j8UYDfubDAB+GAOUqVq9B",
              "type": "PNG image data, 56 x 56, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T149B19F93D2B3BF54D21AF002C7CA511EDD53CC964149F616BABBB16D8131FA3059534B",
              "sha3_384": "c493a6bc8f773b01e9022e04b15f70414b732b824971b48c101c758b4e8ae606b76042875e714a6853fa1389fd28523e",
              "data": null
            },
            {
              "name": "95dd9eca4530c786ba263987b1a410ae138b9f11d5003a5f72e5fbf85e89d015",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/95dd9eca4530c786ba263987b1a410ae138b9f11d5003a5f72e5fbf85e89d015",
              "guest_paths": [
                "ProcessMonitor.dll"
              ],
              "size": 62400,
              "crc32": "446AB2C4",
              "md5": "3942cfcad295d8b07e44e0d055cb8702",
              "sha1": "71564f4d0fe4f10015619233cd4b8c2897b111b0",
              "sha256": "95dd9eca4530c786ba263987b1a410ae138b9f11d5003a5f72e5fbf85e89d015",
              "sha512": "1eda25e6b824795db4e29daec2ae5f8058bac495fd927452ac030d8fe03cb79865c3560bfeae8964704f22fb92d4b2190a58298fdb99982773b61f58b6459552",
              "rh_hash": null,
              "ssdeep": "1536:8a+m2+pwS1QJ0t7xAZO2XnFxKnDJg/N5748:8a+qwh0t7xAZFFxKnDyvB",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T143537D42BB1040B2EBDE023475A5BB3B4C7DF654AFE125C3DF6A4A6E88107E1B67520D",
              "sha3_384": "452266f8a4cadce2ee791fbea28335719a55e1b85e6431b1a8c39d58982f490a3c25dfb7f410ebefb09001f9ce454ae8",
              "data": null
            },
            {
              "name": "aa3d54faf86634822c557e5842ac6cac19ccb5a750aa4bb6817dbdd68f261adf",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/aa3d54faf86634822c557e5842ac6cac19ccb5a750aa4bb6817dbdd68f261adf",
              "guest_paths": [
                "progress.gif"
              ],
              "size": 9830,
              "crc32": "476C81E9",
              "md5": "de013e4250c7b48ce1b2d804167dd1d1",
              "sha1": "d0024840a21e11de765455aff3e837b658a09bd1",
              "sha256": "aa3d54faf86634822c557e5842ac6cac19ccb5a750aa4bb6817dbdd68f261adf",
              "sha512": "cd30fb9305cb91fc089a93e2772fa317be03f9119dae1566f66cea99f96f3ea90297b72314f8e0b7537aae88b774ff96682c34d125c5d8028334561c65302397",
              "rh_hash": null,
              "ssdeep": "192:qh8sSzuv00Ea/Y+UJEU5YBdDQHbGu+pj5+44/FRjQoum9QIn82vzy4LIbLwLq28+:qK9if1/gEU5YBdDQ7GvZ5+bvsoRCIn8k",
              "type": "GIF image data, version 89a, 150 x 124",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1DF124B8F66C92837B96D5E3936E76AB40996C8314681F3522F1F9097720012FC25D5FE",
              "sha3_384": "34e775910e2fc585dc803c53d4202994263971c82e02aa1758bb894bf571a7b889a419bfe828b7077c38206b809483f4",
              "data": null
            },
            {
              "name": "05346c06ab582e106f9e804bc0d7e63a7d65316087c36f6520df7e6c78250f6b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/05346c06ab582e106f9e804bc0d7e63a7d65316087c36f6520df7e6c78250f6b",
              "guest_paths": [
                "progress_hc.gif"
              ],
              "size": 8015,
              "crc32": "9149D016",
              "md5": "07ab11c7f02e1845015a2577f27fb619",
              "sha1": "93c34ce533ff26a8aabeac027ff6aec403f730dc",
              "sha256": "05346c06ab582e106f9e804bc0d7e63a7d65316087c36f6520df7e6c78250f6b",
              "sha512": "0824a335711d7d5b2a3fc8ccf494070ba7476016b2ab54fdb6a66e4f15d80538200a15d163ccdc3f3b1a8992c2e501dc2bf48dcd52eea03b5685e58d48d2050b",
              "rh_hash": null,
              "ssdeep": "192:VE0pkfdhz78Jbo54NI37a6QceYclOvm3vFx5pwoO82uphCpselIbQLMkibLJ33+4:SvlabNNI37a6QnYcGm3vFLpwoO82OhCS",
              "type": "GIF image data, version 89a, 150 x 124",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E0F14A2D58CE98337A6E99D93CC45F3544F28A714E9073136A2EF0F73A9009F598A4E7",
              "sha3_384": "cff6cae2615e27f48c232e82f9b22986192948d00ead4a0abecc645e0ee6b46c441774d3939992d13659e2e475ab8417",
              "data": null
            },
            {
              "name": "5f6cd38d4d0f4d6f20e736b56e21e8617ddd5a55412b120c51f9a34b5a9f1908",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/5f6cd38d4d0f4d6f20e736b56e21e8617ddd5a55412b120c51f9a34b5a9f1908",
              "guest_paths": [
                "proxy.png"
              ],
              "size": 2038,
              "crc32": "2A790F7D",
              "md5": "6740505a57d6852365c9627eb5cc33e6",
              "sha1": "bae29d93fdf4cd9217c882976597b086444801ed",
              "sha256": "5f6cd38d4d0f4d6f20e736b56e21e8617ddd5a55412b120c51f9a34b5a9f1908",
              "sha512": "b5a10c6991be9e2c90c3b3dc50bb0aa68f4405766be52a981bed4fec4f874a9b10661d659f15bfe1e33a775eed8c9f0223b708e7e8f0f88ac8536873a409accc",
              "rh_hash": null,
              "ssdeep": "48:gvwGlhIWuolUr+R/8ewaNAujFXTk8Q3Km7DXA/He:gvw4sol++lcaNAujNk8tWDXoe",
              "type": "PNG image data, 39 x 33, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1AA414EFBBEFDDCDC90C702A045A155933DFE14080C779461C906A9E20CD550C28F568D",
              "sha3_384": "0e92a9b3e8287bb7bf822edd5a0f97a479285a2c8494b9653ae6525a1bf22f4f21e58bad4b859915edfb1736029de43f",
              "data": null
            },
            {
              "name": "20303c157ec6467dbb6c632f3cf6795607a28daad1cf473fa22f2ea8990b9f9a",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/20303c157ec6467dbb6c632f3cf6795607a28daad1cf473fa22f2ea8990b9f9a",
              "guest_paths": [
                "proxystub.dll"
              ],
              "size": 27448,
              "crc32": "89CE63B5",
              "md5": "e471dd5544608c4463a67db599876c99",
              "sha1": "1e39611a84c494da8755a6bc55429fca3d0fba1c",
              "sha256": "20303c157ec6467dbb6c632f3cf6795607a28daad1cf473fa22f2ea8990b9f9a",
              "sha512": "ace946172527c0d160157fcc552444219a7d20db63d4df59eabc60fb9cf28b67cbd4585d24373d641bf712d559a019f87c359b4d793df74825dc7c01479c1d65",
              "rh_hash": null,
              "ssdeep": "384:WcbM8lbLhZiJBDg+6JLMikjKK9g3pXgDi//IYif8ZpHzGov1sQSin:LlZh+6tM9KK9g3pXgDioYifiRPyQV",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E9C26C12FF5449B6E59B06B078F69237A876F3802FC082C76B659B0E0A653D26F31177",
              "sha3_384": "08c7e1f0c61a2c51f1b0064011081d7187e84bf9cfa07201985db59f7dea16f66b98f0366a4a7b08f57a1231f9423fe4",
              "data": null
            },
            {
              "name": "b1e839813c61bb7a312f6fc7e68f6c352d9f71ae5bbdf2f4634909048ea92368",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b1e839813c61bb7a312f6fc7e68f6c352d9f71ae5bbdf2f4634909048ea92368",
              "guest_paths": [
                "qt.conf"
              ],
              "size": 59,
              "crc32": "60B469DD",
              "md5": "aea627d17d3eadea6ca66fc52ea44909",
              "sha1": "5e8ff6a3a8978237e17343caaf46a3ac0e77e3c2",
              "sha256": "b1e839813c61bb7a312f6fc7e68f6c352d9f71ae5bbdf2f4634909048ea92368",
              "sha512": "3a2a31898de3d9c54fd03822cc23060172d8cf860da4aa4167357f2b5d1a8e345b417a7a7f0509dff91073709431548dfd4fe5816777f047517365e674b6bc38",
              "rh_hash": null,
              "ssdeep": "3:hWXrwDrT/bRoDzfLErnY:hQr+C3P",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T183A00211113677655173D70302DFD713541D42C434A79E044614023DAB229531C71B60",
              "sha3_384": "b37fdcb73ed3c19bc52aad507a9ae941361c454e37d0c3d65418f1c20ee24c0d2a2c90d39e86dd717fce219084d84cbe",
              "data": "[Platforms]\nWindowsArguments = dpiawareness=1\n[Paths]\nData="
            },
            {
              "name": "d02448d720c29a0beb4d301fc80d5204e8963f0d462716aa44db7ff8226c0e81",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d02448d720c29a0beb4d301fc80d5204e8963f0d462716aa44db7ff8226c0e81",
              "guest_paths": [
                "reauthentication.png"
              ],
              "size": 1258,
              "crc32": "EC8156DE",
              "md5": "63c963e43f732c1feae84a0c83b96a02",
              "sha1": "4d057ed21abc8df753c8d6563eba0d66d873a3dc",
              "sha256": "d02448d720c29a0beb4d301fc80d5204e8963f0d462716aa44db7ff8226c0e81",
              "sha512": "8622d23837d4c5f06f74efdd39bb653c4306e8fa67eecd9e51a157e0c4007e6917f3dec806df433c7e12e53f934d40a2b6759673cd051debbee00531ed6b3058",
              "rh_hash": null,
              "ssdeep": "24:gYg4HqC99mX8UDgwaaIizB6x8CfPKK48LvqIAh8pwnscZ3tqSc:ZHqKihgwfIi4fPKK9BASpwscZ3w",
              "type": "PNG image data, 23 x 23, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E621E7BB18AE991DA429309082716F2584B14BA0D0266CF37A9099717D3A220F9D22C3",
              "sha3_384": "bcfa47e06ca8b7fd2c7531b661cdfb1eb3bf3f6594ceea567775027beff72e32e1155f6a193c530af6f6a8c8cbab795f",
              "data": null
            },
            {
              "name": "0bd2bc9af5a71656af4b17796095e13442adb46e487f050fac901bff487e1712",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0bd2bc9af5a71656af4b17796095e13442adb46e487f050fac901bff487e1712",
              "guest_paths": [
                "RegMonitor.dll"
              ],
              "size": 60864,
              "crc32": "55E26077",
              "md5": "b5b2b7984a00bd91c193e23ebbdbe17b",
              "sha1": "5854349647c0b60b5e996d9da05edb09c8c7cecf",
              "sha256": "0bd2bc9af5a71656af4b17796095e13442adb46e487f050fac901bff487e1712",
              "sha512": "036d72c1e401059b85b983bc2ee0b6f8a37e2df94eee85b3f3e5fe6345646d45cb4363b933de4cb6b796fc45e38c19f540348f2232297d750402d5e7b239489f",
              "rh_hash": null,
              "ssdeep": "1536:EtLPaQIC7nq0S1p72u+hHsbrWFQSvQDpXN57C:ERPaQ1q0C72uZbrWFQSvQDFvO",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T179537D83BB0440B2E7CE013475E6AF7B4579F6548FE111C3AF6B1AAE59206E2F63520D",
              "sha3_384": "5acdfaf456520c93a4042307dc9935c7aa53897b02699bf914c7c19868e753b4234e849f452f20ab64248a5401387cde",
              "data": null
            },
            {
              "name": "f28e5e670d7f306a40f87dcc8b92e4e20ef02f97561167539bb3a97f7cf464cf",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f28e5e670d7f306a40f87dcc8b92e4e20ef02f97561167539bb3a97f7cf464cf",
              "guest_paths": [
                "RunAs.dll"
              ],
              "size": 38336,
              "crc32": "A3AD47A9",
              "md5": "363d3ddec567a286acc35ac755192ca0",
              "sha1": "92eaffb285dd8c4afc5922140fe03d143e27a19f",
              "sha256": "f28e5e670d7f306a40f87dcc8b92e4e20ef02f97561167539bb3a97f7cf464cf",
              "sha512": "7442ff4f9162689c2f8e73b1047c0128f5188125b4e2bc44f1589694b49be7d32b21a30ccb24fd213c1494cc0c01b795f801f0d88c018394eb84d1db6933a9d8",
              "rh_hash": null,
              "ssdeep": "768:ufWJeh+y2MThEJ/4w2et6iDvp7dC+93bRpueIAZDvKGBkNlT5Yip:6seh+y2MThEJ/NoExz93tIAZDkN57p",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F6032A415A1501D2F38F8A3831E46F2F8CEC321487BD85A797538D6CC6A85D3B66F267",
              "sha3_384": "facb93a73977e47ec99bebde33bf7b2eb2b7da0f179c5ce5f269a1c3d705413467ca1414f4c87b05ae5b5280fe240547",
              "data": null
            },
            {
              "name": "c712de5d52dd8a490c342e43e3965d030cc62fc0c41d97571f4940a3173eea11",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c712de5d52dd8a490c342e43e3965d030cc62fc0c41d97571f4940a3173eea11",
              "guest_paths": [
                "saa.png"
              ],
              "size": 3475,
              "crc32": "842F02BA",
              "md5": "c8e6677ddce73fabfc3e2c1fe22db8bc",
              "sha1": "d748201a40df12021baa72ac0816cee9fdf08d10",
              "sha256": "c712de5d52dd8a490c342e43e3965d030cc62fc0c41d97571f4940a3173eea11",
              "sha512": "06f47e2ebbd92f4937415edd0e2341585c9b6d8e5e1058e21614ee189cb4c4ad79a9473f0dff2f116d34cfb322e9e1cbc48f8060cb6cc440e89e7171099f7f89",
              "rh_hash": null,
              "ssdeep": "96:BoMrdKJaFx3Xe8m3RioAVghm9PZMwCgua6qciiCM:msal/A1HMwwNqc3CM",
              "type": "PNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T11B617D0F36F4CE7A60D7AD1725122356E07462BDD005DB14E375CD1A019AD4C792DAE4",
              "sha3_384": "8e612583b5610f2fe713b3608e4948eb6812d1739574ef930dadce37553ff46cba8d06ab2f10e58cf8d8d4d27395c1cd",
              "data": null
            },
            {
              "name": "329890be8e9335989952d6a363be4eabe4eb780485698bc9daf3a2e4b34efb89",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/329890be8e9335989952d6a363be4eabe4eb780485698bc9daf3a2e4b34efb89",
              "guest_paths": [
                "sad.png"
              ],
              "size": 791,
              "crc32": "766BD46A",
              "md5": "9f83b2096e9d8956c4bc6114e228a34b",
              "sha1": "b29d6474934b092cdca8fd2aadafa8b9014e2741",
              "sha256": "329890be8e9335989952d6a363be4eabe4eb780485698bc9daf3a2e4b34efb89",
              "sha512": "7d5b69eee62aa96d5a36a17bff1f38a3a6eb84d3ab125266d64cf0880044201c36cb944ab48721e07fe01dcbec2013a73c740ae0fb1a0013efa9d289c06827cc",
              "rh_hash": null,
              "ssdeep": "24:36l9HGAHW22a6gt3q+Rtxy33lx5J+AeC8v:36TmA2QnRry3nSh3v",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T11C01CAE37C652DF470904584AC12F01090F2779C71379CDE0E4F0015ADA7B104498945",
              "sha3_384": "d1d655c1062b8e85d9134f6b0451b4afe49a060257e667dff8234d4135ce157d63e8d3e94066476dfd0586baecd10533",
              "data": null
            },
            {
              "name": "f05879a99971a12d0528218b42098051e71326922ce3ec55d4746b673e5a69a6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f05879a99971a12d0528218b42098051e71326922ce3ec55d4746b673e5a69a6",
              "guest_paths": [
                "ScriptRun.dll"
              ],
              "size": 63424,
              "crc32": "CCD99982",
              "md5": "6a792005d4334458add9e061f48d7d18",
              "sha1": "f0eacc9a5e177e4db15030bf5920498bdc9df65b",
              "sha256": "f05879a99971a12d0528218b42098051e71326922ce3ec55d4746b673e5a69a6",
              "sha512": "19021816eec9e5260968f9caa0246b31ee55690fe16bdb035fc7e5f96dfc66b0b399c1bc62c24b664078223adb2d8ca442dc150d6d683d9c38b80e77567753d6",
              "rh_hash": null,
              "ssdeep": "1536:w3SWMto6W6tPkhS1fjb7hkaNxFKeoYWMxDYN57t:w3vMZW6KhE7SqoYRxDYv5",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E1538E52FF4040B2EBCD027035B5AF3B487DE6645FE191C3AFAA0A7D55207E1BA7160A",
              "sha3_384": "8883cfc5183a098e781386d0cc7295d65cdaf0967de3f8c71476e0d15e1725c30c3353a5118044f9f11bc97c75f7546a",
              "data": null
            },
            {
              "name": "2f4aa2713ab30829c0d9e8e51abc623b570367d2ab6e44657b4cbcf916ab6d6a",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2f4aa2713ab30829c0d9e8e51abc623b570367d2ab6e44657b4cbcf916ab6d6a",
              "guest_paths": [
                "SCUIAPI.dll"
              ],
              "size": 99728,
              "crc32": "F98AA268",
              "md5": "a0eabb04a640addd9c23fbe619ef714b",
              "sha1": "8aaf6a2907ce3226f8caa4658a5a807167e9afd1",
              "sha256": "2f4aa2713ab30829c0d9e8e51abc623b570367d2ab6e44657b4cbcf916ab6d6a",
              "sha512": "7ada208a19822c8b60275e50c806fc91821f114e54790d42346309d38d43de982ca74a8fe913202a9efd7ee110645c0150097b74946d2c6093292a32752dfd00",
              "rh_hash": null,
              "ssdeep": "3072:UNOtTngF9xtCIoK6NRXfIVbNG6qjlDZBvX:UNOS9xt5opRX8BG6qnBP",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D5A3AF62250C48F6CCED0532F5894B364EFBA5306EA59463C772C2B90D74D42AEBE376",
              "sha3_384": "1a785365ff1f0ebec968ea893e47d61d7538580e6e244e7668f66badeac3a4962e5307c3c9c0ec6c1a303c6ea88a6394",
              "data": null
            },
            {
              "name": "2d74db7550741fa995e8dfa238e900ce5927dd78dba7c1e9c46a2213786a639c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2d74db7550741fa995e8dfa238e900ce5927dd78dba7c1e9c46a2213786a639c",
              "guest_paths": [
                "SCUIAPI.png"
              ],
              "size": 3733,
              "crc32": "8AA297DD",
              "md5": "d00b25b819dfd377a5616a5a4ee74804",
              "sha1": "0396fc42241ed8b9d8feca3b8c406a48b9a235ba",
              "sha256": "2d74db7550741fa995e8dfa238e900ce5927dd78dba7c1e9c46a2213786a639c",
              "sha512": "e6aab94a7067626641f87a3f0c5430b7705f9b37ceaf4a6f23c2ba5b2d1df49becdbe735557f137ee244d5618c03f2fa475395f5fff8115102a45864443c20c2",
              "rh_hash": null,
              "ssdeep": "96:cK/stawnXgxMLIirUrRPdNcH2cJKslLg/0pssFT5phZ:cKhwnQxZn5d+W7Q0+ssFT5R",
              "type": "PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18D717CBB113AAC1F6DA950F4F8080D2E407CB84CAC562F96E01763EC6068E2A512E019",
              "sha3_384": "24aed16aec57fe04224116d973f481b80b4fefd0dcc031a2a4e5ba7750f13e94424d34b43b53769fb1995c46c0631de1",
              "data": null
            },
            {
              "name": "4c79179fbb4c36d00e4a725f2fa5f7844e1a0c4d9ca0626591061b54ef870cef",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/4c79179fbb4c36d00e4a725f2fa5f7844e1a0c4d9ca0626591061b54ef870cef",
              "guest_paths": [
                "SCUIAPIConnLogo.png"
              ],
              "size": 24962,
              "crc32": "3FB60167",
              "md5": "9872d6a6e6a1b40253d3cc1d1c0bcfcc",
              "sha1": "8d3fb69631de8070919ebec6670d92cd16dcacf1",
              "sha256": "4c79179fbb4c36d00e4a725f2fa5f7844e1a0c4d9ca0626591061b54ef870cef",
              "sha512": "7d2f1d430b9c1a8c534035252298afaf547c52561716e0c127d4f50a1e3841c62bd13bd27bbc27ee439b9692ac92634c36651d7ba5c92a273ca8b86d104276c4",
              "rh_hash": null,
              "ssdeep": "768:r6oCNK8QIlZwVgoUPt/cXQfv6eZsDhB7o3kyNzqBwuDs:yK8x7wVgoUPtXItBekyexs",
              "type": "PNG image data, 537 x 57, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1C7B2D0511A2BEE95F3C9A6BE752408397449B8DD3574D9E0F4388B180C82C7C572EEBA",
              "sha3_384": "0b4c05191b5d65c8596215b3bb54c2b1e79da28a288856d2fcd24869107aac5aa33aa3f0c87c5d99ceebd90caa61580a",
              "data": null
            },
            {
              "name": "9cf436954dd9532fc1c05ac6e6f490537c718999abdff514630be2b61dce0f5c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9cf436954dd9532fc1c05ac6e6f490537c718999abdff514630be2b61dce0f5c",
              "guest_paths": [
                "SCUIAPIEndpointBanner.png"
              ],
              "size": 25076,
              "crc32": "2ED11D59",
              "md5": "9c658f305d7f386d690633fd5a5271ae",
              "sha1": "0801d3a4e06b9c019930a076390c98d598eca193",
              "sha256": "9cf436954dd9532fc1c05ac6e6f490537c718999abdff514630be2b61dce0f5c",
              "sha512": "812e7950f1da698ee4012ff8cf06cdfa3b41345903bd817de63d6fa08e192f6848d1d58ae967b15769bd01006a4498637753cc3b04fb7f34ce51b190ec2faf3f",
              "rh_hash": null,
              "ssdeep": "768:ynKxud7voVoGNJOPITOqX7AK2YHW2HcJwOPn4XtlsEC:ynK0d7soGNOgOqLAG2mcuOP2nsT",
              "type": "PNG image data, 537 x 57, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T171B2D140A22776A6E7DC8C63FA06D0E7AB1A360B00B7FACFB7457A354E54725780F511",
              "sha3_384": "4e99a79409c3f732f40538cbb699623f8582a075a70f518fa7a30828d6c5c6181894c7bca552cfee32ecd825e92f59a4",
              "data": null
            },
            {
              "name": "a964a2b84b32cccb215d00740e337d6d4f005be188162a7426e23b48407156aa",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a964a2b84b32cccb215d00740e337d6d4f005be188162a7426e23b48407156aa",
              "guest_paths": [
                "SCUIAPIEndpointBannerBig.png"
              ],
              "size": 20230,
              "crc32": "012CB82A",
              "md5": "a972bf2473d7559d68ea456644544d80",
              "sha1": "2033d599b8a08fd8a5ebd2ea76b2ea9e9b617807",
              "sha256": "a964a2b84b32cccb215d00740e337d6d4f005be188162a7426e23b48407156aa",
              "sha512": "8d1b112bfb323718894160a5e5771de9e31267cea5737d8cf7b889e386a25d1db05b315cd263dd63bb20f3c29c24f4223e0e1d86e1377c88f0b7ceb82eaf792f",
              "rh_hash": null,
              "ssdeep": "384:FXVvQmDcmhRsgucZwwtd3WpRwN5aSGFRL+n0IzpkNpFKqmrWMYVKyGsnvRZYM5:FFNcWRPLZJ8RwN5000It6q6JVnrY0",
              "type": "PNG image data, 702 x 61, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1CB92E15DEAFD7185270746CB954899C8382A2FCA17D2162F6B01FF385BB18063D622A3",
              "sha3_384": "18da9dd16bd68a783521eb988f423a1001d25a2470379a1f5f34f997d28213887b569c7d02036709238cacd7a908bfe3",
              "data": null
            },
            {
              "name": "15c2f8648877e98686814dcc645f9ab9a551278a27882f253332adaa8b7ea14b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/15c2f8648877e98686814dcc645f9ab9a551278a27882f253332adaa8b7ea14b",
              "guest_paths": [
                "SCVMonitor.dll"
              ],
              "size": 61376,
              "crc32": "78CCF497",
              "md5": "3b60ecd3e8bd87e77608f9f69c675f19",
              "sha1": "c93401202f33e9817ad462e661fab600b0d5e169",
              "sha256": "15c2f8648877e98686814dcc645f9ab9a551278a27882f253332adaa8b7ea14b",
              "sha512": "e4fdc2cdb54254a10bf6b553b8dda837961cceea4de15d50896119b599b4fc90fa311e7c2360fa5563da348d658311868678eb3c4e3f61aff5c76432f073fc1e",
              "rh_hash": null,
              "ssdeep": "1536:AhAzVzpKP9YKqQS1FU78HWF3HcFFiS1RJatmDIvlN578IL:ACJzpOP5l78HZD1RJatmDIvlvIIL",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B3535C42FB0040B3E7CE027435A5BF3648BDFA649FE156C3EFAA1A6D45217E16B74209",
              "sha3_384": "e0dfbc20aa0f712a9b5dfb90870fa9a85aa9a197a0ea65a622c81dc7be7c59de052a494426d1c8b956bca569bda1c6a9",
              "data": null
            },
            {
              "name": "9eb54e3b22f25a4ba5f1e1721967732b59c6cc2547ea29d45119e1100eff3f8e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9eb54e3b22f25a4ba5f1e1721967732b59c6cc2547ea29d45119e1100eff3f8e",
              "guest_paths": [
                "ScvPlugins-32.reg"
              ],
              "size": 23832,
              "crc32": "3EE34968",
              "md5": "acef67a5f509ae67ab088669ca1954d3",
              "sha1": "fc83e9101c34d89c27d607b84a60534341fe1b44",
              "sha256": "9eb54e3b22f25a4ba5f1e1721967732b59c6cc2547ea29d45119e1100eff3f8e",
              "sha512": "ce9d2563284b2ed76c81af3ae43a36add70061663a35c3a2d2405699485e80f5e2aa55cc3e4867a24fb04fceb11af28809fffbd9eaa514821bf7edfa1843a9a1",
              "rh_hash": null,
              "ssdeep": "48:9JfOcONOOqFOIOPkqcnOGuOGNqumOoOcq9Ow6OwKSqCOwOcqH/OFM6OFMc0qI7l2:Paqekqccquqqoq+quqY6nqGCq+2qMq6",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A2B24A660C1C817DF2252800D749BC822251E83F56FA65EF47F84DD3E6B6C534AEA74E",
              "sha3_384": "79ec1766fdcf561d122b14aef9649a621ed682cca7db5525728215448816cde78af5687fc6f740c4dceafbd2aefbf113",
              "data": "Windows Registry Editor Version 5.00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\AntiVirusMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\AntiVirusMonitor\\1.0]\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - AntiVirusMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"IMAGEPATH\"=\"C:\\\\Program Files\\\\CheckPoint\\\\Endpoint Connect\\\\AntiVirusMonitor.dll\"\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,10,6b,36,78,eb,36,de,77,0b,9f,ee,0c,91,\\\n  4d,11,6b,00,00,00,00,04,02,00,00,41,6e,74,69,56,69,72,75,73,4d,6f,6e,69,74,\\\n  6f,72,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\BrowserMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\BrowserMonitor\\1.0]\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - BrowserMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"IMAGEPATH\"=\"C:\\\\Program Files\\\\CheckPoint\\\\Endpoint Connect\\\\BrowserMonitor.dll\"\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,32,4a,f6,00,db,20,18,41,5d,d8,ae,8a,b6,\\\n  8f,58,16,00,00,00,00,04,02,00,00,42,72,6f,77,73,65,72,4d,6f,6e,69,74,6f,72,\\\n  2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\groupmonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\groupmonitor\\1.0]\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - Group Monitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"IMAGEPATH\"=\"C:\\\\Program Files\\\\CheckPoint\\\\Endpoint Connect\\\\GroupMonitor.dll\"\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,39,84,f9,76,c0,0b,42,08,57,8b,af,47,f2,\\\n  97,73,cb,00,00,00,00,04,02,00,00,47,72,6f,75,70,4d,6f,6e,69,74,6f,72,2e,64,\\\n  6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\HotFixMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\SCV\\Plugins\\HotFixMonitor\\1.0]\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - HotFixMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"IMAGEPATH\"=\"C:\\\\Program Files\\\\CheckPoint\\\\Endpoint Connect\\\\HotFixMonitor.dll\"\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,da,2c,33,a8,0f,53,c6,99,9b,c3,4b,bc,f1,\\\n  9c,2b,a7,00,00,00,00,04,02,00,00,48,6f,74,46,69,78,4d,6f,6e,69,74,6f,72,2e,\\\n  64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00, <truncated>"
            },
            {
              "name": "770216ff98abcb96fcd9738d47a12ae99ae867c2eaeaba73c3e2db7f4d85f24d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/770216ff98abcb96fcd9738d47a12ae99ae867c2eaeaba73c3e2db7f4d85f24d",
              "guest_paths": [
                "ScvPlugins-64.reg"
              ],
              "size": 24237,
              "crc32": "A1614F6F",
              "md5": "4f46e5c96b38d5065029e4173643b2ac",
              "sha1": "ee5048de2a1212a1bf10d4480b087942983ad22d",
              "sha256": "770216ff98abcb96fcd9738d47a12ae99ae867c2eaeaba73c3e2db7f4d85f24d",
              "sha512": "f547fc72300c57645c09533c5981f8f9d610f074236e20b8122ef8773728d60dcbdf4b3e525b9ca2d6c6008f9f0ac416d0178958f207c583ef282cca9dd28486",
              "rh_hash": null,
              "ssdeep": "48:9JfgUVeVQYLXaQ5kRnNuNFQ6imZAQm6j6jJQzSONMQGc/kM6kMJQIk08l6HtsQTd:P/Y35kRH6iamkmCGYCu6nWdnDNOeSw6",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T107B26E260D1C817EF2266800D745BD8222A1E83F56FA95EF43F44DD3E2B6C9315EA74E",
              "sha3_384": "5eb76e09ae442153645d82d830cdb365c57825529022aca6fd9b09882a59d71ccdb9ba626485d8a34ea062983076805a",
              "data": "Windows Registry Editor Version 5.00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\AntiVirusMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\AntiVirusMonitor\\1.0]\n\"IMAGEPATH\"=\"C:\\\\Program Files (x86)\\\\CheckPoint\\\\Endpoint Connect\\\\AntiVirusMonitor.dll\"\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - AntiVirusMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,10,6b,36,78,eb,36,de,77,0b,9f,ee,0c,91,\\\n  4d,11,6b,00,00,00,00,04,02,00,00,41,6e,74,69,56,69,72,75,73,4d,6f,6e,69,74,\\\n  6f,72,2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\BrowserMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\BrowserMonitor\\1.0]\n\"IMAGEPATH\"=\"C:\\\\Program Files (x86)\\\\CheckPoint\\\\Endpoint Connect\\\\BrowserMonitor.dll\"\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - BrowserMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,32,4a,f6,00,db,20,18,41,5d,d8,ae,8a,b6,\\\n  8f,58,16,00,00,00,00,04,02,00,00,42,72,6f,77,73,65,72,4d,6f,6e,69,74,6f,72,\\\n  2e,64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\groupmonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\groupmonitor\\1.0]\n\"IMAGEPATH\"=\"C:\\\\Program Files (x86)\\\\CheckPoint\\\\Endpoint Connect\\\\GroupMonitor.dll\"\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - Group Monitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,39,84,f9,76,c0,0b,42,08,57,8b,af,47,f2,\\\n  97,73,cb,00,00,00,00,04,02,00,00,47,72,6f,75,70,4d,6f,6e,69,74,6f,72,2e,64,\\\n  6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\HotFixMonitor]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\TRAC\\SCV\\Plugins\\HotFixMonitor\\1.0]\n\"IMAGEPATH\"=\"C:\\\\Program Files (x86)\\\\CheckPoint\\\\Endpoint Connect\\\\HotFixMonitor.dll\"\n\"DEPENDONGROUP\"=\"\"\n\"DISPLAYNAME\"=\"CheckPoint Scv Check - HotFixMonitor\"\n\"ERRORCONTROL\"=dword:00000001\n\"GROUP\"=\"SCV\"\n\"PRIVATEDATA\"=\"CheckPoint Scv Check\"\n\"START\"=dword:00000002\n\"TYPE\"=dword:00000001\n\"HASHREC\"=hex:20,02,00,00,18,00,00,00,da,2c,33,a8,0f,53,c6,99,9b,c3,4b,bc,f1,\\\n  9c,2b,a7,00,00,00,00,04,02,00,00,48,6f,74,46,69,78,4d,6f,6e,69,74,6f,72,2e,\\\n  64,6c,6c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\\\n  00,00,00,00,00,00,00,00,00,00,00 <truncated>"
            },
            {
              "name": "0757f70c9c1662f428368d365ef39a0d3aca5d10405298807821e91b7362e501",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0757f70c9c1662f428368d365ef39a0d3aca5d10405298807821e91b7362e501",
              "guest_paths": [
                "scvprod_lang_pack.dll"
              ],
              "size": 22464,
              "crc32": "3664425A",
              "md5": "4f54490f798fe62adf454ba7b18bfa20",
              "sha1": "4a9ae869452c9d22dba4995622af0b21d79dc725",
              "sha256": "0757f70c9c1662f428368d365ef39a0d3aca5d10405298807821e91b7362e501",
              "sha512": "d9d88a429c17354634da4fea15f0442b7c0a04ba950f0a14001b69aac38ab05fb0081d1555adf12cc5c31b2ce3911b15e23f28433f5637bae1778ec468338879",
              "rh_hash": null,
              "ssdeep": "384:M0zD0x1QTtJsTmXYu/h1DyWwGBkNl6bCI9IYiDZG:M0/03ut+41/h1DFkNlT5YilG",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T17DA26C43FF744437EE5A0EB068E29517ACBCFA808DD4554B7702D7091E68381BF6953A",
              "sha3_384": "920b3bf78ac3864b831bc2b50ffa8f1831489a17856ef39c2fa40dd21d2448f36c53b1eb281ebd56f7a7443bda02bbf0",
              "data": null
            },
            {
              "name": "6761b681070963954f5fd0ee45e2f7c05ec47b7e06d7eb6c1d9dc6f9d323d597",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6761b681070963954f5fd0ee45e2f7c05ec47b7e06d7eb6c1d9dc6f9d323d597",
              "guest_paths": [
                "ScvProxy-32.reg"
              ],
              "size": 465,
              "crc32": "8D26AD60",
              "md5": "624313ec3c24d14a3e738bd06877c0cc",
              "sha1": "9c524b65e30a2135b456f9dbdca1566d6b37894f",
              "sha256": "6761b681070963954f5fd0ee45e2f7c05ec47b7e06d7eb6c1d9dc6f9d323d597",
              "sha512": "ea4f287951a7caf9907082d28febc1395ba68d04a8738a27dc3db3cff568b9afd1a7797ba10fbc591fdaa397af9816a88fce9d9f5127955636ad5d02c184380a",
              "rh_hash": null,
              "ssdeep": "12:jBJ0SK0TXLyqQ+XLyqIkXLyqLJnshi+tuKKDcUzT56MRj:jBJtDOqVOqxOqNnshaDcUzV",
              "type": "ASCII text, with CR line terminators",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T185F0E2330822D11AE23A6400195BED8233A5B41E13EBD55501ECC1D13BC2CE34A35B0F",
              "sha3_384": "8546275a89c8d7a37d32363b33d2925a4482a365699bf649f9904bf95e1058f5f4dd1c9b4bf75b5e0de35d95de820669",
              "data": "Windows Registry Editor Version 5.00\r\r[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\Plugins]\r\r[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\Plugins\\scvproxy]\r\r[HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\Plugins\\scvproxy\\1.0]\r\"DISPLAYNAME\"=\"Proxy Stub PI\"\r\"DEPENDONGROUP\"=\"\"\r\"PRIVATEDATA\"=\"\"\r\"ERRORCONTROL\"=dword:00000001\r\"TYPE\"=dword:00000001\r\"IMAGEPATH\"=\"C:\\\\Program Files\\\\Checkpoint\\\\Endpoint Connect\\\\scv\\\\proxystub.dll\"\r\"GROUP\"=\"System\"\r\"START\"=dword:00000002\r\r"
            },
            {
              "name": "7ad3019541612e6e3a0b20e48616dae661741f707d37a72487542029ff2edf25",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7ad3019541612e6e3a0b20e48616dae661741f707d37a72487542029ff2edf25",
              "guest_paths": [
                "ScvProxy-64.reg"
              ],
              "size": 507,
              "crc32": "3F1367E4",
              "md5": "d2832141eaa75ad38d46bf1259f4c082",
              "sha1": "821cde32ce3767e9d3554764eb0b21c2de7d28e5",
              "sha256": "7ad3019541612e6e3a0b20e48616dae661741f707d37a72487542029ff2edf25",
              "sha512": "1286169a96a6aae1189acc153b69ecf4e41a7676ac419e8fd11084ea7acbc78865d90757a4ef723d1f6489fe101026ab6c01a0dd89029263d7a3eefa4261aa9d",
              "rh_hash": null,
              "ssdeep": "12:jBJ0SK09LJD/3LJD/jLJD/asSjJoiRtSmJuPjUzT54awZMRt:jBJt9lD/3lD/jlD/SFoF3PjUziaw+",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A3F059774922814AF22968000A97ECD237E1B84F23D7DE1400E8D1803BC3CC3067575E",
              "sha3_384": "5291ee514e317bb6adaf01d1ee1e8171615999ead68e2ad777df940988c41ad7146b16a7fc4df990b462cebf81112e90",
              "data": "Windows Registry Editor Version 5.00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\wow6432node\\CheckPoint\\TRAC\\Plugins]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\wow6432node\\CheckPoint\\TRAC\\Plugins\\scvproxy]\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\wow6432node\\CheckPoint\\TRAC\\Plugins\\scvproxy\\1.0]\n\"DISPLAYNAME\"=\"Proxy Stub PI\"\n\"DEPENDONGROUP\"=\"\"\n\"PRIVATEDATA\"=\"\"\n\"ERRORCONTROL\"=dword:00000001\n\"TYPE\"=dword:00000001\n\"IMAGEPATH\"=\"C:\\\\Program Files (x86)\\\\Checkpoint\\\\Endpoint Connect\\\\scv\\\\proxystub.dll\"\n\"GROUP\"=\"System\"\n\"START\"=dword:00000002\n\n"
            },
            {
              "name": "6471aa33c437d579b6a0ec1e51e1a3e03819e4690a270c5b0f5928db3f1aa45f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6471aa33c437d579b6a0ec1e51e1a3e03819e4690a270c5b0f5928db3f1aa45f",
              "guest_paths": [
                "sdl.png"
              ],
              "size": 3506,
              "crc32": "DC3419AA",
              "md5": "79f3379900da1d3886535d365ca5315a",
              "sha1": "6bdaa7348b5cd1b017a482351b8d138f0f93218a",
              "sha256": "6471aa33c437d579b6a0ec1e51e1a3e03819e4690a270c5b0f5928db3f1aa45f",
              "sha512": "68a2fe0d03e8764b0e115dadbb53ce857aa932ef57931c044e81b66189713dfc1606d85f1142cf4a9de6db5f15d87cbdbd0bbe0de514b3f36a04fd2c00dd72b7",
              "rh_hash": null,
              "ssdeep": "96:WDFUI594znct6HBweL1wRfB6tiD8KZo5vPtdj+JbibD9d:WDmCV6BrLTtiDlo4lEDX",
              "type": "PNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T155716E4DFDB1C9B4556D293E0C119D590D1D0AB6894B8621D5FE3F104D1CEB70AE9580",
              "sha3_384": "88e6bf2d1cef34420111ff8b8f9edbb8c40f117a01700d37c7f2dd242794e431cd124dfef8f38a5cf428551f2fdb47c6",
              "data": null
            },
            {
              "name": "0bc757ffdd77fb0e902089ed7b45a4c71fc4d45fdb171c0831522676e7a8c86b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0bc757ffdd77fb0e902089ed7b45a4c71fc4d45fdb171c0831522676e7a8c86b",
              "guest_paths": [
                "securityAlertIcon.png"
              ],
              "size": 1592,
              "crc32": "F2CB3429",
              "md5": "860310e864233609e1cf884aed3e54f8",
              "sha1": "16fceabcff4ccaacec50efc82e9c64c5ad6b7168",
              "sha256": "0bc757ffdd77fb0e902089ed7b45a4c71fc4d45fdb171c0831522676e7a8c86b",
              "sha512": "d8cb31a41f0bb6a0cb128a613cea4877833cb15a8072539cfe28dc5f4366b063953ca5d631a8c09793e8d0921cc104eae894e8bb89fe8f4085b9810f2ea5d48e",
              "rh_hash": null,
              "ssdeep": "24:5PvsE70RzuZ90xgu8vfRFbVaWyQpuRFY2fJ29ghKy31G2ZlpWj/sLCEigo70o:iE4uXSgxjAfQURFY2fY9g8y31WicgK",
              "type": "PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16C3107BA6A1D946CEE0C128315E9404AF867BE784B68E42D6C6163C29CF2787C4F0DC4",
              "sha3_384": "b026a9d4d765a031552c45552f04b8d3bbca615e5f7d95d9e6398cff5d45cacdae6c8ae16cbbdb275b59e86ba29a1bb7",
              "data": null
            },
            {
              "name": "75985cb324122658268b9f6d11531e8a2c2f300b3aafb07f267c7669c39139d3",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/75985cb324122658268b9f6d11531e8a2c2f300b3aafb07f267c7669c39139d3",
              "guest_paths": [
                "securityInfoIcon.png"
              ],
              "size": 1559,
              "crc32": "DF674C8F",
              "md5": "8f408b788e5fc303eb2ba80328b54b13",
              "sha1": "85323009bc123fd89176a8a32f275b03f4ae0596",
              "sha256": "75985cb324122658268b9f6d11531e8a2c2f300b3aafb07f267c7669c39139d3",
              "sha512": "caad7227b64ac3856b44ddaa1a68bf98773f910c415c2f137e29c3f46787080de6bdb76b6457f2412ad1b33e1d108fa7a1c7c01da8428408ccb5bb922d4f8caf",
              "rh_hash": null,
              "ssdeep": "48:vADueGGAl/1z7o7p/g2hWlaTpcJYeMwX7HH2:4DivlF76g0WUSJYedW",
              "type": "PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B6310AD172D69568142FB4A25D276CA12CA30AD8C414AF1F20ACDF1CCAF4B53D7163A7",
              "sha3_384": "5f9b48a5fa792989c6ecfd6430df44f6ed60df1bb529a253282257b1165a0e40f73cf82a3f2f66d49fe746c8ecd65a00",
              "data": null
            },
            {
              "name": "c30c9f5267edac9d60dc1cb24bd07c7ad1a7ba62569a546d82c9b480cf4367e1",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c30c9f5267edac9d60dc1cb24bd07c7ad1a7ba62569a546d82c9b480cf4367e1",
              "guest_paths": [
                "sidebarBackground.png"
              ],
              "size": 4253,
              "crc32": "4B480677",
              "md5": "84c83c7818c118962fae2c8ca9290fe5",
              "sha1": "49e95c517e34e882802759187203be531844346a",
              "sha256": "c30c9f5267edac9d60dc1cb24bd07c7ad1a7ba62569a546d82c9b480cf4367e1",
              "sha512": "f6ffba8f1474bf80ab3a963e741fb855b192032de58a16deeb7b61449ba6d151cf3122480aa7f87d52ea1d07e0a1f8327db343f1e78b3b8dcbdd97c286b4bcd2",
              "rh_hash": null,
              "ssdeep": "96:tcAgDXJcI6vYcAv9DAQRvzxCNGZmlsvh3L8GK2xzJjQbuqNuf7DarvZ:tJgDJcIPvpAQBzxsq7rNwCfna7Z",
              "type": "PNG image data, 170 x 439, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1EB914BD5EF38DCC5E08ABC7578ADD319FCC09460F81D5B10B461632D1198268B3E32D4",
              "sha3_384": "5cd3da2d19bf9e4b14e6a9bb1afca6da5f13959f31a0686d57efbddd53013eed83a27a07d43e1ea4ce28f2953f2f7329",
              "data": null
            },
            {
              "name": "7c0cdb6e3a498c661306acf7d5ebbadb4422c73048005465d0f42980811cb529",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7c0cdb6e3a498c661306acf7d5ebbadb4422c73048005465d0f42980811cb529",
              "guest_paths": [
                "sidebarButton.png"
              ],
              "size": 589,
              "crc32": "CF150B77",
              "md5": "b2d216c5945ceeac03f26244721f5115",
              "sha1": "17c4d6919b6541050b2826bc62d0813b029676f8",
              "sha256": "7c0cdb6e3a498c661306acf7d5ebbadb4422c73048005465d0f42980811cb529",
              "sha512": "f6d21fe865b980d66c67073ca2abdfd999de425a93a272fa1aee6731134e7db47b7089602af6a7f977692cdd2a9d97bb7efa3b98c930720c74c583bbeb319f68",
              "rh_hash": null,
              "ssdeep": "12:6v/78G/UF/iVy1zNejJBGB8LCRdZfoQVFf0/dN5VEmMAEKENg9t2c:RF/iVyzNejDGGuZfoEFfQnV9M3K72c",
              "type": "PNG image data, 160 x 24, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T102F04797E319085CD38485EA15D3384D5C7A247A17615D1D2C156950C321F5FC989032",
              "sha3_384": "9c5ea1ef7e6f4c01d1e7ef5d9daf49bad06362a82702184924fde946985e5804888a9c54b9db4fb929ef9443ca2c468e",
              "data": null
            },
            {
              "name": "7b02fa6c5eb3760eb2f42c845387fdd8461ffdc3b1fbaf9d7fd61e50c544831d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7b02fa6c5eb3760eb2f42c845387fdd8461ffdc3b1fbaf9d7fd61e50c544831d",
              "guest_paths": [
                "sidebarButtonPressed.png"
              ],
              "size": 578,
              "crc32": "F07C85F5",
              "md5": "2e6f1f8b4bf8f0f52ce36185382e9b7d",
              "sha1": "0663b4d9db970e3b154c3433ad9c7ea98798a0d5",
              "sha256": "7b02fa6c5eb3760eb2f42c845387fdd8461ffdc3b1fbaf9d7fd61e50c544831d",
              "sha512": "1368f7eb6691ce16ece647ae03f2be7db7f428fce227d4646d1032ab8dcf497b2e38e606be7ffe7f3d3269a173a5001331ae5173a3546c7881358643d00489ea",
              "rh_hash": null,
              "ssdeep": "12:6v/78G/Ue0A8BiuZXbYe4w9o/qbWKcgBpp6Jrr:RriWbVcgByVr",
              "type": "PNG image data, 160 x 24, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13CF0E1E7E80C3CDDEA5E419549B34D38B8A69931E6102D28DA0AD06F0C86780D27E64A",
              "sha3_384": "fcedb593daca2badc848e88a1b4726be913813a6a704a4c837a147904eb6cd37da3e739c6367cc2a3e4ccec5e3ee098d",
              "data": null
            },
            {
              "name": "e14b84066a7c9639f033addbb418fa6e5654fb21d3592e864d5dffd2b674855f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e14b84066a7c9639f033addbb418fa6e5654fb21d3592e864d5dffd2b674855f",
              "guest_paths": [
                "sidebarLinkBackground.png"
              ],
              "size": 455,
              "crc32": "3AA523A7",
              "md5": "e867b8eee0b58ea3039ea68ec217cfbf",
              "sha1": "f72d7f1a41b216f9efd8953a4cf37e4558756f47",
              "sha256": "e14b84066a7c9639f033addbb418fa6e5654fb21d3592e864d5dffd2b674855f",
              "sha512": "2d054ba2a7629eb3c82f94c93b59c5124756103cdb000f8a9e72b4a1f3afb86eddae9a095052000f9340eee74e0313797305df44be9cb0e03c2519a0b22cabe0",
              "rh_hash": null,
              "ssdeep": "12:6v/7DE/Ujp6NlEOJtwCa5k0gn2XphuBEBM+cNvvtiU6ZgxUqc:iZjp6NllJt5a5tjXphumBM+cGZ5qc",
              "type": "PNG image data, 161 x 21, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A2F0B3F3E110ACC084865F3DD2DB8E4039305E00023EAA4A830EE80C2E832C48CCBEC3",
              "sha3_384": "45bbc307dce23ffa50810400071152e81946863924ce03f7f92d5b24b3f7ccd36cece135910bfbb2571c78aa485ea764",
              "data": null
            },
            {
              "name": "36950a72af006100609abe5ac351654ed1d450e35c262ba66d23dc62f46fb357",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/36950a72af006100609abe5ac351654ed1d450e35c262ba66d23dc62f46fb357",
              "guest_paths": [
                "site.png"
              ],
              "size": 2609,
              "crc32": "B940A302",
              "md5": "419f1de35abe5910eeb971fbde248270",
              "sha1": "c75090def38505169fea51a6933a25c2b566c876",
              "sha256": "36950a72af006100609abe5ac351654ed1d450e35c262ba66d23dc62f46fb357",
              "sha512": "1e61f20d13461a94db0aa60fdf612d1cbaddd68a4e50d46c0afb26c22dd262a93310fbeb62e5d7152145fb3a1e4e0bd0f8742149516f7b3623d08727c069efc5",
              "rh_hash": null,
              "ssdeep": "48:GwZe2gncaUhQC1/jGTSaRLKBqe5ts5NZEHWRq9Zfz/txGQZT96RL:zYXcfmjeaKqe5yNil9d/GQZT9uL",
              "type": "PNG image data, 41 x 46, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T111514CF92355BCA04397A19258C55764A202CBEB4CE85109EC529F0A79FA404986133F",
              "sha3_384": "239e18c4f337a77a0c7b56a0b731075f478010cb290623beffc6ff284c9431ee4acb57ba98e20e73f796a76a5a3ee9cc",
              "data": null
            },
            {
              "name": "8c1d6c3f4702bc5254316852d1fefb10eff655675bf2001d08cfba2847d0803f",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/8c1d6c3f4702bc5254316852d1fefb10eff655675bf2001d08cfba2847d0803f",
              "guest_paths": [
                "soft.png"
              ],
              "size": 1333,
              "crc32": "44B33E2A",
              "md5": "dcf6ae1ca3c350f141e3ed70dc0e304f",
              "sha1": "5c5e94bc461af248d0fb1fca6dcf6ba6ac383eec",
              "sha256": "8c1d6c3f4702bc5254316852d1fefb10eff655675bf2001d08cfba2847d0803f",
              "sha512": "5af8c2092b017260f07df49186fcffa6d81e7f107a3deabbf08d64b87879fe81c0b041c28f91d9b9f1e13a9b5097a3cf55d51c74d659f418a27b950b57faf3f7",
              "rh_hash": null,
              "ssdeep": "24:Svyhxm6D/Grafp9Siq9nK5qyC/bHFZoUK/dYVsRh3wDT:8yHDOafpSKHUH89Qs734",
              "type": "PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T17A21CBC6554DF45CDF90DAB51CE8CD35FACD05488B78EC51F040E2580AF05C91C6EC56",
              "sha3_384": "77ae5ee8d5be716ac91c8fdb94a369a0fda6b7f6ddd270395728af4689316d353df41235ae59c53116f980e709c715a2",
              "data": null
            },
            {
              "name": "a7c3c2f6d28e5cbaf3ed33ed2265129ab369231e191776299f4c46bc4f2f3e23",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a7c3c2f6d28e5cbaf3ed33ed2265129ab369231e191776299f4c46bc4f2f3e23",
              "guest_paths": [
                "about.png"
              ],
              "size": 14586,
              "crc32": "1A29403B",
              "md5": "2f66c226ae617dfeee67f0bfd4aa4c13",
              "sha1": "c7e7dcf82bfb63d67227f3a5cd3d3f6a3998f541",
              "sha256": "a7c3c2f6d28e5cbaf3ed33ed2265129ab369231e191776299f4c46bc4f2f3e23",
              "sha512": "bae04aa783a52ec983199ede0aaad933bf3172b85787d69a6d7383c3894c57815596813e02601fa9a1ea37e3b3c982bcfec9742fdb8b6a27f7f7cba2f347b614",
              "rh_hash": null,
              "ssdeep": "384:gYci/GIVitDN/E9NLnt4L6UyAeWV+eQa0:PciTcEJIz7V+eQv",
              "type": "PNG image data, 460 x 306, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19E62AE88F71928D99AE63371523D04CE1CB0FC740D2157CBE22E284F611DA447A36EC8",
              "sha3_384": "516488f7e416b0710f11e99b10fbb9ab82382dcbb68326fb8a6b683ce3d30450ee33ac2faf4043738db3c0dc4d3f4641",
              "data": null
            },
            {
              "name": "51cb045da0084be29b137f2b3bb364db9ee92f94b777b482ab7d77d221045463",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/51cb045da0084be29b137f2b3bb364db9ee92f94b777b482ab7d77d221045463",
              "guest_paths": [
                "ConnLogo.png"
              ],
              "size": 15298,
              "crc32": "7EB11561",
              "md5": "2fc8e1edaaede92c1196fb56cc6ce1de",
              "sha1": "dc6cf22a54f68b6f601d19d760ac5f93ae1f7267",
              "sha256": "51cb045da0084be29b137f2b3bb364db9ee92f94b777b482ab7d77d221045463",
              "sha512": "e3061201ff25217b4f9ccdf38defdaf43ac020fc5753bb92360aa128d352e2512ab5ba9057ef7ee8e91be3f7dd0f70d44470f0a72faf91d09a4e318d6fbcb563",
              "rh_hash": null,
              "ssdeep": "384:pPnOWZHFVFZ6qDqVc+LQ4uHm+BswAHBiOeemfH29s3RIJpk3D:tnOWZlVFxccB+wAh0emP2c+pq",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T10C62D071F7E8759D5C1532754582FFB89668964AD9D48AA000930203AF6E02E3FBDE3E",
              "sha3_384": "079a9e7a4a050c0a1cb024e9548741b14ba10a0f1fe041ab82d1c4522b9ccd0c65c642d0966e951fb652549091ff0069",
              "data": null
            },
            {
              "name": "16918b6fbed5f6c862254e7a8ca8b1d2dab59dd2903fa2518d8c365d0f03446a",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/16918b6fbed5f6c862254e7a8ca8b1d2dab59dd2903fa2518d8c365d0f03446a",
              "guest_paths": [
                "CP_Left.png"
              ],
              "size": 7758,
              "crc32": "1FF90B38",
              "md5": "37646481dd868f13920ef07478c7e789",
              "sha1": "83fe5552dd29b7b1853e533aff9fec92450d188c",
              "sha256": "16918b6fbed5f6c862254e7a8ca8b1d2dab59dd2903fa2518d8c365d0f03446a",
              "sha512": "8dff745b62b7c33e0c9c57e0110302550c6bc0542b8e778360eef01ede2d0908aa4f0c32b5eb13cdf44942918f17c7ef1a304cc4ecb0d852a5d976d2a1a9ab4d",
              "rh_hash": null,
              "ssdeep": "192:JTaAW5xXSxR5rLTWb8Fcei0eb2OI4/5g7fwMYRjUGPVeQOgQ:taACm5rHWb8Fjve7/5g7fwMYRRP0p",
              "type": "PNG image data, 255 x 42, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E6F1BF41B32AB18497D8027874600ED2E2918B1B59DFB66DCE384B0746EF86F89DCFD5",
              "sha3_384": "c794b74e259b4602e1392475759ef6bdabb6bf6163cbb1c6770a7c62ad0a825450aa868e045f54eb45c1f86227585cbc",
              "data": null
            },
            {
              "name": "546e6dcb084a28945f36749c8bd7ff7741e9bbf02e582be85e155768b84ab414",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/546e6dcb084a28945f36749c8bd7ff7741e9bbf02e582be85e155768b84ab414",
              "guest_paths": [
                "endpointBanner.png"
              ],
              "size": 15238,
              "crc32": "186258B0",
              "md5": "28624b590dab5ed23bc13816a795ea44",
              "sha1": "91bb22605e1cb13347a2df6ae3b2a1e5169f8156",
              "sha256": "546e6dcb084a28945f36749c8bd7ff7741e9bbf02e582be85e155768b84ab414",
              "sha512": "5e068d487864da906d452de2de60be2f7041eed4906e945a8537da26759a4b566aadfbb51ab32384f041a67bebb321b106b90e9e12d06695ec39d0da4c471f70",
              "rh_hash": null,
              "ssdeep": "384:QpQ9XpJ4uu51omg1QFPCnpf1WnzPuu2UjjARxy5MFwH:QpA251Rg1Q5CZ1Kz1jARkbH",
              "type": "PNG image data, 538 x 56, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18E62B011372121F4DFD96977F1D896D8F22919C18B91BD00500EACB8BC27ABE638B0F2",
              "sha3_384": "2ce42f609b6fdaa35a35ab32a159e2e25e6ca40367a579b54c837c3982c12dc228e569e51ddd95196389cb39772104d6",
              "data": null
            },
            {
              "name": "7d394e799fb1a19ba236605bc3620bcfb5a8e0497b17d89f3109a317afcb2105",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7d394e799fb1a19ba236605bc3620bcfb5a8e0497b17d89f3109a317afcb2105",
              "guest_paths": [
                "endpointBannerBig.png"
              ],
              "size": 16679,
              "crc32": "96A69556",
              "md5": "19673b3f766c7b4592b6203140226397",
              "sha1": "62d5dd9295b36cca0be8b3f418f15a3c2e1f83fe",
              "sha256": "7d394e799fb1a19ba236605bc3620bcfb5a8e0497b17d89f3109a317afcb2105",
              "sha512": "412cb9f9f5f4557b93a95ee00d876d3730a6847937d8c7df745c31d4a0a9dbb6c0d89c46aaffc4d864b713cf9eb97bf8e5349fe4de78d1f7ae2b53b02d634275",
              "rh_hash": null,
              "ssdeep": "384:Tnuf+z1BhDwF/pGwnUiBv/Z3MSVhVxx/ZAPjTnVbjqi6iSLQB7Kz:KW1BBwFUilzhLxhAPjT96NL+O",
              "type": "PNG image data, 702 x 61, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1BA72E19CF712C4A13A16A36733F5602A3CD694505D3260663603B0A1BCFE7589DD0BB6",
              "sha3_384": "c5f9a1a637702fdb7bf1f153f9136e37dc72b9d5551eed1abc0a371ad0750f9c12d8aea0167ab9322104d95c92d65bfd",
              "data": null
            },
            {
              "name": "11b97b72d6155ef453a9d10d7851a289f51e35956a68ea636d2acbad64bcd77e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/11b97b72d6155ef453a9d10d7851a289f51e35956a68ea636d2acbad64bcd77e",
              "guest_paths": [
                "VPNClient.chm"
              ],
              "size": 48603,
              "crc32": "A3487330",
              "md5": "35ed9783add8f8de88112982c2555b05",
              "sha1": "a761eacd5e9a4624fd8ef654c36c0cdaec120155",
              "sha256": "11b97b72d6155ef453a9d10d7851a289f51e35956a68ea636d2acbad64bcd77e",
              "sha512": "64c126b78755ffdeee685892e0ef11f379dd8672831f5f3c224b76c28c4080870466e1349880c1ef1f12c9cc17db1f0f44518faed7d3a5cc1d4e9f0dc1a44a46",
              "rh_hash": null,
              "ssdeep": "768:rzXpB2jSsQU2QTtzZy1Vg3EqmFCBhDwpzs442wGixUY61yVvDH:rzXS29KT/beCz4s/2wGL6r",
              "type": "MS Windows HtmlHelp Data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F423F1177B092A94C3467AB11EC8970F62D7BF39D597929900644D211BB0FADB3978F0",
              "sha3_384": "f21e746eb62569cc22a279adae06c3cf76813aac6fdad91629febf4382e1dc380acbd82623dcc23315d0b2059071288b",
              "data": null
            },
            {
              "name": "d5956ab2360779db81b1d50928cff98529b284d4de1a65e19e1eee97cb710f0e",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d5956ab2360779db81b1d50928cff98529b284d4de1a65e19e1eee97cb710f0e",
              "guest_paths": [
                "State-Error.png"
              ],
              "size": 439,
              "crc32": "D2DDDA3C",
              "md5": "26f0128a76c69a938fa76cb61995d2a3",
              "sha1": "4590dd862d7bc2bfa8c4e359942d4f33e42b8d04",
              "sha256": "d5956ab2360779db81b1d50928cff98529b284d4de1a65e19e1eee97cb710f0e",
              "sha512": "719609a3ba3be1d615539707bd6d3127e18ff369b0a30a4fc79bbc446ca79995180e112d1082ae9ec07f75bf94aaede0b6e85660afd428b2d7166252f1325c5e",
              "rh_hash": null,
              "ssdeep": "12:6v/7V3M/UDHNDY/YsNhnS+F0kSoVZvPCOC8gpvm5ciIdeDHvP/7:S3RTyHH0ALXPCPO5cigeDHvn7",
              "type": "PNG image data, 16 x 14, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F9F023E17D5CA871FC0B6B6B00664195FEB1E01623FBD8C73820D4274E34741C2C1212",
              "sha3_384": "27ead24785a24da78a440e65a04f2342b432e9a17f272e17029772a0cd5988109a1f42892c799d127fd46c464b515574",
              "data": null
            },
            {
              "name": "e2571c4119d33d4f682e4ae32608c7104cac06175b2d84ae74c3daf509466337",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e2571c4119d33d4f682e4ae32608c7104cac06175b2d84ae74c3daf509466337",
              "guest_paths": [
                "State-InProgress.png"
              ],
              "size": 378,
              "crc32": "1BDE1CE6",
              "md5": "679ced9a0defb7fddc232005776f2615",
              "sha1": "6dc10665173837970626e3ee9aae1ed61a489246",
              "sha256": "e2571c4119d33d4f682e4ae32608c7104cac06175b2d84ae74c3daf509466337",
              "sha512": "38fe117b188a69c9699b432ef5d571e99689d236b65d1b7c91b47232366f45b6bfc691555dc432d5d9f0ac1a21feaa53916dde5ae9994a31aafaa6c4ccf0a64c",
              "rh_hash": null,
              "ssdeep": "6:6v/lhPq83MR/UyKuhVqfRzlijTp6eROYWJUwLEykAF8llaSDieOTw3Vp:6v/7V3M/UqhVqAjl6xOxpAFyOTS7",
              "type": "PNG image data, 16 x 14, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15DE0F1E768089D5E8E41051B066BB8C13CF2100403291C09FA1B59026887704C805A40",
              "sha3_384": "c1d78e5b01c5ee2063bc3c88117e0bcbc6170b142dae8a26ab352e8b3276d37007d497a00796a4a0b65615e108a65ff8",
              "data": null
            },
            {
              "name": "606b605f44ff85f48284ddf8ec47f803bf98925a6154fb9d9768f09ce777c543",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/606b605f44ff85f48284ddf8ec47f803bf98925a6154fb9d9768f09ce777c543",
              "guest_paths": [
                "State-NotRunning.png"
              ],
              "size": 410,
              "crc32": "A5FA1FF9",
              "md5": "ef60b8e384e82abccfb0bbd951e5afb5",
              "sha1": "e3bc3a06ce88b51ce58be746a9b3dba700e35478",
              "sha256": "606b605f44ff85f48284ddf8ec47f803bf98925a6154fb9d9768f09ce777c543",
              "sha512": "44501ac28633bcc0ace0ece9390f180ad6a70c0e4f578edcb2e0c7d4491dc0677b8ea8cfba955fb084edb50ac759231a94bcda1e2fb194ea15914942f22c9177",
              "rh_hash": null,
              "ssdeep": "6:6v/lhPq83MR/UyKyk4NwHUJhmk+sUCjAC9HYtrMHQm7DzL1wtbr1Ey9g8rlE4uPE:6v/7V3M/UGk4NfhmkBPHSM73yCmufE",
              "type": "PNG image data, 16 x 14, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T169E0ABD37D4DA850850204DF18962594BC7569F60688295CFDD98D1C0465200C541442",
              "sha3_384": "f0406988fe261c375e9d8bda05891559c53fd76fade923af68bdb5460703f93d706dfddd38c2e464f009e16f75f675cf",
              "data": null
            },
            {
              "name": "73ab3e0c7bc13a7f7c7a59f844850176dfab149d1841e81f5f25126f2971f005",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/73ab3e0c7bc13a7f7c7a59f844850176dfab149d1841e81f5f25126f2971f005",
              "guest_paths": [
                "State-OK.png"
              ],
              "size": 424,
              "crc32": "084E56F4",
              "md5": "7adad4bb23e27b7d10d15ff93167ee32",
              "sha1": "7a8cf0df11e0b1de85aa9de8b526f841ce49be2d",
              "sha256": "73ab3e0c7bc13a7f7c7a59f844850176dfab149d1841e81f5f25126f2971f005",
              "sha512": "07bf36b4db7bbbbe1944e73d72fb9501241d8a270c15fdaf5276818297a62e4474529482262f57ee047c1a08829cb54c39667fbd5cc8781e0e4b9e488dc28978",
              "rh_hash": null,
              "ssdeep": "12:6v/7V3M/U53qAjBSA4uJg5QMovXHsPBj2WO8u05fL1:S3R53bjBSAFY2spSsu0d1",
              "type": "PNG image data, 16 x 14, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E0E0ABF31804AD4E47E5968B8AA2BC21BEAB098E12AF0C1EF52C521945082544087A02",
              "sha3_384": "c90f3d7870f98badffb9750b5e1d07fac3a877e0eff4595536791224cc577dd3490366708a7700cbf037ef0913bb2751",
              "data": null
            },
            {
              "name": "9fc3755fc72322b1ccccc25da06c6a6bbde5c37eaab0efb441590915fdda6db8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9fc3755fc72322b1ccccc25da06c6a6bbde5c37eaab0efb441590915fdda6db8",
              "guest_paths": [
                "State-Warning.png"
              ],
              "size": 502,
              "crc32": "8462BC3C",
              "md5": "73ab78dc320eebd5c683c309eabbb961",
              "sha1": "0307036818b4dec7a35193e8a709e6ea5c1a7d86",
              "sha256": "9fc3755fc72322b1ccccc25da06c6a6bbde5c37eaab0efb441590915fdda6db8",
              "sha512": "6e2662acbdde77b08c10c7a79d03c15f5cfcddaa9c8a0043445ab95528c3b94b90590d573a53392b5107a61b6b7a6676802b755678952a9ea63fefaf3393205f",
              "rh_hash": null,
              "ssdeep": "12:6v/7V3M/Uaf1G/pcsc6X7Y0oAYQxK+4h+PuBe3/yr79:S3Rm1ouscyTHLp4hzE6rx",
              "type": "PNG image data, 16 x 14, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T180F00E6BC62C3CADA11C422D49974B85F4F0D18838996989BD1ABDA1678A2A883E0B45",
              "sha3_384": "24bdb434861336d0c35299381a1aedb38f94d8f9a43acf2b6675f62829fad9facde81a2cfdc0c29a035068ee35d73ba1",
              "data": null
            },
            {
              "name": "d91eeb0fe7cceba2ec30ebfe7d57eaf480207a4c3c7860a8b852e91e34354b8b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/d91eeb0fe7cceba2ec30ebfe7d57eaf480207a4c3c7860a8b852e91e34354b8b",
              "guest_paths": [
                "statusBarGreen.png"
              ],
              "size": 620,
              "crc32": "7E37FBD0",
              "md5": "749a145c206908f90c6480ee1f853935",
              "sha1": "291106cac7ae47816933838748020b1ac7e10dc5",
              "sha256": "d91eeb0fe7cceba2ec30ebfe7d57eaf480207a4c3c7860a8b852e91e34354b8b",
              "sha512": "2bf85cf0daa11dfe279c28c742cfb29baa13f7762f241325a7242660e06de61f6eef0f92b9c43db55246d3184653e2d3f453d5bf34115365740543be2947fec6",
              "rh_hash": null,
              "ssdeep": "12:6v/7/Sb/UdP4bWnHMznCE8+hP2PaUkXuhtIaRHI8fieGHj:sdnHMzCE8uP2P+e7jRHI8fz2",
              "type": "PNG image data, 600 x 41, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16CF07895D2C3503AA13A013F4A620B837BE01CFA2114CC0A044B901FEA83F939CB6C8B",
              "sha3_384": "05ee0c7466108e3d8530cb273b535885b327386e5a2eff862f4145b664cf6a3881b6bf6cb0e0d32087a4bf21a75b24b7",
              "data": null
            },
            {
              "name": "8305c3df5d163d848375922eb7eeb54b856556cdaaeba2e7886979912abed899",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/8305c3df5d163d848375922eb7eeb54b856556cdaaeba2e7886979912abed899",
              "guest_paths": [
                "statusBarOrange.png"
              ],
              "size": 556,
              "crc32": "2D2AAA92",
              "md5": "e433afded3e4093ca30ac08abdfa8c9e",
              "sha1": "cbb7a75db912b2827e071dc983dbc67ecacfa3df",
              "sha256": "8305c3df5d163d848375922eb7eeb54b856556cdaaeba2e7886979912abed899",
              "sha512": "24b511e3d051437daafdb532e6aacb5ca4f37fcdbb8250762fa17d29922e73c934df5eb8ec980eeeecef7f5011ab9e73c4f7260b932581b96195b3bc5a688018",
              "rh_hash": null,
              "ssdeep": "12:6v/7/ytMJWApJd3mpbdMG7HAvdxIho4VxQ41w2SlAMIWiSpP7:fZwNMFoKQjSmpP7",
              "type": "PNG image data, 600 x 41, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T105F0FCE9C26AD075F95510555C5A065465D12D372180C448984EA63F3317FE1CE3DDC3",
              "sha3_384": "eeb73c775481bf48a24b72c240d590ed09d7ea29e82f3e103db7ca14469ebb8572c7e24097dbb61e004c9f7ded8870f5",
              "data": null
            },
            {
              "name": "01473f2a7ef43cd3e1282eb5d5c69bbe66d8a47676194c0d791e5d5ef1be5dda",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/01473f2a7ef43cd3e1282eb5d5c69bbe66d8a47676194c0d791e5d5ef1be5dda",
              "guest_paths": [
                "statusBarRed.png"
              ],
              "size": 557,
              "crc32": "200DA46B",
              "md5": "9164e0b847488637570d2067c88717ca",
              "sha1": "0199afa82914c66c9c4ed5322e766678e97d6972",
              "sha256": "01473f2a7ef43cd3e1282eb5d5c69bbe66d8a47676194c0d791e5d5ef1be5dda",
              "sha512": "5e6debe7cb65679a5f283edc02fbff93360df7947bb3cba17778cabb0ea1e73f2af008b7502b87b6e2a6f35fd0d216bbcad77f7d0a0c0edaf9886a633efa0374",
              "rh_hash": null,
              "ssdeep": "12:6v/7/yV43Uupqe7nMdeMq6Kl18Eox4QZnkzs7ksOSBkf+ykQT09S23Y/SxisRXc:z8J7nt6Kl1b84QZnkoOSem59S27FNc",
              "type": "PNG image data, 600 x 41, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T122F08BC2C606047A944A88B4AE859C8550665D3E521ECF80664AA8BD036BF54EEF7FB1",
              "sha3_384": "f82bbe664f18b40ce693b55af0b76a7197161c68bbea91de50d56683738c9d567b55fa6cdfebc9c982c0fce99895f6d2",
              "data": null
            },
            {
              "name": "6551f30c9d9ef1fd4ebbb45874caed38ee6a8c828ceafc4e0d29d92a5bfa1d92",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6551f30c9d9ef1fd4ebbb45874caed38ee6a8c828ceafc4e0d29d92a5bfa1d92",
              "guest_paths": [
                "trac.config"
              ],
              "size": 33,
              "crc32": "58EB620C",
              "md5": "32a723fe01e742e8f29b0544803700f2",
              "sha1": "ce922f12cb5b20d02956bbe5a920110df08447be",
              "sha256": "6551f30c9d9ef1fd4ebbb45874caed38ee6a8c828ceafc4e0d29d92a5bfa1d92",
              "sha512": "096218eae8ee932992b06751a2c48ecfc52dcbc25cb6cc3d2a08fa70589690aa7c6a5e3b23653d410958017eb8faf98b039260045fa46afb61526c8726469f3d",
              "rh_hash": null,
              "ssdeep": "3:zCkqqPBliCkqqPv:zPlih",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": null,
              "sha3_384": "6ee6e9e9b0bd8c8498ba286a28ae8b22b6b8e244405dd2c37ee411b1475176b5d166cc57e979ffe83b494e2a6acc365f",
              "data": "<CONFIGURATION>\n</CONFIGURATION>\n"
            },
            {
              "name": "9130af9ad3ea9614e85146e37ae7570b05e2117c9221d38d1326561050941742",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/9130af9ad3ea9614e85146e37ae7570b05e2117c9221d38d1326561050941742",
              "guest_paths": [
                "trac.ddf"
              ],
              "size": 1217,
              "crc32": "FE7D1E35",
              "md5": "ae81615c44b5891259a5049fada274cb",
              "sha1": "a28c997f67963d2ae4087271a8c837324f60d0ea",
              "sha256": "9130af9ad3ea9614e85146e37ae7570b05e2117c9221d38d1326561050941742",
              "sha512": "85131f9e3cadd32b198aaebbb7444d9cadce592ac8a497e58b22c6167a68c4f4e423764e925ce2339c09a25feca9ab3571f2a7c3ddb4d20ac9e4fd9866078b03",
              "rh_hash": null,
              "ssdeep": "24:4ZXmwFtTXcDp252UJDit5dD5do45ri5rQbDbZUD+gBReISzw4K/a6ynEb4A4N+N0:4Z2wNsDpQWdddb6wvIMIWK/3go+pr",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T116216B4E09ADE461716D8A7CD8B75ED471AC4ADEF890708ECED52233025195EF680705",
              "sha3_384": "92b93567e7c51e6cfdfaaffb675c379d6e9335fb53b378b569fe75ec8053b95ab6c64940fa609f829b5f14449465330a",
              "data": ".Set CabinetNameTemplate=%fname%\n.Set DiskDirectoryTemplate=.\n.Set MaxDiskSize=512000000\n.Set Compress=on \n.Set Cabinet=ON\n.Set InfFileName=nul\n.Set RptFileName=nul\n\n\"helpdesk.log\"\n\"helpdesk.log.0\"\n\"collect.log\"\n\"TrGUI.log\"\n\"TrGUI.log.0\"\n\"TrGUI.log.1\"\n\"TrGUI.log.2\"\n\"TrGUI.log.3\"\n\"ProxyServer_access.log\"\n\"ProxyServer_access.log.0\"\n\"ProxyServer_agent.log\"\n\"ProxyServer_agent.log.0\"\n\"ProxyServer_error.log\"\n\"ProxyServer_error.log.0\"\n\"ProxyServer_referer.log\"\n\"ProxyServer_referer.log.0\"\n\"TrSAA.log\"\n\"TrSAA.log.0\"\n\"trac.config\"\n\"trac.defaults\"\n\"ver.ini\"\n\"TracSrvWrapper.dmp\"\n\"TrGUI.dmp\"\nTrGUI_appdata.dmp\n\"TrGUI.CRASH.elg\"\n\"TrGUI_appdata.CRASH.elg\"\n\"TracSrvWrapper.CRASH.elg\"\n\"trac_capi.log\"\n\"trac_install.log\"\n\"trac_msi.log\"\n\"scapi_vsmon.log\" \n\"scapi_vsmon.log.0\" \n\"scapi_iclient.log\" \n\"scapi_iclient.log.0\" \n\"tvDebug.log\"\n\"fwpktlog.txt\"\n\"dlog1.txt\"\n\"command_line.log\"\n\"command_line.log.0\"\n\"sys_command_line.log\"\n\"sys_command_line.log.0\"\n\"desktop_policy.ini\"\n\"user_group.ini\"\n\"ConnectedPolicy.xml\"\n\"vsconfig.xml\"\n\"DisconnectedPolicy.xml\"\n\"TrGUI_SDL.log\"\n\"cpgina.log\"\n\"cpplap.log\"\n\"local.scv\"\n\"Installer.log\"\n\"WscScvDebug.txt\"\n\"trac_registry.log\"\n\"DesktopApplicationApiWrapper.log\"\n\"DesktopApplicationApiWrapper.log.0\"\n"
            },
            {
              "name": "f95e849a8ef21ab5825d9cee0ee215d3024c569cdc105287dcafd4e2de8a3a66",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f95e849a8ef21ab5825d9cee0ee215d3024c569cdc105287dcafd4e2de8a3a66",
              "guest_paths": [
                "trac.defaults"
              ],
              "size": 16248,
              "crc32": "64A9B0A8",
              "md5": "2d2b8b84e0b08cb58c561830976465a7",
              "sha1": "d7390a1bc50463142e70566cc2265985630b8884",
              "sha256": "f95e849a8ef21ab5825d9cee0ee215d3024c569cdc105287dcafd4e2de8a3a66",
              "sha512": "df41e067effcab33e47974ed8263e86cbeebc1949412d84dda8894c4e9fc4a1f9ce0acac590cd2ac807c1c4accf1a7bcb592b4d074e4776affa943b35155b995",
              "rh_hash": null,
              "ssdeep": "96:X7ninlmcCLcRe1QZ43XIlyhTFUCnvK0TRs40oR8GHrwmJ5pH89bUfeYqHuiCKqvM:rinrC4Rn0TR4Ke+WTlqnoG8bh3Tw1dM",
              "type": "ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F472153BC5F8CB399180E12805E4955B5B1A377FA14608E3BBF08AE8C38B11C9BDB5C5",
              "sha3_384": "5474bc5f2f8f1e2d97863f5f8d0ad0ce99dc1f5559d433780fab9f3e85c3a980b864103db2a333d8a14824edd1d4d821",
              "data": "OBSCURE_FILE\t\t\t\t\t\t\t\t\t\tINT\t\t\t1\t\t\t\tGLOBAL\t0\nis_abra\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGLOBAL\t0\npredefined_sites_only\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGLOBAL\t0\nhello_protocol_ver\t\t\t\t\t\t\t\t\tINT\t\t\t100\t\t\t\tGW_USER\t0\nclient_enabled\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\nclient_version\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nuse_ikev2\t\t\t\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\ntrac_upgrade_url\t\t\t\t\t\t\t\t\tSTRING\t\t\"/SNX/CSHELL/\"\tGW_USER\t0\nspeed_upgrade_url\t\t\t\t\t\t\t\t\tSTRING\t\t\"/CSHELL/\"\t\tGW_USER\t0\nneo_upgrade_mode\t\t\t\t\t\t\t\t\tSTRING\t\t\"no_upgrade\"\tGW_USER\t0\nspeed_upgrade_mode\t\t\t\t\t\t\t\t\tSTRING\t\t\"force_upgrade\"\tGW_USER\t0\nconn_type\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"IPSec\"\t\t\tGW_USER\t0\ntransport\t\t\t\t\t\t\t\t\t\t\tSTRING\t\tAuto-Detect\t\tGW_USER\t0\nvpnd_ipaddr\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\ntcpt_transport_port\t\t\t\t\t\t\t\t\tINT\t\t\t443\t\t\t\tGW_USER\t0\nnatt_transport_port\t\t\t\t\t\t\t\t\tINT\t\t\t4500\t\t\tGW_USER\t0\ncertificate_url\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"/clients/cert/\"\tGW_USER\t0\ncookie_name\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ninternal_ca_fingerprint\t\t\t\t\t\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\ninternal_ca_sha1_hash\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nrun_ics\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nics_base_url\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nics_ver\t\t\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nics_upgrade_url\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nics_images_ver\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nics_images_url\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nics_cab_version\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nics_cab_url\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nenable_firewall\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nfirewall_policy\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"desktop_policy\"\tGW_USER\t0\nclient_firewall_ver\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tUSER\t1\ngw_firewall_ver\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nfwpolicy_update_time\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nallow_disable_firewall\t\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nfw_log_upload_enable\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nnumber_of_tracker_log_files_limit\t\t\t\t\tINT\t\t\t8\t\t\t\tGW_USER\t0\ntracker_log_file_size_limit\t\t\t\t\t\t\tINT\t\t\t250000\t\t\tGW_USER\t0\nremove_log_files_after_sending\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nwrite_pkt_alert_log_in_chunks\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nenable_feedback\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nenable_trac_fwpktlog\t\t\t\t\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\nfwpktlog_cach_interval_milliseconds\t\t\t\t\tINT\t\t\t\"100\"\t\t\tGW_USER\t0\nperiodic_log_upload\t\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nperiodic_log_upload_interval\t\t\t\t\t\tINT\t\t\t20\t\t\t\tGW_USER\t0\nneo_route_all_traffic_through_gateway\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t1\nneo_remember_user_password\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nneo_remember_user_password_timeout\t\t\t\t\tINT\t\t\t1440\t\t\tGW_USER\t0\nneo_implicit_disconnect\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nneo_implicit_disconnect_timeout\t\t\t\t\t\tINT\t\t\t2\t\t\t\tGW_USER\t0\nneo_check_crl\t\t\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nneo_disconnect_when_idle\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nneo_disconnect_when_idle_timeout\t\t\t\t\tINT\t\t\t5\t\t\t\tGW_USER\t0\nneo_keep_alive_timeout\t\t\t\t\t\t\t\tINT\t\t\t20\t\t\t\tGW_USER\t0\nneo_always_connected\t\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t1\nneo_always_connected_retry\t\t\t\t\t\t\tINT\t\t\t1\t\t\t\tGW_USER\t0\nneo_always_connected_max_retry\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nneo_always_connected_delta_seconds\t\t\t\t\tINT\t\t\t10\t\t\t\tGW_USER\t0\nneo_user_re_auth_timeout\t\t\t\t\t\t\tINT\t\t\t480\t\t\t\tGW_USER\t0\npreliminary_reauthentication_enabled\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nlocation_awareness_enabled\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t1\nlocation_awareness_wlan_networks_are_outside\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nlocation_awareness_dns_suffixes_not_outside\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\ndisplay_firewall_disable_warning_message\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\ndisplay_allow_disable_firewall_menu\t\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\nlocation_awareness_dc_check\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nlocation_awareness_cache_locations\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nlocation_awareness_cache_internal_locations\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nlocation_awareness_wlan_network_names_not_outside\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\nsplit_dns_entry\t\t\t\t\t\t\t\t\t\tOBJECT\t\t\"\"\t\t\t\tGW_USER\t0\npolicy_version\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nsend_client_logs\t\t\t\t\t\t\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\nenable_capi\t\t\t\t\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nrange\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nmep\t\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nscv\t\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ndns\t\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ndesktop\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nuser_groups\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ntrac_client_1\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ncertificate_key_length\t\t\t\t\t\t\t\tINT\t\t\t2048\t\t\tGW_USER\t0\ncertificate_strong_protection\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\ncertificate_provider\t\t\t\t\t\t\t\tSTRING\t\t\"MicrosoftEnhancedRSAandAESCryptographicProvider\"\tGW_USER\t0\ncertificate_auto_renewal_threshold\t\t\t\t\tINT\t\t\t60\t\t\t\tGW_USER\t0\ncertificate_renewal_warning_only\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\ninternal_ca_site\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ninternal_ca_dn\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ntunnel_idleness_timeout\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\ntunnel_idleness_ignored_tcp_ports\t\t\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\ntunnel_idleness_ignored_udp_ports\t\t\t\t\tVEC_STR\t\t53&#137&#138&#\tGW_USER\t0\ntunnel_idleness_ignore_icmp\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nhotspot_detection_enabled\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t1\nhotspot_registration_enabled\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t1\ndisconnect_on_smartcard_removal\t\t\t\t\t\tSTRING\t\tfalse\t\t\tGW_USER\t0\nrun_isw\t\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nflush_dns_cache\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t1\nreadonly_binding_order_monitoring\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t1\ndo_proxy_replacement\t\t\t\t\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t1\nike_connect_timeout\t\t\t\t\t\t\t\t\tINT\t\t\t70000\t\t\tGW_USER\t0\nextended_ike_connect_timeout_for_idp\t\t\t\tINT\t\t\t115000\t\t\tGW_USER\t0\nautomatic_mep_topology\t\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nmep_mode\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"dns_based\"\t\tGW_USER\t0\nips_of_gws_in_mep\t\t\t\t\t\t\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\nauto_mep_mode\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"first_to_respond\"\tGW_USER\t0\nauto_ips_of_gws_in_mep\t\t\t\t\t\t\t\tVEC_STR\t\t\"\"\t\t\t\tGW_USER\t0\nsuspend_tunnel_while_locked\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nurl_to_show_upon_connect\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nrss_feed_url\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nrss_feed_check_interval\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nallow_clear_traffic_while_disconnected\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\nfw_enable_hotspot\t\t\t\t\t\t\t\t\tSTRING\t\t\"true\"\t\t\tGW_USER\t0\nfw_hotspot_ports\t\t\t\t\t\t\t\t\tVEC_STR\t\t80&#8080&#443&#\tGW_USER\t0\nfw_hotspot_connect_timeout\t\t\t\t\t\t\tINT\t\t\t600\t\t\t\tGW_USER\t0\nfw_hotspot_log\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\nom_extended_dhcp_params\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tGW_USER\t0\ngw_ipaddr\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\ngw_internal_ip\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\ngw_hostname\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nauthentication_method\t\t\t\t\t\t\t\tSTRING\t\tcertificate\t\tGW_USER\t1\ndefault_authentication_method\t\t\t\t\t\tSTRING\t\tclient_decide\tGW_USER\t1\ncertificate_path\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nusername\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nsecurID_type\t\t\t\t\t\t\t\t\t\tSTRING\t\tpin_pad\t\t\tUSER\t1\nsoftid_auth_info\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\ndisplay_name\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nactive_site\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tUSER\t1\nenforced_scv_hash\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tUSER\t1\nload_scv_policy\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"false\"\t\t\tUSER\t1\nclient_ics_ver\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nclient_ics_images_ver\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nclient_ics_cab_ver\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t0\nproxy_settings\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"DETECT_PROXY\"\tUSER\t1\nproxy_ipaddr\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tUSER\t1\nproxy_port\t\t\t\t\t\t\t\t\t\t\tINT\t\t\t8080\t\t\tUSER\t1\nproxy_username\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tUSER\t1\nproxy_password\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tUSER\t1\nuser_upgrade_mode\t\t\t\t\t\t\t\t\tSTRING\t\t\"ASK_USER\"\t\tGW_USER\t1\nlast_connect_time\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nlast_connect_time_interval\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t1\nauth_expiration_time\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tGW_USER\t1\nccc_fingerprint\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nserver_cn\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\ndebug_mode\t\t\t\t\t\t\t\t\t\t\tSTRING\t\tbasic\t\t\tUSER\t1\nsdl_enabled\t\t\t\t\t\t\t\t\t\t\tSTRING\t\tfalse\t\t\tUSER\t1\nimplicit_sdl_enabled\t\t\t\t\t\t\t\tSTRING\t\ttrue\t\t\tGW_USER\t0\nimplicit_sdl_state\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tUSER\t1\nlanguage_index\t\t\t\t\t\t\t\t\t\tINT\t\t\t0\t\t\t\tUSER\t1\nlangpack_filename\t\t\t\t\t\t\t\t\tSTRING\t\t\"LangPack1.xml\"\tUSER\t0\nlast_om_ip\t\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t0\nprevious_user\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"\"\t\t\t\tGW_USER\t1\nics_report_name\t\t\t\t\t\t\t\t\t\tSTRING\t\t\"ics_report.html\"\tGW_USER\t0\nics_timeout\t\t\t\t\t\t\t\t\t\t\tINT\t\t\t360000\t\t\tGW_USER\t0\nclient_policies\t\t\t\t\t\t\t\t\t\tVEC_STR\t\ttrac_client_1&#range&#mep&#desktop&#user_groups&#scv&#dns&#extended_ranges&#\tG <truncated>"
            },
            {
              "name": "69bc9fd3f5c46a717b3451906ab5ba529de1067b30bc72fd239560ad7beb1043",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/69bc9fd3f5c46a717b3451906ab5ba529de1067b30bc72fd239560ad7beb1043",
              "guest_paths": [
                "trac.exe"
              ],
              "size": 2880960,
              "crc32": "5FDF7647",
              "md5": "8ec51628fe34c9aa160dce64dc0df79e",
              "sha1": "0029bc53cbd025c216aedadecf446aa6a93397d0",
              "sha256": "69bc9fd3f5c46a717b3451906ab5ba529de1067b30bc72fd239560ad7beb1043",
              "sha512": "198545e6955b18c78f54d2f906ef664c36e5d89cce356af32acfeaed38c0c39187555e7df89a684ab8a83868aff6658f509fce02ad8f856feb7b7805372f6422",
              "rh_hash": null,
              "ssdeep": "49152:TJc/XUCpo6tW+LWbN/dpUZFFdSWP4/a3F+teYWYcZmhe+nZ:TJcQsQN1mSj/aVuD",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [
                {
                  "name": "embedded_macho",
                  "meta": {
                    "author": "nex",
                    "description": "Contains an embedded Mach-O file"
                  },
                  "strings": [
                    "{ FE ED FA CE }"
                  ],
                  "addresses": {
                    "magic3": 2724524
                  }
                }
              ],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T10FD5A053FB8645B2EAC701B5115A377F9C3DA4345720B5D3EBE208A888112D26B3F7DA",
              "sha3_384": "b862209e7d856f270abd5d3e308c81c4dfbdabdf81c5e7c1438392f1977ecde8cf8285415bc5ab94d24c634c74bf5c18",
              "data": null
            },
            {
              "name": "f9e9f9e871454a0e1f838f1fad1450cff346e2747d23babee2bbff1c8f471803",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/f9e9f9e871454a0e1f838f1fad1450cff346e2747d23babee2bbff1c8f471803",
              "guest_paths": [
                "TracCAPI.exe"
              ],
              "size": 2140608,
              "crc32": "5A5B6587",
              "md5": "1621d318b78b99a1f7f07c593b9548f5",
              "sha1": "71d8d407cdc3e06d7e65f1edb105c475c8c69f82",
              "sha256": "f9e9f9e871454a0e1f838f1fad1450cff346e2747d23babee2bbff1c8f471803",
              "sha512": "bb27965968d34b10d7e4eee0868c24be1b9e94fa696aed5b8b72a739736431deee4df6ff8fb4740b2c6c7a3b77cdf48af6ce68b2135ec9b2b559369883164ff0",
              "rh_hash": null,
              "ssdeep": "49152:RKrsbf3ISt9JUTng9IPEXtPOdcX9MYRkh8uxS:RKrQIeJUJPSs6tMC",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13FA5AF31FBC24572EAC70A7551173B7FAD3E91344320B8E3DA9148A998266C1273EBDD",
              "sha3_384": "45e1fc27f61c3249cabf447de2fa1dc7bab29e57ea915f202944abfb1607819d814f6b8f5f22782233dfb422f3977eb1",
              "data": null
            },
            {
              "name": "8e5c2a951251c5468f246ef507c56a560499bd0055cf926c8e5259067b308add",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/8e5c2a951251c5468f246ef507c56a560499bd0055cf926c8e5259067b308add",
              "guest_paths": [
                "TracConnected.wav"
              ],
              "size": 44792,
              "crc32": "39D68063",
              "md5": "3d86f1a941cffc4fd7b5700a66e6483c",
              "sha1": "56cb1b954af0eb91efc95778609bc07c13686084",
              "sha256": "8e5c2a951251c5468f246ef507c56a560499bd0055cf926c8e5259067b308add",
              "sha512": "6fa9bec0c38ced1b875ab03603328333b9ac454ac7539e0e43048fa07114f30bc3ec52efb66453c444ed3bd2dbb99fa53c9c4230859ed54b30821c63810f4851",
              "rh_hash": null,
              "ssdeep": "768:QSoQ2Z63ABNmY+d2uNSvegqVHUdX9CBaJVu4QZSwZoHqFSadRF0:QSUdo+te7YX9CU6joKjv2",
              "type": "RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16B13BE33F69287A4D8E603338E8544022BB9B58DFD6612AF1475DF49F2D3347AA5B324",
              "sha3_384": "324b48ed2f8fca644e988dd8b53569d1f25546ae3f378fd05c16bc5e732f6bc2cd282a9ede3e40d0de264f1673e2fbbc",
              "data": null
            },
            {
              "name": "2274c20552aafadd2d83a61d571a92cef7fa385cb10e9e633bffc01fb982ffdc",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/2274c20552aafadd2d83a61d571a92cef7fa385cb10e9e633bffc01fb982ffdc",
              "guest_paths": [
                "tracCPInfo.cmd"
              ],
              "size": 1584,
              "crc32": "438D3273",
              "md5": "d26104e8e27a39e8c9d85328cb9398e7",
              "sha1": "106b4ab262262c7468686cb08d04d3ae4aea54a5",
              "sha256": "2274c20552aafadd2d83a61d571a92cef7fa385cb10e9e633bffc01fb982ffdc",
              "sha512": "7d3cb552e8135e5d2cbbedb6348f1deac3125b87e9ecfa71991d72b4e456e2fb8ce1fd01fa9f2d97f1c2bf468dbabca0c0ef8952b6257da64b47b6b20d47055d",
              "rh_hash": null,
              "ssdeep": "48:3gQAbJiX0qWCcjNXdpF4FwMR/0MnOPZhH6FY9:uJhpdPI+ZdZ",
              "type": "DOS batch file, ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1653136C796EC34321A104155AFA7E0C0302BA28D62527264117EDB1F729ABDD8C41F6B",
              "sha3_384": "2749f372c201590cfdc5eb3ef71698c343acebc9698be49a98fb739440433f4a0bde5aea87f2e821fa47a455a9d9149b",
              "data": "@ECHO OFF\nREM =============================================\nREM DO NOT EDIT THIS FILE.\nREM =============================================\n\nREM =============================================\nREM  Secure Access CPInfo\nREM  This file is used to collect debug information\nREM  from Check Point End Point Security Secure Access\nREM =============================================\nREM  Copyright Check Point Software Technologies Ltd (c) 2008\nREM =============================================\n\nREM Shared Variables are:\nREM OUTDIR\t- Output Folder, individual CPInfo should append product specific folder name\nREM STATUSFILE \t- Text file to write cpinfo status to\nREM 7ZIP        - Path to the command line 7zip executable (includes the exe filename)\nSETLOCAL\nSET TRAC_OUTDIR=%OUTDIR%\\TRAC\n\nECHO STATUSFILE: %STATUSFILE%\nREM Create Outdir\nIF NOT EXIST \"%TRAC_OUTDIR%\" MKDIR \"%TRAC_OUTDIR%\"\nif NOT \"%ERRORLEVEL%\"==\"0\" (\n\t@ECHO An Error %ERRORLEVEL% occurred whilst creating %TRAC_OUTDIR% folder >> \"%STATUSFILE%\"\n\tGOTO Error  \n\t)\n\nrem Get the installation dir first\nFOR /F \"tokens=1,2,* delims=\t \" %%A  IN ('reg query HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\5.0\\') DO IF \"%%A\"==\"PRODDIR\" SET TRAC_DIR=%%C\n\nrem run sysinfo\nCALL \"%TRAC_DIR%\\collect.bat\" trac.cab \"%TEMP%\\TRAC\"\nif NOT \"%ERRORLEVEL%\"==\"0\" (\n\tECHO An Error %ERRORLEVEL% occurred while running collect.bat >> \"%STATUSFILE%\"\n\tGOTO Error  \n\t)\ncopy /Y \"%TEMP%\\TRAC\\trac.cab\" \"%TRAC_OUTDIR%\\trac.cab\"\n\n@Echo TRAC CPInfo Complete >> \"%STATUSFILE%\"\n\n:Error\n@ECHO An error occurred during TRAC CPInfo processing. >> %STATUSFILE%\n\nENDLOCAL"
            },
            {
              "name": "492c092ff9ea51d2d90fd4aa643e178104304f7f830cddce090715301d71e8d0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/492c092ff9ea51d2d90fd4aa643e178104304f7f830cddce090715301d71e8d0",
              "guest_paths": [
                "TracFailed.wav"
              ],
              "size": 44792,
              "crc32": "526AAA65",
              "md5": "026f863c5505b1d0f95a0ea41ac1420c",
              "sha1": "5f9b6e4247f4ae805066772bac8a22ece06796f3",
              "sha256": "492c092ff9ea51d2d90fd4aa643e178104304f7f830cddce090715301d71e8d0",
              "sha512": "bb790dfc785f0dc838cab93923d3f5babe6fdb94f138032bd15265f95d0d193ecab8489bf5e7513518ebee807956b1ed84ca0104623e69fe76a1082d06f5be8b",
              "rh_hash": null,
              "ssdeep": "768:IpBkBIRVl9o4pjFVzob3vvTrT2hHe71XMUk3vGts0ehB:jBIvljojXTeFGbqua0e/",
              "type": "RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T14613D022F9531F80FAEC0776CD8990C1D442B4A1CD65527636FCD89A6687B83FC2D24D",
              "sha3_384": "e3b57e4629b483e276af940d8ef6cdae05e7056336005066c339061cfe6734844e4a7abfcca2f97080e9fca604670c80",
              "data": null
            },
            {
              "name": "600acb22cd6184f62f4a36d2ded6be2aed88bb7f37cf21c20bd3daa170d1bee9",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/600acb22cd6184f62f4a36d2ded6be2aed88bb7f37cf21c20bd3daa170d1bee9",
              "guest_paths": [
                "TracSiteUpdateSuccess.wav"
              ],
              "size": 99776,
              "crc32": "D4856062",
              "md5": "50605aca99468290ec5817377d2a93d0",
              "sha1": "a6abc9e06b8c48dd6d154abd57d16a5de4f2a974",
              "sha256": "600acb22cd6184f62f4a36d2ded6be2aed88bb7f37cf21c20bd3daa170d1bee9",
              "sha512": "30fc09f3125ba5f6ead0c4bfb49e13bc7b63fe547cb64f6f3daf8fd66ce244c5e3436aa87d37d35c680fa2459c98102890f5a41f13ce69ccbe017d07bec40dc5",
              "rh_hash": null,
              "ssdeep": "1536:xSUdo+te7YX9CU6joKjvzdo+te7YX9CU6joKdo+te7YX9CU6joE:Uto9CxUAMo9CxUbo9CxUE",
              "type": "RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, stereo 22050 Hz",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F2A3AF33F69287A8D8E643338D8544022B79B48CFE6216BF1465DF49E2D7347A79B324",
              "sha3_384": "ea73159757429cc757a3c050746ac9fc1ccb16f775d54b4a8f936f1105d6b41cd8d5299267e7648366d20a0f80745703",
              "data": null
            },
            {
              "name": "7cf5c0a1f2c68857d8470669800c1d6b09d64e4fc31f84a826b621a7031d484d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7cf5c0a1f2c68857d8470669800c1d6b09d64e4fc31f84a826b621a7031d484d",
              "guest_paths": [
                "TracSrvWrapper.exe"
              ],
              "size": 9830848,
              "crc32": "43718928",
              "md5": "aed8776a633339d78f3fdf5d596a4cc2",
              "sha1": "d6329123cbe481efa358cc04c66f1f4f0a4e77a6",
              "sha256": "7cf5c0a1f2c68857d8470669800c1d6b09d64e4fc31f84a826b621a7031d484d",
              "sha512": "19ae1473c09e211cf0aed722bd5a22c7aa2d5f4d11cddc6e21a95377cfa0a7c26f05e64e8757223f0611312f8d49598267b8b27ed8a4569580c0325847a95e42",
              "rh_hash": null,
              "ssdeep": "98304:TdvtQI8E2O9M7Sk/HOocTt7PAiSAO+xP5UuYxTaUDY+V:TbQILACTgADxBUu8D/",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [
                {
                  "name": "embedded_macho",
                  "meta": {
                    "author": "nex",
                    "description": "Contains an embedded Mach-O file"
                  },
                  "strings": [
                    "{ FE ED FA CE }"
                  ],
                  "addresses": {
                    "magic3": 9016120
                  }
                }
              ],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T143A68C707907C631F2E1427D56B93BB6C92D98249B3114C3ABC61FA1492D3DE2E36E93",
              "sha3_384": "8ba31a9f5e38a04b1b3564d3a6ca3202f0880ce163bafa7c17a1d9def1e750e4b5e9854ff892a693d84ca59e724a3574",
              "data": null
            },
            {
              "name": "45fec69ccab954388626c3d6efc7f7e9370802dba427b846849d3eaf6797d71b",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/45fec69ccab954388626c3d6efc7f7e9370802dba427b846849d3eaf6797d71b",
              "guest_paths": [
                "TrAPI.dll"
              ],
              "size": 4006848,
              "crc32": "4C642E0D",
              "md5": "1c475f28c1a6818e34b8ef5970965dd2",
              "sha1": "9933a9d18cb2d594143317900da47605f8442824",
              "sha256": "45fec69ccab954388626c3d6efc7f7e9370802dba427b846849d3eaf6797d71b",
              "sha512": "c33dd73fab8e8571da9a666f8583370b954fc6ac48ff60df8d807b21dc9d477477806322f88acccf82e81baf0b5a79c177bcfd5fbea1620f14180e68d594d37b",
              "rh_hash": null,
              "ssdeep": "49152:lHvrEQNZcbcIp5sbV/A+xQ7mHVCyqtPXyvMcAnOdbBCW0uHOV:lHvrr8JHsBHcyqgv6sO",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [
                {
                  "name": "embedded_macho",
                  "meta": {
                    "author": "nex",
                    "description": "Contains an embedded Mach-O file"
                  },
                  "strings": [
                    "{ FE ED FA CE }"
                  ],
                  "addresses": {
                    "magic3": 3755676
                  }
                }
              ],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13F06BE22BF43A571E6CE48741123937E9E3E6014832454D3DEC6659CCE0EAD26F3B79A",
              "sha3_384": "4e3169b69fe2bdfe5610064045c01f2e9ba9fe9aed5c26008a948845673d3f9f21e2cf40ea03d4f20dbb6f1958ad6481",
              "data": null
            },
            {
              "name": "c92420be1c9ed9b380249c5594b61b4ac9f01f829b6fac65696664f860920aef",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c92420be1c9ed9b380249c5594b61b4ac9f01f829b6fac65696664f860920aef",
              "guest_paths": [
                "TrGUI.exe"
              ],
              "size": 14278592,
              "crc32": "41E9C304",
              "md5": "957e3a89bce890a6dba342cd0214fe93",
              "sha1": "36257e7073973b65b4c7ccfbdf29068d110e65dd",
              "sha256": "c92420be1c9ed9b380249c5594b61b4ac9f01f829b6fac65696664f860920aef",
              "sha512": "f635a954061fa931c8a66c103caf1b391b365e39d46e294002640632acf53550fc851856938c5130da87a05d84722c95bc2ad232f14de654bb86980ff7b5bbb0",
              "rh_hash": null,
              "ssdeep": "196608:O/VAjlz3fp8EFe4xwVZJsv6tWKFdu9CcI8Ficnu:Zz3fmEWZJsv6tWKFdu9CBcnu",
              "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T140E69EC2FA8341B2E8910071543BA76B5734B9084B6596D7A3EC3ED9E9312D13F3B74A",
              "sha3_384": "95ef8c511e4f875d7de328a92bfbfd55b90896664267a4db42e24669d6c970b7a1e79d781cde66ca5119581272480191",
              "data": null
            },
            {
              "name": "b9a916e09520e348acbcfdedc1616de66dd6278b09392514676aae00cb58127d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/b9a916e09520e348acbcfdedc1616de66dd6278b09392514676aae00cb58127d",
              "guest_paths": [
                "triangle.png"
              ],
              "size": 192,
              "crc32": "4A19B14D",
              "md5": "a2592d3f2b8e287f6375baab1f77db54",
              "sha1": "18469d4ddddb700fe11e815ad85753a75f6a9b07",
              "sha256": "b9a916e09520e348acbcfdedc1616de66dd6278b09392514676aae00cb58127d",
              "sha512": "6b3994d9d1c95dff0ff0fc4aaa0648f3938a3bed4cc9cd25d47510405c05bb261e3ddfeb3685274e59c341e5413e87977b3146f2f009c2950985853830e9818c",
              "rh_hash": null,
              "ssdeep": "3:yionv//thPl9vt3l0Lts7CX9/iy3/P6HH57SvocRb1P0V6jxZFLnJE+lrRS8t2up:6v/lhPkR/UyKA8VINFbrRPtVp",
              "type": "PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T15BC022C1B4442928CB16453E48365012BA3A345A02695E0CAF64B8AD420AF4441E2A02",
              "sha3_384": "c934231cc718f4919b9cd7bcb7ee7b49f81db3167883da443d674c0710cc93db77c04293b8cdd278bf94df0f13338023",
              "data": null
            },
            {
              "name": "4be97f302fbbcd5b012848f465cc3bce84ed0ac30737ee930fe2279dcf1af504",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/4be97f302fbbcd5b012848f465cc3bce84ed0ac30737ee930fe2279dcf1af504",
              "guest_paths": [
                "TrSAA.dll"
              ],
              "size": 45368,
              "crc32": "DB48DDB9",
              "md5": "883cd05f1c3c98cd5d83064f00b787e1",
              "sha1": "3a35a5e5dc1245655374d9143eb04581f2bd8a42",
              "sha256": "4be97f302fbbcd5b012848f465cc3bce84ed0ac30737ee930fe2279dcf1af504",
              "sha512": "abd96d3f39293a71a617778f66bb0aaed10b111d8ac2f1366434af324d5f75f5c30d62e0f5fcaac018d24c830b79b92b60760c42e46decfd1be221e6bb7ba0bf",
              "rh_hash": null,
              "ssdeep": "768:MsESwt5lBYHGbPQVv0js6iPB7cD708Ouda5Vk2TD1tmTYifiRPbZz:9FE6HL0v7084Vk2TD6T7fixbV",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1A2136C52770184B2DFCE23B478A95B3F4575F9500FD001C3EB6292EA1F253E2B9B651A",
              "sha3_384": "4af5df6e0cac8ac51521f84b125d8a70f86b846448e21c03666f6cb441c009fd4cd0663a6698339852639d4368ea6838",
              "data": null
            },
            {
              "name": "90ef182afc10b6cf44484e1746147d13e60267e1a1462cb19e7416f763c84573",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/90ef182afc10b6cf44484e1746147d13e60267e1a1462cb19e7416f763c84573",
              "guest_paths": [
                "TrScvStub.dll"
              ],
              "size": 19256,
              "crc32": "B24BD9E0",
              "md5": "6a162812d49d8317de098fe12a5fcff1",
              "sha1": "468eaf735f8188baeb26eaf678c2349876b7a824",
              "sha256": "90ef182afc10b6cf44484e1746147d13e60267e1a1462cb19e7416f763c84573",
              "sha512": "a9cf59e3d345b5406db048ab12debee6532eb01fcd7f78fa8623769d50b7ff403e662674cb58aa62dd8b437c772c7e554e2597db4a3da07c59f7d291f4241b08",
              "rh_hash": null,
              "ssdeep": "384:rcP3mqJE5+X4jDfW7IYif8ZpHzGovTvBO:NqaK4jDfWEYifiRPzQ",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1CF826C76BFA01455EEDA0B30B4F655335D70F6605FE082C673A6810E2E567C2BE2827B",
              "sha3_384": "7cd653ed47e792ca9ead1040cdc5d9f94fd4a8aea66af0892779a41814fd55a0a3022593e429915714d502c76a17a094",
              "data": null
            },
            {
              "name": "dbb059587e7765e174819d915a323a3c245d2a94cc56022b973b106bacca9bbf",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/dbb059587e7765e174819d915a323a3c245d2a94cc56022b973b106bacca9bbf",
              "guest_paths": [
                "ucrtbase.dll"
              ],
              "size": 921896,
              "crc32": "AF37872D",
              "md5": "c55d314563bbe142b76097e1bb6f2f7f",
              "sha1": "301d180aa7bd5db9064501f89e6fea03e78ad579",
              "sha256": "dbb059587e7765e174819d915a323a3c245d2a94cc56022b973b106bacca9bbf",
              "sha512": "ae1a1149be1a11a2cf10e9b3232dca8c48d55b4504ff4e94cc6cfc2c137dd188cd292e2069db2001a06c4fb2d07b4ce9cace47d3c454cc62e51ff81239ccb624",
              "rh_hash": null,
              "ssdeep": "24576:R0qW/eQNMe7KtlQzn4pz+xJlEInEFmcvIZPoy4z1kU:u/eoF54pr5",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T190156A617885C161C8FA71F81AAEF232057EB5944F70A8C337D40FFEE5651E02A3B65A",
              "sha3_384": "33ca91e29f24d8cbc257e4c74f59203a90f85181a1e98382d623b3f38546f36a45cf74eb4d530f87ec05cbb1158ac57f",
              "data": null
            },
            {
              "name": "8c71b1f1a901fcebbec429e611c5c2dc222a4167d8d6636791356d7b4f94a9a3",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/8c71b1f1a901fcebbec429e611c5c2dc222a4167d8d6636791356d7b4f94a9a3",
              "guest_paths": [
                "UninstallSecureClient.exe"
              ],
              "size": 22976,
              "crc32": "CE7F268E",
              "md5": "36962e902c10d5bd9a88d233df022f69",
              "sha1": "02e50de3e481cf097b9f87bce30697a0a7fe6022",
              "sha256": "8c71b1f1a901fcebbec429e611c5c2dc222a4167d8d6636791356d7b4f94a9a3",
              "sha512": "29e23630e5c3a958731eae1b4cafc11ac35e9f13049c3904c13bd381420c24c344581b2b33c085ada85ebd9526b09a7d74b8b81566eb1fcf2e3931503e42aeb1",
              "rh_hash": null,
              "ssdeep": "384:ij1F+iRpKYG4/sJMtl5hlVSd7LdLD6fvwGBkNl6bCI9IYigW8:ij1F+iRAYXsmtn5i7LdLDokNlT5Yid8",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T18CA28C43EF340856FF950F7464F2A417FCBEBEA08FD4918B935682491252784BA1C27E",
              "sha3_384": "1d970a384abf55a9f2c5fb16fd81f13941306f736e352a7b6d56132986870e89a5906748e1220d2e350a67f7f6eadbb0",
              "data": null
            },
            {
              "name": "836e664bc6fa7a7612becfd3f54bb35d1101b4a690cf8d72ce3b350b404a5e8c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/836e664bc6fa7a7612becfd3f54bb35d1101b4a690cf8d72ce3b350b404a5e8c",
              "guest_paths": [
                "update_config_tool.exe"
              ],
              "size": 451520,
              "crc32": "8A2241BB",
              "md5": "3e7c3bbe6f2c816cd9f1dbba89b4da46",
              "sha1": "c212f1637293927b158768cea426b998b80c813a",
              "sha256": "836e664bc6fa7a7612becfd3f54bb35d1101b4a690cf8d72ce3b350b404a5e8c",
              "sha512": "01cdfc0df06f2f384cbc4350ac8c6627b856e1106792f4f8d6792a154b723f2492f5b8bace65b8ac873b06a153c8a3a5c90bf2308e33c1aad7f51f08d664ab62",
              "rh_hash": null,
              "ssdeep": "12288:yuvyd9biLwcaB2+w9YkJ4Uz0tvIlE3Aev2plsydkgoLADsdgX:4sLwcaB2+w9YkJ4Uz0tvIlE3Aev2p6Mn",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T121A47C317707C53AE68653B12FA89B7780345C64A72118C3A3C47EBA2A722D75A37F17",
              "sha3_384": "9871ef7e73bdc57450555639ca1dbed81e3c9338c0f22eb5a531067d1dbf4f0c8e2df644216f64d64e02b7a2e0a9432d",
              "data": null
            },
            {
              "name": "c7a97a914aa227fa7033d5c16d87aa9a82c86b32a5cae866a69c14b2b513d8af",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c7a97a914aa227fa7033d5c16d87aa9a82c86b32a5cae866a69c14b2b513d8af",
              "guest_paths": [
                "update_site.gif"
              ],
              "size": 4464,
              "crc32": "3FF6CDAE",
              "md5": "c9a43c47c18f17814bb32230dc972db5",
              "sha1": "21c3930d5519996f0a5204ab501cf7a6eb881e54",
              "sha256": "c7a97a914aa227fa7033d5c16d87aa9a82c86b32a5cae866a69c14b2b513d8af",
              "sha512": "bf42127a33c31d90f4ef50351dfcd7f2515b335774c108cbe865077e87043fd226ac30acfb5cc1a98f50752cb283f3aa159f5f8dbf4d83ae6ad4fe9cc4948787",
              "rh_hash": null,
              "ssdeep": "96:1C+EDEW+OSNAzt/TaqBf+zyEqmgh2lTjb1Cwr1U9XS:aDd+OSNA9TaqiyEUM9b1/rmi",
              "type": "GIF image data, version 89a, 30 x 30",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1FE914C8FB929F8CFC835145A7D890D487429D68711F49CB073B93FE1C2A53A900A7A0C",
              "sha3_384": "986707e279b9ed94d98509736e504444541772dae8990a45f50335da86d216fe7b0149a2044e951d212e05cafe7fb007",
              "data": null
            },
            {
              "name": "31529aa992c2f14755456bd70b85e61c33082b14b36fbe9dfc3cf83481172df0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/31529aa992c2f14755456bd70b85e61c33082b14b36fbe9dfc3cf83481172df0",
              "guest_paths": [
                "vccorlib140.dll"
              ],
              "size": 269976,
              "crc32": "B5850154",
              "md5": "43977231ea53b7e17aa7b5a9c5d490d3",
              "sha1": "b1150a571e18253bd618dca4ca98d0a70669c10a",
              "sha256": "31529aa992c2f14755456bd70b85e61c33082b14b36fbe9dfc3cf83481172df0",
              "sha512": "885ea0e9f35b062f4e9b69c8626efac573556e6ded23c6e55fc9018159064aee2e59a80b194b936a3adec882a9a70a24a084df454d6e8f67097088396c96861e",
              "rh_hash": null,
              "ssdeep": "3072:nr+bCnEcE/ydL0HipGODOzWQqNVPn5Efdbo2gc0zv8RRaRMH1SNyiIa:rJxdL0CHDOlYCfdUfIWfF",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T10E445C323A9CA476D5BF1239EAD4963810A6B0804FD1D7C72E80DFD91EB87D05D34A6E",
              "sha3_384": "b92c8cc8b37b9af9b68c27ce62eb07e612ee56b92941c7fb54fb57fbd1962ea209d47a0912fc9fb1e153a86f0d3ef8de",
              "data": null
            },
            {
              "name": "7a114a9c1ca86e532d7f38e81c48f24ef2bfe6084f6056b3d4c3566ba43003d6",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7a114a9c1ca86e532d7f38e81c48f24ef2bfe6084f6056b3d4c3566ba43003d6",
              "guest_paths": [
                "vcruntime140.dll"
              ],
              "size": 82752,
              "crc32": "5943CBE6",
              "md5": "e79ef25890b214b13a7473e52330d0ec",
              "sha1": "e47cbd0000a1f6132d74f5e767ad91973bd772d8",
              "sha256": "7a114a9c1ca86e532d7f38e81c48f24ef2bfe6084f6056b3d4c3566ba43003d6",
              "sha512": "dabed378fccfabc10486747fc70cf51a4fcc5b88f869c8a2fa4df30caa83a3af086c89e23806b7a291756da957a97c80a9b834a05e1d8ee7bd5c7159458c537a",
              "rh_hash": null,
              "ssdeep": "1536:Szref/qblSclsganbQrl1cfJfkGuJnmxhpxv5YDanecbFKQhBVh:SGf/qbl55anbnfJX+neN5fnecbFKQh7",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T160839D11F4D540B1C1994D3012BADB33AB7CDA508FE09ED7ABE94D8E1A767C2A73520B",
              "sha3_384": "d1c40f182465b869e4b754cd10f18a651e0eb5bf4dd15273aa92e5cbf5a8a7ba684c981f71903098c992eb69b229ec2a",
              "data": null
            },
            {
              "name": "a73e0a88127b8662ff65b94c7c3ef53a466a3761b8f587e556177c2fae28bae0",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a73e0a88127b8662ff65b94c7c3ef53a466a3761b8f587e556177c2fae28bae0",
              "guest_paths": [
                "ver.ini"
              ],
              "size": 11,
              "crc32": "C9D10944",
              "md5": "eb02141ba600313732572fce18099a4f",
              "sha1": "f89349150c38ec5393516ea14a0791016bfc12af",
              "sha256": "a73e0a88127b8662ff65b94c7c3ef53a466a3761b8f587e556177c2fae28bae0",
              "sha512": "c92f2fa08c8d748eff9a23d576b6077380a368fbe14c12e9c3d9cff0911c98227cb42f1d5a11f2268bd0a35485bde55c51737e67139f317953d5e59d9573b003",
              "rh_hash": null,
              "ssdeep": "3:s4RZN:s4Rv",
              "type": "ASCII text, with CRLF line terminators",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": null,
              "sha3_384": "8513ce75bf3325be192f0c8a353b43fac1d66266667e8031b6ec35197139fad707ba70ffea4971139536284a5a5d21a2",
              "data": "986104605\r\n"
            },
            {
              "name": "889a7794f0b61bd8710f3c373267bd81de2c854e74c104e2de61d795434f687d",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/889a7794f0b61bd8710f3c373267bd81de2c854e74c104e2de61d795434f687d",
              "guest_paths": [
                "vna_install64.exe"
              ],
              "size": 148416,
              "crc32": "B09F749D",
              "md5": "7e46db60fdf7700574efa84882e4fddf",
              "sha1": "7debfdf01e6b9894c45f2b034084d93fd350bafe",
              "sha256": "889a7794f0b61bd8710f3c373267bd81de2c854e74c104e2de61d795434f687d",
              "sha512": "bcb487aa3c7e91fb7bee740aa8992623e4f24d935a53408fb52a4f310af447072699000237918946accda8ea608857afd1f011d15e6f2fb9e2ac2d2779252804",
              "rh_hash": null,
              "ssdeep": "3072:h4VdXZpAmUdHlaS0MDIV+dzlSZBjpXdNGNqcWD5vZ:aVdXQmUdHAMDYnaql",
              "type": "PE32+ executable (console) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T12EE37C5777B530FAE5768238C9A14506F77278710B758BAF0368476A2F233909E3EB21",
              "sha3_384": "7e248e0458a5fcf033fef8e7dfc0cbbc8956cb609db167770db255cc636959922c90aa2f10e54667ccd479133551c5a1",
              "data": null
            },
            {
              "name": "481b7277fe95b91ce791c5055f8f94a8302f0bc52b97607eea889acbfe0bd36c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/481b7277fe95b91ce791c5055f8f94a8302f0bc52b97607eea889acbfe0bd36c",
              "guest_paths": [
                "vna_utils.exe"
              ],
              "size": 100800,
              "crc32": "724BD2AC",
              "md5": "4688c94df3c1f166c7864ef926ae3fba",
              "sha1": "ee5903cc2b89dd89d1519054121b1812a56645f7",
              "sha256": "481b7277fe95b91ce791c5055f8f94a8302f0bc52b97607eea889acbfe0bd36c",
              "sha512": "b0ebd47f580aedc126541276fc4baf7b4d470b718878f9508027abfb976789f290c270b7777888b8af351b603c0b7b1e9b44c201121d29476c14792ab225debc",
              "rh_hash": null,
              "ssdeep": "3072:ecS92D7h0Rk81WxV06tUuzscBv615p89CEuD+vSr:ecS92DF8LcBv61/89Cx",
              "type": "PE32 executable (console) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1E1A37D41BAD38791DA1E0F3A169A67779932BA7C4F0049E3E7B25D905C072D31E3E29C",
              "sha3_384": "19c7674031e3be487c5301f149fe221c28a1673e8672f1e1a0c556da5887b672a815f49dff521d89aa82df80c6596199",
              "data": null
            },
            {
              "name": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
              "guest_paths": [
                "vnaap.cat"
              ],
              "size": 11127,
              "crc32": "A55FB8EB",
              "md5": "f4fdf35de0ef11a52410be44e9f035ec",
              "sha1": "c67019f44b1c886ab57c0ca3528c768aa1fa2401",
              "sha256": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
              "sha512": "19a3d9b9c36e1c1b5dd5a9c7d4cd9a51674e4a56fabd14496589f86a55543cf292e2762cc1780ea1ad6902def9fb0556a7e39074b40dcf528ca2aaee8f01bebc",
              "rh_hash": null,
              "ssdeep": "192:vAKXyBJCSEIPWkjyKDUFWQFooUks9gICQX01k9z3AFN2q:YpPWRFRFU/P/R9zol",
              "type": "DER Encoded PKCS#7 Signed Data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F73228E68A6D0483ADA7BCB013D8E1933C3D67D75C1095BA528BF36019837CAE30813D",
              "sha3_384": "c9806eea9da07583f6595e17bb65d1b99d825487d3d4e1b168d4a4d83b9aed2737468c4d4ffc5b848fd8a6fbdf3b53c1",
              "data": null
            },
            {
              "name": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
              "guest_paths": [
                "vnaap.inf"
              ],
              "size": 4799,
              "crc32": "23BA6B4E",
              "md5": "573345d5fe94093c254fdf95488b66c7",
              "sha1": "638cf92b4d471885e1db95a6bcce402adb91c181",
              "sha256": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
              "sha512": "bb66dd26379c9ab76bddf1550f94aca1c429cf4e680a65fe548050b3f5b5b0fc3c876bac8be46c79a4c9baccdfa65e3767c4a5e5f427f429826b9b155a84553e",
              "rh_hash": null,
              "ssdeep": "48:HkobruhUjdh5sZlexkrrx64NbKkSCNX51vuhFlSh/82HXNptDWNDMV2zLuwuL0Ci:HF/aUp6x6EvoUh/Cm5qDfDIM8uUhGH",
              "type": "Windows setup INFormation",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T16BA173194E424B3731A7E15B63022AC3F327119A2125114C71FE99096BA9F0D937F9FA",
              "sha3_384": "61377681b058685c8046a5026d28cab8517f31bb6179fba8d8879237df14bc41acab821347fccd62394fd2753417bc5e",
              "data": null
            },
            {
              "name": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
              "guest_paths": [
                "vnaap.sys"
              ],
              "size": 76208,
              "crc32": "00CDB731",
              "md5": "7ba5dec4c51df260bfe3129483167489",
              "sha1": "8ebf1331fdb3462bee54f77faec374697d5cedb9",
              "sha256": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
              "sha512": "ea7bc40aefe4a6e8c4181b5d2c29b72d8f598b0cde2725849ed4528e783e245ce9b6d0856904403f7adbbe79b8e8901d4c21fd50dc9ad387c762a5ffb153e5ea",
              "rh_hash": null,
              "ssdeep": "1536:TgV/+nab3+LWQtHAXcBjP1lPpmf9tvgm7nYeGE5+zutC/:bab3+LWQAXcBP1/o9tvgmDYe5Md/",
              "type": "PE32+ executable (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1FE739E82E55458B9E467C8B5D9B0A617E7B07A061B10D3DF0368C2A5AF033D4BF3936E",
              "sha3_384": "cee047d0b042cd7daee2976f71654dab8c6f2b5df58295a640ae144656389f574cf1490670a5291704ed13dfcaf06106",
              "data": null
            },
            {
              "name": "1447f4a7bfe02d34910c5298f6746c59ea9ce6cb2134a5e8b5069975b8d016c2",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/1447f4a7bfe02d34910c5298f6746c59ea9ce6cb2134a5e8b5069975b8d016c2",
              "guest_paths": [
                "VPN_ProxyServer.exe"
              ],
              "size": 105240,
              "crc32": "F944B93A",
              "md5": "c154e436c0643c13ce68e42d01ae9980",
              "sha1": "79c2d88548ddb7b82d4b4e7e5f819529f048bf6e",
              "sha256": "1447f4a7bfe02d34910c5298f6746c59ea9ce6cb2134a5e8b5069975b8d016c2",
              "sha512": "dcc85ccf52f439a9c0061a827e93373517984a6886d669632d073de1f5abe57f28f088519c38f7c3468feca07b461127e5d2f82b57b99cf00f985c738a633b72",
              "rh_hash": null,
              "ssdeep": "1536:AiBM5VacyEffQfHJ5fKGsfvnlrvruf2HfE/SXj:BM5VarESTKHvnxSfGE/yj",
              "type": "PE32 executable (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D0A31A1276C1C6BFC9534EF09F8585C2E771F2106C34D16B72D41F1EEEBAA422A6A352",
              "sha3_384": "2ffe0f9c828998fe9e1846b5820679eff74366e0ce189e7d44aef09e711f6098a6a8282302b709b37c1fda0877cab850",
              "data": null
            },
            {
              "name": "e1e0544b53bbcd232dc9d74d4e65bef8e549b7f611d401bfdaf1564be03e43bc",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e1e0544b53bbcd232dc9d74d4e65bef8e549b7f611d401bfdaf1564be03e43bc",
              "guest_paths": [
                "vsconfig.xml"
              ],
              "size": 260968,
              "crc32": "F7D47025",
              "md5": "f65751a7dbf3a6d71c56017cbfcd7e07",
              "sha1": "1a7774634ab73c9cd0e53b9d2fe03e7698c55b44",
              "sha256": "e1e0544b53bbcd232dc9d74d4e65bef8e549b7f611d401bfdaf1564be03e43bc",
              "sha512": "db75430d90c77cc8f745ca3d3b6e5bd29d51d1cdb947fc3712fea17d4d10222dceab3b08181341d3eba74c7b4413f303e92edd83a78a6a75febf27e77eabad47",
              "rh_hash": null,
              "ssdeep": "3072:AqqdaVkCyLPsTIteRVE8jDmKpjcxlcofgz/eAW:S8jjcxlcs",
              "type": "data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T13E441096A16F22C235D56FFEABA6DC63984013C2A5BD580FD853C18BF7356C0606E48F",
              "sha3_384": "4a6bb869a90668911a9540c76c3e1580bcb0017273c3a1fc9b0529f030ce05e26e27a77197d64867a7b9aea641db0e77",
              "data": null
            },
            {
              "name": "6cc5dcbe68ce9040d9b452dc62b78a459afa9b2d2ad70d9da757f0561f703468",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/6cc5dcbe68ce9040d9b452dc62b78a459afa9b2d2ad70d9da757f0561f703468",
              "guest_paths": [
                "vsdata.dll"
              ],
              "size": 141248,
              "crc32": "7A185E24",
              "md5": "07d9f6c524025cb359abb6edc3de4264",
              "sha1": "28eb6a2a5f0a6346fa66fb615985e73d3de555d9",
              "sha256": "6cc5dcbe68ce9040d9b452dc62b78a459afa9b2d2ad70d9da757f0561f703468",
              "sha512": "65b308109be55de1c672ac10a13ae6223dd92a271f0fae3aa9d64c9be90c73af9e85382a98b161176d25fd71e5df960f10a6cb7c0e3e49b1d70b0716cf47cf59",
              "rh_hash": null,
              "ssdeep": "3072:ZrA1ZuJsSL4YIt5dI1N5C464haD3UVJ8XODaOUIYx+GELmMoikYvF:5wK1N5e4haDLO7UIJGEf",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T122D38D02B3008435D6E9027DAC6E7F3AA63E65B09FE405C3A7618F7E6D641C36E35A47",
              "sha3_384": "d819dbcad1e876836b96f68830be9459894b8e400f7936cf1c13ce1c2807c2c4f72d17883f5c26d74d94ed19494af6ad",
              "data": null
            },
            {
              "name": "5beee8422d26fd7b5bc90063961caebd5769b81ae0cfe1ace82e7ec3692e3ac8",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/5beee8422d26fd7b5bc90063961caebd5769b81ae0cfe1ace82e7ec3692e3ac8",
              "guest_paths": [
                "epklibproxy.sys"
              ],
              "size": 29648,
              "crc32": "DAFAB7DF",
              "md5": "c72af8f98bdde1004f43ef550481e4fb",
              "sha1": "00b8b69dd388848c8139a0cad3b212fc81a21f3f",
              "sha256": "5beee8422d26fd7b5bc90063961caebd5769b81ae0cfe1ace82e7ec3692e3ac8",
              "sha512": "75b4dac307ac95e8799999014837e2b40387c9c47605ea933d63ca0588490b8a07dbbba2cbc9fc5320e66bdb1c06bb67351a7b046a1ce4fad9d57eb064318f76",
              "rh_hash": null,
              "ssdeep": "768:ryTaWaA4cTVQ8/uaF9psxkLETNVZ9yTOTfjnfnmG7Yl9zjRP24:ryTNatG9pBayTOTfjnfng3zjBB",
              "type": "PE32+ executable (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T179D26CC456AD14C7FAFA99B446F8C5C7BC39BA52132296DF02A5C1740C13FD4EA38B15",
              "sha3_384": "789ba621495c33fc623fd0baf8da835f94eed2360318b702745a3ab424074414580d418e4568308aca75e072f24917fe",
              "data": null
            },
            {
              "name": "672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda",
              "guest_paths": [
                "vsdatant.cat"
              ],
              "size": 11513,
              "crc32": "D9A89511",
              "md5": "3fbb5fc32b51b0462dc503a83c6068a7",
              "sha1": "3d2c043cfc05b1c8c55132d5056d698031b736e1",
              "sha256": "672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda",
              "sha512": "61b4a994eae02d28fbde70f1be97284ca5d1ae22b97a55c001054c36f012fd69db868003e4d4e26ed0c23c3caa7cc67ba523f4871e7502316189603720c7ac3c",
              "rh_hash": null,
              "ssdeep": "192:2hdGB5vyM8JCSEtOL7yKnUi8rFWQFaRdt6gqzGslX01k9z3AePptYYQ:wd/u4CFRYnkGER9zFHQ",
              "type": "DER Encoded PKCS#7 Signed Data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1773219D68A6D4087EDA7AC7053E8F8A37C3C6BC71C40956921DBF7A40D927C5EB1812E",
              "sha3_384": "e0e372d9eb80f53c8f4dfac499ffe5226110becf6d6517261380952266afb3bdb58b35afff29f8d1c8db928fbca3ec19",
              "data": null
            },
            {
              "name": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
              "guest_paths": [
                "vsdatant.inf"
              ],
              "size": 3729,
              "crc32": "9A800EDD",
              "md5": "d57d27941fca116d8812d272e0b7d7b6",
              "sha1": "1a375df87cde88f64cc93e69b2daba80b5b93360",
              "sha256": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
              "sha512": "eea58e887644d0c45e0693b4b06c6f7f0702b792ce03f2027da2eaecbee9f97cbebc643909e9741fb09d1e75987abba286462c73bd99becf7a15d1d4959a786c",
              "rh_hash": null,
              "ssdeep": "96:JNZIF3J7FpmsE9GXeA/GSvgvIZPmZLPEbD4vD8RqQdTe:JHIF3J7Hm33A/TvpZPmZLPEbD4vD8Rq/",
              "type": "Windows setup INFormation",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1ED71FF04AFA2837068C7E56D77033CA3E66D3480E5DE1584B2CC9459834ED9E79ACF9B",
              "sha3_384": "551e47ae02acca48ce78e0a39471a5cc3e0c9eea9885d20b321454c7f0dfaf5bf69dce0b60539fb4753ae055d7348f27",
              "data": null
            },
            {
              "name": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
              "guest_paths": [
                "vsdatant.sys"
              ],
              "size": 681072,
              "crc32": "2EB3F1EF",
              "md5": "b7687358512bf036f0910fcfc587a4fa",
              "sha1": "92fba9648b8deb78e8e15436e29e3a78fce91b7b",
              "sha256": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
              "sha512": "197562377f60159d82a0470682ff0cb601b84b59ff40d4fc66cc3b61ef80fb24cf102a3a387d763ec85926c06a57d3fca22673301bde283e2727785116ebfd57",
              "rh_hash": null,
              "ssdeep": "6144:OuYQCl1/oPtzstHFseT/Q3Of6GpruJl7oycFnvuH6pXYPH/ZObSlQj/Efutpp:OuRTtz6lFT96aruJBKFnvuH0IPHxOw6L",
              "type": "PE32+ executable (GUI) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T124E48D47E3A511FDD0ABC1B8CA9B9113F6F1B8091720AAD74760C9153F22FE8A739365",
              "sha3_384": "693eb67bff60f217c7f0c0220e98d619a916769ccc880990ac6c7d6f83356376ae84193e3b49391e7d941601edb780c9",
              "data": null
            },
            {
              "name": "dd0ddd73c42a0806ad48b43f35f300d56ff01db7b447993c5ce7bca5a8fc7091",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/dd0ddd73c42a0806ad48b43f35f300d56ff01db7b447993c5ce7bca5a8fc7091",
              "guest_paths": [
                "VsDrInst.exe"
              ],
              "size": 385984,
              "crc32": "DBD915E6",
              "md5": "a456df569b7b61989c8fdf9cee46bccd",
              "sha1": "40a401e1a15d70aece79c48de1995e3668cd2999",
              "sha256": "dd0ddd73c42a0806ad48b43f35f300d56ff01db7b447993c5ce7bca5a8fc7091",
              "sha512": "e5233fd0b52bce744a4a80a03f261fc3e49b1a87cb9537b0414e0197de21b1795d2c4e119da4764e4482d685033a71d9f816a384bbe55b5450a531bdeb8a97c4",
              "rh_hash": null,
              "ssdeep": "6144:n2pD8mJ4eOeEi4VCsBxkbm9OmdBXHEFpJd2L0ftovIagoh4zOk1dlTUF:n84zeEiMfkbz2BX4FigoEFBA",
              "type": "PE32+ executable (console) x86-64, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T120847D16FBA509FCE077D138C8668945E6727C9E07719BEF2364421A1F376D09E3AB20",
              "sha3_384": "806b43ca0de7d308c4cf7c1d84f42d652abec82f9696db55335de7282cab1ef124a09da9f72158584cb61d7796c5ed5b",
              "data": null
            },
            {
              "name": "7ef385f356ca59bdadfd74cbaf4c64d51019cd40dbb3ab8d5fbc09fdbfd71034",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/7ef385f356ca59bdadfd74cbaf4c64d51019cd40dbb3ab8d5fbc09fdbfd71034",
              "guest_paths": [
                "vsinit.dll"
              ],
              "size": 1750840,
              "crc32": "A3CD6622",
              "md5": "50506e53e44ed4945b9dcdaf2817b53a",
              "sha1": "1c5a604281f89a71c9ede23f04cd995042837746",
              "sha256": "7ef385f356ca59bdadfd74cbaf4c64d51019cd40dbb3ab8d5fbc09fdbfd71034",
              "sha512": "30a6b8bdd6b0c2882a8c4370a7c95fe5b307c009b04d070ad91166de04114c2fbbd7a4dad0b7d6661ddec283101aed43a48e155509a9cfbbc14589993ae9fbec",
              "rh_hash": null,
              "ssdeep": "49152:GjZpQDhxCkean+X4KRC0t6rLn3TuptyirXb:GjZ4Ckean+X4KxtILnZin",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1D3858E01AB4B6429FCCE413D68A676F98E3A64244324CDE3DED433256C60DD72BBEB45",
              "sha3_384": "c5c0dd1fd847786d2ad2ed070b8880d60dd70c1fd3b226b0fa2fb07c2f6837511b87494e0463b1f19ff5cc8dd8c6a29c",
              "data": null
            },
            {
              "name": "ae03c2b55920c983d5523343639bb4179d78bd8f2a3650bf9a0cc7e6bde15d5a",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ae03c2b55920c983d5523343639bb4179d78bd8f2a3650bf9a0cc7e6bde15d5a",
              "guest_paths": [
                "vsutil.dll"
              ],
              "size": 824256,
              "crc32": "223B926B",
              "md5": "2fa09f502019ed5f914ed80341389061",
              "sha1": "9fa76b7f4c30fb0dfb2df74745f1fbe36021c634",
              "sha256": "ae03c2b55920c983d5523343639bb4179d78bd8f2a3650bf9a0cc7e6bde15d5a",
              "sha512": "14488ea8dbe4129992ad846f7360486c8d12e45623c12e68002cea468972e8dc82c4e571dda16ece63af7bc3d1b4e0471ae84dd22043e1caa1c80548a1d79816",
              "rh_hash": null,
              "ssdeep": "24576:GMmJKUhdnexVoprSk0ffonlVwB1xh+w4LIY3TYgI7xS7BH/8gR:EDhUI/03+G4J3TBIQZR",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T155057D227906C032E69901B16839AFAB647D6D390B3851E3B3E4FE3D58701D36B39B57",
              "sha3_384": "cf6b620734861094b10cfab222ffb7ef4b4733db3b81c731087b1b6b9962f7c4522e6094450d79c0cc49cc7f3114b1de",
              "data": null
            },
            {
              "name": "a63769ddc32927d96f6d64a2e150e9ff91f0f35b1b816b4a8ae6f151ffbfd49c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/a63769ddc32927d96f6d64a2e150e9ff91f0f35b1b816b4a8ae6f151ffbfd49c",
              "guest_paths": [
                "watchdog.xml"
              ],
              "size": 1568,
              "crc32": "5D719BBD",
              "md5": "74027e0d34732f85bbae8e4f609d9d33",
              "sha1": "162dbfdc2ea213403610214384414807ad9db616",
              "sha256": "a63769ddc32927d96f6d64a2e150e9ff91f0f35b1b816b4a8ae6f151ffbfd49c",
              "sha512": "d9892c823fd6365170fce08360dba6f09a830d71bfcdcd5ed795d77fe4f125b3ebafe814fa8fc2514d529fbb40ee249053967660d494949a8203f16f5fb6e238",
              "rh_hash": null,
              "ssdeep": "48:i8mOtFqgrgvlvxgQ6Q41qgnyFMFqgaglpvOxcBqgnymb:i8V+lvxgQ6QqqPEPGxcBqkb",
              "type": "XML 1.0 document, ASCII text",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F9317AA2B4EB21A156572C7F218182C5BDF88CBF51001014BACD846A1FF7D8A7BE3F64",
              "sha3_384": "dcf4dd212055e42e19c8f79d75e7b732cc256c431a53682a6967b66c292f0d8bb0f77b44882052456e86d067b3b47fbc",
              "data": "<?xml version='1.0'?>\n<MonitoredElements>\n  <CheckBlades>false</CheckBlades>\n  <RegKey>HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\TRAC\\Watchdog</RegKey>\n  <MonitoredElement>\n    <ProcessIdentifier>@trGuiPath</ProcessIdentifier>    \n\t<BladeIdentifier>vpn</BladeIdentifier>\n    <User>true</User>        \n    <ValidationTime>30</ValidationTime>\n\t<ValidExitCode>0</ValidExitCode>\n    <RemediationActions>\n      <RemediationAction>\n        <Event>ProcessTerminated</Event>\n        <RemediationAction>Restart</RemediationAction>\n        <Parameters>\n          <NumberOfConsequtiveRetries>5</NumberOfConsequtiveRetries>\n          <DelayBetweenConsequtiveRetries>15</DelayBetweenConsequtiveRetries>\n          <ResetFailCountAfter>100</ResetFailCountAfter>\n        </Parameters>\n      </RemediationAction>\n    </RemediationActions>\n  </MonitoredElement>\n  <MonitoredElement>\n    <ProcessIdentifier>@tracPath</ProcessIdentifier>\n    <ServiceIdentifier>TracSrvWrapper</ServiceIdentifier>\n    <BladeIdentifier>vpn</BladeIdentifier>\n    <User>false</User>\n    <ValidationTime>30</ValidationTime>\n    <RemediationActions>\n      <RemediationAction>\n        <Event>ServiceTerminated</Event>\n        <RemediationAction>Restart</RemediationAction>\n        <Parameters>\n          <NumberOfConsequtiveRetries>5</NumberOfConsequtiveRetries>\n          <DelayBetweenConsequtiveRetries>15</DelayBetweenConsequtiveRetries>\n          <ResetFailCountAfter>100</ResetFailCountAfter>\n        </Parameters>\n      </RemediationAction>\n    </RemediationActions>\n  </MonitoredElement>\n</MonitoredElements>"
            },
            {
              "name": "ce559a4ed26c9520428a4b1b5fa29ce2e7360d7dac6811952194f8036bbc8894",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/ce559a4ed26c9520428a4b1b5fa29ce2e7360d7dac6811952194f8036bbc8894",
              "guest_paths": [
                "WatchdogAPI.dll"
              ],
              "size": 23488,
              "crc32": "4CA2921B",
              "md5": "fd8f2a4a625db102cf1295ae3f5fd8af",
              "sha1": "c469caf9934d1f113c10bdc2b5735edec0e0d5c2",
              "sha256": "ce559a4ed26c9520428a4b1b5fa29ce2e7360d7dac6811952194f8036bbc8894",
              "sha512": "e6232d3c78bf787526d8951f169e44a60934793a595440cb664b97e1b35c87e3aa90194d19bc08aa19d9a4a6c5998b8e7ff462d54c1527edcc761cc3e35ef9ed",
              "rh_hash": null,
              "ssdeep": "384:S6y+MsL51qXJpXVVQLmEwxXwGBkNl6bCI9IYiuHc:S/sLgtVQLmEwxfkNlT5YiCc",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T19FB25D43BF604136EF9A0BB0A9F68527AC7CBA814ED588876317470D1F15392BE7813B",
              "sha3_384": "9ddfe394b0b6cddb225014f362e15394ae0595bd0bff0d6fdd0d3f324e4706e8030752c4a75c60bb52170016331ddb91",
              "data": null
            },
            {
              "name": "e966b6b9f3fb954f7cb15463c2337df258159d6337c827df85be1060614758ac",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/e966b6b9f3fb954f7cb15463c2337df258159d6337c827df85be1060614758ac",
              "guest_paths": [
                "welcome.png"
              ],
              "size": 27661,
              "crc32": "12544694",
              "md5": "d4828765fe4a7118b62fea0b48b8be7f",
              "sha1": "6c393621027d8fec680c8d66ed208d2caeeb52ce",
              "sha256": "e966b6b9f3fb954f7cb15463c2337df258159d6337c827df85be1060614758ac",
              "sha512": "96af5eaad7eb789c3a8fee60339e8de179fea8214a4550fe3e64da0e05cb10aa973acc1356aaaa7c3dd4ef67d976f3a8d1f9c7c2e921b1e7e9af19be97ac894b",
              "rh_hash": null,
              "ssdeep": "768:OcFveFcgpxHxBvTSWPXqVOYfE4qn2ye742s9E/9X90:OcchxHxJTSBMyqT+Q9E/9XG",
              "type": "PNG image data, 136 x 314, 8-bit/color RGB, non-interlaced",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1B6C2F2C977C246C5E9DFA8364278397580D3E452CAB418F89FCBC4DA89B5003D69B970",
              "sha3_384": "234b684fa940c500b6094ef4ef940c46f1a9632982d0150188cd20150316ae6b7184fdcd531e946a4757f0424739cb09",
              "data": null
            },
            {
              "name": "0bfb255221dc9a3e70f56a42db611666e93407010c179673937c9ed0b18938dc",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0bfb255221dc9a3e70f56a42db611666e93407010c179673937c9ed0b18938dc",
              "guest_paths": [
                "WindowsSecurityMonitor.dll"
              ],
              "size": 93632,
              "crc32": "F34EF30B",
              "md5": "58f152c388251f688003b7cb3b46d363",
              "sha1": "766688febdb2c6d8328e7b1503628be47dec8725",
              "sha256": "0bfb255221dc9a3e70f56a42db611666e93407010c179673937c9ed0b18938dc",
              "sha512": "900972d16333f1d8b141318ee539677f2cddf9452c9c7068843b0e276bc7923cf56f1fd1a32cfffefd0c704f36592436c9183bd206ca0cb8fd7b52b294e581da",
              "rh_hash": null,
              "ssdeep": "1536:/vnQ0FffLGKEehZhr23yVLS1nbz7DDOMzZDHl/fMfakvcIyD4cUapKIdD7yQjN5g:VBfLEwnr2wLabz7DDOcBfMb7ysnapKIM",
              "type": "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T151939E5273058075DADD017076AAEF378B6CB150CFB211C353A71F6A68A42D2BE3A74E",
              "sha3_384": "ecb38943665da911f113310e44d1f871d6de56e7a3c5396be35718f27c6d291f9a44a54eb0187cfe94d76dbc0d5c8bdc",
              "data": null
            }
          ],
          "extracted_files_time": 0.5252351479721256,
          "password": ""
        }
      },
      "cape_type_code": 0,
      "cape_type": ""
    }
  },
  "dropped": [
    {
      "name": [
        "vnaap.sys"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
      ],
      "size": 76208,
      "crc32": "00CDB731",
      "md5": "7ba5dec4c51df260bfe3129483167489",
      "sha1": "8ebf1331fdb3462bee54f77faec374697d5cedb9",
      "sha256": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
      "sha512": "ea7bc40aefe4a6e8c4181b5d2c29b72d8f598b0cde2725849ed4528e783e245ce9b6d0856904403f7adbbe79b8e8901d4c21fd50dc9ad387c762a5ffb153e5ea",
      "rh_hash": null,
      "ssdeep": "1536:TgV/+nab3+LWQtHAXcBjP1lPpmf9tvgm7nYeGE5+zutC/:bab3+LWQAXcBP1/o9tvgmDYe5Md/",
      "type": "PE32+ executable (GUI) x86-64, for MS Windows",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1FE739E82E55458B9E467C8B5D9B0A617E7B07A061B10D3DF0368C2A5AF033D4BF3936E",
      "sha3_384": "cee047d0b042cd7daee2976f71654dab8c6f2b5df58295a640ae144656389f574cf1490670a5291704ed13dfcaf06106",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": "Wed Feb 22 18:35:36 2023",
          "aux_valid": true,
          "aux_error": null,
          "aux_error_desc": null,
          "aux_signers": [
            {
              "name": "Certificate Chain 1",
              "Issued to": "DigiCert Trusted Root G4",
              "Issued by": "DigiCert Trusted Root G4",
              "Expires": "Fri Jan 15 15:00:00 2038",
              "SHA1 hash": "ddfb16cd4931c973a2037d3fc83a4d7d775d05e4"
            },
            {
              "name": "Certificate Chain 2",
              "Issued to": "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
              "Issued by": "DigiCert Trusted Root G4",
              "Expires": "Tue Apr 29 02:59:59 2036",
              "SHA1 hash": "7b0f360b775f76c94a12ca48445aa2d2a875701c"
            },
            {
              "name": "Certificate Chain 3",
              "Issued to": "Check Point Software Technologies Ltd.",
              "Issued by": "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
              "Expires": "Wed Nov 27 02:59:59 2024",
              "SHA1 hash": "bc9bf10985e23ba74243b6aca44a147577aeac38"
            },
            {
              "name": "Timestamp Chain 1",
              "Issued to": "GlobalSign",
              "Issued by": "GlobalSign",
              "Expires": "Sun Dec 10 03:00:00 2034",
              "SHA1 hash": "8094640eb5a7a1ca119c1fddd59f810263a7fbd1"
            },
            {
              "name": "Timestamp Chain 2",
              "Issued to": "GlobalSign Timestamping CA - SHA384 - G4",
              "Issued by": "GlobalSign",
              "Expires": "Sun Dec 10 03:00:00 2034",
              "SHA1 hash": "f585500925786f88e721d235240a2452ae3d23f9"
            },
            {
              "name": "Timestamp Chain 3",
              "Issued to": "Globalsign TSA for MS Authenticode Advanced - G4",
              "Issued by": "GlobalSign Timestamping CA - SHA384 - G4",
              "Expires": "Sun May 08 10:41:58 2033",
              "SHA1 hash": "31030e176aa4592eab2c8bade83299fcb5585dcf"
            }
          ]
        },
        "digital_signers": [],
        "imagebase": "0x140000000",
        "entrypoint": "0x00010170",
        "ep_bytes": "48895c2408574883ec20488bda488bf9",
        "peid_signatures": null,
        "reported_checksum": "0x00015100",
        "actual_checksum": "0x00015100",
        "osversion": "10.0",
        "pdbpath": "F:\\ckp\\src\\vna\\RAVNA_MAIN\\sln\\x64\\Release\\vnaap.pdb",
        "imports": {
          "NDIS": {
            "dll": "NDIS.SYS",
            "imports": [
              {
                "address": "0x14000c010",
                "name": "NdisMSetMiniportAttributes"
              },
              {
                "address": "0x14000c018",
                "name": "NdisMIndicateStatusEx"
              },
              {
                "address": "0x14000c020",
                "name": "NdisRegisterDeviceEx"
              },
              {
                "address": "0x14000c028",
                "name": "NdisMRegisterMiniportDriver"
              },
              {
                "address": "0x14000c030",
                "name": "NdisMDeregisterMiniportDriver"
              },
              {
                "address": "0x14000c038",
                "name": "NdisAllocateNetBufferListPool"
              },
              {
                "address": "0x14000c040",
                "name": "NdisFreeNetBufferListPool"
              },
              {
                "address": "0x14000c048",
                "name": "NdisAllocateNetBufferList"
              },
              {
                "address": "0x14000c050",
                "name": "NdisFreeNetBufferList"
              },
              {
                "address": "0x14000c058",
                "name": "NdisAllocateNetBufferPool"
              },
              {
                "address": "0x14000c060",
                "name": "NdisFreeNetBufferPool"
              },
              {
                "address": "0x14000c068",
                "name": "NdisAllocateNetBuffer"
              },
              {
                "address": "0x14000c070",
                "name": "NdisFreeMdl"
              },
              {
                "address": "0x14000c078",
                "name": "NdisGetDeviceReservedExtension"
              },
              {
                "address": "0x14000c080",
                "name": "NdisReadConfiguration"
              },
              {
                "address": "0x14000c088",
                "name": "NdisWriteConfiguration"
              },
              {
                "address": "0x14000c090",
                "name": "NdisCloseConfiguration"
              },
              {
                "address": "0x14000c098",
                "name": "NdisReadNetworkAddress"
              },
              {
                "address": "0x14000c0a0",
                "name": "NdisFreeMemory"
              },
              {
                "address": "0x14000c0a8",
                "name": "NdisInitializeString"
              },
              {
                "address": "0x14000c0b0",
                "name": "NdisOpenConfigurationEx"
              },
              {
                "address": "0x14000c0b8",
                "name": "NdisAllocateMemoryWithTagPriority"
              },
              {
                "address": "0x14000c0c0",
                "name": "NdisAllocateMdl"
              },
              {
                "address": "0x14000c0c8",
                "name": "NdisRetreatNetBufferDataStart"
              },
              {
                "address": "0x14000c0d0",
                "name": "NdisAdvanceNetBufferDataStart"
              },
              {
                "address": "0x14000c0d8",
                "name": "NdisGetDataBuffer"
              },
              {
                "address": "0x14000c0e0",
                "name": "NdisMSendNetBufferListsComplete"
              },
              {
                "address": "0x14000c0e8",
                "name": "NdisMIndicateReceiveNetBufferLists"
              },
              {
                "address": "0x14000c0f0",
                "name": "NdisDeregisterDeviceEx"
              }
            ]
          },
          "ntoskrnl": {
            "dll": "ntoskrnl.exe",
            "imports": [
              {
                "address": "0x14000c100",
                "name": "ExAllocatePoolWithTagPriority"
              },
              {
                "address": "0x14000c108",
                "name": "ExFreePoolWithTag"
              },
              {
                "address": "0x14000c110",
                "name": "MmGetSystemRoutineAddress"
              },
              {
                "address": "0x14000c118",
                "name": "IoWMIRegistrationControl"
              },
              {
                "address": "0x14000c120",
                "name": "RtlInitUnicodeString"
              },
              {
                "address": "0x14000c128",
                "name": "KeReleaseSpinLock"
              },
              {
                "address": "0x14000c130",
                "name": "ExInterlockedInsertHeadList"
              },
              {
                "address": "0x14000c138",
                "name": "RtlCompareMemory"
              },
              {
                "address": "0x14000c140",
                "name": "KeInitializeDpc"
              },
              {
                "address": "0x14000c148",
                "name": "KeInsertQueueDpc"
              },
              {
                "address": "0x14000c150",
                "name": "KeRemoveQueueDpc"
              },
              {
                "address": "0x14000c158",
                "name": "_vsnprintf"
              },
              {
                "address": "0x14000c160",
                "name": "strncmp"
              },
              {
                "address": "0x14000c168",
                "name": "RtlIntegerToUnicodeString"
              },
              {
                "address": "0x14000c170",
                "name": "RtlAppendUnicodeStringToString"
              },
              {
                "address": "0x14000c178",
                "name": "ExInterlockedInsertTailList"
              },
              {
                "address": "0x14000c180",
                "name": "ExInterlockedRemoveHeadList"
              },
              {
                "address": "0x14000c188",
                "name": "ExQueryDepthSList"
              },
              {
                "address": "0x14000c190",
                "name": "ExpInterlockedPopEntrySList"
              },
              {
                "address": "0x14000c198",
                "name": "ExpInterlockedPushEntrySList"
              },
              {
                "address": "0x14000c1a0",
                "name": "ExInitializeNPagedLookasideList"
              },
              {
                "address": "0x14000c1a8",
                "name": "ExDeleteNPagedLookasideList"
              },
              {
                "address": "0x14000c1b0",
                "name": "MmMapLockedPagesSpecifyCache"
              },
              {
                "address": "0x14000c1b8",
                "name": "RtlUnicodeStringToInteger"
              },
              {
                "address": "0x14000c1c0",
                "name": "RtlEqualUnicodeString"
              },
              {
                "address": "0x14000c1c8",
                "name": "IofCompleteRequest"
              },
              {
                "address": "0x14000c1d0",
                "name": "IoCsqInitialize"
              },
              {
                "address": "0x14000c1d8",
                "name": "IoCsqInsertIrp"
              },
              {
                "address": "0x14000c1e0",
                "name": "IoCsqRemoveNextIrp"
              },
              {
                "address": "0x14000c1e8",
                "name": "ExAllocatePoolWithTag"
              },
              {
                "address": "0x14000c1f0",
                "name": "ProbeForRead"
              },
              {
                "address": "0x14000c1f8",
                "name": "ProbeForWrite"
              },
              {
                "address": "0x14000c200",
                "name": "__C_specific_handler"
              },
              {
                "address": "0x14000c208",
                "name": "ZwClose"
              },
              {
                "address": "0x14000c210",
                "name": "ZwOpenKey"
              },
              {
                "address": "0x14000c218",
                "name": "ZwEnumerateKey"
              },
              {
                "address": "0x14000c220",
                "name": "ZwQueryValueKey"
              },
              {
                "address": "0x14000c228",
                "name": "KeBugCheckEx"
              },
              {
                "address": "0x14000c230",
                "name": "RtlGetVersion"
              },
              {
                "address": "0x14000c238",
                "name": "KeAcquireSpinLockRaiseToDpc"
              }
            ]
          },
          "HAL": {
            "dll": "HAL.dll",
            "imports": [
              {
                "address": "0x14000c000",
                "name": "KeQueryPerformanceCounter"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x00010200",
            "size": "0x00000050"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x00011000",
            "size": "0x00000378"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x0000e000",
            "size": "0x000007c8"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x0000d800",
            "size": "0x000051b0"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x00012000",
            "size": "0x00000034"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x0000c410",
            "size": "0x00000038"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x0000c450",
            "size": "0x00000138"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x0000c000",
            "size": "0x00000248"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000400",
            "virtual_address": "0x00001000",
            "virtual_size": "0x0000a0d8",
            "size_of_data": "0x0000a200",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x68000020",
            "entropy": "6.39"
          },
          {
            "name": ".rdata",
            "raw_address": "0x0000a600",
            "virtual_address": "0x0000c000",
            "virtual_size": "0x00000f88",
            "size_of_data": "0x00001000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x48000040",
            "entropy": "4.86"
          },
          {
            "name": ".data",
            "raw_address": "0x0000b600",
            "virtual_address": "0x0000d000",
            "virtual_size": "0x00000240",
            "size_of_data": "0x00000200",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
            "characteristics_raw": "0xc8000040",
            "entropy": "1.96"
          },
          {
            "name": ".pdata",
            "raw_address": "0x0000b800",
            "virtual_address": "0x0000e000",
            "virtual_size": "0x000007c8",
            "size_of_data": "0x00000800",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x48000040",
            "entropy": "4.38"
          },
          {
            "name": "PAGE",
            "raw_address": "0x0000c000",
            "virtual_address": "0x0000f000",
            "virtual_size": "0x0000055c",
            "size_of_data": "0x00000600",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x60000020",
            "entropy": "5.64"
          },
          {
            "name": "INIT",
            "raw_address": "0x0000c600",
            "virtual_address": "0x00010000",
            "virtual_size": "0x00000b76",
            "size_of_data": "0x00000c00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x62000020",
            "entropy": "5.43"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x0000d200",
            "virtual_address": "0x00011000",
            "virtual_size": "0x00000378",
            "size_of_data": "0x00000400",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "2.91"
          },
          {
            "name": ".reloc",
            "raw_address": "0x0000d600",
            "virtual_address": "0x00012000",
            "virtual_size": "0x00000034",
            "size_of_data": "0x00000200",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "0.63"
          }
        ],
        "overlay": {
          "offset": "0x0000d800",
          "size": "0x000051b0"
        },
        "resources": [
          {
            "name": "RT_VERSION",
            "offset": "0x00011060",
            "size": "0x00000314",
            "filetype": null,
            "language": "LANG_ENGLISH",
            "sublanguage": "SUBLANG_ENGLISH_US",
            "entropy": "3.39"
          }
        ],
        "versioninfo": [
          {
            "name": "CompanyName",
            "value": "Check Point Software Technologies Ltd."
          },
          {
            "name": "FileDescription",
            "value": ""
          },
          {
            "name": "FileVersion",
            "value": "986104112"
          },
          {
            "name": "InternalName",
            "value": ""
          },
          {
            "name": "LegalCopyright",
            "value": "2022 Copyright Check Point Software Technologies Ltd."
          },
          {
            "name": "OriginalFilename",
            "value": ""
          },
          {
            "name": "ProductName",
            "value": "Check Point Virtual Network Adapter"
          },
          {
            "name": "ProductVersion",
            "value": "2.1"
          },
          {
            "name": "Translation",
            "value": "0x0409 0x04e4"
          }
        ],
        "imphash": "c670c756a56ba2782fab4e0129af5f59",
        "timestamp": "2022-07-27 12:52:53",
        "icon": null,
        "icon_hash": null,
        "icon_fuzzy": null,
        "icon_dhash": null,
        "imported_dll_count": 3
      },
      "data": null,
      "strings": [
        "D8y)r{H",
        "KeInsertQueueDpc",
        "VWAVH",
        "220302185123Z",
        "O0M0K",
        "{un'%",
        "A_A^]",
        "VarFileInfo",
        "N0L0J",
        ".idata$6",
        ".rdata",
        "300930183225Z0|1",
        ">NGdx",
        "WAUAVH",
        "|@N3>",
        "FileVersion",
        "OriginalFilename",
        "` AVH",
        "1(0&0",
        "KeAcquireSpinLockRaiseToDpc",
        "D$(VNA_3",
        "220323000000Z",
        "ehttp://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0",
        "StringFileInfo",
        "ExAllocatePoolWithTagPriority",
        " A_A^A\\",
        "ExFreePoolWithTag",
        "DigiCert Assured ID Root CA0",
        "'7D`D1",
        "LegalCopyright",
        ">0<0:",
        "ZwOpenKey",
        "A_A^A]A\\_",
        "SA|X=G",
        "IoCsqInitialize",
        "+Xt@(",
        "20220728101236Z",
        "qvv@!",
        "RELEASE",
        "2022 Copyright Check Point Software Technologies Ltd.",
        "NetCfgInstanceId",
        "UVWATAUAVAWH",
        "ExInitializeNPagedLookasideList",
        ".fffffff",
        "NDIS.SYS",
        "MmGetSystemRoutineAddress",
        "u0s0q",
        "D$0!D$ H",
        "J>f;O",
        "[K]taM?",
        "NdisMRegisterMiniportDriver",
        "D$8!D$ ",
        "D8f4tHL",
        "0A_A^A]A\\_",
        "EtwUnregister",
        "210429000000Z",
        "v=Y]Bv",
        "RtlGetVersion",
        "DigiCert, Inc.1$0\"",
        "D8i)r",
        "2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 ",
        "]J<0\"0i3",
        "/Microsoft Windows Third Party Component CA 20120",
        "AjEB#AZ",
        "=rIQU",
        "0}0i1",
        "6*f(_",
        "DigiCert, Inc.1A0?",
        ".idata$5",
        "(D$ H",
        "pA_A^A]A\\_^]",
        "370322235959Z0c1",
        "Translation",
        "@8i)r",
        "W'X{5",
        "NdisAllocateNetBufferList",
        ".xdata",
        "p%|Yi1$",
        ".rsrc$02",
        "\\$0E3",
        "@A_A^A]A\\_^]",
        "L$@H3",
        "232825+4695810",
        "L$0H3",
        "$Microsoft Ireland Operations Limited1",
        "NdisRetreatNetBufferDataStart",
        ".idata$2",
        "|Lu?c",
        "t=8Q)r8H",
        "VNA_D",
        "0w0c1",
        "chttp://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0",
        "RtlUnicodeStringToInteger",
        "2xJK7*L",
        "`0^0\\",
        "2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA",
        ".idata$3",
        "e/96M",
        "NdisReadConfiguration",
        "FBTDN",
        "311109235959Z0b1",
        "1/0-0",
        "NYxI9h",
        ".data",
        "IoCsqInsertIrp",
        ">http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0",
        "NdisAdvanceNetBufferDataStart",
        "Microsoft Corporation1200",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10",
        "[3U+ *",
        "t%D8i)r",
        "Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z",
        "Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0",
        ":Check Point Internet Securit",
        "t\"D8i)r",
        "D8f4v+Hc",
        "',=?k",
        " %41g",
        "NdisFreeMemory",
        "RtlAppendUnicodeStringToString",
        "DigiCert Trusted Root G40",
        ")Microsoft Root Certificate Authority 20100",
        "KeRemoveQueueDpc",
        "S0Q0O",
        "`INIT",
        "H.data",
        "NdisAllocateNetBuffer",
        "Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0",
        "http://www.checkpoint.com 0",
        "zLkE0",
        "t#D8a)r",
        "q\\Q17",
        "UVWAVAWH",
        "OOjED",
        "www.digicert.com1$0\"",
        "$3A2$",
        "t`D8q)rZD",
        "t$D8a)r",
        "KeInitializeDpc",
        "NdisWriteConfiguration",
        "U0S0Q",
        "ExpInterlockedPushEntrySList",
        "VnaMacAddress",
        "DigiCert, Inc.1;09",
        "2z|[S",
        "Microsoft Time-Stamp Service0",
        "I0G1-0+",
        "4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 ",
        " A_A\\_",
        ".text",
        "ExDeleteNPagedLookasideList",
        "|$2Cu",
        "7@+]y",
        "VS_VERSION_INFO",
        "x ATAVAWH",
        "2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0",
        "NdisReadNetworkAddress",
        "20220729101236Z0w0=",
        "*9Z9N",
        "WATAWH",
        "WATAUAVAWH",
        "IoCsqRemoveNextIrp",
        "cH98unH",
        "A_A^A]A\\_^]",
        "220727125302Z0+",
        "strncmp",
        "IofCompleteRequest",
        "\\??\\vna_ap",
        "http://ocsp.digicert.com0A",
        "NdisAllocateNetBufferListPool",
        "A_A^A\\",
        "oxEQq6",
        "REQUEST",
        "!]_0t",
        "ExInterlockedInsertTailList",
        "!This program cannot be run in DOS mode.",
        "x AVH",
        "NdisDeregisterDeviceEx",
        "(.Y>Y",
        ".text$mn",
        "NdisOpenConfigurationEx",
        "x]~\\6",
        "mqv)#c",
        "t,@8i)r&H",
        "t)D8a)r#H",
        "http://www.digicert.com/CPS0",
        "DECLINE",
        "D$0ubH",
        "ZwQueryValueKey",
        "RtlEqualUnicodeString",
        "NdisFreeNetBufferListPool",
        ".00cfg",
        "0A_A^A]A\\_^]",
        "120418234838Z",
        "230308195806Z0",
        "7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E",
        "L$hH3",
        "1^h~#{",
        "|$(E3",
        "220609000000Z",
        "Washington1",
        "NdisFreeMdl",
        "NdisMIndicateReceiveNetBufferLists",
        "0A_A^_",
        "0;Mh5",
        "Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0",
        "NdisGetDataBuffer",
        "Microsoft Time-Stamp PCA 2010",
        "HWooZ",
        "ProductVersion",
        "Check Point Virtual Network Adapter",
        "270418235838Z0",
        "t\\D8i)rVH",
        "ZwEnumerateKey",
        "RtlInitUnicodeString",
        "A_A^_^]",
        "NdisCloseConfiguration",
        "InternalName",
        "@SVWH",
        "RSDSu",
        ",W5y+",
        "ProductName",
        "NdisMSetMiniportAttributes",
        "}PH.=C",
        "\\$ UVWATAUAVAWH",
        "2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0",
        "Microsoft Corporation1806",
        "tnD8i)rhH",
        "(f*^[0",
        "H9;u<H",
        "OasisAreTheBest",
        "m0k0$",
        ".idata$4",
        "MmMapLockedPagesSpecifyCache",
        "as.,k{n?,",
        "http://ocsp.digicert.com0X",
        ";\\$Pu",
        "Redmond1",
        "?Et<H",
        "IoWMIRegistrationControl",
        "WmiTraceMessage",
        "xSu$W",
        " A_A^A]A\\_H",
        "t$0E3",
        "!hn7!",
        "Check Point Software Technologies Ltd.",
        "http://ocsp.digicert.com0C",
        " Microsoft Operations Puerto Rico1&0$",
        "N@f;A",
        "t^@8i)rX",
        "CompanyName",
        "Microsoft Corporation1;09",
        "-fffffff",
        ">Mp$d",
        "KeReleaseSpinLock",
        "220329000000Z",
        "D8a)r",
        "t<D8y)r6H",
        "`e_nq",
        "h.rdata",
        "b.rsrc",
        "NdisAllocateNetBufferPool",
        "$Rich",
        "040904e4",
        "ExInterlockedInsertHeadList",
        "0A^A]_",
        "230511185123Z0",
        "?Wue\"v",
        "<_wH:",
        "__C_specific_handler",
        "ExQueryDepthSList",
        "&Check Point Software Technologies Ltd.0",
        "Microsoft Corporation1&0$",
        "t\\Device\\vna_ap",
        "+p&}]1",
        " A_A^A]A\\_",
        "e,>~^",
        "t18Q)r,H",
        "WmiQueryTraceInformation",
        "L$ SVWH",
        "t$ WATAUAVAWH",
        "www.digicert.com1!0",
        ".rsrc$01",
        "3http://www.microsoft.com/pkiops/Docs/Repository.htm0",
        "X0V0T",
        "NdisMSendNetBufferListsComplete",
        "<0:08",
        "DISCOVER",
        "/1(0&0$0\"",
        "_vsnprintf",
        "330314235959Z0L1",
        "2Microsoft Windows Hardware Compatibility Publisher0",
        "Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>",
        "t/D8i)r)E",
        "FileDescription",
        "y2XI1",
        "KeQueryPerformanceCounter",
        "/Microsoft Windows Third Party Component CA 2012",
        "O?a~]",
        ".gfids",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4D36E972-E325-11CE-BFC1-08002BE10318}",
        "RtlIntegerToUnicodeString",
        "HA_A^A]A\\_^][H",
        ".text$mn$21",
        "jj@0HK4",
        "B.reloc",
        "ProbeForWrite",
        "http://ocsp.digicert.com0\\",
        "HAL.dll",
        "6666666666666666\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\",
        "Microsoft Time-Stamp Service",
        "0XYZAXAY",
        "NdisGetDeviceReservedExtension",
        "Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0",
        "NdisFreeNetBufferList",
        "s8f#o",
        "unknown",
        "nFQ85|",
        "360428235959Z0i1",
        "0123456789AB",
        "NdisRegisterDeviceEx",
        "NdisAllocateMemoryWithTagPriority",
        "EtwRegisterClassicProvider",
        "fA;FPr",
        "PAGE$s",
        "VNA_H",
        "h\\&40",
        "RtlCompareMemory",
        "D$(VNA_",
        "ntoskrnl.exe",
        "INFORM",
        "fffff",
        "OFFER",
        "NdisMIndicateStatusEx",
        "jfehv",
        "t$ WH",
        "-g<'<V",
        "LCheck Point Software Technologies Ltd",
        "Thales TSS ESN:7880-E390-80141%0#",
        "H'FbDa2",
        " A_A^_",
        "210930182225Z",
        "J>@G_",
        "5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C",
        "NdisMDeregisterMiniportDriver",
        "Microsoft Corporation1)0'",
        "ip(sf",
        "986104112",
        "Microsoft Time-Stamp PCA 20100",
        "70503",
        "F:\\ckp\\src\\vna\\RAVNA_MAIN\\sln\\x64\\Release\\vnaap.pdb",
        "ExInterlockedRemoveHeadList",
        "DigiCert Timestamp 2022 - 20",
        "Tel Aviv-Yafo1/0-",
        "20220727125302Z",
        "NdisAllocateMdl",
        "D8q)r",
        "20220728115703.38Z0",
        "HPAGE",
        "ProbeForRead",
        "k0i0$",
        "ExAllocatePoolWithTag",
        "ZwClose",
        "LJ%`n",
        ".rdata$zzzdbg",
        "D$$VNA_",
        ".pdata",
        "fg:SM",
        "rj^iI",
        "241126235959Z0",
        "tWD8q)rQH",
        "D$(E3",
        "x UAVAWH",
        "NdisInitializeString",
        "(https://www.microsoft.com/en-us/windows 0",
        "&S|9a",
        "`A_A^A]A\\_^]",
        "DigiCert Inc1",
        "Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l",
        "!TkjE",
        "&Check Point Software Technologies Ltd.1/0-",
        "Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S",
        "211125000000Z",
        "8A_A^A]A\\_^][",
        "SUVWATAUAVAWH",
        "0A^_^",
        "ExpInterlockedPopEntrySList",
        "H$4gn",
        ".text$s",
        ".text$mn$00",
        "220310195806Z",
        "NdisFreeNetBufferPool",
        "PsGetVersion",
        "m0k0i",
        "AQAPRQPH",
        "WAVAWH",
        "fffffff",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
        "KeBugCheckEx"
      ],
      "virustotal": {
        "names": [
          "vnaap64.sys.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
          "vnaap.sys",
          "NULL",
          "1037001864.exe",
          "AllWindows.Persistence.Wow64cpu.csv",
          "2m198egI.exe"
        ],
        "scan_id": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
        "md5": "7ba5dec4c51df260bfe3129483167489",
        "sha1": "8ebf1331fdb3462bee54f77faec374697d5cedb9",
        "sha256": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
        "tlsh": "T1FE739E82E55458B9E467C8B5D9B0A617E7B07A061B10D3DF0368C2A5AF033D4BF3936E",
        "positives": 0,
        "total": 76,
        "permalink": "https://www.virustotal.com/api/v3/files/e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
        "scans": {},
        "resource": "e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab",
        "results": [
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "Skyhigh",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "McAfeeD",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "CTX",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "Varist",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Kingsoft",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Xcitium",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "TrellixENS",
            "sig": null
          },
          {
            "vendor": "huorong",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "DeepInstinct",
            "sig": null
          },
          {
            "vendor": "alibabacloud",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          }
        ],
        "detection": ""
      },
      "selfextract": {
        "overlay": {
          "extracted_files": [
            {
              "name": "0c74ccc5a92359a3f987f74428460f2f8645177422a300d9d1c90b0a90646d73",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/0c74ccc5a92359a3f987f74428460f2f8645177422a300d9d1c90b0a90646d73",
              "guest_paths": [
                "overlay"
              ],
              "size": 20912,
              "crc32": "DA6EA081",
              "md5": "30651b591bc382ed154c9e6d78c03b6f",
              "sha1": "f47ecdda7c6e586701978fbb14eb718fe7cabcc9",
              "sha256": "0c74ccc5a92359a3f987f74428460f2f8645177422a300d9d1c90b0a90646d73",
              "sha512": "159c286e70f81506d11d8195c5badad50b895d39097b45eb52cabbdb2a8b37e306d3f5d03a17acfb65802191d8560dc515449c41997eb9cd05933419b891a1d8",
              "rh_hash": null,
              "ssdeep": "384:lZIYinud4i/8E9VFL2UtvSLWRFREkhE3X+R9zus3uDC/:sYinYeEdiGE5Xi9zutC/",
              "type": "data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1BD927EE28E685842DD576DB072E8D9177D3C63C32D80C1E721AAD5540BC27C6EBAC1BE",
              "sha3_384": "0e23c185f7963b8ea948e86c1dd09c1d38ed40b906ca123d2dcf4bb0eb1ad9b6c87a7b544a5876d813606375f0baf969",
              "data": null
            }
          ],
          "extracted_files_time": 0.0017019090009853244,
          "password": ""
        }
      },
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    },
    {
      "name": [
        "vsdatant.inf"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
      ],
      "size": 3729,
      "crc32": "9A800EDD",
      "md5": "d57d27941fca116d8812d272e0b7d7b6",
      "sha1": "1a375df87cde88f64cc93e69b2daba80b5b93360",
      "sha256": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
      "sha512": "eea58e887644d0c45e0693b4b06c6f7f0702b792ce03f2027da2eaecbee9f97cbebc643909e9741fb09d1e75987abba286462c73bd99becf7a15d1d4959a786c",
      "rh_hash": null,
      "ssdeep": "96:JNZIF3J7FpmsE9GXeA/GSvgvIZPmZLPEbD4vD8RqQdTe:JHIF3J7Hm33A/TvpZPmZLPEbD4vD8Rq/",
      "type": "Windows setup INFormation",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1ED71FF04AFA2837068C7E56D77033CA3E66D3480E5DE1584B2CC9459834ED9E79ACF9B",
      "sha3_384": "551e47ae02acca48ce78e0a39471a5cc3e0c9eea9885d20b321454c7f0dfaf5bf69dce0b60539fb4753ae055d7348f27",
      "data": ";-------------------------------------------------------------------------\n; Vsdatant.INF -- NDIS Usermode I/O Driver\n;\n; Copyright (c) Check Point.  All rights reserved.\n;-------------------------------------------------------------------------\n[version]\nSignature       = \"$Windows NT$\"\nClass       = NetService\nClassGUID   = {4D36E974-E325-11CE-BFC1-08002BE10318}\nProvider        = %Ckpt%\nCatalogFile = Vsdatant.cat\nDriverVer = 11/16/2022,14.39.35.110\n\n[Manufacturer]\n%Ckpt%=CKPT,NTx86,NTamd64\n\n[CKPT]\n%Vsdatant_Desc%=Install, MS_NdisLwf\n\n[CKPT.NTx86]\n%Vsdatant_Desc%=Install, MS_NdisLwf\n\n[CKPT.NTamd64]\n%Vsdatant_Desc%=Install, MS_NdisLwf\n\n;-------------------------------------------------------------------------\n; Installation Section\n;-------------------------------------------------------------------------\n[Install]\nAddReg=Inst_Ndi\nCharacteristics=0x40028 ; NCF_LW_FILTER | NCF_NOT_USER_REMOVABLE | NCF_HIDDEN\nNetCfgInstanceId=\"{AC30BFB5-834B-46d2-B912-6CE71684EB2D}\"\nCopyfiles = Vsdatant.copyfiles.sys\n\n[SourceDisksNames]\n1=%Vsdatant_Desc%,\"\",,\n\n[SourceDisksFiles]\nvsdatant.sys=1\n\n[DestinationDirs]\nDefaultDestDir=12\nVsdatant.copyfiles.sys=12\n\n[Vsdatant.copyfiles.sys]\nvsdatant.sys,,,2\n\n\n;-------------------------------------------------------------------------\n; Ndi installation support\n;-------------------------------------------------------------------------\n[Inst_Ndi]\nHKR, Ndi,Service,,\"Vsdatant\"\nHKR, Ndi,CoServices,0x00010000,\"Vsdatant\"\nHKR, Ndi,HelpText,,%Vsdatant_HelpText%\nHKR, Ndi,FilterClass,, compression\nHKR, Ndi,FilterType,0x00010001,0x00000002\nHKR, Ndi\\Interfaces,UpperRange,,\"noupper\"\nHKR, Ndi\\Interfaces,LowerRange,,\"nolower\"\nHKR, Ndi\\Interfaces, FilterMediaTypes,,\"ethernet, wan, wlan, jnprncva, ppip, bluetooth\"\nHKR, Ndi,FilterRunType, 0x00010001, 2 \n\n;-------------------------------------------------------------------------\n; Service installation support\n;-------------------------------------------------------------------------\n[Install.Services]\nAddService=Vsdatant,,Vsdatant_Service_Inst\n\n[Vsdatant_Service_Inst]\nDisplayName     = %Vsdatant_Desc%\nServiceType     = 1 ;SERVICE_KERNEL_DRIVER\nStartType       = 1 ;SERVICE_SYSTEM_START\nErrorControl    = 1 ;SERVICE_ERROR_NORMAL\nServiceBinary   = %12%\\vsdatant.sys\nLoadOrderGroup  = NDIS\nDescription     = %Vsdatant_Desc%\nAddReg          = Common.Params.reg\nDependencies    = TCPIP\n\n[Install.Remove.Services]\nDelService=Vsdatant,0x200\n\n[Common.Params.reg]\n\nHKR, FilterDriverParams\\DriverParam,        ParamDesc,  , \"Driverparam for lwf\"\nHKR, FilterDriverParams\\DriverParam,        default,    , \"5\"\nHKR, FilterDriverParams\\DriverParam,        type,       , \"int\"\n\nHKR, FilterAdapterParams\\AdapterParam,      ParamDesc,  , \"Adapterparam for lwf\"\nHKR, FilterAdapterParams\\AdapterParam,      default,    , \"10\"\nHKR, FilterAdapterParams\\AdapterParam,      type,       , \"int\"\n\nHKR,%RegInstancesSubkeyName%,%RegDefaultInstanceValueName%,0x00000000,%DefaultInstance%\nHKR,%RegInstancesSubkeyName%\"\\\"%Instance1.Name%,%RegAltitudeValueName%,0x00000000,%Instance1.Altitude%\nHKR,%RegInstancesSubkeyName%\"\\\"%Instance1.Name%,%RegFlagsValueName%,0x00010001,%Instance1.Flags%\n\n[Strings]\nCkpt = \"Check Point Software Technologies Ltd.\"\nVsdatant_Desc = \"Zone Alarm Firewall Driver\"\nVsdatant_HelpText = \"Zone Alarm Firewall Driver, Check Point\"\nRegInstancesSubkeyName = \"Instances\"\nRegDefaultInstanceValueName  = \"DefaultInstance\"\nRegAltitudeValueName    = \"Altitude\"\nRegFlagsValueName  = \"Flags\"\n\nDefaultInstance    = \"Vsdatant - Instance\"\nInstance1.Name     = \"Vsdatant - Instance\"\nInstance1.Altitude = \"84400\"\nInstance1.Flags    = 0x0 ; Not used\n\n",
      "strings": [
        "HKR, FilterAdapterParams\\AdapterParam,      default,    , \"10\"",
        "DriverVer = 11/16/2022,14.39.35.110",
        "[Strings]",
        "HKR, Ndi,FilterClass,, compression",
        "[SourceDisksFiles]",
        "vsdatant.sys=1",
        "; Installation Section",
        "Vsdatant_HelpText = \"Zone Alarm Firewall Driver, Check Point\"",
        "RegFlagsValueName  = \"Flags\"",
        "ServiceType     = 1 ;SERVICE_KERNEL_DRIVER",
        "Class       = NetService",
        "Copyfiles = Vsdatant.copyfiles.sys",
        "HKR, FilterDriverParams\\DriverParam,        type,       , \"int\"",
        "ClassGUID   = {4D36E974-E325-11CE-BFC1-08002BE10318}",
        "Dependencies    = TCPIP",
        "[Install.Services]",
        "[SourceDisksNames]",
        "Characteristics=0x40028 ; NCF_LW_FILTER | NCF_NOT_USER_REMOVABLE | NCF_HIDDEN",
        "HKR,%RegInstancesSubkeyName%,%RegDefaultInstanceValueName%,0x00000000,%DefaultInstance%",
        "; Vsdatant.INF -- NDIS Usermode I/O Driver",
        "[CKPT.NTamd64]",
        "[CKPT.NTx86]",
        "HKR, Ndi,FilterRunType, 0x00010001, 2 ",
        "LoadOrderGroup  = NDIS",
        "; Copyright (c) Check Point.  All rights reserved.",
        "HKR, Ndi\\Interfaces,LowerRange,,\"nolower\"",
        "RegDefaultInstanceValueName  = \"DefaultInstance\"",
        "AddReg=Inst_Ndi",
        "DefaultInstance    = \"Vsdatant - Instance\"",
        "ServiceBinary   = %12%\\vsdatant.sys",
        "AddService=Vsdatant,,Vsdatant_Service_Inst",
        "RegAltitudeValueName    = \"Altitude\"",
        "[Common.Params.reg]",
        "DelService=Vsdatant,0x200",
        "[Install]",
        "[DestinationDirs]",
        "HKR, FilterDriverParams\\DriverParam,        ParamDesc,  , \"Driverparam for lwf\"",
        ";-------------------------------------------------------------------------",
        "StartType       = 1 ;SERVICE_SYSTEM_START",
        "; Service installation support",
        "HKR, FilterAdapterParams\\AdapterParam,      type,       , \"int\"",
        "[Inst_Ndi]",
        "HKR, Ndi,HelpText,,%Vsdatant_HelpText%",
        "Provider        = %Ckpt%",
        "RegInstancesSubkeyName = \"Instances\"",
        "HKR, FilterAdapterParams\\AdapterParam,      ParamDesc,  , \"Adapterparam for lwf\"",
        "HKR,%RegInstancesSubkeyName%\"\\\"%Instance1.Name%,%RegFlagsValueName%,0x00010001,%Instance1.Flags%",
        "HKR, Ndi,Service,,\"Vsdatant\"",
        "ErrorControl    = 1 ;SERVICE_ERROR_NORMAL",
        "Instance1.Flags    = 0x0 ; Not used",
        "Ckpt = \"Check Point Software Technologies Ltd.\"",
        "HKR, Ndi\\Interfaces,UpperRange,,\"noupper\"",
        "DefaultDestDir=12",
        "vsdatant.sys,,,2",
        "%Ckpt%=CKPT,NTx86,NTamd64",
        "%Vsdatant_Desc%=Install, MS_NdisLwf",
        "Instance1.Name     = \"Vsdatant - Instance\"",
        "Instance1.Altitude = \"84400\"",
        "Signature       = \"$Windows NT$\"",
        "DisplayName     = %Vsdatant_Desc%",
        "[Vsdatant.copyfiles.sys]",
        "[CKPT]",
        "[Install.Remove.Services]",
        "Vsdatant_Desc = \"Zone Alarm Firewall Driver\"",
        "HKR, Ndi,CoServices,0x00010000,\"Vsdatant\"",
        "HKR, Ndi,FilterType,0x00010001,0x00000002",
        "NetCfgInstanceId=\"{AC30BFB5-834B-46d2-B912-6CE71684EB2D}\"",
        "HKR, FilterDriverParams\\DriverParam,        default,    , \"5\"",
        "[Manufacturer]",
        "[version]",
        "AddReg          = Common.Params.reg",
        "Description     = %Vsdatant_Desc%",
        "HKR, Ndi\\Interfaces, FilterMediaTypes,,\"ethernet, wan, wlan, jnprncva, ppip, bluetooth\"",
        "CatalogFile = Vsdatant.cat",
        "Vsdatant.copyfiles.sys=12",
        "HKR,%RegInstancesSubkeyName%\"\\\"%Instance1.Name%,%RegAltitudeValueName%,0x00000000,%Instance1.Altitude%",
        "1=%Vsdatant_Desc%,\"\",,",
        "; Ndi installation support",
        "[Vsdatant_Service_Inst]"
      ],
      "virustotal": {
        "names": [
          "vsdatant.inf",
          "vsdatant_win7_64.inf.6B6E64A3_4478_4297_9CD9_3D71DBCD974A"
        ],
        "scan_id": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
        "md5": "d57d27941fca116d8812d272e0b7d7b6",
        "sha1": "1a375df87cde88f64cc93e69b2daba80b5b93360",
        "sha256": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
        "tlsh": "T1ED71FF04AFA2837068C7E56D77033CA3E66D3480E5DE1584B2CC9459834ED9E79ACF9B",
        "positives": 0,
        "total": 73,
        "permalink": "https://www.virustotal.com/api/v3/files/5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
        "scans": {},
        "resource": "5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1",
        "results": [
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "FireEye",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Cyren",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "McAfee-GW-Edition",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Xcitium",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "McAfee",
            "sig": null
          },
          {
            "vendor": "MAX",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "BitDefenderTheta",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          }
        ],
        "detection": ""
      },
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    },
    {
      "name": [
        "Vsdatant.cat"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
      ],
      "size": 11513,
      "crc32": "D9A89511",
      "md5": "3fbb5fc32b51b0462dc503a83c6068a7",
      "sha1": "3d2c043cfc05b1c8c55132d5056d698031b736e1",
      "sha256": "672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda",
      "sha512": "61b4a994eae02d28fbde70f1be97284ca5d1ae22b97a55c001054c36f012fd69db868003e4d4e26ed0c23c3caa7cc67ba523f4871e7502316189603720c7ac3c",
      "rh_hash": null,
      "ssdeep": "192:2hdGB5vyM8JCSEtOL7yKnUi8rFWQFaRdt6gqzGslX01k9z3AePptYYQ:wd/u4CFRYnkGER9zFHQ",
      "type": "DER Encoded PKCS#7 Signed Data",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1773219D68A6D4087EDA7AC7053E8F8A37C3C6BC71C40956921DBF7A40D927C5EB1812E",
      "sha3_384": "e0e372d9eb80f53c8f4dfac499ffe5226110becf6d6517261380952266afb3bdb58b35afff29f8d1c8db928fbca3ec19",
      "data": null,
      "strings": [
        "O0M0K",
        "230308195805Z0",
        "MHaTJ",
        "Microsoft Time-Stamp Service",
        "|)MuT9",
        ">http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0",
        "Microsoft Corporation1%0#",
        "ms_ndislwf",
        "}PH.=C",
        "* 9aW",
        "Microsoft Corporation1200",
        "N0L0J",
        "Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z",
        "300930183225Z0|1",
        "E0C1)0'",
        "Microsoft Corporation1806",
        "Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0",
        ">NGdx",
        ")Microsoft Root Certificate Authority 20100",
        "Thales TSS ESN:3E7A-E359-A25D1%0#",
        "1(0&0",
        "Submission I",
        "}B$,N",
        "L{DE351A42-8E59-11D0-8C47-00C04FC295EE",
        "}[{`HW",
        "Declarativ",
        "VistaX86,VistaX64,_v100_X64_Vb",
        "240202190138Z0",
        "ehttp://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0",
        "q\\Q17",
        "Uuy/z",
        "381CB32F6D20B6F332B3BDDB954DE77B450607DE",
        "as.,k{n?,",
        "Redmond1",
        "232825+4695800",
        "U0S0Q",
        "1A375DF87CDE88F64CC93E69B2DABA80B5B93360",
        "CJ}</",
        "OSAtt",
        "vsdatant.sys",
        "-g<'<V",
        "LCheck Point Software Technologies Ltd",
        "20221117102006Z",
        "Microsoft Time-Stamp Service0",
        "xSu$W",
        "1?0=0",
        "%QKZr79",
        "210930182225Z",
        "u0s0q",
        "ip(sf",
        "J>f;O",
        "Microsoft Corporation1;09",
        "Kn1\\ ",
        "81FB57967715BA442BB428C07129C6F06A4D8DD8",
        "vsdatant.inf",
        "Microsoft Time-Stamp PCA 20100",
        "(/pLk",
        "20221118102006Z0t0:",
        "vsdatant_opt.inf",
        "220310195805Z",
        "L{C689AAB8-8E78-11D0-8C47-00C04FC295EE",
        "!]_0t",
        "30045810_14433451436363601_1152921505695563741",
        "221104190138Z",
        "c6fae1d5-37b5-417b-afb5-a4a1af1b9b95",
        "fg:SM",
        " Microsoft Operations Puerto Rico1",
        "BundleI",
        "/Microsoft Windows Third Party Component CA 20120",
        "1,0*0",
        "*;UTm",
        "Microsoft Corporation1&0$",
        "17050",
        "(https://www.microsoft.com/en-us/windows 0",
        "&S|9a",
        "221117072406Z0",
        "120418234838Z",
        "3http://www.microsoft.com/pkiops/Docs/Repository.htm0",
        "X0V0T",
        "Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l",
        "20221117072455.725Z0",
        "!TkjE",
        "p%|Yi1$",
        "2:6.0,2:10.0",
        "yQ{D.2",
        "2Microsoft Windows Hardware Compatibility Publisher0",
        "Washington1",
        "&Qualification Leve",
        "Microsoft Time-Stamp PCA 2010",
        "Microsoft America Operations1&0$",
        "m0k0i",
        "/Microsoft Windows Third Party Component CA 2012",
        "chttp://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0",
        "270418235838Z0",
        "1I'.G",
        "Universa",
        "`0^0\\"
      ],
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    },
    {
      "name": [
        "vnaap.inf"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
      ],
      "size": 4799,
      "crc32": "23BA6B4E",
      "md5": "573345d5fe94093c254fdf95488b66c7",
      "sha1": "638cf92b4d471885e1db95a6bcce402adb91c181",
      "sha256": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
      "sha512": "bb66dd26379c9ab76bddf1550f94aca1c429cf4e680a65fe548050b3f5b5b0fc3c876bac8be46c79a4c9baccdfa65e3767c4a5e5f427f429826b9b155a84553e",
      "rh_hash": null,
      "ssdeep": "48:HkobruhUjdh5sZlexkrrx64NbKkSCNX51vuhFlSh/82HXNptDWNDMV2zLuwuL0Ci:HF/aUp6x6EvoUh/Cm5qDfDIM8uUhGH",
      "type": "Windows setup INFormation",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T16BA173194E424B3731A7E15B63022AC3F327119A2125114C71FE99096BA9F0D937F9FA",
      "sha3_384": "61377681b058685c8046a5026d28cab8517f31bb6179fba8d8879237df14bc41acab821347fccd62394fd2753417bc5e",
      "data": "; Copyright 2004, Check Point Software Technologies, Inc.\n;  vnaap.inf\n;\n; Setup file for Check Point Virtual Network Adapter\n; \n\n[version]\nsignature=\"$Windows NT$\"\t\t\t\t\t\t; INF designed for NT-based operating system (Win2k , WinXP etc.)\nCompatible  = 0\t\t\t\t\t\t\t\t\t; INF is not compitable for windows 9x\nCatalogFile = vnaap.cat \t\t\t\t\t\t; The signed catalog file\nClass=Net\nClassGUID = {4d36e972-e325-11ce-bfc1-08002be10318}\nProvider=%CP%\nDriverVer = 07/27/2022,2.1.3.0\nPnpLockDown = 1\n\n[Manufacturer]\n%CP% = Models,NTamd64,NTx86\n\n[ControlFlags]\n\n[Models.NTx86]\n; DisplayName               Section         hw-id\n; -------------------------------------------------\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\n\n[Models.NTamd64]\n; DisplayName               Section       hw-id\n; -------------------------------------------------\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\n\n;------------------------------------------------------------------------------------------------------------\n; A DestinationDirs section specifies the target destination directory or directories \n; for all copy, delete, and/or rename operations on files referenced by name elsewhere in the INF file. \n;System directory \n;\n;   11   -    This is equivalent to %windir%\\system32 for NT-based systems and \n;\t\t\t\t to %windir%\\system for Windows 9x/Me.\n;   12   -    Drivers directory\n;\t      This is equivalent to %windir%\\system32\\drivers on NT-based platforms and \n;\t\t\t\t to %windir%\\system\\IoSubsys on Windows 9x/Me platforms. \n;  VNA_[ProductName]_CopyFiles - section that list the driver files \n;  VNAInstaller_CopyFiles -  section that list the co-installer file\n;------------------------------------------------------------------------------------------------------------\n\n[DestinationDirs]\nVNA_Apollo_CopyFiles            =12\nVNA_Apollo_Installer_CopyFiles  =11\n\n;-------------------------------------------------------------\n; NT-based OS specific section\n;-------------------------------------------------------------\n\n[VNA_Apollo.ndi]\nAddReg = VNA_common.reg, Product_Apollo.reg ; add registry entries sections\nCopyFiles = VNA_Apollo_CopyFiles            ; copy files sections\nCharacteristics     = 0x1                       ; NCF_VIRTUAL (0x1) ; NCF_NOT_USER_REMOVEABLE (0x20); NCF_HIDDEN (0x8); NCF_HAS_UI (0x80)\n*IfType             = 0x6 ; IF_TYPE_ETHERNET_CSMACD\n*MediaType          = 0x0 ; NdisMedium802_3\n*PhysicalMediaType  = 14 ; NdisPhysicalMedium802_3\n\n;----------------------------------------------------------\n; Service installation stuff - Service entry, log, etc.\n;----------------------------------------------------------\n\n[VNA_Apollo.ndi.Services]\nAddService = vna_ap, 2, VNA_Apollo.Service, VNA_Apollo.EventLog\n\n[VNA_common.reg]\nHKR,,BusNumber,    0, \"0\"\nHKR, Ndi\\Interfaces, UpperRange, 0, \"ndis5\"\nHKR, Ndi\\Interfaces, LowerRange, 0, \"ethernet\"\n\n;------------------\n;   Apollo\n;------------------\n\n\n[VNA_Apollo.Service]\nDisplayName     = %VNA_Apollo.Service.DispName%\nServiceType     = 1 \t\t\t\t;%SERVICE_KERNEL_DRIVER%\nStartType       = 3 \t\t\t\t;%SERVICE_DEMAND_START%\nErrorControl    = 1 \t\t\t\t;%SERVICE_ERROR_NORMAL%\nServiceBinary   = %12%\\vnaap.sys\t\t\t;%12% is %systemroot%\\system32\\drivers directory\nLoadOrderGroup  = NDIS\n\n[VNA_Apollo.EventLog]\nAddReg = VNA_Apollo.AddEventLog.reg\n\n[VNA_Apollo.AddEventLog.reg]\nHKR, , EventMessageFile, 0x00020000, \"%%SystemRoot%%\\System32\\drivers\\vnaap.sys\"\nHKR, , TypesSupported,   0x00010001, 7\n\n;-------------------------------------------------------------\n; General Copy Files Section\n;-------------------------------------------------------------\n[VNA_Apollo_CopyFiles]\n; destination_filename,[source_filename],[,flags]\nvnaap.sys,\n\n;-------------------------------------------------------------\n; Per Product Sections\n;-------------------------------------------------------------\n[Product_Apollo.reg]\nHKR,, OwnerProduct, 0, \"Apollo\"\nHKR, Ndi, Service, 0,\"vna_ap\"\t\n\n;-----------------------------------------------------------\n; Sources\n;-----------------------------------------------------------\n\n;\n; diskid = description[, [tagfile] [, <unused>, subdir]]\n;\n[SourceDisksNames]\n1 = %VNA_disk%,\"\"\n\n;\n; filename_on_source = diskID[, [subdir][, size]]\n;\n[SourceDisksFiles]\nvnaap.sys = 1,,\n\n;-------------------------------------------------------------------------------\n; Localizable Strings\n;-------------------------------------------------------------------------------\n\n[strings]\nCP=\"Check Point\"\nVNA.DeviceDesc.Apollo=\"Check Point Virtual Network Adapter For Endpoint VPN Client\"\nVNA_Apollo.Service.DispName = \"Check Point Virtual Network Adapter - Apollo\"\nVNA_disk = \"Check Point Virtual Network Adapter Install Disk\"\n \n\n",
      "strings": [
        "CP=\"Check Point\"",
        "*IfType             = 0x6 ; IF_TYPE_ETHERNET_CSMACD",
        "; for all copy, delete, and/or rename operations on files referenced by name elsewhere in the INF file. ",
        "HKR, Ndi, Service, 0,\"vna_ap\"",
        "[SourceDisksFiles]",
        " to %windir%\\system for Windows 9x/Me.",
        "[VNA_Apollo.EventLog]",
        "; Sources",
        "1 = %VNA_disk%,\"\"",
        "VNA.DeviceDesc.Apollo=\"Check Point Virtual Network Adapter For Endpoint VPN Client\"",
        "HKR, , EventMessageFile, 0x00020000, \"%%SystemRoot%%\\System32\\drivers\\vnaap.sys\"",
        "      This is equivalent to %windir%\\system32\\drivers on NT-based platforms and ",
        "; NT-based OS specific section",
        "ServiceBinary   = %12%\\vnaap.sys",
        ";-------------------------------------------------------------",
        "[SourceDisksNames]",
        "DisplayName     = %VNA_Apollo.Service.DispName%",
        "AddService = vna_ap, 2, VNA_Apollo.Service, VNA_Apollo.EventLog",
        "AddReg = VNA_common.reg, Product_Apollo.reg ; add registry entries sections",
        "; INF is not compitable for windows 9x",
        "vnaap.sys = 1,,",
        "Compatible  = 0",
        "LoadOrderGroup  = NDIS",
        "; INF designed for NT-based operating system (Win2k , WinXP etc.)",
        ";----------------------------------------------------------",
        "*PhysicalMediaType  = 14 ; NdisPhysicalMedium802_3",
        ";   12   -    Drivers directory",
        "CatalogFile = vnaap.cat ",
        "StartType       = 3 ",
        ";-----------------------------------------------------------",
        "%CP% = Models,NTamd64,NTx86",
        "[Models.NTamd64]",
        "HKR, Ndi\\Interfaces, UpperRange, 0, \"ndis5\"",
        "[VNA_common.reg]",
        "HKR, , TypesSupported,   0x00010001, 7",
        "; A DestinationDirs section specifies the target destination directory or directories ",
        "[VNA_Apollo.Service]",
        "AddReg = VNA_Apollo.AddEventLog.reg",
        "; filename_on_source = diskID[, [subdir][, size]]",
        ";%SERVICE_ERROR_NORMAL%",
        "[VNA_Apollo_CopyFiles]",
        "VNA_disk = \"Check Point Virtual Network Adapter Install Disk\"",
        "vnaap.sys,",
        "ClassGUID = {4d36e972-e325-11ce-bfc1-08002be10318}",
        "; Localizable Strings",
        "[DestinationDirs]",
        ";   Apollo",
        "; Service installation stuff - Service entry, log, etc.",
        "ServiceType     = 1 ",
        "[VNA_Apollo.ndi]",
        ";  vnaap.inf",
        "VNA_Apollo_CopyFiles            =12",
        "HKR,,BusNumber,    0, \"0\"",
        "; -------------------------------------------------",
        ";System directory ",
        "; General Copy Files Section",
        ";------------------------------------------------------------------------------------------------------------",
        "DriverVer = 07/27/2022,2.1.3.0",
        "; DisplayName               Section       hw-id",
        "ErrorControl    = 1 ",
        "%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA",
        "*MediaType          = 0x0 ; NdisMedium802_3",
        "[VNA_Apollo.ndi.Services]",
        ";-------------------------------------------------------------------------------",
        "; Setup file for Check Point Virtual Network Adapter",
        "[ControlFlags]",
        "HKR,, OwnerProduct, 0, \"Apollo\"",
        "HKR, Ndi\\Interfaces, LowerRange, 0, \"ethernet\"",
        "signature=\"$Windows NT$\"",
        "[VNA_Apollo.AddEventLog.reg]",
        "CopyFiles = VNA_Apollo_CopyFiles            ; copy files sections",
        ";------------------",
        ";%SERVICE_KERNEL_DRIVER%",
        "Class=Net",
        ";  VNAInstaller_CopyFiles -  section that list the co-installer file",
        ";  VNA_[ProductName]_CopyFiles - section that list the driver files ",
        ";%SERVICE_DEMAND_START%",
        " to %windir%\\system\\IoSubsys on Windows 9x/Me platforms. ",
        "[Manufacturer]",
        "VNA_Apollo.Service.DispName = \"Check Point Virtual Network Adapter - Apollo\"",
        "[version]",
        ";   11   -    This is equivalent to %windir%\\system32 for NT-based systems and ",
        "[Product_Apollo.reg]",
        "; diskid = description[, [tagfile] [, <unused>, subdir]]",
        "; destination_filename,[source_filename],[,flags]",
        "Provider=%CP%",
        "Characteristics     = 0x1                       ; NCF_VIRTUAL (0x1) ; NCF_NOT_USER_REMOVEABLE (0x20); NCF_HIDDEN (0x8); NCF_HAS_UI (0x80)",
        "VNA_Apollo_Installer_CopyFiles  =11",
        "[strings]",
        ";%12% is %systemroot%\\system32\\drivers directory",
        "[Models.NTx86]",
        "; Copyright 2004, Check Point Software Technologies, Inc.",
        "; The signed catalog file",
        "PnpLockDown = 1",
        "; DisplayName               Section         hw-id",
        "; Per Product Sections"
      ],
      "virustotal": {
        "names": [
          "vnaap.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
          "vnaap64.inf.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
          "vnaap.inf"
        ],
        "scan_id": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
        "md5": "573345d5fe94093c254fdf95488b66c7",
        "sha1": "638cf92b4d471885e1db95a6bcce402adb91c181",
        "sha256": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
        "tlsh": "T16BA173194E424B3731A7E15B63022AC3F327119A2125114C71FE99096BA9F0D937F9FA",
        "positives": 0,
        "total": 76,
        "permalink": "https://www.virustotal.com/api/v3/files/679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
        "scans": {},
        "resource": "679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37",
        "results": [
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "FireEye",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "McAfee",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Cyren",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Ad-Aware",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "Comodo",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "McAfee-GW-Edition",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Kingsoft",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "MAX",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "BitDefenderTheta",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          },
          {
            "vendor": "Cybereason",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          }
        ],
        "detection": ""
      },
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    },
    {
      "name": [
        "vsdatant.sys"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
      ],
      "size": 681072,
      "crc32": "2EB3F1EF",
      "md5": "b7687358512bf036f0910fcfc587a4fa",
      "sha1": "92fba9648b8deb78e8e15436e29e3a78fce91b7b",
      "sha256": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
      "sha512": "197562377f60159d82a0470682ff0cb601b84b59ff40d4fc66cc3b61ef80fb24cf102a3a387d763ec85926c06a57d3fca22673301bde283e2727785116ebfd57",
      "rh_hash": null,
      "ssdeep": "6144:OuYQCl1/oPtzstHFseT/Q3Of6GpruJl7oycFnvuH6pXYPH/ZObSlQj/Efutpp:OuRTtz6lFT96aruJBKFnvuH0IPHxOw6L",
      "type": "PE32+ executable (GUI) x86-64, for MS Windows",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T124E48D47E3A511FDD0ABC1B8CA9B9113F6F1B8091720AAD74760C9153F22FE8A739365",
      "sha3_384": "693eb67bff60f217c7f0c0220e98d619a916769ccc880990ac6c7d6f83356376ae84193e3b49391e7d941601edb780c9",
      "pe": {
        "guest_signers": {
          "aux_sha1": null,
          "aux_timestamp": "Wed Feb 22 18:35:36 2023",
          "aux_valid": true,
          "aux_error": null,
          "aux_error_desc": null,
          "aux_signers": [
            {
              "name": "Certificate Chain 1",
              "Issued to": "DigiCert Trusted Root G4",
              "Issued by": "DigiCert Trusted Root G4",
              "Expires": "Fri Jan 15 15:00:00 2038",
              "SHA1 hash": "ddfb16cd4931c973a2037d3fc83a4d7d775d05e4"
            },
            {
              "name": "Certificate Chain 2",
              "Issued to": "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
              "Issued by": "DigiCert Trusted Root G4",
              "Expires": "Tue Apr 29 02:59:59 2036",
              "SHA1 hash": "7b0f360b775f76c94a12ca48445aa2d2a875701c"
            },
            {
              "name": "Certificate Chain 3",
              "Issued to": "Check Point Software Technologies Ltd.",
              "Issued by": "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
              "Expires": "Wed Nov 27 02:59:59 2024",
              "SHA1 hash": "bc9bf10985e23ba74243b6aca44a147577aeac38"
            },
            {
              "name": "Timestamp Chain 1",
              "Issued to": "GlobalSign",
              "Issued by": "GlobalSign",
              "Expires": "Sun Dec 10 03:00:00 2034",
              "SHA1 hash": "8094640eb5a7a1ca119c1fddd59f810263a7fbd1"
            },
            {
              "name": "Timestamp Chain 2",
              "Issued to": "GlobalSign Timestamping CA - SHA384 - G4",
              "Issued by": "GlobalSign",
              "Expires": "Sun Dec 10 03:00:00 2034",
              "SHA1 hash": "f585500925786f88e721d235240a2452ae3d23f9"
            },
            {
              "name": "Timestamp Chain 3",
              "Issued to": "Globalsign TSA for MS Authenticode Advanced - G4",
              "Issued by": "GlobalSign Timestamping CA - SHA384 - G4",
              "Expires": "Sun May 08 10:41:58 2033",
              "SHA1 hash": "31030e176aa4592eab2c8bade83299fcb5585dcf"
            }
          ]
        },
        "digital_signers": [],
        "imagebase": "0x140000000",
        "entrypoint": "0x0003e5f0",
        "ep_bytes": "4055535657415441554157488dac24e0",
        "peid_signatures": null,
        "reported_checksum": "0x000ac881",
        "actual_checksum": "0x000ac881",
        "osversion": "6.1",
        "pdbpath": "F:\\ckp\\src\\EP_Vsdata\\E86_90_EWDK\\Sys\\Release\\x64\\Vsdatant.pdb",
        "imports": {
          "CCORE64": {
            "dll": "CCORE64.SYS",
            "imports": [
              {
                "address": "0x140082000",
                "name": "cryptGetFunctionList"
              }
            ]
          },
          "fwpkclnt": {
            "dll": "fwpkclnt.sys",
            "imports": [
              {
                "address": "0x1400821b0",
                "name": "FwpmEngineClose0"
              },
              {
                "address": "0x1400821b8",
                "name": "FwpmTransactionBegin0"
              },
              {
                "address": "0x1400821c0",
                "name": "FwpmBfeStateUnsubscribeChanges0"
              },
              {
                "address": "0x1400821c8",
                "name": "FwpmBfeStateSubscribeChanges0"
              },
              {
                "address": "0x1400821d0",
                "name": "FwpmTransactionCommit0"
              },
              {
                "address": "0x1400821d8",
                "name": "FwpmTransactionAbort0"
              },
              {
                "address": "0x1400821e0",
                "name": "FwpmProviderAdd0"
              },
              {
                "address": "0x1400821e8",
                "name": "FwpmSubLayerAdd0"
              },
              {
                "address": "0x1400821f0",
                "name": "FwpmSubLayerDeleteByKey0"
              },
              {
                "address": "0x1400821f8",
                "name": "FwpmCalloutAdd0"
              },
              {
                "address": "0x140082200",
                "name": "FwpmCalloutDeleteById0"
              },
              {
                "address": "0x140082208",
                "name": "FwpmFilterAdd0"
              },
              {
                "address": "0x140082210",
                "name": "FwpmFilterDeleteById0"
              },
              {
                "address": "0x140082218",
                "name": "FwpsCalloutRegister0"
              },
              {
                "address": "0x140082220",
                "name": "FwpsCalloutRegister1"
              },
              {
                "address": "0x140082228",
                "name": "FwpsCalloutUnregisterById0"
              },
              {
                "address": "0x140082230",
                "name": "FwpsFlowAssociateContext0"
              },
              {
                "address": "0x140082238",
                "name": "FwpsCloneStreamData0"
              },
              {
                "address": "0x140082240",
                "name": "FwpsCopyStreamDataToBuffer0"
              },
              {
                "address": "0x140082248",
                "name": "FwpsStreamContinue0"
              },
              {
                "address": "0x140082250",
                "name": "FwpsStreamInjectAsync0"
              },
              {
                "address": "0x140082258",
                "name": "FwpsQueryPacketInjectionState0"
              },
              {
                "address": "0x140082260",
                "name": "FwpsDereferenceNetBufferList0"
              },
              {
                "address": "0x140082268",
                "name": "FwpsReferenceNetBufferList0"
              },
              {
                "address": "0x140082270",
                "name": "FwpsInjectTransportReceiveAsync0"
              },
              {
                "address": "0x140082278",
                "name": "FwpsInjectTransportSendAsync0"
              },
              {
                "address": "0x140082280",
                "name": "FwpsFreeCloneNetBufferList0"
              },
              {
                "address": "0x140082288",
                "name": "FwpsAllocateCloneNetBufferList0"
              },
              {
                "address": "0x140082290",
                "name": "FwpsFreeNetBufferList0"
              },
              {
                "address": "0x140082298",
                "name": "FwpsAllocateNetBufferAndNetBufferList0"
              },
              {
                "address": "0x1400822a0",
                "name": "FwpsInjectionHandleDestroy0"
              },
              {
                "address": "0x1400822a8",
                "name": "FwpsInjectionHandleCreate0"
              },
              {
                "address": "0x1400822b0",
                "name": "FwpsClassifyOptionSet0"
              },
              {
                "address": "0x1400822b8",
                "name": "FwpsCompleteClassify0"
              },
              {
                "address": "0x1400822c0",
                "name": "FwpsPendClassify0"
              },
              {
                "address": "0x1400822c8",
                "name": "FwpsReleaseClassifyHandle0"
              },
              {
                "address": "0x1400822d0",
                "name": "FwpsAcquireClassifyHandle0"
              },
              {
                "address": "0x1400822d8",
                "name": "FwpsCompleteOperation0"
              },
              {
                "address": "0x1400822e0",
                "name": "FwpsPendOperation0"
              },
              {
                "address": "0x1400822e8",
                "name": "FwpmEngineOpen0"
              },
              {
                "address": "0x1400822f0",
                "name": "FwpsFlowRemoveContext0"
              },
              {
                "address": "0x1400822f8",
                "name": "FwpmBfeStateGet0"
              }
            ]
          },
          "FLTMGR": {
            "dll": "FLTMGR.SYS",
            "imports": [
              {
                "address": "0x140082010",
                "name": "FltUnregisterFilter"
              },
              {
                "address": "0x140082018",
                "name": "FltStartFiltering"
              },
              {
                "address": "0x140082020",
                "name": "FltParseFileName"
              },
              {
                "address": "0x140082028",
                "name": "FltGetFileNameInformationUnsafe"
              },
              {
                "address": "0x140082030",
                "name": "FltGetEcpListFromCallbackData"
              },
              {
                "address": "0x140082038",
                "name": "FltFindExtraCreateParameter"
              },
              {
                "address": "0x140082040",
                "name": "FltQueueGenericWorkItem"
              },
              {
                "address": "0x140082048",
                "name": "FltFreeGenericWorkItem"
              },
              {
                "address": "0x140082050",
                "name": "FltAllocateGenericWorkItem"
              },
              {
                "address": "0x140082058",
                "name": "FltQueryInformationFile"
              },
              {
                "address": "0x140082060",
                "name": "FltIsDirectory"
              },
              {
                "address": "0x140082068",
                "name": "FltGetDestinationFileNameInformation"
              },
              {
                "address": "0x140082070",
                "name": "FltParseFileNameInformation"
              },
              {
                "address": "0x140082078",
                "name": "FltReleaseFileNameInformation"
              },
              {
                "address": "0x140082080",
                "name": "FltGetFileNameInformation"
              },
              {
                "address": "0x140082088",
                "name": "FltCompletePendedPreOperation"
              },
              {
                "address": "0x140082090",
                "name": "FltRegisterFilter"
              }
            ]
          },
          "ntoskrnl": {
            "dll": "ntoskrnl.exe",
            "imports": [
              {
                "address": "0x140082308",
                "name": "KeDelayExecutionThread"
              },
              {
                "address": "0x140082310",
                "name": "KeSetPriorityThread"
              },
              {
                "address": "0x140082318",
                "name": "KeWaitForMultipleObjects"
              },
              {
                "address": "0x140082320",
                "name": "KeWaitForSingleObject"
              },
              {
                "address": "0x140082328",
                "name": "ExInterlockedInsertTailList"
              },
              {
                "address": "0x140082330",
                "name": "ExInterlockedRemoveHeadList"
              },
              {
                "address": "0x140082338",
                "name": "ExQueryDepthSList"
              },
              {
                "address": "0x140082340",
                "name": "ExpInterlockedPopEntrySList"
              },
              {
                "address": "0x140082348",
                "name": "ExpInterlockedPushEntrySList"
              },
              {
                "address": "0x140082350",
                "name": "ExInitializeNPagedLookasideList"
              },
              {
                "address": "0x140082358",
                "name": "ExDeleteNPagedLookasideList"
              },
              {
                "address": "0x140082360",
                "name": "ExQueueWorkItem"
              },
              {
                "address": "0x140082368",
                "name": "PsCreateSystemThread"
              },
              {
                "address": "0x140082370",
                "name": "PsTerminateSystemThread"
              },
              {
                "address": "0x140082378",
                "name": "PsGetVersion"
              },
              {
                "address": "0x140082380",
                "name": "ObReferenceObjectByHandle"
              },
              {
                "address": "0x140082388",
                "name": "ZwCreateFile"
              },
              {
                "address": "0x140082390",
                "name": "ZwSetInformationFile"
              },
              {
                "address": "0x140082398",
                "name": "ZwWriteFile"
              },
              {
                "address": "0x1400823a0",
                "name": "ZwClose"
              },
              {
                "address": "0x1400823a8",
                "name": "KePulseEvent"
              },
              {
                "address": "0x1400823b0",
                "name": "_vsnwprintf"
              },
              {
                "address": "0x1400823b8",
                "name": "ZwQuerySystemInformation"
              },
              {
                "address": "0x1400823c0",
                "name": "isdigit"
              },
              {
                "address": "0x1400823c8",
                "name": "RtlInitAnsiString"
              },
              {
                "address": "0x1400823d0",
                "name": "RtlAnsiStringToUnicodeString"
              },
              {
                "address": "0x1400823d8",
                "name": "ZwReadFile"
              },
              {
                "address": "0x1400823e0",
                "name": "RtlUnicodeStringToAnsiString"
              },
              {
                "address": "0x1400823e8",
                "name": "RtlFreeAnsiString"
              },
              {
                "address": "0x1400823f0",
                "name": "IoAllocateErrorLogEntry"
              },
              {
                "address": "0x1400823f8",
                "name": "IoGetCurrentProcess"
              },
              {
                "address": "0x140082400",
                "name": "IoWriteErrorLogEntry"
              },
              {
                "address": "0x140082408",
                "name": "ObRegisterCallbacks"
              },
              {
                "address": "0x140082410",
                "name": "ObUnRegisterCallbacks"
              },
              {
                "address": "0x140082418",
                "name": "PsSetCreateProcessNotifyRoutineEx"
              },
              {
                "address": "0x140082420",
                "name": "PsGetProcessId"
              },
              {
                "address": "0x140082428",
                "name": "PsLookupProcessByProcessId"
              },
              {
                "address": "0x140082430",
                "name": "ObOpenObjectByPointer"
              },
              {
                "address": "0x140082438",
                "name": "ZwOpenProcessTokenEx"
              },
              {
                "address": "0x140082440",
                "name": "ZwOpenThreadTokenEx"
              },
              {
                "address": "0x140082448",
                "name": "ZwQueryInformationToken"
              },
              {
                "address": "0x140082450",
                "name": "PsIsProtectedProcess"
              },
              {
                "address": "0x140082458",
                "name": "ZwQueryInformationProcess"
              },
              {
                "address": "0x140082460",
                "name": "PsProcessType"
              },
              {
                "address": "0x140082468",
                "name": "PsThreadType"
              },
              {
                "address": "0x140082470",
                "name": "RtlAppendUnicodeToString"
              },
              {
                "address": "0x140082478",
                "name": "RtlTimeToTimeFields"
              },
              {
                "address": "0x140082480",
                "name": "ExSystemTimeToLocalTime"
              },
              {
                "address": "0x140082488",
                "name": "ExAcquireSpinLockShared"
              },
              {
                "address": "0x140082490",
                "name": "ExReleaseSpinLockShared"
              },
              {
                "address": "0x140082498",
                "name": "ExAcquireSpinLockExclusive"
              },
              {
                "address": "0x1400824a0",
                "name": "ExReleaseSpinLockExclusive"
              },
              {
                "address": "0x1400824a8",
                "name": "isspace"
              },
              {
                "address": "0x1400824b0",
                "name": "_stricmp"
              },
              {
                "address": "0x1400824b8",
                "name": "vsprintf"
              },
              {
                "address": "0x1400824c0",
                "name": "wcsncmp"
              },
              {
                "address": "0x1400824c8",
                "name": "_snwprintf"
              },
              {
                "address": "0x1400824d0",
                "name": "ZwOpenFile"
              },
              {
                "address": "0x1400824d8",
                "name": "ZwQueryDirectoryFile"
              },
              {
                "address": "0x1400824e0",
                "name": "NtWaitForSingleObject"
              },
              {
                "address": "0x1400824e8",
                "name": "RtlConvertSidToUnicodeString"
              },
              {
                "address": "0x1400824f0",
                "name": "SeQueryInformationToken"
              },
              {
                "address": "0x1400824f8",
                "name": "PsReferencePrimaryToken"
              },
              {
                "address": "0x140082500",
                "name": "PsDereferencePrimaryToken"
              },
              {
                "address": "0x140082508",
                "name": "KeInitializeMutex"
              },
              {
                "address": "0x140082510",
                "name": "RtlCheckRegistryKey"
              },
              {
                "address": "0x140082518",
                "name": "KeSetEvent"
              },
              {
                "address": "0x140082520",
                "name": "CmUnRegisterCallback"
              },
              {
                "address": "0x140082528",
                "name": "CmRegisterCallbackEx"
              },
              {
                "address": "0x140082530",
                "name": "ZwCreateKey"
              },
              {
                "address": "0x140082538",
                "name": "ZwQueryValueKey"
              },
              {
                "address": "0x140082540",
                "name": "ZwSetValueKey"
              },
              {
                "address": "0x140082548",
                "name": "RtlUpcaseUnicodeString"
              },
              {
                "address": "0x140082550",
                "name": "ExInitializePagedLookasideList"
              },
              {
                "address": "0x140082558",
                "name": "ExDeletePagedLookasideList"
              },
              {
                "address": "0x140082560",
                "name": "CmSetCallbackObjectContext"
              },
              {
                "address": "0x140082568",
                "name": "ObQueryNameString"
              },
              {
                "address": "0x140082570",
                "name": "ZwSaveKey"
              },
              {
                "address": "0x140082578",
                "name": "ZwRestoreKey"
              },
              {
                "address": "0x140082580",
                "name": "towupper"
              },
              {
                "address": "0x140082588",
                "name": "wcsncpy"
              },
              {
                "address": "0x140082590",
                "name": "RtlCompareString"
              },
              {
                "address": "0x140082598",
                "name": "strchr"
              },
              {
                "address": "0x1400825a0",
                "name": "RtlQueryRegistryValues"
              },
              {
                "address": "0x1400825a8",
                "name": "RtlxUnicodeStringToAnsiSize"
              },
              {
                "address": "0x1400825b0",
                "name": "RtlxAnsiStringToUnicodeSize"
              },
              {
                "address": "0x1400825b8",
                "name": "RtlGetVersion"
              },
              {
                "address": "0x1400825c0",
                "name": "KeClearEvent"
              },
              {
                "address": "0x1400825c8",
                "name": "KeQueryTimeIncrement"
              },
              {
                "address": "0x1400825d0",
                "name": "ProbeForRead"
              },
              {
                "address": "0x1400825d8",
                "name": "MmGetSystemRoutineAddress"
              },
              {
                "address": "0x1400825e0",
                "name": "IoAttachDevice"
              },
              {
                "address": "0x1400825e8",
                "name": "IofCallDriver"
              },
              {
                "address": "0x1400825f0",
                "name": "IofCompleteRequest"
              },
              {
                "address": "0x1400825f8",
                "name": "IoCreateNotificationEvent"
              },
              {
                "address": "0x140082600",
                "name": "IoCreateSymbolicLink"
              },
              {
                "address": "0x140082608",
                "name": "IoDeleteDevice"
              },
              {
                "address": "0x140082610",
                "name": "IoDeleteSymbolicLink"
              },
              {
                "address": "0x140082618",
                "name": "IoDetachDevice"
              },
              {
                "address": "0x140082620",
                "name": "IoGetRelatedDeviceObject"
              },
              {
                "address": "0x140082628",
                "name": "IoRegisterShutdownNotification"
              },
              {
                "address": "0x140082630",
                "name": "IoUnregisterShutdownNotification"
              },
              {
                "address": "0x140082638",
                "name": "IoWMIRegistrationControl"
              },
              {
                "address": "0x140082640",
                "name": "ZwQueryInformationFile"
              },
              {
                "address": "0x140082648",
                "name": "ZwOpenKey"
              },
              {
                "address": "0x140082650",
                "name": "ZwOpenSymbolicLinkObject"
              },
              {
                "address": "0x140082658",
                "name": "ZwQuerySymbolicLinkObject"
              },
              {
                "address": "0x140082660",
                "name": "RtlUpperChar"
              },
              {
                "address": "0x140082668",
                "name": "MmIsAddressValid"
              },
              {
                "address": "0x140082670",
                "name": "PsSetCreateThreadNotifyRoutine"
              },
              {
                "address": "0x140082678",
                "name": "PsRemoveCreateThreadNotifyRoutine"
              },
              {
                "address": "0x140082680",
                "name": "PsRemoveLoadImageNotifyRoutine"
              },
              {
                "address": "0x140082688",
                "name": "IoAttachDeviceByPointer"
              },
              {
                "address": "0x140082690",
                "name": "IoVolumeDeviceToDosName"
              },
              {
                "address": "0x140082698",
                "name": "ZwOpenProcess"
              },
              {
                "address": "0x1400826a0",
                "name": "ObIsKernelHandle"
              },
              {
                "address": "0x1400826a8",
                "name": "ObReferenceObjectByName"
              },
              {
                "address": "0x1400826b0",
                "name": "IoFileObjectType"
              },
              {
                "address": "0x1400826b8",
                "name": "MmUserProbeAddress"
              },
              {
                "address": "0x1400826c0",
                "name": "IoDriverObjectType"
              },
              {
                "address": "0x1400826c8",
                "name": "ExAcquireFastMutex"
              },
              {
                "address": "0x1400826d0",
                "name": "ExReleaseFastMutex"
              },
              {
                "address": "0x1400826d8",
                "name": "PsLookupThreadByThreadId"
              },
              {
                "address": "0x1400826e0",
                "name": "MmHighestUserAddress"
              },
              {
                "address": "0x1400826e8",
                "name": "strncpy"
              },
              {
                "address": "0x1400826f0",
                "name": "RtlUpcaseUnicodeChar"
              },
              {
                "address": "0x1400826f8",
                "name": "PsIsThreadTerminating"
              },
              {
                "address": "0x140082700",
                "name": "ZwCreateEvent"
              },
              {
                "address": "0x140082708",
                "name": "ZwWaitForSingleObject"
              },
              {
                "address": "0x140082710",
                "name": "_wcsicmp"
              },
              {
                "address": "0x140082718",
                "name": "KeAcquireSpinLockAtDpcLevel"
              },
              {
                "address": "0x140082720",
                "name": "KeReleaseSpinLockFromDpcLevel"
              },
              {
                "address": "0x140082728",
                "name": "strcmp"
              },
              {
                "address": "0x140082730",
                "name": "strncat"
              },
              {
                "address": "0x140082738",
                "name": "KeStackAttachProcess"
              },
              {
                "address": "0x140082740",
                "name": "KeUnstackDetachProcess"
              },
              {
                "address": "0x140082748",
                "name": "ZwDeleteValueKey"
              },
              {
                "address": "0x140082750",
                "name": "ZwEnumerateKey"
              },
              {
                "address": "0x140082758",
                "name": "ZwQueryKey"
              },
              {
                "address": "0x140082760",
                "name": "_strnicmp"
              },
              {
                "address": "0x140082768",
                "name": "strstr"
              },
              {
                "address": "0x140082770",
                "name": "RtlWriteRegistryValue"
              },
              {
                "address": "0x140082778",
                "name": "KeReadStateEvent"
              },
              {
                "address": "0x140082780",
                "name": "ExRaiseStatus"
              },
              {
                "address": "0x140082788",
                "name": "ZwLoadDriver"
              },
              {
                "address": "0x140082790",
                "name": "ZwUnloadDriver"
              },
              {
                "address": "0x140082798",
                "name": "MmIsNonPagedSystemAddressValid"
              },
              {
                "address": "0x1400827a0",
                "name": "ZwSetSystemInformation"
              },
              {
                "address": "0x1400827a8",
                "name": "PsGetProcessInheritedFromUniqueProcessId"
              },
              {
                "address": "0x1400827b0",
                "name": "PsGetProcessPeb"
              },
              {
                "address": "0x1400827b8",
                "name": "KeAcquireInStackQueuedSpinLock"
              },
              {
                "address": "0x1400827c0",
                "name": "KeReleaseInStackQueuedSpinLock"
              },
              {
                "address": "0x1400827c8",
                "name": "isprint"
              },
              {
                "address": "0x1400827d0",
                "name": "MmBuildMdlForNonPagedPool"
              },
              {
                "address": "0x1400827d8",
                "name": "IoAllocateWorkItem"
              },
              {
                "address": "0x1400827e0",
                "name": "IoFreeWorkItem"
              },
              {
                "address": "0x1400827e8",
                "name": "IoQueueWorkItemEx"
              },
              {
                "address": "0x1400827f0",
                "name": "KeExpandKernelStackAndCalloutEx"
              },
              {
                "address": "0x1400827f8",
                "name": "PsSetCreateProcessNotifyRoutine"
              },
              {
                "address": "0x140082800",
                "name": "RtlCaptureStackBackTrace"
              },
              {
                "address": "0x140082808",
                "name": "KeInitializeEvent"
              },
              {
                "address": "0x140082810",
                "name": "RtlCopyUnicodeString"
              },
              {
                "address": "0x140082818",
                "name": "RtlInitUnicodeString"
              },
              {
                "address": "0x140082820",
                "name": "RtlCreateUnicodeString"
              },
              {
                "address": "0x140082828",
                "name": "RtlFreeUnicodeString"
              },
              {
                "address": "0x140082830",
                "name": "_wcsnicmp"
              },
              {
                "address": "0x140082838",
                "name": "PsGetThreadProcessId"
              },
              {
                "address": "0x140082840",
                "name": "PsGetThreadId"
              },
              {
                "address": "0x140082848",
                "name": "ObfDereferenceObject"
              },
              {
                "address": "0x140082850",
                "name": "ObfReferenceObject"
              },
              {
                "address": "0x140082858",
                "name": "ExGetPreviousMode"
              },
              {
                "address": "0x140082860",
                "name": "KeAreApcsDisabled"
              },
              {
                "address": "0x140082868",
                "name": "__C_specific_handler"
              },
              {
                "address": "0x140082870",
                "name": "sprintf"
              },
              {
                "address": "0x140082878",
                "name": "_vsnprintf"
              },
              {
                "address": "0x140082880",
                "name": "_snprintf"
              },
              {
                "address": "0x140082888",
                "name": "IoFreeMdl"
              },
              {
                "address": "0x140082890",
                "name": "IoAllocateMdl"
              },
              {
                "address": "0x140082898",
                "name": "MmUnmapLockedPages"
              },
              {
                "address": "0x1400828a0",
                "name": "MmMapLockedPagesSpecifyCache"
              },
              {
                "address": "0x1400828a8",
                "name": "MmUnlockPages"
              },
              {
                "address": "0x1400828b0",
                "name": "MmProbeAndLockPages"
              },
              {
                "address": "0x1400828b8",
                "name": "KeReleaseSpinLock"
              },
              {
                "address": "0x1400828c0",
                "name": "KeAcquireSpinLockRaiseToDpc"
              },
              {
                "address": "0x1400828c8",
                "name": "DbgPrint"
              },
              {
                "address": "0x1400828d0",
                "name": "PsGetCurrentThreadId"
              },
              {
                "address": "0x1400828d8",
                "name": "PsGetCurrentProcessId"
              },
              {
                "address": "0x1400828e0",
                "name": "RtlEqualUnicodeString"
              },
              {
                "address": "0x1400828e8",
                "name": "ExDeleteResourceLite"
              },
              {
                "address": "0x1400828f0",
                "name": "ExReleaseResourceAndLeaveCriticalRegion"
              },
              {
                "address": "0x1400828f8",
                "name": "ExEnterCriticalRegionAndAcquireResourceExclusive"
              },
              {
                "address": "0x140082900",
                "name": "ExEnterCriticalRegionAndAcquireResourceShared"
              },
              {
                "address": "0x140082908",
                "name": "ExInitializeResourceLite"
              },
              {
                "address": "0x140082910",
                "name": "ExFreePoolWithTag"
              },
              {
                "address": "0x140082918",
                "name": "ExAllocatePoolWithTag"
              },
              {
                "address": "0x140082920",
                "name": "RtlCompareMemory"
              },
              {
                "address": "0x140082928",
                "name": "KeReleaseMutex"
              },
              {
                "address": "0x140082930",
                "name": "RtlAppendUnicodeStringToString"
              },
              {
                "address": "0x140082938",
                "name": "ZwSetSecurityObject"
              },
              {
                "address": "0x140082940",
                "name": "IoDeviceObjectType"
              },
              {
                "address": "0x140082948",
                "name": "IoCreateDevice"
              },
              {
                "address": "0x140082950",
                "name": "RtlGetDaclSecurityDescriptor"
              },
              {
                "address": "0x140082958",
                "name": "RtlGetGroupSecurityDescriptor"
              },
              {
                "address": "0x140082960",
                "name": "RtlGetOwnerSecurityDescriptor"
              },
              {
                "address": "0x140082968",
                "name": "RtlGetSaclSecurityDescriptor"
              },
              {
                "address": "0x140082970",
                "name": "SeCaptureSecurityDescriptor"
              },
              {
                "address": "0x140082978",
                "name": "RtlLengthSecurityDescriptor"
              },
              {
                "address": "0x140082980",
                "name": "SeExports"
              },
              {
                "address": "0x140082988",
                "name": "RtlCreateSecurityDescriptor"
              },
              {
                "address": "0x140082990",
                "name": "wcschr"
              },
              {
                "address": "0x140082998",
                "name": "RtlAbsoluteToSelfRelativeSD"
              },
              {
                "address": "0x1400829a0",
                "name": "RtlAddAccessAllowedAce"
              },
              {
                "address": "0x1400829a8",
                "name": "RtlLengthSid"
              },
              {
                "address": "0x1400829b0",
                "name": "IoIsWdmVersionAvailable"
              },
              {
                "address": "0x1400829b8",
                "name": "RtlSetDaclSecurityDescriptor"
              },
              {
                "address": "0x1400829c0",
                "name": "ZwTerminateProcess"
              },
              {
                "address": "0x1400829c8",
                "name": "KeBugCheckEx"
              }
            ]
          },
          "NDIS": {
            "dll": "NDIS.SYS",
            "imports": [
              {
                "address": "0x1400820b0",
                "name": "NdisFreeNetBufferList"
              },
              {
                "address": "0x1400820b8",
                "name": "NdisAllocateNetBufferAndNetBufferList"
              },
              {
                "address": "0x1400820c0",
                "name": "NdisFSendNetBufferLists"
              },
              {
                "address": "0x1400820c8",
                "name": "NdisFreeMemory"
              },
              {
                "address": "0x1400820d0",
                "name": "NdisAllocateMemoryWithTagPriority"
              },
              {
                "address": "0x1400820d8",
                "name": "NdisAllocateNetBufferListPool"
              },
              {
                "address": "0x1400820e0",
                "name": "NdisMSleep"
              },
              {
                "address": "0x1400820e8",
                "name": "NdisFRegisterFilterDriver"
              },
              {
                "address": "0x1400820f0",
                "name": "NdisFDeregisterFilterDriver"
              },
              {
                "address": "0x1400820f8",
                "name": "NdisFSetAttributes"
              },
              {
                "address": "0x140082100",
                "name": "NdisFReturnNetBufferLists"
              },
              {
                "address": "0x140082108",
                "name": "NdisFSendNetBufferListsComplete"
              },
              {
                "address": "0x140082110",
                "name": "NdisFIndicateReceiveNetBufferLists"
              },
              {
                "address": "0x140082118",
                "name": "NdisFIndicateStatus"
              },
              {
                "address": "0x140082120",
                "name": "NdisAllocateBufferPool"
              },
              {
                "address": "0x140082128",
                "name": "NdisFreeBufferPool"
              },
              {
                "address": "0x140082130",
                "name": "NdisAllocateBuffer"
              },
              {
                "address": "0x140082138",
                "name": "NdisAllocatePacketPool"
              },
              {
                "address": "0x140082140",
                "name": "NdisFreePacketPool"
              },
              {
                "address": "0x140082148",
                "name": "NdisFreePacket"
              },
              {
                "address": "0x140082150",
                "name": "NdisAllocatePacket"
              },
              {
                "address": "0x140082158",
                "name": "NdisAdvanceNetBufferDataStart"
              },
              {
                "address": "0x140082160",
                "name": "NdisUnchainBufferAtFront"
              },
              {
                "address": "0x140082168",
                "name": "NdisAllocateMemory"
              },
              {
                "address": "0x140082170",
                "name": "NdisGetVersion"
              },
              {
                "address": "0x140082178",
                "name": "NdisDeregisterProtocol"
              },
              {
                "address": "0x140082180",
                "name": "NdisRegisterProtocol"
              },
              {
                "address": "0x140082188",
                "name": "NdisAllocateGenericObject"
              },
              {
                "address": "0x140082190",
                "name": "NdisFreeGenericObject"
              },
              {
                "address": "0x140082198",
                "name": "NdisFreeNetBufferListPool"
              },
              {
                "address": "0x1400821a0",
                "name": "NdisRetreatNetBufferDataStart"
              }
            ]
          },
          "HAL": {
            "dll": "HAL.dll",
            "imports": [
              {
                "address": "0x1400820a0",
                "name": "KeQueryPerformanceCounter"
              }
            ]
          }
        },
        "exported_dll_name": null,
        "exports": [],
        "dirents": [
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
            "virtual_address": "0x000bf4e8",
            "size": "0x0000008c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
            "virtual_address": "0x000c2000",
            "size": "0x000003d0"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
            "virtual_address": "0x000b5000",
            "size": "0x00004f8c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
            "virtual_address": "0x0009d000",
            "size": "0x00009470"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
            "virtual_address": "0x000c3000",
            "size": "0x0000052c"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
            "virtual_address": "0x00085ab0",
            "size": "0x00000054"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_TLS",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
            "virtual_address": "0x00085b10",
            "size": "0x00000118"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_IAT",
            "virtual_address": "0x00082000",
            "size": "0x000009d8"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          },
          {
            "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
            "virtual_address": "0x00000000",
            "size": "0x00000000"
          }
        ],
        "sections": [
          {
            "name": ".text",
            "raw_address": "0x00000400",
            "virtual_address": "0x00001000",
            "virtual_size": "0x00080840",
            "size_of_data": "0x00080a00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x68000020",
            "entropy": "6.39"
          },
          {
            "name": ".rdata",
            "raw_address": "0x00080e00",
            "virtual_address": "0x00082000",
            "virtual_size": "0x0000ba54",
            "size_of_data": "0x0000bc00",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x48000040",
            "entropy": "5.48"
          },
          {
            "name": ".data",
            "raw_address": "0x0008ca00",
            "virtual_address": "0x0008e000",
            "virtual_size": "0x00026538",
            "size_of_data": "0x00003000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
            "characteristics_raw": "0xc8000040",
            "entropy": "2.48"
          },
          {
            "name": ".pdata",
            "raw_address": "0x0008fa00",
            "virtual_address": "0x000b5000",
            "virtual_size": "0x00004f8c",
            "size_of_data": "0x00005000",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x48000040",
            "entropy": "5.90"
          },
          {
            "name": "PAGE",
            "raw_address": "0x00094a00",
            "virtual_address": "0x000ba000",
            "virtual_size": "0x00004c6c",
            "size_of_data": "0x00004e00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x60000020",
            "entropy": "6.31"
          },
          {
            "name": "INIT",
            "raw_address": "0x00099800",
            "virtual_address": "0x000bf000",
            "virtual_size": "0x00002c96",
            "size_of_data": "0x00002e00",
            "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x62000020",
            "entropy": "5.49"
          },
          {
            "name": ".rsrc",
            "raw_address": "0x0009c600",
            "virtual_address": "0x000c2000",
            "virtual_size": "0x000003d0",
            "size_of_data": "0x00000400",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "3.22"
          },
          {
            "name": ".reloc",
            "raw_address": "0x0009ca00",
            "virtual_address": "0x000c3000",
            "virtual_size": "0x0000052c",
            "size_of_data": "0x00000600",
            "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
            "characteristics_raw": "0x42000040",
            "entropy": "5.12"
          }
        ],
        "overlay": {
          "offset": "0x0009d000",
          "size": "0x00009470"
        },
        "resources": [
          {
            "name": "RT_VERSION",
            "offset": "0x000c2060",
            "size": "0x0000036c",
            "filetype": null,
            "language": "LANG_ENGLISH",
            "sublanguage": "SUBLANG_ENGLISH_US",
            "entropy": "3.48"
          }
        ],
        "versioninfo": [
          {
            "name": "CompanyName",
            "value": "Check Point Software Technologies Ltd."
          },
          {
            "name": "FileDescription",
            "value": "ZoneAlarm Firewalling Driver"
          },
          {
            "name": "FileVersion",
            "value": "926005812"
          },
          {
            "name": "InternalName",
            "value": "VSDATANT.SYS"
          },
          {
            "name": "LegalCopyright",
            "value": "  2021 Copyright Check Point Software Technologies Ltd."
          },
          {
            "name": "OriginalFilename",
            "value": "VSDATANT.SYS"
          },
          {
            "name": "ProductName",
            "value": "End Point Security"
          },
          {
            "name": "ProductVersion",
            "value": "R80"
          },
          {
            "name": "Translation",
            "value": "0x0409 0x04e4"
          }
        ],
        "imphash": "664f879989d8c8197dcc36600381e0e8",
        "timestamp": "2022-11-16 12:40:01",
        "icon": null,
        "icon_hash": null,
        "icon_fuzzy": null,
        "icon_dhash": null,
        "imported_dll_count": 6
      },
      "data": null,
      "strings": [
        "\\SystemRoot\\SysWow64\\ZoneLabs\\IPAdaptersDump.bin",
        "maxdebuglog",
        "ZLrpD",
        "FwReEvalRules - state",
        "CACHE",
        "ndis.sys",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\CLASSES",
        "RtlCopyUnicodeString",
        "FltQueryInformationFile",
        "A_A^]",
        "group type was invalid",
        "D9|$$t",
        "ROOTH",
        "^pfA9^,u",
        "FWAllowOut",
        "D$xE3",
        "Sectigo RSA Code Signing CA 2",
        "RECEIVE",
        "ntdll.dll",
        "rulegroupref",
        "ProcessAttributeAction",
        "VSmpH",
        "timegroup",
        "Name has already been set",
        "\\REGISTRY\\MACHINE\\SYSTEM\\SETUP",
        "too many exename attributes",
        "@UVWATAUAVAWH",
        "@SVWATAVH",
        "VSWFP_OutboundNBL_DecideAction: should be blocking %X>%X",
        "\\SystemRoot",
        "%u Packet %s: Proto: %s Flags: 0x%08lx Src: %2u.%2u.%2u.%2u Dest: %2u.%2u.%2u.%2u ",
        "GetRuleEntryTag",
        "first buffer..",
        "4i1g\"",
        "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
        "SrcPort: %u DstPort: %u",
        "<0|'<9",
        "FWPS_LAYER_DATAGRAM_DATA_V4_DISCARD",
        "Process: %s[%d] %s %s[%d] (%s)",
        "protection",
        "ETH_ADDR (%s) != LOCAL",
        "RULSET ",
        "VSDATANT: DriverUnload->StopProtection",
        "ulimit",
        "L$ H9",
        "CA.ISafe",
        "t$Ht.H",
        "%*.*S",
        "\\DosDevices\\vsdatant",
        "Initial LockupInfo: on=%lu server=%08lx port=%hu",
        "IP_ALL",
        "DVSP_FILE_ZLCOMMDB",
        "Isafe.Server",
        " Microsoft Code Verification Root0",
        "FW_CTRL_GET_LIST_SIZE",
        "Upgrade",
        "FwpsAllocateCloneNetBufferList0",
        "FWPS_CALLOUT_NOTIFY_DELETE_FILTER",
        "l$ AVH",
        "too many children",
        "Enabled",
        "t$ UATAUAVAWH",
        "too many weight attributes",
        "A_A^A]_]",
        "CLONED",
        "@UVWH",
        "t8H9y t2H",
        "u0s0q",
        "Zone Alarm Driver vsdatant.sys",
        "toaddress",
        "OsfwObjectFree",
        "bTMHook = %d, && g_Kernel_Events = %d",
        "CPEPSDrive",
        "DriverFastIoDispatch",
        "TCP_FLAG_PSH",
        "FW_CTRL_SET_IPLOCAL",
        "setkey",
        "MULTICAST_TRACEROUTE",
        "AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
        "_wcsnicmp",
        "0A_A^A]A\\]",
        "\\$0H9",
        "invalid default attribute",
        "OSFW_ProcessReferenceOrCreate",
        "OSFW_ProcessQueryRuleForPid",
        "position",
        "SetupRegistry",
        "IoAllocateErrorLogEntry",
        "H9qPtFH",
        "ProcessAttributeName",
        "IoFileObjectType",
        "%s %08lx:",
        "rRj;B7|",
        "VSDATANT: DriverUnload<-ObCallbackInterfaceUnload",
        "D$puzH",
        "WINSYSDIR",
        "TryEx2NotifyRoutine",
        "8D$0t",
        "rulerefentry",
        "Another MDL to use...",
        "|$@E3",
        "A^A\\_]",
        "VsdatantDebugFlag",
        "D$`fA",
        "FWPS_LAYER_ALE_AUTH_RECV_ACCEPT_V4_DISCARD",
        "invalid context attribute",
        "VSWFP_LAYER_ALE_RESOURCE_RELEASE_V4",
        "first",
        "too many protection tags",
        "too many rules specified",
        "@83tbA",
        "Cannot print LONG type",
        "L$ VWATAVAWH",
        "FW_CTRL_DEL_IPLOCAL",
        "SeCaptureSecurityDescriptor",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VET-FILT",
        "IoVolumeDeviceToDosName",
        "C0A05",
        "u:9D$xuj",
        "@SUVWATAVAWH",
        "ZwQueryKey",
        "l$ VWAVH",
        "_snwprintf",
        "VsWfpDebugUdpPortIgnore3",
        "WH_SHELL",
        "|$A=u",
        "UninstPwdSalt",
        "DigiCert, Inc.1A0?",
        ".idata$5",
        "ZwOpenProcessTokenEx",
        "NdisDebugSnifferAddress",
        "VSMON",
        "LOCAL (SUB)NET BROADCAST",
        "A9v8vN",
        "afterstartup",
        "VSWFP_LAYER_ALE_AUTH_LISTEN_V4",
        "L$hE3",
        "%s: adding NAT state (ident out)",
        "ICMP_ROUTER_SOLICIT",
        "\\SystemRoot\\system32\\drivers\\vsconfig.xml",
        "TCP_FLAG_URG",
        "InstallZwTerminateProcessHooks",
        "CPEPCONNECTDIR",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\ComputerAssociates\\ISafe",
        "@A_A^A]A\\_^]",
        "\\$0E3",
        "L$(E3",
        "L$@H3",
        "ESTABLISH",
        "QZ^&A",
        "FltAllocateGenericWorkItem",
        "boSVA",
        "|$ ATAUAVAWL",
        "ExEnterCriticalRegionAndAcquireResourceExclusive",
        "NdisRetreatNetBufferDataStart",
        ":::::::::",
        "@SUAVH",
        "ZlprL",
        "ip addr is invalid",
        "Send_Decide: subp=%d",
        "HKLM\\SOFTWARE\\CHECKPOINT",
        "\\Registry\\MACHINE\\SYSTEM\\Select\\",
        "FWPS_LAYER_ALE_AUTH_RECV_ACCEPT_V6",
        "NOTLOCALSOCKET",
        "no rules tags specified",
        "@VAVAWH",
        "1I'.G",
        "SUVWATAUAVH",
        "ALOCATED",
        "FwpsFlowAssociateContext0",
        "A_A^^]",
        "SeAlA",
        "FW_CTRL_EVAL_PACKET",
        "MmLoadSystemImage",
        "openthread",
        ".data",
        ">http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0",
        "pA_A^A]_^][",
        "NdisAdvanceNetBufferDataStart",
        "too many event attributes",
        "dwMsgLevel: %lu",
        "duplicate attributes",
        "D$(SGOLH",
        "ZwSaveKey",
        "\\$ UVWATAUH",
        "A;xHu",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10",
        "VSWFP_RequestTransportInjectExpended",
        "ETH_ADDR (%s) == LOCAL",
        "protocol",
        "AV.Resident",
        "AC_TermOnExecutionInPolicy",
        "FW_CTRL_SET_LOCKUP_INFO",
        "OsfwFindProcessAndCache",
        "\\BaseNamedObjects\\vsdrvevent",
        "invalid <eventgroup> tag",
        "RtlAppendUnicodeStringToString",
        "FwpsDereferenceNetBufferList0",
        "tQD9!u",
        "FwStateFind",
        "OsfwEngineSetupEvent",
        "}[{`HW",
        "E;B`r",
        "FirewallDelStateNow",
        "invalid &??; char",
        "A\\_^[]",
        "Epklib not loaded...",
        "D$X;CXuaD9D$|uZE;",
        "Failed to start NDIS filter",
        " A^_^",
        "VsWfpDebugUdpPortIgnore6",
        "KeSetPriorityThread",
        "RtlUpcaseUnicodeChar",
        "@8k5tU",
        "FWPS_LAYER_STREAM_V6",
        "__RegNtPreRenameKey",
        "HcKDH",
        "osfirewall",
        "ZwTerminateProcess",
        "dwAction: %s",
        "A_A^A\\_^]",
        "dwFlags: %s",
        "unsupported operation",
        "strstr",
        "D8C%t",
        "t]A:/sS@",
        "HKCS\\Services\\Vsdatant\\Enum",
        "HKLM\\SOFTWARE\\ComputerAssociates\\ISafe",
        "WH_SYSMSGFILTER",
        "20221117102006Z",
        "CmUnRegisterCallback",
        "PsIsProtectedProcess",
        "ObIsKernelHandle",
        "dwDirection: %s",
        "NtWaitForSingleObject",
        ".http://crt.usertrust.com/USERTrustRSAAAACA.crt0%",
        "OSUpgrade Logic: starting protection",
        "ALL DAYS",
        "dPublicKeyId",
        "trusted",
        "ExInitializePagedLookasideList",
        "Vet Drivers",
        "IoAllocateMdl",
        "RtlUpperChar",
        "RSDS/Gk",
        "RULES",
        "SOCK (%s/%s) != LOCAL (SUB)NET BROADCAST:%hu",
        "InitFileStringTableDrive",
        "hClient: %08lx",
        "MmUnlockPages",
        "I\\$pH",
        "wcschr",
        "VS_VERSION_INFO",
        "IP_IPV6",
        "OsfwRuleCreateRuleGroup",
        "FwpsInjectionHandleCreate0",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Control\\GroupOrderList",
        "invalid <rulegroup> tag",
        "SRule%lx",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\GroupRulesDump.bin",
        "%03lx",
        "notify",
        "LinkName",
        "@UVAVH",
        " LOCAL",
        "l$8E3",
        "CPCommonFilesDevice",
        "VSWFP_TCPAuthRecvAcceptClassifyCallbackPostProc",
        "IMAGE",
        "NdisMSleep",
        "dwProtocol: %s",
        "LISTEQ",
        "3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%",
        "PsCreateSystemThread",
        "KeDelayExecutionThread",
        "A_A^A\\",
        "t$X9~8",
        "FirewallAddRuleEx",
        "ICMP_ECHO",
        "D$hE3",
        "A^_^[]",
        "@USVWATAVH",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VETFDDNT",
        "ICMP_REDIRECT",
        "%wZ\\system32\\drivers",
        "MONDAY",
        "ZwRestoreKey",
        "\\$(E3",
        "A_A^A]A\\]",
        "VSDATANT: DriverUnload<-PsRemoveCreateThreadNotifyRoutine",
        "HOOKED",
        "\\Internet Logs",
        "l$PE3",
        "\\srv.sys",
        "\\$ UVATAVAWH",
        "LISTNEQ",
        "reserved groupname",
        "A]A\\_^][",
        "|$ AVH",
        "PsRemoveLoadImageNotifyRoutine",
        "partialnocase",
        "190502000000Z",
        "too many type attributes",
        "http://www.digicert.com/CPS0",
        "FwStateSetFlag",
        "FWPS_LAYER_OUTBOUND_IPPACKET_V4_DISCARD",
        "=LJ=3",
        "D;L$p",
        "FwStateFind(arp)",
        "0A_A^A]A\\_^]",
        "DefaultStateTTL",
        "120418234838Z",
        "VSWFP_OutboundNBL_DecideAction: subp=%d",
        "SATURDAY",
        "OsfwRuleCreateDriverEntry",
        "Washington1",
        "\\SystemRoot\\system32\\drivers\\vetfddnt.sys",
        "D$X;CXu'D9L$|u E;",
        "ExcludedFolders",
        "no event for subevent",
        "Microsoft Time-Stamp PCA 2010",
        "NdisFSendNetBufferListsComplete",
        "RtlCaptureStackBackTrace",
        "ProductVersion",
        "modify",
        "VsZwTerminateProcessDefault",
        "l$@H;",
        "l$PA#",
        "l$HE3",
        "-usE;",
        "ZwWaitForSingleObject",
        "VSCCH",
        "FwpsStreamContinue0",
        "us9-T",
        "H95)6",
        "execute",
        "FirewallDelLocalIP: ip=%08lx",
        "invalid reference attribute",
        "ZoneAlarm Firewalling Driver",
        "{,+{(txH",
        "ICMP_MASK_REPLY",
        "FWPS_LAYER_INBOUND_IPPACKET_V6_DISCARD",
        "restricted",
        "KeAcquireInStackQueuedSpinLock",
        "RtlxUnicodeStringToAnsiSize",
        "RULGRP ",
        "DeviceCharacteristics",
        "A__^][",
        "__RegNtPreSetValueKey",
        "<8 s;H",
        "TranslateToWindowsFileName",
        "ipaddr",
        "t$ E3",
        "createkey",
        "\\??\\A:",
        "E9>u&D9=",
        "D9t$H",
        "PsLookupThreadByThreadId",
        "FWPS_LAYER_STREAM_V4_DISCARD",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion",
        "KeAcquireSpinLockAtDpcLevel",
        "HKCS\\Services\\VETFDDNT",
        "A_A^^",
        "FWPS_LAYER_INBOUND_TRANSPORT_V4",
        "@SWATAUH",
        "bidirectional",
        "DVSP_COPYONREBOOT",
        "OsfwEvalulateFile",
        "name is too long",
        "|$ UH",
        "IoWMIRegistrationControl",
        "PsGetThreadId",
        "\\SystemRoot\\system32\\drivers\\vetmonnt.sys",
        "ProcessAttributeDefault",
        "WmiTraceMessage",
        "RtlTimeToTimeFields",
        "wchar",
        "FwpsFreeNetBufferList0",
        "t$@E3",
        "Bad gateway tag format",
        "L952y",
        "A_A]A\\_[]",
        "0A^_[",
        "\\$HE3",
        "Thread",
        "bad exename attribute",
        "Check Point Software Technologies Ltd.",
        "8D$(t0",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\CVhdMp",
        "FwReplaceState(new): NULL",
        "allowweightranges",
        "LOOPBACK",
        "*L9|$ uyH",
        "equal",
        "PORT (%s/%s) %s",
        "VSDATANT: DriverUnload->DeleteAllHookDevices",
        "GetEventEntryTag",
        "VsWfpDebugUdpPortIgnore2",
        "SeTsH",
        "UWATAUAVAWH",
        "end of string not found",
        "A_A^A\\^]",
        "\\Device\\PhysicalMemory",
        "@SUVWAWH",
        "I9>t.I",
        "-fffffff",
        "0A\\^[",
        "vsprintf",
        "fD;c,uEfD;k.",
        "System.VETFDDNT",
        "-end of block msg",
        "ANY DAY",
        "IoCreateNotificationEvent",
        "SOCKLOCALBCAST",
        "H9537",
        "MASK_REPLY",
        "t1HcI$",
        "t;@8=9",
        "ObReferenceObjectByName",
        "=~b,I6",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\bnistack\\PvsAgent",
        "UninstPwdHash",
        "A_A]]",
        "imagename",
        "InstalledProduct",
        "CPEPS64Drive",
        "UVAWH",
        "UnicodeStringToStringW",
        "StopProtection",
        "@UAVAWH",
        "GetOSFirewallConfig",
        "ZwQueryInformationFile",
        "RtlGetDaclSecurityDescriptor",
        "invalid exename attribute",
        "?u(f9Q",
        "OsfwObjectUnlock",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\RouteRulesDump.bin",
        "_wcsicmp",
        "InjectStackSize",
        "L;=()",
        "0A_A]A\\",
        "\\epklibproxy.sys",
        "&Check Point Software Technologies Ltd.0",
        "SUVWH",
        "DVSP_FILE_RULES",
        "AllowFTPData",
        "@WATAVAWH",
        "@USVWATAUAWH",
        "qHH9A",
        "\\SystemRoot\\system32\\drivers\\vsdatant.sys",
        " A_A^A]A\\]",
        "MmUserProbeAddress",
        ">= %#lx",
        "T$8E2",
        "DAYTIME %s, %s",
        "dwTTL: %lu",
        "DTGMCB",
        "T$ E3",
        "%s: t=%lx h=%lx pflg=%lx subp=%lx sip=%d.%d.%d.%d dip=%d.%d.%d.%d",
        "HandleStartupDir",
        "GetItemEntryTag",
        "ran out of data!!!",
        "MmBuildMdlForNonPagedPool",
        "sprintf",
        "3http://www.microsoft.com/pkiops/Docs/Repository.htm0",
        "FWPS_LAYER_DATAGRAM_DATA_V4",
        "FwpsFlowRemoveContext0",
        "EVTGRP ",
        "HKCS\\Services\\VET-REC",
        "t$:ADr",
        "OsfwObjectReferenceByHeader",
        "ZLDIR",
        "too many log tags",
        "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Class",
        "EnableOSFWLog",
        "SUATAUAWH",
        "group",
        "KeQueryPerformanceCounter",
        "Sectigo RSA Code Signing CA 20",
        "FW_CTRL_ADD_XMLRULE",
        "INJECTED",
        "PA_A^_^]",
        ".text$mn$21",
        "KeWaitForSingleObject",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\safeProgramsZA.xml",
        "IoFreeWorkItem",
        "Empty hostname tag",
        "jj@0HK4",
        "\\SystemRoot\\Internet Logs\\fwdbglog.txt",
        "D$PE3",
        "too manny askonce attributes",
        ".f%4'",
        "CPEPSDIR",
        "B.reloc",
        "3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t",
        "NdisRegisterProtocol",
        "http://ocsp.digicert.com0\\",
        "MHaTJ",
        "ETH_ADDR (%s) == %s",
        "PA^^]",
        "securitypolicy",
        "VSmrI",
        "FwpsInjectTransportReceiveAsync0()",
        "NOT IN [%#lx, %#lx]",
        "84401",
        "L$ UH",
        "VsWfpDebugUdpPortIgnore1",
        "RECEIVE_OR_FORWARD",
        "L$ WATAUAVAWH",
        "InstalledMode",
        "imageentry",
        "present",
        "S@D;+sP",
        "netdelete",
        "FirewallAddLocalIP(%d): #=%lu ip=%08lx mask=%08lx",
        "ProcessAttributeEvent",
        "openprocess",
        "FWPS_LAYER_ALE_AUTH_LISTEN_V6_DISCARD",
        "FWP_ACTION_CONTINUE",
        "EtwRegisterClassicProvider",
        "NdisOpenAdapter",
        "WINDRVDIR",
        "FWAllowDHCP",
        "parser out of memory",
        "FwpmBfeStateGet0",
        "ExReleaseSpinLockExclusive",
        "FirewallAddLocalIP",
        "AVAWH",
        "rule addition failed",
        "iprange",
        "FwStateFind: origin=%lu data=%p",
        "invalid day",
        "prepend",
        "%s:%s\\%s",
        "FWPS_LAYER_ALE_AUTH_CONNECT_V6_DISCARD",
        "]IMrV",
        "I0G0E",
        "9Y(v'",
        "A8h@v;A",
        "HKCS\\Services\\VETMONNT",
        "too many subevent tags",
        "SUAUAVH",
        "@USVAVH",
        "D8s$t",
        "epklibproxy.sys",
        "VWATAUAVH",
        "|$pH;",
        "ProfileImagePath",
        "<= %#lx",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Eventlog\\System\\VETMONNT",
        "fwpkclnt.sys",
        "FwpsStreamInjectAsync0",
        "FwEvalRules",
        "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\",
        "sunday",
        "GX9D$`u",
        "onstartup",
        "84400",
        "IoCreateSymbolicLink",
        "v!fff",
        "VATAUH",
        "wsockverminor",
        "FltUnregisterFilter",
        "NdisAllocatePacket",
        "invalid match attribute",
        "T9w{y",
        "\\DEVICE\\Harddisk",
        "FwpsFreeCloneNetBufferList0",
        "L$8fD",
        "<0|!<9",
        "Z9Mj|",
        "ZwQuerySystemInformation",
        "InstallProcessCallback",
        "PnpSetupInProgress",
        "220414000000Z",
        "E@\\??\\H",
        " A_A^A]A\\^",
        "D$(fA;",
        "DELETE-NOW",
        "ip(sf",
        "VSDATANT: DriverUnload->IoUnregisterShutdownNotification",
        "PsSetCreateProcessNotifyRoutineEx",
        "FltGetDestinationFileNameInformation",
        "SplitPath",
        "70503",
        "OsfwProcessDereference",
        "FwpmSubLayerAdd0",
        "IP_EVERY",
        "macaddr",
        "w L9t$Ht",
        "NdisAllocateMemory",
        "ExInterlockedRemoveHeadList",
        "OnProcessDestroyCallback",
        "t$49q8",
        "tag mismatch",
        "ICMP_DST_UNREACHABLE",
        "|$$D9y8",
        "A_A^_",
        "SEND_OR_FORWARD",
        "GetObjectName",
        "openprocessaction",
        "Route Rule",
        "RtlWriteRegistryValue",
        "ProbeForRead",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Eventlog\\System\\VETFDDNT",
        "RegistryReadSubKeyName",
        "ExRaiseStatus",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_IP_REMOTE_PORT",
        "HHf9Klt",
        ".rdata$zzzdbg",
        "t$`tSH",
        "severityref",
        "FwStateTable_GetEntry",
        "A;}8r",
        "T$`fD",
        "GetRuleGroupTag",
        "DelDelMemAllocateRegCallback",
        "\\system32\\drivers\\vsdatant.sys",
        "tcpudpprotocolrange",
        " A\\_^][",
        "TranslateFromFilePathDrive",
        "Start Menu\\Programs\\Startup",
        "HKCS\\Services\\VET-FILT",
        "RtlGetOwnerSecurityDescriptor",
        "rules",
        "CPCOMMFILEDIR",
        "D$DE3",
        "AppendToPendingFileRenameOperation",
        "CSRSS.exe",
        "SeConvertStringSecurityDescriptorToSecurityDescriptor",
        "l$@E3",
        "d$0fD",
        "Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l",
        "FirewallExit: t=%lx flags=%lx",
        "IP_GRE",
        "u%9t$pu",
        "FirewallInit: t=%lx flags=%lx",
        "hA_A]A\\_^]",
        "oZ%pb",
        "Current",
        "211125000000Z",
        "invalid param attribute",
        "VSDATANT: DriverUnload<-FreePacketLoggingResources",
        "HRule%lx",
        "an action attributes are invalid",
        "strncpy",
        "isspace",
        "Group",
        "HKCS\\Services\\Vsdatant\\Parameters",
        "FirewallClearList: flags=%x",
        "KeReleaseSpinLockFromDpcLevel",
        "xA_A^A]^",
        "WAVAWH",
        "u0D;oXu*D;",
        "VAVAWH",
        "8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1",
        "\\SystemRoot\\SysWow64\\vsdata.dll",
        "SUVWATAUH",
        "SOCK (%s/%s) != %08lx:%hu",
        "event",
        "FltGetEcpListFromCallbackData",
        "6+686E6",
        "DVSP_FILE_HOSTS",
        "\\Registry\\MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\Endpoint Security\\Secure Uninstall",
        "VWAVH",
        "UAUAWH",
        "GetDrvEntryTag",
        "unknown att",
        "{system32\\browseui.dll",
        "eGE8m{",
        "ProcessAttributeType",
        "(D$0H",
        "FALSE",
        "WH_CALLWNDPROC",
        "Services.VETMONNT",
        "@A_A^A]A\\_",
        "drventry",
        "D8Q%t",
        ".idata$6",
        "MmIsNonPagedSystemAddressValid",
        "`A_A]A\\][",
        "L$PH9o",
        "invalid ask attribute",
        "SEND_OR_RECEIVE",
        "Services.VET-REC",
        "300930183225Z0|1",
        "D8X%t",
        "DVSP_FILE_PAPRELOAD",
        "IoDetachDevice",
        "\\SystemRoot\\system32\\drivers\\etc\\hosts",
        "FileVersion",
        "u0fD;",
        "FirewallDelLocalIP: #=%lu ip=%08lx",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VETMONNT",
        "ExAcquireFastMutex",
        "OriginalFilename",
        "cx*l][",
        "physmem",
        "HandleParentPath",
        "VsWfpDebugUdpPort",
        "CreateProcessInfo",
        "FwpsCalloutUnregisterById0",
        "Thales TSS ESN:3E7A-E359-A25D1%0#",
        "\\??\\%s:%s",
        "t;fff",
        "KeAcquireSpinLockRaiseToDpc",
        "A^A]A\\_^[]",
        "VsWfpDebugAll",
        "ehttp://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0",
        "%USERTrust RSA Certification Authority0",
        "r&u=H",
        "E9~8v",
        "tGLcA<",
        "PsThreadType",
        "WH_MOUSE",
        "l$`A;",
        "RtlAddAccessAllowedAce",
        "VSDATANT: DriverUnload<-DeleteAllHookDevices",
        "D8H@v;A",
        "FWPS_LAYER_INBOUND_IPPACKET_V4_DISCARD",
        "VSWFP_LAYER_STREAM_V4_DEFER",
        "B8D:L",
        "notpresent",
        "@SVWATAUAVAWH",
        "srcproc",
        "FW_CTRL_SET_OPT",
        "\\SystemRoot\\Internet Logs\\fwpktlog.txt",
        "LegalCopyright",
        "<J\\tffA",
        "9Y8v/",
        "ALL STD IP",
        "\\SystemRoot\\system32\\drivers\\etc\\lmhosts",
        "ZwOpenKey",
        "persistafterstartup",
        "A_A^A]A\\_",
        "V2_LEAVE_GROUP",
        "@USVWATAUAVH",
        "FwpsCompleteClassify0",
        "ProcessAttributeExemptFromGlobalEventGroup",
        "PsGetCurrentProcessId",
        "bitset",
        "Exclusive",
        "hostsfile",
        "\\??\\%s:%s\\SysWOW64",
        "ExInitializeNPagedLookasideList",
        "NDIS.SYS",
        "ExSystemTimeToLocalTime",
        "bad weight attribute",
        "OSFW_ProcessCreate",
        "ExReleaseSpinLockShared",
        "ObGetObjectType",
        "ProcessAttributeValue",
        "KeReleaseMutex",
        "FwStateCheck",
        "J>f;O",
        "8D$(t\"",
        "IP_UDP",
        "FwStateAdd: Reusing state: internal=%x sip=%d.%d.%d.%d dip=%d.%d.%d.%d sp=%d dp=%d",
        "GROUP_MEMBERSHIP_QUERY",
        "hAssociatedRule: %08lx",
        "ZwOpenThreadTokenEx",
        "3http://crl.sectigo.com/SectigoRSACodeSigningCA2.crl0t",
        "eventgroupref",
        "pchunter",
        "icmpprotocol",
        "ZwQueryInformationThread",
        "added",
        "A_A^A\\_^",
        "E(VSLWH",
        "0A_A^A]A\\_",
        "SVWATH",
        "%USERTrust RSA Certification Authority",
        "E(H9]",
        "KeExpandKernelStackAndCalloutEx",
        "FROM_STATE",
        "\\DEVICE\\",
        "FW_CTRL_SET_RFLAGS",
        "210429000000Z",
        "\\RPC Control\\OLE",
        "H95f0",
        "WH_DEBUG",
        "VSWFP_LAYER_ALE_ENDPOINT_CLOSURE_V4",
        "allowranges",
        "invalid group",
        "PA_A^A]A\\_^]",
        "\\$ UVWH",
        "%&k3m",
        "CCORE64.SYS",
        "D95%/",
        "FRIDAY",
        "relativeposition",
        "4|5Uq",
        "FW_CTRL_DEL_CLIENT",
        "/Microsoft Windows Third Party Component CA 20120",
        "FirewallDelClient: hclient=%x hclient2=%x",
        "KeStackAttachProcess",
        "@SAWH",
        "[ VATAWH",
        "t$X9_8",
        "MONDAY-FRIDAY",
        "onshutdown",
        "CPEPSDevice",
        "fD94GH",
        "pA_A^A]A\\_^]",
        "@8=GV",
        "-VERIFY",
        "FirewallAddState",
        "LISTEN",
        "|$HI;",
        "symbolicpath",
        "D;cXu",
        "FwpsReleaseClassifyHandle0",
        "L$XE3",
        "0c0O1",
        "p%|Yi1$",
        "tW$?~",
        "InstallPsGetVersionHooks",
        "V3_MEMBERSHIP_REPORT",
        "itementry",
        "dstproc",
        "rulegroup",
        "L$0H3",
        "PpRbH",
        "t1@8s4t+",
        "'%s' out of memory",
        "D$HE3",
        "wcsncpy",
        "\\Device\\Ndis",
        "HKLM\\Software",
        "ProcessAttributeSubevent",
        ".edata",
        "TOKEN",
        "!= %s",
        "@SUVWH",
        "VSWFP_LAYER_ALE_RESOURCE_ASSIGNMENT_V4",
        "<!-- xxx --> expected",
        "message",
        "G.f9D$xu",
        "spawnprocess",
        ":Z@sUH",
        "ICMP_TIMESTAMP",
        "> %#lx",
        "T$(E3",
        "|$HH;",
        "srcport",
        "D9=_<",
        "WH_JOURNALRECORD",
        "IoIsWdmVersionAvailable",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\vetredir.dll",
        "`0^0\\",
        "%s/%s",
        "VsWfpDebugNbl",
        "L$(H3",
        "OSFWLogCounter",
        "FwpsCalloutRegister0",
        "VSWFP_OutboundTransportClassifyCallback",
        "C49G$uF",
        "t$(9q8",
        "TUESDAY",
        "\\??\\%wZ",
        "Sectigo Limited1%0#",
        "fwdebuglog",
        "A^^[]",
        "V2_MEMBERSHIP_REPORT",
        "customtext",
        "Failed get signe, the status is: %d",
        "D9=\";",
        "VsHaA",
        "K8 Lc",
        "GetImageEntryTag",
        "%u LogFileCreated",
        "WINDIR",
        "VSWFP_SocketFind",
        "NOT IN {%s}",
        "addressgroup",
        "H.data",
        "NOTIN",
        "system32\\shell32.dll",
        "@83td",
        "l$(E3",
        "EPkPsReleaseProxy",
        "OSFW_ObjectFindByName",
        "Cannot print QUAD type",
        "VERIFIED ",
        "FW_CTRL_ENUM_ADAPTERS",
        "ipsubprotoflags",
        "VsWfpDebugMatch",
        "INFO_REQUEST",
        "H95YF",
        "D9|$,",
        "PsRemoveCreateThreadNotifyRoutine",
        "Services.VET-FILT",
        "\\??\\X:",
        "IPv6H",
        "KeSetEvent",
        "U0S0Q",
        "%SystemRoot%",
        "L$xtO",
        "i-|a/",
        "PAGE$x",
        "tEHcV<",
        "ICMP_PARAM_PROBLEM",
        "filelevel",
        "SeSdH",
        "D$(KyCx3",
        "Microsoft Time-Stamp Service0",
        "ICMP_INFO_REQUEST",
        "ZLnpH",
        "ZLseI",
        "FwArpStateAdd",
        "\\SystemRoot\\system32\\drivers\\vet-filt.sys",
        "bad action specified",
        "bad reference attributes",
        "%aT[:M",
        "EPkAuGetSignerInfoProxy",
        "append",
        "hClient2: %08lx",
        "ZwQueryInformationToken",
        "A^A]A\\_^[",
        "k VAVAWH",
        "FwStateFind(%d sfc=%lu)",
        "rip=%p rsp=%p rbp=%p",
        "D$`xsH",
        "D;S$u",
        "OnProcessChecksumCallback",
        "ExDeleteNPagedLookasideList",
        "invalid value attribute",
        "Rule is too big",
        "\\SystemRoot\\System32\\drivers\\epklibproxy.sys",
        "Hard Rule",
        "FwpsInjectionHandleDestroy0",
        "ZwCreateFile",
        "A_^[]",
        "VSDATANT: DriverUnload->FreeTDIHook",
        "VSDATANT: DriverUnload<-FilterUnload",
        "@USWATAUAVAWH",
        "\\Registry\\Machine\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders",
        "ExDeletePagedLookasideList",
        "A_A^A]_^",
        "T$`E8~",
        "SOCK (%s/%s) == LOCAL:%hu",
        "    seth=?",
        "VSDATANT: DriverUnload<-StopFirewall",
        "dwClientId: %#lx",
        "IoGetCurrentProcess",
        "NdisFreePacket",
        "CreateFakeListensTdi",
        "ROUTERADVERT",
        "CSDVersion",
        "%u.%u.%u.%u",
        "D8k$t",
        "fD94Au",
        "D8T$(t<",
        "VSWFP_InitSocketSearchParams",
        "FWPS_LAYER_STREAM_V4",
        "too manny name attributes",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_FLAGS",
        "D$ fD",
        "x AVH",
        "RtlQueryRegistryValues",
        "tFD9%",
        "CreateRuleSet",
        "protocolgroup",
        "OSFW_ProcessAddRuleForPidByName",
        "MmIsAddressValid",
        "L$@A+",
        "SVAWH",
        "zlcommdb",
        "UAVAWH",
        "PsGetCurrentThreadId",
        "TCPIP_WANARP",
        "TYPE (%s) %s",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\ComputerAssociates\\Anti-Virus",
        "@USVATAVAWH",
        "FWPS_LAYER_INBOUND_TRANSPORT_V6_DISCARD",
        "H95~D",
        "H95I3",
        "D$dfD",
        "LegacyRegRuleSet",
        "driver",
        "FwpsCompleteOperation0",
        "%02x-%02x-%02x-%02x-%02x-%02x",
        "registry",
        "PA^_^",
        "FASTIR",
        "Greater Manchester1",
        "l$PH;",
        "9Y(v&",
        "RtlCreateUnicodeString",
        "invalid <imageentry> tag",
        "GROUP",
        "found",
        "RtlEqualUnicodeString",
        "Zone Alarm Firewall Driver",
        "__OsfwEvaluateCreateProcess",
        "tflg=0",
        "l$`E2",
        "fB9,@u",
        "ProcessAttributeReference",
        "FWPS_LAYER_ALE_AUTH_CONNECT_V4",
        "invalid",
        "OSFW_AddProcessToProcessListOrOverwrite",
        "@UAWH",
        "FWPS_LAYER_OUTBOUND_TRANSPORT_V6",
        "ECHO_REQ",
        "t$(E3",
        "VWATAUAVAWH",
        "Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0",
        "too many <sosfirewall> tags",
        "ZdbgH",
        "IoValidateDeviceIoControlAccess",
        "xA^A\\",
        "PARAM_PROBLEM",
        "VsFltEvaluateFileByNameInfo",
        "<![CDATA[  ]]> expected",
        "signame",
        "ExInitializeResourceLite",
        "270418235838Z0",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters",
        "9XECAt",
        "s5{J&",
        "fA9,FI",
        "@DA8AFr",
        "|$ UATAUAVAWH",
        "DELETE-DEFER",
        "OsfwEngineClearDefaultEventGroup",
        "NdisDebugSip",
        "XA_A^A]A\\^]",
        "@SWAWH",
        "__RegNtPreDeleteValueKey",
        "T$ fD",
        "ProductName",
        "Event: %s.%s ",
        "CmSetCallbackObjectContext",
        "PsGetProcessId",
        "`A_A^_^]",
        "KeInitializeEvent",
        "%s(#=%lu): t=%lx h=%lx subp=%lu sip=%d.%d.%d.%d dip=%d.%d.%d.%d",
        "#Sectigo RSA Time Stamping Signer #30",
        "Zone Alarm Session",
        "__RegNtPreLoadKey",
        "replace",
        "D$Ptq",
        "l$PI;",
        "no name specified",
        "TdiEnable",
        "going to next NB",
        "KeReleaseInStackQueuedSpinLock",
        "RASARP",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\vet.dat",
        "no more memory avalible",
        "FltFindExtraCreateParameter",
        "VsWfpDebugUdpPortIgnore7",
        "D$XD95",
        "daytimerange",
        "TCP_FLAG_FIN",
        "VSWFP_LAYER_ALE_AUTH_RECV_ACCEPT_V4",
        "e0c0:",
        "tcpudpprotocol",
        "NdisCloseAdapter",
        "ZlgtD",
        "\\$ WAVAWH",
        "OsfwEvaluateEvent",
        "as.,k{n?,",
        "@USVWAUAVAWH",
        "& %#lx != %#lx",
        "H9~|t",
        "dwFwVersion: %08lx",
        "\\Registry\\Machine\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
        "OSUpgrade Logic Exit",
        "EVENT ",
        "L$8H3",
        "LOCALSOCKET",
        "\\epklib.sys",
        "t$tI;",
        "8D$(t,",
        "ProcessImageFlagAttributes",
        "D$HXECAH",
        "FLAGS (%#lx, %#lx)",
        "RtlCheckRegistryKey",
        "FltIsDirectory",
        "SUVWAUH",
        "ANY TIME",
        "VSWFP_LAYER_INBOUND_TRANSPORT_V4",
        "t$ WATAWH",
        "T$ E2",
        "Vsdatant",
        "GetEnvVariableValue",
        "CompanyName",
        "D$XE3",
        "@SUVWAVAWH",
        "SVWATAUAVAWH",
        "FakeListensIndicationWorker",
        "WH_GETMESSAGE",
        "spSVH",
        "FwReEvalRules",
        "T$!<lu",
        "L$8E3",
        "GetAllUsersStartupFolder",
        "HKLM\\SOFTWARE\\ComputerAssociates\\ISafe\\Server",
        "L$pH3",
        "invalid operator attribute",
        "@USVAWH",
        "socketgroup",
        "OsfwProcessAddRule",
        "t$ A9n(",
        "tags are ensted too deep",
        "Unload Done",
        "ntfs.sys",
        "b.rsrc",
        "VSutf",
        "040904e4",
        "FwpsAcquireClassifyHandle0",
        "FW_CTRL_CLR_STATES",
        "ExReleaseFastMutex",
        "RtlGetGroupSecurityDescriptor",
        "PA_A^_",
        "9L$XuQ",
        "D9-+F",
        "A_A]][",
        "@SVATH",
        "too manny notify attributes",
        "?Wue\"v",
        "PendingFileRenameOperations",
        "connect",
        "VSDATANT: DriverUnload->UnprotectAllFiles",
        "@A_A^A]A\\]",
        "Exception occured in handling of user-mode data",
        "l$@H9",
        "FwpsPendClassify0",
        "IoAllocateWorkItem",
        "M\\#TH",
        "RtlSetDaclSecurityDescriptor",
        "changeentryref",
        "%02x ",
        "bad rulestack specified",
        "********  OSFW is on  *********",
        "'>' expected",
        "ZLnoH",
        "HKCS\\Control\\Session Manager",
        "D9sdu",
        "*;UTm",
        "OSFW_ProcessCreateSpecial",
        ";Eown",
        "KeWaitForMultipleObjects",
        " A_A^A]A\\_",
        "BanProtection",
        "fF94Iu",
        "PsProcessType",
        "FltStartFiltering",
        "FldcH",
        "DriverModuleNotifyRoutine",
        "%S\\%s",
        "action",
        "/NOTIFY",
        "ruleentry",
        "@A^_^",
        "www.digicert.com1!0",
        "ProcessAttributeExecutable",
        "EPkPsRegisterProxy",
        "UAVAWI",
        "invalid type attribute",
        "FwpmBfeStateSubscribeChanges0",
        "The src process: %d tried to open a handle to target process: %d, the handle won't have vm permissions",
        "2Microsoft Windows Hardware Compatibility Publisher0",
        " A^A]A\\_^",
        "{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}",
        "u$f95fi",
        "match",
        "ExReleaseResourceAndLeaveCriticalRegion",
        "NoUseClass",
        "FwStateFind(1)",
        "f9D$Du2",
        "allow",
        "INFO_REPLY",
        "D$xfA",
        "ICMP_ECHO_REPLY",
        "A_A^A]A\\_^[]",
        "ipinip",
        "tJL95.R",
        "L$@Hc",
        "FWPS_LAYER_OUTBOUND_IPPACKET_V6",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\boot.dat",
        "dwAction2: %#lx",
        "OsfwMonitorStartupCallback",
        "VSWFP_DatagramDataClassifyPreProc",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_IP_LOCAL_ADDRESS",
        "enable",
        "askweightranges",
        "L9|$@",
        "HARD_RULE ",
        "SOCK (%s/%s) == %08lx:%hu",
        "FwReEvalRules - cur pkt",
        "EvaluateAdditionalDelayedDeleteAttemptsOneByOne",
        "TranslateFromAbsolutePath",
        " EXTERNAL",
        "direction",
        "IP_IGMP",
        "H9y t(H",
        "HAL.dll",
        "lockupinfo",
        "DVSP_PROC_VSMON",
        "Microsoft Time-Stamp Service",
        "|)MuT9",
        "tvH9Y",
        "too many class attributes",
        "DROPPED",
        "client",
        "NDMPu",
        "OsfwObjectReference",
        "prochackerold",
        "A_A^A\\_[]",
        "runonce.exe",
        "ruleID",
        "_7\".D",
        "tMHcQ<",
        "T$@E3",
        "VSDATANT: DriverUnload->RestoreProtection",
        "invalid <ruleentry> tag",
        "unknown",
        "FwpmProviderAdd0",
        " on:%lu=>%lu",
        "isProcessSigned",
        "FWPS_LAYER_ALE_RESOURCE_ASSIGNMENT_V4",
        "t#H;5",
        "AppCacheDisable",
        "FwpmTransactionCommit0",
        "invalid time",
        "CmRegisterCallbackEx",
        "MUTLICAST_ROUTER_SOLICITATION",
        "@A^^[",
        "w H9u",
        "[ UVWATAVH",
        "OsfwEngineSetGlobalEventGroup",
        "UninstPwdSaltDA",
        "FwStateFind(0)",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\zlcommdb.xml",
        "CPAppDataDevice",
        "NoDisplayClass",
        "skimp",
        " tflg=%s%s%s%s%s%s",
        "ntoskrnl.exe",
        "&'&4&A&N&[&h&u&",
        "\\RPC Control\\DNSResolver",
        "FWPS_LAYER_OUTBOUND_IPPACKET_V6_DISCARD",
        "h0f0?",
        "TranslateToFilePathDriveW",
        "ALL TRANSPORT",
        "NdisFRegisterFilterDriver",
        "VSDATANT.SYS",
        "VSWFP_StreamClassifyCallback",
        "IP_UDP_TCP",
        "-g<'<V",
        "RtlAbsoluteToSelfRelativeSD",
        "LCheck Point Software Technologies Ltd",
        "E;X u",
        "D$P9D$Du",
        "IoDeviceObjectType",
        "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Session Manager",
        "T$pE3",
        "|$HfD",
        "ExAcquireSpinLockShared",
        "DVSP_REGISTRY",
        "FltGetFileNameInformation",
        "mxR+?[",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_IP_LOCAL_ADDRESS",
        "LwfEnable",
        "Tcpip.Parameters",
        "|$pE3",
        "@UVAVAWH",
        "D$@,M",
        "FwpsCloneStreamData0",
        " A_A^A]A\\_^]",
        "tEfA;",
        "T$HHk",
        "\\REGISTRY\\A",
        " !\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHILMNOP",
        "Microsoft Time-Stamp PCA 20100",
        "IoRegisterShutdownNotification",
        "EXTERNAL ",
        "|$HE3",
        "A_A^A\\_]",
        "http://ocsp.usertrust.com0",
        "FwpmCalloutAdd0",
        "RecvNBLHandler_DecideAction: should be blocking %X>%X",
        "@A]A\\_^]",
        "ZlprH",
        "[context=dircontent] : unexpected entry '%s'",
        "D8t$@t;L95",
        "\\DEVICE\\NAMEDPIPE\\NTSVCS",
        "bad log level",
        "OSUpgrade Logic [OS Upgrade in progress] EPkPsGet=%d ",
        "lsass.exe",
        "NdisEnable",
        "FWPS_LAYER_OUTBOUND_IPPACKET_V4",
        "ModuleHookCallback",
        "L$ VWAVH",
        "A_A^A\\^[]",
        "ProcessingBinaryDumpedRules",
        "20221116124202Z",
        "FirewallSetRuleFlags: %s (0x%lX=>0x%lX)",
        "local",
        "^,9{&vP",
        "\\system32\\drivers\\vsconfig.xml",
        "H9=~?",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CONTROLSET001",
        "HKLM\\SOFTWARE\\ComputerAssociates\\Anti-Virus",
        "D9s u",
        "L$PE3",
        "dircontent",
        "OSUpgrade Logic PVOID=%p, Value=%d",
        "no relative position specified",
        "FWPS_LAYER_ALE_RESOURCE_ASSIGNMENT_V6",
        "write",
        "^@tJH",
        "D$H9A",
        "UVAWI",
        "NdisDeregisterProtocol",
        "FwFragStateAdd",
        "FILE ",
        "ClearAllLogs",
        "NdisUnchainBufferAtFront",
        "Common Startup",
        "&S|9a",
        "H9x t",
        "FwpsInjectTransportSendAsync0()",
        "tfSVH",
        "Flags",
        "Kx%qg",
        "nomonitornotify",
        "\\$ E3",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_IP_REMOTE_ADDRESS",
        "binary",
        "VSDATANT: DriverUnload->FilterUnload",
        "(UDP|TCP): %d>%d",
        "IoCreateDeviceSecure",
        "vsdrinst.exe",
        "SUVWATAUAVAWH",
        "0A^_^",
        "\\Driver\\epklibproxy",
        ".text$mn$00",
        "services.exe:%x(%d) %x(%d) %wZ",
        "WEDNESDAY",
        "@8k4th",
        "A_A^A]_^[]",
        "INIT$s",
        "D$ <#",
        "m0k0i",
        "DVSP_FILE_DRIVER",
        "9^8vNfff",
        "%.h<k",
        "FwpsInjectTransportSendAsync0",
        "vsTdiInsertStream",
        "A9P`v>",
        "{ ATAVAWH",
        "error",
        "=NDMPu",
        "greater",
        "UninstPwdHashDA",
        "socket",
        "REM NOT IN",
        "KeBugCheckEx",
        "OSFirewallTerm",
        "DisableFWProtectionOnUpgrade",
        "param",
        "OSFW_ProcessDestroy",
        "VSWFP_RequestCreatePool",
        "\\$ UATAUAVAWH",
        "\\Registry\\MACHINE\\SOFTWARE\\Citrix\\Configuration",
        "L$0H%",
        "D$`E3",
        "unknown tag",
        "d$hD9F8",
        "VarFileInfo",
        "N0L0J",
        ".rdata",
        "OsfwEngineClearRootEventGroup",
        " sflg=%lx act=%lx",
        "IP_IXMP",
        "delvalue",
        "FW_CTRL_DEL_RULE",
        "ICMP_TIMESTAMP_REPLY",
        "DVSP_FILE_LOG",
        "HHf9Kl",
        "FwDebugMsg",
        "L$8Hc",
        "\\??\\%s:%s\\system32\\drivers",
        "VAUAVAWH",
        "`A__[",
        "ALLOW ",
        "FWP_ACTION_NONE",
        "t$@H;",
        "1(0&0",
        "ProcessAttributeGlobal",
        "READFUTURE",
        "\\Internet Logs\\IAMDB.RDB",
        "xA_A^A]A\\_]",
        "@WATAUAWH",
        "invalid <evententry> tag",
        "NdisDebugStates",
        "Uuy/z",
        "StringFileInfo",
        "ExFreePoolWithTag",
        ":B@rkA",
        "L91uSL",
        "NDISWAN",
        "dstport",
        "\\SystemRoot\\Internet Logs\\osfwlog%d.txt",
        "ProcessAttributeUlimit",
        "D$@E3",
        "VSWFP_LAYER_OUTBOUND_MAC_FRAME_802_3",
        "alert",
        "<0|#<9",
        "Unexpected end of file",
        "|$Hff",
        "module",
        "UVAVH",
        "H9n<t4",
        "invalid customtext attribute",
        "IoGetRelatedDeviceObject",
        "VSWFP_StreamClassifyPostProc",
        "SA|X=G",
        "HKCS\\Services",
        "PERSISTENT ",
        "portrange",
        "RtlInitAnsiString",
        "DVSP_FILE_XMLCONFIG",
        "REMOTE ",
        "New Jersey1",
        "L$XH3",
        "FWPS_LAYER_DATAGRAM_DATA_V6",
        "TRACEROUTE",
        "VsWfpDebugAddress",
        "class",
        "%wZ\\system32",
        "@SUVWAVH",
        "MasterImage",
        "L$pE3",
        "WH_CBT",
        "<? a='b' c = \"d\" ?>",
        "FwpmEngineClose0",
        "@USVWAVH",
        "imagepath",
        "thSVH",
        "\\$ VWAVH",
        "L95\\|",
        "ICMP_INFO_REPLY",
        "OsfwInsertDriverEntry",
        "t9H9Q",
        "TCP_FLAG_RST",
        "HKLM\\SOFTWARE\\ComputerAssociates\\Anti-Virus\\Resident",
        "NdisFreeBufferPool",
        "20221118102006Z0t0:",
        "FwSendRecvPacket",
        "too many firewall tags",
        "VSDATANT: DriverUnload<-UnprotectAllFiles",
        "RtlGetVersion",
        "KePulseEvent",
        "@USVWATAUAVAWH",
        "ipsubnet",
        "HKCS\\Services\\Tcpip\\Parameters",
        "8\\t@I",
        "FwpmEngineOpen0",
        "ethernetaddress",
        "ProcessAttributeOperator",
        "FwpsReferenceNetBufferList0",
        "ProcessAttributeParam",
        " Microsoft Operations Puerto Rico1",
        "FltRegisterFilter",
        "strchr",
        "FWPS_LAYER_ALE_FLOW_ESTABLISHED_V6",
        "UATAUAVAWH",
        "6*f(_",
        "D9=g=",
        "VSWFP_LAYER_ALE_ENDPOINT_CLOSURE_V6",
        "loglevel",
        "HcQ<L",
        "IsExpandable",
        "FirewallSetLockupInfo:",
        "OsfwObjectAllocate",
        "VSDATANT: DriverUnload->DeinitMapMemory",
        "ZwOpenSymbolicLinkObject",
        "VSWFP_SocketCreateUnsafe",
        "totime",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\WOW6432NODE\\CLASSES",
        "L9|$(u",
        ".xdata",
        "DVSP_FILE_PAPRELOAD_ZA",
        "too many subevent attributes",
        "nondirectional",
        "@tCH;N0u0",
        "http://ocsp.sectigo.com0",
        "A;P`r",
        "IoAttachDeviceByPointer",
        "ZlprI",
        "FWPS_LAYER_OUTBOUND_TRANSPORT_V6_DISCARD",
        "C:\\Windows\\System32\\runonce.exe",
        "protocolrange",
        "OSFW_Events",
        ".idata$2",
        "FWBlockAll",
        "^HD<x6",
        "FWPS_LAYER_OUTBOUND_TRANSPORT_V4",
        "\\system32\\services.exe",
        "RtlUpcaseUnicodeString",
        "VSWFP_AuthListenClassifyCallback",
        "H9A|u",
        "UWAVH",
        "VATAWH",
        "VSDATANT: FltCallbackInterfaceUnload->FltUnregisterFilter (0x%p)",
        "A^A]A\\_^][",
        "Msg:BLOCK",
        "chttp://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0",
        "ObfDereferenceObject",
        "_strnicmp",
        "HKLM\\SYSTEM\\Setup",
        "NONLOCAL",
        "&Q92 ",
        "FirewallAddRule: %s",
        "accept",
        "\\$`H;",
        "DEFAULT",
        "Class",
        "250722210349Z0",
        "pA^][",
        "J2QDw:",
        "L$xtN",
        "VSDATANT: DriverUnload<-StopDriverWorkerThread",
        ".idata$3",
        "\\$@E3",
        "Process",
        "9\\uJD",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_IP_LOCAL_INTERFACE",
        "D$TD9u",
        "L$@fA",
        "@(9CXt",
        "OsfwEngineTeardownEvent",
        "MmUnloadSystemImage",
        "portgroup",
        "Microsoft Corporation1200",
        "cName: %s",
        "NdisDebugSnifferPort",
        "IP_TCP",
        "A;^8r",
        "Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z",
        "F8$8J",
        "\\Intern~1",
        "NdisDebugSnifferAll",
        "IP_TCP_UDP",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_IP_LOCAL_PORT",
        "ip type is invalid",
        ":Check Point Internet Securit",
        "IoAttachDevice",
        "AllowRtrAdvIn",
        "t$ WAVAWH",
        "DigiCert Trusted Root G40",
        "H9{ t",
        "LegacyTcpReg",
        "ZwDeleteValueKey",
        "H8f9Klt",
        ")Microsoft Root Certificate Authority 20100",
        "\\Registry\\MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\Endpoint Security\\Secure Uninstall\\ChallResp",
        "ExAcquireSpinLockExclusive",
        "spSVD",
        "ETH_ADDR (%s) != %s",
        "f9,Yu",
        "L$HH3",
        "\\AppData\\Local\\Microsoft\\Windows\\Burn\\Burn",
        "Start",
        "CISCO_TRACE",
        "GetRuleRefEntryTag",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_IP_REMOTE_PORT",
        "FwSendRecvPacket: t=%x proto=%x act=%x",
        "UVWAVAWH",
        "T$pfA+",
        "UNHOOK",
        "VSDATANT: DriverUnload->CpbUninitializeEpklib",
        "Bad parameters",
        "MASKEQ",
        "FW_CTRL_ADD_IPLOCAL",
        "CPAPPDATADIR",
        "services.exe",
        " sp=%hu dp=%hu",
        "=_C &",
        "D;CXu",
        "\\DEVICE\\HarddiskVolume",
        "FWPS_LAYER_ALE_AUTH_LISTEN_V4",
        "FWPS_LAYER_ALE_RESOURCE_ASSIGNMENT_V6_DISCARD",
        "Type %s",
        "ExpInterlockedPushEntrySList",
        "t$HtSH",
        ")D$`H",
        "VSDATANT: DriverUnload<-NdisFreeSpinLock NdisVsdataHookSpinLock",
        ";Eow]L",
        "DST_UNREACHABLE",
        "=0;09",
        "NOT IN",
        "cryptGetFunctionList",
        " ty=%x/%x",
        "A;o8r",
        "VSDATANT: DriverUnload<-IoUnregisterShutdownNotification",
        "FW_CTRL_DUMP_LIST",
        "L;5I^",
        "FW_CTRL_ADD_STATE",
        " A_A\\_",
        ".text",
        "netwrite",
        "strncat",
        "fD9,xu",
        "protocols",
        "MULTICAST_TRACEROUTE_RESPONSE",
        "SOCK (%s/%s) == LOCAL (SUB)NET BROADCAST:%hu",
        "VERIFY ",
        "2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0",
        "tiH9A",
        "ProcessAttributeMatch",
        "FwpsQueryPacketInjectionState0",
        "KeInitializeMutex",
        "@89CXt",
        "@USVWATH",
        "FwEvalRules(%s %s)",
        "INVALID",
        "NdisAllocatePacketPool",
        "RegistryOpenEx",
        "L$@E;",
        "F:\\ckp\\src\\EP_Vsdata\\E86_90_EWDK\\Sys\\Release\\x64\\Vsdatant.pdb",
        "PsGetThreadProcessId",
        "NOTIFY ",
        "RtlUnicodeStringToAnsiString",
        "DVSP_REGISTRY_AV",
        "A_A^A]A\\_^]",
        "TERMNT ",
        "ALECLASSIFY",
        "delete",
        "FwStateFind: adding NAT state (incoming)",
        "dwPktTTL: %lu",
        "assign",
        "RTP/AVP",
        "USVWATAUAWH",
        "OsfwRuleCreateItemEntry",
        "FwpmTransactionBegin0",
        "FW_CTRL_EVAL_RULES",
        "|$0E3",
        "ZlgtH",
        "partial",
        "FW_CTRL_ARP_ACTION",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\arclib.dll",
        "Vs5sE",
        "9D$xu0",
        "\\??\\PIPE\\",
        "dwPosition: %08lx",
        "ROUTE (%#lx) addr:%08lx gw:%08lx mask:%08lx",
        "NdisFIndicateReceiveNetBufferLists",
        "Dump of Firewall Rules (t=%x):",
        "ZwQueryDirectoryFile",
        "L9yHtTH",
        "ZwWriteFile",
        "block",
        ".text$mn",
        "logging",
        "%s\\%S",
        "persistafterstartup=true",
        "Tel Aviv1/0-",
        "EnableFileProtection",
        "IofCallDriver",
        "tinvalid allow attribute",
        "PA_A\\^",
        "askranges",
        "<=9Tqdk",
        "FWPS_LAYER_ALE_AUTH_CONNECT_V4_DISCARD",
        "System.VETMONNT",
        "false",
        "KeAreApcsDisabled",
        "********  OSFW is off *********",
        "XA\\_^[",
        "going to first MDL",
        ".00cfg",
        "recursive rule tags",
        "L$(fA",
        "|$(E3",
        "FltQueueGenericWorkItem",
        "t|A80",
        "FltInstanceSetup",
        "CurrentMasterBlade",
        "FirewallArpTableDel",
        "Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0",
        "0A_A^_",
        "DbgPrint",
        "VSDATANT: DriverUnload->ObCallbackInterfaceUnload",
        "V1_MEMBERSHIP_REPORT",
        "C:\\Windows\\SysWOW64\\runonce.exe",
        "Arp1394",
        "VSDATANT: DriverUnload->StopFirewall",
        "too many rules tags",
        "REJECT",
        ":PXuhH",
        "tfSVL",
        "operation",
        "8\\t|H",
        "VSWFP_LAYER_INBOUND_MAC_FRAME_802_3",
        "FwpmFilterDeleteById0",
        "|$ ATAVAWH",
        "USVWATAUAVAWH",
        "t$ AVH",
        "windeploy.exe",
        "CP64DIR",
        "t$8E3",
        "Wanarp",
        "invalid ulimit attribute",
        "F3d9GT",
        "hRule: %08lx",
        "RtlInitUnicodeString",
        "EPkAuFreeSignerInfoProxy",
        " A_A^]",
        "isdigit",
        "A_A^_^]",
        "InternalName",
        "PA^A\\_^[",
        "FWPS_LAYER_STREAM_V6_DISCARD",
        "230308195805Z0",
        "SUVWAVAWH",
        "== %#lx",
        "InstallDirectory",
        "KHH9J",
        "AC_TermOnExecution",
        "FwReplaceState(new)",
        "}PH.=C",
        "ZwReadFile",
        "FWPS_LAYER_INBOUND_IPPACKET_V4",
        "hostname",
        " A^_^][",
        "toport",
        "u,95K",
        "|$ uY",
        "hA_A^",
        "SUNDAY",
        "T$0E3",
        "Msg:-",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\VET-REC",
        "globalwindowshook",
        "\\Device\\LanManRedirector",
        "\\$ UWAUAVAWH",
        "pathnocase",
        "GetProcessIdFromProcessHandleEx",
        "invalid notify attribute",
        "|$XE3",
        "\\Device\\",
        "NdisDebugRules",
        "FWPS_LAYER_ALE_AUTH_RECV_ACCEPT_V6_DISCARD",
        "HKCS\\Services\\Vsdatant",
        "@UVWATAVAWH",
        "MASKNEQ",
        ".idata$4",
        "FwStateFind frag(1=>0 sfc=%lu)",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\safePrograms.xml",
        "VsWfpDebugUdpPortIgnore9",
        "ACCEPTED",
        "D9|$$",
        "VSWFP_InboundNBL_DecideAction: should be blocking %X>%X",
        "RtlLengthSecurityDescriptor",
        "HKCS\\Services\\Vsmon",
        "too many match attributes",
        "L$`H3",
        "H89KXt",
        "L$$fff",
        "H9]ht",
        "FW_CTRL_DEL_STATE",
        "TCP_FLAG_ALL",
        "CreateRuleGroup",
        "bitclr",
        "&%o=n",
        "  2021 Copyright Check Point Software Technologies Ltd.",
        "going to next MDL",
        "FwStateCheck(h=%x) ticks: state=%x upd=%x hupd=%x supd=%x",
        "GROUP (%s) %s %08lx",
        "destination",
        "lzone",
        "VSDATANT: DriverUnload->StopDriverWorkerThread",
        "XA_A^A]A\\_^[]",
        "wcsncmp",
        "u5D;oXu/D;",
        "H9y t",
        "D$(fD",
        "xSu$W",
        "FWP_ACTION_BLOCK",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Parameters",
        "u*9l$pu$",
        "Tcpip",
        "j0h0?",
        "t$8fD",
        "FltParseFileName",
        "ZwOpenProcess",
        "ipprotocol",
        "pw@Hc",
        "IoQueueWorkItemEx",
        "%SystemDrive%",
        "t,H;5I",
        "H9o0t",
        "CPAppDataDrive",
        "COMMENT: %s",
        "|$(9y(",
        "    seth=",
        "VALID ",
        "%s%02x",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\vet_modules.txt",
        "D8mHt",
        "PsLookupProcessByProcessId",
        "dirpath",
        "STOPFUTURE",
        ">Mp$d",
        "0A_A^]",
        "WH_MOUSE_LL",
        "%ws\\RebootFlag.pending",
        "221116124159Z0?",
        "UNKNOWN ",
        "OSFWLogFactor",
        "\\HARDWARE PROFILES\\",
        "I\\$hH",
        "VSWFP_RequestAllocBuffer",
        "@UVAUAVAWH",
        "h.rdata",
        "debuglevel",
        "ProcessAttributeClass",
        "f;|$pr",
        "short",
        "CONNECT",
        "operator",
        "weight",
        "WH_KEYBOARD",
        "D$xf;",
        "A;|$8r",
        "VSWFP_LAYER_DATAGRAM_DATA_V4",
        "FwpmSubLayerDeleteByKey0",
        "BLOCK",
        "FwStateAdd",
        "[HandleFileExtension] '%s' too many files. Only processed %d files",
        "0A^^[",
        "PsSetLoadImageNotifyRoutine",
        "groups",
        "FirewallEvalRules(%s %s)",
        "FWPS_LAYER_ALE_AUTH_LISTEN_V6",
        "20221116124159Z",
        "\\$0t3H",
        "extension",
        "@SUWATAUAVAWH",
        "isExcludedProcess failed, process image name buffer is null",
        "Microsoft Corporation1&0$",
        "InstallProbeReadHooks",
        "\\DEVICE\\NAMEDPIPE\\",
        "INVITE",
        "ProcessAttributeContext",
        "l$hE2",
        "EL$XH",
        "T$HE3",
        "`A^_^",
        "processhacker",
        "u49=D+",
        "t$xu>",
        "(A^A]A\\_",
        "CreateProcessNotifyRoutineEx",
        "\\$ WATAWH",
        "!= %#lx",
        "ERROR ",
        "t$ WATAUAVAWH",
        "KeQueryTimeIncrement",
        "\\DosDevices\\A:\\",
        "\\Registry\\Machine\\System\\CurrentControlSet\\Services",
        "LOCAL",
        "before",
        "The USERTRUST Network1.0,",
        "Cannot print SHORT type",
        "210525000000Z",
        "<0:08",
        "_vsnprintf",
        "MONITR ",
        "{(D9fD",
        "$< u ",
        "VSWFP_StreamClassifyPreProc",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Instances",
        "L$pfD",
        "SetupFile",
        "\\$ UH",
        "TranslatePath",
        "IoDeleteSymbolicLink",
        "/Microsoft Windows Third Party Component CA 2012",
        "},/r-",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Parameters\\",
        "InstallDirDevice",
        "@SVWATAUAVH",
        "OSUpgrade Logic MS Signer: %s [Signer: %*.*s Length=%d] Removed = %d ",
        "A_A^_^][",
        "VSWFP_WfpRegisterInjection",
        "HandleDirContent",
        "D$`L+",
        "\\Registry\\MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\Endpoint Security\\TID",
        "WH_KEYBOARD_LL",
        "CPEPConnectDevice",
        "(D$@H",
        "H9:t%",
        "KeUnstackDetachProcess",
        " deth=",
        "FORWARD",
        "boSVk",
        "ObQueryNameString",
        "start",
        "D$0u`H",
        "ZwCreateEvent",
        "A]A\\^",
        "|$8E3",
        "D9}#~LH",
        "%s%02x-%02x-%02x-%02x-%02x-%02x",
        "FwStateClear",
        "t$pHc",
        "EITHER",
        "KyCx@",
        "|$@A_A^A]A\\",
        "SOFT_RULE ",
        "too manny reference attributes",
        "NdisFreeNetBufferList",
        "VSmsI",
        "MasterBlade",
        "\\SystemRoot\\system32\\drivers\\vsparam.reg",
        "OsfwEngineSetDefaultEventGroup",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\SoftRulesDump.bin",
        "E9|$8vw",
        "THURSDAY",
        "Properties",
        "fD9,Fu",
        "360428235959Z0i1",
        "UWATAVH",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant\\Instances\\Vsdatant - Instance",
        "\\REGISTRY\\MACHINE",
        "NdisAllocateMemoryWithTagPriority",
        "PHH9H",
        "d$PE3",
        "PAGE$s",
        "@USVH",
        "OnProcessCreateCallback",
        "NdisAllocateBufferPool",
        "Zone Labs Client",
        "@A^][",
        "FwpsInjectTransportReceiveAsync0",
        "ip subprotocol is invalid",
        "L$ WH",
        "@USWATAVAWH",
        "D$h=#",
        "[C]e=P",
        "VSDATANT: DriverUnload->OSFirewallTerm",
        "terminateprocess",
        "IP_VPN",
        "9P`v;",
        "MASK_REQUEST",
        "igmpprotocol",
        "H95m6",
        "NOT IN ",
        "FwStateAdd(fail)",
        "RtlAppendUnicodeToString",
        "RtlAnsiStringToUnicodeString",
        "strcmp",
        "NdisFIndicateStatus",
        "D;K$t",
        "@WATAUAVH",
        "TranslateToFilePathDrive",
        "INREMOTEGROUP",
        "t$ WH",
        "FwClrRule: %s",
        "HKCS\\Services\\Eventlog\\System\\VETFDDNT",
        "VsdatantDebugIoctl",
        "FWPS_CALLOUT_NOTIFY_ADD_FILTER",
        " A_A^_",
        "too many hookafd tags",
        "d$ UAVAWH",
        "5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C",
        "t$ UWAVH",
        "Microsoft Corporation1)0'",
        "PsIsThreadTerminating",
        "too manny operator attributes",
        "logdb",
        "igmpprotocolrange",
        "Sectigo RSA Time Stamping CA",
        "ICMP_ECHO_REQUEST",
        "callback",
        "_PreProcessThreadOperationCallback",
        "NOTLOCAL",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\ComputerAssociates\\Anti-Virus\\Resident",
        "FW_CTRL_xxx",
        "\\Registry\\MACHINE\\Software\\Wow6432Node\\Zone Labs\\ZoneAlarm",
        "D9t$ ",
        "Services.VETFDDNT",
        "<3\\uBL",
        "OsfwInsertImageEntry",
        "== %s",
        " port:%hu=>%hu",
        "@8k4u",
        "VSDATANT: DriverUnload->CmCallbackInterfaceUnload",
        "TCPIP_ARP1394",
        "too many lockup info tags",
        "setuphost.exe",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\isafe.exe",
        "CHANGE ",
        "H9=Mi",
        "L$0E3",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_IP_LOCAL_PORT",
        "D$L9D$Hu",
        "VSDATANT",
        "ZwSetInformationFile",
        "]:l5\\",
        "\\??\\%s:",
        "330810235959Z0j1",
        "Cannot print BINARY type",
        "FWPS_LAYER_ALE_AUTH_RECV_ACCEPT_V4",
        "ETHERNET",
        "NdisDebugSnifferProtocol",
        "NOTINREMOTEGROUP",
        "ROUTE DST",
        "OsfwRuleCreateRuleSet",
        "FWPS_LAYER_INBOUND_IPPACKET_V6",
        "{hH9y",
        "FwpsCalloutRegister1",
        "SystemSetupInProgress",
        "IoDeleteDevice",
        "ExAllocatePoolWithTag",
        "value",
        "7uBL9",
        "H95@;",
        "GetRuleSetTag",
        "exetrack",
        " ' or \" expected",
        " A_A^^",
        "S-1-5-18",
        "persistafterstartup=false",
        "t=D9|$xt(",
        "D8B%t",
        "MmHighestUserAddress",
        "221104190138Z",
        "FirewallArpTableAdd",
        "fg:SM",
        "VsWfpDebugUdpPortIgnore0",
        "241126235959Z0",
        "izone",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\cafix.exe",
        "SearchCharW",
        "ProtectProcess",
        "HandleFileExtension",
        "f;D$pr",
        "RtlCreateSecurityDescriptor",
        "(https://www.microsoft.com/en-us/windows 0",
        "VSDATANT: DriverUnload<-WFPIPv6Cleanup",
        "_,9{&vO",
        "HKCS\\Services\\Vsmon\\Security",
        " NOSTATE",
        "SEND_OR_RECEIVE_OR_FORWARD",
        "too many param attributes",
        "invalid <rulerefentry> tag",
        "Sectigo RSA Time Stamping CA0",
        "FWPS_LAYER_ALE_AUTH_CONNECT_V6",
        "REM IN",
        "source",
        "RtlLengthSid",
        "ADDR (%s/%s) %s",
        "missing end tag",
        "DigiCert Inc1",
        "|$PH9",
        "FROM_ROUTE ",
        "TIME_EXCEEDED",
        "@A_A^_",
        "VsZwTerminateProcess",
        "FwFragStateAdd(fail)",
        "ipaddress",
        "FWPS_LAYER_ALE_RESOURCE_ASSIGNMENT_V4_DISCARD",
        "4?t7H",
        "CreateEventGroup",
        "RtlFreeAnsiString",
        ".text$s",
        "fD9$Fu",
        "VSDATANT: DriverUnload->NdisFreeSpinLock NdisVsdataHookSpinLock",
        "too manny allow attributes",
        "D$0fA",
        "invalid xml char",
        "IoFreeMdl",
        "PsGetVersion",
        "Microsoft America Operations1&0$",
        "create",
        "DROP ",
        "FirewallCtrl",
        "\\REGISTRY\\USER",
        "PsSetCreateProcessNotifyRoutineEx2",
        "T$`fA",
        "invalid <itementry> tag",
        "ZwCreateKey",
        "DONE ",
        "H9|$H",
        "server",
        "RegistryReadSubKeyStringW",
        "O0M0K",
        "subprotocol",
        "StartProtection",
        "https://sectigo.com/CPS0",
        "Soft Rule",
        "%wZ\\SysWOW64",
        "NdisAllocateNetBufferAndNetBufferList",
        "%s: adding NAT state (ident in)",
        "IPChecksummVerification",
        "tLfA;",
        "too manny ask attributes",
        "{ AVH",
        "ApplyDumpedRules",
        "9] vaff",
        "FltReleaseFileNameInformation",
        "system",
        "A_A]A\\_",
        "LOCAL ",
        "l$8M;",
        ">NGdx",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET\\SERVICES\\epklibproxy",
        "H9=zG",
        "VSDATANT: DriverUnload<-OSFirewallTerm",
        "FwpsClassifyOptionSet0",
        "PasswordIsValid",
        "Sectigo Limited1&0$",
        "#Sectigo RSA Time Stamping Signer #3",
        "towupper",
        "VSDATANT: DriverUnload<-DeinitMapMemory",
        "too many firewall debug tags",
        "IP Proto %d",
        "240202190138Z0",
        "|$ 9A8",
        "%s arp: t=%lx h=%lx pflg=%lx sip=%d.%d.%d.%d tip=%d.%d.%d.%d ty=%x act=%lx",
        " A_A^A\\",
        "FltFreeGenericWorkItem",
        "\\$@A9z`vMA",
        "NdisGetVersion",
        "@SVAVH",
        "c$`o]a",
        "%*.*s",
        "OsfwRuleEvaluateItemEntry",
        "~49q(",
        "FWPS_LAYER_ALE_FLOW_ESTABLISHED_V4",
        "CLOSE",
        "\\Device\\vsdatant",
        "FW_CTRL_DEFAULT_STATE_TTL_SET",
        "UVWATAUAVAWH",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_IP_REMOTE_ADDRESS",
        "AllocateUnicodeString",
        ".fffffff",
        "PHASE2",
        "MmGetSystemRoutineAddress",
        "FLTMGR.SYS",
        "ALL NETWORK",
        "AllocateMemAndReadFile",
        "Application Control blade",
        "WH_JOURNALPLAYBACK",
        "tDeviceEventName",
        "ZBWUP",
        "L$`E3",
        "enabling the rules failed",
        "PACKETDRIVER",
        "(Hcy<E3",
        "OsfwRuleCreateEventGroup",
        "FwpsAllocateNetBufferAndNetBufferList0",
        "[K]taM?",
        "invalid askonce attribute",
        "<0|&<9",
        "%wZ%s",
        "ipprotocolrange",
        "OsfwObjectLock",
        "VSDATANT\\Parameters",
        "+D$DA",
        "t*@8{%t",
        "t$0fD",
        "_5J:#",
        "VWATAVAWH",
        "A;~8r",
        "IP_ICMP",
        "FwHandleRtrAdv",
        "DriverEntry",
        "Salford1",
        "\\SystemRoot\\system32\\drivers\\vet-rec.sys",
        "|$ tKI",
        "A^A\\_^[]",
        "PsTerminateSystemThread",
        "FWPS_LAYER_ALE_AUTH_LISTEN_V4_DISCARD",
        "EtwUnregister",
        "A_A]A\\_^[]",
        "__RegNtPreDeleteKey",
        "wednesday",
        "ECHO_REPLY",
        "220310195805Z",
        "FwpmBfeStateUnsubscribeChanges0",
        "FW_CTRL_CLR_LIST",
        "ZwOpenFile",
        "D9=O9",
        "@SUVWATH",
        " sfc=%lx act=%lx",
        "h VWAVH",
        "ASK1CE ",
        "FWPS_LAYER_ALE_FLOW_ESTABLISHED_V4_DISCARD",
        "XA_A^A]A\\_^",
        "|$(;y(",
        "D8%Q(",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Services\\vsdatant",
        "ZwQueryInformationProcess",
        "invalid <ruleset> tag",
        "HTTPCLOSE",
        "380118235959Z0}1",
        "0}0i1",
        "?u0fD9Y",
        "CA.AV",
        "NOT LOCAL (SUB)NET BROADCAST",
        "NdisAllocateGenericObject",
        "VSDATANT: DriverUnload->WFPIPv6Cleanup",
        "%s\\%s",
        "VWAUAVAWH",
        "D8T$(t,",
        "A_A^A]A\\_^][",
        "DataBasePath",
        "L$8A\"",
        "t$PE3",
        "ALTERNATEHOSTADDRESS",
        "FwpmTransactionAbort0",
        "Translation",
        "AllowFTPD%05hu",
        ".in-addr.arpa.",
        "UVATAUAVAWH",
        "global",
        "d$@E3",
        "GetDrvSyncEvent",
        "Security",
        ".rsrc$02",
        "yQ{D.2",
        "InitFileStringTableDevice",
        "NdisFSendNetBufferLists",
        "REDIRECT ",
        "DeviceName",
        "avregistry",
        "VsWfpDebugProtocol",
        "\\Device\\LanmanRedirector\\",
        "BogusDriver",
        " A_A^A]_^",
        "D9=T?",
        "tosrcport",
        "|$ E3",
        "FWPS_LAYER_OUTBOUND_TRANSPORT_V4_DISCARD",
        "Group%lx",
        "D$(KyCxE3",
        "isProcessCPSigned",
        "invalid name attribute",
        "VSWFP_LAYER_ALE_RESOURCE_RELEASE_V6",
        "]usE;",
        "DriverYield",
        "t-f9q",
        "PA_A^A]_^][",
        "H;X(t5H",
        "SRC_QUENCH",
        "fD;c.u",
        "t$ UWATAVAWH",
        "@UAVH",
        "FW_CTRL_DEL_ARPTABLE",
        "EPkAuGetUnverifiedEmbeddedSignerInfoProxy",
        "LOCALBCAST",
        "ATAVH",
        "FW_CTRL_GET_OPT",
        "ROUTERSOLICIT",
        "tDH9=",
        "CleanOnBoot",
        "VsWfpDebugTcpPort",
        "DeviceType",
        "FwReEvalRules - synth pkt",
        "port is invalid",
        "GetFileNameFromFileInformation",
        "HKCS\\Services\\Vsmon\\Enum",
        "NdisDebugArpTable",
        "Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0",
        "vsdatant",
        "NdisFreeGenericObject",
        "startuphookafd",
        "KeClearEvent",
        "tfSVD",
        "Manchester1",
        "VsWfpDebugTraffic",
        "NdisFreeMemory",
        "\\SystemRoot\\system32\\drivers\\vsndis.reg",
        "`INIT",
        "G,f9D$xu",
        "TIMESTAMP",
        "VSDATANT: DriverUnload",
        "VSDATANT: DriverUnload<-CmCallbackInterfaceUnload",
        "HKCS\\Services\\Eventlog\\System\\VETMONNT",
        "evententry",
        "LegacyEventGroup",
        " ty=%lu",
        "http://www.checkpoint.com 0",
        "!!!EXCEPTION!!! Log string size over 2048",
        "CREATE",
        "q\\Q17",
        "\\??\\%s:%s\\system32",
        "OSFW_ProcessCreateComplete",
        ")D$pA",
        "926005812",
        "RootEventGroup",
        "SeQueryInformationToken",
        "invalid class attribute",
        "\\SystemRoot\\system32\\drivers\\DisconnectedPolicy.xml",
        "CPEPConnectDrive",
        "imcomplete time tag",
        "DisableFireWire",
        "ErrorControl",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Control\\NetworkSetup2\\Filters\\{AC30BFB5-834B-46D2-B912-6CE71684EB2D}",
        "VSDATANT: DriverUnload<-RestoreProtection",
        "FltPreIRP_MJ_ACQUIRE_FOR_SECTION_SYNCHRONIZATION",
        "232825+4695800",
        "times",
        "MmUnmapLockedPages",
        " A^^]",
        "toprotocol",
        "ImagePath",
        "M;T$puyH",
        "HandleContextSymbolicPath",
        "delkey",
        "VsWfpDebugUdpPortIgnore4",
        "IoCreateDevice",
        "(A]A\\_[",
        "Jersey City1",
        "FltPreIRP_MJ_CREATE",
        "VSDATANT: DriverUnload->PsRemoveLoadImageNotifyRoutine",
        "& %#lx == %#lx",
        "fD;k,",
        "Convert8Dot3ToLongPath",
        "too many attributes",
        "EpklibProxyUnloadDriver",
        "equalnocase",
        "QUERY",
        "IMPORTED",
        "FwArpStateAdd(fail)",
        "NdisFReturnNetBufferLists",
        "VSmsL",
        "ObRegisterCallbacks",
        "L9{xu%H",
        "GROUP ",
        "ipsubprotoflaggroup",
        "@A_A^A\\",
        "\\REGISTRY\\MACHINE\\SOFTWARE\\ComputerAssociates\\ISafe\\Server",
        "too manny value attributes",
        "default",
        "FwStateFind(RECV_SRC0)",
        "too many customtext attributes",
        "D$8Hi",
        "-end of deny msg",
        "RtlGetSaclSecurityDescriptor",
        "rzone",
        "HKCS\\Control\\GroupOrderList",
        "VSWFP_LAYER_ALE_FLOW_ESTABLISHED_V4",
        "H;X(t2H",
        "L$DE;",
        " server:%08lx=>%08lx",
        "E;w(r",
        "VsWfpDebugNblData",
        "WATAWH",
        "H95CG",
        "L$pfA",
        "WATAUAVAWH",
        "ROUTE SRC",
        "winlogon.exe",
        "VsdatantDebugLevel",
        "ExDeleteResourceLite",
        "NdisFSetAttributes",
        "ZwLoadDriver",
        "execution",
        "%s(frag:#=%lu): t=%lx h=%lx subp=%lu sip=%d.%d.%d.%d dip=%d.%d.%d.%d id=%lx",
        "Cannot print CHAR type",
        "ExpandEnvironmentVariable",
        "FwStateFind(0 sfc=%lu)",
        "RegistryOpenQueryKey",
        "VsHaI",
        "IofCompleteRequest",
        "http://ocsp.digicert.com0A",
        "dwSubProtocol: %s",
        " REMOTE",
        "NdisAllocateNetBufferListPool",
        "ALLOW",
        "too many groups defined",
        "IP_CAST",
        "|$,D9y8",
        "D:P(A;;GA;;;SY)(A;;GA;;;BA)",
        "VsdatantDebugYield",
        "NdisFDeregisterFilterDriver",
        "!]_0t",
        "H;-0-",
        "r-McF",
        "eventgroup",
        "ExInterlockedInsertTailList",
        "!This program cannot be run in DOS mode.",
        "firewall",
        "IP_SKIP",
        "TD;w0",
        "L$ L+",
        "InstallDirDrive",
        "hA_A^A]A\\_^][",
        "filename",
        "VSmsE",
        "l$ VAVAWH",
        "ICMP_SRC_QUENCH",
        "VSWFP_LAYER_ALE_AUTH_CONNECT_V4",
        "@USAUH",
        "NdisAllocateBuffer",
        "ExEnterCriticalRegionAndAcquireResourceShared",
        "OnProcessNameCallback",
        "avfiles",
        "@UAUH",
        "VSDATANT: DriverUnload<-CpbUninitializeEpklib",
        "cppAH",
        "ZwQueryValueKey",
        "ZlCltEventGroup",
        "RtlxAnsiStringToUnicodeSize",
        "D$pH9",
        "VSDATANT: DriverUnload->PsRemoveCreateThreadNotifyRoutine",
        "NdisFreeNetBufferListPool",
        "DeleteFlag",
        "address",
        "A_A^A]A\\_[]",
        "\\Intern~1\\IAMDB.RDB",
        "5vw%M",
        "keyboard",
        "L$hH3",
        "ProcessAttributeCustomtext",
        "AUAWH",
        "%s: adding NAT state (outgoing)",
        "STRMPST",
        "@SUVH",
        "HKLM\\Software\\Wow6432Node",
        "FWPS_LAYER_ALE_ENDPOINT_CLOSURE_V4",
        "D9|$|A",
        "invalid weight attribute",
        "PROTOCOL %s",
        "ZLsoA",
        "FW_CTRL_ADD_ARPTABLE",
        "%s frag: t=%lx h=%lx pflg=%lx subp=%lx sip=%d.%d.%d.%d dip=%d.%d.%d.%d id=%x f=%s%s%s off=%hu act=%lx",
        "MULTICAST_ROUTER_ADVERTISEMENT",
        "FWPS_FIELD_INBOUND_TRANSPORT_V6_FLAGS",
        "NdisFreePacketPool",
        "A_A^A\\_^][",
        "d$`=#",
        "FwpsCopyStreamDataToBuffer0",
        "ZoneAlaram WFP Sub layer",
        "VSDATANT: DriverUnload->FreePacketLoggingResources",
        "ZwEnumerateKey",
        "startupprocess",
        "ObUnRegisterCallbacks",
        "nonlocal",
        "no group name",
        "220511000000Z",
        "%s(arp:#=%lu): t=%lx h=%lx sip=%d.%d.%d.%d tip=%d.%d.%d.%d ty=%lx",
        "@SVWH",
        "@VAWH",
        "|$\\A#",
        "@SWAVH",
        "SUAUAWH",
        "The signer found for process: %wZ, the signer is: %s",
        "XA_A^A\\_",
        "WH_???",
        "{AC30BFB5-834B-46d2-B912-6CE71684EB2D}",
        "FwReplaceState(old)",
        "PsSetCreateThreadNotifyRoutine",
        "IoWriteErrorLogEntry",
        "9}8vj",
        "GetEventGroupTag",
        "\\$ UVWATAUAVAWH",
        "OsfwEngineHookEvent",
        "SOCK (%s/%s) != LOCAL:%hu",
        "FltParseFileNameInformation",
        "PsDereferencePrimaryToken",
        "A^A]][",
        "A_A^A]A\\_^[",
        "inthex",
        "Microsoft Corporation1806",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\HardRulesDump.bin",
        "sl9=\"",
        "VsWfpDebugUdpPortIgnore5",
        "@USWATAUAWH",
        "CACHE ",
        "TCP_FLAG_ACK",
        "qDD+qHtKH",
        "A88t`A",
        "l$@I;",
        "}B$,N",
        "tuesday",
        "@USWH",
        "MmMapLockedPagesSpecifyCache",
        "\\SystemRoot\\SysWow64\\ZoneLabs\\vsconfig.xml",
        "A_A^A\\_^[]",
        "REDIRECT",
        "Bad igmp or icmp type",
        "L$ SVH",
        "invalid event attribute",
        "HKCS\\Services\\Vsdatant\\Security",
        "IoUnregisterShutdownNotification",
        "Redmond1",
        ":H@vTH",
        "FirewallClearStates: arg=%x",
        "rulestack",
        "subevent",
        ":::::::::::::::::::: !\"#$%::::::::::&&&&&&&&&:::::::'()*::::::::::::+,-./0:::::::::::1&&::::::::::::&&&&2:::::::::::34567&896:::::::&&&&&:::::::::::&&&&&&&&",
        "r :NDr",
        "gateway",
        "Exception: Code=%08x Flags=%08x Record=%p Address=%p Params=%u",
        "@UVWATAUAWH",
        "MISSING",
        "D9%^@",
        "OSFW_ProcessAddRuleForPidByHandle",
        "\\Windows\\ApiPort",
        "REJECT ",
        "lesser",
        "IoDriverObjectType",
        "8Y@v1",
        "FirewallDelState",
        "t$Ptv",
        "@SUVWATAUAVAWH",
        "Disabled",
        "ZwUnloadDriver",
        "fE9\\E",
        "360524235959Z0O1",
        "?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v",
        "_stricmp",
        "\\SystemRoot\\system32\\drivers\\vsflt.reg",
        "Microsoft Corporation1;09",
        "ExGetPreviousMode",
        "C$D8s4",
        "ICMP_TIME_EXCEEDED",
        "KeReleaseSpinLock",
        "D;u8r",
        "`A_A\\^",
        "L$PH3",
        "MATCH",
        "RtlConvertSidToUnicodeString",
        "20221117072457.135Z0",
        "D$0LL",
        "RegistryReadStringW",
        "tyH9y",
        "EPkPsGetProxy",
        ":H@s.H",
        "l$ VH",
        "|$dtEH",
        "9_&v ff",
        "pA^A\\_^]",
        "\\REGISTRY\\MACHINE\\SYSTEM\\CURRENTCONTROLSET",
        "ObReferenceObjectByHandle",
        "__RegNtPreCreateKeyEx",
        "ZwSetValueKey",
        "End Point Security",
        "NO-MATCH",
        "process",
        "t;@8=<",
        "\\$PE3",
        "d$(E3",
        "InstallIoCreateDeviceHooks",
        "WH_MSGFILTER",
        "FWPS_FIELD_OUTBOUND_TRANSPORT_V6_IP_LOCAL_INTERFACE",
        "L$PHc",
        "LegacyAvReg",
        "D$xE;",
        "tfSVI",
        "FwpmFilterAdd0",
        "FltGetFileNameInformationUnsafe",
        "?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0q",
        "UninstallAuthentication",
        "__C_specific_handler",
        "ExQueryDepthSList",
        "oleconnect",
        "OSFW_EventEvaluate",
        "SeExports",
        "1,0*0",
        "Cxt3A",
        "\\REGISTRY",
        "inverse",
        "AllocateUnicodeStringFromString",
        "PsSetCreateProcessNotifyRoutine",
        "D$h H",
        "OsfwRuleCreateImageEntry",
        "FwUpdateArpTable",
        "VSWFP_LAYER_OUTBOUND_TRANSPORT_V4",
        "WmiQueryTraceInformation",
        "L$ SVWH",
        "ZwSetSystemInformation",
        "DGMPST",
        "VSWFP_AuthConnectClassifyCallback",
        ".rsrc$01",
        "system32\\ieframe.dll",
        "X0V0T",
        "NOSTATE ",
        "%#lx ",
        "FWP_ACTION_PERMIT",
        "D9s,usH",
        "Route%lx",
        "fC94tu",
        "no execute tag",
        "VSDATANT: DriverUnload<-FreeTDIHook",
        "Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>",
        "/l}.aQ",
        "t$H9x t",
        "ipsubprotoflag",
        "No firewall tag specified",
        "route",
        "VSWFP_RequestTransportInject",
        "FileDescription",
        "debugflags",
        "|$hI;",
        ".gfids",
        "FwFragStateAdd(found)",
        "windowshook",
        "D$0E3",
        "ATAUAWH",
        "@USVWATAVAWH",
        "I<M9H",
        "VsWfpDebugUdpPortIgnore8",
        "IP_AH",
        "askonce",
        "ObfReferenceObject",
        "@8{$t",
        "@8l$@t",
        "Microsoft Corporation1%0#",
        "ProcessAttributeWeightRange",
        "H95$G",
        "Sectigo Limited1,0*",
        "TIMESTAMP_REPLY",
        "bad name attribute",
        "Apt7H",
        "too many context attributes",
        "l$ WH",
        "E0C1)0'",
        "RtlCompareString",
        "_snprintf",
        "todstport",
        "PsReferencePrimaryToken",
        "dwTickCount: %#lx",
        "3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#",
        "T$ht{H",
        "DVSP_FILES_AV",
        "FWPS_LAYER_INBOUND_TRANSPORT_V6",
        "150722210349Z",
        "SynAckCheck",
        "pcComment: %#lx",
        "FW_CTRL_ADD_RULE",
        "OsfwEngineUnhookEvent",
        "SWAWH",
        "totype",
        " EVENT",
        "VSWFP_InboundTransportClassifyCallback",
        "FWPS_LAYER_ALE_FLOW_ESTABLISHED_V6_DISCARD",
        "RtlFreeUnicodeString",
        "REAUTHORIZE",
        "CPEPS64Device",
        "mJD9i",
        "x88_!v",
        "rulesetref",
        "RtlCompareMemory",
        "_vsnwprintf",
        "thursday",
        "t$pI;",
        "ProcessAttributeWeight",
        "\\Registry\\MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\Endpoint Security\\TID\\ChallResp",
        "\\$8E2",
        "t*D8k$t",
        "v'fff",
        "A8Y!vzH",
        "icmpprotocolrange",
        "kvIp{",
        "FwStateFind(1=>0 sfc=%lu)",
        "XA_A^A]A\\_^][",
        "PrintLocalAddressesCallback",
        "VSDATANT: DriverUnload<-StopProtection",
        "FwpsPendOperation0",
        "D$ E3",
        "Section",
        "FwpmCalloutDeleteById0",
        "A]_^][",
        "LegacyZlReg",
        "ClearAllLogs: Done",
        "PHASE1",
        "< %#lx",
        "friday",
        "210930182225Z",
        "J>@G_",
        "OsfwEngineSetRootEventGroup",
        "FWPS_LAYER_DATAGRAM_DATA_V6_DISCARD",
        "CreateProcessEntryForNewProcess",
        "unload",
        "WH_FOREGROUNDIDLE",
        "FWPS_LAYER_INBOUND_TRANSPORT_V4_DISCARD",
        "SendNBLHandler_DecideAction: should be blocking %X>%X",
        "TranslateCPEPSDIR",
        "FWPS_LAYER_ALE_ENDPOINT_CLOSURE_V6",
        "isprint",
        "fF94Au",
        "VSDATANT: DriverUnload<-PsRemoveLoadImageNotifyRoutine",
        "0A_A^A]A\\_^[",
        "KeReadStateEvent",
        "ruleset",
        "OSFirewallInit",
        "FltCompletePendedPreOperation",
        "PA_A^A]A\\_^[",
        "f9,Xu",
        "\\DEVICE\\NAMEDPIPE\\SCHEDULE",
        "reverting to default startup firewall rules",
        "__RegNtPostCreateKeyEx",
        "wsockvermajor",
        "NLOCALBCAST",
        "eeSVH",
        "closing the file failed",
        "ALL IP",
        "ICMP_ROUTER_ADVERT",
        "8D$(t&",
        "Control.OrderList",
        "Tel Aviv-Yafo1/0-",
        "saturday",
        "0A^_]",
        "l$0fD",
        "FW_CTRL_GET_HANDLE",
        "FirewallEvalRules",
        "context",
        "D;S(u",
        "too many ulimit attributes",
        "OSFW_GetEventProviderParameterArrayAndSize",
        "X a)*&+",
        "D;e8r",
        "r<@8k4H",
        "HPAGE",
        "VsHaH",
        "k0i0$",
        "ZwClose",
        "no xml file",
        "SetupExecute",
        "changeentry",
        "MmProbeAndLockPages",
        "L$ VWH",
        "CreateRebootFlagPendingFile",
        "IN [%#lx, %#lx]",
        "3http://crt.sectigo.com/SectigoRSACodeSigningCA2.crt0#",
        "EPkPsUnregisterProxy",
        "IP_ESP",
        "ZwSetSecurityObject",
        ".pdata",
        "ACCEPT",
        "|$hff",
        "NON-DEFAULT",
        " deth=?",
        "after",
        "too many default attributes",
        "PsGetProcessPeb",
        "FLAGS",
        "ExQueueWorkItem",
        "ObOpenObjectByPointer",
        "D$(E3",
        "\\Registry\\MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "Lcc$A",
        "VATAUAVAWH",
        "mouse",
        "FwStateCheck(re-eval) - frag state",
        ":P@w;",
        "%02d:%02d:%02d %s ",
        "@A_A\\_",
        "OsfwObjectDereference",
        "dwLength: %lu",
        "Microsoft Windows",
        "monday",
        "!TkjE",
        "A_A^A]^]",
        "TCP_FLAG_SYN",
        "PA_A\\_",
        "&Check Point Software Technologies Ltd.1/0-",
        "Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S",
        "startupdir",
        "u\\D9- L",
        "L$0Hc",
        "8A_A^A]A\\_^][",
        "ExpInterlockedPopEntrySList",
        "MULTICAST_ROUTER_TERMINATION",
        "ZwQuerySymbolicLinkObject",
        "d$0E3",
        "ICMP_MASK_REQUEST",
        "PA_A^A]A\\_][",
        "IN {%s}",
        "221116124202Z0?",
        "230407235959Z0",
        "SUVWAUAVAWH",
        "\\$hH;",
        "SOCKNLOCALBCAST",
        "PsGetProcessInheritedFromUniqueProcessId",
        "\\Registry\\MACHINE\\SOFTWARE\\Wow6432Node\\CheckPoint\\Endpoint Security",
        "CPCommonFilesDrive",
        "\\RPC Control\\ntsvcs",
        "VSWFP_DatagramDataClassifyCallback",
        "fffffff",
        "WH_CALLWNDPROCRET",
        "D$8E3",
        "setvalue",
        "|$ UAVAWH",
        "\\SystemRoot\\system32\\vete.dll"
      ],
      "virustotal": {
        "names": [
          "vsdatant.sys",
          "vsdatant_92605812.sys",
          "VSDATANT.SYS",
          "vsdatant_win7_64.sys.6B6E64A3_4478_4297_9CD9_3D71DBCD974A"
        ],
        "scan_id": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
        "md5": "b7687358512bf036f0910fcfc587a4fa",
        "sha1": "92fba9648b8deb78e8e15436e29e3a78fce91b7b",
        "sha256": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
        "tlsh": "T124E48D47E3A511FDD0ABC1B8CA9B9113F6F1B8091720AAD74760C9153F22FE8A739365",
        "positives": 0,
        "total": 76,
        "permalink": "https://www.virustotal.com/api/v3/files/a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
        "scans": {},
        "resource": "a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5",
        "results": [
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "Skyhigh",
            "sig": null
          },
          {
            "vendor": "McAfee",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "FireEye",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Varist",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Kingsoft",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Xcitium",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "BitDefenderTheta",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "MAX",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "DeepInstinct",
            "sig": null
          },
          {
            "vendor": "alibabacloud",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          }
        ],
        "detection": ""
      },
      "selfextract": {
        "overlay": {
          "extracted_files": [
            {
              "name": "c9c5916a7b34cf7d6f74cf6d09a6d4b42ba1412b6e2168eafe6887c80f51448c",
              "path": "/opt/CAPEv2/storage/analyses/31/selfextracted/c9c5916a7b34cf7d6f74cf6d09a6d4b42ba1412b6e2168eafe6887c80f51448c",
              "guest_paths": [
                "overlay"
              ],
              "size": 38000,
              "crc32": "66385AB3",
              "md5": "83dae2d1675c209b3226f54662857554",
              "sha1": "992e77288ab36b99cff51e9adbfee49ca9b5236c",
              "sha256": "c9c5916a7b34cf7d6f74cf6d09a6d4b42ba1412b6e2168eafe6887c80f51448c",
              "sha512": "e48b41dc54ee1bf771f844a7d8b840b549478abf82d774f540b9e938ddc95c591286243c9215e43640253a96b3c6ef8e6cd2955217e121fff2f8428a1ae21b48",
              "rh_hash": null,
              "ssdeep": "768:LiQhgMgFFc2cZtDhSyiRpnUl+9zLwiQhgMgFJYi5tyiRp:LiQzgxcZtD0yijnUYzLwiQzgD75tyiz",
              "type": "data",
              "yara": [],
              "cape_yara": [],
              "clamav": [],
              "tlsh": "T1F2038DE25D687841DD836D60A2ECED63BC70B7E36E8080D122A5E4991ED77C5BB0C12F",
              "sha3_384": "26c56d67c38b3d96b7d4383b4e522b052d8a812126cb53fbf86edc2d775aba79aeb492e62b25917461f5b5e1a5db079b",
              "data": null
            }
          ],
          "extracted_files_time": 0.0016928419936448336,
          "password": ""
        }
      },
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    },
    {
      "name": [
        "vnaap.cat"
      ],
      "path": "/opt/CAPEv2/storage/analyses/31/files/6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
      "guest_paths": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
      ],
      "size": 11127,
      "crc32": "A55FB8EB",
      "md5": "f4fdf35de0ef11a52410be44e9f035ec",
      "sha1": "c67019f44b1c886ab57c0ca3528c768aa1fa2401",
      "sha256": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
      "sha512": "19a3d9b9c36e1c1b5dd5a9c7d4cd9a51674e4a56fabd14496589f86a55543cf292e2762cc1780ea1ad6902def9fb0556a7e39074b40dcf528ca2aaee8f01bebc",
      "rh_hash": null,
      "ssdeep": "192:vAKXyBJCSEIPWkjyKDUFWQFooUks9gICQX01k9z3AFN2q:YpPWRFRFU/P/R9zol",
      "type": "DER Encoded PKCS#7 Signed Data",
      "yara": [],
      "cape_yara": [],
      "clamav": [],
      "tlsh": "T1F73228E68A6D0483ADA7BCB013D8E1933C3D67D75C1095BA528BF36019837CAE30813D",
      "sha3_384": "c9806eea9da07583f6595e17bb65d1b99d825487d3d4e1b168d4a4d83b9aed2737468c4d4ffc5b848fd8a6fbdf3b53c1",
      "data": null,
      "strings": [
        "Thales TSS ESN:D082-4BFD-EEBA1%0#",
        "EEF27F3A96057E0DBE45B8B9E16AB0AC6D43FCC3",
        "O0M0K",
        "Microsoft Time-Stamp Service",
        ">http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0",
        "}PH.=C",
        "Microsoft Corporation1200",
        "N0L0J",
        "Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z",
        "300930183225Z0|1",
        "Microsoft Corporation1806",
        "Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0",
        ">NGdx",
        ")Microsoft Root Certificate Authority 20100",
        "20220728115701.813Z0",
        "1(0&0",
        "Submission I",
        "L{DE351A42-8E59-11D0-8C47-00C04FC295EE",
        "Declarativ",
        "VistaX86,VistaX64,_v100_X64_Vb",
        "ehttp://www.microsoft.com/pkiops/certs/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crt0",
        "q\\Q17",
        "as.,k{n?,",
        "17}pa",
        "Redmond1",
        "638CF92B4D471885E1DB95A6BCCE402ADB91C181",
        "U0S0Q",
        "OSAtt",
        "2z|[S",
        "-g<'<V",
        "LCheck Point Software Technologies Ltd",
        "Microsoft Time-Stamp Service0",
        "30045810_14325615438830959_1152921505695100561",
        "xSu$W",
        "1?0=0",
        "I0G1-0+",
        "210930182225Z",
        "107d3275-31a0-43c5-8fb4-78ec2617b118",
        "u0s0q",
        "@dx'\\",
        "ip(sf",
        "J>f;O",
        "230126192746Z0",
        "Microsoft Corporation1;09",
        "220728055442Z0",
        "Microsoft Time-Stamp PCA 20100",
        "vnaap.inf",
        "[bbeCG",
        "L{C689AAB8-8E78-11D0-8C47-00C04FC295EE",
        "!]_0t",
        "$Microsoft Ireland Operations Limited1&0$",
        "fg:SM",
        "BundleI",
        "/Microsoft Windows Third Party Component CA 20120",
        "1,0*0",
        "Microsoft Corporation1&0$",
        "+p&}]1",
        "17050",
        "(https://www.microsoft.com/en-us/windows 0",
        "&S|9a",
        "MDLNxx",
        "120418234838Z",
        "3http://www.microsoft.com/pkiops/Docs/Repository.htm0",
        "230308195806Z0",
        "X0V0T",
        "Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l",
        "!TkjE",
        "p%|Yi1$",
        "2:6.0,2:10.0",
        "2Microsoft Windows Hardware Compatibility Publisher0",
        "232825+4695810",
        "$Microsoft Ireland Operations Limited1",
        "Washington1",
        "Microsoft Corporation1-0+",
        ".+D8B1Qy",
        "&Qualification Leve",
        "vnaap.sys",
        "211028192746Z",
        "220310195806Z",
        "Microsoft Time-Stamp PCA 2010",
        "cp_apvna",
        "m0k0i",
        "/Microsoft Windows Third Party Component CA 2012",
        "chttp://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Third%20Party%20Component%20CA%202012.crl0",
        "270418235838Z0",
        "20220728080929Z",
        "Universa",
        "`0^0\\",
        "20220729080929Z0t0:"
      ],
      "virustotal": {
        "names": [
          "vnaap64.cat.2C0EAE67_7A1D_43BF_B3D9_476098DF60F5",
          "vnaap.cat"
        ],
        "scan_id": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
        "md5": "f4fdf35de0ef11a52410be44e9f035ec",
        "sha1": "c67019f44b1c886ab57c0ca3528c768aa1fa2401",
        "sha256": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
        "tlsh": "T1F73228E68A6D0483ADA7BCB013D8E1933C3D67D75C1095BA528BF36019837CAE30813D",
        "positives": 0,
        "total": 75,
        "permalink": "https://www.virustotal.com/api/v3/files/6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
        "scans": {},
        "resource": "6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388",
        "results": [
          {
            "vendor": "Bkav",
            "sig": null
          },
          {
            "vendor": "Lionic",
            "sig": null
          },
          {
            "vendor": "ClamAV",
            "sig": null
          },
          {
            "vendor": "CMC",
            "sig": null
          },
          {
            "vendor": "CAT-QuickHeal",
            "sig": null
          },
          {
            "vendor": "McAfee",
            "sig": null
          },
          {
            "vendor": "Malwarebytes",
            "sig": null
          },
          {
            "vendor": "Zillya",
            "sig": null
          },
          {
            "vendor": "Sangfor",
            "sig": null
          },
          {
            "vendor": "K7AntiVirus",
            "sig": null
          },
          {
            "vendor": "K7GW",
            "sig": null
          },
          {
            "vendor": "Baidu",
            "sig": null
          },
          {
            "vendor": "VirIT",
            "sig": null
          },
          {
            "vendor": "Cyren",
            "sig": null
          },
          {
            "vendor": "Symantec",
            "sig": null
          },
          {
            "vendor": "ESET-NOD32",
            "sig": null
          },
          {
            "vendor": "TrendMicro-HouseCall",
            "sig": null
          },
          {
            "vendor": "Avast",
            "sig": null
          },
          {
            "vendor": "Cynet",
            "sig": null
          },
          {
            "vendor": "Kaspersky",
            "sig": null
          },
          {
            "vendor": "BitDefender",
            "sig": null
          },
          {
            "vendor": "NANO-Antivirus",
            "sig": null
          },
          {
            "vendor": "SUPERAntiSpyware",
            "sig": null
          },
          {
            "vendor": "MicroWorld-eScan",
            "sig": null
          },
          {
            "vendor": "Rising",
            "sig": null
          },
          {
            "vendor": "Sophos",
            "sig": null
          },
          {
            "vendor": "F-Secure",
            "sig": null
          },
          {
            "vendor": "DrWeb",
            "sig": null
          },
          {
            "vendor": "VIPRE",
            "sig": null
          },
          {
            "vendor": "TrendMicro",
            "sig": null
          },
          {
            "vendor": "McAfee-GW-Edition",
            "sig": null
          },
          {
            "vendor": "FireEye",
            "sig": null
          },
          {
            "vendor": "Emsisoft",
            "sig": null
          },
          {
            "vendor": "Ikarus",
            "sig": null
          },
          {
            "vendor": "GData",
            "sig": null
          },
          {
            "vendor": "Jiangmin",
            "sig": null
          },
          {
            "vendor": "Avira",
            "sig": null
          },
          {
            "vendor": "Antiy-AVL",
            "sig": null
          },
          {
            "vendor": "Kingsoft",
            "sig": null
          },
          {
            "vendor": "Gridinsoft",
            "sig": null
          },
          {
            "vendor": "Xcitium",
            "sig": null
          },
          {
            "vendor": "Arcabit",
            "sig": null
          },
          {
            "vendor": "ViRobot",
            "sig": null
          },
          {
            "vendor": "ZoneAlarm",
            "sig": null
          },
          {
            "vendor": "Microsoft",
            "sig": null
          },
          {
            "vendor": "Google",
            "sig": null
          },
          {
            "vendor": "AhnLab-V3",
            "sig": null
          },
          {
            "vendor": "Acronis",
            "sig": null
          },
          {
            "vendor": "BitDefenderTheta",
            "sig": null
          },
          {
            "vendor": "ALYac",
            "sig": null
          },
          {
            "vendor": "TACHYON",
            "sig": null
          },
          {
            "vendor": "VBA32",
            "sig": null
          },
          {
            "vendor": "Tencent",
            "sig": null
          },
          {
            "vendor": "Yandex",
            "sig": null
          },
          {
            "vendor": "MAX",
            "sig": null
          },
          {
            "vendor": "MaxSecure",
            "sig": null
          },
          {
            "vendor": "Fortinet",
            "sig": null
          },
          {
            "vendor": "AVG",
            "sig": null
          },
          {
            "vendor": "Panda",
            "sig": null
          },
          {
            "vendor": "Zoner",
            "sig": null
          },
          {
            "vendor": "Avast-Mobile",
            "sig": null
          },
          {
            "vendor": "SymantecMobileInsight",
            "sig": null
          },
          {
            "vendor": "BitDefenderFalx",
            "sig": null
          },
          {
            "vendor": "tehtris",
            "sig": null
          },
          {
            "vendor": "Elastic",
            "sig": null
          },
          {
            "vendor": "APEX",
            "sig": null
          },
          {
            "vendor": "Paloalto",
            "sig": null
          },
          {
            "vendor": "Trapmine",
            "sig": null
          },
          {
            "vendor": "Alibaba",
            "sig": null
          },
          {
            "vendor": "Webroot",
            "sig": null
          },
          {
            "vendor": "Cylance",
            "sig": null
          },
          {
            "vendor": "SentinelOne",
            "sig": null
          },
          {
            "vendor": "Trustlook",
            "sig": null
          },
          {
            "vendor": "Cybereason",
            "sig": null
          },
          {
            "vendor": "CrowdStrike",
            "sig": null
          }
        ],
        "detection": ""
      },
      "cape_type_code": 0,
      "cape_type": "",
      "pid": ""
    }
  ],
  "CAPE": {
    "payloads": [],
    "configs": []
  },
  "info": {
    "version": "2.4-CAPE",
    "started": "2026-02-10 12:21:53",
    "ended": "2026-02-10 12:26:27",
    "duration": 274,
    "id": 31,
    "category": "file",
    "custom": "",
    "machine": {
      "id": 25,
      "status": "stopping",
      "name": "MalwareGuest",
      "label": "MalwareGuest",
      "platform": "windows",
      "manager": "Proxmox",
      "started_on": "2026-02-10 12:21:53",
      "shutdown_on": "2026-02-10 12:26:26"
    },
    "package": "msi",
    "timeout": false,
    "tlp": null,
    "parent_sample": null,
    "options": {},
    "source_url": null,
    "route": "internet",
    "user_id": 0,
    "CAPE_current_commit": "b8e0bcad685cdd750a8c54cd86745809ad1c320b"
  },
  "behavior": {
    "processes": [
      {
        "process_id": 4880,
        "process_name": "msiexec.exe",
        "parent_id": 956,
        "module_path": "C:\\Windows\\SysWOW64\\msiexec.exe",
        "first_seen": "2026-02-10 09:21:59,234",
        "calls": [
          {
            "timestamp": "2026-02-10 09:21:59,328",
            "thread_id": "4884",
            "caller": "0x76fb65e6",
            "parentcaller": "0x76fb64f1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 4,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b9c3b",
            "parentcaller": "0x003b93de",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x003b9be0"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b7d3f",
            "parentcaller": "0x003b7d64",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "34",
                "pretty_value": "ProcessExecuteFlags"
              },
              {
                "name": "ProcessInformation",
                "value": "9"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100020",
                "pretty_value": "FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "4884"
              }
            ],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\comctl32.dll"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\comctl32.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\comctl32.dll"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x72cc0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00210000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "35"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "VERSION.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\COMCTL32"
              },
              {
                "name": "DllBase",
                "value": "0x72cc0000"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001200a9",
                "pretty_value": "FILE_GENERIC_READ|FILE_GENERIC_EXECUTE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\WindowsShell.Manifest"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\WindowsShell.Manifest"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02df0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\WindowsShell.Manifest"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x9e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x02df0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "synchronization",
            "api": "NtAddAtomEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "AtomName",
                "value": "ThemePropScrollBarCtl"
              },
              {
                "name": "Atom",
                "value": "0x0000c020"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "synchronization",
            "api": "NtAddAtomEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "AtomName",
                "value": "MicrosoftTabletPenServiceProperty"
              },
              {
                "name": "Atom",
                "value": "0x0000c021"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "misc",
            "api": "SystemParametersInfoW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Action",
                "value": "0x00001022"
              },
              {
                "name": "uiParam",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "LPK"
              },
              {
                "name": "ModuleHandle",
                "value": "0x0049414e"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "GDI32"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75110000"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "GDI32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75110000"
              },
              {
                "name": "FunctionName",
                "value": "LpkEditControl"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7512d440"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b36",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\comctl32"
              },
              {
                "name": "BaseAddress",
                "value": "0x72cc0000"
              },
              {
                "name": "InitRoutine",
                "value": "0x72d454e0"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b8b54",
            "parentcaller": "0x003b7d7c",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "COMCTL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72cc0000"
              },
              {
                "name": "FunctionName",
                "value": "InitCommonControlsEx"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x72d133e0"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b7d95",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "52"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x10\\x00\\x00\\x00\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b643a",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "NtQueryLicenseValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Name",
                "value": "TerminalServices-RemoteConnectionManager-AllowAppServerMode"
              },
              {
                "name": "Type",
                "value": "0x00000004"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 3,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              },
              {
                "name": "FunctionName",
                "value": "SortGetHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7653eb20"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              },
              {
                "name": "FunctionName",
                "value": "SortCloseHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x765397e0"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\SortDefault.nls"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07040000"
              },
              {
                "name": "SectionOffset",
                "value": "0x02d3cac4"
              },
              {
                "name": "ViewSize",
                "value": "0x00338000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b68d0",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b63b9",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "Kernel32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b63ca",
            "parentcaller": "0x003b7d9d",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              },
              {
                "name": "FunctionName",
                "value": "HeapSetInformation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76541a20"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b912d",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "api-ms-win-core-delayload-l1-1-1.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x758d0000"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b914e",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x758d0000"
              },
              {
                "name": "FunctionName",
                "value": "ResolveDelayLoadedAPI"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x75a0ad40"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b9162",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x758d0000"
              },
              {
                "name": "FunctionName",
                "value": "ResolveDelayLoadsFromDll"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x75aa4380"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "msi.dll"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\msi.dll"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:21:59,343",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\msi.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:21:59,359",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\msi.dll"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:21:59,359",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x72a20000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00299000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:21:59,359",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:21:59,359",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00120089",
                "pretty_value": "FILE_GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\msi.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "VERSION.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "misc",
            "api": "RtlDosPathNameToNtPathName_U",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DosFileName",
                "value": "C:\\Windows\\System32\\msi.dll"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020000",
                "pretty_value": "READ_CONTROL"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\msi.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\msi"
              },
              {
                "name": "DllBase",
                "value": "0x72a20000"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtQueryLicenseValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Name",
                "value": "TerminalServices-RemoteConnectionManager-AllowAppServerMode"
              },
              {
                "name": "Type",
                "value": "0x00000004"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              },
              {
                "name": "FunctionName",
                "value": "GetNativeSystemInfo"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76542150"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b91df",
            "parentcaller": "0x003ba0f6",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\SysWOW64\\msi"
              },
              {
                "name": "BaseAddress",
                "value": "0x72a20000"
              },
              {
                "name": "InitRoutine",
                "value": "0x72c78aa0"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:21:59,375",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "Comctl32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x72cc0000"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x73b80000"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\srpapi"
              },
              {
                "name": "DllBase",
                "value": "0x729f0000"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "srpapi.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x729f0000"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\TSAPPCMP.DLL"
              },
              {
                "name": "BaseAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:21:59,390",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "Ntdll.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\shlwapi.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76e50000"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\ole32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x75180000"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x75800000"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:21:59,406",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\coml2"
              },
              {
                "name": "DllBase",
                "value": "0x75720000"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\advapi32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x75b10000"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "COMCTL32"
              },
              {
                "name": "BaseAddress",
                "value": "0x72cc0000"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x739f0000"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x739f0000"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:21:59,422",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\MSCTF"
              },
              {
                "name": "DllBase",
                "value": "0x76bd0000"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:21:59,437",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "comctl32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x72cc0000"
              }
            ],
            "repeated": 1,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:21:59,453",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\ntmarta"
              },
              {
                "name": "DllBase",
                "value": "0x725e0000"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:21:59,453",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreMessaging"
              },
              {
                "name": "DllBase",
                "value": "0x72610000"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:21:59,453",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\wintypes"
              },
              {
                "name": "DllBase",
                "value": "0x72500000"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:21:59,453",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\CoreUIComponents"
              },
              {
                "name": "DllBase",
                "value": "0x726b0000"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:21:59,453",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\textinputframework"
              },
              {
                "name": "DllBase",
                "value": "0x72930000"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\shell32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x75f60000"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\Wldp"
              },
              {
                "name": "DllBase",
                "value": "0x747a0000"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\windows.storage"
              },
              {
                "name": "DllBase",
                "value": "0x747d0000"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "shell32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x75f60000"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:21:59,468",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\PROPSYS"
              },
              {
                "name": "DllBase",
                "value": "0x73c20000"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:21:59,484",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:21:59,484",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\TextShaping"
              },
              {
                "name": "DllBase",
                "value": "0x72460000"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x76fb65e6",
            "parentcaller": "0x76fb64f1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759ea206",
            "parentcaller": "0x75a0fb91",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              },
              {
                "name": "FunctionName",
                "value": "GetSystemWow64DirectoryW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76543a70"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759ea206",
            "parentcaller": "0x75a0fb91",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\NETAPI32"
              },
              {
                "name": "DllBase",
                "value": "0x72440000"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759ea206",
            "parentcaller": "0x75a0fb91",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\netapi32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x72440000"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\WKSCLI"
              },
              {
                "name": "DllBase",
                "value": "0x72420000"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "NETAPI32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72440000"
              },
              {
                "name": "FunctionName",
                "value": "NetGetJoinInformation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x72423270"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759f9924",
            "parentcaller": "0x75bcc2f8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000003d0"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x75bc826a",
            "parentcaller": "0x75bc7a6b",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PIPE\\wkssvc"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x75a1100a",
            "parentcaller": "0x75bc7a97",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\NamedPipe\\wkssvc"
              },
              {
                "name": "FileInformationClass",
                "value": "23",
                "pretty_value": "FilePipeInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x75bc906e",
            "parentcaller": "0x75bc7ab3",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\NamedPipe\\wkssvc"
              },
              {
                "name": "FileInformationClass",
                "value": "41",
                "pretty_value": "FileIoStatusBlockRangeInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x76fb739f",
            "parentcaller": "0x76fb71b6",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\NamedPipe\\wkssvc"
              },
              {
                "name": "FileInformationClass",
                "value": "30",
                "pretty_value": "FileCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\x00\\x00\\x00PNG\\x03"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x759df8f1",
            "parentcaller": "0x759df6cb",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:21:59,515",
            "thread_id": "1652",
            "caller": "0x75bf00b8",
            "parentcaller": "0x75bc7fbb",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\NamedPipe\\wkssvc"
              },
              {
                "name": "Buffer",
                "value": "\\x05\\x00\\x0b\\x03\\x10\\x00\\x00\\x00t\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\xb8\\x10\\xb8\\x10\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x98\\xd0\\xffk\\x12\\xa1\\x106\\x983F\\xc3\\xf8~4Z\\x01\\x00\\x00\\x00\\x04]\\x88\\x8a\\xeb\\x1c\\xc9\\x11\\x9f\\xe8\\x08\\x00+\\x10H`\\x02\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x98\\xd0\\xffk\\x12\\xa1\\x106\\x983F\\xc3\\xf8~4Z\\x01\\x00\\x00\\x00,\\x1c\\xb7l\\x12\\x98@E\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x75bc85af",
            "parentcaller": "0x75bc8569",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003d8"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\NamedPipe\\wkssvc"
              },
              {
                "name": "Buffer",
                "value": "\\x05\\x00\\x0c\\x03\\x10\\x00\\x00\\x00\\\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\xb8\\x10\\xb8\\x10\\xaf\\x14\\x00\\x00\r\\x00\\PIPE\\wkssvc\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04]\\x88\\x8a\\xeb\\x1c\\xc9\\x11\\x9f\\xe8\\x08\\x00+\\x10H`\\x02\\x00\\x00\\x00\\x03\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\NETUTILS"
              },
              {
                "name": "DllBase",
                "value": "0x72410000"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "NETAPI32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72440000"
              },
              {
                "name": "FunctionName",
                "value": "NetApiBufferFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x72411840"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b7d1b0",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759df8f1",
            "parentcaller": "0x759df6cb",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b7d5a8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759ec134",
            "parentcaller": "0x72aac469",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000028"
              },
              {
                "name": "TokenHandle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72aac4a2",
            "parentcaller": "0x72aac60a",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeShutdownPrivilege"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x72aac4df",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759ec134",
            "parentcaller": "0x72aac469",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000028"
              },
              {
                "name": "TokenHandle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72aac4a2",
            "parentcaller": "0x72aac60a",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeIncreaseQuotaPrivilege"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x72aac4df",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72b528ad",
            "parentcaller": "0x72b77848",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759e9b67",
            "parentcaller": "0x759e92be",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "MutexName",
                "value": "Global\\_MSIExecute"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b7cf79",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:21:59,531",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoCreateInstance"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x755794c0"
              }
            ],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:01,625",
            "thread_id": "1652",
            "caller": "0x72b534f8",
            "parentcaller": "0x72aadd3b",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\clbcatq"
              },
              {
                "name": "DllBase",
                "value": "0x76ea0000"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:01,625",
            "thread_id": "4536",
            "caller": "0x76fb65e6",
            "parentcaller": "0x76fb64f1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:01,625",
            "thread_id": "4540",
            "caller": "0x759f9924",
            "parentcaller": "0x75bcc2f8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000430"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:01,625",
            "thread_id": "4544",
            "caller": "0x76fb65e6",
            "parentcaller": "0x76fb64f1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:01,625",
            "thread_id": "4544",
            "caller": "0x759f9924",
            "parentcaller": "0x75bcc2f8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000448"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x755c8344",
            "parentcaller": "0x76f8105f",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000032A-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "00000149-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x75581477",
            "parentcaller": "0x75588b43",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000339-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b534f8",
            "parentcaller": "0x72aadd3b",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "000C101C-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000004",
                "pretty_value": "CLSCTX_LOCAL_SERVER"
              },
              {
                "name": "riid",
                "value": "00000000-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": "IMsiServer"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoQueryProxyBlanket"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x755c7af0"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x75bceacc",
            "parentcaller": "0x75bcea60",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fb7bb9",
            "parentcaller": "0x75bd22d7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xe7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00`\\x00\\x00\\x00<\\xe8\\xee\\x07\\x1e^\\xf9vH\\xee\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00J\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0\\xe7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00 5A\\x034\\xe8\\xee\\x07\\x1e^\\xf9v\\xf4\\xec\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00J\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000462"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045e"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xdc\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00L\\xdd\\xee\\x07\\xdc\\xdc\\xee\\x07\\x1e^\\xf9v\\x9c\\xe2\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00 \\x00\\x00\\x00\\xbc\\xdb\\xee\\x07\\x1e^\\xf9v|\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "P\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x14\\x00\r\\x00\\x94\\xdb\\xee\\x07\\x1e^\\xf9vT\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "P\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03\\x94\\xdb\\xee\\x07\\x1e^\\xf9vT\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x01\\x04\\x00\\x00\\x04\\xdc\\xee\\x07\\x1e^\\xf9v\\xfc\\xe1\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xda\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xff\\x07\\x00\\x00<\\xdb\\xee\\x07\\x1e^\\xf9v\\xfc\\xdf\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xd0\\xdd\\xee\\x07d\\xdb\\xee\\x07\\x1e^\\xf9v$\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03d\\xdb\\xee\\x07\\x1e^\\xf9v$\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\xda\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x14{\\xfdv\\x1c\\xdb\\xee\\x07\\x1e^\\xf9v\\xdc\\xdf\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000462"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00H\\x0eW.\\xc4\\xdb\\xee\\x07\\x1e^\\xf9v\\x84\\xe1\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xdb\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03\\xc4\\xdb\\xee\\x07\\x1e^\\xf9v\\x84\\xe1\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00<\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045e"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xd8\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xf4\\xd8\\xee\\x07\\x84\\xd8\\xee\\x07\\x1e^\\xf9vD\\xde\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xd7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00 \\x00\\x00\\x00d\\xd7\\xee\\x07\\x1e^\\xf9v$\\xdc\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x14\\x00\t\\x00<\\xd7\\xee\\x07\\x1e^\\xf9v\\xfc\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03<\\xd7\\xee\\x07\\x1e^\\xf9v\\xfc\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\xd7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x01\\x04\\x00\\x00\\xac\\xd7\\xee\\x07\\x1e^\\xf9v\\xa4\\xdd\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xff\\x07\\x00\\x00\\xe4\\xd6\\xee\\x07\\x1e^\\xf9v\\xa4\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc8\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00x\\xd9\\xee\\x07\\x0c\\xd7\\xee\\x07\\x1e^\\xf9v\\xcc\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc8\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03\\x0c\\xd7\\xee\\x07\\x1e^\\xf9v\\xcc\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x14{\\xfdv\\xc4\\xd6\\xee\\x07\\x1e^\\xf9v\\x84\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000462"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "(\\xd7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00H\\x0eW.l\\xd7\\xee\\x07\\x1e^\\xf9v,\\xdd\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "(\\xd7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03l\\xd7\\xee\\x07\\x1e^\\xf9v,\\xdd\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00<\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb0\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00hv\\x01\\x01\\xf4\\xd6\\xee\\x07\\x1e^\\xf9v\\xf0\\xdc\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00<\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "P\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x000\\xaf\\xfcv\\x94\\xd6\\xee\\x07\\x1e^\\xf9vT\\xdb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xd6\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00^\\x04\\x00\\x00\\xd4\\xd6\\xee\\x07\\x1e^\\xf9v\\x94\\xdc\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\xd7\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00:\\x03\\xac\\xd7\\xee\\x07\\x1e^\\xf9v\\xb0\\xdd\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x004\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9dub\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000462"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045e"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xe5\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x86\\xe6\\xee\\x07\\xdc\\xe5\\xee\\x07\\x1e^\\xf9v\\xe8\\xeb\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045e"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759ea206",
            "parentcaller": "0x755610d6",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\msi.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x72a20000"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f1b7a",
            "parentcaller": "0x75561074",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "msi.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72a20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetClassObject"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x72afb570"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f1b7a",
            "parentcaller": "0x75561086",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000139",
            "pretty_return": "ENTRYPOINT_NOT_FOUND",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "msi.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72a20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetActivationFactory"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f1b7a",
            "parentcaller": "0x755610a3",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "msi.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x72a20000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x72aad590"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b528ad",
            "parentcaller": "0x72b316d3",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759ec134",
            "parentcaller": "0x72b3174d",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000002"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x72b31775",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeCreateTokenPrivilege"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeAssignPrimaryTokenPrivilege"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeLockMemoryPrivilege"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeIncreaseQuotaPrivilege"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeUnsolicitedInputPrivilege"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeMachineAccountPrivilege"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeTcbPrivilege"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeSecurityPrivilege"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeTakeOwnershipPrivilege"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeLoadDriverPrivilege"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeSystemProfilePrivilege"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeSystemtimePrivilege"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeProfileSingleProcessPrivilege"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeIncreaseBasePriorityPrivilege"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeCreatePagefilePrivilege"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeCreatePermanentPrivilege"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeBackupPrivilege"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeRestorePrivilege"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeShutdownPrivilege"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeDebugPrivilege"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeAuditPrivilege"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeSystemEnvironmentPrivilege"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeChangeNotifyPrivilege"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeRemoteShutdownPrivilege"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeUndockPrivilege"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeSyncAgentPrivilege"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeEnableDelegationPrivilege"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeManageVolumePrivilege"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeImpersonatePrivilege"
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b5b07a",
            "parentcaller": "0x72b31784",
            "category": "system",
            "api": "LookupPrivilegeValueW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "SystemName",
                "value": ""
              },
              {
                "name": "PrivilegeName",
                "value": "SeCreateGlobalPrivilege"
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoSetProxyBlanket"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7552c960"
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75c054df",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e9e76",
            "parentcaller": "0x75c066f9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "gA\\x08\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x02\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\xe1A\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75c06712",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75c06ea0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x75bceacc",
            "parentcaller": "0x75bcea60",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e9e76",
            "parentcaller": "0x75c066f9",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "gA\\x08\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x02\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\xe1A\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75c06712",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x72b31815",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x7657d191",
            "parentcaller": "0x72b41d51",
            "category": "device",
            "api": "NtPowerInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "InformationLevel",
                "value": "43"
              },
              {
                "name": "InputBuffer",
                "value": "\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00Z\\x00\\\\x00P\\xe4rN\\x00D\\x00P\\x00O\\x00I\\x00N\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": "`\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x7657d21f",
            "parentcaller": "0x72b41d5f",
            "category": "device",
            "api": "NtPowerInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "InformationLevel",
                "value": "44"
              },
              {
                "name": "InputBuffer",
                "value": "`\\x04\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\xf1H\\x03\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b41d8a",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x72b41bdc",
            "parentcaller": "0x72b41cdc",
            "category": "misc",
            "api": "SystemParametersInfoW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Action",
                "value": "0x00000010"
              },
              {
                "name": "uiParam",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759df8f1",
            "parentcaller": "0x759df6cb",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:22:03,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": ""
              },
              {
                "name": "Length",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemAlloc"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x755a2ed0"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb0\\xe0\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00`\\x00\\x00\\x00\\xf4\\xe0\\xee\\x07\\x1e^\\xf9v\\x00\\xe7\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00J\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9du^\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa3909",
            "parentcaller": "0x759dff24",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xe0\\xee\\x07\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xe0;A\\x03\\xec\\xe0\\xee\\x07\\x1e^\\xf9v\\xac\\xe5\\xee\\x07\\x1e^\\xf9v\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00J\\x02\\x00\\x00\\xec,\\xfcv\\xdc\\xfc\\x9duj\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046a"
              }
            ],
            "repeated": 0,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759e040b",
            "parentcaller": "0x7321859e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045e"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fb7bb9",
            "parentcaller": "0x75bd22d7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x75bd12f8",
            "parentcaller": "0x75bd0561",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x0000045c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759ec134",
            "parentcaller": "0x75bd1389",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa6a20",
            "parentcaller": "0x76fa9456",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "\\x15\\xa3\\x07\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x11+\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa90c4",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc4p>\\x03\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9103",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb0O<\\x03`\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x003\\x002\\x00.\\x00d\\x00l\\x00l\\x00\\x00\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9120",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa915f",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "4\\xf2H\\x03\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9178",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa91b3",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "t`<\\x03\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9240",
            "parentcaller": "0x76fa91c3",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\xcf\\x12s\\x88\\xea\\x12s\\x06\\x00\\x00\\x00t\\xea\\x12sT\\x00\\x00\\x00p`<\\x03\\x00\\x00#\\x00\\xe4\\xe4\\xd8\\xe4h\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00:\\x03#\\x00\\x00\\xc0h\\x04\\x00\\x00,\\xe5\\xee\\x07\\xb3\\x91\\xfavh\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa926e",
            "parentcaller": "0x76fa91c3",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x19\\x1as\\xc4W\\x00\\x05\\x00\\xc9\\x14s\\xe8\\xe4\\xee\\x07@\\xe7\\xee\\x07\\xf2\tT[\\xd4\\xdf\\xee\\x07\\x88\\xee\\xee\\x07\\x88\\xee\\xee\\x07\\xa0\\x8b\\x08s\\x06\\xca\\xae/\\xfe\\xff\\xff\\xff\\xe4\\xe4\\xee\\x07f\\xc8\\xf4r9\\x00\\x00\\x00 \\xcf\\x12s\\xa4\\xea\\x12s"
              }
            ],
            "repeated": 0,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa6a20",
            "parentcaller": "0x76fa7151",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "\\x15\\xa3\\x07\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x11+\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa90c4",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb4q>\\x03\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9103",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08P<\\x03`\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00w\\x00i\\x00n\\x00t\\x00y\\x00p\\x00e\\x00s\\x00.\\x00d\\x00l\\x00l\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9120",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa915f",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xbc\\xf1H\\x03\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9178",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa91b3",
            "parentcaller": "0x76fa6ac5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd4c<\\x03\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa9240",
            "parentcaller": "0x76fa91c3",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\xcf\\x12s\\x88\\xea\\x12s\\x06\\x00\\x00\\x00t\\xea\\x12sT\\x00\\x00\\x00\\xd0c<\\x03\\x00\\x00#\\x00\\xcc\\xe2\\xc0\\xe2h\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00:\\x03#\\x00\\x00\\xc0h\\x04\\x00\\x00\\x14\\xe3\\xee\\x07\\xb3\\x91\\xfavh\\x04\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x76fa926e",
            "parentcaller": "0x76fa91c3",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x19\\x1as\\xc4W\\x00\\x05\\x00\\xc9\\x14s\\xd0\\xe2\\xee\\x07(\\xe5\\xee\\x07\\x1a\\x0fT[\\xbc\\xdd\\xee\\x07\\x88\\xee\\xee\\x07\\x88\\xee\\xee\\x07\\xa0\\x8b\\x08s\\x06\\xca\\xae/\\xfe\\xff\\xff\\xff\\xcc\\xe2\\xee\\x07f\\xc8\\xf4r9\\x00\\x00\\x00 \\xcf\\x12s\\xa4\\xea\\x12s"
              }
            ],
            "repeated": 0,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75bd13d9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:22:03,859",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75bd13f2",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:22:03,890",
            "thread_id": "4544",
            "caller": "0x759e9e76",
            "parentcaller": "0x7559dffe",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": ",C\\x08\\x00\\x00\\x00\\x00\\x00\\xe7\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xebL\\xb6&u \\x06\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x90\\x0f\\x00\\x00\\x0b\\x00\\x00\\x00\\x13\\x00\\x00\\x00q@\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:22:03,890",
            "thread_id": "4544",
            "caller": "0x759eab1a",
            "parentcaller": "0x7559dfc0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:22:03,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:22:03,906",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbe\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\x11\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "M\\x00S\\x00I\\x00 \\x00(\\x00c\\x00)\\x00 \\x00(\\x001\\x000\\x00:\\x001\\x004\\x00)\\x00 \\x00[\\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x003\\x00:\\x009\\x000\\x004\\x00]\\x00:\\x00 \\x00F\\x00o\\x00n\\x00t\\x00 \\x00c\\x00r\\x00e\\x00a\\x00t\\x00e\\x00d\\x00.\\x00 \\x00 \\x00C\\x00h\\x00a\\x00r\\x00s\\x00e\\x00t\\x00:\\x00 \\x00R\\x00e\\x00q\\x00=\\x000\\x00,\\x00 \\x00R\\x00e\\x00t\\x00=\\x000\\x00,\\x00 \\x00F\\x00o\\x00n\\x00t\\x00:\\x00 \\x00R\\x00e\\x00q\\x00=\\x00,\\x00 \\x00R\\x00e\\x00t\\x00=\\x00A\\x00r\\x00i\\x00a\\x00l\\x00\n\\x00\r\\x00\n\\x00M\\x00S\\x00I\\x00 \\x00(\\x00c\\x00)\\x00 \\x00(\\x001\\x000\\x00:\\x001\\x004\\x00)\\x00 \\x00[\\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x003\\x00:\\x009\\x003\\x006\\x00]\\x00:\\x00 \\x00F\\x00o\\x00"
              },
              {
                "name": "Length",
                "value": "376"
              }
            ],
            "repeated": 0,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:22:03,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:22:04,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 9,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xd6Z\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "=\\x00=\\x00=\\x00 \\x00L\\x00o\\x00g\\x00g\\x00i\\x00n\\x00g\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00:\\x00 \\x001\\x000\\x00.\\x000\\x002\\x00.\\x002\\x000\\x002\\x006\\x00 \\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00 \\x00=\\x00=\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 3,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x90_\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:22:04,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00Vb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Vb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00_\\x00x\\x008\\x006\\x00_\\x00V\\x00C\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xbcc\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbcc\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00_\\x00x\\x008\\x006\\x00_\\x00V\\x00C\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xb4e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x18g\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x14i\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:22:04,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x86j\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86j\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x80l\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80l\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xe6m\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6m\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xdeo\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeo\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00Bq\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Bq\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00>s\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">s\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:22:04,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xaet\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaet\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xb6v\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6v\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xdew\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdew\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:22:04,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xc2|\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc2|\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00S\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "90"
              }
            ],
            "repeated": 0,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\xe6}\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6}\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00S\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:22:04,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:22:04,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:22:04,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00h\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:22:04,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\x7f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:22:04,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x06\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x06\\x80\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00l\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l\\x80\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00T\\x00h\\x00e\\x00 \\x00u\\x00s\\x00e\\x00r\\x00 \\x00i\\x00s\\x00 \\x00A\\x00d\\x00m\\x00i\\x00n\\x00i\\x00s\\x00t\\x00r\\x00a\\x00t\\x00o\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xd2\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x480\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00I\\x00n\\x00t\\x00e\\x00g\\x00r\\x00i\\x00t\\x00y\\x00 \\x00l\\x00e\\x00v\\x00e\\x00l\\x00 \\x00i\\x00s\\x00 \\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00.\\x81\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ".\\x81\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xe4\\x81\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\x81\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:22:04,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00J\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "J\\x82\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00U\\x00s\\x00e\\x00r\\x00 \\x00i\\x00s\\x00 \\x00a\\x00n\\x00 \\x00a\\x00d\\x00m\\x00i\\x00n\\x00i\\x00s\\x00t\\x00r\\x00a\\x00t\\x00o\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "100"
              }
            ],
            "repeated": 0,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xae\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xae\\x82\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00>\\x83\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">\\x83\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00d\\x00o\\x00e\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00e\\x00x\\x00i\\x00s\\x00t\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x9c\\x83\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\x83\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00c\\x00r\\x00e\\x00a\\x00t\\x00e\\x00d\\x00 \\x00s\\x00e\\x00c\\x00u\\x00r\\x00e\\x00d\\x00 \\x00f\\x00o\\x00l\\x00d\\x00e\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x84\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16\\x84\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00 \\x00f\\x00i\\x00n\\x00i\\x00s\\x00h\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:22:04,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x85\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04\\x85\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00U\\x00s\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xc2\\x85\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x85\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00F\\x00i\\x00n\\x00d\\x00R\\x00e\\x00l\\x00a\\x00t\\x00e\\x00d\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "90"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x8e\\x86\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\x86\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00F\\x00i\\x00n\\x00d\\x00R\\x00e\\x00l\\x00a\\x00t\\x00e\\x00d\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x87\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08\\x87\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00A\\x00p\\x00p\\x00S\\x00e\\x00a\\x00r\\x00c\\x00h\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xfa\\x8b\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfa\\x8b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:22:04,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00A\\x00p\\x00p\\x00S\\x00e\\x00a\\x00r\\x00c\\x00h\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00`\\x8c\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x8c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00V\\x00a\\x00l\\x00i\\x00d\\x00a\\x00t\\x00e\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00I\\x00D\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x008\\x8d\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8\\x8d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00V\\x00a\\x00l\\x00i\\x00d\\x00a\\x00t\\x00e\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00I\\x00D\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:22:04,750",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\xc4\\x8e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00I\\x00n\\x00i\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x8f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\x8f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x005\\x001\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00e\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x94\\x8f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\x8f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x005\\x005\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00a\\x00b\\x00o\\x00u\\x00t\\x00 \\x00t\\x00o\\x00 \\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:22:04,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00<\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "<\\x90\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x005\\x007\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00>\\x00 \\x00e\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xb4\\x90\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\x90\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x006\\x000\\x00>\\x00 \\x00<\\x00I\\x00s\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00D\\x00i\\x00s\\x00a\\x00b\\x00l\\x00e\\x00d\\x00>\\x00 \\x00N\\x00O\\x00_\\x00O\\x00F\\x00F\\x00I\\x00C\\x00E\\x00_\\x00M\\x00O\\x00D\\x00E\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00i\\x00s\\x00 \\x000\\x00 \\x00-\\x00>\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00f\\x00a\\x00l\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00z\\x91\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\x91\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x006\\x008\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00>\\x00 \\x00 \\x00'\\x00n\\x00o\\x00 \\x00o\\x00f\\x00f\\x00i\\x00c\\x00e\\x00 \\x00m\\x00o\\x00d\\x00e\\x00'\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00n\\x00o\\x00t\\x00 \\x00f\\x00o\\x00u\\x00n\\x00d\\x00 \\x00/\\x00 \\x00n\\x00o\\x00t\\x00 \\x00m\\x00a\\x00r\\x00k\\x00e\\x00d\\x00 \\x00a\\x00s\\x00 \\x00d\\x00i\\x00s\\x00a\\x00b\\x00l\\x00e\\x00d\\x00 \\x00-\\x00>\\x00 \\x00l\\x00o\\x00o\\x00k\\x00 \\x00f\\x00o\\x00r\\x00 \\x00t\\x00h\\x00e\\x00 \\x00n\\x00o\\x00O\\x00"
              },
              {
                "name": "Length",
                "value": "340"
              }
            ],
            "repeated": 0,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xce\\x92\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x392\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x007\\x001\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00>\\x00 \\x00b\\x00I\\x00s\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00=\\x00f\\x00a\\x00l\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:22:04,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00P\\x93\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\x93\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x007\\x003\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00,\\x00 \\x00d\\x00o\\x00 \\x00n\\x00o\\x00t\\x00h\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xe6\\x93\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\x93\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x007\\x006\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00N\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00.\\x00.\\x00.\\x00d\\x00o\\x00n\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x84\\x94\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\x94\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x007\\x009\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00=\\x00U\\x00N\\x00D\\x00E\\x00F\\x00I\\x00N\\x00E\\x00D\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x95\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\x95\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x008\\x002\\x00>\\x00 \\x00<\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00c\\x00a\\x00l\\x00l\\x00 \\x00G\\x00e\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00T\\x00y\\x00p\\x00e\\x00F\\x00r\\x00o\\x00m\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "166"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xba\\x9d\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\x9d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00.\\x008\\x008\\x005\\x00>\\x00 \\x00<\\x00G\\x00e\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00T\\x00y\\x00p\\x00e\\x00F\\x00r\\x00o\\x00m\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00>\\x00 \\x00c\\x00l\\x00i\\x00e\\x00n\\x00t\\x00 \\x00s\\x00u\\x00b\\x00 \\x00t\\x00y\\x00p\\x00e\\x00 \\x00n\\x00o\\x00t\\x00 \\x00f\\x00o\\x00u\\x00n\\x00d\\x00 \\x00i\\x00n\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00 \\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:22:04,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00p\\x9e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "p\\x9e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00I\\x00n\\x00i\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x001\\x001\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x9f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\x9f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "380"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xa0\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00I\\x00n\\x00i\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00a\\x00c\\x00t\\x00u\\x00a\\x00l\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00c\\x00o\\x00d\\x00e\\x00 \\x001\\x006\\x000\\x003\\x00 \\x00b\\x00u\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00t\\x00r\\x00a\\x00n\\x00s\\x00l\\x00a\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00d\\x00u\\x00e\\x00 \\x00t\\x00o\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00 \\x00m\\x00a\\x00r\\x00k\\x00i\\x00n\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "244"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x0c\\xa2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xa2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00I\\x00n\\x00i\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xba\\xa3\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xa3\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00e\\x00t\\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00T\\x00y\\x00p\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x8e\\xa4\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\xa4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00e\\x00t\\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00T\\x00y\\x00p\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:22:04,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\xa6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\xa6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00e\\x00t\\x00F\\x00W\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x004\\xa7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4\\xa7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00S\\x00e\\x00t\\x00F\\x00W\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:22:04,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\xa8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb8\\xa8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x004\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00S\\x00h\\x00a\\x002\\x00K\\x00b\\x00I\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00f\\xa9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\xa9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x000\\x001\\x009\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00S\\x00h\\x00a\\x002\\x00K\\x00b\\x00I\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00c\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00&\\xac\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\xac\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x000\\x002\\x002\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00S\\x00h\\x00a\\x002\\x00K\\x00b\\x00I\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00w\\x00i\\x00n\\x007\\x00 \\x00p\\x00r\\x00o\\x00c\\x00e\\x00e\\x00d\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xc8\\xac\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x22c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00S\\x00h\\x00a\\x002\\x00K\\x00b\\x00I\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x002\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "250"
              }
            ],
            "repeated": 0,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:22:05,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xc2\\xad\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xad\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "466"
              }
            ],
            "repeated": 0,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00L\\xb0\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\xb0\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00S\\x00h\\x00a\\x002\\x00K\\x00b\\x00I\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "206"
              }
            ],
            "repeated": 0,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:22:05,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xb2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x9c\\xb2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\xb2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x003\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x84\\xb3\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\xb3\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x003\\x005\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00U\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00a\\x00s\\x00s\\x00w\\x00o\\x00r\\x00d\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00U\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00a\\x00s\\x00s\\x00w\\x00o\\x00r\\x00d\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "292"
              }
            ],
            "repeated": 0,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:22:05,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\xb4\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\xb4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x003\\x008\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00U\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00a\\x00s\\x00s\\x00w\\x00o\\x00r\\x00d\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00=\\x00A\\x00L\\x00L\\x00,\\x00 \\x00n\\x00o\\x00 \\x00n\\x00e\\x00e\\x00d\\x00 \\x00p\\x00a\\x00s\\x00s\\x00w\\x00o\\x00r\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00J\\xb5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "J\\xb5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x004\\x001\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00I\\x00s\\x00A\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00>\\x00 \\x00I\\x00n\\x00s\\x00i\\x00d\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xca\\xb5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x2b5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x004\\x004\\x00>\\x00 \\x00<\\x00C\\x00h\\x00e\\x00c\\x00k\\x00I\\x00f\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00I\\x00s\\x00A\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00>\\x00 \\x00r\\x00e\\x00b\\x00o\\x00o\\x00t\\x00_\\x00f\\x00i\\x00l\\x00e\\x00.\\x00l\\x00o\\x00g\\x00 \\x00i\\x00s\\x00 \\x00s\\x00t\\x00i\\x00l\\x00l\\x00 \\x00p\\x00e\\x00n\\x00d\\x00i\\x00n\\x00g\\x00 \\x00f\\x00o\\x00r\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00i\\x00o\\x00n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x92\\xb6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x92\\xb6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x004\\x007\\x00>\\x00 \\x00<\\x00G\\x00e\\x00t\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00E\\x00N\\x00D\\x00P\\x00O\\x00I\\x00N\\x00T\\x00_\\x00S\\x00E\\x00C\\x00U\\x00R\\x00I\\x00T\\x00Y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "186"
              }
            ],
            "repeated": 0,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00L\\xb7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\xb7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x005\\x000\\x00>\\x00 \\x00<\\x00I\\x00s\\x00I\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00C\\x00a\\x00s\\x00e\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00u\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00c\\x00a\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xc2\\xb7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x005\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00I\\x00n\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00/\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00 \\x00c\\x00a\\x00s\\x00e\\x00.\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00i\\x00f\\x00 \\x00F\\x00W\\x00 \\x00c\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00 \\x00i\\x00s\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00 \\x00o\\x00n\\x00 \\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "220"
              }
            ],
            "repeated": 0,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:22:05,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x9e\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9e\\xb8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x005\\x005\\x00>\\x00 \\x00<\\x00F\\x00w\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00I\\x00n\\x00s\\x00i\\x00d\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\xb9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\xb9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x005\\x007\\x00>\\x00 \\x00<\\x00F\\x00w\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00 \\x00c\\x00a\\x00n\\x00n\\x00o\\x00t\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00k\\x00e\\x00y\\x00 \\x00'\\x00S\\x00O\\x00F\\x00T\\x00W\\x00A\\x00R\\x00E\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00'\\x00 \\x00-\\x00>\\x00 \\x00a\\x00s\\x00s\\x00u\\x00m\\x00e\\x00 \\x00E\\x00P\\x00S\\x00_\\x00R\\x008\\x000\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00i\\x00"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\"\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\xba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x006\\x001\\x00>\\x00 \\x00<\\x00F\\x00w\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00f\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\\\x00C\\x00u\\x00r\\x00r\\x00e\\x00n\\x00t\\x00C\\x00o\\x00n\\x00t\\x00r\\x00o\\x00l\\x00S\\x00e\\x00t\\x00\\\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00\\\\x00P\\x00a\\x00r\\x00a\\x00m\\x00e\\x00t\\x00e\\x00r\\x00s\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "230"
              }
            ],
            "repeated": 0,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\xbb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08\\xbb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x006\\x003\\x00>\\x00 \\x00<\\x00F\\x00w\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00>\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00c\\x00o\\x00d\\x00e\\x00:\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x86\\xbb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86\\xbb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x006\\x006\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00N\\x00o\\x00 \\x00F\\x00W\\x00 \\x00c\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00 \\x00w\\x00a\\x00s\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00 \\x00-\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00a\\x00t\\x00i\\x00o\\x00n\\x00.\\x00.\\x00.\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00<\\xbc\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "<\\xbc\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x006\\x008\\x00>\\x00 \\x00<\\x00S\\x00e\\x00t\\x00O\\x00v\\x00e\\x00r\\x00r\\x00i\\x00d\\x00e\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00U\\x00p\\x00o\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00>\\x00 \\x00b\\x00I\\x00s\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00=\\x00f\\x00a\\x00l\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:22:05,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xd6\\xbc\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x5bc\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x007\\x001\\x00>\\x00 \\x00<\\x00S\\x00e\\x00t\\x00O\\x00v\\x00e\\x00r\\x00r\\x00i\\x00d\\x00e\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00U\\x00p\\x00o\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00,\\x00 \\x00d\\x00o\\x00 \\x00n\\x00o\\x00t\\x00h\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x84\\xbd\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\xbd\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x007\\x003\\x00>\\x00 \\x00<\\x00r\\x00e\\x00s\\x00t\\x00o\\x00r\\x00e\\x00S\\x00e\\x00c\\x00u\\x00r\\x00e\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00U\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00i\\x00n\\x00g\\x00 \\x00F\\x00A\\x00L\\x00S\\x00E\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xbe\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 752
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xbe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 753
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x007\\x007\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00n\\x00o\\x00 \\x00n\\x00e\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00r\\x00e\\x00s\\x00t\\x00o\\x00r\\x00e\\x00 \\x00S\\x00C\\x00 \\x00u\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00s\\x00e\\x00t\\x00t\\x00i\\x00n\\x00g\\x00s\\x00.\\x00 \\x00C\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 754
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 755
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 756
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 757
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xbe\\xbe\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 758
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xbe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 759
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x008\\x000\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00D\\x00I\\x00R\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 760
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 761
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 762
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 763
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00@\\xbf\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 764
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "@\\xbf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 765
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x008\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00 \\x00s\\x00e\\x00t\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00D\\x00I\\x00R\\x00 \\x00t\\x00o\\x00 \\x00f\\x00w\\x00_\\x00i\\x00n\\x00s\\x00t\\x00d\\x00i\\x00r\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 766
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 767
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 768
          },
          {
            "timestamp": "2026-02-10 09:22:05,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 769
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xbf\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 770
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\xbf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 771
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x008\\x005\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00c\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00Q\\x00u\\x00e\\x00r\\x00y\\x00D\\x00o\\x00s\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 772
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 773
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 774
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 775
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x006\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 776
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\xc0\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 777
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x008\\x008\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00D\\x00o\\x00s\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00C\\x00=\\x00\\\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00\\\\x00H\\x00a\\x00r\\x00d\\x00d\\x00i\\x00s\\x00k\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 778
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 779
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 780
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 781
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xbe\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 782
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xc0\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 783
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x009\\x001\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00f\\x00w\\x00_\\x00i\\x00n\\x00s\\x00t\\x00d\\x00i\\x00r\\x00 \\x00a\\x00f\\x00t\\x00e\\x00r\\x00 \\x00t\\x00h\\x00e\\x00 \\x00s\\x00t\\x00r\\x00r\\x00c\\x00h\\x00r\\x00:\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 784
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 785
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 786
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 787
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x004\\xc2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 788
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4\\xc2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 789
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x009\\x003\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00D\\x00o\\x00s\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00C\\x00 \\x00a\\x00f\\x00t\\x00e\\x00r\\x00 \\x00t\\x00h\\x00e\\x00 \\x00s\\x00t\\x00r\\x00n\\x00c\\x00a\\x00t\\x00:\\x00 \\x00\\\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00\\\\x00H\\x00a\\x00r\\x00d\\x00d\\x00i\\x00s\\x00k\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 790
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 791
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 792
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 793
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe2\\xc2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 794
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\xc2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 795
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x009\\x006\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00G\\x00e\\x00t\\x00T\\x00e\\x00m\\x00p\\x00P\\x00a\\x00t\\x00h\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 796
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 797
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 798
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 799
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\\\xc3\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 800
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\\\xc3\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 801
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x001\\x009\\x009\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00t\\x00m\\x00p\\x00n\\x00a\\x00m\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 802
          },
          {
            "timestamp": "2026-02-10 09:22:05,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 803
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 804
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 805
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xce\\xc3\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 806
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xce\\xc3\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 807
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x000\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00f\\x00i\\x00l\\x00e\\x00n\\x00a\\x00m\\x00e\\x00 \\x00a\\x00f\\x00t\\x00e\\x00r\\x00 \\x00t\\x00h\\x00e\\x00 \\x00s\\x00t\\x00r\\x00r\\x00c\\x00h\\x00r\\x00:\\x00 \\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 808
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 809
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 810
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 811
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00Z\\xc5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 812
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\xc5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 813
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x000\\x005\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00I\\x00N\\x00N\\x00E\\x00R\\x00_\\x00M\\x00S\\x00I\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 814
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 815
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 816
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 817
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xde\\xc5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 818
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde\\xc5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 819
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x001\\x000\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00S\\x00C\\x00_\\x00U\\x00I\\x00F\\x00R\\x00A\\x00M\\x00E\\x00W\\x00O\\x00R\\x00K\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 820
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 821
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 822
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 823
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00l\\xc6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 824
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l\\xc6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 825
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x001\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00D\\x00E\\x00A\\x00F\\x00U\\x00L\\x00T\\x00_\\x00V\\x00P\\x00N\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00E\\x00C\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 826
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 827
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 828
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 829
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf4\\xc6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 830
          },
          {
            "timestamp": "2026-02-10 09:22:05,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4\\xc6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 831
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x001\\x005\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00S\\x00D\\x00L\\x00_\\x00E\\x00N\\x00A\\x00B\\x00L\\x00E\\x00D\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 832
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 833
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 834
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 835
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00|\\xc7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 836
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "|\\xc7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 837
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x001\\x008\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00c\\x00o\\x00p\\x00y\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00t\\x00o\\x00:\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00A\\x00C\\x006\\x009\\x00.\\x00t\\x00m\\x00p\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 838
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 839
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 840
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 841
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xc8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 842
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xc8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 843
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x002\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00F\\x00I\\x00X\\x00E\\x00D\\x00_\\x00M\\x00A\\x00C\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 844
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 845
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 846
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 847
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x84\\xc8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 848
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\xc8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 849
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x002\\x004\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00N\\x00o\\x00K\\x00e\\x00e\\x00p\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "90"
              }
            ],
            "repeated": 0,
            "id": 850
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 851
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 852
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 853
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xde\\xc8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 854
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde\\xc8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 855
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x002\\x007\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00I\\x00n\\x00n\\x00e\\x00r\\x00M\\x00S\\x00I\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 856
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 857
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 858
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 859
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00<\\xc9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 860
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "<\\xc9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 861
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x002\\x009\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00U\\x00I\\x00_\\x00F\\x00r\\x00a\\x00m\\x00e\\x00w\\x00o\\x00r\\x00k\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 862
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 863
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 864
          },
          {
            "timestamp": "2026-02-10 09:22:05,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 865
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xa2\\xc9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 866
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xc9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 867
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x003\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00E\\x00P\\x00C\\x00_\\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00_\\x00V\\x00P\\x00N\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 868
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 869
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 870
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 871
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 872
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xca\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 873
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x003\\x005\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00S\\x00D\\x00L\\x00 \\x00s\\x00h\\x00o\\x00u\\x00l\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00b\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 874
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 875
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 876
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 877
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x8a\\xca\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 878
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a\\xca\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 879
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x003\\x009\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00F\\x00i\\x00x\\x00e\\x00d\\x00M\\x00A\\x00C\\x00B\\x00u\\x00f\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "100"
              }
            ],
            "repeated": 0,
            "id": 880
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 881
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 882
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 883
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xee\\xca\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 884
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\xca\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 885
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x004\\x001\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00U\\x00I\\x00_\\x00L\\x00e\\x00v\\x00e\\x00l\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 886
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 887
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 888
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 889
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00n\\xcb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 890
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "n\\xcb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 891
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x004\\x004\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00 \\x00u\\x00i\\x00 \\x00l\\x00e\\x00v\\x00e\\x00l\\x00 \\x00!\\x00=\\x00 \\x002\\x00 \\x00-\\x00>\\x00 \\x00N\\x00O\\x00T\\x00 \\x00s\\x00i\\x00l\\x00e\\x00n\\x00t\\x00 \\x00-\\x00>\\x00 \\x00O\\x00t\\x00h\\x00e\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 892
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 893
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 894
          },
          {
            "timestamp": "2026-02-10 09:22:05,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 895
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xfc\\xcb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 896
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\xcb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 897
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x004\\x007\\x00>\\x00 \\x00<\\x00I\\x00s\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00D\\x00i\\x00s\\x00a\\x00b\\x00l\\x00e\\x00d\\x00>\\x00 \\x00N\\x00O\\x00_\\x00O\\x00F\\x00F\\x00I\\x00C\\x00E\\x00_\\x00M\\x00O\\x00D\\x00E\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00i\\x00s\\x00 \\x000\\x00 \\x00-\\x00>\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00f\\x00a\\x00l\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 898
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 899
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 900
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 901
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x0e\\xce\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 902
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\xce\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 903
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x005\\x000\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00 \\x00'\\x00n\\x00o\\x00 \\x00o\\x00f\\x00f\\x00i\\x00c\\x00e\\x00 \\x00m\\x00o\\x00d\\x00e\\x00'\\x00 \\x00p\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00f\\x00o\\x00u\\x00n\\x00d\\x00 \\x00/\\x00 \\x00n\\x00o\\x00t\\x00 \\x00m\\x00a\\x00r\\x00k\\x00e\\x00d\\x00 \\x00a\\x00s\\x00 \\x00d\\x00i\\x00s\\x00a\\x00b\\x00l\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 904
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 905
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 906
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 907
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd2\\xce\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 908
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xce\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 909
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x005\\x003\\x00>\\x00 \\x00<\\x00S\\x00e\\x00t\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00S\\x00e\\x00t\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "288"
              }
            ],
            "repeated": 0,
            "id": 910
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 911
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 912
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 913
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf2\\xcf\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 914
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2\\xcf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 915
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x005\\x006\\x00>\\x00 \\x00<\\x00S\\x00e\\x00t\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00>\\x00 \\x00C\\x00o\\x00u\\x00l\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00e\\x00t\\x00r\\x00e\\x00i\\x00v\\x00e\\x00 \\x00P\\x00R\\x00O\\x00D\\x00D\\x00I\\x00R\\x00 \\x00f\\x00r\\x00o\\x00m\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 916
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 917
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 918
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 919
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xa2\\xd0\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 920
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xd0\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 921
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x005\\x009\\x00>\\x00 \\x00<\\x00S\\x00e\\x00t\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00S\\x00e\\x00t\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "284"
              }
            ],
            "repeated": 0,
            "id": 922
          },
          {
            "timestamp": "2026-02-10 09:22:05,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 923
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 924
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 925
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xbe\\xd1\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 926
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xd1\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 927
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x006\\x001\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00E\\x00x\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00=\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 928
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 929
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 930
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 931
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xd2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 932
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\xd2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 933
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x006\\x009\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00E\\x00x\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00e\\x00x\\x00i\\x00t\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 934
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 935
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 936
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 937
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd4\\xd2\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 938
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4\\xd2\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 939
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x007\\x002\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00=\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 940
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 941
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 942
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 943
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00f\\xd3\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 944
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\xd3\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 945
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x007\\x005\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00l\\x00e\\x00_\\x00n\\x00a\\x00m\\x00e\\x00=\\x00L\\x00a\\x00n\\x00g\\x00P\\x00a\\x00c\\x00k\\x001\\x00.\\x00x\\x00m\\x00l\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 946
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 947
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 948
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 949
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x16\\xd4\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 950
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16\\xd4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 951
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x007\\x007\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00 \\x00q\\x00u\\x00e\\x00r\\x00y\\x00 \\x00S\\x00E\\x00L\\x00E\\x00C\\x00T\\x00 \\x00*\\x00 \\x00F\\x00R\\x00O\\x00M\\x00 \\x00B\\x00i\\x00n\\x00a\\x00r\\x00y\\x00 \\x00W\\x00H\\x00E\\x00R\\x00E\\x00 \\x00N\\x00a\\x00m\\x00e\\x00=\\x00'\\x00C\\x00P\\x00I\\x00N\\x00S\\x00T\\x00A\\x00D\\x00D\\x00I\\x00N\\x00T\\x00_\\x00L\\x00a\\x00n\\x00g\\x00P\\x00a\\x00c\\x00k\\x001\\x00.\\x00x\\x00m\\x00l\\x00'\\x00"
              },
              {
                "name": "Length",
                "value": "260"
              }
            ],
            "repeated": 0,
            "id": 952
          },
          {
            "timestamp": "2026-02-10 09:22:05,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 953
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 954
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 955
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x1a\\xd5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 956
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\xd5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 957
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x008\\x000\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00F\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00M\\x00s\\x00i\\x00V\\x00i\\x00e\\x00w\\x00F\\x00e\\x00t\\x00c\\x00h\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00n\\x00u\\x00m\\x00b\\x00e\\x00r\\x00 \\x002\\x005\\x009\\x00 \\x00(\\x00L\\x00a\\x00n\\x00g\\x00P\\x00a\\x00c\\x00k\\x001\\x00.\\x00x\\x00m\\x00l\\x00 \\x00s\\x00e\\x00c\\x00t\\x00i\\x00o\\x00n\\x00)\\x00 \\x00(\\x00E\\x00r\\x00r\\x00o\\x00"
              },
              {
                "name": "Length",
                "value": "354"
              }
            ],
            "repeated": 0,
            "id": 958
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 959
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 960
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 961
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00|\\xd6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 962
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "|\\xd6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 963
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x008\\x003\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00l\\x00e\\x00_\\x00n\\x00a\\x00m\\x00e\\x00=\\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 964
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 965
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 966
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 967
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00(\\xd7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 968
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xd7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 969
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x008\\x006\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00 \\x00q\\x00u\\x00e\\x00r\\x00y\\x00 \\x00S\\x00E\\x00L\\x00E\\x00C\\x00T\\x00 \\x00*\\x00 \\x00F\\x00R\\x00O\\x00M\\x00 \\x00B\\x00i\\x00n\\x00a\\x00r\\x00y\\x00 \\x00W\\x00H\\x00E\\x00R\\x00E\\x00 \\x00N\\x00a\\x00m\\x00e\\x00=\\x00'\\x00C\\x00P\\x00I\\x00N\\x00S\\x00T\\x00A\\x00D\\x00D\\x00I\\x00N\\x00T\\x00_\\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00'\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "256"
              }
            ],
            "repeated": 0,
            "id": 970
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 971
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 972
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 973
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00(\\xd8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 974
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xd8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 975
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x008\\x009\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00e\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00t\\x00e\\x00m\\x00p\\x00 \\x00d\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 976
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 977
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 978
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 979
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0\\xd8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 980
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0\\xd8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 981
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x009\\x002\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00l\\x00e\\x00_\\x00n\\x00a\\x00m\\x00e\\x00=\\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 982
          },
          {
            "timestamp": "2026-02-10 09:22:05,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 983
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 984
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 985
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x98\\xd9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 986
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98\\xd9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 987
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x002\\x009\\x005\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00 \\x00q\\x00u\\x00e\\x00r\\x00y\\x00 \\x00S\\x00E\\x00L\\x00E\\x00C\\x00T\\x00 \\x00*\\x00 \\x00F\\x00R\\x00O\\x00M\\x00 \\x00B\\x00i\\x00n\\x00a\\x00r\\x00y\\x00 \\x00W\\x00H\\x00E\\x00R\\x00E\\x00 \\x00N\\x00a\\x00m\\x00e\\x00=\\x00'\\x00C\\x00P\\x00I\\x00N\\x00S\\x00T\\x00A\\x00D\\x00D\\x00I\\x00N\\x00T\\x00_\\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00'\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 988
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 989
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 990
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 991
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x94\\xda\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 992
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\xda\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 993
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x003\\x000\\x000\\x00>\\x00 \\x00<\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00T\\x00o\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00 \\x00e\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00t\\x00e\\x00m\\x00p\\x00 \\x00d\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 994
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 995
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 996
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 997
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00X\\xdb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 998
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "X\\xdb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 999
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x003\\x000\\x003\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00c\\x00h\\x00a\\x00n\\x00g\\x00e\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00s\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00 \\x00a\\x00c\\x00c\\x00o\\x00r\\x00d\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00c\\x00l\\x00i\\x00e\\x00n\\x00t\\x00 \\x00t\\x00y\\x00p\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 1000
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1001
          },
          {
            "timestamp": "2026-02-10 09:22:05,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 3,
            "id": 1002
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1003
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x01\\x00\\x00\\x00\\x00\\x00.\\x05\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1004
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ".\\x05\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1005
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00.\\x003\\x001\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 1006
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1007
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1008
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1009
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x01\\x00\\x00\\x00\\x00\\x00\\x12\\x06\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1010
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\x06\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1011
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x006\\x000\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "218"
              }
            ],
            "repeated": 0,
            "id": 1012
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1013
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1014
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1015
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x01\\x00\\x00\\x00\\x00\\x00\\xec\\x06\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1016
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec\\x06\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1017
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "434"
              }
            ],
            "repeated": 0,
            "id": 1018
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1019
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1020
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1021
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x01\\x00\\x00\\x00\\x00\\x00\\x1a\\x0b\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1022
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\x0b\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1023
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00O\\x00n\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 1024
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1025
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1026
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1027
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x01\\x00\\x00\\x00\\x00\\x00f\\x0c\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1028
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\x0c\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1029
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00o\\x00s\\x00t\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 1030
          },
          {
            "timestamp": "2026-02-10 09:22:05,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1031
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1032
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1033
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x01\\x00\\x00\\x00\\x00\\x00\\x84\\x13\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1034
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\x13\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1035
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00o\\x00s\\x00t\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 1036
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1037
          },
          {
            "timestamp": "2026-02-10 09:22:05,328",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1038
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1039
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x01\\x00\\x00\\x00\\x00\\x00\\xc4\\x1c\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1040
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4\\x1c\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1041
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00R\\x00e\\x00s\\x00o\\x00l\\x00v\\x00e\\x00S\\x00o\\x00u\\x00r\\x00c\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 1042
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1043
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1044
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1045
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x80F\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1046
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80F\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1047
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00R\\x00e\\x00s\\x00o\\x00l\\x00v\\x00e\\x00S\\x00o\\x00u\\x00r\\x00c\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 1048
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1049
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1050
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1051
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xeeH\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1052
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeeH\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1053
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00F\\x00i\\x00l\\x00e\\x00C\\x00o\\x00s\\x00t\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 1054
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1055
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1056
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1057
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xaaI\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1058
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaaI\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1059
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00F\\x00i\\x00l\\x00e\\x00C\\x00o\\x00s\\x00t\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "100"
              }
            ],
            "repeated": 0,
            "id": 1060
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1061
          },
          {
            "timestamp": "2026-02-10 09:22:05,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1062
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1063
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe8\\x8f\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1064
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\\x8f\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1065
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00o\\x00s\\x00t\\x00F\\x00i\\x00n\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 1066
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1067
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1068
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1069
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x04\\x91\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1070
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04\\x91\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1071
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00o\\x00s\\x00t\\x00F\\x00i\\x00n\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 1072
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1073
          },
          {
            "timestamp": "2026-02-10 09:22:05,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1074
          },
          {
            "timestamp": "2026-02-10 09:22:05,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1075
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00~\\x92\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1076
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\x92\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1077
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 1078
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1079
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1080
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1081
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\"\\x93\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1082
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\x93\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1083
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 1084
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1085
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1086
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1087
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x92\\x93\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1088
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x92\\x93\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1089
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00N\\x00T\\x00 \\x00=\\x00 \\x006\\x000\\x003\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 1090
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1091
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1092
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1093
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x04\\x94\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1094
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04\\x94\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1095
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00P\\x00a\\x00c\\x00k\\x00L\\x00e\\x00v\\x00e\\x00l\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 1096
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1097
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1098
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1099
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x80\\x94\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1100
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80\\x94\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1101
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00F\\x00o\\x00u\\x00n\\x00d\\x00 \\x008\\x00 \\x00n\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00 \\x00f\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 1102
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1103
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1104
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1105
          },
          {
            "timestamp": "2026-02-10 09:22:05,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x115\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1106
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x115\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1107
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00C\\x00o\\x00u\\x00l\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00e\\x00a\\x00d\\x00 \\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00,\\x00 \\x00i\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00a\\x00d\\x00d\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "180"
              }
            ],
            "repeated": 0,
            "id": 1108
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1109
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1110
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1111
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00x\\x96\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1112
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "x\\x96\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1113
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00:\\x00 \\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 1114
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1115
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1116
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1117
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xbc\\x97\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1118
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbc\\x97\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1119
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 1120
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1121
          },
          {
            "timestamp": "2026-02-10 09:22:05,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 1122
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1123
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x94\\x99\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1124
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\x99\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1125
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x005\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "170"
              }
            ],
            "repeated": 0,
            "id": 1126
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1127
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1128
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1129
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00>\\x9a\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1130
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">\\x9a\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1131
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1132
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1133
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1134
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1135
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x9b\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1136
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x9b\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1137
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00 \\x00c\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00i\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00a\\x00i\\x00n\\x00g\\x00 \\x00s\\x00h\\x00a\\x00r\\x00e\\x00d\\x00 \\x00m\\x00e\\x00m\\x00o\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "156"
              }
            ],
            "repeated": 0,
            "id": 1138
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1139
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1140
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1141
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x9c\\x9b\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1142
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\x9b\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1143
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00i\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00 \\x00=\\x00 \\x000\\x00,\\x00P\\x00I\\x00D\\x00=\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 1144
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1145
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1146
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1147
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x9c\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1148
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\x9c\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1149
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00T\\x00r\\x00y\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00p\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00 \\x00w\\x00/\\x00 \\x00P\\x00I\\x00D\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1150
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1151
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1152
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1153
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x9a\\x9c\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1154
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\x9c\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1155
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00G\\x00o\\x00t\\x00:\\x00 \\x00 \\x000\\x00,\\x00 \\x00G\\x00e\\x00t\\x00L\\x00a\\x00s\\x00t\\x00E\\x00r\\x00r\\x00o\\x00r\\x00(\\x00)\\x00=\\x008\\x007\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 1156
          },
          {
            "timestamp": "2026-02-10 09:22:05,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1157
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1158
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1159
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x0e\\x9d\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1160
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\x9d\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1161
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00(\\x00)\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00s\\x00:\\x00 \\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 1162
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1163
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1164
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1165
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x96\\x9d\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1166
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96\\x9d\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1167
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 1168
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1169
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1170
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1171
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x02\\x9e\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1172
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\x9e\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1173
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00C\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00d\\x00o\\x00n\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "98"
              }
            ],
            "repeated": 0,
            "id": 1174
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1175
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1176
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1177
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00d\\x9e\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1178
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\x9e\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1179
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00V\\x00E\\x00R\\x00S\\x00I\\x00O\\x00N\\x00 \\x00=\\x00 \\x008\\x00.\\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1180
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1181
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1182
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1183
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xea\\x9e\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1184
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xea\\x9e\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1185
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00 \\x00=\\x00 \\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1186
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1187
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1188
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1189
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xac\\x9f\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1190
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\x9f\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1191
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 1192
          },
          {
            "timestamp": "2026-02-10 09:22:05,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1193
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1194
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1195
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00,\\xa0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1196
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ",\\xa0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1197
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00V\\x00E\\x00R\\x00R\\x00I\\x00D\\x00E\\x00_\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 1198
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1199
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1200
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1201
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x120\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1202
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x120\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1203
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00S\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 1204
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1205
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1206
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1207
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00>\\xa1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1208
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">\\xa1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1209
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1210
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1211
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1212
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1213
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x121\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1214
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x121\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1215
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 1216
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1217
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1218
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1219
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x006\\xa2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1220
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\xa2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1221
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00=\\x00N\\x00O\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00N\\x00O\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 1222
          },
          {
            "timestamp": "2026-02-10 09:22:05,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1223
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1224
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1225
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe6\\xa2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1226
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\xa2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1227
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1228
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1229
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1230
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1231
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa8\\xa3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1232
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\xa3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1233
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00e\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00e\\x00d\\x00 \\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00t\\x00o\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x00"
              },
              {
                "name": "Length",
                "value": "366"
              }
            ],
            "repeated": 0,
            "id": 1234
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1235
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1236
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1237
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa6\\xa6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1238
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa6\\xa6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1239
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\\\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00"
              },
              {
                "name": "Length",
                "value": "304"
              }
            ],
            "repeated": 0,
            "id": 1240
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1241
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1242
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1243
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x5a7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1244
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x5a7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1245
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00i\\x00n\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 1246
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1247
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1248
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1249
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00V\\xa8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1250
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "V\\xa8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1251
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00A\\x00L\\x00L\\x00C\\x00A\\x00D\\x00P\\x00R\\x00O\\x00P\\x00S\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1252
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1253
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1254
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1255
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x728\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1256
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x728\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1257
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00T\\x00O\\x00R\\x00E\\x00D\\x00P\\x00R\\x00O\\x00P\\x00E\\x00R\\x00T\\x00I\\x00E\\x00S\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 1258
          },
          {
            "timestamp": "2026-02-10 09:22:05,828",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1259
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1260
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1261
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00l\\xa9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1262
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l\\xa9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1263
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00F\\x00r\\x00e\\x00s\\x00h\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 1264
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1265
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1266
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1267
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xf6\\xa9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1268
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6\\xa9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1269
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00F\\x00r\\x00e\\x00s\\x00h\\x00A\\x00f\\x00t\\x00e\\x00r\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 1270
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1271
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1272
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1273
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00~\\xaa\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1274
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\xaa\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1275
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 1276
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1277
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1278
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1279
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\n\\xab\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1280
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\n\\xab\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1281
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00A\\x00f\\x00t\\x00e\\x00r\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 1282
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1283
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1284
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1285
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x94\\xab\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1286
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\xab\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1287
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 1288
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1289
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1290
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1291
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\"\\xac\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1292
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\xac\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1293
          },
          {
            "timestamp": "2026-02-10 09:22:05,843",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00A\\x00f\\x00t\\x00e\\x00r\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 1294
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1295
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1296
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1297
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xae\\xac\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1298
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xae\\xac\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1299
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 1300
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1301
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1302
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1303
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00<\\xad\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1304
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "<\\xad\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1305
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x001\\x00F\\x003\\x005\\x007\\x009\\x002\\x003\\x00_\\x00E\\x005\\x00E\\x00D\\x00_\\x004\\x00F\\x004\\x00F\\x00_\\x009\\x00B\\x002\\x008\\x00_\\x00B\\x001\\x004\\x006\\x001\\x005\\x003\\x00C\\x007\\x004\\x004\\x006\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "216"
              }
            ],
            "repeated": 0,
            "id": 1306
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1307
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1308
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1309
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x14\\xae\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1310
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\xae\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1311
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 1312
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1313
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1314
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1315
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xac\\xae\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1316
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\xae\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1317
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "226"
              }
            ],
            "repeated": 0,
            "id": 1318
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1319
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1320
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1321
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8e\\xaf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1322
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\xaf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1323
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 1324
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1325
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1326
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1327
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00(\\xb0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1328
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xb0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1329
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 1330
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1331
          },
          {
            "timestamp": "2026-02-10 09:22:05,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1332
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1333
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x0c\\xb1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1334
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xb1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1335
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x00D\\x00F\\x00E\\x005\\x008\\x00C\\x002\\x00-\\x003\\x002\\x003\\x00A\\x00-\\x004\\x00A\\x00B\\x00C\\x00-\\x008\\x00D\\x009\\x002\\x00-\\x005\\x003\\x00A\\x003\\x004\\x00F\\x000\\x00B\\x006\\x005\\x007\\x005\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1336
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1337
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1338
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1339
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x3b1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1340
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x3b1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1341
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00S\\x00 \\x00=\\x00 \\x00#\\x001\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 1342
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1343
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1344
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1345
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00R\\xb2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1346
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "R\\xb2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1347
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00_\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 1348
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1349
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1350
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1351
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x10\\xb3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1352
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xb3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1353
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00A\\x00g\\x00r\\x00e\\x00e\\x00T\\x00o\\x00L\\x00i\\x00c\\x00e\\x00n\\x00s\\x00e\\x00 \\x00=\\x00 \\x00N\\x00o\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 1354
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1355
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1356
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1357
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\\xb3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1358
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xb3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1359
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00_\\x00I\\x00s\\x00M\\x00a\\x00i\\x00n\\x00t\\x00e\\x00n\\x00a\\x00n\\x00c\\x00e\\x00 \\x00=\\x00 \\x00R\\x00e\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 1360
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1361
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1362
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1363
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x1e\\xb4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1364
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xb4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1365
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00=\\x00 \\x00E\\x00N\\x00D\\x00P\\x00O\\x00I\\x00N\\x00T\\x00_\\x00S\\x00E\\x00C\\x00U\\x00R\\x00I\\x00T\\x00Y\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "160"
              }
            ],
            "repeated": 0,
            "id": 1366
          },
          {
            "timestamp": "2026-02-10 09:22:05,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1367
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1368
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1369
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xbe\\xb4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1370
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xb4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1371
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 1372
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1373
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1374
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1375
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x008\\xb5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1376
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8\\xb5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1377
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00A\\x00R\\x00P\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00I\\x00C\\x00O\\x00N\\x00 \\x00=\\x00 \\x00i\\x00c\\x00o\\x00n\\x00.\\x00i\\x00c\\x00o\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 1378
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1379
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1380
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1381
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x135\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1382
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x135\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1383
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00M\\x00s\\x00i\\x00L\\x00o\\x00g\\x00g\\x00i\\x00n\\x00g\\x00 \\x00=\\x00 \\x00v\\x00o\\x00i\\x00c\\x00e\\x00w\\x00a\\x00r\\x00m\\x00u\\x00p\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 1384
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1385
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1386
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1387
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00N\\xb6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1388
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "N\\xb6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1389
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00H\\x00O\\x00W\\x00_\\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00T\\x00Y\\x00P\\x00E\\x00_\\x00D\\x00L\\x00G\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 1390
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1391
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1392
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1393
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x7b6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1394
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x7b6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1395
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00I\\x00S\\x00A\\x00B\\x00L\\x00E\\x00A\\x00D\\x00V\\x00T\\x00S\\x00H\\x00O\\x00R\\x00T\\x00C\\x00U\\x00T\\x00S\\x00 \\x00=\\x00 \\x001\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 1396
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1397
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1398
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1399
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00h\\xb7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1400
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xb7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1401
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00A\\x00C\\x00K\\x00A\\x00G\\x00E\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00=\\x00 \\x00#\\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 1402
          },
          {
            "timestamp": "2026-02-10 09:22:05,890",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1403
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1404
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1405
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe4\\xb7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1406
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\xb7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1407
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00T\\x00E\\x00L\\x00E\\x00M\\x00E\\x00T\\x00R\\x00Y\\x00_\\x00D\\x00I\\x00S\\x00A\\x00B\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1408
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1409
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1410
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1411
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00j\\xb8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1412
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xb8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1413
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00D\\x00i\\x00a\\x00l\\x00o\\x00g\\x00 \\x00=\\x00 \\x00S\\x00e\\x00t\\x00u\\x00p\\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 1414
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1415
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1416
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1417
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xf4\\xb8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1418
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4\\xb8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1419
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00U\\x00I\\x00F\\x00o\\x00n\\x00t\\x00 \\x00=\\x00 \\x00W\\x00i\\x00x\\x00U\\x00I\\x00_\\x00F\\x00o\\x00n\\x00t\\x00_\\x00N\\x00o\\x00r\\x00m\\x00a\\x00l\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "156"
              }
            ],
            "repeated": 0,
            "id": 1420
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1421
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1422
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1423
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\\xb9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1424
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xb9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1425
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00M\\x00a\\x00n\\x00u\\x00f\\x00a\\x00c\\x00t\\x00u\\x00r\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00o\\x00f\\x00t\\x00w\\x00a\\x00r\\x00e\\x00 \\x00T\\x00e\\x00c\\x00h\\x00n\\x00o\\x00l\\x00o\\x00g\\x00i\\x00e\\x00s\\x00 \\x00L\\x00t\\x00d\\x00.\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 1426
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1427
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1428
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1429
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00T\\xba\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1430
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\xba\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1431
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1432
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1433
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1434
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1435
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x16\\xbb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1436
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16\\xbb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1437
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00L\\x00a\\x00n\\x00g\\x00u\\x00a\\x00g\\x00e\\x00 \\x00=\\x00 \\x001\\x000\\x003\\x003\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1438
          },
          {
            "timestamp": "2026-02-10 09:22:05,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1439
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1440
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1441
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x9c\\xbb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1442
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\xbb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1443
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00N\\x00a\\x00m\\x00e\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00V\\x00P\\x00N\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "148"
              }
            ],
            "repeated": 0,
            "id": 1444
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1445
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1446
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1447
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x000\\xbc\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1448
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\xbc\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1449
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x00=\\x00 \\x009\\x008\\x00.\\x006\\x001\\x00.\\x004\\x006\\x000\\x005\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 1450
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1451
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1452
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1453
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc0\\xbc\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1454
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\xbc\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1455
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00e\\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00 \\x00=\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00;\\x00E\\x00P\\x00S\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00;\\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00;\\x00I\\x00S\\x00A\\x00C\\x00T\\x00I\\x00O\\x00N\\x00P\\x00R\\x00O\\x00P\\x001\\x00;\\x00I\\x00S\\x00D\\x00O\\x00W\\x00N\\x00"
              },
              {
                "name": "Length",
                "value": "370"
              }
            ],
            "repeated": 0,
            "id": 1456
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1457
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1458
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1459
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x002\\xbe\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1460
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2\\xbe\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1461
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00I\\x00X\\x00E\\x00D\\x00_\\x00M\\x00A\\x00C\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 1462
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1463
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1464
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1465
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa8\\xbe\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1466
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\xbe\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1467
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00N\\x00O\\x00_\\x00O\\x00F\\x00F\\x00I\\x00C\\x00E\\x00_\\x00M\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 1468
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1469
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1470
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1471
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00&\\xbf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1472
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\xbf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1473
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00D\\x00L\\x00_\\x00E\\x00N\\x00A\\x00B\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 1474
          },
          {
            "timestamp": "2026-02-10 09:22:05,922",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1475
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1476
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1477
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xbf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1478
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xbf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1479
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1480
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1481
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1482
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1483
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00&\\xc0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1484
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\xc0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1485
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00N\\x00A\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 1486
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1487
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1488
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1489
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa2\\xc0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1490
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xc0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1491
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00N\\x00E\\x00R\\x00_\\x00M\\x00S\\x00I\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 1492
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1493
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1494
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1495
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\xc1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1496
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xc1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1497
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00C\\x00_\\x00U\\x00I\\x00F\\x00R\\x00A\\x00M\\x00E\\x00W\\x00O\\x00R\\x00K\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 1498
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1499
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1500
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1501
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x98\\xc1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1502
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98\\xc1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1503
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00E\\x00A\\x00F\\x00U\\x00L\\x00T\\x00_\\x00V\\x00P\\x00N\\x00 \\x00=\\x00 \\x00E\\x00C\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 1504
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1505
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1506
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1507
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x12\\xc2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1508
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\xc2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1509
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00N\\x00o\\x00K\\x00e\\x00e\\x00p\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 1510
          },
          {
            "timestamp": "2026-02-10 09:22:05,937",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1511
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1512
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1513
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x82\\xc2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1514
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82\\xc2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1515
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00N\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00N\\x00O\\x00P\\x00A\\x00S\\x00S\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 1516
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1517
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1518
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1519
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x12\\xc3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1520
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\xc3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1521
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00M\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00o\\x00m\\x00u\\x00s\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1522
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1523
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1524
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1525
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x94\\xc3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1526
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\xc3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1527
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00_\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00E\\x00P\\x00_\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00E\\x008\\x007\\x00_\\x002\\x000\\x00\\\\x00B\\x008\\x006\\x008\\x007\\x002\\x000\\x000\\x000\\x006\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "246"
              }
            ],
            "repeated": 0,
            "id": 1528
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1529
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1530
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1531
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8a\\xc4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1532
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a\\xc4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1533
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00V\\x00E\\x00R\\x00S\\x00I\\x00O\\x00N\\x00 \\x00=\\x00 \\x008\\x00.\\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1534
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1535
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1536
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1537
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1538
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xc5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1539
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00 \\x00=\\x00 \\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 1540
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1541
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1542
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1543
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd2\\xc5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1544
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xc5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1545
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00D\\x00R\\x00V\\x00_\\x00R\\x00E\\x00P\\x00L\\x00A\\x00C\\x00E\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1546
          },
          {
            "timestamp": "2026-02-10 09:22:05,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1547
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1548
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1549
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00T\\xc6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1550
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\xc6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1551
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00\\\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00p\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "202"
              }
            ],
            "repeated": 0,
            "id": 1552
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1553
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1554
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1555
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x1e\\xc7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1556
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xc7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1557
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00E\\x00R\\x00R\\x00O\\x00R\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1558
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1559
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1560
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1561
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xc7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1562
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xc7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1563
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\\\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00.\\x00x\\x00m\\x00l\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 1564
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1565
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1566
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1567
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa6\\xc8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1568
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa6\\xc8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1569
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00_\\x00M\\x00S\\x00M\\x00_\\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00E\\x00P\\x00_\\x00M\\x00S\\x00M\\x00_\\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00\\\\x00E\\x008\\x007\\x00_\\x002\\x000\\x00\\\\x00B\\x008\\x006\\x008\\x007\\x002\\x000\\x000\\x00"
              },
              {
                "name": "Length",
                "value": "266"
              }
            ],
            "repeated": 0,
            "id": 1570
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1571
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1572
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1573
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\xc9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1574
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb0\\xc9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1575
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00A\\x00L\\x00L\\x00U\\x00S\\x00E\\x00R\\x00S\\x00 \\x00=\\x00 \\x001\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 1576
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1577
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1578
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1579
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\"\\xca\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1580
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\xca\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1581
          },
          {
            "timestamp": "2026-02-10 09:22:05,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00T\\x00a\\x00b\\x00l\\x00e\\x001\\x000\\x000\\x00_\\x00x\\x008\\x006\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00D\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00T\\x00a\\x00b\\x00l\\x00e\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "240"
              }
            ],
            "repeated": 0,
            "id": 1582
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1583
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1584
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1585
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x12\\xcb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1586
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\xcb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1587
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "218"
              }
            ],
            "repeated": 0,
            "id": 1588
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1589
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1590
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1591
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xec\\xcb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1592
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec\\xcb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1593
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00D\\x00I\\x00R\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 1594
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1595
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1596
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1597
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd0\\xcc\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1598
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0\\xcc\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1599
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00S\\x00e\\x00c\\x00u\\x00"
              },
              {
                "name": "Length",
                "value": "272"
              }
            ],
            "repeated": 0,
            "id": 1600
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1601
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1602
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1603
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xcd\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1604
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe0\\xcd\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1605
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00"
              },
              {
                "name": "Length",
                "value": "282"
              }
            ],
            "repeated": 0,
            "id": 1606
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1607
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1608
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1609
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xfa\\xce\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1610
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfa\\xce\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1611
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 1612
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1613
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1614
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1615
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe2\\xcf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1616
          },
          {
            "timestamp": "2026-02-10 09:22:05,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\xcf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1617
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "242"
              }
            ],
            "repeated": 0,
            "id": 1618
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1619
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1620
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1621
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd4\\xd0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1622
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4\\xd0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1623
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "248"
              }
            ],
            "repeated": 0,
            "id": 1624
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1625
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1626
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1627
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xcc\\xd1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1628
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcc\\xd1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1629
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00\\\\x00\r\\x00"
              },
              {
                "name": "Length",
                "value": "258"
              }
            ],
            "repeated": 0,
            "id": 1630
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1631
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1632
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1633
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xce\\xd2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1634
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xce\\xd2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1635
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00r\\x00e\\x00s\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "212"
              }
            ],
            "repeated": 0,
            "id": 1636
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1637
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1638
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1639
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa2\\xd3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1640
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xd3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1641
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00r\\x00e\\x00s\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "222"
              }
            ],
            "repeated": 0,
            "id": 1642
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1643
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1644
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1645
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x80\\xd4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1646
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80\\xd4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1647
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 1648
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1649
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1650
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1651
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\xd5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1652
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xd5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1653
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 1654
          },
          {
            "timestamp": "2026-02-10 09:22:06,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1655
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1656
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1657
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xba\\xd5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1658
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xd5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1659
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "210"
              }
            ],
            "repeated": 0,
            "id": 1660
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1661
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1662
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1663
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8c\\xd6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1664
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8c\\xd6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1665
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "220"
              }
            ],
            "repeated": 0,
            "id": 1666
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1667
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1668
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1669
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00h\\xd7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1670
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xd7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1671
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00 \\x00"
              },
              {
                "name": "Length",
                "value": "260"
              }
            ],
            "repeated": 0,
            "id": 1672
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1673
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1674
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1675
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00l\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1676
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l\\xd8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1677
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00"
              },
              {
                "name": "Length",
                "value": "270"
              }
            ],
            "repeated": 0,
            "id": 1678
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1679
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1680
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1681
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00z\\xd9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1682
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\xd9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1683
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "236"
              }
            ],
            "repeated": 0,
            "id": 1684
          },
          {
            "timestamp": "2026-02-10 09:22:06,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1685
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1686
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1687
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00f\\xda\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1688
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\xda\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1689
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "246"
              }
            ],
            "repeated": 0,
            "id": 1690
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1691
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1692
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1693
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\\\xdb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1694
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\\\xdb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1695
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00T\\x00A\\x00R\\x00G\\x00E\\x00T\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 1696
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1697
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1698
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1699
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd4\\xdb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1700
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4\\xdb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1701
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00T\\x00A\\x00R\\x00G\\x00E\\x00T\\x00D\\x00I\\x00R\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1702
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1703
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1704
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1705
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00V\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1706
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "V\\xdc\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1707
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 1708
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1709
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1710
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1711
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x14\\xdd\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1712
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\xdd\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1713
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 1714
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1715
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1716
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1717
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xdc\\xdd\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1718
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdc\\xdd\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1719
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 1720
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1721
          },
          {
            "timestamp": "2026-02-10 09:22:06,031",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1722
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1723
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8e\\xde\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1724
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\xde\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1725
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 1726
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1727
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1728
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1729
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00J\\xdf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1730
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "J\\xdf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1731
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 1732
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1733
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1734
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1735
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xda\\xdf\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1736
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xda\\xdf\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1737
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 1738
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1739
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1740
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1741
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00t\\xe0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1742
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t\\xe0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1743
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00T\\x00e\\x00l\\x00e\\x00m\\x00e\\x00t\\x00r\\x00y\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "208"
              }
            ],
            "repeated": 0,
            "id": 1744
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1745
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1746
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1747
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00D\\xe1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1748
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D\\xe1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1749
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00T\\x00e\\x00l\\x00e\\x00m\\x00e\\x00t\\x00r\\x00y\\x00D\\x00i\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "218"
              }
            ],
            "repeated": 0,
            "id": 1750
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1751
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1752
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1753
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x1e\\xe2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1754
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xe2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1755
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 1756
          },
          {
            "timestamp": "2026-02-10 09:22:06,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1757
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1758
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1759
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc6\\xe2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1760
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6\\xe2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1761
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00D\\x00i\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 1762
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1763
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1764
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1765
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00x\\xe3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1766
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "x\\xe3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1767
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 1768
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1769
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1770
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1771
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x1c\\xe4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1772
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1c\\xe4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1773
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 1774
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1775
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1776
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1777
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xca\\xe4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1778
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xca\\xe4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1779
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00_\\x00P\\x00r\\x00o\\x00x\\x00y\\x00S\\x00e\\x00r\\x00v\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00"
              },
              {
                "name": "Length",
                "value": "334"
              }
            ],
            "repeated": 0,
            "id": 1780
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1781
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1782
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1783
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\xe6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1784
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xe6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1785
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00V\\x00P\\x00N\\x00_\\x00P\\x00r\\x00o\\x00x\\x00y\\x00S\\x00e\\x00r\\x00v\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00"
              },
              {
                "name": "Length",
                "value": "344"
              }
            ],
            "repeated": 0,
            "id": 1786
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1787
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1788
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1789
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\xe7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1790
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "p\\xe7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1791
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 1792
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1793
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1794
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1795
          },
          {
            "timestamp": "2026-02-10 09:22:06,062",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00l\\xe8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1796
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l\\xe8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1797
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 1798
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1799
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1800
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1801
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00r\\xe9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1802
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "r\\xe9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1803
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00"
              },
              {
                "name": "Length",
                "value": "264"
              }
            ],
            "repeated": 0,
            "id": 1804
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1805
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1806
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1807
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00z\\xea\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1808
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\xea\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1809
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00"
              },
              {
                "name": "Length",
                "value": "274"
              }
            ],
            "repeated": 0,
            "id": 1810
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1811
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1812
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1813
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8c\\xeb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1814
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8c\\xeb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1815
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "234"
              }
            ],
            "repeated": 0,
            "id": 1816
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1817
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1818
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1819
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00v\\xec\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1820
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\xec\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1821
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "244"
              }
            ],
            "repeated": 0,
            "id": 1822
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1823
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1824
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1825
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00j\\xed\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1826
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xed\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1827
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00T\\x00V\\x00D\\x00I\\x00R\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00l\\x00a\\x00b\\x00s\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "238"
              }
            ],
            "repeated": 0,
            "id": 1828
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1829
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1830
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1831
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00X\\xee\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1832
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "X\\xee\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1833
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00T\\x00V\\x00D\\x00I\\x00R\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00l\\x00a\\x00b\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "248"
              }
            ],
            "repeated": 0,
            "id": 1834
          },
          {
            "timestamp": "2026-02-10 09:22:06,078",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1835
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1836
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1837
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00P\\xef\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1838
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\xef\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1839
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 1840
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1841
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1842
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1843
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00L\\xf0\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1844
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\xf0\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1845
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 1846
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1847
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1848
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1849
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00R\\xf1\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1850
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "R\\xf1\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1851
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00 \\x00\r\\x00"
              },
              {
                "name": "Length",
                "value": "258"
              }
            ],
            "repeated": 0,
            "id": 1852
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1853
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1854
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1855
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00T\\xf2\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1856
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\xf2\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1857
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00"
              },
              {
                "name": "Length",
                "value": "268"
              }
            ],
            "repeated": 0,
            "id": 1858
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1859
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1860
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1861
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00`\\xf3\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1862
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\xf3\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1863
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00D\\x00i\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00"
              },
              {
                "name": "Length",
                "value": "312"
              }
            ],
            "repeated": 0,
            "id": 1864
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1865
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1866
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1867
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x98\\xf4\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1868
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98\\xf4\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1869
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00D\\x00i\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00"
              },
              {
                "name": "Length",
                "value": "322"
              }
            ],
            "repeated": 0,
            "id": 1870
          },
          {
            "timestamp": "2026-02-10 09:22:06,093",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1871
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1872
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1873
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xda\\xf5\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1874
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xda\\xf5\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1875
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 1876
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1877
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1878
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1879
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd6\\xf6\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1880
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6\\xf6\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1881
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 1882
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1883
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1884
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1885
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xdc\\xf7\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1886
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdc\\xf7\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1887
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00"
              },
              {
                "name": "Length",
                "value": "264"
              }
            ],
            "repeated": 0,
            "id": 1888
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1889
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1890
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1891
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe4\\xf8\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1892
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\xf8\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1893
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00"
              },
              {
                "name": "Length",
                "value": "274"
              }
            ],
            "repeated": 0,
            "id": 1894
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1895
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1896
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1897
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xf6\\xf9\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1898
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6\\xf9\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1899
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00K\\x00P\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 1900
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1901
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1902
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1903
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xda\\xfa\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1904
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xda\\xfa\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1905
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00K\\x00P\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "238"
              }
            ],
            "repeated": 0,
            "id": 1906
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1907
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1908
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1909
          },
          {
            "timestamp": "2026-02-10 09:22:06,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc8\\xfb\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1910
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8\\xfb\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1911
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 1912
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1913
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1914
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1915
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc4\\xfc\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1916
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4\\xfc\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1917
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 1918
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1919
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1920
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1921
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xca\\xfd\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1922
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xca\\xfd\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1923
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00L\\x00o\\x00g\\x00s\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00s\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "240"
              }
            ],
            "repeated": 0,
            "id": 1924
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1925
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1926
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1927
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xba\\xfe\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1928
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xfe\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1929
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00L\\x00o\\x00g\\x00s\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "250"
              }
            ],
            "repeated": 0,
            "id": 1930
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1931
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1932
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1933
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb4\\xff\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1934
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\xff\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1935
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "238"
              }
            ],
            "repeated": 0,
            "id": 1936
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1937
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1938
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1939
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa2\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1940
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\x00\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1941
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "248"
              }
            ],
            "repeated": 0,
            "id": 1942
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1943
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1944
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1945
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x9a\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1946
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\x01\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1947
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00_\\x00x\\x008\\x006\\x00_\\x00V\\x00C\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "248"
              }
            ],
            "repeated": 0,
            "id": 1948
          },
          {
            "timestamp": "2026-02-10 09:22:06,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1949
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1950
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1951
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x92\\x02\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1952
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x92\\x02\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1953
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00_\\x00x\\x008\\x006\\x00_\\x00V\\x00C\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00"
              },
              {
                "name": "Length",
                "value": "258"
              }
            ],
            "repeated": 0,
            "id": 1954
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1955
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1956
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1957
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x94\\x03\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1958
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\x03\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1959
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "234"
              }
            ],
            "repeated": 0,
            "id": 1960
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1961
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1962
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1963
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00~\\x04\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1964
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\x04\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1965
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "244"
              }
            ],
            "repeated": 0,
            "id": 1966
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1967
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1968
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1969
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00r\\x05\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1970
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "r\\x05\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1971
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00L\\x00D\\x00V\\x00E\\x00R\\x00S\\x00I\\x00O\\x00N\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 1972
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1973
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1974
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1975
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe6\\x05\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1976
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\x05\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1977
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00N\\x00T\\x00 \\x00=\\x00 \\x006\\x000\\x003\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 1978
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1979
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1980
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1981
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00^\\x06\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1982
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\x06\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1983
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00N\\x00T\\x006\\x004\\x00 \\x00=\\x00 \\x006\\x000\\x003\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 1984
          },
          {
            "timestamp": "2026-02-10 09:22:06,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1985
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1986
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1987
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xda\\x06\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1988
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xda\\x06\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1989
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00P\\x00a\\x00c\\x00k\\x00L\\x00e\\x00v\\x00e\\x00l\\x00 \\x00=\\x00 \\x000\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 1990
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1991
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1992
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1993
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\\\x07\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1994
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\\\x07\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1995
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00N\\x00O\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 1996
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1997
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 1998
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 1999
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe2\\x07\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2000
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\x07\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2001
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00 \\x00=\\x00 \\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 2002
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2003
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2004
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2005
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa4\\x08\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2006
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4\\x08\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2007
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2008
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2009
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2010
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2011
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x16\t\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2012
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16\t\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2013
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00R\\x00O\\x00D\\x00C\\x00O\\x00D\\x00E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2014
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2015
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2016
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2017
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\t\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2018
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\t\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2019
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2020
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2021
          },
          {
            "timestamp": "2026-02-10 09:22:06,156",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2022
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2023
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x06\n\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2024
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x06\n\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2025
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 2026
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2027
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2028
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2029
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8a\n\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2030
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a\n\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2031
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 2032
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2033
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2034
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2035
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x006\\x0b\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2036
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\x0b\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2037
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 2038
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2039
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2040
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2041
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb2\\x0b\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2042
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2\\x0b\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2043
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2044
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2045
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2046
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2047
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00,\\x0c\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2048
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ",\\x0c\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2049
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00O\\x00N\\x00F\\x00I\\x00G\\x00F\\x00I\\x00L\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2050
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2051
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2052
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2053
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\x0c\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2054
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\x0c\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2055
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2056
          },
          {
            "timestamp": "2026-02-10 09:22:06,172",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2057
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2058
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2059
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x14\r\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2060
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\r\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2061
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00G\\x00I\\x00S\\x00T\\x00R\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 2062
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2063
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2064
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2065
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x8c\r\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2066
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8c\r\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2067
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00Z\\x00L\\x00P\\x00R\\x00O\\x00P\\x00E\\x00R\\x00T\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 2068
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2069
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2070
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2071
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x08\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2072
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08\\x0e\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2073
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00E\\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2074
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2075
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2076
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2077
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x82\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2078
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82\\x0e\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2079
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 2080
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2081
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2082
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2083
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xee\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2084
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\x0e\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2085
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00I\\x00N\\x00G\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 2086
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2087
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2088
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2089
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00v\\x0f\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2090
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\x0f\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2091
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 2092
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2093
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2094
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2095
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xee\\x0f\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2096
          },
          {
            "timestamp": "2026-02-10 09:22:06,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\x0f\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2097
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00S\\x00C\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2098
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2099
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2100
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2101
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00b\\x10\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2102
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "b\\x10\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2103
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00S\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2104
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2105
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2106
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2107
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd6\\x10\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2108
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6\\x10\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2109
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00A\\x00V\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2110
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2111
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2112
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2113
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00L\\x11\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2114
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\x11\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2115
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00D\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2116
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2117
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2118
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2119
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc2\\x11\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2120
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc2\\x11\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2121
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00N\\x00E\\x00W\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "148"
              }
            ],
            "repeated": 0,
            "id": 2122
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2123
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2124
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2125
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00V\\x12\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2126
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "V\\x12\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2127
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00N\\x00E\\x00W\\x00U\\x00S\\x00E\\x00R\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 2128
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2129
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2130
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2131
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe4\\x12\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2132
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\x12\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2133
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00N\\x00E\\x00W\\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00E\\x00K\\x00E\\x00Y\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 2134
          },
          {
            "timestamp": "2026-02-10 09:22:06,203",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2135
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2136
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2137
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00n\\x13\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2138
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "n\\x13\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2139
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 2140
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2141
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2142
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2143
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xfc\\x13\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2144
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\x13\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2145
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00S\\x00E\\x00R\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 2146
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2147
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2148
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2149
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x84\\x14\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2150
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\x14\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2151
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00E\\x00K\\x00E\\x00Y\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 2152
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2153
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2154
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2155
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x08\\x15\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2156
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08\\x15\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2157
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00N\\x00A\\x00B\\x00L\\x00E\\x00P\\x00R\\x00O\\x00T\\x00E\\x00C\\x00T\\x00O\\x00R\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 2158
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2159
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2160
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2161
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x86\\x15\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2162
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86\\x15\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2163
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00S\\x00A\\x00V\\x00E\\x00D\\x00V\\x00S\\x00D\\x00A\\x00T\\x00A\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2164
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2165
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2166
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2167
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xfc\\x15\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2168
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\x15\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2169
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00L\\x00D\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2170
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2171
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2172
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2173
          },
          {
            "timestamp": "2026-02-10 09:22:06,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\x16\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2174
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "p\\x16\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2175
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00O\\x00L\\x00D\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2176
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2177
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2178
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2179
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xea\\x16\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2180
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xea\\x16\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2181
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00M\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2182
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2183
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2184
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2185
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00^\\x17\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2186
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\x17\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2187
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 2188
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2189
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2190
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2191
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xcc\\x17\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2192
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcc\\x17\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2193
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00_\\x00T\\x00A\\x00S\\x00K\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2194
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2195
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2196
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2197
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00>\\x18\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2198
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">\\x18\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2199
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00T\\x00R\\x00A\\x00C\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2200
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2201
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2202
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2203
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb2\\x18\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2204
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2\\x18\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2205
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00R\\x00E\\x00G\\x00K\\x00E\\x00Y\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 2206
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2207
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2208
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2209
          },
          {
            "timestamp": "2026-02-10 09:22:06,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xbc!\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2210
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbc!\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2211
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00S\\x00T\\x00O\\x00R\\x00E\\x00D\\x00P\\x00R\\x00O\\x00P\\x00E\\x00R\\x00T\\x00I\\x00E\\x00S\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 2212
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2213
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2214
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2215
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x1c+\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2216
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1c+\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2217
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00F\\x00r\\x00e\\x00s\\x00h\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 2218
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2219
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2220
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2221
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00v4\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2222
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v4\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2223
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00F\\x00r\\x00e\\x00s\\x00h\\x00A\\x00f\\x00t\\x00e\\x00r\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 2224
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2225
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2226
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2227
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xce=\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2228
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xce=\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2229
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 2230
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2231
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2232
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2233
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00*G\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2234
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*G\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2235
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00A\\x00f\\x00t\\x00e\\x00r\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 2236
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2237
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2238
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2239
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x84P\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2240
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84P\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2241
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 2242
          },
          {
            "timestamp": "2026-02-10 09:22:06,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2243
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2244
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2245
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe2Y\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2246
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2Y\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2247
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00A\\x00f\\x00t\\x00e\\x00r\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 2248
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2249
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2250
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2251
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00>c\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2252
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">c\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2253
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 2254
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2255
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2256
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2257
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x9cl\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2258
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9cl\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2259
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x001\\x00F\\x003\\x005\\x007\\x009\\x002\\x003\\x00_\\x00E\\x005\\x00E\\x00D\\x00_\\x004\\x00F\\x004\\x00F\\x00_\\x009\\x00B\\x002\\x008\\x00_\\x00B\\x001\\x004\\x006\\x001\\x005\\x003\\x00C\\x007\\x004\\x004\\x006\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00"
              },
              {
                "name": "Length",
                "value": "270"
              }
            ],
            "repeated": 0,
            "id": 2260
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2261
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2262
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2263
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00Dv\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2264
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Dv\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2265
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "206"
              }
            ],
            "repeated": 0,
            "id": 2266
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2267
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2268
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2269
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xac\\x7f\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2270
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\x7f\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2271
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00"
              },
              {
                "name": "Length",
                "value": "280"
              }
            ],
            "repeated": 0,
            "id": 2272
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2273
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2274
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2275
          },
          {
            "timestamp": "2026-02-10 09:22:06,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00^\\x89\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2276
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\x89\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2277
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "208"
              }
            ],
            "repeated": 0,
            "id": 2278
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2279
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2280
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2281
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x212\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2282
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x212\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2283
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00=\\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00 \\x00(\\x00o\\x00l\\x00d\\x00 \\x00v\\x00a\\x00l\\x00u\\x00"
              },
              {
                "name": "Length",
                "value": "282"
              }
            ],
            "repeated": 0,
            "id": 2284
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2285
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2286
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2287
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe2\\x93\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2288
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\x93\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2289
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00:\\x00 \\x00 \\x00S\\x00t\\x00o\\x00r\\x00e\\x00P\\x00r\\x00o\\x00p\\x00F\\x00o\\x00r\\x00D\\x00e\\x00f\\x00e\\x00r\\x00r\\x00e\\x00d\\x00C\\x00A\\x00 \\x00c\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00a\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 2290
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2291
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2292
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2293
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa4\\x95\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2294
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4\\x95\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2295
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00P\\x00r\\x00e\\x00p\\x00a\\x00r\\x00e\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "202"
              }
            ],
            "repeated": 0,
            "id": 2296
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2297
          },
          {
            "timestamp": "2026-02-10 09:22:06,281",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2298
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2299
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xaa\\x9d\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2300
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaa\\x9d\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2301
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 2302
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2303
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2304
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2305
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x82\\x9e\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2306
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82\\x9e\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2307
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00I\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2308
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2309
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2310
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2311
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00H\\xa0\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2312
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "H\\xa0\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2313
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 2314
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2315
          },
          {
            "timestamp": "2026-02-10 09:22:06,297",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2316
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2317
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x04\\xec\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2318
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04\\xec\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2319
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2320
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2321
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2322
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2323
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00z\\xec\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2324
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\xec\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2325
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00U\\x00n\\x00p\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 2326
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2327
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2328
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2329
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x96\\xed\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2330
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96\\xed\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2331
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00U\\x00n\\x00p\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2332
          },
          {
            "timestamp": "2026-02-10 09:22:06,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2333
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2334
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2335
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x0c\\xee\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2336
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xee\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2337
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 2338
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2339
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2340
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2341
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\xef\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2342
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xef\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2343
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "186"
              }
            ],
            "repeated": 0,
            "id": 2344
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2345
          },
          {
            "timestamp": "2026-02-10 09:22:06,328",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2346
          },
          {
            "timestamp": "2026-02-10 09:22:06,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2347
          },
          {
            "timestamp": "2026-02-10 09:22:06,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xd2\\xef\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2348
          },
          {
            "timestamp": "2026-02-10 09:22:06,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xef\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2349
          },
          {
            "timestamp": "2026-02-10 09:22:06,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 2350
          },
          {
            "timestamp": "2026-02-10 09:22:06,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2351
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2352
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2353
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2354
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe0\\xf0\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2355
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 2356
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2357
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2358
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2359
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00F\\xf1\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2360
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "F\\xf1\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2361
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00o\\x00p\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "156"
              }
            ],
            "repeated": 0,
            "id": 2362
          },
          {
            "timestamp": "2026-02-10 09:22:06,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2363
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2364
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2365
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00Z\\xf2\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2366
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\xf2\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2367
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00o\\x00p\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 2368
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2369
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2370
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2371
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x16\\xf3\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2372
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16\\xf3\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2373
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 2374
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2375
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2376
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2377
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x004\\xf4\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2378
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4\\xf4\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2379
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 2380
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2381
          },
          {
            "timestamp": "2026-02-10 09:22:06,375",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2382
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2383
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xf4\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2384
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xf4\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2385
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "166"
              }
            ],
            "repeated": 0,
            "id": 2386
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2387
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2388
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2389
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa2\\xf7\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2390
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xf7\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2391
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 2392
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2393
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2394
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2395
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00h\\xf8\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2396
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xf8\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2397
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00D\\x00e\\x00l\\x00e\\x00t\\x00e\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 2398
          },
          {
            "timestamp": "2026-02-10 09:22:06,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2399
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2400
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2401
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xee\\xfd\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2402
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\xfd\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2403
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00D\\x00e\\x00l\\x00e\\x00t\\x00e\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 2404
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2405
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2406
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2407
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00^\\xfe\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2408
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\xfe\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2409
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 2410
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2411
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2412
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2413
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x008\\xff\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2414
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8\\xff\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2415
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 2416
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2417
          },
          {
            "timestamp": "2026-02-10 09:22:06,406",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2418
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2419
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb4\\xff\\x02\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2420
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\xff\\x02\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2421
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2422
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2423
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2424
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2425
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xac\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2426
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\x00\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2427
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2428
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2429
          },
          {
            "timestamp": "2026-02-10 09:22:06,422",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2430
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2431
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00F\\x02\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2432
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "F\\x02\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2433
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00U\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2434
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2435
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2436
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2437
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc0\\x02\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2438
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\x02\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2439
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00E\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00 \\x00i\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x00M\\x00S\\x00I\\x00B\\x001\\x003\\x004\\x00.\\x00t\\x00m\\x00p\\x00,\\x00 \\x00v\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x003\\x00.\\x008\\x00.\\x009\\x000\\x000\\x002\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 2440
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2441
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2442
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2443
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xa8\\x03\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2444
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\x03\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2445
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00 \\x00'\\x00T\\x00r\\x00G\\x00U\\x00I\\x00.\\x00e\\x00x\\x00e\\x00'\\x00 \\x00a\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00t\\x00e\\x00 \\x00(\\x001\\x00)\\x00 \\x00d\\x00o\\x00e\\x00s\\x00n\\x00'\\x00t\\x00 \\x00m\\x00a\\x00t\\x00c\\x00h\\x00 \\x00r\\x00e\\x00q\\x00u\\x00e\\x00s\\x00t\\x00 \\x00(\\x002\\x00)\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "184"
              }
            ],
            "repeated": 0,
            "id": 2446
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2447
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2448
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2449
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00`\\x04\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2450
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x04\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2451
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00 \\x00'\\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00.\\x00e\\x00x\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00'\\x00 \\x00a\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00t\\x00e\\x00 \\x00(\\x001\\x00)\\x00 \\x00d\\x00o\\x00e\\x00s\\x00n\\x00'\\x00t\\x00 \\x00m\\x00a\\x00t\\x00c\\x00h\\x00 \\x00r\\x00e\\x00q\\x00"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 2452
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2453
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2454
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2455
          },
          {
            "timestamp": "2026-02-10 09:22:06,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00t\\x05\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2456
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t\\x05\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2457
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00N\\x00o\\x00 \\x00f\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00 \\x00e\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00 \\x00s\\x00c\\x00h\\x00e\\x00d\\x00u\\x00l\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 2458
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2459
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2460
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2461
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00b\\x06\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2462
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "b\\x06\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2463
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00U\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 2464
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2465
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2466
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2467
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xfc\\x06\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2468
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\x06\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2469
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00F\\x00i\\x00l\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 2470
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2471
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2472
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2473
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc0\\x07\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2474
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\x07\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2475
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00F\\x00i\\x00l\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "106"
              }
            ],
            "repeated": 0,
            "id": 2476
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2477
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2478
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2479
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00*\\x08\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2480
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*\\x08\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2481
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 2482
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2483
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2484
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2485
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00B\t\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2486
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "B\t\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2487
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 2488
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2489
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2490
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2491
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\t\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2492
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb0\t\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2493
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00k\\x00F\\x00l\\x00d\\x00r\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 2494
          },
          {
            "timestamp": "2026-02-10 09:22:06,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2495
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2496
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2497
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc8\n\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2498
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8\n\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2499
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00k\\x00F\\x00l\\x00d\\x00r\\x00B\\x00e\\x00f\\x00o\\x00r\\x00e\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 2500
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2501
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2502
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2503
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x86\\x0b\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2504
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86\\x0b\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2505
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00r\\x00e\\x00a\\x00t\\x00e\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 2506
          },
          {
            "timestamp": "2026-02-10 09:22:06,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2507
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2508
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2509
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc2\\x0f\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2510
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc2\\x0f\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2511
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00r\\x00e\\x00a\\x00t\\x00e\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 2512
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2513
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2514
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2515
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x000\\x10\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2516
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\x10\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2517
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00k\\x00F\\x00l\\x00d\\x00r\\x00A\\x00f\\x00t\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "156"
              }
            ],
            "repeated": 0,
            "id": 2518
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2519
          },
          {
            "timestamp": "2026-02-10 09:22:06,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2520
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2521
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00D\\x11\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2522
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D\\x11\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2523
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00k\\x00F\\x00l\\x00d\\x00r\\x00A\\x00f\\x00t\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 2524
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2525
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2526
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2527
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2528
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x12\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2529
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 2530
          },
          {
            "timestamp": "2026-02-10 09:22:06,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2531
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2532
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2533
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x002\\x1a\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2534
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2\\x1a\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2535
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00l\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 2536
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2537
          },
          {
            "timestamp": "2026-02-10 09:22:06,515",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2538
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2539
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc2\\x1b\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2540
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc2\\x1b\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2541
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2542
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2543
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2544
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2545
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x008\\x1c\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2546
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8\\x1c\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2547
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00E\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00 \\x00i\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x00M\\x00S\\x00I\\x00B\\x001\\x009\\x002\\x00.\\x00t\\x00m\\x00p\\x00,\\x00 \\x00v\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x003\\x00.\\x008\\x00.\\x009\\x000\\x000\\x002\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 2548
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2549
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2550
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2551
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00: \\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2552
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ": \\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2553
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00u\\x00l\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00 \\x00e\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00 \\x00(\\x001\\x00\\x02\\x04C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00G\\x00U\\x00I\\x00\\x02\\x042\\x001\\x004\\x007\\x004\\x008\\x003\\x006\\x004\\x007\\x00\\x02\\x04*\\x00\\x02\\x041\\x00\\x02\\x042\\x00\\x02\\x04C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00"
              },
              {
                "name": "Length",
                "value": "672"
              }
            ],
            "repeated": 0,
            "id": 2554
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2555
          },
          {
            "timestamp": "2026-02-10 09:22:06,531",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2556
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2557
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x82#\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2558
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82#\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2559
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 2560
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2561
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2562
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2563
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x10'\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2564
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10'\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2565
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "156"
              }
            ],
            "repeated": 0,
            "id": 2566
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2567
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2568
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2569
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00L(\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2570
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L(\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2571
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 2572
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2573
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2574
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2575
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc0(\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2576
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0(\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2577
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "148"
              }
            ],
            "repeated": 0,
            "id": 2578
          },
          {
            "timestamp": "2026-02-10 09:22:06,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2579
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2580
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2581
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xd2)\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2582
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2)\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2583
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00i\\x00x\\x00S\\x00c\\x00h\\x00e\\x00d\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 2584
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2585
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2586
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2587
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00h*\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2588
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h*\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2589
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00r\\x00e\\x00a\\x00t\\x00e\\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2590
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2591
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2592
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2593
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00l,\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2594
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "l,\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2595
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00r\\x00e\\x00a\\x00t\\x00e\\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2596
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2597
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2598
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2599
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xde,\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2600
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde,\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2601
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00r\\x00i\\x00t\\x00e\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "90"
              }
            ],
            "repeated": 0,
            "id": 2602
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2603
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2604
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2605
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x0c.\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2606
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c.\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2607
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00W\\x00r\\x00i\\x00t\\x00e\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 2608
          },
          {
            "timestamp": "2026-02-10 09:22:06,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2609
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2610
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2611
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x86.\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2612
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86.\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2613
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 2614
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2615
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2616
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2617
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xec/\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2618
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec/\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2619
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 2620
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2621
          },
          {
            "timestamp": "2026-02-10 09:22:06,578",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2622
          },
          {
            "timestamp": "2026-02-10 09:22:06,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2623
          },
          {
            "timestamp": "2026-02-10 09:22:06,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xb40\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2624
          },
          {
            "timestamp": "2026-02-10 09:22:06,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb40\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2625
          },
          {
            "timestamp": "2026-02-10 09:22:06,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 2626
          },
          {
            "timestamp": "2026-02-10 09:22:06,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2627
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2628
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2629
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x122\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2630
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x122\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2631
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 2632
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2633
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2634
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2635
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc42\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2636
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc42\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2637
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "160"
              }
            ],
            "repeated": 0,
            "id": 2638
          },
          {
            "timestamp": "2026-02-10 09:22:06,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2639
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2640
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2641
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xe23\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2642
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe23\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2643
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 2644
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2645
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2646
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2647
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xa24\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2648
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa24\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2649
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2650
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2651
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2652
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2653
          },
          {
            "timestamp": "2026-02-10 09:22:06,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc85\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2654
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc85\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2655
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2656
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2657
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2658
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2659
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00:6\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2660
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ":6\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2661
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 2662
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2663
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2664
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2665
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00f7\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2666
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f7\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2667
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 2668
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2669
          },
          {
            "timestamp": "2026-02-10 09:22:06,640",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2670
          },
          {
            "timestamp": "2026-02-10 09:22:06,656",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2671
          },
          {
            "timestamp": "2026-02-10 09:22:06,656",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00:9\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2672
          },
          {
            "timestamp": "2026-02-10 09:22:06,656",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ":9\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2673
          },
          {
            "timestamp": "2026-02-10 09:22:06,656",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "88"
              }
            ],
            "repeated": 0,
            "id": 2674
          },
          {
            "timestamp": "2026-02-10 09:22:06,656",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2675
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2676
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2677
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x8a:\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2678
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a:\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2679
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00:\\x00 \\x00 \\x00E\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00i\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x00M\\x00S\\x00I\\x00B\\x002\\x001\\x000\\x00.\\x00t\\x00m\\x00p\\x00,\\x00 \\x00v\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x003\\x00.\\x008\\x00.\\x001\\x001\\x002\\x008\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "212"
              }
            ],
            "repeated": 0,
            "id": 2680
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2681
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2682
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2683
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xe8;\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2684
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8;\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2685
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 2686
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2687
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2688
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2689
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xd2=\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2690
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2=\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2691
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 2692
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2693
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2694
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2695
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xd2>\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2696
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2>\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2697
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 2698
          },
          {
            "timestamp": "2026-02-10 09:22:06,672",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2699
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2700
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2701
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00(?\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2702
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(?\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2703
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2704
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2705
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2706
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2707
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x18@\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2708
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18@\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2709
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 2710
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2711
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2712
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2713
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x90@\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2714
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90@\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2715
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 2716
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2717
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2718
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2719
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00VA\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2720
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "VA\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2721
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 2722
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2723
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2724
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2725
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xc4A\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2726
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4A\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2727
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00U\\x00s\\x00e\\x00r\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 2728
          },
          {
            "timestamp": "2026-02-10 09:22:06,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2729
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2730
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2731
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x8eB\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2732
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8eB\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2733
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00U\\x00s\\x00e\\x00r\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 2734
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2735
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2736
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2737
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xfaB\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2738
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfaB\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2739
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2740
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2741
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2742
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2743
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x9eH\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2744
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9eH\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2745
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2746
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2747
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2748
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2749
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x10I\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2750
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10I\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2751
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2752
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2753
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2754
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2755
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xdeI\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2756
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeI\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2757
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 2758
          },
          {
            "timestamp": "2026-02-10 09:22:06,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2759
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2760
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2761
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00PJ\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2762
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "PJ\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2763
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 2764
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2765
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2766
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2767
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00jK\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2768
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "jK\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2769
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00s\\x00h\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 2770
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2771
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2772
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2773
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xdaK\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2774
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdaK\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2775
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 2776
          },
          {
            "timestamp": "2026-02-10 09:22:06,718",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2777
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2778
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2779
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00FM\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2780
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "FM\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2781
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 2782
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2783
          },
          {
            "timestamp": "2026-02-10 09:22:06,734",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2784
          },
          {
            "timestamp": "2026-02-10 09:22:06,750",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2785
          },
          {
            "timestamp": "2026-02-10 09:22:06,750",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\x04N\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2786
          },
          {
            "timestamp": "2026-02-10 09:22:06,750",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04N\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2787
          },
          {
            "timestamp": "2026-02-10 09:22:06,750",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00o\\x00p\\x00y\\x00L\\x00a\\x00s\\x00t\\x00M\\x00S\\x00I\\x00L\\x00o\\x00g\\x00F\\x00i\\x00l\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 2788
          },
          {
            "timestamp": "2026-02-10 09:22:06,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2789
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2790
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2791
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00$O\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2792
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "$O\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2793
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00C\\x00o\\x00p\\x00y\\x00L\\x00a\\x00s\\x00t\\x00M\\x00S\\x00I\\x00L\\x00o\\x00g\\x00F\\x00i\\x00l\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 2794
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2795
          },
          {
            "timestamp": "2026-02-10 09:22:06,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2796
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2797
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x80\\x03\\x00\\x00\\x00\\x00\\x00\\xfeU\\x03\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2798
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfeU\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2799
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x006\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 2800
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2801
          },
          {
            "timestamp": "2026-02-10 09:22:06,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 563,
            "id": 2802
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2803
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x02\\xa3\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2804
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\xa3\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2805
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x004\\x004\\x007\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00F\\x00r\\x00o\\x00m\\x00S\\x00C\\x00M\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00F\\x00r\\x00o\\x00m\\x00S\\x00C\\x00M\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 2806
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2807
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2808
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2809
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x90\\xa3\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2810
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xa3\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2811
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x004\\x006\\x003\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00F\\x00r\\x00o\\x00m\\x00S\\x00C\\x00M\\x00 \\x00F\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00 \\x00E\\x00P\\x00W\\x00D\\x00.\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x001\\x000\\x006\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "160"
              }
            ],
            "repeated": 0,
            "id": 2812
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2813
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2814
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2815
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x2a4\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2816
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x2a4\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2817
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x004\\x006\\x003\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00F\\x00r\\x00o\\x00m\\x00S\\x00C\\x00M\\x00 \\x00W\\x00D\\x00_\\x00S\\x00t\\x00o\\x00p\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00F\\x00r\\x00o\\x00m\\x00S\\x00C\\x00M\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 2818
          },
          {
            "timestamp": "2026-02-10 09:22:07,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2819
          },
          {
            "timestamp": "2026-02-10 09:22:07,484",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2820
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2821
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00b\\xa7\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2822
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "b\\xa7\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2823
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00.\\x005\\x007\\x005\\x00>\\x00 \\x00<\\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "240"
              }
            ],
            "repeated": 0,
            "id": 2824
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2825
          },
          {
            "timestamp": "2026-02-10 09:22:07,578",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 2826
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2827
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00R\\xa8\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2828
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "R\\xa8\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2829
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00.\\x005\\x008\\x006\\x00>\\x00 \\x00<\\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00>\\x00 \\x00t\\x00h\\x00e\\x00 \\x00p\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00 \\x00i\\x00d\\x00 \\x00o\\x00f\\x00 \\x00T\\x00r\\x00G\\x00u\\x00i\\x00.\\x00e\\x00x\\x00e\\x00 \\x00i\\x00s\\x00 \\x00-\\x001\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2830
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2831
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 2832
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2833
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00v\\xad\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2834
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\xad\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2835
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00.\\x005\\x009\\x001\\x00>\\x00 \\x00<\\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "236"
              }
            ],
            "repeated": 0,
            "id": 2836
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2837
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2838
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2839
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00b\\xae\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2840
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "b\\xae\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2841
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x006\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 2842
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2843
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2844
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2845
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xf4\\xae\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2846
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4\\xae\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2847
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "362"
              }
            ],
            "repeated": 0,
            "id": 2848
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2849
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2850
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2851
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00N\\xb1\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2852
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "N\\xb1\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2853
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00U\\x00n\\x00l\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00a\\x00c\\x00t\\x00u\\x00a\\x00l\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00c\\x00o\\x00d\\x00e\\x00 \\x001\\x006\\x000\\x003\\x00 \\x00b\\x00u\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00t\\x00r\\x00a\\x00n\\x00s\\x00l\\x00a\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00d\\x00u\\x00e\\x00 \\x00t\\x00o\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00 \\x00m\\x00a\\x00r\\x00k\\x00i\\x00n\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 2854
          },
          {
            "timestamp": "2026-02-10 09:22:07,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2855
          },
          {
            "timestamp": "2026-02-10 09:22:07,609",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 2856
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2857
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xae\\xb4\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2858
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xae\\xb4\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2859
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00.\\x006\\x009\\x005\\x00>\\x00 \\x00<\\x00S\\x00t\\x00o\\x00p\\x00T\\x00R\\x00A\\x00C\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00T\\x00r\\x00y\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00s\\x00t\\x00o\\x00p\\x00 \\x00T\\x00R\\x00A\\x00C\\x00 \\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2860
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2861
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2862
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2863
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00p\\xb7\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2864
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "p\\xb7\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2865
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00.\\x006\\x009\\x008\\x00>\\x00 \\x00<\\x00S\\x00t\\x00o\\x00p\\x00T\\x00R\\x00A\\x00C\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00F\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00t\\x00o\\x00p\\x00 \\x00T\\x00R\\x00A\\x00C\\x00 \\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2866
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2867
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2868
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2869
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xfc\\xb7\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2870
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\xb7\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2871
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00S\\x00t\\x00o\\x00p\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x002\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 2872
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2873
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2874
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2875
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xe8\\xb9\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2876
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\\xb9\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2877
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "448"
              }
            ],
            "repeated": 0,
            "id": 2878
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2879
          },
          {
            "timestamp": "2026-02-10 09:22:07,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 2880
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2881
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xd2\\xc7\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2882
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xc7\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2883
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "190"
              }
            ],
            "repeated": 0,
            "id": 2884
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2885
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2886
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2887
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x90\\xc8\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2888
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xc8\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2889
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00 \\x00c\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00i\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00a\\x00i\\x00n\\x00g\\x00 \\x00s\\x00h\\x00a\\x00r\\x00e\\x00d\\x00 \\x00m\\x00e\\x00m\\x00o\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 2890
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2891
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2892
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2893
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00(\\xc9\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2894
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xc9\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2895
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00i\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00 \\x00=\\x00 \\x000\\x00,\\x00P\\x00I\\x00D\\x00=\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 2896
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2897
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2898
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2899
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xa0\\xc9\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2900
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xc9\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2901
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00T\\x00r\\x00y\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00p\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00 \\x00w\\x00/\\x00 \\x00P\\x00I\\x00D\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "126"
              }
            ],
            "repeated": 0,
            "id": 2902
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2903
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2904
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2905
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x1e\\xca\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2906
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xca\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2907
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00G\\x00o\\x00t\\x00:\\x00 \\x00 \\x000\\x00,\\x00 \\x00G\\x00e\\x00t\\x00L\\x00a\\x00s\\x00t\\x00E\\x00r\\x00r\\x00o\\x00r\\x00(\\x00)\\x00=\\x008\\x007\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 2908
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2909
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2910
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2911
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x8e\\xca\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2912
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\xca\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2913
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00(\\x00)\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00s\\x00:\\x00 \\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 2914
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2915
          },
          {
            "timestamp": "2026-02-10 09:22:07,765",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2916
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2917
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x12\\xcb\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2918
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\xcb\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2919
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 2920
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2921
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2922
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2923
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00z\\xcb\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2924
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\xcb\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2925
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00C\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00d\\x00o\\x00n\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 2926
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2927
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2928
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2929
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xd8\\xcb\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2930
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd8\\xcb\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2931
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00I\\x00N\\x00G\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 2932
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2933
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2934
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2935
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\\\xcc\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2936
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\\\xcc\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2937
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2938
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2939
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2940
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2941
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xe8\\xcc\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2942
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\\xcc\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2943
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00I\\x00N\\x00G\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 2944
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2945
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2946
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2947
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00j\\xcd\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2948
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xcd\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2949
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 2950
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2951
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2952
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2953
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xd2\\xcd\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2954
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xcd\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2955
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2956
          },
          {
            "timestamp": "2026-02-10 09:22:07,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2957
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2958
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2959
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00^\\xce\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2960
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\xce\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2961
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 2962
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2963
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2964
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2965
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xc4\\xce\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2966
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4\\xce\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2967
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 2968
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2969
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2970
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2971
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00:\\xcf\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2972
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ":\\xcf\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2973
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2974
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2975
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2976
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2977
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xc6\\xcf\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2978
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6\\xcf\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2979
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00=\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 2980
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2981
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2982
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2983
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x82\\xd0\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2984
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82\\xd0\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2985
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 2986
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2987
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2988
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2989
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xf0\\xd0\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2990
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0\\xd0\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2991
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 2992
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2993
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 2994
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 2995
          },
          {
            "timestamp": "2026-02-10 09:22:07,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xba\\xd2\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2996
          },
          {
            "timestamp": "2026-02-10 09:22:07,812",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xd2\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2997
          },
          {
            "timestamp": "2026-02-10 09:22:07,812",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00B\\x00e\\x00g\\x00i\\x00n\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 2998
          },
          {
            "timestamp": "2026-02-10 09:22:07,812",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2999
          },
          {
            "timestamp": "2026-02-10 09:22:07,812",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 8,
            "id": 3000
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3001
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00X\\xdc\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3002
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "X\\xdc\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3003
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x008\\x007\\x005\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 3004
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3005
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3006
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3007
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xcc\\xdd\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3008
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcc\\xdd\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3009
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x008\\x007\\x005\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00C\\x00P\\x00 \\x00f\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00p\\x00r\\x00o\\x00t\\x00e\\x00c\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 3010
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3011
          },
          {
            "timestamp": "2026-02-10 09:22:07,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 8,
            "id": 3012
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3013
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\xe4\\xe6\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3014
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\xe6\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3015
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x009\\x005\\x003\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 3016
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3017
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3018
          },
          {
            "timestamp": "2026-02-10 09:22:07,953",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3019
          },
          {
            "timestamp": "2026-02-10 09:22:07,968",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x8e\\xe8\\x06\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3020
          },
          {
            "timestamp": "2026-02-10 09:22:07,968",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\xe8\\x06\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3021
          },
          {
            "timestamp": "2026-02-10 09:22:07,968",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x007\\x00:\\x009\\x005\\x003\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00W\\x00D\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00C\\x00P\\x00 \\x00f\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00p\\x00r\\x00o\\x00t\\x00e\\x00c\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 3022
          },
          {
            "timestamp": "2026-02-10 09:22:07,968",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3023
          },
          {
            "timestamp": "2026-02-10 09:22:07,968",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 449,
            "id": 3024
          },
          {
            "timestamp": "2026-02-10 09:22:09,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3025
          },
          {
            "timestamp": "2026-02-10 09:22:09,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xba\\xa7\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3026
          },
          {
            "timestamp": "2026-02-10 09:22:09,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xa7\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3027
          },
          {
            "timestamp": "2026-02-10 09:22:09,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00E\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00 \\x00i\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x00M\\x00S\\x00I\\x00B\\x00C\\x00B\\x006\\x00.\\x00t\\x00m\\x00p\\x00,\\x00 \\x00v\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x003\\x00.\\x008\\x00.\\x009\\x000\\x000\\x002\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 3028
          },
          {
            "timestamp": "2026-02-10 09:22:09,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3029
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3030
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3031
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x9e\\xa8\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3032
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9e\\xa8\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3033
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00C\\x00r\\x00e\\x00a\\x00t\\x00i\\x00n\\x00g\\x00 \\x00E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00T\\x00h\\x00r\\x00e\\x00a\\x00d\\x00 \\x00t\\x00h\\x00r\\x00e\\x00a\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3034
          },
          {
            "timestamp": "2026-02-10 09:22:09,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3035
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3036
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3037
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00,\\xa9\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3038
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ",\\xa9\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3039
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00 \\x00e\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x002\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00G\\x00U\\x00I\\x00 \\x00(\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00"
              },
              {
                "name": "Length",
                "value": "316"
              }
            ],
            "repeated": 0,
            "id": 3040
          },
          {
            "timestamp": "2026-02-10 09:22:09,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3041
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3042
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3043
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00h\\xaa\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3044
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xaa\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3045
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00f\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00 \\x00e\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x002\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00 \\x00(\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00"
              },
              {
                "name": "Length",
                "value": "342"
              }
            ],
            "repeated": 0,
            "id": 3046
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3047
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3048
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3049
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x32c\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3050
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x32c\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3051
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00:\\x00 \\x00 \\x00N\\x00o\\x00 \\x00t\\x00i\\x00m\\x00e\\x00o\\x00u\\x00t\\x00,\\x00 \\x00e\\x00x\\x00i\\x00t\\x00 \\x00c\\x00o\\x00d\\x00e\\x00:\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 3052
          },
          {
            "timestamp": "2026-02-10 09:22:09,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3053
          },
          {
            "timestamp": "2026-02-10 09:22:09,468",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 81,
            "id": 3054
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3055
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x9c\\xe7\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3056
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\xe7\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3057
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 3058
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3059
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3060
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3061
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x14\\xe8\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3062
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\xe8\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3063
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00:\\x00 \\x00 \\x00C\\x00o\\x00u\\x00l\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00e\\x00a\\x00d\\x00 \\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00,\\x00 \\x00i\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00m\\x00a\\x00n\\x00u\\x00a\\x00l\\x00l\\x00y\\x00 \\x00s\\x00e\\x00t\\x00 \\x00t\\x00o\\x00 \\x001\\x004\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "210"
              }
            ],
            "repeated": 0,
            "id": 3064
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3065
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3066
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3067
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xe6\\xe8\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3068
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\xe8\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3069
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00:\\x00 \\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00s\\x00e\\x00t\\x00 \\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 3070
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3071
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3072
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3073
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00F\\xea\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3074
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "F\\xea\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3075
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00:\\x00 \\x00 \\x00I\\x00n\\x00c\\x00r\\x00e\\x00a\\x00s\\x00e\\x00F\\x00i\\x00l\\x00t\\x00e\\x00r\\x00s\\x00M\\x00a\\x00x\\x00N\\x00u\\x00m\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 3076
          },
          {
            "timestamp": "2026-02-10 09:22:09,687",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3077
          },
          {
            "timestamp": "2026-02-10 09:22:09,703",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3078
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3079
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x18\\xed\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3080
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xed\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3081
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x007\\x002\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "244"
              }
            ],
            "repeated": 0,
            "id": 3082
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3083
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 3084
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3085
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x0c\\xee\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3086
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xee\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3087
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x008\\x003\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00n\\x00e\\x00w\\x00 \\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 3088
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3089
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3090
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3091
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x82\\xee\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3092
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82\\xee\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3093
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x008\\x004\\x00>\\x00 \\x00<\\x00S\\x00t\\x00o\\x00p\\x00T\\x00R\\x00A\\x00C\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00T\\x00r\\x00y\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00s\\x00t\\x00o\\x00p\\x00 \\x00T\\x00R\\x00A\\x00C\\x00 \\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 3094
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3095
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3096
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3097
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x0e\\xef\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3098
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\xef\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3099
          },
          {
            "timestamp": "2026-02-10 09:22:09,781",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x008\\x006\\x00>\\x00 \\x00<\\x00S\\x00t\\x00o\\x00p\\x00T\\x00R\\x00A\\x00C\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00F\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00t\\x00o\\x00p\\x00 \\x00T\\x00R\\x00A\\x00C\\x00 \\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 3100
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3101
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3102
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3103
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x9a\\xef\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3104
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\xef\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3105
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x008\\x008\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00i\\x00f\\x00 \\x00V\\x00N\\x00A\\x00 \\x00a\\x00l\\x00r\\x00e\\x00a\\x00d\\x00y\\x00 \\x00e\\x00x\\x00i\\x00s\\x00t\\x00s\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "140"
              }
            ],
            "repeated": 0,
            "id": 3106
          },
          {
            "timestamp": "2026-02-10 09:22:09,797",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3107
          },
          {
            "timestamp": "2026-02-10 09:22:09,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3108
          },
          {
            "timestamp": "2026-02-10 09:22:09,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3109
          },
          {
            "timestamp": "2026-02-10 09:22:09,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00&\\xf0\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3110
          },
          {
            "timestamp": "2026-02-10 09:22:09,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\xf0\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3111
          },
          {
            "timestamp": "2026-02-10 09:22:09,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x007\\x009\\x000\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00v\\x00n\\x00a\\x00_\\x00u\\x00t\\x00i\\x00l\\x00s\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00 \\x00-\\x00d\\x00 \\x00"
              },
              {
                "name": "Length",
                "value": "314"
              }
            ],
            "repeated": 0,
            "id": 3112
          },
          {
            "timestamp": "2026-02-10 09:22:09,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3113
          },
          {
            "timestamp": "2026-02-10 09:22:12,859",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3114
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3115
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00`\\xf1\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3116
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\xf1\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3117
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x000\\x009\\x00.\\x008\\x006\\x006\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00v\\x00n\\x00a\\x00_\\x00u\\x00t\\x00i\\x00l\\x00s\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00 \\x00-\\x00d\\x00 \\x00"
              },
              {
                "name": "Length",
                "value": "446"
              }
            ],
            "repeated": 0,
            "id": 3118
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3119
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3120
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3121
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x1e\\xf3\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3122
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xf3\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3123
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x008\\x007\\x000\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00I\\x00n\\x00f\\x00o\\x00r\\x00m\\x00a\\x00t\\x00i\\x00o\\x00n\\x00a\\x00l\\x00.\\x00 \\x00S\\x00t\\x00a\\x00t\\x00u\\x00s\\x00=\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 3124
          },
          {
            "timestamp": "2026-02-10 09:22:12,875",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3125
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3126
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3127
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x96\\xf3\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3128
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96\\xf3\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3129
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x008\\x007\\x004\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00v\\x00n\\x00a\\x00_\\x00u\\x00t\\x00i\\x00l\\x00s\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00 \\x00-\\x00d\\x00 \\x00"
              },
              {
                "name": "Length",
                "value": "298"
              }
            ],
            "repeated": 0,
            "id": 3130
          },
          {
            "timestamp": "2026-02-10 09:22:12,906",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3131
          },
          {
            "timestamp": "2026-02-10 09:22:12,922",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3132
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3133
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xc0\\xf4\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3134
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\xf4\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3135
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x002\\x002\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00v\\x00n\\x00a\\x00_\\x00u\\x00t\\x00i\\x00l\\x00s\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00 \\x00-\\x00d\\x00 \\x00"
              },
              {
                "name": "Length",
                "value": "294"
              }
            ],
            "repeated": 0,
            "id": 3136
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3137
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3138
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3139
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xe6\\xf5\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3140
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\xf5\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3141
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x009\\x000\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00g\\x00o\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00r\\x00u\\x00n\\x00 \\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x009\\x00t\\x00o\\x001\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 3142
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3143
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3144
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3145
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00~\\xf6\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3146
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\xf6\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3147
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x009\\x001\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x009\\x00t\\x00o\\x001\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3148
          },
          {
            "timestamp": "2026-02-10 09:22:12,984",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3149
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3150
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x0c\\xf7\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3151
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xf7\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3152
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x009\\x004\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00 \\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x00 \\x00K\\x00e\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00>\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00d\\x00 \\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00i\\x00s\\x00 \\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00 \\x00i\\x00n\\x00 \\x00S\\x00u\\x00b\\x00k\\x00e\\x00y\\x00 \\x000\\x000\\x000\\x002\\x00 \\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "210"
              }
            ],
            "repeated": 0,
            "id": 3153
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3154
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "4544",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3155
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3156
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xde\\xf7\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3157
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde\\xf7\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3158
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x009\\x005\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00 \\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x00 \\x00K\\x00e\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00>\\x00 \\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x00 \\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00w\\x00a\\x00s\\x00 \\x00c\\x00h\\x00a\\x00n\\x00g\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x001\\x00 \\x00a\\x00t\\x00 \\x00S\\x00u\\x00b\\x00k\\x00e\\x00y\\x00 \\x000\\x000\\x000\\x002\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "224"
              }
            ],
            "repeated": 0,
            "id": 3159
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3160
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3161
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x76fb65e6",
            "parentcaller": "0x76fb64f1",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3162
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xbe\\xf8\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3163
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xf8\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3164
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x002\\x00.\\x009\\x009\\x008\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00 \\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x00 \\x00K\\x00e\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00E\\x00R\\x00R\\x00O\\x00R\\x00>\\x00 \\x00C\\x00a\\x00n\\x00'\\x00t\\x00 \\x00Q\\x00u\\x00e\\x00r\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00d\\x00 \\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00a\\x00t\\x00 \\x00S\\x00u\\x00b\\x00k\\x00e\\x00y\\x00 \\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00u\\x00r\\x00a\\x00t\\x00i\\x00o\\x00n\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "236"
              }
            ],
            "repeated": 0,
            "id": 3165
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3166
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x759f9924",
            "parentcaller": "0x75bcc2f8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000490"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 3167
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3168
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3169
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\xaa\\xf9\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3170
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaa\\xf9\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3171
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x000\\x000\\x000\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00 \\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x00 \\x00K\\x00e\\x00y\\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00E\\x00R\\x00R\\x00O\\x00R\\x00>\\x00 \\x00C\\x00a\\x00n\\x00'\\x00t\\x00 \\x00Q\\x00u\\x00e\\x00r\\x00y\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00I\\x00d\\x00 \\x00V\\x00a\\x00l\\x00u\\x00e\\x00 \\x00a\\x00t\\x00 \\x00S\\x00u\\x00b\\x00k\\x00e\\x00y\\x00 \\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "230"
              }
            ],
            "repeated": 0,
            "id": 3172
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3173
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3174
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3175
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0c\\x00\\x00\\x00\\x00\\x00\\x90\\xfa\\x0b\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3176
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xfa\\x0b\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3177
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x000\\x000\\x002\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00C\\x00h\\x00a\\x00r\\x00a\\x00c\\x00t\\x00e\\x00r\\x00i\\x00s\\x00t\\x00i\\x00c\\x00s\\x009\\x00t\\x00o\\x001\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 3178
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3179
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3180
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3181
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x8e\\x0b\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3182
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\x0b\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3183
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x000\\x000\\x005\\x00>\\x00 \\x00<\\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "240"
              }
            ],
            "repeated": 0,
            "id": 3184
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3185
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3186
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3187
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00~\\x0c\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3188
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\x0c\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3189
          },
          {
            "timestamp": "2026-02-10 09:22:13,000",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x002\\x003\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "224"
              }
            ],
            "repeated": 0,
            "id": 3190
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3191
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3192
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00^\r\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3193
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\r\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3194
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "440"
              }
            ],
            "repeated": 0,
            "id": 3195
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3196
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3197
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3198
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\n\\x10\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3199
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\n\\x10\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3200
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00V\\x00n\\x00a\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00a\\x00c\\x00t\\x00u\\x00a\\x00l\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00c\\x00o\\x00d\\x00e\\x00 \\x001\\x006\\x000\\x003\\x00 \\x00b\\x00u\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00t\\x00r\\x00a\\x00n\\x00s\\x00l\\x00a\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00d\\x00"
              },
              {
                "name": "Length",
                "value": "304"
              }
            ],
            "repeated": 0,
            "id": 3201
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3202
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3203
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3204
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x1a\\x14\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3205
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\x14\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3206
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x001\\x000\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "272"
              }
            ],
            "repeated": 0,
            "id": 3207
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3208
          },
          {
            "timestamp": "2026-02-10 09:22:13,109",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 3209
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3210
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00*\\x15\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3211
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*\\x15\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3212
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x001\\x009\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00W\\x00O\\x00W\\x006\\x004\\x00 \\x00d\\x00e\\x00t\\x00e\\x00c\\x00t\\x00e\\x00d\\x00.\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "120"
              }
            ],
            "repeated": 0,
            "id": 3213
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3214
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3215
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3216
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa2\\x15\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3217
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\x15\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3218
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x002\\x004\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00t\\x00e\\x00m\\x00p\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00n\\x00a\\x00m\\x00e\\x00:\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00A\\x00C\\x006\\x009\\x00.\\x00t\\x00m\\x00p\\x00N\\x00N\\x00N\\x00Y\\x00N\\x00N\\x00E\\x00O\\x00N\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "194"
              }
            ],
            "repeated": 0,
            "id": 3219
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3220
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3221
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3222
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00d\\x16\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3223
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\x16\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3224
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x002\\x005\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00N\\x00o\\x00K\\x00e\\x00e\\x00p\\x00F\\x00l\\x00a\\x00g\\x00 \\x00=\\x00 \\x00N\\x00;\\x00 \\x00I\\x00n\\x00n\\x00e\\x00r\\x00M\\x00S\\x00I\\x00 \\x00=\\x00 \\x00N\\x00;\\x00 \\x00U\\x00I\\x00_\\x00F\\x00r\\x00a\\x00m\\x00e\\x00w\\x00o\\x00r\\x00k\\x00 \\x00=\\x00 \\x00N\\x00;\\x00 \\x00E\\x00P\\x00C\\x00_\\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00_\\x00V\\x00P\\x00N\\x00 \\x00=\\x00 \\x00Y\\x00;\\x00 \\x00S\\x00D\\x00L\\x00E\\x00n\\x00a\\x00b\\x00l\\x00e\\x00d\\x00 \\x00=\\x00 \\x00N\\x00;\\x00 \\x00F\\x00"
              },
              {
                "name": "Length",
                "value": "384"
              }
            ],
            "repeated": 0,
            "id": 3225
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3226
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3227
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3228
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xe4\\x17\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3229
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\x17\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3230
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x002\\x007\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00=\\x00 \\x00'\\x00E\\x00'\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3231
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3232
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3233
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3234
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00d\\x18\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3235
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\x18\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3236
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x002\\x008\\x00>\\x00 \\x00<\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00S\\x00c\\x00v\\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00>\\x00 \\x00W\\x00e\\x00 \\x00a\\x00r\\x00e\\x00 \\x00i\\x00n\\x00 \\x006\\x004\\x00 \\x00b\\x00i\\x00t\\x00 \\x00O\\x00S\\x00.\\x00 \\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00C\\x00V\\x00 \\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00 \\x00u\\x00n\\x00d\\x00e\\x00r\\x00 \\x00w\\x00o\\x00w\\x006\\x004\\x003\\x002\\x00n\\x00o\\x00d\\x00e\\x00 \\x00k\\x00e\\x00y\\x00 \\x00i\\x00n\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "246"
              }
            ],
            "repeated": 0,
            "id": 3237
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3238
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3239
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3240
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00Z\\x19\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3241
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\x19\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3242
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x003\\x001\\x00>\\x00 \\x00<\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00S\\x00c\\x00v\\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00>\\x00 \\x00(\\x00r\\x00e\\x00l\\x00e\\x00v\\x00e\\x00n\\x00t\\x00 \\x00f\\x00o\\x00r\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00 \\x00o\\x00n\\x00l\\x00y\\x00)\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x00 \\x00t\\x00o\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00 \\x00k\\x00e\\x00y\\x00 \\x00S\\x00O\\x00F\\x00T\\x00W\\x00A\\x00R\\x00E\\x00\\\\x00W\\x00o\\x00w\\x006\\x004\\x003\\x002\\x00N\\x00o\\x00d\\x00e\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00T\\x00R\\x00A\\x00"
              },
              {
                "name": "Length",
                "value": "322"
              }
            ],
            "repeated": 0,
            "id": 3243
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3244
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3245
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3246
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9c\\x1a\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3247
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\x1a\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3248
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x003\\x003\\x00>\\x00 \\x00<\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00S\\x00c\\x00v\\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00>\\x00 \\x00(\\x00r\\x00e\\x00l\\x00e\\x00v\\x00e\\x00n\\x00t\\x00 \\x00f\\x00o\\x00r\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00 \\x00o\\x00n\\x00l\\x00y\\x00)\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x00 \\x00t\\x00o\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00 \\x00k\\x00e\\x00y\\x00 \\x00S\\x00O\\x00F\\x00T\\x00W\\x00A\\x00R\\x00E\\x00\\\\x00W\\x00o\\x00w\\x006\\x004\\x003\\x002\\x00N\\x00o\\x00d\\x00e\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00T\\x00R\\x00A\\x00"
              },
              {
                "name": "Length",
                "value": "314"
              }
            ],
            "repeated": 0,
            "id": 3249
          },
          {
            "timestamp": "2026-02-10 09:22:13,125",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3250
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3251
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd6\\x1b\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3252
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6\\x1b\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3253
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x003\\x004\\x00>\\x00 \\x00<\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00S\\x00c\\x00v\\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00>\\x00 \\x00(\\x00r\\x00e\\x00l\\x00e\\x00v\\x00e\\x00n\\x00t\\x00 \\x00f\\x00o\\x00r\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00 \\x00o\\x00n\\x00l\\x00y\\x00)\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x00 \\x00t\\x00o\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00 \\x00k\\x00e\\x00y\\x00 \\x00S\\x00O\\x00F\\x00T\\x00W\\x00A\\x00R\\x00E\\x00\\\\x00W\\x00o\\x00w\\x006\\x004\\x003\\x002\\x00N\\x00o\\x00d\\x00e\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00T\\x00R\\x00A\\x00"
              },
              {
                "name": "Length",
                "value": "322"
              }
            ],
            "repeated": 0,
            "id": 3254
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3255
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3256
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3257
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x18\\x1d\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3258
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\x1d\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3259
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x003\\x006\\x00>\\x00 \\x00<\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00S\\x00c\\x00v\\x00P\\x00l\\x00u\\x00g\\x00i\\x00n\\x00s\\x00>\\x00 \\x00(\\x00r\\x00e\\x00l\\x00e\\x00v\\x00e\\x00n\\x00t\\x00 \\x00f\\x00o\\x00r\\x00 \\x00u\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00 \\x00o\\x00n\\x00l\\x00y\\x00)\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x00 \\x00t\\x00o\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00 \\x00k\\x00e\\x00y\\x00 \\x00S\\x00O\\x00F\\x00T\\x00W\\x00A\\x00R\\x00E\\x00\\\\x00W\\x00o\\x00w\\x006\\x004\\x003\\x002\\x00N\\x00o\\x00d\\x00e\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00T\\x00R\\x00A\\x00"
              },
              {
                "name": "Length",
                "value": "314"
              }
            ],
            "repeated": 0,
            "id": 3260
          },
          {
            "timestamp": "2026-02-10 09:22:13,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3261
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3262
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3263
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00R\\x1e\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3264
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "R\\x1e\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3265
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x001\\x003\\x009\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00r\\x00e\\x00g\\x00e\\x00d\\x00i\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00/\\x00s\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00S\\x00c\\x00v\\x00"
              },
              {
                "name": "Length",
                "value": "292"
              }
            ],
            "repeated": 0,
            "id": 3266
          },
          {
            "timestamp": "2026-02-10 09:22:13,218",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3267
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3268
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3269
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00v\\x1f\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3270
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\x1f\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3271
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x002\\x000\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00r\\x00e\\x00g\\x00e\\x00d\\x00i\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00/\\x00s\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00S\\x00c\\x00v\\x00"
              },
              {
                "name": "Length",
                "value": "288"
              }
            ],
            "repeated": 0,
            "id": 3272
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3273
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3274
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3275
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x96 \\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3276
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96 \\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3277
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x005\\x002\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00,\\x00 \\x00P\\x00r\\x00o\\x00d\\x00D\\x00i\\x00r\\x00=\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00"
              },
              {
                "name": "Length",
                "value": "278"
              }
            ],
            "repeated": 0,
            "id": 3278
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3279
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3280
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3281
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xac!\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3282
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac!\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3283
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x005\\x004\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00F\\x00i\\x00l\\x00e\\x00N\\x00a\\x00m\\x00e\\x00=\\x00L\\x00a\\x00n\\x00g\\x00P\\x00a\\x00c\\x00k\\x001\\x00.\\x00x\\x00m\\x00l\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 3284
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3285
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3286
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3287
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00^\"\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3288
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\"\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3289
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x005\\x006\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00L\\x00a\\x00n\\x00g\\x00P\\x00a\\x00c\\x00k\\x001\\x00.\\x00x\\x00m\\x00l\\x00 \\x00d\\x00o\\x00e\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00e\\x00x\\x00i\\x00s\\x00t\\x00 \\x00i\\x00n\\x00 \\x00t\\x00e\\x00m\\x00p\\x00 \\x00d\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00,\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 3290
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3291
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3292
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3293
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00B#\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3294
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "B#\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3295
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x005\\x008\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00F\\x00i\\x00l\\x00e\\x00N\\x00a\\x00m\\x00e\\x00=\\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 3296
          },
          {
            "timestamp": "2026-02-10 09:22:13,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3297
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3298
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3299
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xf0#\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3300
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0#\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3301
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x005\\x009\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00o\\x00p\\x00y\\x00 \\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00t\\x00o\\x00 \\x00t\\x00a\\x00r\\x00g\\x00e\\x00t\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 3302
          },
          {
            "timestamp": "2026-02-10 09:22:13,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3303
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3304
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3305
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x98$\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3306
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98$\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3307
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x002\\x006\\x003\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00c\\x00m\\x00d\\x00 \\x00/\\x00c\\x00 \\x00\"\\x00d\\x00e\\x00l\\x00 \\x00/\\x00F\\x00 \\x00/\\x00Q\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00T\\x00r\\x00a\\x00c\\x00.\\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00\"\\x00\"\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "206"
              }
            ],
            "repeated": 0,
            "id": 3308
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3309
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3310
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3311
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00f%\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3312
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f%\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3313
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x000\\x004\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00F\\x00i\\x00l\\x00e\\x00N\\x00a\\x00m\\x00e\\x00=\\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "170"
              }
            ],
            "repeated": 0,
            "id": 3314
          },
          {
            "timestamp": "2026-02-10 09:22:13,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3315
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3316
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3317
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x10&\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3318
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10&\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3319
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x000\\x007\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00o\\x00p\\x00y\\x00 \\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00 \\x00t\\x00o\\x00 \\x00t\\x00a\\x00r\\x00g\\x00e\\x00t\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 3320
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3321
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3322
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3323
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb4&\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3324
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4&\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3325
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x000\\x009\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00c\\x00m\\x00d\\x00 \\x00/\\x00c\\x00 \\x00\"\\x00d\\x00e\\x00l\\x00 \\x00/\\x00F\\x00 \\x00/\\x00Q\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00P\\x00i\\x00r\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00\"\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "202"
              }
            ],
            "repeated": 0,
            "id": 3326
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3327
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3328
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3329
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00~'\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3330
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~'\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3331
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x005\\x000\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00c\\x00h\\x00e\\x00c\\x00k\\x00i\\x00n\\x00g\\x00 \\x00u\\x00s\\x00e\\x00r\\x00 \\x00d\\x00e\\x00f\\x00i\\x00n\\x00e\\x00d\\x00 \\x00e\\x00x\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00 \\x00f\\x00i\\x00l\\x00e\\x00s\\x00 \\x00t\\x00o\\x00 \\x00c\\x00o\\x00p\\x00y\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "210"
              }
            ],
            "repeated": 0,
            "id": 3332
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3333
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3334
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3335
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00P(\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3336
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P(\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3337
          },
          {
            "timestamp": "2026-02-10 09:22:13,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x005\\x002\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00A\\x00n\\x00d\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00r\\x00o\\x00m\\x00T\\x00e\\x00m\\x00p\\x00D\\x00i\\x00r\\x00>\\x00 \\x00E\\x00x\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00E\\x00x\\x00t\\x00r\\x00a\\x00c\\x00t\\x00e\\x00d\\x00F\\x00i\\x00l\\x00e\\x00s\\x00.\\x00t\\x00x\\x00t\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00d\\x00o\\x00e\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00e\\x00x\\x00i\\x00s\\x00t\\x00,\\x00 \\x00d\\x00o\\x00 \\x00n\\x00o\\x00t\\x00h\\x00i\\x00n\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 3338
          },
          {
            "timestamp": "2026-02-10 09:22:13,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3339
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3340
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3341
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x008)\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3342
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8)\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3343
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x005\\x004\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00c\\x00m\\x00d\\x00 \\x00/\\x00c\\x00 \\x00\"\\x00d\\x00e\\x00l\\x00 \\x00/\\x00F\\x00 \\x00/\\x00Q\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00P\\x00i\\x00R\\x00e\\x00g\\x00.\\x00e\\x00x\\x00e\\x00\"\\x00\"\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "202"
              }
            ],
            "repeated": 0,
            "id": 3344
          },
          {
            "timestamp": "2026-02-10 09:22:13,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3345
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3346
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3347
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x02*\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3348
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02*\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3349
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x003\\x009\\x005\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00c\\x00m\\x00d\\x00 \\x00/\\x00c\\x00 \\x00\"\\x00d\\x00e\\x00l\\x00 \\x00/\\x00F\\x00 \\x00/\\x00Q\\x00 \\x00\"\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00"
              },
              {
                "name": "Length",
                "value": "284"
              }
            ],
            "repeated": 0,
            "id": 3350
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3351
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3352
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3353
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x1e+\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3354
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e+\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3355
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x004\\x003\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00r\\x00e\\x00t\\x00r\\x00i\\x00e\\x00v\\x00e\\x00d\\x00 \\x00t\\x00e\\x00m\\x00p\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00n\\x00a\\x00m\\x00e\\x00:\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00A\\x00C\\x006\\x009\\x00.\\x00t\\x00m\\x00p\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 3356
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3357
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3358
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3359
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xce+\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3360
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xce+\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3361
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x004\\x008\\x00>\\x00 \\x00<\\x00I\\x00s\\x00S\\x00C\\x00U\\x00I\\x00A\\x00P\\x00I\\x00M\\x00o\\x00d\\x00e\\x00>\\x00 \\x00f\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00r\\x00e\\x00a\\x00d\\x00 \\x00m\\x00o\\x00d\\x00e\\x00 \\x00f\\x00r\\x00o\\x00m\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "148"
              }
            ],
            "repeated": 0,
            "id": 3362
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3363
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3364
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3365
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00b,\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3366
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "b,\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3367
          },
          {
            "timestamp": "2026-02-10 09:22:13,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x004\\x009\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00N\\x00o\\x00K\\x00e\\x00e\\x00p\\x00 \\x00=\\x00 \\x00f\\x00a\\x00l\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 3368
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3369
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3370
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3371
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd6,\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3372
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6,\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3373
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x005\\x006\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00 \\x00n\\x00o\\x00O\\x00f\\x00f\\x00i\\x00c\\x00e\\x00M\\x00o\\x00d\\x00e\\x00 \\x00i\\x00s\\x00 \\x00d\\x00i\\x00s\\x00a\\x00b\\x00l\\x00e\\x00d\\x00 \\x00-\\x00>\\x00 \\x00d\\x00o\\x00 \\x00n\\x00o\\x00t\\x00 \\x00w\\x00r\\x00i\\x00t\\x00e\\x00 \\x00i\\x00t\\x00 \\x00t\\x00o\\x00 \\x00r\\x00e\\x00g\\x00i\\x00s\\x00t\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 3374
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3375
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3376
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3377
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9e-\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3378
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9e-\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3379
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x005\\x007\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00p\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00N\\x00a\\x00m\\x00e\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "182"
              }
            ],
            "repeated": 0,
            "id": 3380
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3381
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3382
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3383
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00T.\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3384
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T.\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3385
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x006\\x002\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00=\\x00 \\x00'\\x00E\\x00'\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3386
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3387
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3388
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3389
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd4.\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3390
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4.\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3391
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x006\\x004\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00e\\x00 \\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00 \\x00-\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 3392
          },
          {
            "timestamp": "2026-02-10 09:22:13,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3393
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3394
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x84/\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3395
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84/\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3396
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x006\\x005\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00W\\x00S\\x00C\\x00S\\x00V\\x00C\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00W\\x00S\\x00C\\x00S\\x00V\\x00C\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00T\\x00y\\x00p\\x00e\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "296"
              }
            ],
            "repeated": 0,
            "id": 3397
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3398
          },
          {
            "timestamp": "2026-02-10 09:22:13,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3399
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3400
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xac0\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3401
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac0\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3402
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x004\\x006\\x008\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00s\\x00c\\x00 \\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00w\\x00s\\x00c\\x00s\\x00v\\x00c\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00=\\x00 \\x00a\\x00u\\x00t\\x00o\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 3403
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3404
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3405
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3406
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00^1\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3407
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^1\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3408
          },
          {
            "timestamp": "2026-02-10 09:22:13,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x005\\x001\\x001\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00W\\x00S\\x00C\\x00S\\x00V\\x00C\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00F\\x00a\\x00i\\x00l\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00r\\x00u\\x00n\\x00 \\x00s\\x00c\\x00 \\x00c\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00w\\x00s\\x00c\\x00s\\x00v\\x00c\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00=\\x00 \\x00a\\x00u\\x00t\\x00o\\x00 \\x00-\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00:\\x001\\x008\\x003\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "210"
              }
            ],
            "repeated": 0,
            "id": 3409
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3410
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3411
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3412
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x0002\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3413
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "02\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3414
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x005\\x001\\x003\\x00>\\x00 \\x00<\\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00W\\x00S\\x00C\\x00S\\x00V\\x00C\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00T\\x00y\\x00p\\x00e\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00C\\x00h\\x00a\\x00n\\x00g\\x00e\\x00W\\x00S\\x00C\\x00S\\x00V\\x00C\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00T\\x00y\\x00p\\x00e\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "292"
              }
            ],
            "repeated": 0,
            "id": 3415
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3416
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3417
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3418
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xcaR\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3419
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcaR\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3420
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x003\\x00.\\x005\\x001\\x009\\x00>\\x00 \\x00<\\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00"
              },
              {
                "name": "Length",
                "value": "268"
              }
            ],
            "repeated": 0,
            "id": 3421
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3422
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3423
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3424
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd6S\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3425
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6S\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3426
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x004\\x005\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "238"
              }
            ],
            "repeated": 0,
            "id": 3427
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3428
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3429
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3430
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xc4T\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3431
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4T\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3432
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "454"
              }
            ],
            "repeated": 0,
            "id": 3433
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3434
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3435
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3436
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa0W\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3437
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0W\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3438
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00a\\x00c\\x00t\\x00u\\x00a\\x00l\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00c\\x00o\\x00d\\x00e\\x00 \\x001\\x006\\x000\\x003\\x00 \\x00b\\x00u\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00t\\x00r\\x00a\\x00n\\x00s\\x00l\\x00a\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00u\\x00"
              },
              {
                "name": "Length",
                "value": "318"
              }
            ],
            "repeated": 0,
            "id": 3439
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3440
          },
          {
            "timestamp": "2026-02-10 09:22:13,515",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 8,
            "id": 3441
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3442
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xdei\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3443
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdei\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3444
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 3445
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3446
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3447
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3448
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9ej\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3449
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9ej\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3450
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00 \\x00c\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00i\\x00n\\x00i\\x00t\\x00i\\x00a\\x00l\\x00i\\x00z\\x00a\\x00i\\x00n\\x00g\\x00 \\x00s\\x00h\\x00a\\x00r\\x00e\\x00d\\x00 \\x00m\\x00e\\x00m\\x00o\\x00r\\x00y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 3451
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3452
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3453
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3454
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x008k\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3455
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "8k\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3456
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00i\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00 \\x00=\\x00 \\x000\\x00,\\x00P\\x00I\\x00D\\x00=\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 3457
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3458
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3459
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3460
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb2k\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3461
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2k\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3462
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00T\\x00r\\x00y\\x00i\\x00n\\x00g\\x00 \\x00t\\x00o\\x00 \\x00o\\x00p\\x00e\\x00n\\x00 \\x00p\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00 \\x00w\\x00/\\x00 \\x00P\\x00I\\x00D\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3463
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3464
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3465
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3466
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x002l\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3467
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2l\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3468
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00G\\x00o\\x00t\\x00:\\x00 \\x00 \\x000\\x00,\\x00 \\x00G\\x00e\\x00t\\x00L\\x00a\\x00s\\x00t\\x00E\\x00r\\x00r\\x00o\\x00r\\x00(\\x00)\\x00=\\x008\\x007\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 3469
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3470
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3471
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3472
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa4l\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3473
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4l\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3474
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00G\\x00e\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00H\\x00a\\x00n\\x00d\\x00l\\x00e\\x00(\\x00)\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00s\\x00:\\x00 \\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 3475
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3476
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3477
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3478
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00*m\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3479
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*m\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3480
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "106"
              }
            ],
            "repeated": 0,
            "id": 3481
          },
          {
            "timestamp": "2026-02-10 09:22:13,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3482
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3483
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3484
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x94m\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3485
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94m\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3486
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00C\\x00o\\x00n\\x00s\\x00t\\x00r\\x00u\\x00c\\x00t\\x00o\\x00r\\x00 \\x00d\\x00o\\x00n\\x00e\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "96"
              }
            ],
            "repeated": 0,
            "id": 3487
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3488
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3489
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3490
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xf4m\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3491
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4m\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3492
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00I\\x00N\\x00G\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 3493
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3494
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3495
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3496
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00zn\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3497
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "zn\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3498
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3499
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3500
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3501
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3502
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x08o\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3503
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x08o\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3504
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00U\\x00P\\x00G\\x00R\\x00A\\x00D\\x00I\\x00N\\x00G\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 3505
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3506
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3507
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3508
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x8co\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3509
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8co\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3510
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "106"
              }
            ],
            "repeated": 0,
            "id": 3511
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3512
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3513
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3514
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xf6o\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3515
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6o\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3516
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3517
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3518
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3519
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3520
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x84p\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3521
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84p\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3522
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 3523
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3524
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3525
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3526
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xecp\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3527
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xecp\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3528
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00f\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00 \\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 3529
          },
          {
            "timestamp": "2026-02-10 09:22:13,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3530
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3531
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00Zq\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3532
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3533
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Zq\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3534
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00T\\x00V\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00:\\x00 \\x00 \\x00F\\x00r\\x00e\\x00s\\x00h\\x00A\\x00f\\x00t\\x00e\\x00r\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 3535
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3536
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3537
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3538
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xe2q\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3539
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2q\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3540
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 3541
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3542
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3543
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3544
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\r\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3545
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\r\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3546
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3547
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3548
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3549
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3550
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xear\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3551
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xear\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3552
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\\\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00.\\x00x\\x00m\\x00l\\x00\r\\x00"
              },
              {
                "name": "Length",
                "value": "258"
              }
            ],
            "repeated": 0,
            "id": 3553
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3554
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3555
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3556
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xecs\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3557
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xecs\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3558
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00T\\x00V\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00:\\x00 \\x00 \\x00C\\x00o\\x00p\\x00y\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 3559
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3560
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3561
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3562
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00tt\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3563
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "tt\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3564
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00c\\x00o\\x00p\\x00i\\x00e\\x00d\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\\\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00.\\x00x\\x00m\\x00l\\x00 \\x00t\\x00o\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00"
              },
              {
                "name": "Length",
                "value": "348"
              }
            ],
            "repeated": 0,
            "id": 3565
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3566
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3567
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3568
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd0u\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3569
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0u\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3570
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00T\\x00V\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00:\\x00 \\x00 \\x00C\\x00o\\x00p\\x00y\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00 \\x00f\\x00i\\x00n\\x00i\\x00s\\x00h\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 3571
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3572
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3573
          },
          {
            "timestamp": "2026-02-10 09:22:13,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3574
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00Zv\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3575
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Zv\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3576
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00e\\x00p\\x00k\\x00l\\x00i\\x00b\\x00.\\x00s\\x00y\\x00s\\x00 \\x00w\\x00a\\x00s\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "162"
              }
            ],
            "repeated": 0,
            "id": 3577
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3578
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3579
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3580
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xfcv\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3581
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfcv\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3582
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00c\\x00o\\x00p\\x00i\\x00e\\x00d\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00l\\x00a\\x00b\\x00s\\x00\\\\x00e\\x00p\\x00k\\x00l\\x00i\\x00b\\x00.\\x00s\\x00y\\x00s\\x00 \\x00t\\x00o\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00e\\x00p\\x00k\\x00l\\x00i\\x00b\\x00.\\x00s\\x00"
              },
              {
                "name": "Length",
                "value": "264"
              }
            ],
            "repeated": 0,
            "id": 3583
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3584
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3585
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3586
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x04x\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3587
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04x\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3588
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00c\\x00c\\x00o\\x00r\\x00e\\x006\\x004\\x00.\\x00s\\x00y\\x00s\\x00 \\x00w\\x00a\\x00s\\x00 \\x00d\\x00e\\x00l\\x00e\\x00t\\x00e\\x00d\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 3589
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3590
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3591
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3592
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa8x\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3593
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8x\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3594
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00 \\x00c\\x00o\\x00p\\x00i\\x00e\\x00d\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00l\\x00a\\x00b\\x00s\\x00\\\\x00c\\x00c\\x00o\\x00r\\x00e\\x006\\x004\\x00.\\x00s\\x00y\\x00s\\x00 \\x00t\\x00o\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00c\\x00c\\x00o\\x00r\\x00e\\x006\\x004\\x00"
              },
              {
                "name": "Length",
                "value": "268"
              }
            ],
            "repeated": 0,
            "id": 3595
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3596
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3597
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3598
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb4y\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3599
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4y\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3600
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00r\\x00I\\x00n\\x00s\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00-\\x00i\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "234"
              }
            ],
            "repeated": 0,
            "id": 3601
          },
          {
            "timestamp": "2026-02-10 09:22:13,640",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3602
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3603
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3604
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9ez\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3605
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9ez\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3606
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00 \\x00c\\x00m\\x00d\\x00:\\x00 \\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00r\\x00I\\x00n\\x00s\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00-\\x00i\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 3607
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3608
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3609
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3610
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa4{\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3611
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4{\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3612
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00T\\x00h\\x00e\\x00 \\x00o\\x00u\\x00t\\x00p\\x00u\\x00t\\x00 \\x00o\\x00f\\x00 \\x00t\\x00h\\x00e\\x00 \\x00c\\x00o\\x00m\\x00m\\x00a\\x00n\\x00d\\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00r\\x00I\\x00n\\x00s\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00-\\x00i\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00"
              },
              {
                "name": "Length",
                "value": "288"
              }
            ],
            "repeated": 0,
            "id": 3613
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3614
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3615
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3616
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xc4|\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3617
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4|\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3618
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00G\\x00U\\x00I\\x00D\\x00 \\x00i\\x00s\\x00 \\x00i\\x00n\\x00v\\x00a\\x00l\\x00i\\x00d\\x00.\\x00 \\x00(\\x00I\\x00s\\x00 \\x00i\\x00t\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00?\\x00)\\x00\r\\x00\n\\x00T\\x00h\\x00e\\x00 \\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00 \\x00i\\x00s\\x00 \\x00a\\x00p\\x00p\\x00a\\x00r\\x00e\\x00n\\x00t\\x00l\\x00y\\x00 \\x00n\\x00o\\x00t\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00.\\x00.\\x00.\\x00\r\\x00\n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00A\\x00d\\x00d\\x00i\\x00o\\x00t\\x00i\\x00o\\x00n\\x00a\\x00l\\x00F\\x00i\\x00l\\x00e\\x00:\\x00 \\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00"
              },
              {
                "name": "Length",
                "value": "1300"
              }
            ],
            "repeated": 0,
            "id": 3619
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3620
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3621
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3622
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x601\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3623
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x601\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3624
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00E\\x00n\\x00d\\x00 \\x00o\\x00f\\x00 \\x00o\\x00u\\x00t\\x00p\\x00u\\x00t\\x00 \\x00o\\x00f\\x00 \\x00t\\x00h\\x00e\\x00 \\x00c\\x00o\\x00m\\x00m\\x00a\\x00n\\x00d\\x00:\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00L\\x00a\\x00b\\x00s\\x00\\\\x00v\\x00s\\x00d\\x00r\\x00I\\x00n\\x00s\\x00t\\x00.\\x00e\\x00x\\x00e\\x00 \\x00-\\x00i\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00"
              },
              {
                "name": "Length",
                "value": "294"
              }
            ],
            "repeated": 0,
            "id": 3625
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3626
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3627
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3628
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xfe\\x82\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3629
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfe\\x82\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3630
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00F\\x00e\\x00a\\x00t\\x00u\\x00r\\x00e\\x00T\\x00V\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00:\\x00 \\x00 \\x00F\\x00r\\x00e\\x00s\\x00h\\x00A\\x00f\\x00t\\x00e\\x00r\\x00 \\x00f\\x00i\\x00n\\x00i\\x00s\\x00h\\x00e\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "138"
              }
            ],
            "repeated": 0,
            "id": 3631
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3632
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3633
          },
          {
            "timestamp": "2026-02-10 09:22:16,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3634
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x88\\x83\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3635
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88\\x83\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3636
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00I\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00.\\x00e\\x00x\\x00e\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 3637
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3638
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3639
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3640
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x02\\x84\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3641
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\x84\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3642
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00u\\x00n\\x00a\\x00b\\x00l\\x00e\\x00 \\x00t\\x00o\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x00p\\x00r\\x00o\\x00t\\x00e\\x00c\\x00t\\x00i\\x00o\\x00n\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00.\\x00e\\x00x\\x00e\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 3643
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3644
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3645
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3646
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb2\\x84\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3647
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2\\x84\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3648
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00:\\x00:\\x00G\\x00e\\x00t\\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00F\\x00l\\x00a\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 3649
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3650
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3651
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3652
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x1a\\x85\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3653
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1a\\x85\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3654
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00 \\x00f\\x00l\\x00a\\x00g\\x00 \\x00i\\x00s\\x00 \\x00F\\x00A\\x00L\\x00S\\x00E\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 3655
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3656
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3657
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3658
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x80\\x85\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3659
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80\\x85\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3660
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00I\\x00n\\x00s\\x00t\\x00H\\x00e\\x00l\\x00p\\x00e\\x00r\\x00.\\x00e\\x00x\\x00e\\x00 \\x00i\\x00s\\x00 \\x00n\\x00o\\x00t\\x00 \\x00r\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "122"
              }
            ],
            "repeated": 0,
            "id": 3661
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3662
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3663
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3664
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xfa\\x85\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3665
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfa\\x85\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3666
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3667
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3668
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3669
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3670
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00z\\x86\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3671
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\x86\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3672
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00 \\x00=\\x00 \\x00<\\x00h\\x00i\\x00d\\x00d\\x00e\\x00n\\x00>\\x00 \\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3673
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3674
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3675
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3676
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9c\\x88\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3677
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\x88\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3678
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00A\\x00:\\x00 \\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00:\\x00 \\x00 \\x00M\\x00s\\x00i\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00E\\x00x\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00=\\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 3679
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3680
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3681
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3682
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x1e\\x89\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3683
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\x89\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3684
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00F\\x00i\\x00n\\x00i\\x00s\\x00h\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x001\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "244"
              }
            ],
            "repeated": 0,
            "id": 3685
          },
          {
            "timestamp": "2026-02-10 09:22:16,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3686
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3687
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3688
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x10a\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3689
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10a\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3690
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "460"
              }
            ],
            "repeated": 0,
            "id": 3691
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3692
          },
          {
            "timestamp": "2026-02-10 09:22:16,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 3,
            "id": 3693
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3694
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xe4\\x91\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3695
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\x91\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3696
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00:\\x00 \\x00 \\x00E\\x00n\\x00t\\x00e\\x00r\\x00i\\x00n\\x00g\\x00 \\x00E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00i\\x00n\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x00M\\x00S\\x00I\\x00D\\x008\\x003\\x002\\x00.\\x00t\\x00m\\x00p\\x00,\\x00 \\x00v\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x003\\x00.\\x008\\x00.\\x001\\x001\\x002\\x008\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "208"
              }
            ],
            "repeated": 0,
            "id": 3697
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3698
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3699
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3700
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb4\\x92\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3701
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\x92\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3702
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00:\\x00 \\x00 \\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00u\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00:\\x00 \\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 3703
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3704
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3705
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3706
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00&\\x93\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3707
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\x93\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3708
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00:\\x00 \\x00 \\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00u\\x00r\\x00i\\x00n\\x00g\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00:\\x00 \\x00E\\x00P\\x00W\\x00D\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 3709
          },
          {
            "timestamp": "2026-02-10 09:22:16,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3710
          },
          {
            "timestamp": "2026-02-10 09:22:16,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 17,
            "id": 3711
          },
          {
            "timestamp": "2026-02-10 09:22:17,656",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3712
          },
          {
            "timestamp": "2026-02-10 09:22:17,656",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x90\\xcc\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3713
          },
          {
            "timestamp": "2026-02-10 09:22:17,656",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xcc\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3714
          },
          {
            "timestamp": "2026-02-10 09:22:17,656",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x007\\x00.\\x006\\x005\\x009\\x00>\\x00 \\x00<\\x00S\\x00t\\x00a\\x00r\\x00t\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00c\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00n\\x00e\\x00t\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00.\\x00.\\x00.\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 3715
          },
          {
            "timestamp": "2026-02-10 09:22:17,656",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3716
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3717
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3718
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00.\\xcd\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3719
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ".\\xcd\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3720
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x001\\x007\\x00.\\x006\\x006\\x001\\x00>\\x00 \\x00<\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00W\\x00i\\x00t\\x00h\\x00o\\x00u\\x00t\\x00C\\x00o\\x00n\\x00s\\x00o\\x00l\\x00e\\x00W\\x00a\\x00i\\x00t\\x00>\\x00 \\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00:\\x00 \\x00n\\x00e\\x00t\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "170"
              }
            ],
            "repeated": 0,
            "id": 3721
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3722
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3723
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3724
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xbe\\xd0\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3725
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbe\\xd0\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3726
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x000\\x005\\x001\\x00>\\x00 \\x00<\\x00S\\x00t\\x00a\\x00r\\x00t\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00>\\x00 \\x00n\\x00e\\x00t\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 3727
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3728
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3729
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3730
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00V\\xd1\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3731
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "V\\xd1\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3732
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00T\\x00r\\x00a\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x003\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "234"
              }
            ],
            "repeated": 0,
            "id": 3733
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3734
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3735
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3736
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x006\\xd3\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3737
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\xd3\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3738
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "450"
              }
            ],
            "repeated": 0,
            "id": 3739
          },
          {
            "timestamp": "2026-02-10 09:22:20,047",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3740
          },
          {
            "timestamp": "2026-02-10 09:22:20,062",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3741
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3742
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x14\\xd9\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3743
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\xd9\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3744
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x001\\x004\\x004\\x00>\\x00 \\x00<\\x00C\\x00o\\x00p\\x00y\\x00L\\x00a\\x00s\\x00t\\x00M\\x00S\\x00I\\x00L\\x00o\\x00g\\x00F\\x00i\\x00l\\x00e\\x00>\\x00 \\x00T\\x00h\\x00e\\x00 \\x00l\\x00a\\x00t\\x00e\\x00s\\x00t\\x00 \\x00M\\x00S\\x00I\\x00 \\x00l\\x00o\\x00g\\x00 \\x00f\\x00i\\x00l\\x00e\\x00 \\x00i\\x00s\\x00:\\x00 \\x00M\\x00S\\x00I\\x004\\x009\\x005\\x00d\\x004\\x00.\\x00L\\x00O\\x00G\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 3745
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3746
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3747
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3748
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xc0\\xd9\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3749
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\xd9\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3750
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00C\\x00o\\x00p\\x00y\\x00L\\x00a\\x00s\\x00t\\x00M\\x00S\\x00I\\x00L\\x00o\\x00g\\x00F\\x00i\\x00l\\x00e\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x001\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "238"
              }
            ],
            "repeated": 0,
            "id": 3751
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3752
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3753
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3754
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x94\\xdb\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3755
          },
          {
            "timestamp": "2026-02-10 09:22:20,140",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\xdb\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3756
          },
          {
            "timestamp": "2026-02-10 09:22:20,156",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "454"
              }
            ],
            "repeated": 0,
            "id": 3757
          },
          {
            "timestamp": "2026-02-10 09:22:20,156",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3758
          },
          {
            "timestamp": "2026-02-10 09:22:20,156",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 8,
            "id": 3759
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3760
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00*\\xe3\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3761
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*\\xe3\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3762
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00F\\x00i\\x00n\\x00a\\x00l\\x00i\\x00z\\x00e\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 3763
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3764
          },
          {
            "timestamp": "2026-02-10 09:22:20,187",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3765
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3766
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xae\\xe4\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3767
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xae\\xe4\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3768
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 3769
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3770
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3771
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3772
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xe2\\xe5\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3773
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\xe5\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3774
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00O\\x00n\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 3775
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3776
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3777
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3778
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xaa\\xe6\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3779
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaa\\xe6\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3780
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00E\\x00x\\x00i\\x00s\\x00t\\x00i\\x00n\\x00g\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "96"
              }
            ],
            "repeated": 0,
            "id": 3781
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3782
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 5,
            "id": 3783
          },
          {
            "timestamp": "2026-02-10 09:22:20,234",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3784
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x86\\xe7\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3785
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86\\xe7\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3786
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00E\\x00x\\x00i\\x00s\\x00t\\x00i\\x00n\\x00g\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3787
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3788
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3789
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3790
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xcc\\xe8\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3791
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcc\\xe8\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3792
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00S\\x00u\\x00p\\x00p\\x00r\\x00e\\x00s\\x00s\\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 3793
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3794
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3795
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3796
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x006\\xea\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3797
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\xea\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3798
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00S\\x00u\\x00p\\x00p\\x00r\\x00e\\x00s\\x00s\\x00R\\x00e\\x00b\\x00o\\x00o\\x00t\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 3799
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3800
          },
          {
            "timestamp": "2026-02-10 09:22:20,250",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3801
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3802
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x9c\\xeb\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3803
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\xeb\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3804
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3805
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3806
          },
          {
            "timestamp": "2026-02-10 09:22:20,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3807
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3808
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xde\\xeb\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3809
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde\\xeb\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3810
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x003\\x003\\x006\\x00>\\x00 \\x00<\\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "232"
              }
            ],
            "repeated": 0,
            "id": 3811
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3812
          },
          {
            "timestamp": "2026-02-10 09:22:20,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 3813
          },
          {
            "timestamp": "2026-02-10 09:22:20,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3814
          },
          {
            "timestamp": "2026-02-10 09:22:20,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xc6\\xec\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3815
          },
          {
            "timestamp": "2026-02-10 09:22:20,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6\\xec\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3816
          },
          {
            "timestamp": "2026-02-10 09:22:20,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x003\\x006\\x002\\x00>\\x00 \\x00<\\x00I\\x00s\\x00U\\x00s\\x00e\\x00r\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00>\\x00 \\x00G\\x00o\\x00t\\x00 \\x00t\\x00h\\x00e\\x00 \\x00a\\x00c\\x00c\\x00o\\x00u\\x00n\\x00t\\x00 \\x00s\\x00i\\x00d\\x00.\\x00 \\x00s\\x00n\\x00u\\x00:\\x001\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 3817
          },
          {
            "timestamp": "2026-02-10 09:22:20,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3818
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3819
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3820
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xe0\\xf1\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3821
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe0\\xf1\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3822
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x006\\x000\\x008\\x00>\\x00 \\x00<\\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "228"
              }
            ],
            "repeated": 0,
            "id": 3823
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3824
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3825
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3826
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xc4\\xf2\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3827
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4\\xf2\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3828
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x006\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 3829
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3830
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3831
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3832
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00R\\xf3\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3833
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "R\\xf3\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3834
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "358"
              }
            ],
            "repeated": 0,
            "id": 3835
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3836
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3837
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3838
          },
          {
            "timestamp": "2026-02-10 09:22:20,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xb8\\xf4\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3839
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb8\\xf4\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3840
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00 \\x00r\\x00e\\x00t\\x00u\\x00r\\x00n\\x00e\\x00d\\x00 \\x00a\\x00c\\x00t\\x00u\\x00a\\x00l\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00c\\x00o\\x00d\\x00e\\x00 \\x001\\x006\\x000\\x003\\x00 \\x00b\\x00u\\x00t\\x00 \\x00w\\x00i\\x00l\\x00l\\x00 \\x00b\\x00e\\x00 \\x00t\\x00r\\x00a\\x00n\\x00s\\x00l\\x00a\\x00t\\x00e\\x00d\\x00 \\x00t\\x00o\\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00d\\x00u\\x00e\\x00 \\x00t\\x00o\\x00 \\x00c\\x00o\\x00n\\x00t\\x00i\\x00n\\x00u\\x00e\\x00 \\x00m\\x00a\\x00r\\x00k\\x00i\\x00n\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "224"
              }
            ],
            "repeated": 0,
            "id": 3841
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3842
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3843
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3844
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\n\\xf6\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3845
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\n\\xf6\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3846
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00L\\x00o\\x00a\\x00d\\x00G\\x00U\\x00I\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "98"
              }
            ],
            "repeated": 0,
            "id": 3847
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3848
          },
          {
            "timestamp": "2026-02-10 09:22:20,625",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3849
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3850
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00f\\xf7\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3851
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3852
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\xf7\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3853
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00:\\x00 \\x00O\\x00n\\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 3854
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3855
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3856
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3857
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xac\\xf7\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3858
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\xf7\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3859
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x007\\x004\\x009\\x00>\\x00 \\x00<\\x00O\\x00n\\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00>\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00 \\x00O\\x00n\\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00s\\x00t\\x00a\\x00r\\x00t\\x00e\\x00d\\x00 \\x00*\\x00*\\x00*\\x00*\\x00*\\x00\n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 3860
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3861
          },
          {
            "timestamp": "2026-02-10 09:22:20,750",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 4,
            "id": 3862
          },
          {
            "timestamp": "2026-02-10 09:22:21,250",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3863
          },
          {
            "timestamp": "2026-02-10 09:22:21,250",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x000\\xf8\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3864
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\xf8\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3865
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x000\\x00.\\x007\\x006\\x001\\x00>\\x00 \\x00<\\x00I\\x00s\\x00I\\x00n\\x00R\\x00e\\x00m\\x00o\\x00v\\x00e\\x00C\\x00a\\x00s\\x00e\\x00>\\x00 \\x00n\\x00o\\x00t\\x00 \\x00u\\x00n\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00c\\x00a\\x00s\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 3866
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3867
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3868
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3869
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x90\\xfc\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3870
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xfc\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3871
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "<\\x001\\x000\\x00 \\x00F\\x00e\\x00b\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x001\\x00.\\x002\\x006\\x002\\x00>\\x00 \\x00<\\x00O\\x00n\\x00E\\x00n\\x00d\\x00>\\x00 \\x00T\\x00e\\x00l\\x00e\\x00m\\x00e\\x00t\\x00r\\x00y\\x00 \\x00w\\x00a\\x00s\\x00 \\x00s\\x00e\\x00n\\x00t\\x00 \\x00s\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00f\\x00u\\x00l\\x00l\\x00y\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "128"
              }
            ],
            "repeated": 0,
            "id": 3872
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3873
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3874
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3875
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x10\\xfd\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3876
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xfd\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3877
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00B\\x00U\\x00G\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00 \\x002\\x007\\x006\\x009\\x00:\\x00 \\x00 \\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00 \\x00A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00O\\x00n\\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00 \\x00d\\x00i\\x00d\\x00 \\x00n\\x00o\\x00t\\x00 \\x00c\\x00l\\x00o\\x00s\\x00e\\x00 \\x005\\x00 \\x00M\\x00S\\x00I\\x00H\\x00A\\x00N\\x00D\\x00L\\x00E\\x00s\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "146"
              }
            ],
            "repeated": 0,
            "id": 3878
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3879
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3880
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3881
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xa2\\xfd\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3882
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xfd\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3883
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "T\\x00h\\x00e\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00 \\x00h\\x00a\\x00s\\x00 \\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00a\\x00n\\x00 \\x00u\\x00n\\x00e\\x00x\\x00p\\x00e\\x00c\\x00t\\x00e\\x00d\\x00 \\x00e\\x00r\\x00r\\x00o\\x00r\\x00 \\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00i\\x00n\\x00g\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00i\\x00s\\x00 \\x00m\\x00a\\x00y\\x00 \\x00i\\x00n\\x00d\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00a\\x00 \\x00p\\x00r\\x00o\\x00b\\x00l\\x00e\\x00m\\x00 \\x00w\\x00i\\x00t\\x00h\\x00 \\x00t\\x00h\\x00i\\x00s\\x00 \\x00p\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00.\\x00 \\x00T\\x00h\\x00e\\x00 \\x00e\\x00r\\x00"
              },
              {
                "name": "Length",
                "value": "362"
              }
            ],
            "repeated": 0,
            "id": 3884
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3885
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3886
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3887
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x0c\\xff\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3888
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\xff\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3889
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x001\\x00:\\x00 \\x00O\\x00n\\x00S\\x00u\\x00c\\x00c\\x00e\\x00s\\x00s\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "102"
              }
            ],
            "repeated": 0,
            "id": 3890
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3891
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3892
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3893
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00r\\xff\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3894
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "r\\xff\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3895
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "A\\x00c\\x00t\\x00i\\x00o\\x00n\\x00 \\x00e\\x00n\\x00d\\x00e\\x00d\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x001\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00.\\x00 \\x00R\\x00e\\x00t\\x00u\\x00r\\x00n\\x00 \\x00v\\x00a\\x00l\\x00u\\x00e\\x00 \\x001\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "98"
              }
            ],
            "repeated": 0,
            "id": 3896
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3897
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 2,
            "id": 3898
          },
          {
            "timestamp": "2026-02-10 09:22:21,265",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3899
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\xd4\\xff\\x0c\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3900
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4\\xff\\x0c\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3901
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00p\\x00g\\x00r\\x00a\\x00d\\x00e\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x00D\\x00F\\x00E\\x005\\x008\\x00C\\x002\\x00-\\x003\\x002\\x003\\x00A\\x00-\\x004\\x00A\\x00B\\x00C\\x00-\\x008\\x00D\\x009\\x002\\x00-\\x005\\x003\\x00A\\x003\\x004\\x00F\\x000\\x00B\\x006\\x005\\x007\\x005\\x00}\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 3902
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3903
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3904
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3905
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00Z\\x00\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3906
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\x00\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3907
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00i\\x00x\\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00=\\x00 \\x001\\x00\\x80\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00G\\x00U\\x00I\\x00\\x80\\x002\\x001\\x004\\x007\\x004\\x008\\x003\\x006\\x004\\x007\\x00\\x80\\x00*\\x00\\x80\\x001\\x00\\x80\\x002\\x00\\x80\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x00"
              },
              {
                "name": "Length",
                "value": "660"
              }
            ],
            "repeated": 0,
            "id": 3908
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3909
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3910
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3911
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xee\\x02\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3912
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\x02\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3913
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00i\\x00x\\x00E\\x00x\\x00e\\x00c\\x00F\\x00i\\x00r\\x00e\\x00w\\x00a\\x00l\\x00l\\x00E\\x00x\\x00c\\x00e\\x00p\\x00t\\x00i\\x00o\\x00n\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00 \\x00=\\x00 \\x001\\x00\\x80\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00 \\x00G\\x00U\\x00I\\x00\\x80\\x002\\x001\\x004\\x007\\x004\\x008\\x003\\x006\\x004\\x007\\x00\\x80\\x00*\\x00\\x80\\x001\\x00\\x80\\x002\\x00\\x80\\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00"
              },
              {
                "name": "Length",
                "value": "652"
              }
            ],
            "repeated": 0,
            "id": 3914
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3915
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3916
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3917
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00z\\x05\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3918
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "z\\x05\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3919
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "158"
              }
            ],
            "repeated": 0,
            "id": 3920
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3921
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3922
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3923
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x18\\x06\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3924
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\x06\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3925
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "212"
              }
            ],
            "repeated": 0,
            "id": 3926
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3927
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3928
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3929
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xec\\x06\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3930
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec\\x06\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3931
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00M\\x00o\\x00b\\x00i\\x00l\\x00e\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 3932
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3933
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3934
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3935
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x98\\x07\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3936
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98\\x07\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3937
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00S\\x00e\\x00c\\x00u\\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 3938
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3939
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3940
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3941
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00T\\x08\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3942
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\x08\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3943
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00r\\x00e\\x00s\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00r\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "152"
              }
            ],
            "repeated": 0,
            "id": 3944
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3945
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3946
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3947
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xec\\x08\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3948
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec\\x08\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3949
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 3950
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3951
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3952
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3953
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00H\t\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3954
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "H\t\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3955
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00N\\x00T\\x006\\x004\\x00 \\x00=\\x00 \\x006\\x000\\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3956
          },
          {
            "timestamp": "2026-02-10 09:22:21,281",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3957
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3958
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x88\t\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3959
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88\t\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3960
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 3961
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3962
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 3963
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3964
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x1e\n\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3965
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\n\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3966
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00S\\x00 \\x00=\\x00 \\x00#\\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3967
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3968
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3969
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3970
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00f\n\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3971
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\n\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3972
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00_\\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00S\\x00u\\x00b\\x00T\\x00y\\x00p\\x00e\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00 \\x00V\\x00P\\x00N\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 3973
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3974
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3975
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3976
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe8\n\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3977
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\n\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3978
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00g\\x00r\\x00e\\x00e\\x00T\\x00o\\x00L\\x00i\\x00c\\x00e\\x00n\\x00s\\x00e\\x00 \\x00=\\x00 \\x00N\\x00o\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 3979
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3980
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3981
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3982
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00,\\x0b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3983
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ",\\x0b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3984
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00_\\x00I\\x00s\\x00M\\x00a\\x00i\\x00n\\x00t\\x00e\\x00n\\x00a\\x00n\\x00c\\x00e\\x00 \\x00=\\x00 \\x00R\\x00e\\x00i\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 3985
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3986
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3987
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3988
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00~\\x0b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3989
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\x0b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3990
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00=\\x00 \\x00E\\x00N\\x00D\\x00P\\x00O\\x00I\\x00N\\x00T\\x00_\\x00S\\x00E\\x00C\\x00U\\x00R\\x00I\\x00T\\x00Y\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "100"
              }
            ],
            "repeated": 0,
            "id": 3991
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3992
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3993
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 3994
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe2\\x0b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3995
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\x0b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3996
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3997
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 3998
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 3999
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4000
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00 \\x0c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4001
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x0c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4002
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00S\\x00u\\x00p\\x00p\\x00r\\x00e\\x00s\\x00s\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4003
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4004
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4005
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4006
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\x0c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4007
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x0c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4008
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 4009
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4010
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4011
          },
          {
            "timestamp": "2026-02-10 09:22:21,297",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4012
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00(\r\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4013
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\r\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4014
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "176"
              }
            ],
            "repeated": 0,
            "id": 4015
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4016
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4017
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4018
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd8\r\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4019
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd8\r\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4020
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00A\\x00R\\x00G\\x00E\\x00T\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 4021
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4022
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4023
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4024
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x14\\x0e\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4025
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\x0e\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4026
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 4027
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4028
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4029
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4030
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x96\\x0e\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4031
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96\\x0e\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4032
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "118"
              }
            ],
            "repeated": 0,
            "id": 4033
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4034
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4035
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4036
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x0c\\x0f\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4037
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\x0f\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4038
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "84"
              }
            ],
            "repeated": 0,
            "id": 4039
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4040
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4041
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4042
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\x0f\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4043
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x0f\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4044
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00e\\x00l\\x00e\\x00m\\x00e\\x00t\\x00r\\x00y\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00i\\x00t\\x00y\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "148"
              }
            ],
            "repeated": 0,
            "id": 4045
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4046
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4047
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4048
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf4\\x0f\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4049
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4\\x0f\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4050
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "108"
              }
            ],
            "repeated": 0,
            "id": 4051
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4052
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4053
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4054
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\x10\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4055
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x10\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4056
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 4057
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4058
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4059
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4060
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc8\\x10\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4061
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8\\x10\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4062
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00o\\x00u\\x00r\\x00c\\x00e\\x00D\\x00i\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4063
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4064
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4065
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4066
          },
          {
            "timestamp": "2026-02-10 09:22:21,312",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x0e\\x11\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4067
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\x11\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4068
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00R\\x00P\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00I\\x00C\\x00O\\x00N\\x00 \\x00=\\x00 \\x00i\\x00c\\x00o\\x00n\\x00.\\x00i\\x00c\\x00o\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 4069
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4070
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4071
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4072
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00^\\x11\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4073
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\x11\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4074
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00L\\x00o\\x00g\\x00g\\x00i\\x00n\\x00g\\x00 \\x00=\\x00 \\x00v\\x00o\\x00i\\x00c\\x00e\\x00w\\x00a\\x00r\\x00m\\x00u\\x00p\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 4075
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4076
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4077
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4078
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xac\\x11\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4079
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\x11\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4080
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00H\\x00O\\x00W\\x00_\\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00T\\x00Y\\x00P\\x00E\\x00_\\x00D\\x00L\\x00G\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "84"
              }
            ],
            "repeated": 0,
            "id": 4081
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4082
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4083
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4084
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x12\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4085
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x12\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4086
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00I\\x00S\\x00A\\x00B\\x00L\\x00E\\x00A\\x00D\\x00V\\x00T\\x00S\\x00H\\x00O\\x00R\\x00T\\x00C\\x00U\\x00T\\x00S\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 4087
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4088
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4089
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4090
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00N\\x12\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4091
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "N\\x12\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4092
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00A\\x00C\\x00K\\x00A\\x00G\\x00E\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00 \\x00=\\x00 \\x00#\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4093
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4094
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4095
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4096
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x8e\\x12\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4097
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8e\\x12\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4098
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00E\\x00L\\x00E\\x00M\\x00E\\x00T\\x00R\\x00Y\\x00_\\x00D\\x00I\\x00S\\x00A\\x00B\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4099
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4100
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4101
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4102
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd8\\x12\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4103
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd8\\x12\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4104
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00r\\x00r\\x00o\\x00r\\x00D\\x00i\\x00a\\x00l\\x00o\\x00g\\x00 \\x00=\\x00 \\x00S\\x00e\\x00t\\x00u\\x00p\\x00E\\x00r\\x00r\\x00o\\x00r\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 4105
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4106
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4107
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4108
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00&\\x13\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4109
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\x13\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4110
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00e\\x00f\\x00a\\x00u\\x00l\\x00t\\x00U\\x00I\\x00F\\x00o\\x00n\\x00t\\x00 \\x00=\\x00 \\x00W\\x00i\\x00x\\x00U\\x00I\\x00_\\x00F\\x00o\\x00n\\x00t\\x00_\\x00N\\x00o\\x00r\\x00m\\x00a\\x00l\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "96"
              }
            ],
            "repeated": 0,
            "id": 4111
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4112
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4113
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4114
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x86\\x13\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4115
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86\\x13\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4116
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00a\\x00n\\x00u\\x00f\\x00a\\x00c\\x00t\\x00u\\x00r\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00S\\x00o\\x00f\\x00t\\x00w\\x00a\\x00r\\x00e\\x00 \\x00T\\x00e\\x00c\\x00h\\x00n\\x00o\\x00l\\x00o\\x00g\\x00i\\x00e\\x00s\\x00 \\x00L\\x00t\\x00d\\x00.\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 4117
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4118
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4119
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4120
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x0e\\x14\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4121
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\x14\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4122
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 4123
          },
          {
            "timestamp": "2026-02-10 09:22:21,328",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4124
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4125
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4126
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x94\\x14\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4127
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\x14\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4128
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00L\\x00a\\x00n\\x00g\\x00u\\x00a\\x00g\\x00e\\x00 \\x00=\\x00 \\x001\\x000\\x003\\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4129
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4130
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4131
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4132
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xde\\x14\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4133
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xde\\x14\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4134
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00N\\x00a\\x00m\\x00e\\x00 \\x00=\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00V\\x00P\\x00N\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "88"
              }
            ],
            "repeated": 0,
            "id": 4135
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4136
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4137
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4138
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x006\\x15\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4139
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6\\x15\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4140
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00 \\x00=\\x00 \\x009\\x008\\x00.\\x006\\x001\\x00.\\x004\\x006\\x000\\x005\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "84"
              }
            ],
            "repeated": 0,
            "id": 4141
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4142
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4143
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4144
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x8a\\x15\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4145
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a\\x15\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4146
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00e\\x00c\\x00u\\x00r\\x00e\\x00C\\x00u\\x00s\\x00t\\x00o\\x00m\\x00P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00i\\x00e\\x00s\\x00 \\x00=\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00_\\x00S\\x00U\\x00B\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00;\\x00E\\x00P\\x00S\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00E\\x00D\\x00;\\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00;\\x00I\\x00S\\x00A\\x00C\\x00T\\x00I\\x00O\\x00N\\x00P\\x00R\\x00O\\x00P\\x001\\x00;\\x00I\\x00S\\x00D\\x00O\\x00W\\x00N\\x00G\\x00R\\x00A\\x00D\\x00E\\x00;\\x00P\\x00A\\x00C\\x00K\\x00A\\x00G\\x00E\\x00_\\x00T\\x00Y\\x00P\\x00E\\x00;\\x00R\\x00E\\x00M\\x00O\\x00V\\x00E\\x00_\\x00S\\x00U\\x00B\\x00"
              },
              {
                "name": "Length",
                "value": "310"
              }
            ],
            "repeated": 0,
            "id": 4147
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4148
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4149
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4150
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc0\\x16\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4151
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\x16\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4152
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00P\\x00N\\x00_\\x00P\\x00r\\x00o\\x00x\\x00y\\x00S\\x00e\\x00r\\x00v\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00V\\x00P\\x00N\\x00_\\x00P\\x00r\\x00o\\x00x\\x00y\\x00"
              },
              {
                "name": "Length",
                "value": "274"
              }
            ],
            "repeated": 0,
            "id": 4153
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4154
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4155
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4156
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd2\\x17\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4157
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\x17\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4158
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 4159
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4160
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4161
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4162
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x92\\x18\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4163
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x92\\x18\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4164
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "204"
              }
            ],
            "repeated": 0,
            "id": 4165
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4166
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4167
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4168
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00^\\x19\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4169
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\x19\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4170
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00N\\x00T\\x00 \\x00=\\x00 \\x006\\x000\\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 4171
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4172
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4173
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4174
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x9a\\x19\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4175
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\x19\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4176
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00o\\x00n\\x00e\\x00n\\x00t\\x00s\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x002\\x00\\\\x00A\\x00C\\x006\\x009\\x00.\\x00t\\x00m\\x00p\\x00N\\x00N\\x00N\\x00Y\\x00N\\x00N\\x00E\\x00O\\x00N\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 4177
          },
          {
            "timestamp": "2026-02-10 09:22:21,343",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4178
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4179
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4180
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\x1a\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4181
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x1a\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4182
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00x\\x00e\\x00c\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00=\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00\\x80\\x00T\\x00r\\x00a\\x00c\\x00S\\x00r\\x00v\\x00W\\x00r\\x00a\\x00p\\x00p\\x00e\\x00r\\x00\\x80\\x000\\x00\\x80\\x00r\\x00e\\x00s\\x00t\\x00a\\x00r\\x00t\\x00\\x80\\x00r\\x00e\\x00s\\x00t\\x00a\\x00r\\x00t\\x00\\x80\\x00n\\x00o\\x00n\\x00e\\x00\\x80\\x000\\x00\\x80\\x000\\x00\\x80\\x00\\x80\\x00\\x80\\x00E\\x00P\\x00W\\x00D\\x00\\x80\\x000\\x00\\x80\\x00r\\x00e\\x00s\\x00t\\x00a\\x00r\\x00t\\x00\\x80\\x00r\\x00e\\x00s\\x00t\\x00a\\x00r\\x00t\\x00\\x80\\x00n\\x00o\\x00n\\x00e\\x00\\x80\\x001\\x00\\x80\\x000\\x00\\x80\\x00"
              },
              {
                "name": "Length",
                "value": "262"
              }
            ],
            "repeated": 0,
            "id": 4183
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4184
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4185
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4186
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00f\\x1b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4187
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\x1b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4188
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00o\\x00l\\x00l\\x00b\\x00a\\x00c\\x00k\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00 \\x00=\\x00 \\x00S\\x00c\\x00h\\x00e\\x00d\\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00C\\x00o\\x00n\\x00f\\x00i\\x00g\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 4189
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4190
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4191
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4192
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd8\\x1b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4193
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd8\\x1b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4194
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00I\\x00X\\x00E\\x00D\\x00_\\x00M\\x00A\\x00C\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4195
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4196
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4197
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4198
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x12\\x1c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4199
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12\\x1c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4200
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00N\\x00O\\x00_\\x00O\\x00F\\x00F\\x00I\\x00C\\x00E\\x00_\\x00M\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 4201
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4202
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4203
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4204
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00T\\x1c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4205
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\x1c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4206
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00D\\x00L\\x00_\\x00E\\x00N\\x00A\\x00B\\x00L\\x00E\\x00D\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 4207
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4208
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4209
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4210
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x92\\x1c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4211
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x92\\x1c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4212
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00R\\x00E\\x00B\\x00O\\x00O\\x00T\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4213
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4214
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4215
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4216
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xdc\\x1c\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4217
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdc\\x1c\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4218
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00N\\x00A\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4219
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4220
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4221
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4222
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x1c\\x1d\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4223
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1c\\x1d\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4224
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00N\\x00E\\x00R\\x00_\\x00M\\x00S\\x00I\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4225
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4226
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4227
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4228
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00V\\x1d\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4229
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "V\\x1d\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4230
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00C\\x00_\\x00U\\x00I\\x00F\\x00R\\x00A\\x00M\\x00E\\x00W\\x00O\\x00R\\x00K\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 4231
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4232
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4233
          },
          {
            "timestamp": "2026-02-10 09:22:21,359",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4234
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x9a\\x1d\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4235
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\x1d\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4236
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00E\\x00A\\x00F\\x00U\\x00L\\x00T\\x00_\\x00V\\x00P\\x00N\\x00 \\x00=\\x00 \\x00E\\x00C\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 4237
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4238
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4239
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4240
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd8\\x1d\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4241
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd8\\x1d\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4242
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00N\\x00o\\x00K\\x00e\\x00e\\x00p\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 4243
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4244
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4245
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4246
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x0c\\x1e\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4247
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0c\\x1e\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4248
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00N\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00A\\x00S\\x00S\\x00W\\x00O\\x00R\\x00D\\x00 \\x00=\\x00 \\x00N\\x00O\\x00P\\x00A\\x00S\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "84"
              }
            ],
            "repeated": 0,
            "id": 4249
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4250
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4251
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4252
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\x1e\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4253
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\x1e\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4254
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00E\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00M\\x00O\\x00D\\x00E\\x00 \\x00=\\x00 \\x00o\\x00m\\x00u\\x00s\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4255
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4256
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4257
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4258
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa6\\x1e\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4259
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa6\\x1e\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4260
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 4261
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4262
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4263
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4264
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00T\\x1f\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4265
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "T\\x1f\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4266
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00V\\x00D\\x00I\\x00R\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00Z\\x00o\\x00n\\x00e\\x00l\\x00a\\x00b\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 4267
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4268
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4269
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4270
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x06 \r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4271
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x06 \r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4272
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 4273
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4274
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4275
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4276
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc6 \r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4277
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6 \r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4278
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "198"
              }
            ],
            "repeated": 0,
            "id": 4279
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4280
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4281
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4282
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x8cA\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4283
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8cA\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4284
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "7\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00]\\x00]\\x00|\\x00[\\x00[\\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00C\\x00O\\x00D\\x00E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00"
              },
              {
                "name": "Length",
                "value": "1300"
              }
            ],
            "repeated": 0,
            "id": 4285
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4286
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4287
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4288
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa0f\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4289
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0f\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4290
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00]\\x00]\\x00|\\x00[\\x00[\\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00C\\x00O\\x00D\\x00E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00"
              },
              {
                "name": "Length",
                "value": "1302"
              }
            ],
            "repeated": 0,
            "id": 4291
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4292
          },
          {
            "timestamp": "2026-02-10 09:22:21,375",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4293
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4294
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb6\\x8b\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4295
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6\\x8b\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4296
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00"
              },
              {
                "name": "Length",
                "value": "1226"
              }
            ],
            "repeated": 0,
            "id": 4297
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4298
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4299
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4300
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x80\\xb0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4301
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80\\xb0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4302
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x00E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00"
              },
              {
                "name": "Length",
                "value": "1228"
              }
            ],
            "repeated": 0,
            "id": 4303
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4304
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4305
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4306
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00L\\xb5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4307
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\xb5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4308
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00P\\x00_\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00.\\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00 \\x00=\\x00 \\x00E\\x00P\\x00_\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00E\\x008\\x007\\x00_\\x002\\x000\\x00\\\\x00B\\x008\\x006\\x008\\x007\\x002\\x000\\x000\\x000\\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "186"
              }
            ],
            "repeated": 0,
            "id": 4309
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4310
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4311
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4312
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x06\\xb6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4313
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x06\\xb6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4314
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00V\\x00E\\x00R\\x00S\\x00I\\x00O\\x00N\\x00 \\x00=\\x00 \\x008\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4315
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4316
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4317
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4318
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00P\\xb6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4319
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\xb6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4320
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00P\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00G\\x00U\\x00I\\x00D\\x00 \\x00=\\x00 \\x006\\x00B\\x006\\x00E\\x006\\x004\\x00A\\x003\\x00_\\x004\\x004\\x007\\x008\\x00_\\x004\\x002\\x009\\x007\\x00_\\x009\\x00C\\x00D\\x009\\x00_\\x003\\x00D\\x007\\x001\\x00D\\x00B\\x00C\\x00D\\x009\\x007\\x004\\x00A\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 4321
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4322
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4323
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4324
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x5b6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4325
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x5b6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4326
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00D\\x00R\\x00V\\x00_\\x00R\\x00E\\x00P\\x00L\\x00A\\x00C\\x00E\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4327
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4328
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4329
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4330
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x1c\\xb7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4331
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1c\\xb7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4332
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00\\\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00p\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 4333
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4334
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4335
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4336
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xaa\\xb7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4337
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaa\\xb7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4338
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00E\\x00R\\x00R\\x00O\\x00R\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4339
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4340
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4341
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4342
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf0\\xb7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4343
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0\\xb7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4344
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\\\\x00D\\x00i\\x00s\\x00c\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00e\\x00d\\x00P\\x00o\\x00l\\x00i\\x00c\\x00y\\x00.\\x00x\\x00m\\x00l\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "202"
              }
            ],
            "repeated": 0,
            "id": 4345
          },
          {
            "timestamp": "2026-02-10 09:22:21,390",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4346
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4347
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xb8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4348
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00D\\x00i\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00C\\x00o\\x00n\\x00n\\x00e\\x00c\\x00t\\x00\\\\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "252"
              }
            ],
            "repeated": 0,
            "id": 4349
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4350
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4351
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4352
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb6\\xb9\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4353
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6\\xb9\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4354
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 4355
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4356
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4357
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4358
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00v\\xba\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4359
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\xba\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4360
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00a\\x00n\\x00y\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "204"
              }
            ],
            "repeated": 0,
            "id": 4361
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4362
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4363
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4364
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00B\\xbb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4365
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "B\\xbb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4366
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00K\\x00P\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "168"
              }
            ],
            "repeated": 0,
            "id": 4367
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4368
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4369
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4370
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xea\\xbb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4371
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xea\\xbb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4372
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00_\\x00c\\x00f\\x00g\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "192"
              }
            ],
            "repeated": 0,
            "id": 4373
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4374
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4375
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4376
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xaa\\xbc\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4377
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaa\\xbc\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4378
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00o\\x00g\\x00s\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\\\x00L\\x00o\\x00g\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "180"
              }
            ],
            "repeated": 0,
            "id": 4379
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4380
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4381
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4382
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00^\\xbd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4383
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\xbd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4384
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "178"
              }
            ],
            "repeated": 0,
            "id": 4385
          },
          {
            "timestamp": "2026-02-10 09:22:21,406",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4386
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4387
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4388
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x10\\xbe\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4389
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\xbe\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4390
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00E\\x00P\\x00_\\x00M\\x00S\\x00M\\x00_\\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00.\\x001\\x003\\x002\\x008\\x000\\x00B\\x004\\x000\\x00_\\x009\\x001\\x003\\x000\\x00_\\x004\\x00E\\x002\\x00F\\x00_\\x009\\x007\\x00C\\x00C\\x00_\\x00F\\x00F\\x002\\x00D\\x009\\x00A\\x005\\x00C\\x005\\x007\\x00F\\x004\\x00 \\x00=\\x00 \\x00E\\x00P\\x00_\\x00M\\x00S\\x00M\\x00_\\x00W\\x00a\\x00t\\x00c\\x00h\\x00d\\x00o\\x00g\\x00\\\\x00E\\x008\\x007\\x00_\\x002\\x000\\x00\\\\x00B\\x008\\x006\\x008\\x007\\x002\\x000\\x000\\x000\\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "206"
              }
            ],
            "repeated": 0,
            "id": 4391
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4392
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4393
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4394
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x7be\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4395
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x7be\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4396
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00_\\x00x\\x008\\x006\\x00_\\x00V\\x00C\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "188"
              }
            ],
            "repeated": 0,
            "id": 4397
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4398
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4399
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4400
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x9a\\xbf\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4401
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a\\xbf\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4402
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "174"
              }
            ],
            "repeated": 0,
            "id": 4403
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4404
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4405
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4406
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00H\\xc0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4407
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "H\\xc0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4408
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00L\\x00L\\x00U\\x00S\\x00E\\x00R\\x00S\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 4409
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4410
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4411
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4412
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00~\\xc0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4413
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "~\\xc0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4414
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00T\\x00a\\x00b\\x00l\\x00e\\x001\\x000\\x000\\x00_\\x00x\\x008\\x006\\x00.\\x004\\x00E\\x000\\x00C\\x000\\x005\\x002\\x001\\x00_\\x007\\x00D\\x004\\x00B\\x00_\\x003\\x00B\\x009\\x007\\x00_\\x009\\x00D\\x004\\x00C\\x00_\\x005\\x00A\\x004\\x007\\x00A\\x004\\x00B\\x007\\x00B\\x004\\x00B\\x003\\x00 \\x00=\\x00 \\x00D\\x00i\\x00r\\x00e\\x00c\\x00t\\x00o\\x00r\\x00y\\x00T\\x00a\\x00b\\x00l\\x00e\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "180"
              }
            ],
            "repeated": 0,
            "id": 4415
          },
          {
            "timestamp": "2026-02-10 09:22:21,422",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4416
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4417
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4418
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x002\\xc1\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4419
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2\\xc1\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4420
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00L\\x00o\\x00g\\x00F\\x00i\\x00l\\x00e\\x00L\\x00o\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00M\\x00S\\x00I\\x004\\x009\\x005\\x00d\\x004\\x00.\\x00L\\x00O\\x00G\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 4421
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4422
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4423
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4424
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa2\\xc1\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4425
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa2\\xc1\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4426
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00C\\x00o\\x00d\\x00e\\x00 \\x00=\\x00 \\x00{\\x003\\x002\\x008\\x009\\x007\\x000\\x003\\x00B\\x00-\\x006\\x001\\x00D\\x003\\x00-\\x004\\x002\\x008\\x00B\\x00-\\x00A\\x004\\x009\\x006\\x00-\\x002\\x004\\x00F\\x00F\\x003\\x007\\x00B\\x00C\\x00E\\x003\\x00C\\x006\\x00}\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 4427
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4428
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4429
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4430
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00(\\xc2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4431
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xc2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4432
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00S\\x00t\\x00a\\x00t\\x00e\\x00 \\x00=\\x00 \\x00-\\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4433
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4434
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4435
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4436
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00h\\xc2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4437
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xc2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4438
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00a\\x00c\\x00k\\x00a\\x00g\\x00e\\x00c\\x00o\\x00d\\x00e\\x00C\\x00h\\x00a\\x00n\\x00g\\x00i\\x00n\\x00g\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 4439
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4440
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4441
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4442
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb4\\xc2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4443
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\xc2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4444
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00C\\x00C\\x00E\\x00P\\x00T\\x00E\\x00U\\x00L\\x00A\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4445
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4446
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4447
          },
          {
            "timestamp": "2026-02-10 09:22:21,437",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4448
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xee\\xc2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4449
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xee\\xc2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4450
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00I\\x00C\\x00E\\x00N\\x00S\\x00E\\x00A\\x00C\\x00C\\x00E\\x00P\\x00T\\x00E\\x00D\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 4451
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4452
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4453
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4454
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x002\\xc3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4455
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2\\xc3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4456
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00U\\x00R\\x00R\\x00E\\x00N\\x00T\\x00D\\x00I\\x00R\\x00E\\x00C\\x00T\\x00O\\x00R\\x00Y\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "82"
              }
            ],
            "repeated": 0,
            "id": 4457
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4458
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4459
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4460
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x84\\xc3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4461
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\xc3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4462
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00U\\x00I\\x00L\\x00E\\x00V\\x00E\\x00L\\x00 \\x00=\\x00 \\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4463
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4464
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4465
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4466
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc4\\xc3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4467
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4\\xc3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4468
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00L\\x00I\\x00E\\x00N\\x00T\\x00P\\x00R\\x00O\\x00C\\x00E\\x00S\\x00S\\x00I\\x00D\\x00 \\x00=\\x00 \\x004\\x008\\x008\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4469
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4470
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4471
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4472
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x0e\\xc4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4473
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0e\\xc4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4474
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00R\\x00e\\x00s\\x00t\\x00a\\x00r\\x00t\\x00M\\x00a\\x00n\\x00a\\x00g\\x00e\\x00r\\x00S\\x00e\\x00s\\x00s\\x00i\\x00o\\x00n\\x00K\\x00e\\x00y\\x00 \\x00=\\x00 \\x009\\x00c\\x00c\\x00c\\x000\\x007\\x006\\x00a\\x009\\x007\\x000\\x00f\\x003\\x003\\x004\\x00b\\x00a\\x00e\\x005\\x000\\x00c\\x00b\\x002\\x008\\x004\\x004\\x001\\x007\\x004\\x00e\\x003\\x009\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 4475
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4476
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4477
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4478
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa8\\xc4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4479
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\xc4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4480
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00D\\x00a\\x00t\\x00a\\x00b\\x00a\\x00s\\x00e\\x00 \\x00=\\x00 \\x003\\x000\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 4481
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4482
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4483
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4484
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf0\\xc4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4485
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0\\xc4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4486
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00e\\x00r\\x00s\\x00i\\x00o\\x00n\\x00M\\x00s\\x00i\\x00 \\x00=\\x00 \\x005\\x00.\\x000\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4487
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4488
          },
          {
            "timestamp": "2026-02-10 09:22:21,453",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4489
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4490
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x000\\xc5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4491
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\xc5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4492
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00B\\x00u\\x00i\\x00l\\x00d\\x00 \\x00=\\x00 \\x009\\x006\\x000\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 4493
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4494
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4495
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4496
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00t\\xc5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4497
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t\\xc5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4498
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00P\\x00a\\x00c\\x00k\\x00L\\x00e\\x00v\\x00e\\x00l\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4499
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4500
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4501
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4502
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xba\\xc5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4503
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xba\\xc5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4504
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00P\\x00a\\x00c\\x00k\\x00L\\x00e\\x00v\\x00e\\x00l\\x00M\\x00i\\x00n\\x00o\\x00r\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 4505
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4506
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4507
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4508
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\n\\xc6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4509
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\n\\xc6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4510
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00N\\x00T\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00T\\x00y\\x00p\\x00e\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4511
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4512
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4513
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4514
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00P\\xc6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4515
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\xc6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4516
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 4517
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4518
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4519
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4520
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x94\\xc6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4521
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x94\\xc6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4522
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x006\\x004\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00s\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "104"
              }
            ],
            "repeated": 0,
            "id": 4523
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4524
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4525
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4526
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xfc\\xc6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4527
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc\\xc6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4528
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00W\\x00O\\x00W\\x006\\x004\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "100"
              }
            ],
            "repeated": 0,
            "id": 4529
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4530
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4531
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4532
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00`\\xc7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4533
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "`\\xc7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4534
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00e\\x00m\\x00o\\x00t\\x00e\\x00A\\x00d\\x00m\\x00i\\x00n\\x00T\\x00S\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4535
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4536
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4537
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4538
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa0\\xc7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4539
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xc7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4540
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00e\\x00m\\x00p\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 4541
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4542
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4543
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4544
          },
          {
            "timestamp": "2026-02-10 09:22:21,468",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe8\\xc7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4545
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\\xc7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4546
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00F\\x00i\\x00l\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00 \\x00(\\x00x\\x008\\x006\\x00)\\x00\\\\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 4547
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4548
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4549
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4550
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00v\\xc8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4551
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v\\xc8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4552
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00F\\x00i\\x00l\\x00e\\x00s\\x006\\x004\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 4553
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4554
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4555
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4556
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe4\\xc8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4557
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4\\xc8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4558
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00F\\x00i\\x00l\\x00e\\x00s\\x006\\x004\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00C\\x00o\\x00m\\x00m\\x00o\\x00n\\x00 \\x00F\\x00i\\x00l\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "134"
              }
            ],
            "repeated": 0,
            "id": 4559
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4560
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4561
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4562
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00j\\xc9\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4563
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xc9\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4564
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00R\\x00o\\x00a\\x00m\\x00i\\x00n\\x00g\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "124"
              }
            ],
            "repeated": 0,
            "id": 4565
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4566
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4567
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4568
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe6\\xc9\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4569
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe6\\xc9\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4570
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00a\\x00v\\x00o\\x00r\\x00i\\x00t\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00F\\x00a\\x00v\\x00o\\x00r\\x00i\\x00t\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 4571
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4572
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4573
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4574
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00Z\\xca\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4575
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\xca\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4576
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00N\\x00e\\x00t\\x00H\\x00o\\x00o\\x00d\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00R\\x00o\\x00a\\x00m\\x00i\\x00n\\x00g\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00 \\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "196"
              }
            ],
            "repeated": 0,
            "id": 4577
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4578
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4579
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x1e\\xcb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4580
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1e\\xcb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4581
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00e\\x00r\\x00s\\x00o\\x00n\\x00a\\x00l\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00D\\x00o\\x00c\\x00u\\x00m\\x00e\\x00n\\x00t\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "114"
              }
            ],
            "repeated": 0,
            "id": 4582
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4583
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "5560",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 4584
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4585
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x90\\xcb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4586
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90\\xcb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4587
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00i\\x00n\\x00t\\x00H\\x00o\\x00o\\x00d\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00R\\x00o\\x00a\\x00m\\x00i\\x00n\\x00g\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00P\\x00r\\x00i\\x00n\\x00t\\x00e\\x00r\\x00 \\x00S\\x00h\\x00o\\x00r\\x00t\\x00c\\x00u\\x00t\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "200"
              }
            ],
            "repeated": 0,
            "id": 4588
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4589
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4590
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4591
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00X\\xcc\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4592
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "X\\xcc\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4593
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00e\\x00c\\x00e\\x00n\\x00t\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00R\\x00o\\x00a\\x00m\\x00i\\x00n\\x00g\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00R\\x00e\\x00c\\x00e\\x00n\\x00t\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 4594
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4595
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4596
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4597
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x04\\xcd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4598
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x04\\xcd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4599
          },
          {
            "timestamp": "2026-02-10 09:22:21,484",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00e\\x00n\\x00d\\x00T\\x00o\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00R\\x00o\\x00a\\x00m\\x00i\\x00n\\x00g\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00e\\x00n\\x00d\\x00T\\x00o\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "172"
              }
            ],
            "repeated": 0,
            "id": 4600
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4601
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4602
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4603
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb0\\xcd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4604
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb0\\xcd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4605
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00e\\x00m\\x00p\\x00l\\x00a\\x00t\\x00e\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00l\\x00a\\x00t\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "150"
              }
            ],
            "repeated": 0,
            "id": 4606
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4607
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4608
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4609
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00F\\xce\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4610
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "F\\xce\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4611
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00o\\x00c\\x00a\\x00l\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00A\\x00p\\x00p\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00L\\x00o\\x00c\\x00a\\x00l\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "130"
              }
            ],
            "repeated": 0,
            "id": 4612
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4613
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4614
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4615
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc8\\xce\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4616
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8\\xce\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4617
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00y\\x00P\\x00i\\x00c\\x00t\\x00u\\x00r\\x00e\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00\\\\x00P\\x00i\\x00c\\x00t\\x00u\\x00r\\x00e\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "116"
              }
            ],
            "repeated": 0,
            "id": 4618
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4619
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4620
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4621
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00<\\xcf\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4622
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "<\\xcf\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4623
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00d\\x00m\\x00i\\x00n\\x00T\\x00o\\x00o\\x00l\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00A\\x00d\\x00m\\x00i\\x00n\\x00i\\x00s\\x00t\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x00 \\x00T\\x00o\\x00o\\x00l\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "216"
              }
            ],
            "repeated": 0,
            "id": 4624
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4625
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4626
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4627
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x14\\xd0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4628
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x14\\xd0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4629
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00u\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "184"
              }
            ],
            "repeated": 0,
            "id": 4630
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4631
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4632
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4633
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xcc\\xd0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4634
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcc\\xd0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4635
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00t\\x00a\\x00r\\x00t\\x00M\\x00e\\x00n\\x00u\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00P\\x00r\\x00o\\x00g\\x00r\\x00a\\x00m\\x00D\\x00a\\x00t\\x00a\\x00\\\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00t\\x00a\\x00r\\x00t\\x00 \\x00M\\x00e\\x00n\\x00u\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "154"
              }
            ],
            "repeated": 0,
            "id": 4636
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4637
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4638
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4639
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00f\\xd1\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4640
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "f\\xd1\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4641
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00e\\x00s\\x00k\\x00t\\x00o\\x00p\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00U\\x00s\\x00e\\x00r\\x00s\\x00\\\\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00\\\\x00D\\x00e\\x00s\\x00k\\x00t\\x00o\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "110"
              }
            ],
            "repeated": 0,
            "id": 4642
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4643
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4644
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4645
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd4\\xd1\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4646
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd4\\xd1\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4647
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00o\\x00n\\x00t\\x00s\\x00F\\x00o\\x00l\\x00d\\x00e\\x00r\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00F\\x00o\\x00n\\x00t\\x00s\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 4648
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4649
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4650
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4651
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x000\\xd2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4652
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\xd2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4653
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00G\\x00P\\x00T\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4654
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4655
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4656
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4657
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00j\\xd2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4658
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xd2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4659
          },
          {
            "timestamp": "2026-02-10 09:22:21,500",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00O\\x00L\\x00E\\x00A\\x00d\\x00v\\x00t\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 4660
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4661
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4662
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4663
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xac\\xd2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4664
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\xd2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4665
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00h\\x00e\\x00l\\x00l\\x00A\\x00d\\x00v\\x00t\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4666
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4667
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4668
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4669
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf2\\xd2\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4670
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2\\xd2\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4671
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00A\\x00M\\x00D\\x006\\x004\\x00 \\x00=\\x00 \\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 4672
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4673
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4674
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4675
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00(\\xd3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4676
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xd3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4677
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00x\\x006\\x004\\x00 \\x00=\\x00 \\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 4678
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4679
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4680
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4681
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00Z\\xd3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4682
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Z\\xd3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4683
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00n\\x00t\\x00e\\x00l\\x00 \\x00=\\x00 \\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "48"
              }
            ],
            "repeated": 0,
            "id": 4684
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4685
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4686
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4687
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x8a\\xd3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4688
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a\\xd3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4689
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00h\\x00y\\x00s\\x00i\\x00c\\x00a\\x00l\\x00M\\x00e\\x00m\\x00o\\x00r\\x00y\\x00 \\x00=\\x00 \\x004\\x000\\x009\\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 4690
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4691
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4692
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4693
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd2\\xd3\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4694
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd2\\xd3\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4695
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00V\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00M\\x00e\\x00m\\x00o\\x00r\\x00y\\x00 \\x00=\\x00 \\x004\\x005\\x009\\x008\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4696
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4697
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4698
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4699
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x18\\xd4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4700
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x18\\xd4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4701
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00d\\x00m\\x00i\\x00n\\x00U\\x00s\\x00e\\x00r\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 4702
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4703
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4704
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4705
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00P\\xd4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4706
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "P\\xd4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4707
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00T\\x00r\\x00u\\x00e\\x00A\\x00d\\x00m\\x00i\\x00n\\x00U\\x00s\\x00e\\x00r\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4708
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4709
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4710
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4711
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x96\\xd4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4712
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96\\xd4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4713
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00o\\x00g\\x00o\\x00n\\x00U\\x00s\\x00e\\x00r\\x00 \\x00=\\x00 \\x00A\\x00d\\x00m\\x00i\\x00n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4714
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4715
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4716
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4717
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xd6\\xd4\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4718
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd6\\xd4\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4719
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00s\\x00e\\x00r\\x00S\\x00I\\x00D\\x00 \\x00=\\x00 \\x00S\\x00-\\x001\\x00-\\x005\\x00-\\x002\\x001\\x00-\\x003\\x003\\x001\\x008\\x009\\x004\\x000\\x007\\x003\\x001\\x00-\\x003\\x003\\x007\\x009\\x008\\x001\\x008\\x004\\x000\\x000\\x00-\\x002\\x001\\x004\\x004\\x008\\x004\\x005\\x003\\x005\\x007\\x00-\\x001\\x000\\x000\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "142"
              }
            ],
            "repeated": 0,
            "id": 4720
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4721
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4722
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4723
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00d\\xd5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4724
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\xd5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4725
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00s\\x00e\\x00r\\x00L\\x00a\\x00n\\x00g\\x00u\\x00a\\x00g\\x00e\\x00I\\x00D\\x00 \\x00=\\x00 \\x001\\x000\\x004\\x009\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 4726
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4727
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4728
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4729
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xac\\xd5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4730
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xac\\xd5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4731
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00m\\x00p\\x00u\\x00t\\x00e\\x00r\\x00N\\x00a\\x00m\\x00e\\x00 \\x00=\\x00 \\x00H\\x00O\\x00M\\x00E\\x00-\\x00P\\x00C\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4732
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4733
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4734
          },
          {
            "timestamp": "2026-02-10 09:22:21,515",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4735
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf6\\xd5\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4736
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6\\xd5\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4737
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x00L\\x00a\\x00n\\x00g\\x00u\\x00a\\x00g\\x00e\\x00I\\x00D\\x00 \\x00=\\x00 \\x001\\x000\\x004\\x009\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 4738
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4739
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4740
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4741
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00B\\xd6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4742
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "B\\xd6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4743
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00c\\x00r\\x00e\\x00e\\x00n\\x00X\\x00 \\x00=\\x00 \\x001\\x000\\x002\\x004\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4744
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4745
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4746
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4747
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00|\\xd6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4748
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "|\\xd6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4749
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00c\\x00r\\x00e\\x00e\\x00n\\x00Y\\x00 \\x00=\\x00 \\x007\\x006\\x008\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 4750
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4751
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4752
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4753
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb4\\xd6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4754
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4\\xd6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4755
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00a\\x00p\\x00t\\x00i\\x00o\\x00n\\x00H\\x00e\\x00i\\x00g\\x00h\\x00t\\x00 \\x00=\\x00 \\x002\\x008\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 4756
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4757
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4758
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4759
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf6\\xd6\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4760
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6\\xd6\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4761
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00B\\x00o\\x00r\\x00d\\x00e\\x00r\\x00T\\x00o\\x00p\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 4762
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4763
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4764
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4765
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00.\\xd7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4766
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ".\\xd7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4767
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00B\\x00o\\x00r\\x00d\\x00e\\x00r\\x00S\\x00i\\x00d\\x00e\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4768
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4769
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4770
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4771
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00h\\xd7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4772
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h\\xd7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4773
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00e\\x00x\\x00t\\x00H\\x00e\\x00i\\x00g\\x00h\\x00t\\x00 \\x00=\\x00 \\x001\\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 4774
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4775
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4776
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4777
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa4\\xd7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4778
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4\\xd7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4779
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00e\\x00x\\x00t\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00L\\x00e\\x00a\\x00d\\x00i\\x00n\\x00g\\x00 \\x00=\\x00 \\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 4780
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4781
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4782
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4783
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xf0\\xd7\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4784
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0\\xd7\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4785
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00l\\x00o\\x00r\\x00B\\x00i\\x00t\\x00s\\x00 \\x00=\\x00 \\x003\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4786
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4787
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4788
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4789
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00*\\xd8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4790
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*\\xd8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4791
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00T\\x00C\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4792
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4793
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4794
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4795
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00d\\xd8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4796
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\xd8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4797
          },
          {
            "timestamp": "2026-02-10 09:22:21,531",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00=\\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 4798
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4799
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4800
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4801
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa0\\xd8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4802
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa0\\xd8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4803
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00a\\x00t\\x00e\\x00 \\x00=\\x00 \\x001\\x000\\x00.\\x000\\x002\\x00.\\x002\\x000\\x002\\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 4804
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4805
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4806
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4807
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe0\\xd8\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4808
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe0\\xd8\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4809
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00N\\x00e\\x00t\\x00A\\x00s\\x00s\\x00e\\x00m\\x00b\\x00l\\x00y\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x004\\x00.\\x008\\x00.\\x009\\x000\\x003\\x007\\x00.\\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "98"
              }
            ],
            "repeated": 0,
            "id": 4810
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4811
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4812
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4813
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00B\\xd9\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4814
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "B\\xd9\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4815
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00W\\x00i\\x00n\\x003\\x002\\x00A\\x00s\\x00s\\x00e\\x00m\\x00b\\x00l\\x00y\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x001\\x000\\x00.\\x000\\x00.\\x001\\x009\\x000\\x004\\x001\\x00.\\x003\\x006\\x003\\x006\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 4816
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4817
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4818
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4819
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb2\\xd9\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4820
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2\\xd9\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4821
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00e\\x00d\\x00i\\x00r\\x00e\\x00c\\x00t\\x00e\\x00d\\x00D\\x00l\\x00l\\x00S\\x00u\\x00p\\x00p\\x00o\\x00r\\x00t\\x00 \\x00=\\x00 \\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 4822
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4823
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4824
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4825
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\xda\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4826
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xda\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4827
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00M\\x00s\\x00i\\x00R\\x00u\\x00n\\x00n\\x00i\\x00n\\x00g\\x00E\\x00l\\x00e\\x00v\\x00a\\x00t\\x00e\\x00d\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4828
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4829
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4830
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4831
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00J\\xda\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4832
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "J\\xda\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4833
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00i\\x00v\\x00i\\x00l\\x00e\\x00g\\x00e\\x00d\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 4834
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4835
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4836
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4837
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x84\\xda\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4838
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x84\\xda\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4839
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00S\\x00E\\x00R\\x00N\\x00A\\x00M\\x00E\\x00 \\x00=\\x00 \\x00A\\x00d\\x00m\\x00i\\x00n\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 4840
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4841
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4842
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4843
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc2\\xda\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4844
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc2\\xda\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4845
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 4846
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4847
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4848
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4849
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x002\\xdb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4850
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "2\\xdb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4851
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00O\\x00r\\x00i\\x00g\\x00i\\x00n\\x00a\\x00l\\x00D\\x00a\\x00t\\x00a\\x00b\\x00a\\x00s\\x00e\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00E\\x008\\x007\\x00.\\x002\\x000\\x00_\\x00C\\x00h\\x00e\\x00c\\x00k\\x00P\\x00o\\x00i\\x00n\\x00t\\x00V\\x00P\\x00N\\x00.\\x00m\\x00s\\x00i\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 4852
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4853
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4854
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4855
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xb6\\xdb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4856
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6\\xdb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4857
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00U\\x00I\\x00L\\x00e\\x00v\\x00e\\x00l\\x00 \\x00=\\x00 \\x003\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 4858
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4859
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4860
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4861
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xea\\xdb\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4862
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xea\\xdb\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4863
          },
          {
            "timestamp": "2026-02-10 09:22:21,547",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00A\\x00C\\x00T\\x00I\\x00O\\x00N\\x00 \\x00=\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 4864
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4865
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4866
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4867
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00(\\xdc\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4868
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "(\\xdc\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4869
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00_\\x00S\\x00T\\x00A\\x00R\\x00T\\x00 \\x00=\\x00 \\x003\\x000\\x005\\x007\\x001\\x008\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4870
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4871
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4872
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4873
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00r\\xdc\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4874
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "r\\xdc\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4875
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00F\\x00W\\x00_\\x00D\\x00O\\x00S\\x00_\\x00D\\x00E\\x00V\\x00I\\x00C\\x00E\\x00_\\x00C\\x00 \\x00=\\x00 \\x00\\\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00\\\\x00H\\x00a\\x00r\\x00d\\x00d\\x00i\\x00s\\x00k\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x002\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 4876
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4877
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4878
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4879
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xe2\\xdc\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4880
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2\\xdc\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4881
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00L\\x00o\\x00a\\x00d\\x00T\\x00e\\x00s\\x00t\\x00G\\x00U\\x00I\\x00.\\x002\\x00C\\x000\\x00E\\x00A\\x00E\\x006\\x007\\x00_\\x007\\x00A\\x001\\x00D\\x00_\\x004\\x003\\x00B\\x00F\\x00_\\x00B\\x003\\x00D\\x009\\x00_\\x004\\x007\\x006\\x000\\x009\\x008\\x00D\\x00F\\x006\\x000\\x00F\\x005\\x00 \\x00=\\x00 \\x00N\\x00O\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "136"
              }
            ],
            "repeated": 0,
            "id": 4882
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4883
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4884
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4885
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00j\\xdd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4886
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "j\\xdd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4887
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00R\\x00O\\x00O\\x00T\\x00D\\x00R\\x00I\\x00V\\x00E\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 4888
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4889
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4890
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4891
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa6\\xdd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4892
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa6\\xdd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4893
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00C\\x00o\\x00s\\x00t\\x00i\\x00n\\x00g\\x00C\\x00o\\x00m\\x00p\\x00l\\x00e\\x00t\\x00e\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "68"
              }
            ],
            "repeated": 0,
            "id": 4894
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4895
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4896
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4897
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xea\\xdd\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4898
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xea\\xdd\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4899
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00O\\x00U\\x00R\\x00C\\x00E\\x00D\\x00I\\x00R\\x00 \\x00=\\x00 \\x00C\\x00:\\x00\\\\x00T\\x00e\\x00m\\x00p\\x00\\\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 4900
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4901
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4902
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4903
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x000\\xde\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4904
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0\\xde\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4905
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00S\\x00o\\x00u\\x00r\\x00c\\x00e\\x00d\\x00i\\x00r\\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00=\\x00 \\x00{\\x009\\x003\\x008\\x00B\\x006\\x008\\x000\\x004\\x00-\\x007\\x007\\x00B\\x00B\\x00-\\x004\\x00B\\x005\\x003\\x00-\\x009\\x007\\x002\\x00A\\x00-\\x002\\x00E\\x00E\\x001\\x008\\x000\\x00F\\x004\\x005\\x002\\x005\\x000\\x00}\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "144"
              }
            ],
            "repeated": 0,
            "id": 4906
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4907
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4908
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4909
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xc0\\xde\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4910
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc0\\xde\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4911
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00O\\x00u\\x00t\\x00O\\x00f\\x00D\\x00i\\x00s\\x00k\\x00S\\x00p\\x00a\\x00c\\x00e\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 4912
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4913
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4914
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4915
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x02\\xdf\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4916
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\xdf\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4917
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00O\\x00u\\x00t\\x00O\\x00f\\x00N\\x00o\\x00R\\x00b\\x00D\\x00i\\x00s\\x00k\\x00S\\x00p\\x00a\\x00c\\x00e\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "74"
              }
            ],
            "repeated": 0,
            "id": 4918
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4919
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4920
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4921
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00L\\xdf\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4922
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "L\\xdf\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4923
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00S\\x00p\\x00a\\x00c\\x00e\\x00A\\x00v\\x00a\\x00i\\x00l\\x00a\\x00b\\x00l\\x00e\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 4924
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4925
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4926
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4927
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\xa8\\xdf\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4928
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa8\\xdf\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4929
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00S\\x00p\\x00a\\x00c\\x00e\\x00R\\x00e\\x00q\\x00u\\x00i\\x00r\\x00e\\x00d\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "90"
              }
            ],
            "repeated": 0,
            "id": 4930
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4931
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4932
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4933
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x02\\xe0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4934
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02\\xe0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4935
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00S\\x00p\\x00a\\x00c\\x00e\\x00R\\x00e\\x00m\\x00a\\x00i\\x00n\\x00i\\x00n\\x00g\\x00 \\x00=\\x00 \\x000\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "92"
              }
            ],
            "repeated": 0,
            "id": 4936
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4937
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4938
          },
          {
            "timestamp": "2026-02-10 09:22:21,562",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4939
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00^\\xe0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4940
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "^\\xe0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4941
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00S\\x00T\\x00A\\x00L\\x00L\\x00L\\x00E\\x00V\\x00E\\x00L\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 4942
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4943
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4944
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4945
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x9c\\xe0\r\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4946
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9c\\xe0\r\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4947
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00I\\x00N\\x00C\\x00R\\x00E\\x00A\\x00S\\x00E\\x00N\\x00E\\x00T\\x00W\\x00O\\x00R\\x00K\\x00F\\x00I\\x00L\\x00T\\x00E\\x00R\\x00S\\x00 \\x00=\\x00 \\x00Y\\x00E\\x00S\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "86"
              }
            ],
            "repeated": 0,
            "id": 4948
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4949
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4950
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4951
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x0e\\x00\\x00\\x00\\x00\\x00\\xf2\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4952
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2\\x00\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4953
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00"
              },
              {
                "name": "Length",
                "value": "1218"
              }
            ],
            "repeated": 0,
            "id": 4954
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4955
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4956
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4957
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\xb4%\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4958
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4%\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4959
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00|\\x00[\\x00"
              },
              {
                "name": "Length",
                "value": "1212"
              }
            ],
            "repeated": 0,
            "id": 4960
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4961
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4962
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4963
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00pJ\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4964
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "pJ\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4965
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00"
              },
              {
                "name": "Length",
                "value": "1210"
              }
            ],
            "repeated": 0,
            "id": 4966
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4967
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4968
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4969
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00*o\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4970
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "*o\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4971
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00|\\x00"
              },
              {
                "name": "Length",
                "value": "1214"
              }
            ],
            "repeated": 0,
            "id": 4972
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4973
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4974
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4975
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\xe8\\x93\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4976
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe8\\x93\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4977
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00|\\x00[\\x00"
              },
              {
                "name": "Length",
                "value": "1212"
              }
            ],
            "repeated": 0,
            "id": 4978
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4979
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4980
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4981
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\xa4\\xb8\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4982
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4\\xb8\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4983
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00"
              },
              {
                "name": "Length",
                "value": "1216"
              }
            ],
            "repeated": 0,
            "id": 4984
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4985
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4986
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4987
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00d\\xdd\\x0e\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4988
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "d\\xdd\\x0e\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4989
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00|\\x00"
              },
              {
                "name": "Length",
                "value": "1214"
              }
            ],
            "repeated": 0,
            "id": 4990
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4991
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4992
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4993
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\"\\x02\\x0f\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4994
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\x02\\x0f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4995
          },
          {
            "timestamp": "2026-02-10 09:22:21,578",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00[\\x00U\\x00P\\x00D\\x00A\\x00T\\x00E\\x00K\\x00E\\x00Y\\x00F\\x00I\\x00L\\x00E\\x00S\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00I\\x00N\\x00T\\x00E\\x00G\\x00R\\x00I\\x00T\\x00Y\\x00_\\x00P\\x00E\\x00M\\x00=\\x00]\\x00]\\x00"
              },
              {
                "name": "Length",
                "value": "1216"
              }
            ],
            "repeated": 0,
            "id": 4996
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 4997
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 4998
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x07890000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4999
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\xe2&\\x0f\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5000
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe2&\\x0f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5001
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "D\\x009\\x007\\x004\\x00A\\x00]\\x00]\\x00|\\x00[\\x00[\\x00R\\x00U\\x00N\\x00H\\x00E\\x00L\\x00P\\x00E\\x00R\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00C\\x00O\\x00D\\x00E\\x00_\\x00T\\x00E\\x00M\\x00P\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00P\\x00R\\x00O\\x00D\\x00U\\x00C\\x00T\\x00C\\x00O\\x00D\\x00E\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00I\\x00S\\x00C\\x00O\\x00N\\x00N\\x00E\\x00C\\x00T\\x00E\\x00D\\x00P\\x00O\\x00L\\x00I\\x00C\\x00Y\\x00=\\x00]\\x00]\\x00|\\x00[\\x00[\\x00D\\x00A\\x00T\\x00A\\x00B\\x00A\\x00S\\x00E\\x00=\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00I\\x00n\\x00s\\x00t\\x00a\\x00l\\x00l\\x00e\\x00r\\x00\\\\x004\\x00a\\x007\\x009\\x006\\x00.\\x00m\\x00s\\x00i\\x00]\\x00]\\x00|\\x00[\\x00"
              },
              {
                "name": "Length",
                "value": "1290"
              }
            ],
            "repeated": 0,
            "id": 5002
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 5003
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 5004
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077d0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 5005
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\xec+\\x0f\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5006
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xec+\\x0f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5007
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "P\\x00r\\x00o\\x00p\\x00e\\x00r\\x00t\\x00y\\x00(\\x00S\\x00)\\x00:\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00T\\x00o\\x00B\\x00e\\x00R\\x00e\\x00g\\x00i\\x00s\\x00t\\x00e\\x00r\\x00e\\x00d\\x00 \\x00=\\x00 \\x001\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 5008
          },
          {
            "timestamp": "2026-02-10 09:22:21,593",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 5009
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 5010
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "1652",
            "caller": "0x75a08de2",
            "parentcaller": "0x75a08da5",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 5011
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "1652",
            "caller": "0x759f7303",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x961\\x0f\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5012
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "1652",
            "caller": "0x759f7282",
            "parentcaller": "0x72b61865",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x961\\x0f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5013
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "1652",
            "caller": "0x759e944c",
            "parentcaller": "0x72b619a0",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000103",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Temp\\MSI495d4.LOG"
              },
              {
                "name": "Buffer",
                "value": "=\\x00=\\x00=\\x00 \\x00L\\x00o\\x00g\\x00g\\x00i\\x00n\\x00g\\x00 \\x00s\\x00t\\x00o\\x00p\\x00p\\x00e\\x00d\\x00:\\x00 \\x001\\x000\\x00.\\x000\\x002\\x00.\\x002\\x000\\x002\\x006\\x00 \\x00 \\x001\\x002\\x00:\\x002\\x002\\x00:\\x002\\x001\\x00 \\x00=\\x00=\\x00=\\x00\r\\x00\n\\x00"
              },
              {
                "name": "Length",
                "value": "94"
              }
            ],
            "repeated": 0,
            "id": 5014
          },
          {
            "timestamp": "2026-02-10 09:22:21,609",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b619f4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 5015
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "4540",
            "caller": "0x755a187d",
            "parentcaller": "0x755e05ca",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080064"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 1,
            "id": 5016
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x755a32f0"
              }
            ],
            "repeated": 0,
            "id": 5017
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x7657d13e",
            "parentcaller": "0x72b41de6",
            "category": "device",
            "api": "NtPowerInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "InformationLevel",
                "value": "44"
              },
              {
                "name": "InputBuffer",
                "value": "`\\x04\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 5018
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x72b41df2",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5019
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b41e23",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5020
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x72b41ca4",
            "parentcaller": "0x72b41cec",
            "category": "misc",
            "api": "SystemParametersInfoW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Action",
                "value": "0x00000010"
              },
              {
                "name": "uiParam",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5021
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x72b41cb9",
            "parentcaller": "0x72b41cec",
            "category": "misc",
            "api": "SystemParametersInfoW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Action",
                "value": "0x00000011"
              },
              {
                "name": "uiParam",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5022
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75c071fc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5023
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759edd70",
            "parentcaller": "0x72b767b6",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 1,
            "id": 5024
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759f1c1d",
            "parentcaller": "0x7653f804",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75180000"
              },
              {
                "name": "FunctionName",
                "value": "CoUninitialize"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x75547fd0"
              }
            ],
            "repeated": 0,
            "id": 5025
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759e917f",
            "parentcaller": "0x75546a20",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "oleaut32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x75e30000"
              }
            ],
            "repeated": 0,
            "id": 5026
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x72b52ecd",
            "parentcaller": "0x72b60144",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5027
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x76fbb6b6",
            "parentcaller": "0x72b6014e",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1652"
              }
            ],
            "repeated": 0,
            "id": 5028
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75bed5f4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d0"
              }
            ],
            "repeated": 0,
            "id": 5029
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x759eab1a",
            "parentcaller": "0x75bed676",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              }
            ],
            "repeated": 0,
            "id": 5030
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x751545ae",
            "parentcaller": "0x7515442c",
            "category": "misc",
            "api": "GetKeyboardLayout",
            "status": true,
            "return": "0x04090409",
            "arguments": [
              {
                "name": "KeyboardLayout",
                "value": "0x00000409"
              },
              {
                "name": "LanguageName",
                "value": "English (United States)"
              }
            ],
            "repeated": 0,
            "id": 5031
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "1652",
            "caller": "0x76fbb6d9",
            "parentcaller": "0x72b6014e",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5032
          },
          {
            "timestamp": "2026-02-10 09:22:21,625",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "shell32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x75f60000"
              }
            ],
            "repeated": 0,
            "id": 5033
          },
          {
            "timestamp": "2026-02-10 09:22:21,656",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 3,
            "id": 5034
          },
          {
            "timestamp": "2026-02-10 09:22:21,656",
            "thread_id": "4884",
            "caller": "0x003b4e5b",
            "parentcaller": "0x003b5348",
            "category": "misc",
            "api": "MsiInstallProductW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "PackagePath",
                "value": "C:\\Temp\\E87.20_CheckPointVPN.msi"
              },
              {
                "name": "CommandLine",
                "value": " ACCEPTEULA=1  LicenseAccepted=1 "
              }
            ],
            "repeated": 0,
            "id": 5035
          },
          {
            "timestamp": "2026-02-10 09:22:21,656",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5036
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4540",
            "caller": "0x75bd0f20",
            "parentcaller": "0x75bc117e",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5037
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4540",
            "caller": "0x75bc1284",
            "parentcaller": "0x75bc121d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 5038
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76520000"
              }
            ],
            "repeated": 0,
            "id": 5039
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "kernelbase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x758d0000"
              }
            ],
            "repeated": 0,
            "id": 5040
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f4"
              }
            ],
            "repeated": 0,
            "id": 5041
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x075f0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5042
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003fc"
              }
            ],
            "repeated": 0,
            "id": 5043
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5044
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5045
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 5046
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 5047
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 5048
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5049
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5050
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 5051
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 5052
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 5053
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 5054
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 5055
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 5056
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 5057
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 5058
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 5059
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 5060
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 5061
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              }
            ],
            "repeated": 0,
            "id": 5062
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5063
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5064
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000364"
              }
            ],
            "repeated": 0,
            "id": 5065
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              }
            ],
            "repeated": 0,
            "id": 5066
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 5067
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5068
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5069
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 5070
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 5071
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5072
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5073
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 5074
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 5075
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5076
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5077
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5078
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5079
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 5080
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 5081
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000033c"
              }
            ],
            "repeated": 0,
            "id": 5082
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 5083
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 5084
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 5085
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 5086
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 5087
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 5088
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 5089
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 5090
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 5091
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 5092
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 5093
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 5094
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 5095
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 5096
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5097
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5098
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 5099
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 5100
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 5101
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 5102
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 5103
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x077b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00014000"
              }
            ],
            "repeated": 0,
            "id": 5104
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5105
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03380000"
              },
              {
                "name": "RegionSize",
                "value": "0x00015000"
              }
            ],
            "repeated": 0,
            "id": 5106
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 5107
          },
          {
            "timestamp": "2026-02-10 09:22:21,672",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x031b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00009000"
              }
            ],
            "repeated": 0,
            "id": 5108
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5109
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5110
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03190000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              }
            ],
            "repeated": 0,
            "id": 5111
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 5112
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5113
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5114
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 5115
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 5116
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 5117
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 5118
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 5119
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 5120
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 5121
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 5122
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5123
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5124
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 5125
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 5126
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 5127
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 5128
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 5129
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 5130
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5131
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5132
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 5133
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 5134
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 5135
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000200"
              }
            ],
            "repeated": 0,
            "id": 5136
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5137
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5138
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 5139
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x06250000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5140
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              }
            ],
            "repeated": 0,
            "id": 5141
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 5142
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 5143
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 5144
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 5145
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e4"
              }
            ],
            "repeated": 0,
            "id": 5146
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 5147
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e0"
              }
            ],
            "repeated": 0,
            "id": 5148
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              }
            ],
            "repeated": 0,
            "id": 5149
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              }
            ],
            "repeated": 0,
            "id": 5150
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5151
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000c0"
              }
            ],
            "repeated": 0,
            "id": 5152
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c4"
              }
            ],
            "repeated": 0,
            "id": 5153
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c0"
              }
            ],
            "repeated": 0,
            "id": 5154
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000188"
              }
            ],
            "repeated": 0,
            "id": 5155
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000018c"
              }
            ],
            "repeated": 0,
            "id": 5156
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000190"
              }
            ],
            "repeated": 0,
            "id": 5157
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000194"
              }
            ],
            "repeated": 0,
            "id": 5158
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000198"
              }
            ],
            "repeated": 0,
            "id": 5159
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001a0"
              }
            ],
            "repeated": 0,
            "id": 5160
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000019c"
              }
            ],
            "repeated": 0,
            "id": 5161
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000168"
              }
            ],
            "repeated": 0,
            "id": 5162
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000016c"
              }
            ],
            "repeated": 0,
            "id": 5163
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000164"
              }
            ],
            "repeated": 0,
            "id": 5164
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5165
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000160"
              }
            ],
            "repeated": 0,
            "id": 5166
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000158"
              }
            ],
            "repeated": 0,
            "id": 5167
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000015c"
              }
            ],
            "repeated": 0,
            "id": 5168
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000154"
              }
            ],
            "repeated": 0,
            "id": 5169
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000150"
              }
            ],
            "repeated": 0,
            "id": 5170
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000014c"
              }
            ],
            "repeated": 0,
            "id": 5171
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x76f50000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x76faf560"
              }
            ],
            "repeated": 0,
            "id": 5172
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 5173
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000148"
              }
            ],
            "repeated": 0,
            "id": 5174
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000130"
              }
            ],
            "repeated": 0,
            "id": 5175
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000134"
              }
            ],
            "repeated": 0,
            "id": 5176
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000138"
              }
            ],
            "repeated": 0,
            "id": 5177
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000013c"
              }
            ],
            "repeated": 0,
            "id": 5178
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000140"
              }
            ],
            "repeated": 0,
            "id": 5179
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000144"
              }
            ],
            "repeated": 0,
            "id": 5180
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000124"
              }
            ],
            "repeated": 0,
            "id": 5181
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000010c"
              }
            ],
            "repeated": 0,
            "id": 5182
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000110"
              }
            ],
            "repeated": 0,
            "id": 5183
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000114"
              }
            ],
            "repeated": 0,
            "id": 5184
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000118"
              }
            ],
            "repeated": 0,
            "id": 5185
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000011c"
              }
            ],
            "repeated": 0,
            "id": 5186
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000120"
              }
            ],
            "repeated": 0,
            "id": 5187
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000012c"
              }
            ],
            "repeated": 0,
            "id": 5188
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000128"
              }
            ],
            "repeated": 0,
            "id": 5189
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000108"
              }
            ],
            "repeated": 0,
            "id": 5190
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000c4"
              }
            ],
            "repeated": 0,
            "id": 5191
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000c8"
              }
            ],
            "repeated": 0,
            "id": 5192
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000dc"
              }
            ],
            "repeated": 0,
            "id": 5193
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000d8"
              }
            ],
            "repeated": 0,
            "id": 5194
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e0"
              }
            ],
            "repeated": 0,
            "id": 5195
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000110"
              }
            ],
            "repeated": 0,
            "id": 5196
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000010c"
              }
            ],
            "repeated": 0,
            "id": 5197
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x073bd000"
              },
              {
                "name": "RegionSize",
                "value": "0x0001a000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5198
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x0341e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5199
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03476000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5200
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03482000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5201
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x03417000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5202
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000ac"
              }
            ],
            "repeated": 0,
            "id": 5203
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 5204
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a4"
              }
            ],
            "repeated": 0,
            "id": 5205
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000088"
              }
            ],
            "repeated": 0,
            "id": 5206
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000009c"
              }
            ],
            "repeated": 0,
            "id": 5207
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a0"
              }
            ],
            "repeated": 0,
            "id": 5208
          },
          {
            "timestamp": "2026-02-10 09:22:21,687",
            "thread_id": "4884",
            "caller": "0x003b7de8",
            "parentcaller": "0x003b94a0",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5209
          }
        ],
        "threads": [
          "4884",
          "5084",
          "1652",
          "4536",
          "4540",
          "4544",
          "5560"
        ],
        "environ": {
          "UserName": "Admin",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "\"C:\\Windows\\system32\\msiexec.exe\" /I \"C:\\Temp\\E87.20_CheckPointVPN.msi\" /qb ACCEPTEULA=1 LicenseAccepted=1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x003b0000",
          "MainExeSize": "0x00012000",
          "Bitness": "32-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 740,
        "process_name": "svchost.exe",
        "parent_id": 600,
        "module_path": "C:\\Windows\\System32\\svchost.exe",
        "first_seen": "2026-02-10 09:21:59,562",
        "calls": [
          {
            "timestamp": "2026-02-10 09:22:03,547",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:22:03,812",
            "thread_id": "3968",
            "caller": "0x7ffee10bacfe",
            "parentcaller": "0x7ffee32b9f03",
            "category": "services",
            "api": "StartServiceW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ServiceHandle",
                "value": "0x26c84c12fa0"
              },
              {
                "name": "ServiceName",
                "value": "msiserver"
              },
              {
                "name": "Arguments",
                "value": []
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:22:08,843",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000a8c"
              },
              {
                "name": "SourceHandle",
                "value": "0x000007ec"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e5c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:22:08,843",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000eb8"
              },
              {
                "name": "SourceHandle",
                "value": "0x000007ec"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e5c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "744",
            "caller": "0x7ff6305618fe",
            "parentcaller": "0x7ff6305615e9",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x00000a8c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee32adfb0"
              },
              {
                "name": "Parameter",
                "value": "0x26c84cc7660"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000004"
              },
              {
                "name": "ThreadId",
                "value": "4976"
              },
              {
                "name": "ProcessId",
                "value": "740"
              }
            ],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "744",
            "caller": "0x7ff6305618fe",
            "parentcaller": "0x7ff6305615e9",
            "category": "threading",
            "api": "NtResumeThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000a8c"
              },
              {
                "name": "SuspendCount",
                "value": "1"
              },
              {
                "name": "ThreadId",
                "value": "4976"
              },
              {
                "name": "ProcessId",
                "value": "740"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "4976",
            "caller": "0x7ff630563baa",
            "parentcaller": "0x7ff630564126",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\umpnpmgr.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf740000"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "4976",
            "caller": "0x7ff630564340",
            "parentcaller": "0x00000000",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "4976",
            "caller": "0x7ff630564340",
            "parentcaller": "0x00000000",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x00000f0c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffedf743580"
              },
              {
                "name": "Parameter",
                "value": "0x00000000"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "3704"
              },
              {
                "name": "ProcessId",
                "value": "740"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "3704",
            "caller": "0x7ffee1425914",
            "parentcaller": "0x7ffee1424ac1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f2c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMNotify"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "2872",
            "caller": "0x7ffee34cfc9c",
            "parentcaller": "0x7ffee34cf7b0",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e8c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "2872",
            "caller": "0x7ffee3484d42",
            "parentcaller": "0x7ffee3484aaa",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00014000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:22:10,031",
            "thread_id": "2872",
            "caller": "0x7ffee3484d42",
            "parentcaller": "0x7ffee3484aaa",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "c:\\windows\\system32\\DEVRTL"
              },
              {
                "name": "DllBase",
                "value": "0x7ffec7f70000"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a522",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f3c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00ad7e800"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a0fc",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfd4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10fd7fd",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfd4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10fd832",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfd4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedf74c595",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000f38"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f3c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f3c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00ad7e9e0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10bfcb5",
            "parentcaller": "0x7ffee10bfacc",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:22:10,078",
            "thread_id": "2872",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e9666",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000ce8"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\""
              },
              {
                "name": "DllPath",
                "value": ""
              },
              {
                "name": "ProcessId",
                "value": "140728898423700"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:22:10,156",
            "thread_id": "2872",
            "caller": "0x7ffee10e9666",
            "parentcaller": "0x7ffee167cec4",
            "category": "process",
            "api": "CreateProcessInternalW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ApplicationName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\""
              },
              {
                "name": "CreationFlags",
                "value": "0x00000008",
                "pretty_value": "DETACHED_PROCESS"
              },
              {
                "name": "ProcessId",
                "value": "2964"
              },
              {
                "name": "ThreadId",
                "value": "348"
              },
              {
                "name": "ProcessHandle",
                "value": "0x00000ce8"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:22:10,734",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000f44"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000f40"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f44"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedf7473ad",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000f3c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e88"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedf7485d3",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006c8"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f4c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "3968",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "3968",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a522",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "FH\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "3968",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00b4feec0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:22:11,750",
            "thread_id": "3968",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a0fc",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:22:11,765",
            "thread_id": "3968",
            "caller": "0x7ffee10fd7fd",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:22:11,765",
            "thread_id": "3968",
            "caller": "0x7ffee10fd832",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:22:11,765",
            "thread_id": "3968",
            "caller": "0x7ffee10bfcb5",
            "parentcaller": "0x7ffee10bfacc",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e80"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:22:11,765",
            "thread_id": "3968",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e9666",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000e80"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\""
              },
              {
                "name": "DllPath",
                "value": ""
              },
              {
                "name": "ProcessId",
                "value": "140728898425380"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:22:11,812",
            "thread_id": "3968",
            "caller": "0x7ffee10e9666",
            "parentcaller": "0x7ffee167cec4",
            "category": "process",
            "api": "CreateProcessInternalW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ApplicationName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\""
              },
              {
                "name": "CreationFlags",
                "value": "0x00000008",
                "pretty_value": "DETACHED_PROCESS"
              },
              {
                "name": "ProcessId",
                "value": "4644"
              },
              {
                "name": "ThreadId",
                "value": "4632"
              },
              {
                "name": "ProcessHandle",
                "value": "0x00000ef4"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000e80"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "324",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a48"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "324",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "324",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "324",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x26c83a40000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-18.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:22:12,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000a48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f54"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f58"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f48"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f50"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f50"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:22:12,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f54"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f58"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000a48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e84"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:22:12,609",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f50"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f48"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f54"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "5188",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f48"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f44"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f50"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000e84"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f44"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:22:12,625",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000a48"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a48"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f5c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:22:12,734",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:22:12,781",
            "thread_id": "5252",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000a48"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:22:12,843",
            "thread_id": "3968",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:22:12,843",
            "thread_id": "3968",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a522",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mV\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:22:12,843",
            "thread_id": "3968",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00b4feec0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:22:12,843",
            "thread_id": "3968",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a0fc",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:22:12,859",
            "thread_id": "3968",
            "caller": "0x7ffee10fd7fd",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:22:12,859",
            "thread_id": "3968",
            "caller": "0x7ffee10fd832",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb4V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "3968",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000f64"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000f60"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f64"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000b2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:22:13,015",
            "thread_id": "912",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e89f3",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000e70"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000b2c"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\system32\\DllHost.exe"
              },
              {
                "name": "CommandLine",
                "value": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "DllPath",
                "value": ""
              },
              {
                "name": "ProcessId",
                "value": "140728898426316"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:22:13,093",
            "thread_id": "912",
            "caller": "0x7ffee10e89f3",
            "parentcaller": "0x7ffee167de30",
            "category": "process",
            "api": "CreateProcessInternalW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ApplicationName",
                "value": "C:\\Windows\\system32\\DllHost.exe"
              },
              {
                "name": "CommandLine",
                "value": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000410",
                "pretty_value": "CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              },
              {
                "name": "ThreadId",
                "value": "5584"
              },
              {
                "name": "ProcessHandle",
                "value": "0x00000e70"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000b2c"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:22:13,312",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f60"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:22:13,547",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:22:13,734",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a522",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5Y\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000e70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00af7e9c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10e3013",
            "parentcaller": "0x7ffec7f7a0fc",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0eZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10fd7fd",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0eZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10fd832",
            "parentcaller": "0x7ffec7f7a719",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0eZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedf74c595",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e70"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10fc386",
            "parentcaller": "0x7ffee10fc25e",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000e70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa00af7eba0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10bfcb5",
            "parentcaller": "0x7ffee10bfacc",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:22:13,750",
            "thread_id": "912",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e9666",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000f24"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\""
              },
              {
                "name": "DllPath",
                "value": ""
              },
              {
                "name": "ProcessId",
                "value": "140728898422356"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:22:13,812",
            "thread_id": "912",
            "caller": "0x7ffee10e9666",
            "parentcaller": "0x7ffee167cec4",
            "category": "process",
            "api": "CreateProcessInternalW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ApplicationName",
                "value": "C:\\Windows\\system32\\DrvInst.exe"
              },
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\""
              },
              {
                "name": "CreationFlags",
                "value": "0x00000008",
                "pretty_value": "DETACHED_PROCESS"
              },
              {
                "name": "ProcessId",
                "value": "1620"
              },
              {
                "name": "ThreadId",
                "value": "3424"
              },
              {
                "name": "ProcessHandle",
                "value": "0x00000f24"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:22:14,984",
            "thread_id": "3968",
            "caller": "0x7ffee10bacfe",
            "parentcaller": "0x7ffee32b9f03",
            "category": "services",
            "api": "StartServiceW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ServiceHandle",
                "value": "0x26c84c2f560"
              },
              {
                "name": "ServiceName",
                "value": "WSearch"
              },
              {
                "name": "Arguments",
                "value": []
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:22:15,515",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f04"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:22:15,515",
            "thread_id": "912",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f44"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:22:15,515",
            "thread_id": "912",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:22:16,140",
            "thread_id": "3968",
            "caller": "0x7ffee10bacfe",
            "parentcaller": "0x7ffee32b9f03",
            "category": "services",
            "api": "StartServiceW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ServiceHandle",
                "value": "0x26c84742120"
              },
              {
                "name": "ServiceName",
                "value": "WSearch"
              },
              {
                "name": "Arguments",
                "value": []
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:22:16,906",
            "thread_id": "5188",
            "caller": "0x7ffee08574d2",
            "parentcaller": "0x7ffee085739e",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f44"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:22:18,953",
            "thread_id": "3968",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000e70"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000e88"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e70"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:22:19,000",
            "thread_id": "3968",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000a5c"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:22:20,765",
            "thread_id": "3968",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee2f66d2f",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f24"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:22:20,765",
            "thread_id": "3968",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000884"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000079c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f44"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:22:23,547",
            "thread_id": "5188",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f4c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:22:31,859",
            "thread_id": "3968",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee10be6a1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 1,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:22:33,547",
            "thread_id": "632",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e84"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "5188",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee2f66d2f",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e84"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "5188",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "5188",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "5188",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "5188",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x26c83a40000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-18.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f34"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f30"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:22:42,562",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:42,578",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000a84"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000844"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000844"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000844"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000844"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000844"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000844"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ea0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:42,593",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f58"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f58"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000e70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:42,609",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:43,547",
            "thread_id": "5188",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:44,031",
            "thread_id": "2872",
            "caller": "0x7ffee10bacfe",
            "parentcaller": "0x7ffee32b9f03",
            "category": "services",
            "api": "StartServiceW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ServiceHandle",
                "value": "0x26c84c12fa0"
              },
              {
                "name": "ServiceName",
                "value": "WSearch"
              },
              {
                "name": "Arguments",
                "value": []
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:44,328",
            "thread_id": "2872",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000a84"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:44,328",
            "thread_id": "2872",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f44"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:44,328",
            "thread_id": "2872",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:53,562",
            "thread_id": "632",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f38"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:23:00,015",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000ce8"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000079c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:23:00,015",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000079c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:23:03,547",
            "thread_id": "3968",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ce8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:23:09,000",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9ab182",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x00000e80"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000079c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000ce8"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:23:09,078",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 1,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:23:09,093",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000ec8"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:23:09,093",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 1,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:23:09,140",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:23:09,140",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:23:09,156",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:23:09,156",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:23:09,156",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000e6c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:23:09,156",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000c2c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:23:09,234",
            "thread_id": "2872",
            "caller": "0x7ffedeaa22bd",
            "parentcaller": "0x7ffede89ce49",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000ee0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000ec0"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:23:09,234",
            "thread_id": "2872",
            "caller": "0x7ffedeaa22bd",
            "parentcaller": "0x7ffede89ce49",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000ee0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000eec"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:23:09,234",
            "thread_id": "2872",
            "caller": "0x7ffede897024",
            "parentcaller": "0x7ffede897125",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000eec"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:23:09,234",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffedeb51c70",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000006a0"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000f50"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:23:09,281",
            "thread_id": "2872",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e89f3",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000e80"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe"
              },
              {
                "name": "CommandLine",
                "value": "\"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca"
              },
              {
                "name": "DllPath",
                "value": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy;"
              },
              {
                "name": "ProcessId",
                "value": "140728898426808"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:23:12,000",
            "thread_id": "2872",
            "caller": "0x7ffee10e89f3",
            "parentcaller": "0x7ffee167de30",
            "category": "process",
            "api": "CreateProcessInternalW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ApplicationName",
                "value": "C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe"
              },
              {
                "name": "CommandLine",
                "value": "\"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca"
              },
              {
                "name": "CreationFlags",
                "value": "0x00080414",
                "pretty_value": "CREATE_SUSPENDED|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT"
              },
              {
                "name": "ProcessId",
                "value": "6072"
              },
              {
                "name": "ThreadId",
                "value": "3424"
              },
              {
                "name": "ParentHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ProcessHandle",
                "value": "0x00000ac0"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000e80"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:23:13,125",
            "thread_id": "2872",
            "caller": "0x7ffedeb73391",
            "parentcaller": "0x7ffedeb31704",
            "category": "threading",
            "api": "NtResumeThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000e80"
              },
              {
                "name": "SuspendCount",
                "value": "1"
              },
              {
                "name": "ThreadId",
                "value": "3424"
              },
              {
                "name": "ProcessId",
                "value": "6072"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:23:13,547",
            "thread_id": "324",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000e78"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:23:13,812",
            "thread_id": "2872",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000e30"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "912",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "912",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x26c83a40000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-18.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:23:13,843",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f40"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000eb4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:23:13,859",
            "thread_id": "912",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffede9abe00",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0x00000e30"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000ddc"
              },
              {
                "name": "Options",
                "value": "0x00000003"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f70"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f70"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f6c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:23:13,875",
            "thread_id": "2392",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f28"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f58"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f58"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f28"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:23:13,890",
            "thread_id": "3984",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:23:15,328",
            "thread_id": "912",
            "caller": "0x7ffee10bacfe",
            "parentcaller": "0x7ffee32b9f03",
            "category": "services",
            "api": "StartServiceW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ServiceHandle",
                "value": "0x26c84c2f3e0"
              },
              {
                "name": "ServiceName",
                "value": "WSearch"
              },
              {
                "name": "Arguments",
                "value": []
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:23:15,656",
            "thread_id": "912",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f68"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:23:15,656",
            "thread_id": "912",
            "caller": "0x7ffee10a3d8e",
            "parentcaller": "0x7ffee10a3354",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000f7c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:23:15,656",
            "thread_id": "912",
            "caller": "0x7ffee10a3395",
            "parentcaller": "0x7ffee10a3f0a",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x26c84b90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:23:23,562",
            "thread_id": "324",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000f40"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:23:27,406",
            "thread_id": "324",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee10be6a1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:23:33,547",
            "thread_id": "324",
            "caller": "0x7ffee10c6579",
            "parentcaller": "0x7ffee10c5fe6",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000d40"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\??\\PhysicalDrive0"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:23:39,125",
            "thread_id": "324",
            "caller": "0x7ffee10ec5f2",
            "parentcaller": "0x7ffee10e89f3",
            "category": "process",
            "api": "NtCreateUserProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000f94"
              },
              {
                "name": "ThreadHandle",
                "value": "0x00000f90"
              },
              {
                "name": "ProcessDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ThreadDesiredAccess",
                "value": "0x02000000"
              },
              {
                "name": "ProcessFileName",
                "value": ""
              },
              {
                "name": "ThreadName",
                "value": ""
              },
              {
                "name": "ImagePathName",
                "value": "C:\\Windows\\system32\\DllHost.exe"
              },
              {
                "name": "CommandLine",
                "value": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "DllPath",
                "value": ""
              },
              {
                "name": "ProcessId",
                "value": "140728898426216"
              }
            ],
            "repeated": 0,
            "id": 258
          }
        ],
        "threads": [
          "912",
          "3968",
          "2872",
          "744",
          "4976",
          "3704",
          "324",
          "2392",
          "5188",
          "3984",
          "5252",
          "632"
        ],
        "environ": {
          "UserName": "￑￈￑ￒￅￌ￀",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "C:\\Windows\\system32\\svchost.exe -k DcomLaunch -p",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff630560000",
          "MainExeSize": "0x00010000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 2964,
        "process_name": "drvinst.exe",
        "parent_id": 740,
        "module_path": "C:\\Windows\\System32\\drvinst.exe",
        "first_seen": "2026-02-10 09:22:10,188",
        "calls": [
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "348",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "348",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\cfgmgr32"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1420000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee1433750"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "348",
            "caller": "0x7ffee34dc2c7",
            "parentcaller": "0x7ffee34dc05a",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\ntmarta"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfcb0000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedfcb6930"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "348",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "4268",
            "caller": "0x7ffee34ceb32",
            "parentcaller": "0x7ffee34877c3",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 2,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:22:10,329",
            "thread_id": "4692",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 3,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3c9cf1",
            "parentcaller": "0x7ff70a3c9859",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x7ff70a3c9ca0"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248909d6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248909d7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a39265a",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtOpenProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x000001f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000040",
                "pretty_value": "PROCESS_DUP_HANDLE"
              },
              {
                "name": "ProcessIdentifier",
                "value": "740"
              },
              {
                "name": "ProcessName",
                "value": "Error obtaining target process name"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a392684",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "misc",
            "api": "GetCommandLineW",
            "status": true,
            "return": "0x24890a02078",
            "arguments": [
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\""
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a39280d",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x000001f8"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000e88"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000204"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a39288f",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x000001f8"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000f3c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000208"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a392b23",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000208"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7fae0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a392b42",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "348"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "DEVRTL.dll"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000208"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000208"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00014000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\DEVRTL"
              },
              {
                "name": "DllBase",
                "value": "0x7ffec7f70000"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\devrtl"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffec7f71690"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a39e8f6",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a394623",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393eb6",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000210"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a394723",
            "parentcaller": "0x7ff70a393eb6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393ee2",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000210"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a393eee",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a393f23",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ValueName",
                "value": "DebugDriver"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a393f2f",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000210"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000020c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000210"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00148000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\drvstore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffeced50000"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a2d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\drvstore"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffeced5b160"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:22:10,344",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000230"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a2f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xfd4\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfd4\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ee90"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "=5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "=5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "=5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "=5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a393d20",
            "parentcaller": "0x7ff70a393e36",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "8"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a393d8c",
            "parentcaller": "0x7ff70a393e36",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00=5\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "=5\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ee90"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x905\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x905\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x905\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x905\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:22:10,360",
            "thread_id": "348",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000230"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x905\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x905\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7f760"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x076\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x076\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x076\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x076\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a30000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a32000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x909"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 1,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a34000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a36000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a38000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a40000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a42000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a44000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a46000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:10,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a48000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000080"
              },
              {
                "name": "ValueName",
                "value": "000603xx"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "kernel32.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortGetHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee166a190"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortCloseHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1680170"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\SortDefault.nls"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893750000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e793b0"
              },
              {
                "name": "ViewSize",
                "value": "0x00338000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a4"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e79840"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a4"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a4"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a54000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a56000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 14,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 7,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 1,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 1,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 3,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a5a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00011000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 3,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 8,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 3,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 14,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 6,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 13,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a55000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a69000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a51000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:22:10,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a55000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a51000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a38000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000a000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000a000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a38000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a69000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a6b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00021000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e79830"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 14,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 7,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 4,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 18,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000d000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a37000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:22:10,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002b4"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a680"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a37000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 14,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 8,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002b0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7adb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a38000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a38000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x076\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x076\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c830"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x846\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x846\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:22:10,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x846\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x846\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b840"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a53000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 14,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 7,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 4,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 2,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002ac"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b0"
              },
              {
                "name": "ValueName",
                "value": "DisableDecoratedModelsRequirement"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement"
              }
            ],
            "repeated": 0,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 3,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 8,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 3,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 14,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 4,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 13,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:22:10,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 9,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 16,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 4,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 1,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 2,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 1,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 9,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 46,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x846\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x846\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c870"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "api-ms-win-eventing-provider-l1-1-0.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "EventSetInformation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2af0"
              }
            ],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 752
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 753
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 754
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 755
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 756
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 757
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 758
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 759
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 760
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 761
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 762
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 763
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 764
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 765
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 766
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 767
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 768
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 769
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 770
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 771
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 772
          },
          {
            "timestamp": "2026-02-10 09:22:10,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 773
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 774
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 775
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xcf6\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 776
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 777
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c830"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 778
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 779
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": " 7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 780
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 781
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 782
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": " 7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 783
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": " 7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 784
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": " 7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 785
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 786
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp"
              }
            ],
            "repeated": 0,
            "id": 787
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 788
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 789
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 790
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 791
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 792
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 793
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 794
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 3,
            "id": 795
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 796
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 3,
            "id": 797
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 798
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 3,
            "id": 799
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 800
          },
          {
            "timestamp": "2026-02-10 09:22:10,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 801
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00 7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 802
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": " 7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 803
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 804
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000250"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 805
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 806
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 807
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 808
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 809
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 810
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "[7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 811
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "[7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 812
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 813
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 4,
            "id": 814
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 815
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 816
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 1,
            "id": 817
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 818
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\"
              }
            ],
            "repeated": 0,
            "id": 819
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a330",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 820
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 821
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 1,
            "id": 822
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\cabinet"
              },
              {
                "name": "DllBase",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 823
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "cabinet.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 824
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffed9750000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "cabinet.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 825
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICreate"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9758d10"
              }
            ],
            "repeated": 0,
            "id": 826
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 827
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 828
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 829
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\"
              }
            ],
            "repeated": 0,
            "id": 830
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xc86241be"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d5acde"
              }
            ],
            "repeated": 0,
            "id": 831
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 832
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 833
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 834
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 835
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 836
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICopy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9755f00"
              }
            ],
            "repeated": 0,
            "id": 837
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 838
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 839
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 840
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 841
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "Buffer",
                "value": "0\\x82+s\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82+d0\\x82+`\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 842
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 843
          },
          {
            "timestamp": "2026-02-10 09:22:10,485",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 844
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 845
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 846
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000258"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 847
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000258"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ad40"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 848
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 849
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 850
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 851
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 852
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 1,
            "id": 853
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 854
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 855
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 856
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 857
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00[7\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 858
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[7\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 859
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 860
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000254"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ac30"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 861
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 862
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 863
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 864
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 865
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 866
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 867
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 868
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 869
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 870
          },
          {
            "timestamp": "2026-02-10 09:22:10,501",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 871
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              }
            ],
            "repeated": 0,
            "id": 872
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 873
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01J\\xf9\\xf8\\xbbn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 874
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 875
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 876
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 877
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "PrivCopyFileExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1682940"
              }
            ],
            "repeated": 0,
            "id": 878
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 879
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 880
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 881
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 882
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 883
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 884
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 885
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 886
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 887
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ValueName",
                "value": "CopyFileBufferedSynchronousIo"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo"
              }
            ],
            "repeated": 0,
            "id": 888
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 889
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 890
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 891
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 892
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01J\\xf9\\xf8\\xbbn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 893
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 894
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01J\\xf9\\xf8\\xbbn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 895
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 896
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 897
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "J\\xf9\\xf8\\xbbn\\x9a\\xdc\\x01SV\\xfb\\xbbn\\x9a\\xdc\\x01SV\\xfb\\xbbn\\x9a\\xdc\\x01SV\\xfb\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 898
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 899
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 900
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 901
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 902
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000024c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000250"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 903
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 904
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 1,
            "id": 905
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "w+\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 906
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 907
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "ValueName",
                "value": "CopyFileChunkSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize"
              }
            ],
            "repeated": 0,
            "id": 908
          },
          {
            "timestamp": "2026-02-10 09:22:10,516",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "ValueName",
                "value": "CopyFileOverlappedCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount"
              }
            ],
            "repeated": 0,
            "id": 909
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 910
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 911
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 912
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 913
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 914
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 915
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 916
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 917
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 918
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 919
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01J\\xf9\\xf8\\xbbn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 920
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 921
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 922
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 923
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 1,
            "id": 924
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 925
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 926
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 1,
            "id": 927
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 928
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\"
              }
            ],
            "repeated": 0,
            "id": 929
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a3f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 930
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 931
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 932
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 933
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 934
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 935
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\"
              }
            ],
            "repeated": 0,
            "id": 936
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a450",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xc86241be"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d5acde"
              }
            ],
            "repeated": 0,
            "id": 937
          },
          {
            "timestamp": "2026-02-10 09:22:10,532",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 938
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 939
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 940
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 941
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 942
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 943
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 944
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 945
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 946
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "Buffer",
                "value": "; Copyright 2004, Check Point Softwa"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 947
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 948
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 949
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 950
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 951
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 952
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ad40"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 953
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 954
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 955
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 956
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 957
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 958
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 959
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 960
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 961
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 962
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1d8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 963
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 964
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ac30"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 965
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 966
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 967
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 968
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 969
          },
          {
            "timestamp": "2026-02-10 09:22:10,548",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 970
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 971
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 972
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 973
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 974
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 975
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              }
            ],
            "repeated": 0,
            "id": 976
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 977
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01!\\x1c\\x00\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 978
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 979
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 980
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 981
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 982
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 983
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01!\\x1c\\x00\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 984
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 985
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01!\\x1c\\x00\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 986
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 987
          },
          {
            "timestamp": "2026-02-10 09:22:10,563",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 988
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "!\\x1c\\x00\\xbcn\\x9a\\xdc\\x01\\xaa}\\x02\\xbcn\\x9a\\xdc\\x01\\xaa}\\x02\\xbcn\\x9a\\xdc\\x01\\xaa}\\x02\\xbcn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 989
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000002e8"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000002ec"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 990
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 991
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 1,
            "id": 992
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 993
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 994
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 995
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 996
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 997
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 998
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 999
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1000
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1001
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1002
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01!\\x1c\\x00\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1003
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1004
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1005
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 1006
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 1,
            "id": 1007
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1008
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1009
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 1,
            "id": 1010
          },
          {
            "timestamp": "2026-02-10 09:22:10,579",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1011
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\"
              }
            ],
            "repeated": 0,
            "id": 1012
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1013
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1014
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 1015
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1016
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1017
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1018
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\"
              }
            ],
            "repeated": 0,
            "id": 1019
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xc86241be"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d5acde"
              }
            ],
            "repeated": 0,
            "id": 1020
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1021
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a450",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 1022
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1023
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xba686ecb"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 1024
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1025
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 1026
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1027
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 1028
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1029
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "Buffer",
                "value": "MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 1030
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1031
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1032
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1033
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x01\\x00\\x00\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1034
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "FileName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1035
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ad40"
              },
              {
                "name": "ViewSize",
                "value": "0x00013000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1036
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00013000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1037
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1038
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1039
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1040
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 1041
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1042
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1043
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1044
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1045
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdf8\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1046
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1047
          },
          {
            "timestamp": "2026-02-10 09:22:10,594",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ac30"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1048
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa19\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1049
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1050
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1051
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa19\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1052
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa19\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1053
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa19\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1054
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1055
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1056
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1057
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1058
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              }
            ],
            "repeated": 0,
            "id": 1059
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1060
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc6G\\x07\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1061
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1062
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 1063
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1064
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1065
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x01\\x00\\x00\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1066
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc6G\\x07\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1067
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x000\\x01\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 1068
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc6G\\x07\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1069
          },
          {
            "timestamp": "2026-02-10 09:22:10,610",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1070
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1071
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6G\\x07\\xbcn\\x9a\\xdc\\x01m\t\\x0c\\xbcn\\x9a\\xdc\\x01m\t\\x0c\\xbcn\\x9a\\xdc\\x01m\t\\x0c\\xbcn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1072
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000002e4"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x0000025c"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1073
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000025c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 1074
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 1,
            "id": 1075
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1076
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1077
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 1078
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1079
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x94\\xf88\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1080
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 1081
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 1082
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1083
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1084
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1085
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc6G\\x07\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1086
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1087
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1088
          },
          {
            "timestamp": "2026-02-10 09:22:10,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 1089
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1090
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xa19\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1091
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa19\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1092
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1093
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1094
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1095
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xef9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1096
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1097
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1098
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xef9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1099
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xef9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1100
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000024c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xef9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1101
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1102
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 1103
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 1104
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1105
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1106
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1107
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1108
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1109
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1110
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1111
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1112
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1113
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1114
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1115
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1116
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1117
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1118
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a3f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1119
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1120
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1121
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1122
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000294"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 1123
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000294"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7af20"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1124
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1125
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1126
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1127
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1128
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1129
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a50000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1130
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1131
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a39000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1132
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890982000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1133
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 1134
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1135
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1136
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1137
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1138
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1139
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1140
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1141
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1142
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1143
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1144
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1145
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1146
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1147
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1148
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1149
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1150
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1151
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1152
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1153
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1154
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1155
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1156
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1157
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1158
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1159
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1160
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1161
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1162
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1163
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1164
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1165
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1166
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1167
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 1,
            "id": 1168
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 14,
            "id": 1169
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1170
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1171
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1172
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1173
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 8,
            "id": 1174
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1175
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1176
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1177
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a39000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1178
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a4b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1179
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a50000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1180
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1181
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1182
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1183
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1184
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1185
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1186
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1187
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 1188
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 1189
          },
          {
            "timestamp": "2026-02-10 09:22:10,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1190
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1191
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 1192
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1193
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 1194
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1195
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1196
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1197
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1198
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1199
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1200
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1201
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1202
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1203
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1204
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1205
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1206
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1207
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1208
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1209
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a390",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1210
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 1211
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 1212
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1213
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xef9\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1214
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xef9\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1215
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1216
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1217
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1218
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1219
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1220
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1221
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1222
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "4:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1223
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "4:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1224
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1225
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a395b15",
            "parentcaller": "0x7ff70a39d173",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a2a3f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1226
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a395b3c",
            "parentcaller": "0x7ff70a39d173",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1227
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca927",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1228
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca927",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1229
          },
          {
            "timestamp": "2026-02-10 09:22:10,657",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 1,
            "id": 1230
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1231
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 1232
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ec"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c110"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1233
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 1234
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\MSASN1"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee0690000"
              }
            ],
            "repeated": 0,
            "id": 1235
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1236
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 1237
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "CRYPTSP.dll"
              }
            ],
            "repeated": 0,
            "id": 1238
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              }
            ],
            "repeated": 0,
            "id": 1239
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1240
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              }
            ],
            "repeated": 0,
            "id": 1241
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00018000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1242
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0465000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1243
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1244
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1245
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1246
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1247
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1248
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1249
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 1250
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1251
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\CRYPTSP"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee0450000"
              }
            ],
            "repeated": 0,
            "id": 1252
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 12,
            "id": 1253
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\cryptsp"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee0454aa0"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1254
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1255
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1256
          },
          {
            "timestamp": "2026-02-10 09:22:10,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\rsaenh"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 1257
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 1258
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 1259
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptAcquireContextA",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": "Microsoft Enhanced RSA and AES Cryptographic Provider"
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 1260
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1261
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002ac"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000002e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1262
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllFindOIDInfo"
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo"
              }
            ],
            "repeated": 0,
            "id": 1263
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1264
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1265
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 1266
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1267
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1268
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1269
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1270
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1271
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1272
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1273
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1274
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000278"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1275
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1276
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1277
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Isolated User Mode (IUM)"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1278
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1279
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1280
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1281
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1282
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1283
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1284
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1285
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1286
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1287
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1288
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Isolated User Mode (IUM)"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1289
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1290
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 1291
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1292
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1293
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1294
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 1295
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1296
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1297
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1298
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1299
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1300
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1301
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1302
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1303
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000278"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1304
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1305
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1306
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Enclave"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101"
              }
            ],
            "repeated": 0,
            "id": 1307
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1308
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1309
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1310
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1311
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1312
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1313
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1314
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1315
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1316
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1317
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Enclave"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101"
              }
            ],
            "repeated": 0,
            "id": 1318
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1319
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 1320
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1321
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1322
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1323
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 1324
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1325
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1326
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1327
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1328
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1329
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1330
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1331
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1332
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000278"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1333
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1334
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\dnsapi.dll"
              }
            ],
            "repeated": 0,
            "id": 1335
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103"
              }
            ],
            "repeated": 0,
            "id": 1336
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1337
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1338
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1339
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1340
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1341
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1342
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1343
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1344
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1345
          },
          {
            "timestamp": "2026-02-10 09:22:10,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\dnsapi.dll"
              }
            ],
            "repeated": 0,
            "id": 1346
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000278"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103"
              }
            ],
            "repeated": 0,
            "id": 1347
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1348
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 1349
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1350
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1351
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1352
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 1353
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1354
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1355
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1356
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1357
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1358
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1359
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1360
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1361
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000268"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1362
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1363
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\wuaueng.dll"
              }
            ],
            "repeated": 0,
            "id": 1364
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400"
              }
            ],
            "repeated": 0,
            "id": 1365
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1366
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1367
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1368
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1369
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1370
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1371
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1372
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1373
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1374
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\wuaueng.dll"
              }
            ],
            "repeated": 0,
            "id": 1375
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400"
              }
            ],
            "repeated": 0,
            "id": 1376
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1377
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1378
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1379
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1380
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1381
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 1382
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1383
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1384
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1385
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1386
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1387
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1388
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1389
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1390
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000268"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1391
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1392
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
              }
            ],
            "repeated": 0,
            "id": 1393
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              }
            ],
            "repeated": 0,
            "id": 1394
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1395
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1396
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1397
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1398
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1399
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1400
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1401
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1402
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1403
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
              }
            ],
            "repeated": 0,
            "id": 1404
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              }
            ],
            "repeated": 0,
            "id": 1405
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1406
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1407
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1408
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1409
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1410
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "88"
              }
            ],
            "repeated": 0,
            "id": 1411
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1412
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1413
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1414
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1415
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1416
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1417
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1418
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1419
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000268"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1420
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1421
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\NgcRecovery.dll"
              }
            ],
            "repeated": 0,
            "id": 1422
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1423
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1424
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1425
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1426
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1427
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1428
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x91H\\x02\\x00\\x00i\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1429
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1430
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1431
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1432
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\NgcRecovery.dll"
              }
            ],
            "repeated": 0,
            "id": 1433
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1434
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1435
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1436
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1437
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\"
              }
            ],
            "repeated": 0,
            "id": 1438
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1439
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1440
          },
          {
            "timestamp": "2026-02-10 09:22:10,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 1441
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\Cryptography\\ECCParameters"
              },
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Cryptography\\ECCParameters"
              }
            ],
            "repeated": 0,
            "id": 1442
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Cryptography\\ECCParameters\\"
              }
            ],
            "repeated": 0,
            "id": 1443
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 1444
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a3c000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000d000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1445
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 1446
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ru-RU\\CRYPT32.dll.mui"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1447
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ac"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ru-RU\\crypt32.dll.mui"
              }
            ],
            "repeated": 0,
            "id": 1448
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911c0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a900"
              },
              {
                "name": "ViewSize",
                "value": "0x0000c000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1449
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1450
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1451
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1452
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "device",
            "api": "NtDeviceIoControlFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000174"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\KsecDD"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390400"
              },
              {
                "name": "InputBuffer",
                "value": "M<+\\x1a\\x00\\x00\\x02\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": "\\x01\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00A\\x002\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xffS\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00P\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00 \\x00P\\x00r\\x00o\\x00v\\x00i\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00b\\x00c\\x00r\\x00y\\x00p\\x00t\\x00p\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00s\\x00.\\x00d\\x00l\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1453
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\bcryptprimitives.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 1454
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1390000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\bcryptprimitives.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1455
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetHashInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13a4460"
              }
            ],
            "repeated": 0,
            "id": 1456
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1457
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1458
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1459
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1460
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x004:\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1461
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1462
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1463
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c1a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1464
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1465
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1466
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1467
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1468
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "t:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1469
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "t:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1470
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1471
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b5ba0",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1472
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 1473
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "WINTRUST.dll"
              }
            ],
            "repeated": 0,
            "id": 1474
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00067000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1475
          },
          {
            "timestamp": "2026-02-10 09:22:10,719",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1476
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1477
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1478
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1479
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1480
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1481
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1482
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1483
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\WINTRUST"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 1484
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 1485
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1486
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1487
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1488
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1489
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1490
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1491
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\wintrust"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee1481670"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1492
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1493
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1494
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1495
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 1496
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 1497
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bfd0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1498
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1499
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 1500
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000002cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1501
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1502
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002cc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1503
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllPutSignedDataMsg"
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg"
              }
            ],
            "repeated": 0,
            "id": 1504
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 1505
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 1506
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1507
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\MSISIP.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1508
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "MsiSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1509
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1510
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1511
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1512
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1513
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1514
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1515
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1516
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 1517
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 1518
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1519
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1520
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1521
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1522
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 1523
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 1524
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1525
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1526
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxBundleSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1527
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1528
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 1529
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 1530
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1531
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1532
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1533
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1534
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1535
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1536
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1537
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1538
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1539
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1540
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 1541
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 1542
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1543
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1544
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "P7xSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1545
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1546
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 1547
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 1548
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 1549
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pwrshsip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1550
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PsPutSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1551
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1552
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1553
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1554
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1555
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1556
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1557
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1558
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 1559
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 1560
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1561
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1562
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipPutSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1563
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1564
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1565
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1566
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1567
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1568
          },
          {
            "timestamp": "2026-02-10 09:22:10,735",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1569
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1570
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1571
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1572
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1573
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1574
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1575
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1576
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1577
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1578
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1579
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1580
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1581
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1582
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 1583
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 1584
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1585
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1586
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1587
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1588
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 1589
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 1590
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1591
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1592
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxBundleSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1593
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1594
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1595
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1596
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1597
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1598
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1599
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1600
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1601
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1602
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1603
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1604
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1605
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1606
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\"
              }
            ],
            "repeated": 0,
            "id": 1607
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1608
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1609
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1610
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002cc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1611
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllPutSignedDataMsg"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllPutSignedDataMsg"
              }
            ],
            "repeated": 0,
            "id": 1612
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1613
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 1614
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 1615
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 1616
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1617
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000139",
            "pretty_return": "ENTRYPOINT_NOT_FOUND",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1618
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 1619
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000002"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\crypt32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0b90000"
              }
            ],
            "repeated": 0,
            "id": 1620
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0b90000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\System32\\CRYPT32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000011"
              }
            ],
            "repeated": 0,
            "id": 1621
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee0bdb180"
              },
              {
                "name": "Parameter",
                "value": "0x24890a3b0e0"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "1816"
              },
              {
                "name": "ProcessId",
                "value": "2964"
              },
              {
                "name": "Module",
                "value": "CRYPT32.dll"
              }
            ],
            "repeated": 0,
            "id": 1622
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x0000027c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee0bdb180"
              },
              {
                "name": "Parameter",
                "value": "0x24890a3b0e0"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "1816"
              },
              {
                "name": "ProcessId",
                "value": "2964"
              }
            ],
            "repeated": 0,
            "id": 1623
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1624
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1625
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1626
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1627
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "1816",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1628
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1629
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1630
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 1631
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\AuthRoot"
              }
            ],
            "repeated": 0,
            "id": 1632
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config"
              }
            ],
            "repeated": 0,
            "id": 1633
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 1634
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertSyncDeltaTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime"
              }
            ],
            "repeated": 0,
            "id": 1635
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1636
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 1637
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\ChainEngine\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\ChainEngine\\Config"
              }
            ],
            "repeated": 0,
            "id": 1638
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "DisableMandatoryBasicConstraints"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints"
              }
            ],
            "repeated": 0,
            "id": 1639
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "DisableCANameConstraints"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints"
              }
            ],
            "repeated": 0,
            "id": 1640
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "DisableUnsupportedCriticalExtensions"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions"
              }
            ],
            "repeated": 0,
            "id": 1641
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlCountInCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert"
              }
            ],
            "repeated": 0,
            "id": 1642
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1643
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxUrlRetrievalByteCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount"
              }
            ],
            "repeated": 0,
            "id": 1644
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalByteCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount"
              }
            ],
            "repeated": 0,
            "id": 1645
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalCertCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount"
              }
            ],
            "repeated": 0,
            "id": 1646
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxVerifySignatureCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1647
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxIssuerDepth"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth"
              }
            ],
            "repeated": 0,
            "id": 1648
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MaxPathCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1649
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "CryptnetPreFetchTriggerPeriodSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds"
              }
            ],
            "repeated": 0,
            "id": 1650
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "EnableWeakSignatureFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags"
              }
            ],
            "repeated": 0,
            "id": 1651
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "MinRsaPubKeyBitLength"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength"
              }
            ],
            "repeated": 0,
            "id": 1652
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakRsaPubKeyTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime"
              }
            ],
            "repeated": 0,
            "id": 1653
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "ChainCacheResyncFiletime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime"
              }
            ],
            "repeated": 0,
            "id": 1654
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "EnableStrictChecksFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags"
              }
            ],
            "repeated": 0,
            "id": 1655
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000270"
              },
              {
                "name": "SubKey",
                "value": "Default"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default"
              }
            ],
            "repeated": 0,
            "id": 1656
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\CI\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CI\\Config"
              }
            ],
            "repeated": 0,
            "id": 1657
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Default"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default"
              }
            ],
            "repeated": 0,
            "id": 1658
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1659
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyFlags"
              },
              {
                "name": "Data",
                "value": "18446744071705722880"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1660
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyAfterTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1661
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyAfterTime"
              },
              {
                "name": "Data",
                "value": "\\x00\\xc0)\\xb8C\\x9a\\xc9\\x01"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1662
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1663
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1664
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1665
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1666
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1667
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1668
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1669
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1670
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "Data",
                "value": "\\x00\\x00\\x001\\x5754\\x5241\\x5c45\\x694d\\x7263\\x736f\\x666f\\x5c74\\x7243\\x7079\\x6f74\\x7267\\x7061\\x7968\\x4f5c\\x4449\\x455c\\x636e\\x646f\\x6e69\\x5467\\x7079\\x2065\\x5c30\\x6543\\x7472\\x6c44\\x436c\\x6572\\x7461\\x4365\\x7265\\x6974\\x6966\\x6163\\x6574\\x6843\\x6961\\x456e\\x676e\\x6e69\\x5c65\\x6f43\\x666e\\x6769\\x445c\\x6665\\x7561\\x746c\\x575c\\x6165\\x4d6b\\x3544\\x6854\\x7269\\x5064\\x7261\\x7974\\x6853\\x3261\\x3635\\x6c41\\x6f6c\\x4177\\x4843\\x4e49\\x5c45\\x4f53\\x5446\\x4157\\x4552Q\\x5100\\x5970"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1671
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1672
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1673
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1674
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1675
          },
          {
            "timestamp": "2026-02-10 09:22:10,751",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1676
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1677
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyFlags"
              },
              {
                "name": "Data",
                "value": "18446744071562330112"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1678
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyAfterTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1679
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1680
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1681
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1682
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1683
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1684
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1685
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1686
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1687
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1688
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1689
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1690
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1691
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1692
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1693
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1694
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1695
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1696
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1697
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1698
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1699
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1700
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1701
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1702
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1703
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 1704
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1705
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 1706
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Services\\crypt32"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32"
              }
            ],
            "repeated": 0,
            "id": 1707
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "DiagLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel"
              }
            ],
            "repeated": 0,
            "id": 1708
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "ValueName",
                "value": "DiagMatchAnyMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask"
              }
            ],
            "repeated": 0,
            "id": 1709
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1710
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Services\\crypt32"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32"
              }
            ],
            "repeated": 0,
            "id": 1711
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000004"
              },
              {
                "name": "WatchSubtree",
                "value": "0"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1712
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000002d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1713
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "2940",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1714
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1715
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002d4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1716
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CertDllOpenStoreProv"
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv"
              }
            ],
            "repeated": 0,
            "id": 1717
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "#16"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16"
              }
            ],
            "repeated": 0,
            "id": 1718
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "#16"
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16"
              }
            ],
            "repeated": 0,
            "id": 1719
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 1720
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptnet.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1721
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "LdapProvOpenStore"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1722
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1723
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "Ldap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap"
              }
            ],
            "repeated": 0,
            "id": 1724
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "Ldap"
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap"
              }
            ],
            "repeated": 0,
            "id": 1725
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 1726
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptnet.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1727
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "LdapProvOpenStore"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1728
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1729
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\"
              }
            ],
            "repeated": 0,
            "id": 1730
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1731
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1732
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1733
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002d4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1734
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CertDllOpenStoreProv"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllOpenStoreProv"
              }
            ],
            "repeated": 0,
            "id": 1735
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1736
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 1737
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1738
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1739
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1740
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1741
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1742
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1743
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1744
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1745
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1746
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1747
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1748
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1749
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1750
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1751
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd4\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1752
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1753
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1754
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1755
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1756
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1757
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1758
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1759
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1760
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1761
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1762
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1763
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1764
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1765
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1766
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1767
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1768
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1769
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1770
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1771
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1772
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1773
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1774
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1775
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1776
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xb3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xdbg\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xa4\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1777
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1778
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1779
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1780
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1781
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1782
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1783
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1784
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1785
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1786
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1787
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1788
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1789
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1790
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1791
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1792
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1793
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1794
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1795
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1796
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1797
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xaf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xabc\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xd5\\xa0\\x90H\\x02\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1798
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1799
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1800
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 1801
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1802
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a8"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1803
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1804
          },
          {
            "timestamp": "2026-02-10 09:22:10,766",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000298"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1805
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1806
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1807
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000298"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1808
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1809
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1810
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000298"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1811
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1812
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1813
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1814
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1815
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1816
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1817
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1818
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1819
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1820
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "3"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1821
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 1822
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 1823
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1824
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1825
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1826
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft W"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1827
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 1828
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 1829
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1830
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1831
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1832
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign "
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1833
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 1834
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 1835
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1836
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1837
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1838
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1839
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1840
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1841
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1842
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1843
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 1844
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 1845
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1846
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1847
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1848
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r0008310"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1849
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1850
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1851
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1852
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1853
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1854
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1855
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1856
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1857
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1858
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1859
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1860
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1861
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1862
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1863
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1864
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1865
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1866
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1867
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1868
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1869
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1870
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1871
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1872
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1873
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1874
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1875
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1876
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1877
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1878
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1879
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1880
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1881
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1882
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1883
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1884
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1885
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1886
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1887
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1888
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1889
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1890
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1891
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1892
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1893
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1894
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1895
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1896
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1897
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1898
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1899
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1900
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1901
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1902
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1903
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1904
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1905
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1906
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1907
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1908
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1909
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1910
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1911
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "(\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xebx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\xc0\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\\\xa1\\x90H\\x02\\x00\\x00\\xd0\\xbb\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x90\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x90\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1912
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1913
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1914
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1915
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1916
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1917
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1918
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1919
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1920
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1921
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1922
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1923
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1924
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1925
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1926
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xb3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xdbg\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00d\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1927
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1928
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1929
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1930
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1931
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 1932
          },
          {
            "timestamp": "2026-02-10 09:22:10,782",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1933
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1934
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1935
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1936
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1937
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1938
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1939
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1940
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1941
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1942
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1943
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1944
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1945
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1946
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1947
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xaf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xabc\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00pq\\xa3\\x90H\\x02\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1948
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1949
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1950
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 1951
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1952
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000254"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1953
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1954
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1955
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1956
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1957
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1958
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1959
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1960
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1961
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1962
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1963
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1964
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1965
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1966
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1967
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1968
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "X\\xb3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00;g\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\xf0\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\\\xa1\\x90H\\x02\\x00\\x00\\x00\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1969
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1970
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1971
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1972
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1973
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1974
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1975
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 1976
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1977
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1978
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1979
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1980
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1981
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1982
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1983
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1984
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1985
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 1986
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 1987
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1988
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1989
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1990
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1991
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1992
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 1993
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1994
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1995
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1996
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1997
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1998
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1999
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 2000
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2001
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000290"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2002
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 2003
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2004
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2005
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2006
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2007
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2008
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 2009
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2010
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000294"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2011
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2012
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2013
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000294"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2014
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2015
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2016
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000294"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2017
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2018
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2019
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2020
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2021
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2022
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2023
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2024
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2025
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2026
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2027
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2028
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2029
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2030
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2031
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2032
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2033
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2034
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2035
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2036
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2037
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2038
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2039
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2040
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2041
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2042
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2043
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2044
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2045
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2046
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2047
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2048
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2049
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2050
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2051
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2052
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2053
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2054
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0by\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00@;\\xa4\\x90H\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\xb0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\x10\\x01\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2055
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2056
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2057
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2058
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2059
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xdbf\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\x10\\x01\\x80\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2060
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2061
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2062
          },
          {
            "timestamp": "2026-02-10 09:22:10,798",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2063
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 2064
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2065
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\"
              }
            ],
            "repeated": 0,
            "id": 2066
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2067
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2068
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2069
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2070
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2071
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2072
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2073
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2074
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2075
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2076
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x88\\xb4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00Kf\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\xd0Y\\xa4\\x90H\\x02\\x00\\x00\\xf0\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xf0\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\x10\\x01\\x80\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2077
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2078
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2079
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2080
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2081
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2082
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2083
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "Data",
                "value": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2084
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2085
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2086
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 2087
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2088
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2089
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2090
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2091
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2092
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "103"
              }
            ],
            "repeated": 1,
            "id": 2093
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2094
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000248"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\"
              }
            ],
            "repeated": 0,
            "id": 2095
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2096
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2097
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "12"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2098
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2099
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2100
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2101
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2102
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2103
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1=0;\\x06\\x03U\\x04\\x03\\x134Microsoft Time Stamp Root Certificate Authority 20140\\x1e\\x17\r141022220857Z\\x17\r391022221519Z0\\x81\\x931\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nW"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2104
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2105
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2106
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2107
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2108
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2109
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2110
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1>0<\\x06\\x03U\\x04\\x03\\x135Microsoft ECC Product Root Certificate Authority 20180\\x1e\\x17\r180227204208Z\\x17\r430227205046Z0\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2111
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2112
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2113
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2114
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2115
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2116
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2117
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2118
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2119
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2120
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2121
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2122
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2123
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2124
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2125
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2126
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2127
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2128
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1907\\x06\\x03U\\x04\\x03\\x130Microsoft ECC TS Root Certificate Authority 20180\\x1e\\x17\r180227205134Z\\x17\r430227210012Z0\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashingt"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2129
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2130
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2131
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2132
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2133
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2134
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215724Z\\x17\r350623220401Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2135
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2136
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2137
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2138
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2139
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2140
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2141
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2142
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2143
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2144
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a8f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2145
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2146
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2147
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220528Z\\x17\r360322221304Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2148
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2149
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2150
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2151
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2152
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2153
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2154
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2155
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2156
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2157
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2158
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2159
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2160
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microso"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2161
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2162
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2163
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2164
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2165
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2166
          },
          {
            "timestamp": "2026-02-10 09:22:10,813",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bD"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2167
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2168
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2169
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2170
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2171
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2172
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certi"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2173
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2174
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2175
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2176
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2177
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2178
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2179
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 2180
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2181
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2182
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000002f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2183
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2184
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2185
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "11"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2186
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2187
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2188
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2189
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2190
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2191
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1$0\"\\x06\\x03U\\x04\\x03\\x13\\x1bDigiCert Assured ID Root CA0\\x1e\\x17\r061110000000Z\\x17\r311110000000Z0e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1$0\"\\x06\\x03U\\x04\\x03\\x13"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2192
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2193
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2194
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2195
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a92000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2196
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2197
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2198
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03\\x13\\x1eHotspot 2.0 Trust Root CA - 030\\x1e\\x17\r131208120000Z\\x17\r431208120000Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03\\x13\\x1eHotspot 2.0 Trust Root CA - 030\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2199
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2200
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2201
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2202
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2203
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2204
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r960129000000Z\\x17\r280801235959Z0_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certificatio"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2205
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2206
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2207
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2208
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2209
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2210
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root G30\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCe"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2211
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2212
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2213
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2214
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a93000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2215
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2216
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2217
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x830\\x82\\x03k\\xa0\\x03\\x02\\x01\\x02\\x02\\x0eE\\xe6\\xbb\\x03\\x833\\xc3\\x85eH\\xe6\\xffEQ0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R61\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x1e\\x17\r141210000000Z\\x17\r341210000000Z0L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R61\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x02\\x0f\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2218
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2219
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2220
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2221
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2222
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2223
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root CA0\\x1e\\x17\r061110000000Z\\x17\r311110000000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17Dig"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2224
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2225
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2226
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2227
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2228
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2229
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2230
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2231
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2232
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2233
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2234
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2235
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04\\x00\\x00\\x00\\x00\\x01!XS\\x08\\xa20\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R31\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x1e\\x17\r090318100000Z\\x17\r290318100000Z0L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R31\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2236
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2237
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2238
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2239
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a96000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2240
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2241
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2242
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu\\0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18DigiCert Trusted Root G40\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Di"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2243
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2244
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2245
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2246
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2247
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2248
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x8e0\\x82\\x02v\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x03:\\xf1\\xe6\\xa7\\x11\\xa9\\xa0\\xbb(d\\xb1\\x1d\t\\xfa\\xe50\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root G20\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17Dig"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2249
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2250
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2251
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2252
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2253
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2254
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1H0F\\x06\\x03U\\x04\\x03\\x13?Microsoft Identity Verification Root Certificate Authority 20200\\x1e\\x17\r200416183616Z\\x17\r450416184440Z0w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1H0F\\x06\\x03U\\x04\\x03\\x13"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2255
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2256
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2257
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2258
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2259
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2260
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2261
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2262
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2263
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2264
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2265
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2266
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2267
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2268
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2269
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2270
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2271
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2272
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 2273
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2274
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2275
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2276
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2277
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2278
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\"
              }
            ],
            "repeated": 0,
            "id": 2279
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2280
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2281
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2282
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2283
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2284
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2285
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2286
          },
          {
            "timestamp": "2026-02-10 09:22:10,829",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2287
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 2288
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2289
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2290
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2291
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2292
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2293
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2294
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2295
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2296
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2297
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2298
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2299
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2300
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2301
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2302
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2303
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2304
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2305
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2306
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0by\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0R\\xa9\\x90H\\x02\\x00\\x00 \\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00\\xb0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\x10\\x01\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2307
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2308
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2309
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2310
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000304"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2311
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2312
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2313
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2314
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2315
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2316
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2317
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2318
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2319
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2320
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2321
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2322
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2323
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2324
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2325
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2326
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2327
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2328
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2329
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2330
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2331
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2332
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2333
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2334
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2335
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2336
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2337
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2338
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2339
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2340
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2341
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2342
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2343
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2344
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2345
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bx\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2346
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2347
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2348
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2349
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2350
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2351
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2352
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2353
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2354
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2355
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2356
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2357
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2358
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2359
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2360
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2361
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xb3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xdbg\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x90\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2362
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2363
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2364
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2365
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 2366
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2367
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2368
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2369
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2370
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2371
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2372
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2373
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2374
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000308"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2375
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2376
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2377
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 2378
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2379
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2380
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2381
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2382
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xaf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xabc\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10P\\xa4\\x90H\\x02\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2383
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2384
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2385
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 2386
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2387
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000308"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2388
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2389
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000030c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2390
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 2391
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2392
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000030c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2393
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 2394
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2395
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000030c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2396
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 2397
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2398
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2399
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2400
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2401
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2402
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2403
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2404
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2405
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2406
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2407
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2408
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2409
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2410
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2411
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2412
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2413
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2414
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2415
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2416
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2417
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2418
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2419
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2420
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2421
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000310"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2422
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 2423
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2424
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2425
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2426
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2427
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2428
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000310"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2429
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000314"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2430
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000314"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2431
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2432
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000314"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2433
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000314"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2434
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2435
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000314"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2436
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000314"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2437
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2438
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2439
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2440
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2441
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2442
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2443
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2444
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2445
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2446
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2447
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 2448
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2449
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2450
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2451
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2452
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xaby\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2453
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2454
          },
          {
            "timestamp": "2026-02-10 09:22:10,844",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2455
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2456
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2457
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2458
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2459
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2460
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2461
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2462
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xaby\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00P\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2463
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2464
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2465
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000318"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2466
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2467
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2468
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2469
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2470
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2471
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2472
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2473
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2474
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2475
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2476
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2477
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xb3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00{g\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x000\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x00\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2478
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2479
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000318"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2480
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2481
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 2482
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000318"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\"
              }
            ],
            "repeated": 0,
            "id": 2483
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2484
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2485
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 2486
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2487
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2488
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 2489
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2490
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2491
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 2492
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2493
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 2494
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2495
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2496
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2497
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2498
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x88\\xaf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00Kc\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00 \\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`W\\xa4\\x90H\\x02\\x00\\x00\\xf0\\xb0\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xf0\\xb0\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x94\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2499
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2500
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2501
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 2502
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2503
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2504
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2505
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000320"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2506
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 2507
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2508
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000320"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2509
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 2510
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2511
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000320"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2512
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 2513
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2514
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2515
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2516
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2517
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2518
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a99000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2519
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\"
              }
            ],
            "repeated": 0,
            "id": 2520
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2521
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2522
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2523
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2524
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2525
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2526
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2527
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2528
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2529
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2530
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2531
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2532
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2533
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2534
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2535
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2536
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2537
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2538
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2539
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 2540
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2541
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2542
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2543
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2544
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2545
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000294"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\"
              }
            ],
            "repeated": 0,
            "id": 2546
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2547
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2548
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 2549
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2550
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2551
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 2552
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2553
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2554
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 2555
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 2556
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2557
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2558
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2559
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2560
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2561
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2562
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2563
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2564
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2565
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2566
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2567
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00k{\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00(C\\xa5\\x90H\\x02\\x00\\x00@\\xb9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xb9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xb9\\xe7\\xd1\\xa1\\x00\\x00\\x00PS\\xa4\\x90H\\x02\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2568
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2569
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2570
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2571
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2572
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "Data",
                "value": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2573
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2574
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 2575
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2576
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2577
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2578
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "12"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2579
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2580
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2581
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2582
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2583
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2584
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2585
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2586
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2587
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2588
          },
          {
            "timestamp": "2026-02-10 09:22:10,860",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2589
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2590
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2591
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2592
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2593
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2594
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2595
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2596
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2597
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2598
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2599
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2600
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2601
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2602
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2603
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2604
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a9c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2605
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2606
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2607
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2608
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2609
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2610
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2611
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2612
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2613
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2614
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2615
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2616
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2617
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2618
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2619
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2620
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2621
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2622
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2623
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2624
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2625
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2626
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2627
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2628
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2629
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2630
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2631
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2632
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2633
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2634
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2635
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2636
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2637
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2638
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2639
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2640
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2641
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2642
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2643
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2644
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000248"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2645
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2646
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2647
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a9e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2648
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2649
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2650
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2651
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "11"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2652
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2653
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2654
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2655
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2656
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2657
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2658
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2659
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2660
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2661
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2662
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2663
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2664
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2665
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2666
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2667
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2668
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2669
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2670
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2671
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2672
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2673
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2674
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2675
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2676
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2677
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2678
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2679
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2680
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2681
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2682
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2683
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2684
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2685
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2686
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2687
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2688
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2689
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2690
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2691
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2692
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2693
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2694
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2695
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2696
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2697
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2698
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2699
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2700
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2701
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2702
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aa0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2703
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2704
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2705
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2706
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2707
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 2708
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2709
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2710
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2711
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2712
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2713
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2714
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2715
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 2716
          },
          {
            "timestamp": "2026-02-10 09:22:10,876",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2717
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2718
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 2719
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2720
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf420000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00023000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2721
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf440000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2722
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2723
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2724
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2725
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2726
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2727
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2728
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 2729
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2730
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "35"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x06\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x8ck\\xb0\\x83\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0054\"\\xaf\\xdd7\rw\\x02\\x00\\x00\\x00H\\x00\\xf1\\x8c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd1N\\xd0\\xe6(C7\\x99\\x02\\x00\\x00\\x00\\xd9\\x9aqs\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x007o\\x928\\x1e}\\x12<\\x02\\x00\\x00\\x00m\\xe1\\xfcR\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00a\\xbe\\xa2(\\xc7\\x1c\\xa3\\xa7\\x02\\x00\\x00\\x00\\xa4\\xdfJn\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x007\\x9d\\x13<R\\x8e\\xbd\\xb9\\x02\\x00\\x00\\x00\\xd5\nj=\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x82\\x10H\\x1f\\xdc\\xf4\\xef\\xa5\\x02\\x00\\x00\\x008c\\x84N\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10I\\x17\\xb8\\xc0\\x1e\\xc7\\x0f"
              }
            ],
            "repeated": 0,
            "id": 2731
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\gpapi"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedf420000"
              }
            ],
            "repeated": 0,
            "id": 2732
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\gpapi"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf420000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedf423730"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2733
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2734
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2735
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              }
            ],
            "repeated": 0,
            "id": 2736
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              },
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              }
            ],
            "repeated": 0,
            "id": 2737
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "ValueName",
                "value": "UserenvDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2738
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 2739
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 2740
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "ValueName",
                "value": "GpSvcDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2741
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 2742
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 2743
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 2744
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 2745
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000354"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000002f0"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 2746
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates"
              },
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates"
              }
            ],
            "repeated": 0,
            "id": 2747
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2748
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              }
            ],
            "repeated": 0,
            "id": 2749
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000035c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2750
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000360"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2751
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 2752
          },
          {
            "timestamp": "2026-02-10 09:22:10,891",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000035c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2753
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000360"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2754
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 2755
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000035c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2756
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000360"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2757
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 2758
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2759
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2760
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000370"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2761
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000370"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2762
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              }
            ],
            "repeated": 0,
            "id": 2763
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000370"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2764
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000370"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2765
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              }
            ],
            "repeated": 0,
            "id": 2766
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002f8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000370"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2767
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000370"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2768
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              }
            ],
            "repeated": 0,
            "id": 2769
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2770
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2771
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2772
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 2773
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2774
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2775
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 2776
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002fc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2777
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2778
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 2779
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2780
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2781
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2782
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 2783
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2784
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2785
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 2786
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000304"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2787
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2788
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 2789
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2790
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2791
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2792
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2793
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2794
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2795
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2796
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2797
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2798
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000364"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2799
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2800
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2801
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2802
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2803
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2804
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000394"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2805
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000394"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2806
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000394"
              }
            ],
            "repeated": 0,
            "id": 2807
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000394"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2808
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000394"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2809
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000394"
              }
            ],
            "repeated": 0,
            "id": 2810
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000318"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000394"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2811
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000394"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2812
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000394"
              }
            ],
            "repeated": 0,
            "id": 2813
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              }
            ],
            "repeated": 0,
            "id": 2814
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              },
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              }
            ],
            "repeated": 0,
            "id": 2815
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "ValueName",
                "value": "UserenvDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2816
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 2817
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 2818
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "ValueName",
                "value": "GpSvcDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2819
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 2820
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 2821
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 2822
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 2823
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000039c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000003a0"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 2824
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a8"
              }
            ],
            "repeated": 0,
            "id": 2825
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2826
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2827
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2828
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2829
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00ky\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00@\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xa4\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2830
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2831
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000003a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2832
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates"
              },
              {
                "name": "Handle",
                "value": "0x000003a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates"
              }
            ],
            "repeated": 0,
            "id": 2833
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2834
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2835
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              }
            ],
            "repeated": 0,
            "id": 2836
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003ac"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2837
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2838
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2839
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003ac"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2840
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2841
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2842
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003ac"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2843
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2844
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2845
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 2846
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2847
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2848
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2849
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2850
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2851
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2852
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2853
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000320"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2854
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2855
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2856
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Handle",
                "value": "0x000003bc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              }
            ],
            "repeated": 0,
            "id": 2857
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003bc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2858
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2859
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2860
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003bc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2861
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2862
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2863
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003bc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2864
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2865
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2866
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              }
            ],
            "repeated": 0,
            "id": 2867
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2868
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2869
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2870
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 2871
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2872
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2873
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 2874
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2875
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2876
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 2877
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2878
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2879
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2880
          },
          {
            "timestamp": "2026-02-10 09:22:10,907",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2881
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2882
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2883
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2884
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2885
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2886
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2887
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a8"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Handle",
                "value": "0x000003d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              }
            ],
            "repeated": 0,
            "id": 2888
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2889
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2890
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2891
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2892
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2893
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2894
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2895
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2896
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2897
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d8"
              }
            ],
            "repeated": 0,
            "id": 2898
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2899
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2900
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2901
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "3"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2902
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 2903
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e4"
              },
              {
                "name": "SubKey",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 2904
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2905
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2906
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              }
            ],
            "repeated": 0,
            "id": 2907
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 2908
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e4"
              },
              {
                "name": "SubKey",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 2909
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2910
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2911
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              }
            ],
            "repeated": 0,
            "id": 2912
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 2913
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e4"
              },
              {
                "name": "SubKey",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 2914
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2915
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2916
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              }
            ],
            "repeated": 0,
            "id": 2917
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2918
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2919
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2920
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2921
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 2922
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e4"
              },
              {
                "name": "SubKey",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 2923
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2924
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2925
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              }
            ],
            "repeated": 0,
            "id": 2926
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2927
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000298"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2928
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2929
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2930
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              }
            ],
            "repeated": 0,
            "id": 2931
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2932
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2933
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2934
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2935
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2936
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2937
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2938
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2939
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2940
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              }
            ],
            "repeated": 0,
            "id": 2941
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2942
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2943
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2944
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f4"
              }
            ],
            "repeated": 0,
            "id": 2945
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2946
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2947
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f4"
              }
            ],
            "repeated": 0,
            "id": 2948
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003f4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2949
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2950
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f4"
              }
            ],
            "repeated": 0,
            "id": 2951
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2952
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2953
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2954
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2955
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2956
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2957
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2958
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2959
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2960
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000364"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2961
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2962
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000370"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2963
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2964
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2965
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2966
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2967
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2968
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000394"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2969
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2970
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2971
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2972
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2973
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2974
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2975
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2976
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2977
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2978
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2979
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2980
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2981
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2982
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2983
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2984
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2985
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2986
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2987
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2988
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2989
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2990
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2991
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2992
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2993
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2994
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2995
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000254"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 2996
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000360"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2997
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2998
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 2999
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000360"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3000
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3001
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 3002
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000360"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3003
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3004
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 3005
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 3006
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3007
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3008
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3009
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 3010
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3011
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3012
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 3013
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3014
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3015
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3016
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 3017
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000040c"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 3018
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 3019
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 3020
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              }
            ],
            "repeated": 0,
            "id": 3021
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3022
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 3023
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 3024
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3025
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3026
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 3027
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3028
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3029
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 3030
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3031
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3032
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 3033
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              }
            ],
            "repeated": 0,
            "id": 3034
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3035
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3036
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3037
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3038
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3039
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3040
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3041
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000290"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3042
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3043
          },
          {
            "timestamp": "2026-02-10 09:22:10,923",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3044
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3045
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3046
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3047
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3048
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3049
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3050
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3051
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000300"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3052
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3053
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3054
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000308"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Handle",
                "value": "0x0000042c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              }
            ],
            "repeated": 0,
            "id": 3055
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3056
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3057
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3058
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3059
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3060
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3061
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3062
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3063
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3064
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000042c"
              }
            ],
            "repeated": 0,
            "id": 3065
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3066
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aa5000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3067
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3068
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3069
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3070
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3071
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3072
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3073
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000030c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3074
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3075
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3076
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Handle",
                "value": "0x0000043c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              }
            ],
            "repeated": 0,
            "id": 3077
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3078
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3079
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3080
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3081
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3082
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3083
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3084
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3085
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3086
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000043c"
              }
            ],
            "repeated": 0,
            "id": 3087
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3088
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3089
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3090
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3091
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3092
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3093
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3094
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000310"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3095
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3096
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3097
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aa8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3098
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3099
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertLastSyncTime"
              },
              {
                "name": "Data",
                "value": "\\xb3@\\xd9\\xb0n\\x9a\\xdc\\x01"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime"
              }
            ],
            "repeated": 0,
            "id": 3100
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3101
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3102
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000044c"
              }
            ],
            "repeated": 0,
            "id": 3103
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3104
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3105
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3106
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3107
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00kz\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xe8\\xa3\\xa8\\x90H\\x02\\x00\\x00\\x88\\xa1\\xa8\\x90H\\x02\\x00\\x00\\x10\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00H\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3108
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3109
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3110
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000448"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3111
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3112
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3113
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertEncodedCtl"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl"
              }
            ],
            "repeated": 0,
            "id": 3114
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aa9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3115
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertEncodedCtl"
              },
              {
                "name": "Data",
                "value": "0\\x82\\x17\\xcc\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x17\\xbd0\\x82\\x17\\xb9\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x000\\x82\\x08(\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x08\\x190\\x82\\x08\\x150\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x07\\xa00\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<\\xac\\xeejW0\\x12\\x04\\x10\\x1e%\\xf2N\\xdf"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl"
              }
            ],
            "repeated": 0,
            "id": 3116
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3117
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aad000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3118
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3119
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ab0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3120
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ab2000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3121
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ab4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3122
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3123
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "AutoFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags"
              }
            ],
            "repeated": 0,
            "id": 3124
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ab7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3125
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "DisableAutoFlushProcessNameList"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList"
              }
            ],
            "repeated": 0,
            "id": 3126
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "AutoFlushFirstDeltaSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds"
              }
            ],
            "repeated": 0,
            "id": 3127
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "AutoFlushNextDeltaSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds"
              }
            ],
            "repeated": 0,
            "id": 3128
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 3129
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3130
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3131
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3132
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3133
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3134
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllCreateIndirectData"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData"
              }
            ],
            "repeated": 0,
            "id": 3135
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 3136
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 3137
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3138
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\MSISIP.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3139
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "MsiSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3140
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3141
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3142
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3143
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3144
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3145
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3146
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3147
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 3148
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 3149
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3150
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3151
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3152
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3153
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 3154
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 3155
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3156
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3157
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxBundleSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3158
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3159
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 3160
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 3161
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3162
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3163
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3164
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3165
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3166
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3167
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3168
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3169
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3170
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3171
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 3172
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 3173
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3174
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3175
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "P7SipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3176
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3177
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 3178
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 3179
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 3180
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pwrshsip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3181
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PsCreateHash"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3182
          },
          {
            "timestamp": "2026-02-10 09:22:10,938",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3183
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3184
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3185
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3186
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3187
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3188
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3189
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3190
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3191
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3192
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3193
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipCreateHash"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3194
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3195
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3196
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3197
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3198
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3199
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3200
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3201
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3202
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3203
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3204
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3205
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3206
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3207
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3208
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3209
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3210
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3211
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3212
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3213
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 3214
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 3215
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3216
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3217
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3218
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3219
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 3220
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 3221
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3222
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3223
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxBundleSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3224
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3225
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3226
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3227
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3228
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3229
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3230
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3231
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3232
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3233
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3234
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3235
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3236
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3237
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\"
              }
            ],
            "repeated": 0,
            "id": 3238
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3239
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3240
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3241
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3242
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllCreateIndirectData"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllCreateIndirectData"
              }
            ],
            "repeated": 0,
            "id": 3243
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3244
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3245
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3246
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477d80"
              }
            ],
            "repeated": 0,
            "id": 3247
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3248
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3249
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3250
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObjectEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObjectEx"
              }
            ],
            "repeated": 0,
            "id": 3251
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3252
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3253
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3254
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObjectEx"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx"
              }
            ],
            "repeated": 0,
            "id": 3255
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.1.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3256
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.1.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3257
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3258
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3259
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssReceiptEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3260
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3261
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1"
              }
            ],
            "repeated": 0,
            "id": 3262
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1"
              }
            ],
            "repeated": 0,
            "id": 3263
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3264
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3265
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssReceiptRequestEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3266
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3267
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.11"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11"
              }
            ],
            "repeated": 0,
            "id": 3268
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.11"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11"
              }
            ],
            "repeated": 0,
            "id": 3269
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3270
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3271
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssKeyExchPreferenceEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3272
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3273
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.12"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12"
              }
            ],
            "repeated": 0,
            "id": 3274
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.12"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12"
              }
            ],
            "repeated": 0,
            "id": 3275
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3276
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3277
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssSignCertificateEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3278
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3279
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2"
              }
            ],
            "repeated": 0,
            "id": 3280
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.2"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2"
              }
            ],
            "repeated": 0,
            "id": 3281
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3282
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3283
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssSecurityLabelEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3284
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3285
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3"
              }
            ],
            "repeated": 0,
            "id": 3286
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.3"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3"
              }
            ],
            "repeated": 0,
            "id": 3287
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3288
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3289
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssMLHistoryEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3290
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3291
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4"
              }
            ],
            "repeated": 0,
            "id": 3292
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.4"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4"
              }
            ],
            "repeated": 0,
            "id": 3293
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3294
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3295
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssContentHintEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3296
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3297
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\"
              }
            ],
            "repeated": 0,
            "id": 3298
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3299
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3300
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3301
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3302
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3303
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3304
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3305
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObject"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObject"
              }
            ],
            "repeated": 0,
            "id": 3306
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3307
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3308
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3309
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObject"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject"
              }
            ],
            "repeated": 0,
            "id": 3310
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "#2000"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000"
              }
            ],
            "repeated": 0,
            "id": 3311
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2000"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000"
              }
            ],
            "repeated": 0,
            "id": 3312
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 3313
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3314
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpAgencyInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3315
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3316
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "#2001"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001"
              }
            ],
            "repeated": 0,
            "id": 3317
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2001"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001"
              }
            ],
            "repeated": 0,
            "id": 3318
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3319
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3320
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcMinimalCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3321
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3322
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "#2002"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002"
              }
            ],
            "repeated": 0,
            "id": 3323
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2002"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002"
              }
            ],
            "repeated": 0,
            "id": 3324
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 3325
          },
          {
            "timestamp": "2026-02-10 09:22:10,954",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3326
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcFinancialCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3327
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3328
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "#2003"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003"
              }
            ],
            "repeated": 0,
            "id": 3329
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2003"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003"
              }
            ],
            "repeated": 0,
            "id": 3330
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3331
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3332
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcIndirectDataContentEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3333
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3334
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "#2004"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004"
              }
            ],
            "repeated": 0,
            "id": 3335
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2004"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004"
              }
            ],
            "repeated": 0,
            "id": 3336
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3337
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3338
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3339
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3340
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "#2005"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005"
              }
            ],
            "repeated": 0,
            "id": 3341
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2005"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005"
              }
            ],
            "repeated": 0,
            "id": 3342
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3343
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3344
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3345
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3346
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "#2006"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006"
              }
            ],
            "repeated": 0,
            "id": 3347
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2006"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006"
              }
            ],
            "repeated": 0,
            "id": 3348
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 3349
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3350
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcStatementTypeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3351
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3352
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "#2007"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007"
              }
            ],
            "repeated": 0,
            "id": 3353
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2007"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007"
              }
            ],
            "repeated": 0,
            "id": 3354
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3355
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3356
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpOpusInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3357
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3358
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "#2008"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008"
              }
            ],
            "repeated": 0,
            "id": 3359
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2008"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008"
              }
            ],
            "repeated": 0,
            "id": 3360
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3361
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3362
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3363
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3364
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "#2009"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009"
              }
            ],
            "repeated": 0,
            "id": 3365
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2009"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009"
              }
            ],
            "repeated": 0,
            "id": 3366
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3367
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3368
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3369
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3370
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "#2010"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010"
              }
            ],
            "repeated": 0,
            "id": 3371
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2010"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010"
              }
            ],
            "repeated": 0,
            "id": 3372
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 3373
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3374
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1IntentToSealAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3375
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3376
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "#2011"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011"
              }
            ],
            "repeated": 0,
            "id": 3377
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2011"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011"
              }
            ],
            "repeated": 0,
            "id": 3378
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3379
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3380
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingSignatureAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3381
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3382
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "#2012"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012"
              }
            ],
            "repeated": 0,
            "id": 3383
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2012"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012"
              }
            ],
            "repeated": 0,
            "id": 3384
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3385
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3386
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingTimestampAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3387
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3388
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "#2130"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130"
              }
            ],
            "repeated": 0,
            "id": 3389
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2130"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130"
              }
            ],
            "repeated": 0,
            "id": 3390
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "48"
              }
            ],
            "repeated": 0,
            "id": 3391
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3392
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSigInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3393
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3394
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "#2221"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221"
              }
            ],
            "repeated": 0,
            "id": 3395
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2221"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221"
              }
            ],
            "repeated": 0,
            "id": 3396
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 3397
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3398
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatNameValueEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3399
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3400
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "#2222"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222"
              }
            ],
            "repeated": 0,
            "id": 3401
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2222"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222"
              }
            ],
            "repeated": 0,
            "id": 3402
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3403
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3404
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3405
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3406
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "#2223"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223"
              }
            ],
            "repeated": 0,
            "id": 3407
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2223"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223"
              }
            ],
            "repeated": 0,
            "id": 3408
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3409
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3410
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfo2Encode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3411
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3412
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1"
              }
            ],
            "repeated": 0,
            "id": 3413
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1"
              }
            ],
            "repeated": 0,
            "id": 3414
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 3415
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3416
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatNameValueEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3417
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3418
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "18"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2"
              }
            ],
            "repeated": 0,
            "id": 3419
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.2"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2"
              }
            ],
            "repeated": 0,
            "id": 3420
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3421
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3422
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3423
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3424
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "19"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3"
              }
            ],
            "repeated": 0,
            "id": 3425
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.3"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3"
              }
            ],
            "repeated": 0,
            "id": 3426
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3427
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3428
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfo2Encode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3429
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3430
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "20"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.16.1.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3431
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.16.1.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3432
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3433
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptdlg.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3434
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EncodeAttrSequence"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3435
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3436
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "21"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.16.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4"
              }
            ],
            "repeated": 0,
            "id": 3437
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.16.4"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4"
              }
            ],
            "repeated": 0,
            "id": 3438
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3439
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptdlg.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3440
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EncodeRecipientID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3441
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3442
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "22"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.10"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10"
              }
            ],
            "repeated": 0,
            "id": 3443
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.10"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10"
              }
            ],
            "repeated": 0,
            "id": 3444
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 3445
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3446
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpAgencyInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3447
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3448
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "23"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.11"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11"
              }
            ],
            "repeated": 0,
            "id": 3449
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.11"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11"
              }
            ],
            "repeated": 0,
            "id": 3450
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 3451
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3452
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcStatementTypeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3453
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3454
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "24"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.12"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12"
              }
            ],
            "repeated": 0,
            "id": 3455
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.12"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12"
              }
            ],
            "repeated": 0,
            "id": 3456
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3457
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3458
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpOpusInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3459
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3460
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "25"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.15"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15"
              }
            ],
            "repeated": 0,
            "id": 3461
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.15"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15"
              }
            ],
            "repeated": 0,
            "id": 3462
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3463
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3464
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3465
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3466
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "26"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.20"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20"
              }
            ],
            "repeated": 0,
            "id": 3467
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.20"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20"
              }
            ],
            "repeated": 0,
            "id": 3468
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3469
          },
          {
            "timestamp": "2026-02-10 09:22:10,969",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3470
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3471
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3472
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "27"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25"
              }
            ],
            "repeated": 0,
            "id": 3473
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.25"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25"
              }
            ],
            "repeated": 0,
            "id": 3474
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3475
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3476
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3477
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3478
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "28"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.26"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26"
              }
            ],
            "repeated": 0,
            "id": 3479
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.26"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26"
              }
            ],
            "repeated": 0,
            "id": 3480
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3481
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3482
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcMinimalCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3483
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3484
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "29"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.27"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27"
              }
            ],
            "repeated": 0,
            "id": 3485
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.27"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27"
              }
            ],
            "repeated": 0,
            "id": 3486
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 3487
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3488
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcFinancialCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3489
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3490
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "30"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.28"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28"
              }
            ],
            "repeated": 0,
            "id": 3491
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.28"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28"
              }
            ],
            "repeated": 0,
            "id": 3492
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3493
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3494
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3495
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3496
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "31"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.30"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30"
              }
            ],
            "repeated": 0,
            "id": 3497
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.30"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30"
              }
            ],
            "repeated": 0,
            "id": 3498
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "48"
              }
            ],
            "repeated": 0,
            "id": 3499
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3500
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSigInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3501
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3502
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "32"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4"
              }
            ],
            "repeated": 0,
            "id": 3503
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.4"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4"
              }
            ],
            "repeated": 0,
            "id": 3504
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3505
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3506
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcIndirectDataContentEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3507
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3508
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "33"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2"
              }
            ],
            "repeated": 0,
            "id": 3509
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.2"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2"
              }
            ],
            "repeated": 0,
            "id": 3510
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 3511
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3512
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1IntentToSealAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3513
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3514
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "34"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3"
              }
            ],
            "repeated": 0,
            "id": 3515
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.3"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3"
              }
            ],
            "repeated": 0,
            "id": 3516
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3517
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3518
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingSignatureAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3519
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3520
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "35"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4"
              }
            ],
            "repeated": 0,
            "id": 3521
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.4"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4"
              }
            ],
            "repeated": 0,
            "id": 3522
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000464"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3523
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3524
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingTimestampAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3525
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 3526
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "36"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\"
              }
            ],
            "repeated": 0,
            "id": 3527
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3528
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3529
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3530
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3531
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147e0d0"
              }
            ],
            "repeated": 0,
            "id": 3532
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3533
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3534
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 3535
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3536
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 3537
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 3538
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 3539
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "Buffer",
                "value": "; Copyright 2004, Check Point Software Technologies, Inc.\r\n;  vnaap.inf\r\n;\r\n; Setup file for Check Point Virtual Network Adapter\r\n; \r\n\r\n[version]\r\nsignature=\"$Windows NT$\"\t\t\t\t\t\t; INF designed for NT-based operating system (Win2k , WinXP etc.)\r\nCompatible  "
              },
              {
                "name": "Length",
                "value": "4799"
              }
            ],
            "repeated": 0,
            "id": 3540
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3541
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7be50"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3542
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3543
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3544
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptCreateHash",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Algid",
                "value": "0x00008004",
                "pretty_value": "SHA1"
              },
              {
                "name": "CryptKey",
                "value": "0x00000000"
              },
              {
                "name": "Hash object",
                "value": "0x24890a9ded0"
              }
            ],
            "repeated": 0,
            "id": 3545
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptHashData",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CryptHash",
                "value": "0x24890a9ded0"
              },
              {
                "name": "Buffer",
                "value": "; Copyright 2004, Check Point Software Technologies, Inc.\r\n;  vnaap.inf\r\n;\r\n; Setup file for Check Point Virtual Network Adapter\r\n; \r\n\r\n[version]\r\nsignature=\"$Windows NT$\"\t\t\t\t\t\t; INF designed for NT-based operating system (Win2k , WinXP etc.)\r\nCompatible  = 0\t\t\t\t\t\t\t\t\t; INF is not compitable for windows 9x\r\nCatalogFile = vnaap.cat \t\t\t\t\t\t; The signed catalog file\r\nClass=Net\r\nClassGUID = {4d36e972-e325-11ce-bfc1-08002be10318}\r\nProvider=%CP%\r\nDriverVer = 07/27/2022,2.1.3.0\r\nPnpLockDown = 1\r\n\r\n[Manufacturer]\r\n%CP% = Models,NTamd64,NTx86\r\n\r\n[ControlFlags]\r\n\r\n[Models.NTx86]\r\n; DisplayName               Section         hw-id\r\n; -------------------------------------------------\r\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\r\n\r\n[Models.NTamd64]\r\n; DisplayName               Section       hw-id\r\n; -------------------------------------------------\r\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\r\n\r\n;------------------------------------------------------------------------------------------------------------\r\n; A DestinationDirs section specifies the target destination directory or directories \r\n; for all copy, delete, and/or rename operations on files referenced by name elsewhere in the INF file. \r\n;System directory \r\n;\r\n;   11   -    This is equivalent to %windir%\\system32 for NT-based systems and \r\n;\t\t\t\t to %windir%\\system for Windows 9x/Me.\r\n;   12   -    Drivers directory\r\n;\t      This is equivalent to %windir%\\system32\\drivers on NT-based platforms and \r\n;\t\t\t\t to %windir%\\system\\IoSubsys on Windows 9x/Me platforms. \r\n;  VNA_[ProductName]_CopyFiles - section that list the driver files \r\n;  VNAInstaller_CopyFiles -  section that list the co-installer file\r\n;------------------------------------------------------------------------------------------------------------\r\n\r\n[DestinationDirs]\r\nVNA_Apollo_CopyFiles            =12\r\nVNA_Apollo_Installer_CopyFiles  =11\r\n\r\n;-------------------------------------------------------------\r\n; NT-based OS specific section\r\n;-------------------------------------------------------------"
              },
              {
                "name": "Length",
                "value": "4799"
              }
            ],
            "repeated": 0,
            "id": 3546
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890aba000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3547
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3548
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3549
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3550
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3551
          },
          {
            "timestamp": "2026-02-10 09:22:10,985",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 3552
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c1f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3553
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3554
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3555
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3556
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3557
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3558
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001\\x000\\x000\\x005\\x006\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3559
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04J1\\x000\\x007\\x00d\\x003\\x002\\x007\\x005\\x00-\\x003\\x001\\x00a\\x000\\x00-\\x004\\x003\\x00c\\x005\\x00-\\x008\\x00f\\x00b\\x004\\x00-\\x007\\x008\\x00e\\x00c\\x002\\x006\\x001\\x007\\x00b\\x001\\x001\\x008\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3560
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3561
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3562
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3563
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x12c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3564
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3565
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3566
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248909d8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3567
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3568
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3569
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3570
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3571
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3572
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14c\\x8c\\xf9+MG\\x18\\x85\\xe1\\xdb\\x95\\xa6\\xbc\\xce@*\\xdb\\x91\\xc1\\x81"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3573
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a3b5d85",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 3574
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3575
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3576
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3577
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3578
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3579
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3580
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3581
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3582
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3583
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3584
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3585
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 3586
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43550",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 3587
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3588
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3589
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004a4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3590
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004a4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 3591
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a760"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3592
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3593
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3594
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3595
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890abf000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3596
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ac4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3597
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ac6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3598
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3599
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 3600
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ac7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3601
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 3602
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3603
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3604
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3605
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3606
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3607
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3608
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3609
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3610
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3611
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3612
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3613
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3614
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3615
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3616
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3617
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3618
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3619
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3620
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3621
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3622
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3623
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3624
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3625
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3626
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3627
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3628
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3629
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3630
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3631
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3632
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3633
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3634
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3635
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3636
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 14,
            "id": 3637
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3638
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3639
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3640
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3641
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 7,
            "id": 3642
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 4,
            "id": 3643
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3644
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3645
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3646
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3647
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3648
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3649
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3650
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3651
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3652
          },
          {
            "timestamp": "2026-02-10 09:22:11,001",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3653
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3654
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3655
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3656
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3657
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3658
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3659
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3660
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 3661
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 3662
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 1,
            "id": 3663
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 3664
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3665
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3666
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3667
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3668
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3669
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3670
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b5586",
            "parentcaller": "0x7ff70a3b57a1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\xfc\\xbf\\x9a%\\xa7P\\xceG\\xaf\\x08h\\xc9\\xa7\\xd73f\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x12\\x00\\x00\\x006\\x00.\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3671
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3672
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3673
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3674
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3675
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00t:\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3676
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "t:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3677
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3678
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3679
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890acb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00009000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3680
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3681
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3682
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3683
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 3684
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3685
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3686
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3687
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3688
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3689
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3690
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb9:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3691
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3692
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3693
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3694
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3695
          },
          {
            "timestamp": "2026-02-10 09:22:11,016",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 3696
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3697
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3698
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3699
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3700
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3701
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3702
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf2:\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3703
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3704
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3705
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "w;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3706
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3707
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3708
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "w;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3709
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "w;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3710
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "w;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3711
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3712
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3713
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00w;\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3714
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "w;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3715
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3716
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3717
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3718
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3719
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3720
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3721
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3722
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3723
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3724
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4607",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 3725
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b4607",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 3726
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b46f8",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 3727
          },
          {
            "timestamp": "2026-02-10 09:22:11,032",
            "thread_id": "348",
            "caller": "0x7ff70a3b46f8",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 3728
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b475f",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3729
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3730
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 3731
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a990"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3732
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3733
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3734
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 3735
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3736
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3737
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3738
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3739
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 3740
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 3741
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "Buffer",
                "value": "; Copyright 2004, Check Point Software Technologies, Inc.\r\n;  vnaap.inf\r\n;\r\n; Setup file for Check Point Virtual Network Adapter\r\n; \r\n\r\n[version]\r\nsignature=\"$Windows NT$\"\t\t\t\t\t\t; INF designed for NT-based operating system (Win2k , WinXP etc.)\r\nCompatible  "
              },
              {
                "name": "Length",
                "value": "4799"
              }
            ],
            "repeated": 0,
            "id": 3742
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3743
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a810"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3744
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptCreateHash",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Algid",
                "value": "0x00008004",
                "pretty_value": "SHA1"
              },
              {
                "name": "CryptKey",
                "value": "0x00000000"
              },
              {
                "name": "Hash object",
                "value": "0x24890a9df40"
              }
            ],
            "repeated": 0,
            "id": 3745
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptHashData",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CryptHash",
                "value": "0x24890a9df40"
              },
              {
                "name": "Buffer",
                "value": "; Copyright 2004, Check Point Software Technologies, Inc.\r\n;  vnaap.inf\r\n;\r\n; Setup file for Check Point Virtual Network Adapter\r\n; \r\n\r\n[version]\r\nsignature=\"$Windows NT$\"\t\t\t\t\t\t; INF designed for NT-based operating system (Win2k , WinXP etc.)\r\nCompatible  = 0\t\t\t\t\t\t\t\t\t; INF is not compitable for windows 9x\r\nCatalogFile = vnaap.cat \t\t\t\t\t\t; The signed catalog file\r\nClass=Net\r\nClassGUID = {4d36e972-e325-11ce-bfc1-08002be10318}\r\nProvider=%CP%\r\nDriverVer = 07/27/2022,2.1.3.0\r\nPnpLockDown = 1\r\n\r\n[Manufacturer]\r\n%CP% = Models,NTamd64,NTx86\r\n\r\n[ControlFlags]\r\n\r\n[Models.NTx86]\r\n; DisplayName               Section         hw-id\r\n; -------------------------------------------------\r\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\r\n\r\n[Models.NTamd64]\r\n; DisplayName               Section       hw-id\r\n; -------------------------------------------------\r\n%VNA.DeviceDesc.Apollo% = VNA_Apollo.ndi, CP_APVNA\r\n\r\n;------------------------------------------------------------------------------------------------------------\r\n; A DestinationDirs section specifies the target destination directory or directories \r\n; for all copy, delete, and/or rename operations on files referenced by name elsewhere in the INF file. \r\n;System directory \r\n;\r\n;   11   -    This is equivalent to %windir%\\system32 for NT-based systems and \r\n;\t\t\t\t to %windir%\\system for Windows 9x/Me.\r\n;   12   -    Drivers directory\r\n;\t      This is equivalent to %windir%\\system32\\drivers on NT-based platforms and \r\n;\t\t\t\t to %windir%\\system\\IoSubsys on Windows 9x/Me platforms. \r\n;  VNA_[ProductName]_CopyFiles - section that list the driver files \r\n;  VNAInstaller_CopyFiles -  section that list the co-installer file\r\n;------------------------------------------------------------------------------------------------------------\r\n\r\n[DestinationDirs]\r\nVNA_Apollo_CopyFiles            =12\r\nVNA_Apollo_Installer_CopyFiles  =11\r\n\r\n;-------------------------------------------------------------\r\n; NT-based OS specific section\r\n;-------------------------------------------------------------"
              },
              {
                "name": "Length",
                "value": "4799"
              }
            ],
            "repeated": 0,
            "id": 3746
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3747
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3748
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 3749
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3750
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3751
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3752
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3753
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3754
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3755
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3756
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3757
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3758
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3759
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3760
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverFinalPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3761
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3762
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3763
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3764
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverInitializePolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3765
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3766
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3767
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3768
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3769
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3770
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3771
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3772
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3773
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3774
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3775
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3776
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3777
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3778
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3779
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3780
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3781
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverCleanupPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3782
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3783
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ad60"
              }
            ],
            "repeated": 0,
            "id": 3784
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverFinalPolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147b880"
              }
            ],
            "repeated": 0,
            "id": 3785
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverInitializePolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1471a80"
              }
            ],
            "repeated": 0,
            "id": 3786
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1478770"
              }
            ],
            "repeated": 0,
            "id": 3787
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ccc0"
              }
            ],
            "repeated": 0,
            "id": 3788
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147efa0"
              }
            ],
            "repeated": 0,
            "id": 3789
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverCleanupPolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147e970"
              }
            ],
            "repeated": 0,
            "id": 3790
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3791
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 3792
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptAcquireContextA",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": "Microsoft Enhanced RSA and AES Cryptographic Provider"
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 3793
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3794
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00w\\x9d\\x90H\\x02\\x00\\x00\\xae-E\\xe0\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00d\\xd2P\\x91H\\x02\\x00\\x00H\\xa7\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\xb2H\\xc0\\xfe\\x7f\\x00\\x00\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x82\\x9d\\x90H\\x02\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x03\\x9d\\x90H\\x02\\x00\\x00P\\x01\\x9d\\x90H\\x02\\x00\\x00\\x00\\x00\\xb9\\xdf\\xfe\\x7f\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@t\\xa4\\x90H\\x02\\x00\\x00\\x008\\x9d\\x90H\\x02\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb9\\x00\\xae\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x00\\x00\\x00\\x00\\x00\\x00\\xb9\\xdf\\xfe\\x7f\\x00\\x00\\x9a\\x00\\xae\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x80\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3795
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3796
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3797
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004cc"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 3798
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 3799
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "State"
              },
              {
                "name": "Data",
                "value": "146432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State"
              }
            ],
            "repeated": 0,
            "id": 3800
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3801
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3802
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\xa1[I\\xe3\\xfe\\x7f\\x00\\x00\\x10\\x00\\x00\\x00H\\x02\\x00\\x00\\xa9\\xa4\\x00\r\\xa1\\x00\\x00\\x00\\x1bm\\xac\\x80\\xbe\\xd3\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x87\\x00\\x9c\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00d\\xd2P\\x91H\\x02\\x00\\x00\\xa8\\xa7\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\xb2H\\xc0\\xfe\\x7f\\x00\\x00\\xca\\xac\\x00f\\xfe\\x7f\\x00\\x00\\xc8\\xa7j\\xc0\\xfe\\x7f\\x00\\x00\\x81\\x04G\\xc0\\xfe\\x7f\\x00\\x00\\xe0\\xa9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xb0\\xfbT\\x91H\\x02\\x00\\x00\\xc0\\xfbT\\x91H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00o\\xe2J\\xe3\\xfe\\x7f\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3803
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3804
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3805
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d0"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Internet Explorer\\Security"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\Security"
              }
            ],
            "repeated": 0,
            "id": 3806
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3807
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3808
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3809
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xa4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xdbV\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xb8K\\xe1\\xfe\\x7f\\x00\\x00\\x90\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd8\\xaa\\xe7\\xd1\\xa1\\x00\\x00\\x00`\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\xa6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3810
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3811
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3812
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d0"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3813
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3814
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3815
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3816
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3817
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3818
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3819
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3820
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3821
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3822
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3823
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3824
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3825
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubAuthenticode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3826
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3827
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3828
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3829
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubInitialize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3830
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3831
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3832
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3833
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3834
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3835
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3836
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3837
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3838
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3839
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3840
          },
          {
            "timestamp": "2026-02-10 09:22:11,048",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3841
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3842
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3843
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3844
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3845
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3846
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCleanup"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3847
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3848
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ad60"
              }
            ],
            "repeated": 0,
            "id": 3849
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubAuthenticode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147be20"
              }
            ],
            "repeated": 0,
            "id": 3850
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubInitialize"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147c4d0"
              }
            ],
            "repeated": 0,
            "id": 3851
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1478770"
              }
            ],
            "repeated": 0,
            "id": 3852
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ccc0"
              }
            ],
            "repeated": 0,
            "id": 3853
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147efa0"
              }
            ],
            "repeated": 0,
            "id": 3854
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCleanup"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147f3b0"
              }
            ],
            "repeated": 0,
            "id": 3855
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 3856
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": false,
            "return": "0xffffffff80430006",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "143"
              }
            ],
            "repeated": 0,
            "id": 3857
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 3858
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3859
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3860
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 3861
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a650"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3862
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3863
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3864
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffff80000005",
            "pretty_return": "BUFFER_OVERFLOW",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "18",
                "pretty_value": "FileAllInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 3865
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3866
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3867
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001\\x000\\x000\\x005\\x006\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3868
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04J1\\x000\\x007\\x00d\\x003\\x002\\x007\\x005\\x00-\\x003\\x001\\x00a\\x000\\x00-\\x004\\x003\\x00c\\x005\\x00-\\x008\\x00f\\x00b\\x004\\x00-\\x007\\x008\\x00e\\x00c\\x002\\x006\\x001\\x007\\x00b\\x001\\x001\\x008\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3869
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3870
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3871
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3872
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x12c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3873
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "1\\x82\\x01%06\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x011(0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x000@\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x011200\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x000E\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x0417050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14c\\x8c\\xf9+MG\\x18\\x85\\xe1\\xdb\\x95\\xa6\\xbc\\xce@*\\xdb\\x91\\xc1\\x810b\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x021T0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x001\\x00D\\x000\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3874
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3875
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3876
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3877
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14c\\x8c\\xf9+MG\\x18\\x85\\xe1\\xdb\\x95\\xa6\\xbc\\xce@*\\xdb\\x91\\xc1\\x81"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3878
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 3879
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3880
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3881
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3882
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d8"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllGetCaps"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps"
              }
            ],
            "repeated": 0,
            "id": 3883
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3884
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3885
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3886
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3887
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3888
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3889
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3890
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3891
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3892
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3893
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3894
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3895
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3896
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3897
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3898
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3899
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3900
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3901
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3902
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3903
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3904
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3905
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3906
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3907
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3908
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3909
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3910
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3911
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3912
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3913
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3914
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3915
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3916
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3917
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3918
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3919
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3920
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3921
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3922
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3923
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3924
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3925
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\"
              }
            ],
            "repeated": 0,
            "id": 3926
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 3927
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3928
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3929
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3930
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d8"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllGetCaps"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllGetCaps"
              }
            ],
            "repeated": 0,
            "id": 3931
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3932
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3933
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3934
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477cf0"
              }
            ],
            "repeated": 0,
            "id": 3935
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x7f0\\x82\\x04g\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdd\\xdcA T\\xe2v\\xc9&\\x00\\x00\\x00\\x00\\x00\\xdd0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195806Z\\x17\r230308195806Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3936
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3937
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248909d9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3938
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "crypt32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0b90000"
              }
            ],
            "repeated": 0,
            "id": 3939
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0b90000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "crypt32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3940
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0b90000"
              },
              {
                "name": "FunctionName",
                "value": "CryptVerifyTimeStampSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee0b93ca0"
              }
            ],
            "repeated": 0,
            "id": 3941
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "3\\xa2\\x08\\x00\\x00\\x00\\x00\\x00\\xe7\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xebL\\xb6&u \\x06\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x88\\x0e\\x00\\x00\\x10\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x9b\\xa0\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3942
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " 6\\xa4\\x90H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3943
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\x99\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x803\\x00D\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00=\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00+\\x00\\x00\\x00\\x00\\x00\\x00\\x00F\\x02\\x00\\x00\\x00\\x00\\x00\\x00T\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3944
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 3945
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Control Panel\\International"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International"
              }
            ],
            "repeated": 0,
            "id": 3946
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3947
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "LocaleName"
              },
              {
                "name": "ValueBuffer",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\LocaleName"
              }
            ],
            "repeated": 0,
            "id": 3948
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sList"
              },
              {
                "name": "ValueBuffer",
                "value": ";"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sList"
              }
            ],
            "repeated": 0,
            "id": 3949
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sDecimal"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sDecimal"
              }
            ],
            "repeated": 0,
            "id": 3950
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sThousand"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sThousand"
              }
            ],
            "repeated": 0,
            "id": 3951
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sGrouping"
              }
            ],
            "repeated": 0,
            "id": 3952
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sNativeDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "0123456789"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNativeDigits"
              }
            ],
            "repeated": 0,
            "id": 3953
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sMonDecimalSep"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonDecimalSep"
              }
            ],
            "repeated": 0,
            "id": 3954
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sMonThousandSep"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonThousandSep"
              }
            ],
            "repeated": 0,
            "id": 3955
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sMonGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonGrouping"
              }
            ],
            "repeated": 0,
            "id": 3956
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sPositiveSign"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sPositiveSign"
              }
            ],
            "repeated": 0,
            "id": 3957
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sNegativeSign"
              },
              {
                "name": "ValueBuffer",
                "value": "-"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNegativeSign"
              }
            ],
            "repeated": 0,
            "id": 3958
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sTimeFormat"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm:ss"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sTimeFormat"
              }
            ],
            "repeated": 0,
            "id": 3959
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sShortTime"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortTime"
              }
            ],
            "repeated": 0,
            "id": 3960
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "s1159"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s1159"
              }
            ],
            "repeated": 0,
            "id": 3961
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "s2359"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s2359"
              }
            ],
            "repeated": 0,
            "id": 3962
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sShortDate"
              },
              {
                "name": "ValueBuffer",
                "value": "dd.MM.yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortDate"
              }
            ],
            "repeated": 0,
            "id": 3963
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sYearMonth"
              },
              {
                "name": "ValueBuffer",
                "value": "MMMM yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sYearMonth"
              }
            ],
            "repeated": 0,
            "id": 3964
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sLongDate"
              },
              {
                "name": "ValueBuffer",
                "value": "d MMMM yyyy '\\x433.'"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sLongDate"
              }
            ],
            "repeated": 0,
            "id": 3965
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iCountry"
              },
              {
                "name": "ValueBuffer",
                "value": "7"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCountry"
              }
            ],
            "repeated": 0,
            "id": 3966
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iMeasure"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iMeasure"
              }
            ],
            "repeated": 0,
            "id": 3967
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iPaperSize"
              },
              {
                "name": "ValueBuffer",
                "value": "9"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iPaperSize"
              }
            ],
            "repeated": 0,
            "id": 3968
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iDigits"
              }
            ],
            "repeated": 0,
            "id": 3969
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iLZero"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iLZero"
              }
            ],
            "repeated": 0,
            "id": 3970
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iNegNumber"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegNumber"
              }
            ],
            "repeated": 0,
            "id": 3971
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "NumShape"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\NumShape"
              }
            ],
            "repeated": 0,
            "id": 3972
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iCurrDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrDigits"
              }
            ],
            "repeated": 0,
            "id": 3973
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iCurrency"
              },
              {
                "name": "ValueBuffer",
                "value": "3"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrency"
              }
            ],
            "repeated": 0,
            "id": 3974
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iNegCurr"
              },
              {
                "name": "ValueBuffer",
                "value": "8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegCurr"
              }
            ],
            "repeated": 0,
            "id": 3975
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iFirstDayOfWeek"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstDayOfWeek"
              }
            ],
            "repeated": 0,
            "id": 3976
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iFirstWeekOfYear"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstWeekOfYear"
              }
            ],
            "repeated": 0,
            "id": 3977
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "sCurrency"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x20bd"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency"
              }
            ],
            "repeated": 0,
            "id": 3978
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "iCalendarType"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType"
              }
            ],
            "repeated": 0,
            "id": 3979
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              }
            ],
            "repeated": 0,
            "id": 3980
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3981
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3982
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a0"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 3983
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a0"
              },
              {
                "name": "ValueName",
                "value": "ru"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru"
              }
            ],
            "repeated": 0,
            "id": 3984
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01@\\x02\\x01\\x01\\x06\n+\\x06\\x01\\x04\\x01\\x84Y\n\\x03\\x01010\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x00\\x04 '?\\x02\\xe8N\\x89!I\\xc1\\x8f?Zd\\x81\\xdb\\xb8@\\x0f\\xe7*\\x05\\xc5\\x05\\xff`\\x18\\xff)\\xa2TO\\x8b\\x02\\x06b\\xde\\x881W@\\x18\\x1320220728115701.813Z0\\x04\\x80\\x02\\x01\\xf4\\xa0\\x81\\xd8\\xa4\\x81\\xd50\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Ireland Operations Limited1&0$\\x06\\x03U\\x04\\x0b\\x13\\x1d"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3985
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3986
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01@\\x02\\x01\\x01\\x06\n+\\x06\\x01\\x04\\x01\\x84Y\n\\x03\\x01010\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x00\\x04 '?\\x02\\xe8N\\x89!I\\xc1\\x8f?Zd\\x81\\xdb\\xb8@\\x0f\\xe7*\\x05\\xc5\\x05\\xff`\\x18\\xff)\\xa2TO\\x8b\\x02\\x06b\\xde\\x881W@\\x18\\x1320220728115701.813Z0\\x04\\x80\\x02\\x01\\xf4\\xa0\\x81\\xd8\\xa4\\x81\\xd50\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Ireland Operations Limited1&0$\\x06\\x03U\\x04\\x0b\\x13\\x1d"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3987
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x140\\x82\\x04\\xfc\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\x8f\\xf3Q\\xa8\\xebZr\\xdd\\xcc\\x00\\x01\\x00\\x00\\x01\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r211028192746Z\\x17\r230126192746Z0\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3988
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3989
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3990
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3991
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3992
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3993
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllVerifyEncodedSignature"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllVerifyEncodedSignature"
              }
            ],
            "repeated": 0,
            "id": 3994
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3995
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3996
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3997
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllVerifyEncodedSignature"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllVerifyEncodedSignature"
              }
            ],
            "repeated": 0,
            "id": 3998
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3999
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4000
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4001
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 4002
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4003
          },
          {
            "timestamp": "2026-02-10 09:22:11,063",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4004
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx2"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx2"
              }
            ],
            "repeated": 0,
            "id": 4005
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4006
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4007
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4008
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx2"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx2"
              }
            ],
            "repeated": 0,
            "id": 4009
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4010
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4011
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4012
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\x99W>\\xfe\\xb5\\xcf\\x17\\x1e\\x85\\x93\\x8f\\x82\\xa4\\xba\\xeel:\\xcbM\\xad\\xd0\\xb8\\x01\\xd1U{\\xb2\\xfb;1_\t(\\x82D\\xf4k\\xe5\\xd6\\xb8\\x16\\x9b\\xc0|\\xaa\\x8f\\xc4Q\\x89\\x94\\x10\\xbd\\xdb\\xdb:\\xaeMDLNxx\\x9a\n\\xd9\\x14\\xb1\r6\\x11 \\x1e\\xf4,\\xfe\\x96\\x80M\\xb6\\xc7\\xc2\\xab\\xce:\\xbbz-Xp\\x89\\x96\\xa9/\\x0e\\xb4\\xab\\xeec\\x01\\xab\\x07\\x11c\\xb7\\x1f\\x84\\x01\\x9f.\\xf9i1*#\\xa0\t\\xe4\\xed\\x17\\xa3\\xfa7\t\\x9d\\x8cHx\\xdd\\xf8\\x17x}'\\x00\rc~\\xb4\\xa0f\\x02!.\\xe9,\\xea,Y_\\x9b\\xc6\\xe8=\\xba$\\xd9`O\\xd7r\\\\x984^\\x97w6\\x7f\\xcc?\\xf8S\\x9aqO\\x83\\x19Bl\\xc1\\x1a\\xf0\\xec\\xfb\\xc7\\x03t\\x0f\\xec\\xb5\\x97\\xe3\\xfe\\xbc\\xbe\\x8bE\\xd4`\\xd1O\\x86\\xea\\x9c\\xf9B\\xa4\\xc2o\\xd74p~\\x08;\\x06B_\\x99KA\\x9cmE.\\x9f\\x85ON\\x11\\xc9\\x9b\\xa9\\x91\\x03\\x02\\xf9\\xcb\\xcc\\xe9\\xb5a\\x08\\xa1\\xc6\\xd3y"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4013
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "device",
            "api": "NtDeviceIoControlFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000174"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\KsecDD"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390400"
              },
              {
                "name": "InputBuffer",
                "value": "M<+\\x1a\\x00\\x00\\x02\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00R\\x00S\\x00A\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": "\\x01\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00X\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00A\\x00\\x00\\x00\\x98\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xffR\\x00S\\x00A\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00P\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00 \\x00P\\x00r\\x00o\\x00v\\x00i\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x00\\x00\\x00\\x00\\x00\\x00\\x00K\\x00e\\x00y\\x00L\\x00e\\x00n\\x00g\\x00t\\x00h\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00b\\x00c\\x00r\\x00y\\x00p\\x00t\\x00p\\x00r\\x00i\\x00m\\x00i\\x00t\\x00"
              }
            ],
            "repeated": 0,
            "id": 4014
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetAsymmetricEncryptionInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13af980"
              }
            ],
            "repeated": 0,
            "id": 4015
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x99W>\\xfe\\xb5\\xcf\\x17\\x1e\\x85\\x93\\x8f\\x82\\xa4\\xba\\xeel:\\xcbM\\xad\\xd0\\xb8\\x01\\xd1U{\\xb2\\xfb;1_\t(\\x82D\\xf4k\\xe5\\xd6\\xb8\\x16\\x9b\\xc0|\\xaa\\x8f\\xc4Q\\x89\\x94\\x10\\xbd\\xdb\\xdb:\\xaeMDLNxx\\x9a\n\\xd9\\x14\\xb1\r6\\x11 \\x1e\\xf4,\\xfe\\x96\\x80M\\xb6\\xc7\\xc2\\xab\\xce:\\xbbz-Xp\\x89\\x96\\xa9/\\x0e\\xb4\\xab\\xeec\\x01\\xab\\x07\\x11c\\xb7\\x1f\\x84\\x01\\x9f.\\xf9i1*#\\xa0\t\\xe4\\xed\\x17\\xa3\\xfa7\t\\x9d\\x8cHx\\xdd\\xf8\\x17x}'\\x00\rc~\\xb4\\xa0f\\x02!.\\xe9,\\xea,Y_\\x9b\\xc6\\xe8=\\xba$\\xd9`O\\xd7r\\\\x984^\\x97w6\\x7f\\xcc?\\xf8S\\x9aqO\\x83\\x19Bl\\xc1\\x1a\\xf0\\xec\\xfb\\xc7\\x03t\\x0f\\xec\\xb5\\x97\\xe3\\xfe\\xbc\\xbe\\x8bE\\xd4`\\xd1O\\x86\\xea\\x9c\\xf9B\\xa4\\xc2o\\xd74p~\\x08;\\x06B_\\x99KA\\x9cmE.\\x9f\\x85ON"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a472c0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4016
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad9000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000a000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4017
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4018
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4019
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4020
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x140\\x82\\x04\\xfc\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\x8f\\xf3Q\\xa8\\xebZr\\xdd\\xcc\\x00\\x01\\x00\\x00\\x01\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r211028192746Z\\x17\r230126192746Z0\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4021
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4022
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4023
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\x9f\\xa7\\x15]\\x00^b]\\x83\\xf4\\xe5\\xd2e\\xa7\\x1bS5\\x19\\xe9r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4024
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 4025
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4026
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4027
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx"
              }
            ],
            "repeated": 0,
            "id": 4028
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4029
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4030
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4031
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx"
              }
            ],
            "repeated": 0,
            "id": 4032
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4033
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4034
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4035
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 4036
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4037
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4038
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllConvertPublicKeyInfo"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllConvertPublicKeyInfo"
              }
            ],
            "repeated": 0,
            "id": 4039
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4040
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4041
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4042
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptDllConvertPublicKeyInfo"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllConvertPublicKeyInfo"
              }
            ],
            "repeated": 0,
            "id": 4043
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4044
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4045
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4046
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\x99W>\\xfe\\xb5\\xcf\\x17\\x1e\\x85\\x93\\x8f\\x82\\xa4\\xba\\xeel:\\xcbM\\xad\\xd0\\xb8\\x01\\xd1U{\\xb2\\xfb;1_\t(\\x82D\\xf4k\\xe5\\xd6\\xb8\\x16\\x9b\\xc0|\\xaa\\x8f\\xc4Q\\x89\\x94\\x10\\xbd\\xdb\\xdb:\\xaeMDLNxx\\x9a\n\\xd9\\x14\\xb1\r6\\x11 \\x1e\\xf4,\\xfe\\x96\\x80M\\xb6\\xc7\\xc2\\xab\\xce:\\xbbz-Xp\\x89\\x96\\xa9/\\x0e\\xb4\\xab\\xeec\\x01\\xab\\x07\\x11c\\xb7\\x1f\\x84\\x01\\x9f.\\xf9i1*#\\xa0\t\\xe4\\xed\\x17\\xa3\\xfa7\t\\x9d\\x8cHx\\xdd\\xf8\\x17x}'\\x00\rc~\\xb4\\xa0f\\x02!.\\xe9,\\xea,Y_\\x9b\\xc6\\xe8=\\xba$\\xd9`O\\xd7r\\\\x984^\\x97w6\\x7f\\xcc?\\xf8S\\x9aqO\\x83\\x19Bl\\xc1\\x1a\\xf0\\xec\\xfb\\xc7\\x03t\\x0f\\xec\\xb5\\x97\\xe3\\xfe\\xbc\\xbe\\x8bE\\xd4`\\xd1O\\x86\\xea\\x9c\\xf9B\\xa4\\xc2o\\xd74p~\\x08;\\x06B_\\x99KA\\x9cmE.\\x9f\\x85ON\\x11\\xc9\\x9b\\xa9\\x91\\x03\\x02\\xf9\\xcb\\xcc\\xe9\\xb5a\\x08\\xa1\\xc6\\xd3y"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4047
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x10\\x00\\x00\\x01\\x00\\x01\\x00\\xc3@[\\xc3a\\x07\\x0euA\\x04\\xab^?\\xe3\\xfc;\\x8b\\x81`\\xd5\\x08\\xca\\xc1d\\x8c\\xf1\\xa9\n\\xfc\\xff\\x91\\x99U$\\xdd\\x17D\\x9b\\xd2<o\\x02\\xb2\\xb2\\xe0x_\\x81\\x87\\xcc{\\xb6\\x89\\x04\\x02)\\xb6\\x7f\\xe0g\\xfeyQ1B8D+.\\xff\\x83\\x8b0i\\xde\\x80'E\\xa6\\xcc\\xb3\\xeb\\x12M\\xf8\\xdcw\\x04p\\x1cjE\\xf0\\x93\\xcd\\xd7Z\\x08\\xc9\\xe9\\xa9\\xb4\\xb13\\xa2\\xe2\\xf9\\xfdB>\\x94\\x11+P\\xf5\\x86\\x98\\xb2o\\xd4\\x07\\xac/6O\\x9a\\xfak\\xa8\\xce\\xb8\\xb2\\xb2j\\xc6\\x9d\\xef\\xd4a\\xce\\xf3c\\xb4\\xd9tM\\xef\\xd3\\xa7h\\xc5\\xc2\\xefE\\x13H\\x8c\t\\x8e\\xedx\\x08\\xb6X\\xdf\\x1e\\xe0\\xb3\\x04R(r\\x8a\\xdf\\x9e\\x11#\\x99\\xb9u;\\xc0\\x01^\\xc8\\xaaM\\xe9\\xfa\\xc6\\xaaK\\x95J?\t{7\\x1d\\xf0\\xd2\\x99df\\x9c\\xe9\\xc3\\x0e\\x12\\xd02\\x94\\x8a\\x1b:.\\xb4\\xa0\\x04\\xc1:\\x1d\\x1d\\xf3\\x0f\\xc5f\\xee&\\xcb\\x85\\'xd@"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a9e1e0"
              },
              {
                "name": "Length",
                "value": "532"
              }
            ],
            "repeated": 0,
            "id": 4048
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4049
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0S0Q\\x06\\x0c+\\x06\\x01\\x04\\x01\\x827L\\x83}\\x01\\x010A0?\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x02\\x01\\x163http://www.microsoft.com/pkiops/Docs/Repository.htm"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4050
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4051
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4052
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4053
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4054
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4055
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x10\\x00\\x00\\x01\\x00\\x01\\x00\\xad.\\xe2j>\\xb7\\xb7{\\xae\\xc6ir\\x16\\x9e\\x8f\\xda^\\x87\\x1e\\xf5\\xb6E\\xabx?\\x18\\x15\\x08\\xc77\\x1a\\xdb\\x15<\\xc0\\x93\\x17\\x85\\xc4R\\xf9\\x8d\\xefr\\x1d\\x11\\xc5lz\\x05P\\xaf\\xba%\\xdb\\x12]QR\\\\xf6k\\xc5\\x1c\\xd4\\xb2\\xfd\\xd1\\x1b\\xdc\\xdbG\\x84\\x185\\x066\\xf3a\\x89\\x0b\\xf9P\\xb9\\xd8\\x94\\x94\\x91t0_]!\\x83\\xa6\\xa0[\\x8bd6\\xc9\\x0coc\\xd7\n\\x12\\xfa\\xc2\\xf0 \\xa7\\xd7r\\x183\\xe2\\x02v(\\xd7^\\xa2g\\xcas\\x01aZ\\x18j\\xbd\\xd1\\xe2FQ\\x84\\xea\\x10.hB\\xbc\\x02\\x8eL93\\xc1NC=s\\xd8\\xd5\\xf3\\xc2^\\xaf\\xdbL?|\\x99\\xe8\\xa7\\xed\\x18G\\xb7\\xf2\\x10\\xf0\\x0f\\x824\\x1c\\x94t7M\\xa6s\\xd1\\xa3\\x03\\x05\\xbf\\xe8Q\\x12\\xa8n+\\xf6L6\\xec6~\\xaa\\xdb\\xba\\x80_}\\xdb/r\\xb6\\xdfE\\x9e\\xd9\\xfc~} \\xa5\\xfd\\xd6\\x89\\x12\\xdd4_\\xc4\\xcduF\\x9aA}s\\xcf "
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a9e1e0"
              },
              {
                "name": "Length",
                "value": "532"
              }
            ],
            "repeated": 0,
            "id": 4056
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4057
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4058
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215724Z\\x17\r350623220401Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4059
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4060
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a8d510"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4061
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4062
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4063
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4064
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a8d0c0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4065
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x140\\x82\\x04\\xfc\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\x8f\\xf3Q\\xa8\\xebZr\\xdd\\xcc\\x00\\x01\\x00\\x00\\x01\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r211028192746Z\\x17\r230126192746Z0\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4066
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4067
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a8d5a0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4068
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4069
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xc7\\xdc8C\\x02y\\x11\\x8d9\\x85\\x92\\x15\\xb3\\xb2+\\x03\\xbe*\\xb1+\\xcb#\\xb82X\\xb2~\\xa2K9\\xba?\\xa6\\xc6)\\xe7\\x99\\x0e\\xc9\\xff\\xd28.\\x06>\\x17+p&}]1\\x14\\x83\\x80_%4\\xe9g\\xb3-\\xe4\\xc6\\xa7 \\xc3\\xbe}\\xae\\xbd\\x12\\xb4\\x97n\\xbb\\xe1\\x1b\\x1aj\\xca\\xe9v\\xdef^\\xfd\\xaf\t,\\x84\\x80\\xce\\x00\\x1c]'\\x16\\x80\\xcd\\x82J\\x05.}\\x03\\xb7\\xb6\\x8c\\x877q\\xbc\\xec\\xda\\xa6\\x16\\x13\\x8b|v\\xc9\\x9eY\\xfa\\xe3N\\xe1\\xb7\"`L\\xbe\\xf2\\xeah\\x0cH\\xddqo\\x13\\x1e\\x17\\x87\\xbdr\\x0f;\\x00\\x1e5\t\\x96\\x13\\x92'\\xdd\\x97\\xf9\\xe8}%\\x8c\\xbc\\xd7}Z\\x97\\x12\\xb8\\xbc\\xd4g\\xcbm\\x8c\\x85\\x15)\\xfb\\x84x\\x1f\\xcb_\\xf4\\x89\\xe5L\\x9e,\"\\xf7\\x1d7>\"\\xd6\\xd1\\x0c\\x9a\\x07W\\xdb\\x17\\x14\\xb2\\xa4\\xf7\\xa4\\x84V\\xf3^\\xe5XfO\\xd8\\xde\\xde\\xad\\x19\\xcd\\xc1\\x05\\xceg\\xdfZ\\xa7Kv\\xbe\\xc8g\\x1c\\xd4\\xe0\\xb7\\xb6[\\xe6J~\\xbb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4070
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x08\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xc7\\xdc8C\\x02y\\x11\\x8d9\\x85\\x92\\x15\\xb3\\xb2+\\x03\\xbe*\\xb1+\\xcb#\\xb82X\\xb2~\\xa2K9\\xba?\\xa6\\xc6)\\xe7\\x99\\x0e\\xc9\\xff\\xd28.\\x06>\\x17+p&}]1\\x14\\x83\\x80_%4\\xe9g\\xb3-\\xe4\\xc6\\xa7 \\xc3\\xbe}\\xae\\xbd\\x12\\xb4\\x97n\\xbb\\xe1\\x1b\\x1aj\\xca\\xe9v\\xdef^\\xfd\\xaf\t,\\x84\\x80\\xce\\x00\\x1c]'\\x16\\x80\\xcd\\x82J\\x05.}\\x03\\xb7\\xb6\\x8c\\x877q\\xbc\\xec\\xda\\xa6\\x16\\x13\\x8b|v\\xc9\\x9eY\\xfa\\xe3N\\xe1\\xb7\"`L\\xbe\\xf2\\xeah\\x0cH\\xddqo\\x13\\x1e\\x17\\x87\\xbdr\\x0f;\\x00\\x1e5\t\\x96\\x13\\x92'\\xdd\\x97\\xf9\\xe8}%\\x8c\\xbc\\xd7}Z\\x97\\x12\\xb8\\xbc\\xd4g\\xcbm\\x8c\\x85\\x15)\\xfb\\x84x\\x1f\\xcb_\\xf4\\x89\\xe5L\\x9e,\"\\xf7\\x1d7>\"\\xd6\\xd1\\x0c\\x9a\\x07W\\xdb\\x17\\x14\\xb2\\xa4\\xf7\\xa4\\x84V\\xf3^\\xe5XfO\\xd8\\xde\\xde\\xad\\x19\\xcd\\xc1\\x05\\xceg"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a8d5d0"
              },
              {
                "name": "Length",
                "value": "283"
              }
            ],
            "repeated": 0,
            "id": 4071
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4072
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4073
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4074
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x7f0\\x82\\x04g\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdd\\xdcA T\\xe2v\\xc9&\\x00\\x00\\x00\\x00\\x00\\xdd0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195806Z\\x17\r230308195806Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4075
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4076
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4077
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14aq\\xa7\\x87\\xaf\\xffi\\xd5!vOR\\x93(\\x00\\xbey\\x12\\xab\\x84"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4078
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xc7\\xdc8C\\x02y\\x11\\x8d9\\x85\\x92\\x15\\xb3\\xb2+\\x03\\xbe*\\xb1+\\xcb#\\xb82X\\xb2~\\xa2K9\\xba?\\xa6\\xc6)\\xe7\\x99\\x0e\\xc9\\xff\\xd28.\\x06>\\x17+p&}]1\\x14\\x83\\x80_%4\\xe9g\\xb3-\\xe4\\xc6\\xa7 \\xc3\\xbe}\\xae\\xbd\\x12\\xb4\\x97n\\xbb\\xe1\\x1b\\x1aj\\xca\\xe9v\\xdef^\\xfd\\xaf\t,\\x84\\x80\\xce\\x00\\x1c]'\\x16\\x80\\xcd\\x82J\\x05.}\\x03\\xb7\\xb6\\x8c\\x877q\\xbc\\xec\\xda\\xa6\\x16\\x13\\x8b|v\\xc9\\x9eY\\xfa\\xe3N\\xe1\\xb7\"`L\\xbe\\xf2\\xeah\\x0cH\\xddqo\\x13\\x1e\\x17\\x87\\xbdr\\x0f;\\x00\\x1e5\t\\x96\\x13\\x92'\\xdd\\x97\\xf9\\xe8}%\\x8c\\xbc\\xd7}Z\\x97\\x12\\xb8\\xbc\\xd4g\\xcbm\\x8c\\x85\\x15)\\xfb\\x84x\\x1f\\xcb_\\xf4\\x89\\xe5L\\x9e,\"\\xf7\\x1d7>\"\\xd6\\xd1\\x0c\\x9a\\x07W\\xdb\\x17\\x14\\xb2\\xa4\\xf7\\xa4\\x84V\\xf3^\\xe5XfO\\xd8\\xde\\xde\\xad\\x19\\xcd\\xc1\\x05\\xceg\\xdfZ\\xa7Kv\\xbe\\xc8g\\x1c\\xd4\\xe0\\xb7\\xb6[\\xe6J~\\xbb"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4079
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x08\\x00\\x00\\x01\\x00\\x01\\x00-\\x08\\x8aS[|z2\\xc0\\xbb~J\\xe6[\\xb6\\xb7\\xe0\\xd4\\x1cg\\xc8\\xbevK\\xa7Z\\xdfg\\xce\\x05\\xc1\\xcd\\x19\\xad\\xde\\xde\\xd8OfX\\xe5^\\xf3V\\x84\\xa4\\xf7\\xa4\\xb2\\x14\\x17\\xdbW\\x07\\x9a\\x0c\\xd1\\xd6\">7\\x1d\\xf7\",\\x9eL\\xe5\\x89\\xf4_\\xcb\\x1fx\\x84\\xfb)\\x15\\x85\\x8cm\\xcbg\\xd4\\xbc\\xb8\\x12\\x97Z}\\xd7\\xbc\\x8c%}\\xe8\\xf9\\x97\\xdd'\\x92\\x13\\x96\t5\\x1e\\x00;\\x0fr\\xbd\\x87\\x17\\x1e\\x13oq\\xddH\\x0ch\\xea\\xf2\\xbeL`\"\\xb7\\xe1N\\xe3\\xfaY\\x9e\\xc9v|\\x8b\\x13\\x16\\xa6\\xda\\xec\\xbcq7\\x87\\x8c\\xb6\\xb7\\x03}.\\x05J\\x82\\xcd\\x80\\x16']\\x1c\\x00\\xce\\x80\\x84,\t\\xaf\\xfd^f\\xdev\\xe9\\xcaj\\x1a\\x1b\\xe1\\xbbn\\x97\\xb4\\x12\\xbd\\xae}\\xbe\\xc3 \\xa7\\xc6\\xe4-\\xb3g\\xe94%_\\x80\\x83\\x141]}&p+\\x17>\\x06.8\\xd2\\xff\\xc9\\x0e\\x99\\xe7)\\xc6\\xa6?\\xba9K\\xa2~\\xb2X2\\xb8#\\xcb"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a9e1e0"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 4080
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4081
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4082
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4083
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4084
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf\\xdd~\\xfb\\x95^\\xa1\\x01\\xcdC\\xb1\\x07\\xd7\\xa40\\xee\\x9b\\x86\\x1a"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4085
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x08\\x00\\x00\\x01\\x00\\x01\\x00\\x8bot\\xa2Y\\x0b\\xc1n*\\x1a\\x86\\x9b\\xee0\\xa4\\xd7\\x07\\xb1C\\xcd\\x01\\xa1^\\x95\\xfb~\\xdd\\xcf\\x95\\xe4\\xb8\\xfd\\xc7\\x8e\\xcd\\xc6\\x95$\\xe0\\xeeC=.HP}\\x00p\\xc8mh\\xb6\\x10f\\xb2d\\xeatd\\x14\\xed\\x01:\\x8e\\x13\\x83V\\xec\\xe8\\x82\\xfc\\xac\nNF\\x01M\\x1d\\xed\\x0f\\xb8\\xfe\\xbdo7\\xdc\\xaa\\xe9\r\\xd1C\\xe1\\x18\\xfb\\xe8\\x1d\\x01t\\x7f\\xb8\\x05\\xf9,\\xcd\\xbdw\\x9e\\xf9\\xcbSE3\\xd5\\x1e\\x89\\xa2\\xecU\\xa7\\xabNj\\xe9\\x8e\\xda\\xf4\\xcc\\x8a\\xe8G5\\xbd\\x86\\x0f}e\\x7f\\xfd\\xe3f\\x90V<'<g-\\x1b\\xf9\\x9bY\"N\\xa0\\x0c\\xf9\\x98\\xb7a7\\x19Wy\\x86S\\x0c\\dN\\x81\\x02*~\\xcb\\xa7\\xd1\\xbfh\\xee\\xf0\\xbc%a\\xdf\\xeb\\xc5\\xe4d\\x9b<\\xfd\\xa5\\x1c(\\xbdq\\xc4)\\xb4 \\xac\\x02X\\x8b\\x98/h\\x9f\\xb5\\x99\\xa5\\xe7.\\x10\\xed\\xd5\\xaeK\\xa5Z\ne\\x08\tg\\xce\\xd4P\\xb2\\x071\\x9a\\x81&1W"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a9e1e0"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 4086
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4087
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4088
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a43c80"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4089
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x7f0\\x82\\x04g\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdd\\xdcA T\\xe2v\\xc9&\\x00\\x00\\x00\\x00\\x00\\xdd0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195806Z\\x17\r230308195806Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4090
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf\\xdd~\\xfb\\x95^\\xa1\\x01\\xcdC\\xb1\\x07\\xd7\\xa40\\xee\\x9b\\x86\\x1a"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4091
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x08\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a43cb0"
              },
              {
                "name": "Length",
                "value": "283"
              }
            ],
            "repeated": 0,
            "id": 4092
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 2,
            "id": 4093
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4094
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4095
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4096
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0H\\x02A\\x00\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4097
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4098
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x9cP\\x05\\x1d\\xe2\\x0eLS\\xd8\\xd9\\xb5\\xe5\\xfd\\xe9\\xe3\\xad\\x83K\\x80\\x08\\xd9\\xdc\\xe8\\xe85\\xf8\\x11\\xf1\\xe9\\x9b\\x03zedv5\\xce8,\\xf2\\xb6q\\x9e\\x06\\xd9\\xbf\\xbb1i\\xa3\\xf60\\xa0x{\\x18\\xddPMy\\x1e\\xeba\\xc1\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4099
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4100
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4101
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4102
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4103
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\x9f\\xa7\\x15]\\x00^b]\\x83\\xf4\\xe5\\xd2e\\xa7\\x1bS5\\x19\\xe9r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4104
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0S0Q\\x06\\x0c+\\x06\\x01\\x04\\x01\\x827L\\x83}\\x01\\x010A0?\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x02\\x01\\x163http://www.microsoft.com/pkiops/Docs/Repository.htm"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4105
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4106
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4107
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4108
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4109
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4110
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4111
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a43f20"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4112
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x140\\x82\\x04\\xfc\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\x8f\\xf3Q\\xa8\\xebZr\\xdd\\xcc\\x00\\x01\\x00\\x00\\x01\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r211028192746Z\\x17\r230126192746Z0\\x81\\xd21\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4113
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4114
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x24890a43f20"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4115
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 2,
            "id": 4116
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4117
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4118
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4119
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0H\\x02A\\x00\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4120
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4121
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x9cP\\x05\\x1d\\xe2\\x0eLS\\xd8\\xd9\\xb5\\xe5\\xfd\\xe9\\xe3\\xad\\x83K\\x80\\x08\\xd9\\xdc\\xe8\\xe85\\xf8\\x11\\xf1\\xe9\\x9b\\x03zedv5\\xce8,\\xf2\\xb6q\\x9e\\x06\\xd9\\xbf\\xbb1i\\xa3\\xf60\\xa0x{\\x18\\xddPMy\\x1e\\xeba\\xc1\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4122
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 4123
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4124
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4125
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CertDllVerifyCertificateChainPolicy"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllVerifyCertificateChainPolicy"
              }
            ],
            "repeated": 0,
            "id": 4126
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4127
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4128
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4129
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CertDllVerifyCertificateChainPolicy"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllVerifyCertificateChainPolicy"
              }
            ],
            "repeated": 0,
            "id": 4130
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4131
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4132
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4133
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 4134
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1;09\\x06\\x03U\\x04\\x03\\x132Microsoft Windows Hardware Compatibility Publisher"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4135
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0K\\xa4I0G1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Ireland Operations Limited1\\x160\\x14\\x06\\x03U\\x04\\x05\\x13\r232825+469581"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4136
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0G1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Ireland Operations Limited1\\x160\\x14\\x06\\x03U\\x04\\x05\\x13\r232825+469581"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4137
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4138
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4139
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4140
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4141
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4142
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4143
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4144
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4145
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4146
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4147
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4148
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4149
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4150
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4151
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4152
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4153
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4154
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\x9f\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00{S\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x000\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x00\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xdc\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4155
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4156
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4157
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4158
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4159
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4160
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4161
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4162
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4163
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4164
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\x9f\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00{S\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x000\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x00\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xdc\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4165
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4166
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4167
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4168
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4169
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4170
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4171
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4172
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xa0\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00[R\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\x10\\xa2\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\\\xa1\\x90H\\x02\\x00\\x00 \\xa5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xe0\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa2\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xe0\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4173
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4174
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4175
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4176
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4177
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4178
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4179
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4180
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4181
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4182
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4183
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4184
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4185
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4186
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4187
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\x9d\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0bQ\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xe0\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xb0\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4188
          },
          {
            "timestamp": "2026-02-10 09:22:11,079",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4189
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4190
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4191
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4192
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4193
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4194
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4195
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4196
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4197
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4198
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4199
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4200
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4201
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4202
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4203
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4204
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4205
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4206
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4207
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4208
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "8\\x99\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1b]\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xd0\\x9a\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000=\\xad\\x90H\\x02\\x00\\x00\\xa0\\x9a\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x9a\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xa0\\x9a\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xdc\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4209
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4210
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4211
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 4212
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4213
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4214
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4215
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4216
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4217
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4218
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4219
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4220
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4221
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4222
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4223
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4224
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4225
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4226
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4227
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4228
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4229
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\x9c\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00k^\\xac\\x80\\xbe\\xd3\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00@\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00p\\\\xa1\\x90H\\x02\\x00\\x00P\\xa1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\x9e\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4230
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4231
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4232
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4233
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4234
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4235
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4236
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4237
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4238
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4239
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4240
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4241
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4242
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4243
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4244
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4245
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4246
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4247
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4248
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4249
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4250
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4251
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4252
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4253
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4254
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4255
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4256
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4257
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4258
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4259
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4260
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4261
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4262
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4263
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4264
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4265
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4266
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4267
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4268
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4269
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4270
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4271
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4272
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4273
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4274
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4275
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4276
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4277
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4278
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4279
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4280
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4281
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000004fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4282
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4283
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4284
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000004fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4285
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4286
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4287
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000004fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4288
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004fc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4289
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4290
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x00000500"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 4291
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000500"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4292
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000504"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4293
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4294
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000500"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4295
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000504"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4296
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4297
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000500"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4298
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000504"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4299
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4300
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4301
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4302
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4303
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000050c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4304
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4305
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4306
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000050c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4307
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4308
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4309
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000050c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4310
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000050c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4311
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4312
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000050c"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4313
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4314
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4315
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4316
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4317
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4318
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 4319
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000510"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4320
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000514"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4321
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 4322
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000510"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4323
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000514"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4324
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 4325
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000510"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4326
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000514"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4327
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 4328
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4329
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4330
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4331
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000051c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4332
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4333
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4334
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000051c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4335
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4336
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004ec"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4337
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000051c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4338
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4339
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4340
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4341
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4342
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 4343
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4344
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4345
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4346
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4347
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4348
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4349
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4350
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4351
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4352
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4353
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 4354
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4355
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4356
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4357
          },
          {
            "timestamp": "2026-02-10 09:22:11,094",
            "thread_id": "348",
            "caller": "0x7ff70a3b3e0c",
            "parentcaller": "0x7ff70a3b4c08",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 5,
            "id": 4358
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4359
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4360
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfc;\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4361
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4362
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4363
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4364
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4365
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4366
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4367
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "D<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4368
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "D<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4369
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4370
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b5451",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 4371
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4372
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00D<\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4373
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4374
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4375
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7aab0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4376
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4377
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4378
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4379
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4380
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4381
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4382
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4383
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 4384
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4385
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 4386
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4387
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 4388
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 4389
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4390
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 4391
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4392
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 4393
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4394
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 4395
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4396
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4397
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4398
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4399
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4400
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 4401
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4402
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4403
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 4404
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 4405
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              }
            ],
            "repeated": 0,
            "id": 4406
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              }
            ],
            "repeated": 0,
            "id": 4407
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 0,
            "id": 4408
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4409
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4410
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 4411
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 4412
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 0,
            "id": 4413
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              }
            ],
            "repeated": 0,
            "id": 4414
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39d333",
            "parentcaller": "0x7ff70a39e83d",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "103"
              }
            ],
            "repeated": 0,
            "id": 4415
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4416
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4417
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4418
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4419
          },
          {
            "timestamp": "2026-02-10 09:22:11,110",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4420
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4421
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4422
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4423
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4424
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4425
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4426
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4427
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43550",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4428
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 4429
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4430
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4431
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4432
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a9f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4433
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893aa0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00100000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4434
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893aa0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00022000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4435
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4436
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4437
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 4438
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4439
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4440
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4441
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4442
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4443
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4444
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4445
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4446
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4447
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4448
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4449
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4450
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4451
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4452
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4453
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4454
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4455
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4456
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4457
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4458
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4459
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4460
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4461
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4462
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4463
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4464
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4465
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4466
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4467
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4468
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4469
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4470
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4471
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4472
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4473
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4474
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 1,
            "id": 4475
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 11,
            "id": 4476
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4477
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4478
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4479
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4480
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 6,
            "id": 4481
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4482
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4483
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 4484
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 4485
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 4486
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 4487
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 4488
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4489
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 0,
            "id": 4490
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              }
            ],
            "repeated": 0,
            "id": 4491
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 4492
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 4493
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4494
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4495
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              }
            ],
            "repeated": 0,
            "id": 4496
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 0,
            "id": 4497
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 4498
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              }
            ],
            "repeated": 0,
            "id": 4499
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4500
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 4501
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4502
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4503
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4504
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4505
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 4506
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 4507
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4508
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4509
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4510
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4511
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a39d424",
            "parentcaller": "0x7ff70a39e83d",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\MiniNT"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MiniNT"
              }
            ],
            "repeated": 0,
            "id": 4512
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a395b15",
            "parentcaller": "0x7ff70a39d5aa",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43550",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4513
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a395b3c",
            "parentcaller": "0x7ff70a39d5aa",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4514
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5ba0",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4515
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x01\\x00\\x00\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4516
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 4517
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893ba0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bfd0"
              },
              {
                "name": "ViewSize",
                "value": "0x00013000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4518
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893ba0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00013000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4519
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4520
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 4521
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4522
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4523
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4524
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477d80"
              }
            ],
            "repeated": 0,
            "id": 4525
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1480890"
              }
            ],
            "repeated": 0,
            "id": 4526
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4527
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4528
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4529
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetHashInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13a4460"
              }
            ],
            "repeated": 2,
            "id": 4530
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x01\\x00\\x00\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4531
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 4532
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ae3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00013000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4533
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 4534
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "Buffer",
                "value": "MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\x00\\x00\\x00\\x0e\\x1f\\xba\\x0e\\x00\\xb4\t\\xcd!\\xb8\\x01L\\xcd!This program cannot be run in DOS mode.\r\r\n$\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaeT\\xa3w\\xea5\\xcd$\\xea5\\xcd$\\xea5\\xcd$9G\\xce%\\xef5\\xcd$9G\\xc9%\\xed5\\xcd$9G\\xcc%\\xed5\\xcd$\\xea5\\xcc$\\xac5\\xcd$3A\\xc8%\\xfa5\\xcd$3A2$\\xeb5\\xcd$3A\\xcf%\\xeb5\\xcd$Rich\\xea5\\xcd$\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00PE\\x00\\x00d\\x86\\x08\\x00%5\\xe1b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x00\"\\x00\\x0b\\x02\\x0e\\x1c\\x00\\xb4\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "76208"
              }
            ],
            "repeated": 0,
            "id": 4535
          },
          {
            "timestamp": "2026-02-10 09:22:11,126",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4536
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893ba0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bca0"
              },
              {
                "name": "ViewSize",
                "value": "0x00013000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4537
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad8000"
              },
              {
                "name": "RegionSize",
                "value": "0x0001d000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4538
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893ba0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00013000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4539
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4540
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4541
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000458"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4542
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000458"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 4543
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c1f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4544
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4545
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4546
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4547
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4548
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4549
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001\\x000\\x000\\x005\\x006\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4550
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04J1\\x000\\x007\\x00d\\x003\\x002\\x007\\x005\\x00-\\x003\\x001\\x00a\\x000\\x00-\\x004\\x003\\x00c\\x005\\x00-\\x008\\x00f\\x00b\\x004\\x00-\\x007\\x008\\x00e\\x00c\\x002\\x006\\x001\\x007\\x00b\\x001\\x001\\x008\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4551
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4552
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4553
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4554
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x12c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4555
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4556
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4557
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4558
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4559
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24893a90000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4560
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4561
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00C\\x006\\x008\\x009\\x00A\\x00A\\x00B\\x008\\x00-\\x008\\x00E\\x007\\x008\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4562
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0=0\\x18\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x0f0\n\\x03\\x02\\x05\\xa0\\xa0\\x04\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14\\xee\\xf2\\x7f:\\x96\\x05~\r\\xbeE\\xb8\\xb9\\xe1j\\xb0\\xacmC\\xfc\\xc3"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4563
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3b5d85",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4564
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3c2839",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 4565
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3c2839",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee3470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "ntdll.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000800"
              }
            ],
            "repeated": 0,
            "id": 4566
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3c2857",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlGetNtSystemRoot"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee3486bb0"
              }
            ],
            "repeated": 0,
            "id": 4567
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3c0c07",
            "parentcaller": "0x7ff70a3bdd74",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4568
          },
          {
            "timestamp": "2026-02-10 09:22:11,141",
            "thread_id": "348",
            "caller": "0x7ff70a3c0b0a",
            "parentcaller": "0x7ff70a3bdd74",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x01\\x00\\x00\\x00\\x00\\x00\\x0co\\x04\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 1,
            "id": 4569
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c15fe",
            "parentcaller": "0x7ff70a3c0d7d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000460"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              }
            ],
            "repeated": 0,
            "id": 4570
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c1650",
            "parentcaller": "0x7ff70a3c0d7d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7df49d630000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00047000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4571
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c52cd",
            "parentcaller": "0x7ff70a3bb108",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 4572
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b66fe",
            "parentcaller": "0x7ff70a39e37c",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf\\*.*"
              }
            ],
            "repeated": 0,
            "id": 4573
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c0f08",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4574
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c0f23",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4575
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3c0f42",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7df49d630000"
              },
              {
                "name": "RegionSize",
                "value": "0x00047000"
              }
            ],
            "repeated": 0,
            "id": 4576
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b686d",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 4577
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b68a5",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 4578
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b68b8",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4579
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b6920",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 4580
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b6958",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "ValueName",
                "value": "PnpSetupInProgress"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 4581
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b6978",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4582
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4583
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4584
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4585
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4586
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4587
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9a<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4588
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4589
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4590
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4591
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4592
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4593
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4594
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4595
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4596
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4597
          },
          {
            "timestamp": "2026-02-10 09:22:11,157",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4598
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4599
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-security-cryptoapi-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              }
            ],
            "repeated": 0,
            "id": 4600
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0450000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-security-cryptoapi-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 4601
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0450000"
              },
              {
                "name": "FunctionName",
                "value": "CryptAcquireContextW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee0452450"
              }
            ],
            "repeated": 0,
            "id": 4602
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4603
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 4604
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptAcquireContextW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": ""
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 4605
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4606
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 4607
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 4608
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATOpen"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee149a310"
              }
            ],
            "repeated": 0,
            "id": 4609
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4610
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4611
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4612
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 4613
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c9f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4614
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4615
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4616
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4617
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4618
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4619
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001\\x000\\x000\\x005\\x006\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4620
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04J1\\x000\\x007\\x00d\\x003\\x002\\x007\\x005\\x00-\\x003\\x001\\x00a\\x000\\x00-\\x004\\x003\\x00c\\x005\\x00-\\x008\\x00f\\x00b\\x004\\x00-\\x007\\x008\\x00e\\x00c\\x002\\x006\\x001\\x007\\x00b\\x001\\x001\\x008\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4621
          },
          {
            "timestamp": "2026-02-10 09:22:11,204",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4622
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4623
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4624
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x12c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4625
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4626
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4627
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x14v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4628
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4629
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4630
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4631
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4632
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATEnumerateCatAttr"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147bd40"
              }
            ],
            "repeated": 0,
            "id": 4633
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4634
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4635
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATClose"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1473150"
              }
            ],
            "repeated": 0,
            "id": 4636
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4637
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4638
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0450000"
              },
              {
                "name": "FunctionName",
                "value": "CryptReleaseContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee04536b0"
              }
            ],
            "repeated": 0,
            "id": 4639
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4640
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4641
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4642
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1<\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4643
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4644
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c940"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4645
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4646
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4647
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4648
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4649
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "-=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4650
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "-=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4651
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4652
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4653
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00-=\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4654
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4655
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4656
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c940"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4657
          },
          {
            "timestamp": "2026-02-10 09:22:11,219",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4658
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4659
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 4660
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4661
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4662
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4663
          },
          {
            "timestamp": "2026-02-10 09:22:11,235",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4664
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4665
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4666
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8a=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4667
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4668
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c940"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4669
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4670
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4671
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 4672
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4673
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4674
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004cc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4675
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4676
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4677
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4678
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4679
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4680
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4681
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4682
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4683
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4684
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4685
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4686
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4687
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4688
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4689
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4690
          },
          {
            "timestamp": "2026-02-10 09:22:11,251",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4691
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4692
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4693
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b8b0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4694
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4695
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4696
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4697
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad8000"
              },
              {
                "name": "RegionSize",
                "value": "0x0001d000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4698
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4699
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4700
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4701
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4702
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4703
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4704
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4705
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4706
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4707
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4708
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4709
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4710
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4711
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4712
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4713
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4714
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4715
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4716
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4717
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4718
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4719
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4720
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4721
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4722
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4723
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4724
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4725
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4726
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4727
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4728
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4729
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4730
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4731
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4732
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4733
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4734
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 1,
            "id": 4735
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 14,
            "id": 4736
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4737
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4738
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4739
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4740
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 8,
            "id": 4741
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4742
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4743
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4744
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bfe0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4745
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4746
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 4747
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4748
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4749
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4750
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4751
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 4752
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 4753
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4754
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4755
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4756
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 4757
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4758
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 4759
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4760
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4761
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 4762
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 4763
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 4764
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 4765
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4766
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4767
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 4768
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 4769
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 4770
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4771
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4772
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4773
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4774
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4775
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4776
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4777
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4778
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              },
              {
                "name": "MutexName",
                "value": "Global\\DriverStore_Mutex_vnaap.inf_amd64_ea39d26158cde1be"
              },
              {
                "name": "InitialOwner",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4779
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4780
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4781
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3=\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4782
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4783
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004e8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c940"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4784
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4785
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "I>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4786
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4787
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4788
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "I>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4789
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "I>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4790
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "I>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4791
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4792
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4793
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4794
          },
          {
            "timestamp": "2026-02-10 09:22:11,266",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00I>\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4795
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "I>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4796
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4797
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000458"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4798
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4799
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4800
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4801
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4802
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4803
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4804
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4805
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4806
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4807
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x90>\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4808
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4809
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4810
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4811
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4812
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4813
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4814
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4815
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4816
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4817
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4818
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4819
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository"
              }
            ],
            "repeated": 0,
            "id": 4820
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4821
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4822
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe9>\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4823
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4824
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bfe0"
              },
              {
                "name": "ViewSize",
                "value": "0x00004000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4825
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4826
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "s?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4827
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4828
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4829
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "s?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4830
          },
          {
            "timestamp": "2026-02-10 09:22:11,282",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "s?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4831
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000050c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "s?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4832
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4833
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4834
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00s?\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4835
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "s?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4836
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4837
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000050c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c020"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4838
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4839
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4840
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4841
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4842
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4843
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4844
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4845
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a436d0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\*"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbbf4333d"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 4846
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be"
              }
            ],
            "repeated": 0,
            "id": 4847
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\"
              }
            ],
            "repeated": 0,
            "id": 4848
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be"
              }
            ],
            "repeated": 0,
            "id": 4849
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43670",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4850
          },
          {
            "timestamp": "2026-02-10 09:22:11,298",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4851
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 4852
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4853
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xe1\\xa9\\x90H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00c\\x00a\\x00t\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4854
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4855
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43430",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4856
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4857
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4858
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4859
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00m\\xa5\\x90H\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4860
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4861
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43430",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4862
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4863
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 4864
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4865
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4866
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4867
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4868
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4869
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4870
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5?\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4871
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4872
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000051c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bfe0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4873
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4874
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4875
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4876
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4877
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4878
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "D@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4879
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "D@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4880
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4881
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4882
          },
          {
            "timestamp": "2026-02-10 09:22:11,313",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4883
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0110080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\drvstore.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "4",
                "pretty_value": "FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000102",
                "pretty_value": "FILE_ATTRIBUTE_HIDDEN|FILE_ATTRIBUTE_TEMPORARY"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4884
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4885
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00D@\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4886
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "D@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4887
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000050c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4888
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000050c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b840"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4889
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4890
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4891
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4892
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4893
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4894
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4895
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4896
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4897
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4898
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4899
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4900
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4901
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4902
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4903
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4904
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4905
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4906
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4907
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4908
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4909
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 4910
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4911
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4912
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4913
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 4914
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a850"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4915
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4916
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4917
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4918
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4919
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4920
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4921
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4922
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4923
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4924
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4925
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4926
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4927
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4928
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4929
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4930
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4931
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4932
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4933
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4934
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4935
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4936
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4937
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4938
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4939
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4940
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4941
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4942
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4943
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4944
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4945
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4946
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4947
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4948
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4949
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4950
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4951
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4952
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4953
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 4954
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 1,
            "id": 4955
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 14,
            "id": 4956
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4957
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4958
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4959
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4960
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 8,
            "id": 4961
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xc2\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4962
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4963
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4964
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xc2\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4965
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xc2\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4966
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xc2\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4967
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4968
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P5\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4969
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P5\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4970
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\n\\x00\\x00\\x00\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc4\\xbb\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4971
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd06\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0b\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf8\\xb5\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4972
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0c\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbc\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4973
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd06\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\xbe\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4974
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0e\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00x\\xbe\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4975
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0f\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xbe\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4976
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf04\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xdf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4977
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8e^\\x9d\\x90H\\x02\\x00\\x00f\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4978
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf04\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x07\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xf1\\xe7\\xd1\\xa1\\x00\\x00\\x00f\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4979
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x106\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\xc1b\\xa1M\\xb1^@A\\xa4DPd\\xc9\\x81Nv\t\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xeb\\xe7\\xd1\\xa1\\x00\\x00\\x00^\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4980
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4981
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x1a\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4982
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf04\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba%\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa4\\xc0\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4983
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p6\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x08\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\xbb\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4984
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x15\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xbb\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4985
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4986
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4987
          },
          {
            "timestamp": "2026-02-10 09:22:11,329",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4988
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe5@\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4989
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4990
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000510"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b880"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4991
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "dA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4992
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4993
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4994
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "dA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4995
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "dA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4996
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "dA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4997
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4998
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x01\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4999
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\x80\\x00\\x00\\x00."
              }
            ],
            "repeated": 0,
            "id": 5000
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x80s\\xa9\\x90H\\x02\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5001
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xc3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5002
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5003
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5004
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00Pv\\xa4\\x90H\\x02\\x00\\x00\"\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5005
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0r\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 1,
            "id": 5006
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0r\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5007
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 5008
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5009
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00dA\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5010
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "dA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5011
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5012
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b880"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5013
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xccA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5014
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5015
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5016
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xccA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5017
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xccA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5018
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xccA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5019
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 5020
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0p\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5021
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x17\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5022
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00@w\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xcb\\xab\\x90H\\x02\\x00\\x00D\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5023
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5024
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xccA\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5025
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xccA\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5026
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5027
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b880"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5028
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5029
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5030
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5031
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5032
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": ">B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5033
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": ">B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5034
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 5035
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P5\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5036
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5037
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5038
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5039
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 5040
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 5041
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 5042
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5043
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 5044
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 5045
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5046
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5047
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5048
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5049
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5050
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5051
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5052
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5053
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5054
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5055
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5056
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5057
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5058
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5059
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5060
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5061
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5062
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5063
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5064
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5065
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5066
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5067
          },
          {
            "timestamp": "2026-02-10 09:22:11,344",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5068
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5069
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00>B\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5070
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5071
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5072
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b840"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5073
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5074
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5075
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5076
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5077
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5078
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5079
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5080
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5081
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5082
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x96B\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5083
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x96B\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5084
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5085
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bdd0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5086
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5087
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5088
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5089
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5090
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5091
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "6C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5092
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "6C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5093
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5094
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5095
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5096
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00R\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5097
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P5\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5098
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd06\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5099
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P5\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xc0\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5100
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5101
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5102
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5103
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0p\\xa4\\x90H\\x02\\x00\\x00\"\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5104
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0r\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5105
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5106
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5107
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x106\\xa4\\x90H\\x02\\x00\\x00R\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5108
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p6\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc4\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5109
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0r\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0D\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5110
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00 s\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00D\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5111
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x0004\\xa4\\x90H\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00."
              }
            ],
            "repeated": 0,
            "id": 5112
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xdc\\xab\\x90H\\x02\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00."
              }
            ],
            "repeated": 0,
            "id": 5113
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xdc\\xab\\x90H\\x02\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00H\\x02"
              }
            ],
            "repeated": 0,
            "id": 5114
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00 s\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5115
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5116
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x006C\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5117
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5118
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5119
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004b4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ad70"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5120
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5121
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5122
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5123
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5124
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5125
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5126
          },
          {
            "timestamp": "2026-02-10 09:22:11,360",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5127
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5128
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 5129
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5130
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 5131
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 5132
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 5133
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 5134
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 5135
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 5136
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 5137
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:2964:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5138
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5139
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5140
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5141
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5142
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5143
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5144
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5145
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5146
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5147
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "PrivCopyFileExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1682940"
              }
            ],
            "repeated": 0,
            "id": 5148
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5149
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5150
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5151
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5152
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc0Uv\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01N\\xf5s\\xbcn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5153
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 5154
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01\\xc0Uv\\xbcn\\x9a\\xdc\\x01\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01N\\xf5s\\xbcn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5155
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5156
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5157
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07\\x7f}\\xbcn\\x9a\\xdc\\x01\\x07\\x7f}\\xbcn\\x9a\\xdc\\x01\\x07\\x7f}\\xbcn\\x9a\\xdc\\x01\\x07\\x7f}\\xbcn\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5158
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000454"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000004b4"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5159
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 5160
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 1,
            "id": 5161
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5162
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5163
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5164
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5165
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00w\\xb7\\xf1\"\\xab\\xd8\\x01N\\xf5s\\xbcn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5166
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 5167
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5168
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5169
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5170
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5171
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x98C\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5172
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98C\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5173
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5174
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a8a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5175
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02D\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5176
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5177
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5178
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02D\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5179
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02D\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5180
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02D\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5181
          },
          {
            "timestamp": "2026-02-10 09:22:11,376",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5182
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5183
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5184
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xac\\xde\\x7f\\xbcn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5185
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5186
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 5187
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5188
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5189
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5190
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5191
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5192
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5193
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5194
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5195
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5196
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5197
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5198
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5199
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5200
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5201
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5202
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5203
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000460"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000518"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 5204
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000460"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e79250"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5205
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5206
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5207
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5208
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5209
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5210
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 5211
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5212
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5213
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5214
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5215
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5216
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5217
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5218
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5219
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5220
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5221
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5222
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5223
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5224
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5225
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5226
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5227
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5228
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5229
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5230
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5231
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5232
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5233
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5234
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5235
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5236
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5237
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5238
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5239
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5240
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5241
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5242
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5243
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5244
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 1,
            "id": 5245
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 14,
            "id": 5246
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5247
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5248
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5249
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5250
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 8,
            "id": 5251
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5252
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00pm\\xa5\\x90H\\x02\\x00\\x00`\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5253
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 5254
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0r\\xa5\\x90H\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc08\n\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5255
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0r\\xa5\\x90H\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\n\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00n\\x00e\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00a\\x00t\\x00h\\x00w\\x008\\x00x\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00b\\x00c\\x00m\\x00d\\x00h\\x00d\\x006\\x004\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00b\\x00c\\x00m\\x00w\\x00d\\x00i\\x00d\\x00h\\x00d\\x00p\\x00c\\x00i\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00m\\x00r\\x00v\\x00l\\x00p\\x00c\\x00i\\x00e\\x008\\x008\\x009\\x007\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x008\\x001\\x008\\x005\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x008\\x001\\x008\\x007\\x00b\\x00v\\x006\\x004\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x008\\x001\\x008\\x007\\x00s\\x00e\\x006\\x004\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x008\\x001\\x009\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5256
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00pm\\xa5\\x90H\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00\\xc0T\\xac\\x90H\\x02\\x00\\x00J\n\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5257
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 1,
            "id": 5258
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5259
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 3,
            "id": 5260
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5261
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5262
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5263
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5264
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5265
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5266
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5267
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 1,
            "id": 5268
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 7,
            "id": 5269
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5270
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 2,
            "id": 5271
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5272
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5273
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5274
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 14,
            "id": 5275
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5276
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 4,
            "id": 5277
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5278
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5279
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5280
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 13,
            "id": 5281
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5282
          },
          {
            "timestamp": "2026-02-10 09:22:11,391",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5283
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5284
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5285
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 9,
            "id": 5286
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5287
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 16,
            "id": 5288
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5289
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 3,
            "id": 5290
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5291
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5292
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5293
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 1,
            "id": 5294
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5295
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 2,
            "id": 5296
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5297
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5298
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 1,
            "id": 5299
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5300
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5301
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5302
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 9,
            "id": 5303
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5304
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 16,
            "id": 5305
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0u\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5306
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0u\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00t\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5307
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 5308
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0p\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5309
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0u\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00p\\xf2\\xa9\\x90H\\x02\\x00\\x00\\x18\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5310
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5311
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x02D\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5312
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02D\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5313
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000478"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5314
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000478"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7a280"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5315
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5316
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5317
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 5318
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5319
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "cD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5320
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000474"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "cD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5321
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 5322
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 5323
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 5324
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5325
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5326
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5327
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 5328
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 5329
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 5330
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5331
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 5332
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5333
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5334
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5335
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5336
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5337
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5338
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5339
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5340
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5341
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5342
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5343
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5344
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5345
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5346
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5347
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5348
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5349
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5350
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5351
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5352
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5353
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5354
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5355
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5356
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5357
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5358
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0u\\xa4\\x90H\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xdc\\xab\\x90H\\x02\\x00\\x00B\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5359
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 5360
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5361
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5362
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5363
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5364
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5365
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5366
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5367
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5368
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5369
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5370
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5371
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5372
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5373
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5374
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5375
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5376
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 5377
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e79cc0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5378
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5379
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5380
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5381
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5382
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5383
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 5384
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5385
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5386
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5387
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5388
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5389
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5390
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5391
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5392
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5393
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5394
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5395
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5396
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5397
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5398
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5399
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5400
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5401
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5402
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5403
          },
          {
            "timestamp": "2026-02-10 09:22:11,407",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5404
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5405
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5406
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5407
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5408
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5409
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5410
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5411
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5412
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5413
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5414
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5415
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5416
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5417
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 1,
            "id": 5418
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 14,
            "id": 5419
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5420
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5421
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5422
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5423
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 8,
            "id": 5424
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5425
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5426
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5427
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 5428
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5429
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 5430
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5431
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5432
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5433
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5434
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5435
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5436
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5437
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5438
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5439
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5440
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5441
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5442
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5443
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5444
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5445
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5446
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5447
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5448
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5449
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5450
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 5451
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5452
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5453
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5454
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5455
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xaf\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5456
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5457
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5458
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 5459
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xc1\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5460
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5461
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 5462
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1090000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5463
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegFlushKey"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10f2af0"
              }
            ],
            "repeated": 0,
            "id": 5464
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5465
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5466
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00cD\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5467
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5468
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5469
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000514"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bdb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5470
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5471
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5472
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5473
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5474
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5475
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5476
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5477
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5478
          },
          {
            "timestamp": "2026-02-10 09:22:11,423",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5479
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5480
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5481
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbbD\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5482
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5483
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bdb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5484
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x13E\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5485
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5486
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5487
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x13E\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5488
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x13E\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5489
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x13E\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5490
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5491
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5492
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5493
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x13E\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5494
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x13E\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5495
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5496
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000514"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7bdd0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5497
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5498
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "jE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5499
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5500
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5501
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "jE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5502
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "jE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5503
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "jE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5504
          },
          {
            "timestamp": "2026-02-10 09:22:11,438",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5505
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5506
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5507
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5508
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5509
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5510
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5511
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5512
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5513
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5514
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5515
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5516
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5517
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5518
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5519
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5520
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000540"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5521
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000540"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5522
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000544"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000540"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 5523
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000544"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7ac60"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5524
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5525
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5526
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5527
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5528
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5529
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 5530
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5531
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5532
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5533
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5534
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5535
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5536
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5537
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5538
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5539
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5540
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5541
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5542
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5543
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5544
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5545
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5546
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5547
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5548
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5549
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5550
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5551
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5552
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5553
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5554
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5555
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5556
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5557
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5558
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5559
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5560
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5561
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5562
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5563
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 1,
            "id": 5564
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 14,
            "id": 5565
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 5566
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5567
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5568
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 5569
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 8,
            "id": 5570
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5571
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5572
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5573
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 5574
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 5575
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              }
            ],
            "repeated": 0,
            "id": 5576
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 5577
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 5578
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 5579
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5580
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 5581
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 5582
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 5583
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              }
            ],
            "repeated": 0,
            "id": 5584
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              }
            ],
            "repeated": 0,
            "id": 5585
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 0,
            "id": 5586
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 5587
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 5588
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 5589
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 5590
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 0,
            "id": 5591
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              }
            ],
            "repeated": 0,
            "id": 5592
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 5593
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5594
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5595
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5596
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5597
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5598
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              }
            ],
            "repeated": 0,
            "id": 5599
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5600
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43670",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5601
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5602
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43430",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5603
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5604
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 5605
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100010",
                "pretty_value": "FILE_WRITE_EA|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5606
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5607
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a434f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5608
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5609
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 5610
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5611
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00jE\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5612
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "jE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5613
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5614
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5615
          },
          {
            "timestamp": "2026-02-10 09:22:11,454",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5616
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xafE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5617
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5618
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5619
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xafE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5620
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xafE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5621
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xafE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5622
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5623
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c829",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5624
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c829",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5625
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c870",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5626
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c870",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5627
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c89d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5628
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c89d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5629
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c8bc",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5630
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c8bc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5631
          },
          {
            "timestamp": "2026-02-10 09:22:11,469",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5632
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xafE\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5633
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xafE\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5634
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5635
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004a8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c870"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5636
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\tF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5637
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5638
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5639
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\tF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5640
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\tF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5641
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\tF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5642
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5643
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 5644
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 5645
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5646
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5eb2",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 5647
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5eb2",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 5648
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5649
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 5650
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000454"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c480"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5651
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5652
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00w+\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5653
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x101\\xe1\\xc6\"\\xfcn\\xf7@\\xb5\\x92\\xda\\xf9?[\t\"\\x17\r220728055442Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 5654
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x890J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 5655
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5656
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5657
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5658
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5659
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\CatRoot"
              }
            ],
            "repeated": 0,
            "id": 5660
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020000",
                "pretty_value": "READ_CONTROL"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5661
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5662
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\catroot2"
              }
            ],
            "repeated": 0,
            "id": 5663
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000514"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020000",
                "pretty_value": "READ_CONTROL"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5664
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5665
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5666
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5667
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "services",
            "api": "OpenSCManagerW",
            "status": true,
            "return": "0x24890a470b0",
            "arguments": [
              {
                "name": "MachineName",
                "value": ""
              },
              {
                "name": "DatabaseName",
                "value": ""
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "SC_MANAGER_CONNECT"
              }
            ],
            "repeated": 0,
            "id": 5668
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "services",
            "api": "OpenServiceW",
            "status": true,
            "return": "0x24890a47440",
            "arguments": [
              {
                "name": "ServiceControlManager",
                "value": "0x24890a470b0"
              },
              {
                "name": "ServiceName",
                "value": "CryptSvc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000005",
                "pretty_value": "SERVICE_QUERY_CONFIG|SERVICE_QUERY_STATUS"
              }
            ],
            "repeated": 0,
            "id": 5669
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5670
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5671
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5672
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\xba\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00H\\x02\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00h^\\xa0\\x90H\\x02\\x00\\x000V\\xad\\x90H\\x02\\x00\\x00\\xb1GI\\xe3\\xfe\\x7f\\x00\\x00\\xf0\\xdbB\\xe3\\xfe\\x7f\\x00\\x00`\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00`\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xdbB\\xe3\\xfe\\x7f\\x00\\x00\\xa0\\xb6\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xa0\\xb8\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\xc0sL\\xe1\\xfe\\x7f\\x00\\x00(5M\\xe1\\xfe\\x7f\\x00\\x00\\xdc\\x04H\\xe3\\xfe\\x7f\\x00\\x00\\x10\\x81*\\xe3\\xfe\\x7f\\x00\\x00\\x90\\xc2\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xc0\\xb7\\xa4\\x90H\\x02\\x00\\x00\\xc0\\xb7\\xa4\\x90H\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5673
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5674
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5675
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5676
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5677
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5678
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5679
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5680
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5681
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5682
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5683
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5684
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5685
          },
          {
            "timestamp": "2026-02-10 09:22:11,485",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5686
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5687
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000c4"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 5688
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000558"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000000c4"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Cryptography\\CatalogDB"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\CatalogDB"
              }
            ],
            "repeated": 0,
            "id": 5689
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "ValueName",
                "value": "CatDBLogging"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging"
              }
            ],
            "repeated": 0,
            "id": 5690
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5691
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 5692
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5693
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5694
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5695
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5696
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5697
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5698
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5699
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5700
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5701
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5702
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5703
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5704
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5705
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5706
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5707
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5708
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5709
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5710
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5711
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5712
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5713
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5714
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5715
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5716
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5717
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5718
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\xf5\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 1,
            "id": 5719
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf5\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5720
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "Buffer",
                "value": "CatalogDB: 12:22:11 10.02.2026: DONE Adding Catalog File (109ms): oem1.cat\r\n"
              },
              {
                "name": "Length",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 5721
          },
          {
            "timestamp": "2026-02-10 09:22:11,594",
            "thread_id": "348",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5722
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5723
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\tF\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5724
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\tF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5725
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000558"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5726
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000558"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c650"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5727
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "ZF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5728
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5729
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5730
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "ZF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5731
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "ZF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5732
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "ZF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5733
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5734
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5735
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5736
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5737
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5738
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5739
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5740
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5741
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5742
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5743
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5744
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5745
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5746
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43430",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 5747
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5748
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5749
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5750
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000046c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 5751
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7b810"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5752
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5753
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5754
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5755
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5756
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5757
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 5758
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5759
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5760
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5761
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5762
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5763
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5764
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5765
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5766
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5767
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5768
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5769
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5770
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5771
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5772
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5773
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5774
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5775
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5776
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5777
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5778
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5779
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5780
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5781
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5782
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5783
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5784
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5785
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5786
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5787
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5788
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5789
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5790
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5791
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 1,
            "id": 5792
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 14,
            "id": 5793
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5794
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5795
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5796
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5797
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 10,
            "id": 5798
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 1,
            "id": 5799
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 3,
            "id": 5800
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5801
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5802
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5803
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5804
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5805
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 1,
            "id": 5806
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5807
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 1,
            "id": 5808
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 2,
            "id": 5809
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5810
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 5811
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5812
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 5813
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 5814
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5815
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5816
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 5817
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 5818
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 5819
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 5820
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5821
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 5822
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5823
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 5824
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5825
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 5826
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5827
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 5828
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5829
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5830
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5831
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5832
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5833
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5834
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5835
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5836
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5837
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5838
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5839
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 5840
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5841
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 5842
          },
          {
            "timestamp": "2026-02-10 09:22:11,610",
            "thread_id": "348",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5843
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5844
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00ZF\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5845
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "ZF\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5846
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5847
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c900"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5848
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5849
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5850
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5851
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 5852
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5853
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5854
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5855
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5856
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 1,
            "id": 5857
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5858
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5859
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1F\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5860
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000558"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5861
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000558"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7c940"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5862
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5863
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07G\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5864
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5865
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5866
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07G\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5867
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07G\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5868
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07G\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5869
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5870
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5871
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5872
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x24890a43430",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\*"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbbf4333d"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 5873
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5874
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5875
          },
          {
            "timestamp": "2026-02-10 09:22:11,626",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5876
          },
          {
            "timestamp": "2026-02-10 09:22:11,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
              }
            ],
            "repeated": 0,
            "id": 5877
          },
          {
            "timestamp": "2026-02-10 09:22:11,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5878
          },
          {
            "timestamp": "2026-02-10 09:22:11,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000510"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5879
          },
          {
            "timestamp": "2026-02-10 09:22:11,641",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5880
          },
          {
            "timestamp": "2026-02-10 09:22:11,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 5881
          },
          {
            "timestamp": "2026-02-10 09:22:11,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5882
          },
          {
            "timestamp": "2026-02-10 09:22:11,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5883
          },
          {
            "timestamp": "2026-02-10 09:22:11,657",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 5884
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 5885
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5886
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000508"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5887
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000508"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5888
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5889
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "RemoveDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
              }
            ],
            "repeated": 0,
            "id": 5890
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 5891
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 5892
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 5893
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 5894
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 5895
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 5896
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad8000"
              },
              {
                "name": "RegionSize",
                "value": "0x0001d000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5897
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a2f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5898
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad1000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5899
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890abf000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5900
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890a2f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5901
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5902
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x07G\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5903
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x07G\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5904
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5905
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0xa1d1e7f760"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5906
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5907
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "RG\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5908
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5909
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 5910
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "RG\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5911
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "RG\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5912
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "RG\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5913
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 5914
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 5915
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5916
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 5917
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890abf000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5918
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5919
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x24890ad1000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5920
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 5921
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5922
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5923
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5924
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 1,
            "id": 5925
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b38e8",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xa0\\xd5\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5926
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3af7c4",
            "parentcaller": "0x7ff70a3b0743",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 5927
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3af7e1",
            "parentcaller": "0x7ff70a3b0743",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 5928
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3ac017",
            "parentcaller": "0x7ff70a3afced",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 5929
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3afd69",
            "parentcaller": "0x7ff70a3af82a",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 5930
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3abf8a",
            "parentcaller": "0x7ff70a3adbe3",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 5931
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3acc51",
            "parentcaller": "0x7ff70a3aff35",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 5932
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3abefb",
            "parentcaller": "0x7ff70a3b02e8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 5933
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b128a",
            "parentcaller": "0x7ff70a3afb53",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:2964:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5934
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b12b3",
            "parentcaller": "0x7ff70a3afb53",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5935
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad0ac",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5936
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad0ac",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5937
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad123",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5938
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad123",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5939
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3ad152",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              }
            ],
            "repeated": 0,
            "id": 5940
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3ad16b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              }
            ],
            "repeated": 0,
            "id": 5941
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3acd73",
            "parentcaller": "0x7ff70a3b132a",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5942
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3b1337",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5943
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca1a4",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5944
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca1a4",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5945
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b0ef3",
            "parentcaller": "0x7ff70a3b3910",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470803"
              },
              {
                "name": "InBuffer",
                "value": "\\x18\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0|\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5946
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b0f53",
            "parentcaller": "0x7ff70a3b3910",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470803"
              },
              {
                "name": "InBuffer",
                "value": "\\x18\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00|\\x14\\x00\\x00\\x00\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\\\x004\\x00&\\x002\\x00c\\x003\\x005\\x002\\x00a\\x002\\x007\\x00&\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\\\x00C\\x00P\\x00U\\x00_\\x00H\\x00o\\x00t\\x00p\\x00l\\x00u\\x00g\\x00_\\x00r\\x00e\\x00s\\x00o\\x00u\\x00r\\x00c\\x00e\\x00s\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\\\x004\\x00&\\x002\\x00c\\x003\\x005\\x002\\x00a\\x002\\x007\\x00&\\x000\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00s\\x00\\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00v\\x00o\\x00"
              }
            ],
            "repeated": 0,
            "id": 5947
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5948
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5949
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00F\\x001\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5950
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5951
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5952
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5953
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00m\\x00o\\x00u\\x00s\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5954
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5955
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5956
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5957
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5958
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5959
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5960
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5961
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5962
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5963
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5964
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5965
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x007\\x000\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5966
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5967
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5968
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5969
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00f\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5970
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5971
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5972
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5973
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x006\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00L\\x00o\\x00c\\x00a\\x00l\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 5974
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5975
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00p\\x00r\\x00i\\x00n\\x00t\\x00q\\x00u\\x00e\\x00u\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00]\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5976
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00N\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 5977
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5978
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5979
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5980
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5981
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5982
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00V\\x00O\\x00L\\x00M\\x00G\\x00R\\x00\\x00\\x00\\x00\\x00w\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5983
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5984
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00n\\x00f\\x00"
              }
            ],
            "repeated": 0,
            "id": 5985
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00R\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5986
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5987
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5988
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5989
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5990
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe6\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00{\\x000\\x008\\x004\\x00f\\x000\\x001\\x00f\\x00a\\x00-\\x00e\\x006\\x003\\x004\\x00-\\x004\\x00d\\x007\\x007\\x00-\\x008\\x003\\x00e\\x00e\\x00-\\x000\\x007\\x004\\x008\\x001\\x007\\x00c\\x000\\x003\\x005\\x008\\x001\\x00}\\x00\\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00L\\x00o\\x00c\\x00a\\x00l\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00{\\x000\\x008\\x004\\x00f\\x000\\x001\\x00f\\x00a\\x00-\\x00e\\x006\\x003\\x004\\x00-\\x004\\x00d\\x007\\x007\\x00-\\x008\\x003\\x00e\\x00e\\x00-\\x000\\x007\\x004\\x008\\x001\\x007\\x00c\\x000\\x003\\x005\\x008\\x001\\x00}\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5991
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5992
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5993
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00p\\x00r\\x00i\\x00n\\x00t\\x00q\\x00u\\x00e\\x00u\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00]\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5994
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5995
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00o\\x00e\\x00m\\x000\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5996
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00T\\x00\\x00\\x00\\x12 \\x00\\x00G\\x00e\\x00n\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x000\\x003\\x00"
              }
            ],
            "repeated": 0,
            "id": 5997
          },
          {
            "timestamp": "2026-02-10 09:22:11,673",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5998
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5999
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00]\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6000
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6001
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6002
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6003
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00&\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00B\\x00a\\x00s\\x00i\\x00c\\x00D\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6004
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0$\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6005
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00b\\x00a\\x00s\\x00i\\x00c\\x00d\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6006
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6007
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6008
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6009
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00B\\x000\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00B\\x000\\x000\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00B\\x000\\x000\\x00\\x00\\x00\\x00\\x008\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 6010
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6011
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6012
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6013
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00e\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 6014
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6015
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6016
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6017
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00N\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6018
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6019
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6020
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a39b1dc",
            "parentcaller": "0x7ff70a3b39b6",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xf3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6021
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a39b215",
            "parentcaller": "0x7ff70a3b39b6",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xf3\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6022
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6023
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6024
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00P\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x01\\x00\\x00\\x12 \\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x000\\x00\\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00\\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00U\\x00P\\x00:\\x000\\x000\\x000\\x001\\x00_\\x00U\\x00:\\x000\\x000\\x000\\x002\\x00\\x00\\x00H\\x00I\\x00D\\x00_\\x00D\\x00E\\x00V\\x00I\\x00C\\x00E\\x00_\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00_\\x00M\\x00O\\x00U\\x00S\\x00E\\x00\\x00\\x00H\\x00I\\x00D\\x00_\\x00D\\x00E\\x00V\\x00I\\x00C\\x00E\\x00_\\x00U\\x00P\\x00:\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6025
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6026
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6027
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6028
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6029
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00m\\x00o\\x00u\\x00s\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00e\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 6030
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6031
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6032
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00i\\x00n\\x00p\\x00u\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 6033
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00P\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6034
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00D\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6035
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6036
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00D\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x007\\x00&\\x00"
              }
            ],
            "repeated": 0,
            "id": 6037
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6038
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 6039
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00D\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6040
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6041
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6042
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x003\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x003\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x003\\x000\\x003\\x00\\x00\\x00\\x00\\x00I\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6043
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6044
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6045
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6046
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00k\\x00e\\x00y\\x00b\\x00o\\x00a\\x00r\\x00d\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x002\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6047
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6048
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6049
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6050
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00D\\x00\\x00\\x00\\x12 \\x00\\x00I\\x00n\\x00t\\x00e\\x00l\\x00-\\x00P\\x00I\\x00I\\x00X\\x003\\x00\\x00\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00_\\x00I\\x00D\\x00E\\x00_\\x00C\\x00h\\x00a\\x00n\\x00n\\x00e\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00"
              }
            ],
            "repeated": 0,
            "id": 6051
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6052
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6053
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 6054
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x006\\x000\\x000\\x00\\x00\\x00\\x00\\x003\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6055
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6056
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6057
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6058
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00D\\x00\\x00\\x00\\x12 \\x00\\x00I\\x00n\\x00t\\x00e\\x00l\\x00-\\x00P\\x00I\\x00I\\x00X\\x003\\x00\\x00\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00_\\x00I\\x00D\\x00E\\x00_\\x00C\\x00h\\x00a\\x00n\\x00n\\x00e\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00"
              }
            ],
            "repeated": 0,
            "id": 6059
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6060
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6061
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6062
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x006\\x000\\x000\\x00\\x00\\x00\\x00\\x003\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6063
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6064
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6065
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6066
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x001\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x001\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x001\\x000\\x003\\x00\\x00\\x00\\x00\\x00I\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6067
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6068
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6069
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6070
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6071
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6072
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x9a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6073
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6074
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x9a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\x01\\x00\\x00\\x12 \\x00\\x00I\\x00D\\x00E\\x00\\\\x00C\\x00d\\x00R\\x00o\\x00m\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00D\\x00V\\x00D\\x00-\\x00R\\x00O\\x00M\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x002\\x00.\\x005\\x00+\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00I\\x00D\\x00E\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00D\\x00V\\x00D\\x00-\\x00R\\x00O\\x00M\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x002\\x00.\\x005\\x00+\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00I\\x00D\\x00E\\x00\\\\x00C\\x00d\\x00R\\x00o\\x00m\\x00"
              }
            ],
            "repeated": 0,
            "id": 6075
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00t\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6076
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6077
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00d\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6078
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6079
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6080
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00d\\x00r\\x00o\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00e\\x00m\\x00"
              }
            ],
            "repeated": 0,
            "id": 6081
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x9a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00G\\x00e\\x00n\\x00C\\x00d\\x00R\\x00o\\x00m\\x00\\x00\\x00\\x00\\x00E\\x00M\\x00"
              }
            ],
            "repeated": 0,
            "id": 6082
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6083
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00d\\x00r\\x00o\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6084
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00V\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6085
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6086
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00V\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00l\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6087
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6088
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6089
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00V\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00&\\x00S\\x00u\\x00b\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x000\\x00&\\x00P\\x00r\\x00o\\x00t\\x00_\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00&\\x00S\\x00u\\x00b\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00\\x00\\x00\\x00\\x00D\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6090
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6091
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x002\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6092
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6093
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00i\\x00n\\x00p\\x00u\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6094
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6095
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6096
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00&\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00C\\x00o\\x00m\\x00p\\x00o\\x00s\\x00i\\x00t\\x00e\\x00B\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00s\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 6097
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0$\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6098
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00o\\x00m\\x00p\\x00o\\x00s\\x00i\\x00t\\x00e\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x91\\xc1\\x81\\x00"
              }
            ],
            "repeated": 0,
            "id": 6099
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6100
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6101
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6102
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00v\\x00d\\x00r\\x00v\\x00r\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x00\\x00u\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 6103
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6104
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00d\\x00r\\x00v\\x00r\\x00o\\x00o\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00n\\x00f\\x00"
              }
            ],
            "repeated": 0,
            "id": 6105
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6106
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6107
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6108
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6109
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6110
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6111
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6112
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6113
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 6114
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6115
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6116
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6117
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6118
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6119
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6120
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6121
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6122
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6123
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6124
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6125
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00_\\x007\\x00"
              }
            ],
            "repeated": 0,
            "id": 6126
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6127
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6128
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6129
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6130
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6131
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6132
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6133
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00R\\x00o\\x00o\\x00t\\x00\\\\x00S\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00\\x00\\x00_\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6134
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6135
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6136
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00^\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00\\x00\\x000\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 6137
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x006\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6138
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6139
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6140
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6141
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6142
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6143
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6144
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6145
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6146
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6147
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6148
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6149
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6150
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6151
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6152
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6153
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6154
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6155
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6156
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6157
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6158
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00_\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 6159
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6160
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6161
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6162
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6163
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6164
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6165
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6166
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00o\\x00o\\x00t\\x00\\\\x00k\\x00d\\x00n\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00&\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6167
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6168
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00k\\x00d\\x00n\\x00i\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6169
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6170
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6171
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6172
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00&\\x00V\\x00I\\x00D\\x008\\x000\\x008\\x006\\x00&\\x00P\\x00I\\x00D\\x007\\x000\\x002\\x000\\x00&\\x00R\\x00E\\x00V\\x000\\x000\\x000\\x001\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00&\\x00V\\x00I\\x00D\\x008\\x000\\x008\\x006\\x00&\\x00P\\x00I\\x00D\\x007\\x000\\x002\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00\\x00\\x00\\x00\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6173
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6174
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6175
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6176
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6177
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6178
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6179
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6180
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00A\\x00C\\x00P\\x00I\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x001\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00A\\x00C\\x00P\\x00I\\x000\\x000\\x001\\x000\\x00\\x00\\x00*\\x00A\\x00C\\x00P\\x00I\\x000\\x000\\x001\\x000\\x00\\x00\\x00\\x00\\x00B\\x00&\\x00"
              }
            ],
            "repeated": 0,
            "id": 6181
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6182
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6183
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6184
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6185
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x005\\x00\\x00\\x00\\x00\\x00C\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6186
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6187
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00C\\x004\\x00"
              }
            ],
            "repeated": 0,
            "id": 6188
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6189
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6190
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00P\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6191
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6192
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6193
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6194
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6195
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6196
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x01\\x00\\x00\\x12 \\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x002\\x00.\\x005\\x00+\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6197
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6198
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00D\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6199
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6200
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6201
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6202
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6203
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00d\\x00i\\x00s\\x00k\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6204
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00R\\x00A\\x00W\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6205
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6206
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6207
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6208
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6209
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6210
          },
          {
            "timestamp": "2026-02-10 09:22:11,688",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6211
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6212
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6213
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6214
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6215
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6216
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6217
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6218
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6219
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6220
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6221
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6222
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6223
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6224
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6225
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6226
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6227
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6228
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6229
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6230
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6231
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6232
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00e\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6233
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6234
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6235
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6236
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6237
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6238
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6239
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6240
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6241
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6242
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6243
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6244
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6245
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6246
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6247
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6248
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6249
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6250
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6251
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6252
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6253
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6254
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6255
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6256
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6257
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6258
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6259
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6260
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6261
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00S\\x00T\\x00O\\x00R\\x00A\\x00G\\x00E\\x00\\\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6262
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6263
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00u\\x00m\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6264
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6265
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6266
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6267
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6268
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6269
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6270
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6271
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6272
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6273
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6274
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6275
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6276
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6277
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6278
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6279
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6280
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6281
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6282
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6283
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00o\\x00o\\x00t\\x00\\\\x00u\\x00m\\x00b\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00&\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6284
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6285
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\x80"
              }
            ],
            "repeated": 0,
            "id": 6286
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6287
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6288
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6289
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00M\\x00O\\x00N\\x00I\\x00T\\x00O\\x00R\\x00\\\\x00R\\x00H\\x00T\\x001\\x002\\x003\\x004\\x00\\x00\\x00\\x00\\x002\\x009\\x00"
              }
            ],
            "repeated": 0,
            "id": 6290
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00 \\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6291
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x009\\x00F\\x00F\\x00\\x00\\x00\\x00\\x00T\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 6292
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6293
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00o\\x00n\\x00i\\x00t\\x00o\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6294
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6295
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6296
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6297
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6298
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6299
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6300
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6301
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6302
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6303
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6304
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6305
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6306
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6307
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6308
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6309
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6310
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00a\\x00c\\x00p\\x00i\\x00a\\x00p\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00c\\x00R\\x00"
              }
            ],
            "repeated": 0,
            "id": 6311
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6312
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00h\\x00a\\x00l\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6313
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\x00\\x00\\x00\\x00_\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6314
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6315
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6316
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6317
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6318
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x003\\x00\\x00\\x00\\x00\\x00_\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6319
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6320
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6321
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6322
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6323
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6324
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6325
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6326
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x006\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\\\x00P\\x00N\\x00P\\x000\\x00C\\x000\\x008\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00C\\x000\\x008\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 6327
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6328
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6329
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00a\\x00c\\x00p\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00H\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6330
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6331
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6332
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6333
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6334
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6335
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6336
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6337
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00B\\x00a\\x00s\\x00i\\x00c\\x00R\\x00e\\x00n\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 6338
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\"\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6339
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00b\\x00a\\x00s\\x00i\\x00c\\x00r\\x00e\\x00n\\x00d\\x00e\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6340
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6341
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6342
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6343
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6344
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6345
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6346
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6347
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6348
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6349
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6350
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6351
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6352
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6353
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6354
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6355
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x005\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x005\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6356
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6357
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6358
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6359
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6360
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6361
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6362
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6363
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6364
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6365
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6366
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6367
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6368
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6369
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6370
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00F\\x00i\\x00x\\x00e\\x00d\\x00B\\x00u\\x00t\\x00t\\x00o\\x00n\\x00\\x00\\x00*\\x00F\\x00i\\x00x\\x00e\\x00d\\x00B\\x00u\\x00t\\x00t\\x00o\\x00n\\x00\\x00\\x00\\x00\\x00I\\x00\\\\x00"
              }
            ],
            "repeated": 0,
            "id": 6371
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6372
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00}\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6373
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6374
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6375
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6376
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6377
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6378
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6379
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6380
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6381
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6382
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6383
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6384
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6385
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6386
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6387
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6388
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6389
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6390
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00d\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00C\\x004\\x00"
              }
            ],
            "repeated": 0,
            "id": 6391
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6392
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6393
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6394
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00N\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6395
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6396
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6397
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6398
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6399
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6400
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00S\\x00T\\x00O\\x00R\\x00A\\x00G\\x00E\\x00\\\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00\\x00\\x00\\x00\\x00W\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6401
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6402
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00u\\x00m\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x006\\x008"
              }
            ],
            "repeated": 0,
            "id": 6403
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6404
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6405
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6406
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00T\\x00S\\x00_\\x00U\\x00R\\x00B\\x00_\\x00H\\x00U\\x00B\\x00\\x00\\x00\\x00\\x00W\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6407
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6408
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00t\\x00s\\x00u\\x00s\\x00b\\x00h\\x00u\\x00b\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6409
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6410
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6411
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6412
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6413
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6414
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6415
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6416
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6417
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6418
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6419
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6420
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00n\\x00e\\x00t\\x00e\\x001\\x00g\\x003\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6421
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6422
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6423
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6424
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6425
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6426
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x002\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6427
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6428
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x002\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00N\\x00d\\x00i\\x00s\\x00V\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00B\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00&\\x00R\\x00"
              }
            ],
            "repeated": 0,
            "id": 6429
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0(\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6430
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\x00\\x00\\x00\\x12 \\x00\\x00n\\x00d\\x00i\\x00s\\x00v\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00d\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 6431
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x002\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6432
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6433
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6434
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x001\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x001\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6435
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6436
          },
          {
            "timestamp": "2026-02-10 09:22:11,704",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6437
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6438
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6439
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6440
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6441
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6442
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6443
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6444
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6445
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6446
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6447
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6448
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6449
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6450
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6451
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6452
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6453
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6454
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6455
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6456
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6457
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6458
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6459
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6460
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6461
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6462
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6463
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00r\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6464
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6465
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18n\\x00f\\x00"
              }
            ],
            "repeated": 0,
            "id": 6466
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x002\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00V\\x00G\\x00I\\x00D\\x00\\x00\\x00*\\x00Q\\x00E\\x00M\\x00U\\x00V\\x00G\\x00I\\x00D\\x00\\x00\\x00\\x00\\x00_\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6467
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6468
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6469
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00M\\x00_\\x00G\\x00e\\x00n\\x00_\\x00C\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00\\x00\\x00V\\x00M\\x00_\\x00G\\x00e\\x00n\\x00_\\x00C\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00_\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 6470
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6471
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\"\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6472
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00w\\x00g\\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6473
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6474
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6475
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00m\\x00s\\x00s\\x00m\\x00b\\x00i\\x00o\\x00s\\x00\\x00\\x00\\x00\\x00n\\x00t\\x00"
              }
            ],
            "repeated": 0,
            "id": 6476
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6477
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00s\\x00m\\x00b\\x00i\\x00o\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6478
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6479
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6480
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6481
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6482
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6483
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6484
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6485
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6486
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6487
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6488
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6489
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6490
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6491
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6492
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6493
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6494
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6495
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6496
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6497
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6498
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6499
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6500
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6501
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6502
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6503
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6504
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6505
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6506
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6507
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6508
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6509
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6510
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6511
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6512
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6513
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6514
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6515
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6516
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6517
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6518
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6519
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6520
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6521
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6522
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6523
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6524
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6525
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6526
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6527
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6528
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6529
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00S\\x00W\\x00E\\x00N\\x00U\\x00M\\x00\\x00\\x00\\x00\\x00C\\x00C\\x00"
              }
            ],
            "repeated": 0,
            "id": 6530
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6531
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00s\\x00w\\x00e\\x00n\\x00u\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00}\\x00"
              }
            ],
            "repeated": 0,
            "id": 6532
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6533
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6534
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6535
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00R\\x00D\\x00P\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00C\\x00C\\x00"
              }
            ],
            "repeated": 0,
            "id": 6536
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6537
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00d\\x00p\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6538
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6539
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x006\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6540
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6541
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x006\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x002\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x000\\x000\\x000\\x002\\x00\\x00\\x00*\\x00Q\\x00E\\x00M\\x00U\\x000\\x000\\x000\\x002\\x00\\x00\\x00\\x00\\x00V\\x00E\\x00"
              }
            ],
            "repeated": 0,
            "id": 6542
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6543
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6544
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6545
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x006\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6546
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xf4\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6547
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x90\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6548
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6549
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6550
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6551
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6552
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6553
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6554
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe9\\xe7\\xd1\\xa1\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6555
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6556
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6557
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6558
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6559
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6560
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6561
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x008\\x009"
              }
            ],
            "repeated": 0,
            "id": 6562
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000234"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xca\\xe7\\xd1\\xa1\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6563
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b3a70",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 6564
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a3b3a70",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 6565
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a392ea7",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x248911a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 6566
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a392ec0",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 6567
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a392efc",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 6568
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a392f10",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 6569
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a391747",
            "parentcaller": "0x7ff70a392f1a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 6570
          },
          {
            "timestamp": "2026-02-10 09:22:11,719",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 6571
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 6572
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 6573
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 6574
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6575
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6576
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 6577
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 6578
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 6579
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 6580
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 6581
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 6582
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 6583
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 6584
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 6585
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 6586
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 6587
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              }
            ],
            "repeated": 0,
            "id": 6588
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 6589
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 6590
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 6591
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 6592
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDIDestroy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed97572b0"
              }
            ],
            "repeated": 0,
            "id": 6593
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 1,
            "id": 6594
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 6595
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 6596
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 6597
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 6598
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 6599
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e4"
              }
            ],
            "repeated": 0,
            "id": 6600
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              }
            ],
            "repeated": 0,
            "id": 6601
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 6602
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d4"
              }
            ],
            "repeated": 0,
            "id": 6603
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 6604
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c8"
              }
            ],
            "repeated": 0,
            "id": 6605
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c4"
              }
            ],
            "repeated": 0,
            "id": 6606
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 6607
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 6608
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000190"
              }
            ],
            "repeated": 0,
            "id": 6609
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000194"
              }
            ],
            "repeated": 0,
            "id": 6610
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000018c"
              }
            ],
            "repeated": 0,
            "id": 6611
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000017c"
              }
            ],
            "repeated": 0,
            "id": 6612
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000015c"
              }
            ],
            "repeated": 0,
            "id": 6613
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000160"
              }
            ],
            "repeated": 0,
            "id": 6614
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000158"
              }
            ],
            "repeated": 0,
            "id": 6615
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000140"
              }
            ],
            "repeated": 0,
            "id": 6616
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000144"
              }
            ],
            "repeated": 0,
            "id": 6617
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000148"
              }
            ],
            "repeated": 0,
            "id": 6618
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000014c"
              }
            ],
            "repeated": 0,
            "id": 6619
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000150"
              }
            ],
            "repeated": 0,
            "id": 6620
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000154"
              }
            ],
            "repeated": 0,
            "id": 6621
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 6622
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 6623
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000138"
              }
            ],
            "repeated": 0,
            "id": 6624
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000013c"
              }
            ],
            "repeated": 0,
            "id": 6625
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000134"
              }
            ],
            "repeated": 0,
            "id": 6626
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6627
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6628
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000118"
              }
            ],
            "repeated": 0,
            "id": 6629
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000011c"
              }
            ],
            "repeated": 0,
            "id": 6630
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000120"
              }
            ],
            "repeated": 0,
            "id": 6631
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000124"
              }
            ],
            "repeated": 0,
            "id": 6632
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000128"
              }
            ],
            "repeated": 0,
            "id": 6633
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000130"
              }
            ],
            "repeated": 0,
            "id": 6634
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000012c"
              }
            ],
            "repeated": 0,
            "id": 6635
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f8"
              }
            ],
            "repeated": 0,
            "id": 6636
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000fc"
              }
            ],
            "repeated": 0,
            "id": 6637
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f4"
              }
            ],
            "repeated": 0,
            "id": 6638
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f0"
              }
            ],
            "repeated": 0,
            "id": 6639
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e8"
              }
            ],
            "repeated": 0,
            "id": 6640
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000ec"
              }
            ],
            "repeated": 0,
            "id": 6641
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e4"
              }
            ],
            "repeated": 0,
            "id": 6642
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e0"
              }
            ],
            "repeated": 0,
            "id": 6643
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000dc"
              }
            ],
            "repeated": 0,
            "id": 6644
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6645
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000c8"
              }
            ],
            "repeated": 0,
            "id": 6646
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000cc"
              }
            ],
            "repeated": 0,
            "id": 6647
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a4"
              }
            ],
            "repeated": 0,
            "id": 6648
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a0"
              }
            ],
            "repeated": 0,
            "id": 6649
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6650
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 6651
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "ValueName",
                "value": "DisableMetaFiles"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
              }
            ],
            "repeated": 0,
            "id": 6652
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6653
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 6654
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "ValueName",
                "value": "DisableUmpdBufferSizeCheck"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck"
              }
            ],
            "repeated": 0,
            "id": 6655
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6656
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6657
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 6658
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000090"
              }
            ],
            "repeated": 0,
            "id": 6659
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000008c"
              }
            ],
            "repeated": 0,
            "id": 6660
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6661
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001a0"
              }
            ],
            "repeated": 0,
            "id": 6662
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000084"
              }
            ],
            "repeated": 0,
            "id": 6663
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6664
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6665
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000064"
              }
            ],
            "repeated": 0,
            "id": 6666
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000004c"
              }
            ],
            "repeated": 0,
            "id": 6667
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000005c"
              }
            ],
            "repeated": 0,
            "id": 6668
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000060"
              }
            ],
            "repeated": 0,
            "id": 6669
          },
          {
            "timestamp": "2026-02-10 09:22:11,735",
            "thread_id": "348",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 6670
          }
        ],
        "threads": [
          "348",
          "4268",
          "4692",
          "1816",
          "2940"
        ],
        "environ": {
          "UserName": "￑￈￑ￒￅￌ￀",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\"",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff70a390000",
          "MainExeSize": "0x00057000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 4644,
        "process_name": "drvinst.exe",
        "parent_id": 740,
        "module_path": "C:\\Windows\\System32\\drvinst.exe",
        "first_seen": "2026-02-10 09:22:11,823",
        "calls": [
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "4632",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "4632",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\cfgmgr32"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1420000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee1433750"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "4632",
            "caller": "0x7ffee34dc2c7",
            "parentcaller": "0x7ffee34dc05a",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\ntmarta"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfcb0000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedfcb6930"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "4632",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "2776",
            "caller": "0x7ffee34ceb32",
            "parentcaller": "0x7ffee34877c3",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 2,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:22:11,948",
            "thread_id": "3980",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 3,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3c9cf1",
            "parentcaller": "0x7ff70a3c9859",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x7ff70a3c9ca0"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118ad000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120d6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120d7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a39265a",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtOpenProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x000001ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000040",
                "pretty_value": "PROCESS_DUP_HANDLE"
              },
              {
                "name": "ProcessIdentifier",
                "value": "740"
              },
              {
                "name": "ProcessName",
                "value": "Error obtaining target process name"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a392684",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "misc",
            "api": "GetCommandLineW",
            "status": true,
            "return": "0x21411882078",
            "arguments": [
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\""
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a392cb9",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x000001ec"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000e88"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000001e0"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a394623",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393eb6",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000001d0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Policies\\Microsoft\\Windows\\DeviceInstall"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\DeviceInstall"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a394723",
            "parentcaller": "0x7ff70a393eb6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d0"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a391efd",
            "parentcaller": "0x7ff70a392e1a",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x000001d0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ff70a391d70"
              },
              {
                "name": "Parameter",
                "value": "0x32fa50fd78"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              },
              {
                "name": "ProcessId",
                "value": "4644"
              },
              {
                "name": "Module",
                "value": "DrvInst.exe"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "4632",
            "caller": "0x7ff70a391efd",
            "parentcaller": "0x7ff70a392e1a",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x000001d0",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ff70a391d70"
              },
              {
                "name": "Parameter",
                "value": "0x32fa50fd78"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              },
              {
                "name": "ProcessId",
                "value": "4644"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118ae000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "DEVRTL.dll"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000001dc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00014000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:22:11,963",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\DEVRTL"
              },
              {
                "name": "DllBase",
                "value": "0x7ffec7f70000"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\devrtl"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffec7f71690"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39af78",
            "parentcaller": "0x7ff70a391da2",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf02",
            "parentcaller": "0x7ff70a39af85",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xe6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf60",
            "parentcaller": "0x7ff70a39af85",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118af000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf60",
            "parentcaller": "0x7ff70a39af85",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf60",
            "parentcaller": "0x7ff70a39af85",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a394623",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393eb6",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000220"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000021c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a394723",
            "parentcaller": "0x7ff70a393eb6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393ee2",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000220"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a393eee",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a393f23",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "DebugInstall"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugInstall"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a393f2f",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a6c3",
            "parentcaller": "0x7ff70a39b0ab",
            "category": "synchronization",
            "api": "NtCreateEvent",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "EventName",
                "value": "Global\\DrvInst_Sync_ROOT#NET#0000"
              },
              {
                "name": "EventType",
                "value": "0"
              },
              {
                "name": "InitialState",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000220"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000224"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000220"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000224"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00148000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\drvstore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffeced50000"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\drvstore"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffeced5b160"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b2000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b4000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000244"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x0f"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a813",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 1,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000098"
              },
              {
                "name": "ValueName",
                "value": "000603xx"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "kernel32.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortGetHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee166a190"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortCloseHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1680170"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000248"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000248"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\SortDefault.nls"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214139b0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7dc50"
              },
              {
                "name": "ViewSize",
                "value": "0x00338000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000248"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xee\\xe7\\xb7\\xfa2\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xee\\xe7\\xb7\\xfa2\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00B\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\x00\\x00d\\x00r\\x00"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a0a50",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbc7d7f07"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000250"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem1.inf"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000254"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d090"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000250"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118bb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c1000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 1,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b8000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000e000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x80~\\xd0K\\xa1\\xd8\\x01w\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x02\\x00w\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0\\xe3\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00s\\x00 \\x00"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0\\x13\\x8a\\x11\\x14\\x02\\x00\\x00R\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x17\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:11,979",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39a888",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39a8e4",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xf3\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39a979",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0\\xd4\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39a9b1",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xf4\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39a213",
            "parentcaller": "0x7ff70a39a9ef",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\xee\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xdde\\xb8\\xa8=.\\x94@\\xad\\x97\\xe5\\x93\\xa7\\x0cu\\xd6\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b8000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000e000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 1,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xf0\\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b9000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000d000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a39aa5f",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b9000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000d000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a399e70",
            "parentcaller": "0x7ff70a39aa98",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a399fa8",
            "parentcaller": "0x7ff70a39aa98",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xd1\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a399f17",
            "parentcaller": "0x7ff70a39aa98",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3b338d",
            "parentcaller": "0x7ff70a39aab2",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xc9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00s\\x00 \\x00"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a39aab2",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xc9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a39aab2",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xe8\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00`\\xc9\\xb7\\xfa2\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00`\\xc9\\xb7\\xfa2\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf02",
            "parentcaller": "0x7ff70a3a185a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf60",
            "parentcaller": "0x7ff70a3a185a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3aaf60",
            "parentcaller": "0x7ff70a3a185a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1880",
            "parentcaller": "0x7ff70a3a1fb2",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": "DrvInst.exe_mutex_{5B10AC83-4F13-4fde-8C0B-B85681BA8D73}"
              },
              {
                "name": "InitialOwner",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000260"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000264"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x90H\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000264"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000264"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7e770"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000260"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a70c4",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7123",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 1,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7235",
            "parentcaller": "0x7ff70a39ab24",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xc9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7294",
            "parentcaller": "0x7ff70a39ab24",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xe9\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:22:11,995",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "DEVOBJ.dll"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devobj.dll"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000268"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devobj.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000026c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000268"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devobj.dll"
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000026c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0870000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00033000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee08a0000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0892000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\DEVOBJ"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee0870000"
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\devobj"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0870000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee08775d0"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca0d1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7398",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a395201",
            "parentcaller": "0x7ff70a399a90",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00!"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1c45",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 1,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1d3a",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x80~\\xd0K\\xa1\\xd8\\x01w\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1d91",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x02\\x00w\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1df0",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12\\x00\\x00\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00\\x00\\x00T\\x00$\\x00"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1e48",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1e90",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1e90",
            "parentcaller": "0x7ff70a3a1f5b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a67af",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xe6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01 \\x80\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00t\\x00"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\r\\x8a\\x11\\x14\\x02\\x00\\x00R\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\x16\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00|\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a81cf",
            "parentcaller": "0x7ff70a3a69e0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xd1\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6a53",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047085b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xe6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6aa8",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8H\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000280"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000280"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7df10"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000027c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5bfe",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5c19",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5c81",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xde\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5c81",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xde\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5c81",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:22:12,010",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebb5",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xdd\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01 \\x80\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x12I\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x12I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7dcb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "KI\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "KI\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "KI\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "KI\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ebed",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a392f8b",
            "parentcaller": "0x7ff70a39ec7c",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047081b"
              },
              {
                "name": "InBuffer",
                "value": "8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xdc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ecd7",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xdd\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xc5\\xa6@C\\xfa\\x93\\x06G\\x97,{d\\x80\\x08\\xa5\\xa7\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12\\x00\\x00\\x00H\\x00T\\x00R\\x00E\\x00E\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00\\\\x000\\x00\\x00\\x00$\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00KI\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "KI\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7dcb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed0a",
            "parentcaller": "0x7ff70a3a20d9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5d2f",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5d2f",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5dd7",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5dd7",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\x13\\x8c\\x11\\x14\\x02\\x00\\x00\\x12\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:22:12,026",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\x13\\x8c\\x11\\x14\\x02\\x00\\x00\\x12\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00B\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00e\\x00a\\x003\\x009\\x00d\\x002\\x006\\x001\\x005\\x008\\x00c\\x00d\\x00e\\x001\\x00b\\x00e\\x00\\x00\\x00o\\x00g\\x00"
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xc2\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xc6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00_\\x00a\\x00"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0\\x16\\x8a\\x11\\x14\\x02\\x00\\x00R\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x000\\x18\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xc6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xc6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xc6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a56ee",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\xc6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000288"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x86I\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x86I\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d010"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1bJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000024c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d050"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:22:12,042",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "YJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "YJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118cb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118cd000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118cf000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d1000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d5000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00 \\xbb\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a0ab0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002d4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002d4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b5f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118da000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118df000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118e0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118e2000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 14,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118e6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00011000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 7,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 4,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 1,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xec\\x02\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00YJ\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:22:12,057",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YJ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000258"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000258"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c620"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb5J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c620"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002ec"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 1,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 1,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 3,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 1,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 5,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d6000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000c000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118f3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c6000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000b000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118c6000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000b000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d6000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000c000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118f3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:22:12,073",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118f7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00021000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a1290",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000300"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000300"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\xbf\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000300"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000304"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b830"
              },
              {
                "name": "ViewSize",
                "value": "0x00002000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 14,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 7,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 4,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 1,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\x17\\x8a\\x11\\x14\\x02\\x00\\x00R\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0\\x13\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x03\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\r\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x0b\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x88\\x11\\x14\\x02"
              }
            ],
            "repeated": 0,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x0b\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\xc1b\\xa1M\\xb1^@A\\xa4DPd\\xc9\\x81Nv\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00p\\x14\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x0b\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\r\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x15\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x000\\x10\\x8b\\x11\\x14\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000318"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Descriptors"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000318"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Configurations"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000318"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Strings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xec'\\x8f\\x11\\x14\\x02\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:4644:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddress",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtOpenKeyEx"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350f3e0"
              }
            ],
            "repeated": 0,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000032c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000032c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet\\Services"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000033c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000340"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000344"
              },
              {
                "name": "ObjectAttributesName",
                "value": "PnpLockdownFiles"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles"
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000348"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000344"
              },
              {
                "name": "ObjectAttributesName",
                "value": "PnpResources"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpResources"
              }
            ],
            "repeated": 0,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000344"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "ValueName",
                "value": "DisableDecoratedModelsRequirement"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement"
              }
            ],
            "repeated": 0,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 3,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:22:12,088",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 1,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 8,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 3,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 14,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 13,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 9,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 16,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 2,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 1,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 9,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 39,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:22:12,104",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 752
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf7J\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 753
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 754
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c510"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 755
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "kK\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 756
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 757
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 758
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "kK\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 759
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "kK\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 760
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "kK\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 761
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 762
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 763
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 764
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00kK\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 765
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "kK\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 766
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000364"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 767
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000364"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c550"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 768
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 769
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 770
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000364"
              }
            ],
            "repeated": 0,
            "id": 771
          },
          {
            "timestamp": "2026-02-10 09:22:12,120",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 772
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 773
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 774
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 775
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 776
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 1,
            "id": 777
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 778
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 779
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb2K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 780
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 781
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b5f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 782
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 783
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 784
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 785
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 786
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 787
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 788
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 789
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 3,
            "id": 790
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 791
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xa6\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 792
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 793
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 794
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 795
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 796
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1K\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 797
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 798
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 799
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 800
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 801
          },
          {
            "timestamp": "2026-02-10 09:22:12,135",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 802
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 803
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 804
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 805
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 806
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 807
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x001L\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 808
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 809
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 810
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 811
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "qL\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 812
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 813
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 814
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "qL\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 815
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "qL\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 816
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "qL\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 817
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 818
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 819
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00qL\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 820
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "qL\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 821
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 822
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 823
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 824
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 825
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 826
          },
          {
            "timestamp": "2026-02-10 09:22:12,151",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 827
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 828
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 829
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 830
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 831
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 832
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1L\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 833
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 834
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 835
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 836
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 837
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 838
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 839
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 840
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 841
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 842
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 843
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 844
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x16M\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 845
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 846
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 847
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000360"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 848
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 849
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 850
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 851
          },
          {
            "timestamp": "2026-02-10 09:22:12,167",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 852
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 853
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 854
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 855
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 856
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x81M\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 857
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 858
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 859
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 860
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 861
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 862
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 863
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 864
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 865
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000328"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 866
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 867
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 868
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000360"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000328"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet"
              }
            ],
            "repeated": 0,
            "id": 869
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 870
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000360"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Services"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 871
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000328"
              },
              {
                "name": "ObjectAttributesName",
                "value": "vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap"
              }
            ],
            "repeated": 0,
            "id": 872
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 873
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-service-management-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee32a0000"
              }
            ],
            "repeated": 0,
            "id": 874
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee32a0000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-service-management-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 875
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "OpenSCManagerW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32a83e0"
              }
            ],
            "repeated": 0,
            "id": 876
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 877
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "services",
            "api": "OpenSCManagerW",
            "status": true,
            "return": "0x214118b12d0",
            "arguments": [
              {
                "name": "MachineName",
                "value": ""
              },
              {
                "name": "DatabaseName",
                "value": ""
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f003f",
                "pretty_value": "SC_MANAGER_ALL_ACCESS"
              }
            ],
            "repeated": 0,
            "id": 878
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 879
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "CreateServiceW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32e6f10"
              }
            ],
            "repeated": 0,
            "id": 880
          },
          {
            "timestamp": "2026-02-10 09:22:12,182",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 881
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "services",
            "api": "CreateServiceW",
            "status": true,
            "return": "0x214118b1120",
            "arguments": [
              {
                "name": "ServiceControlHandle",
                "value": "0x214118b12d0"
              },
              {
                "name": "ServiceName",
                "value": "vna_ap"
              },
              {
                "name": "DisplayName",
                "value": "@oem1.inf,%VNA_Apollo.Service.DispName%;Check Point Virtual Network Adapter - Apollo"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000007",
                "pretty_value": "SERVICE_QUERY_CONFIG|SERVICE_CHANGE_CONFIG|SERVICE_QUERY_STATUS"
              },
              {
                "name": "ServiceType",
                "value": "1",
                "pretty_value": "SERVICE_KERNEL_DRIVER"
              },
              {
                "name": "StartType",
                "value": "3",
                "pretty_value": "SERVICE_DEMAND_START"
              },
              {
                "name": "ErrorControl",
                "value": "1",
                "pretty_value": "SERVICE_ERROR_NORMAL"
              },
              {
                "name": "BinaryPathName",
                "value": "\\SystemRoot\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "ServiceStartName",
                "value": ""
              },
              {
                "name": "Password",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 882
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 883
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 884
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc4M\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 885
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 886
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b630"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 887
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 888
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 889
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 890
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 891
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 892
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 893
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 894
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 895
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-service-management-l2-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee32a0000"
              }
            ],
            "repeated": 0,
            "id": 896
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee32a0000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-service-management-l2-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 897
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "ChangeServiceConfig2W"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32bc810"
              }
            ],
            "repeated": 0,
            "id": 898
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 899
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 900
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "QueryServiceConfig2W"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32a78d0"
              }
            ],
            "repeated": 0,
            "id": 901
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 902
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000328"
              },
              {
                "name": "ObjectAttributesName",
                "value": "vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap"
              }
            ],
            "repeated": 0,
            "id": 903
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 904
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 905
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1090000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 906
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegQueryValueExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10c3700"
              }
            ],
            "repeated": 0,
            "id": 907
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 908
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Owners"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners"
              }
            ],
            "repeated": 0,
            "id": 909
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 910
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegSetValueExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10c4800"
              }
            ],
            "repeated": 0,
            "id": 911
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 912
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Owners"
              },
              {
                "name": "Type",
                "value": "7",
                "pretty_value": "REG_MULTI_SZ"
              },
              {
                "name": "Buffer",
                "value": "\\x00"
              },
              {
                "name": "BufferLength",
                "value": "20"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners"
              }
            ],
            "repeated": 0,
            "id": 913
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 914
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "EventLog"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 915
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "System"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 916
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000378"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000374"
              },
              {
                "name": "ObjectAttributesName",
                "value": "vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 917
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 918
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 919
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 920
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 921
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000037c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 922
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 923
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "ValueName",
                "value": "EventMessageFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile"
              }
            ],
            "repeated": 0,
            "id": 924
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "ValueName",
                "value": "EventMessageFile"
              },
              {
                "name": "Type",
                "value": "2",
                "pretty_value": "REG_EXPAND_SZ"
              },
              {
                "name": "Buffer",
                "value": "%SystemRoot%\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "BufferLength",
                "value": "80"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile"
              }
            ],
            "repeated": 0,
            "id": 925
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 926
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 927
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 928
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 929
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "ValueName",
                "value": "TypesSupported"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported"
              }
            ],
            "repeated": 0,
            "id": 930
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "ValueName",
                "value": "TypesSupported"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "7"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported"
              }
            ],
            "repeated": 0,
            "id": 931
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 932
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 933
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "CloseServiceHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32a84e0"
              }
            ],
            "repeated": 0,
            "id": 934
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 935
          },
          {
            "timestamp": "2026-02-10 09:22:12,198",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 936
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x10N\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 937
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 938
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 939
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b5f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 940
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 941
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 942
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 943
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 944
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "YN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 945
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "YN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 946
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 947
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 5,
            "id": 948
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 1,
            "id": 949
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 3,
            "id": 950
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 951
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000340"
              },
              {
                "name": "ObjectAttributesName",
                "value": "%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 952
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "ValueName",
                "value": "Owners"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners"
              }
            ],
            "repeated": 0,
            "id": 953
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              },
              {
                "name": "ValueName",
                "value": "Owners"
              },
              {
                "name": "Type",
                "value": "7",
                "pretty_value": "REG_MULTI_SZ"
              },
              {
                "name": "Buffer",
                "value": "\\x00"
              },
              {
                "name": "BufferLength",
                "value": "20"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners"
              }
            ],
            "repeated": 0,
            "id": 954
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 955
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 956
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 957
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00YN\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 958
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "YN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 959
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 960
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000380"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c550"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 961
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 962
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 963
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 964
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 965
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 966
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 967
          },
          {
            "timestamp": "2026-02-10 09:22:12,213",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 968
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000288"
              },
              {
                "name": "ObjectAttributesName",
                "value": "CP_APVNA"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 969
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Configuration"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "VNA_Apollo.ndi"
              },
              {
                "name": "BufferLength",
                "value": "30"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration"
              }
            ],
            "repeated": 0,
            "id": 970
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Manufacturer"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "%cp%"
              },
              {
                "name": "BufferLength",
                "value": "10"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Manufacturer"
              }
            ],
            "repeated": 0,
            "id": 971
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 972
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Description"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "%vna.devicedesc.apollo%"
              },
              {
                "name": "BufferLength",
                "value": "48"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Description"
              }
            ],
            "repeated": 0,
            "id": 973
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 974
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 975
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 976
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 977
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 978
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 979
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9aN\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 980
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000374"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 981
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000374"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c3d0"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 982
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 983
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 984
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 985
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 986
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 987
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 988
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 989
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f003f",
                "pretty_value": "KEY_ALL_ACCESS"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000254"
              },
              {
                "name": "ObjectAttributesName",
                "value": "VNA_Apollo.ndi"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi"
              }
            ],
            "repeated": 0,
            "id": 990
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000254"
              },
              {
                "name": "ObjectAttributesName",
                "value": "VNA_Apollo.ndi"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 991
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "Service"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "vna_ap"
              },
              {
                "name": "BufferLength",
                "value": "14"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service"
              }
            ],
            "repeated": 0,
            "id": 992
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 993
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 994
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf4N\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 995
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 996
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000384"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c410"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 997
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "9O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 998
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 999
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1000
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "9O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1001
          },
          {
            "timestamp": "2026-02-10 09:22:12,229",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "9O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1002
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "9O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1003
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 1004
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1005
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1006
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1007
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 1008
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 1009
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "ConfigScope"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "5"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigScope"
              }
            ],
            "repeated": 0,
            "id": 1010
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1011
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Driver"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1012
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Device"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Device"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1013
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000378"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Services"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1014
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1015
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1016
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              },
              {
                "name": "ValueName",
                "value": "BusNumber"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber"
              }
            ],
            "repeated": 0,
            "id": 1017
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              },
              {
                "name": "ValueName",
                "value": "BusNumber"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "0"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber"
              }
            ],
            "repeated": 0,
            "id": 1018
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1019
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Ndi\\Interfaces"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1020
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004",
                "pretty_value": "KEY_CREATE_SUB_KEY"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Ndi"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1021
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000384"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Interfaces"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1022
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1023
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "UpperRange"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "ndis5"
              },
              {
                "name": "BufferLength",
                "value": "12"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\UpperRange"
              }
            ],
            "repeated": 0,
            "id": 1024
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1025
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Ndi\\Interfaces"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1026
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "LowerRange"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange"
              }
            ],
            "repeated": 0,
            "id": 1027
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "LowerRange"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "ethernet"
              },
              {
                "name": "BufferLength",
                "value": "18"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange"
              }
            ],
            "repeated": 0,
            "id": 1028
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1029
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1030
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "OwnerProduct"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct"
              }
            ],
            "repeated": 0,
            "id": 1031
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "OwnerProduct"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "Apollo"
              },
              {
                "name": "BufferLength",
                "value": "14"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct"
              }
            ],
            "repeated": 0,
            "id": 1032
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1033
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Ndi"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1034
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "Service"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service"
              }
            ],
            "repeated": 0,
            "id": 1035
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "Service"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "vna_ap"
              },
              {
                "name": "BufferLength",
                "value": "14"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service"
              }
            ],
            "repeated": 0,
            "id": 1036
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1037
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1038
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*IfType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType"
              }
            ],
            "repeated": 0,
            "id": 1039
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*IfType"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "6"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType"
              }
            ],
            "repeated": 0,
            "id": 1040
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1041
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1042
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*MediaType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType"
              }
            ],
            "repeated": 0,
            "id": 1043
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*MediaType"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "0"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType"
              }
            ],
            "repeated": 0,
            "id": 1044
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1045
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1046
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*PhysicalMediaType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType"
              }
            ],
            "repeated": 0,
            "id": 1047
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "*PhysicalMediaType"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "14"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType"
              }
            ],
            "repeated": 0,
            "id": 1048
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1049
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000380"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1050
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "Characteristics"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics"
              }
            ],
            "repeated": 0,
            "id": 1051
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              },
              {
                "name": "ValueName",
                "value": "Characteristics"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "1"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics"
              }
            ],
            "repeated": 0,
            "id": 1052
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1053
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 1054
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000378"
              },
              {
                "name": "ObjectAttributesName",
                "value": "vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1055
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 1056
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000384"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1057
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1058
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "ValueName",
                "value": "EventMessageFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile"
              }
            ],
            "repeated": 0,
            "id": 1059
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "ValueName",
                "value": "EventMessageFile"
              },
              {
                "name": "Type",
                "value": "2",
                "pretty_value": "REG_EXPAND_SZ"
              },
              {
                "name": "Buffer",
                "value": "%SystemRoot%\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "BufferLength",
                "value": "80"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile"
              }
            ],
            "repeated": 0,
            "id": 1060
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1061
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 1062
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000038c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1063
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1064
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              },
              {
                "name": "ValueName",
                "value": "TypesSupported"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported"
              }
            ],
            "repeated": 0,
            "id": 1065
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              },
              {
                "name": "ValueName",
                "value": "TypesSupported"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "7"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported"
              }
            ],
            "repeated": 0,
            "id": 1066
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1067
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1068
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegQueryInfoKeyW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10c1550"
              }
            ],
            "repeated": 0,
            "id": 1069
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1070
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1071
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1072
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000378"
              },
              {
                "name": "ObjectAttributesName",
                "value": "vna_ap"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services\\vna_ap"
              }
            ],
            "repeated": 0,
            "id": 1073
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              }
            ],
            "repeated": 1,
            "id": 1074
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Interfaces"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Interfaces"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1075
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1076
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Filters"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Filters"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1077
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1078
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Devices"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Devices"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "1",
                "pretty_value": "REG_CREATED_NEW_KEY"
              }
            ],
            "repeated": 0,
            "id": 1079
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000390"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Devices"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Devices"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1080
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 1,
            "id": 1081
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "ValueName",
                "value": "ConfigFlags"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "0"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags"
              }
            ],
            "repeated": 0,
            "id": 1082
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1083
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x009O\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1084
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "9O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1085
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000398"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1086
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000398"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c410"
              },
              {
                "name": "ViewSize",
                "value": "0x00005000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1087
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1088
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1089
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 1090
          },
          {
            "timestamp": "2026-02-10 09:22:12,245",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1091
          },
          {
            "timestamp": "2026-02-10 09:22:12,260",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1092
          },
          {
            "timestamp": "2026-02-10 09:22:12,260",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000394"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1093
          },
          {
            "timestamp": "2026-02-10 09:22:12,260",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000394"
              }
            ],
            "repeated": 0,
            "id": 1094
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "6"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1095
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 1096
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1097
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 1098
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Device"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Device"
              }
            ],
            "repeated": 0,
            "id": 1099
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              }
            ],
            "repeated": 1,
            "id": 1100
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000378"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1101
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 1102
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000378"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Services"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services"
              }
            ],
            "repeated": 0,
            "id": 1103
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000378"
              }
            ],
            "repeated": 1,
            "id": 1104
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1105
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 1106
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Filters"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Filters"
              }
            ],
            "repeated": 0,
            "id": 1107
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000384"
              }
            ],
            "repeated": 1,
            "id": 1108
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1109
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1110
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Interfaces"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Interfaces"
              }
            ],
            "repeated": 0,
            "id": 1111
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000388"
              }
            ],
            "repeated": 1,
            "id": 1112
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1113
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1114
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00010000",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000358"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Devices"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Devices"
              }
            ],
            "repeated": 0,
            "id": 1115
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtDeleteKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 1,
            "id": 1116
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": false,
            "return": "0x000003fa",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000390"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1117
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1118
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 1119
          },
          {
            "timestamp": "2026-02-10 09:22:12,323",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1120
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x82O\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1121
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x82O\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1122
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1123
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c3d0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1124
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1125
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1126
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1127
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1128
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1129
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000358"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1130
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 1131
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 1132
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1133
          },
          {
            "timestamp": "2026-02-10 09:22:12,338",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1134
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xdeO\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1135
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1136
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000358"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7c510"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1137
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'P\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1138
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1139
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 1140
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'P\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1141
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "'P\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1142
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000037c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "'P\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1143
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 1144
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 1145
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "ValueName",
                "value": "vna.devicedesc.apollo"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "Check Point Virtual Network Adapter For Endpoint VPN Client"
              },
              {
                "name": "BufferLength",
                "value": "120"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\vna.devicedesc.apollo"
              }
            ],
            "repeated": 0,
            "id": 1146
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 4,
            "id": 1147
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "ValueName",
                "value": "cp"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Buffer",
                "value": "Check Point"
              },
              {
                "name": "BufferLength",
                "value": "24"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\cp"
              }
            ],
            "repeated": 0,
            "id": 1148
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1149
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1150
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1151
          },
          {
            "timestamp": "2026-02-10 09:22:12,354",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00'P\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1152
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'P\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1153
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1154
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7cc70"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1155
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1156
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "lP\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1157
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1158
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 1159
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "lP\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1160
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "lP\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1161
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "lP\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1162
          },
          {
            "timestamp": "2026-02-10 09:22:12,370",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1163
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 4,
            "id": 1164
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a13b0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1165
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1166
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 1,
            "id": 1167
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1168
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\"
              }
            ],
            "repeated": 0,
            "id": 1169
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a1530",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xf1b77700"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8ab22"
              }
            ],
            "repeated": 0,
            "id": 1170
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1171
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 1,
            "id": 1172
          },
          {
            "timestamp": "2026-02-10 09:22:12,385",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\cabinet"
              },
              {
                "name": "DllBase",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 1173
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "cabinet.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 1174
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffed9750000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "cabinet.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1175
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICreate"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9758d10"
              }
            ],
            "repeated": 0,
            "id": 1176
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1177
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1178
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1179
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\"
              }
            ],
            "repeated": 0,
            "id": 1180
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a1710",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x3a6eea36"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d5acdd"
              }
            ],
            "repeated": 0,
            "id": 1181
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1182
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a11d0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x89276d36"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d5acde"
              }
            ],
            "repeated": 0,
            "id": 1183
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1184
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x214118a1470",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbc71941d"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 1185
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1186
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICopy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9755f00"
              }
            ],
            "repeated": 0,
            "id": 1187
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 1188
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1189
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 1190
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1191
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "Buffer",
                "value": "MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 1192
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1193
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1194
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1195
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x01\\x00\\x00\\x00\\x00\\x00\\xb0)\\x01\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1196
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1197
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b3f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00013000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1198
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00013000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1199
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1200
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1201
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1202
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 1,
            "id": 1203
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1204
          },
          {
            "timestamp": "2026-02-10 09:22:12,401",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00lP\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1205
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "lP\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1206
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1207
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7b2e0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1208
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ")Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1209
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1210
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1211
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ")Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1212
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": ")Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1213
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": ")Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1214
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1215
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1216
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 1217
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1218
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "FindFirstFileNameW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1684f40"
              }
            ],
            "repeated": 0,
            "id": 1219
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100080",
                "pretty_value": "FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1220
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "24"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x05\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              }
            ],
            "repeated": 0,
            "id": 1221
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x2141246c4e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1222
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000340"
              },
              {
                "name": "ObjectAttributesName",
                "value": "%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1223
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "ValueName",
                "value": "Class"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class"
              }
            ],
            "repeated": 0,
            "id": 1224
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1225
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x2e007000610061"
              },
              {
                "name": "DesiredAccess",
                "value": "0x81100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE|ACCESS_SYSTEM_SECURITY"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1226
          },
          {
            "timestamp": "2026-02-10 09:22:12,417",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x1f800010000f"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00110080",
                "pretty_value": "FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1227
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000390"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1228
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000390"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00Z\\x91\\x11\\x14\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00R\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00d\\x00r\\x00i\\x00v\\x00e\\x00r\\x00s\\x00\\\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00s\\x00y\\x00s\\x00D\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 1229
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1230
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 2,
            "id": 1231
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000390"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000340"
              },
              {
                "name": "ObjectAttributesName",
                "value": "%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys"
              }
            ],
            "repeated": 0,
            "id": 1232
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              },
              {
                "name": "ValueName",
                "value": "Class"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class"
              }
            ],
            "repeated": 0,
            "id": 1233
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1234
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "NtCreateKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000390"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020006",
                "pretty_value": "KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000340"
              },
              {
                "name": "ObjectAttributesName",
                "value": "%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1235
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              },
              {
                "name": "ValueName",
                "value": "Class"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Buffer",
                "value": "4"
              },
              {
                "name": "BufferLength",
                "value": "4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class"
              }
            ],
            "repeated": 0,
            "id": 1236
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1237
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegDeleteValueW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10f42a0"
              }
            ],
            "repeated": 0,
            "id": 1238
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1239
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegDeleteValueW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              },
              {
                "name": "ValueName",
                "value": "Security"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Security"
              }
            ],
            "repeated": 0,
            "id": 1240
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "registry",
            "api": "RegSetValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              },
              {
                "name": "ValueName",
                "value": "Source"
              },
              {
                "name": "Type",
                "value": "2",
                "pretty_value": "REG_EXPAND_SZ"
              },
              {
                "name": "Buffer",
                "value": "%SystemRoot%\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
              },
              {
                "name": "BufferLength",
                "value": "184"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Source"
              }
            ],
            "repeated": 0,
            "id": 1241
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000390"
              }
            ],
            "repeated": 0,
            "id": 1242
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1243
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-security-sddl-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee32a0000"
              }
            ],
            "repeated": 0,
            "id": 1244
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee32a0000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-security-sddl-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1245
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "sechost.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee32a0000"
              },
              {
                "name": "FunctionName",
                "value": "ConvertStringSecurityDescriptorToSecurityDescriptorW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee32b10b0"
              }
            ],
            "repeated": 0,
            "id": 1246
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1247
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1248
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1249
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-security-base-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 1250
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1090000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-security-base-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1251
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "GetSecurityDescriptorOwner"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1110d70"
              }
            ],
            "repeated": 0,
            "id": 1252
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1253
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1254
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "GetSecurityDescriptorGroup"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee11110c0"
              }
            ],
            "repeated": 0,
            "id": 1255
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1256
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1257
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "GetSecurityDescriptorControl"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10f79b0"
              }
            ],
            "repeated": 0,
            "id": 1258
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1259
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1260
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "GetSecurityDescriptorDacl"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10fea20"
              }
            ],
            "repeated": 0,
            "id": 1261
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1262
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020002"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1263
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1264
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "GetKernelObjectSecurity"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10c67c0"
              }
            ],
            "repeated": 0,
            "id": 1265
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1266
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1267
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "DuplicateTokenEx"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10ffd90"
              }
            ],
            "repeated": 0,
            "id": 1268
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1269
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1270
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "AdjustTokenPrivileges"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1109660"
              }
            ],
            "repeated": 0,
            "id": 1271
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1272
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000388"
              }
            ],
            "repeated": 0,
            "id": 1273
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1274
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x001c0080",
                "pretty_value": "FILE_READ_ATTRIBUTES|WRITE_DAC|WRITE_OWNER|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drivers\\vnaap.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1275
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1276
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "SetKernelObjectSecurity"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee11105a0"
              }
            ],
            "repeated": 0,
            "id": 1277
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1278
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1279
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1280
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00)Q\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1281
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ")Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1282
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1283
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003a0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7cc70"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1284
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1285
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1286
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1287
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1288
          },
          {
            "timestamp": "2026-02-10 09:22:12,432",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1289
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1290
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1291
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1292
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xa0\\x0f\\x8b\\x11\\x14\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x12\\x8b\\x11\\x14\\x02\\x00\\x00 \\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1293
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\x11\\x8a\\x11\\x14\\x02\\x00\\x00T\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00%\\x02\\x00\\xc0"
              }
            ],
            "repeated": 0,
            "id": 1294
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1295
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0%\\x8f\\x11\\x14\\x02\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xd2\\xb7\\xfa2\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1296
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1297
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1298
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1299
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1300
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d050"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1301
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1302
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1303
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1304
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1305
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1306
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1307
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1308
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 1309
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 1310
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1311
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 1312
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1313
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 1314
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1315
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1316
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000033c"
              }
            ],
            "repeated": 0,
            "id": 1317
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1318
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ec"
              }
            ],
            "repeated": 0,
            "id": 1319
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1320
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 1321
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 1322
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 1323
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 1324
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 1325
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 1326
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000358"
              }
            ],
            "repeated": 0,
            "id": 1327
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000037c"
              }
            ],
            "repeated": 0,
            "id": 1328
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1329
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000318"
              }
            ],
            "repeated": 0,
            "id": 1330
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1331
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1332
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 1333
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 1334
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 1335
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 1336
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1337
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 1338
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 1339
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 1340
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 1341
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 1342
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 1343
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 1344
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 1345
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000350"
              }
            ],
            "repeated": 0,
            "id": 1346
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1347
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 1348
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 1349
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 1350
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 1351
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 1352
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1353
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 1354
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 1355
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 1356
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 1357
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1358
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1359
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 1360
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1361
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1362
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1363
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1364
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1365
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1366
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1367
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 1368
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1369
          },
          {
            "timestamp": "2026-02-10 09:22:12,448",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1370
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1371
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe4Q\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1372
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1373
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000035c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d010"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1374
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1375
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1376
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1377
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1378
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "0R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1379
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "0R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1380
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58b0",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1381
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1382
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x000R\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1383
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "0R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1384
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1385
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d5a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1386
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x83R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1387
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1388
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1389
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x83R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1390
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x83R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1391
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x83R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1392
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a58f6",
            "parentcaller": "0x7ff70a3a59c1",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1393
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a83ed",
            "parentcaller": "0x7ff70a3a84b0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1394
          },
          {
            "timestamp": "2026-02-10 09:22:12,463",
            "thread_id": "1824",
            "caller": "0x7ff70a3a83ed",
            "parentcaller": "0x7ff70a3a84b0",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00e\\x00g\\x00"
              }
            ],
            "repeated": 0,
            "id": 1395
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8360",
            "parentcaller": "0x7ff70a3a83ed",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be"
              }
            ],
            "repeated": 0,
            "id": 1396
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8336",
            "parentcaller": "0x7ff70a3a83ed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00 \\xb2\\xb7\\xfa2\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1397
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8360",
            "parentcaller": "0x7ff70a3a83ed",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be"
              },
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be"
              }
            ],
            "repeated": 0,
            "id": 1398
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8526",
            "parentcaller": "0x7ff70a3a8c8e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a0"
              },
              {
                "name": "SubKey",
                "value": "Descriptors\\cp_apvna"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\cp_apvna"
              }
            ],
            "repeated": 0,
            "id": 1399
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8573",
            "parentcaller": "0x7ff70a3a8c8e",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "ValueName",
                "value": "Configuration"
              },
              {
                "name": "Data",
                "value": "VNA_Apollo.ndi"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration"
              }
            ],
            "repeated": 0,
            "id": 1400
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8623",
            "parentcaller": "0x7ff70a3a8c8e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a0"
              },
              {
                "name": "SubKey",
                "value": "Configurations\\VNA_Apollo.ndi"
              },
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi"
              }
            ],
            "repeated": 0,
            "id": 1401
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8649",
            "parentcaller": "0x7ff70a3a8c8e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1402
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a865d",
            "parentcaller": "0x7ff70a3a8c8e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1403
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a394bf1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "IncludedConfigs"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\IncludedConfigs"
              }
            ],
            "repeated": 0,
            "id": 1404
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a8d64",
            "parentcaller": "0x7ff70a3a59d6",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "Reboot"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Reboot"
              }
            ],
            "repeated": 0,
            "id": 1405
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5f31",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00qI\\x80s\\x8c\\xb9H\\xaa\\xd9\\xce8~\\x19\\xc5n\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1406
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a5f31",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1407
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a392f8b",
            "parentcaller": "0x7ff70a3a5f9f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047081b"
              },
              {
                "name": "InBuffer",
                "value": "8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1408
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6009",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xde\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x0b\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00\\xa0E\\x8c\\x11\\x14\\x02\\x00\\x00D\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1409
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6009",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1410
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1411
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x83R\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1412
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x83R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1413
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1414
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7df10"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1415
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1416
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1417
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1418
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1419
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1420
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1421
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1422
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a60a3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1423
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1424
          },
          {
            "timestamp": "2026-02-10 09:22:12,479",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1425
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3R\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1426
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1427
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7df10"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1428
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1429
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1430
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1431
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1432
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "'S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1433
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "'S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1434
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6101",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1435
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6136",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020002"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1436
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6136",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1437
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6136",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1438
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6136",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047084f"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1439
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a62ac",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1440
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a62ac",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1441
          },
          {
            "timestamp": "2026-02-10 09:22:12,495",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1442
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00'S\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1443
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "'S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1444
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1445
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7df10"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1446
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1447
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1448
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1449
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1450
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1451
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1452
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1453
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6316",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1454
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a392f8b",
            "parentcaller": "0x7ff70a3a6360",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047081b"
              },
              {
                "name": "InBuffer",
                "value": "8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1455
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a393008",
            "parentcaller": "0x7ff70a3a637e",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047081f"
              },
              {
                "name": "InBuffer",
                "value": "8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00x\\xe1\\xb7\\xfa2\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1456
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a4fb6",
            "parentcaller": "0x7ff70a3a6400",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "ConfigFlags"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags"
              }
            ],
            "repeated": 0,
            "id": 1457
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a394bf1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffff80000005",
            "pretty_return": "BUFFER_OVERFLOW",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "Service"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service"
              }
            ],
            "repeated": 0,
            "id": 1458
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a394c51",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "Service"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "vna_ap"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service"
              }
            ],
            "repeated": 0,
            "id": 1459
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a394bf1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "LowerFilters"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\LowerFilters"
              }
            ],
            "repeated": 0,
            "id": 1460
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a394bf1",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ac"
              },
              {
                "name": "ValueName",
                "value": "UpperFilters"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\UpperFilters"
              }
            ],
            "repeated": 0,
            "id": 1461
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee08a0000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1462
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee08a0000"
              },
              {
                "name": "ModuleName",
                "value": "DEVOBJ.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1463
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1464
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xdd\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01 \\x80\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1465
          },
          {
            "timestamp": "2026-02-10 09:22:12,510",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1466
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x81S\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1467
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x81S\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1468
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1469
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7dca0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1470
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1471
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1472
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 1473
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1474
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1475
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1476
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1477
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1478
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1479
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbaS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1480
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1481
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1482
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1483
          },
          {
            "timestamp": "2026-02-10 09:22:12,526",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1484
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1485
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 1486
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1487
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1488
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000038c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1489
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1490
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00_\\x00a\\x00p\\x00\\x00\\x00{Res"
              }
            ],
            "repeated": 0,
            "id": 1491
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x17\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1492
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x16\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1493
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "\\x10\\xd7\\x08\\x00\\x00\\x00\\x00\\x00\\xe7\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xebL\\xb6&u \\x06\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x88\\x0e\\x00\\x00\\x10\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x9b\\xa0\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1494
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\x13\\x8a\\x11\\x14\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1495
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\xd0\\xb7\\xfa2\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x14\\x02\\x00\\x00\\x02\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x13\\x8a\\x11\\x14\\x02\\x00\\x00\\x00`:\n\\xf7\\x7f\\x00\\x00\\x00\\x009\n\\xf7\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00 \\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1496
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1497
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000038c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Control Panel\\International"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International"
              }
            ],
            "repeated": 0,
            "id": 1498
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 1499
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "LocaleName"
              },
              {
                "name": "ValueBuffer",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\LocaleName"
              }
            ],
            "repeated": 0,
            "id": 1500
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sList"
              },
              {
                "name": "ValueBuffer",
                "value": ";"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sList"
              }
            ],
            "repeated": 0,
            "id": 1501
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sDecimal"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sDecimal"
              }
            ],
            "repeated": 0,
            "id": 1502
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sThousand"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sThousand"
              }
            ],
            "repeated": 0,
            "id": 1503
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sGrouping"
              }
            ],
            "repeated": 0,
            "id": 1504
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sNativeDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "0123456789"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNativeDigits"
              }
            ],
            "repeated": 0,
            "id": 1505
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sMonDecimalSep"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonDecimalSep"
              }
            ],
            "repeated": 0,
            "id": 1506
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sMonThousandSep"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonThousandSep"
              }
            ],
            "repeated": 0,
            "id": 1507
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sMonGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonGrouping"
              }
            ],
            "repeated": 0,
            "id": 1508
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sPositiveSign"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sPositiveSign"
              }
            ],
            "repeated": 0,
            "id": 1509
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sNegativeSign"
              },
              {
                "name": "ValueBuffer",
                "value": "-"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNegativeSign"
              }
            ],
            "repeated": 0,
            "id": 1510
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sTimeFormat"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm:ss"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sTimeFormat"
              }
            ],
            "repeated": 0,
            "id": 1511
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sShortTime"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortTime"
              }
            ],
            "repeated": 0,
            "id": 1512
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "s1159"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s1159"
              }
            ],
            "repeated": 0,
            "id": 1513
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "s2359"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s2359"
              }
            ],
            "repeated": 0,
            "id": 1514
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sShortDate"
              },
              {
                "name": "ValueBuffer",
                "value": "dd.MM.yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortDate"
              }
            ],
            "repeated": 0,
            "id": 1515
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sYearMonth"
              },
              {
                "name": "ValueBuffer",
                "value": "MMMM yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sYearMonth"
              }
            ],
            "repeated": 0,
            "id": 1516
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sLongDate"
              },
              {
                "name": "ValueBuffer",
                "value": "d MMMM yyyy '\\x433.'"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sLongDate"
              }
            ],
            "repeated": 0,
            "id": 1517
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iCountry"
              },
              {
                "name": "ValueBuffer",
                "value": "7"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCountry"
              }
            ],
            "repeated": 0,
            "id": 1518
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iMeasure"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iMeasure"
              }
            ],
            "repeated": 0,
            "id": 1519
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iPaperSize"
              },
              {
                "name": "ValueBuffer",
                "value": "9"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iPaperSize"
              }
            ],
            "repeated": 0,
            "id": 1520
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iDigits"
              }
            ],
            "repeated": 0,
            "id": 1521
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iLZero"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iLZero"
              }
            ],
            "repeated": 0,
            "id": 1522
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iNegNumber"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegNumber"
              }
            ],
            "repeated": 0,
            "id": 1523
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "NumShape"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\NumShape"
              }
            ],
            "repeated": 0,
            "id": 1524
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iCurrDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrDigits"
              }
            ],
            "repeated": 0,
            "id": 1525
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iCurrency"
              },
              {
                "name": "ValueBuffer",
                "value": "3"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrency"
              }
            ],
            "repeated": 0,
            "id": 1526
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iNegCurr"
              },
              {
                "name": "ValueBuffer",
                "value": "8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegCurr"
              }
            ],
            "repeated": 0,
            "id": 1527
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iFirstDayOfWeek"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstDayOfWeek"
              }
            ],
            "repeated": 0,
            "id": 1528
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iFirstWeekOfYear"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstWeekOfYear"
              }
            ],
            "repeated": 0,
            "id": 1529
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "sCurrency"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x20bd"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency"
              }
            ],
            "repeated": 0,
            "id": 1530
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "iCalendarType"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType"
              }
            ],
            "repeated": 0,
            "id": 1531
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002f8"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              }
            ],
            "repeated": 0,
            "id": 1532
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000248"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 1533
          },
          {
            "timestamp": "2026-02-10 09:22:12,542",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000248"
              },
              {
                "name": "ValueName",
                "value": "ru"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru"
              }
            ],
            "repeated": 0,
            "id": 1534
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470803"
              },
              {
                "name": "InBuffer",
                "value": "\\x18\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\xe0]\\x91\\x11\\x14\\x02\\x00\\x00\\x0e\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x00\\x00\\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00N\\x00E\\x00T\\x00\\\\x000\\x000\\x000\\x000\\x00\\x00\\x00\\x00\\x007\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 1535
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xd5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1536
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xd5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01 \\x80\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1537
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000003a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "FILE_READ_ACCESS"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\Driver"
              }
            ],
            "repeated": 0,
            "id": 1538
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryDirectoryObject",
            "status": true,
            "return": "0x00000105",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 4,
            "id": 1539
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1540
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryDirectoryObject",
            "status": false,
            "return": "0xffffffff8000001a",
            "pretty_return": "NO_MORE_ENTRIES",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1541
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1542
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x13\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00%\\x02\\x00\\xc0"
              }
            ],
            "repeated": 0,
            "id": 1543
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1544
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1545
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfbS\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1546
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1547
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1548
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1549
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1550
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 1551
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1552
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "4T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1553
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "4T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1554
          },
          {
            "timestamp": "2026-02-10 09:22:12,557",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 1555
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020002"
              },
              {
                "name": "TokenHandle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1556
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1557
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1558
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047084f"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1559
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01$\\x80\\x018\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1560
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xd3\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xc5\\xa6@C\\xfa\\x93\\x06G\\x97,{d\\x80\\x08\\xa5\\xa7\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1561
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xd6\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1562
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xd4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01$\\x80\\x018\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1563
          },
          {
            "timestamp": "2026-02-10 09:22:12,604",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xd3\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xc5\\xa6@C\\xfa\\x93\\x06G\\x97,{d\\x80\\x08\\xa5\\xa7\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1564
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1565
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x004T\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1566
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "4T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1567
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1568
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d370"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1569
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1570
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1571
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              }
            ],
            "repeated": 0,
            "id": 1572
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1573
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1574
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1575
          },
          {
            "timestamp": "2026-02-10 09:22:12,620",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 1576
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1577
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1578
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd0T\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1579
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1580
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7d5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1581
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1582
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16U\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1583
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1584
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1585
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16U\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1586
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16U\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1587
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16U\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1588
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 1589
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020002"
              },
              {
                "name": "TokenHandle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 1590
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1591
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 1592
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047085b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x11\\x02\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xdf\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1593
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6484",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1594
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a61b3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xde\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xdde\\xb8\\xa8=.\\x94@\\xad\\x97\\xe5\\x93\\xa7\\x0cu\\xd6\\x17\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb4\\xe1\\xb7\\xfa2\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1595
          },
          {
            "timestamp": "2026-02-10 09:22:12,635",
            "thread_id": "1824",
            "caller": "0x7ff70a3a61b3",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1596
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1597
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x16U\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1598
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x16U\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1599
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1600
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003b0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7df10"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1601
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1602
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1603
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1604
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 1605
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1606
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "cU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1607
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "cU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1608
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a623b",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 1609
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6250",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1610
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6250",
            "parentcaller": "0x7ff70a3a6ae5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1611
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6afa",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1612
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6b5c",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xe5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1613
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6b5c",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xe5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 1614
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a6b5c",
            "parentcaller": "0x7ff70a3a76ce",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1615
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 1616
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1617
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 1618
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1619
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 1620
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1621
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1622
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00a\\x00m\\x00"
              }
            ],
            "repeated": 0,
            "id": 1623
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a017d",
            "parentcaller": "0x7ff70a3a2137",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 1,
            "id": 1624
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a024a",
            "parentcaller": "0x7ff70a3a2137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xb9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\xc1b\\xa1M\\xb1^@A\\xa4DPd\\xc9\\x81Nv\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00^\\x00\\x00\\x00\\x12\\x00\\x00\\x003\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x003\\x002\\x005\\x006\\x001\\x005\\x004\\x003\\x008\\x008\\x003\\x000\\x009\\x005\\x009\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x001\\x000\\x000\\x005\\x006\\x001\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1625
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a02ab",
            "parentcaller": "0x7ff70a3a2137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xb9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1626
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39eebb",
            "parentcaller": "0x7ff70a3a02cd",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xb9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\xc1b\\xa1M\\xb1^@A\\xa4DPd\\xc9\\x81Nv\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1627
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a036b",
            "parentcaller": "0x7ff70a3a2137",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\xb9\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1628
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a039c",
            "parentcaller": "0x7ff70a3a2137",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 1629
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a039c",
            "parentcaller": "0x7ff70a3a2137",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 1630
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3b116b",
            "parentcaller": "0x7ff70a39f1dc",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1631
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f259",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xc5\\xa6@C\\xfa\\x93\\x06G\\x97,{d\\x80\\x08\\xa5\\xa7\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12\\x00\\x00\\x00H\\x00T\\x00R\\x00E\\x00E\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00\\\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1632
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f2a3",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00l\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 1633
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f31f",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1634
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f3cd",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)d\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x10\\x00\\x00\\x00}v)\\xbdn\\x9a\\xdc\\x01w\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 1635
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f032",
            "parentcaller": "0x7ff70a39f3f7",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xdde\\xb8\\xa8=.\\x94@\\xad\\x97\\xe5\\x93\\xa7\\x0cu\\xd6\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0x\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1636
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f097",
            "parentcaller": "0x7ff70a39f3f7",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xdde\\xb8\\xa8=.\\x94@\\xad\\x97\\xe5\\x93\\xa7\\x0cu\\xd6\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00x\\x00\\x00\\x00\\x12\\x00\\x00\\x00C\\x00h\\x00e\\x00c\\x00k\\x00 \\x00P\\x00o\\x00i\\x00n\\x00t\\x00 \\x00V\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00 \\x00N\\x00e\\x00t\\x00w\\x00o\\x00r\\x00k\\x00 \\x00A\\x00d\\x00a\\x00p\\x00t\\x00e\\x00r\\x00 \\x00F\\x00o\\x00r\\x00 \\x00E\\x00n\\x00d\\x00p\\x00o\\x00i\\x00n\\x00t\\x00 \\x00V\\x00P\\x00N\\x00 \\x00C\\x00l\\x00i\\x00e\\x00n\\x00t\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1637
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f443",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x00000244"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0\\x9d\\xb7\\xfa2\\x00\\x00\\x00B\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1638
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f032",
            "parentcaller": "0x7ff70a39f4bd",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xdde\\xb8\\xa8=.\\x94@\\xad\\x97\\xe5\\x93\\xa7\\x0cu\\xd6\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1639
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f4f7",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x12\\x00\\x00\\x00v\\x00n\\x00a\\x00_\\x00a\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1640
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f032",
            "parentcaller": "0x7ff70a39f526",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x16\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1641
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f032",
            "parentcaller": "0x7ff70a39f53b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00&c\\xda\\x83\\xa6\\x97\\x88@\\x94S\\xa1\\x92?W;)\\x17\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1642
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed76",
            "parentcaller": "0x7ff70a39f55e",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbd\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1643
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39ed76",
            "parentcaller": "0x7ff70a39f571",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbd\\xb7\\xfa2\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x15\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1644
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f032",
            "parentcaller": "0x7ff70a39f58a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0(\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1645
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f097",
            "parentcaller": "0x7ff70a39f58a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\x00\\x00\\x00\\x12 \\x00\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00\\\\x00P\\x00n\\x00p\\x00M\\x00a\\x00n\\x00a\\x00g\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00d\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 1646
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f5bf",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1647
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f607",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1648
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f658",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x13\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1649
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a392f8b",
            "parentcaller": "0x7ff70a39f683",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047081b"
              },
              {
                "name": "InBuffer",
                "value": "8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1650
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f6a1",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01$\\x80\\x018\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1651
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a39f6f5",
            "parentcaller": "0x7ff70a3a073a",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xbc\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\xc5\\xa6@C\\xfa\\x93\\x06G\\x97,{d\\x80\\x08\\xa5\\xa7\\x0c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1652
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a0744",
            "parentcaller": "0x7ff70a3a2137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1653
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a0744",
            "parentcaller": "0x7ff70a3a2137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1654
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7d72",
            "parentcaller": "0x7ff70a3a68a3",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1655
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7405",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 1,
            "id": 1656
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3992a6",
            "parentcaller": "0x7ff70a3a7455",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1657
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7487",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 1658
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1659
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00cU\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1660
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "cU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1661
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1662
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7e770"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1663
          },
          {
            "timestamp": "2026-02-10 09:22:12,651",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1664
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1665
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1666
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1667
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1668
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1669
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003ac"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1670
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a74dd",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1671
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1f85",
            "parentcaller": "0x7ff70a3a74ef",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1672
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1f98",
            "parentcaller": "0x7ff70a3a74ef",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1673
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7521",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 1,
            "id": 1674
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1202",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1675
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a125b",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xe4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1676
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a125b",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xe4\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00r\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 1677
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a125b",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1678
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a12bc",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xe5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1679
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a12bc",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1680
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1326",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xe5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1681
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1326",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ac"
              }
            ],
            "repeated": 0,
            "id": 1682
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca314",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1683
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca314",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1684
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\DevQuery"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\DevQuery"
              }
            ],
            "repeated": 0,
            "id": 1685
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "11"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "2"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1686
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1687
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1688
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1689
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1690
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1691
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1692
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1693
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1694
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1695
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1696
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1697
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1698
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1699
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1700
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1701
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1702
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1703
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1704
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1705
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1706
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1707
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1708
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1709
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1710
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1711
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1712
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1713
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1714
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1715
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1716
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "1"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1"
              }
            ],
            "repeated": 0,
            "id": 1717
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1718
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1719
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "10"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1720
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1721
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1722
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1723
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1724
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1725
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1726
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1727
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1728
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1729
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1730
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1731
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1732
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1733
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1734
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "LRPC"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1735
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1736
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1737
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1738
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1739
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1740
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1741
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "10"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10"
              }
            ],
            "repeated": 0,
            "id": 1742
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "Data",
                "value": "289e5e0f-414a-4de9-8d17-244507fffc07"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1743
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1744
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "11"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1745
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1746
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1747
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1748
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 1749
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1750
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1751
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1752
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1753
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1754
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1755
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1756
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1757
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1758
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1759
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1760
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1761
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1762
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1763
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1764
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1765
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1766
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1767
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1768
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1769
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1770
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1771
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1772
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1773
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1774
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "11"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11"
              }
            ],
            "repeated": 0,
            "id": 1775
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1776
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1777
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1778
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1779
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1780
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1781
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1782
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1783
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1784
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "Uuid"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1785
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1786
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1787
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1788
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1789
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1790
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1791
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1792
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1793
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1794
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1795
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1796
          },
          {
            "timestamp": "2026-02-10 09:22:12,667",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1797
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 1798
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1799
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1800
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1801
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1802
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1803
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1804
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1805
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1806
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1807
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "2"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2"
              }
            ],
            "repeated": 0,
            "id": 1808
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1809
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1810
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1811
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1812
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1813
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1814
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1815
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1816
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1817
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1818
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1819
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1820
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1821
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1822
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1823
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1824
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1825
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1826
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1827
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1828
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1829
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1830
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1831
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1832
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1833
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1834
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1835
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1836
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1837
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1838
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1839
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1840
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "3"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3"
              }
            ],
            "repeated": 0,
            "id": 1841
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1842
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1843
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1844
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1845
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1846
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1847
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1848
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1849
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1850
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "Uuid"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1851
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1852
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1853
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1854
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1855
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1856
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1857
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1858
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1859
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1860
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1861
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1862
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1863
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1864
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1865
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1866
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1867
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1868
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1869
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1870
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1871
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1872
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1873
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "4"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4"
              }
            ],
            "repeated": 0,
            "id": 1874
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1875
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 1876
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1877
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1878
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1879
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1880
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1881
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1882
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1883
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1884
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1885
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1886
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1887
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1888
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1889
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1890
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1891
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "LRPC"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1892
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1893
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1894
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1895
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1896
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1897
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1898
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "5"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5"
              }
            ],
            "repeated": 0,
            "id": 1899
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "Data",
                "value": "289e5e0f-414a-4de9-8d17-244507fffc07"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1900
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1901
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "6"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1902
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1903
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1904
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1905
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1906
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1907
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1908
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "Uuid"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1909
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1910
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1911
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1912
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1913
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1914
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1915
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1916
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "LRPC"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1917
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1918
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1919
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1920
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1921
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1922
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1923
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "6"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6"
              }
            ],
            "repeated": 0,
            "id": 1924
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "UUID"
              },
              {
                "name": "Data",
                "value": "289e5e0f-414a-4de9-8d17-244507fffc07"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID"
              }
            ],
            "repeated": 0,
            "id": 1925
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1926
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1927
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1928
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1929
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1930
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1931
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1932
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1933
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "Uuid"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1934
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1935
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1936
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1937
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1938
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1939
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1940
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1941
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "IOCTL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1942
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1943
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1944
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1945
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1946
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1947
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1948
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1949
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "QueryFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile"
              }
            ],
            "repeated": 0,
            "id": 1950
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1951
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1952
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1953
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1954
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1955
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1956
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "7"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7"
              }
            ],
            "repeated": 0,
            "id": 1957
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "NoStateFile"
              },
              {
                "name": "Data",
                "value": "\\Device\\DeviceApi\\Dev\\NoState"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile"
              }
            ],
            "repeated": 0,
            "id": 1958
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1959
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1960
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1961
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1962
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1963
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1964
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1965
          },
          {
            "timestamp": "2026-02-10 09:22:12,682",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1966
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "String"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1967
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1968
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1969
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1970
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1971
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1972
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1973
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1974
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "InProc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport"
              }
            ],
            "repeated": 0,
            "id": 1975
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1976
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1977
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1978
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "DllName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName"
              }
            ],
            "repeated": 0,
            "id": 1979
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1980
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1981
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1982
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "DllName"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\DevDispItemProvider.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName"
              }
            ],
            "repeated": 0,
            "id": 1983
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1984
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1985
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1986
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "DevQueryEntry"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry"
              }
            ],
            "repeated": 0,
            "id": 1987
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1988
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1989
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "8"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8"
              }
            ],
            "repeated": 0,
            "id": 1990
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "DevQueryEntry"
              },
              {
                "name": "Data",
                "value": "DevQueryEntry"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry"
              }
            ],
            "repeated": 0,
            "id": 1991
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1992
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "9"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 1993
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1994
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 1995
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType"
              }
            ],
            "repeated": 0,
            "id": 1996
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 1997
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 1998
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 1999
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "IdType"
              },
              {
                "name": "Data",
                "value": "Uuid"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType"
              }
            ],
            "repeated": 0,
            "id": 2000
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2001
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2002
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2003
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport"
              }
            ],
            "repeated": 0,
            "id": 2004
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2005
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2006
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2007
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "ValueName",
                "value": "Transport"
              },
              {
                "name": "Data",
                "value": "InProc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport"
              }
            ],
            "repeated": 0,
            "id": 2008
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2009
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2010
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2011
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "DllName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName"
              }
            ],
            "repeated": 0,
            "id": 2012
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 2013
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2014
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2015
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "DllName"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\DevDispItemProvider.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName"
              }
            ],
            "repeated": 0,
            "id": 2016
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 2017
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2018
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2019
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "DevQueryEntry"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry"
              }
            ],
            "repeated": 0,
            "id": 2020
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 2021
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 2022
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000003c0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "9"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9"
              }
            ],
            "repeated": 0,
            "id": 2023
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              },
              {
                "name": "ValueName",
                "value": "DevQueryEntry"
              },
              {
                "name": "Data",
                "value": "DevQueryEntry"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry"
              }
            ],
            "repeated": 0,
            "id": 2024
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 2025
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2026
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee146b000"
              },
              {
                "name": "ModuleName",
                "value": "cfgmgr32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2027
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee146b000"
              },
              {
                "name": "ModuleName",
                "value": "cfgmgr32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2028
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\Dev\\Query"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2029
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c0"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\DeviceApi"
              },
              {
                "name": "FileInformationClass",
                "value": "30",
                "pretty_value": "FileCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\x12\\x8c\\x11\\x14\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2030
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a1550",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000003c0"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470000"
              },
              {
                "name": "InBuffer",
                "value": "\\x01\\x10\\x08\\x00\\xcc\\xcc\\xcc\\xcc0\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x1dF/\\x12\\xa8Y\\x02\\x00;M/\\x12\\xa8Y\\xdc\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00N\\x00E\\x00T\\x00\\\\x000\\x000\\x000\\x000\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x02\\x00\\x01\\x00\\x01\\x00~\\x94\\x0bT@\\x8b\\xbcE\\xa8\\xa2j\\x0b\\x89L\\xbd\\xa2\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 2031
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2032
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "5232",
            "caller": "0x7ffee1675921",
            "parentcaller": "0x7ffee142657b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000003c0"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470008"
              },
              {
                "name": "InBuffer",
                "value": ""
              },
              {
                "name": "OutBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 2033
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "5236",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2034
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2035
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xaeU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2036
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 2037
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7e540"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2038
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2039
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2040
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2041
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2042
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2043
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2044
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2045
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15bb",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 2046
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15e5",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2047
          },
          {
            "timestamp": "2026-02-10 09:22:12,698",
            "thread_id": "1824",
            "caller": "0x7ff70a3a15e5",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              },
              {
                "name": "Milliseconds",
                "value": "225000"
              }
            ],
            "repeated": 0,
            "id": 2048
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "5236",
            "caller": "0x7ffee1675921",
            "parentcaller": "0x7ffee142657b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000003c0"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470007"
              },
              {
                "name": "InBuffer",
                "value": ""
              },
              {
                "name": "OutBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 2049
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "5232",
            "caller": "0x7ffee1675921",
            "parentcaller": "0x7ffee142657b",
            "category": "device",
            "api": "DeviceIoControl",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000003c0"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470008"
              },
              {
                "name": "InBuffer",
                "value": ""
              },
              {
                "name": "OutBuffer",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 2050
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2051
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2052
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xfdU\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2053
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 2054
          },
          {
            "timestamp": "2026-02-10 09:22:12,792",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7e540"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2055
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2056
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2057
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2058
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              }
            ],
            "repeated": 0,
            "id": 2059
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2060
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": ">V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2061
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": ">V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2062
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16a6",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c8"
              }
            ],
            "repeated": 0,
            "id": 2063
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a16ca",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470827"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xe5\\xb7\\xfa2\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0b \\x80\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2064
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2065
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00>V\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2066
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": ">V\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2067
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 2068
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000003c4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x32fab7e540"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2069
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mV\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2070
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214120a0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2071
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c4"
              }
            ],
            "repeated": 0,
            "id": 2072
          },
          {
            "timestamp": "2026-02-10 09:22:12,807",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mV\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2073
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "mV\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2074
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000003b4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "mV\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2075
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17a9",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 2076
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17c8",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2077
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a17e1",
            "parentcaller": "0x7ff70a3a1fed",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003bc"
              }
            ],
            "repeated": 0,
            "id": 2078
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a758f",
            "parentcaller": "0x7ff70a39ab24",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 2079
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a75f7",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 2080
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a75f7",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2081
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3998d4",
            "parentcaller": "0x7ff70a3a762a",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 2082
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39527e",
            "parentcaller": "0x7ff70a399c4f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 2083
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3952a1",
            "parentcaller": "0x7ff70a399c4f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 2084
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 2085
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 2086
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118d2000"
              },
              {
                "name": "RegionSize",
                "value": "0x00010000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 2087
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118bb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 2088
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118cb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 2089
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118bb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2090
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 2091
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a3a7648",
            "parentcaller": "0x7ff70a39ab24",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2092
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39abed",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 2093
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39abed",
            "parentcaller": "0x7ff70a39b137",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 2094
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39abed",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b2000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000e000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 2095
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39abed",
            "parentcaller": "0x7ff70a39b137",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x214118b2000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000e000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2096
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ff70a39b15d",
            "parentcaller": "0x7ff70a391da2",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 2097
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee34c467e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              }
            ],
            "repeated": 0,
            "id": 2098
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10bdd5d",
            "parentcaller": "0x7ffeced51d0d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 2099
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffecedbfb2b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDIDestroy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed97572b0"
              }
            ],
            "repeated": 0,
            "id": 2100
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10bdd5d",
            "parentcaller": "0x7ffecedb6c28",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 2101
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10bdd5d",
            "parentcaller": "0x7ffec7f72495",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 2102
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e41e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              }
            ],
            "repeated": 0,
            "id": 2103
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e4e4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000364"
              }
            ],
            "repeated": 0,
            "id": 2104
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "1824",
            "caller": "0x7ffee34c469e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2105
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a3921a5",
            "parentcaller": "0x7ff70a392e1a",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x000001d0"
              },
              {
                "name": "ThreadInformationClass",
                "value": "0",
                "pretty_value": "ThreadBasicInformation"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x12\\x00\\x00\\x00\\x00\\x00\\x00 \\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "1824"
              }
            ],
            "repeated": 0,
            "id": 2106
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a39235b",
            "parentcaller": "0x7ff70a392e1a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d0"
              }
            ],
            "repeated": 0,
            "id": 2107
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a392ec0",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e0"
              }
            ],
            "repeated": 0,
            "id": 2108
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a392ed8",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 2109
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a392efc",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 2110
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a392f10",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 2111
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a391747",
            "parentcaller": "0x7ff70a392f1a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 2112
          },
          {
            "timestamp": "2026-02-10 09:22:12,823",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 2113
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 2114
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2115
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 2116
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 2117
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 2118
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 2119
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 2120
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 2121
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 2122
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 2123
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 2124
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 1,
            "id": 2125
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 2126
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 2127
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 2128
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 2129
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              }
            ],
            "repeated": 0,
            "id": 2130
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 2131
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 2132
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000200"
              }
            ],
            "repeated": 0,
            "id": 2133
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 2134
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 2135
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 2136
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 2137
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              }
            ],
            "repeated": 0,
            "id": 2138
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c8"
              }
            ],
            "repeated": 0,
            "id": 2139
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000080"
              }
            ],
            "repeated": 0,
            "id": 2140
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000084"
              }
            ],
            "repeated": 0,
            "id": 2141
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000198"
              }
            ],
            "repeated": 0,
            "id": 2142
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000190"
              }
            ],
            "repeated": 0,
            "id": 2143
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000170"
              }
            ],
            "repeated": 0,
            "id": 2144
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000174"
              }
            ],
            "repeated": 0,
            "id": 2145
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000016c"
              }
            ],
            "repeated": 0,
            "id": 2146
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000154"
              }
            ],
            "repeated": 0,
            "id": 2147
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000158"
              }
            ],
            "repeated": 0,
            "id": 2148
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000015c"
              }
            ],
            "repeated": 0,
            "id": 2149
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000160"
              }
            ],
            "repeated": 0,
            "id": 2150
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000164"
              }
            ],
            "repeated": 0,
            "id": 2151
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000168"
              }
            ],
            "repeated": 0,
            "id": 2152
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2153
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2154
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000014c"
              }
            ],
            "repeated": 0,
            "id": 2155
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000150"
              }
            ],
            "repeated": 0,
            "id": 2156
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000148"
              }
            ],
            "repeated": 0,
            "id": 2157
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 2158
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2159
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000012c"
              }
            ],
            "repeated": 0,
            "id": 2160
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000130"
              }
            ],
            "repeated": 0,
            "id": 2161
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000134"
              }
            ],
            "repeated": 0,
            "id": 2162
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000138"
              }
            ],
            "repeated": 0,
            "id": 2163
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000013c"
              }
            ],
            "repeated": 0,
            "id": 2164
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000144"
              }
            ],
            "repeated": 0,
            "id": 2165
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000140"
              }
            ],
            "repeated": 0,
            "id": 2166
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000010c"
              }
            ],
            "repeated": 0,
            "id": 2167
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000110"
              }
            ],
            "repeated": 0,
            "id": 2168
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000108"
              }
            ],
            "repeated": 0,
            "id": 2169
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000104"
              }
            ],
            "repeated": 0,
            "id": 2170
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000fc"
              }
            ],
            "repeated": 0,
            "id": 2171
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000100"
              }
            ],
            "repeated": 0,
            "id": 2172
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f8"
              }
            ],
            "repeated": 0,
            "id": 2173
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f4"
              }
            ],
            "repeated": 0,
            "id": 2174
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f0"
              }
            ],
            "repeated": 0,
            "id": 2175
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2176
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000dc"
              }
            ],
            "repeated": 0,
            "id": 2177
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e0"
              }
            ],
            "repeated": 0,
            "id": 2178
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a3abede",
            "parentcaller": "0x7ff70a3cb59f",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 2179
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a3abefb",
            "parentcaller": "0x7ff70a3cb59f",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2180
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000b8"
              }
            ],
            "repeated": 0,
            "id": 2181
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000b4"
              }
            ],
            "repeated": 0,
            "id": 2182
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000bc"
              }
            ],
            "repeated": 0,
            "id": 2183
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 2184
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000bc"
              },
              {
                "name": "ValueName",
                "value": "DisableMetaFiles"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
              }
            ],
            "repeated": 0,
            "id": 2185
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000bc"
              }
            ],
            "repeated": 0,
            "id": 2186
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 2187
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000bc"
              },
              {
                "name": "ValueName",
                "value": "DisableUmpdBufferSizeCheck"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck"
              }
            ],
            "repeated": 0,
            "id": 2188
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000bc"
              }
            ],
            "repeated": 0,
            "id": 2189
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2190
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 2191
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a4"
              }
            ],
            "repeated": 0,
            "id": 2192
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a0"
              }
            ],
            "repeated": 0,
            "id": 2193
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2194
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000090"
              }
            ],
            "repeated": 0,
            "id": 2195
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000009c"
              }
            ],
            "repeated": 0,
            "id": 2196
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 2197
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 2198
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000064"
              }
            ],
            "repeated": 0,
            "id": 2199
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000044"
              }
            ],
            "repeated": 0,
            "id": 2200
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000005c"
              }
            ],
            "repeated": 0,
            "id": 2201
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000060"
              }
            ],
            "repeated": 0,
            "id": 2202
          },
          {
            "timestamp": "2026-02-10 09:22:12,838",
            "thread_id": "4632",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 2203
          }
        ],
        "threads": [
          "4632",
          "2776",
          "3980",
          "1824",
          "5232",
          "5236"
        ],
        "environ": {
          "UserName": "￑￈￑ￒￅￌ￀",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\"",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff70a390000",
          "MainExeSize": "0x00057000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 5580,
        "process_name": "dllhost.exe",
        "parent_id": 740,
        "module_path": "C:\\Windows\\System32\\dllhost.exe",
        "first_seen": "2026-02-10 09:22:13,105",
        "calls": [
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5708",
            "caller": "0x7ffee34ceb32",
            "parentcaller": "0x7ffee34877c3",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 3,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f81712f2",
            "parentcaller": "0x7ff6f81713bb",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f42a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171349",
            "parentcaller": "0x7ff6f81713dc",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x7ff6f8171b60"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5712",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\system32\\rpcss.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000202"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5708",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5704",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5700",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f42c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5700",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "5584"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000001e8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001ec"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00012000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea7f000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedea70000"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\kernel.appcore"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea70000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedea73f10"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "bcryptPrimitives.dll"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00082000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f42d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000094"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000094"
              },
              {
                "name": "ValueName",
                "value": "STE"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000094"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000094"
              },
              {
                "name": "ValueName",
                "value": "Enabled"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001d0"
              },
              {
                "name": "ValueName",
                "value": "FipsAlgorithmPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000094"
              },
              {
                "name": "ValueName",
                "value": "MDMEnabled"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d0"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:22:13,246",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Policies\\Microsoft\\Cryptography\\Configuration"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Policies\\Microsoft\\Cryptography\\Configuration"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000008c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\Device\\CNG"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000008c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390008",
                "pretty_value": "IOCTL_KSEC_RANDOM_FILL_BUFFER"
              },
              {
                "name": "InBuffer",
                "value": ""
              },
              {
                "name": "OutBuffer",
                "value": "cLA3!d\\xdb3\\x87\\xcd\\xc6\\x0f\\x9a\r\\xda\\xed\\x14\\xc6\\x10\\xc3\"$\\x0f\\xf6\\xd3t\\xbe\\xc8Y\\xa6\r\\xbbTh\\x93$\\xca\\xcb\\x0fTR,\\xe2 8]\\xbc\\x8d"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\bcryptprimitives"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee13c8b60"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f430000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CLSIDFromOle1Class"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fef760"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd0\\xf5\\xcf\\x9be\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x80\\xf6\\xcf\\x9be\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000208"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\User\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:5580:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000204"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004"
              },
              {
                "name": "ObjectAttributes",
                "value": "Global\\__ComCatalogCache__"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000204"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x17150dc0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x659bcff6a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\COM3"
              },
              {
                "name": "Handle",
                "value": "0x0000020c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              },
              {
                "name": "ValueName",
                "value": "Com+Enabled"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "clbcatq.dll"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c20000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x000a9000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2cc4000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c98000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c98000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\clbcatq"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee2c20000"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              },
              {
                "name": "EventName",
                "value": "\\KernelObjects\\MaximumCommitCondition"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\clbcatq"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c20000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee2c3d990"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000214"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004"
              },
              {
                "name": "ObjectAttributes",
                "value": "Global\\__ComCatalogCache__"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000214"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x17150de0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x659bcff3f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021a"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "LocalService"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "Data",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "RunAs"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "ActivateAtStorage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "ROTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "AppIDFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "MGOTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "ProcessMitigationPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "LaunchPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "LegacyAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "LegacyImpersonationLevel"
              },
              {
                "name": "Data",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel"
              }
            ],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "RemoteServerName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "SRPTrustLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "PreferredServerBitness"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "LoadUserSettings"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xef\\xcf\\x9be\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x1a\\x02\\x00\\x00\\x00\\x00\\x00\\x00PQ$\\xe3\\xfe\\x7f\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000021c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Classes"
              },
              {
                "name": "Handle",
                "value": "0x00000220"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              },
              {
                "name": "ValueName",
                "value": "ProtectionLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel"
              }
            ],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021a"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f436000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000224"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020119",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|KEY_WOW64_64KEY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000224"
              },
              {
                "name": "ValueName",
                "value": "AllowDevelopmentWithoutDevLicense"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000224"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020119",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|KEY_WOW64_64KEY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000224"
              },
              {
                "name": "ValueName",
                "value": "AllowDevelopmentWithoutDevLicense"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f438000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f439000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE\\AppCompat"
              },
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\AppCompat"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "ValueName",
                "value": "RaiseActivationAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\xed\\xcf\\x9be\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x90\\xee\\xcf\\x9be\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000228"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\User\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000022a"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x00000226"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:13,261",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000226"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE\\AppCompat"
              },
              {
                "name": "Handle",
                "value": "0x0000022c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\AppCompat"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "RaiseDefaultAuthnLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000226"
              },
              {
                "name": "ValueName",
                "value": "AccessPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000226"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SOFTWARE\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "ValueName",
                "value": "DefaultAccessPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd0?COq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\system32\\rpcss.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xf3\\xcf\\x9be\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\xa6C\\x0c\\xe1\\xfe\\x7f\\x00\\x00]~\\x0c\\xcc\\xcaq\\x00\\x00\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f43b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000015cc"
              },
              {
                "name": "EventName",
                "value": "MSFT.VSA.COM.DISABLE.5580"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "EventName",
                "value": "MSFT.VSA.IEC.STATUS.6c736db0"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f43c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f43d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000022a"
              },
              {
                "name": "SubKey",
                "value": "Interface\\{00000134-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x0000023a"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000023a"
              },
              {
                "name": "SubKey",
                "value": "ProxyStubClsid32"
              },
              {
                "name": "Handle",
                "value": "0x0000023e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023e"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "{00000320-0000-0000-C000-000000000046}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023e"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023a"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE\\Software\\Microsoft\\Rpc\\Extensions"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc\\Extensions"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001d0"
              },
              {
                "name": "ValueName",
                "value": "NdrOleExtDLL"
              },
              {
                "name": "Type",
                "value": "2",
                "pretty_value": "REG_EXPAND_SZ"
              },
              {
                "name": "Information",
                "value": "combase.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d0"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "NdrOleInitializeExtension"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee3014240"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "StringFromIID"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fe9780"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemAlloc"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff2e80"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff1b70"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoCreateInstance"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6a420"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000001d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xf6AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00i\\x005\\x00n\\x00\\\\x00d\\x00a\\x00t\\x00a\\x00\\\\x00y\\x00a\\x00r\\x00a\\x00\\\\x00c\\x00a\\x00p\\x00e\\x00m\\x00o\\x00n\\x00.\\x00y\\x00a\\x00c\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": " \\xf7AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\\\x00W\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00.\\x00d\\x00l\\x00l\\x00"
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8@COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\xf7AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xcdp\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00P\\xe9\\xcf\\x9be\\x00\\x00\\x00H\\xe9\\xcf\\x9be\\x00\\x00\\x00\\x18\\xe9\\xcf\\x9be\\x00\\x00\\x008\\xe9\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xf7AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x008\\xe7\\xcf\\x9be\\x00\\x00\\x00\\x94\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xf8AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xf9AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "xACOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xfbAOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00-M\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xe5\\xcf\\x9be\\x00\\x00\\x00\\xa8\\xe5\\xcf\\x9be\\x00\\x00\\x00x\\xe5\\xcf\\x9be\\x00\\x00\\x00\\x98\\xe5\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xfbAOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x98\\xe3\\xcf\\x9be\\x00\\x00\\x00\\x94\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d0"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000238"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x1714f42a050"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "5876"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x00000238",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x1714f42a050"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "5876"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000238"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xf7AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xfeAOq\\x01\\x00\\x00`\\x00\\x00\\x00\\\\x00W\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00.\\x00d\\x00l\\x00l\\x00"
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8=COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xefAOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xbdt\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00 \\xed\\xcf\\x9be\\x00\\x00\\x00\\x18\\xed\\xcf\\x9be\\x00\\x00\\x00\\xe8\\xec\\xcf\\x9be\\x00\\x00\\x00\\x08\\xed\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xefAOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x08\\xeb\\xcf\\x9be\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xf9AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\xf7AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18>COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xf2AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1dq\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe9\\xcf\\x9be\\x00\\x00\\x00x\\xe9\\xcf\\x9be\\x00\\x00\\x00H\\xe9\\xcf\\x9be\\x00\\x00\\x00h\\xe9\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xf2AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xe7\\xcf\\x9be\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xfbAOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xfeAOq\\x01\\x00\\x00`\\x00\\x00\\x00\\\\x00W\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00.\\x00d\\x00l\\x00l\\x00"
              }
            ],
            "repeated": 0,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8?COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xf2AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xbdt\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00 \\xed\\xcf\\x9be\\x00\\x00\\x00\\x18\\xed\\xcf\\x9be\\x00\\x00\\x00\\xe8\\xec\\xcf\\x9be\\x00\\x00\\x00\\x08\\xed\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xf2AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x08\\xeb\\xcf\\x9be\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xf7AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "`\\xf0AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8CCOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "8\\xefAOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1dq\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe9\\xcf\\x9be\\x00\\x00\\x00x\\xe9\\xcf\\x9be\\x00\\x00\\x00H\\xe9\\xcf\\x9be\\x00\\x00\\x00h\\xe9\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xefAOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xe7\\xcf\\x9be\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000238"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "8\\xefAOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xfeAOq\\x01\\x00\\x00`\\x00\\x00\\x00\\\\x00W\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00.\\x00d\\x00l\\x00l\\x00"
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8?COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xf7AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xbdt\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00 \\xed\\xcf\\x9be\\x00\\x00\\x00\\x18\\xed\\xcf\\x9be\\x00\\x00\\x00\\xe8\\xec\\xcf\\x9be\\x00\\x00\\x00\\x08\\xed\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xf7AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x08\\xeb\\xcf\\x9be\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xf2AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xefAOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00A\\x00S\\x00E\\x00.\\x00D\\x00L\\x00L\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00:\\x7f\\x00\\x00\\xf0\\x00@Oq\\x01\\x00\\x00\\xf0\\x00@Oq\\x01\\x00\\x00`\\x00@O"
              }
            ],
            "repeated": 0,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8=COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\xf7AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1dq\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe9\\xcf\\x9be\\x00\\x00\\x00x\\xe9\\xcf\\x9be\\x00\\x00\\x00H\\xe9\\xcf\\x9be\\x00\\x00\\x00h\\xe9\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xf7AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xe7\\xcf\\x9be\\x00\\x00\\x00L\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x0000024c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xf7AOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\xf7AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "8BCOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xf2AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xbdt\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00 \\xed\\xcf\\x9be\\x00\\x00\\x00\\x18\\xed\\xcf\\x9be\\x00\\x00\\x00\\xe8\\xec\\xcf\\x9be\\x00\\x00\\x00\\x08\\xed\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xf2AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x08\\xeb\\xcf\\x9be\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "8\\xfeAOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xf9AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8?COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "8\\xefAOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1dq\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe9\\xcf\\x9be\\x00\\x00\\x00x\\xe9\\xcf\\x9be\\x00\\x00\\x00H\\xe9\\xcf\\x9be\\x00\\x00\\x00h\\xe9\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xefAOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xe7\\xcf\\x9be\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f440000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f442000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5880",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:22:13,277",
            "thread_id": "5880",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000254"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5884",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f444000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5884",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x0000025c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x1714f429e90"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "5888"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x0000025c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x1714f429e90"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "5888"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f445000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x7ffede5b0000"
              }
            ],
            "repeated": 0,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffede5b0000"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffede5b0000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\uxtheme.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000008"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee1f92bbb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "uxtheme.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffede5b0000"
              },
              {
                "name": "FunctionName",
                "value": "ThemeInitApiHook"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffede5bcde0"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffede5bce20",
            "parentcaller": "0x7ffee1f92d8c",
            "category": "system",
            "api": "IsDebuggerPresent",
            "status": false,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee34867b5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xec\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34867ec",
            "parentcaller": "0x7ffee10a5140",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c3f4b",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c3f76",
            "parentcaller": "0x7ffee1144fd4",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000274"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000270"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c2fe4",
            "parentcaller": "0x7ffede5ed921",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "AppsUseLightTheme"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c3018",
            "parentcaller": "0x7ffede5ed921",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffede5bd96c",
            "parentcaller": "0x7ffede5bd1d1",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000278"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f446000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xefAOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00A\\x00S\\x00E\\x00.\\x00D\\x00L\\x00L\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00:\\x7f\\x00\\x00\\xf0\\x00@Oq\\x01\\x00\\x00\\xf0\\x00@O"
              }
            ],
            "repeated": 0,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\xf0AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "8BCOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "X\\xf0AOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00=v\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xa0\\xee\\x7f\\x9ce\\x00\\x00\\x00\\x98\\xee\\x7f\\x9ce\\x00\\x00\\x00h\\xee\\x7f\\x9ce\\x00\\x00\\x00\\x88\\xee\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xf0AOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x88\\xec\\x7f\\x9ce\\x00\\x00\\x00\\x80\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8wDOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@uDOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8CCOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8{DOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x9dr\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x00\\xeb\\x7f\\x9ce\\x00\\x00\\x00\\xf8\\xea\\x7f\\x9ce\\x00\\x00\\x00\\xc8\\xea\\x7f\\x9ce\\x00\\x00\\x00\\xe8\\xea\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0{DOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xe8\\xe8\\x7f\\x9ce\\x00\\x00\\x00\\x80\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5888",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f448000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000280"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xefAOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "`\\xf0AOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "x>COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "xzDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xedq\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00p\\xea\\xcf\\x9be\\x00\\x00\\x00h\\xea\\xcf\\x9be\\x00\\x00\\x008\\xea\\xcf\\x9be\\x00\\x00\\x00X\\xea\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00pzDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00X\\xe8\\xcf\\x9be\\x00\\x00\\x00|\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8sDOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00|DOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8>COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18tDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00MN\\x0c\\xcc\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xd0\\xe6\\xcf\\x9be\\x00\\x00\\x00\\xc8\\xe6\\xcf\\x9be\\x00\\x00\\x00\\x98\\xe6\\xcf\\x9be\\x00\\x00\\x00\\xb8\\xe6\\xcf\\x9b"
              }
            ],
            "repeated": 0,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10tDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xb8\\xe4\\xcf\\x9be\\x00\\x00\\x00|\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f44a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:22:13,293",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee3027db0"
              },
              {
                "name": "Parameter",
                "value": "0x1714f428c70"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "5908"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x0000027c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee3027db0"
              },
              {
                "name": "Parameter",
                "value": "0x1714f428c70"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "5908"
              },
              {
                "name": "ProcessId",
                "value": "5580"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5908",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f44c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "Milliseconds",
                "value": "20000"
              }
            ],
            "repeated": 0,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5908",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5908",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee3027dc9",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              },
              {
                "name": "Milliseconds",
                "value": "30000"
              }
            ],
            "repeated": 0,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5908",
            "caller": "0x7ffee34c467e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "5908"
              }
            ],
            "repeated": 0,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5908",
            "caller": "0x7ffee34c469e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000284"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f44d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f68ce0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "On\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x02\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x03\\x00\\x00\\x00*$\\x03\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2f68c8a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fed427",
            "parentcaller": "0x7ffee2f63d82",
            "category": "misc",
            "api": "GetCommandLineW",
            "status": true,
            "return": "0x1714f402158",
            "arguments": [
              {
                "name": "CommandLine",
                "value": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f44e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30142bf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30142e9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014313",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "StringFromIID"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fe9780"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee301433d",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemAlloc"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff2e80"
              }
            ],
            "repeated": 0,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014367",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff1b70"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014391",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoCreateInstance"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6a420"
              }
            ],
            "repeated": 0,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30143bb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee30141cf",
            "parentcaller": "0x7ffee34b38c0",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000032A-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "00000149-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f9b0ca",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff224d",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000338-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xc9o\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x90\\xcao\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029e"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Class Factory for Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029e"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002a2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a2"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a2"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Apartment"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a2"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xc8o\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00 \\xc9o\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029e"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xc8o\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00 \\xc9o\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029e"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029e"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fe94b2",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fe94ea",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxSxSHashCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount"
              }
            ],
            "repeated": 0,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fe9503",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fede68",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SOFTWARE\\Microsoft\\COM3"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fedea4",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "GipActivityBypass"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fedebd",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x0004034c"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "XsDOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": " qDOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "x>COq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8wDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xcd@\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00P\\xd9\\x7f\\x9ce\\x00\\x00\\x00H\\xd9\\x7f\\x9ce\\x00\\x00\\x00\\x18\\xd9\\x7f\\x9ce\\x00\\x00\\x008\\xd9\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0wDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x008\\xd7\\x7f\\x9ce\\x00\\x00\\x00\\xac\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f451000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8qDOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80nDOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8DCOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8nDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00-]\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xd5\\x7f\\x9ce\\x00\\x00\\x00\\xa8\\xd5\\x7f\\x9ce\\x00\\x00\\x00x\\xd5\\x7f\\x9ce\\x00\\x00\\x00\\x98\\xd5\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0nDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x98\\xd3\\x7f\\x9ce\\x00\\x00\\x00\\xac\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee110c06d",
            "parentcaller": "0x7ffee10bd794",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x17150df0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10bed78",
            "parentcaller": "0x7ffee11106f5",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10bdbb1",
            "parentcaller": "0x7ffee10bd381",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee10bdda6",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "Milliseconds",
                "value": "4000"
              }
            ],
            "repeated": 0,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee110c06d",
            "parentcaller": "0x7ffee10bdcda",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x17150e00000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee10bdd5d",
            "parentcaller": "0x7ffee10bdd0d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5884",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x0004034c"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\xd0\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xae\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x00\\xd1\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002ae"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:22:13,308",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Class Factory for Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002ae"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Apartment"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xce\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xae\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x90\\xcf\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002ae"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xce\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xae\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x90\\xcf\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002ae"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ab08",
            "parentcaller": "0x7ffee2f7a7d9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002ae"
              },
              {
                "name": "SubKey",
                "value": "LocalServer32"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer32"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7a825",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "ValueName",
                "value": "AppID"
              },
              {
                "name": "Data",
                "value": "{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee3015483",
            "parentcaller": "0x7ffee2f94bdc",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f94c07",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "LocalService"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "Data",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f79bff",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "RunAs"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f79d1a",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "ActivateAtStorage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79e39",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79e8d",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ROTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79ee0",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "AppIDFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79f30",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "MGOTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79f84",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ProcessMitigationPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f79fa7",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee3009058",
            "parentcaller": "0x7ffee2f79fcb",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "LaunchPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a010",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a052",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "ValueName",
                "value": "LegacyAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a0a5",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "ValueName",
                "value": "LegacyImpersonationLevel"
              },
              {
                "name": "Data",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a0de",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a123",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "RemoteServerName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a1c8",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "SRPTrustLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a227",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "PreferredServerBitness"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a28a",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "LoadUserSettings"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7a318",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "ProtectionLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f94e2a",
            "parentcaller": "0x7ffee2f7a9ba",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee301450c",
            "parentcaller": "0x7ffee2f7aa90",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002ae"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee3014529",
            "parentcaller": "0x7ffee2f7aa90",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10bddf0",
            "parentcaller": "0x7ffee3014a29",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10bde10",
            "parentcaller": "0x7ffee3014a29",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd0\\xcd\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xae\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\xd0\\xce\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002ae"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002ae"
              },
              {
                "name": "ObjectAttributesName",
                "value": "LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ad16",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ad4d",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002aa"
              },
              {
                "name": "SubKey",
                "value": "Elevation"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\Elevation"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f7adb1",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              }
            ],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2f725e9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000022a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002ae"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2fef8f8",
            "parentcaller": "0x7ffee2f7213b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002ae"
              },
              {
                "name": "SubKey",
                "value": "TreatAs"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee2f72160",
            "parentcaller": "0x7ffee2f69277",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ae"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\shcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1880000"
              }
            ],
            "repeated": 0,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee34d7cc6",
            "parentcaller": "0x7ffee34addf7",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:22:13,324",
            "thread_id": "5888",
            "caller": "0x7ffee34d7cc6",
            "parentcaller": "0x7ffee34addf7",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\thumbcache"
              },
              {
                "name": "DllBase",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffecda20000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00002008"
              }
            ],
            "repeated": 0,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96acf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetClassObject"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda3a900"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96ae8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetActivationFactory"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda4c5c0"
              }
            ],
            "repeated": 0,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96b08",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda3be50"
              }
            ],
            "repeated": 0,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda83000"
              },
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda83000"
              },
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffecda35294",
            "parentcaller": "0x7ffee2fd5144",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000034B-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "0000015B-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee2f80e64",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80e82",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoGetMarshalSizeMax"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fac590"
              }
            ],
            "repeated": 0,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80e9f",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80ebc",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80ed9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2fefbe4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000022a"
              },
              {
                "name": "SubKey",
                "value": "Interface\\{75121952-E0D0-43E5-9380-1D80483ACF72}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{75121952-E0D0-43E5-9380-1D80483ACF72}"
              }
            ],
            "repeated": 0,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2fefa51",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b2"
              },
              {
                "name": "SubKey",
                "value": "ProxyStubClsid32"
              },
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2fefa8c",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2fefad3",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              }
            ],
            "repeated": 0,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2fefae4",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xc0\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x000\\xc1\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "PSFactoryBuffer"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b2"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10e4aa9",
            "parentcaller": "0x7ffee10c31c6",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "%SystemRoot%\\system32\\propsys.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 1,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Both"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              }
            ],
            "repeated": 0,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xbe\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\xc0\\xbf\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xbe\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\xc0\\xbf\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0\\xbc\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\xf0\\xbd\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "PSFactoryBuffer"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b2"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10e4aa9",
            "parentcaller": "0x7ffee10c31c6",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "%SystemRoot%\\system32\\propsys.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 1,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Both"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              }
            ],
            "repeated": 0,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xbb\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x80\\xbc\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xbb\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\x80\\xbc\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ab08",
            "parentcaller": "0x7ffee2f7a7d9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b2"
              },
              {
                "name": "SubKey",
                "value": "LocalServer32"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer32"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7a825",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "AppID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID"
              }
            ],
            "repeated": 0,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xba\\x7f\\x9ce\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xb2\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00e\\x00\\x00\\x00\\xc0\\xbb\\x7f\\x9ce\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b2"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002b2"
              },
              {
                "name": "ObjectAttributesName",
                "value": "LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ad16",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000020a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002b6"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7ad4d",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b6"
              },
              {
                "name": "SubKey",
                "value": "Elevation"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\Elevation"
              }
            ],
            "repeated": 0,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f7adb1",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b6"
              }
            ],
            "repeated": 0,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2f725e9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000022a"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2fef8f8",
            "parentcaller": "0x7ffee2f7213b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b2"
              },
              {
                "name": "SubKey",
                "value": "TreatAs"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee2f72160",
            "parentcaller": "0x7ffee2f69277",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:22:13,339",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\propsys"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedc720000"
              }
            ],
            "repeated": 0,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\propsys.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedc720000"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffedc720000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\propsys.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00002008"
              }
            ],
            "repeated": 0,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96acf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetClassObject"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffedc72b810"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96ae8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000139",
            "pretty_return": "ENTRYPOINT_NOT_FOUND",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetActivationFactory"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96b08",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffedc756430"
              }
            ],
            "repeated": 0,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8vDOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0wDOq\\x01\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8CEOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "xnDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1dV\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xce\\x7f\\x9ce\\x00\\x00\\x00x\\xce\\x7f\\x9ce\\x00\\x00\\x00H\\xce\\x7f\\x9ce\\x00\\x00\\x00h\\xce\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00pnDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xcc\\x7f\\x9ce\\x00\\x00\\x00\\xc0\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "vP\t\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8|DOq\\x01\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00t\\x00h\\x00u\\x00m\\x00b\\x00c\\x00a\\x00c\\x00h\\x00e\\x00.\\x00d\\x00l\\x00l\\x00"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": " tDOq\\x01\\x00\\x00`\\x00\\x00\\x00-\\x00w\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00e\\x00-\\x00w\\x00i\\x00n\\x003\\x002\\x00k\\x00-\\x00f\\x00u\\x00l\\x00l\\x00u\\x00s\\x00e\\x00r\\x00-\\x00l\\x001\\x00-\\x001\\x00-\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18EEOq\\x01\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18qDOq\\x01\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00}R\\xbc\\xcb\\xcaq\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xe0\\xca\\x7f\\x9ce\\x00\\x00\\x00\\xd8\\xca\\x7f\\x9ce\\x00\\x00\\x00\\xa8\\xca\\x7f\\x9ce\\x00\\x00\\x00\\xc8\\xca\\x7f\\x9c"
              }
            ],
            "repeated": 0,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10qDOq\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xc8\\xc8\\x7f\\x9ce\\x00\\x00\\x00\\xc0\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:22:13,355",
            "thread_id": "5884",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:22:13,402",
            "thread_id": "5884",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee303b785",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x0004034c"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:22:13,402",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:22:13,402",
            "thread_id": "5584",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              },
              {
                "name": "Milliseconds",
                "value": "5000"
              }
            ],
            "repeated": 0,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "windows",
            "api": "PostThreadMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ProcessId",
                "value": "5580"
              },
              {
                "name": "ThreadId",
                "value": "5888"
              },
              {
                "name": "Message",
                "value": "1033"
              }
            ],
            "repeated": 0,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34c0444",
            "parentcaller": "0x7ffecda4c60f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffecda39248",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffecda3774b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffecda3774b",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "unload"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\thumbcache"
              },
              {
                "name": "DllBase",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34c0444",
            "parentcaller": "0x7ffee18b4def",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee189c408",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee189c3cb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee189c3cb",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "unload"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\shcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1880000"
              }
            ],
            "repeated": 0,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34e0db0",
            "parentcaller": "0x7ffee34a0391",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1880000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34e0db0",
            "parentcaller": "0x7ffee34a0391",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda20000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee2f6ea0e",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "oleaut32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2a80000"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001ec"
              }
            ],
            "repeated": 0,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2fe2ec5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtDelayExecution",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee2f6cd6e",
            "parentcaller": "0x7ffee2fe2ed4",
            "category": "system",
            "api": "IsDebuggerPresent",
            "status": false,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2fe4324",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34c467e",
            "parentcaller": "0x7ffee110f79a",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "5888"
              }
            ],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5884",
            "caller": "0x7ffee338bf07",
            "parentcaller": "0x7ffee338be66",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5884",
            "caller": "0x7ffee3345bc1",
            "parentcaller": "0x7ffee3345b34",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee1da15b8",
            "parentcaller": "0x7ffee3489a1d",
            "category": "misc",
            "api": "GetKeyboardLayout",
            "status": true,
            "return": "0x04090409",
            "arguments": [
              {
                "name": "KeyboardLayout",
                "value": "0x00000409"
              },
              {
                "name": "LanguageName",
                "value": "English (United States)"
              }
            ],
            "repeated": 0,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f42f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e41e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e4e4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x1714f448000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x17150dc0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5888",
            "caller": "0x7ffee34c469e",
            "parentcaller": "0x7ffee110f79a",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020a"
              }
            ],
            "repeated": 0,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "oleaut32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2a80000"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:22:18,418",
            "thread_id": "5584",
            "caller": "0x7ff6f8171193",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 752
          }
        ],
        "threads": [
          "5584",
          "5708",
          "5712",
          "5704",
          "5700",
          "5880",
          "5884",
          "5888",
          "5908"
        ],
        "environ": {
          "UserName": "Admin",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff6f8170000",
          "MainExeSize": "0x00009000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 1620,
        "process_name": "drvinst.exe",
        "parent_id": 740,
        "module_path": "C:\\Windows\\System32\\drvinst.exe",
        "first_seen": "2026-02-10 09:22:13,827",
        "calls": [
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "3424",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "3424",
            "caller": "0x7ffee1425d32",
            "parentcaller": "0x7ffee1433fdd",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\cfgmgr32"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1420000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee1433750"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "3424",
            "caller": "0x7ffee34dc2c7",
            "parentcaller": "0x7ffee34dc05a",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\ntmarta"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfcb0000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedfcb6930"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "3424",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "5500",
            "caller": "0x7ffee34ceb32",
            "parentcaller": "0x7ffee34877c3",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 1,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:22:13,967",
            "thread_id": "5508",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 3,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3c9cf1",
            "parentcaller": "0x7ff70a3c9859",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x7ff70a3c9ca0"
              }
            ],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec7b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f2b6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3c979e",
            "parentcaller": "0x7ff70a3c9899",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f2b7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a393c61",
            "parentcaller": "0x7ff70a3925a0",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39265a",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtOpenProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x000001f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000040",
                "pretty_value": "PROCESS_DUP_HANDLE"
              },
              {
                "name": "ProcessIdentifier",
                "value": "740"
              },
              {
                "name": "ProcessName",
                "value": "Error obtaining target process name"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a392684",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "misc",
            "api": "GetCommandLineW",
            "status": true,
            "return": "0x2568ec52078",
            "arguments": [
              {
                "name": "CommandLine",
                "value": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\""
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39280d",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x000001f4"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000e88"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000200"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39288f",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0x000001f4"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000e70"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000204"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a392b23",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000204"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f200000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedf7a0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a392b42",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "3424"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "DEVRTL.dll"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000204"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000208"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000204"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\devrtl.dll"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000208"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00014000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f7c000"
              },
              {
                "name": "ModuleName",
                "value": "DEVRTL.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\DEVRTL"
              },
              {
                "name": "DllBase",
                "value": "0x7ffec7f70000"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\devrtl"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffec7f70000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffec7f71690"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca22f",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39e8f6",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a394623",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393eb6",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000210"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a394723",
            "parentcaller": "0x7ff70a393eb6",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3946ef",
            "parentcaller": "0x7ff70a393ee2",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000210"
              },
              {
                "name": "ObjectAttributesName",
                "value": ""
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a393eee",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a394a7d",
            "parentcaller": "0x7ff70a393f23",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ValueName",
                "value": "DebugDriver"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a393f2f",
            "parentcaller": "0x7ff70a393072",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000210"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000020c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\drvstore.dll"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000210"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00148000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4d000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee4c000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\drvstore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffeced50000"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec7c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\drvstore"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffeced50000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffeced5b160"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca6f3",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000230"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:22:13,983",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x0eZ\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x0eZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedeb50"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "IZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "IZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "IZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "IZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4c49",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a393d20",
            "parentcaller": "0x7ff70a393e36",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "8"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a393d8c",
            "parentcaller": "0x7ff70a393e36",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00IZ\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "IZ\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedeb50"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a3a4e61",
            "parentcaller": "0x7ff70a39e984",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:22:13,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "LogPath"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000230"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "SetupOverride"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogLevel"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "536887297"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000022c"
              },
              {
                "name": "ValueName",
                "value": "LogMaxFileSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x97Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedf420"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec7e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec80000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec82000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000023c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80000000",
                "pretty_value": "GENERIC_READ"
              },
              {
                "name": "FileName",
                "value": "\\Device\\DeviceApi\\CMApi"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf8:"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 1,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec84000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec87000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec89000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec91000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec93000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec95000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec97000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b630",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:22:14,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002ac"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced9500"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec99000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a8"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec9b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca1000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 14,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 7,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 1,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 1,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000080"
              },
              {
                "name": "ValueName",
                "value": "000603xx"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "kernel32.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortGetHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee166a190"
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "SortCloseHandle"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1680170"
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\Globalization\\Sorting\\SortDefault.nls"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x25690d00000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced9860"
              },
              {
                "name": "ViewSize",
                "value": "0x00338000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 1,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 3,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca7000"
              },
              {
                "name": "RegionSize",
                "value": "0x00011000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 1,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 3,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 8,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 3,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 1,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 13,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 6,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 1,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 13,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec98000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecb6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec87000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00009000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00009000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec98000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec87000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecb6000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:22:14,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecb8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00021000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6c170",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced94f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 14,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 7,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 3,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 3,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 17,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6be10",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002dc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002dc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e0"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda340"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:22:14,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 14,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 8,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002e4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002e8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedaa70"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e8"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e0"
              }
            ],
            "repeated": 0,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002dc"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d4"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf6Z\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002a4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc4f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:22:14,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "[[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "[[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6c050",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000270"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000270"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000274"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000270"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000274"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb500"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 1,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 14,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 7,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 3,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 3,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 2,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000025c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000258"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000025c"
              },
              {
                "name": "ValueName",
                "value": "DisableDecoratedModelsRequirement"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 3,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 1,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 8,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 3,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 13,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 4,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:22:14,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 37,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 16,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 4,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 1,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 1,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 37,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec86000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 15,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 1,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e974-e325-11ce-bfc1-08002be10318}\\Schema"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e974-e325-11ce-bfc1-08002be10318}\\Schema"
              }
            ],
            "repeated": 0,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 7,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00[[\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "[[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002c8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc530"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002c4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "api-ms-win-eventing-provider-l1-1-0.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "EventSetInformation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2af0"
              }
            ],
            "repeated": 0,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f0"
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:22:14,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 752
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 753
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 754
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 755
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 756
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 757
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 758
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 759
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xa4[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 760
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 761
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000027c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc4f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 762
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 763
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 764
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 765
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 766
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 767
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 768
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000278"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 769
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 770
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp"
              }
            ],
            "repeated": 0,
            "id": 771
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 772
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 773
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 774
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 775
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6c170",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 776
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 777
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 778
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 3,
            "id": 779
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 780
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 3,
            "id": 781
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 782
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 3,
            "id": 783
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 784
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 785
          },
          {
            "timestamp": "2026-02-10 09:22:14,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 786
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf0[\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 787
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 788
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000028c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc280"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 789
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 790
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 791
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 792
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 793
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 794
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 795
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 796
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 797
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 4,
            "id": 798
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b6f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 799
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 800
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 801
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 802
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\"
              }
            ],
            "repeated": 0,
            "id": 803
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b270",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 804
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 805
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 1,
            "id": 806
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\cabinet"
              },
              {
                "name": "DllBase",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 807
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "cabinet.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffed9750000"
              }
            ],
            "repeated": 0,
            "id": 808
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffed9750000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "cabinet.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 809
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICreate"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9758d10"
              }
            ],
            "repeated": 0,
            "id": 810
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 811
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 812
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 813
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\"
              }
            ],
            "repeated": 0,
            "id": 814
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDICopy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed9755f00"
              }
            ],
            "repeated": 0,
            "id": 815
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 816
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 817
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 818
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 819
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "Buffer",
                "value": "0\\x82,\\xf5\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82,\\xe60\\x82,\\xe2\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 820
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 821
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 822
          },
          {
            "timestamp": "2026-02-10 09:22:14,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 823
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 824
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 825
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedaa00"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 826
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 827
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 828
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 829
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 830
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 1,
            "id": 831
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 832
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 833
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 834
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 835
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00&\\\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 836
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "&\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 837
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 838
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000288"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda8f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 839
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 840
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 841
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 842
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 843
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 844
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 845
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 846
          },
          {
            "timestamp": "2026-02-10 09:22:14,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 847
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 848
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 849
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              }
            ],
            "repeated": 0,
            "id": 850
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 851
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01:L$\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 852
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 853
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 854
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 855
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "PrivCopyFileExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1682940"
              }
            ],
            "repeated": 0,
            "id": 856
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 857
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 858
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 859
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 860
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 861
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 862
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 863
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 864
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 865
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002f4"
              },
              {
                "name": "ValueName",
                "value": "CopyFileBufferedSynchronousIo"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo"
              }
            ],
            "repeated": 0,
            "id": 866
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 867
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 868
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": "  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 869
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 870
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01:L$\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 871
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 872
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01:L$\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 873
          },
          {
            "timestamp": "2026-02-10 09:22:14,155",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 874
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00002020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE|FILE_ATTRIBUTE_NOT_CONTENT_INDEXED"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 875
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": ":L$\\xben\\x9a\\xdc\\x01\\x99\\x17)\\xben\\x9a\\xdc\\x01\\x99\\x17)\\xben\\x9a\\xdc\\x01\\x99\\x17)\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 876
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 877
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 878
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 879
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 880
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x000002f4"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000300"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 881
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000300"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 882
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 1,
            "id": 883
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 884
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 885
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "ValueName",
                "value": "CopyFileChunkSize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize"
              }
            ],
            "repeated": 0,
            "id": 886
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000300"
              },
              {
                "name": "ValueName",
                "value": "CopyFileOverlappedCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount"
              }
            ],
            "repeated": 0,
            "id": 887
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 888
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 889
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 890
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 891
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 892
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 893
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 894
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 895
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 896
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 897
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01:L$\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 898
          },
          {
            "timestamp": "2026-02-10 09:22:14,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 899
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 900
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 901
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 902
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6bb10",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 903
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 904
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 905
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 906
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\"
              }
            ],
            "repeated": 0,
            "id": 907
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b810",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 908
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 909
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 910
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 911
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 912
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 913
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\"
              }
            ],
            "repeated": 0,
            "id": 914
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 915
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 916
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 917
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 918
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "Buffer",
                "value": ";-----------------------------------"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 919
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 920
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 921
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 922
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 923
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 924
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedaa00"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 925
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 926
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 927
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 928
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 929
          },
          {
            "timestamp": "2026-02-10 09:22:14,186",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 930
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 931
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 932
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 933
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 934
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3\\\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 935
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000308"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 936
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000308"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda8f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 937
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80]\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 938
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 939
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 940
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80]\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 941
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80]\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 942
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80]\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 943
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 944
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 945
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 946
          },
          {
            "timestamp": "2026-02-10 09:22:14,202",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 947
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              }
            ],
            "repeated": 0,
            "id": 948
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 949
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x94r+\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 950
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 951
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 952
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 953
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": "  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 954
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 955
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x94r+\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 956
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 957
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x94r+\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 958
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000304"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 959
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00002020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE|FILE_ATTRIBUTE_NOT_CONTENT_INDEXED"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 960
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"\\xd7-\\xben\\x9a\\xdc\\x01I80\\xben\\x9a\\xdc\\x01I80\\xben\\x9a\\xdc\\x01I80\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 961
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000304"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x000002fc"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 962
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 963
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 1,
            "id": 964
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 965
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 966
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 967
          },
          {
            "timestamp": "2026-02-10 09:22:14,217",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 968
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01s\\xbc=\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 969
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 970
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 971
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 972
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 973
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 974
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x94r+\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 975
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 976
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 977
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 978
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 979
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b750",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 980
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 981
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 1,
            "id": 982
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 983
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\"
              }
            ],
            "repeated": 0,
            "id": 984
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6be10",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 985
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 986
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 987
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 988
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 989
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "12"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x80\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 990
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\"
              }
            ],
            "repeated": 0,
            "id": 991
          },
          {
            "timestamp": "2026-02-10 09:22:14,233",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 992
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 993
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 994
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 995
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002fc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "Buffer",
                "value": "MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "Length",
                "value": "36"
              }
            ],
            "repeated": 0,
            "id": 996
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 997
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 998
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 999
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\n\\x00\\x00\\x00\\x00\\x00pd\n\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1000
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002f4"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 1001
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedaa00"
              },
              {
                "name": "ViewSize",
                "value": "0x000a7000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1002
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "RegionSize",
                "value": "0x000a7000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1003
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002fc"
              }
            ],
            "repeated": 0,
            "id": 1004
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 1005
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 1006
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 1007
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "2",
                "pretty_value": "FILE_CREATE"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1008
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1009
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1010
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x80]\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1011
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80]\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1012
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1013
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002f4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda8f0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1014
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1015
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1016
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f4"
              }
            ],
            "repeated": 0,
            "id": 1017
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1018
          },
          {
            "timestamp": "2026-02-10 09:22:14,249",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "-^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1019
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "-^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1020
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1021
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1022
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1023
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1024
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              }
            ],
            "repeated": 0,
            "id": 1025
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1026
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x98\\xfc4\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x18\\x1f@\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1027
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1028
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 1029
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1030
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": "  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1031
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\n\\x00\\x00\\x00\\x00\\x00pd\n\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1032
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x98\\xfc4\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x18\\x1f@\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1033
          },
          {
            "timestamp": "2026-02-10 09:22:14,264",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00pd\n\\x00\\x00\\x00\\x00\\x00\\x00p\n\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 1034
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x98\\xfc4\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x18\\x1f@\\xbbn\\x9a\\xdc\\x01  \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1035
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1036
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00002020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE|FILE_ATTRIBUTE_NOT_CONTENT_INDEXED"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1037
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x98\\xfc4\\xben\\x9a\\xdc\\x01\\x03\\xc29\\xben\\x9a\\xdc\\x01\\x03\\xc29\\xben\\x9a\\xdc\\x01\\x03\\xc29\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1038
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000290"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000288"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1039
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000288"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 1040
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 1,
            "id": 1041
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "pd\n\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1042
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000290"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "58"
              },
              {
                "name": "FileInformation",
                "value": ".\\x00\\x00\\x00\\\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00\\\\x00H\\x00a\\x00r\\x00d\\x00d\\x00i\\x00s\\x00k\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 1043
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "58"
              },
              {
                "name": "FileInformation",
                "value": ".\\x00\\x00\\x00\\\\x00D\\x00e\\x00v\\x00i\\x00c\\x00e\\x00\\\\x00H\\x00a\\x00r\\x00d\\x00d\\x00i\\x00s\\x00k\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 1044
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1045
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 1046
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 1047
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 1048
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1049
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1050
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1051
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x18\\x1f@\\xbbn\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1052
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 1053
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 1054
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1055
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1056
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1057
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x98\\xfc4\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1058
          },
          {
            "timestamp": "2026-02-10 09:22:14,280",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1059
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1060
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "MoveFileWithProgressTransactedW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExistingFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
              },
              {
                "name": "NewFileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "Flags",
                "value": "0x00000001",
                "pretty_value": "MOVEFILE_REPLACE_EXISTING"
              }
            ],
            "repeated": 0,
            "id": 1061
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1062
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00-^\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1063
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "-^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1064
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000290"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1065
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000290"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc280"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1066
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1067
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1068
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1069
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 1070
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1071
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "v^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1072
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000028c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "v^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1073
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1074
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1075
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1076
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1077
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1078
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1079
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1080
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1081
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1082
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1083
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1084
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1085
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1086
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1087
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1088
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1089
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1090
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b6f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 1091
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1092
          },
          {
            "timestamp": "2026-02-10 09:22:14,296",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1093
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1094
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000025c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000254"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 1095
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000025c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedabe0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1096
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1097
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1098
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1099
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1100
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1101
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 1102
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1103
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1104
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1105
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1106
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1107
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1108
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1109
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1110
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1111
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1112
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1113
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1114
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1115
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1116
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1117
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1118
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1119
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1120
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1121
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1122
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1123
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1124
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1125
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1126
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1127
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1128
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1129
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1130
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1131
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1132
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1133
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 1,
            "id": 1134
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 14,
            "id": 1135
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 1136
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1137
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1138
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 1139
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 8,
            "id": 1140
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 1141
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 1142
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 1143
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1144
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1145
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec87000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 1146
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 1147
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 1148
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1149
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1150
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec8d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00012000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1151
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 1152
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1153
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1154
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1155
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1156
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000300"
              }
            ],
            "repeated": 0,
            "id": 1157
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000028c"
              }
            ],
            "repeated": 0,
            "id": 1158
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 1159
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000294"
              }
            ],
            "repeated": 0,
            "id": 1160
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d0"
              }
            ],
            "repeated": 0,
            "id": 1161
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1162
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 1163
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1164
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 1165
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 1166
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 1167
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 1168
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c0"
              }
            ],
            "repeated": 0,
            "id": 1169
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 1170
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 1171
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 1172
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1173
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1174
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b6f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 1175
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1176
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6c170",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 1177
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1178
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 1179
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1180
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00v^\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1181
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "v^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1182
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000250"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1183
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000250"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1184
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1185
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1186
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1187
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1188
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1189
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1190
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002bc"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1191
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1192
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a395b15",
            "parentcaller": "0x7ff70a39d173",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b6f0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 1193
          },
          {
            "timestamp": "2026-02-10 09:22:14,311",
            "thread_id": "3424",
            "caller": "0x7ff70a395b3c",
            "parentcaller": "0x7ff70a39d173",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1194
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca927",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1195
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca927",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1196
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 1,
            "id": 1197
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1198
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000310"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 1199
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000310"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbdd0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1200
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 1201
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec87000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1202
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\MSASN1"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee0690000"
              }
            ],
            "repeated": 0,
            "id": 1203
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1204
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 1205
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568eca0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1206
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "CRYPTSP.dll"
              }
            ],
            "repeated": 0,
            "id": 1207
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              }
            ],
            "repeated": 0,
            "id": 1208
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000310"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1209
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000310"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\cryptsp.dll"
              }
            ],
            "repeated": 0,
            "id": 1210
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000002bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00018000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1211
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0465000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1212
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1213
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1214
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1215
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1216
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1217
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 1218
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 1219
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee045d000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1220
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\CRYPTSP"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee0450000"
              }
            ],
            "repeated": 0,
            "id": 1221
          },
          {
            "timestamp": "2026-02-10 09:22:14,327",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 12,
            "id": 1222
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\cryptsp"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee0454aa0"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1223
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1224
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1225
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\rsaenh"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 1226
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 1227
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 1228
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptAcquireContextA",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": "Microsoft Enhanced RSA and AES Cryptographic Provider"
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 1229
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1230
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1231
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "CryptDllFindOIDInfo"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo"
              }
            ],
            "repeated": 0,
            "id": 1232
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1233
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1234
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 1235
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1236
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7"
              }
            ],
            "repeated": 0,
            "id": 1237
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1238
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1239
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1240
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1241
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1242
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1243
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1244
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1245
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1246
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Isolated User Mode (IUM)"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1247
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1248
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1249
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1250
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1251
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1252
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1253
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1254
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1255
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1256
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1257
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Isolated User Mode (IUM)"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1258
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1259
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1260
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1261
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1262
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1263
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 1264
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1265
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7"
              }
            ],
            "repeated": 0,
            "id": 1266
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1267
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1268
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1269
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1270
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1271
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1272
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1273
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1274
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1275
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Enclave"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101"
              }
            ],
            "repeated": 0,
            "id": 1276
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1277
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1278
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1279
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1280
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1281
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1282
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1283
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1284
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1285
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ci.dll"
              }
            ],
            "repeated": 0,
            "id": 1286
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\ci.dll,-101"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "Enclave"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101"
              }
            ],
            "repeated": 0,
            "id": 1287
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1288
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1289
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1290
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1291
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1292
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 1293
          },
          {
            "timestamp": "2026-02-10 09:22:14,342",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1294
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1295
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1296
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1297
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1298
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1299
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1300
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1301
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1302
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1303
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\dnsapi.dll"
              }
            ],
            "repeated": 0,
            "id": 1304
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103"
              }
            ],
            "repeated": 0,
            "id": 1305
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1306
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1307
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1308
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1309
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1310
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1311
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1312
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1313
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1314
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\dnsapi.dll"
              }
            ],
            "repeated": 0,
            "id": 1315
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103"
              }
            ],
            "repeated": 0,
            "id": 1316
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1317
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1318
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1319
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1320
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1321
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "80"
              }
            ],
            "repeated": 0,
            "id": 1322
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1323
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7"
              }
            ],
            "repeated": 0,
            "id": 1324
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1325
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1326
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1327
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1328
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1329
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1330
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1331
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1332
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\wuaueng.dll"
              }
            ],
            "repeated": 0,
            "id": 1333
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400"
              }
            ],
            "repeated": 0,
            "id": 1334
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1335
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1336
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1337
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1338
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1339
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1340
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1341
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1342
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1343
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\wuaueng.dll"
              }
            ],
            "repeated": 0,
            "id": 1344
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400"
              }
            ],
            "repeated": 0,
            "id": 1345
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1346
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1347
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1348
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1349
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1350
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "132"
              }
            ],
            "repeated": 0,
            "id": 1351
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1352
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7"
              }
            ],
            "repeated": 0,
            "id": 1353
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1354
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1355
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1356
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1357
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1358
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1359
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1360
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1361
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
              }
            ],
            "repeated": 0,
            "id": 1362
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              }
            ],
            "repeated": 0,
            "id": 1363
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1364
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1365
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1366
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1367
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1368
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1369
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1370
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1371
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1372
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
              }
            ],
            "repeated": 0,
            "id": 1373
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
              }
            ],
            "repeated": 0,
            "id": 1374
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1375
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1376
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1377
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1378
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1379
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "1"
              },
              {
                "name": "MaxValueNameLength",
                "value": "4"
              },
              {
                "name": "MaxValueLength",
                "value": "88"
              }
            ],
            "repeated": 0,
            "id": 1380
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1381
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7"
              }
            ],
            "repeated": 0,
            "id": 1382
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1383
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1384
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1385
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1386
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1387
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1388
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000330"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1389
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1390
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\NgcRecovery.dll"
              }
            ],
            "repeated": 0,
            "id": 1391
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1392
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1393
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "ValueName",
                "value": "Name"
              },
              {
                "name": "Data",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name"
              }
            ],
            "repeated": 0,
            "id": 1394
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings"
              }
            ],
            "repeated": 0,
            "id": 1395
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "ValueName",
                "value": "StringCacheGeneration"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration"
              }
            ],
            "repeated": 0,
            "id": 1396
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1397
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb8'\\xe1\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00I\\x8fV\\x02\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1398
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 1399
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0002001f",
                "pretty_value": "KEY_READ|KEY_WRITE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000334"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78"
              }
            ],
            "repeated": 0,
            "id": 1400
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1401
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\NgcRecovery.dll"
              }
            ],
            "repeated": 0,
            "id": 1402
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "ValueName",
                "value": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
              }
            ],
            "repeated": 0,
            "id": 1403
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1404
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1405
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1406
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\"
              }
            ],
            "repeated": 0,
            "id": 1407
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1408
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1409
          },
          {
            "timestamp": "2026-02-10 09:22:14,358",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000250"
              }
            ],
            "repeated": 0,
            "id": 1410
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\Cryptography\\ECCParameters"
              },
              {
                "name": "Handle",
                "value": "0x000002a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Cryptography\\ECCParameters"
              }
            ],
            "repeated": 0,
            "id": 1411
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Cryptography\\ECCParameters\\"
              }
            ],
            "repeated": 0,
            "id": 1412
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a0"
              }
            ],
            "repeated": 0,
            "id": 1413
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 1414
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ru-RU\\CRYPT32.dll.mui"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 1415
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000002a0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\ru-RU\\crypt32.dll.mui"
              }
            ],
            "repeated": 0,
            "id": 1416
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f250000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x0000c000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1417
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 1418
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1419
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1420
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "device",
            "api": "NtDeviceIoControlFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000174"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\KsecDD"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390400"
              },
              {
                "name": "InputBuffer",
                "value": "M<+\\x1a\\x00\\x00\\x02\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": "\\x01\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00A\\x002\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xffS\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00P\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00 \\x00P\\x00r\\x00o\\x00v\\x00i\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00b\\x00c\\x00r\\x00y\\x00p\\x00t\\x00p\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00s\\x00.\\x00d\\x00l\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1421
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\bcryptprimitives.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 1422
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1390000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\bcryptprimitives.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1423
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetHashInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13a4460"
              }
            ],
            "repeated": 0,
            "id": 1424
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1425
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1426
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5e28",
            "parentcaller": "0x7ff70a39d185",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 1427
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1428
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1429
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1430
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 1431
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000230"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbe60"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1432
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecd9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00009000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1433
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1434
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1435
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 1436
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1437
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1438
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1439
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a39d209",
            "parentcaller": "0x7ff70a39e83d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 1440
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5ba0",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1441
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 1442
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000304"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "WINTRUST.dll"
              }
            ],
            "repeated": 0,
            "id": 1443
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000304"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00067000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1444
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1445
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1446
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1447
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1448
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1449
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1450
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 1451
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14ba000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1452
          },
          {
            "timestamp": "2026-02-10 09:22:14,374",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\WINTRUST"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 1453
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 1454
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1455
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1456
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1457
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1458
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1459
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1460
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\wintrust"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee1481670"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1461
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1462
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3cac3a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1463
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1464
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 1465
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 1466
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000234"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbc90"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1467
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1468
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 1469
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1470
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1471
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000234"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1472
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllPutSignedDataMsg"
              },
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg"
              }
            ],
            "repeated": 0,
            "id": 1473
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 1474
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 1475
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1476
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\MSISIP.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1477
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "MsiSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1478
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1479
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1480
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1481
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1482
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1483
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1484
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1485
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 1486
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 1487
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1488
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1489
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1490
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1491
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 1492
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 1493
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1494
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1495
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxBundleSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1496
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1497
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 1498
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 1499
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1500
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1501
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1502
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1503
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1504
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 1505
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1506
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1507
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1508
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1509
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 1510
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 1511
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1512
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1513
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "P7xSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1514
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1515
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 1516
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 1517
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 1518
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pwrshsip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1519
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PsPutSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1520
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1521
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1522
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1523
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1524
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1525
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1526
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1527
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 1528
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 1529
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 1530
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1531
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipPutSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1532
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1533
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1534
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1535
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1536
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1537
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1538
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1539
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1540
          },
          {
            "timestamp": "2026-02-10 09:22:14,389",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1541
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1542
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1543
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1544
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1545
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1546
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1547
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1548
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1549
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1550
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1551
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 1552
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 1553
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1554
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1555
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1556
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1557
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 1558
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 1559
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 1560
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1561
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxBundleSipPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1562
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1563
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1564
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1565
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1566
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1567
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1568
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1569
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1570
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002b4"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 1571
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "50"
              }
            ],
            "repeated": 0,
            "id": 1572
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1573
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1574
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1575
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\"
              }
            ],
            "repeated": 0,
            "id": 1576
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 1577
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1578
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1579
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000234"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000002a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1580
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a4"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllPutSignedDataMsg"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllPutSignedDataMsg"
              }
            ],
            "repeated": 0,
            "id": 1581
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 1582
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 1583
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 1584
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 1585
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1586
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000139",
            "pretty_return": "ENTRYPOINT_NOT_FOUND",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 1587
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 1588
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000002"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\crypt32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0b90000"
              }
            ],
            "repeated": 0,
            "id": 1589
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0b90000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\System32\\CRYPT32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000011"
              }
            ],
            "repeated": 0,
            "id": 1590
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x000002a4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee0bdb180"
              },
              {
                "name": "Parameter",
                "value": "0x2568ecd78c0"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "6080"
              },
              {
                "name": "ProcessId",
                "value": "1620"
              },
              {
                "name": "Module",
                "value": "CRYPT32.dll"
              }
            ],
            "repeated": 0,
            "id": 1591
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x000002a4",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee0bdb180"
              },
              {
                "name": "Parameter",
                "value": "0x2568ecd78c0"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "6080"
              },
              {
                "name": "ProcessId",
                "value": "1620"
              }
            ],
            "repeated": 0,
            "id": 1592
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1593
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 1594
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1595
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1596
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "6080",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1597
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1598
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              }
            ],
            "repeated": 0,
            "id": 1599
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 1600
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\AuthRoot"
              }
            ],
            "repeated": 0,
            "id": 1601
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config"
              },
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config"
              }
            ],
            "repeated": 0,
            "id": 1602
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 1603
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertSyncDeltaTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime"
              }
            ],
            "repeated": 0,
            "id": 1604
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1605
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 1606
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\ChainEngine\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\ChainEngine\\Config"
              }
            ],
            "repeated": 0,
            "id": 1607
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "DisableMandatoryBasicConstraints"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints"
              }
            ],
            "repeated": 0,
            "id": 1608
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "DisableCANameConstraints"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints"
              }
            ],
            "repeated": 0,
            "id": 1609
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "DisableUnsupportedCriticalExtensions"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions"
              }
            ],
            "repeated": 0,
            "id": 1610
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlCountInCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert"
              }
            ],
            "repeated": 0,
            "id": 1611
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1612
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxUrlRetrievalByteCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount"
              }
            ],
            "repeated": 0,
            "id": 1613
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalByteCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount"
              }
            ],
            "repeated": 0,
            "id": 1614
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxAIAUrlRetrievalCertCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount"
              }
            ],
            "repeated": 0,
            "id": 1615
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxVerifySignatureCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1616
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxIssuerDepth"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth"
              }
            ],
            "repeated": 0,
            "id": 1617
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MaxPathCountPerChain"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain"
              }
            ],
            "repeated": 0,
            "id": 1618
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "CryptnetPreFetchTriggerPeriodSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds"
              }
            ],
            "repeated": 0,
            "id": 1619
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "EnableWeakSignatureFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags"
              }
            ],
            "repeated": 0,
            "id": 1620
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "MinRsaPubKeyBitLength"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength"
              }
            ],
            "repeated": 0,
            "id": 1621
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakRsaPubKeyTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime"
              }
            ],
            "repeated": 0,
            "id": 1622
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "ChainCacheResyncFiletime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime"
              }
            ],
            "repeated": 0,
            "id": 1623
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "EnableStrictChecksFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags"
              }
            ],
            "repeated": 0,
            "id": 1624
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029c"
              },
              {
                "name": "SubKey",
                "value": "Default"
              },
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default"
              }
            ],
            "repeated": 0,
            "id": 1625
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\CI\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CI\\Config"
              }
            ],
            "repeated": 0,
            "id": 1626
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000288"
              },
              {
                "name": "SubKey",
                "value": "Default"
              },
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default"
              }
            ],
            "repeated": 0,
            "id": 1627
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1628
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyFlags"
              },
              {
                "name": "Data",
                "value": "18446744071705722880"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1629
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyAfterTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1630
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartyAfterTime"
              },
              {
                "name": "Data",
                "value": "\\x00\\xc0)\\xb8C\\x9a\\xc9\\x01"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1631
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1632
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1633
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1634
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1635
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1636
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1637
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1638
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1639
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "Data",
                "value": "\\x00\\x00\\x001\\x3b5b\\xf70a\\x7f\\x1200P\\xd21b\\xa39\\x7ff7"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1640
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1641
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1642
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1643
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1644
          },
          {
            "timestamp": "2026-02-10 09:22:14,405",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakMD5AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1645
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1646
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyFlags"
              },
              {
                "name": "Data",
                "value": "18446744071562330112"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1647
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartyAfterTime"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime"
              }
            ],
            "repeated": 0,
            "id": 1648
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1649
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1650
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1651
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags"
              }
            ],
            "repeated": 0,
            "id": 1652
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1653
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1654
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1655
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1656
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1657
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1658
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1ThirdPartySha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1659
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              },
              {
                "name": "ValueName",
                "value": "WeakSHA1AllSha256Allow"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow"
              }
            ],
            "repeated": 0,
            "id": 1660
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1661
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1662
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1663
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakRSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1664
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1665
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1666
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1667
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1668
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1669
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAThirdPartyFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags"
              }
            ],
            "repeated": 0,
            "id": 1670
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1671
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              },
              {
                "name": "ValueName",
                "value": "WeakECDSAAllFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags"
              }
            ],
            "repeated": 0,
            "id": 1672
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002f8"
              }
            ],
            "repeated": 0,
            "id": 1673
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1674
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000308"
              }
            ],
            "repeated": 0,
            "id": 1675
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Services\\crypt32"
              },
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32"
              }
            ],
            "repeated": 0,
            "id": 1676
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "DiagLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel"
              }
            ],
            "repeated": 0,
            "id": 1677
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "ValueName",
                "value": "DiagMatchAnyMask"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask"
              }
            ],
            "repeated": 0,
            "id": 1678
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 1679
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Services\\crypt32"
              },
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32"
              }
            ],
            "repeated": 0,
            "id": 1680
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000004"
              },
              {
                "name": "WatchSubtree",
                "value": "0"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 1681
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000278"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 1682
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "6072",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 1683
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1684
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000278"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 1685
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CertDllOpenStoreProv"
              },
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv"
              }
            ],
            "repeated": 0,
            "id": 1686
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "#16"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16"
              }
            ],
            "repeated": 0,
            "id": 1687
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "#16"
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16"
              }
            ],
            "repeated": 0,
            "id": 1688
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000284"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 1689
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptnet.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1690
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "LdapProvOpenStore"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1691
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1692
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "Ldap"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap"
              }
            ],
            "repeated": 0,
            "id": 1693
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "Ldap"
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap"
              }
            ],
            "repeated": 0,
            "id": 1694
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000284"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 1695
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptnet.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap\\Dll"
              }
            ],
            "repeated": 0,
            "id": 1696
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "LdapProvOpenStore"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 1697
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1698
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\"
              }
            ],
            "repeated": 0,
            "id": 1699
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1700
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1701
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1702
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000278"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 1703
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CertDllOpenStoreProv"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllOpenStoreProv"
              }
            ],
            "repeated": 0,
            "id": 1704
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1705
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 1706
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1707
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1708
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1709
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1710
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1711
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1712
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1713
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1714
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1715
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1716
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1717
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1718
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1719
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1720
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00x\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1721
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 1722
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1723
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1724
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1725
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1726
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1727
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1728
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1729
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1730
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00|\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1731
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1732
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1733
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1734
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1735
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1736
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1737
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1738
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1739
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1740
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1741
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1742
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1743
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1744
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1745
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xb0\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xf06\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00P\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x80\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1746
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1747
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1748
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1749
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 1750
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000280"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1751
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1752
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000284"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1753
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1754
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1755
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000284"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1756
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1757
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1758
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000284"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1759
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1760
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1761
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 1762
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1763
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1764
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1765
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1766
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xac\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x00:\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00@\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00PL\\xca\\x8eV\\x02\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x00|\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1767
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1768
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1769
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000284"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 1770
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1771
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000284"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1772
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1773
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1774
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1775
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1776
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1777
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1778
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1779
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1780
          },
          {
            "timestamp": "2026-02-10 09:22:14,421",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 1781
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 1782
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1783
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1784
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1785
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1786
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000250"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1787
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1788
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1789
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "3"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1790
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 1791
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 1792
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1793
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1794
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1795
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft W"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1796
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 1797
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 1798
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1799
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1800
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1801
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign "
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1802
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 1803
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 1804
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1805
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1806
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1807
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1808
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1809
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1810
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1811
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1812
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 1813
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 1814
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1815
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1816
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1817
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r0008310"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 1818
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1819
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1820
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1821
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1822
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1823
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1824
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1825
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1826
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1827
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1828
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1829
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1830
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1831
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000031c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1832
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000031c"
              }
            ],
            "repeated": 0,
            "id": 1833
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1834
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1835
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1836
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1837
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1838
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000031c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\"
              }
            ],
            "repeated": 0,
            "id": 1839
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1840
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1841
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1842
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1843
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1844
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1845
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1846
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000324"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1847
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1848
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1849
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1850
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1851
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1852
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1853
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1854
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1855
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1856
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1857
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1858
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1859
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1860
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1861
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1862
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1863
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1864
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1865
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1866
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1867
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1868
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1869
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1870
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1871
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1872
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1873
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1874
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1875
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1876
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1877
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1878
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1879
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1880
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe8\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xc03\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\x80\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00 X\\xc6\\x8eV\\x02\\x00\\x00\\x90\\xb8\\xed\\x1c\\x97\\x00\\x00\\x00P\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00P\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1881
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1882
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1883
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1884
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1885
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1886
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1887
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1888
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1889
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1890
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1891
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1892
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1893
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1894
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1895
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xb0\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xf06\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00P\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00$\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1896
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1897
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1898
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1899
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000324"
              }
            ],
            "repeated": 0,
            "id": 1900
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000324"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 1901
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1902
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1903
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1904
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1905
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1906
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1907
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1908
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000328"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1909
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1910
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1911
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000328"
              }
            ],
            "repeated": 0,
            "id": 1912
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1913
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1914
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1915
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1916
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xac\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x00:\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00@\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00@U\\xca\\x8eV\\x02\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1917
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1918
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1919
          },
          {
            "timestamp": "2026-02-10 09:22:14,436",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000328"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 1920
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1921
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000328"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1922
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000032c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1923
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000032c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1924
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000032c"
              }
            ],
            "repeated": 0,
            "id": 1925
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000330"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1926
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1927
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1928
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000330"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1929
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000330"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1930
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000330"
              }
            ],
            "repeated": 0,
            "id": 1931
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1932
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1933
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1934
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1935
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1936
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1937
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xb0\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x907\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\xb0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00 X\\xc6\\x8eV\\x02\\x00\\x00\\xc0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x80\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1938
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1939
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 1940
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1941
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1942
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 1943
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1944
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000330"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 1945
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1946
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1947
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1948
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1949
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1950
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1951
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1952
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1953
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 1954
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 1955
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 1956
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1957
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 1958
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1959
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 1960
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1961
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1962
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1963
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1964
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1965
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1966
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1967
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1968
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1969
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1970
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000334"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1971
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000334"
              }
            ],
            "repeated": 0,
            "id": 1972
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1973
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 1974
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1975
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1976
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1977
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000334"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 1978
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1979
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000338"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1980
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1981
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1982
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000338"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1983
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1984
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 1985
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000338"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 1986
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1987
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1988
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1989
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1990
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1991
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1992
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1993
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1994
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1995
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1996
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 1997
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 1998
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 1999
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2000
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2001
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2002
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2003
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2004
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2005
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2006
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2007
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2008
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2009
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2010
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2011
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2012
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2013
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2014
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2015
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2016
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2017
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2018
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2019
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2020
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2021
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2022
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2023
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa01\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xad\\xc8\\x8eV\\x02\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00p\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\xc0\\x10\\x01\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2024
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2025
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2026
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2027
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000033c"
              }
            ],
            "repeated": 0,
            "id": 2028
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xf01\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00 \\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\xc0\\x10\\x01\\x80\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2029
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000033c"
              }
            ],
            "repeated": 0,
            "id": 2030
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000033c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2031
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2032
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2033
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000033c"
              }
            ],
            "repeated": 0,
            "id": 2034
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000033c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\"
              }
            ],
            "repeated": 0,
            "id": 2035
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2036
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2037
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2038
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2039
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2040
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2041
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2042
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2043
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2044
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2045
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00`1\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00h\\x02\\x00\\x00\\x00\\x00\\x00\\x00@\\xa3\\xc9\\x8eV\\x02\\x00\\x00\\xb0\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\xc0\\x10\\x01\\x80\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2046
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2047
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2048
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2049
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0ce9000"
              },
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2050
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2051
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2052
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "Data",
                "value": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2053
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2054
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2055
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000268"
              }
            ],
            "repeated": 0,
            "id": 2056
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2057
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2058
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2059
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2060
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2061
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "103"
              }
            ],
            "repeated": 1,
            "id": 2062
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2063
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000268"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\"
              }
            ],
            "repeated": 0,
            "id": 2064
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2065
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2066
          },
          {
            "timestamp": "2026-02-10 09:22:14,452",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "12"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2067
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2068
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2069
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2070
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2071
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2072
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1=0;\\x06\\x03U\\x04\\x03\\x134Microsoft Time Stamp Root Certificate Authority 20140\\x1e\\x17\r141022220857Z\\x17\r391022221519Z0\\x81\\x931\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nW"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2073
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2074
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2075
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2076
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2077
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2078
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1>0<\\x06\\x03U\\x04\\x03\\x135Microsoft ECC Product Root Certificate Authority 20180\\x1e\\x17\r180227204208Z\\x17\r430227205046Z0\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2079
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2080
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2081
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2082
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2083
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2084
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2085
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2086
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2087
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2088
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2089
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2090
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2091
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2092
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2093
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2094
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2095
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2096
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1907\\x06\\x03U\\x04\\x03\\x130Microsoft ECC TS Root Certificate Authority 20180\\x1e\\x17\r180227205134Z\\x17\r430227210012Z0\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashingt"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2097
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2098
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2099
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2100
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2101
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2102
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215724Z\\x17\r350623220401Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2103
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2104
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2105
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2106
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2107
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2108
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2109
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2110
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2111
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2112
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2113
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2114
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220528Z\\x17\r360322221304Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2115
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2116
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2117
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2118
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2119
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2120
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2121
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2122
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2123
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2124
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2125
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2126
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microso"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2127
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2128
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2129
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2130
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2131
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2132
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bD"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2133
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2134
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2135
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2136
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2137
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2138
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certi"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2139
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2140
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2141
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2142
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2143
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2144
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000340"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2145
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000340"
              }
            ],
            "repeated": 0,
            "id": 2146
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2147
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2148
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000340"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2149
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2150
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2151
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "11"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2152
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2153
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2154
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2155
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2156
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2157
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1$0\"\\x06\\x03U\\x04\\x03\\x13\\x1bDigiCert Assured ID Root CA0\\x1e\\x17\r061110000000Z\\x17\r311110000000Z0e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1$0\"\\x06\\x03U\\x04\\x03\\x13"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2158
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2159
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2160
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2161
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2162
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2163
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03\\x13\\x1eHotspot 2.0 Trust Root CA - 030\\x1e\\x17\r131208120000Z\\x17\r431208120000Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03\\x13\\x1eHotspot 2.0 Trust Root CA - 030\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2164
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2165
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2166
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2167
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2168
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2169
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r960129000000Z\\x17\r280801235959Z0_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certificatio"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2170
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2171
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2172
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2173
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2174
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2175
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root G30\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCe"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2176
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2177
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2178
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2179
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2180
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2181
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x830\\x82\\x03k\\xa0\\x03\\x02\\x01\\x02\\x02\\x0eE\\xe6\\xbb\\x03\\x833\\xc3\\x85eH\\xe6\\xffEQ0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R61\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x1e\\x17\r141210000000Z\\x17\r341210000000Z0L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R61\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x02\\x0f\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2182
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2183
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2184
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2185
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2186
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2187
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ece8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2188
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root CA0\\x1e\\x17\r061110000000Z\\x17\r311110000000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17Dig"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2189
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2190
          },
          {
            "timestamp": "2026-02-10 09:22:14,467",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2191
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2192
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2193
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2194
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x82\\x02\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2195
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2196
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2197
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2198
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2199
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2200
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04\\x00\\x00\\x00\\x00\\x01!XS\\x08\\xa20\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R31\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x1e\\x17\r090318100000Z\\x17\r290318100000Z0L1 0\\x1e\\x06\\x03U\\x04\\x0b\\x13\\x17GlobalSign Root CA - R31\\x130\\x11\\x06\\x03U\\x04\n\\x13\nGlobalSign1\\x130\\x11\\x06\\x03U\\x04\\x03\\x13\nGlobalSign0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2201
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2202
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2203
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2204
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2205
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2206
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu\\0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18DigiCert Trusted Root G40\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Di"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2207
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2208
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2209
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2210
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2211
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2212
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x03\\x8e0\\x82\\x02v\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x03:\\xf1\\xe6\\xa7\\x11\\xa9\\xa0\\xbb(d\\xb1\\x1d\t\\xfa\\xe50\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17DigiCert Global Root G20\\x1e\\x17\r130801120000Z\\x17\r380115120000Z0a1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03U\\x04\\x0b\\x13\\x10www.digicert.com1 0\\x1e\\x06\\x03U\\x04\\x03\\x13\\x17Dig"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2213
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2214
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2215
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2216
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2217
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2218
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecec000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2219
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1H0F\\x06\\x03U\\x04\\x03\\x13?Microsoft Identity Verification Root Certificate Authority 20200\\x1e\\x17\r200416183616Z\\x17\r450416184440Z0w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1H0F\\x06\\x03U\\x04\\x03\\x13"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 2220
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2221
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2222
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2223
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2224
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2225
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2226
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2227
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2228
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2229
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2230
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2231
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2232
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2233
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2234
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2235
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2236
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000344"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2237
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000344"
              }
            ],
            "repeated": 0,
            "id": 2238
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2239
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2240
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2241
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2242
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2243
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000344"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\"
              }
            ],
            "repeated": 0,
            "id": 2244
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2245
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000348"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2246
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2247
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2248
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000348"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2249
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2250
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2251
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000348"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2252
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000348"
              }
            ],
            "repeated": 0,
            "id": 2253
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2254
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2255
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000348"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2256
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2257
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2258
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2259
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2260
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2261
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2262
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2263
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000034c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2264
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2265
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2266
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2267
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2268
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2269
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2270
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2271
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa01\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00P\\x8b\\xce\\x8eV\\x02\\x00\\x00 \\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00p\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\xc0\\x10\\x01\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2272
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2273
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2274
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2275
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000350"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              }
            ],
            "repeated": 0,
            "id": 2276
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2277
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2278
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2279
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2280
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2281
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2282
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2283
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2284
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2285
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2286
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2287
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2288
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2289
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2290
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2291
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2292
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2293
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2294
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2295
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2296
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2297
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2298
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2299
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2300
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2301
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2302
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2303
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2304
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2305
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2306
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2307
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2308
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2309
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2310
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa00\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\xb4\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2311
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2312
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2313
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2314
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2315
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2316
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2317
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2318
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2319
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2320
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2321
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2322
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2323
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2324
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2325
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2326
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xb0\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xf06\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00P\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00 \\xb2\\xed\\x1c\\x97\\x00\\x00\\x00L\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2327
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2328
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2329
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2330
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000034c"
              }
            ],
            "repeated": 0,
            "id": 2331
          },
          {
            "timestamp": "2026-02-10 09:22:14,483",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000034c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2332
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2333
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2334
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2335
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2336
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2337
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2338
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2339
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000027c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2340
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2341
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2342
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 2343
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2344
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2345
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2346
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2347
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xac\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x00:\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00@\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xaa\\xc9\\x8eV\\x02\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xae\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xae\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2348
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2349
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2350
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000027c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 2351
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2352
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2353
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2354
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2355
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 2356
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2357
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2358
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 2359
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2360
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000264"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2361
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000264"
              }
            ],
            "repeated": 0,
            "id": 2362
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2363
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2364
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2365
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2366
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2367
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000264"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2368
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2369
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2370
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2371
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2372
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2373
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2374
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2375
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2376
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2377
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2378
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2379
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2380
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2381
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2382
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2383
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2384
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2385
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2386
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000258"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2387
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000258"
              }
            ],
            "repeated": 0,
            "id": 2388
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2389
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2390
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2391
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2392
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2393
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000258"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\"
              }
            ],
            "repeated": 0,
            "id": 2394
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2395
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2396
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2397
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2398
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2399
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2400
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2401
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000260"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2402
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2403
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2404
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2405
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2406
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2407
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2408
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2409
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2410
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2411
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2412
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2413
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2414
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2415
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2416
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2417
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x000\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00@\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xb4\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2418
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2419
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2420
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2421
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2422
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2423
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2424
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2425
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2426
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2427
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x000\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00@\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x10\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xb4\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2428
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2429
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2430
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2431
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2432
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2433
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2434
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2435
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2436
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2437
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2438
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2439
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2440
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2441
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2442
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "X\\xb0\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00P6\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xf0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xb1\\xed\\x1c\\x97\\x00\\x00\\x00`\\x02\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2443
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2444
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2445
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2446
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000260"
              }
            ],
            "repeated": 0,
            "id": 2447
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000260"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\"
              }
            ],
            "repeated": 0,
            "id": 2448
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2449
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2450
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 2451
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2452
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2453
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 2454
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2455
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000254"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2456
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 2457
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2458
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000254"
              }
            ],
            "repeated": 0,
            "id": 2459
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2460
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2461
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2462
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2463
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "H\\xac\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00`:\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xe0\\xad\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xad\\xc9\\x8eV\\x02\\x00\\x00\\xb0\\xad\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xad\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xad\\xed\\x1c\\x97\\x00\\x00\\x008\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2464
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2465
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2466
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000254"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 2467
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2468
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000254"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2469
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2470
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000025c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2471
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 2472
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2473
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000025c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2474
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 2475
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2476
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000025c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2477
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 2478
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2479
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2480
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2481
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2482
          },
          {
            "timestamp": "2026-02-10 09:22:14,499",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2483
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000025c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\"
              }
            ],
            "repeated": 0,
            "id": 2484
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2485
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2486
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2487
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2488
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2489
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2490
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2491
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2492
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2493
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2494
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2495
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2496
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2497
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2498
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2499
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2500
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2501
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2502
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000026c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2503
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000026c"
              }
            ],
            "repeated": 0,
            "id": 2504
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2505
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 2506
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2507
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2508
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2509
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000338"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x0000026c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\"
              }
            ],
            "repeated": 0,
            "id": 2510
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2511
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2512
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2513
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2514
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2515
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2516
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 2517
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000354"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2518
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              }
            ],
            "repeated": 0,
            "id": 2519
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              }
            ],
            "repeated": 0,
            "id": 2520
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2521
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2522
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2523
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2524
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2525
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2526
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2527
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000033c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2528
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000035c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2529
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2530
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2531
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00@2\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00(\\xd9\\xc8\\x8eV\\x02\\x00\\x00\\x00\\xb6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xd0\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00`\\x9e\\xc9\\x8eV\\x02\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2532
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2533
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2534
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000035c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              },
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots"
              }
            ],
            "repeated": 0,
            "id": 2535
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2536
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              },
              {
                "name": "ValueName",
                "value": "Certificates"
              },
              {
                "name": "Data",
                "value": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2537
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000360"
              }
            ],
            "repeated": 0,
            "id": 2538
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              }
            ],
            "repeated": 0,
            "id": 2539
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2540
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2541
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000368"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2542
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000368"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "12"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2543
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2544
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8"
              }
            ],
            "repeated": 0,
            "id": 2545
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2546
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2547
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2548
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecef000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2549
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2550
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352"
              }
            ],
            "repeated": 0,
            "id": 2551
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2552
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2553
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2554
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2555
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25"
              }
            ],
            "repeated": 0,
            "id": 2556
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2557
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2558
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2559
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2560
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85"
              }
            ],
            "repeated": 0,
            "id": 2561
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2562
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2563
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2564
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2565
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "31F9FC8BA3805986B721EA7295C65B3A44534274"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274"
              }
            ],
            "repeated": 0,
            "id": 2566
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2567
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2568
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2569
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2570
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5"
              }
            ],
            "repeated": 0,
            "id": 2571
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2572
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2573
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2574
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2575
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "7F88CD7223F3C813818C994614A89C99FA3B5247"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247"
              }
            ],
            "repeated": 0,
            "id": 2576
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2577
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2578
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2579
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2580
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE"
              }
            ],
            "repeated": 0,
            "id": 2581
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2582
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2583
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2584
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2585
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "92B46C76E13054E104F230517E6E504D43AB10B5"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5"
              }
            ],
            "repeated": 0,
            "id": 2586
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2587
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2588
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2589
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2590
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "A43489159A520F0D93D032CCAF37E7FE20A8B419"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419"
              }
            ],
            "repeated": 0,
            "id": 2591
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2592
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2593
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2594
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2595
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656"
              }
            ],
            "repeated": 0,
            "id": 2596
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2597
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2598
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2599
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2600
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000368"
              },
              {
                "name": "SubKey",
                "value": "CDD4EEAE6000AC7F40C3802C171E30148030C072"
              },
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072"
              }
            ],
            "repeated": 0,
            "id": 2601
          },
          {
            "timestamp": "2026-02-10 09:22:14,514",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2602
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2603
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000036c"
              }
            ],
            "repeated": 0,
            "id": 2604
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              }
            ],
            "repeated": 0,
            "id": 2605
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2606
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000368"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2607
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              }
            ],
            "repeated": 0,
            "id": 2608
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000268"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2609
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000368"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2610
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              }
            ],
            "repeated": 0,
            "id": 2611
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2612
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2613
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2614
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "11"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2615
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2616
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43"
              }
            ],
            "repeated": 0,
            "id": 2617
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2618
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2619
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2620
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2621
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "51501FBFCE69189D609CFAF140C576755DCC1FDF"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF"
              }
            ],
            "repeated": 0,
            "id": 2622
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2623
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2624
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2625
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2626
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "742C3192E607E424EB4549542BE1BBC53E6174E2"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2"
              }
            ],
            "repeated": 0,
            "id": 2627
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2628
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2629
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2630
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2631
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E"
              }
            ],
            "repeated": 0,
            "id": 2632
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2633
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2634
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2635
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2636
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1"
              }
            ],
            "repeated": 0,
            "id": 2637
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2638
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2639
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2640
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2641
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436"
              }
            ],
            "repeated": 0,
            "id": 2642
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2643
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2644
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2645
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2646
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "CABD2A79A1076A31F21D253635CB039D4329A5E8"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8"
              }
            ],
            "repeated": 0,
            "id": 2647
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2648
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2649
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2650
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2651
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "D69B561148F01C77C54578C10926DF5B856976AD"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD"
              }
            ],
            "repeated": 0,
            "id": 2652
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2653
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2654
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2655
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2656
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4"
              }
            ],
            "repeated": 0,
            "id": 2657
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2658
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2659
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2660
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2661
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4"
              }
            ],
            "repeated": 0,
            "id": 2662
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2663
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2664
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2665
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2666
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000374"
              },
              {
                "name": "SubKey",
                "value": "F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              },
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2"
              }
            ],
            "repeated": 0,
            "id": 2667
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2668
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2669
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000378"
              }
            ],
            "repeated": 0,
            "id": 2670
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 2671
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2672
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2673
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 2674
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000340"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2675
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000374"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2676
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              }
            ],
            "repeated": 0,
            "id": 2677
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 2678
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2679
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2680
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 2681
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000384"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000380"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\gpapi.dll"
              }
            ],
            "repeated": 0,
            "id": 2682
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000384"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf420000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00023000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2683
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf440000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2684
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2685
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2686
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2687
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2688
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2689
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000384"
              }
            ],
            "repeated": 0,
            "id": 2690
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 2691
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf433000"
              },
              {
                "name": "ModuleName",
                "value": "gpapi.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2692
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "35"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x06\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x007\\x01\\x00\\x00\n\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00_W\\x28eV\\x02\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2693
          },
          {
            "timestamp": "2026-02-10 09:22:14,530",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\gpapi"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedf420000"
              }
            ],
            "repeated": 0,
            "id": 2694
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\gpapi"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedf420000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedf423730"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2695
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2696
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee135b000"
              },
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2697
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              }
            ],
            "repeated": 0,
            "id": 2698
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              }
            ],
            "repeated": 0,
            "id": 2699
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "UserenvDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2700
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 2701
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 2702
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "GpSvcDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2703
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 2704
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 2705
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 2706
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 2707
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x0000037c"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000270"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 2708
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates"
              },
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates"
              }
            ],
            "repeated": 0,
            "id": 2709
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2710
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              },
              {
                "name": "Handle",
                "value": "0x000002c4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
              }
            ],
            "repeated": 0,
            "id": 2711
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002c4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2712
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2713
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 2714
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002c4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2715
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2716
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 2717
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002c4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000002c8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2718
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002c8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2719
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 2720
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              }
            ],
            "repeated": 0,
            "id": 2721
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2722
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2723
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002d8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2724
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 2725
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2726
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002d8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2727
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 2728
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000344"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2729
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002d8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2730
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              }
            ],
            "repeated": 0,
            "id": 2731
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2732
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2733
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2734
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 2735
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2736
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2737
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 2738
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000348"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2739
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2740
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              }
            ],
            "repeated": 0,
            "id": 2741
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2742
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2743
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2744
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 2745
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2746
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2747
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 2748
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000350"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2749
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000380"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2750
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              }
            ],
            "repeated": 0,
            "id": 2751
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2752
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2753
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2754
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2755
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2756
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2757
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2758
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2759
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2760
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2761
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2762
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2763
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2764
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2765
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2766
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2767
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2768
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 2769
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2770
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2771
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 2772
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000260"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2773
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000038c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2774
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              }
            ],
            "repeated": 0,
            "id": 2775
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics"
              }
            ],
            "repeated": 0,
            "id": 2776
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              },
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"
              }
            ],
            "repeated": 0,
            "id": 2777
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "ValueName",
                "value": "UserenvDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2778
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 2779
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\Windows\\System"
              },
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System"
              }
            ],
            "repeated": 0,
            "id": 2780
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "ValueName",
                "value": "GpSvcDebugLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel"
              }
            ],
            "repeated": 0,
            "id": 2781
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 2782
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 2783
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 2784
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 2785
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000394"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000398"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 2786
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a0"
              }
            ],
            "repeated": 0,
            "id": 2787
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 2788
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2789
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 2790
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 2791
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00@0\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xd0\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00\\x9c\\x03\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 2792
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 2793
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x0000039c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 2794
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000039c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates"
              },
              {
                "name": "Handle",
                "value": "0x000003a0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates"
              }
            ],
            "repeated": 0,
            "id": 2795
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000039c"
              }
            ],
            "repeated": 0,
            "id": 2796
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2797
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000254"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Handle",
                "value": "0x000003a4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              }
            ],
            "repeated": 0,
            "id": 2798
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2799
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2800
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a8"
              }
            ],
            "repeated": 0,
            "id": 2801
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2802
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2803
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a8"
              }
            ],
            "repeated": 0,
            "id": 2804
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003a4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003a8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2805
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003a8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2806
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a8"
              }
            ],
            "repeated": 0,
            "id": 2807
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              }
            ],
            "repeated": 0,
            "id": 2808
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2809
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2810
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2811
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2812
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2813
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2814
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2815
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000025c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2816
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2817
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              }
            ],
            "repeated": 0,
            "id": 2818
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              },
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
              }
            ],
            "repeated": 0,
            "id": 2819
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003b4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2820
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2821
          },
          {
            "timestamp": "2026-02-10 09:22:14,546",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2822
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003b4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2823
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2824
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2825
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003b4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003b8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2826
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003b8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2827
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b8"
              }
            ],
            "repeated": 0,
            "id": 2828
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              }
            ],
            "repeated": 0,
            "id": 2829
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2830
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2831
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2832
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2833
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2834
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2835
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2836
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000026c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2837
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003c0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2838
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              }
            ],
            "repeated": 0,
            "id": 2839
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2840
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2841
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003cc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2842
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              }
            ],
            "repeated": 0,
            "id": 2843
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2844
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003cc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2845
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              }
            ],
            "repeated": 0,
            "id": 2846
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000280"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003cc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2847
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003cc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2848
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              }
            ],
            "repeated": 0,
            "id": 2849
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000284"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Handle",
                "value": "0x000003d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              }
            ],
            "repeated": 0,
            "id": 2850
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d0"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2851
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2852
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2853
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d0"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2854
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2855
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2856
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003d0"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2857
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003d4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2858
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d4"
              }
            ],
            "repeated": 0,
            "id": 2859
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d0"
              }
            ],
            "repeated": 0,
            "id": 2860
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2861
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2862
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2863
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "3"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2864
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 2865
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003dc"
              },
              {
                "name": "SubKey",
                "value": "109F1CAED645BB78B3EA2B94C0697C740733031C"
              },
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C"
              }
            ],
            "repeated": 0,
            "id": 2866
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2867
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2868
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              }
            ],
            "repeated": 0,
            "id": 2869
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 2870
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003dc"
              },
              {
                "name": "SubKey",
                "value": "D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              },
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8"
              }
            ],
            "repeated": 0,
            "id": 2871
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2872
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2873
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              }
            ],
            "repeated": 0,
            "id": 2874
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 2875
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003dc"
              },
              {
                "name": "SubKey",
                "value": "FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              },
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4"
              }
            ],
            "repeated": 0,
            "id": 2876
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2877
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2878
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              }
            ],
            "repeated": 0,
            "id": 2879
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2880
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2881
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2882
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2883
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 2884
          },
          {
            "timestamp": "2026-02-10 09:22:14,561",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003dc"
              },
              {
                "name": "SubKey",
                "value": "A377D1B1C0538833035211F4083D00FECC414DAB"
              },
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB"
              }
            ],
            "repeated": 0,
            "id": 2885
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2886
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2887
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              }
            ],
            "repeated": 0,
            "id": 2888
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2889
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000250"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2890
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003dc"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2891
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              }
            ],
            "repeated": 0,
            "id": 2892
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              },
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
              }
            ],
            "repeated": 0,
            "id": 2893
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e0"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2894
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2895
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2896
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e0"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2897
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2898
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2899
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003e0"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2900
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2901
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e4"
              }
            ],
            "repeated": 0,
            "id": 2902
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              }
            ],
            "repeated": 0,
            "id": 2903
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2904
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2905
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2906
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2907
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2908
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2909
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2910
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000031c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2911
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2912
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003ec"
              }
            ],
            "repeated": 0,
            "id": 2913
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2914
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000354"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2915
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2916
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000035c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2917
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2918
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000368"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2919
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2920
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000374"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2921
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2922
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2923
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2924
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002d8"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2925
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2926
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002e4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2927
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2928
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000380"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2929
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2930
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000038c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2931
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2932
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003a4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2933
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2934
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b0"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2935
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2936
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003b4"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2937
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2938
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003c0"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2939
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2940
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003cc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2941
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2942
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003d0"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2943
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2944
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2945
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 2946
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003e0"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2947
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2948
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecf3000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2949
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000003f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2950
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2951
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f8"
              }
            ],
            "repeated": 0,
            "id": 2952
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000003f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2953
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2954
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f8"
              }
            ],
            "repeated": 0,
            "id": 2955
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000324"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000003f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2956
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000003f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2957
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003f8"
              }
            ],
            "repeated": 0,
            "id": 2958
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000328"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x000003fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 2959
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003fc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2960
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2961
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 2962
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003fc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2963
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2964
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 2965
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000003fc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000404"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2966
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000404"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2967
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000404"
              }
            ],
            "repeated": 0,
            "id": 2968
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000003fc"
              }
            ],
            "repeated": 0,
            "id": 2969
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2970
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2971
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2972
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 2973
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2974
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2975
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 2976
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000330"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2977
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2978
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000040c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 2979
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 2980
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000040c"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 2981
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2982
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 2983
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              }
            ],
            "repeated": 0,
            "id": 2984
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 2985
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000040c"
              }
            ],
            "repeated": 0,
            "id": 2986
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x00000410"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 2987
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2988
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2989
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 2990
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 2991
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2992
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 2993
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000410"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000414"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 2994
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000414"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 2995
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000414"
              }
            ],
            "repeated": 0,
            "id": 2996
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000410"
              }
            ],
            "repeated": 0,
            "id": 2997
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 2998
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 2999
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3000
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3001
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3002
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3003
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3004
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000334"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x0000041c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3005
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000041c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3006
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000041c"
              }
            ],
            "repeated": 0,
            "id": 3007
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3008
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3009
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3010
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3011
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3012
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3013
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3014
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000034c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000428"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3015
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000428"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3016
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000428"
              }
            ],
            "repeated": 0,
            "id": 3017
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000027c"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Handle",
                "value": "0x0000042c"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              }
            ],
            "repeated": 0,
            "id": 3018
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3019
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3020
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3021
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3022
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3023
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3024
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000042c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000430"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3025
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000430"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3026
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000430"
              }
            ],
            "repeated": 0,
            "id": 3027
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000042c"
              }
            ],
            "repeated": 0,
            "id": 3028
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3029
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3030
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3031
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3032
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3033
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3034
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3035
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000264"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000438"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3036
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000438"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3037
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000438"
              }
            ],
            "repeated": 0,
            "id": 3038
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              },
              {
                "name": "Handle",
                "value": "0x0000043c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
              }
            ],
            "repeated": 0,
            "id": 3039
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3040
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3041
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3042
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3043
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3044
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3045
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000043c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000440"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3046
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000440"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3047
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000440"
              }
            ],
            "repeated": 0,
            "id": 3048
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000043c"
              }
            ],
            "repeated": 0,
            "id": 3049
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3050
          },
          {
            "timestamp": "2026-02-10 09:22:14,577",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 3051
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3052
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3053
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 3054
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3055
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3056
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000258"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 3057
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000448"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 3058
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3059
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecf9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3060
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecfa000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3061
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3062
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertLastSyncTime"
              },
              {
                "name": "Data",
                "value": "\\xb3@\\xd9\\xb0n\\x9a\\xdc\\x01"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime"
              }
            ],
            "repeated": 0,
            "id": 3063
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3064
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3065
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000044c"
              }
            ],
            "repeated": 0,
            "id": 3066
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3067
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3068
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3069
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3070
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00@-\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00\\x08i\\xcd\\x8eV\\x02\\x00\\x00\\xa8f\\xcd\\x8eV\\x02\\x00\\x00\\xd0\\xb6\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xb6\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xd0\\xb6\\xed\\x1c\\x97\\x00\\x00\\x00H\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3071
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3072
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3073
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000448"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3074
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3075
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              },
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate"
              }
            ],
            "repeated": 0,
            "id": 3076
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertEncodedCtl"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl"
              }
            ],
            "repeated": 0,
            "id": 3077
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecfb000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3078
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              },
              {
                "name": "ValueName",
                "value": "DisallowedCertEncodedCtl"
              },
              {
                "name": "Data",
                "value": "0\\x82\\x17\\xcc\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x17\\xbd0\\x82\\x17\\xb9\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x000\\x82\\x08(\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x08\\x190\\x82\\x08\\x150\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x07\\xa00\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<\\xac\\xeejW0\\x12\\x04\\x10\\x1e%\\xf2N\\xdf"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl"
              }
            ],
            "repeated": 0,
            "id": 3079
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3080
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000448"
              }
            ],
            "repeated": 0,
            "id": 3081
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ecff000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3082
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed01000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3083
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 3084
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "AutoFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags"
              }
            ],
            "repeated": 0,
            "id": 3085
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed03000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3086
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed06000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3087
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "DisableAutoFlushProcessNameList"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList"
              }
            ],
            "repeated": 0,
            "id": 3088
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "AutoFlushFirstDeltaSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds"
              }
            ],
            "repeated": 0,
            "id": 3089
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029c"
              },
              {
                "name": "ValueName",
                "value": "AutoFlushNextDeltaSeconds"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds"
              }
            ],
            "repeated": 0,
            "id": 3090
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 3091
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3092
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3093
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3094
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3095
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3096
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllCreateIndirectData"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData"
              }
            ],
            "repeated": 0,
            "id": 3097
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 3098
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{000C10F1-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 3099
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3100
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\MSISIP.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3101
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "MsiSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3102
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3103
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3104
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3105
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3106
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3107
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3108
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3109
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 3110
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}"
              }
            ],
            "repeated": 0,
            "id": 3111
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3112
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3113
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3114
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3115
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 3116
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}"
              }
            ],
            "repeated": 0,
            "id": 3117
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3118
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3119
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "AppxBundleSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3120
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3121
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 3122
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}"
              }
            ],
            "repeated": 0,
            "id": 3123
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3124
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3125
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3126
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3127
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3128
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{1A610570-38CE-11D4-A2A3-00104BD35090}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}"
              }
            ],
            "repeated": 0,
            "id": 3129
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3130
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\wshext.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3131
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3132
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3133
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 3134
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}"
              }
            ],
            "repeated": 0,
            "id": 3135
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3136
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3137
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "P7SipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3138
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3139
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 3140
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}"
              }
            ],
            "repeated": 0,
            "id": 3141
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "112"
              }
            ],
            "repeated": 0,
            "id": 3142
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pwrshsip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3143
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "PsCreateHash"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3144
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3145
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3146
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3147
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3148
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3149
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3150
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3151
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3152
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3153
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3154
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3155
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipCreateHash"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3156
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3157
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3158
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3159
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3160
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3161
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3162
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3163
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3164
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3165
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3166
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3167
          },
          {
            "timestamp": "2026-02-10 09:22:14,592",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3168
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3169
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3170
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3171
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3172
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3173
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3174
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3175
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 3176
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}"
              }
            ],
            "repeated": 0,
            "id": 3177
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "64"
              }
            ],
            "repeated": 0,
            "id": 3178
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3179
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3180
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3181
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 3182
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}"
              }
            ],
            "repeated": 0,
            "id": 3183
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3184
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\AppxSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3185
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EappxBundleSipCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3186
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3187
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3188
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3189
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3190
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3191
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3192
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3193
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3194
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3195
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3196
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3197
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3198
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3199
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\"
              }
            ],
            "repeated": 0,
            "id": 3200
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3201
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3202
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3203
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3204
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllCreateIndirectData"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllCreateIndirectData"
              }
            ],
            "repeated": 0,
            "id": 3205
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3206
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3207
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3208
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477d80"
              }
            ],
            "repeated": 0,
            "id": 3209
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3210
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3211
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3212
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObjectEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObjectEx"
              }
            ],
            "repeated": 0,
            "id": 3213
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3214
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3215
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3216
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObjectEx"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx"
              }
            ],
            "repeated": 0,
            "id": 3217
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.1.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3218
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.1.1"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3219
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3220
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3221
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssReceiptEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3222
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3223
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1"
              }
            ],
            "repeated": 0,
            "id": 3224
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.1"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1"
              }
            ],
            "repeated": 0,
            "id": 3225
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3226
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3227
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssReceiptRequestEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3228
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3229
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.11"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11"
              }
            ],
            "repeated": 0,
            "id": 3230
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.11"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11"
              }
            ],
            "repeated": 0,
            "id": 3231
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3232
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3233
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssKeyExchPreferenceEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3234
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3235
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.12"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12"
              }
            ],
            "repeated": 0,
            "id": 3236
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.12"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12"
              }
            ],
            "repeated": 0,
            "id": 3237
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3238
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3239
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssSignCertificateEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3240
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3241
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2"
              }
            ],
            "repeated": 0,
            "id": 3242
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.2"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2"
              }
            ],
            "repeated": 0,
            "id": 3243
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3244
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3245
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssSecurityLabelEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3246
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3247
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3"
              }
            ],
            "repeated": 0,
            "id": 3248
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.3"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3"
              }
            ],
            "repeated": 0,
            "id": 3249
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3250
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3251
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssMLHistoryEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3252
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3253
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "1.2.840.113549.1.9.16.2.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4"
              }
            ],
            "repeated": 0,
            "id": 3254
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.2.840.113549.1.9.16.2.4"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4"
              }
            ],
            "repeated": 0,
            "id": 3255
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3256
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\inetcomm.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3257
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EssContentHintEncodeEx"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3258
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3259
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\"
              }
            ],
            "repeated": 0,
            "id": 3260
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3261
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3262
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3263
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3264
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3265
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3266
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3267
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObject"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObject"
              }
            ],
            "repeated": 0,
            "id": 3268
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3269
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3270
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000450"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3271
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CryptDllEncodeObject"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject"
              }
            ],
            "repeated": 0,
            "id": 3272
          },
          {
            "timestamp": "2026-02-10 09:22:14,608",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "#2000"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000"
              }
            ],
            "repeated": 0,
            "id": 3273
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2000"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000"
              }
            ],
            "repeated": 0,
            "id": 3274
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 3275
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3276
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpAgencyInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3277
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3278
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "#2001"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001"
              }
            ],
            "repeated": 0,
            "id": 3279
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2001"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001"
              }
            ],
            "repeated": 0,
            "id": 3280
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3281
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3282
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcMinimalCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3283
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3284
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "#2002"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002"
              }
            ],
            "repeated": 0,
            "id": 3285
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2002"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002"
              }
            ],
            "repeated": 0,
            "id": 3286
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 3287
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3288
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcFinancialCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3289
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3290
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "#2003"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003"
              }
            ],
            "repeated": 0,
            "id": 3291
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2003"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003"
              }
            ],
            "repeated": 0,
            "id": 3292
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3293
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3294
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcIndirectDataContentEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3295
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3296
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "#2004"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004"
              }
            ],
            "repeated": 0,
            "id": 3297
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2004"
              },
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004"
              }
            ],
            "repeated": 0,
            "id": 3298
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000045c"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3299
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3300
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3301
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3302
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "#2005"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005"
              }
            ],
            "repeated": 0,
            "id": 3303
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2005"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005"
              }
            ],
            "repeated": 0,
            "id": 3304
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3305
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3306
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3307
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3308
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "#2006"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006"
              }
            ],
            "repeated": 0,
            "id": 3309
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2006"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006"
              }
            ],
            "repeated": 0,
            "id": 3310
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 3311
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3312
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcStatementTypeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3313
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3314
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": "#2007"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007"
              }
            ],
            "repeated": 0,
            "id": 3315
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2007"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007"
              }
            ],
            "repeated": 0,
            "id": 3316
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3317
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3318
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpOpusInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3319
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3320
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "8"
              },
              {
                "name": "Name",
                "value": "#2008"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008"
              }
            ],
            "repeated": 0,
            "id": 3321
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2008"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008"
              }
            ],
            "repeated": 0,
            "id": 3322
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3323
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3324
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3325
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3326
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "9"
              },
              {
                "name": "Name",
                "value": "#2009"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009"
              }
            ],
            "repeated": 0,
            "id": 3327
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2009"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009"
              }
            ],
            "repeated": 0,
            "id": 3328
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3329
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3330
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3331
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3332
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "10"
              },
              {
                "name": "Name",
                "value": "#2010"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010"
              }
            ],
            "repeated": 0,
            "id": 3333
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2010"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010"
              }
            ],
            "repeated": 0,
            "id": 3334
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 3335
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3336
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1IntentToSealAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3337
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3338
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "11"
              },
              {
                "name": "Name",
                "value": "#2011"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011"
              }
            ],
            "repeated": 0,
            "id": 3339
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2011"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011"
              }
            ],
            "repeated": 0,
            "id": 3340
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3341
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3342
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingSignatureAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3343
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3344
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "12"
              },
              {
                "name": "Name",
                "value": "#2012"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012"
              }
            ],
            "repeated": 0,
            "id": 3345
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2012"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012"
              }
            ],
            "repeated": 0,
            "id": 3346
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3347
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3348
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingTimestampAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3349
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3350
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "13"
              },
              {
                "name": "Name",
                "value": "#2130"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130"
              }
            ],
            "repeated": 0,
            "id": 3351
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2130"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130"
              }
            ],
            "repeated": 0,
            "id": 3352
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "48"
              }
            ],
            "repeated": 0,
            "id": 3353
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3354
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSigInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3355
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3356
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "14"
              },
              {
                "name": "Name",
                "value": "#2221"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221"
              }
            ],
            "repeated": 0,
            "id": 3357
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2221"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221"
              }
            ],
            "repeated": 0,
            "id": 3358
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 3359
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3360
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatNameValueEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3361
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3362
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "15"
              },
              {
                "name": "Name",
                "value": "#2222"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222"
              }
            ],
            "repeated": 0,
            "id": 3363
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2222"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222"
              }
            ],
            "repeated": 0,
            "id": 3364
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3365
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3366
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3367
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3368
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "16"
              },
              {
                "name": "Name",
                "value": "#2223"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223"
              }
            ],
            "repeated": 0,
            "id": 3369
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "#2223"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223"
              }
            ],
            "repeated": 0,
            "id": 3370
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3371
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3372
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfo2Encode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3373
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3374
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "17"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1"
              }
            ],
            "repeated": 0,
            "id": 3375
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1"
              }
            ],
            "repeated": 0,
            "id": 3376
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "52"
              }
            ],
            "repeated": 0,
            "id": 3377
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3378
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatNameValueEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3379
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3380
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "18"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2"
              }
            ],
            "repeated": 0,
            "id": 3381
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.2"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2"
              }
            ],
            "repeated": 0,
            "id": 3382
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3383
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3384
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3385
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3386
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "19"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.12.2.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3"
              }
            ],
            "repeated": 0,
            "id": 3387
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.12.2.3"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3"
              }
            ],
            "repeated": 0,
            "id": 3388
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3389
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3390
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1CatMemberInfo2Encode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3391
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3392
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "20"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.16.1.1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3393
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.16.1.1"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1"
              }
            ],
            "repeated": 0,
            "id": 3394
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3395
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptdlg.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3396
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EncodeAttrSequence"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3397
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3398
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "21"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.16.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4"
              }
            ],
            "repeated": 0,
            "id": 3399
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.16.4"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4"
              }
            ],
            "repeated": 0,
            "id": 3400
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "66"
              }
            ],
            "repeated": 0,
            "id": 3401
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\cryptdlg.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3402
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EncodeRecipientID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3403
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3404
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "22"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.10"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10"
              }
            ],
            "repeated": 0,
            "id": 3405
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.10"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10"
              }
            ],
            "repeated": 0,
            "id": 3406
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "58"
              }
            ],
            "repeated": 0,
            "id": 3407
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3408
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpAgencyInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3409
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3410
          },
          {
            "timestamp": "2026-02-10 09:22:14,624",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "23"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.11"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11"
              }
            ],
            "repeated": 0,
            "id": 3411
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.11"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11"
              }
            ],
            "repeated": 0,
            "id": 3412
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "60"
              }
            ],
            "repeated": 0,
            "id": 3413
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3414
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcStatementTypeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3415
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3416
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "24"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.12"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12"
              }
            ],
            "repeated": 0,
            "id": 3417
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.12"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12"
              }
            ],
            "repeated": 0,
            "id": 3418
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "54"
              }
            ],
            "repeated": 0,
            "id": 3419
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3420
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSpOpusInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3421
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3422
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "25"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.15"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15"
              }
            ],
            "repeated": 0,
            "id": 3423
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.15"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15"
              }
            ],
            "repeated": 0,
            "id": 3424
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "56"
              }
            ],
            "repeated": 0,
            "id": 3425
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3426
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3427
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3428
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "26"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.20"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20"
              }
            ],
            "repeated": 0,
            "id": 3429
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.20"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20"
              }
            ],
            "repeated": 0,
            "id": 3430
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3431
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3432
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3433
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3434
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "27"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.25"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25"
              }
            ],
            "repeated": 0,
            "id": 3435
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.25"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25"
              }
            ],
            "repeated": 0,
            "id": 3436
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3437
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3438
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3439
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3440
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "28"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.26"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26"
              }
            ],
            "repeated": 0,
            "id": 3441
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.26"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26"
              }
            ],
            "repeated": 0,
            "id": 3442
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3443
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3444
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcMinimalCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3445
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3446
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "29"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.27"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27"
              }
            ],
            "repeated": 0,
            "id": 3447
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.27"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27"
              }
            ],
            "repeated": 0,
            "id": 3448
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "76"
              }
            ],
            "repeated": 0,
            "id": 3449
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3450
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcFinancialCriteriaInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3451
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3452
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "30"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.28"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28"
              }
            ],
            "repeated": 0,
            "id": 3453
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.28"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28"
              }
            ],
            "repeated": 0,
            "id": 3454
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "42"
              }
            ],
            "repeated": 0,
            "id": 3455
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3456
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3457
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3458
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "31"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.30"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30"
              }
            ],
            "repeated": 0,
            "id": 3459
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.30"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30"
              }
            ],
            "repeated": 0,
            "id": 3460
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "48"
              }
            ],
            "repeated": 0,
            "id": 3461
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3462
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcSigInfoEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3463
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3464
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "32"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.1.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4"
              }
            ],
            "repeated": 0,
            "id": 3465
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.1.4"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4"
              }
            ],
            "repeated": 0,
            "id": 3466
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "72"
              }
            ],
            "repeated": 0,
            "id": 3467
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3468
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SpcIndirectDataContentEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3469
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3470
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "33"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.2"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2"
              }
            ],
            "repeated": 0,
            "id": 3471
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.2"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2"
              }
            ],
            "repeated": 0,
            "id": 3472
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "70"
              }
            ],
            "repeated": 0,
            "id": 3473
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3474
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1IntentToSealAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3475
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3476
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "34"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.3"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3"
              }
            ],
            "repeated": 0,
            "id": 3477
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.3"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3"
              }
            ],
            "repeated": 0,
            "id": 3478
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3479
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3480
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingSignatureAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3481
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3482
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "35"
              },
              {
                "name": "Name",
                "value": "1.3.6.1.4.1.311.2.4.4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4"
              }
            ],
            "repeated": 0,
            "id": 3483
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "1.3.6.1.4.1.311.2.4.4"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4"
              }
            ],
            "repeated": 0,
            "id": 3484
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "78"
              }
            ],
            "repeated": 0,
            "id": 3485
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3486
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "WVTAsn1SealingTimestampAttributeEncode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3487
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 3488
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "Index",
                "value": "36"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\"
              }
            ],
            "repeated": 0,
            "id": 3489
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 3490
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 3491
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3492
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3493
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WVTAsn1SpcLinkEncode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147e0d0"
              }
            ],
            "repeated": 0,
            "id": 3494
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3495
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3496
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 3497
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3498
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config"
              }
            ],
            "repeated": 0,
            "id": 3499
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 3500
          },
          {
            "timestamp": "2026-02-10 09:22:14,639",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 3501
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "Buffer",
                "value": ";-------------------------------------------------------------------------\r\n; Vsdatant.INF -- NDIS Usermode I/O Driver\r\n;\r\n; Copyright (c) Check Point.  All rights reserved.\r\n;-------------------------------------------------------------------------\r\n[vers"
              },
              {
                "name": "Length",
                "value": "3729"
              }
            ],
            "repeated": 0,
            "id": 3502
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3503
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbb10"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3504
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3505
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3506
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptCreateHash",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Algid",
                "value": "0x00008004",
                "pretty_value": "SHA1"
              },
              {
                "name": "CryptKey",
                "value": "0x00000000"
              },
              {
                "name": "Hash object",
                "value": "0x2568ecf1a40"
              }
            ],
            "repeated": 0,
            "id": 3507
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptHashData",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CryptHash",
                "value": "0x2568ecf1a40"
              },
              {
                "name": "Buffer",
                "value": ";-------------------------------------------------------------------------\r\n; Vsdatant.INF -- NDIS Usermode I/O Driver\r\n;\r\n; Copyright (c) Check Point.  All rights reserved.\r\n;-------------------------------------------------------------------------\r\n[version]\r\nSignature       = \"$Windows NT$\"\r\nClass       = NetService\r\nClassGUID   = {4D36E974-E325-11CE-BFC1-08002BE10318}\r\nProvider        = %Ckpt%\r\nCatalogFile = Vsdatant.cat\r\nDriverVer = 11/16/2022,14.39.35.110\r\n\r\n[Manufacturer]\r\n%Ckpt%=CKPT,NTx86,NTamd64\r\n\r\n[CKPT]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n[CKPT.NTx86]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n[CKPT.NTamd64]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n;-------------------------------------------------------------------------\r\n; Installation Section\r\n;-------------------------------------------------------------------------\r\n[Install]\r\nAddReg=Inst_Ndi\r\nCharacteristics=0x40028 ; NCF_LW_FILTER | NCF_NOT_USER_REMOVABLE | NCF_HIDDEN\r\nNetCfgInstanceId=\"{AC30BFB5-834B-46d2-B912-6CE71684EB2D}\"\r\nCopyfiles = Vsdatant.copyfiles.sys\r\n\r\n[SourceDisksNames]\r\n1=%Vsdatant_Desc%,\"\",,\r\n\r\n[SourceDisksFiles]\r\nvsdatant.sys=1\r\n\r\n[DestinationDirs]\r\nDefaultDestDir=12\r\nVsdatant.copyfiles.sys=12\r\n\r\n[Vsdatant.copyfiles.sys]\r\nvsdatant.sys,,,2\r\n\r\n\r\n;-------------------------------------------------------------------------\r\n; Ndi installation support\r\n;-------------------------------------------------------------------------\r\n[Inst_Ndi]\r\nHKR, Ndi,Service,,\"Vsdatant\"\r\nHKR, Ndi,CoServices,0x00010000,\"Vsdatant\"\r\nHKR, Ndi,HelpText,,%Vsdatant_HelpText%\r\nHKR, Ndi,FilterClass,, compression\r\nHKR, Ndi,FilterType,0x00010001,0x00000002\r\nHKR, Ndi\\Interfaces,UpperRange,,\"noupper\"\r\nHKR, Ndi\\Interfaces,LowerRange,,\"nolower\"\r\nHKR, Ndi\\Interfaces, FilterMediaTypes,,\"ethernet, wan, wlan, jnprncva, ppip, bluetooth\"\r\nHKR, Ndi,FilterRunType, 0x00010001, 2 \r\n\r\n;-------------------------------------------------------------------------\r\n; Service installation support\r\n;-------------------------------------------------------------------------\r\n[Install.Servic"
              },
              {
                "name": "Length",
                "value": "3729"
              }
            ],
            "repeated": 0,
            "id": 3508
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3509
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3510
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3511
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3512
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 3513
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbeb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3514
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 3515
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3516
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3517
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3518
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3519
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005\\x006\\x003\\x007\\x004\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3520
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04Jc\\x006\\x00f\\x00a\\x00e\\x001\\x00d\\x005\\x00-\\x003\\x007\\x00b\\x005\\x00-\\x004\\x001\\x007\\x00b\\x00-\\x00a\\x00f\\x00b\\x005\\x00-\\x00a\\x004\\x00a\\x001\\x00a\\x00f\\x001\\x00b\\x009\\x00b\\x009\\x005\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3521
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3522
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3523
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3524
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x16m\\x00s\\x00_\\x00n\\x00d\\x00i\\x00s\\x00l\\x00w\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3525
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3526
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3527
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f2b8000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3528
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3529
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "04\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\"v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00_\\x00o\\x00p\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3530
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3531
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed09000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3532
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3533
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3534
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3535
          },
          {
            "timestamp": "2026-02-10 09:22:14,655",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3536
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3537
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d21b",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14\\x1a7]\\xf8|\\xde\\x88\\xf6L\\xc9>i\\xb2\\xda\\xba\\x80\\xb5\\xb93`"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3538
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5d85",
            "parentcaller": "0x7ff70a39d21b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 3539
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3540
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3541
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3542
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3543
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3544
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3545
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3546
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3547
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3548
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3549
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3550
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 3551
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 3552
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 3553
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3554
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3555
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004bc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004b8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 3556
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004bc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda420"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3557
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3558
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3559
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3560
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 3561
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3562
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed12000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3563
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3564
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed13000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3565
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 3566
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 3567
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3568
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3569
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3570
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3571
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3572
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3573
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3574
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3575
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3576
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3577
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3578
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3579
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3580
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3581
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3582
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3583
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3584
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3585
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3586
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3587
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3588
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3589
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3590
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3591
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3592
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3593
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3594
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3595
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3596
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3597
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3598
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 1,
            "id": 3599
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 14,
            "id": 3600
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 3601
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3602
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3603
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 3604
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 7,
            "id": 3605
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 3,
            "id": 3606
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3607
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3608
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3609
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3610
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3611
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3612
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3613
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 3,
            "id": 3614
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3615
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3616
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3617
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3618
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3619
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3620
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3621
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3622
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3623
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 3624
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 3625
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39ceba",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 3626
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3627
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3628
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a39cf7d",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3629
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3630
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3631
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b5722",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3632
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5586",
            "parentcaller": "0x7ff70a3b57a1",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\xfc\\xbf\\x9a%\\xa7P\\xceG\\xaf\\x08h\\xc9\\xa7\\xd73f\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3633
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 3634
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 3635
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b450f",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3636
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3637
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3638
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xf1^\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3639
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3640
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3641
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3642
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3643
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3644
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3645
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3646
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "1_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3647
          },
          {
            "timestamp": "2026-02-10 09:22:14,671",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "1_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3648
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4538",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3649
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3650
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x001_\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3651
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3652
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3653
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00006000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3654
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3655
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3656
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 3657
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3658
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "h_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3659
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "h_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3660
          },
          {
            "timestamp": "2026-02-10 09:22:14,686",
            "thread_id": "3424",
            "caller": "0x7ff70a3b455c",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3661
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3662
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00h_\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3663
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "h_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3664
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3665
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3666
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3667
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3668
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3669
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3670
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3671
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3672
          },
          {
            "timestamp": "2026-02-10 09:22:14,702",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4584",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3673
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3674
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3675
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xeb_\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3676
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 3677
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3678
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "n`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3679
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3680
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 3681
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "n`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3682
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "n`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3683
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "n`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3684
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b45ae",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 3685
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4607",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 3686
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4607",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 3687
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b46f8",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 3688
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b46f8",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 3689
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b475f",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3690
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3691
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 3692
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda650"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3693
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3694
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3695
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 3696
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3697
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3698
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3699
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3700
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 3701
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 3702
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "Buffer",
                "value": ";-------------------------------------------------------------------------\r\n; Vsdatant.INF -- NDIS Usermode I/O Driver\r\n;\r\n; Copyright (c) Check Point.  All rights reserved.\r\n;-------------------------------------------------------------------------\r\n[vers"
              },
              {
                "name": "Length",
                "value": "3729"
              }
            ],
            "repeated": 0,
            "id": 3703
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3704
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda4d0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3705
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptCreateHash",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Algid",
                "value": "0x00008004",
                "pretty_value": "SHA1"
              },
              {
                "name": "CryptKey",
                "value": "0x00000000"
              },
              {
                "name": "Hash object",
                "value": "0x2568ecf1b20"
              }
            ],
            "repeated": 0,
            "id": 3706
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptHashData",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CryptHash",
                "value": "0x2568ecf1b20"
              },
              {
                "name": "Buffer",
                "value": ";-------------------------------------------------------------------------\r\n; Vsdatant.INF -- NDIS Usermode I/O Driver\r\n;\r\n; Copyright (c) Check Point.  All rights reserved.\r\n;-------------------------------------------------------------------------\r\n[version]\r\nSignature       = \"$Windows NT$\"\r\nClass       = NetService\r\nClassGUID   = {4D36E974-E325-11CE-BFC1-08002BE10318}\r\nProvider        = %Ckpt%\r\nCatalogFile = Vsdatant.cat\r\nDriverVer = 11/16/2022,14.39.35.110\r\n\r\n[Manufacturer]\r\n%Ckpt%=CKPT,NTx86,NTamd64\r\n\r\n[CKPT]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n[CKPT.NTx86]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n[CKPT.NTamd64]\r\n%Vsdatant_Desc%=Install, MS_NdisLwf\r\n\r\n;-------------------------------------------------------------------------\r\n; Installation Section\r\n;-------------------------------------------------------------------------\r\n[Install]\r\nAddReg=Inst_Ndi\r\nCharacteristics=0x40028 ; NCF_LW_FILTER | NCF_NOT_USER_REMOVABLE | NCF_HIDDEN\r\nNetCfgInstanceId=\"{AC30BFB5-834B-46d2-B912-6CE71684EB2D}\"\r\nCopyfiles = Vsdatant.copyfiles.sys\r\n\r\n[SourceDisksNames]\r\n1=%Vsdatant_Desc%,\"\",,\r\n\r\n[SourceDisksFiles]\r\nvsdatant.sys=1\r\n\r\n[DestinationDirs]\r\nDefaultDestDir=12\r\nVsdatant.copyfiles.sys=12\r\n\r\n[Vsdatant.copyfiles.sys]\r\nvsdatant.sys,,,2\r\n\r\n\r\n;-------------------------------------------------------------------------\r\n; Ndi installation support\r\n;-------------------------------------------------------------------------\r\n[Inst_Ndi]\r\nHKR, Ndi,Service,,\"Vsdatant\"\r\nHKR, Ndi,CoServices,0x00010000,\"Vsdatant\"\r\nHKR, Ndi,HelpText,,%Vsdatant_HelpText%\r\nHKR, Ndi,FilterClass,, compression\r\nHKR, Ndi,FilterType,0x00010001,0x00000002\r\nHKR, Ndi\\Interfaces,UpperRange,,\"noupper\"\r\nHKR, Ndi\\Interfaces,LowerRange,,\"nolower\"\r\nHKR, Ndi\\Interfaces, FilterMediaTypes,,\"ethernet, wan, wlan, jnprncva, ppip, bluetooth\"\r\nHKR, Ndi,FilterRunType, 0x00010001, 2 \r\n\r\n;-------------------------------------------------------------------------\r\n; Service installation support\r\n;-------------------------------------------------------------------------\r\n[Install.Servic"
              },
              {
                "name": "Length",
                "value": "3729"
              }
            ],
            "repeated": 0,
            "id": 3707
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3708
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b48d1",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3709
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 3710
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3711
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3712
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3713
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3714
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3715
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3716
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3717
          },
          {
            "timestamp": "2026-02-10 09:22:14,717",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3718
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3719
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3720
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3721
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverFinalPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3722
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3723
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3724
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3725
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverInitializePolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3726
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3727
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3728
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3729
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3730
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3731
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3732
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3733
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3734
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3735
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3736
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3737
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3738
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3739
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3740
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3741
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3742
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "DriverCleanupPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3743
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3744
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ad60"
              }
            ],
            "repeated": 0,
            "id": 3745
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverFinalPolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147b880"
              }
            ],
            "repeated": 0,
            "id": 3746
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverInitializePolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1471a80"
              }
            ],
            "repeated": 0,
            "id": 3747
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1478770"
              }
            ],
            "repeated": 0,
            "id": 3748
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ccc0"
              }
            ],
            "repeated": 0,
            "id": 3749
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147efa0"
              }
            ],
            "repeated": 0,
            "id": 3750
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "DriverCleanupPolicy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147e970"
              }
            ],
            "repeated": 0,
            "id": 3751
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3752
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 3753
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptAcquireContextA",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": "Microsoft Enhanced RSA and AES Cryptographic Provider"
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 3754
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3755
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0\\xa2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0v+\\x8fV\\x02\\x00\\x00\\xae-E\\xe0\\xfe\\x7f\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00d\\xd2y\\x8fV\\x02\\x00\\x00\\x08\\xa4\\xed\\x1c\\x97\\x00\\x00\\x00p\\xb2H\\xc0\\xfe\\x7f\\x00\\x00\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x81+\\x8fV\\x02\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x03+\\x8fV\\x02\\x00\\x00P\\x01+\\x8fV\\x02\\x00\\x00\\x00\\x00\\xb9\\xdf\\xfe\\x7f\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80A\\xce\\x8eV\\x02\\x00\\x00\\x048+\\x8fV\\x02\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb9\\x00\\xae\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x00\\x00\\x00\\x00\\x00\\x00\\xb9\\xdf\\xfe\\x7f\\x00\\x00\\x9a\\x00\\xae\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x80\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3756
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3757
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004d4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3758
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d4"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 3759
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 3760
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "State"
              },
              {
                "name": "Data",
                "value": "146432"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State"
              }
            ],
            "repeated": 0,
            "id": 3761
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3762
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3763
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0\\xa2\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\xa1[I\\xe3\\xfe\\x7f\\x00\\x00\\x10\\x00\\x00\\x00V\\x02\\x00\\x00\\xa9\\xa4\\x00\r\\x97\\x00\\x00\\x00\\xb0=\\xae\\xf5<4\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x87\\x00\\x9c\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00d\\xd2y\\x8fV\\x02\\x00\\x00h\\xa4\\xed\\x1c\\x97\\x00\\x00\\x00p\\xb2H\\xc0\\xfe\\x7f\\x00\\x00\\xca\\xac\\x00f\\xfe\\x7f\\x00\\x00\\xc8\\xa7j\\xc0\\xfe\\x7f\\x00\\x00\\x81\\x04G\\xc0\\xfe\\x7f\\x00\\x00\\xa0\\xa6\\xed\\x1c\\x97\\x00\\x00\\x00\\xb0\\xfb}\\x8fV\\x02\\x00\\x00\\xc0\\xfb}\\x8fV\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00o\\xe2J\\xe3\\xfe\\x7f\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3764
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3765
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3766
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d8"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Internet Explorer\\Security"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\Security"
              }
            ],
            "repeated": 0,
            "id": 3767
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3768
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3769
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3770
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xa1\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xf0\\x01\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xb8K\\xe1\\xfe\\x7f\\x00\\x00P\\xa3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x98\\xa7\\xed\\x1c\\x97\\x00\\x00\\x00 \\xa3\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xa3\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00 \\xa3\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3771
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3772
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 3773
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004d8"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3774
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3775
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 3776
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3777
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3778
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 3779
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3780
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3781
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3782
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3783
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3784
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3785
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3786
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubAuthenticode"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3787
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3788
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3789
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3790
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubInitialize"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3791
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3792
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3793
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3794
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3795
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3796
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3797
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3798
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3799
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3800
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3801
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3802
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3803
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3804
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3805
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3806
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$DLL"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL"
              }
            ],
            "repeated": 0,
            "id": 3807
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "ValueName",
                "value": "$Function"
              },
              {
                "name": "Data",
                "value": "SoftpubCleanup"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function"
              }
            ],
            "repeated": 0,
            "id": 3808
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 3809
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WintrustCertificateTrust"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ad60"
              }
            ],
            "repeated": 0,
            "id": 3810
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubAuthenticode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147be20"
              }
            ],
            "repeated": 0,
            "id": 3811
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubInitialize"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147c4d0"
              }
            ],
            "repeated": 0,
            "id": 3812
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadMessage"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1478770"
              }
            ],
            "repeated": 0,
            "id": 3813
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubLoadSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147ccc0"
              }
            ],
            "repeated": 0,
            "id": 3814
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCheckCert"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147efa0"
              }
            ],
            "repeated": 0,
            "id": 3815
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "SoftpubCleanup"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147f3b0"
              }
            ],
            "repeated": 0,
            "id": 3816
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 3817
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": false,
            "return": "0xffffffff80430006",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "143"
              }
            ],
            "repeated": 0,
            "id": 3818
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryFullAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 3819
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3820
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3821
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 3822
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda310"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3823
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3824
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 3825
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffff80000005",
            "pretty_return": "BUFFER_OVERFLOW",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "18",
                "pretty_value": "FileAllInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 3826
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3827
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3828
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005\\x006\\x003\\x007\\x004\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3829
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04Jc\\x006\\x00f\\x00a\\x00e\\x001\\x00d\\x005\\x00-\\x003\\x007\\x00b\\x005\\x00-\\x004\\x001\\x007\\x00b\\x00-\\x00a\\x00f\\x00b\\x005\\x00-\\x00a\\x004\\x00a\\x001\\x00a\\x00f\\x001\\x00b\\x009\\x00b\\x009\\x005\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3830
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3831
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3832
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3833
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x16m\\x00s\\x00_\\x00n\\x00d\\x00i\\x00s\\x00l\\x00w\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3834
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "1\\x82\\x01+0<\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x011.0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x000@\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x011200\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x000E\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x0417050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14\\x1a7]\\xf8|\\xde\\x88\\xf6L\\xc9>i\\xb2\\xda\\xba\\x80\\xb5\\xb93`0b\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x021T0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3835
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3836
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3837
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00D\\x00E\\x003\\x005\\x001\\x00A\\x004\\x002\\x00-\\x008\\x00E\\x005\\x009\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3838
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "050\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x19\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14\\x1a7]\\xf8|\\xde\\x88\\xf6L\\xc9>i\\xb2\\xda\\xba\\x80\\xb5\\xb93`"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3839
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 3840
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3841
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3842
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3843
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllGetCaps"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps"
              }
            ],
            "repeated": 0,
            "id": 3844
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3845
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3846
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3847
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3848
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3849
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3850
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3851
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}"
              }
            ],
            "repeated": 0,
            "id": 3852
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "62"
              }
            ],
            "repeated": 0,
            "id": 3853
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\EsdSip.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3854
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "EsdSipGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3855
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3856
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3857
          },
          {
            "timestamp": "2026-02-10 09:22:14,733",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3858
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3859
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3860
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3861
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3862
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "3"
              },
              {
                "name": "Name",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3863
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3864
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3865
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3866
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3867
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3868
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "4"
              },
              {
                "name": "Name",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3869
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3870
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3871
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3872
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3873
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3874
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "5"
              },
              {
                "name": "Name",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3875
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3876
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3877
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3878
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3879
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3880
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "6"
              },
              {
                "name": "Name",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3881
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}"
              }
            ],
            "repeated": 0,
            "id": 3882
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "2"
              },
              {
                "name": "MaxValueNameLength",
                "value": "8"
              },
              {
                "name": "MaxValueLength",
                "value": "32"
              }
            ],
            "repeated": 0,
            "id": 3883
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "ValueName",
                "value": "Dll"
              },
              {
                "name": "Data",
                "value": "WINTRUST.DLL"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\Dll"
              }
            ],
            "repeated": 0,
            "id": 3884
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumValueW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "ValueName",
                "value": "FuncName"
              },
              {
                "name": "Data",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}\\FuncName"
              }
            ],
            "repeated": 0,
            "id": 3885
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3886
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "7"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\"
              }
            ],
            "repeated": 0,
            "id": 3887
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 3888
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3889
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3890
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004dc"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3891
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e0"
              },
              {
                "name": "SubKey",
                "value": "CryptSIPDllGetCaps"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllGetCaps"
              }
            ],
            "repeated": 0,
            "id": 3892
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e0"
              }
            ],
            "repeated": 0,
            "id": 3893
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3894
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 3895
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPGetCaps"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477cf0"
              }
            ],
            "repeated": 0,
            "id": 3896
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05{0\\x82\\x04c\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdc4\\x1aR\\x0f\\xbb\\xcf=\\x8c\\x00\\x00\\x00\\x00\\x00\\xdc0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195805Z\\x17\r230308195805Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3897
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3898
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed17000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3899
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3900
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f2b9000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3901
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "crypt32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0b90000"
              }
            ],
            "repeated": 0,
            "id": 3902
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0b90000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "crypt32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 3903
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPT32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0b90000"
              },
              {
                "name": "FunctionName",
                "value": "CryptVerifyTimeStampSignature"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee0b93ca0"
              }
            ],
            "repeated": 0,
            "id": 3904
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "\\x07\\x88\t\\x00\\x00\\x00\\x00\\x00\\xe7\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xebL\\xb6&u \\x06\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x88\\x0e\\x00\\x00\\x10\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x9b\\xa0\\x08\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3905
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p~\\x24eV\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3906
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\x96\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00V\\x02\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x803\\x00D\\xc0\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00=\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00+\\x00\\x00\\x00\\x00\\x00\\x00\\x00F\\x02\\x00\\x00\\x00\\x00\\x00\\x00T\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 3907
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004dc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-18"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 3908
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000004dc"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Control Panel\\International"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International"
              }
            ],
            "repeated": 0,
            "id": 3909
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              }
            ],
            "repeated": 0,
            "id": 3910
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "LocaleName"
              },
              {
                "name": "ValueBuffer",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\LocaleName"
              }
            ],
            "repeated": 0,
            "id": 3911
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sList"
              },
              {
                "name": "ValueBuffer",
                "value": ";"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sList"
              }
            ],
            "repeated": 0,
            "id": 3912
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sDecimal"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sDecimal"
              }
            ],
            "repeated": 0,
            "id": 3913
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sThousand"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sThousand"
              }
            ],
            "repeated": 0,
            "id": 3914
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sGrouping"
              }
            ],
            "repeated": 0,
            "id": 3915
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sNativeDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "0123456789"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNativeDigits"
              }
            ],
            "repeated": 0,
            "id": 3916
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sMonDecimalSep"
              },
              {
                "name": "ValueBuffer",
                "value": ","
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonDecimalSep"
              }
            ],
            "repeated": 0,
            "id": 3917
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sMonThousandSep"
              },
              {
                "name": "ValueBuffer",
                "value": "\\xa0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonThousandSep"
              }
            ],
            "repeated": 0,
            "id": 3918
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sMonGrouping"
              },
              {
                "name": "ValueBuffer",
                "value": "3;0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonGrouping"
              }
            ],
            "repeated": 0,
            "id": 3919
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sPositiveSign"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sPositiveSign"
              }
            ],
            "repeated": 0,
            "id": 3920
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sNegativeSign"
              },
              {
                "name": "ValueBuffer",
                "value": "-"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNegativeSign"
              }
            ],
            "repeated": 0,
            "id": 3921
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sTimeFormat"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm:ss"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sTimeFormat"
              }
            ],
            "repeated": 0,
            "id": 3922
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sShortTime"
              },
              {
                "name": "ValueBuffer",
                "value": "H:mm"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortTime"
              }
            ],
            "repeated": 0,
            "id": 3923
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "s1159"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s1159"
              }
            ],
            "repeated": 0,
            "id": 3924
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "s2359"
              },
              {
                "name": "ValueBuffer",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s2359"
              }
            ],
            "repeated": 0,
            "id": 3925
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sShortDate"
              },
              {
                "name": "ValueBuffer",
                "value": "dd.MM.yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortDate"
              }
            ],
            "repeated": 0,
            "id": 3926
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sYearMonth"
              },
              {
                "name": "ValueBuffer",
                "value": "MMMM yyyy"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sYearMonth"
              }
            ],
            "repeated": 0,
            "id": 3927
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sLongDate"
              },
              {
                "name": "ValueBuffer",
                "value": "d MMMM yyyy '\\x433.'"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sLongDate"
              }
            ],
            "repeated": 0,
            "id": 3928
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iCountry"
              },
              {
                "name": "ValueBuffer",
                "value": "7"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCountry"
              }
            ],
            "repeated": 0,
            "id": 3929
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iMeasure"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iMeasure"
              }
            ],
            "repeated": 0,
            "id": 3930
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iPaperSize"
              },
              {
                "name": "ValueBuffer",
                "value": "9"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iPaperSize"
              }
            ],
            "repeated": 0,
            "id": 3931
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iDigits"
              }
            ],
            "repeated": 0,
            "id": 3932
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iLZero"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iLZero"
              }
            ],
            "repeated": 0,
            "id": 3933
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iNegNumber"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegNumber"
              }
            ],
            "repeated": 0,
            "id": 3934
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "NumShape"
              },
              {
                "name": "ValueBuffer",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\NumShape"
              }
            ],
            "repeated": 0,
            "id": 3935
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iCurrDigits"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrDigits"
              }
            ],
            "repeated": 0,
            "id": 3936
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iCurrency"
              },
              {
                "name": "ValueBuffer",
                "value": "3"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrency"
              }
            ],
            "repeated": 0,
            "id": 3937
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iNegCurr"
              },
              {
                "name": "ValueBuffer",
                "value": "8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegCurr"
              }
            ],
            "repeated": 0,
            "id": 3938
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iFirstDayOfWeek"
              },
              {
                "name": "ValueBuffer",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstDayOfWeek"
              }
            ],
            "repeated": 0,
            "id": 3939
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryMultipleValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iFirstWeekOfYear"
              },
              {
                "name": "ValueBuffer",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstWeekOfYear"
              }
            ],
            "repeated": 0,
            "id": 3940
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "sCurrency"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "\\x20bd"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency"
              }
            ],
            "repeated": 0,
            "id": 3941
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ValueName",
                "value": "iCalendarType"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType"
              }
            ],
            "repeated": 0,
            "id": 3942
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000004e0"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d"
              }
            ],
            "repeated": 0,
            "id": 3943
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 3944
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3945
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ValueName",
                "value": "ru-RU"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU"
              }
            ],
            "repeated": 0,
            "id": 3946
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002b8"
              },
              {
                "name": "ValueName",
                "value": "ru"
              },
              {
                "name": "Type",
                "value": "1",
                "pretty_value": "REG_SZ"
              },
              {
                "name": "Information",
                "value": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru"
              }
            ],
            "repeated": 0,
            "id": 3947
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x018\\x02\\x01\\x01\\x06\n+\\x06\\x01\\x04\\x01\\x84Y\n\\x03\\x01010\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x00\\x04 \\xc8.\\xc4\\x8a\\x0eAY\\x90\\xb7\\x9f\\xd0\\x80\\xf4C\\x90\\xf3\\x13}\\xa6\\xb7=\\x02\\xa5\\xec\\x85o\\xb7_q\\x9a}\\xe5\\x02\\x06cm\\x08\\xcb\\xed\\xad\\x18\\x1320221117072455.725Z0\\x04\\x80\\x02\\x01\\xf4\\xa0\\x81\\xd0\\xa4\\x81\\xcd0\\x81\\xca1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1%0#\\x06\\x03U\\x04\\x0b\\x13\\x1cMicrosoft America Operations1&0$\\x06\\x03U\\x04\\x0b\\x13\\x1dThales T"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3948
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x0c0\\x82\\x04\\xf4\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\xc9\\xfa\\xd5\\x8e% t\\x02^\\x00\\x01\\x00\\x00\\x01\\xc90\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r221104190138Z\\x17\r240202190138Z0\\x81\\xca1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3949
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3950
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3951
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1e000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3952
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3953
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3954
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3955
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllVerifyEncodedSignature"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllVerifyEncodedSignature"
              }
            ],
            "repeated": 0,
            "id": 3956
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3957
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3958
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3959
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllVerifyEncodedSignature"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllVerifyEncodedSignature"
              }
            ],
            "repeated": 0,
            "id": 3960
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3961
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3962
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 3963
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3964
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3965
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3966
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx2"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx2"
              }
            ],
            "repeated": 0,
            "id": 3967
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3968
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3969
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3970
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx2"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx2"
              }
            ],
            "repeated": 0,
            "id": 3971
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3972
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3973
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 3974
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xd6r\\xe2\\xe5\\x8eo\\xcf\\xc2\\xbeZ\\x8ca\\x93\\xba\\x86[\\xfb\\xc2\\xc6.^\\xb934\\xd58\\x84lS\\x86\\xf2\\x0e\\xd2\\x14\\x1d\\x1526 \\xa3\\xa4\\xe2G8\\x0eC\\xe0\\x8d\\xe7s\\x818\\xa9r0u\\xb3D\\xbe1\\xbd\\xa4\\xb4\\xdd\\x99H\\x81\\xebH \\xb6\"\\x01* \\xb0Ke\\x8f1%Ds\\xbb|1\\x83\\x15g\\x1d\\xcf\\xe9B5\\x89\\x89\\xa3;[\\x1bs\\xcc\\xae|[\\x95A\\xc7RJ\\xf8\\x0b\\xb1\\x01\\x1d\\xbd\\x98\\xd3\\xb1\\x9d\\xe4bA\\x80\\xff>\\xe4\\x06M\\xb19l\\x1cg3\\x1e\\xce9\\x9ac\\xfb\\xadH\\x1c2\\x7f\\xffs\\xc4?\\x19\\x84\\xaau>\\x0e\\B\\xe9\\xe7x}\\xf4I\\xf2\\x17\\x8c\\xdc\\xb1\\xdd\\x99\\x16<]\\x8fYO\\xf1\\x01\\xb0e\\x94\\xb8\\x17\\xcd\\x89\\x04g\\xb6\\xa4*\\xd2jL\\x85\\x8d<s\\x14\\xa5\\x0e\\xc1\\xc4\\x1e\\xaf\\x00Q\\xfd\\x86\\x90\\x97.\\xe6\\xb4*\\xda\\xe0\\xf3\\\\xc8D&\\xfa\\x7f\\xcb\r\\xc7\\xbfUX\\x90k\\xc3\\x8c\\xdapY\\x1c\\xac:\\x0b#*\\x131I'"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3975
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "device",
            "api": "NtDeviceIoControlFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000174"
              },
              {
                "name": "HandleName",
                "value": "\\Device\\KsecDD"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390400"
              },
              {
                "name": "InputBuffer",
                "value": "M<+\\x1a\\x00\\x00\\x02\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x01\\x00\\x00\\x00\\x02\\x00\\x00\\x00R\\x00S\\x00A\\x00\\x00\\x00"
              },
              {
                "name": "OutputBuffer",
                "value": "\\x01\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00X\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00A\\x00\\x00\\x00\\x98\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xffR\\x00S\\x00A\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00P\\x00r\\x00i\\x00m\\x00i\\x00t\\x00i\\x00v\\x00e\\x00 \\x00P\\x00r\\x00o\\x00v\\x00i\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x00\\x00\\x00\\x00\\x00\\x00\\x00K\\x00e\\x00y\\x00L\\x00e\\x00n\\x00g\\x00t\\x00h\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00b\\x00c\\x00r\\x00y\\x00p\\x00t\\x00p\\x00r\\x00i\\x00m\\x00i\\x00t\\x00"
              }
            ],
            "repeated": 0,
            "id": 3976
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetAsymmetricEncryptionInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13af980"
              }
            ],
            "repeated": 0,
            "id": 3977
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xd6r\\xe2\\xe5\\x8eo\\xcf\\xc2\\xbeZ\\x8ca\\x93\\xba\\x86[\\xfb\\xc2\\xc6.^\\xb934\\xd58\\x84lS\\x86\\xf2\\x0e\\xd2\\x14\\x1d\\x1526 \\xa3\\xa4\\xe2G8\\x0eC\\xe0\\x8d\\xe7s\\x818\\xa9r0u\\xb3D\\xbe1\\xbd\\xa4\\xb4\\xdd\\x99H\\x81\\xebH \\xb6\"\\x01* \\xb0Ke\\x8f1%Ds\\xbb|1\\x83\\x15g\\x1d\\xcf\\xe9B5\\x89\\x89\\xa3;[\\x1bs\\xcc\\xae|[\\x95A\\xc7RJ\\xf8\\x0b\\xb1\\x01\\x1d\\xbd\\x98\\xd3\\xb1\\x9d\\xe4bA\\x80\\xff>\\xe4\\x06M\\xb19l\\x1cg3\\x1e\\xce9\\x9ac\\xfb\\xadH\\x1c2\\x7f\\xffs\\xc4?\\x19\\x84\\xaau>\\x0e\\B\\xe9\\xe7x}\\xf4I\\xf2\\x17\\x8c\\xdc\\xb1\\xdd\\x99\\x16<]\\x8fYO\\xf1\\x01\\xb0e\\x94\\xb8\\x17\\xcd\\x89\\x04g\\xb6\\xa4*\\xd2jL\\x85\\x8d<s\\x14\\xa5\\x0e\\xc1\\xc4\\x1e\\xaf\\x00Q\\xfd\\x86\\x90\\x97.\\xe6\\xb4*\\xda\\xe0\\xf3\\\\xc8D&\\xfa\\x7f\\xcb\r\\xc7\\xbfU"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ece43c0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 3978
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed21000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000a000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 3979
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 3980
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 3981
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 3982
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x0c0\\x82\\x04\\xf4\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\xc9\\xfa\\xd5\\x8e% t\\x02^\\x00\\x01\\x00\\x00\\x01\\xc90\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r221104190138Z\\x17\r240202190138Z0\\x81\\xca1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 3983
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3984
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3985
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\x9f\\xa7\\x15]\\x00^b]\\x83\\xf4\\xe5\\xd2e\\xa7\\x1bS5\\x19\\xe9r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 3986
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3987
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3988
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3989
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx"
              }
            ],
            "repeated": 0,
            "id": 3990
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3991
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3992
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 3993
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllImportPublicKeyInfoEx"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx"
              }
            ],
            "repeated": 0,
            "id": 3994
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 3995
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 3996
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 3997
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 3998
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 3999
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4000
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllConvertPublicKeyInfo"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllConvertPublicKeyInfo"
              }
            ],
            "repeated": 0,
            "id": 4001
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4002
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4003
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4004
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CryptDllConvertPublicKeyInfo"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllConvertPublicKeyInfo"
              }
            ],
            "repeated": 0,
            "id": 4005
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4006
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4007
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4008
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xd6r\\xe2\\xe5\\x8eo\\xcf\\xc2\\xbeZ\\x8ca\\x93\\xba\\x86[\\xfb\\xc2\\xc6.^\\xb934\\xd58\\x84lS\\x86\\xf2\\x0e\\xd2\\x14\\x1d\\x1526 \\xa3\\xa4\\xe2G8\\x0eC\\xe0\\x8d\\xe7s\\x818\\xa9r0u\\xb3D\\xbe1\\xbd\\xa4\\xb4\\xdd\\x99H\\x81\\xebH \\xb6\"\\x01* \\xb0Ke\\x8f1%Ds\\xbb|1\\x83\\x15g\\x1d\\xcf\\xe9B5\\x89\\x89\\xa3;[\\x1bs\\xcc\\xae|[\\x95A\\xc7RJ\\xf8\\x0b\\xb1\\x01\\x1d\\xbd\\x98\\xd3\\xb1\\x9d\\xe4bA\\x80\\xff>\\xe4\\x06M\\xb19l\\x1cg3\\x1e\\xce9\\x9ac\\xfb\\xadH\\x1c2\\x7f\\xffs\\xc4?\\x19\\x84\\xaau>\\x0e\\B\\xe9\\xe7x}\\xf4I\\xf2\\x17\\x8c\\xdc\\xb1\\xdd\\x99\\x16<]\\x8fYO\\xf1\\x01\\xb0e\\x94\\xb8\\x17\\xcd\\x89\\x04g\\xb6\\xa4*\\xd2jL\\x85\\x8d<s\\x14\\xa5\\x0e\\xc1\\xc4\\x1e\\xaf\\x00Q\\xfd\\x86\\x90\\x97.\\xe6\\xb4*\\xda\\xe0\\xf3\\\\xc8D&\\xfa\\x7f\\xcb\r\\xc7\\xbfUX\\x90k\\xc3\\x8c\\xdapY\\x1c\\xac:\\x0b#*\\x131I'"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4009
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x10\\x00\\x00\\x01\\x00\\x01\\x00\\xcb\tp\\xf12{\\xa1\\xda'D \\x9aF\\xbf\\x0f\\xf8\\x08\\x1d\\x90cpHd\\xa49im\\x90\\xff\\xd6\\x8eB\\xde\\xfc\\xc4E\\x96\\x02\\xfa\\xa5\\xc0n\\x9d\\xf3\\xbe\\xfe&g\\xf3\\x95\\x15J\\x18H\\x96\\xc7\\xb7\\x97\\xc3\\x07\\xec>=\\xed\\xa9\\xbbI\\xee\\xb5\\xb7\\xe2\\xf3\\xa7\\x99d\\xa4\\xcf,4\\xab\\xd5\\x06\\x80&\\xfb\\xd9\\xc5`[\\xf0\\xea\\xe9(\\xc4\\x95\\x0f\\xb4\\xde\\xce\\xaa\\x82t?\\xc8Bm\\xf3#)P\\xb5\\x8d\\xcd\\xb9\r\\x9d\\xda\\xbca\\x03\\x14XE\\xa5\\xa3W\\xd2A\\x15\\x81]z~s\\xa1\\x03\\xe2\\x94]){\\xae\\xde\\xb0L,\\x11\\xf5\\x17\\x1c\\xce\\xab\\xe8\\x07o\\xedN,$B}\\x7f>\\xd3\\xb1\nU\\x1ck\\xb4\\xc1\\xb4\\xc6\\x87\\xb9\\x80]\\x82\\xeaR\\xbb\\xe1C\\xef\\xe4\\xf1u\\xcc\\x9b\\xd6X\\xc8A\\x84\\xed\\xcf\\xcb*E\\xc8]\\xf9S\\\\xdc\\x02\\xf6\\x06q\\xa1\\xc7\\x9c\\xfc\\x0bW\\xce\\xe6\\x9a\\x12\\xe8x\\xd5\\xc6\\xddar\\xcb\\xcb_\\x14\\x13\\x86\\xbce +"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ecf0e00"
              },
              {
                "name": "Length",
                "value": "532"
              }
            ],
            "repeated": 0,
            "id": 4010
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4011
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0S0Q\\x06\\x0c+\\x06\\x01\\x04\\x01\\x827L\\x83}\\x01\\x010A0?\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x02\\x01\\x163http://www.microsoft.com/pkiops/Docs/Repository.htm"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4012
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4013
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4014
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4015
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4016
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4017
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x10\\x00\\x00\\x01\\x00\\x01\\x00\\xad.\\xe2j>\\xb7\\xb7{\\xae\\xc6ir\\x16\\x9e\\x8f\\xda^\\x87\\x1e\\xf5\\xb6E\\xabx?\\x18\\x15\\x08\\xc77\\x1a\\xdb\\x15<\\xc0\\x93\\x17\\x85\\xc4R\\xf9\\x8d\\xefr\\x1d\\x11\\xc5lz\\x05P\\xaf\\xba%\\xdb\\x12]QR\\\\xf6k\\xc5\\x1c\\xd4\\xb2\\xfd\\xd1\\x1b\\xdc\\xdbG\\x84\\x185\\x066\\xf3a\\x89\\x0b\\xf9P\\xb9\\xd8\\x94\\x94\\x91t0_]!\\x83\\xa6\\xa0[\\x8bd6\\xc9\\x0coc\\xd7\n\\x12\\xfa\\xc2\\xf0 \\xa7\\xd7r\\x183\\xe2\\x02v(\\xd7^\\xa2g\\xcas\\x01aZ\\x18j\\xbd\\xd1\\xe2FQ\\x84\\xea\\x10.hB\\xbc\\x02\\x8eL93\\xc1NC=s\\xd8\\xd5\\xf3\\xc2^\\xaf\\xdbL?|\\x99\\xe8\\xa7\\xed\\x18G\\xb7\\xf2\\x10\\xf0\\x0f\\x824\\x1c\\x94t7M\\xa6s\\xd1\\xa3\\x03\\x05\\xbf\\xe8Q\\x12\\xa8n+\\xf6L6\\xec6~\\xaa\\xdb\\xba\\x80_}\\xdb/r\\xb6\\xdfE\\x9e\\xd9\\xfc~} \\xa5\\xfd\\xd6\\x89\\x12\\xdd4_\\xc4\\xcduF\\x9aA}s\\xcf "
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ecf0e00"
              },
              {
                "name": "Length",
                "value": "532"
              }
            ],
            "repeated": 0,
            "id": 4018
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4019
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4020
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215724Z\\x17\r350623220401Z0\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x10"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4021
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4022
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ece4030"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4023
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4024
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4025
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4026
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98ea0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4027
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x0c0\\x82\\x04\\xf4\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\xc9\\xfa\\xd5\\x8e% t\\x02^\\x00\\x01\\x00\\x00\\x01\\xc90\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r221104190138Z\\x17\r240202190138Z0\\x81\\xca1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4028
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4029
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98bd0"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4030
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4031
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa2\\xd2\\x93z\\x06a]\\xfc?/\\x80ni];\\xfdR$A\\xd5\\xf3-\\x8d\\xbe\\xc6\\x03\\x99|)MuT9\\xe9\\xf9\\x8e\\x16\\xb5\\xae-\\x07\\x08e\\xf6>L\\xf5\\xec\\xa5+O+\\xd6f\\xffjsx\tS\\xac\\xf5\\x1b\\xa5\\xbf\\xfaJ\\x84\\xbde\\xd1\\xf2\\x98\\x01-\\xe5\\xe4\r\\x8cVj\\xe4\\x7f\\xc9O\\x88\\xd0[\\xdc\\xf6}i\\x14\\x13rR\\x9eK\\xda(\\x95\\xca\\xe1}hX\\xbe]q\\xf5\\x12F\\xa6\\xb0\\x0f\\x95\\x1a\\xff\\x7f&m\\xb6\\xc0\\x91%Q\\x82\\xc6\\xd1\\xaeg\\x1b\\xe7uTj=\\x98X'XE\\x89\\xaa~k<\\xd7\\x82kve\\xa2\n\\x07O\\x86\\xc3~g~\\xca\\xf3\\xb4\\xe4\\x0c+\\xff\\x88vrt\\x81\\x9b\\xec\\xe6\\xd4\\xfa\\xa1\\xd4\\xb9\\xe5\\xb6\\xdf\\xbe #Z\rR\\xa0\\xfc\\xc9\\x9eT\\xbak\\x14\\x9b\\xd0}|\\xd8A\\x0bKP)\\xb3Y\\xbb\\xe490$\\xb8\\x02dm\\x10\\xae\\xe4\\x9eG\\xca\\x86>?\\xf5I\\x0b\\x89 :\\xa1\\xc8uu%\\xfa\\xb9f\\xca+\\xd5\\xeeo"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4032
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x08\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xa2\\xd2\\x93z\\x06a]\\xfc?/\\x80ni];\\xfdR$A\\xd5\\xf3-\\x8d\\xbe\\xc6\\x03\\x99|)MuT9\\xe9\\xf9\\x8e\\x16\\xb5\\xae-\\x07\\x08e\\xf6>L\\xf5\\xec\\xa5+O+\\xd6f\\xffjsx\tS\\xac\\xf5\\x1b\\xa5\\xbf\\xfaJ\\x84\\xbde\\xd1\\xf2\\x98\\x01-\\xe5\\xe4\r\\x8cVj\\xe4\\x7f\\xc9O\\x88\\xd0[\\xdc\\xf6}i\\x14\\x13rR\\x9eK\\xda(\\x95\\xca\\xe1}hX\\xbe]q\\xf5\\x12F\\xa6\\xb0\\x0f\\x95\\x1a\\xff\\x7f&m\\xb6\\xc0\\x91%Q\\x82\\xc6\\xd1\\xaeg\\x1b\\xe7uTj=\\x98X'XE\\x89\\xaa~k<\\xd7\\x82kve\\xa2\n\\x07O\\x86\\xc3~g~\\xca\\xf3\\xb4\\xe4\\x0c+\\xff\\x88vrt\\x81\\x9b\\xec\\xe6\\xd4\\xfa\\xa1\\xd4\\xb9\\xe5\\xb6\\xdf\\xbe #Z\rR\\xa0\\xfc\\xc9\\x9eT\\xbak\\x14\\x9b\\xd0}|\\xd8A\\x0bKP)\\xb3Y\\xbb\\xe490$\\xb8\\x02dm\\x10\\xae\\xe4\\x9eG\\xca\\x86>?\\xf5"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98d50"
              },
              {
                "name": "Length",
                "value": "283"
              }
            ],
            "repeated": 0,
            "id": 4033
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4034
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4035
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4036
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05{0\\x82\\x04c\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdc4\\x1aR\\x0f\\xbb\\xcf=\\x8c\\x00\\x00\\x00\\x00\\x00\\xdc0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195805Z\\x17\r230308195805Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4037
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4038
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4039
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14aq\\xa7\\x87\\xaf\\xffi\\xd5!vOR\\x93(\\x00\\xbey\\x12\\xab\\x84"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4040
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa2\\xd2\\x93z\\x06a]\\xfc?/\\x80ni];\\xfdR$A\\xd5\\xf3-\\x8d\\xbe\\xc6\\x03\\x99|)MuT9\\xe9\\xf9\\x8e\\x16\\xb5\\xae-\\x07\\x08e\\xf6>L\\xf5\\xec\\xa5+O+\\xd6f\\xffjsx\tS\\xac\\xf5\\x1b\\xa5\\xbf\\xfaJ\\x84\\xbde\\xd1\\xf2\\x98\\x01-\\xe5\\xe4\r\\x8cVj\\xe4\\x7f\\xc9O\\x88\\xd0[\\xdc\\xf6}i\\x14\\x13rR\\x9eK\\xda(\\x95\\xca\\xe1}hX\\xbe]q\\xf5\\x12F\\xa6\\xb0\\x0f\\x95\\x1a\\xff\\x7f&m\\xb6\\xc0\\x91%Q\\x82\\xc6\\xd1\\xaeg\\x1b\\xe7uTj=\\x98X'XE\\x89\\xaa~k<\\xd7\\x82kve\\xa2\n\\x07O\\x86\\xc3~g~\\xca\\xf3\\xb4\\xe4\\x0c+\\xff\\x88vrt\\x81\\x9b\\xec\\xe6\\xd4\\xfa\\xa1\\xd4\\xb9\\xe5\\xb6\\xdf\\xbe #Z\rR\\xa0\\xfc\\xc9\\x9eT\\xbak\\x14\\x9b\\xd0}|\\xd8A\\x0bKP)\\xb3Y\\xbb\\xe490$\\xb8\\x02dm\\x10\\xae\\xe4\\x9eG\\xca\\x86>?\\xf5I\\x0b\\x89 :\\xa1\\xc8uu%\\xfa\\xb9f\\xca+\\xd5\\xeeo"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4041
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x08\\x00\\x00\\x01\\x00\\x01\\x001\\xfd6\\x04\\xf4:S\\x94\\x03o\\xee\\xd5+\\xcaf\\xb9\\xfa%uu\\xc8\\xa1: \\x89\\x0bI\\xf5?>\\x86\\xcaG\\x9e\\xe4\\xae\\x10md\\x02\\xb8$09\\xe4\\xbbY\\xb3)PK\\x0bA\\xd8|}\\xd0\\x9b\\x14k\\xbaT\\x9e\\xc9\\xfc\\xa0R\rZ# \\xbe\\xdf\\xb6\\xe5\\xb9\\xd4\\xa1\\xfa\\xd4\\xe6\\xec\\x9b\\x81trv\\x88\\xff+\\x0c\\xe4\\xb4\\xf3\\xca~g~\\xc3\\x86O\\x07\n\\xa2evk\\x82\\xd7<k~\\xaa\\x89EX'X\\x98=jTu\\xe7\\x1bg\\xae\\xd1\\xc6\\x82Q%\\x91\\xc0\\xb6m&\\x7f\\xff\\x1a\\x95\\x0f\\xb0\\xa6F\\x12\\xf5q]\\xbeXh}\\xe1\\xca\\x95(\\xdaK\\x9eRr\\x13\\x14i}\\xf6\\xdc[\\xd0\\x88O\\xc9\\x7f\\xe4jV\\x8c\r\\xe4\\xe5-\\x01\\x98\\xf2\\xd1e\\xbd\\x84J\\xfa\\xbf\\xa5\\x1b\\xf5\\xacS\txsj\\xfff\\xd6+O+\\xa5\\xec\\xf5L>\\xf6e\\x08\\x07-\\xae\\xb5\\x16\\x8e\\xf9\\xe99TuM)|\\x99\\x03\\xc6\\xbe\\x8d-\\xf3"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ecf0e00"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 4042
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 1,
            "id": 4043
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4044
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4045
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4046
          },
          {
            "timestamp": "2026-02-10 09:22:14,749",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf\\xdd~\\xfb\\x95^\\xa1\\x01\\xcdC\\xb1\\x07\\xd7\\xa40\\xee\\x9b\\x86\\x1a"
              },
              {
                "name": "Flags",
                "value": "0x00008000"
              }
            ],
            "repeated": 0,
            "id": 4047
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptImportKey",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "\\x06\\x02\\x00\\x00\\x00\\xa4\\x00\\x00RSA1\\x00\\x08\\x00\\x00\\x01\\x00\\x01\\x00\\x8bot\\xa2Y\\x0b\\xc1n*\\x1a\\x86\\x9b\\xee0\\xa4\\xd7\\x07\\xb1C\\xcd\\x01\\xa1^\\x95\\xfb~\\xdd\\xcf\\x95\\xe4\\xb8\\xfd\\xc7\\x8e\\xcd\\xc6\\x95$\\xe0\\xeeC=.HP}\\x00p\\xc8mh\\xb6\\x10f\\xb2d\\xeatd\\x14\\xed\\x01:\\x8e\\x13\\x83V\\xec\\xe8\\x82\\xfc\\xac\nNF\\x01M\\x1d\\xed\\x0f\\xb8\\xfe\\xbdo7\\xdc\\xaa\\xe9\r\\xd1C\\xe1\\x18\\xfb\\xe8\\x1d\\x01t\\x7f\\xb8\\x05\\xf9,\\xcd\\xbdw\\x9e\\xf9\\xcbSE3\\xd5\\x1e\\x89\\xa2\\xecU\\xa7\\xabNj\\xe9\\x8e\\xda\\xf4\\xcc\\x8a\\xe8G5\\xbd\\x86\\x0f}e\\x7f\\xfd\\xe3f\\x90V<'<g-\\x1b\\xf9\\x9bY\"N\\xa0\\x0c\\xf9\\x98\\xb7a7\\x19Wy\\x86S\\x0c\\dN\\x81\\x02*~\\xcb\\xa7\\xd1\\xbfh\\xee\\xf0\\xbc%a\\xdf\\xeb\\xc5\\xe4d\\x9b<\\xfd\\xa5\\x1c(\\xbdq\\xc4)\\xb4 \\xac\\x02X\\x8b\\x98/h\\x9f\\xb5\\x99\\xa5\\xe7.\\x10\\xed\\xd5\\xaeK\\xa5Z\ne\\x08\tg\\xce\\xd4P\\xb2\\x071\\x9a\\x81&1W"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ecf0e00"
              },
              {
                "name": "Length",
                "value": "276"
              }
            ],
            "repeated": 0,
            "id": 4048
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05\\xe10\\x82\\x03\\xc9\\xa0\\x03\\x02\\x01\\x02\\x02\na\\x0b\\xaa\\xc1\\x00\\x00\\x00\\x00\\x00\t0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r120418234838Z\\x17\r270418235838Z0\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4049
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4050
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98a20"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4051
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x05{0\\x82\\x04c\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\xdc4\\x1aR\\x0f\\xbb\\xcf=\\x8c\\x00\\x00\\x00\\x00\\x00\\xdc0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x8e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1806\\x06\\x03U\\x04\\x03\\x13/Microsoft Windows Third Party Component CA 20120\\x1e\\x17\r220310195805Z\\x17\r230308195805Z0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWas"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4052
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf\\xdd~\\xfb\\x95^\\xa1\\x01\\xcdC\\xb1\\x07\\xd7\\xa40\\xee\\x9b\\x86\\x1a"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4053
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x08\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xa3\\x9c0\\x84\t\\xa7c.\\xcf\nG\\xf0\\xea$\\xf9\\xa30 \\x0f^W1&\\x81\\x9a1\\x07\\xb2P\\xd4\\xceg\t\\x08e\nZ\\xa5K\\xae\\xd5\\xed\\x10.\\xe7\\xa5\\x99\\xb5\\x9fh/\\x98\\x8bX\\x02\\xac \\xb4)\\xc4q\\xbd(\\x1c\\xa5\\xfd<\\x9bd\\xe4\\xc5\\xeb\\xdfa%\\xbc\\xf0\\xeeh\\xbf\\xd1\\xa7\\xcb~*\\x02\\x81Nd\\\\x0cS\\x86yW\\x197a\\xb7\\x98\\xf9\\x0c\\xa0N\"Y\\x9b\\xf9\\x1b-g<'<V\\x90f\\xe3\\xfd\\x7fe}\\x0f\\x86\\xbd5G\\xe8\\x8a\\xcc\\xf4\\xda\\x8e\\xe9jN\\xab\\xa7U\\xec\\xa2\\x89\\x1e\\xd53ES\\xcb\\xf9\\x9ew\\xbd\\xcd,\\xf9\\x05\\xb8\\x7ft\\x01\\x1d\\xe8\\xfb\\x18\\xe1C\\xd1\r\\xe9\\xaa\\xdc7o\\xbd\\xfe\\xb8\\x0f\\xed\\x1dM\\x01FN\n\\xac\\xfc\\x82\\xe8\\xecV\\x83\\x13\\x8e:\\x01\\xed\\x14dt\\xead\\xb2f\\x10\\xb6hm\\xc8p\\x00}PH.=C\\xee\\xe0$\\x95\\xc6\\xcd\\x8e\\xc7\\xfd\\xb8\\xe4\\x95\\xcf"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98a50"
              },
              {
                "name": "Length",
                "value": "283"
              }
            ],
            "repeated": 0,
            "id": 4054
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 2,
            "id": 4055
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4056
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4057
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4058
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0H\\x02A\\x00\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4059
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4060
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x9cP\\x05\\x1d\\xe2\\x0eLS\\xd8\\xd9\\xb5\\xe5\\xfd\\xe9\\xe3\\xad\\x83K\\x80\\x08\\xd9\\xdc\\xe8\\xe85\\xf8\\x11\\xf1\\xe9\\x9b\\x03zedv5\\xce8,\\xf2\\xb6q\\x9e\\x06\\xd9\\xbf\\xbb1i\\xa3\\xf60\\xa0x{\\x18\\xddPMy\\x1e\\xeba\\xc1\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4061
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4062
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4063
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4064
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4065
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\x9f\\xa7\\x15]\\x00^b]\\x83\\xf4\\xe5\\xd2e\\xa7\\x1bS5\\x19\\xe9r"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4066
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0S0Q\\x06\\x0c+\\x06\\x01\\x04\\x01\\x827L\\x83}\\x01\\x010A0?\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x02\\x01\\x163http://www.microsoft.com/pkiops/Docs/Repository.htm"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4067
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4068
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x03\\x01\\x01\\xff"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4069
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "\\x03\\x02\\x01\\x86"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4070
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x16\\x80\\x14\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4071
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07q0\\x82\\x05Y\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x00\\x15\\xc5\\xe7k\\x9e\\x02\\x9bI\\x99\\x00\\x00\\x00\\x00\\x00\\x150\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r210930182225Z\\x17\r300930183225Z0|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4072
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4073
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ec98c00"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4074
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x07\\x0c0\\x82\\x04\\xf4\\xa0\\x03\\x02\\x01\\x02\\x02\\x133\\x00\\x00\\x01\\xc9\\xfa\\xd5\\x8e% t\\x02^\\x00\\x01\\x00\\x00\\x01\\xc90\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000|1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1&0$\\x06\\x03U\\x04\\x03\\x13\\x1dMicrosoft Time-Stamp PCA 20100\\x1e\\x17\r221104190138Z\\x17\r240202190138Z0\\x81\\xca1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07R"
              },
              {
                "name": "Flags",
                "value": "0x0000800d"
              }
            ],
            "repeated": 0,
            "id": 4075
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)7\\xac\\xcb\\xeb\\x83E\\xe7Fn\\xca2\\xd5\\xc0\\x860\\O,"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4076
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "BCryptImportKeyPair",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyBlob",
                "value": "RSA1\\x00\\x10\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\xe4\\xe1\\xa6L\\xe7\\xb4r!\\x0by\\xa2\\xcb\\xd7$y\\xbd\\x0e\\xd5\\x82\\xd3\\xfd\\xee\\x9c\\x07\\x07\\xd2\\xa9lNu\\xc8\\xca5W\\xf6\\x01\\x7flJ\\xe0\\xe2\\xbd\\xb9>\\x17`3\\xff\\O\\xc7f\\xf7\\x95SqZ\\xe2~JZ\\xfe\\xb86g\\x85F#\\x0c\\xb5\\x8d\\x13\\xcfw2\\xc0\\x10\\x18\\xe8`}jR\\x83D\\xb7\\xa6\\x8eFk\\x07\\x14\\xf3\\xc5v\\xf5\\x86P\\xdc\\xc1D\\xc8q\\Q17\\xa0\n8n\\x8d\\xed\\xd7\\x0f\\xd8&S|9a\\x02z\\xc4\\xaa\\xfdri\\xaf\\x1d\\xab\\xac\\xf66\\xbe5&d\\xda\\x98;\\xba\\x1a{3\\xad\\x80[~\\x8c\\x10\\x1c\\x9dR\\xfe\\xb6\\xe8b%\\xdcj\\x0f\\xcf]\\xf4\\xfe\\x8eS\\xcf\\xd6\\xec\\x85VM\\xef\\xdd\\xbc\\x8d\\xa4\\xe3\\x91\\x8f\\xb29,Q\\x9c\\xe9pi\r\\xca6-p\\x8e1\\xc85(\\xbd\\xe3\\xb4\\x87$\\xc3\\xe0\\xc9\\x8f~\\xb5T\\x8f\\xdc\\xfa\\x05U\\x98mh;\\x9aF\\xbd\\xed\\xa4\\xaez)"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "CryptKey",
                "value": "0x2568ece2380"
              },
              {
                "name": "Length",
                "value": "539"
              }
            ],
            "repeated": 0,
            "id": 4077
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 2,
            "id": 4078
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4079
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4080
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4081
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0H\\x02A\\x00\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4082
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\n\\x02\\x82\\x02\\x01\\x00\\xb9\\x08\\x9e(\\xe4\\xe4\\xec\\x06NPh\\xb3A\\xc5{\\xeb\\xae\\xb6\\x8e\\xaf\\x81\\xba\"D\\x1fe4iL\\xbep@\\x17\\xf2\\x16{\\xe2y\\xfd\\x86\\xed\r9\\xf4\\x1b\\xa8\\xad\\x92\\x90\\x1e\\xcb=v\\x8fZ\\xd9\\xb5\\x91\\x10.<\\x05\\x8d\\x8am$T\\xe7\\x1f\\xedV\\xad\\x83\\xb4P\\x9c\\x15\\xa5\\x17t\\x88Y \\xfc\\x08\\xc5\\x84v\\xd3h\\xd4o(x\\xce\\\\xb8\\xf3P\\x90D\\xff\\xe3c_\\xbe\\xa1\\x9a,\\x96\\x15\\x04\\xd6\\x07\\xfe\\x1e\\x84!\\xe0B1\\x11\\xc4(6\\x94\\xcfP\\xa4b\\x9e\\xc9\\xd6\\xabq\\x00\\xb2[\\x0c\\xe6\\x96\\xd4\n$\\x96\\xf5\\xff\\xc6\\xd5\\xb7\\x1b\\xd7\\xcb\\xb7!b\\xaf\\x12\\xdc\\xa1]7\\xe3\\x1a\\xfb\\x1aF\\x98\\xc0\\x9b\\xc0\\xe7c\\x1f*\\x08\\x93\\x02~\\x1ej\\x8e\\xf2\\x9f\\x18\\x89\\xe4\"\\x85\\xa2\\xb1\\x84W@\\xff\\xf5\\x0e\\xd8o\\x9c\\xed\\xe2E1\\x01\\xcd\\x17\\xe9\\x7f\\xb0\\x81E\\xe3\\xaa!@&\\xa1r\\xaa\\xa7O<\\x01\\x05~\\xee\\x83X\\xb1^\\x06c\\x99b\\x91x\\x82\\xb7\r\\x93\\x0c$j\\xb4\\x1b\\xdb"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4083
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0G\\x02@\\x9cP\\x05\\x1d\\xe2\\x0eLS\\xd8\\xd9\\xb5\\xe5\\xfd\\xe9\\xe3\\xad\\x83K\\x80\\x08\\xd9\\xdc\\xe8\\xe85\\xf8\\x11\\xf1\\xe9\\x9b\\x03zedv5\\xce8,\\xf2\\xb6q\\x9e\\x06\\xd9\\xbf\\xbb1i\\xa3\\xf60\\xa0x{\\x18\\xddPMy\\x1e\\xeba\\xc1\\x02\\x03\\x01\\x00\\x01"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4084
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Cryptography\\OID"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID"
              }
            ],
            "repeated": 0,
            "id": 4085
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "EncodingType 0"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4086
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 0"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0"
              }
            ],
            "repeated": 0,
            "id": 4087
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CertDllVerifyCertificateChainPolicy"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllVerifyCertificateChainPolicy"
              }
            ],
            "repeated": 0,
            "id": 4088
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4089
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "Index",
                "value": "1"
              },
              {
                "name": "Name",
                "value": "EncodingType 1"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4090
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "EncodingType 1"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1"
              }
            ],
            "repeated": 0,
            "id": 4091
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExA",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CertDllVerifyCertificateChainPolicy"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllVerifyCertificateChainPolicy"
              }
            ],
            "repeated": 0,
            "id": 4092
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4093
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExA",
            "status": false,
            "return": "0x00000103",
            "pretty_return": "NO_MORE_ITEMS",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "Index",
                "value": "2"
              },
              {
                "name": "Name",
                "value": ""
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\"
              }
            ],
            "repeated": 0,
            "id": 4094
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4095
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 4096
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x911\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1;09\\x06\\x03U\\x04\\x03\\x132Microsoft Windows Hardware Compatibility Publisher"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4097
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0G\\xa4E0C1)0'\\x06\\x03U\\x04\\x0b\\x13 Microsoft Operations Puerto Rico1\\x160\\x14\\x06\\x03U\\x04\\x05\\x13\r232825+469580"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4098
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0C1)0'\\x06\\x03U\\x04\\x0b\\x13 Microsoft Operations Puerto Rico1\\x160\\x14\\x06\\x03U\\x04\\x05\\x13\r232825+469580"
              },
              {
                "name": "Flags",
                "value": "0x00008005"
              }
            ],
            "repeated": 0,
            "id": 4099
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4100
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4101
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4102
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4103
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4104
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4105
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4106
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4107
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4108
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4109
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4110
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4111
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4112
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4113
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4114
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4115
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4116
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "X\\x9c\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00P\n\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\xf0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00T\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4117
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4118
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4119
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4120
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4121
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4122
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4123
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4124
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4125
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4126
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "X\\x9c\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00P\n\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xf0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xc0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00T\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4127
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4128
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4129
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4130
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4131
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4132
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4133
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4134
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "8\\x9d\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00p\\x05\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\xd0\\x9e\\xed\\x1c\\x97\\x00\\x00\\x00 X\\xc6\\x8eV\\x02\\x00\\x00\\xe0\\xa1\\xed\\x1c\\x97\\x00\\x00\\x00\\xa0\\x9e\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\x9e\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xa0\\x9e\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4135
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4136
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4137
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4138
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4139
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4140
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4141
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4142
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4143
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4144
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4145
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4146
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4147
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4148
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4149
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x08\\x9a\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xa0\t\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\xa0\\x9b\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1f\\x00\\x03\\x00\\x00\\x00\\x00\\x00p\\x9b\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x9b\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00p\\x9b\\xed\\x1c\\x97\\x00\\x00\\x00X\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4150
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4151
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4152
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4153
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4154
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4155
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4156
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4157
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4158
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4159
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4160
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4161
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4162
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000460"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4163
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4164
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4165
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4166
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4167
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4168
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4169
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4170
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\x95\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xb0\r\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x19\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x90\\x97\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x87\\xd0\\x8eV\\x02\\x00\\x00`\\x97\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x97\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00`\\x97\\xed\\x1c\\x97\\x00\\x00\\x00T\\x04\\x00\\x00\\x00\\x00\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4171
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4172
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4173
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\"
              }
            ],
            "repeated": 0,
            "id": 4174
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4175
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000460"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4176
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4177
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4178
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4179
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4180
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4181
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4182
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4183
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e4"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4184
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4185
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4186
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4187
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4188
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4189
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4190
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4191
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "h\\x99\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00@\t\\xae\\xf5<4\\x00\\x00h\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xe1\\xca\\xe0\\xfe\\x7f\\x00\\x00\\x00\\x9b\\xed\\x1c\\x97\\x00\\x00\\x00 X\\xc6\\x8eV\\x02\\x00\\x00\\x10\\x9e\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\x9a\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00OzH\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x9a\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00h\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xeaj\\xc0\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0\\xfe\\x7f\\x00\\x00\\xd0\\x9a\\xed\\x1c\\x97\\x00\\x00\\x00\\xd0\\xd7\\xca\\xe0\\xfe\\x7f\\x00\\x00k\\x02\\x10\\xe1\\xfe\\x7f\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4192
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4193
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000003",
                "pretty_value": "HKEY_USERS"
              },
              {
                "name": "SubKey",
                "value": "S-1-5-18"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\S-1-5-18"
              }
            ],
            "repeated": 0,
            "id": 4194
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4195
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4196
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer"
              }
            ],
            "repeated": 0,
            "id": 4197
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4198
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4199
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4200
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4201
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4202
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4203
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4204
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4205
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4206
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4207
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4208
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4209
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4210
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4211
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4212
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4213
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4214
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4215
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4216
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4217
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4218
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4219
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4220
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4221
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4222
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4223
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4224
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004e8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4225
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4226
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4227
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores"
              }
            ],
            "repeated": 0,
            "id": 4228
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4229
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4230
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4231
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000454"
              },
              {
                "name": "SubKey",
                "value": ""
              },
              {
                "name": "Handle",
                "value": "0x000004e8"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              }
            ],
            "repeated": 0,
            "id": 4232
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4233
          },
          {
            "timestamp": "2026-02-10 09:22:14,764",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4234
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4235
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4236
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4237
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4238
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCreateKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "Access",
                "value": "0x0003001f",
                "pretty_value": "KEY_QUERY_VALUE|KEY_SET_VALUE|KEY_CREATE_SUB_KEY|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "Handle",
                "value": "0x000004ec"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              },
              {
                "name": "Disposition",
                "value": "2",
                "pretty_value": "REG_OPENED_EXISTING_KEY"
              }
            ],
            "repeated": 0,
            "id": 4239
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004ec"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4240
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4241
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4242
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4243
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4244
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4245
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4246
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4247
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4248
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4249
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000458"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x000004f8"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4250
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000004f8"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4251
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4252
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000460"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x000004fc"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 4253
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004fc"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000500"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4254
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000500"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4255
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4256
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004fc"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000500"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4257
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000500"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4258
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4259
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004fc"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000500"
              },
              {
                "name": "FullName",
                "value": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4260
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000500"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4261
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4262
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4263
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4264
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000508"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4265
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000508"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4266
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4267
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000508"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4268
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000508"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4269
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4270
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e4"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000508"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4271
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000508"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4272
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000508"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "1"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4273
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegEnumKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              },
              {
                "name": "Index",
                "value": "0"
              },
              {
                "name": "Name",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4274
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000508"
              },
              {
                "name": "SubKey",
                "value": "27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              },
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA"
              }
            ],
            "repeated": 0,
            "id": 4275
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4276
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "ValueName",
                "value": "Blob"
              },
              {
                "name": "Data",
                "value": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob"
              }
            ],
            "repeated": 0,
            "id": 4277
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4278
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4279
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4280
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              },
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
              }
            ],
            "repeated": 0,
            "id": 4281
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000050c"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4282
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000510"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4283
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4284
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000050c"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4285
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000510"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4286
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4287
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000050c"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4288
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000510"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4289
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4290
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4291
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4292
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "Certificates"
              },
              {
                "name": "Handle",
                "value": "0x00000518"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
              }
            ],
            "repeated": 0,
            "id": 4293
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000518"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4294
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4295
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CRLs"
              },
              {
                "name": "Handle",
                "value": "0x00000518"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
              }
            ],
            "repeated": 0,
            "id": 4296
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000518"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4297
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4298
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000004e8"
              },
              {
                "name": "SubKey",
                "value": "CTLs"
              },
              {
                "name": "Handle",
                "value": "0x00000518"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
              }
            ],
            "repeated": 0,
            "id": 4299
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegQueryInfoKeyW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000518"
              },
              {
                "name": "Class",
                "value": ""
              },
              {
                "name": "SubKeyCount",
                "value": "0"
              },
              {
                "name": "MaxSubKeyLength",
                "value": "0"
              },
              {
                "name": "MaxClassLength",
                "value": "0"
              },
              {
                "name": "ValueCount",
                "value": "0"
              },
              {
                "name": "MaxValueNameLength",
                "value": "0"
              },
              {
                "name": "MaxValueLength",
                "value": "0"
              }
            ],
            "repeated": 1,
            "id": 4300
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 4301
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4302
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4303
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 4304
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 4305
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 4306
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 4307
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 4308
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 4309
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 4310
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 4311
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 4312
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 4313
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 4314
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 4315
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 4316
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 4317
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4318
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4a74",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4319
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3e0c",
            "parentcaller": "0x7ff70a3b4c08",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\"\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03'\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x05\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 5,
            "id": 4320
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4321
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00n`\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4322
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "n`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4323
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004ec"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4324
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004ec"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4325
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4326
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4327
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 4328
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4329
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4330
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000454"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4331
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b4c35",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 4332
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5451",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4333
          },
          {
            "timestamp": "2026-02-10 09:22:14,780",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4334
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4335
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb1`\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4336
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4337
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000045c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda770"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4338
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4339
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4340
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4341
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 4342
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4343
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4344
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d0"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4345
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b54ed",
            "parentcaller": "0x7ff70a3b5886",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d0"
              }
            ],
            "repeated": 0,
            "id": 4346
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4347
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 4348
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4349
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 4350
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4351
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4352
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4353
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4354
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4355
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 4356
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4357
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4358
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 4359
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 4360
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              }
            ],
            "repeated": 0,
            "id": 4361
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4362
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 0,
            "id": 4363
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 4364
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4365
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              }
            ],
            "repeated": 0,
            "id": 4366
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 4367
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4368
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              }
            ],
            "repeated": 0,
            "id": 4369
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 4370
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4371
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 0,
            "id": 4372
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 4373
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 4374
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 4375
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d053",
            "parentcaller": "0x7ff70a39d26d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 4376
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d333",
            "parentcaller": "0x7ff70a39e83d",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "103"
              }
            ],
            "repeated": 0,
            "id": 4377
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4378
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4379
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4380
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4381
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4382
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4383
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4384
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4385
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4386
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4387
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4388
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4389
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec98640",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4390
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4391
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4392
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004c8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4393
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004c8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4394
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004cc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda6b0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4395
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4396
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4397
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4398
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4399
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4400
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4401
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4402
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4403
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4404
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4405
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4406
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4407
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4408
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4409
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4410
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4411
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4412
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4413
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4414
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4415
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4416
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4417
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4418
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4419
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4420
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4421
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4422
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4423
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4424
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4425
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4426
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4427
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4428
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4429
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4430
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4431
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4432
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 1,
            "id": 4433
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 11,
            "id": 4434
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4435
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4436
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4437
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4438
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39c9bc",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 6,
            "id": 4439
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4440
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004cc"
              }
            ],
            "repeated": 0,
            "id": 4441
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c8"
              }
            ],
            "repeated": 0,
            "id": 4442
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1e000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000c000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4443
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed13000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4444
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c4"
              }
            ],
            "repeated": 0,
            "id": 4445
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004c0"
              }
            ],
            "repeated": 0,
            "id": 4446
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004bc"
              }
            ],
            "repeated": 0,
            "id": 4447
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b8"
              }
            ],
            "repeated": 0,
            "id": 4448
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4449
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b4"
              }
            ],
            "repeated": 0,
            "id": 4450
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004b0"
              }
            ],
            "repeated": 0,
            "id": 4451
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ac"
              }
            ],
            "repeated": 0,
            "id": 4452
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a8"
              }
            ],
            "repeated": 0,
            "id": 4453
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a4"
              }
            ],
            "repeated": 0,
            "id": 4454
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004a0"
              }
            ],
            "repeated": 0,
            "id": 4455
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000049c"
              }
            ],
            "repeated": 0,
            "id": 4456
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000498"
              }
            ],
            "repeated": 0,
            "id": 4457
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000494"
              }
            ],
            "repeated": 0,
            "id": 4458
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000490"
              }
            ],
            "repeated": 0,
            "id": 4459
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000048c"
              }
            ],
            "repeated": 0,
            "id": 4460
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000488"
              }
            ],
            "repeated": 0,
            "id": 4461
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000484"
              }
            ],
            "repeated": 0,
            "id": 4462
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000480"
              }
            ],
            "repeated": 0,
            "id": 4463
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000047c"
              }
            ],
            "repeated": 0,
            "id": 4464
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 4465
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000474"
              }
            ],
            "repeated": 0,
            "id": 4466
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 4467
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4468
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4469
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4470
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39ca11",
            "parentcaller": "0x7ff70a39d3c8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 4471
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a39d424",
            "parentcaller": "0x7ff70a39e83d",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SYSTEM\\CurrentControlSet\\Control\\MiniNT"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MiniNT"
              }
            ],
            "repeated": 0,
            "id": 4472
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a395b15",
            "parentcaller": "0x7ff70a39d5aa",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4473
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a395b3c",
            "parentcaller": "0x7ff70a39d5aa",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 4474
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5ba0",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4475
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\n\\x00\\x00\\x00\\x00\\x00pd\n\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4476
          },
          {
            "timestamp": "2026-02-10 09:22:14,796",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 4477
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbc90"
              },
              {
                "name": "ViewSize",
                "value": "0x000a7000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4478
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "RegionSize",
                "value": "0x000a7000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4479
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4480
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPPutSignedDataMsg"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee14a0790"
              }
            ],
            "repeated": 0,
            "id": 4481
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 4482
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000338"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4483
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4484
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptSIPCreateIndirectData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1477d80"
              }
            ],
            "repeated": 0,
            "id": 4485
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "WVTAsn1SpcPeImageDataEncode"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1480890"
              }
            ],
            "repeated": 0,
            "id": 4486
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4487
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4488
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4489
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1390000"
              },
              {
                "name": "FunctionName",
                "value": "GetHashInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee13a4460"
              }
            ],
            "repeated": 2,
            "id": 4490
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\n\\x00\\x00\\x00\\x00\\x00pd\n\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4491
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 4492
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x25691040000"
              },
              {
                "name": "RegionSize",
                "value": "0x00100000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4493
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x25691040000"
              },
              {
                "name": "RegionSize",
                "value": "0x00082000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4494
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 2,
            "id": 4495
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtReadFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "Buffer",
                "value": "MZ\\x90\\x00\\x03\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\xff\\xff\\x00\\x00\\xb8\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\x00\\x00\\x00\\x0e\\x1f\\xba\\x0e\\x00\\xb4\t\\xcd!\\xb8\\x01L\\xcd!This program cannot be run in DOS mode.\r\r\n$\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa9e\\xc5\\x81\\xed\\x04\\xab\\xd2\\xed\\x04\\xab\\xd2\\xed\\x04\\xab\\xd2\\xf9o\\xad\\xd3\\xea\\x04\\xab\\xd2\\xf9o\\xa8\\xd3\\xe8\\x04\\xab\\xd2\\xf9o\\xaf\\xd3\\xe5\\x04\\xab\\xd2\\xf9o\\xaa\\xd3\\xe7\\x04\\xab\\xd2\\xe4|8\\xd2\\xee\\x04\\xab\\xd2\\xed\\x04\\xaa\\xd2\\xa4\\x05\\xab\\xd2$i\\xaf\\xd3\\xd4\\x04\\xab\\xd2$iT\\xd2\\xec\\x04\\xab\\xd2$i\\xa9\\xd3\\xec\\x04\\xab\\xd2Rich\\xed\\x04\\xab\\xd2\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00PE\\x00\\x00d\\x86\\x08\\x00!\\xdatc\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x00\"\\x00"
              },
              {
                "name": "Length",
                "value": "524288"
              }
            ],
            "repeated": 0,
            "id": 4496
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4497
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb960"
              },
              {
                "name": "ViewSize",
                "value": "0x000a7000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4498
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f3c0000"
              },
              {
                "name": "RegionSize",
                "value": "0x000a7000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4499
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5bef",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4500
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4501
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4502
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 4503
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000468"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbeb0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4504
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4505
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4506
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4507
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4508
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4509
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005\\x006\\x003\\x007\\x004\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4510
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04Jc\\x006\\x00f\\x00a\\x00e\\x001\\x00d\\x005\\x00-\\x003\\x007\\x00b\\x005\\x00-\\x004\\x001\\x007\\x00b\\x00-\\x00a\\x00f\\x00b\\x005\\x00-\\x00a\\x004\\x00a\\x001\\x00a\\x00f\\x001\\x00b\\x009\\x00b\\x009\\x005\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4511
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4512
          },
          {
            "timestamp": "2026-02-10 09:22:14,811",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4513
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4514
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x16m\\x00s\\x00_\\x00n\\x00d\\x00i\\x00s\\x00l\\x00w\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4515
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4516
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 3,
            "id": 4517
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "04\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\"v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00_\\x00o\\x00p\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4518
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4519
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4520
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f260000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4521
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cd4",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4522
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0R\\x1eL\\x00{\\x00C\\x006\\x008\\x009\\x00A\\x00A\\x00B\\x008\\x00-\\x008\\x00E\\x007\\x008\\x00-\\x001\\x001\\x00D\\x000\\x00-\\x008\\x00C\\x004\\x007\\x00-\\x000\\x000\\x00C\\x000\\x004\\x00F\\x00C\\x002\\x009\\x005\\x00E\\x00E\\x00}\\x02\\x02\\x02\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4523
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5cff",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0=0\\x18\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x02\\x01\\x0f0\n\\x03\\x02\\x05\\xa0\\xa0\\x04\\xa2\\x02\\x80\\x000!0\t\\x06\\x05+\\x0e\\x03\\x02\\x1a\\x05\\x00\\x04\\x14\\x81\\xfbW\\x96w\\x15\\xbaD+\\xb4(\\xc0q)\\xc6\\xf0jM\\x8d\\xd8"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4524
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5d85",
            "parentcaller": "0x7ff70a39d5b9",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 4525
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c2839",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 4526
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c2839",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee3470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "ntdll.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000800"
              }
            ],
            "repeated": 0,
            "id": 4527
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c2857",
            "parentcaller": "0x7ff70a3c2775",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlGetNtSystemRoot"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee3486bb0"
              }
            ],
            "repeated": 0,
            "id": 4528
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c0c07",
            "parentcaller": "0x7ff70a3bdd74",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4529
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c0b0a",
            "parentcaller": "0x7ff70a3bdd74",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x90\\x01\\x00\\x00\\x00\\x00\\x00\\x0co\\x04\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 1,
            "id": 4530
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c15fe",
            "parentcaller": "0x7ff70a3c0d7d",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000030c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\apppatch\\drvmain.sdb"
              }
            ],
            "repeated": 0,
            "id": 4531
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c1650",
            "parentcaller": "0x7ff70a3c0d7d",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000464"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7df472ad0000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00047000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4532
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c52cd",
            "parentcaller": "0x7ff70a3bb108",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 4533
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b66fe",
            "parentcaller": "0x7ff70a39e37c",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf\\*.*"
              }
            ],
            "repeated": 0,
            "id": 4534
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c0f08",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 4535
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c0f23",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4536
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3c0f42",
            "parentcaller": "0x7ff70a3be0cc",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7df472ad0000"
              },
              {
                "name": "RegionSize",
                "value": "0x00047000"
              }
            ],
            "repeated": 0,
            "id": 4537
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b686d",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 4538
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b68a5",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "ValueName",
                "value": "SystemSetupInProgress"
              },
              {
                "name": "Data",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 4539
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b68b8",
            "parentcaller": "0x7ff70a3b3f4c",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4540
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b6920",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "System\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\System\\Setup"
              }
            ],
            "repeated": 0,
            "id": 4541
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b6958",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "ValueName",
                "value": "PnpSetupInProgress"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress"
              }
            ],
            "repeated": 0,
            "id": 4542
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b6978",
            "parentcaller": "0x7ff70a3b3f55",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 4543
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed13000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4544
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4545
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 4546
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4547
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x25691041000"
              },
              {
                "name": "RegionSize",
                "value": "0x00080000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4548
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4549
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed13000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 4550
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4551
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3f96",
            "parentcaller": "0x7ff70a39e3bd",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed13000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4552
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4553
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x02a\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4554
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4555
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4556
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4557
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4558
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Ta\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4559
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4560
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 4561
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Ta\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4562
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "Ta\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4563
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "Ta\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4564
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4565
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4566
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-security-cryptoapi-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee0450000"
              }
            ],
            "repeated": 0,
            "id": 4567
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee0450000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-security-cryptoapi-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 4568
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0450000"
              },
              {
                "name": "FunctionName",
                "value": "CryptAcquireContextW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee0452450"
              }
            ],
            "repeated": 0,
            "id": 4569
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4570
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\rsaenh.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedfb90000"
              }
            ],
            "repeated": 0,
            "id": 4571
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptAcquireContextW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Container",
                "value": ""
              },
              {
                "name": "Provider",
                "value": ""
              },
              {
                "name": "Flags",
                "value": "0xf0000000"
              }
            ],
            "repeated": 0,
            "id": 4572
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4573
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1470000"
              }
            ],
            "repeated": 0,
            "id": 4574
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1470000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 4575
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATOpen"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee149a310"
              }
            ],
            "repeated": 0,
            "id": 4576
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4577
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4578
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4579
          },
          {
            "timestamp": "2026-02-10 09:22:14,827",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 4580
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc6b0"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4581
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 4582
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4583
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 4584
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4585
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4586
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005\\x006\\x003\\x007\\x004\\x001\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4587
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0d\\x1e\\x10\\x00B\\x00u\\x00n\\x00d\\x00l\\x00e\\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04Jc\\x006\\x00f\\x00a\\x00e\\x001\\x00d\\x005\\x00-\\x003\\x007\\x00b\\x005\\x00-\\x004\\x001\\x007\\x00b\\x00-\\x00a\\x00f\\x00b\\x005\\x00-\\x00a\\x004\\x00a\\x001\\x00a\\x00f\\x001\\x00b\\x009\\x00b\\x009\\x005\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4588
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0&\\x1e\\x12\\x00U\\x00n\\x00i\\x00v\\x00e\\x00r\\x00s\\x00a\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4589
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\\x16\\x00D\\x00e\\x00c\\x00l\\x00a\\x00r\\x00a\\x00t\\x00i\\x00v\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\nT\\x00r\\x00u\\x00e\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4590
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0L\\x1e\\x04\\x00O\\x00S\\x02\\x04\\x10\\x01\\x00\\x01\\x04>V\\x00i\\x00s\\x00t\\x00a\\x00X\\x008\\x006\\x00,\\x00V\\x00i\\x00s\\x00t\\x00a\\x00X\\x006\\x004\\x00,\\x00_\\x00v\\x001\\x000\\x000\\x00_\\x00X\\x006\\x004\\x00_\\x00V\\x00b\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4591
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0*\\x1e\n\\x00H\\x00W\\x00I\\x00D\\x001\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x16m\\x00s\\x00_\\x00n\\x00d\\x00i\\x00s\\x00l\\x00w\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4592
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4593
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 3,
            "id": 4594
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "04\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\"v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00_\\x00o\\x00p\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4595
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "0,\\x1e\\x08\\x00F\\x00i\\x00l\\x00e\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1av\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4596
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00010001"
              },
              {
                "name": "Encoded",
                "value": "00\\x1e\\x0c\\x00O\\x00S\\x00A\\x00t\\x00t\\x00r\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x1a2\\x00:\\x006\\x00.\\x000\\x00,\\x002\\x00:\\x001\\x000\\x00.\\x000\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 4597
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4598
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4599
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4600
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATEnumerateCatAttr"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee147bd40"
              }
            ],
            "repeated": 0,
            "id": 4601
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4602
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4603
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1470000"
              },
              {
                "name": "FunctionName",
                "value": "CryptCATClose"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1473150"
              }
            ],
            "repeated": 0,
            "id": 4604
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4605
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4606
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "CRYPTSP.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee0450000"
              },
              {
                "name": "FunctionName",
                "value": "CryptReleaseContext"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee04536b0"
              }
            ],
            "repeated": 0,
            "id": 4607
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4608
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4609
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00Ta\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4610
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Ta\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4611
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4612
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc600"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4613
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4614
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4615
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 4616
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4617
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4618
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4619
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4620
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4621
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4622
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x8ba\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4623
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4624
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc600"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4625
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4626
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4627
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 4628
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4629
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4630
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4631
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4632
          },
          {
            "timestamp": "2026-02-10 09:22:14,842",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4633
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4634
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3a\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4635
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4636
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000450"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc600"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4637
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "7b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4638
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4639
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 4640
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "7b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4641
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "7b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4642
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000004d8"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "7b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4643
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4644
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4645
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4646
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4647
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4648
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4649
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4650
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4651
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4652
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4653
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4654
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4655
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4656
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6bd50",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4657
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 4658
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000056c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4659
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000056c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4660
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000570"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000056c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4661
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000570"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb570"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4662
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4663
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4664
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 4665
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4666
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1e000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000c000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4667
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4668
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4669
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4670
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4671
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4672
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4673
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4674
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4675
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4676
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4677
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4678
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4679
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4680
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4681
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4682
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4683
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4684
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4685
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4686
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4687
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4688
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4689
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4690
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4691
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4692
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4693
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4694
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4695
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4696
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4697
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4698
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4699
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4700
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 1,
            "id": 4701
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 14,
            "id": 4702
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 4703
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000578"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4704
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4705
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 4706
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 8,
            "id": 4707
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000584"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4708
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000584"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4709
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000588"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000584"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4710
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000588"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbca0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4711
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4712
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4713
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              }
            ],
            "repeated": 0,
            "id": 4714
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4715
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 4716
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 4717
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000578"
              }
            ],
            "repeated": 0,
            "id": 4718
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4719
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 4720
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 4721
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 4722
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 4723
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 4724
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 4725
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 4726
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 4727
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 4728
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 4729
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 4730
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 4731
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 4732
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 4733
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              }
            ],
            "repeated": 0,
            "id": 4734
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 4735
          },
          {
            "timestamp": "2026-02-10 09:22:14,858",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 4736
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 4737
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 4738
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 4739
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              }
            ],
            "repeated": 0,
            "id": 4740
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              }
            ],
            "repeated": 0,
            "id": 4741
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4742
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 4743
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              }
            ],
            "repeated": 0,
            "id": 4744
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              },
              {
                "name": "MutexName",
                "value": "Global\\DriverStore_Mutex_vsdatant.inf_amd64_c01fe17aaf09e5fc"
              },
              {
                "name": "InitialOwner",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 4745
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4746
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x007b\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4747
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "7b\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4748
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4749
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc600"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4750
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4751
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4752
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4753
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4754
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4755
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4756
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4757
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4758
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4759
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4760
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4761
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9bb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4762
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4763
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4764
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4765
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xddb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4766
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4767
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4768
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xddb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4769
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xddb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4770
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xddb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4771
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4772
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4773
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xddb\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4774
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xddb\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4775
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4776
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4777
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4778
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4779
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4780
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4781
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4782
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "1c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4783
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "1c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4784
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4785
          },
          {
            "timestamp": "2026-02-10 09:22:14,874",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository"
              }
            ],
            "repeated": 0,
            "id": 4786
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4787
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x001c\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4788
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4789
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000568"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4790
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000568"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbca0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4791
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4792
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4793
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4794
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 4795
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4796
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4797
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4798
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4799
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4800
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4801
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xb6c\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4802
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000568"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4803
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000568"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbce0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4804
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4805
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4806
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 4807
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4808
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "6d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4809
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "6d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4810
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4811
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b8d0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\*"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbe1f86dc"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 4812
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc"
              }
            ],
            "repeated": 0,
            "id": 4813
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\"
              }
            ],
            "repeated": 0,
            "id": 4814
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc"
              }
            ],
            "repeated": 0,
            "id": 4815
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6bd50",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4816
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4817
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 4818
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4819
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xd7\\xd1\\x8eV\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc6\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00c\\x000\\x001\\x00f\\x00e\\x001\\x007\\x00a\\x00a\\x00f\\x000\\x009\\x00e\\x005\\x00f\\x00c\\x00\\\\x00V\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00c\\x00a\\x00t\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4820
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4821
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec98340",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4822
          },
          {
            "timestamp": "2026-02-10 09:22:14,889",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4823
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4824
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4825
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xd7\\xd1\\x8eV\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc6\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00c\\x000\\x001\\x00f\\x00e\\x001\\x007\\x00a\\x00a\\x00f\\x000\\x009\\x00e\\x005\\x00f\\x00c\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4826
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4827
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4828
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4829
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": false,
            "return": "0xffffffffffffffff",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 4830
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 4831
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "11",
                "pretty_value": "FileLinkInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\xd7\\xd1\\x8eV\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc6\\x00\\x00\\x00\\\\x00?\\x00?\\x00\\\\x00C\\x00:\\x00\\\\x00W\\x00i\\x00n\\x00d\\x00o\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00D\\x00r\\x00i\\x00v\\x00e\\x00r\\x00S\\x00t\\x00o\\x00r\\x00e\\x00\\\\x00F\\x00i\\x00l\\x00e\\x00R\\x00e\\x00p\\x00o\\x00s\\x00i\\x00t\\x00o\\x00r\\x00y\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00c\\x000\\x001\\x00f\\x00e\\x001\\x007\\x00a\\x00a\\x00f\\x000\\x009\\x00e\\x005\\x00f\\x00c\\x00\\\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00s\\x00y\\x00s\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4832
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4833
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4834
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4835
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x006d\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4836
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4837
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000055c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4838
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000055c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedbca0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4839
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4840
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4841
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4842
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 4843
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4844
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4845
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000468"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4846
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 4847
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4848
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x80\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4849
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000055c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0110080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|DELETE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\drvstore.tmp"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "4",
                "pretty_value": "FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000102",
                "pretty_value": "FILE_ATTRIBUTE_HIDDEN|FILE_ATTRIBUTE_TEMPORARY"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4850
          },
          {
            "timestamp": "2026-02-10 09:22:14,905",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4851
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x80d\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4852
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x80d\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4853
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4854
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb500"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4855
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4856
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4857
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4858
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 4859
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4860
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4861
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000568"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4862
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 4863
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4864
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4865
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4866
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4867
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4868
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4869
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4870
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4871
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4872
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4873
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4874
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4875
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 4876
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 4877
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000580"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4878
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000580"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4879
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000574"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000580"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 4880
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000574"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda510"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4881
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4882
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4883
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 4884
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4885
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 4886
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 4887
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4888
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4889
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4890
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4891
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4892
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4893
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4894
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4895
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4896
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4897
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4898
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4899
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4900
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4901
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4902
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4903
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4904
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4905
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4906
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4907
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4908
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4909
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4910
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4911
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4912
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4913
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4914
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4915
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4916
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4917
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 4918
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 1,
            "id": 4919
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 14,
            "id": 4920
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 4921
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4922
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4923
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 4924
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 8,
            "id": 4925
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4926
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4927
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4928
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x19\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4929
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4930
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\xf434j&V\\xe8@\\xa9\\xb9\\xdb\\xd9\\xec\\xd2\\x88K\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4931
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4932
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4933
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4934
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\n\\x00\\x00\\x00\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x84\\xb8\\xed\\x1c\\x97\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4935
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0b\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4936
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0c\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xb9\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4937
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\xbb\\xed\\x1c\\x97\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4938
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0e\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\xbb\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4939
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x0f\\x00\\x00\\x00\t\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\xbb\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4940
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00F\\xdc\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4941
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00h^+\\x8fV\\x02\\x00\\x00:\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4942
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x07\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\xee\\xed\\x1c\\x97\\x00\\x00\\x00f\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4943
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\xc1b\\xa1M\\xb1^@A\\xa4DPd\\xc9\\x81Nv\t\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\xed\\x1c\\x97\\x00\\x00\\x00^\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4944
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4945
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x000D\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x1a\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf8\\xb2\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4946
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba%\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00d\\xbd\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4947
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x08\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4948
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x15\\x00\\x00\\x00\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\xed\\x1c\\x97\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4949
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4950
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4951
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\"e\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4952
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\"e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4953
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000058c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4954
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000058c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb540"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4955
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4956
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4957
          },
          {
            "timestamp": "2026-02-10 09:22:14,921",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              }
            ],
            "repeated": 0,
            "id": 4958
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4959
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4960
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4961
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4962
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x01\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4963
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\xc0\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4964
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x04\\x00\\x00\\x00\\x03\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\x9d\\xce\\x8eV\\x02\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4965
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4966
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4967
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\xda\\xba\\x80\\xb5"
              }
            ],
            "repeated": 0,
            "id": 4968
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00`=\\x38eV\\x02\\x00\\x00\"\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4969
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x000@\\x38eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4970
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0<\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4971
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0<\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4972
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4973
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4974
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4975
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x9fe\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4976
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000058c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4977
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000058c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb540"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4978
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4979
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4980
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              }
            ],
            "repeated": 0,
            "id": 4981
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4982
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4983
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4984
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 4985
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0>\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4986
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x17\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4987
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00`~\\xc9\\x8eV\\x02\\x00\\x00J\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4988
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4989
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x02f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4990
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x02f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4991
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000594"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 4992
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000594"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb540"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 4993
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "rf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4994
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 4995
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 4996
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "rf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4997
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "rf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4998
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000588"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "rf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 4999
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 5000
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x000D\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5001
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5002
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5003
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5004
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 5005
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 5006
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 5007
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000578"
              }
            ],
            "repeated": 0,
            "id": 5008
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              }
            ],
            "repeated": 0,
            "id": 5009
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 5010
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 5011
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5012
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 5013
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              }
            ],
            "repeated": 0,
            "id": 5014
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5015
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 5016
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              }
            ],
            "repeated": 0,
            "id": 5017
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5018
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 5019
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              }
            ],
            "repeated": 0,
            "id": 5020
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 5021
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 5022
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5023
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5024
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5025
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5026
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5027
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5028
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5029
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5030
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5031
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5032
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5033
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5034
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00rf\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5035
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "rf\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5036
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5037
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb500"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5038
          },
          {
            "timestamp": "2026-02-10 09:22:14,936",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5039
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5040
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5041
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5042
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5043
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5044
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5045
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5046
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5047
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5048
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc5f\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5049
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5050
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedba90"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5051
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5052
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "fg\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5053
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5054
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5055
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "fg\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5056
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "fg\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5057
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "fg\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5058
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5059
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5060
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5061
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00`~\\x24eV\\x02\\x00\\x00X\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5062
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x000D\\x28eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5063
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x002\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x3ceV\\x02"
              }
            ],
            "repeated": 0,
            "id": 5064
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\xbd\\xed\\x1c\\x97\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5065
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5066
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5067
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5068
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe0>\\xce\\x8eV\\x02\\x00\\x00\"\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5069
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00P>\\x38eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5070
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5071
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5072
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00`~\\x24eV\\x02\\x00\\x00X\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5073
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\x28eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd4\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5074
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0<\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0J\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5075
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0<\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00J\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00s\\x00d\\x00a\\x00t\\x00a\\x00n\\x00t\\x00.\\x00i\\x00n\\x00f\\x00_\\x00a\\x00m\\x00d\\x006\\x004\\x00_\\x00c\\x000\\x001\\x00f\\x00e\\x001\\x007\\x00a\\x00a\\x00f\\x000\\x009\\x00e\\x005\\x00f\\x00c\\x00\\x00\\x00\\x00\\x00t\\x00m\\x00"
              }
            ],
            "repeated": 0,
            "id": 5076
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00Z\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5077
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00`~\\xc9\\x8eV\\x02\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x11\\x00\\x00\\x00\\xff\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5078
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00`~\\xc9\\x8eV\\x02\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\n\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x05\\x00\\x00\\x00\t\\x00\\x00\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 5079
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00 >\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5080
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5081
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00fg\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5082
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "fg\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5083
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000030c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5084
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000030c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedaa30"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5085
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5086
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5087
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 5088
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5089
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5090
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5091
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5092
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5093
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "kernel32.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1660000"
              }
            ],
            "repeated": 0,
            "id": 5094
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1660000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "kernel32.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5095
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 5096
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 5097
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 5098
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 5099
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 5100
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 5101
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 5102
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:1620:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5103
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5104
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5105
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5106
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5107
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5108
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              }
            ],
            "repeated": 0,
            "id": 5109
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5110
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5111
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5112
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNEL32.DLL"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1660000"
              },
              {
                "name": "FunctionName",
                "value": "PrivCopyFileExW"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee1682940"
              }
            ],
            "repeated": 0,
            "id": 5113
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5114
          },
          {
            "timestamp": "2026-02-10 09:22:14,952",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5115
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "35",
                "pretty_value": "FileAttributeTagInformation"
              },
              {
                "name": "FileInformation",
                "value": " \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5116
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5117
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\xbe'\\x9a\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01_\\xc3\\x97\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5118
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "22",
                "pretty_value": "FileStreamInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x0e\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00:\\x00:\\x00$\\x00D\\x00A\\x00T\\x00A\\x00"
              }
            ],
            "repeated": 0,
            "id": 5119
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01\\xbe'\\x9a\\xben\\x9a\\xdc\\x01\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01_\\xc3\\x97\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5120
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000464"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "7",
                "pretty_value": "FileEaInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5121
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0150081",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ACCESS|FILE_READ_ATTRIBUTES|DELETE|WRITE_DAC|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "5",
                "pretty_value": "FILE_OVERWRITE_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000020",
                "pretty_value": "FILE_ATTRIBUTE_ARCHIVE"
              },
              {
                "name": "ExistedBefore",
                "value": "no"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5122
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xd3M\\xa1\\xben\\x9a\\xdc\\x01\\xd3M\\xa1\\xben\\x9a\\xdc\\x01\\xd3M\\xa1\\xben\\x9a\\xdc\\x01\\xd3M\\xa1\\xben\\x9a\\xdc\\x01 \\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5123
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0x00000464"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000598"
              },
              {
                "name": "Options",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5124
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000598"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 5125
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              }
            ],
            "repeated": 1,
            "id": 5126
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5127
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "GetVolumeInformationByHandleW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              },
              {
                "name": "VolumeName",
                "value": ""
              },
              {
                "name": "VolumeSerial",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5128
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5129
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              }
            ],
            "repeated": 0,
            "id": 5130
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\xb6\\x97\\x8f\\xfa\\xd8\\x01_\\xc3\\x97\\xben\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5131
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": false,
            "return": "0xffffffffc000000d",
            "pretty_return": "INVALID_PARAMETER",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "55",
                "pretty_value": "FileReplaceCompletionInformation"
              },
              {
                "name": "FileInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 5132
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5133
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5134
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5135
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5136
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5137
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc6g\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5138
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000059c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5139
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000059c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda560"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5140
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5141
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5142
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000059c"
              }
            ],
            "repeated": 0,
            "id": 5143
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5144
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "1h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5145
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "1h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5146
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5147
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "3",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5148
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5149
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000594"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd3M\\xa1\\xben\\x9a\\xdc\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5150
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5151
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 5152
          },
          {
            "timestamp": "2026-02-10 09:22:14,967",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5153
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5154
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5155
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5156
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5157
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5158
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5159
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5160
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5161
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5162
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5163
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5164
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec98340",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5165
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5166
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5167
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5168
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 5169
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced8f10"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5170
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5171
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5172
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5173
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5174
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 5175
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 5176
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5177
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5178
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5179
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5180
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5181
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5182
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5183
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5184
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5185
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5186
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5187
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5188
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5189
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5190
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5191
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5192
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5193
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5194
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5195
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5196
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5197
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5198
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5199
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5200
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5201
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5202
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5203
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5204
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5205
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5206
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5207
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 1,
            "id": 5208
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 14,
            "id": 5209
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5210
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5211
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5212
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5213
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 8,
            "id": 5214
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5215
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00`\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00@\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5216
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5217
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\n\\x01\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5218
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xb0@\\xca\\x8eV\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\n\\x01\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00n\\x00e\\x00t\\x00s\\x00e\\x00r\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00b\\x00r\\x00d\\x00g\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00n\\x00w\\x00i\\x00f\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00v\\x00w\\x00i\\x00f\\x00i\\x00f\\x00l\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00d\\x00i\\x00s\\x00c\\x00a\\x00p\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00w\\x00f\\x00p\\x00c\\x00a\\x00p\\x00t\\x00u\\x00r\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00r\\x00a\\x00s\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00s\\x00e\\x00r\\x00v\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00e\\x00t\\x00n\\x00b\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5219
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\xca\\x8eV\\x02\\x00\\x00`\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x000\t\\xca\\x8eV\\x02\\x00\\x00\\x1c\\x01\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5220
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 1,
            "id": 5221
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5222
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 3,
            "id": 5223
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5224
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5225
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5226
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5227
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5228
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5229
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5230
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 1,
            "id": 5231
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 7,
            "id": 5232
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5233
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 2,
            "id": 5234
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5235
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5236
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5237
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 13,
            "id": 5238
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5239
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 4,
            "id": 5240
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5241
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5242
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5243
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 37,
            "id": 5244
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5245
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 16,
            "id": 5246
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5247
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 3,
            "id": 5248
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5249
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5250
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5251
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 1,
            "id": 5252
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5253
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 1,
            "id": 5254
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5255
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 1,
            "id": 5256
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5257
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 37,
            "id": 5258
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5259
          },
          {
            "timestamp": "2026-02-10 09:22:14,983",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 9,
            "id": 5260
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\x38eV\\x02\\x00\\x00(\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5261
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00pB\\x38eV\\x02\\x00\\x00(\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x05\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5262
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 5263
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00`C\\xce\\x8eV\\x02\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5264
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xa0B\\xce\\x8eV\\x02\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x8a\\xc8\\x8eV\\x02\\x00\\x00\\x18\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5265
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5266
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x001h\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5267
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "1h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5268
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5269
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000057c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced9f40"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5270
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5271
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5272
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5273
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5274
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5275
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000550"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5276
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 5277
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5278
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5279
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5280
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5281
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5282
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5283
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5284
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5285
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 5286
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5287
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              }
            ],
            "repeated": 0,
            "id": 5288
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 5289
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5290
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5291
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 5292
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              }
            ],
            "repeated": 0,
            "id": 5293
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5294
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 5295
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5296
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5297
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5298
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5299
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5300
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5301
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5302
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5303
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5304
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5305
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5306
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5307
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5308
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5309
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5310
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5311
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x01\\x00\\x00\\x00\\x00\\x00@?\\xce\\x8eV\\x02\\x00\\x00$\\x00\\x00\\x00\\x02\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x03\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x00\\x00\\x00\\x00`~\\xc9\\x8eV\\x02\\x00\\x00H\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5312
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5313
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5314
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5315
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5316
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5317
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5318
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5319
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5320
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5321
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5322
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5323
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec98340",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5324
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 5325
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5326
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5327
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 5328
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000046c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ced9980"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5329
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5330
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5331
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5332
          },
          {
            "timestamp": "2026-02-10 09:22:14,999",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5333
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5334
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5335
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5336
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5337
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000053c"
              }
            ],
            "repeated": 0,
            "id": 5338
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000548"
              }
            ],
            "repeated": 0,
            "id": 5339
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000534"
              }
            ],
            "repeated": 0,
            "id": 5340
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000540"
              }
            ],
            "repeated": 0,
            "id": 5341
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000518"
              }
            ],
            "repeated": 0,
            "id": 5342
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000514"
              }
            ],
            "repeated": 0,
            "id": 5343
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000510"
              }
            ],
            "repeated": 0,
            "id": 5344
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e8"
              }
            ],
            "repeated": 0,
            "id": 5345
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000050c"
              }
            ],
            "repeated": 0,
            "id": 5346
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000508"
              }
            ],
            "repeated": 0,
            "id": 5347
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000504"
              }
            ],
            "repeated": 0,
            "id": 5348
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000500"
              }
            ],
            "repeated": 0,
            "id": 5349
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004e4"
              }
            ],
            "repeated": 0,
            "id": 5350
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004fc"
              }
            ],
            "repeated": 0,
            "id": 5351
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000460"
              }
            ],
            "repeated": 0,
            "id": 5352
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f8"
              }
            ],
            "repeated": 0,
            "id": 5353
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f4"
              }
            ],
            "repeated": 0,
            "id": 5354
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004f0"
              }
            ],
            "repeated": 0,
            "id": 5355
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000458"
              }
            ],
            "repeated": 0,
            "id": 5356
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004ec"
              }
            ],
            "repeated": 0,
            "id": 5357
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000454"
              }
            ],
            "repeated": 0,
            "id": 5358
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000045c"
              }
            ],
            "repeated": 0,
            "id": 5359
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000030c"
              }
            ],
            "repeated": 0,
            "id": 5360
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000598"
              }
            ],
            "repeated": 0,
            "id": 5361
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000464"
              }
            ],
            "repeated": 0,
            "id": 5362
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000594"
              }
            ],
            "repeated": 0,
            "id": 5363
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetSystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5364
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470817"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00@\\xb4\\xed\\x1c\\x97\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x12\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xac\\xed\\x1c\\x97\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x08\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5365
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 5366
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5367
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xc0\\xbd\\xed\\x1c\\x97\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5368
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5369
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1090000"
              }
            ],
            "repeated": 0,
            "id": 5370
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffee1090000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "api-ms-win-core-registry-l1-1-0.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 5371
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "KERNELBASE.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee1090000"
              },
              {
                "name": "FunctionName",
                "value": "RegFlushKey"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee10f2af0"
              }
            ],
            "repeated": 0,
            "id": 5372
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecee94000"
              },
              {
                "name": "ModuleName",
                "value": "drvstore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5373
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5374
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x90h\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5375
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x90h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5376
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5377
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedba70"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5378
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5379
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5380
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5381
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5382
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5383
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5384
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5385
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5386
          },
          {
            "timestamp": "2026-02-10 09:22:15,014",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x0047086b"
              },
              {
                "name": "InBuffer",
                "value": "0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xe8\\xe4\\xe4\\xce\\xfe\\x7f\\x00\\x00\\x0e\\x00\\x00\\x00\\x1f\\x00\\x02\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x04\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5387
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5388
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5389
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xe3h\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5390
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5391
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedba70"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5392
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5393
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5394
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 5395
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5396
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "6i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5397
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000057c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "6i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5398
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5399
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5400
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5401
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x006i\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5402
          },
          {
            "timestamp": "2026-02-10 09:22:15,030",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "6i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5403
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5404
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000470"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedba90"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5405
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5406
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5407
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5408
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5409
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5410
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5411
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000450"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5412
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5413
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5414
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5415
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5416
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5417
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5418
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5419
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5420
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5421
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5422
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5423
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5424
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5425
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97f80",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5426
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5427
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000528"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5428
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000528"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5429
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000051c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000528"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 5430
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000051c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971ceda920"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5431
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5432
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5433
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5434
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5435
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5436
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5437
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5438
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5439
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5440
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5441
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5442
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5443
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5444
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5445
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5446
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5447
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 5448
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              }
            ],
            "repeated": 0,
            "id": 5449
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              }
            ],
            "repeated": 0,
            "id": 5450
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5451
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5452
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 5453
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              }
            ],
            "repeated": 0,
            "id": 5454
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 5455
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 5456
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000578"
              }
            ],
            "repeated": 0,
            "id": 5457
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 5458
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 5459
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              }
            ],
            "repeated": 0,
            "id": 5460
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 5461
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5462
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000590"
              }
            ],
            "repeated": 0,
            "id": 5463
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5464
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5465
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5466
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5467
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec97e60",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5468
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5469
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100010",
                "pretty_value": "FILE_WRITE_EA|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5470
          },
          {
            "timestamp": "2026-02-10 09:22:15,046",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5471
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec98340",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5472
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5473
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5474
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x88i\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5475
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x88i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5476
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5477
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5478
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5479
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5480
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5481
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5482
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5483
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5484
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5485
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5486
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c829",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5487
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c829",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5488
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c870",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5489
          },
          {
            "timestamp": "2026-02-10 09:22:15,061",
            "thread_id": "3424",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c870",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5490
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c89d",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\oem2.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5491
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c89d",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5492
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c6dd",
            "parentcaller": "0x7ff70a39c8bc",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0x40100080",
                "pretty_value": "GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5493
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c789",
            "parentcaller": "0x7ff70a39c8bc",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5494
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5495
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5496
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xc8i\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5497
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5498
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc530"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5499
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5500
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5501
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d4"
              }
            ],
            "repeated": 0,
            "id": 5502
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5503
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5504
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000530"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5505
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39c900",
            "parentcaller": "0x7ff70a39e611",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000530"
              }
            ],
            "repeated": 0,
            "id": 5506
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39cd6c",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              },
              {
                "name": "Handle",
                "value": "0x00000470"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup"
              }
            ],
            "repeated": 0,
            "id": 5507
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdac",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              },
              {
                "name": "ValueName",
                "value": "MinimizeFootprint"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint"
              }
            ],
            "repeated": 0,
            "id": 5508
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a39cdd3",
            "parentcaller": "0x7ff70a3b5ffb",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5509
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5eb2",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 5510
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5eb2",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\"
              }
            ],
            "repeated": 0,
            "id": 5511
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5512
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 5513
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000524"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc140"
              },
              {
                "name": "ViewSize",
                "value": "0x00003000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5514
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000524"
              }
            ],
            "repeated": 0,
            "id": 5515
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\xf9,\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5516
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x800\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x01\\x04\\x10\\x98\\xbf\\xa5\\xb99Q\\x7fG\\x83\\x9cS!\\xa1\\xbf8\\x04\\x17\r221117072406Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x01\\x02\\x05\\x00\\x00\\x00"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 5517
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "crypto",
            "api": "CryptDecodeObjectEx",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "CertEncodingType",
                "value": "0x00000001"
              },
              {
                "name": "Encoded",
                "value": "0\\x82\\x02\\x8d0J\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04<0:\\x1e&\\x00Q\\x00u\\x00a\\x00l\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00L\\x00e\\x00v\\x00e\\x00l\\x02\\x04\\x10\\x01\\x00\\x01\\x04\n1\\x000\\x000\\x000\\x00\\x00\\x000$\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x160\\x14\\x1e\\x06\\x00D\\x00T\\x00C\\x02\\x04\\x10\\x01\\x00\\x01\\x04\\x041\\x00\\x00\\x000\\x81\\x94\\x06\n+\\x06\\x01\\x04\\x01\\x827\\x0c\\x02\\x01\\x04\\x81\\x850\\x81\\x82\\x1e\\x1a\\x00S\\x00u\\x00b\\x00m\\x00i\\x00s\\x00s\\x00i\\x00o\\x00n\\x00 \\x00I\\x00D\\x02\\x04\\x10\\x01\\x00\\x01\\x04^3\\x000\\x000\\x004\\x005\\x008\\x001\\x000\\x00_\\x001\\x004\\x004\\x003\\x003\\x004\\x005\\x001\\x004\\x003\\x006\\x003\\x006\\x003\\x006\\x000\\x001\\x00_\\x001\\x001\\x005\\x002\\x009\\x002\\x001\\x005\\x000\\x005\\x006\\x009\\x005\\x005"
              },
              {
                "name": "Flags",
                "value": "0x00008004"
              }
            ],
            "repeated": 0,
            "id": 5518
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5519
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5520
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5521
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5522
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\CatRoot"
              }
            ],
            "repeated": 0,
            "id": 5523
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020000",
                "pretty_value": "READ_CONTROL"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\CatRoot"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5524
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5525
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "CreateDirectoryW",
            "status": false,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\catroot2"
              }
            ],
            "repeated": 0,
            "id": 5526
          },
          {
            "timestamp": "2026-02-10 09:22:15,077",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000470"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020000",
                "pretty_value": "READ_CONTROL"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5527
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5528
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5529
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5530
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "services",
            "api": "OpenSCManagerW",
            "status": true,
            "return": "0x2568ece4180",
            "arguments": [
              {
                "name": "MachineName",
                "value": ""
              },
              {
                "name": "DatabaseName",
                "value": ""
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "SC_MANAGER_CONNECT"
              }
            ],
            "repeated": 0,
            "id": 5531
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "services",
            "api": "OpenServiceW",
            "status": true,
            "return": "0x2568ece3d90",
            "arguments": [
              {
                "name": "ServiceControlManager",
                "value": "0x2568ece4180"
              },
              {
                "name": "ServiceName",
                "value": "CryptSvc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000005",
                "pretty_value": "SERVICE_QUERY_CONFIG|SERVICE_QUERY_STATUS"
              }
            ],
            "repeated": 0,
            "id": 5532
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5533
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5534
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5535
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xb7\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00V\\x02\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe8\\xc8\\xd1\\x8eV\\x02\\x00\\x00 l\\xd1\\x8eV\\x02\\x00\\x00\\xb1GI\\xe3\\xfe\\x7f\\x00\\x00\\xf0\\xdbB\\xe3\\xfe\\x7f\\x00\\x00 \\xb3\\xed\\x1c\\x97\\x00\\x00\\x00 \\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xf0\\xdbB\\xe3\\xfe\\x7f\\x00\\x00`\\xb3\\xed\\x1c\\x97\\x00\\x00\\x00`\\xb5\\xed\\x1c\\x97\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\xc0sL\\xe1\\xfe\\x7f\\x00\\x00(5M\\xe1\\xfe\\x7f\\x00\\x00\\xdc\\x04H\\xe3\\xfe\\x7f\\x00\\x00\\x10\\x81*\\xe3\\xfe\\x7f\\x00\\x00P\\xbf\\xed\\x1c\\x97\\x00\\x00\\x00 \\x0f\\xca\\x8eV\\x02\\x00\\x00 \\x0f\\xca\\x8eV\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5536
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000470"
              }
            ],
            "repeated": 0,
            "id": 5537
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5538
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5539
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ebc2000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5540
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5541
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee14d3000"
              },
              {
                "name": "ModuleName",
                "value": "WINTRUST.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5542
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5543
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2bfb000"
              },
              {
                "name": "ModuleName",
                "value": "ADVAPI32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5544
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5545
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5546
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5547
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5548
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5549
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5550
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "misc",
            "api": "RtlSetCurrentTransaction",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "TransactionHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 1,
            "id": 5551
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000c4"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 5552
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000590"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000000c4"
              },
              {
                "name": "ObjectAttributesName",
                "value": "Software\\Microsoft\\Cryptography\\CatalogDB"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\CatalogDB"
              }
            ],
            "repeated": 0,
            "id": 5553
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000590"
              },
              {
                "name": "ValueName",
                "value": "CatDBLogging"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging"
              }
            ],
            "repeated": 0,
            "id": 5554
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000590"
              }
            ],
            "repeated": 0,
            "id": 5555
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 5556
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5557
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5558
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5559
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5560
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5561
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5562
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5563
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5564
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5565
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5566
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5567
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5568
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5569
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5570
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5571
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5572
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5573
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5574
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5575
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5576
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5577
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5578
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5579
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5580
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004dc"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5581
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "0"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000080",
                "pretty_value": "FILE_ATTRIBUTE_NORMAL"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5582
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00A\\x06\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 1,
            "id": 5583
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "A\\x06\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5584
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "filesystem",
            "api": "NtWriteFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\catroot2\\dberr.txt"
              },
              {
                "name": "Buffer",
                "value": "CatalogDB: 12:22:15 10.02.2026: DONE Adding Catalog File (15ms): oem2.cat\r\n"
              },
              {
                "name": "Length",
                "value": "75"
              }
            ],
            "repeated": 0,
            "id": 5585
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a3b5f15",
            "parentcaller": "0x7ff70a3b600a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000590"
              }
            ],
            "repeated": 0,
            "id": 5586
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5587
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5588
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x1ej\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5589
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000478"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5590
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000478"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc310"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5591
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5592
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5593
          },
          {
            "timestamp": "2026-02-10 09:22:15,092",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000478"
              }
            ],
            "repeated": 0,
            "id": 5594
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5595
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "mj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5596
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000590"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "mj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5597
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b3d2",
            "parentcaller": "0x7ff70a39e634",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000590"
              }
            ],
            "repeated": 0,
            "id": 5598
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5599
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5600
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5601
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5602
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5603
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5604
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5605
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5606
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5607
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5608
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5609
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b8d0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0x97b63e00"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01d8fa8f"
              }
            ],
            "repeated": 0,
            "id": 5610
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5611
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "DesiredAccess",
                "value": "0x80100080",
                "pretty_value": "GENERIC_READ|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "CreateDisposition",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5612
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x10\\x00\\x00\\x00\\x00\\x00\\x00\\x91\\x0e\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5613
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0005",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000520"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 5614
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000004d8"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedb4d0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5615
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5616
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5617
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5618
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5619
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5620
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7b0",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005a0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5621
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005a8"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5622
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b7ec",
            "parentcaller": "0x7ff70a39e652",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005b0"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5623
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000004d8"
              }
            ],
            "repeated": 0,
            "id": 5624
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000520"
              }
            ],
            "repeated": 0,
            "id": 5625
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000051c"
              }
            ],
            "repeated": 0,
            "id": 5626
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000528"
              }
            ],
            "repeated": 0,
            "id": 5627
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005a0"
              }
            ],
            "repeated": 0,
            "id": 5628
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000059c"
              }
            ],
            "repeated": 0,
            "id": 5629
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005a8"
              }
            ],
            "repeated": 0,
            "id": 5630
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005a4"
              }
            ],
            "repeated": 0,
            "id": 5631
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005b0"
              }
            ],
            "repeated": 0,
            "id": 5632
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000005ac"
              }
            ],
            "repeated": 0,
            "id": 5633
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000046c"
              }
            ],
            "repeated": 0,
            "id": 5634
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000550"
              }
            ],
            "repeated": 0,
            "id": 5635
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000058c"
              }
            ],
            "repeated": 0,
            "id": 5636
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000588"
              }
            ],
            "repeated": 0,
            "id": 5637
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000574"
              }
            ],
            "repeated": 0,
            "id": 5638
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000580"
              }
            ],
            "repeated": 0,
            "id": 5639
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000056c"
              }
            ],
            "repeated": 0,
            "id": 5640
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000578"
              }
            ],
            "repeated": 0,
            "id": 5641
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000584"
              }
            ],
            "repeated": 0,
            "id": 5642
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000570"
              }
            ],
            "repeated": 0,
            "id": 5643
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000558"
              }
            ],
            "repeated": 0,
            "id": 5644
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000568"
              }
            ],
            "repeated": 0,
            "id": 5645
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000560"
              }
            ],
            "repeated": 0,
            "id": 5646
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000468"
              }
            ],
            "repeated": 0,
            "id": 5647
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000054c"
              }
            ],
            "repeated": 0,
            "id": 5648
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000554"
              }
            ],
            "repeated": 0,
            "id": 5649
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000544"
              }
            ],
            "repeated": 0,
            "id": 5650
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5651
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5652
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5653
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5654
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39b83f",
            "parentcaller": "0x7ff70a39e652",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5655
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5656
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00mj\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5657
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "mj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5658
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000052c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5659
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000052c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc5c0"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5660
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5661
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5662
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5663
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5664
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5665
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5666
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5667
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5668
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5669
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5670
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\xbfj\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5671
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000052c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5672
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000052c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedc600"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5673
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5674
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10k\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5675
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5676
          },
          {
            "timestamp": "2026-02-10 09:22:15,108",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 5677
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10k\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5678
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10k\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5679
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10k\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5680
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5681
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              }
            ],
            "repeated": 0,
            "id": 5682
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "FindFirstFileExW",
            "status": true,
            "return": "0x2568ec6b8d0",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\*"
              },
              {
                "name": "FirstCreateTimeLow",
                "value": "0xbe1f86dc"
              },
              {
                "name": "FirstCreateTimeHigh",
                "value": "0x01dc9a6e"
              }
            ],
            "repeated": 0,
            "id": 5683
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5684
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5685
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5686
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
              }
            ],
            "repeated": 0,
            "id": 5687
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5688
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5689
          },
          {
            "timestamp": "2026-02-10 09:22:15,124",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5690
          },
          {
            "timestamp": "2026-02-10 09:22:15,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
              }
            ],
            "repeated": 0,
            "id": 5691
          },
          {
            "timestamp": "2026-02-10 09:22:15,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5692
          },
          {
            "timestamp": "2026-02-10 09:22:15,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000538"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5693
          },
          {
            "timestamp": "2026-02-10 09:22:15,139",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000538"
              }
            ],
            "repeated": 0,
            "id": 5694
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "DeleteFileW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
              }
            ],
            "repeated": 0,
            "id": 5695
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              }
            ],
            "repeated": 0,
            "id": 5696
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000564"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100100",
                "pretty_value": "FILE_WRITE_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 5697
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x00000564"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              },
              {
                "name": "FileInformationClass",
                "value": "4",
                "pretty_value": "FileBasicInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x80\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5698
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000564"
              }
            ],
            "repeated": 0,
            "id": 5699
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "RemoveDirectoryW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DirectoryName",
                "value": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
              }
            ],
            "repeated": 0,
            "id": 5700
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000244"
              }
            ],
            "repeated": 0,
            "id": 5701
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 5702
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000024c"
              }
            ],
            "repeated": 0,
            "id": 5703
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000248"
              }
            ],
            "repeated": 0,
            "id": 5704
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed1e000"
              },
              {
                "name": "RegionSize",
                "value": "0x0000c000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5705
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5706
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec82000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 5707
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ec82000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5708
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 5709
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 5710
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtCreateFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "DesiredAccess",
                "value": "0xc0100080",
                "pretty_value": "GENERIC_READ|GENERIC_WRITE|FILE_READ_ATTRIBUTES|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "CreateDisposition",
                "value": "3",
                "pretty_value": "FILE_OPEN_IF"
              },
              {
                "name": "ShareAccess",
                "value": "1",
                "pretty_value": "FILE_SHARE_READ"
              },
              {
                "name": "FileAttributes",
                "value": "0x00000000"
              },
              {
                "name": "ExistedBefore",
                "value": "yes"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5711
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "5",
                "pretty_value": "FileStandardInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x00p\\x00\\x00\\x00\\x00\\x00\\x00\\x10k\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5712
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "\\x10k\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5713
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000238"
              },
              {
                "name": "DesiredAccess",
                "value": "0x000f0007",
                "pretty_value": "STANDARD_RIGHTS_REQUIRED|SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_WRITE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              }
            ],
            "repeated": 0,
            "id": 5714
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000238"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "SectionOffset",
                "value": "0x971cedf420"
              },
              {
                "name": "ViewSize",
                "value": "0x00007000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5715
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "GetLocalTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5716
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Vk\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5717
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f220000"
              },
              {
                "name": "RegionSize",
                "value": "0x00007000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5718
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 5719
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtQueryInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "14",
                "pretty_value": "FilePositionInformation"
              },
              {
                "name": "FileInformation",
                "value": "Vk\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5720
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "20",
                "pretty_value": "FileEndOfFileInformation"
              },
              {
                "name": "FileInformation",
                "value": "Vk\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5721
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "filesystem",
            "api": "NtSetInformationFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x0000022c"
              },
              {
                "name": "HandleName",
                "value": "C:\\Windows\\INF\\setupapi.dev.log"
              },
              {
                "name": "FileInformationClass",
                "value": "19",
                "pretty_value": "FileAllocationInformation"
              },
              {
                "name": "FileInformation",
                "value": "Vk\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5722
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a39eab3",
            "parentcaller": "0x7ff70a392be8",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 5723
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\DriverStore"
              }
            ],
            "repeated": 0,
            "id": 5724
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5725
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 5726
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568ed0a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00004000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5727
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows"
              }
            ],
            "repeated": 0,
            "id": 5728
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5729
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3813",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470877"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00\\x00\\x00D\\x00R\\x00I\\x00V\\x00E\\x00R\\x00S\\x00\\x00\\x00\\x00\\x00]\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5730
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b38e8",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00`\\xd2\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12\\x00\\x00\\x00o\\x00e\\x00m\\x002\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x000\\x1f\\x06\\x03"
              }
            ],
            "repeated": 0,
            "id": 5731
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3af7c4",
            "parentcaller": "0x7ff70a3b0743",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 5732
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3af7e1",
            "parentcaller": "0x7ff70a3b0743",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 5733
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3ac017",
            "parentcaller": "0x7ff70a3afced",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 5734
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3afd69",
            "parentcaller": "0x7ff70a3af82a",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 5735
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3abf8a",
            "parentcaller": "0x7ff70a3adbe3",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 5736
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3acc51",
            "parentcaller": "0x7ff70a3aff35",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 5737
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3abefb",
            "parentcaller": "0x7ff70a3b02e8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 5738
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b128a",
            "parentcaller": "0x7ff70a3afb53",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:1620:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5739
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b12b3",
            "parentcaller": "0x7ff70a3afb53",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 5740
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad0ac",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5741
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad0ac",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5742
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad123",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 5743
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3ad201",
            "parentcaller": "0x7ff70a3ad123",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 5744
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3ad152",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000057c"
              }
            ],
            "repeated": 0,
            "id": 5745
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3ad16b",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000450"
              }
            ],
            "repeated": 0,
            "id": 5746
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3acd43",
            "parentcaller": "0x7ff70a3b1337",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000055c"
              }
            ],
            "repeated": 0,
            "id": 5747
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca1a4",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5748
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3a9352",
            "parentcaller": "0x7ff70a3ca1a4",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ff70a3e4000"
              },
              {
                "name": "ModuleName",
                "value": "DrvInst.exe"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 5749
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b0ef3",
            "parentcaller": "0x7ff70a3b3910",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470803"
              },
              {
                "name": "InBuffer",
                "value": "\\x18\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0|\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5750
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b0f53",
            "parentcaller": "0x7ff70a3b3910",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470803"
              },
              {
                "name": "InBuffer",
                "value": "\\x18\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00|\\x14\\x00\\x00\\x00\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\\\x004\\x00&\\x002\\x00c\\x003\\x005\\x002\\x00a\\x002\\x007\\x00&\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\\\x00C\\x00P\\x00U\\x00_\\x00H\\x00o\\x00t\\x00p\\x00l\\x00u\\x00g\\x00_\\x00r\\x00e\\x00s\\x00o\\x00u\\x00r\\x00c\\x00e\\x00s\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\\\x004\\x00&\\x002\\x00c\\x003\\x005\\x002\\x00a\\x002\\x007\\x00&\\x000\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00s\\x00\\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00v\\x00o\\x00"
              }
            ],
            "repeated": 0,
            "id": 5751
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5752
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5753
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00F\\x001\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00F\\x001\\x003\\x00\\x00\\x00\\x00\\x00t\\x00p\\x00"
              }
            ],
            "repeated": 0,
            "id": 5754
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5755
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5756
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5757
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00m\\x00o\\x00u\\x00s\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5758
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5759
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5760
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5761
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00t\\x00p\\x00"
              }
            ],
            "repeated": 0,
            "id": 5762
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5763
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5764
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5765
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5766
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5767
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5768
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5769
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x007\\x000\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x007\\x000\\x000\\x00\\x00\\x00\\x00\\x00t\\x00p\\x00"
              }
            ],
            "repeated": 0,
            "id": 5770
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5771
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5772
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5773
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00f\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5774
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5775
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5776
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5777
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x006\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00L\\x00o\\x00c\\x00a\\x00l\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 5778
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5779
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00p\\x00r\\x00i\\x00n\\x00t\\x00q\\x00u\\x00e\\x00u\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00]\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5780
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00N\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 5781
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5782
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5783
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5784
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5785
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5786
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00V\\x00O\\x00L\\x00M\\x00G\\x00R\\x00\\x00\\x00\\x00\\x00w\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5787
          },
          {
            "timestamp": "2026-02-10 09:22:15,171",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5788
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00n\\x00f\\x00"
              }
            ],
            "repeated": 0,
            "id": 5789
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00R\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00v\\x00o\\x00l\\x00m\\x00g\\x00r\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5790
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5791
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5792
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5793
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5794
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe6\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00{\\x000\\x008\\x004\\x00f\\x000\\x001\\x00f\\x00a\\x00-\\x00e\\x006\\x003\\x004\\x00-\\x004\\x00d\\x007\\x007\\x00-\\x008\\x003\\x00e\\x00e\\x00-\\x000\\x007\\x004\\x008\\x001\\x007\\x00c\\x000\\x003\\x005\\x008\\x001\\x00}\\x00\\x00\\x00P\\x00R\\x00I\\x00N\\x00T\\x00E\\x00N\\x00U\\x00M\\x00\\\\x00L\\x00o\\x00c\\x00a\\x00l\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00{\\x000\\x008\\x004\\x00f\\x000\\x001\\x00f\\x00a\\x00-\\x00e\\x006\\x003\\x004\\x00-\\x004\\x00d\\x007\\x007\\x00-\\x008\\x003\\x00e\\x00e\\x00-\\x000\\x007\\x004\\x008\\x001\\x007\\x00c\\x000\\x003\\x005\\x008\\x001\\x00}\\x00\\x00\\x00\\x00\\x00O\\x00T\\x00"
              }
            ],
            "repeated": 0,
            "id": 5795
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5796
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5797
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00p\\x00r\\x00i\\x00n\\x00t\\x00q\\x00u\\x00e\\x00u\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5798
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5799
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00o\\x00e\\x00m\\x000\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5800
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00T\\x00\\x00\\x00\\x12 \\x00\\x00G\\x00e\\x00n\\x00P\\x00r\\x00i\\x00n\\x00t\\x00Q\\x00u\\x00e\\x00u\\x00e\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x000\\x003\\x00"
              }
            ],
            "repeated": 0,
            "id": 5801
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5802
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5803
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5804
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5805
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5806
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5807
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00&\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00B\\x00a\\x00s\\x00i\\x00c\\x00D\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5808
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0$\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5809
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00b\\x00a\\x00s\\x00i\\x00c\\x00d\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5810
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5811
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5812
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5813
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00B\\x000\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00B\\x000\\x000\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00B\\x000\\x000\\x00\\x00\\x00\\x00\\x008\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 5814
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5815
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5816
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5817
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5818
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5819
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5820
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5821
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00_\\x00a\\x00p\\x00v\\x00n\\x00a\\x00\\x00\\x00\\x00\\x00N\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 5822
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5823
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00o\\x00e\\x00m\\x001\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5824
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5825
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00P\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5826
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5827
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00P\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x01\\x00\\x00\\x12 \\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x000\\x00\\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00\\x00\\x00H\\x00I\\x00D\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00U\\x00P\\x00:\\x000\\x000\\x000\\x001\\x00_\\x00U\\x00:\\x000\\x000\\x000\\x002\\x00\\x00\\x00H\\x00I\\x00D\\x00_\\x00D\\x00E\\x00V\\x00I\\x00C\\x00E\\x00_\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x00_\\x00M\\x00O\\x00U\\x00S\\x00E\\x00\\x00\\x00H\\x00I\\x00D\\x00_\\x00D\\x00E\\x00V\\x00I\\x00C\\x00E\\x00_\\x00U\\x00P\\x00:\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5828
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5829
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5830
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5831
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5832
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00m\\x00o\\x00u\\x00s\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 5833
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5834
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5835
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00i\\x00n\\x00p\\x00u\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 5836
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00P\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 5837
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00D\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5838
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5839
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00D\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x007\\x00&\\x00"
              }
            ],
            "repeated": 0,
            "id": 5840
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5841
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5842
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00D\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 5843
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5844
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5845
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x003\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x003\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x003\\x000\\x003\\x00\\x00\\x00\\x00\\x00I\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 5846
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5847
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5848
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5849
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00k\\x00e\\x00y\\x00b\\x00o\\x00a\\x00r\\x00d\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x002\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5850
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5851
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5852
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5853
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00D\\x00\\x00\\x00\\x12 \\x00\\x00I\\x00n\\x00t\\x00e\\x00l\\x00-\\x00P\\x00I\\x00I\\x00X\\x003\\x00\\x00\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00_\\x00I\\x00D\\x00E\\x00_\\x00C\\x00h\\x00a\\x00n\\x00n\\x00e\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00"
              }
            ],
            "repeated": 0,
            "id": 5854
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5855
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5856
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 5857
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x006\\x000\\x000\\x00\\x00\\x00\\x00\\x003\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5858
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5859
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5860
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5861
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00D\\x00\\x00\\x00\\x12 \\x00\\x00I\\x00n\\x00t\\x00e\\x00l\\x00-\\x00P\\x00I\\x00I\\x00X\\x003\\x00\\x00\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00_\\x00I\\x00D\\x00E\\x00_\\x00C\\x00h\\x00a\\x00n\\x00n\\x00e\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00"
              }
            ],
            "repeated": 0,
            "id": 5862
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5863
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5864
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00y\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 5865
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x006\\x000\\x000\\x00\\x00\\x00\\x00\\x003\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5866
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5867
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5868
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 5869
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x001\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x001\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x001\\x000\\x003\\x00\\x00\\x00\\x00\\x00I\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 5870
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5871
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5872
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5873
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5874
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5875
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x9a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5876
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5877
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x9a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb8\\x01\\x00\\x00\\x12 \\x00\\x00I\\x00D\\x00E\\x00\\\\x00C\\x00d\\x00R\\x00o\\x00m\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00D\\x00V\\x00D\\x00-\\x00R\\x00O\\x00M\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x002\\x00.\\x005\\x00+\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00I\\x00D\\x00E\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00D\\x00V\\x00D\\x00-\\x00R\\x00O\\x00M\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x002\\x00.\\x005\\x00+\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00I\\x00D\\x00E\\x00\\\\x00C\\x00d\\x00R\\x00o\\x00m\\x00"
              }
            ],
            "repeated": 0,
            "id": 5878
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00t\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5879
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5880
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00d\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5881
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5882
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5883
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00d\\x00r\\x00o\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5884
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x9a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00G\\x00e\\x00n\\x00C\\x00d\\x00R\\x00o\\x00m\\x00\\x00\\x00\\x00\\x00E\\x00M\\x00"
              }
            ],
            "repeated": 0,
            "id": 5885
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5886
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00d\\x00r\\x00o\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5887
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00V\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5888
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5889
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00V\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00l\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00V\\x00I\\x00D\\x00_\\x000\\x006\\x002\\x007\\x00&\\x00P\\x00I\\x00D\\x00_\\x000\\x000\\x000\\x001\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 5890
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5891
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5892
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00V\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00&\\x00S\\x00u\\x00b\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x000\\x00&\\x00P\\x00r\\x00o\\x00t\\x00_\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00&\\x00S\\x00u\\x00b\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00C\\x00l\\x00a\\x00s\\x00s\\x00_\\x000\\x003\\x00\\x00\\x00\\x00\\x00D\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 5893
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5894
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x002\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5895
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5896
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00i\\x00n\\x00p\\x00u\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5897
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5898
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5899
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00&\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00C\\x00o\\x00m\\x00p\\x00o\\x00s\\x00i\\x00t\\x00e\\x00B\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00s\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 5900
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0$\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5901
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00o\\x00m\\x00p\\x00o\\x00s\\x00i\\x00t\\x00e\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5902
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5903
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5904
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5905
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00v\\x00d\\x00r\\x00v\\x00r\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x00\\x00u\\x00s\\x00"
              }
            ],
            "repeated": 0,
            "id": 5906
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5907
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00d\\x00r\\x00v\\x00r\\x00o\\x00o\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x002\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5908
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5909
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5910
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5911
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 5912
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5913
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5914
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5915
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5916
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x001\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x001\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 5917
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5918
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5919
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00s\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 5920
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5921
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5922
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5923
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5924
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5925
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00s\\x00.\\x00"
              }
            ],
            "repeated": 0,
            "id": 5926
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5927
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5928
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00_\\x007\\x00"
              }
            ],
            "repeated": 0,
            "id": 5929
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5930
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5931
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5932
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00i\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 5933
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5934
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5935
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5936
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00R\\x00o\\x00o\\x00t\\x00\\\\x00S\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00\\x00\\x00_\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5937
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5938
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5939
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00^\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00s\\x00p\\x00a\\x00c\\x00e\\x00p\\x00o\\x00r\\x00t\\x00\\x00\\x00\\x00\\x000\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 5940
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x006\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5941
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5942
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5943
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5944
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 5945
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5946
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5947
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5948
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5949
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x002\\x003\\x007\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5950
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5951
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5952
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5953
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5954
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5955
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5956
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5957
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5958
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5959
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5960
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5961
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x006\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x006\\x00\\x00\\x00\\x00\\x00_\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 5962
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5963
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5964
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5965
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5966
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00F\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5967
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5968
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5969
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00o\\x00o\\x00t\\x00\\\\x00k\\x00d\\x00n\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00&\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 5970
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5971
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00k\\x00d\\x00n\\x00i\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5972
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5973
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5974
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5975
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa0\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00&\\x00V\\x00I\\x00D\\x008\\x000\\x008\\x006\\x00&\\x00P\\x00I\\x00D\\x007\\x000\\x002\\x000\\x00&\\x00R\\x00E\\x00V\\x000\\x000\\x000\\x001\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00&\\x00V\\x00I\\x00D\\x008\\x000\\x008\\x006\\x00&\\x00P\\x00I\\x00D\\x007\\x000\\x002\\x000\\x00\\x00\\x00U\\x00S\\x00B\\x00\\\\x00R\\x00O\\x00O\\x00T\\x00_\\x00H\\x00U\\x00B\\x00\\x00\\x00\\x00\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 5976
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5977
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5978
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5979
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00M\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 5980
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5981
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5982
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5983
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00A\\x00C\\x00P\\x00I\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x001\\x000\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00A\\x00C\\x00P\\x00I\\x000\\x000\\x001\\x000\\x00\\x00\\x00*\\x00A\\x00C\\x00P\\x00I\\x000\\x000\\x001\\x000\\x00\\x00\\x00\\x00\\x00_\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 5984
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5985
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5986
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5987
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00E\\x00\\\\x00"
              }
            ],
            "repeated": 0,
            "id": 5988
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x005\\x00\\x00\\x00\\x00\\x00C\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 5989
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5990
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00I\\x00\\\\x00"
              }
            ],
            "repeated": 0,
            "id": 5991
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5992
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5993
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00P\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 5994
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5995
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x005\\x00"
              }
            ],
            "repeated": 0,
            "id": 5996
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 5997
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 5998
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 5999
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x01\\x00\\x00\\x12 \\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x002\\x00.\\x005\\x00+\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00_\\x00H\\x00A\\x00R\\x00D\\x00D\\x00I\\x00S\\x00K\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6000
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6001
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00D\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6002
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6003
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00>\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6004
          },
          {
            "timestamp": "2026-02-10 09:22:15,186",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6005
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6006
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00d\\x00i\\x00s\\x00k\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6007
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00j\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00D\\x00i\\x00s\\x00k\\x00\\x00\\x00S\\x00C\\x00S\\x00I\\x00\\\\x00R\\x00A\\x00W\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6008
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6009
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6010
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6011
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6012
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6013
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6014
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6015
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6016
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6017
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6018
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6019
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6020
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6021
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6022
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6023
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6024
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6025
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6026
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6027
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6028
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6029
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6030
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6031
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6032
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6033
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6034
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6035
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6036
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6037
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6038
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6039
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6040
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6041
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6042
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6043
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6044
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6045
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6046
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6047
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6048
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6049
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6050
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6051
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa6\\x01\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00*\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00l\\x00y\\x00_\\x006\\x00_\\x00M\\x00o\\x00d\\x00e\\x00l\\x00_\\x007\\x009\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00G\\x00e\\x00n\\x00u\\x00i\\x00n\\x00e\\x00I\\x00n\\x00t\\x00e\\x00l\\x00_\\x00-\\x00_\\x00I\\x00n\\x00t\\x00e\\x00l\\x006\\x004\\x00_\\x00F\\x00a\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6052
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6053
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00T\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6054
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00J\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6055
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6056
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6057
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x008\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6058
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x000\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6059
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\xba\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00r\\x00o\\x00c\\x00e\\x00s\\x00s\\x00o\\x00r\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6060
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6061
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00c\\x00p\\x00u\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6062
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6063
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6064
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00S\\x00T\\x00O\\x00R\\x00A\\x00G\\x00E\\x00\\\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00\\x00\\x00\\x00\\x00l\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6065
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6066
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00u\\x00m\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00D\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 6067
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6068
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6069
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6070
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6071
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6072
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6073
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6074
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6075
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x002\\x009\\x002\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x001\\x000\\x006\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6076
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6077
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6078
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6079
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6080
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6081
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6082
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00h\\x00d\\x00c\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00_\\x00Q\\x00"
              }
            ],
            "repeated": 0,
            "id": 6083
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6084
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6085
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6086
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00o\\x00o\\x00t\\x00\\\\x00u\\x00m\\x00b\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00&\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6087
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6088
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6089
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6090
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6091
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6092
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00M\\x00O\\x00N\\x00I\\x00T\\x00O\\x00R\\x00\\\\x00R\\x00H\\x00T\\x001\\x002\\x003\\x004\\x00\\x00\\x00\\x00\\x002\\x009\\x00"
              }
            ],
            "repeated": 0,
            "id": 6093
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00 \\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6094
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x009\\x00F\\x00F\\x00\\x00\\x00\\x00\\x00T\\x001\\x00"
              }
            ],
            "repeated": 0,
            "id": 6095
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6096
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00o\\x00n\\x00i\\x00t\\x00o\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6097
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6098
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6099
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6100
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6101
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6102
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x003\\x00&\\x00"
              }
            ],
            "repeated": 0,
            "id": 6103
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6104
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6105
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6106
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6107
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6108
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6109
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6110
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6111
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6112
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6113
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00a\\x00c\\x00p\\x00i\\x00a\\x00p\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00c\\x00R\\x00"
              }
            ],
            "repeated": 0,
            "id": 6114
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6115
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00h\\x00a\\x00l\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6116
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00I\\x00n\\x00t\\x00e\\x00r\\x00n\\x00a\\x00l\\x00\\\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\x00\\x00D\\x00E\\x00T\\x00E\\x00C\\x00T\\x00E\\x00D\\x00\\\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\x00\\x00\\x00\\x00_\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6117
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6118
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00$\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6119
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6120
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6121
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00P\\x00N\\x00P\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x00A\\x000\\x003\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x003\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00A\\x000\\x003\\x00\\x00\\x00\\x00\\x00_\\x002\\x00"
              }
            ],
            "repeated": 0,
            "id": 6122
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6123
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6124
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6125
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6126
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6127
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6128
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18N\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6129
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x006\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00_\\x00H\\x00A\\x00L\\x00\\\\x00P\\x00N\\x00P\\x000\\x00C\\x000\\x008\\x00\\x00\\x00*\\x00P\\x00N\\x00P\\x000\\x00C\\x000\\x008\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 6130
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6131
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x14\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6132
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x12 \\x00\\x00a\\x00c\\x00p\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6133
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6134
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6135
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6136
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6137
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6138
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6139
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6140
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00B\\x00a\\x00s\\x00i\\x00c\\x00R\\x00e\\x00n\\x00d\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00P\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 6141
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\"\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6142
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00b\\x00a\\x00s\\x00i\\x00c\\x00r\\x00e\\x00n\\x00d\\x00e\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x004\\x00"
              }
            ],
            "repeated": 0,
            "id": 6143
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6144
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6145
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6146
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6147
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6148
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00f\\x005\\x00"
              }
            ],
            "repeated": 0,
            "id": 6149
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00B\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6150
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6151
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6152
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00U\\x00M\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00e\\x00n\\x00"
              }
            ],
            "repeated": 0,
            "id": 6153
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x16\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6154
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x16\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00m\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00_\\x00Q\\x00"
              }
            ],
            "repeated": 0,
            "id": 6155
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6156
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6157
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6158
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x005\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x005\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6159
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6160
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6161
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6162
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6163
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x000\\x00F\\x00F\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6164
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6165
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6166
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6167
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6168
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6169
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6170
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6171
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6172
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6173
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00>\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00F\\x00i\\x00x\\x00e\\x00d\\x00B\\x00u\\x00t\\x00t\\x00o\\x00n\\x00\\x00\\x00*\\x00F\\x00i\\x00x\\x00e\\x00d\\x00B\\x00u\\x00t\\x00t\\x00o\\x00n\\x00\\x00\\x00\\x00\\x00I\\x00\\\\x00"
              }
            ],
            "repeated": 0,
            "id": 6174
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6175
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x00:\\x00"
              }
            ],
            "repeated": 0,
            "id": 6176
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6177
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6178
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6179
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6180
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6181
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6182
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6183
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6184
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6185
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x002\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x001\\x001\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x002\\x003\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x003\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6186
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6187
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6188
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6189
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6190
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6191
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6192
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6193
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00d\\x00i\\x00s\\x00p\\x00l\\x00a\\x00y\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6194
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6195
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6196
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6197
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00N\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x008\\x00\\x00\\x00\\x12 \\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00R\\x00a\\x00w\\x00\\x00\\x00S\\x00W\\x00D\\x00\\\\x00G\\x00e\\x00n\\x00e\\x00r\\x00i\\x00c\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x00"
              }
            ],
            "repeated": 0,
            "id": 6198
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0 \\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6199
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00c\\x00_\\x00s\\x00w\\x00d\\x00e\\x00v\\x00i\\x00c\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6200
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6201
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6202
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6203
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00S\\x00T\\x00O\\x00R\\x00A\\x00G\\x00E\\x00\\\\x00V\\x00o\\x00l\\x00u\\x00m\\x00e\\x00\\x00\\x00\\x00\\x00W\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6204
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6205
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00v\\x00o\\x00l\\x00u\\x00m\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00n\\x00f\\x00"
              }
            ],
            "repeated": 0,
            "id": 6206
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\\x8e\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6207
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6208
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6209
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00 \\x00\\x00\\x00\\x12 \\x00\\x00U\\x00M\\x00B\\x00\\\\x00T\\x00S\\x00_\\x00U\\x00R\\x00B\\x00_\\x00H\\x00U\\x00B\\x00\\x00\\x00\\x00\\x00W\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6210
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6211
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00t\\x00s\\x00u\\x00s\\x00b\\x00h\\x00u\\x00b\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00I\\x00N\\x00"
              }
            ],
            "repeated": 0,
            "id": 6212
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00b\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00B\\x00"
              }
            ],
            "repeated": 0,
            "id": 6213
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6214
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6215
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6216
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6217
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6218
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6219
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6220
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x00E\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6221
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6222
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6223
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00n\\x00e\\x00t\\x00e\\x001\\x00g\\x003\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6224
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6225
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6226
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6227
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6228
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6229
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x002\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6230
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6231
          },
          {
            "timestamp": "2026-02-10 09:22:15,202",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x002\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00*\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00N\\x00d\\x00i\\x00s\\x00V\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00B\\x00u\\x00s\\x00\\x00\\x00\\x00\\x00&\\x00R\\x00"
              }
            ],
            "repeated": 0,
            "id": 6232
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0(\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6233
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00(\\x00\\x00\\x00\\x12 \\x00\\x00n\\x00d\\x00i\\x00s\\x00v\\x00i\\x00r\\x00t\\x00u\\x00a\\x00l\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00e\\x00r\\x00"
              }
            ],
            "repeated": 0,
            "id": 6234
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x002\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6235
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6236
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6237
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x001\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x001\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6238
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6239
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6240
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6241
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6242
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00D\\x00E\\x00V\\x00_\\x001\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00&\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x002\\x000\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6243
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6244
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6245
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6246
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6247
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6248
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6249
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6250
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6251
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6252
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6253
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6254
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6255
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6256
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6257
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x001\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6258
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6259
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6260
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6261
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6262
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6263
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6264
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6265
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6266
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00a\\x00c\\x00h\\x00i\\x00n\\x00e\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x005\\x00D\\x00"
              }
            ],
            "repeated": 0,
            "id": 6267
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6268
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6269
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x002\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x00V\\x00G\\x00I\\x00D\\x00\\x00\\x00*\\x00Q\\x00E\\x00M\\x00U\\x00V\\x00G\\x00I\\x00D\\x00\\x00\\x00\\x00\\x00_\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6270
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6271
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6272
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x004\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00H\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00M\\x00_\\x00G\\x00e\\x00n\\x00_\\x00C\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00\\x00\\x00V\\x00M\\x00_\\x00G\\x00e\\x00n\\x00_\\x00C\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00\\x00\\x00\\x00\\x00_\\x008\\x00"
              }
            ],
            "repeated": 0,
            "id": 6273
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00(\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6274
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\"\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6275
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"\\x00\\x00\\x00\\x12 \\x00\\x00w\\x00g\\x00e\\x00n\\x00c\\x00o\\x00u\\x00n\\x00t\\x00e\\x00r\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00m\\x00i\\x00"
              }
            ],
            "repeated": 0,
            "id": 6276
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6277
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6278
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1e\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00m\\x00s\\x00s\\x00m\\x00b\\x00i\\x00o\\x00s\\x00\\x00\\x00\\x00\\x00n\\x00t\\x00"
              }
            ],
            "repeated": 0,
            "id": 6279
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6280
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x12 \\x00\\x00m\\x00s\\x00s\\x00m\\x00b\\x00i\\x00o\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00R\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6281
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00&\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6282
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6283
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6284
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6285
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6286
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6287
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6288
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6289
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6290
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6291
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6292
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6293
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6294
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6295
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6296
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6297
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6298
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6299
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6300
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6301
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6302
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6303
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6304
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6305
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6306
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6307
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6308
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6309
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6310
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6311
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6312
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6313
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6314
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6315
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18\\x00\\x00F\\x00"
              }
            ],
            "repeated": 0,
            "id": 6316
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x8a\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x001\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6317
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6318
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6319
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6320
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6321
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6322
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6323
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xa8\\x00\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x001\\x00B\\x003\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x006\\x000\\x004\\x00\\x00\\x00\\x00\\x00C\\x00I\\x00"
              }
            ],
            "repeated": 0,
            "id": 6324
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6325
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6326
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6327
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6328
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x12\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6329
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x12\\x00\\x00\\x00\\x12 \\x00\\x00p\\x00c\\x00i\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00F\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6330
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6331
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6332
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00S\\x00W\\x00E\\x00N\\x00U\\x00M\\x00\\x00\\x00\\x00\\x00C\\x00C\\x00"
              }
            ],
            "repeated": 0,
            "id": 6333
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6334
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00s\\x00w\\x00e\\x00n\\x00u\\x00m\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6335
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6336
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6337
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6338
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00R\\x00O\\x00O\\x00T\\x00\\\\x00R\\x00D\\x00P\\x00B\\x00U\\x00S\\x00\\x00\\x00\\x00\\x00C\\x00C\\x00"
              }
            ],
            "repeated": 0,
            "id": 6339
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x18\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6340
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x12 \\x00\\x00r\\x00d\\x00p\\x00b\\x00u\\x00s\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6341
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00\"\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6342
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x006\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6343
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6344
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x006\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00`\\x00\\x00\\x00\\x12 \\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x00Q\\x00E\\x00M\\x00U\\x00&\\x00D\\x00E\\x00V\\x00_\\x000\\x000\\x000\\x002\\x00\\x00\\x00A\\x00C\\x00P\\x00I\\x00\\\\x00Q\\x00E\\x00M\\x00U\\x000\\x000\\x000\\x002\\x00\\x00\\x00*\\x00Q\\x00E\\x00M\\x00U\\x000\\x000\\x000\\x002\\x00\\x00\\x00\\x00\\x00V\\x00E\\x00"
              }
            ],
            "repeated": 0,
            "id": 6345
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6346
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6347
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6348
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x006\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00%\\x02\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6349
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b394e",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470843"
              },
              {
                "name": "InBuffer",
                "value": "(\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xe0\\xf0\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6350
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b344f",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x00\\x00\\x00\\x00\\x00P\\xc7\\xed\\x1c\\x97\\x00\\x00\\x00H\\x00\\x00\\x00\\x01\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\r\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x00\r\\x00\\x00\\x00t\\xe96M%\\xe3\\xce\\x11\\xbf\\xc1\\x08\\x00+\\xe1\\x03\\x18x\\x00)\\x00"
              }
            ],
            "repeated": 0,
            "id": 6351
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00$\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00S\\x00U\\x00B\\x00S\\x00Y\\x00S\\x00_\\x001\\x001\\x000\\x000\\x001\\x00A\\x00F\\x004\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00"
              }
            ],
            "repeated": 0,
            "id": 6352
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00Z\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6353
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00L\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6354
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6355
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00@\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x000\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6356
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00<\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6357
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b34f8",
            "parentcaller": "0x7ff70a3b399f",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001c4"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xc0\\xe5\\xed\\x1c\\x97\\x00\\x00\\x00z\\x00\\x00\\x00N%\\\\xa4\\x1c\\xdf\\xfdN\\x80 g\\xd1F\\xa8P\\xe0\\x04\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x0e\\x01\\x00\\x00\\x12 \\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00&\\x00R\\x00E\\x00V\\x00_\\x000\\x001\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00D\\x00E\\x00V\\x00_\\x007\\x000\\x002\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x000\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00&\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00V\\x00E\\x00N\\x00_\\x008\\x000\\x008\\x006\\x00\\x00\\x00P\\x00C\\x00I\\x00\\\\x00C\\x00C\\x00_\\x000\\x00C\\x000\\x003\\x000\\x00"
              }
            ],
            "repeated": 0,
            "id": 6358
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00:\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6359
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00,\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6360
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00.\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6361
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00*\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6362
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6363
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00#\\x00\\x00\\xc0\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6364
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1a\\x00\\x00\\x00\\x12 \\x00\\x00u\\x00s\\x00b\\x00p\\x00o\\x00r\\x00t\\x00.\\x00i\\x00n\\x00f\\x00\\x00\\x00\\x00\\x00_\\x00_\\x00"
              }
            ],
            "repeated": 0,
            "id": 6365
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3aa034",
            "parentcaller": "0x7ff70a3b3665",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x0000023c"
              },
              {
                "name": "IoControlCode",
                "value": "0x00470813"
              },
              {
                "name": "InBuffer",
                "value": "H\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\xd0\\xc6\\xed\\x1c\\x97\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x04\\xebc\\x81,\\x14zO\\x94\\xe1\\xa2t\\xccG\\xdb\\xba\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00"
              },
              {
                "name": "OutBuffer",
                "value": "\\x14\\x00\\x00\\x004\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 6366
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3a70",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000052c"
              }
            ],
            "repeated": 0,
            "id": 6367
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a3b3a70",
            "parentcaller": "0x7ff70a39eaf4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 6368
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a392ea7",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x2568f200000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 6369
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a392ec0",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000200"
              }
            ],
            "repeated": 0,
            "id": 6370
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a392efc",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 6371
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a392f10",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 6372
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a391747",
            "parentcaller": "0x7ff70a392f1a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f0"
              }
            ],
            "repeated": 0,
            "id": 6373
          },
          {
            "timestamp": "2026-02-10 09:22:15,217",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 6374
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000398"
              }
            ],
            "repeated": 0,
            "id": 6375
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 6376
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000304"
              }
            ],
            "repeated": 0,
            "id": 6377
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6378
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6379
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000320"
              }
            ],
            "repeated": 0,
            "id": 6380
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000314"
              }
            ],
            "repeated": 0,
            "id": 6381
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000290"
              }
            ],
            "repeated": 0,
            "id": 6382
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 6383
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002bc"
              }
            ],
            "repeated": 0,
            "id": 6384
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000310"
              }
            ],
            "repeated": 0,
            "id": 6385
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000023c"
              }
            ],
            "repeated": 0,
            "id": 6386
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000220"
              }
            ],
            "repeated": 0,
            "id": 6387
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 6388
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000218"
              }
            ],
            "repeated": 0,
            "id": 6389
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              }
            ],
            "repeated": 0,
            "id": 6390
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000228"
              }
            ],
            "repeated": 0,
            "id": 6391
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 6392
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "cabinet.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffed9750000"
              },
              {
                "name": "FunctionName",
                "value": "FDIDestroy"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffed97572b0"
              }
            ],
            "repeated": 0,
            "id": 6393
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 6394
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000020c"
              }
            ],
            "repeated": 0,
            "id": 6395
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 6396
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 6397
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c8"
              }
            ],
            "repeated": 0,
            "id": 6398
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 6399
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 6400
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e4"
              }
            ],
            "repeated": 0,
            "id": 6401
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e0"
              }
            ],
            "repeated": 0,
            "id": 6402
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              }
            ],
            "repeated": 0,
            "id": 6403
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d8"
              }
            ],
            "repeated": 0,
            "id": 6404
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001d4"
              }
            ],
            "repeated": 0,
            "id": 6405
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001c4"
              }
            ],
            "repeated": 0,
            "id": 6406
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000190"
              }
            ],
            "repeated": 0,
            "id": 6407
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000194"
              }
            ],
            "repeated": 0,
            "id": 6408
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000018c"
              }
            ],
            "repeated": 0,
            "id": 6409
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000017c"
              }
            ],
            "repeated": 0,
            "id": 6410
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000015c"
              }
            ],
            "repeated": 0,
            "id": 6411
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000160"
              }
            ],
            "repeated": 0,
            "id": 6412
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000158"
              }
            ],
            "repeated": 0,
            "id": 6413
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000140"
              }
            ],
            "repeated": 0,
            "id": 6414
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000144"
              }
            ],
            "repeated": 0,
            "id": 6415
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000148"
              }
            ],
            "repeated": 0,
            "id": 6416
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000014c"
              }
            ],
            "repeated": 0,
            "id": 6417
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000150"
              }
            ],
            "repeated": 0,
            "id": 6418
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000154"
              }
            ],
            "repeated": 0,
            "id": 6419
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 6420
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1831000"
              },
              {
                "name": "ModuleName",
                "value": "ole32.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 6421
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000138"
              }
            ],
            "repeated": 0,
            "id": 6422
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000013c"
              }
            ],
            "repeated": 0,
            "id": 6423
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000134"
              }
            ],
            "repeated": 0,
            "id": 6424
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6425
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6426
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000118"
              }
            ],
            "repeated": 0,
            "id": 6427
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000011c"
              }
            ],
            "repeated": 0,
            "id": 6428
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000120"
              }
            ],
            "repeated": 0,
            "id": 6429
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000124"
              }
            ],
            "repeated": 0,
            "id": 6430
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000128"
              }
            ],
            "repeated": 0,
            "id": 6431
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000130"
              }
            ],
            "repeated": 0,
            "id": 6432
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000012c"
              }
            ],
            "repeated": 0,
            "id": 6433
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f8"
              }
            ],
            "repeated": 0,
            "id": 6434
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000fc"
              }
            ],
            "repeated": 0,
            "id": 6435
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f4"
              }
            ],
            "repeated": 0,
            "id": 6436
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000f0"
              }
            ],
            "repeated": 0,
            "id": 6437
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e8"
              }
            ],
            "repeated": 0,
            "id": 6438
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000ec"
              }
            ],
            "repeated": 0,
            "id": 6439
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e4"
              }
            ],
            "repeated": 0,
            "id": 6440
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000e0"
              }
            ],
            "repeated": 0,
            "id": 6441
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000dc"
              }
            ],
            "repeated": 0,
            "id": 6442
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6443
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000c8"
              }
            ],
            "repeated": 0,
            "id": 6444
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000cc"
              }
            ],
            "repeated": 0,
            "id": 6445
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a4"
              }
            ],
            "repeated": 0,
            "id": 6446
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a0"
              }
            ],
            "repeated": 0,
            "id": 6447
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6448
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 6449
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "ValueName",
                "value": "DisableMetaFiles"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
              }
            ],
            "repeated": 0,
            "id": 6450
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6451
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize"
              }
            ],
            "repeated": 0,
            "id": 6452
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000000a8"
              },
              {
                "name": "ValueName",
                "value": "DisableUmpdBufferSizeCheck"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck"
              }
            ],
            "repeated": 0,
            "id": 6453
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000000a8"
              }
            ],
            "repeated": 0,
            "id": 6454
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6455
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000094"
              }
            ],
            "repeated": 0,
            "id": 6456
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000090"
              }
            ],
            "repeated": 0,
            "id": 6457
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000008c"
              }
            ],
            "repeated": 0,
            "id": 6458
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6459
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001a0"
              }
            ],
            "repeated": 0,
            "id": 6460
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000084"
              }
            ],
            "repeated": 0,
            "id": 6461
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 6462
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 6463
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000064"
              }
            ],
            "repeated": 0,
            "id": 6464
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000044"
              }
            ],
            "repeated": 0,
            "id": 6465
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000005c"
              }
            ],
            "repeated": 0,
            "id": 6466
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000060"
              }
            ],
            "repeated": 0,
            "id": 6467
          },
          {
            "timestamp": "2026-02-10 09:22:15,233",
            "thread_id": "3424",
            "caller": "0x7ff70a392f4b",
            "parentcaller": "0x7ff70a3c98fd",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 6468
          }
        ],
        "threads": [
          "3424",
          "5500",
          "5508",
          "6080",
          "6072"
        ],
        "environ": {
          "UserName": "￑￈￑ￒￅￌ￀",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\"",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff70a390000",
          "MainExeSize": "0x00057000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      },
      {
        "process_id": 5480,
        "process_name": "dllhost.exe",
        "parent_id": 740,
        "module_path": "C:\\Windows\\System32\\dllhost.exe",
        "first_seen": "2026-02-10 09:23:39,213",
        "calls": [
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 0
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "4884",
            "caller": "0x7ffee34ceb32",
            "parentcaller": "0x7ffee34877c3",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 1
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ff6f81712f2",
            "parentcaller": "0x7ff6f81713bb",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e980fa000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 2
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ff6f8171349",
            "parentcaller": "0x7ff6f81713dc",
            "category": "hooking",
            "api": "SetUnhandledExceptionFilter",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ExceptionFilter",
                "value": "0x7ff6f8171b60"
              }
            ],
            "repeated": 0,
            "id": 3
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "4160",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 4
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\system32\\rpcss.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000202"
              }
            ],
            "repeated": 0,
            "id": 5
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "748",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 6
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 7
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000038"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 8
          },
          {
            "timestamp": "2026-02-10 09:23:39,338",
            "thread_id": "5560",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 9
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "4884",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e980fc000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 10
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "4884",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 11
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 12
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "42"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "5916"
              }
            ],
            "repeated": 0,
            "id": 13
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 14
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtQueryAttributesFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 15
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001f8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100021",
                "pretty_value": "FILE_READ_ACCESS|FILE_EXECUTE|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              },
              {
                "name": "ShareAccess",
                "value": "5",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 16
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtCreateSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d",
                "pretty_value": "SECTION_QUERY|SECTION_MAP_READ|SECTION_MAP_EXECUTE"
              },
              {
                "name": "ObjectAttributes",
                "value": ""
              },
              {
                "name": "FileHandle",
                "value": "0x000001f8"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\kernel.appcore.dll"
              }
            ],
            "repeated": 0,
            "id": 17
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea70000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00012000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 18
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea7f000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 19
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 20
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 21
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 22
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 23
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 24
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 25
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 26
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea75000"
              },
              {
                "name": "ModuleName",
                "value": "kernel.appcore.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 27
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\SYSTEM32\\kernel.appcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedea70000"
              }
            ],
            "repeated": 0,
            "id": 28
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\kernel.appcore"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedea70000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffedea73f10"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 29
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 30
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 31
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 32
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001fc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "bcryptPrimitives.dll"
              }
            ],
            "repeated": 0,
            "id": 33
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001fc"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x00082000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 34
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 35
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 36
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 37
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 38
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 39
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001fc"
              }
            ],
            "repeated": 0,
            "id": 40
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee13f7000"
              },
              {
                "name": "ModuleName",
                "value": "bcryptPrimitives.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 41
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\bcryptPrimitives"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1390000"
              }
            ],
            "repeated": 0,
            "id": 42
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e980fd000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 43
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 44
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001cc"
              },
              {
                "name": "ValueName",
                "value": "STE"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE"
              }
            ],
            "repeated": 0,
            "id": 45
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 46
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001cc"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 47
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001cc"
              },
              {
                "name": "ValueName",
                "value": "Enabled"
              },
              {
                "name": "Type",
                "value": "4",
                "pretty_value": "REG_DWORD"
              },
              {
                "name": "Information",
                "value": "0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled"
              }
            ],
            "repeated": 0,
            "id": 48
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Lsa"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa"
              }
            ],
            "repeated": 0,
            "id": 49
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001e8"
              },
              {
                "name": "ValueName",
                "value": "FipsAlgorithmPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy"
              }
            ],
            "repeated": 0,
            "id": 50
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000001cc"
              },
              {
                "name": "ValueName",
                "value": "MDMEnabled"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled"
              }
            ],
            "repeated": 0,
            "id": 51
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 52
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e8"
              }
            ],
            "repeated": 0,
            "id": 53
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Policies\\Microsoft\\Cryptography\\Configuration"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Policies\\Microsoft\\Cryptography\\Configuration"
              }
            ],
            "repeated": 0,
            "id": 54
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenFile",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileHandle",
                "value": "0x000001e8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00100001",
                "pretty_value": "FILE_READ_ACCESS|SYNCHRONIZE"
              },
              {
                "name": "FileName",
                "value": "\\Device\\CNG"
              },
              {
                "name": "ShareAccess",
                "value": "7",
                "pretty_value": "FILE_SHARE_READ|FILE_SHARE_WRITE|FILE_SHARE_DELETE"
              }
            ],
            "repeated": 0,
            "id": 55
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "device",
            "api": "DeviceIoControl",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "DeviceHandle",
                "value": "0x000001e8"
              },
              {
                "name": "IoControlCode",
                "value": "0x00390008",
                "pretty_value": "IOCTL_KSEC_RANDOM_FILL_BUFFER"
              },
              {
                "name": "InBuffer",
                "value": ""
              },
              {
                "name": "OutBuffer",
                "value": "b\\x8d\\xc94\\x10#\\xfe\\xadi\\x05\\xf9\\xf7WqY$\\x94kqT\\x9ef\\x9b\\xfa\\x8caY\\xf6\\x0336\\x976S\\xcflC\\xfc\\x98E\\xc6\\xa6\\xc3\\xdc}\\xe2\\xc0f"
              }
            ],
            "repeated": 0,
            "id": 56
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\bcryptprimitives"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1390000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee13c8b60"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 57
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 58
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee345e000"
              },
              {
                "name": "ModuleName",
                "value": "RPCRT4.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 59
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f8171153",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98100000"
              },
              {
                "name": "RegionSize",
                "value": "0x00006000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 60
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 61
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CLSIDFromOle1Class"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fef760"
              }
            ],
            "repeated": 0,
            "id": 62
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 63
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 64
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 65
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x10\\xf3\\xefi\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xc0\\xf3\\xefi\\x82\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0"
              }
            ],
            "repeated": 0,
            "id": 66
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000200"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\User\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 67
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 68
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 69
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x40000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              },
              {
                "name": "MutexName",
                "value": "Local\\SM0:5480:304:WilStaging_02"
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 70
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 71
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 72
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 73
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 74
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 75
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              }
            ],
            "repeated": 0,
            "id": 76
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 77
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 78
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 79
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001f4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004"
              },
              {
                "name": "ObjectAttributes",
                "value": "Global\\__ComCatalogCache__"
              }
            ],
            "repeated": 0,
            "id": 80
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x000001f4"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e99b10000"
              },
              {
                "name": "SectionOffset",
                "value": "0x8269eff3e0"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 81
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\COM3"
              },
              {
                "name": "Handle",
                "value": "0x00000204"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3"
              }
            ],
            "repeated": 0,
            "id": 82
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              },
              {
                "name": "ValueName",
                "value": "Com+Enabled"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled"
              }
            ],
            "repeated": 0,
            "id": 83
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 84
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtSetInformationProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessInformationClass",
                "value": "93"
              },
              {
                "name": "ProcessInformation",
                "value": "\\x7f7\\x9e}"
              }
            ],
            "repeated": 0,
            "id": 85
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000204"
              },
              {
                "name": "DesiredAccess",
                "value": "0x0000000d"
              },
              {
                "name": "ObjectAttributes",
                "value": "clbcatq.dll"
              }
            ],
            "repeated": 0,
            "id": 86
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x00000204"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c20000"
              },
              {
                "name": "SectionOffset",
                "value": "0x00000000"
              },
              {
                "name": "ViewSize",
                "value": "0x000a9000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000080",
                "pretty_value": "PAGE_EXECUTE_WRITECOPY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 87
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2cc4000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 88
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 89
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 90
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 91
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c99000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 92
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c98000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 93
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000204"
              }
            ],
            "repeated": 0,
            "id": 94
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c98000"
              },
              {
                "name": "ModuleName",
                "value": "clbcatq.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00002000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 95
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\clbcatq"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee2c20000"
              }
            ],
            "repeated": 0,
            "id": 96
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000208"
              },
              {
                "name": "EventName",
                "value": "\\KernelObjects\\MaximumCommitCondition"
              }
            ],
            "repeated": 0,
            "id": 97
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrpCallInitRoutine",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "MappedPath",
                "value": "\\Device\\HarddiskVolume2\\Windows\\System32\\clbcatq"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee2c20000"
              },
              {
                "name": "InitRoutine",
                "value": "0x7ffee2c3d990"
              },
              {
                "name": "Reason",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 98
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 99
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 100
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000004"
              },
              {
                "name": "ObjectAttributes",
                "value": "Global\\__ComCatalogCache__"
              }
            ],
            "repeated": 0,
            "id": 101
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtMapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SectionHandle",
                "value": "0x0000020c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e99b20000"
              },
              {
                "name": "SectionOffset",
                "value": "0x8269eff130"
              },
              {
                "name": "ViewSize",
                "value": "0x00001000"
              },
              {
                "name": "Win32Protect",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 102
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 103
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000212"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 104
          },
          {
            "timestamp": "2026-02-10 09:23:39,354",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 105
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 106
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98106000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 107
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "LocalService"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService"
              }
            ],
            "repeated": 0,
            "id": 108
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 109
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "Data",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 110
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "RunAs"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs"
              }
            ],
            "repeated": 0,
            "id": 111
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "ActivateAtStorage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage"
              }
            ],
            "repeated": 0,
            "id": 112
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x00000216"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 113
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000216"
              },
              {
                "name": "ValueName",
                "value": "ROTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags"
              }
            ],
            "repeated": 0,
            "id": 114
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000216"
              },
              {
                "name": "ValueName",
                "value": "AppIDFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags"
              }
            ],
            "repeated": 0,
            "id": 115
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000216"
              },
              {
                "name": "ValueName",
                "value": "MGOTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags"
              }
            ],
            "repeated": 0,
            "id": 116
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000216"
              },
              {
                "name": "ValueName",
                "value": "ProcessMitigationPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy"
              }
            ],
            "repeated": 0,
            "id": 117
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000216"
              }
            ],
            "repeated": 0,
            "id": 118
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "LaunchPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission"
              }
            ],
            "repeated": 0,
            "id": 119
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 120
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "ValueName",
                "value": "LegacyAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 121
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "ValueName",
                "value": "LegacyImpersonationLevel"
              },
              {
                "name": "Data",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel"
              }
            ],
            "repeated": 0,
            "id": 122
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              }
            ],
            "repeated": 0,
            "id": 123
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 124
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "RemoteServerName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName"
              }
            ],
            "repeated": 0,
            "id": 125
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "SRPTrustLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel"
              }
            ],
            "repeated": 0,
            "id": 126
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "PreferredServerBitness"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness"
              }
            ],
            "repeated": 0,
            "id": 127
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "LoadUserSettings"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings"
              }
            ],
            "repeated": 0,
            "id": 128
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xec\\xefi\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x12\\x02\\x00\\x00\\x00\\x00\\x00\\x00PQ$\\xe3\\xfe\\x7f\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 129
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000214"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 130
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000214"
              },
              {
                "name": "SubKey",
                "value": "Software\\Classes"
              },
              {
                "name": "Handle",
                "value": "0x00000218"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 131
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              }
            ],
            "repeated": 0,
            "id": 132
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegNotifyChangeKeyValue",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\"
              },
              {
                "name": "NotifyFilter",
                "value": "0x10000005"
              },
              {
                "name": "WatchSubtree",
                "value": "1"
              },
              {
                "name": "Asynchronous",
                "value": "1"
              }
            ],
            "repeated": 0,
            "id": 133
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              },
              {
                "name": "ValueName",
                "value": "ProtectionLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel"
              }
            ],
            "repeated": 0,
            "id": 134
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000212"
              }
            ],
            "repeated": 0,
            "id": 135
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 136
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 137
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 138
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 139
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 140
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 141
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 142
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "164"
              }
            ],
            "repeated": 0,
            "id": 143
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020119",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|KEY_WOW64_64KEY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx"
              }
            ],
            "repeated": 0,
            "id": 144
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "AllowDevelopmentWithoutDevLicense"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense"
              }
            ],
            "repeated": 0,
            "id": 145
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 146
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020119",
                "pretty_value": "KEY_QUERY_VALUE|KEY_ENUMERATE_SUB_KEYS|KEY_NOTIFY|KEY_WOW64_64KEY|STANDARD_RIGHTS_REQUIRED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\Machine\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock"
              }
            ],
            "repeated": 0,
            "id": 147
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "AllowDevelopmentWithoutDevLicense"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense"
              }
            ],
            "repeated": 0,
            "id": 148
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 149
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 150
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlRegisterFeatureConfigurationChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34793b0"
              }
            ],
            "repeated": 0,
            "id": 151
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "NtQueryWnfStateData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee350fc40"
              }
            ],
            "repeated": 0,
            "id": 152
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlSubscribeWnfStateChangeNotification"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34b2460"
              }
            ],
            "repeated": 0,
            "id": 153
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDisownModuleHeapAllocation"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34efa30"
              }
            ],
            "repeated": 0,
            "id": 154
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlQueryFeatureConfiguration"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34ccbd0"
              }
            ],
            "repeated": 0,
            "id": 155
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98108000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 156
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE\\AppCompat"
              },
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\AppCompat"
              }
            ],
            "repeated": 0,
            "id": 157
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "RaiseActivationAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 158
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 159
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 160
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "20"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 161
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "18"
              },
              {
                "name": "TokenInformation",
                "value": "\\x01\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 162
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": " \\xeb\\xefi\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xbf'k\\xc0\\xfe\\x7f\\x00\\x008%k\\xc0\\xfe\\x7f\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\xd0\\xeb\\xefi\\x82\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0'k\\xc0"
              }
            ],
            "repeated": 0,
            "id": 163
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000220"
              },
              {
                "name": "DesiredAccess",
                "value": "0x02000000",
                "pretty_value": "MAXIMUM_ALLOWED"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\Registry\\User\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes"
              }
            ],
            "repeated": 0,
            "id": 164
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 165
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000222"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 166
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 167
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE\\AppCompat"
              },
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\AppCompat"
              }
            ],
            "repeated": 0,
            "id": 168
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              },
              {
                "name": "ValueName",
                "value": "RaiseDefaultAuthnLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel"
              }
            ],
            "repeated": 0,
            "id": 169
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 170
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              },
              {
                "name": "ValueName",
                "value": "AccessPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission"
              }
            ],
            "repeated": 0,
            "id": 171
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021e"
              }
            ],
            "repeated": 0,
            "id": 172
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SOFTWARE\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 173
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              },
              {
                "name": "ValueName",
                "value": "DefaultAccessPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission"
              }
            ],
            "repeated": 0,
            "id": 174
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 175
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 176
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0L\\x10\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 177
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 178
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": false,
            "return": "0xffffffffc0000135",
            "pretty_return": "DLL_NOT_FOUND",
            "arguments": [
              {
                "name": "FileName",
                "value": "C:\\Windows\\system32\\rpcss.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 179
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000021c"
              }
            ],
            "repeated": 0,
            "id": 180
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb0\\xf0\\xefi\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\xa6C\\x0c\\xe1\\xfe\\x7f\\x00\\x00\\xfe\\xb6?\\xd4\\xfen\\x00\\x00\\xff\\xff\\xff\\xff\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 181
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 182
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 183
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 184
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9810a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 185
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000224"
              }
            ],
            "repeated": 0,
            "id": 186
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 187
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 188
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 189
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9810c000"
              },
              {
                "name": "RegionSize",
                "value": "0x00003000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 190
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00001568"
              },
              {
                "name": "EventName",
                "value": "MSFT.VSA.COM.DISABLE.5480"
              }
            ],
            "repeated": 0,
            "id": 191
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "synchronization",
            "api": "NtOpenEvent",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "EventName",
                "value": "MSFT.VSA.IEC.STATUS.6c736db0"
              }
            ],
            "repeated": 0,
            "id": 192
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000222"
              },
              {
                "name": "SubKey",
                "value": "Interface\\{00000134-0000-0000-C000-000000000046}"
              },
              {
                "name": "Handle",
                "value": "0x00000232"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}"
              }
            ],
            "repeated": 0,
            "id": 193
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000232"
              },
              {
                "name": "SubKey",
                "value": "ProxyStubClsid32"
              },
              {
                "name": "Handle",
                "value": "0x00000236"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32"
              }
            ],
            "repeated": 0,
            "id": 194
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000236"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "{00000320-0000-0000-C000-000000000046}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 195
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000236"
              }
            ],
            "repeated": 0,
            "id": 196
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000232"
              }
            ],
            "repeated": 0,
            "id": 197
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\MACHINE\\Software\\Microsoft\\Rpc\\Extensions"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc\\Extensions"
              }
            ],
            "repeated": 0,
            "id": 198
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "NtQueryValueKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000230"
              },
              {
                "name": "ValueName",
                "value": "NdrOleExtDLL"
              },
              {
                "name": "Type",
                "value": "2",
                "pretty_value": "REG_EXPAND_SZ"
              },
              {
                "name": "Information",
                "value": "combase.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL"
              }
            ],
            "repeated": 0,
            "id": 199
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 200
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 201
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "NdrOleInitializeExtension"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee3014240"
              }
            ],
            "repeated": 0,
            "id": 202
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 203
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 204
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "StringFromIID"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fe9780"
              }
            ],
            "repeated": 0,
            "id": 205
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemAlloc"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff2e80"
              }
            ],
            "repeated": 0,
            "id": 206
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff1b70"
              }
            ],
            "repeated": 0,
            "id": 207
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoCreateInstance"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6a420"
              }
            ],
            "repeated": 0,
            "id": 208
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 209
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9810f000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 210
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 211
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000230"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 212
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 213
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 214
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00w\\x00s\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 215
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 216
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 217
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98K\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 218
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 219
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 220
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00n\\x83?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x90\\xe6\\xefi\\x82\\x00\\x00\\x00\\x88\\xe6\\xefi\\x82\\x00\\x00\\x00X\\xe6\\xefi\\x82\\x00\\x00\\x00x\\xe6\\xefi"
              }
            ],
            "repeated": 0,
            "id": 221
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00x\\xe4\\xefi\\x82\\x00\\x00\\x004\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 222
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 223
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "X\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x04]\\x88\\x8a\\xeb\\x1c\\xc9\\x11\\x9f\\xe8\\x08\\x00+\\x10H`\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00m\\x00o\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 224
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": " \\x19\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\xcf \\x96\\xf0\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\xeb\\x1c\\xc9\\x11\\x9f\\xe8\\x08\\x00+\\x10H`\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\x03\\xa6\\xe0\\xfe\\x7f\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 225
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 226
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "hN\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 227
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 228
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 229
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x0e\\x87?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xf0\\xe2\\xefi\\x82\\x00\\x00\\x00\\xe8\\xe2\\xefi\\x82\\x00\\x00\\x00\\xb8\\xe2\\xefi\\x82\\x00\\x00\\x00\\xd8\\xe2\\xefi"
              }
            ],
            "repeated": 0,
            "id": 230
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xd8\\xe0\\xefi\\x82\\x00\\x00\\x004\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 231
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000230"
              }
            ],
            "repeated": 0,
            "id": 232
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 233
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 234
          },
          {
            "timestamp": "2026-02-10 09:23:39,370",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 235
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000238"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x20e980f9f10"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "4588"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 236
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x00000238",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x20e980f9f10"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "4588"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              }
            ],
            "repeated": 0,
            "id": 237
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 238
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 239
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000238"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 240
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 241
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 242
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 243
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 244
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 245
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "xM\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 246
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 247
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "X\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 248
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\xbc?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xea\\xefi\\x82\\x00\\x00\\x00X\\xea\\xefi\\x82\\x00\\x00\\x00(\\xea\\xefi\\x82\\x00\\x00\\x00H\\xea\\xefi"
              }
            ],
            "repeated": 0,
            "id": 249
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00H\\xe8\\xefi\\x82\\x00\\x00\\x00@\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 250
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 251
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 252
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\x1a\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 253
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 254
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98N\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 255
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 256
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 257
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00>\\x83?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xe6\\xefi\\x82\\x00\\x00\\x00\\xb8\\xe6\\xefi\\x82\\x00\\x00\\x00\\x88\\xe6\\xefi\\x82\\x00\\x00\\x00\\xa8\\xe6\\xefi"
              }
            ],
            "repeated": 0,
            "id": 258
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xd0\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xa8\\xe4\\xefi\\x82\\x00\\x00\\x00@\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 259
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 260
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 261
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 262
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000240"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 263
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 264
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 265
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 266
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 267
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 268
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "HP\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 269
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 270
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 271
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\xbc?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xea\\xefi\\x82\\x00\\x00\\x00X\\xea\\xefi\\x82\\x00\\x00\\x00(\\xea\\xefi\\x82\\x00\\x00\\x00H\\xea\\xefi"
              }
            ],
            "repeated": 0,
            "id": 272
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00H\\xe8\\xefi\\x82\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 273
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 274
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "X\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 275
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 276
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 277
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8K\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 278
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 279
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 280
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00>\\x83?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xe6\\xefi\\x82\\x00\\x00\\x00\\xb8\\xe6\\xefi\\x82\\x00\\x00\\x00\\x88\\xe6\\xefi\\x82\\x00\\x00\\x00\\xa8\\xe6\\xefi"
              }
            ],
            "repeated": 0,
            "id": 281
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xa8\\xe4\\xefi\\x82\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 282
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 283
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 284
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 285
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000238"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 286
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 287
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 288
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 289
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "`\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 290
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 291
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8I\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 292
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 293
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 294
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\xbc?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xea\\xefi\\x82\\x00\\x00\\x00X\\xea\\xefi\\x82\\x00\\x00\\x00(\\xea\\xefi\\x82\\x00\\x00\\x00H\\xea\\xefi"
              }
            ],
            "repeated": 0,
            "id": 295
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00H\\xe8\\xefi\\x82\\x00\\x00\\x00@\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 296
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98111000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 297
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 298
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 299
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 300
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 301
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8J\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 302
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 303
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 304
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00>\\x83?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xe6\\xefi\\x82\\x00\\x00\\x00\\xb8\\xe6\\xefi\\x82\\x00\\x00\\x00\\x88\\xe6\\xefi\\x82\\x00\\x00\\x00\\xa8\\xe6\\xefi"
              }
            ],
            "repeated": 0,
            "id": 305
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xa8\\xe4\\xefi\\x82\\x00\\x00\\x00@\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 306
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 307
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 308
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 309
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000240"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 310
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 311
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 312
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x16\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 313
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "`\\x18\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x05\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 314
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 315
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8N\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 316
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 317
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 318
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x9e\\xbc?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00`\\xea\\xefi\\x82\\x00\\x00\\x00X\\xea\\xefi\\x82\\x00\\x00\\x00(\\xea\\xefi\\x82\\x00\\x00\\x00H\\xea\\xefi"
              }
            ],
            "repeated": 0,
            "id": 319
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00H\\xe8\\xefi\\x82\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 320
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 321
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "x\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05"
              }
            ],
            "repeated": 0,
            "id": 322
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\x19\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 323
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 324
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x88L\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 325
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 326
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "8\\x1a\\x0f\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 327
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00>\\x83?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xc0\\xe6\\xefi\\x82\\x00\\x00\\x00\\xb8\\xe6\\xefi\\x82\\x00\\x00\\x00\\x88\\xe6\\xefi\\x82\\x00\\x00\\x00\\xa8\\xe6\\xefi"
              }
            ],
            "repeated": 0,
            "id": 328
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x000\\x1a\\x0f\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xa8\\xe4\\xefi\\x82\\x00\\x00\\x008\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 329
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98112000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 330
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 331
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 332
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 333
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98114000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 334
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4592",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 335
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4592",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000254"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 336
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4592",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98116000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 337
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4596",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98118000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 338
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 339
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4596",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 340
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x0000025c"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x20e980f9cd0"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "4608"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 341
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x0000025c",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee2fe2d30"
              },
              {
                "name": "Parameter",
                "value": "0x20e980f9cd0"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "4608"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              }
            ],
            "repeated": 0,
            "id": 342
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000025c"
              }
            ],
            "repeated": 0,
            "id": 343
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 344
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4608",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 345
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4608",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98119000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 346
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4608",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 347
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4608",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 348
          },
          {
            "timestamp": "2026-02-10 09:23:39,385",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\uxtheme"
              },
              {
                "name": "DllBase",
                "value": "0x7ffede5b0000"
              }
            ],
            "repeated": 0,
            "id": 349
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\uxtheme.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffede5b0000"
              }
            ],
            "repeated": 0,
            "id": 350
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee1f92b57",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffede5b0000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\uxtheme.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00000008"
              }
            ],
            "repeated": 0,
            "id": 351
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee1f92bbb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "uxtheme.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffede5b0000"
              },
              {
                "name": "FunctionName",
                "value": "ThemeInitApiHook"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffede5bcde0"
              }
            ],
            "repeated": 0,
            "id": 352
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffede5bce20",
            "parentcaller": "0x7ffee1f92d8c",
            "category": "system",
            "api": "IsDebuggerPresent",
            "status": false,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 353
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee34867b5",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xea\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 354
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34867ec",
            "parentcaller": "0x7ffee10a5140",
            "category": "registry",
            "api": "NtOpenKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020019",
                "pretty_value": "KEY_READ"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER"
              }
            ],
            "repeated": 0,
            "id": 355
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c3f4b",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000270"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 356
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c3f76",
            "parentcaller": "0x7ffee1144fd4",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000274"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000270"
              },
              {
                "name": "ObjectAttributesName",
                "value": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize"
              }
            ],
            "repeated": 0,
            "id": 357
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c2fe4",
            "parentcaller": "0x7ffede5ed921",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              },
              {
                "name": "ValueName",
                "value": "AppsUseLightTheme"
              },
              {
                "name": "Data",
                "value": "1"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme"
              }
            ],
            "repeated": 0,
            "id": 358
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c3018",
            "parentcaller": "0x7ffede5ed921",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 359
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffede5bd96c",
            "parentcaller": "0x7ffede5bd1d1",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000270"
              }
            ],
            "repeated": 0,
            "id": 360
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x00000278"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 361
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9811a000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 362
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 363
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x0000027c"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 364
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 365
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 366
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "x\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00w\\x00s\\x00\\\\x00S\\x00Y\\x00S\\x00T\\x00E\\x00M\\x003\\x002\\x00\\\\x00k\\x00e\\x00r\\x00n\\x00e\\x00l\\x00.\\x00a\\x00p\\x00p\\x00c\\x00o\\x00r\\x00e\\x00"
              }
            ],
            "repeated": 0,
            "id": 367
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 368
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 369
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "HM\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 370
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 371
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9811b000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 372
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xac\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 373
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00^\\xb9O\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xa0\\xec\\x9fj\\x82\\x00\\x00\\x00\\x98\\xec\\x9fj\\x82\\x00\\x00\\x00h\\xec\\x9fj\\x82\\x00\\x00\\x00\\x88\\xec\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 374
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xac\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x88\\xea\\x9fj\\x82\\x00\\x00\\x00\\x80\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 375
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 376
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xab\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 377
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xb0\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 378
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 379
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98K\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 380
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 381
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "X\\xa2\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 382
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xfe\\xbdO\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x00\\xe9\\x9fj\\x82\\x00\\x00\\x00\\xf8\\xe8\\x9fj\\x82\\x00\\x00\\x00\\xc8\\xe8\\x9fj\\x82\\x00\\x00\\x00\\xe8\\xe8\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 383
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xa2\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xe8\\xe6\\x9fj\\x82\\x00\\x00\\x00\\x80\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 384
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000027c"
              }
            ],
            "repeated": 0,
            "id": 385
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000280"
              }
            ],
            "repeated": 0,
            "id": 386
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 387
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x00000284"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 388
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 389
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 390
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\x1c\\x0f\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 391
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xa2\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 392
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 393
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8L\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 394
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 395
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xa9\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 396
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00N\\x82?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xe7\\xefi\\x82\\x00\\x00\\x00\\xa8\\xe7\\xefi\\x82\\x00\\x00\\x00x\\xe7\\xefi\\x82\\x00\\x00\\x00\\x98\\xe7\\xefi"
              }
            ],
            "repeated": 0,
            "id": 397
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xa9\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x98\\xe5\\xefi\\x82\\x00\\x00\\x00\\x88\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 398
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 399
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd8\\xaf\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00`\\x00\r\\x98\\x0e\\x02\\x00\\x00\\x00\\xb0\\x11\\x98\\x0e\\x02\\x00\\x00\\x00@\\x0b\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 400
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xaa\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 401
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 402
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8N\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 403
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 404
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xa8\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 405
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xee\\x86?\\xd4\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x10\\xe4\\xefi\\x82\\x00\\x00\\x00\\x08\\xe4\\xefi\\x82\\x00\\x00\\x00\\xd8\\xe3\\xefi\\x82\\x00\\x00\\x00\\xf8\\xe3\\xefi"
              }
            ],
            "repeated": 0,
            "id": 406
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xb0\\xa8\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xf8\\xe1\\xefi\\x82\\x00\\x00\\x00\\x88\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 407
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000284"
              }
            ],
            "repeated": 0,
            "id": 408
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 409
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "NtCreateThreadEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000288"
              },
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartAddress",
                "value": "0x7ffee3027db0"
              },
              {
                "name": "Parameter",
                "value": "0x20e981045d0"
              },
              {
                "name": "CreateFlags",
                "value": "0x00000001"
              },
              {
                "name": "ThreadId",
                "value": "4564"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              },
              {
                "name": "Module",
                "value": "combase.dll"
              }
            ],
            "repeated": 0,
            "id": 410
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "threading",
            "api": "CreateRemoteThreadEx",
            "status": true,
            "return": "0x00000288",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "StartRoutine",
                "value": "0x7ffee3027db0"
              },
              {
                "name": "Parameter",
                "value": "0x20e981045d0"
              },
              {
                "name": "CreationFlags",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "4564"
              },
              {
                "name": "ProcessId",
                "value": "5480"
              }
            ],
            "repeated": 0,
            "id": 411
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 412
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              },
              {
                "name": "Milliseconds",
                "value": "20000"
              }
            ],
            "repeated": 0,
            "id": 413
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4564",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9811d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 414
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4564",
            "caller": "0x7ffee34e507d",
            "parentcaller": "0x7ffee34e4c43",
            "category": "threading",
            "api": "NtTestAlert",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 415
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4564",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee3027dc9",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e0"
              },
              {
                "name": "Milliseconds",
                "value": "30000"
              }
            ],
            "repeated": 0,
            "id": 416
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4564",
            "caller": "0x7ffee34c467e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "4564"
              }
            ],
            "repeated": 0,
            "id": 417
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4564",
            "caller": "0x7ffee34c469e",
            "parentcaller": "0x7ffee167734d",
            "category": "threading",
            "api": "NtTerminateThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0x00000000"
              },
              {
                "name": "ExitStatus",
                "value": "0x00000000"
              },
              {
                "name": "ThreadId",
                "value": "0"
              },
              {
                "name": "ProcessId",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 418
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 419
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 420
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10f6f4c",
            "parentcaller": "0x7ffee336ef53",
            "category": "system",
            "api": "NtDuplicateObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SourceProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "SourceHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "TargetProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "TargetHandle",
                "value": "0x0000027c"
              },
              {
                "name": "Options",
                "value": "0x00000002"
              }
            ],
            "repeated": 0,
            "id": 421
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f68ce0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": " Q\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x02\\x00\\x00\\x00\\x02\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 422
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2f68c8a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000288"
              }
            ],
            "repeated": 0,
            "id": 423
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee2fed427",
            "parentcaller": "0x7ffee2f63d82",
            "category": "misc",
            "api": "GetCommandLineW",
            "status": true,
            "return": "0x20e980d2248",
            "arguments": [
              {
                "name": "CommandLine",
                "value": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 424
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30142bf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 425
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30142e9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 426
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014313",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "StringFromIID"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fe9780"
              }
            ],
            "repeated": 0,
            "id": 427
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee301433d",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemAlloc"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff2e80"
              }
            ],
            "repeated": 0,
            "id": 428
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014367",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoTaskMemFree"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2ff1b70"
              }
            ],
            "repeated": 0,
            "id": 429
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee3014391",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoCreateInstance"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6a420"
              }
            ],
            "repeated": 0,
            "id": 430
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee30143bb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 431
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee30141cf",
            "parentcaller": "0x7ffee34b38c0",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000032A-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "00000149-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 432
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f9b0ca",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 433
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff224d",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000338-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 434
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x0000029a"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 435
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 436
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 437
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xe0\\xcc\\x8fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9a\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xe0\\xcd\\x8fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 438
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 439
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 440
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029a"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 441
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 442
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029a"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 443
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029a"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 444
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029a"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Class Factory for Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 445
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x0000029a"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 446
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 447
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 448
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 449
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Apartment"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 450
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029e"
              }
            ],
            "repeated": 0,
            "id": 451
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 452
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 453
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xcb\\x8fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9a\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00p\\xcc\\x8fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 454
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 455
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 456
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029a"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 457
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 458
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 459
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "p\\xcb\\x8fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\x9a\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00p\\xcc\\x8fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 460
          },
          {
            "timestamp": "2026-02-10 09:23:39,401",
            "thread_id": "4596",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 461
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x0000029a"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 462
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x0000029a"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 463
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000029a"
              }
            ],
            "repeated": 0,
            "id": 464
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fe94b2",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 465
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fe94ea",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "ValueName",
                "value": "MaxSxSHashCount"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount"
              }
            ],
            "repeated": 0,
            "id": 466
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fe9503",
            "parentcaller": "0x7ffee2fd54b4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 467
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fede68",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "SOFTWARE\\Microsoft\\COM3"
              },
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3"
              }
            ],
            "repeated": 0,
            "id": 468
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fedea4",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              },
              {
                "name": "ValueName",
                "value": "GipActivityBypass"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass"
              }
            ],
            "repeated": 0,
            "id": 469
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fedebd",
            "parentcaller": "0x7ffee2fa71ff",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000298"
              }
            ],
            "repeated": 0,
            "id": 470
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 471
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 472
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000002a4"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 473
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 474
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 475
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xaf\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 476
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "@\\xa4\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 477
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 478
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "HM\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 479
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 480
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "x\\xa3\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 481
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\xae\\x93O\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00P\\xd7\\x9fj\\x82\\x00\\x00\\x00H\\xd7\\x9fj\\x82\\x00\\x00\\x00\\x18\\xd7\\x9fj\\x82\\x00\\x00\\x008\\xd7\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 482
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00p\\xa3\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x008\\xd5\\x9fj\\x82\\x00\\x00\\x00\\xa8\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 483
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98121000"
              },
              {
                "name": "RegionSize",
                "value": "0x00002000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 484
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 485
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf8\\xaa\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 486
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": " \\xa3\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 487
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 488
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc8N\\x10\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 489
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 490
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xad\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 491
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00N\\x96O\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xb0\\xd3\\x9fj\\x82\\x00\\x00\\x00\\xa8\\xd3\\x9fj\\x82\\x00\\x00\\x00x\\xd3\\x9fj\\x82\\x00\\x00\\x00\\x98\\xd3\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 492
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xad\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\x98\\xd1\\x9fj\\x82\\x00\\x00\\x00\\xa8\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 493
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a4"
              }
            ],
            "repeated": 0,
            "id": 494
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 495
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee110c06d",
            "parentcaller": "0x7ffee10bd794",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e99b30000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 496
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10bed78",
            "parentcaller": "0x7ffee11106f5",
            "category": "synchronization",
            "api": "NtCreateMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "MutexName",
                "value": ""
              },
              {
                "name": "InitialOwner",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 497
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10bdbb1",
            "parentcaller": "0x7ffee10bd381",
            "category": "misc",
            "api": "GetSystemInfo",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 1,
            "id": 498
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee10bdda6",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              },
              {
                "name": "Milliseconds",
                "value": "4000"
              }
            ],
            "repeated": 0,
            "id": 499
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee110c06d",
            "parentcaller": "0x7ffee10bdcda",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e99b40000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 500
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee10bdd5d",
            "parentcaller": "0x7ffee10bdd0d",
            "category": "synchronization",
            "api": "NtReleaseMutant",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002ac"
              }
            ],
            "repeated": 0,
            "id": 501
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee347e715",
            "parentcaller": "0x7ffee347e37b",
            "category": "process",
            "api": "NtAllocateVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98123000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Protection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 502
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 503
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 504
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 505
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 506
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 507
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\xce\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xaa\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\x00\\xcf\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 508
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 509
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 510
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002aa"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 511
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 512
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 513
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 514
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Class Factory for Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 515
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002aa"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 516
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 517
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 518
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 519
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Apartment"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 520
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              }
            ],
            "repeated": 0,
            "id": 521
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 522
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 523
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xcc\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xaa\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\x90\\xcd\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 524
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 525
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 526
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002aa"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 527
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 528
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 529
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x90\\xcc\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xaa\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\x90\\xcd\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 530
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 531
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 532
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002aa"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 533
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ab08",
            "parentcaller": "0x7ffee2f7a7d9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002aa"
              },
              {
                "name": "SubKey",
                "value": "LocalServer32"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer32"
              }
            ],
            "repeated": 0,
            "id": 534
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7a825",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "ValueName",
                "value": "AppID"
              },
              {
                "name": "Data",
                "value": "{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID"
              }
            ],
            "repeated": 0,
            "id": 535
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee3015483",
            "parentcaller": "0x7ffee2f94bdc",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 536
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f94c07",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002a6"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 537
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 538
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "Thumbnail Cache Out of Proc Server"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 539
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "LocalService"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService"
              }
            ],
            "repeated": 0,
            "id": 540
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 541
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "DllSurrogate"
              },
              {
                "name": "Data",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate"
              }
            ],
            "repeated": 0,
            "id": 542
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f79bff",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "RunAs"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs"
              }
            ],
            "repeated": 0,
            "id": 543
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f79d1a",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "ActivateAtStorage"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage"
              }
            ],
            "repeated": 0,
            "id": 544
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79e39",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 545
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79e8d",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ROTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags"
              }
            ],
            "repeated": 0,
            "id": 546
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79ee0",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "AppIDFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags"
              }
            ],
            "repeated": 0,
            "id": 547
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79f30",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "MGOTFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags"
              }
            ],
            "repeated": 0,
            "id": 548
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79f84",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              },
              {
                "name": "ValueName",
                "value": "ProcessMitigationPolicy"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy"
              }
            ],
            "repeated": 0,
            "id": 549
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f79fa7",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b2"
              }
            ],
            "repeated": 0,
            "id": 550
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee3009058",
            "parentcaller": "0x7ffee2f79fcb",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "LaunchPermission"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission"
              }
            ],
            "repeated": 0,
            "id": 551
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a010",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x80000002",
                "pretty_value": "HKEY_LOCAL_MACHINE"
              },
              {
                "name": "SubKey",
                "value": "Software\\Microsoft\\OLE"
              },
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE"
              }
            ],
            "repeated": 0,
            "id": 552
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a052",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "ValueName",
                "value": "LegacyAuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 553
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a0a5",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              },
              {
                "name": "ValueName",
                "value": "LegacyImpersonationLevel"
              },
              {
                "name": "Data",
                "value": "2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel"
              }
            ],
            "repeated": 0,
            "id": 554
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a0de",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b0"
              }
            ],
            "repeated": 0,
            "id": 555
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a123",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "AuthenticationLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel"
              }
            ],
            "repeated": 0,
            "id": 556
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "RemoteServerName"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName"
              }
            ],
            "repeated": 0,
            "id": 557
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a1c8",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "SRPTrustLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel"
              }
            ],
            "repeated": 0,
            "id": 558
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a227",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "PreferredServerBitness"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness"
              }
            ],
            "repeated": 0,
            "id": 559
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a28a",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "LoadUserSettings"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings"
              }
            ],
            "repeated": 0,
            "id": 560
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7a318",
            "parentcaller": "0x7ffee2f94dd5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "ValueName",
                "value": "ProtectionLevel"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel"
              }
            ],
            "repeated": 0,
            "id": 561
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f94e2a",
            "parentcaller": "0x7ffee2f7a9ba",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              }
            ],
            "repeated": 0,
            "id": 562
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee301450c",
            "parentcaller": "0x7ffee2f7aa90",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002aa"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 563
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee3014529",
            "parentcaller": "0x7ffee2f7aa90",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              }
            ],
            "repeated": 0,
            "id": 564
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10bddf0",
            "parentcaller": "0x7ffee3014a29",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "0",
                "pretty_value": "FILE_SUPERSEDE"
              }
            ],
            "repeated": 0,
            "id": 565
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10bde10",
            "parentcaller": "0x7ffee3014a29",
            "category": "misc",
            "api": "NtQuerySystemInformation",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "SystemInformationClass",
                "value": "1",
                "pretty_value": "FILE_OPEN"
              }
            ],
            "repeated": 0,
            "id": 566
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 567
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 568
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xd0\\xcb\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xaa\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xd0\\xcc\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 569
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 570
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002aa"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 571
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002aa"
              },
              {
                "name": "ObjectAttributesName",
                "value": "LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 572
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ad16",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002a6"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 573
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ad4d",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002a6"
              },
              {
                "name": "SubKey",
                "value": "Elevation"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\Elevation"
              }
            ],
            "repeated": 0,
            "id": 574
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f7adb1",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a6"
              }
            ],
            "repeated": 0,
            "id": 575
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 576
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2f725e9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000222"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              },
              {
                "name": "Handle",
                "value": "0x000002aa"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
              }
            ],
            "repeated": 0,
            "id": 577
          },
          {
            "timestamp": "2026-02-10 09:23:39,417",
            "thread_id": "4608",
            "caller": "0x7ffee2fef8f8",
            "parentcaller": "0x7ffee2f7213b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002aa"
              },
              {
                "name": "SubKey",
                "value": "TreatAs"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 578
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f72160",
            "parentcaller": "0x7ffee2f69277",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002aa"
              }
            ],
            "repeated": 0,
            "id": 579
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\shcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1880000"
              }
            ],
            "repeated": 0,
            "id": 580
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34d7cc6",
            "parentcaller": "0x7ffee34addf7",
            "category": "system",
            "api": "NtQuerySystemTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 581
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34d7cc6",
            "parentcaller": "0x7ffee34addf7",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\thumbcache"
              },
              {
                "name": "DllBase",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 582
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 583
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffecda20000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\System32\\thumbcache.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00002008"
              }
            ],
            "repeated": 0,
            "id": 584
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96acf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetClassObject"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda3a900"
              }
            ],
            "repeated": 0,
            "id": 585
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96ae8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetActivationFactory"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda4c5c0"
              }
            ],
            "repeated": 0,
            "id": 586
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96b08",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffecda20000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffecda3be50"
              }
            ],
            "repeated": 0,
            "id": 587
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda83000"
              },
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 588
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda83000"
              },
              {
                "name": "ModuleName",
                "value": "thumbcache.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 589
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffecda35294",
            "parentcaller": "0x7ffee2fd5144",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000034B-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "0000015B-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 590
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee2f80e64",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              }
            ],
            "repeated": 0,
            "id": 591
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80e82",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoGetMarshalSizeMax"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fac590"
              }
            ],
            "repeated": 0,
            "id": 592
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80e9f",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoMarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fbb0b0"
              }
            ],
            "repeated": 0,
            "id": 593
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80ebc",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoUnmarshalInterface"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2fb8b50"
              }
            ],
            "repeated": 0,
            "id": 594
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f80ed9",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2f40000"
              },
              {
                "name": "FunctionName",
                "value": "CoReleaseMarshalData"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee2f6e790"
              }
            ],
            "repeated": 0,
            "id": 595
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2fefbe4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000222"
              },
              {
                "name": "SubKey",
                "value": "Interface\\{75121952-E0D0-43E5-9380-1D80483ACF72}"
              },
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{75121952-E0D0-43E5-9380-1D80483ACF72}"
              }
            ],
            "repeated": 0,
            "id": 596
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2fefa51",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002be"
              },
              {
                "name": "SubKey",
                "value": "ProxyStubClsid32"
              },
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32"
              }
            ],
            "repeated": 0,
            "id": 597
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2fefa8c",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 598
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2fefad3",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              }
            ],
            "repeated": 0,
            "id": 599
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2fefae4",
            "parentcaller": "0x7ffee2fb42ab",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              }
            ],
            "repeated": 0,
            "id": 600
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 601
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 602
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 603
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "0\\xbe\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x000\\xbf\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 604
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 605
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 606
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 607
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 608
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 609
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 610
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "PSFactoryBuffer"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 611
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002be"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 612
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 613
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 614
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10e4aa9",
            "parentcaller": "0x7ffee10c31c6",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "%SystemRoot%\\system32\\propsys.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 1,
            "id": 615
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Both"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 616
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              }
            ],
            "repeated": 0,
            "id": 617
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 618
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 619
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xbc\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xc0\\xbd\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 620
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 621
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 622
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 623
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 624
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 625
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xbc\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xc0\\xbd\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 626
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 627
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 628
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 629
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              }
            ],
            "repeated": 0,
            "id": 630
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 631
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 632
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f77b74",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 633
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 634
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 635
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xf0\\xba\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xf0\\xbb\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 636
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 637
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 638
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "TreatAs"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 639
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee30022e1",
            "parentcaller": "0x7ffee2f77c1d",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 640
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f781f5",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": "ActivateOnHostFlags"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags"
              }
            ],
            "repeated": 0,
            "id": 641
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 642
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f787bc",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "PSFactoryBuffer"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 643
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f78485",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002be"
              },
              {
                "name": "SubKey",
                "value": "InprocServer32"
              },
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 644
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": "InprocServer32"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32"
              }
            ],
            "repeated": 0,
            "id": 645
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7870d",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 0,
            "id": 646
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10e4aa9",
            "parentcaller": "0x7ffee10c31c6",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": ""
              },
              {
                "name": "Data",
                "value": "%SystemRoot%\\system32\\propsys.dll"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)"
              }
            ],
            "repeated": 1,
            "id": 647
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f78d32",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "ValueName",
                "value": "ThreadingModel"
              },
              {
                "name": "Data",
                "value": "Both"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel"
              }
            ],
            "repeated": 0,
            "id": 648
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee2f7855f",
            "parentcaller": "0x7ffee2f7829e",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              }
            ],
            "repeated": 0,
            "id": 649
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 650
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 651
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xb9\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\x80\\xba\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 652
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 653
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 654
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler32"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32"
              }
            ],
            "repeated": 0,
            "id": 655
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 656
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 657
          },
          {
            "timestamp": "2026-02-10 09:23:39,432",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xb9\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\x80\\xba\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 658
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 659
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 660
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "InprocHandler"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler"
              }
            ],
            "repeated": 0,
            "id": 661
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ab08",
            "parentcaller": "0x7ffee2f7a7d9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002be"
              },
              {
                "name": "SubKey",
                "value": "LocalServer32"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer32"
              }
            ],
            "repeated": 0,
            "id": 662
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c2e92",
            "parentcaller": "0x7ffee2f7a825",
            "category": "registry",
            "api": "RegQueryValueExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "ValueName",
                "value": "AppID"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID"
              }
            ],
            "repeated": 0,
            "id": 663
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c45a7",
            "parentcaller": "0x7ffee10c0705",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\REGISTRY\\MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "KeyInformationClass",
                "value": "3"
              }
            ],
            "repeated": 0,
            "id": 664
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c2314",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 665
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34a6c8b",
            "parentcaller": "0x7ffee10c23a0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "1"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc0\\xb8\\x9fj\\x82\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\x7f\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\xea\\x03\\x00\\x00\\xfe\\x7f\\x00\\x00\\x087k\\xc0\\xfe\\x7f\\x00\\x00\\xbe\\x02\\x00\\x00\\x00\\x00\\x00\\x000:k\\xc0\\xfe\\x7f\\x00\\x00\\x04\\x00\\x00\\x00\\x82\\x00\\x00\\x00\\xc0\\xb9\\x9fj\\x82\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 666
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c24a8",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x00000000"
              },
              {
                "name": "ObjectAttributesName",
                "value": "\\REGISTRY\\USER\\S-1-5-21-3318940731-3379818400-2144845357-1002_Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 667
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c40c4",
            "parentcaller": "0x7ffee10c25c4",
            "category": "registry",
            "api": "NtQueryKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x000002be"
              },
              {
                "name": "KeyInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "KeyInformationClass",
                "value": "7"
              }
            ],
            "repeated": 0,
            "id": 668
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c25e2",
            "parentcaller": "0x7ffee10c0732",
            "category": "registry",
            "api": "NtOpenKeyEx",
            "status": false,
            "return": "0xffffffffc0000034",
            "pretty_return": "OBJECT_NAME_NOT_FOUND",
            "arguments": [
              {
                "name": "KeyHandle",
                "value": "0x00000000"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000001",
                "pretty_value": "KEY_QUERY_VALUE"
              },
              {
                "name": "ObjectAttributesHandle",
                "value": "0x000002be"
              },
              {
                "name": "ObjectAttributesName",
                "value": "LocalServer"
              },
              {
                "name": "ObjectAttributes",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer"
              }
            ],
            "repeated": 0,
            "id": 669
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ad16",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000202"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002c2"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 670
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f7ad4d",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002c2"
              },
              {
                "name": "SubKey",
                "value": "Elevation"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\Elevation"
              }
            ],
            "repeated": 0,
            "id": 671
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f7adb1",
            "parentcaller": "0x7ffee2f783b8",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c2"
              }
            ],
            "repeated": 0,
            "id": 672
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f78010",
            "parentcaller": "0x7ffee2f753d4",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              }
            ],
            "repeated": 0,
            "id": 673
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f722bf",
            "parentcaller": "0x7ffee2f725e9",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x00000222"
              },
              {
                "name": "SubKey",
                "value": "CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              },
              {
                "name": "Handle",
                "value": "0x000002be"
              },
              {
                "name": "FullName",
                "value": "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
              }
            ],
            "repeated": 0,
            "id": 674
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2fef8f8",
            "parentcaller": "0x7ffee2f7213b",
            "category": "registry",
            "api": "RegOpenKeyExW",
            "status": false,
            "return": "0x00000002",
            "arguments": [
              {
                "name": "Registry",
                "value": "0x000002be"
              },
              {
                "name": "SubKey",
                "value": "TreatAs"
              },
              {
                "name": "Handle",
                "value": "0x00000000"
              },
              {
                "name": "FullName",
                "value": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs"
              }
            ],
            "repeated": 0,
            "id": 675
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2f72160",
            "parentcaller": "0x7ffee2f69277",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002be"
              }
            ],
            "repeated": 0,
            "id": 676
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 677
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 678
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "load"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\system32\\propsys"
              },
              {
                "name": "DllBase",
                "value": "0x7ffedc720000"
              }
            ],
            "repeated": 0,
            "id": 679
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LdrLoadDll",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Flags",
                "value": "0x00000000"
              },
              {
                "name": "FileName",
                "value": "C:\\Windows\\System32\\propsys.dll"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffedc720000"
              }
            ],
            "repeated": 0,
            "id": 680
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c56b2",
            "parentcaller": "0x7ffee2f96b6d",
            "category": "system",
            "api": "LoadLibraryExW",
            "status": true,
            "return": "0x7ffedc720000",
            "arguments": [
              {
                "name": "lpLibFileName",
                "value": "C:\\Windows\\system32\\propsys.dll"
              },
              {
                "name": "dwFlags",
                "value": "0x00002008"
              }
            ],
            "repeated": 0,
            "id": 681
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96acf",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetClassObject"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffedc72b810"
              }
            ],
            "repeated": 0,
            "id": 682
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96ae8",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": false,
            "return": "0xffffffffc0000139",
            "pretty_return": "ENTRYPOINT_NOT_FOUND",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllGetActivationFactory"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 683
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee2f96b08",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "propsys.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffedc720000"
              },
              {
                "name": "FunctionName",
                "value": "DllCanUnloadNow"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffedc756430"
              }
            ],
            "repeated": 0,
            "id": 684
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34b3f7a",
            "parentcaller": "0x7ffee3350ed7",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 685
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee3350cd1",
            "parentcaller": "0x7ffee334f28f",
            "category": "filesystem",
            "api": "NtOpenDirectoryObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "DirectoryHandle",
                "value": "0x000002c8"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00020001",
                "pretty_value": "FILE_READ_ACCESS|READ_CONTROL"
              },
              {
                "name": "ObjectAttributes",
                "value": "C:\\RPC Control"
              }
            ],
            "repeated": 0,
            "id": 686
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee110026b",
            "parentcaller": "0x7ffee3350daf",
            "category": "process",
            "api": "NtOpenProcessToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "DesiredAccess",
                "value": "0x00000008"
              },
              {
                "name": "TokenHandle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 687
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34e9c4e",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 688
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\xb8\\xa5\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 689
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa0\\xad\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 690
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 691
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xc8\\xc9\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 692
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 693
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "X\\xae\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 694
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00~\\x99O\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\x80\\xcc\\x9fj\\x82\\x00\\x00\\x00x\\xcc\\x9fj\\x82\\x00\\x00\\x00H\\xcc\\x9fj\\x82\\x00\\x00\\x00h\\xcc\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 695
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00P\\xae\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00h\\xca\\x9fj\\x82\\x00\\x00\\x00\\xcc\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 696
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34a8cde",
            "parentcaller": "0x7ffee34a953a",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "`J\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x02p\\x01\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 697
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e46",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "4"
              },
              {
                "name": "TokenInformation",
                "value": "\\x18\\xac\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 698
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6e9b",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "25"
              },
              {
                "name": "TokenInformation",
                "value": "\\x80\\xa3\\x11\\x98\\x0e\\x02\\x00\\x00`\\x00\\x00\\x00\\\\x00W\\x00\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x10\\x000\\x00\\x00\\\\x00S\\x00y\\x00s\\x00t\\x00e\\x00m\\x003\\x002\\x00\\\\x00t\\x00h\\x00u\\x00m\\x00b\\x00c\\x00a\\x00c\\x00h\\x00e\\x00.\\x00d\\x00l\\x00l\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 699
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6ec0",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 700
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f0e",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "5"
              },
              {
                "name": "TokenInformation",
                "value": "\\xa8\\xcb\\x11\\x98\\x0e\\x02\\x00\\x00\\x01\\x05\\x00\\x00\\x00\\x00\\x00\\x05\\x15\\x00\\x00\\x00;\\x04\\xd3\\xc5\\xa0\\xefs\\xc9-\\xbe\\xd7\\x7f\\x01\\x02\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 701
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f37",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": false,
            "return": "0xffffffffc0000023",
            "pretty_return": "BUFFER_TOO_SMALL",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 702
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d6f8f",
            "parentcaller": "0x7ffee34a8d8f",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "6"
              },
              {
                "name": "TokenInformation",
                "value": "\\x98\\xa1\\x11\\x98\\x0e\\x02\\x00\\x00\\x02\\x00P\\x00\\x03\\x00\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\x00\\x10\\x01\\x02\\x00\\x00\\x00\\x00\\x00\\x05 \\x00\\x00\\x00 \\x02\\x00\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x00\\x10\\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x05\\x12\\x00\\x00\\x00\\x00\\x00\\x1c\\x00\\x00\\x00\\x00\\xa0\\x01\\x03\\x00\\x00\\x00\\x00\\x00\\x05\\x05\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x1do\\x01\\x00"
              }
            ],
            "repeated": 0,
            "id": 703
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d7048",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x88\\x9bn\\xc0\\xfe\\x7f\\x00\\x00+\\x06G\\xc0\\xfe\\x7f\\x00\\x00\\x1e\\x9dO\\xd7\\xfen\\x00\\x00\\x80\\xbaj\\xc0\\xfe\\x7f\\x00\\x00\\xe0\\xc8\\x9fj\\x82\\x00\\x00\\x00\\xd8\\xc8\\x9fj\\x82\\x00\\x00\\x00\\xa8\\xc8\\x9fj\\x82\\x00\\x00\\x00\\xc8\\xc8\\x9fj"
              }
            ],
            "repeated": 0,
            "id": 704
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee34d707b",
            "parentcaller": "0x7ffee34d6fa8",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "41"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x90\\xa1\\x11\\x98\\x0e\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x19{H\\xc0\\xfe\\x7f\\x00\\x00#\\x00\\x00\\xc0\\x00\\x00\\x00\\x00\\xc8\\xc6\\x9fj\\x82\\x00\\x00\\x00\\xcc\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x9a\\x00i\\xa3\\xfe\\x7f\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xaa\nk\\xc0"
              }
            ],
            "repeated": 0,
            "id": 705
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e27",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002c8"
              }
            ],
            "repeated": 0,
            "id": 706
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee3350e49",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002cc"
              }
            ],
            "repeated": 0,
            "id": 707
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 708
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee303b785",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 709
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f68ce0",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "10"
              },
              {
                "name": "TokenInformation",
                "value": "\\x1eR\\x0b\\x00\\x00\\x00\\x00\\x00\\xc2o\\x01\\x00\\x00\\x00\\x00\\x00\\xff\\xff\\xff\\xff\\xff\\xff\\xff\\x7f\\x02\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x94\\x0f\\x00\\x00\\x0e\\x00\\x00\\x00\\x18\\x00\\x00\\x00\\xe4n\\x05\\x00\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 710
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2f68c8a",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 711
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 712
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              },
              {
                "name": "Milliseconds",
                "value": "5000"
              }
            ],
            "repeated": 0,
            "id": 713
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f9b0ca",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 714
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff224d",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000338-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 715
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 716
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 717
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 718
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 719
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4608",
            "caller": "0x7ffecda35294",
            "parentcaller": "0x7ffee2fd5144",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000034B-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "0000015B-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 720
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 721
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee303b785",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 722
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 723
          },
          {
            "timestamp": "2026-02-10 09:23:39,448",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              },
              {
                "name": "Milliseconds",
                "value": "5000"
              }
            ],
            "repeated": 0,
            "id": 724
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f9b0ca",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 725
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff224d",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000338-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 726
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 727
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 728
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 729
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4608",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 730
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4608",
            "caller": "0x7ffecda35294",
            "parentcaller": "0x7ffee2fd5144",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000034B-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "0000015B-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 731
          },
          {
            "timestamp": "2026-02-10 09:23:39,463",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 732
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee303b785",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 733
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 734
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              },
              {
                "name": "Milliseconds",
                "value": "5000"
              }
            ],
            "repeated": 0,
            "id": 735
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee10c54eb",
            "parentcaller": "0x7ffee2f9b0ca",
            "category": "process",
            "api": "NtQueryInformationToken",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "TokenInformationClass",
                "value": "29"
              },
              {
                "name": "TokenInformation",
                "value": "\\x00\\x00\\x00\\x00"
              }
            ],
            "repeated": 0,
            "id": 736
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff224d",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000338-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 737
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 738
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee10b30ce",
            "parentcaller": "0x7ffee2ff2cd1",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000214"
              },
              {
                "name": "Milliseconds",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 739
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee2fc2cd6",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 740
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4608",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 741
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4608",
            "caller": "0x7ffecda35294",
            "parentcaller": "0x7ffee2fd5144",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "0000034B-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000001",
                "pretty_value": "CLSCTX_INPROC_SERVER"
              },
              {
                "name": "riid",
                "value": "0000015B-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 742
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee2fb92b9",
            "parentcaller": "0x7ffee2ff1dfa",
            "category": "com",
            "api": "CoCreateInstance",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "rclsid",
                "value": "00000344-0000-0000-C000-000000000046"
              },
              {
                "name": "ClsContext",
                "value": "0x00000403",
                "pretty_value": "CLSCTX_INPROC_SERVER|CLSCTX_INPROC_HANDLER|CLSCTX_NO_CODE_DOWNLOAD"
              },
              {
                "name": "riid",
                "value": "00000003-0000-0000-C000-000000000046"
              },
              {
                "name": "ProgID",
                "value": ""
              }
            ],
            "repeated": 0,
            "id": 743
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "4596",
            "caller": "0x7ffee2fc0e98",
            "parentcaller": "0x7ffee303b785",
            "category": "windows",
            "api": "PostMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "WindowHandle",
                "value": "0x00080298"
              },
              {
                "name": "Message",
                "value": "0x00000400"
              }
            ],
            "repeated": 0,
            "id": 744
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 745
          },
          {
            "timestamp": "2026-02-10 09:23:39,479",
            "thread_id": "5916",
            "caller": "0x7ff6f817116a",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001dc"
              },
              {
                "name": "Milliseconds",
                "value": "5000"
              }
            ],
            "repeated": 0,
            "id": 746
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "windows",
            "api": "PostThreadMessageW",
            "status": true,
            "return": "0x00000001",
            "arguments": [
              {
                "name": "ProcessId",
                "value": "5480"
              },
              {
                "name": "ThreadId",
                "value": "4608"
              },
              {
                "name": "Message",
                "value": "1033"
              }
            ],
            "repeated": 0,
            "id": 747
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtWaitForSingleObject",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              },
              {
                "name": "Milliseconds",
                "value": "18446744073709551615"
              },
              {
                "name": "Status",
                "value": "Infinite"
              }
            ],
            "repeated": 0,
            "id": 748
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34c0444",
            "parentcaller": "0x7ffecda4c60f",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b8"
              }
            ],
            "repeated": 0,
            "id": 749
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffecda39248",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 750
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffecda3774b",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 751
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffecda3774b",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "unload"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\thumbcache"
              },
              {
                "name": "DllBase",
                "value": "0x7ffecda20000"
              }
            ],
            "repeated": 0,
            "id": 752
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34c0444",
            "parentcaller": "0x7ffee18b4def",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002b4"
              }
            ],
            "repeated": 0,
            "id": 753
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee189c408",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              }
            ],
            "repeated": 0,
            "id": 754
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee189c3cb",
            "category": "system",
            "api": "LdrGetProcedureAddressForCaller",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ModuleName",
                "value": "ntdll.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee3470000"
              },
              {
                "name": "FunctionName",
                "value": "RtlDllShutdownInProgress"
              },
              {
                "name": "Ordinal",
                "value": "0"
              },
              {
                "name": "FunctionAddress",
                "value": "0x7ffee34d3410"
              }
            ],
            "repeated": 0,
            "id": 755
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10cac31",
            "parentcaller": "0x7ffee189c3cb",
            "category": "system",
            "api": "DllLoadNotification",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "NotificationReason",
                "value": "unload"
              },
              {
                "name": "DllName",
                "value": "C:\\Windows\\System32\\shcore"
              },
              {
                "name": "DllBase",
                "value": "0x7ffee1880000"
              }
            ],
            "repeated": 0,
            "id": 756
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34e0db0",
            "parentcaller": "0x7ffee34a0391",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee1880000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 757
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34e0db0",
            "parentcaller": "0x7ffee34a0391",
            "category": "process",
            "api": "NtUnmapViewOfSection",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffecda20000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              }
            ],
            "repeated": 0,
            "id": 758
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10be76a",
            "parentcaller": "0x7ffee2f6ea0e",
            "category": "system",
            "api": "LdrGetDllHandle",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "FileName",
                "value": "oleaut32.dll"
              },
              {
                "name": "ModuleHandle",
                "value": "0x7ffee2a80000"
              }
            ],
            "repeated": 0,
            "id": 759
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34b7830",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 760
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34b7881",
            "parentcaller": "0x7ffee34a20f9",
            "category": "process",
            "api": "NtProtectVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x7ffee3271000"
              },
              {
                "name": "ModuleName",
                "value": "combase.dll"
              },
              {
                "name": "NumberOfBytesProtected",
                "value": "0x00001000"
              },
              {
                "name": "MemoryType",
                "value": "0x00000000"
              },
              {
                "name": "NewAccessProtection",
                "value": "0x00000002",
                "pretty_value": "PAGE_READONLY"
              },
              {
                "name": "OldAccessProtection",
                "value": "0x00000004",
                "pretty_value": "PAGE_READWRITE"
              },
              {
                "name": "StackPivoted",
                "value": "no"
              }
            ],
            "repeated": 0,
            "id": 761
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000238"
              }
            ],
            "repeated": 0,
            "id": 762
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001cc"
              }
            ],
            "repeated": 0,
            "id": 763
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001e4"
              }
            ],
            "repeated": 0,
            "id": 764
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f8"
              }
            ],
            "repeated": 0,
            "id": 765
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x0000022c"
              }
            ],
            "repeated": 0,
            "id": 766
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000234"
              }
            ],
            "repeated": 0,
            "id": 767
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2fe2ec5",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000002a8"
              }
            ],
            "repeated": 0,
            "id": 768
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee2f6cd6e",
            "parentcaller": "0x7ffee2fe2ed4",
            "category": "system",
            "api": "IsDebuggerPresent",
            "status": false,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 769
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee2fe4324",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000240"
              }
            ],
            "repeated": 0,
            "id": 770
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee34c467e",
            "parentcaller": "0x7ffee110f79a",
            "category": "threading",
            "api": "NtQueryInformationThread",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ThreadHandle",
                "value": "0xfffffffe"
              },
              {
                "name": "ThreadInformationClass",
                "value": "12"
              },
              {
                "name": "ThreadInformation",
                "value": "\\x00\\x00\\x00\\x00"
              },
              {
                "name": "ThreadId",
                "value": "4608"
              }
            ],
            "repeated": 0,
            "id": 771
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4596",
            "caller": "0x7ffee338bf07",
            "parentcaller": "0x7ffee338be66",
            "category": "system",
            "api": "GetSystemTimeAsFileTime",
            "status": true,
            "return": "0x00000000",
            "arguments": [],
            "repeated": 0,
            "id": 772
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000210"
              }
            ],
            "repeated": 0,
            "id": 773
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e980ff000"
              },
              {
                "name": "RegionSize",
                "value": "0x00005000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 774
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e9810d000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 775
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtFreeVirtualMemory",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e98129000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "FreeType",
                "value": "0x00004000"
              }
            ],
            "repeated": 0,
            "id": 776
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee1da15b8",
            "parentcaller": "0x7ffee3489a1d",
            "category": "misc",
            "api": "GetKeyboardLayout",
            "status": true,
            "return": "0x04090409",
            "arguments": [
              {
                "name": "KeyboardLayout",
                "value": "0x00000409"
              },
              {
                "name": "LanguageName",
                "value": "English (United States)"
              }
            ],
            "repeated": 0,
            "id": 777
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtUnmapViewOfSectionEx",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "BaseAddress",
                "value": "0x20e99b10000"
              },
              {
                "name": "RegionSize",
                "value": "0x00001000"
              },
              {
                "name": "Flags",
                "value": "0"
              }
            ],
            "repeated": 0,
            "id": 778
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x000001f4"
              }
            ],
            "repeated": 0,
            "id": 779
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171176",
            "parentcaller": "0x7ff6f8171466",
            "category": "registry",
            "api": "RegCloseKey",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000202"
              }
            ],
            "repeated": 0,
            "id": 780
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e41e",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000278"
              }
            ],
            "repeated": 0,
            "id": 781
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "4608",
            "caller": "0x7ffee10c6785",
            "parentcaller": "0x7ffee339e4e4",
            "category": "system",
            "api": "NtClose",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "Handle",
                "value": "0x00000274"
              }
            ],
            "repeated": 0,
            "id": 782
          },
          {
            "timestamp": "2026-02-10 09:23:44,495",
            "thread_id": "5916",
            "caller": "0x7ff6f8171193",
            "parentcaller": "0x7ff6f8171466",
            "category": "process",
            "api": "NtTerminateProcess",
            "status": true,
            "return": "0x00000000",
            "arguments": [
              {
                "name": "ProcessHandle",
                "value": "0xffffffff"
              },
              {
                "name": "ExitCode",
                "value": "0x00000000"
              }
            ],
            "repeated": 0,
            "id": 783
          }
        ],
        "threads": [
          "5916",
          "4884",
          "4160",
          "748",
          "5560",
          "4592",
          "4596",
          "4608",
          "4564"
        ],
        "environ": {
          "UserName": "Admin",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff6f8170000",
          "MainExeSize": "0x00009000",
          "Bitness": "64-bit"
        },
        "file_activities": {
          "read_files": [],
          "write_files": [],
          "delete_files": []
        }
      }
    ],
    "anomaly": [],
    "processtree": [
      {
        "name": "msiexec.exe",
        "pid": 4880,
        "parent_id": 956,
        "module_path": "C:\\Windows\\SysWOW64\\msiexec.exe",
        "children": [],
        "threads": [
          "4884",
          "5084",
          "1652",
          "4536",
          "4540",
          "4544",
          "5560"
        ],
        "environ": {
          "UserName": "Admin",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "\"C:\\Windows\\system32\\msiexec.exe\" /I \"C:\\Temp\\E87.20_CheckPointVPN.msi\" /qb ACCEPTEULA=1 LicenseAccepted=1",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x003b0000",
          "MainExeSize": "0x00012000",
          "Bitness": "32-bit"
        }
      },
      {
        "name": "svchost.exe",
        "pid": 740,
        "parent_id": 600,
        "module_path": "C:\\Windows\\System32\\svchost.exe",
        "children": [
          {
            "name": "drvinst.exe",
            "pid": 2964,
            "parent_id": 740,
            "module_path": "C:\\Windows\\System32\\drvinst.exe",
            "children": [],
            "threads": [
              "348",
              "4268",
              "4692",
              "1816",
              "2940"
            ],
            "environ": {
              "UserName": "￑￈￑ￒￅￌ￀",
              "ComputerName": "HOME-PC",
              "WindowsPath": "C:\\Windows",
              "TempPath": "C:\\Temp\\",
              "CommandLine": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\"",
              "RegisteredOwner": "",
              "RegisteredOrganization": "",
              "ProductName": "",
              "SystemVolumeSerialNumber": "a0c0-2cc3",
              "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
              "MachineGUID": "",
              "MainExeBase": "0x7ff70a390000",
              "MainExeSize": "0x00057000",
              "Bitness": "64-bit"
            }
          },
          {
            "name": "drvinst.exe",
            "pid": 4644,
            "parent_id": 740,
            "module_path": "C:\\Windows\\System32\\drvinst.exe",
            "children": [],
            "threads": [
              "4632",
              "2776",
              "3980",
              "1824",
              "5232",
              "5236"
            ],
            "environ": {
              "UserName": "￑￈￑ￒￅￌ￀",
              "ComputerName": "HOME-PC",
              "WindowsPath": "C:\\Windows",
              "TempPath": "C:\\Temp\\",
              "CommandLine": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\"",
              "RegisteredOwner": "",
              "RegisteredOrganization": "",
              "ProductName": "",
              "SystemVolumeSerialNumber": "a0c0-2cc3",
              "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
              "MachineGUID": "",
              "MainExeBase": "0x7ff70a390000",
              "MainExeSize": "0x00057000",
              "Bitness": "64-bit"
            }
          },
          {
            "name": "dllhost.exe",
            "pid": 5580,
            "parent_id": 740,
            "module_path": "C:\\Windows\\System32\\dllhost.exe",
            "children": [],
            "threads": [
              "5584",
              "5708",
              "5712",
              "5704",
              "5700",
              "5880",
              "5884",
              "5888",
              "5908"
            ],
            "environ": {
              "UserName": "Admin",
              "ComputerName": "HOME-PC",
              "WindowsPath": "C:\\Windows",
              "TempPath": "C:\\Temp\\",
              "CommandLine": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
              "RegisteredOwner": "",
              "RegisteredOrganization": "",
              "ProductName": "",
              "SystemVolumeSerialNumber": "a0c0-2cc3",
              "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
              "MachineGUID": "",
              "MainExeBase": "0x7ff6f8170000",
              "MainExeSize": "0x00009000",
              "Bitness": "64-bit"
            }
          },
          {
            "name": "drvinst.exe",
            "pid": 1620,
            "parent_id": 740,
            "module_path": "C:\\Windows\\System32\\drvinst.exe",
            "children": [],
            "threads": [
              "3424",
              "5500",
              "5508",
              "6080",
              "6072"
            ],
            "environ": {
              "UserName": "￑￈￑ￒￅￌ￀",
              "ComputerName": "HOME-PC",
              "WindowsPath": "C:\\Windows",
              "TempPath": "C:\\Temp\\",
              "CommandLine": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\"",
              "RegisteredOwner": "",
              "RegisteredOrganization": "",
              "ProductName": "",
              "SystemVolumeSerialNumber": "a0c0-2cc3",
              "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
              "MachineGUID": "",
              "MainExeBase": "0x7ff70a390000",
              "MainExeSize": "0x00057000",
              "Bitness": "64-bit"
            }
          },
          {
            "name": "dllhost.exe",
            "pid": 5480,
            "parent_id": 740,
            "module_path": "C:\\Windows\\System32\\dllhost.exe",
            "children": [],
            "threads": [
              "5916",
              "4884",
              "4160",
              "748",
              "5560",
              "4592",
              "4596",
              "4608",
              "4564"
            ],
            "environ": {
              "UserName": "Admin",
              "ComputerName": "HOME-PC",
              "WindowsPath": "C:\\Windows",
              "TempPath": "C:\\Temp\\",
              "CommandLine": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
              "RegisteredOwner": "",
              "RegisteredOrganization": "",
              "ProductName": "",
              "SystemVolumeSerialNumber": "a0c0-2cc3",
              "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
              "MachineGUID": "",
              "MainExeBase": "0x7ff6f8170000",
              "MainExeSize": "0x00009000",
              "Bitness": "64-bit"
            }
          }
        ],
        "threads": [
          "912",
          "3968",
          "2872",
          "744",
          "4976",
          "3704",
          "324",
          "2392",
          "5188",
          "3984",
          "5252",
          "632"
        ],
        "environ": {
          "UserName": "￑￈￑ￒￅￌ￀",
          "ComputerName": "HOME-PC",
          "WindowsPath": "C:\\Windows",
          "TempPath": "C:\\Temp\\",
          "CommandLine": "C:\\Windows\\system32\\svchost.exe -k DcomLaunch -p",
          "RegisteredOwner": "",
          "RegisteredOrganization": "",
          "ProductName": "",
          "SystemVolumeSerialNumber": "a0c0-2cc3",
          "SystemVolumeGUID": "2d3f192c-0000-0000-0000-300300000000",
          "MachineGUID": "",
          "MainExeBase": "0x7ff630560000",
          "MainExeSize": "0x00010000",
          "Bitness": "64-bit"
        }
      }
    ],
    "summary": {
      "files": [
        "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db",
        "C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\comctl32.dll",
        "C:\\Windows\\WindowsShell.Manifest",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Windows\\SysWOW64\\msi.dll",
        "C:\\Windows\\System32\\msi.dll",
        "\\??\\PIPE\\wkssvc",
        "\\??\\PhysicalDrive0",
        "\\Device\\DeviceApi\\CMNotify",
        "C:\\Windows\\System32\\devrtl.dll",
        "C:\\Windows\\INF\\setupapi.dev.log",
        "C:\\Windows\\System32\\",
        "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-21-3318940731-3379818400-2144845357-1002.pckgdep",
        "C:\\ProgramData\\Microsoft\\Windows\\AppRepository\\Packages\\Microsoft.Windows.Search_1.14.10.19041_neutral_neutral_cw5n1h2txyewy\\S-1-5-18.pckgdep",
        "\\Device\\DeviceApi\\CMApi",
        "C:\\Windows\\System32\\drvstore.dll",
        "C:\\Windows\\INF\\",
        "C:\\Windows\\System32\\DriverStore",
        "C:\\Windows",
        "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}",
        "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\",
        "C:\\Windows\\System32\\vnaap.cat",
        "C:\\program files (x86)\\checkpoint\\endpoint connect\\",
        "C:\\program files (x86)",
        "C:\\program files (x86)\\checkpoint",
        "C:\\program files (x86)\\checkpoint\\endpoint connect",
        "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp",
        "C:\\Windows\\System32\\vnaap.inf",
        "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp",
        "C:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.sys",
        "C:\\Windows\\System32\\vnaap.sys",
        "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp",
        "C:\\Windows\\System32\\cryptsp.dll",
        "C:\\Windows\\System32\\ci.dll",
        "C:\\Windows\\System32\\dnsapi.dll",
        "C:\\Windows\\System32\\wuaueng.dll",
        "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
        "C:\\Windows\\System32\\NgcRecovery.dll",
        "C:\\Windows\\System32\\ru-RU\\CRYPT32.dll.mui",
        "C:\\Windows\\System32\\gpapi.dll",
        "C:\\Windows\\System32\\CatRoot\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\",
        "C:\\Windows\\System32\\catroot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\",
        "C:\\Windows\\apppatch\\drvmain.sdb",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf\\*.*",
        "C:\\Windows\\System32\\DriverStore\\FileRepository",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\*",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\drvstore.tmp",
        "C:\\Windows\\INF\\oem1.inf",
        "C:\\Windows\\System32\\CatRoot",
        "C:\\Windows\\System32\\catroot2",
        "C:\\Windows\\System32\\catroot2\\dberr.txt",
        "C:\\Windows\\System32\\devobj.dll",
        "C:\\Windows\\System32\\drivers\\vnaap.sys",
        "C:\\Windows\\System32\\drivers\\",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\",
        "\\Device\\DeviceApi\\Dev\\Query",
        "C:\\Windows\\System32\\kernel.appcore.dll",
        "\\Device\\CNG",
        "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}",
        "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\",
        "C:\\Windows\\System32\\Vsdatant.cat",
        "C:\\Windows\\SysWOW64\\Zonelabs\\",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp",
        "C:\\Windows\\System32\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp",
        "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys",
        "C:\\Windows\\System32\\vsdatant.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf\\*.*",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\*",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys",
        "C:\\Windows\\INF\\oem2.inf"
      ],
      "read_files": [],
      "write_files": [
        "\\??\\PIPE\\wkssvc",
        "C:\\Windows\\INF\\setupapi.dev.log",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\drvstore.tmp",
        "C:\\Windows\\INF\\oem1.inf",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf",
        "C:\\Windows\\System32\\catroot2\\dberr.txt",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys",
        "C:\\Windows\\INF\\oem2.inf",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf"
      ],
      "delete_files": [
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys",
        "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
      ],
      "keys": [
        "HKEY_LOCAL_MACHINE",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Device Installer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\Sorting\\Ids",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CustomLocale",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\ExtendedLocale",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\System",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MUI\\StringCacheSettings",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_CURRENT_USER",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Cryptography\\ECCParameters",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\LanguageOverlay\\OverlayPackages\\ru-RU",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Wintrust\\Config",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{000C10F1-0000-0000-C000-000000000046}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{06C9E010-38CE-11D4-A2A3-00104BD35090}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{1A610570-38CE-11D4-A2A3-00104BD35090}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllPutSignedDataMsg\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllPutSignedDataMsg",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\AuthRoot",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\ChainEngine\\Config",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CI\\Config",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\#16",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllOpenStoreProv\\Ldap",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllOpenStoreProv",
        "HKEY_USERS\\S-1-5-18",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs",
        "HKEY_USERS\\.DEFAULT\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPublisher\\Safer",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust\\PhysicalStores",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Diagnostics",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
        "HKEY_LOCAL_MACHINE\\System\\Setup",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates",
        "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{000C10F1-0000-0000-C000-000000000046}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{06C9E010-38CE-11D4-A2A3-00104BD35090}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0AC5DF4B-CE07-4DE2-B76E-23C839A09FD1}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{0F5F58B3-AADE-4B9A-A434-95742D92ECEB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1629F04E-2799-4DB5-8FE5-ACE10F17EBAB}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{1A610570-38CE-11D4-A2A3-00104BD35090}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{5598CFF1-68DB-4340-B57F-1CACF88C9A51}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{603BCC1F-4B59-4E08-B724-D2C6297EF351}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{CF78C6DE-64A2-4799-B506-89ADFF5D16D6}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{D1D04F0C-9ABA-430D-B0E4-D7E96ACCE66C}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllCreateIndirectData\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllCreateIndirectData",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObjectEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.1.1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.11",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.12",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObjectEx\\1.2.840.113549.1.9.16.2.4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllEncodeObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2000",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2001",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2002",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2003",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2004",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2005",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2006",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2007",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2008",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2009",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2010",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2011",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2012",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2130",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2221",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2222",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\#2223",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.12.2.3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.1.1",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.16.4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.10",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.11",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.12",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.15",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.20",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.25",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.26",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.27",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.28",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.30",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.1.4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllEncodeObject\\1.3.6.1.4.1.311.2.4.4",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\Security",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\DiagnosticPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9BA61D3F-E73A-11D0-8CD2-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{9F3053C5-439D-4BF7-8A77-04F0450A1D9F}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AAB9-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{C689AABA-8E78-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A42-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetCaps\\{DE351A43-8E59-11D0-8C47-00C04FC295EE}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptSIPDllGetCaps",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\LocaleName",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sList",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sDecimal",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sThousand",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sGrouping",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNativeDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonDecimalSep",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonThousandSep",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonGrouping",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sPositiveSign",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNegativeSign",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sTimeFormat",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortTime",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s1159",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s2359",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortDate",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sYearMonth",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sLongDate",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCountry",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iMeasure",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iPaperSize",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iLZero",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegNumber",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\NumShape",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrency",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegCurr",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstDayOfWeek",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstWeekOfYear",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\\\xed\\xa0\\xbc\\xed\\xbc\\x8e\\xed\\xa0\\xbc\\xed\\xbc\\x8f\\xed\\xa0\\xbc\\xed\\xbc\\x8d",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllVerifyEncodedSignature",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllVerifyEncodedSignature",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllImportPublicKeyInfoEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllImportPublicKeyInfoEx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllConvertPublicKeyInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CryptDllConvertPublicKeyInfo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllVerifyCertificateChainPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 1\\CertDllVerifyCertificateChainPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MiniNT",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography\\CatalogDB",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\DeviceInstall",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugInstall",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpResources",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\System\\vna_ap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Manufacturer",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Description",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigScope",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Device",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\UpperRange",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services\\vna_ap",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Interfaces",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Filters",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Devices",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\vna.devicedesc.apollo",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\cp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Source",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\cp_apvna",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\IncludedConfigs",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Reboot",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\LowerFilters",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\UpperFilters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\DevQuery",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa\\FipsAlgorithmPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Lsa",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Policies\\Microsoft\\Cryptography\\Configuration",
        "HKEY_CURRENT_USER\\Software\\Classes",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled",
        "HKEY_CURRENT_USER\\Software\\Classes\\AppID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OLE\\AppCompat",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission",
        "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc\\Extensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\TreatAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler32",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalServer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\Elevation",
        "HKEY_CURRENT_USER\\Software\\Classes\\Interface\\{75121952-E0D0-43E5-9380-1D80483ACF72}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\TreatAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler32",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InprocHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID",
        "HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\LocalServer",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\Elevation",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Class\\{4d36e974-e325-11ce-bfc1-08002be10318}\\Schema"
      ],
      "read_keys": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
        "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
        "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\LocaleName",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sList",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sDecimal",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sThousand",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sGrouping",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNativeDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonDecimalSep",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonThousandSep",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sMonGrouping",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sPositiveSign",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sNegativeSign",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sTimeFormat",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortTime",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s1159",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\s2359",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sShortDate",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sYearMonth",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sLongDate",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCountry",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iMeasure",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iPaperSize",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iLZero",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegNumber",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\NumShape",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrDigits",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCurrency",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iNegCurr",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstDayOfWeek",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iFirstWeekOfYear",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency",
        "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugInstall",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\IncludedConfigs",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Reboot",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\LowerFilters",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\UpperFilters",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL",
        "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID"
      ],
      "write_keys": [
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Manufacturer",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Description",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigScope",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Device",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\UpperRange",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Services\\vna_ap",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Interfaces",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Filters",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Devices",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\vna.devicedesc.apollo",
        "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\cp",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Source"
      ],
      "delete_keys": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Security"
      ],
      "executed_commands": [
        "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\"",
        "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\"",
        "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}",
        "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\"",
        "\"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca"
      ],
      "resolved_apis": [
        "ntdll.dll.NtOpenKeyEx"
      ],
      "mutexes": [
        "Global\\_MSIExecute",
        "Global\\DriverStore_Mutex_vnaap.inf_amd64_ea39d26158cde1be",
        "Local\\SM0:2964:304:WilStaging_02",
        "DrvInst.exe_mutex_{5B10AC83-4F13-4fde-8C0B-B85681BA8D73}",
        "Local\\SM0:4644:304:WilStaging_02",
        "Local\\SM0:5580:304:WilStaging_02",
        "Global\\DriverStore_Mutex_vsdatant.inf_amd64_c01fe17aaf09e5fc",
        "Local\\SM0:1620:304:WilStaging_02",
        "Local\\SM0:5480:304:WilStaging_02"
      ],
      "created_services": [
        "vna_ap"
      ],
      "started_services": [
        "msiserver",
        "WSearch"
      ]
    },
    "enhanced": [
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 1,
        "data": {
          "file": "VERSION.DLL",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 2,
        "data": {
          "file": "LPK",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 3,
        "data": {
          "file": "GDI32",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 4,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 5,
        "data": {
          "file": "Kernel32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,343",
        "eid": 6,
        "data": {
          "file": "api-ms-win-core-delayload-l1-1-1.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,375",
        "eid": 7,
        "data": {
          "file": "VERSION.DLL",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,375",
        "eid": 8,
        "data": {
          "file": "KERNEL32.DLL",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,375",
        "eid": 9,
        "data": {
          "file": "Comctl32.dll",
          "pathtofile": null,
          "moduleaddress": "0x72cc0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,390",
        "eid": 10,
        "data": {
          "file": "srpapi.dll",
          "pathtofile": null,
          "moduleaddress": "0x729f0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,390",
        "eid": 11,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,390",
        "eid": 12,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\TSAPPCMP.DLL",
          "pathtofile": null,
          "moduleaddress": "0x00000000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,390",
        "eid": 13,
        "data": {
          "file": "Ntdll.dll",
          "pathtofile": null,
          "moduleaddress": "0x76f50000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,406",
        "eid": 14,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,406",
        "eid": 15,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\shlwapi.dll",
          "pathtofile": null,
          "moduleaddress": "0x76e50000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,406",
        "eid": 16,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,406",
        "eid": 17,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\ole32.dll",
          "pathtofile": null,
          "moduleaddress": "0x75180000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 18,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 19,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 20,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 21,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\advapi32.dll",
          "pathtofile": null,
          "moduleaddress": "0x75b10000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 22,
        "data": {
          "file": "COMCTL32",
          "pathtofile": null,
          "moduleaddress": "0x72cc0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,422",
        "eid": 23,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x739f0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,437",
        "eid": 24,
        "data": {
          "file": "comctl32.dll",
          "pathtofile": null,
          "moduleaddress": "0x72cc0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,468",
        "eid": 25,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,468",
        "eid": 26,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\shell32.dll",
          "pathtofile": null,
          "moduleaddress": "0x75f60000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,468",
        "eid": 27,
        "data": {
          "file": "shell32.dll",
          "pathtofile": null,
          "moduleaddress": "0x75f60000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,515",
        "eid": 28,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x76520000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:21:59,515",
        "eid": 29,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\netapi32.dll",
          "pathtofile": null,
          "moduleaddress": "0x72440000"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:21:59,515",
        "eid": 30,
        "data": {
          "file": "\\Device\\NamedPipe\\wkssvc"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:21:59,531",
        "eid": 31,
        "data": {
          "file": "\\Device\\NamedPipe\\wkssvc"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:03,843",
        "eid": 32,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\msi.dll",
          "pathtofile": null,
          "moduleaddress": "0x72a20000"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:03,859",
        "eid": 33,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:03,968",
        "eid": 34,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,437",
        "eid": 35,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,437",
        "eid": 36,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,453",
        "eid": 37,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,453",
        "eid": 38,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,453",
        "eid": 39,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,453",
        "eid": 40,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,453",
        "eid": 41,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 42,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 43,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 44,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 45,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 46,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,468",
        "eid": 47,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,484",
        "eid": 48,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,484",
        "eid": 49,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,484",
        "eid": 50,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,640",
        "eid": 51,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,640",
        "eid": 52,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,687",
        "eid": 53,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,703",
        "eid": 54,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,703",
        "eid": 55,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,703",
        "eid": 56,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,703",
        "eid": 57,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,703",
        "eid": 58,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,718",
        "eid": 59,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,718",
        "eid": 60,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,718",
        "eid": 61,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,718",
        "eid": 62,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,718",
        "eid": 63,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,734",
        "eid": 64,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,734",
        "eid": 65,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,734",
        "eid": 66,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,734",
        "eid": 67,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,734",
        "eid": 68,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,750",
        "eid": 69,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,750",
        "eid": 70,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,843",
        "eid": 71,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,843",
        "eid": 72,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,843",
        "eid": 73,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,859",
        "eid": 74,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,859",
        "eid": 75,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,859",
        "eid": 76,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,859",
        "eid": 77,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,875",
        "eid": 78,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,875",
        "eid": 79,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,875",
        "eid": 80,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,875",
        "eid": 81,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,875",
        "eid": 82,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 83,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 84,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 85,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 86,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 87,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,890",
        "eid": 88,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,906",
        "eid": 89,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:04,906",
        "eid": 90,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,015",
        "eid": 91,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,015",
        "eid": 92,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,015",
        "eid": 93,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,015",
        "eid": 94,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,031",
        "eid": 95,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,031",
        "eid": 96,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,125",
        "eid": 97,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,125",
        "eid": 98,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,125",
        "eid": 99,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 100,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 101,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 102,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 103,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 104,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,140",
        "eid": 105,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 106,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 107,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 108,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 109,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 110,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,156",
        "eid": 111,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,172",
        "eid": 112,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,172",
        "eid": 113,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,172",
        "eid": 114,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,172",
        "eid": 115,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,172",
        "eid": 116,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 117,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 118,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 119,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 120,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 121,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,187",
        "eid": 122,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,203",
        "eid": 123,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,203",
        "eid": 124,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,203",
        "eid": 125,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,203",
        "eid": 126,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 127,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 128,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 129,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 130,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 131,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,218",
        "eid": 132,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,234",
        "eid": 133,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,234",
        "eid": 134,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,234",
        "eid": 135,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,234",
        "eid": 136,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,234",
        "eid": 137,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,250",
        "eid": 138,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,250",
        "eid": 139,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,250",
        "eid": 140,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,250",
        "eid": 141,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,250",
        "eid": 142,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,265",
        "eid": 143,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,265",
        "eid": 144,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,265",
        "eid": 145,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,265",
        "eid": 146,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,265",
        "eid": 147,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,281",
        "eid": 148,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,281",
        "eid": 149,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,281",
        "eid": 150,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,281",
        "eid": 151,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,281",
        "eid": 152,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,297",
        "eid": 153,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,297",
        "eid": 154,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,297",
        "eid": 155,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,312",
        "eid": 156,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,312",
        "eid": 157,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,312",
        "eid": 158,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,312",
        "eid": 159,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,312",
        "eid": 160,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,328",
        "eid": 161,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,609",
        "eid": 162,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,609",
        "eid": 163,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,609",
        "eid": 164,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,609",
        "eid": 165,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,640",
        "eid": 166,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,640",
        "eid": 167,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,703",
        "eid": 168,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,703",
        "eid": 169,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,703",
        "eid": 170,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,703",
        "eid": 171,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,703",
        "eid": 172,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,718",
        "eid": 173,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,718",
        "eid": 174,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,718",
        "eid": 175,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 176,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 177,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 178,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 179,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 180,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,781",
        "eid": 181,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 182,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 183,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 184,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 185,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 186,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,797",
        "eid": 187,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,812",
        "eid": 188,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,812",
        "eid": 189,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,812",
        "eid": 190,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,812",
        "eid": 191,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,812",
        "eid": 192,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 193,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 194,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 195,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 196,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 197,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,828",
        "eid": 198,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 199,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 200,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 201,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 202,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 203,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,843",
        "eid": 204,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 205,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 206,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 207,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 208,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 209,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,859",
        "eid": 210,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 211,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 212,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 213,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 214,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 215,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,875",
        "eid": 216,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 217,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 218,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 219,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 220,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 221,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,890",
        "eid": 222,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 223,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 224,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 225,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 226,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 227,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,906",
        "eid": 228,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 229,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 230,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 231,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 232,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 233,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,922",
        "eid": 234,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 235,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 236,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 237,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 238,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 239,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,937",
        "eid": 240,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 241,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 242,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 243,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 244,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 245,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,953",
        "eid": 246,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 247,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 248,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 249,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 250,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 251,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,968",
        "eid": 252,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,984",
        "eid": 253,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,984",
        "eid": 254,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,984",
        "eid": 255,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,984",
        "eid": 256,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:05,984",
        "eid": 257,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 258,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 259,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 260,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 261,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 262,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 263,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,000",
        "eid": 264,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,015",
        "eid": 265,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,015",
        "eid": 266,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,015",
        "eid": 267,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,015",
        "eid": 268,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,015",
        "eid": 269,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 270,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 271,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 272,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 273,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 274,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,031",
        "eid": 275,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 276,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 277,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 278,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 279,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 280,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,047",
        "eid": 281,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 282,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 283,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 284,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 285,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 286,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,062",
        "eid": 287,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 288,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 289,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 290,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 291,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 292,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 293,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,078",
        "eid": 294,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 295,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 296,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 297,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 298,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 299,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,093",
        "eid": 300,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 301,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 302,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 303,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 304,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 305,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,109",
        "eid": 306,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 307,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 308,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 309,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 310,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 311,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 312,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,125",
        "eid": 313,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 314,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 315,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 316,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 317,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 318,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,140",
        "eid": 319,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 320,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 321,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 322,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 323,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 324,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,156",
        "eid": 325,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 326,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 327,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 328,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 329,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 330,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,172",
        "eid": 331,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 332,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 333,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 334,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 335,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 336,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,187",
        "eid": 337,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 338,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 339,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 340,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 341,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 342,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 343,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,203",
        "eid": 344,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 345,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 346,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 347,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 348,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 349,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,218",
        "eid": 350,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 351,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 352,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 353,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 354,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 355,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,234",
        "eid": 356,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 357,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 358,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 359,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 360,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 361,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,250",
        "eid": 362,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,265",
        "eid": 363,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,265",
        "eid": 364,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,265",
        "eid": 365,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,265",
        "eid": 366,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,265",
        "eid": 367,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,281",
        "eid": 368,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,281",
        "eid": 369,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,281",
        "eid": 370,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,281",
        "eid": 371,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,297",
        "eid": 372,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,297",
        "eid": 373,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,297",
        "eid": 374,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,312",
        "eid": 375,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,312",
        "eid": 376,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,312",
        "eid": 377,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,328",
        "eid": 378,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,328",
        "eid": 379,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,343",
        "eid": 380,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,359",
        "eid": 381,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,359",
        "eid": 382,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,375",
        "eid": 383,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,375",
        "eid": 384,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,375",
        "eid": 385,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,390",
        "eid": 386,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,390",
        "eid": 387,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,390",
        "eid": 388,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,406",
        "eid": 389,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,406",
        "eid": 390,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,406",
        "eid": 391,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,422",
        "eid": 392,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,422",
        "eid": 393,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,437",
        "eid": 394,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,437",
        "eid": 395,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,437",
        "eid": 396,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,437",
        "eid": 397,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 398,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 399,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 400,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 401,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 402,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 403,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,453",
        "eid": 404,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,468",
        "eid": 405,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,468",
        "eid": 406,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,484",
        "eid": 407,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,484",
        "eid": 408,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,500",
        "eid": 409,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,500",
        "eid": 410,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,515",
        "eid": 411,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,531",
        "eid": 412,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,531",
        "eid": 413,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,531",
        "eid": 414,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,547",
        "eid": 415,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,547",
        "eid": 416,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,547",
        "eid": 417,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,547",
        "eid": 418,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,562",
        "eid": 419,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,562",
        "eid": 420,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,562",
        "eid": 421,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,562",
        "eid": 422,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,562",
        "eid": 423,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,578",
        "eid": 424,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,578",
        "eid": 425,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,593",
        "eid": 426,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,609",
        "eid": 427,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,609",
        "eid": 428,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,625",
        "eid": 429,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,625",
        "eid": 430,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,640",
        "eid": 431,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,640",
        "eid": 432,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,640",
        "eid": 433,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,656",
        "eid": 434,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,672",
        "eid": 435,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,672",
        "eid": 436,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,672",
        "eid": 437,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,672",
        "eid": 438,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,687",
        "eid": 439,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,687",
        "eid": 440,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,687",
        "eid": 441,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,687",
        "eid": 442,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,687",
        "eid": 443,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,703",
        "eid": 444,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,703",
        "eid": 445,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,703",
        "eid": 446,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,703",
        "eid": 447,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,703",
        "eid": 448,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,718",
        "eid": 449,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,718",
        "eid": 450,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,718",
        "eid": 451,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,734",
        "eid": 452,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,750",
        "eid": 453,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,765",
        "eid": 454,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:06,781",
        "eid": 455,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,468",
        "eid": 456,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,468",
        "eid": 457,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,468",
        "eid": 458,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,578",
        "eid": 459,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,593",
        "eid": 460,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,593",
        "eid": 461,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,593",
        "eid": 462,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,593",
        "eid": 463,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,593",
        "eid": 464,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,703",
        "eid": 465,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,703",
        "eid": 466,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,703",
        "eid": 467,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,703",
        "eid": 468,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 469,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 470,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 471,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 472,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 473,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,765",
        "eid": 474,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 475,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 476,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 477,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 478,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 479,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 480,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,781",
        "eid": 481,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 482,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 483,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 484,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 485,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 486,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,797",
        "eid": 487,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,812",
        "eid": 488,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,875",
        "eid": 489,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,875",
        "eid": 490,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,953",
        "eid": 491,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:07,968",
        "eid": 492,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,375",
        "eid": 493,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,390",
        "eid": 494,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,437",
        "eid": 495,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,453",
        "eid": 496,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,453",
        "eid": 497,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,687",
        "eid": 498,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,687",
        "eid": 499,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,687",
        "eid": 500,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,687",
        "eid": 501,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,781",
        "eid": 502,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,781",
        "eid": 503,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,781",
        "eid": 504,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,781",
        "eid": 505,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,797",
        "eid": 506,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:09,875",
        "eid": 507,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,875",
        "eid": 508,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,875",
        "eid": 509,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,906",
        "eid": 510,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,984",
        "eid": 511,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,984",
        "eid": 512,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,984",
        "eid": 513,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 514,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 515,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 516,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 517,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 518,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 519,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,000",
        "eid": 520,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,015",
        "eid": 521,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,015",
        "eid": 522,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,109",
        "eid": 523,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 524,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 525,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 526,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 527,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 528,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 529,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,125",
        "eid": 530,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,140",
        "eid": 531,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,140",
        "eid": 532,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,218",
        "eid": 533,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,250",
        "eid": 534,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,250",
        "eid": 535,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,250",
        "eid": 536,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,250",
        "eid": 537,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,250",
        "eid": 538,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,265",
        "eid": 539,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,297",
        "eid": 540,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,297",
        "eid": 541,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,312",
        "eid": 542,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,343",
        "eid": 543,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,343",
        "eid": 544,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,343",
        "eid": 545,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,390",
        "eid": 546,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,437",
        "eid": 547,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,437",
        "eid": 548,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,437",
        "eid": 549,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,437",
        "eid": 550,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,453",
        "eid": 551,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,453",
        "eid": 552,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,453",
        "eid": 553,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,453",
        "eid": 554,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,468",
        "eid": 555,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,500",
        "eid": 556,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,500",
        "eid": 557,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,515",
        "eid": 558,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,515",
        "eid": 559,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,515",
        "eid": 560,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,515",
        "eid": 561,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,515",
        "eid": 562,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 563,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 564,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 565,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 566,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 567,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 568,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,593",
        "eid": 569,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 570,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 571,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 572,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 573,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 574,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 575,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 576,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,609",
        "eid": 577,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 578,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 579,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 580,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 581,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 582,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 583,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,625",
        "eid": 584,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,640",
        "eid": 585,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,640",
        "eid": 586,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,640",
        "eid": 587,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,640",
        "eid": 588,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,640",
        "eid": 589,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,359",
        "eid": 590,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,359",
        "eid": 591,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,359",
        "eid": 592,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,359",
        "eid": 593,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,359",
        "eid": 594,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 595,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 596,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 597,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 598,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 599,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 600,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 601,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 602,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,375",
        "eid": 603,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,390",
        "eid": 604,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,406",
        "eid": 605,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,406",
        "eid": 606,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:16,406",
        "eid": 607,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:17,656",
        "eid": 608,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,047",
        "eid": 609,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,047",
        "eid": 610,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,047",
        "eid": 611,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,047",
        "eid": 612,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,140",
        "eid": 613,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,140",
        "eid": 614,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,156",
        "eid": 615,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,187",
        "eid": 616,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,234",
        "eid": 617,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,234",
        "eid": 618,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,234",
        "eid": 619,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,250",
        "eid": 620,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,250",
        "eid": 621,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,250",
        "eid": 622,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,328",
        "eid": 623,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,343",
        "eid": 624,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,593",
        "eid": 625,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,609",
        "eid": 626,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,609",
        "eid": 627,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,609",
        "eid": 628,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,625",
        "eid": 629,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,625",
        "eid": 630,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,750",
        "eid": 631,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:20,750",
        "eid": 632,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 633,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 634,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 635,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 636,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 637,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,265",
        "eid": 638,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 639,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 640,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 641,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 642,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 643,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 644,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 645,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 646,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 647,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,281",
        "eid": 648,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 649,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 650,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 651,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 652,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 653,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 654,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 655,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 656,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,297",
        "eid": 657,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 658,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 659,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 660,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 661,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 662,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 663,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 664,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 665,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,312",
        "eid": 666,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 667,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 668,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 669,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 670,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 671,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 672,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 673,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 674,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 675,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,328",
        "eid": 676,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 677,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 678,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 679,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 680,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 681,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 682,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 683,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 684,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,343",
        "eid": 685,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 686,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 687,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 688,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 689,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 690,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 691,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 692,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 693,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,359",
        "eid": 694,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 695,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 696,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 697,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 698,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 699,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 700,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 701,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 702,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 703,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,375",
        "eid": 704,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 705,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 706,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 707,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 708,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 709,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 710,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 711,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 712,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,390",
        "eid": 713,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 714,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 715,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 716,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 717,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 718,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 719,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,406",
        "eid": 720,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,422",
        "eid": 721,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,422",
        "eid": 722,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,422",
        "eid": 723,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,422",
        "eid": 724,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,422",
        "eid": 725,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,437",
        "eid": 726,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,437",
        "eid": 727,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,437",
        "eid": 728,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,437",
        "eid": 729,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,437",
        "eid": 730,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 731,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 732,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 733,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 734,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 735,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 736,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,453",
        "eid": 737,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 738,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 739,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 740,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 741,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 742,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 743,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 744,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 745,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,468",
        "eid": 746,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 747,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 748,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 749,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 750,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 751,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 752,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 753,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 754,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 755,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,484",
        "eid": 756,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 757,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 758,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 759,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 760,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 761,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 762,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 763,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 764,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 765,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,500",
        "eid": 766,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 767,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 768,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 769,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 770,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 771,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 772,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 773,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 774,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 775,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 776,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 777,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,515",
        "eid": 778,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 779,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 780,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 781,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 782,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 783,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 784,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 785,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 786,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 787,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 788,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,531",
        "eid": 789,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 790,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 791,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 792,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 793,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 794,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 795,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 796,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 797,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 798,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 799,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,547",
        "eid": 800,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 801,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 802,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 803,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 804,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 805,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 806,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 807,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 808,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 809,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 810,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 811,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,562",
        "eid": 812,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 813,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 814,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 815,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 816,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 817,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 818,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 819,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 820,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 821,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,578",
        "eid": 822,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,593",
        "eid": 823,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,593",
        "eid": 824,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:21,609",
        "eid": 825,
        "data": {
          "file": "C:\\Temp\\MSI495d4.LOG"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,625",
        "eid": 826,
        "data": {
          "file": "oleaut32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,625",
        "eid": 827,
        "data": {
          "file": "shell32.dll",
          "pathtofile": null,
          "moduleaddress": "0x75f60000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 828,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 829,
        "data": {
          "file": "kernelbase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 830,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 831,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 832,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 833,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 834,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 835,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 836,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,672",
        "eid": 837,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 838,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 839,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 840,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 841,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 842,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:21,687",
        "eid": 843,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "start",
        "object": "service",
        "timestamp": "2026-02-10 09:22:03,812",
        "eid": 844,
        "data": {
          "service": "msiserver"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,031",
        "eid": 845,
        "data": {
          "file": "C:\\Windows\\System32\\umpnpmgr.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedf740000"
        }
      },
      {
        "event": "execute",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,156",
        "eid": 846,
        "data": {
          "file": "DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\""
        }
      },
      {
        "event": "execute",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,812",
        "eid": 847,
        "data": {
          "file": "DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\""
        }
      },
      {
        "event": "execute",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,093",
        "eid": 848,
        "data": {
          "file": "C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}"
        }
      },
      {
        "event": "execute",
        "object": "file",
        "timestamp": "2026-02-10 09:22:13,812",
        "eid": 849,
        "data": {
          "file": "DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\""
        }
      },
      {
        "event": "start",
        "object": "service",
        "timestamp": "2026-02-10 09:22:14,984",
        "eid": 850,
        "data": {
          "service": "WSearch"
        }
      },
      {
        "event": "start",
        "object": "service",
        "timestamp": "2026-02-10 09:22:16,140",
        "eid": 851,
        "data": {
          "service": "WSearch"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:31,859",
        "eid": 852,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "start",
        "object": "service",
        "timestamp": "2026-02-10 09:22:44,031",
        "eid": 853,
        "data": {
          "service": "WSearch"
        }
      },
      {
        "event": "execute",
        "object": "file",
        "timestamp": "2026-02-10 09:23:12,000",
        "eid": 854,
        "data": {
          "file": "\"C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe\" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca"
        }
      },
      {
        "event": "start",
        "object": "service",
        "timestamp": "2026-02-10 09:23:15,328",
        "eid": 855,
        "data": {
          "service": "WSearch"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:27,406",
        "eid": 856,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,344",
        "eid": 857,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,344",
        "eid": 858,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,344",
        "eid": 859,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,360",
        "eid": 860,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,360",
        "eid": 861,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,360",
        "eid": 862,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,360",
        "eid": 863,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 864,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 865,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 866,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 867,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 868,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,376",
        "eid": 869,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,391",
        "eid": 870,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx",
          "content": "kernel32.dll"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,391",
        "eid": 871,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,391",
        "eid": 872,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,391",
        "eid": 873,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,391",
        "eid": 874,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,438",
        "eid": 875,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,454",
        "eid": 876,
        "data": {
          "file": "api-ms-win-eventing-provider-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:10,469",
        "eid": 877,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,485",
        "eid": 878,
        "data": {
          "file": "cabinet.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffed9750000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,485",
        "eid": 879,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,485",
        "eid": 880,
        "data": {
          "file": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.cat"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 881,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 882,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 883,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 884,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 885,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 886,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,516",
        "eid": 887,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount",
          "content": null
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,532",
        "eid": 888,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,548",
        "eid": 889,
        "data": {
          "file": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.inf"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,563",
        "eid": 890,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,579",
        "eid": 891,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,594",
        "eid": 892,
        "data": {
          "file": "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\vnaap.sys"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,610",
        "eid": 893,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,626",
        "eid": 894,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 895,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 896,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 897,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 898,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
          "content": "Isolated User Mode (IUM)"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 899,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 900,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 901,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
          "content": "Isolated User Mode (IUM)"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 902,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-101"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 903,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 904,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
          "content": "Enclave"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 905,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-101"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 906,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 907,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
          "content": "Enclave"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 908,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 909,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 910,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
          "content": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 911,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,688",
        "eid": 912,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 913,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
          "content": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 914,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
          "content": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 915,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 916,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
          "content": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 917,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
          "content": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 918,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 919,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
          "content": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 920,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 921,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 922,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 923,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 924,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 925,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 926,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 927,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 928,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 929,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 930,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,704",
        "eid": 931,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,719",
        "eid": 932,
        "data": {
          "file": "C:\\Windows\\System32\\bcryptprimitives.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1390000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,719",
        "eid": 933,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 934,
        "data": {
          "file": "WINTRUST.DLL",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 935,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 936,
        "data": {
          "file": "C:\\Windows\\System32\\crypt32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0b90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 937,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 938,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 939,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 940,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 941,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 942,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 943,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 944,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 945,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 946,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 947,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 948,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 949,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 950,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 951,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 952,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 953,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 954,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 955,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 956,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 957,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags",
          "content": "18446744071705722880"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 958,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 959,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
          "content": "\\x00\\xc0)\\xb8C\\x9a\\xc9\\x01"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 960,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 961,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 962,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 963,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 964,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 965,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 966,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 967,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": "\\x00\\x00\\x001\\x5754\\x5241\\x5c45\\x694d\\x7263\\x736f\\x666f\\x5c74\\x7243\\x7079\\x6f74\\x7267\\x7061\\x7968\\x4f5c\\x4449\\x455c\\x636e\\x646f\\x6e69\\x5467\\x7079\\x2065\\x5c30\\x6543\\x7472\\x6c44\\x436c\\x6572\\x7461\\x4365\\x7265\\x6974\\x6966\\x6163\\x6574\\x6843\\x6961\\x456e\\x676e\\x6e69\\x5c65\\x6f43\\x666e\\x6769\\x445c\\x6665\\x7561\\x746c\\x575c\\x6165\\x4d6b\\x3544\\x6854\\x7269\\x5064\\x7261\\x7974\\x6853\\x3261\\x3635\\x6c41\\x6f6c\\x4177\\x4843\\x4e49\\x5c45\\x4f53\\x5446\\x4157\\x4552Q\\x5100\\x5970"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 968,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 969,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 970,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 971,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,751",
        "eid": 972,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 973,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 974,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags",
          "content": "18446744071562330112"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 975,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 976,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 977,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 978,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 979,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 980,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 981,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 982,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 983,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 984,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 985,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 986,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 987,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 988,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 989,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 990,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 991,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 992,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 993,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 994,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 995,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 996,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 997,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 998,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 999,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1000,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1001,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1002,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1003,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1004,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1005,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1006,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1007,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,766",
        "eid": 1008,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1009,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1010,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1011,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1012,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1013,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1014,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1015,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1016,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1017,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1018,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1019,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1020,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1021,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1022,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1023,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1024,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1025,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1026,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1027,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1028,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1029,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1030,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1031,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1032,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1033,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1034,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,782",
        "eid": 1035,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1036,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1037,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1038,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1039,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1040,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1041,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1042,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1043,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1044,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1045,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1046,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1047,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1048,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1049,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1050,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1051,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1052,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1053,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1054,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1055,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1056,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1057,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1058,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,798",
        "eid": 1059,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1060,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1061,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1062,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1063,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1064,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1065,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1066,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1067,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1068,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1069,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1070,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1071,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1072,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1073,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1074,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1075,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1076,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1077,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1078,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1079,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1080,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1081,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1082,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1083,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1084,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1085,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1086,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1087,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1088,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,813",
        "eid": 1089,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1090,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1091,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1092,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1093,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1094,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1095,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1096,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1097,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1098,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1099,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1100,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1101,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1102,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1103,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1104,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1105,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1106,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1107,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1108,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1109,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1110,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1111,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1112,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1113,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1114,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1115,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1116,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1117,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1118,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1119,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1120,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1121,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1122,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1123,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1124,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1125,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1126,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1127,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,829",
        "eid": 1128,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1129,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1130,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1131,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1132,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1133,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1134,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1135,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1136,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1137,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1138,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1139,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1140,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1141,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1142,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1143,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1144,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1145,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1146,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1147,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1148,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1149,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1150,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1151,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1152,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1153,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1154,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1155,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1156,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1157,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1158,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,844",
        "eid": 1159,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1160,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1161,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1162,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1163,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1164,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1165,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1166,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1167,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1168,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1169,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1170,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1171,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1172,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1173,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1174,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1175,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1176,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1177,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1178,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1179,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1180,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1181,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1182,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1183,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1184,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1185,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1186,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1187,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,860",
        "eid": 1188,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1189,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1190,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1191,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1192,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1193,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1194,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1195,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1196,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1197,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1198,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1199,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1200,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1201,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1202,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1203,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1204,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1205,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1206,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1207,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1208,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1209,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1210,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1211,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1212,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1213,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1214,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1215,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1216,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1217,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1218,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1219,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1220,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1221,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1222,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1223,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1224,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1225,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1226,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1227,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1228,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1229,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,876",
        "eid": 1230,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,891",
        "eid": 1231,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,891",
        "eid": 1232,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,891",
        "eid": 1233,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,907",
        "eid": 1234,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,907",
        "eid": 1235,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,907",
        "eid": 1236,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1237,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1238,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1239,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1240,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1241,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1242,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1243,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1244,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1245,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,923",
        "eid": 1246,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1247,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime",
          "content": "\\xb3@\\xd9\\xb0n\\x9a\\xdc\\x01"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1248,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1249,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
          "content": "0\\x82\\x17\\xcc\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x17\\xbd0\\x82\\x17\\xb9\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x000\\x82\\x08(\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x08\\x190\\x82\\x08\\x150\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x07\\xa00\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<\\xac\\xeejW0\\x12\\x04\\x10\\x1e%\\xf2N\\xdf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1250,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1251,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1252,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:10,938",
        "eid": 1253,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:10,985",
        "eid": 1254,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,016",
        "eid": 1255,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,016",
        "eid": 1256,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,016",
        "eid": 1257,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1258,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1259,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1260,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "WintrustCertificateTrust"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1261,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1262,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverFinalPolicy"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1263,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1264,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverInitializePolicy"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1265,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1266,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadMessage"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1267,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1268,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadSignature"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1269,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1270,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubCheckCert"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1271,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1272,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverCleanupPolicy"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1273,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1274,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1275,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
          "content": "146432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1276,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1277,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "WintrustCertificateTrust"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1278,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1279,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubAuthenticode"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1280,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1281,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubInitialize"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1282,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1283,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadMessage"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1284,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1285,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadSignature"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,048",
        "eid": 1286,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1287,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubCheckCert"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1288,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1289,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubCleanup"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1290,
        "data": {
          "file": "crypt32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0b90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1291,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1292,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency",
          "content": "\\x20bd"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1293,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1294,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,063",
        "eid": 1295,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru",
          "content": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,079",
        "eid": 1296,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1297,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1298,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1299,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1300,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1301,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1302,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1303,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1304,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1305,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1306,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1307,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1308,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1309,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1310,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1311,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1312,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1313,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1314,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1315,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1316,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1317,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1318,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1319,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1320,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1321,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,094",
        "eid": 1322,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,126",
        "eid": 1323,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,141",
        "eid": 1324,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee3470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,141",
        "eid": 1325,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,157",
        "eid": 1326,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,157",
        "eid": 1327,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,204",
        "eid": 1328,
        "data": {
          "file": "api-ms-win-security-cryptoapi-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0450000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,204",
        "eid": 1329,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,204",
        "eid": 1330,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,204",
        "eid": 1331,
        "data": {
          "file": "WINTRUST.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,204",
        "eid": 1332,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:11,298",
        "eid": 1333,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,376",
        "eid": 1334,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,376",
        "eid": 1335,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,376",
        "eid": 1336,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,423",
        "eid": 1337,
        "data": {
          "file": "api-ms-win-core-registry-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1090000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,423",
        "eid": 1338,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,485",
        "eid": 1339,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:11,485",
        "eid": 1340,
        "data": {
          "file": "C:\\Windows\\System32\\CatRoot"
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:11,485",
        "eid": 1341,
        "data": {
          "file": "C:\\Windows\\System32\\catroot2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,594",
        "eid": 1342,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging",
          "content": "1"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,594",
        "eid": 1343,
        "data": {
          "file": "C:\\Windows\\System32\\catroot2\\dberr.txt"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,641",
        "eid": 1344,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,657",
        "eid": 1345,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:11,673",
        "eid": 1346,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
        }
      },
      {
        "event": "delete",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:11,673",
        "eid": 1347,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,673",
        "eid": 1348,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,735",
        "eid": 1349,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,735",
        "eid": 1350,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,735",
        "eid": 1351,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,735",
        "eid": 1352,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,735",
        "eid": 1353,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1354,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugInstall",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1355,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx",
          "content": "kernel32.dll"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1356,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1357,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1358,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,979",
        "eid": 1359,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1360,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1361,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1362,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1363,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1364,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:11,995",
        "eid": 1365,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1366,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1367,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1368,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1369,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1370,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,042",
        "eid": 1371,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,088",
        "eid": 1372,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,088",
        "eid": 1373,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,088",
        "eid": 1374,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,182",
        "eid": 1375,
        "data": {
          "file": "api-ms-win-service-management-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee32a0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,182",
        "eid": 1376,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1377,
        "data": {
          "file": "api-ms-win-service-management-l2-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee32a0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1378,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1379,
        "data": {
          "file": "api-ms-win-core-registry-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1090000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1380,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1381,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1382,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\vna_ap\\Owners",
          "content": "\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1383,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1384,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
          "content": "%SystemRoot%\\System32\\drivers\\vnaap.sys"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1385,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,198",
        "eid": 1386,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
          "content": "7"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,213",
        "eid": 1387,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,213",
        "eid": 1388,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Owners",
          "content": "\\x00"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,229",
        "eid": 1389,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration",
          "content": "VNA_Apollo.ndi"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,229",
        "eid": 1390,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Manufacturer",
          "content": "%cp%"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,229",
        "eid": 1391,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Description",
          "content": "%vna.devicedesc.apollo%"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,229",
        "eid": 1392,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
          "content": "vna_ap"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1393,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigScope",
          "content": "5"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1394,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1395,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\BusNumber",
          "content": "0"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1396,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\UpperRange",
          "content": "ndis5"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1397,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1398,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Interfaces\\LowerRange",
          "content": "ethernet"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1399,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1400,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\OwnerProduct",
          "content": "Apollo"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1401,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1402,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Ndi\\Service",
          "content": "vna_ap"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1403,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1404,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*IfType",
          "content": "6"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1405,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1406,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*MediaType",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1407,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1408,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\*PhysicalMediaType",
          "content": "14"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1409,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1410,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Driver\\Characteristics",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1411,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1412,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\EventMessageFile",
          "content": "%SystemRoot%\\System32\\drivers\\vnaap.sys"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1413,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1414,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\EventLog\\System\\vna_ap\\TypesSupported",
          "content": "7"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,245",
        "eid": 1415,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags",
          "content": "0"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,354",
        "eid": 1416,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\vna.devicedesc.apollo",
          "content": "Check Point Virtual Network Adapter For Endpoint VPN Client"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,354",
        "eid": 1417,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Strings\\cp",
          "content": "Check Point"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,401",
        "eid": 1418,
        "data": {
          "file": "cabinet.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffed9750000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,401",
        "eid": 1419,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:12,401",
        "eid": 1420,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,417",
        "eid": 1421,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,417",
        "eid": 1422,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,417",
        "eid": 1423,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1424,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1425,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Class",
          "content": "4"
        }
      },
      {
        "event": "delete",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1426,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Security"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1427,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\PnpLockdownFiles\\%SystemRoot%/System32/drivers/vnaap.sys\\Source",
          "content": "%SystemRoot%\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1428,
        "data": {
          "file": "api-ms-win-security-sddl-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee32a0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1429,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1430,
        "data": {
          "file": "api-ms-win-security-base-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1090000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,432",
        "eid": 1431,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,479",
        "eid": 1432,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Descriptors\\CP_APVNA\\Configuration",
          "content": "VNA_Apollo.ndi"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,479",
        "eid": 1433,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\IncludedConfigs",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,479",
        "eid": 1434,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Reboot",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,510",
        "eid": 1435,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\ConfigFlags",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,510",
        "eid": 1436,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,510",
        "eid": 1437,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\Service",
          "content": "vna_ap"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,510",
        "eid": 1438,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\LowerFilters",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,510",
        "eid": 1439,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\DRIVERS\\DriverDatabase\\DriverPackages\\vnaap.inf_amd64_ea39d26158cde1be\\Configurations\\VNA_Apollo.ndi\\UpperFilters",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,542",
        "eid": 1440,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency",
          "content": "\\x20bd"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,542",
        "eid": 1441,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,542",
        "eid": 1442,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,542",
        "eid": 1443,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru",
          "content": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1444,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1445,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1446,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1447,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1448,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1449,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1450,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1451,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\1\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1452,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1453,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1454,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1455,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\Transport",
          "content": "LRPC"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1456,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1457,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\10\\UUID",
          "content": "289e5e0f-414a-4de9-8d17-244507fffc07"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1458,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1459,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1460,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1461,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1462,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1463,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1464,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1465,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\11\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1466,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1467,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\IdType",
          "content": "Uuid"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1468,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1469,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,667",
        "eid": 1470,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1471,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1472,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1473,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\2\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1474,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1475,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1476,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1477,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1478,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1479,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1480,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1481,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\3\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1482,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1483,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\IdType",
          "content": "Uuid"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1484,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1485,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1486,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1487,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1488,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1489,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\4\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1490,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1491,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1492,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1493,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\Transport",
          "content": "LRPC"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1494,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1495,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\5\\UUID",
          "content": "289e5e0f-414a-4de9-8d17-244507fffc07"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1496,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1497,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\IdType",
          "content": "Uuid"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1498,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1499,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\Transport",
          "content": "LRPC"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1500,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1501,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\6\\UUID",
          "content": "289e5e0f-414a-4de9-8d17-244507fffc07"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1502,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1503,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\IdType",
          "content": "Uuid"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1504,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1505,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\Transport",
          "content": "IOCTL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1506,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1507,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\QueryFile",
          "content": "\\Device\\DeviceApi\\Dev\\Query"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1508,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1509,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\7\\NoStateFile",
          "content": "\\Device\\DeviceApi\\Dev\\NoState"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,682",
        "eid": 1510,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1511,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\IdType",
          "content": "String"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1512,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1513,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\Transport",
          "content": "InProc"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1514,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1515,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DllName",
          "content": "C:\\Windows\\System32\\DevDispItemProvider.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1516,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1517,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\8\\DevQueryEntry",
          "content": "DevQueryEntry"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1518,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1519,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\IdType",
          "content": "Uuid"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1520,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1521,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\Transport",
          "content": "InProc"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1522,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1523,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DllName",
          "content": "C:\\Windows\\System32\\DevDispItemProvider.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1524,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,698",
        "eid": 1525,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\DevQuery\\9\\DevQueryEntry",
          "content": "DevQueryEntry"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1526,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1527,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1528,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1529,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1530,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:12,838",
        "eid": 1531,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,246",
        "eid": 1532,
        "data": {
          "file": "C:\\Windows\\system32\\rpcss.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,246",
        "eid": 1533,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,246",
        "eid": 1534,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,246",
        "eid": 1535,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,246",
        "eid": 1536,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1537,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1538,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1539,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1540,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1541,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1542,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1543,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": ""
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1544,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1545,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1546,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1547,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1548,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1549,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1550,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1551,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1552,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1553,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1554,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1555,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1556,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1557,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1558,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1559,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1560,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1561,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1562,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,261",
        "eid": 1563,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1564,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1565,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1566,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1567,
        "data": {
          "file": "C:\\Windows\\system32\\rpcss.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1568,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)",
          "content": "{00000320-0000-0000-C000-000000000046}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1569,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL",
          "content": "combase.dll"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1570,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,277",
        "eid": 1571,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,293",
        "eid": 1572,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,293",
        "eid": 1573,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffede5b0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,293",
        "eid": 1574,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,293",
        "eid": 1575,
        "data": {
          "regkey": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1576,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1577,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1578,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Class Factory for Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1579,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1580,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1581,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": "C:\\Windows\\System32\\thumbcache.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1582,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
          "content": "Apartment"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1583,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1584,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1585,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1586,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,308",
        "eid": 1587,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Class Factory for Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1588,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1589,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1590,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": "C:\\Windows\\System32\\thumbcache.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1591,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
          "content": "Apartment"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1592,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID",
          "content": "{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1593,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1594,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1595,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1596,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1597,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": ""
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1598,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1599,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1600,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1601,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1602,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1603,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1604,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1605,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1606,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1607,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1608,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1609,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1610,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1611,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,324",
        "eid": 1612,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1613,
        "data": {
          "file": "C:\\Windows\\System32\\thumbcache.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffecda20000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1614,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1615,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1616,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)",
          "content": "{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1617,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1618,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1619,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": "PSFactoryBuffer"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1620,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1621,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1622,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": "%SystemRoot%\\system32\\propsys.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1623,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
          "content": "Both"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1624,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1625,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1626,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": "PSFactoryBuffer"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1627,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1628,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1629,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": "%SystemRoot%\\system32\\propsys.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1630,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
          "content": "Both"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,339",
        "eid": 1631,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,355",
        "eid": 1632,
        "data": {
          "file": "C:\\Windows\\System32\\propsys.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedc720000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:13,355",
        "eid": 1633,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:18,418",
        "eid": 1634,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:18,418",
        "eid": 1635,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:18,418",
        "eid": 1636,
        "data": {
          "file": "oleaut32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:18,418",
        "eid": 1637,
        "data": {
          "file": "oleaut32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1638,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\DebugDriver",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1639,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1640,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1641,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1642,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1643,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,983",
        "eid": 1644,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,999",
        "eid": 1645,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:13,999",
        "eid": 1646,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,014",
        "eid": 1647,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SetupOverride",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,014",
        "eid": 1648,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
          "content": "536887297"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,014",
        "eid": 1649,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMask",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,014",
        "eid": 1650,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogMaxFileSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,030",
        "eid": 1651,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,030",
        "eid": 1652,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,030",
        "eid": 1653,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Versions\\000603xx",
          "content": "kernel32.dll"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,030",
        "eid": 1654,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,030",
        "eid": 1655,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,077",
        "eid": 1656,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DisableDecoratedModelsRequirement",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,092",
        "eid": 1657,
        "data": {
          "file": "api-ms-win-eventing-provider-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:14,108",
        "eid": 1658,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,124",
        "eid": 1659,
        "data": {
          "file": "cabinet.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffed9750000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,124",
        "eid": 1660,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,124",
        "eid": 1661,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.cat"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,155",
        "eid": 1662,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,155",
        "eid": 1663,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,155",
        "eid": 1664,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,155",
        "eid": 1665,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,155",
        "eid": 1666,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileBufferedSynchronousIo",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,171",
        "eid": 1667,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileChunkSize",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,171",
        "eid": 1668,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\CopyFileOverlappedCount",
          "content": null
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,186",
        "eid": 1669,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,186",
        "eid": 1670,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.inf"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,217",
        "eid": 1671,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,233",
        "eid": 1672,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,249",
        "eid": 1673,
        "data": {
          "file": "C:\\Windows\\SysWOW64\\Zonelabs\\vsdatant.sys"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,264",
        "eid": 1674,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
        }
      },
      {
        "event": "move",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,296",
        "eid": 1675,
        "data": {
          "from": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp",
          "to": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1676,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1677,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1678,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1679,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
          "content": "Isolated User Mode (IUM)"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1680,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.37!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1681,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1682,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-100",
          "content": "Isolated User Mode (IUM)"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1683,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-101"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1684,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1685,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
          "content": "Enclave"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1686,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.10.3.42!7\\Name",
          "content": "@%SystemRoot%\\System32\\ci.dll,-101"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1687,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,342",
        "eid": 1688,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\ci.dll,-101",
          "content": "Enclave"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1689,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1690,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1691,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
          "content": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1692,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.64.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\dnsapi.dll,-103"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1693,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1694,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\dnsapi.dll,-103",
          "content": "\\x414\\x43e\\x432\\x435\\x440\\x435\\x43d\\x43d\\x44b\\x439 DNS-\\x441\\x435\\x440\\x432\\x435\\x440"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1695,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
          "content": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1696,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1697,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
          "content": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1698,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.76.6.1!7\\Name",
          "content": "@%SystemRoot%\\System32\\wuaueng.dll,-400"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1699,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1700,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\System32\\wuaueng.dll,-400",
          "content": "\\x426\\x435\\x43d\\x442\\x440 \\x43e\\x431\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1701,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1702,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1703,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1704,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.80.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1705,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1706,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\powershell.exe,-124",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x434\\x43e\\x43a\\x443\\x43c\\x435\\x43d\\x442\\x43e\\x432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1707,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1708,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1709,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1710,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptDllFindOIDInfo\\1.3.6.1.4.1.311.92.1.1!7\\Name",
          "content": "@%SystemRoot%\\system32\\NgcRecovery.dll,-100"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1711,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,358",
        "eid": 1712,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Classes\\Local Settings\\MuiCache\\2\\B1A07F78\\@%SystemRoot%\\system32\\NgcRecovery.dll,-100",
          "content": "\\x428\\x438\\x444\\x440\\x43e\\x432\\x430\\x43d\\x438\\x435 \\x43a\\x43b\\x44e\\x447\\x430 \\x432\\x43e\\x441\\x441\\x442\\x430\\x43d\\x43e\\x432\\x43b\\x435\\x43d\\x438\\x44f Windows Hello"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,374",
        "eid": 1713,
        "data": {
          "file": "C:\\Windows\\System32\\bcryptprimitives.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1390000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,374",
        "eid": 1714,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1715,
        "data": {
          "file": "WINTRUST.DLL",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1716,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1717,
        "data": {
          "file": "C:\\Windows\\System32\\crypt32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0b90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1718,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1719,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertSyncDeltaTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1720,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableMandatoryBasicConstraints",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1721,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableCANameConstraints",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1722,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableUnsupportedCriticalExtensions",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1723,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlCountInCert",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1724,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1725,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxUrlRetrievalByteCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1726,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalByteCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1727,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxAIAUrlRetrievalCertCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1728,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxVerifySignatureCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1729,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxIssuerDepth",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1730,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MaxPathCountPerChain",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1731,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\CryptnetPreFetchTriggerPeriodSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1732,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableWeakSignatureFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1733,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\MinRsaPubKeyBitLength",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1734,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRsaPubKeyTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1735,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\ChainCacheResyncFiletime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1736,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\EnableStrictChecksFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1737,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1738,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyFlags",
          "content": "18446744071705722880"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1739,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1740,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartyAfterTime",
          "content": "\\x00\\xc0)\\xb8C\\x9a\\xc9\\x01"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1741,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1742,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1743,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1744,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1745,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1746,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1747,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1748,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": "\\x00\\x00\\x001\\x3b5b\\xf70a\\x7f\\x1200P\\xd21b\\xa39\\x7ff7"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1749,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1750,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1751,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1752,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,405",
        "eid": 1753,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakMD5AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1754,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1755,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyFlags",
          "content": "18446744071562330112"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1756,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartyAfterTime",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1757,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1758,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1759,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1760,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1761,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1762,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1763,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1764,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1765,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1766,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1767,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1ThirdPartySha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1768,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CI\\Config\\Default\\WeakSHA1AllSha256Allow",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1769,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1770,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1771,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakRSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1772,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakRSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1773,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1774,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1775,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1776,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1777,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1778,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAThirdPartyFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1779,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\WeakECDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1780,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\Default\\WeakECDSAAllFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1781,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1782,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\crypt32\\DiagMatchAnyMask",
          "content": null
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1783,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1784,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1785,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1786,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1787,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1788,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1789,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1790,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,421",
        "eid": 1791,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1792,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1793,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1794,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1795,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1796,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1797,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1798,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1799,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1800,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1801,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1802,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1803,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1804,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1805,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1806,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1807,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1808,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1809,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1810,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\CA"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1811,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1812,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1813,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\CA\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1814,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1815,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1816,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1817,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,436",
        "eid": 1818,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1819,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1820,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1821,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1822,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1823,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1824,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1825,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1826,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1827,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1828,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1829,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1830,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1831,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1832,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1833,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1834,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1835,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1836,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1837,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1838,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1839,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1840,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1841,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1842,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1843,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1844,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1845,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1846,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1847,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,452",
        "eid": 1848,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1849,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1850,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1851,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1852,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1853,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1854,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1855,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1856,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1857,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1858,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1859,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1860,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1861,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1862,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1863,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1864,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1865,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1866,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1867,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1868,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1869,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1870,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1871,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1872,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1873,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1874,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1875,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\AuthRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1876,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1877,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1878,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1879,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1880,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1881,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1882,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1883,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1884,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1885,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1886,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1887,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,467",
        "eid": 1888,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1889,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1890,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1891,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1892,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1893,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1894,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1895,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1896,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1897,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1898,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1899,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1900,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1901,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1902,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1903,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1904,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1905,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1906,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Root"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1907,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1908,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1909,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Root\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1910,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1911,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1912,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1913,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1914,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1915,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1916,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1917,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\SmartCardRoot\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1918,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,483",
        "eid": 1919,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1920,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1921,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1922,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1923,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1924,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1925,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1926,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1927,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1928,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1929,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1930,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1931,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1932,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1933,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1934,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1935,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1936,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1937,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\TrustedPeople"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1938,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1939,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1940,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\TrustedPeople\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1941,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1942,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1943,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1944,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1945,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1946,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1947,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1948,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1949,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1950,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,499",
        "eid": 1951,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1952,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1953,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1954,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1955,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1956,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1957,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1958,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\trust\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1959,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1960,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\trust"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1961,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1962,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1963,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Trust\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1964,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1965,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Root\\ProtectedRoots\\Certificates",
          "content": "\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xe0\\xb55Z\\xd7:\\xda\\x01\\x00\\x00\\x00\\x00\\x18\\x00\\x00\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1966,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1967,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\0119E81BE9A14CD8E22F40AC118C687ECBA3F4D8\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xfc\\x02\\xa4\\x9e.\\x1e\\x8eH\\x8c\\xa2\\x91!5W,\\xc2\\xf8\\xe7\\x1b\\xb0\\xe2\\xf2\\x85\\x96\\xb3r\"\\x99\\xf5\\xcb\\x9cb\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x84's\\x95\\x00\\x86\\xd0k\\x04\\xd7\\x02-b\\xa2\\x84\\xbek\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00e\\xaf\\x95\\xf4\\xbe\\x86\\x84sDcB\\x82\\xf9A\\xb2\\xe6\\x05\\x06>\\xf0\\xc8T/\\x01L\\xa0\\x88\\xd1\\x82\\x10\\x9eO\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00j\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x004\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x19\\xe8\\x1b\\xe9\\xa1L\\xd8\\xe2/@\\xac\\x11\\x8ch~\\xcb\\xa3\\xf4\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x004\\xf7&\\x98\\xd7\\x0e#\\x1f\\x8d\\xc4[W\\xf1\\x18\\xa4K\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe4\\xa2\\xf6\\xfe\\x9c\\xa7\\xf1\\x8a+\\xeb\\xa9aa0\\x8b\\xaa\\x88\\x80\\xb0\\x13\\x16\\x1d\\xdd\\x852\\xd4%\\x9e'\\xe5\\x05p\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcb\\xd1\\xf2\\xceH\\xfd\\x01\\x9f\\xeaV\\xaaW\\xd1~\\x99X\\xf8?\\xff\\xe0Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x07\\x06\\x00\\x000\\x82\\x06\\x030\\x82\\x03\\xeb\\xa0\\x03\\x02\\x01\\x02\\x02\\x10/\\xd6zC\"\\x932\\x90E\\xe9S4>\\xe2tf0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x931\\x0b0\t\\x06"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1968,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1969,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\06F1AA330B927B753A40E68CDF22E34BCBEF3352\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\x9e}\\x1e\\x8d]\\xa1\\x1d\\xc0\\xc8K\\x07W\\xec\\xed\\xcb\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x002\\x99\\x19\\x81\\xbf\\x15u\\xa1\\xa50;\\xb9:8\\x17#\\xea4k\\x9e\\xc10\\xfd\\xb5\\x96\\xa7[\\xa1\\xd7\\xce\\x0b\n\\x06W\\x0b\\xb9\\x85\\xd2XA\\xe2;\\xe9D\\xe8\\xff\\x11\\x8f\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00l\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00P\\x00r\\x00o\\x00d\\x00u\\x00c\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x06\\xf1\\xaa3\\x0b\\x92{u:@\\xe6\\x8c\\xdf\"\\xe3K\\xcb\\xef3R\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x1f\\x12N\\xde\\x13\\xe0j\\x02<\\xd7\\xc0\\x9aOH\\xc3\\xd6\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00C\\xefp\\x87\\xb8\\x9d\\xbf\\xec\\x88\\x19\\xdc\\xc6\\xc4ku\ru43\\x08\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00'\\x03\\x00\\x000\\x82\\x03#0\\x82\\x02\\xa8\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x14\\x98&f\\xdc|\\xcd\\x8f@Sg{\\xb9\\x99\\xec\\x850\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x941\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft C"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1970,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1971,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe5=4\\xce\\xcb\\x05\\xc1~\\xe32\\xc7I\\xd7\\x8c\\x02V\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00e\\xfcGR\\x0ff89b\\xec\\x0b{\\x88\\xa0\\x82\\x1d\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x18\\xf7\\xc1\\xfc\\xc3\t\\x02\\x03\\xfd[\\xaa/\\x86\\x1auIv\\xc8\\xdd%\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00T\\x00i\\x00m\\x00e\\x00 \\x00S\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00>\\xdf)\\x0c\\xc1\\xf5\\xccs,\\xeb=$\\xe1~R\\xda\\xbd'\\xe2\\xf0 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc0\\x02\\x00\\x000\\x82\\x02\\xbc0\\x82\\x02%\\x02\\x10J\\x19\\xd28\\x8c\\x82Y\\x1c\\xa5]s_\\x15]\\xdc\\xa30\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1,0*\\x06\\x03U\\x04\\x0b\\x13#VeriSign Time Stamping Service Root1402\\x06\\x03U\\x04\\x0b\\x13+NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.0\\x1e\\x17\r970512000000Z\\x17\r040107235959Z0\\x81\\x9e1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, I"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1972,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1973,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7f\\xdf\\xf5\\x07)Dg\\x10$JD|\\xa2\\xa1\\x97\\xea\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9d\\xf0\\xd11\\x00\\x12:\\xec\\xa7p\\x13\\x0fJ\\xd8\\xd2\t\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00$\\\\x97\\xdfu\\x14\\xe7\\xcf-\\xf8\\xber\\xae\\x95{\\x9e\\x04t\\x1e\\x85\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x004O0-%i1\\x91\\xea\\xf7s\\\\xab\\xf5\\x86\\x8d7\\x82@\\xec \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb1\\x02\\x00\\x000\\x82\\x02\\xad0\\x82\\x02\\x16\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03U\\x04\\x0b\\x13$Microsoft Time Stamping Service Root1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.0\\x1e\\x17\r970513161259Z\\x17\r991230235959Z0\\x81\\x9e1 0\\x1e\\x06\\x03U\\x04\n\\x13\\x17Microsoft Trust Network1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1-0+\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1974,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1975,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\31F9FC8BA3805986B721EA7295C65B3A44534274\\Blob",
          "content": "Y\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00E\\x00C\\x00D\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x003\\x008\\x004\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe8G\\xc8B\\x9a\\xb0\\x9d\\xaeo\\x0b(;\\x98\\x15\\x8f\\xe3\\xb1\\xe8\\x80\\xb2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x03\\xd1\\xc7ge\\xed\\xa8\\x8b\\xc8\\xe0\\x87^`\\x91\\xd0`C%C\\xd1\\x80\\xbc\\xb8l\\x06I6\\xad\\xb9A\\xc4!cx\\x0b\\x82\\x89\\x92\\x1a\\x94\\xfe\\xbb\\x7f\\x9eG\\xed\\xac\\x12\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x007\\x94)X\\x86*\\x06\\xe6\\xbb\\xcf\\xd7\\xabY\\xc7\\xf2<i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00b\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00E\\x00C\\x00C\\x00 \\x00T\\x00S\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x008\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x001\\xf9\\xfc\\x8b\\xa3\\x80Y\\x86\\xb7!\\xear\\x95\\xc6[:DSBtk\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\xd4\\xbe\\x8b\\xaa\\xd2\\xf2n\\x1b\\xde\\x06\\xc7XK\\xb7 \\xdd\\x1a\\x97-\\x11\\x1fZI\\x99\\xbcD\\xb0\\x8f\\xb4\\x96\r\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa4\\x0f<\\xb7\\xf5\\xff\\xa3\\xe8\\x12\\xbe\\xc7\\xf8U\\x07\\xcb\\xf4|\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xc5u\\x0b\\xf8_E\\x9f\\xb7\\x0e+l\\xd1\\x89\\x8d7^\\x92\\xd7\\x93\\x8eG\\xa6\\xe04\\xcc\\xe0\\xc1-07,\\xcd \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1b\\x03\\x00\\x000\\x82\\x03\\x170\\x82\\x02\\x9e\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x158u\\xe1d~\\xd1\\xb0G\\xb4\\xef\\xafA\\x12\\x82E0\n\\x06\\x08*\\x86H\\xce=\\x04\\x03\\x030\\x81\\x8f1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02U"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1976,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1977,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\3B1EFD3A66EA28B16697394703A72CA340A05BD5\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00<p\\xfa\\xea%`\\x0c\\xe3\\xb2\\xcc_\\x0b\".\\xd6)\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x08\\xfb\\xa81\\xc0\\x85D \\x8fR\\x08hk\\x99\\x1c\\xa1\\xb2\\xcf\\xc5\\x10\\xe70\\x17\\x84\\xdd\\xf1\\xeb[\\xf0929i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x000\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00;\\x1e\\xfd:f\\xea(\\xb1f\\x979G\\x03\\xa7,\\xa3@\\xa0[\\xd5\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5\\xf6V\\xcb\\x8f\\xe8\\xa2\\bh\\xd1=\\x94\\x90[\\xd7\\xce\\x9a\\x18\\xc4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa2f\\xbb}\\xcc8\\xa5bc\\x13a\\xbb\\xf6\\x1d\\xd1\\x1b \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10(\\xcc:%\\xbf\\xbaD\\xacD\\x9a\\x9bXkC9\\xaa0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20100\\x1e\\x17\r100623215"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1978,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1979,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\7F88CD7223F3C813818C994614A89C99FA3B5247\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x07\\xd3M\\xedI\\x8dEw\\xf2a\\xbd8\\xb6\\xb8sn\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd6uv\\xf5R\\x1d\\x1c\\xca\\xb5.\\x92\\x15\\xe0\\xf9\\xf7C\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x7f\\x88\\xcdr#\\xf3\\xc8\\x13\\x81\\x8c\\x99F\\x14\\xa8\\x9c\\x99\\xfa;RG\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00e\\x00n\\x00t\\x00i\\x00c\\x00o\\x00d\\x00e\\x00(\\x00t\\x00m\\x00)\\x00 \\x00R\\x00o\\x00o\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\xf03L\\x1a\\xa1\\xd9\\xee[{\\xa9\\xdeC\\xbc\\x02}W\t3\\xfb \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xda\\x03\\x00\\x000\\x82\\x03\\xd60\\x82\\x02\\xbe\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x1e\\x17\r950101080001Z\\x17\r991231235959Z0P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\r0\\x0b\\x06\\x03U\\x04\n\\x13\\x04MSFT1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Authenticode(tm) Root Authority0\\x82\\x01\"0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x82\\x01\\x0f\\x000\\x82\\x01\n\\x02\\x82\\x01\\x01\\x00\\xdf\\x08\\xba\\xe3?nd\\x9b\\xf5\\x89"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1980,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1981,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xce\\x04\\x90\\xd5\\xe5l4\\xa5\\xae\\x0b\\xe9\\x8b\\xe5\\x81\\x18]\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00'\\x9c\\xd6R\\xc4\\xe2R\\xbf\\xbeR\\x17\\xacr\"\\x05\\xd7r\\x9b\\xa4\t\\x14\\x8c\\xfa\\x9em\\x9e[\\x1c\\xb9N\\xaf\\xf1\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x001\\x001\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8fC(\\x8a\\xd2r\\xf3\\x10;o\\xb1B\\x84\\x85\\xea0\\x14\\xc0\\xbc\\xfe\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00r-:\\x021\\x90C\\xb9\\x14\\x05N\\xe1\\xea\\xa7\\xc71\\xd1#\\x894\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbb\\x04\\x8f\\x1889_o\\xc3\\xa1\\xf3\\xd2\\xb7\\xe9vT \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xf1\\x05\\x00\\x000\\x82\\x05\\xed0\\x82\\x03\\xd5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10?\\x8b\\xc8\\xb5\\xfc\\x9f\\xb2\\x96C\\xb5i\\xd6lB\\xe1D0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000\\x81\\x881\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x130\\x11\\x06\\x03U\\x04\\x08\\x13\nWashington1\\x100\\x0e\\x06\\x03U\\x04\\x07\\x13\\x07Redmond1\\x1e0\\x1c\\x06\\x03U\\x04\n\\x13\\x15Microsoft Corporation1200\\x06\\x03U\\x04\\x03\\x13)Microsoft Root Certificate Authority 20110\\x1e\\x17\r110322220"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1982,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1983,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\92B46C76E13054E104F230517E6E504D43AB10B5\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00M\\xec\\xdf&\\x06\\xdc$\\x10\\xc0\\xb6\\x99\\xf4\\xd79\\xc7o\\x19\\xf8&(\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00WS\\xd5}h\\xf32&,L\\xc2\\xe5\\xefv\\x84\\x8e\\x03\\xdd\\xc8!,4\\xc7W\\x08|*\\xa7\\xe3 \\xa9F\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00q\\xd0\\xa5\\xff-Yt\\x16\\x94\\xbe\\xe3}\\x1e\\\\x86\\x0b\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x92\\xb4lv\\xe10T\\xe1\\x04\\xf20Q~nPMC\\xab\\x10\\xb5k\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x8a^H\\x81\\xd4/tu\\xe8\\xec7&\\xfc\\xd5\\xe5\\x18\\x84\\xaa\\x04\\xda\\xa9\\xfaz\\xda\\xc8\\xcd&E,\\xf8\\x85\\xd4\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc8\\xb53\\x18\\xbf\\xf7\\xf6\\x89\\xdf\\xeak\\xfc?\\xd7\\x93rY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xc1\\x03\\x00\\x000\\x82\\x03\\xbd0\\x82\\x02\\xa5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0fkU/\\x9e\\xbf\\x90{\\x0ff)\\xa9\\xbd\\xf4\\xd8\\xce0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Corporation1604\\x06\\x03U\\x04\\x03\\x13-Symantec Enterprise Mobile Root for Microsoft0\\x1e\\x17\r120315000000Z\\x17\r320314235959Z0d1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x1d0\\x1b\\x06\\x03U\\x04\n\\x13\\x14Symantec Cor"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1984,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1985,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\A43489159A520F0D93D032CCAF37E7FE20A8B419\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00?\\xc8\\xcb\\x0b\\xc0RA\\xe5\\x8de\\xe9D\\x8b-\\x07\\xc2\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x8b<0\\x87\\xb7\\x05o^\\xc5\\xdd\\xba\\x91\\xa1\\xb9\\x01\\xf0i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa44\\x89\\x15\\x9aR\\x0f\r\\x93\\xd02\\xcc\\xaf7\\xe7\\xfe \\xa8\\xb4\\x19\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00J\\u\"\\xaaF\\xbf\\xa4\\x08\\x9d9\\x97N\\xbd\\xb4\\xa3`\\xf7\\xa0\\x1d \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x04\\x00\\x000\\x82\\x04\\x120\\x82\\x02\\xfa\\xa0\\x03\\x02\\x01\\x02\\x02\\x0f\\x00\\xc1\\x00\\x8b<<\\x88\\x11\\xd1>\\xf6c\\xec\\xdf@0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r970110070000Z\\x17\r201231070000Z0p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft R"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1986,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1987,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\BE36A4562FB2EE05DBB3D32323ADF445084ED656\\Blob",
          "content": "\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe8\\xa5\\x98\\xbe\\x84\\x82\\x8e\\xfe\\xaep\\x11\\x15\\x015v\\xb2\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x7ffzq\\xd3\\xebix \\x9aQ\\x14\\x9d\\x83\\xda \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xbe6\\xa4V/\\xb2\\xee\\x05\\xdb\\xb3\\xd3##\\xad\\xf4E\\x08N\\xd6V\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00.\\x00\\x00\\x00T\\x00h\\x00a\\x00w\\x00t\\x00e\\x00 \\x00T\\x00i\\x00m\\x00e\\x00s\\x00t\\x00a\\x00m\\x00p\\x00i\\x00n\\x00g\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x18\\x1c+\\xe0XQ\\xf9i\\x93\\xe1\\x96\\xf2y\\x95K#\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xbc\\xbd\\x86\\x9c?\\x07\\xed@\\xe3\\x1b\\x08\\xef\\xce\\xc4\\xd1\\x88\\xcd;\\x15 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xa5\\x02\\x00\\x000\\x82\\x02\\xa10\\x82\\x02\n\\xa0\\x03\\x02\\x01\\x02\\x02\\x01\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r\\x06\\x03U\\x04\n\\x13\\x06Thawte1\\x1d0\\x1b\\x06\\x03U\\x04\\x0b\\x13\\x14Thawte Certification1\\x1f0\\x1d\\x06\\x03U\\x04\\x03\\x13\\x16Thawte Timestamping CA0\\x1e\\x17\r970101000000Z\\x17\r201231235959Z0\\x81\\x8b1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02ZA1\\x150\\x13\\x06\\x03U\\x04\\x08\\x13\\x0cWestern Cape1\\x140\\x12\\x06\\x03U\\x04\\x07\\x13\\x0bDurbanville1\\x0f0\r"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,514",
        "eid": 1988,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1989,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\ROOT\\Certificates\\CDD4EEAE6000AC7F40C3802C171E30148030C072\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x98;\\x13&5\\xb7\\xe9\\x1d\\xee\\xf5Jg\\x80\\xc0\\x92i\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x009\\x1b\\xe9(\\x83\\xd5%\t\\x15[\\xfe\\xae'\\xb9\\xbd4\\x01p\\xb7k\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xcd\\xd4\\xee\\xae`\\x00\\xac\\x7f@\\xc3\\x80,\\x17\\x1e0\\x14\\x800\\xc0r\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00J\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00\\x00\\x00i\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x03\\x02\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x0e\\xac\\x82`@V'\\x97\\xe5%\\x13\\xfc*\\xe1\nS\\x95Y\\xe4\\xa4 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x9d\\x05\\x00\\x000\\x82\\x05\\x990\\x82\\x03\\x81\\xa0\\x03\\x02\\x01\\x02\\x02\\x10y\\xad\\x16\\xa1J\\xa0\\xa5\\xadLsX\\xf4\\x07\\x13.e0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate Authority0\\x1e\\x17\r010509231922Z\\x17\r210509232813Z0_1\\x130\\x11\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\\x03com1\\x190\\x17\\x06\n\t\\x92&\\x89\\x93\\xf2,d\\x01\\x19\\x16\tmicrosoft1-0+\\x06\\x03U\\x04\\x03\\x13$Microsoft Root Certificate A"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1990,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1991,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x87\\xce\\x0b{*\\x0eI\\x00\\xe1Xq\\x9b7\\xa8\\x93r\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x05c\\xb8c\rb\\xd7Z\\xbb\\xc8\\xab\\x1eK\\xdf\\xb5\\xa8\\x99\\xb2MC\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O_\\x10i09\\x8d\t\\x10{@\\xc3\\xc7\\xca\\x8f\\x1c\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00E\\xeb\\xa2\\xaf\\xf4\\x92\\xcb\\x821-Q\\x8b\\xa7\\xa7!\\x9d\\xf3m\\xc8\\x0fb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00>\\x90\\x99\\xb5\\x01^\\x8fHl\\x00\\xbc\\xea\\x9d\\x11\\x1e\\xe7!\\xfa\\xba5Z\\x89\\xbc\\xf1\\xdfiV\\x1e=\\xc62\\\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00m\\xca[\\xd0\r\\xcf\\x1c\\x0f2pY\\xd3t\\xb2\\x9c\\xa6\\xe3\\xc5\n\\xa6\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00t\\x99f\\xce\\xcc\\x95\\xc1\\x87A\\x94\\xcar\\x03\\xf9\\xb6  \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xbb\\x03\\x00\\x000\\x82\\x03\\xb70\\x82\\x02\\x9f\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xe7\\xe0\\xe5\\x17\\xd8F\\xfe\\x8f\\xe5`\\xfc\\x1b\\xf0090\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000e1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x150\\x13\\x06\\x03U\\x04\n\\x13\\x0cDigiCert Inc1\\x190\\x17\\x06\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1992,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1993,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\51501FBFCE69189D609CFAF140C576755DCC1FDF\\Blob",
          "content": "\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x000\\x1e\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xeb\\x15w\\xb4\\x0b<\\x8b\\xab\\xae4m\\xd9\\x8e\\xad\\x07\\x80\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00QP\\x1f\\xbf\\xcei\\x18\\x9d`\\x9c\\xfa\\xf1@\\xc5vu]\\xcc\\x1f\\xdf\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00[\\xcb\\x93\\xea\\xdb}mO\\xb7\\xa0\n/:\\xe5\\x03\\x0c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00g\\x0eI,a\\x17\\x9e\\xeb\\xed\\xe0T\\xe7\\x84\\xd9\\x9b\\xadd`seb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xa3\\xcchY]\\xfe~\\x86\\xd8\\xad\\x17r\\xa8\\xb5(J\\xddT\\xac\\xe3\\xb8\\xa7\\x98\\xdfG\\xbc\\xca\\xfb\\x1f\\xdb\\x84\\xdf\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00>\\x00\\x00\\x00H\\x00o\\x00t\\x00s\\x00p\\x00o\\x00t\\x00 \\x002\\x00.\\x000\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x000\\x003\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xbeR\\xe4a\\xb1}\\xd6%'q%\\x1bE\\xe9\\x8f\\x122\\xca\\xa1%\\x12\\xdcy\\x11\\x8d\\x0c_\\xces\\xa5M\\x95\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00O\\xcb\\x14\\xf7\\xc4\\xa3\\x8f/&\\\\x1f\\x12\\xc9\\xafVwY\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x00R\\x00S\\x00A\\x00/\\x00S\\x00H\\x00A\\x002\\x005\\x006\\x00\\x00\\x00 \\x00\\x00\\x00\\x01\\x00\\x00\\x00p\\x05\\x00\\x000\\x82\\x05l0\\x82\\x03T\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x0c\\xb3\\x0fp\\xf2\\x86\\xa43\\xe0\\xb9\t\\x89\\xde\\x01\\xed\\xb70\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000P1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x180\\x16\\x06\\x03U\\x04\n\\x13\\x0fWFA Hotspot 2.01'0%\\x06\\x03U\\x04\\x03"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1994,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1995,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\742C3192E607E424EB4549542BE1BBC53E6174E2\\Blob",
          "content": "h\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00=\\xb6[\\xd9\\xd5\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0e\\x00\\x00\\x000\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x02S\\x00\\x00\\x00\\x01\\x00\\x00\\x00$\\x00\\x00\\x000\"0 \\x06\n+\\x06\\x01\\x04\\x01\\x827^\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd7\\xc6;\\xe0\\x83}\\xba\\xbf\\x88\\x1dO\\xbf_\\x98j\\xd8\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x10\\xfcc]\\xf6&>\r\\xf3%\\xbe_y\\xcdgg\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00F\\x00\\x00\\x00V\\x00e\\x00r\\x00i\\x00S\\x00i\\x00g\\x00n\\x00 \\x00C\\x00l\\x00a\\x00s\\x00s\\x00 \\x003\\x00 \\x00P\\x00u\\x00b\\x00l\\x00i\\x00c\\x00 \\x00P\\x00r\\x00i\\x00m\\x00a\\x00r\\x00y\\x00 \\x00C\\x00A\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xe2\\x7f{\\xd8w\\xd5\\xdf\\x9e\n?\\x9e\\xb4\\xcb\\x0e.\\xa9\\xef\\xdbiw\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00'\\xb3Qvg3\\x1c\\xe2\\xc1\\xe7@\\x02\\xb5\\xff\"\\x98\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00t,1\\x92\\xe6\\x07\\xe4$\\xebEIT+\\xe1\\xbb\\xc5>at\\xe2\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00*\\x00\\x00\\x000(\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xe7hV4\\xef\\xac\\xf6\\x9a\\xce\\x93\\x9ak%[{O\\xab\\xefB\\x93[P\\xa2e\\xac\\xb5\\xcb`'\\xe4Np~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x00\\x10\\xc5\\x1e\\x92\\xd2\\x01 \\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x02\\x00\\x000\\x82\\x02<0\\x82\\x01\\xa5\\x02\\x10p\\xba\\xe4\\x1d\\x10\\xd9)4\\xb68\\xca{\\x03\\xcc\\xba\\xbf0\r\\x06\t"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1996,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1997,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\7E04DE896A3E666D00E687D33FFAD93BE83D349E\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x80\\x01\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xb0\t\\xe9\\x9a\\\\xfc\\x92\\x8a\\x171\\x90\\x10m\\xbb2\\xa9\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00~\\x04\\xde\\x89j>fm\\x00\\xe6\\x87\\xd3?\\xfa\\xd9;\\xe8=4\\x9e\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xab9\\xed\\xd1\\xa4\\xd8\\x9aU\\x12\\x88-\\xeb\t\\xcb\\x13\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3\\xdbH\\xa4\\xf9\\xa1\\xc5\\xd8\\xae6A\\xcc\\x11cib)\\xbcK\\xc6b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x001\\xadfH\\xf8\\x10A8\\xc78\\xf3\\x9e\\xa42\\x0139>:\\x18\\xcc\\x02)n\\xf9|*\\xc9\\xefg1\\xd0\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x003\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00\\x82\\xc8\\x01\\x999w\"\\xb5z\\xd4s\\xea&k\\x93\\xd4\\x7f\\xfcw\\xfe\\x07\\xf0\\x93\\x884_ \\xda\\xb6\\xad\\xdd\\x08vr\\xf9\\x88\\xb4\\xbb\\xfd\\x15LK\\x13<p\\xc9\\xec\\xff\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xf5]\\xa4P\\xa5\\xfb(~\\x1e\\x0f\r\\xcc\\x96WV\\xca \\x00\\x00\\x00\\x01\\x00\\x00\\x00C\\x02\\x00\\x000\\x82\\x02?0\\x82\\x01\\xc5\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05UV\\xbc\\xf2^\\xa455\\xc3\\xa4\\x0f\\xd5\\xabEr0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1998,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 1999,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xcb\\x9d\\xd0\\xfc\\xea\\xaaI/u\\xce),!\\xbb\\xfb\\xdd\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x80\\x94d\\x0e\\xb5\\xa7\\xa1\\xca\\x11\\x9c\\x1f\\xdd\\xd5\\x9f\\x81\\x02c\\xa7\\xfb\\xd1~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01z\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00R\\x1f\\\\x98\\x97\r\\x19\\xa8\\xe5\\x15\\xefn\\xebmH\\xef\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xael\\x05\\xa3\\x93\\x13\\xe2\\xa2\\xe7\\xe2\\xd7\\x1c\\xd6\\xc7\\xf0\\x7f\\xc8gS\\xa0\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\tb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00,\\xab\\xea\\xfe7\\xd0l\\xa2*\\xbas\\x91\\xc0\\x03=%\\x98)R\\xc4SdsIv::\\xb5\\xadl\\xcfi\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x006\\x00\\x00\\x00\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00V\\x00\\x00\\x000T\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\t\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08S\\x00\\x00\\x00\\x01\\x00\\x00\\x00~\\x00\\x00\\x000|0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x020\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x010\\x120\\x10\\x06\n+"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2000,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2001,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00y\\xe4\\xa9\\x84\r}:\\x96\\xd7\\xc0O\\xe2CL\\x89.\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00CH\\xa0\\xe9DLx\\xcb&^\\x05\\x8d^\\x89D\\xb4\\xd8O\\x96b\\xbd&\\xdb%\\x7f\\x894\\xa4C\\xc7\\x01a\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x03\\xdeP5V\\xd1L\\xbbf\\xf0\\xa3\\xe2\\x1b\\x1b\\xc3\\x97\\xb2=\\xd1U\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x12\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00\\x00\\x00\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00Yw\\x9e9\\xe2\\x1a.=\\xfc\\xedhW\\xed\\_\\xd9\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa8\\x98]:e\\xe5\\xe5\\xc4\\xb2\\xd7\\xd6m@\\xc6\\xdd/\\xb1\\x9cT6\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xb3M\\xdd7.\\xd9.\\x8f*\\xbf\\xbb\\x9e \\xa9\\xd3\\x1f O\\x19K\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0f:\\x05'\\xd2B\\xde-\\xc9\\x8e\\\\xfc\\xb1\\xe9\\x91\\xee \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb3\\x03\\x00\\x000\\x82\\x03\\xaf0\\x82\\x02\\x97\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x08;\\xe0V\\x90BF\\xb1\\xa1uj\\xc9Y\\x91\\xc7J0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x00"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2002,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2003,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\CABD2A79A1076A31F21D253635CB039D4329A5E8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x0c\\xd2\\xf9\\xe0\\xda\\x17s\\xe9\\xed\\x86M\\xa5\\xe3p\\xe7N\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00?\\x04\\x11\\xed\\xe9\\xc4GpW\\xd5~W\\x88;\\x1f [ \\xcd\\xc0\\xf3&1)\\xb1\\xee\\x02i\\xa2g\\x8fc\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xca\\xbd*y\\xa1\\x07j1\\xf2\\x1d%65\\xcb\\x03\\x9dC)\\xa5\\xe8\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00s\\xb6\\x87a\\x95\\xf5\\xd1\\x8e\\x04\\x85\\x10B*\\xef\\x04\\xe3\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00y\\xb4Y\\xe6{\\xb6\\xe5\\xe4\\x01s\\x80\\x08\\x88\\xc8\\x1aX\\xf6\\xe9\\x9bn\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x1a\\x00\\x00\\x00I\\x00S\\x00R\\x00G\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00X\\x001\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\x96\\xbc\\xec\\x06&Iv\\xf3t`w\\x9a\\xcf(\\xc5\\xa7\\xcf\\xe8\\xa3\\xc0\\xaa\\xe1\\x1a\\x8f\\xfc\\xee\\x05\\xc0\\xbd\\xdf\\x08\\xc6\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00/\\xe1\\xf7\\x0b\\xb0]|\\x923[\\xc5\\xe0[\\x98M\\xa6 \\x00\\x00\\x00\\x01\\x00\\x00\\x00o\\x05\\x00\\x000\\x82\\x05k0\\x82\\x03S\\xa0\\x03\\x02\\x01\\x02\\x02\\x11\\x00\\x82\\x10\\xcf\\xb0\\xd2@\\xe3YDc\\xe0\\xbbc\\x82\\x8b\\x000\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0b\\x05\\x000O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1)0'\\x06\\x03U\\x04\n\\x13 Internet Security Research Group1\\x150\\x13\\x06\\x03U\\x04\\x03\\x13\\x0cISRG Root X10\\x1e\\x17\r150604110438Z\\x17\r350604110438Z0O1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2004,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2005,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\D69B561148F01C77C54578C10926DF5B856976AD\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xc5\\xdf\\xb8I\\xca\\x05\\x13U\\xee-\\xba\\x1a\\xc3>\\xb0(\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd6\\x9bV\\x11H\\xf0\\x1cw\\xc5Ex\\xc1\t&\\xdf[\\x85iv\\xad\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x01r\\x8e\\x1e\\xcfz\\x9d\\x86\\xfb<\\xec\\x89H\\xab\\xa9S\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x8f\\xf0K\\x7f\\xa8.E$\\xaeMP\\xfac\\x9a\\x8b\\xde\\xe2\\xdd\\x1b\\xbcb\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb\\xb5\"\\xd7\\xb7\\xf1'\\xadj\\x01\\x13\\x86[\\xdf\\x1c\\xd4\\x10.}\\x07Y\\xafcZ|\\xf4r\r\\xc9c\\xc5;\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00S\\x00i\\x00g\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00A\\x00 \\x00-\\x00 \\x00R\\x003\\x00\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t+\\x06\\x01\\x04\\x01\\xa02\\x01\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00T\\x00\\x00\\x000R\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x06\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x07\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00R)\\xba\\x15\\xb3\\x1b\\x0coL\\xca\\x89\\xc2\\x98Qw\\x97C'\\xd1\\xb6\\x89\\xa3\\xb95\\xa0\\xbd\\x97U2\\xaf\"\\xab\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xd0\\xfd<\\x9c8\r{e\\xe2k\\x9a?\\xed\\xd3\\x9b\\x8f \\x00\\x00\\x00\\x01\\x00\\x00\\x00c\\x03\\x00\\x000\\x82\\x03_0\\x82\\x02G\\xa0\\x03\\x02\\x01\\x02\\x02\\x0b\\x04"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2006,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2007,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xff\\xac y\\x97\\xbb,\\xfe\\x86Up\\x17\\x9e\\xe07\\xb9\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00N\\xa1\\xb3K\\x10\\xb9\\x82\\xa9j8\\x91XCPx \\xadc,j\\xad\\x83C\\xe37\\xb3Mf\\x0c\\xd86o\\xa1TTJ\\xe8\\x06h\\xae\\x1f\\xdf91\\xd5~\\x19\\x96S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x002\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00T\\x00r\\x00u\\x00s\\x00t\\x00e\\x00d\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x004\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00U/{\\xdc\\xf1\\xa7\\xaf\\x9el\\xe6r\\x01\\x7fO\\x12\\xab\\xf7r@\\xc7\\x8ev\\x1a\\xc2\\x03\\xd1\\xd9\\xd2\n\\xc8\\x99\\x88\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xec\\xd7\\xe3\\x82\\xd2q]dL\\xdf.g?\\xe7\\xba\\x98\\xae\\x1c\\x0fO\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xa8m\\xc6\\xa23\\xeb3\\x96\\x10\\xf3\\xedAI'\\xc5Y\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdd\\xfb\\x16\\xcdI1\\xc9s\\xa2\\x03}?\\xc8:M}w]\\x05\\xe4\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00x\\xf2\\xfc\\xaa`\\x1f/\\xb4\\xeb\\xc97\\xbaS.uI \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x94\\x05\\x00\\x000\\x82\\x05\\x900\\x82\\x03x\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x05\\x9b\\x1bW\\x9e\\x8e!2\\xe29\\x07\\xbd\\xa7wu"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2008,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2009,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe4\\xa6\\x8a\\xc8T\\xacRBF\n\\xfdrH\\x1b*D\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x08\\x00\\x00S\\x00\\x00\\x00\\x01\\x00\\x00\\x00@\\x00\\x00\\x000>0\\x1f\\x06\t`\\x86H\\x01\\x86\\xfdl\\x02\\x010\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc00\\x1b\\x06\\x05g\\x81\\x0c\\x01\\x030\\x120\\x10\\x06\n+\\x06\\x01\\x04\\x01\\x827<\\x01\\x01\\x03\\x02\\x00\\xc0\t\\x00\\x00\\x00\\x01\\x00\\x00\\x004\\x00\\x00\\x0002\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x04\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00D\\x00i\\x00g\\x00i\\x00C\\x00e\\x00r\\x00t\\x00 \\x00G\\x00l\\x00o\\x00b\\x00a\\x00l\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00G\\x002\\x00\\x00\\x00b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00\\xcb<\\xcb\\xb7`1\\xe5\\xe0\\x13\\x8f\\x8d\\xd3\\x9a#\\xf9\\xdeG\\xff\\xc3^C\\xc1\\x14L\\xea'\\xd4jZ\\xb1\\xcb_\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00N\"T \\x18\\x95\\xe6\\xe3n\\xe6\\x0f\\xfa\\xfa\\xb9\\x12\\xed\\x06\\x17\\x8f9\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00}\\xc3\\x0b\\xc9tiU`\\xa2\\xf0\t\neEUl\\x7f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x0c\\x00\\x00\\x000\n\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03~\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x08\\x00\\x00\\x00\\x00\\x80\\xc8+h\\x86\\xd7\\x01\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xdf<$\\xf9\\xbf\\xd6fv\\x1b&\\x80s\\xfe\\x06\\xd1\\xcc\\x8dO\\x82\\xa4\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00KN\\xb4\\xb0t)\\x8b\\x82\\x8b\\\\x000\\x95\\xa1\\x0bE#\\xfb\\x95\\x1c\\x0c\\x884\\x8b\t\\xc5>[\\xab\\xa4\\x08\\xa3\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x14\\xc3\\xbd5I\\xee\"Z\\xec\\xe174\\xad\\x8c\\xa0\\xb8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x92\\x03\\x00\\x000\\x82\\x03\\x8e"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2010,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,530",
        "eid": 2011,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\F40042E2E5F7E8EF8189FED15519AECE42C3BFA2\\Blob",
          "content": "\\\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x04\\x00\\x00\\x00\\x00\\x10\\x00\\x00\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xbe\\x95O\\x16\\x01!\"D\\x8c\\xa8\\xbc'\\x96\\x02\\xac\\xf5\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xf4\\x00B\\xe2\\xe5\\xf7\\xe8\\xef\\x81\\x89\\xfe\\xd1U\\x19\\xae\\xceB\\xc3\\xbf\\xa2\\x1d\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xe7\\x89!\\xf8\\x1c\\xeaMA\\x05\\xd2\\xb5\\xf4\\xaf\\xae\\x0cx\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xc8~\\xd2j\\x85*\\x1b\\xca\\x19\\x98\\x04\\x07'\\xcfP\\x10Oh\\xa8\\xa2\t\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x16\\x00\\x00\\x000\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x03\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x08b\\x00\\x00\\x00\\x01\\x00\\x00\\x00 \\x00\\x00\\x00Sg\\xf2\\x0cz\\xde\\x0e+\\xcay\t\\x15\\x05m\\x08kr\\x0c3\\xc1\\xfa*&a\\xac\\xf7\\x87\\xe3).\\x12p\\x0b\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x80\\x00\\x00\\x00M\\x00i\\x00c\\x00r\\x00o\\x00s\\x00o\\x00f\\x00t\\x00 \\x00I\\x00d\\x00e\\x00n\\x00t\\x00i\\x00t\\x00y\\x00 \\x00V\\x00e\\x00r\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00i\\x00o\\x00n\\x00 \\x00R\\x00o\\x00o\\x00t\\x00 \\x00C\\x00e\\x00r\\x00t\\x00i\\x00f\\x00i\\x00c\\x00a\\x00t\\x00e\\x00 \\x00A\\x00u\\x00t\\x00h\\x00o\\x00r\\x00i\\x00t\\x00y\\x00 \\x002\\x000\\x002\\x000\\x00\\x00\\x00\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x000\\x00\\x00\\x00A\\xce\\x92Vx\\xdf\\xe0\\xcc\\xaa\\x80\\x89&<$+\\x89|\\xa5\\x82\\x08\\x9d\\x14\\xe5\\xebh_\\xca\\x96\\x7f6\\xdb\\xd34\\xe9~\\x81\\xfd\\x0ed\\x81_\\x85\\x1f\\x91J\\xde\\x1a\\x1e\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x9fhu\\x81\\xf7\\xeftN\\xcf\\xc1+\\x9c\\xeeb8\\xf1 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xd0\\x05\\x00\\x000\\x82\\x05\\xcc0\\x82\\x03\\xb4\\xa0\\x03\\x02\\x01\\x02\\x02\\x10T\\x98\\xd2\\xd1\\xd4[\\x19\\x95H\\x13y\\xc8\\x11\\xc0\\x87\\x990\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x0c\\x05\\x000w1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2012,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2013,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2014,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2015,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\UserenvDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2016,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\GpSvcDebugLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,546",
        "eid": 2017,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2018,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2019,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\109F1CAED645BB78B3EA2B94C0697C740733031C\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x83\\xb6S\\x18fNo\\xa2E\\xe0\\xd7`\\x9f\\xb9X \\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x10\\x9f\\x1c\\xae\\xd6E\\xbbx\\xb3\\xea+\\x94\\xc0i|t\\x073\\x03\\x1c\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00&]\\x05\\x07\\xd8/\\xa2`\\x84\\xbd\\x83}\\xf5!\\x80\\xa7\\x05oZ\\x85 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x13\\x04\\x00\\x000\\x82\\x04\\x0f0\\x82\\x02\\xf7\\xa0\\x03\\x02\\x01\\x02\\x02\n\\x19\\x8b\\x11\\xd1?\\x9a\\x8f\\xfei\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000p1+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation1!0\\x1f\\x06\\x03U\\x04\\x03\\x13\\x18Microsoft Root Authority0\\x1e\\x17\r971001070000Z\\x17\r021231070000Z0\\x81\\xc31+0)\\x06\\x03U\\x04\\x0b\\x13\"Copyright (c) 1997 Microsoft Corp.1A0?\\x06\\x03U\\x04\\x0b\\x138Microsoft Windows Hardware Compatibility Intermediate CA1\\x1e0\\x1c\\x06\\x03U\\x04\\x0b\\x13\\x15Microsoft Corporation110/\\x06\\x03U\\x04\\x03\\x13(Microsoft Windows Hardware Compatibility0\\x81\\x9f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03\\x81\\x8d\\x000\\x81"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2020,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2021,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\D559A586669B08F46A30A133F8A9ED3D038E2EA8\\Blob",
          "content": "\\x04\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xac\\xd8\\x0e\\xa2{\\xb7,\\xe7\\x00\\xdc\"rJ_\\x1e\\x92\\x0f\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00Is\\xe0\\x92\\xcf\\x8a\\x9e,\\xa5\\xf9\\x88I:[\\xac\\xfe8\\x95\\x94.\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\n\\xcf\\xebK\\x07\\xe7\\x03\\xa0\\x1fL\\xef(\\xeerV\\xf7Qu\\x91U\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00n\\xd6\\xed}\\xf5/\\xc1\\x9b\\xdc\\x9e_\\xe9\\xe2\\xbe!\\xfb\\x18\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\x91\\x16\\x1b\\x89K\\x11~\\xcd\\xc2Wb\\x8d\\xb4`\\xcc\\x04\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xd5Y\\xa5\\x86f\\x9b\\x08\\xf4j0\\xa13\\xf8\\xa9\\xed=\\x03\\x8e.\\xa8 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x87\\x03\\x00\\x000\\x82\\x03\\x830\\x82\\x02\\xec\\xa0\\x03\\x02\\x01\\x02\\x02\\x10F\\xfc\\xeb\\xba\\xb4\\xd0/\\x0f\\x92`\\x98#?\\x93\\x07\\x8f0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x05\\x05\\x000_1\\x0b0\t\\x06\\x03U\\x04\\x06\\x13\\x02US1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1705\\x06\\x03U\\x04\\x0b\\x13.Class 3 Public Primary Certification Authority0\\x1e\\x17\r970417000000Z\\x17\r161024235959Z0\\x81\\xba1\\x1f0\\x1d\\x06\\x03U\\x04\n\\x13\\x16VeriSign Trust Network1\\x170\\x15\\x06\\x03U\\x04\\x0b\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign International Server CA - Class 31I0G\\x06\\x03U\\x04\\x0b\\x13@www.verisign.com/CPS"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2022,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,561",
        "eid": 2023,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\Certificates\\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\\Blob",
          "content": "\\x19\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x10\\x00\\x00\\x00\\xed\\xbc\\xcd\\xd5\\x10j\\x07\\x1c]\\x8bF\\x90\\x91\\x8eH\\xaa\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xfe\\xe4I\\xee\\x0e9e\\xa5$o\\x00\\x0e\\x87\\xfd\\xe2\\xa0e\\xfd\\x89\\xd4\\x14\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\x9a\\xa6X\\x7f\\x94\\xdd\\x91\\xd9\\x1ec\\xdf\\xd3\\xf0\\xce_\\xae\\x18\\x93\\xaa\\xb7 \\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xce\\x01\\x00\\x000\\x82\\x01\\xca0\\x82\\x01t\\xa0\\x03\\x02\\x01\\x02\\x02\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x000\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0\\x1e\\x17\r960528220259Z\\x17\r391231235959Z0\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency0[0\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x01\\x05\\x00\\x03J\\x000G\\x02@\\x81U\"\\xb9\\x8a\\xa4o\\xed\\xd6\\xe7\\xd9f\\x0fU\\xbc\\xd7\\xcd\\xd5\\xbcN@\\x02!\\xa2\\xb1\\xf7\\x870\\x85^\\xd2\\xf2D\\xb9\\xdc\\x9bu\\xb6\\xfbF_B\\xb6\\x9d#6\\x0b\\xdeT\\x0f\\xcd\\xbd\\x1f\\x99*\\x10X\\x11\\xcb@\\xcb\\xb5\\xa7A\\x02\\x03\\x01\\x00\\x01\\xa3\\x81\\x9e0\\x81\\x9b0P\\x06\\x03U\\x04\\x03\\x04I\\x13GFor Testing Purposes Only Sample Software Publishing Credentials Agency0G\\x06\\x03U\\x1d\\x01\\x04@0>\\x80\\x10\\x12\\xe4\t-\\x06\\x1d\\x1dO\\x00\\x8da!\\xdc\\x16dc\\xa1\\x180\\x161\\x140\\x12\\x06\\x03U\\x04\\x03\\x13\\x0bRoot Agency\\x82\\x10\\x067l\\x00\\xaa\\x00d\\x8a\\x11\\xcf\\xb8\\xd4\\xaa\\5\\xf40\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x04\\x05\\x00\\x03A\\x00-.>{\\x89B\\x89?\\xa8!"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,577",
        "eid": 2024,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,577",
        "eid": 2025,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\CA\\CRLs\\A377D1B1C0538833035211F4083D00FECC414DAB\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x14\\x00\\x00\\x00\\xa3w\\xd1\\xb1\\xc0S\\x883\\x03R\\x11\\xf4\\x08=\\x00\\xfe\\xccAM\\xab!\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\xb5\\x01\\x00\\x000\\x82\\x01\\xb10\\x82\\x01\\x1a\\x02\\x01\\x010\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x000a1\\x110\\x0f\\x06\\x03U\\x04\\x07\\x13\\x08Internet1\\x170\\x15\\x06\\x03U\\x04\n\\x13\\x0eVeriSign, Inc.1301\\x06\\x03U\\x04\\x0b\\x13*VeriSign Commercial Software Publishers CA\\x17\r010324000000Z\\x17\r040107235959Z0i0!\\x02\\x10\\x1bQ\\x90\\xf77$9\\x9c\\x92T\\xcdBF7\\x99j\\x17\r010130000124Z0!\\x02\\x10u\\x0e@\\xff\\x97\\xf0G\\xed\\xf5V\\xc7\\x08N\\xb1\\xab\\xfd\\x17\r010131000049Z0!\\x02\\x10w\\xe6ZCY\\x93]_zu\\x80\\x1a\\xcd\\xad\\xc2\"\\x17\r000831000056Z\\xa0\\x1a0\\x180\t\\x06\\x03U\\x1d\\x13\\x04\\x020\\x000\\x0b\\x06\\x03U\\x1d\\x0f\\x04\\x04\\x03\\x02\\x05\\xa00\r\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x01\\x02\\x05\\x00\\x03\\x81\\x81\\x00\\x18,\\xe8\\xfc\\x16m\\x91J=\\x88TH]\\xb8\\x11\\xbfd\\xbb\\xf9\\xdaY\\x19\\xdd\\x0ee\\xab\\xc0\\x0c\\xfag~!\\x1e\\x83\\x0e\\xcf\\x9b\\x89\\x8a\\xcf\\x0cK\\xc19\\x9d\\xe7j\\xacFtj\\x91b\"\r\\xc4\\x08\\xbd\\xf5\n\\x90\\x7f\\x06!=~\\xa7\\xaa^\\xcd\"\\x15\\xe6\\x0cu\\x8en\\xad\\xf1\\x84\\xe4\"\\xb40o\\xfbd\\x8f\\xd7\\x80C\\xf5\\x19\\x18f\\x1dr\\xa3\\xe3\\x94\\x82(R\\xa0\\x06N\\xb1\\xc8\\x92\\x0c\\x97\\xbe\\x15\\x07\\xabz\\xc9\\xea\\x08gCMQc;\\x9c\\x9c\\xcd"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,577",
        "eid": 2026,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,577",
        "eid": 2027,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2028,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertLastSyncTime",
          "content": "\\xb3@\\xd9\\xb0n\\x9a\\xdc\\x01"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2029,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2030,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\AutoUpdate\\DisallowedCertEncodedCtl",
          "content": "0\\x82\\x17\\xcc\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x17\\xbd0\\x82\\x17\\xb9\\x02\\x01\\x011\\x0f0\r\\x06\t`\\x86H\\x01e\\x03\\x04\\x02\\x01\\x05\\x000\\x82\\x08(\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x08\\x190\\x82\\x08\\x150\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x048D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00A\\x00u\\x00t\\x00o\\x00U\\x00p\\x00d\\x00a\\x00t\\x00e\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xdc\\x1e\\x14\\x131$\\xbf\\x17\r250905032048Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x07\\xa00\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<\\xac\\xeejW0\\x12\\x04\\x10\\x1e%\\xf2N\\xdf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2031,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2032,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\DisableAutoFlushProcessNameList",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2033,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushFirstDeltaSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,592",
        "eid": 2034,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CertDllCreateCertificateChainEngine\\Config\\AutoFlushNextDeltaSeconds",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,655",
        "eid": 2035,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,671",
        "eid": 2036,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,671",
        "eid": 2037,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,671",
        "eid": 2038,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,717",
        "eid": 2039,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,717",
        "eid": 2040,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,717",
        "eid": 2041,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "WintrustCertificateTrust"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2042,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2043,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverFinalPolicy"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2044,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2045,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverInitializePolicy"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2046,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2047,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadMessage"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2048,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2049,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadSignature"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2050,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2051,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "SoftpubCheckCert"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2052,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2053,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\$Function",
          "content": "DriverCleanupPolicy"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2054,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2055,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2056,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\WinTrust\\Trust Providers\\Software Publishing\\State",
          "content": "146432"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2057,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2058,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Certificate\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "WintrustCertificateTrust"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2059,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2060,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubAuthenticode"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2061,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2062,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Initialization\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubInitialize"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2063,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2064,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Message\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadMessage"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2065,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2066,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Signature\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubLoadSignature"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2067,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2068,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\CertCheck\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubCheckCert"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2069,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$DLL",
          "content": "WINTRUST.DLL"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,733",
        "eid": 2070,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Providers\\Trust\\Cleanup\\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\\$Function",
          "content": "SoftpubCleanup"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2071,
        "data": {
          "file": "crypt32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0b90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2072,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2073,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\sCurrency",
          "content": "\\x20bd"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2074,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Control Panel\\International\\iCalendarType",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2075,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru-RU",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,749",
        "eid": 2076,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Sorting\\Ids\\ru",
          "content": "{0000004A-57EE-1E5C-00B4-D0000BB1E11E}"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2077,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2078,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2079,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2080,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2081,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2082,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2083,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2084,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2085,
        "data": {
          "regkey": "HKEY_USERS\\.DEFAULT\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2086,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2087,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2088,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2089,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2090,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2091,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2092,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2093,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\SystemCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2094,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2095,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2096,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\SystemCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2097,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2098,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\EnterpriseCertificates\\Disallowed"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,764",
        "eid": 2099,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\Certificates"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,780",
        "eid": 2100,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CRLs"
        }
      },
      {
        "event": "write",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,780",
        "eid": 2101,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\EnterpriseCertificates\\Disallowed\\CTLs"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,780",
        "eid": 2102,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,780",
        "eid": 2103,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\Disallowed\\CTLs\\27748148BBE67A43CDBFEC6C3784862CE134E6EA\\Blob",
          "content": "\\x03\\x00\\x00\\x00\\x01\\x00\\x01\\x00\\x14\\x00\\x00\\x00't\\x81H\\xbb\\xe6zC\\xcd\\xbf\\xecl7\\x84\\x86,\\xe14\\xe6\\xea\"\\x00\\x00\\x00\\x01\\x00\\x01\\x00*\\x02\\x00\\x000\\x82\\x02&\\x06\t*\\x86H\\x86\\xf7\r\\x01\\x07\\x02\\xa0\\x82\\x02\\x170\\x82\\x02\\x13\\x02\\x01\\x011\\x000\\x82\\x02\\x08\\x06\t+\\x06\\x01\\x04\\x01\\x827\n\\x01\\xa0\\x82\\x01\\xf90\\x82\\x01\\xf50\\x0c\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x03\\x1e\\x04(D\\x00i\\x00s\\x00a\\x00l\\x00l\\x00o\\x00w\\x00e\\x00d\\x00C\\x00e\\x00r\\x00t\\x00_\\x00O\\x00S\\x00_\\x001\\x00\\x00\\x00\\x02\\x08\\x01\\xcd??\\xac\\xc3\\xee\\x89\\x17\r120531151137Z0\\x0e\\x06\n+\\x06\\x01\\x04\\x01\\x827\n\\x0b\\x0f\\x05\\x000\\x82\\x01\\x900\\x12\\x04\\x10%\\xfbz]\\x86\\xf7/^g(\\x8fys\\x05\\xfe\\x940\\x12\\x04\\x10o-Ce\\xc1\\x02\\x1f[\\x8bc\\xef\\x13+\\xc3\\xb3`0\\x12\\x04\\x10\\xad\\x11\\xdb\\xb7l\\x9c\\xf1\\xab\\x99\\x98\\xcd\\x84.\\xc1vs0\\x12\\x04\\x10\\xdf\\xbd\\xd7/\\x99\\xc3\\xb6Jy~Z\\xc9mY\\xbeV0\\x12\\x04\\x10\\xc6h\\x15K\\xe9^\\x16\\xad\\xbc2\\x1a\\xbc1n8J0\\x12\\x04\\x1079.\\x83=\\xc6\\x05\\xdd{8$G9\\x93\\x9e\\xe30\\x12\\x04\\x101y\\xfeKW&\\xd8\\xdb*\\xaf=\\xf9X\\xc9k\\x970\\x12\\x04\\x10\\xc3Z\\x97\\xc8\\x0fh}\\xc3\\xc1\\x08\\xc6\\xa33\\x9bhF0\\x12\\x04\\x10!\\x18\\xa4\\xc6\\xf7\\x18\\xcf\\xc7\\xd6\\xd8x\\x8cSt\\xd3)0\\x12\\x04\\x10Rj9\\xc0M\\x15\\x86-B\\x7f\\xd9%\\xaf\\x036\\x900\\x12\\x04\\x10<6\\xe1h\\xab\\xcc\\x85\\x96c\\xedG\\xa0\\xc0Z\\xeey0\\x12\\x04\\x10\\x01\\x9e}V\\xd6\r\\xb9\\xad\\xec@\\xb9g\\xb1\\xbc\\xba\\x9f0\\x12\\x04\\x106\\xcd\\xe9\\x9a\\xb8s\\x7f\\x86(|X7\\x04\\xc9^\\x160\\x12\\x04\\x10&\\x99\nwX~\\xd8d\\x01\\x84\\xc4\\x93f\\xac\\xb0u0\\x12\\x04\\x10\\xf6\\x9d\"\\xae\\x1e\\xd6\\x15\\xb1\\xb9\\xe3\\x90\\xe3\\x10\\xbb\\xbb10\\x12\\x04\\x10\\xeb\\xe9\n\\xd1\\x01\\xd3\\x80+\\x8aL\\x91<"
        }
      },
      {
        "event": "read",
        "object": "file",
        "timestamp": "2026-02-10 09:22:14,811",
        "eid": 2104,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2105,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee3470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2106,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2107,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2108,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\PnpSetupInProgress",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2109,
        "data": {
          "file": "api-ms-win-security-cryptoapi-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee0450000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2110,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2111,
        "data": {
          "file": "C:\\Windows\\System32\\rsaenh.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedfb90000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2112,
        "data": {
          "file": "WINTRUST.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1470000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,827",
        "eid": 2113,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:14,889",
        "eid": 2114,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,952",
        "eid": 2115,
        "data": {
          "file": "kernel32.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1660000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,952",
        "eid": 2116,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:14,952",
        "eid": 2117,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,014",
        "eid": 2118,
        "data": {
          "file": "api-ms-win-core-registry-l1-1-0.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffee1090000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,014",
        "eid": 2119,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:15,077",
        "eid": 2120,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\MinimizeFootprint",
          "content": null
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:15,077",
        "eid": 2121,
        "data": {
          "file": "C:\\Windows\\System32\\CatRoot"
        }
      },
      {
        "event": "create",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:15,077",
        "eid": 2122,
        "data": {
          "file": "C:\\Windows\\System32\\catroot2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:15,092",
        "eid": 2123,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\CatalogDB\\CatDBLogging",
          "content": "1"
        }
      },
      {
        "event": "write",
        "object": "file",
        "timestamp": "2026-02-10 09:22:15,092",
        "eid": 2124,
        "data": {
          "file": "C:\\Windows\\System32\\catroot2\\dberr.txt"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:15,124",
        "eid": 2125,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:15,139",
        "eid": 2126,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
        }
      },
      {
        "event": "delete",
        "object": "file",
        "timestamp": "2026-02-10 09:22:15,171",
        "eid": 2127,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
        }
      },
      {
        "event": "delete",
        "object": "dir",
        "timestamp": "2026-02-10 09:22:15,171",
        "eid": 2128,
        "data": {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,171",
        "eid": 2129,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,233",
        "eid": 2130,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,233",
        "eid": 2131,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:15,233",
        "eid": 2132,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:22:15,233",
        "eid": 2133,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableUmpdBufferSizeCheck",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:22:15,233",
        "eid": 2134,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,338",
        "eid": 2135,
        "data": {
          "file": "C:\\Windows\\system32\\rpcss.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2136,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\STE",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2137,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\Enabled",
          "content": "0"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2138,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2139,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\FipsAlgorithmPolicy\\MDMEnabled",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2140,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2141,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\Com+Enabled",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,354",
        "eid": 2142,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2143,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2144,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2145,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2146,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": ""
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2147,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2148,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2149,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2150,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2151,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2152,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2153,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2154,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2155,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2156,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2157,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2158,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2159,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2160,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2161,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2162,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\Appx\\AllowDevelopmentWithoutDevLicense",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2163,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock\\AllowDevelopmentWithoutDevLicense",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2164,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2165,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseActivationAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2166,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2167,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\AppCompat\\RaiseDefaultAuthnLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2168,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AccessPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2169,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\DefaultAccessPermission",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2170,
        "data": {
          "file": "C:\\Windows\\system32\\rpcss.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2171,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{00000134-0000-0000-C000-000000000046}\\ProxyStubClsid32\\(Default)",
          "content": "{00000320-0000-0000-C000-000000000046}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2172,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\Extensions\\NdrOleExtDLL",
          "content": "combase.dll"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2173,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,370",
        "eid": 2174,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,385",
        "eid": 2175,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2176,
        "data": {
          "file": "C:\\Windows\\System32\\uxtheme.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffede5b0000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2177,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2178,
        "data": {
          "regkey": "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Themes\\Personalize\\AppsUseLightTheme",
          "content": "1"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2179,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2180,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2181,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Class Factory for Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2182,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2183,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2184,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": "C:\\Windows\\System32\\thumbcache.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,401",
        "eid": 2185,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
          "content": "Apartment"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2186,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaxSxSHashCount",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2187,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\GipActivityBypass",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2188,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2189,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2190,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Class Factory for Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2191,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2192,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2193,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\(Default)",
          "content": "C:\\Windows\\System32\\thumbcache.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2194,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\InprocServer32\\ThreadingModel",
          "content": "Apartment"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2195,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppID",
          "content": "{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2196,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2197,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\(Default)",
          "content": "Thumbnail Cache Out of Proc Server"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2198,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LocalService",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2199,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2200,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\DllSurrogate",
          "content": ""
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2201,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RunAs",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2202,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ActivateAtStorage",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2203,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ROTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2204,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AppIDFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2205,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\MGOTFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2206,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProcessMitigationPolicy",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2207,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LaunchPermission",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2208,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyAuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2209,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\LegacyImpersonationLevel",
          "content": "2"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2210,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\AuthenticationLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2211,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\RemoteServerName",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2212,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\SRPTrustLevel",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2213,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\PreferredServerBitness",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2214,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\LoadUserSettings",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,417",
        "eid": 2215,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AppID\\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\\ProtectionLevel",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2216,
        "data": {
          "file": "C:\\Windows\\System32\\thumbcache.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffecda20000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2217,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2218,
        "data": {
          "file": "combase.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2219,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Interface\\{75121952-e0d0-43e5-9380-1d80483acf72}\\ProxyStubClsid32\\(Default)",
          "content": "{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2220,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2221,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2222,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": "PSFactoryBuffer"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2223,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2224,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2225,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": "%SystemRoot%\\system32\\propsys.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2226,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
          "content": "Both"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2227,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\ActivateOnHostFlags",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2228,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2229,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\(Default)",
          "content": "PSFactoryBuffer"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2230,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\InprocServer32",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2231,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": null
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2232,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\(Default)",
          "content": "%SystemRoot%\\system32\\propsys.dll"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,432",
        "eid": 2233,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\InProcServer32\\ThreadingModel",
          "content": "Both"
        }
      },
      {
        "event": "read",
        "object": "registry",
        "timestamp": "2026-02-10 09:23:39,448",
        "eid": 2234,
        "data": {
          "regkey": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\\AppID",
          "content": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,448",
        "eid": 2235,
        "data": {
          "file": "C:\\Windows\\System32\\propsys.dll",
          "pathtofile": null,
          "moduleaddress": "0x7ffedc720000"
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:39,448",
        "eid": 2236,
        "data": {
          "file": null,
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:44,495",
        "eid": 2237,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:44,495",
        "eid": 2238,
        "data": {
          "file": "ntdll.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      },
      {
        "event": "load",
        "object": "library",
        "timestamp": "2026-02-10 09:23:44,495",
        "eid": 2239,
        "data": {
          "file": "oleaut32.dll",
          "pathtofile": null,
          "moduleaddress": null
        }
      }
    ],
    "encryptedbuffers": []
  },
  "debug": {
    "log": "2025-11-20 02:03:42,150 [root] INFO: Date set to: 20260210T12:21:51, timeout set to: 200\n2026-02-10 12:21:51,046 [root] DEBUG: Starting analyzer from: C:\\tsm41i5n\n2026-02-10 12:21:51,046 [root] DEBUG: Storing results at: C:\\nYtPPrAYz\n2026-02-10 12:21:51,046 [root] DEBUG: Pipe server name: \\\\.\\PIPE\\nRifguh\n2026-02-10 12:21:51,047 [root] DEBUG: Python path: C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32\n2026-02-10 12:21:51,047 [root] INFO: analysis running as an admin\n2026-02-10 12:21:51,047 [root] INFO: analysis package specified: \"msi\"\n2026-02-10 12:21:51,047 [root] DEBUG: importing analysis package module: \"modules.packages.msi\"...\n2026-02-10 12:21:51,077 [root] DEBUG: imported analysis package \"msi\"\n2026-02-10 12:21:51,077 [root] DEBUG: initializing analysis package \"msi\"...\n2026-02-10 12:21:51,077 [lib.common.common] INFO: wrapping\n2026-02-10 12:21:51,077 [lib.core.compound] INFO: C:\\Temp already exists, skipping creation\n2026-02-10 12:21:51,078 [root] DEBUG: New location of moved file: C:\\Temp\\E87.20_CheckPointVPN.msi\n2026-02-10 12:21:51,078 [root] INFO: Analyzer: Package modules.packages.msi does not specify a DLL option\n2026-02-10 12:21:51,078 [root] INFO: Analyzer: Package modules.packages.msi does not specify a DLL_64 option\n2026-02-10 12:21:51,078 [root] INFO: Analyzer: Package modules.packages.msi does not specify a loader option\n2026-02-10 12:21:51,078 [root] INFO: Analyzer: Package modules.packages.msi does not specify a loader_64 option\n2026-02-10 12:21:51,123 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.browser\"\n2026-02-10 12:21:51,144 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.digisig\"\n2026-02-10 12:21:51,193 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.disguise\"\n2026-02-10 12:21:51,224 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.human\"\n2026-02-10 12:21:51,237 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'\n2026-02-10 12:21:51,744 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'\n2026-02-10 12:21:51,766 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'\n2026-02-10 12:21:51,858 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance\n2026-02-10 12:21:51,859 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.screenshots\"\n2026-02-10 12:21:51,862 [root] DEBUG: Imported auxiliary module \"modules.auxiliary.tlsdump\"\n2026-02-10 12:21:51,862 [root] DEBUG: Initialized auxiliary module \"Browser\"\n2026-02-10 12:21:51,863 [root] DEBUG: attempting to configure 'Browser' from data\n2026-02-10 12:21:51,864 [root] DEBUG: module Browser does not support data configuration, ignoring\n2026-02-10 12:21:51,864 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.browser\"...\n2026-02-10 12:21:51,865 [root] DEBUG: Started auxiliary module modules.auxiliary.browser\n2026-02-10 12:21:51,865 [root] DEBUG: Initialized auxiliary module \"DigiSig\"\n2026-02-10 12:21:51,865 [root] DEBUG: attempting to configure 'DigiSig' from data\n2026-02-10 12:21:51,866 [root] DEBUG: module DigiSig does not support data configuration, ignoring\n2026-02-10 12:21:51,866 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.digisig\"...\n2026-02-10 12:21:51,866 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature\n2026-02-10 12:21:53,396 [modules.auxiliary.digisig] DEBUG: File has a valid signature\n2026-02-10 12:21:53,397 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json\n2026-02-10 12:21:53,401 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig\n2026-02-10 12:21:53,401 [root] DEBUG: Initialized auxiliary module \"Disguise\"\n2026-02-10 12:21:53,402 [root] DEBUG: attempting to configure 'Disguise' from data\n2026-02-10 12:21:53,402 [root] DEBUG: module Disguise does not support data configuration, ignoring\n2026-02-10 12:21:53,402 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.disguise\"...\n2026-02-10 12:21:53,403 [modules.auxiliary.disguise] INFO: Disguising GUID to 7e28c91c-5807-4e80-9d9b-908f5ec503a2\n2026-02-10 12:21:53,403 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise\n2026-02-10 12:21:53,403 [root] DEBUG: Initialized auxiliary module \"Human\"\n2026-02-10 12:21:53,403 [root] DEBUG: attempting to configure 'Human' from data\n2026-02-10 12:21:53,404 [root] DEBUG: module Human does not support data configuration, ignoring\n2026-02-10 12:21:53,404 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.human\"...\n2026-02-10 12:21:53,406 [root] DEBUG: Started auxiliary module modules.auxiliary.human\n2026-02-10 12:21:53,406 [root] DEBUG: Initialized auxiliary module \"Screenshots\"\n2026-02-10 12:21:53,407 [root] DEBUG: attempting to configure 'Screenshots' from data\n2026-02-10 12:21:53,408 [root] DEBUG: module Screenshots does not support data configuration, ignoring\n2026-02-10 12:21:53,408 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.screenshots\"...\n2026-02-10 12:21:53,408 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots\n2026-02-10 12:21:53,409 [root] DEBUG: Initialized auxiliary module \"TLSDumpMasterSecrets\"\n2026-02-10 12:21:53,409 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data\n2026-02-10 12:21:53,410 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring\n2026-02-10 12:21:53,410 [root] DEBUG: Trying to start auxiliary module \"modules.auxiliary.tlsdump\"...\n2026-02-10 12:21:53,413 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 608\n2026-02-10 12:21:53,674 [lib.api.process] INFO: Monitor config for <Process 608 lsass.exe>: C:\\tsm41i5n\\dll\\608.ini\n2026-02-10 12:21:53,676 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor\n2026-02-10 12:21:53,684 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:21:53,706 [root] DEBUG: Loader: Injecting process 608 with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:21:53,725 [root] DEBUG: 608: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:21:53,726 [root] DEBUG: 608: Disabling sleep skipping.\n2026-02-10 12:21:53,727 [root] DEBUG: 608: TLS secret dump mode enabled.\n2026-02-10 12:21:53,766 [root] DEBUG: 608: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:21:53,768 [root] DEBUG: 608: Monitor initialised: 64-bit capemon loaded in process 608 at 0x00007FFEC03D0000, thread 4344, image base 0x00007FF60EE30000, stack from 0x000000A5F4C73000-0x000000A5F4C80000\n2026-02-10 12:21:53,769 [root] DEBUG: 608: Commandline: C:\\Windows\\system32\\lsass.exe\n2026-02-10 12:21:53,785 [root] DEBUG: 608: Hooked 5 out of 5 functions\n2026-02-10 12:21:53,787 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.\n2026-02-10 12:21:53,788 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:21:53,791 [lib.api.process] INFO: Injected into 64-bit <Process 608 lsass.exe>\n2026-02-10 12:21:53,791 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump\n2026-02-10 12:21:54,207 [root] DEBUG: 608: TLS 1.2 secrets logged to: C:\\nYtPPrAYz\\tlsdump\\tlsdump.log\n2026-02-10 12:21:56,939 [root] INFO: Restarting WMI Service\n2026-02-10 12:21:57,068 [root] DEBUG: package modules.packages.msi does not support configure, ignoring\n2026-02-10 12:21:57,070 [root] WARNING: configuration error for package modules.packages.msi: error importing data.packages.msi: No module named 'data.packages'\n2026-02-10 12:21:57,071 [lib.core.compound] INFO: C:\\Temp already exists, skipping creation\n2026-02-10 12:21:57,085 [lib.api.process] INFO: Successfully executed process from path \"C:\\Windows\\system32\\msiexec.exe\" with arguments \"/I \"C:\\Temp\\E87.20_CheckPointVPN.msi\" /qb ACCEPTEULA=1 LicenseAccepted=1\" with pid 4880\n2026-02-10 12:21:57,086 [lib.api.process] INFO: Monitor config for <Process 4880 msiexec.exe>: C:\\tsm41i5n\\dll\\4880.ini\n2026-02-10 12:21:57,090 [lib.api.process] INFO: 32-bit DLL to inject is C:\\tsm41i5n\\dll\\AmnoyIy.dll, loader C:\\tsm41i5n\\bin\\ZAmYBun.exe\n2026-02-10 12:21:57,109 [root] DEBUG: Loader: Injecting process 4880 (thread 4884) with C:\\tsm41i5n\\dll\\AmnoyIy.dll.\n2026-02-10 12:21:57,111 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:21:57,112 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\AmnoyIy.dll.\n2026-02-10 12:21:57,115 [lib.api.process] INFO: Injected into 32-bit <Process 4880 msiexec.exe>\n2026-02-10 12:21:59,141 [lib.api.process] INFO: Successfully resumed <Process 4880 msiexec.exe>\n2026-02-10 12:21:59,231 [root] DEBUG: 4880: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:21:59,233 [root] DEBUG: 4880: Disabling sleep skipping.\n2026-02-10 12:21:59,234 [root] DEBUG: 4880: Dropped file limit defaulting to 100.\n2026-02-10 12:21:59,236 [root] DEBUG: 4880: MsiExec hook set enabled\n2026-02-10 12:21:59,243 [root] DEBUG: 4880: Monitor initialised: 32-bit capemon loaded in process 4880 at 0x72f10000, thread 4884, image base 0x3b0000, stack from 0x2d33000-0x2d40000\n2026-02-10 12:21:59,244 [root] DEBUG: 4880: Commandline: \"C:\\Windows\\system32\\msiexec.exe\" /I \"C:\\Temp\\E87.20_CheckPointVPN.msi\" /qb ACCEPTEULA=1 LicenseAccepted=1\n2026-02-10 12:21:59,284 [root] DEBUG: 4880: hook_api: LdrpCallInitRoutine export address 0x76FC2B50 obtained via GetFunctionAddress\n2026-02-10 12:21:59,301 [root] DEBUG: 4880: hook_api: combase::CoCreateInstance export address 0x755794C0 differs from GetProcAddress -> 0x731FC790\n2026-02-10 12:21:59,304 [root] DEBUG: 4880: hook_api: Warning - CopyFileA export address 0x76538B60 differs from GetProcAddress -> 0x73217D30 (AcLayers.DLL::0x47d30)\n2026-02-10 12:21:59,304 [root] DEBUG: 4880: hook_api: Warning - CopyFileW export address 0x76543A80 differs from GetProcAddress -> 0x73217E70 (AcLayers.DLL::0x47e70)\n2026-02-10 12:21:59,305 [root] DEBUG: 4880: hook_api: Warning - CopyFileExW export address 0x76539730 differs from GetProcAddress -> 0x73217E00 (AcLayers.DLL::0x47e00)\n2026-02-10 12:21:59,306 [root] DEBUG: 4880: hook_api: Warning - DeleteFileA export address 0x76543400 differs from GetProcAddress -> 0x73218190 (AcLayers.DLL::0x48190)\n2026-02-10 12:21:59,307 [root] DEBUG: 4880: hook_api: Warning - DeleteFileW export address 0x76543410 differs from GetProcAddress -> 0x732181F0 (AcLayers.DLL::0x481f0)\n2026-02-10 12:21:59,312 [root] WARNING: b'Unable to place hook on GetCommandLineA'\n2026-02-10 12:21:59,313 [root] DEBUG: 4880: set_hooks: Unable to hook GetCommandLineA\n2026-02-10 12:21:59,314 [root] WARNING: b'Unable to place hook on GetCommandLineW'\n2026-02-10 12:21:59,315 [root] DEBUG: 4880: set_hooks: Unable to hook GetCommandLineW\n2026-02-10 12:21:59,333 [root] DEBUG: 4880: Hooked 625 out of 627 functions\n2026-02-10 12:21:59,341 [root] DEBUG: 4880: RestoreHeaders: Restored original import table.\n2026-02-10 12:21:59,342 [root] INFO: Loaded monitor into process with pid 4880\n2026-02-10 12:21:59,343 [root] DEBUG: 4880: caller_dispatch: Added region at 0x003B0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x003B9C3B, thread 4884).\n2026-02-10 12:21:59,344 [root] DEBUG: 4880: ProcessImageBase: Main module image at 0x003B0000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:21:59,352 [root] DEBUG: 4880: DLL loaded at 0x72CC0000: C:\\Windows\\WinSxS\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\\COMCTL32 (0x210000 bytes).\n2026-02-10 12:21:59,380 [root] DEBUG: 4880: DLL loaded at 0x72A20000: C:\\Windows\\System32\\msi (0x299000 bytes).\n2026-02-10 12:21:59,395 [root] DEBUG: 4880: set_hooks_by_export_directory: Hooked 0 out of 627 functions\n2026-02-10 12:21:59,396 [root] DEBUG: 4880: DLL loaded at 0x73B80000: C:\\Windows\\SYSTEM32\\kernel.appcore (0xf000 bytes).\n2026-02-10 12:21:59,397 [root] DEBUG: 4880: DLL loaded at 0x729F0000: C:\\Windows\\System32\\srpapi (0x25000 bytes).\n2026-02-10 12:21:59,408 [root] DEBUG: 4880: DLL loaded at 0x75800000: C:\\Windows\\System32\\bcryptPrimitives (0x5f000 bytes).\n2026-02-10 12:21:59,409 [root] DEBUG: 4880: DLL loaded at 0x75720000: C:\\Windows\\System32\\coml2 (0x5e000 bytes).\n2026-02-10 12:21:59,432 [root] DEBUG: 4880: DLL loaded at 0x739F0000: C:\\Windows\\system32\\uxtheme (0x74000 bytes).\n2026-02-10 12:21:59,435 [root] DEBUG: 4880: DLL loaded at 0x76BD0000: C:\\Windows\\System32\\MSCTF (0xd4000 bytes).\n2026-02-10 12:21:59,462 [root] DEBUG: 4880: DLL loaded at 0x725E0000: C:\\Windows\\SYSTEM32\\ntmarta (0x29000 bytes).\n2026-02-10 12:21:59,463 [root] DEBUG: 4880: DLL loaded at 0x72610000: C:\\Windows\\System32\\CoreMessaging (0x9b000 bytes).\n2026-02-10 12:21:59,464 [root] DEBUG: 4880: DLL loaded at 0x72500000: C:\\Windows\\SYSTEM32\\wintypes (0xdc000 bytes).\n2026-02-10 12:21:59,465 [root] DEBUG: 4880: DLL loaded at 0x726B0000: C:\\Windows\\System32\\CoreUIComponents (0x27f000 bytes).\n2026-02-10 12:21:59,466 [root] DEBUG: 4880: DLL loaded at 0x72930000: C:\\Windows\\SYSTEM32\\textinputframework (0xb9000 bytes).\n2026-02-10 12:21:59,473 [root] DEBUG: 4880: DLL loaded at 0x747A0000: C:\\Windows\\SYSTEM32\\Wldp (0x24000 bytes).\n2026-02-10 12:21:59,474 [root] DEBUG: 4880: DLL loaded at 0x747D0000: C:\\Windows\\SYSTEM32\\windows.storage (0x613000 bytes).\n2026-02-10 12:21:59,477 [root] DEBUG: 4880: DLL loaded at 0x73C20000: C:\\Windows\\SYSTEM32\\PROPSYS (0xc2000 bytes).\n2026-02-10 12:21:59,498 [root] DEBUG: 4880: DLL loaded at 0x72460000: C:\\Windows\\SYSTEM32\\TextShaping (0x95000 bytes).\n2026-02-10 12:21:59,526 [root] DEBUG: 4880: DLL loaded at 0x72440000: C:\\Windows\\System32\\NETAPI32 (0x14000 bytes).\n2026-02-10 12:21:59,528 [root] DEBUG: 4880: DLL loaded at 0x72420000: C:\\Windows\\System32\\WKSCLI (0x11000 bytes).\n2026-02-10 12:21:59,534 [root] DEBUG: 4880: DLL loaded at 0x72410000: C:\\Windows\\System32\\NETUTILS (0xb000 bytes).\n2026-02-10 12:21:59,537 [lib.api.process] INFO: Monitor config for <Process 740 svchost.exe>: C:\\tsm41i5n\\dll\\740.ini\n2026-02-10 12:21:59,541 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:21:59,553 [root] DEBUG: Loader: Injecting process 740 with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:21:59,557 [root] DEBUG: 740: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:21:59,558 [root] DEBUG: 740: Disabling sleep skipping.\n2026-02-10 12:21:59,558 [root] DEBUG: 740: Dropped file limit defaulting to 100.\n2026-02-10 12:21:59,561 [root] DEBUG: 740: Services hook set enabled\n2026-02-10 12:21:59,583 [root] DEBUG: 740: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:21:59,584 [root] DEBUG: 740: Monitor initialised: 64-bit capemon loaded in process 740 at 0x00007FFEC03D0000, thread 1704, image base 0x00007FF630560000, stack from 0x000000A00B872000-0x000000A00B880000\n2026-02-10 12:21:59,584 [root] DEBUG: 740: Commandline: C:\\Windows\\system32\\svchost.exe -k DcomLaunch -p\n2026-02-10 12:21:59,607 [root] DEBUG: 740: Hooked 69 out of 69 functions\n2026-02-10 12:21:59,609 [root] INFO: Loaded monitor into process with pid 740\n2026-02-10 12:21:59,610 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.\n2026-02-10 12:21:59,611 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:21:59,614 [lib.api.process] INFO: Injected into 64-bit <Process 740 svchost.exe>\n2026-02-10 12:22:01,628 [root] DEBUG: 4880: DLL loaded at 0x76EA0000: C:\\Windows\\System32\\clbcatq (0x7e000 bytes).\n2026-02-10 12:22:01,718 [root] INFO: Announced starting service \"b'msiserver'\"\n2026-02-10 12:22:01,719 [lib.api.process] INFO: Monitor config for <Process 600 services.exe>: C:\\tsm41i5n\\dll\\600.ini\n2026-02-10 12:22:01,723 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:01,733 [root] DEBUG: Loader: Injecting process 600 with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:01,737 [root] DEBUG: Loader: Copied config file C:\\tsm41i5n\\dll\\600.ini to system path C:\\600.ini\n2026-02-10 12:22:01,751 [root] DEBUG: Loader: Unable to open process, launched: PPLinject64.exe 600 C:\\tsm41i5n\\dll\\eSAgRU.dll\n2026-02-10 12:22:01,751 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:01,754 [lib.api.process] INFO: Injected into 64-bit <Process 600 services.exe>\n2026-02-10 12:22:03,849 [root] DEBUG: 4880: api-rate-cap: memcpy hook disabled due to rate\n2026-02-10 12:22:10,080 [root] DEBUG: 740: DLL loaded at 0x00007FFEC7F70000: c:\\windows\\system32\\DEVRTL (0x14000 bytes).\n2026-02-10 12:22:10,094 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 2964: C:\\Windows\\system32\\DrvInst.exe, ImageBase: 0x00007FF70A390000\n2026-02-10 12:22:10,096 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 2964\n2026-02-10 12:22:10,097 [lib.api.process] INFO: Monitor config for <Process 2964 drvinst.exe>: C:\\tsm41i5n\\dll\\2964.ini\n2026-02-10 12:22:10,121 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:10,140 [root] DEBUG: Loader: Injecting process 2964 (thread 348) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:10,142 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:22:10,143 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:10,150 [lib.api.process] INFO: Injected into 64-bit <Process 2964 drvinst.exe>\n2026-02-10 12:22:10,153 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 2964\n2026-02-10 12:22:10,153 [lib.api.process] INFO: Monitor config for <Process 2964 drvinst.exe>: C:\\tsm41i5n\\dll\\2964.ini\n2026-02-10 12:22:10,156 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:10,166 [root] DEBUG: Loader: Injecting process 2964 (thread 348) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:10,167 [root] DEBUG: InjectDllViaIAT: This image has already been patched.\n2026-02-10 12:22:10,168 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:10,170 [lib.api.process] INFO: Injected into 64-bit <Process 2964 drvinst.exe>\n2026-02-10 12:22:10,185 [root] DEBUG: 2964: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:22:10,186 [root] DEBUG: 2964: Dropped file limit defaulting to 100.\n2026-02-10 12:22:10,192 [root] DEBUG: 2964: Disabling sleep skipping.\n2026-02-10 12:22:10,205 [root] DEBUG: 2964: YaraInit: Compiled 43 rule files\n2026-02-10 12:22:10,208 [root] DEBUG: 2964: YaraInit: Compiled rules saved to file C:\\tsm41i5n\\data\\yara\\capemon.yac\n2026-02-10 12:22:10,233 [root] DEBUG: 2964: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:22:10,234 [root] DEBUG: 2964: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:10,240 [root] DEBUG: 2964: Monitor initialised: 64-bit capemon loaded in process 2964 at 0x00007FFEC03D0000, thread 348, image base 0x00007FF70A390000, stack from 0x000000A1D1E72000-0x000000A1D1E80000\n2026-02-10 12:22:10,241 [root] DEBUG: 2964: Commandline: DrvInst.exe \"4\" \"1\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\\vnaap.inf\" \"9\" \"4b8ec8843\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000F3C\" \"208\" \"c:\\program files (x86)\\checkpoint\\endpoint connect\"\n2026-02-10 12:22:10,254 [root] DEBUG: 2964: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress\n2026-02-10 12:22:10,305 [root] WARNING: b'Unable to place hook on LockResource'\n2026-02-10 12:22:10,306 [root] DEBUG: 2964: set_hooks: Unable to hook LockResource\n2026-02-10 12:22:10,318 [root] DEBUG: 2964: Hooked 619 out of 620 functions\n2026-02-10 12:22:10,324 [root] DEBUG: 2964: Syscall hook installed, syscall logging level 1\n2026-02-10 12:22:10,334 [root] DEBUG: 2964: RestoreHeaders: Restored original import table.\n2026-02-10 12:22:10,335 [root] INFO: Loaded monitor into process with pid 2964\n2026-02-10 12:22:10,338 [root] DEBUG: 2964: caller_dispatch: Added region at 0x00007FF70A390000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70A3C9CF1, thread 348).\n2026-02-10 12:22:10,339 [root] DEBUG: 2964: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:10,345 [root] DEBUG: 2964: ProcessImageBase: Main module image at 0x00007FF70A390000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:22:10,347 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ￎ￲￪￠￧￠￭￮ ￢ ￤￮￱￲￳￯￥.\n2026-02-10 12:22:10,348 [root] DEBUG: 2964: OpenProcessHandler: Injection info created for process 740, handle 0x1f8: Error obtaining target process name\n2026-02-10 12:22:10,352 [root] DEBUG: 2964: DLL loaded at 0x00007FFEC7F70000: C:\\Windows\\system32\\DEVRTL (0x14000 bytes).\n2026-02-10 12:22:10,356 [root] DEBUG: 2964: DLL loaded at 0x00007FFECED50000: C:\\Windows\\system32\\drvstore (0x148000 bytes).\n2026-02-10 12:22:10,368 [root] INFO: Added new file to list with pid None and path C:\\Windows\\INF\\setupapi.dev.log\n2026-02-10 12:22:10,494 [root] DEBUG: 2964: DLL loaded at 0x00007FFED9750000: C:\\Windows\\system32\\cabinet (0x29000 bytes).\n2026-02-10 12:22:10,516 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp\n2026-02-10 12:22:10,535 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp\n2026-02-10 12:22:10,568 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp\n2026-02-10 12:22:10,585 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp\n2026-02-10 12:22:10,617 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp\n2026-02-10 12:22:10,634 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp\n2026-02-10 12:22:10,677 [root] DEBUG: 2964: DLL loaded at 0x00007FFEE0690000: C:\\Windows\\system32\\MSASN1 (0x12000 bytes).\n2026-02-10 12:22:10,685 [root] DEBUG: 2964: DLL loaded at 0x00007FFEE0450000: C:\\Windows\\system32\\CRYPTSP (0x18000 bytes).\n2026-02-10 12:22:10,687 [root] DEBUG: 2964: DLL loaded at 0x00007FFEDFB90000: C:\\Windows\\system32\\rsaenh (0x34000 bytes).\n2026-02-10 12:22:10,690 [root] DEBUG: 2964: DLL loaded at 0x00007FFEE1390000: C:\\Windows\\System32\\bcryptPrimitives (0x82000 bytes).\n2026-02-10 12:22:10,737 [root] DEBUG: 2964: DLL loaded at 0x00007FFEE1470000: C:\\Windows\\System32\\WINTRUST (0x67000 bytes).\n2026-02-10 12:22:10,901 [root] DEBUG: 2964: DLL loaded at 0x00007FFEDF420000: C:\\Windows\\SYSTEM32\\gpapi (0x23000 bytes).\n2026-02-10 12:22:11,380 [root] INFO: Added new file to list with pid None and path C:\\Windows\\INF\\oem1.inf\n2026-02-10 12:22:11,460 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.sys\n2026-02-10 12:22:11,472 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.cat\n2026-02-10 12:22:11,477 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vnaap.inf_amd64_ea39d26158cde1be\\vnaap.inf\n2026-02-10 12:22:11,604 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\catroot2\\dberr.txt\n2026-02-10 12:22:11,633 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat to files\\6e8c0cbfe7cb1be818b4095dbbafd4fba04db9b02f4fe592c20afb80934d6388; Size is 11127; Max size: 100000000\n2026-02-10 12:22:11,641 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf to files\\679939d1e3c1e51d32a86c5ce348c58ba3448295b92238e350aee27b45de5c37; Size is 4799; Max size: 100000000\n2026-02-10 12:22:11,658 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys to files\\e1089ec93d636938186c936f9f28f360ef40ff33862e741da002317dbec4cfab; Size is 76208; Max size: 100000000\n2026-02-10 12:22:11,724 [root] DEBUG: 2964: NtTerminateProcess hook: Attempting to dump process 2964\n2026-02-10 12:22:11,725 [root] DEBUG: 2964: DoProcessDump: Skipping process dump as code is identical on disk.\n2026-02-10 12:22:11,741 [root] INFO: Process with pid 2964 has terminated\n2026-02-10 12:22:11,764 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 4644: C:\\Windows\\system32\\DrvInst.exe, ImageBase: 0x00007FF70A390000\n2026-02-10 12:22:11,765 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 4644\n2026-02-10 12:22:11,766 [lib.api.process] INFO: Monitor config for <Process 4644 drvinst.exe>: C:\\tsm41i5n\\dll\\4644.ini\n2026-02-10 12:22:11,772 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:11,783 [root] DEBUG: Loader: Injecting process 4644 (thread 4632) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:11,784 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:22:11,785 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:11,788 [lib.api.process] INFO: Injected into 64-bit <Process 4644 drvinst.exe>\n2026-02-10 12:22:11,789 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 4644\n2026-02-10 12:22:11,790 [lib.api.process] INFO: Monitor config for <Process 4644 drvinst.exe>: C:\\tsm41i5n\\dll\\4644.ini\n2026-02-10 12:22:11,798 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:11,810 [root] DEBUG: Loader: Injecting process 4644 (thread 4632) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:11,814 [root] DEBUG: InjectDllViaIAT: This image has already been patched.\n2026-02-10 12:22:11,815 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:11,817 [lib.api.process] INFO: Injected into 64-bit <Process 4644 drvinst.exe>\n2026-02-10 12:22:11,830 [root] DEBUG: 4644: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:22:11,831 [root] DEBUG: 4644: Dropped file limit defaulting to 100.\n2026-02-10 12:22:11,835 [root] DEBUG: 4644: Disabling sleep skipping.\n2026-02-10 12:22:11,838 [root] DEBUG: 4644: YaraInit: Compiled rules loaded from existing file C:\\tsm41i5n\\data\\yara\\capemon.yac\n2026-02-10 12:22:11,861 [root] DEBUG: 4644: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:22:11,862 [root] DEBUG: 4644: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:11,868 [root] DEBUG: 4644: Monitor initialised: 64-bit capemon loaded in process 4644 at 0x00007FFEC03D0000, thread 4632, image base 0x00007FF70A390000, stack from 0x00000032FA505000-0x00000032FA510000\n2026-02-10 12:22:11,869 [root] DEBUG: 4644: Commandline: DrvInst.exe \"2\" \"211\" \"ROOT\\NET\\0000\" \"C:\\Windows\\INF\\oem1.inf\" \"oem1.inf:daca4e3358f55059:VNA_Apollo.ndi:2.1.3.0:cp_apvna,\" \"4b8ec8843\" \"0000000000000E88\"\n2026-02-10 12:22:11,882 [root] DEBUG: 4644: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress\n2026-02-10 12:22:11,932 [root] WARNING: b'Unable to place hook on LockResource'\n2026-02-10 12:22:11,933 [root] DEBUG: 4644: set_hooks: Unable to hook LockResource\n2026-02-10 12:22:11,944 [root] DEBUG: 4644: Hooked 619 out of 620 functions\n2026-02-10 12:22:11,951 [root] DEBUG: 4644: Syscall hook installed, syscall logging level 1\n2026-02-10 12:22:11,959 [root] DEBUG: 4644: RestoreHeaders: Restored original import table.\n2026-02-10 12:22:11,960 [root] INFO: Loaded monitor into process with pid 4644\n2026-02-10 12:22:11,963 [root] DEBUG: 4644: caller_dispatch: Added region at 0x00007FF70A390000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70A3C9CF1, thread 4632).\n2026-02-10 12:22:11,964 [root] DEBUG: 4644: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:11,971 [root] DEBUG: 4644: ProcessImageBase: Main module image at 0x00007FF70A390000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:22:11,973 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ￎ￲￪￠￧￠￭￮ ￢ ￤￮￱￲￳￯￥.\n2026-02-10 12:22:11,973 [root] DEBUG: 4644: OpenProcessHandler: Injection info created for process 740, handle 0x1ec: Error obtaining target process name\n2026-02-10 12:22:11,979 [root] DEBUG: 4644: DLL loaded at 0x00007FFEC7F70000: C:\\Windows\\system32\\DEVRTL (0x14000 bytes).\n2026-02-10 12:22:11,984 [root] DEBUG: 4644: DLL loaded at 0x00007FFECED50000: C:\\Windows\\system32\\drvstore (0x148000 bytes).\n2026-02-10 12:22:12,014 [root] DEBUG: 4644: DLL loaded at 0x00007FFEE0870000: C:\\Windows\\system32\\DEVOBJ (0x33000 bytes).\n2026-02-10 12:22:12,405 [root] DEBUG: 4644: DLL loaded at 0x00007FFED9750000: C:\\Windows\\system32\\cabinet (0x29000 bytes).\n2026-02-10 12:22:12,832 [root] DEBUG: 4644: NtTerminateProcess hook: Attempting to dump process 4644\n2026-02-10 12:22:12,833 [root] DEBUG: 4644: DoProcessDump: Skipping process dump as code is identical on disk.\n2026-02-10 12:22:12,848 [root] INFO: Process with pid 4644 has terminated\n2026-02-10 12:22:13,021 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 5580: C:\\Windows\\system32\\DllHost.exe, ImageBase: 0x00007FF6F8170000\n2026-02-10 12:22:13,023 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5580\n2026-02-10 12:22:13,023 [lib.api.process] INFO: Monitor config for <Process 5580 dllhost.exe>: C:\\tsm41i5n\\dll\\5580.ini\n2026-02-10 12:22:13,030 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:13,050 [root] DEBUG: Loader: Injecting process 5580 (thread 5584) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,052 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:22:13,053 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,057 [lib.api.process] INFO: Injected into 64-bit <Process 5580 dllhost.exe>\n2026-02-10 12:22:13,063 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5580\n2026-02-10 12:22:13,064 [lib.api.process] INFO: Monitor config for <Process 5580 dllhost.exe>: C:\\tsm41i5n\\dll\\5580.ini\n2026-02-10 12:22:13,070 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:13,092 [root] DEBUG: Loader: Injecting process 5580 (thread 5584) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,093 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:22:13,094 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,098 [lib.api.process] INFO: Injected into 64-bit <Process 5580 dllhost.exe>\n2026-02-10 12:22:13,112 [root] DEBUG: 5580: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:22:13,114 [root] DEBUG: 5580: Dropped file limit defaulting to 100.\n2026-02-10 12:22:13,119 [root] DEBUG: 5580: Disabling sleep skipping.\n2026-02-10 12:22:13,121 [root] DEBUG: 5580: YaraInit: Compiled rules loaded from existing file C:\\tsm41i5n\\data\\yara\\capemon.yac\n2026-02-10 12:22:13,146 [root] DEBUG: 5580: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:22:13,147 [root] DEBUG: 5580: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026\n2026-02-10 12:22:13,149 [root] DEBUG: 5580: Monitor initialised: 64-bit capemon loaded in process 5580 at 0x00007FFEC03D0000, thread 5584, image base 0x00007FF6F8170000, stack from 0x000000659BCF5000-0x000000659BD00000\n2026-02-10 12:22:13,149 [root] DEBUG: 5580: Commandline: C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\n2026-02-10 12:22:13,164 [root] DEBUG: 5580: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress\n2026-02-10 12:22:13,218 [root] WARNING: b'Unable to place hook on LockResource'\n2026-02-10 12:22:13,219 [root] DEBUG: 5580: set_hooks: Unable to hook LockResource\n2026-02-10 12:22:13,235 [root] DEBUG: 5580: Hooked 619 out of 620 functions\n2026-02-10 12:22:13,237 [root] DEBUG: 5580: Syscall hook installed, syscall logging level 1\n2026-02-10 12:22:13,244 [root] DEBUG: 5580: RestoreHeaders: Restored original import table.\n2026-02-10 12:22:13,246 [root] INFO: Loaded monitor into process with pid 5580\n2026-02-10 12:22:13,248 [root] DEBUG: 5580: caller_dispatch: Added region at 0x00007FF6F8170000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F81712F2, thread 5584).\n2026-02-10 12:22:13,249 [root] DEBUG: 5580: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026\n2026-02-10 12:22:13,252 [root] DEBUG: 5580: ProcessImageBase: Main module image at 0x00007FF6F8170000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:22:13,257 [root] DEBUG: 5580: set_hooks_by_export_directory: Hooked 0 out of 620 functions\n2026-02-10 12:22:13,258 [root] DEBUG: 5580: DLL loaded at 0x00007FFEDEA70000: C:\\Windows\\SYSTEM32\\kernel.appcore (0x12000 bytes).\n2026-02-10 12:22:13,260 [root] DEBUG: 5580: DLL loaded at 0x00007FFEE1390000: C:\\Windows\\System32\\bcryptPrimitives (0x82000 bytes).\n2026-02-10 12:22:13,266 [root] DEBUG: 5580: DLL loaded at 0x00007FFEE2C20000: C:\\Windows\\System32\\clbcatq (0xa9000 bytes).\n2026-02-10 12:22:13,300 [root] DEBUG: 5580: DLL loaded at 0x00007FFEDE5B0000: C:\\Windows\\system32\\uxtheme (0x9e000 bytes).\n2026-02-10 12:22:13,337 [root] DEBUG: 5580: DLL loaded at 0x00007FFEE1880000: C:\\Windows\\System32\\shcore (0xad000 bytes).\n2026-02-10 12:22:13,338 [root] DEBUG: 5580: DLL loaded at 0x00007FFECDA20000: C:\\Windows\\System32\\thumbcache (0x66000 bytes).\n2026-02-10 12:22:13,356 [root] DEBUG: 5580: DLL loaded at 0x00007FFEDC720000: C:\\Windows\\system32\\propsys (0xf6000 bytes).\n2026-02-10 12:22:13,755 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 1620: C:\\Windows\\system32\\DrvInst.exe, ImageBase: 0x00007FF70A390000\n2026-02-10 12:22:13,757 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 1620\n2026-02-10 12:22:13,758 [lib.api.process] INFO: Monitor config for <Process 1620 drvinst.exe>: C:\\tsm41i5n\\dll\\1620.ini\n2026-02-10 12:22:13,767 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:13,778 [root] DEBUG: Loader: Injecting process 1620 (thread 3424) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,779 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:22:13,782 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,786 [lib.api.process] INFO: Injected into 64-bit <Process 1620 drvinst.exe>\n2026-02-10 12:22:13,788 [root] INFO: Announced 64-bit process name: drvinst.exe pid: 1620\n2026-02-10 12:22:13,789 [lib.api.process] INFO: Monitor config for <Process 1620 drvinst.exe>: C:\\tsm41i5n\\dll\\1620.ini\n2026-02-10 12:22:13,795 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:22:13,810 [root] DEBUG: Loader: Injecting process 1620 (thread 3424) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,814 [root] DEBUG: InjectDllViaIAT: This image has already been patched.\n2026-02-10 12:22:13,816 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:22:13,824 [lib.api.process] INFO: Injected into 64-bit <Process 1620 drvinst.exe>\n2026-02-10 12:22:13,839 [root] DEBUG: 1620: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:22:13,840 [root] DEBUG: 1620: Dropped file limit defaulting to 100.\n2026-02-10 12:22:13,845 [root] DEBUG: 1620: Disabling sleep skipping.\n2026-02-10 12:22:13,847 [root] DEBUG: 1620: YaraInit: Compiled rules loaded from existing file C:\\tsm41i5n\\data\\yara\\capemon.yac\n2026-02-10 12:22:13,873 [root] DEBUG: 1620: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:22:13,874 [root] DEBUG: 1620: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:13,880 [root] DEBUG: 1620: Monitor initialised: 64-bit capemon loaded in process 1620 at 0x00007FFEC03D0000, thread 3424, image base 0x00007FF70A390000, stack from 0x000000971CED5000-0x000000971CEE0000\n2026-02-10 12:22:13,881 [root] DEBUG: 1620: Commandline: DrvInst.exe \"4\" \"1\" \"C:\\Windows\\SysWOW64\\ZoneLabs\\vsdatant.inf\" \"9\" \"493f6c84b\" \"0000000000000E88\" \"WinSta0\\Default\" \"0000000000000E70\" \"208\" \"C:\\Windows\\SysWOW64\\ZoneLabs\"\n2026-02-10 12:22:13,895 [root] DEBUG: 1620: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress\n2026-02-10 12:22:13,946 [root] WARNING: b'Unable to place hook on LockResource'\n2026-02-10 12:22:13,947 [root] DEBUG: 1620: set_hooks: Unable to hook LockResource\n2026-02-10 12:22:13,958 [root] DEBUG: 1620: Hooked 619 out of 620 functions\n2026-02-10 12:22:13,964 [root] DEBUG: 1620: Syscall hook installed, syscall logging level 1\n2026-02-10 12:22:13,970 [root] INFO: Announced starting service \"b'WSearch'\"\n2026-02-10 12:22:13,973 [root] DEBUG: 1620: RestoreHeaders: Restored original import table.\n2026-02-10 12:22:13,974 [root] INFO: Loaded monitor into process with pid 1620\n2026-02-10 12:22:13,976 [root] DEBUG: 1620: caller_dispatch: Added region at 0x00007FF70A390000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF70A3C9CF1, thread 3424).\n2026-02-10 12:22:13,977 [root] DEBUG: 1620: YaraScan: Scanning 0x00007FF70A390000, size 0x561c4\n2026-02-10 12:22:13,984 [root] DEBUG: 1620: ProcessImageBase: Main module image at 0x00007FF70A390000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:22:13,986 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: ￎ￲￪￠￧￠￭￮ ￢ ￤￮￱￲￳￯￥.\n2026-02-10 12:22:13,987 [root] DEBUG: 1620: OpenProcessHandler: Injection info created for process 740, handle 0x1f4: Error obtaining target process name\n2026-02-10 12:22:13,991 [root] DEBUG: 1620: DLL loaded at 0x00007FFEC7F70000: C:\\Windows\\system32\\DEVRTL (0x14000 bytes).\n2026-02-10 12:22:13,996 [root] DEBUG: 1620: DLL loaded at 0x00007FFECED50000: C:\\Windows\\system32\\drvstore (0x148000 bytes).\n2026-02-10 12:22:14,134 [root] DEBUG: 1620: DLL loaded at 0x00007FFED9750000: C:\\Windows\\system32\\cabinet (0x29000 bytes).\n2026-02-10 12:22:14,157 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp\n2026-02-10 12:22:14,183 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp\n2026-02-10 12:22:14,217 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp\n2026-02-10 12:22:14,236 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp\n2026-02-10 12:22:14,270 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp\n2026-02-10 12:22:14,292 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp\n2026-02-10 12:22:14,333 [root] DEBUG: 1620: DLL loaded at 0x00007FFEE0690000: C:\\Windows\\system32\\MSASN1 (0x12000 bytes).\n2026-02-10 12:22:14,343 [root] DEBUG: 1620: DLL loaded at 0x00007FFEE0450000: C:\\Windows\\system32\\CRYPTSP (0x18000 bytes).\n2026-02-10 12:22:14,345 [root] DEBUG: 1620: DLL loaded at 0x00007FFEDFB90000: C:\\Windows\\system32\\rsaenh (0x34000 bytes).\n2026-02-10 12:22:14,348 [root] DEBUG: 1620: DLL loaded at 0x00007FFEE1390000: C:\\Windows\\System32\\bcryptPrimitives (0x82000 bytes).\n2026-02-10 12:22:14,392 [root] DEBUG: 1620: DLL loaded at 0x00007FFEE1470000: C:\\Windows\\System32\\WINTRUST (0x67000 bytes).\n2026-02-10 12:22:14,547 [root] DEBUG: 1620: DLL loaded at 0x00007FFEDF420000: C:\\Windows\\SYSTEM32\\gpapi (0x23000 bytes).\n2026-02-10 12:22:14,967 [root] INFO: Added new file to list with pid None and path C:\\Windows\\INF\\oem2.inf\n2026-02-10 12:22:14,990 [root] DEBUG: 1620: api-rate-cap: NtReleaseMutant hook disabled due to rate\n2026-02-10 12:22:15,052 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.sys\n2026-02-10 12:22:15,067 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\Vsdatant.cat\n2026-02-10 12:22:15,074 [root] INFO: Added new file to list with pid None and path C:\\Windows\\System32\\DriverStore\\FileRepository\\vsdatant.inf_amd64_c01fe17aaf09e5fc\\vsdatant.inf\n2026-02-10 12:22:15,124 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat to files\\672681757a0e5f6d88b0e85dd8e6f1fcb1a50b3691633be50bc9cb83238b0cda; Size is 11513; Max size: 100000000\n2026-02-10 12:22:15,135 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf to files\\5bacd54dafc483f9557711593486ce17f7680855efb62453c24114fa75939df1; Size is 3729; Max size: 100000000\n2026-02-10 12:22:15,140 [root] INFO: Announced starting service \"b'WSearch'\"\n2026-02-10 12:22:15,150 [lib.common.results] INFO: Uploading file C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys to files\\a86f3e175b66ca4597c04fcb9ed080b7b4fc4991fb9713368c7c2665bfc8bee5; Size is 681072; Max size: 100000000\n2026-02-10 12:22:15,221 [root] DEBUG: 1620: NtTerminateProcess hook: Attempting to dump process 1620\n2026-02-10 12:22:15,223 [root] DEBUG: 1620: DoProcessDump: Skipping process dump as code is identical on disk.\n2026-02-10 12:22:15,238 [root] INFO: Process with pid 1620 has terminated\n2026-02-10 12:22:18,420 [root] INFO: Process with pid 5580 has terminated\n2026-02-10 12:22:18,422 [root] DEBUG: 5580: NtTerminateProcess hook: Attempting to dump process 5580\n2026-02-10 12:22:18,424 [root] DEBUG: 5580: DoProcessDump: Skipping process dump as code is identical on disk.\n2026-02-10 12:22:21,673 [root] DEBUG: 4880: NtTerminateProcess hook: Attempting to dump process 4880\n2026-02-10 12:22:21,676 [root] DEBUG: 4880: DoProcessDump: Skipping process dump as code is identical on disk.\n2026-02-10 12:22:21,692 [root] INFO: Process with pid 4880 has terminated\n2026-02-10 12:22:43,009 [root] INFO: Announced starting service \"b'WSearch'\"\n2026-02-10 12:23:09,286 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 6072: C:\\Windows\\SystemApps\\ShellExperienceHost_cw5n1h2txyewy\\ShellExperienceHost.exe, ImageBase: 0x00007FF750720000\n2026-02-10 12:23:09,287 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 6072\n2026-02-10 12:23:09,288 [lib.api.process] INFO: Monitor config for <Process 6072 ShellExperienceHost.exe>: C:\\tsm41i5n\\dll\\6072.ini\n2026-02-10 12:23:10,740 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:23:10,756 [root] DEBUG: Loader: Injecting process 6072 (thread 3424) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:10,758 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:23:10,759 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:10,764 [lib.api.process] INFO: Injected into 64-bit <Process 6072 ShellExperienceHost.exe>\n2026-02-10 12:23:10,767 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 6072\n2026-02-10 12:23:10,769 [lib.api.process] INFO: Monitor config for <Process 6072 ShellExperienceHost.exe>: C:\\tsm41i5n\\dll\\6072.ini\n2026-02-10 12:23:11,986 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:23:11,997 [root] DEBUG: Loader: Injecting process 6072 (thread 3424) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:11,998 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:23:11,999 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:12,003 [lib.api.process] INFO: Injected into 64-bit <Process 6072 ShellExperienceHost.exe>\n2026-02-10 12:23:12,005 [root] INFO: Announced 64-bit process name: ShellExperienceHost.exe pid: 6072\n2026-02-10 12:23:12,006 [lib.api.process] INFO: Monitor config for <Process 6072 ShellExperienceHost.exe>: C:\\tsm41i5n\\dll\\6072.ini\n2026-02-10 12:23:13,110 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:23:13,123 [root] DEBUG: Loader: Injecting process 6072 (thread 3424) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:13,125 [root] DEBUG: InjectDllViaIAT: This image has already been patched.\n2026-02-10 12:23:13,127 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:13,131 [lib.api.process] INFO: Injected into 64-bit <Process 6072 ShellExperienceHost.exe>\n2026-02-10 12:23:14,310 [root] INFO: Announced starting service \"b'WSearch'\"\n2026-02-10 12:23:39,139 [root] DEBUG: 740: CreateProcessHandler: Injection info set for new process 5480: C:\\Windows\\system32\\DllHost.exe, ImageBase: 0x00007FF6F8170000\n2026-02-10 12:23:39,141 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5480\n2026-02-10 12:23:39,142 [lib.api.process] INFO: Monitor config for <Process 5480 dllhost.exe>: C:\\tsm41i5n\\dll\\5480.ini\n2026-02-10 12:23:39,151 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:23:39,165 [root] DEBUG: Loader: Injecting process 5480 (thread 5916) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:39,167 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:23:39,168 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:39,174 [lib.api.process] INFO: Injected into 64-bit <Process 5480 dllhost.exe>\n2026-02-10 12:23:39,176 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 5480\n2026-02-10 12:23:39,178 [lib.api.process] INFO: Monitor config for <Process 5480 dllhost.exe>: C:\\tsm41i5n\\dll\\5480.ini\n2026-02-10 12:23:39,186 [lib.api.process] INFO: 64-bit DLL to inject is C:\\tsm41i5n\\dll\\eSAgRU.dll, loader C:\\tsm41i5n\\bin\\wyKvxohY.exe\n2026-02-10 12:23:39,200 [root] DEBUG: Loader: Injecting process 5480 (thread 5916) with C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:39,202 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.\n2026-02-10 12:23:39,204 [root] DEBUG: Successfully injected DLL C:\\tsm41i5n\\dll\\eSAgRU.dll.\n2026-02-10 12:23:39,207 [lib.api.process] INFO: Injected into 64-bit <Process 5480 dllhost.exe>\n2026-02-10 12:23:39,221 [root] DEBUG: 5480: Python path set to 'C:\\Users\\Admin\\AppData\\Local\\Programs\\Python\\Python313-32'.\n2026-02-10 12:23:39,222 [root] DEBUG: 5480: Dropped file limit defaulting to 100.\n2026-02-10 12:23:39,226 [root] DEBUG: 5480: Disabling sleep skipping.\n2026-02-10 12:23:39,229 [root] DEBUG: 5480: YaraInit: Compiled rules loaded from existing file C:\\tsm41i5n\\data\\yara\\capemon.yac\n2026-02-10 12:23:39,253 [root] DEBUG: 5480: RtlInsertInvertedFunctionTable 0x00007FFEE348090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEE35DD4F0\n2026-02-10 12:23:39,254 [root] DEBUG: 5480: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026\n2026-02-10 12:23:39,256 [root] DEBUG: 5480: Monitor initialised: 64-bit capemon loaded in process 5480 at 0x00007FFEC03D0000, thread 5916, image base 0x00007FF6F8170000, stack from 0x0000008269EF5000-0x0000008269F00000\n2026-02-10 12:23:39,258 [root] DEBUG: 5480: Commandline: C:\\Windows\\system32\\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}\n2026-02-10 12:23:39,271 [root] DEBUG: 5480: hook_api: LdrpCallInitRoutine export address 0x00007FFEE34899BC obtained via GetFunctionAddress\n2026-02-10 12:23:39,320 [root] WARNING: b'Unable to place hook on LockResource'\n2026-02-10 12:23:39,323 [root] DEBUG: 5480: set_hooks: Unable to hook LockResource\n2026-02-10 12:23:39,334 [root] DEBUG: 5480: Hooked 619 out of 620 functions\n2026-02-10 12:23:39,336 [root] DEBUG: 5480: Syscall hook installed, syscall logging level 1\n2026-02-10 12:23:39,344 [root] DEBUG: 5480: RestoreHeaders: Restored original import table.\n2026-02-10 12:23:39,346 [root] INFO: Loaded monitor into process with pid 5480\n2026-02-10 12:23:39,349 [root] DEBUG: 5480: caller_dispatch: Added region at 0x00007FF6F8170000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6F81712F2, thread 5916).\n2026-02-10 12:23:39,350 [root] DEBUG: 5480: YaraScan: Scanning 0x00007FF6F8170000, size 0x8026\n2026-02-10 12:23:39,352 [root] DEBUG: 5480: ProcessImageBase: Main module image at 0x00007FF6F8170000 unmodified (entropy change 0.000000e+00)\n2026-02-10 12:23:39,358 [root] DEBUG: 5480: set_hooks_by_export_directory: Hooked 0 out of 620 functions\n2026-02-10 12:23:39,359 [root] DEBUG: 5480: DLL loaded at 0x00007FFEDEA70000: C:\\Windows\\SYSTEM32\\kernel.appcore (0x12000 bytes).\n2026-02-10 12:23:39,362 [root] DEBUG: 5480: DLL loaded at 0x00007FFEE1390000: C:\\Windows\\System32\\bcryptPrimitives (0x82000 bytes).\n2026-02-10 12:23:39,368 [root] DEBUG: 5480: DLL loaded at 0x00007FFEE2C20000: C:\\Windows\\System32\\clbcatq (0xa9000 bytes).\n2026-02-10 12:23:39,400 [root] DEBUG: 5480: DLL loaded at 0x00007FFEDE5B0000: C:\\Windows\\system32\\uxtheme (0x9e000 bytes).\n2026-02-10 12:23:39,435 [root] DEBUG: 5480: DLL loaded at 0x00007FFEE1880000: C:\\Windows\\System32\\shcore (0xad000 bytes).\n2026-02-10 12:23:39,437 [root] DEBUG: 5480: DLL loaded at 0x00007FFECDA20000: C:\\Windows\\System32\\thumbcache (0x66000 bytes).\n2026-02-10 12:23:39,452 [root] DEBUG: 5480: DLL loaded at 0x00007FFEDC720000: C:\\Windows\\system32\\propsys (0xf6000 bytes).\n2026-02-10 12:23:44,496 [root] INFO: Process with pid 5480 has terminated\n2026-02-10 12:23:44,498 [root] DEBUG: 5480: NtTerminateProcess hook: Attempting to dump process 5480\n2026-02-10 12:23:44,500 [root] DEBUG: 5480: DoProcessDump: Skipping process dump as code is identical on disk.\n",
    "errors": []
  },
  "network": {
    "pcap_sha256": "df845e1ff07e17e61b2ce3e8567d522a58374aa97c18ba51a16f0ec70dfd27fd",
    "hosts": [
      {
        "ip": "3.174.113.98",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "gwevents.checkpoint.com",
        "inaddrarpa": "server-3-174-113-98.hel51.r.cloudfront.net.",
        "ports": []
      },
      {
        "ip": "23.73.2.148",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "vpnhotspot.checkpoint.com",
        "inaddrarpa": "a23-73-2-148.deploy.static.akamaitechnologies.com.",
        "ports": []
      },
      {
        "ip": "3.174.113.56",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "gwevents.checkpoint.com",
        "inaddrarpa": "server-3-174-113-56.hel51.r.cloudfront.net.",
        "ports": []
      },
      {
        "ip": "98.66.133.184",
        "country_name": "unknown",
        "asn": "",
        "asn_name": "",
        "hostname": "",
        "inaddrarpa": "",
        "ports": []
      }
    ],
    "domains": [
      {
        "domain": "mozilla.map.fastly.net",
        "ip": "151.101.129.91"
      },
      {
        "domain": "gwevents.checkpoint.com",
        "ip": "3.174.113.12"
      },
      {
        "domain": "vpnhotspot.checkpoint.com",
        "ip": "184.51.88.19"
      }
    ],
    "tcp": [
      {
        "src": "192.168.1.2",
        "sport": 49673,
        "dst": "98.66.133.184",
        "dport": 443,
        "offset": 24,
        "time": 0.0
      },
      {
        "src": "192.168.1.2",
        "sport": 49672,
        "dst": "98.66.133.184",
        "dport": 443,
        "offset": 193,
        "time": 0.1163640022277832
      },
      {
        "src": "192.168.1.2",
        "sport": 49676,
        "dst": "199.232.210.172",
        "dport": 80,
        "offset": 6826,
        "time": 0.6682510375976562
      },
      {
        "src": "192.168.1.2",
        "sport": 49683,
        "dst": "34.120.208.123",
        "dport": 443,
        "offset": 27566,
        "time": 1.3749830722808838
      },
      {
        "src": "192.168.1.2",
        "sport": 49686,
        "dst": "23.210.163.238",
        "dport": 80,
        "offset": 52342,
        "time": 1.4322021007537842
      },
      {
        "src": "192.168.1.2",
        "sport": 49688,
        "dst": "151.101.65.91",
        "dport": 443,
        "offset": 63056,
        "time": 1.6237401962280273
      },
      {
        "src": "192.168.1.2",
        "sport": 49692,
        "dst": "23.210.163.238",
        "dport": 80,
        "offset": 98006,
        "time": 1.8954451084136963
      },
      {
        "src": "192.168.1.2",
        "sport": 49694,
        "dst": "23.210.163.238",
        "dport": 80,
        "offset": 117570,
        "time": 2.081937074661255
      },
      {
        "src": "192.168.1.2",
        "sport": 49699,
        "dst": "151.101.193.91",
        "dport": 443,
        "offset": 128296,
        "time": 2.4733850955963135
      },
      {
        "src": "192.168.1.2",
        "sport": 49700,
        "dst": "20.73.194.208",
        "dport": 443,
        "offset": 138373,
        "time": 2.6803231239318848
      },
      {
        "src": "192.168.1.2",
        "sport": 49704,
        "dst": "40.127.240.158",
        "dport": 443,
        "offset": 215572,
        "time": 3.1229259967803955
      },
      {
        "src": "192.168.1.2",
        "sport": 49707,
        "dst": "151.101.193.91",
        "dport": 443,
        "offset": 251495,
        "time": 3.7840871810913086
      },
      {
        "src": "192.168.1.2",
        "sport": 49710,
        "dst": "40.127.240.158",
        "dport": 443,
        "offset": 596113,
        "time": 4.931332111358643
      },
      {
        "src": "192.168.1.2",
        "sport": 49712,
        "dst": "40.127.240.158",
        "dport": 443,
        "offset": 613890,
        "time": 5.3525331020355225
      },
      {
        "src": "192.168.1.2",
        "sport": 49715,
        "dst": "40.127.240.158",
        "dport": 443,
        "offset": 635003,
        "time": 8.419686079025269
      },
      {
        "src": "192.168.1.2",
        "sport": 49719,
        "dst": "4.231.128.59",
        "dport": 443,
        "offset": 649973,
        "time": 9.414152145385742
      },
      {
        "src": "192.168.1.2",
        "sport": 49721,
        "dst": "4.231.128.59",
        "dport": 443,
        "offset": 664539,
        "time": 10.252799034118652
      },
      {
        "src": "192.168.1.2",
        "sport": 49741,
        "dst": "98.66.133.184",
        "dport": 443,
        "offset": 685254,
        "time": 25.942413091659546
      },
      {
        "src": "192.168.1.2",
        "sport": 49742,
        "dst": "98.66.133.184",
        "dport": 443,
        "offset": 685660,
        "time": 25.95362615585327
      },
      {
        "src": "192.168.1.2",
        "sport": 49756,
        "dst": "3.174.113.56",
        "dport": 443,
        "offset": 714470,
        "time": 29.97717308998108
      },
      {
        "src": "192.168.1.2",
        "sport": 49768,
        "dst": "95.100.177.68",
        "dport": 80,
        "offset": 726046,
        "time": 62.522696018218994
      },
      {
        "src": "192.168.1.2",
        "sport": 49786,
        "dst": "3.174.113.98",
        "dport": 443,
        "offset": 730110,
        "time": 79.09073805809021
      }
    ],
    "udp": [
      {
        "src": "192.168.1.2",
        "sport": 63102,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 6057,
        "time": 0.5761899948120117
      },
      {
        "src": "192.168.1.2",
        "sport": 65443,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 26432,
        "time": 1.337421178817749
      },
      {
        "src": "192.168.1.2",
        "sport": 49719,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 27141,
        "time": 1.364267110824585
      },
      {
        "src": "192.168.1.2",
        "sport": 62222,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 62336,
        "time": 1.5880250930786133
      },
      {
        "src": "192.168.1.2",
        "sport": 62681,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 92259,
        "time": 1.7601630687713623
      },
      {
        "src": "192.168.1.2",
        "sport": 57352,
        "dst": "239.255.255.250",
        "dport": 1900,
        "offset": 121208,
        "time": 2.2115111351013184
      },
      {
        "src": "192.168.1.2",
        "sport": 60210,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 126676,
        "time": 2.406684160232544
      },
      {
        "src": "192.168.1.2",
        "sport": 59316,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 202665,
        "time": 3.0305261611938477
      },
      {
        "src": "192.168.1.2",
        "sport": 63821,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 203010,
        "time": 3.0553781986236572
      },
      {
        "src": "192.168.1.2",
        "sport": 53164,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 250149,
        "time": 3.7176930904388428
      },
      {
        "src": "192.168.1.2",
        "sport": 63291,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 649391,
        "time": 9.31795597076416
      },
      {
        "src": "192.168.1.2",
        "sport": 57348,
        "dst": "239.255.255.250",
        "dport": 3702,
        "offset": 680410,
        "time": 21.818516969680786
      },
      {
        "src": "192.168.1.2",
        "sport": 60725,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 713931,
        "time": 29.77690815925598
      },
      {
        "src": "192.168.1.2",
        "sport": 56520,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 724162,
        "time": 61.32353210449219
      },
      {
        "src": "192.168.1.2",
        "sport": 137,
        "dst": "192.168.1.255",
        "dport": 137,
        "offset": 727744,
        "time": 62.64393901824951
      },
      {
        "src": "192.168.1.2",
        "sport": 5353,
        "dst": "224.0.0.251",
        "dport": 5353,
        "offset": 727960,
        "time": 62.64463996887207
      },
      {
        "src": "192.168.1.2",
        "sport": 57591,
        "dst": "224.0.0.252",
        "dport": 5355,
        "offset": 728045,
        "time": 62.64596509933472
      },
      {
        "src": "192.168.1.2",
        "sport": 56435,
        "dst": "1.1.1.1",
        "dport": 53,
        "offset": 729571,
        "time": 77.99538516998291
      },
      {
        "src": "192.168.1.2",
        "sport": 138,
        "dst": "192.168.1.255",
        "dport": 138,
        "offset": 740579,
        "time": 134.47879099845886
      }
    ],
    "icmp": [],
    "http": [],
    "dns": [
      {
        "request": "mozilla.map.fastly.net",
        "type": "A",
        "answers": [
          {
            "type": "A",
            "data": "151.101.1.91"
          },
          {
            "type": "A",
            "data": "151.101.65.91"
          },
          {
            "type": "A",
            "data": "151.101.129.91"
          },
          {
            "type": "A",
            "data": "151.101.193.91"
          }
        ],
        "first_seen": 1770726127.338773
      },
      {
        "request": "mozilla.map.fastly.net",
        "type": "AAAA",
        "answers": [
          {
            "type": "AAAA",
            "data": "2a04:4e42:600::347"
          },
          {
            "type": "AAAA",
            "data": "2a04:4e42:200::347"
          },
          {
            "type": "AAAA",
            "data": "2a04:4e42:400::347"
          },
          {
            "type": "AAAA",
            "data": "2a04:4e42::347"
          }
        ],
        "first_seen": 1770726127.340517
      },
      {
        "request": "gwevents.checkpoint.com",
        "type": "A",
        "answers": [
          {
            "type": "A",
            "data": "3.174.113.12"
          },
          {
            "type": "CNAME",
            "data": "d32y9xjj51kli0.cloudfront.net"
          },
          {
            "type": "A",
            "data": "3.174.113.98"
          },
          {
            "type": "A",
            "data": "3.174.113.56"
          },
          {
            "type": "A",
            "data": "3.174.113.112"
          }
        ],
        "first_seen": 1770726155.527656
      },
      {
        "request": "vpnhotspot.checkpoint.com",
        "type": "A",
        "answers": [
          {
            "type": "CNAME",
            "data": "vpnhotspot.checkpoint.com.edgesuite.net"
          },
          {
            "type": "A",
            "data": "23.73.2.148"
          },
          {
            "type": "A",
            "data": "23.73.2.133"
          },
          {
            "type": "CNAME",
            "data": "a724.b.akamai.net"
          }
        ],
        "first_seen": 1770726190.690941
      }
    ],
    "smtp": [],
    "irc": [],
    "dead_hosts": [
      [
        "23.73.2.148",
        80
      ]
    ]
  },
  "url_analysis": {},
  "procmemory": [],
  "signatures": [
    {
      "name": "stealth_network",
      "description": "Network activity detected but not expressed in monitor API logs",
      "categories": [
        "stealth"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "ip": "3.174.113.98"
        },
        {
          "ip": "23.73.2.148"
        },
        {
          "ip": "3.174.113.56"
        },
        {
          "ip": "98.66.133.184"
        },
        {
          "domain": "mozilla.map.fastly.net"
        },
        {
          "domain": "gwevents.checkpoint.com"
        },
        {
          "domain": "vpnhotspot.checkpoint.com"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "queries_keyboard_layout",
      "description": "Queries the keyboard layout",
      "categories": [
        "location_discovery"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "type": "call",
          "pid": 4880,
          "cid": 5031
        },
        {
          "type": "call",
          "pid": 5580,
          "cid": 741
        },
        {
          "type": "call",
          "pid": 5480,
          "cid": 777
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "antidebug_setunhandledexceptionfilter",
      "description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
      "categories": [
        "anti-debug"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 40,
      "references": [],
      "data": [
        {
          "type": "call",
          "pid": 4880,
          "cid": 1
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "stealth_timeout",
      "description": "Possible date expiration check, exits too soon after checking local time",
      "categories": [
        "stealth"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 40,
      "references": [],
      "data": [
        {
          "process": "msiexec.exe, PID 4880"
        },
        {
          "type": "call",
          "pid": 4880,
          "cid": 5036
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "language_check_registry",
      "description": "Checks system language via registry key (possible geofencing)",
      "categories": [
        "location_discovery",
        "geofence"
      ],
      "severity": 1,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\ru-RU"
        },
        {
          "regkey": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\ru-RU"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "anomalous_deletefile",
      "description": "Anomalous file deletion behavior detected (10+)",
      "categories": [
        "malware"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC11A.tmp"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 872
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC14A.tmp"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 976
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\SETC179.tmp"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 1059
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.cat"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 5877
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.inf"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 5881
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{6e536eff-2c8a-9945-99bf-f39880f4bd0a}\\vnaap.sys"
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 5885
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF52.tmp"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 850
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCF92.tmp"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 948
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\SETCFC2.tmp"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 1025
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\Vsdatant.cat"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 5687
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.inf"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 5691
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\Temp\\{bc98a47b-37a0-c84d-abba-914ddb19a511}\\vsdatant.sys"
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 5695
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "encrypted_ioc",
      "description": "At least one IP Address, Domain, or File Name was found in a crypto call",
      "categories": [
        "encryption"
      ],
      "severity": 2,
      "weight": 0,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "type": "call",
          "pid": 2964,
          "cid": 3546
        },
        {
          "type": "call",
          "pid": 2964,
          "cid": 3746
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 3508
        },
        {
          "type": "call",
          "pid": 1620,
          "cid": 3707
        },
        {
          "ioc": "vnaap.inf"
        },
        {
          "ioc": "vnaap.cat"
        },
        {
          "ioc": "2.1.3.0"
        },
        {
          "ioc": "pollo.ndi"
        },
        {
          "ioc": "sdatant.cat"
        },
        {
          "ioc": "14.39.35.110"
        },
        {
          "ioc": "sdatant.copyfiles.sys"
        },
        {
          "ioc": "vsdatant.sys"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "resumethread_remote_process",
      "description": "Resumed a thread in another process",
      "categories": [
        "injection",
        "unpacking"
      ],
      "severity": 2,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "thread_resumed": "Process svchost.exe with process ID 740 resumed a thread in another process with the process ID 6072"
        },
        {
          "type": "call",
          "pid": 740,
          "cid": 198
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "stealth_file",
      "description": "Creates a hidden or system file",
      "categories": [
        "stealth"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 50,
      "references": [],
      "data": [
        {
          "type": "call",
          "pid": 2964,
          "cid": 4884
        },
        {
          "file": "C:\\Windows\\System32\\DriverStore\\drvstore.tmp"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    },
    {
      "name": "persistence_service",
      "description": "Created a service that was not started",
      "categories": [
        "persistence"
      ],
      "severity": 3,
      "weight": 1,
      "confidence": 100,
      "references": [],
      "data": [
        {
          "service": "vna_ap"
        }
      ],
      "new_data": [],
      "alert": false,
      "families": []
    }
  ],
  "malscore": 6.9,
  "ttps": [
    {
      "signature": "anomalous_deletefile",
      "ttps": [
        "T1485"
      ],
      "mbcs": [
        "OB0008",
        "E1485",
        "OC0001",
        "C0047"
      ]
    },
    {
      "signature": "resumethread_remote_process",
      "ttps": [
        "T1055"
      ],
      "mbcs": [
        "OC0006",
        "C0002"
      ]
    },
    {
      "signature": "stealth_file",
      "ttps": [
        "T1564.001",
        "T1564"
      ],
      "mbcs": [
        "OB0006",
        "F0005",
        "OC0001",
        "C0016"
      ]
    },
    {
      "signature": "persistence_service",
      "ttps": [
        "T1543.003",
        "T1543"
      ],
      "mbcs": [
        "OB0012",
        "F0011"
      ]
    }
  ],
  "malstatus": null
}